system
The system uses generative AI to monitor and respond to cyberattacks, enhancing security by detecting unauthorized access and predicting future threats, thereby safeguarding enterprises and social infrastructure.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- SOFTBANK GROUP CORP
- Filing Date
- 2024-10-18
- Publication Date
- 2026-05-01
AI Technical Summary
Existing systems fail to adequately detect cyberattacks at an early stage and implement appropriate countermeasures, posing risks to enterprises and social infrastructure.
A system utilizing generative AI at the gateway of communication infrastructure to monitor network traffic, detect unauthorized access and system intrusions, and take countermeasures, including blocking access, notifying administrators, and predicting future attacks based on past data.
Enables early detection and prevention of cyberattacks, protecting businesses and homes by quickly responding to known and unknown threats and minimizing damage.
Smart Images

Figure 2026073150000001_ABST
Abstract
Description
Technical Field
[0001] The technology of the present disclosure relates to a system.
Background Art
[0002] Patent Document 1 discloses a method for controlling a persona chatbot, which is performed by at least one processor, and includes steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to an explanation of a character of the chatbot, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance in response to the user utterance.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] In the conventional technology, early detection of cyberattacks and appropriate countermeasures are not sufficiently taken, which may have a great impact on enterprises and social infrastructure.
[0005] The system according to the embodiment aims to detect a cyberattack at an early stage and take appropriate countermeasures.
Means for Solving the Problems
[0006] The system according to this embodiment comprises a monitoring unit, a detection unit, a countermeasure unit, and an analysis unit. The monitoring unit monitors network traffic. The detection unit detects unauthorized access and system intrusions from the traffic monitored by the monitoring unit. The countermeasure unit takes appropriate countermeasures against cyberattacks detected by the detection unit. The analysis unit analyzes past attack methods and predicts future attacks. [Effects of the Invention]
[0007] The system according to this embodiment can detect cyberattacks early and take appropriate countermeasures. [Brief explanation of the drawing]
[0008] [Figure 1] This is a conceptual diagram showing an example of the configuration of a data processing system according to the first embodiment. [Figure 2] This is a conceptual diagram showing an example of the essential functions of a data processing device and a smart device according to the first embodiment. [Figure 3] This is a conceptual diagram showing an example of the configuration of a data processing system according to the second embodiment. [Figure 4] This is a conceptual diagram showing an example of the main functions of a data processing device and smart glasses according to the second embodiment. [Figure 5] This is a conceptual diagram showing an example of the configuration of a data processing system according to the third embodiment. [Figure 6] This is a conceptual diagram showing an example of the main functions of a data processing device and a headset-type terminal according to the third embodiment. [Figure 7] This is a conceptual diagram showing an example of the configuration of a data processing system according to the fourth embodiment. [Figure 8] This is a conceptual diagram showing an example of the main functions of a data processing device and a robot according to the fourth embodiment. [Figure 9] This shows an emotion map where multiple emotions are mapped. [Figure 10] This shows an emotion map where multiple emotions are mapped. [Modes for carrying out the invention]
[0009] Hereinafter, an example of an embodiment of the system relating to the technology of this disclosure will be described with reference to the attached drawings.
[0010] First, let's explain the terminology used in the following explanation.
[0011] In the following embodiments, the signed processor (hereinafter simply referred to as "processor") may be a single arithmetic unit or a combination of multiple arithmetic units. Furthermore, the processor may be a single type of arithmetic unit or a combination of multiple types of arithmetic units. Examples of arithmetic units include CPU (Central Processing Unit), GPU (Graphics Processing Unit), GPGPU (General-Purpose computing on Graphics Processing Units), APU (Accelerated Processing Unit), or TPU (Tensor Processing Unit).
[0012] In the following embodiments, signed RAM (Random Access Memory) is a memory that temporarily stores information and is used as work memory by the processor.
[0013] In the following embodiments, the signed storage is one or more non-volatile storage devices that store various programs and various parameters. Examples of non-volatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), or magnetic tapes.
[0014] In the following embodiments, the labeled communication I / F (Interface) is an interface including a communication processor, an antenna, and the like. The communication I / F manages communication between a plurality of computers. Examples of communication standards applicable to the communication I / F include wireless communication standards such as 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), or Bluetooth (registered trademark).
[0015] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B". That is, "A and / or B" means that it may be only A, only B, or a combination of A and B. Also, in this specification, when expressing three or more matters connected by "and / or", the same concept as "A and / or B" is applied.
[0016] [First Embodiment] FIG. 1 shows an example of the configuration of a data processing system 10 according to the first embodiment.
[0017] As shown in FIG. 1, the data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.
[0018] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. Also, the database 24 and the communication I / F 26 are connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0019] The smart device 14 comprises a computer 36, a receiving device 38, an output device 40, a camera 42, and a communication interface 44. The computer 36 comprises a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The receiving device 38, output device 40, and camera 42 are also connected to the bus 52.
[0020] The reception device 38 is equipped with a touch panel 38A and a microphone 38B, and accepts user input. The touch panel 38A accepts user input via touch by detecting contact with an object (e.g., a pen or finger). The microphone 38B accepts user input via voice by detecting the user's voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and microphone 38B to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 (see Figure 2) acquires the data indicating the user input.
[0021] The output device 40 includes a display 40A and a speaker 40B, and presents data to the user by outputting the data in a form perceptible to the user (e.g., audio and / or text). The display 40A displays visible information such as text and images according to instructions from the processor 46. The speaker 40B outputs audio according to instructions from the processor 46. The camera 42 is a small digital camera equipped with an optical system such as a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.
[0022] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various types of information between processor 46 and processor 28 via network 54.
[0023] Figure 2 shows an example of the main functions of the data processing device 12 and the smart device 14.
[0024] As shown in Figure 2, in the data processing device 12, a specific processing is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" related to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.
[0025] Storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotions using the emotion identification model 59 and perform identification processing using the user's emotions. The emotion estimation function (emotion identification function) using the emotion identification model 59 performs various estimations and predictions regarding the user's emotions, including but not limited to these examples. Furthermore, emotion estimation and prediction also include, for example, emotion analysis.
[0026] In the smart device 14, specific processing is performed by the processor 46. The storage 50 stores a specific processing program 60. The specific processing program 60 is used in conjunction with the specific processing program 56 by the data processing system 10. The processor 46 reads the specific processing program 60 from the storage 50 and executes the read specific processing program 60 on the RAM 48. The specific processing is realized by the processor 46 operating as a control unit 46A according to the specific processing program 60 executed on the RAM 48. The smart device 14 also has a data generation model 58 and an emotion identification model 59, similar to the data generation model and emotion identification model 59, and can perform processing similar to that of the specific processing unit 290 using these models.
[0027] Furthermore, other devices besides the data processing device 12 may also have the data generation model 58. For example, a server device (e.g., a generation server) may have the data generation model 58. In this case, the data processing device 12 obtains processing results (such as prediction results) using the data generation model 58 by communicating with the server device having the data generation model 58. The data processing device 12 may also be a server device or a terminal device owned by a user (e.g., a mobile phone, robot, home appliance, etc.). Next, an example of processing by the data processing system 10 according to the first embodiment will be described.
[0028] (Example of form 1) The cyberattack-specialized system according to an embodiment of the present invention is a system using generative AI for the purpose of early detection and prevention of cyberattacks. This system is equipped with generative AI at the gateway of a communication infrastructure and can detect cyberattacks such as unauthorized access, system intrusion, malware infection, and remote control at an early stage and take countermeasures. This system is important for protecting the business continuity of companies, supply chains, and the stability of social infrastructure, and can also be applied as a home gateway to prevent attacks on IoT devices that are widespread in homes. For example, the generative AI is installed at the gateway of a communication infrastructure and monitors network traffic. For example, in a company network, the generative AI analyzes data packets in real time and detects signs of unauthorized access or system intrusion. Specifically, it detects theft or guessing of account information, brute-force attacks, attacks that exploit software defects or vulnerabilities, and fraudulent means of inducement. Next, the generative AI takes appropriate countermeasures according to the type of cyberattack detected. For example, if unauthorized access is detected, the generative AI immediately blocks access and notifies the system administrator. Also, if malware infection is detected, the generative AI identifies the infection route and implements measures to prevent the spread of infection. Furthermore, the generating AI instantly analyzes past attack methods and predicts future attacks to maintain the system's normal operation. For example, based on data from past cyberattacks, it can predict future attack patterns and take preventative measures. This improves the security of businesses and social infrastructure, minimizing damage from cyberattacks. This system can be applied not only to corporate networks but also to IoT devices in homes. For example, if a smart device in a home is subjected to a cyberattack, the generating AI can immediately detect the attack and take countermeasures to protect the home's safety. This strengthens cybersecurity measures in anticipation of future IoT proliferation, creating a secure social infrastructure. In short, this cyberattack-specific system enables early detection and prevention of cyberattacks, protecting the safety of businesses and homes.
[0029] The cyberattack-specialized system according to this embodiment comprises a monitoring unit, a detection unit, a countermeasure unit, and an analysis unit. The monitoring unit monitors network traffic. The monitoring unit analyzes data packets in real time on a corporate network, for example. The monitoring unit is installed, for example, at the gateway of a communication infrastructure and monitors network traffic. The monitoring unit analyzes the contents of data packets to detect anomalies in network traffic, for example. The detection unit detects unauthorized access and system intrusion from the traffic monitored by the monitoring unit. The detection unit detects, for example, theft or guessing of account information, brute-force attacks, attacks exploiting software defects or vulnerabilities, and fraudulent means of intrusion. The detection unit analyzes the contents of data packets to detect anomalies in network traffic, for example. The detection unit detects anomalies in network traffic using, for example, generative AI. The countermeasure unit takes appropriate countermeasures against cyberattacks detected by the detection unit. The countermeasure unit blocks access and notifies the system administrator, for example, when unauthorized access is detected. The countermeasures department, for example, identifies the infection route when a malware infection is detected and implements measures to prevent the spread of infection. The countermeasures department, for example, uses generative AI to take countermeasures against cyberattacks. The analysis department analyzes past attack methods and predicts future attacks. The analysis department, for example, predicts future attack patterns based on data from past cyberattacks and takes countermeasures in advance. The analysis department, for example, uses generative AI to analyze past attack methods and predict future attacks. As a result, the cyberattack-specialized system according to this embodiment can achieve early detection and prevention of cyberattacks and protect the safety of businesses and homes.
[0030] The monitoring unit monitors network traffic. For example, the monitoring unit analyzes data packets in real time within a company's network. Specifically, the monitoring unit is installed at the gateway of the communication infrastructure and monitors network traffic. This allows for constant monitoring of communication between the company's internal and external networks, enabling early detection of abnormal traffic. The monitoring unit analyzes the contents of data packets in detail and identifies abnormal packets that deviate from normal communication patterns. For example, it can detect a large volume of requests from a specific IP address or a large volume of data transfers occurring outside of normal business hours. This allows the monitoring unit to detect network traffic anomalies in real time and respond quickly. The monitoring unit also records the network traffic monitoring results as logs, which can be used for later analysis and troubleshooting. Furthermore, the monitoring unit shares network traffic monitoring results with other systems and departments to realize integrated security measures. For example, it can notify the detection unit and the response unit in real time of the abnormal traffic information it has detected, prompting a rapid response. In this way, the monitoring unit strengthens the security of the entire network and contributes to the early detection and prevention of cyberattacks.
[0031] The detection unit detects unauthorized access and system intrusions from traffic monitored by the monitoring unit. Specifically, the detection unit detects theft or guessing of account information, brute-force attacks, attacks exploiting software flaws and vulnerabilities, and fraudulent means of intrusion. The detection unit analyzes the contents of data packets in detail to detect anomalies in network traffic. For example, it identifies attack traffic with specific patterns or signatures and issues an alert immediately. Furthermore, the detection unit uses generative AI to detect anomalies in network traffic. Generative AI has the ability to learn from large amounts of traffic data and distinguish between normal and abnormal communication patterns. For example, generative AI learns communication patterns during normal business hours and detects large amounts of data transfers and access from suspicious IP addresses that occur during abnormal times. In addition, generative AI can predict new attack patterns based on past attack data and respond to unknown attacks. As a result, the detection unit can respond quickly not only to known attacks but also to unknown attacks, thereby strengthening system security. Furthermore, the detection unit notifies the countermeasures unit of the detected anomaly traffic information to encourage a rapid response. This allows the detection unit to enhance the security of the entire network and contribute to the early detection and prevention of cyberattacks.
[0032] The Countermeasures Department takes appropriate measures against cyberattacks detected by the Detection Department. Specifically, it blocks access and notifies system administrators when unauthorized access is detected. For example, the Countermeasures Department immediately blocks malicious traffic using firewalls and intrusion prevention systems (IPS). Furthermore, when malware infection is detected, the Countermeasures Department identifies the infection route and implements measures to prevent the spread of infection. For example, it isolates infected devices from the network and removes malware. In addition, the Countermeasures Department uses Generative AI to implement countermeasures against cyberattacks. Generative AI proposes optimal countermeasures based on past attack data, supporting a rapid and effective response. For example, Generative AI proposes the optimal defense against a specific attack pattern and notifies system administrators. Generative AI can also automatically apply countermeasures to deal with the latest attack methods based on attack information that is updated in real time. This allows the Countermeasures Department to always implement effective countermeasures based on the latest information. Furthermore, the Countermeasures Department works in cooperation with the Detection Department and Monitoring Department to realize integrated security measures. For example, the countermeasures department immediately begins taking action upon receiving notification from the detection department and evaluates the effectiveness of the countermeasures based on information from the monitoring department. In this way, the countermeasures department strengthens the security of the entire network and contributes to the early detection and prevention of cyberattacks.
[0033] The analytics department analyzes past attack methods and predicts future attacks. Specifically, it predicts future attack patterns based on data from past cyberattacks and takes preventative measures. For example, the analytics department analyzes past attack data in detail to understand attackers' methods and tendencies. This allows them to formulate preventative measures against future attacks and strengthen system security. Furthermore, the analytics department uses generative AI to analyze past attack methods and predict future attacks. Generative AI has the ability to learn from large amounts of attack data and predict attacker behavior patterns and new attack methods. For example, based on past attack data, generative AI can predict an increase in attacks during specific periods or events and take preventative measures. In addition, generative AI can use anomaly detection algorithms to detect unusual patterns and abnormal data and issue warnings early. This allows the analytics department to not only grasp the situation in real time but also to handle long-term risk management and anomaly detection, improving the reliability and security of the entire system. Furthermore, the analytics department collaborates with other departments to realize integrated security measures. For example, the analysis department uses information from the monitoring and detection departments to predict future attacks and propose optimal defense measures to the countermeasures department. This allows the analysis department to strengthen the overall network security and contribute to the early detection and prevention of cyberattacks.
[0034] The monitoring unit can analyze data packets in real time. For example, the monitoring unit can analyze data packets in real time to detect anomalies in network traffic. For example, the monitoring unit can analyze data packets in real time to detect signs of unauthorized access or system intrusion. For example, the monitoring unit can analyze data packets in real time to detect signs of malware infection. This enables real-time data analysis. Some or all of the above-described processes in the monitoring unit may be performed using or without generation AI. For example, the monitoring unit can use generation AI to analyze data packets in real time.
[0035] The detection unit can detect theft or guessing of account information, brute-force attacks, attacks exploiting software flaws or vulnerabilities, and fraudulent means of inducement. For example, the detection unit can detect theft of account information. For example, the detection unit can detect brute-force attacks. For example, the detection unit can detect attacks exploiting software flaws or vulnerabilities. For example, the detection unit can detect fraudulent means of inducement. This makes it possible to detect a variety of cyberattacks. Some or all of the above-described processes in the detection unit may be performed using generative AI, or they may not be performed using generative AI. For example, the detection unit can use generative AI to detect theft or guessing of account information, brute-force attacks, attacks exploiting software flaws or vulnerabilities, and fraudulent means of inducement.
[0036] The countermeasures unit can block access and notify the system administrator when unauthorized access is detected. For example, the countermeasures unit blocks access when unauthorized access is detected. For example, the countermeasures unit notifies the system administrator when unauthorized access is detected. For example, the countermeasures unit blocks access and notifies the system administrator when unauthorized access is detected. This enables immediate response to unauthorized access. Some or all of the above processing in the countermeasures unit may be performed using or without generating AI. For example, the countermeasures unit can use generating AI to block access and notify the system administrator when unauthorized access is detected.
[0037] The countermeasures unit can identify the infection route and implement measures to prevent the spread of infection when a malware infection is detected. For example, the countermeasures unit can identify the infection route when a malware infection is detected. For example, the countermeasures unit can implement measures to prevent the spread of infection when a malware infection is detected. For example, the countermeasures unit can identify the infection route and implement measures to prevent the spread of infection when a malware infection is detected. This makes it possible to prevent the spread of malware infection. Some or all of the above processing in the countermeasures unit may be performed using a generation AI, or it may be performed without using a generation AI. For example, the countermeasures unit can use a generation AI to identify the infection route and implement measures to prevent the spread of infection when a malware infection is detected.
[0038] The analysis department can predict future attack patterns based on past cyberattack data and take countermeasures in advance. For example, the analysis department predicts future attack patterns based on past cyberattack data. The analysis department predicts future attack patterns and takes countermeasures in advance. The analysis department predicts future attack patterns based on past cyberattack data and takes countermeasures in advance. This makes it possible to take proactive measures against future attacks. Some or all of the above processing in the analysis department may be performed using generative AI, or not. For example, the analysis department can use generative AI to predict future attack patterns based on past cyberattack data and take countermeasures in advance.
[0039] The monitoring unit can change the monitoring intensity based on specific time periods or days of the week when monitoring network traffic. For example, the monitoring unit can increase the monitoring intensity during business hours and decrease it at night or on holidays. For example, the monitoring unit can set the monitoring intensity lower than usual on weekends and public holidays. For example, the monitoring unit can temporarily increase the monitoring intensity during specific events or campaigns. This makes it possible to adjust the monitoring intensity according to the time of day and day of the week. Some or all of the above processing in the monitoring unit may be performed using or without generating AI. For example, the monitoring unit can use generating AI to change the monitoring intensity based on specific time periods or days of the week when monitoring network traffic.
[0040] The monitoring unit can prioritize monitoring for specific protocols or ports during monitoring. For example, the monitoring unit may prioritize monitoring HTTP or HTTPS traffic. For example, the monitoring unit may prioritize monitoring for specific ports (e.g., 80, 443). For example, the monitoring unit may prioritize monitoring for specific application protocols (e.g., FTP, SMTP). This enables prioritized monitoring for specific protocols or ports. Some or all of the above processing in the monitoring unit may be performed using or without a generating AI. For example, the monitoring unit can use a generating AI to prioritize monitoring for specific protocols or ports during monitoring.
[0041] The monitoring unit can customize its monitoring method based on the type of device in the network during monitoring. For example, the monitoring unit may prioritize monitoring critical devices such as servers and routers. For example, the monitoring unit may apply a specific monitoring method to IoT devices. For example, the monitoring unit may apply a different monitoring method to mobile devices. This allows for customization of the monitoring method according to the type of device. Some or all of the above processing in the monitoring unit may be performed using generative AI, or not. For example, the monitoring unit can use generative AI to customize its monitoring method based on the type of device in the network during monitoring.
[0042] The monitoring unit can adjust its monitoring range during monitoring, taking into account the geographical distribution of the network. For example, the monitoring unit may prioritize monitoring geographically important locations. For example, the monitoring unit may apply different monitoring intensities to overseas locations. For example, the monitoring unit may dynamically adjust its monitoring range for geographically dispersed networks. This makes it possible to adjust the monitoring range according to the geographical distribution. Some or all of the above processing in the monitoring unit may be performed using generative AI, or not. For example, the monitoring unit can use generative AI to adjust its monitoring range during monitoring, taking into account the geographical distribution of the network.
[0043] The detection unit can optimize its detection algorithm by referring to past attack patterns when an attack is detected. For example, the detection unit adjusts its detection algorithm based on past attack data. For example, the detection unit learns past attack patterns and detects new attacks. For example, the detection unit strengthens its detection algorithm based on past attack methods. This makes it possible to optimize the detection algorithm based on past attack patterns. Some or all of the above processes in the detection unit may be performed using generative AI, or they may not be performed using generative AI. For example, the detection unit can use generative AI to optimize its detection algorithm by referring to past attack patterns when an attack is detected.
[0044] The detection unit can apply different detection algorithms to specific attack methods upon detection. For example, the detection unit may apply a specific detection algorithm to brute-force attacks. For example, the detection unit may apply a different detection algorithm to phishing attacks. For example, the detection unit may apply a dedicated detection algorithm to malware infections. This makes it possible to apply detection algorithms to specific attack methods. Some or all of the above processing in the detection unit may be performed using generative AI, or not. For example, the detection unit may use generative AI to apply different detection algorithms to specific attack methods upon detection.
[0045] The detection unit can improve detection accuracy by considering the attribute information of devices in the network when detection occurs. For example, the detection unit adjusts the detection algorithm according to the type of device. For example, the detection unit improves detection accuracy based on the attribute information of the device. For example, the detection unit optimizes the detection algorithm by considering the usage status of the device. This makes it possible to improve detection accuracy based on the attribute information of the device. Some or all of the above processing in the detection unit may be performed using a generation AI, or it may be performed without a generation AI. For example, the detection unit can use a generation AI to improve detection accuracy by considering the attribute information of devices in the network when detection occurs.
[0046] The detection unit can adjust its detection range by referring to network topology information when detection occurs. For example, the detection unit dynamically adjusts the detection range based on network topology information. For example, the detection unit prioritizes detecting important parts by referring to topology information. For example, the detection unit optimizes the detection algorithm based on topology information. This makes it possible to adjust the detection range based on topology information. Some or all of the above processing in the detection unit may be performed using generative AI, or without generative AI. For example, the detection unit can use generative AI to adjust the detection range by referring to network topology information when detection occurs.
[0047] The countermeasures unit can select the optimal countermeasure method by referring to past countermeasure history when implementing countermeasures. For example, the countermeasures unit selects the optimal countermeasure method based on past countermeasure history. For example, the countermeasures unit implements effective countermeasures by referring to past countermeasure data. For example, the countermeasures unit optimizes countermeasure methods based on past countermeasure methods. This makes it possible to select the optimal countermeasure method based on past countermeasure history. Some or all of the above processes in the countermeasures unit may be performed using a generation AI, or they may be performed without a generation AI. For example, the countermeasures unit can use a generation AI to select the optimal countermeasure method by referring to past countermeasure history when implementing countermeasures.
[0048] The countermeasures unit can apply different countermeasures to specific attack methods when implementing countermeasures. For example, the unit can apply specific countermeasures to brute-force attacks. For example, the unit can apply different countermeasures to phishing attacks. For example, the unit can apply dedicated countermeasures to malware infections. This makes it possible to apply countermeasures to specific attack methods. Some or all of the above-described processes in the countermeasures unit may be performed using a generating AI, or not. For example, the countermeasures unit can use a generating AI to apply different countermeasures to specific attack methods when implementing countermeasures.
[0049] The countermeasure unit can customize its countermeasures based on the type of device in the network when implementing countermeasures. For example, the countermeasure unit can apply specific countermeasures to critical devices such as servers and routers. For example, the countermeasure unit can apply different countermeasures to IoT devices. For example, the countermeasure unit can apply a dedicated countermeasure to mobile devices. This makes it possible to customize countermeasures according to the type of device. Some or all of the above processing in the countermeasure unit may be performed using generative AI, or it may be performed without generative AI. For example, the countermeasure unit can use generative AI to customize countermeasures based on the type of device in the network when implementing countermeasures.
[0050] The countermeasures unit can adjust the scope of countermeasures when implementing countermeasures, taking into account the geographical distribution of the network. For example, the countermeasures unit may prioritize countermeasures for geographically important locations. For example, the countermeasures unit may apply different countermeasures to overseas locations. For example, the countermeasures unit may dynamically adjust the scope of countermeasures for geographically dispersed networks. This makes it possible to adjust the scope of countermeasures according to the geographical distribution. Some or all of the above processing in the countermeasures unit may be performed using generative AI, or not. For example, the countermeasures unit may use generative AI to adjust the scope of countermeasures when implementing countermeasures, taking into account the geographical distribution of the network.
[0051] The analysis unit can optimize its analysis algorithm by referring to past attack data during analysis. For example, the analysis unit adjusts its analysis algorithm based on past attack data. For example, the analysis unit learns past attack patterns and analyzes new attacks. For example, the analysis unit strengthens its analysis algorithm based on past attack methods. This makes it possible to optimize the analysis algorithm based on past attack data. Some or all of the above processes in the analysis unit may be performed using generative AI, or not. For example, the analysis unit can use generative AI to optimize its analysis algorithm by referring to past attack data during analysis.
[0052] The analysis unit can apply different analysis methods to specific attack patterns during analysis. For example, the analysis unit can apply a specific analysis method to brute-force attacks. For example, the analysis unit can apply a different analysis method to phishing attacks. For example, the analysis unit can apply a dedicated analysis method to malware infections. This makes it possible to apply analysis methods to specific attack patterns. Some or all of the above-described processes in the analysis unit may be performed using generative AI, or not. For example, the analysis unit can use generative AI to apply different analysis methods to specific attack patterns during analysis.
[0053] The analysis unit can improve analysis accuracy by considering the attribute information of devices in the network during analysis. For example, the analysis unit adjusts the analysis algorithm according to the type of device. For example, the analysis unit improves analysis accuracy based on the device attribute information. For example, the analysis unit optimizes the analysis algorithm by considering the usage status of the device. This makes it possible to improve analysis accuracy based on the device attribute information. Some or all of the above processing in the analysis unit may be performed using generative AI, or not using generative AI. For example, the analysis unit can use generative AI to improve analysis accuracy by considering the attribute information of devices in the network during analysis.
[0054] The analysis unit can adjust the analysis range by referring to the network topology information during analysis. For example, the analysis unit dynamically adjusts the analysis range based on the network topology information. For example, the analysis unit prioritizes the analysis of important parts by referring to the topology information. For example, the analysis unit optimizes the analysis algorithm based on the topology information. This makes it possible to adjust the analysis range based on the topology information. Some or all of the above processes in the analysis unit may be performed using generative AI, or not. For example, the analysis unit can use generative AI to adjust the analysis range by referring to the network topology information during analysis.
[0055] The system according to the embodiment is not limited to the example described above, and various modifications are possible, for example, as follows.
[0056] A cyberattack-specific system can also include a prediction unit. This unit can predict future attack patterns based on historical attack data and current network traffic. For example, it can analyze historical attack data to identify attack patterns associated with specific times or events. It can also analyze attack trends in specific industries or regions to assess future attack risks. Furthermore, it can monitor network traffic in real time, detect anomalous patterns, and predict future attacks. This allows the system to take proactive measures and reduce the risk of cyberattacks.
[0057] A cyberattack-focused system can also include an education department. This department can provide users with cybersecurity education. For example, it can provide training to help users recognize signs of cyberattacks and take appropriate countermeasures. It can also provide guidelines on how to identify phishing emails and how to create secure passwords. Furthermore, it can regularly inform users of the latest security information and best practices. This can improve users' security awareness and reduce the risk of cyberattacks.
[0058] A cyberattack-focused system can also include a cooperation unit. This unit can collaborate with other security systems and external organizations to share information. For example, the cooperation unit can share information about cyberattacks with other companies and government agencies and jointly implement countermeasures. The cooperation unit can, for instance, work with security vendors to obtain the latest threat intelligence and incorporate it into the system. The cooperation unit can, for example, collaborate with international security organizations to monitor global cyberattack trends. This allows the system to implement countermeasures based on a broader range of information, thereby reducing the risk of cyberattacks.
[0059] A cyberattack-specific system can also include a reporting unit. This unit can report the results of cyberattack detection and countermeasures to the user. For example, the reporting unit can generate and provide a detailed report of detected cyberattacks. It can also record a history of cyberattacks for which countermeasures have been taken, allowing the user to refer to it later. Furthermore, it can periodically notify the user of the system's security status and suggest improvements. This allows the user to understand the system's security status and take necessary measures.
[0060] A cyberattack-specific system may also include a recovery unit. This recovery unit can assist in the recovery of a system damaged by a cyberattack. For example, it can recover data damaged by the attack. It can also use system backups to restore the system to its pre-attack state. Furthermore, it can provide emergency response procedures to minimize the impact of the attack. This allows for rapid recovery from cyberattack damage and the resumption of normal system operation.
[0061] The following briefly describes the processing flow for example form 1.
[0062] Step 1: The monitoring unit monitors network traffic. The monitoring unit, for example, analyzes data packets in real time within a company's network and is installed at the gateway of the communication infrastructure. The monitoring unit analyzes the contents of data packets to detect anomalies in network traffic. Step 2: The detection unit detects unauthorized access and system intrusions from the traffic monitored by the monitoring unit. The detection unit detects, for example, theft or guessing of account information, brute-force attacks, attacks exploiting software flaws or vulnerabilities, and fraudulent means of intrusion. The detection unit may also analyze the contents of data packets and use generating AI to detect anomalies in network traffic. Step 3: The countermeasures unit takes appropriate measures against cyberattacks detected by the detection unit. For example, if unauthorized access is detected, the countermeasures unit will block access and notify the system administrator. If malware infection is detected, the unit will identify the infection route and implement measures to prevent the spread of infection. The countermeasures unit may also use generated AI to take countermeasures against cyberattacks. Step 4: The analysis department analyzes past attack methods and predicts future attacks. For example, the analysis department predicts future attack patterns based on data from past cyberattacks and takes countermeasures in advance. The analysis department may also use generative AI to analyze past attack methods and predict future attacks.
[0063] (Example of form 2) The cyberattack-specialized system according to an embodiment of the present invention is a system using generative AI for the purpose of early detection and prevention of cyberattacks. This system is equipped with generative AI at the gateway of a communication infrastructure and can detect cyberattacks such as unauthorized access, system intrusion, malware infection, and remote control at an early stage and take countermeasures. This system is important for protecting the business continuity of companies, supply chains, and the stability of social infrastructure, and can also be applied as a home gateway to prevent attacks on IoT devices that are widespread in homes. For example, the generative AI is installed at the gateway of a communication infrastructure and monitors network traffic. For example, in a company network, the generative AI analyzes data packets in real time and detects signs of unauthorized access or system intrusion. Specifically, it detects theft or guessing of account information, brute-force attacks, attacks that exploit software defects or vulnerabilities, and fraudulent means of inducement. Next, the generative AI takes appropriate countermeasures according to the type of cyberattack detected. For example, if unauthorized access is detected, the generative AI immediately blocks access and notifies the system administrator. Also, if malware infection is detected, the generative AI identifies the infection route and implements measures to prevent the spread of infection. Furthermore, the generating AI instantly analyzes past attack methods and predicts future attacks to maintain the system's normal operation. For example, based on data from past cyberattacks, it can predict future attack patterns and take preventative measures. This improves the security of businesses and social infrastructure, minimizing damage from cyberattacks. This system can be applied not only to corporate networks but also to IoT devices in homes. For example, if a smart device in a home is subjected to a cyberattack, the generating AI can immediately detect the attack and take countermeasures to protect the home's safety. This strengthens cybersecurity measures in anticipation of future IoT proliferation, creating a secure social infrastructure. In short, this cyberattack-specific system enables early detection and prevention of cyberattacks, protecting the safety of businesses and homes.
[0064] The cyberattack-specialized system according to this embodiment comprises a monitoring unit, a detection unit, a countermeasure unit, and an analysis unit. The monitoring unit monitors network traffic. The monitoring unit analyzes data packets in real time on a corporate network, for example. The monitoring unit is installed, for example, at the gateway of a communication infrastructure and monitors network traffic. The monitoring unit analyzes the contents of data packets to detect anomalies in network traffic, for example. The detection unit detects unauthorized access and system intrusion from the traffic monitored by the monitoring unit. The detection unit detects, for example, theft or guessing of account information, brute-force attacks, attacks exploiting software defects or vulnerabilities, and fraudulent means of intrusion. The detection unit analyzes the contents of data packets to detect anomalies in network traffic, for example. The detection unit detects anomalies in network traffic using, for example, generative AI. The countermeasure unit takes appropriate countermeasures against cyberattacks detected by the detection unit. The countermeasure unit blocks access and notifies the system administrator, for example, when unauthorized access is detected. The countermeasures department, for example, identifies the infection route when a malware infection is detected and implements measures to prevent the spread of infection. The countermeasures department, for example, uses generative AI to take countermeasures against cyberattacks. The analysis department analyzes past attack methods and predicts future attacks. The analysis department, for example, predicts future attack patterns based on data from past cyberattacks and takes countermeasures in advance. The analysis department, for example, uses generative AI to analyze past attack methods and predict future attacks. As a result, the cyberattack-specialized system according to this embodiment can achieve early detection and prevention of cyberattacks and protect the safety of businesses and homes.
[0065] The monitoring unit monitors network traffic. For example, the monitoring unit analyzes data packets in real time within a company's network. Specifically, the monitoring unit is installed at the gateway of the communication infrastructure and monitors network traffic. This allows for constant monitoring of communication between the company's internal and external networks, enabling early detection of abnormal traffic. The monitoring unit analyzes the contents of data packets in detail and identifies abnormal packets that deviate from normal communication patterns. For example, it can detect a large volume of requests from a specific IP address or a large volume of data transfers occurring outside of normal business hours. This allows the monitoring unit to detect network traffic anomalies in real time and respond quickly. The monitoring unit also records the network traffic monitoring results as logs, which can be used for later analysis and troubleshooting. Furthermore, the monitoring unit shares network traffic monitoring results with other systems and departments to realize integrated security measures. For example, it can notify the detection unit and the response unit in real time of the abnormal traffic information it has detected, prompting a rapid response. In this way, the monitoring unit strengthens the security of the entire network and contributes to the early detection and prevention of cyberattacks.
[0066] The detection unit detects unauthorized access and system intrusions from traffic monitored by the monitoring unit. Specifically, the detection unit detects theft or guessing of account information, brute-force attacks, attacks exploiting software flaws and vulnerabilities, and fraudulent means of intrusion. The detection unit analyzes the contents of data packets in detail to detect anomalies in network traffic. For example, it identifies attack traffic with specific patterns or signatures and issues an alert immediately. Furthermore, the detection unit uses generative AI to detect anomalies in network traffic. Generative AI has the ability to learn from large amounts of traffic data and distinguish between normal and abnormal communication patterns. For example, generative AI learns communication patterns during normal business hours and detects large amounts of data transfers and access from suspicious IP addresses that occur during abnormal times. In addition, generative AI can predict new attack patterns based on past attack data and respond to unknown attacks. As a result, the detection unit can respond quickly not only to known attacks but also to unknown attacks, thereby strengthening system security. Furthermore, the detection unit notifies the countermeasures unit of the detected anomaly traffic information to encourage a rapid response. This allows the detection unit to enhance the security of the entire network and contribute to the early detection and prevention of cyberattacks.
[0067] The Countermeasures Department takes appropriate measures against cyberattacks detected by the Detection Department. Specifically, it blocks access and notifies system administrators when unauthorized access is detected. For example, the Countermeasures Department immediately blocks malicious traffic using firewalls and intrusion prevention systems (IPS). Furthermore, when malware infection is detected, the Countermeasures Department identifies the infection route and implements measures to prevent the spread of infection. For example, it isolates infected devices from the network and removes malware. In addition, the Countermeasures Department uses Generative AI to implement countermeasures against cyberattacks. Generative AI proposes optimal countermeasures based on past attack data, supporting a rapid and effective response. For example, Generative AI proposes the optimal defense against a specific attack pattern and notifies system administrators. Generative AI can also automatically apply countermeasures to deal with the latest attack methods based on attack information that is updated in real time. This allows the Countermeasures Department to always implement effective countermeasures based on the latest information. Furthermore, the Countermeasures Department works in cooperation with the Detection Department and Monitoring Department to realize integrated security measures. For example, the countermeasures department immediately begins taking action upon receiving notification from the detection department and evaluates the effectiveness of the countermeasures based on information from the monitoring department. In this way, the countermeasures department strengthens the security of the entire network and contributes to the early detection and prevention of cyberattacks.
[0068] The analytics department analyzes past attack methods and predicts future attacks. Specifically, it predicts future attack patterns based on data from past cyberattacks and takes preventative measures. For example, the analytics department analyzes past attack data in detail to understand attackers' methods and tendencies. This allows them to formulate preventative measures against future attacks and strengthen system security. Furthermore, the analytics department uses generative AI to analyze past attack methods and predict future attacks. Generative AI has the ability to learn from large amounts of attack data and predict attacker behavior patterns and new attack methods. For example, based on past attack data, generative AI can predict an increase in attacks during specific periods or events and take preventative measures. In addition, generative AI can use anomaly detection algorithms to detect unusual patterns and abnormal data and issue warnings early. This allows the analytics department to not only grasp the situation in real time but also to handle long-term risk management and anomaly detection, improving the reliability and security of the entire system. Furthermore, the analytics department collaborates with other departments to realize integrated security measures. For example, the analysis department uses information from the monitoring and detection departments to predict future attacks and propose optimal defense measures to the countermeasures department. This allows the analysis department to strengthen the overall network security and contribute to the early detection and prevention of cyberattacks.
[0069] The monitoring unit can analyze data packets in real time. For example, the monitoring unit can analyze data packets in real time to detect anomalies in network traffic. For example, the monitoring unit can analyze data packets in real time to detect signs of unauthorized access or system intrusion. For example, the monitoring unit can analyze data packets in real time to detect signs of malware infection. This enables real-time data analysis. Some or all of the above-described processes in the monitoring unit may be performed using or without generation AI. For example, the monitoring unit can use generation AI to analyze data packets in real time.
[0070] The detection unit can detect theft or guessing of account information, brute-force attacks, attacks exploiting software flaws or vulnerabilities, and fraudulent means of inducement. For example, the detection unit can detect theft of account information. For example, the detection unit can detect brute-force attacks. For example, the detection unit can detect attacks exploiting software flaws or vulnerabilities. For example, the detection unit can detect fraudulent means of inducement. This makes it possible to detect a variety of cyberattacks. Some or all of the above-described processes in the detection unit may be performed using generative AI, or they may not be performed using generative AI. For example, the detection unit can use generative AI to detect theft or guessing of account information, brute-force attacks, attacks exploiting software flaws or vulnerabilities, and fraudulent means of inducement.
[0071] The countermeasures unit can block access and notify the system administrator when unauthorized access is detected. For example, the countermeasures unit blocks access when unauthorized access is detected. For example, the countermeasures unit notifies the system administrator when unauthorized access is detected. For example, the countermeasures unit blocks access and notifies the system administrator when unauthorized access is detected. This enables immediate response to unauthorized access. Some or all of the above processing in the countermeasures unit may be performed using or without generating AI. For example, the countermeasures unit can use generating AI to block access and notify the system administrator when unauthorized access is detected.
[0072] The countermeasures unit can identify the infection route and implement measures to prevent the spread of infection when a malware infection is detected. For example, the countermeasures unit can identify the infection route when a malware infection is detected. For example, the countermeasures unit can implement measures to prevent the spread of infection when a malware infection is detected. For example, the countermeasures unit can identify the infection route and implement measures to prevent the spread of infection when a malware infection is detected. This makes it possible to prevent the spread of malware infection. Some or all of the above processing in the countermeasures unit may be performed using a generation AI, or it may be performed without using a generation AI. For example, the countermeasures unit can use a generation AI to identify the infection route and implement measures to prevent the spread of infection when a malware infection is detected.
[0073] The analysis department can predict future attack patterns based on past cyberattack data and take countermeasures in advance. For example, the analysis department predicts future attack patterns based on past cyberattack data. The analysis department predicts future attack patterns and takes countermeasures in advance. The analysis department predicts future attack patterns based on past cyberattack data and takes countermeasures in advance. This makes it possible to take proactive measures against future attacks. Some or all of the above processing in the analysis department may be performed using generative AI, or not. For example, the analysis department can use generative AI to predict future attack patterns based on past cyberattack data and take countermeasures in advance.
[0074] The monitoring unit can estimate the user's emotions and adjust the monitoring frequency based on the estimated emotions. For example, if the user is stressed, the monitoring unit can increase the monitoring frequency to provide reassurance. For example, if the user is relaxed, the monitoring unit can decrease the monitoring frequency to conserve system resources. For example, if the user is in a hurry, the monitoring unit can prioritize monitoring only important traffic. This makes it possible to adjust the monitoring frequency according to the user's emotions. Emotion estimation is achieved using an emotion estimation function, such as an emotion engine or generative AI. Generative AI is, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above processing in the monitoring unit may be performed using generative AI or not. For example, the monitoring unit can use generative AI to estimate the user's emotions and adjust the monitoring frequency based on the estimated emotions.
[0075] The monitoring unit can change the monitoring intensity based on specific time periods or days of the week when monitoring network traffic. For example, the monitoring unit can increase the monitoring intensity during business hours and decrease it at night or on holidays. For example, the monitoring unit can set the monitoring intensity lower than usual on weekends and public holidays. For example, the monitoring unit can temporarily increase the monitoring intensity during specific events or campaigns. This makes it possible to adjust the monitoring intensity according to the time of day and day of the week. Some or all of the above processing in the monitoring unit may be performed using or without generating AI. For example, the monitoring unit can use generating AI to change the monitoring intensity based on specific time periods or days of the week when monitoring network traffic.
[0076] The monitoring unit can prioritize monitoring for specific protocols or ports during monitoring. For example, the monitoring unit may prioritize monitoring HTTP or HTTPS traffic. For example, the monitoring unit may prioritize monitoring for specific ports (e.g., 80, 443). For example, the monitoring unit may prioritize monitoring for specific application protocols (e.g., FTP, SMTP). This enables prioritized monitoring for specific protocols or ports. Some or all of the above processing in the monitoring unit may be performed using or without a generating AI. For example, the monitoring unit can use a generating AI to prioritize monitoring for specific protocols or ports during monitoring.
[0077] The monitoring unit can estimate the user's emotions and determine the priority of traffic to monitor based on the estimated emotions. For example, if the user is feeling anxious, the monitoring unit will prioritize monitoring important traffic. For example, if the user is relaxed, the monitoring unit will prioritize monitoring normal traffic. For example, if the user is in a hurry, the monitoring unit will prioritize monitoring traffic that requires real-time information. This makes it possible to prioritize traffic according to the user's emotions. Emotion estimation is achieved using an emotion estimation function, such as an emotion engine or generative AI. Generative AI is, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above processing in the monitoring unit may be performed using generative AI or not. For example, the monitoring unit can use generative AI to estimate the user's emotions and determine the priority of traffic to monitor based on the estimated emotions.
[0078] The monitoring unit can customize its monitoring method based on the type of device in the network during monitoring. For example, the monitoring unit may prioritize monitoring critical devices such as servers and routers. For example, the monitoring unit may apply a specific monitoring method to IoT devices. For example, the monitoring unit may apply a different monitoring method to mobile devices. This allows for customization of the monitoring method according to the type of device. Some or all of the above processing in the monitoring unit may be performed using generative AI, or not. For example, the monitoring unit can use generative AI to customize its monitoring method based on the type of device in the network during monitoring.
[0079] The monitoring unit can adjust its monitoring range during monitoring, taking into account the geographical distribution of the network. For example, the monitoring unit may prioritize monitoring geographically important locations. For example, the monitoring unit may apply different monitoring intensities to overseas locations. For example, the monitoring unit may dynamically adjust its monitoring range for geographically dispersed networks. This makes it possible to adjust the monitoring range according to the geographical distribution. Some or all of the above processing in the monitoring unit may be performed using generative AI, or not. For example, the monitoring unit can use generative AI to adjust its monitoring range during monitoring, taking into account the geographical distribution of the network.
[0080] The detection unit can estimate the user's emotions and adjust the detection threshold based on the estimated emotions. For example, if the user is feeling anxious, the detection unit will set the detection threshold low. For example, if the user is relaxed, the detection unit will set the detection threshold to normal. For example, if the user is in a hurry, the detection unit will adjust the threshold to detect only critical attacks. This allows for adjustment of the detection threshold according to the user's emotions. Emotion estimation is achieved using an emotion estimation function, such as an emotion engine or generative AI. Generative AI may be, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above processing in the detection unit may be performed using generative AI or not. For example, the detection unit can use generative AI to estimate the user's emotions and adjust the detection threshold based on the estimated emotions.
[0081] The detection unit can optimize its detection algorithm by referring to past attack patterns when an attack is detected. For example, the detection unit adjusts its detection algorithm based on past attack data. For example, the detection unit learns past attack patterns and detects new attacks. For example, the detection unit strengthens its detection algorithm based on past attack methods. This makes it possible to optimize the detection algorithm based on past attack patterns. Some or all of the above processes in the detection unit may be performed using generative AI, or they may not be performed using generative AI. For example, the detection unit can use generative AI to optimize its detection algorithm by referring to past attack patterns when an attack is detected.
[0082] The detection unit can apply different detection algorithms to specific attack methods upon detection. For example, the detection unit may apply a specific detection algorithm to brute-force attacks. For example, the detection unit may apply a different detection algorithm to phishing attacks. For example, the detection unit may apply a dedicated detection algorithm to malware infections. This makes it possible to apply detection algorithms to specific attack methods. Some or all of the above processing in the detection unit may be performed using generative AI, or not. For example, the detection unit may use generative AI to apply different detection algorithms to specific attack methods upon detection.
[0083] The detection unit can estimate the user's emotions and adjust the display method of the detection results based on the estimated emotions. For example, if the user is tense, the detection unit provides a simple and highly visible display method. For example, if the user is relaxed, the detection unit provides a display method that includes detailed information. For example, if the user is in a hurry, the detection unit provides a display method that gets straight to the point. This makes it possible to adjust the display method of the detection results according to the user's emotions. Emotion estimation is achieved using an emotion estimation function, such as an emotion engine or a generative AI. The generative AI is, but is not limited to, a text generation AI (e.g., LLM) or a multimodal generation AI. Some or all of the above processing in the detection unit may be performed using a generative AI or not. For example, the detection unit can use a generative AI to estimate the user's emotions and adjust the display method of the detection results based on the estimated emotions.
[0084] The detection unit can improve detection accuracy by considering the attribute information of devices in the network when detection occurs. For example, the detection unit adjusts the detection algorithm according to the type of device. For example, the detection unit improves detection accuracy based on the attribute information of the device. For example, the detection unit optimizes the detection algorithm by considering the usage status of the device. This makes it possible to improve detection accuracy based on the attribute information of the device. Some or all of the above processing in the detection unit may be performed using a generation AI, or it may be performed without a generation AI. For example, the detection unit can use a generation AI to improve detection accuracy by considering the attribute information of devices in the network when detection occurs.
[0085] The detection unit can adjust its detection range by referring to network topology information when detection occurs. For example, the detection unit dynamically adjusts the detection range based on network topology information. For example, the detection unit prioritizes detecting important parts by referring to topology information. For example, the detection unit optimizes the detection algorithm based on topology information. This makes it possible to adjust the detection range based on topology information. Some or all of the above processing in the detection unit may be performed using generative AI, or without generative AI. For example, the detection unit can use generative AI to adjust the detection range by referring to network topology information when detection occurs.
[0086] The response unit can estimate the user's emotions and determine the priority of countermeasures based on the estimated emotions. For example, if the user is feeling anxious, the response unit will prioritize important countermeasures. For example, if the user is relaxed, the response unit will implement normal countermeasures. For example, if the user is in a hurry, the response unit will implement countermeasures quickly. This makes it possible to determine the priority of countermeasures according to the user's emotions. Emotion estimation is achieved using an emotion estimation function, such as an emotion engine or generative AI. Generative AI is, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above processing in the response unit may be performed using generative AI or not. For example, the response unit can use generative AI to estimate the user's emotions and determine the priority of countermeasures based on the estimated emotions.
[0087] The countermeasures unit can select the optimal countermeasure method by referring to past countermeasure history when implementing countermeasures. For example, the countermeasures unit selects the optimal countermeasure method based on past countermeasure history. For example, the countermeasures unit implements effective countermeasures by referring to past countermeasure data. For example, the countermeasures unit optimizes countermeasure methods based on past countermeasure methods. This makes it possible to select the optimal countermeasure method based on past countermeasure history. Some or all of the above processes in the countermeasures unit may be performed using a generation AI, or they may be performed without a generation AI. For example, the countermeasures unit can use a generation AI to select the optimal countermeasure method by referring to past countermeasure history when implementing countermeasures.
[0088] The countermeasures unit can apply different countermeasures to specific attack methods when implementing countermeasures. For example, the unit can apply specific countermeasures to brute-force attacks. For example, the unit can apply different countermeasures to phishing attacks. For example, the unit can apply dedicated countermeasures to malware infections. This makes it possible to apply countermeasures to specific attack methods. Some or all of the above-described processes in the countermeasures unit may be performed using a generating AI, or not. For example, the countermeasures unit can use a generating AI to apply different countermeasures to specific attack methods when implementing countermeasures.
[0089] The response unit can estimate the user's emotions and adjust the timing of the response based on the estimated emotions. For example, if the user is feeling anxious, the response unit will implement the response quickly. If the user is relaxed, the response unit will implement the response at the usual time. If the user is in a hurry, the response unit will implement the response immediately. This makes it possible to adjust the timing of the response according to the user's emotions. Emotion estimation is achieved using an emotion estimation function, such as an emotion engine or generative AI. Generative AI is, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above processing in the response unit may be performed using generative AI or not. For example, the response unit can use generative AI to estimate the user's emotions and adjust the timing of the response based on the estimated emotions.
[0090] The countermeasure unit can customize its countermeasures based on the type of device in the network when implementing countermeasures. For example, the countermeasure unit can apply specific countermeasures to critical devices such as servers and routers. For example, the countermeasure unit can apply different countermeasures to IoT devices. For example, the countermeasure unit can apply a dedicated countermeasure to mobile devices. This makes it possible to customize countermeasures according to the type of device. Some or all of the above processing in the countermeasure unit may be performed using generative AI, or it may be performed without generative AI. For example, the countermeasure unit can use generative AI to customize countermeasures based on the type of device in the network when implementing countermeasures.
[0091] The countermeasures unit can adjust the scope of countermeasures when implementing countermeasures, taking into account the geographical distribution of the network. For example, the countermeasures unit may prioritize countermeasures for geographically important locations. For example, the countermeasures unit may apply different countermeasures to overseas locations. For example, the countermeasures unit may dynamically adjust the scope of countermeasures for geographically dispersed networks. This makes it possible to adjust the scope of countermeasures according to the geographical distribution. Some or all of the above processing in the countermeasures unit may be performed using generative AI, or not. For example, the countermeasures unit may use generative AI to adjust the scope of countermeasures when implementing countermeasures, taking into account the geographical distribution of the network.
[0092] The analysis unit can estimate the user's emotions and adjust the level of detail of the analysis based on the estimated emotions. For example, if the user is feeling anxious, the analysis unit will provide detailed analysis results. For example, if the user is relaxed, the analysis unit will provide normal analysis results. For example, if the user is in a hurry, the analysis unit will provide concise analysis results. This allows for adjustment of the level of detail of the analysis according to the user's emotions. Emotion estimation is achieved using an emotion estimation function, such as an emotion engine or generative AI. Generative AI may be, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above-described processes in the analysis unit may be performed using generative AI or not. For example, the analysis unit can use generative AI to estimate the user's emotions and adjust the level of detail of the analysis based on the estimated emotions.
[0093] The analysis unit can optimize its analysis algorithm by referring to past attack data during analysis. For example, the analysis unit adjusts its analysis algorithm based on past attack data. For example, the analysis unit learns past attack patterns and analyzes new attacks. For example, the analysis unit strengthens its analysis algorithm based on past attack methods. This makes it possible to optimize the analysis algorithm based on past attack data. Some or all of the above processes in the analysis unit may be performed using generative AI, or not. For example, the analysis unit can use generative AI to optimize its analysis algorithm by referring to past attack data during analysis.
[0094] The analysis unit can apply different analysis methods to specific attack patterns during analysis. For example, the analysis unit can apply a specific analysis method to brute-force attacks. For example, the analysis unit can apply a different analysis method to phishing attacks. For example, the analysis unit can apply a dedicated analysis method to malware infections. This makes it possible to apply analysis methods to specific attack patterns. Some or all of the above-described processes in the analysis unit may be performed using generative AI, or not. For example, the analysis unit can use generative AI to apply different analysis methods to specific attack patterns during analysis.
[0095] The analysis unit can estimate the user's emotions and adjust the display method of the analysis results based on the estimated emotions. For example, if the user is nervous, the analysis unit provides a simple and highly visible display method. For example, if the user is relaxed, the analysis unit provides a display method that includes detailed information. For example, if the user is in a hurry, the analysis unit provides a display method that gets straight to the point. This makes it possible to adjust the display method of the analysis results according to the user's emotions. Emotion estimation is achieved using an emotion estimation function, such as an emotion engine or generative AI. Generative AI is, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above processing in the analysis unit may be performed using generative AI or not. For example, the analysis unit can use generative AI to estimate the user's emotions and adjust the display method of the analysis results based on the estimated emotions.
[0096] The analysis unit can improve analysis accuracy by considering the attribute information of devices in the network during analysis. For example, the analysis unit adjusts the analysis algorithm according to the type of device. For example, the analysis unit improves analysis accuracy based on the device attribute information. For example, the analysis unit optimizes the analysis algorithm by considering the usage status of the device. This makes it possible to improve analysis accuracy based on the device attribute information. Some or all of the above processing in the analysis unit may be performed using generative AI, or not using generative AI. For example, the analysis unit can use generative AI to improve analysis accuracy by considering the attribute information of devices in the network during analysis.
[0097] The analysis unit can adjust the analysis range by referring to the network topology information during analysis. For example, the analysis unit dynamically adjusts the analysis range based on the network topology information. For example, the analysis unit prioritizes the analysis of important parts by referring to the topology information. For example, the analysis unit optimizes the analysis algorithm based on the topology information. This makes it possible to adjust the analysis range based on the topology information. Some or all of the above processes in the analysis unit may be performed using generative AI, or not. For example, the analysis unit can use generative AI to adjust the analysis range by referring to the network topology information during analysis.
[0098] The system according to the embodiment is not limited to the example described above, and various modifications are possible, for example, as follows.
[0099] A cyberattack-specific system can also include a prediction unit. This unit can predict future attack patterns based on historical attack data and current network traffic. For example, it can analyze historical attack data to identify attack patterns associated with specific times or events. It can also analyze attack trends in specific industries or regions to assess future attack risks. Furthermore, it can monitor network traffic in real time, detect anomalous patterns, and predict future attacks. This allows the system to take proactive measures and reduce the risk of cyberattacks.
[0100] A cyberattack-focused system can also include an education department. This department can provide users with cybersecurity education. For example, it can provide training to help users recognize signs of cyberattacks and take appropriate countermeasures. It can also provide guidelines on how to identify phishing emails and how to create secure passwords. Furthermore, it can regularly inform users of the latest security information and best practices. This can improve users' security awareness and reduce the risk of cyberattacks.
[0101] A cyberattack-focused system can also include a cooperation unit. This unit can collaborate with other security systems and external organizations to share information. For example, the cooperation unit can share information about cyberattacks with other companies and government agencies and jointly implement countermeasures. The cooperation unit can, for instance, work with security vendors to obtain the latest threat intelligence and incorporate it into the system. The cooperation unit can, for example, collaborate with international security organizations to monitor global cyberattack trends. This allows the system to implement countermeasures based on a broader range of information, thereby reducing the risk of cyberattacks.
[0102] A cyberattack-specific system can also include a reporting unit. This unit can report the results of cyberattack detection and countermeasures to the user. For example, the reporting unit can generate and provide a detailed report of detected cyberattacks. It can also record a history of cyberattacks for which countermeasures have been taken, allowing the user to refer to it later. Furthermore, it can periodically notify the user of the system's security status and suggest improvements. This allows the user to understand the system's security status and take necessary measures.
[0103] A cyberattack-specific system may also include a recovery unit. This recovery unit can assist in the recovery of a system damaged by a cyberattack. For example, it can recover data damaged by the attack. It can also use system backups to restore the system to its pre-attack state. Furthermore, it can provide emergency response procedures to minimize the impact of the attack. This allows for rapid recovery from cyberattack damage and the resumption of normal system operation.
[0104] A cyberattack-focused system can also be equipped with an emotion estimation unit. This unit can estimate the user's emotions and adjust the system's operation based on the estimated emotions. For example, if the user is stressed, the emotion estimation unit can reduce the frequency of system notifications to lessen the user's burden. If the user is relaxed, for example, the emotion estimation unit can provide detailed security information to enhance the user's understanding. If the user is in a hurry, for example, the emotion estimation unit can prioritize displaying only important information. This enables flexible system operation that responds to the user's emotions.
[0105] A cyberattack-focused system can also be equipped with an emotional feedback unit. This unit can monitor the user's emotions in real time and reflect them in the system's operation. For example, if the user is feeling anxious, the emotional feedback unit will strengthen the system's security measures. If the user is feeling secure, for example, the emotional feedback unit will reduce the monitoring frequency to conserve system resources. If the user is feeling stressed, for example, the emotional feedback unit will provide a simple and highly visible interface. This allows for system optimization based on the user's emotions.
[0106] A cyberattack-specialized system can also be equipped with an emotion notification unit. This unit can estimate the user's emotions and provide appropriate notifications based on those estimates. For example, if the user is stressed, the emotion notification unit will only provide important notifications and refrain from unnecessary ones. If the user is relaxed, for example, the emotion notification unit will provide detailed security information. If the user is in a hurry, for example, the emotion notification unit will provide concise notifications that get straight to the point. This enables appropriate notifications tailored to the user's emotions.
[0107] A cyberattack-focused system can also be equipped with an emotion logging section. This section can record user emotions and use the data to improve the system. For example, it can record when a user feels anxious and analyze the cause. It can also record system behavior when a user is relaxed to find optimal operating methods. Furthermore, it can record operation history when a user is in a hurry to improve system response speed. This enables continuous system improvement based on user emotions.
[0108] A cyberattack-specific system can also be equipped with an emotion alerting unit. This unit can estimate the user's emotions and adjust the content and frequency of alerts based on those emotions. For example, if the user is feeling anxious, the emotion alerting unit will display only important alerts. If the user is relaxed, for example, the emotion alerting unit will provide detailed alert information. If the user is in a hurry, for example, the emotion alerting unit will display concise alerts that get straight to the point. This allows for the optimization of alerts according to the user's emotions.
[0109] The following briefly describes the processing flow for example form 2.
[0110] Step 1: The monitoring unit monitors network traffic. The monitoring unit, for example, analyzes data packets in real time within a company's network and is installed at the gateway of the communication infrastructure. The monitoring unit analyzes the contents of data packets to detect anomalies in network traffic. Step 2: The detection unit detects unauthorized access and system intrusions from the traffic monitored by the monitoring unit. The detection unit detects, for example, theft or guessing of account information, brute-force attacks, attacks exploiting software flaws or vulnerabilities, and fraudulent means of intrusion. The detection unit may also analyze the contents of data packets and use generating AI to detect anomalies in network traffic. Step 3: The countermeasures unit takes appropriate measures against cyberattacks detected by the detection unit. For example, if unauthorized access is detected, the countermeasures unit will block access and notify the system administrator. If malware infection is detected, the unit will identify the infection route and implement measures to prevent the spread of infection. The countermeasures unit may also use generated AI to take countermeasures against cyberattacks. Step 4: The analysis department analyzes past attack methods and predicts future attacks. For example, the analysis department predicts future attack patterns based on data from past cyberattacks and takes countermeasures in advance. The analysis department may also use generative AI to analyze past attack methods and predict future attacks.
[0111] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.
[0112] Data generation model 58 is a form of so-called generative AI (Artificial Intelligence). An example of data generation model 58 is ChatGPT (registered trademark) (Internet search).<URL: https: / / openai.com / blog / chatgpt> Examples of generative AI include text generation AI, image generation AI, and multimodal generation AI. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images (e.g., still image data or video data). The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference result in one or more data formats from audio data, text data, and image data. The data generation model 58 includes, for example, text generation AI, image generation AI, and multimodal generation AI. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The specific processing unit 290 performs the specific processing described above using the data generation model 58. The data generation model 58 may be a fine-tuned model that outputs inference results from prompts that do not contain instructions, in which case the data generation model 58 can output inference results from prompts that do not contain instructions. In the data processing device 12, etc., there are multiple types of data generation models 58, and the data generation model 58 includes AI other than generative AI. AI other than generative AI includes, for example, linear regression, logistic regression, decision trees, random forests, support vector machines (SVMs), k-means clustering, convolutional neural networks (CNNs), recurrent neural networks (RNNs), generative adversarial networks (GANs), or naive Bayes, and can perform various processes, but is not limited to these examples. Also, the AI may be an AI agent. Furthermore, when the processing of each of the above parts is performed by the AI, the processing may be performed by the AI in part or in whole, but is not limited to this example.Furthermore, processing performed by AI, including generative AI, may be replaced with rule-based processing, and rule-based processing may be replaced with processing performed by AI, including generative AI.
[0113] Furthermore, the processing performed by the data processing system 10 described above is carried out by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the smart device 14, but it may also be carried out by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the smart device 14. In addition, the specific processing unit 290 of the data processing device 12 acquires or collects information necessary for processing from the smart device 14 or an external device, and the smart device 14 acquires or collects information necessary for processing from the data processing device 12 or an external device.
[0114] Each of the multiple elements described above, including the monitoring unit, detection unit, countermeasure unit, and analysis unit, is implemented in at least one of the smart device 14 and the data processing unit 12. For example, the monitoring unit monitors network traffic using the communication I / F 44 of the smart device 14 and analyzes data packets using the processor 46. The detection unit is implemented in the specific processing unit 290 of the data processing unit 12 and detects unauthorized access and system intrusion using generated AI. The countermeasure unit is implemented in the control unit 46A of the smart device 14 and takes appropriate countermeasures against detected cyberattacks. The analysis unit is implemented in the specific processing unit 290 of the data processing unit 12 and analyzes past attack methods and predicts future attacks. The correspondence between each unit and the device or control unit is not limited to the example described above and can be modified in various ways.
[0115] [Second Embodiment] Figure 3 shows an example of the configuration of the data processing system 210 according to the second embodiment.
[0116] As shown in Figure 3, the data processing system 210 includes a data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.
[0117] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN and / or LAN.
[0118] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication interface 44. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, and camera 42 are also connected to the bus 52.
[0119] The microphone 238 receives voice signals from the user and accepts instructions from the user. The microphone 238 captures the voice signals from the user, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0120] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, which captures images of the area around the user (for example, an imaging range defined by a field of view equivalent to the field of vision of a typical healthy person).
[0121] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0122] Figure 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Figure 4, the data processing device 12 performs specific processing by the processor 28. The storage 32 stores the specific processing program 56.
[0123] The processor 28 reads a specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 acting as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.
[0124] Storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotions using the emotion identification model 59 and perform identification processing using the user's emotions. The emotion estimation function (emotion identification function) using the emotion identification model 59 performs various estimations and predictions regarding the user's emotions, including but not limited to these examples. Furthermore, emotion estimation and prediction also include, for example, emotion analysis.
[0125] In the smart glasses 214, specific processing is performed by the processor 46. The storage 50 stores a specific processing program 60. The processor 46 reads the specific processing program 60 from the storage 50 and executes the read specific processing program 60 on the RAM 48. The specific processing is realized by the processor 46 acting as a control unit 46A according to the specific processing program 60 executed on the RAM 48. The smart glasses 214 also have a data generation model 58 and an emotion identification model 59, similar to the data generation model and emotion identification model 59, and can perform processing similar to that of the specific processing unit 290 using these models.
[0126] Furthermore, other devices besides the data processing device 12 may also have the data generation model 58. For example, a server device may have the data generation model 58. In this case, the data processing device 12 obtains processing results (such as prediction results) using the data generation model 58 by communicating with the server device that has the data generation model 58. Also, the data processing device 12 may be a server device or a terminal device owned by the user (for example, a mobile phone, robot, home appliance, etc.).
[0127] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0128] The data generation model 58 is a so-called generative AI. An example of a data generation model 58 is a generative AI such as ChatGPT. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and inference data such as audio data representing speech, text data representing text, and image data representing images (e.g., still image data or video data). The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference result in one or more data formats such as audio data, text data, and image data. The data generation model 58 includes, for example, text generation AI, image generation AI, and multimodal generation AI. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The specific processing unit 290 performs the specific processing described above using the data generation model 58. The data generation model 58 may be a fine-tuned model that outputs inference results from prompts that do not contain instructions, in which case the data generation model 58 can output inference results from prompts that do not contain instructions. In the data processing device 12, etc., there are multiple types of data generation models 58, and the data generation model 58 includes AI other than generative AI. AI other than generative AI includes, for example, linear regression, logistic regression, decision trees, random forests, support vector machines (SVM), k-means clustering, convolutional neural networks (CNN), recurrent neural networks (RNN), generative adversarial networks (GAN), or naive Bayes, and can perform various processes, but is not limited to these examples. Also, the AI may be an AI agent. Furthermore, when the processing of each part described above is performed by the AI, the processing may be performed by the AI in part or in whole, but is not limited to this example. Also, processing performed by an AI including a generative AI may be replaced by rule-based processing, and rule-based processing may be replaced by processing performed by an AI including a generative AI.
[0129] The data processing system 210 according to the second embodiment performs the same processing as the data processing system 10 according to the first embodiment. The processing by the data processing system 210 is performed by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the smart glasses 214, but it may also be performed by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the smart glasses 214. In addition, the specific processing unit 290 of the data processing device 12 acquires or collects information necessary for processing from the smart glasses 214 or an external device, and the smart glasses 214 acquires or collects information necessary for processing from the data processing device 12 or an external device.
[0130] Each of the multiple elements described above, including the monitoring unit, detection unit, countermeasure unit, and analysis unit, is implemented, for example, in at least one of the smart glasses 214 and the data processing unit 12. For example, the monitoring unit monitors network traffic using the communication I / F 44 of the smart glasses 214 and analyzes data packets with the processor 46. The detection unit is implemented, for example, in the specific processing unit 290 of the data processing unit 12 and detects unauthorized access and system intrusion using generated AI. The countermeasure unit is implemented, for example, in the control unit 46A of the smart glasses 214 and takes appropriate countermeasures against detected cyberattacks. The analysis unit is implemented, for example, in the specific processing unit 290 of the data processing unit 12 and analyzes past attack methods and predicts future attacks. The correspondence between each unit and the device or control unit is not limited to the example described above and can be changed in various ways.
[0131] [Third Embodiment] Figure 5 shows an example of the configuration of the data processing system 310 according to the third embodiment.
[0132] As shown in Figure 5, the data processing system 310 includes a data processing device 12 and a headset terminal 314. An example of the data processing device 12 is a server.
[0133] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN and / or LAN.
[0134] The headset terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a display 343. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and display 343 are also connected to the bus 52.
[0135] The microphone 238 receives voice signals from the user and accepts instructions from the user. The microphone 238 captures the voice signals from the user, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0136] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, which captures images of the area around the user (for example, an imaging range defined by a field of view equivalent to the field of vision of a typical healthy person).
[0137] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0138] Figure 6 shows an example of the main functions of the data processing device 12 and the headset terminal 314. As shown in Figure 6, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.
[0139] The processor 28 reads a specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 acting as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.
[0140] Storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotions using the emotion identification model 59 and perform identification processing using the user's emotions. The emotion estimation function (emotion identification function) using the emotion identification model 59 performs various estimations and predictions regarding the user's emotions, including but not limited to these examples. Furthermore, emotion estimation and prediction also include, for example, emotion analysis.
[0141] In the headset terminal 314, specific processing is performed by the processor 46. The storage 50 stores a specific program 60. The processor 46 reads the specific program 60 from the storage 50 and executes the read specific program 60 on the RAM 48. The specific processing is realized by the processor 46 acting as a control unit 46A according to the specific program 60 executed on the RAM 48. The headset terminal 314 also has a data generation model 58 and an emotion identification model 59, similar to the data generation model and emotion identification model 59, and can perform processing similar to that of the specific processing unit 290 using these models.
[0142] Furthermore, other devices besides the data processing device 12 may also have the data generation model 58. For example, a server device may have the data generation model 58. In this case, the data processing device 12 obtains processing results (such as prediction results) using the data generation model 58 by communicating with the server device that has the data generation model 58. Also, the data processing device 12 may be a server device or a terminal device owned by the user (for example, a mobile phone, robot, home appliance, etc.).
[0143] The specific processing unit 290 transmits the result of the specific processing to the headset terminal 314. In the headset terminal 314, the control unit 46A causes the speaker 240 and display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0144] The data generation model 58 is a so-called generative AI. An example of a data generation model 58 is a generative AI such as ChatGPT. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and inference data such as audio data representing speech, text data representing text, and image data representing images (e.g., still image data or video data). The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference result in one or more data formats such as audio data, text data, and image data. The data generation model 58 includes, for example, text generation AI, image generation AI, and multimodal generation AI. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The specific processing unit 290 performs the specific processing described above using the data generation model 58. The data generation model 58 may be a fine-tuned model that outputs inference results from prompts that do not contain instructions, in which case the data generation model 58 can output inference results from prompts that do not contain instructions. In the data processing device 12, etc., there are multiple types of data generation models 58, and the data generation model 58 includes AI other than generative AI. AI other than generative AI includes, for example, linear regression, logistic regression, decision trees, random forests, support vector machines (SVM), k-means clustering, convolutional neural networks (CNN), recurrent neural networks (RNN), generative adversarial networks (GAN), or naive Bayes, and can perform various processes, but is not limited to these examples. Also, the AI may be an AI agent. Furthermore, when the processing of each part described above is performed by the AI, the processing may be performed by the AI in part or in whole, but is not limited to this example. Also, processing performed by an AI including a generative AI may be replaced by rule-based processing, and rule-based processing may be replaced by processing performed by an AI including a generative AI.
[0145] The data processing system 310 according to the third embodiment performs the same processing as the data processing system 10 according to the first embodiment. The processing by the data processing system 310 is performed by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the headset terminal 314, but may also be performed by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the headset terminal 314. In addition, the specific processing unit 290 of the data processing device 12 acquires or collects information necessary for processing from the headset terminal 314 or an external device, and the headset terminal 314 acquires or collects information necessary for processing from the data processing device 12 or an external device.
[0146] Each of the multiple elements described above, including the monitoring unit, detection unit, countermeasure unit, and analysis unit, is implemented in at least one of the headset terminal 314 and the data processing unit 12. For example, the monitoring unit monitors network traffic using the communication I / F 44 of the headset terminal 314 and analyzes data packets using the processor 46. The detection unit is implemented in the specific processing unit 290 of the data processing unit 12 and detects unauthorized access and system intrusion using generated AI. The countermeasure unit is implemented in the control unit 46A of the headset terminal 314 and takes appropriate countermeasures against detected cyberattacks. The analysis unit is implemented in the specific processing unit 290 of the data processing unit 12 and analyzes past attack methods and predicts future attacks. The correspondence between each unit and the devices and control units is not limited to the example described above and can be modified in various ways.
[0147] [Fourth Embodiment] Figure 7 shows an example of the configuration of the data processing system 410 according to the fourth embodiment.
[0148] As shown in Figure 7, the data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.
[0149] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN and / or LAN.
[0150] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a controlled object 443. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and controlled object 443 are also connected to the bus 52.
[0151] The microphone 238 receives voice signals from the user and accepts instructions from the user. The microphone 238 captures the voice signals from the user, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0152] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS image sensor or CCD image sensor, which captures images of the area around the user (for example, an imaging range defined by a field of view equivalent to the field of vision of a typical healthy person).
[0153] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0154] The controlled object 443 includes a display device, LEDs in the eyes, and motors that drive the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the robot 414's emotions can be expressed by controlling these motors. The robot 414's facial expressions can also be expressed by controlling the illumination state of the LEDs in its eyes.
[0155] Figure 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Figure 8, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.
[0156] The processor 28 reads a specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 acting as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.
[0157] Storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotions using the emotion identification model 59 and perform identification processing using the user's emotions. The emotion estimation function (emotion identification function) using the emotion identification model 59 performs various estimations and predictions regarding the user's emotions, including but not limited to these examples. Furthermore, emotion estimation and prediction also include, for example, emotion analysis.
[0158] In robot 414, specific processing is performed by processor 46. A specific program 60 is stored in storage 50. Processor 46 reads the specific program 60 from storage 50 and executes it on RAM 48. The specific processing is achieved by processor 46 acting as a control unit 46A according to the specific program 60 executed on RAM 48. Robot 414 also has data generation model 58 and emotion identification model 59, similar to those of the robot, and can perform processing similar to that of the specific processing unit 290 using these models.
[0159] Furthermore, other devices besides the data processing device 12 may also have the data generation model 58. For example, a server device may have the data generation model 58. In this case, the data processing device 12 obtains processing results (such as prediction results) using the data generation model 58 by communicating with the server device that has the data generation model 58. Also, the data processing device 12 may be a server device or a terminal device owned by the user (for example, a mobile phone, robot, home appliance, etc.).
[0160] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the controlled object 443 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0161] The data generation model 58 is a so-called generative AI. An example of a data generation model 58 is a generative AI such as ChatGPT. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and inference data such as audio data representing speech, text data representing text, and image data representing images (e.g., still image data or video data). The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference result in one or more data formats such as audio data, text data, and image data. The data generation model 58 includes, for example, text generation AI, image generation AI, and multimodal generation AI. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The specific processing unit 290 performs the specific processing described above using the data generation model 58. The data generation model 58 may be a fine-tuned model that outputs inference results from prompts that do not contain instructions, in which case the data generation model 58 can output inference results from prompts that do not contain instructions. In the data processing device 12, etc., there are multiple types of data generation models 58, and the data generation model 58 includes AI other than generative AI. AI other than generative AI includes, for example, linear regression, logistic regression, decision trees, random forests, support vector machines (SVM), k-means clustering, convolutional neural networks (CNN), recurrent neural networks (RNN), generative adversarial networks (GAN), or naive Bayes, and can perform various processes, but is not limited to these examples. Also, the AI may be an AI agent. Furthermore, when the processing of each part described above is performed by the AI, the processing may be performed by the AI in part or in whole, but is not limited to this example. Also, processing performed by an AI including a generative AI may be replaced by rule-based processing, and rule-based processing may be replaced by processing performed by an AI including a generative AI.
[0162] The data processing system 410 according to the fourth embodiment performs the same processing as the data processing system 10 according to the first embodiment. The processing by the data processing system 410 is performed by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the robot 414, but it may also be performed by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the robot 414. In addition, the specific processing unit 290 of the data processing device 12 acquires or collects information necessary for processing from the robot 414 or an external device, and the robot 414 acquires or collects information necessary for processing from the data processing device 12 or an external device.
[0163] Each of the multiple elements described above, including the monitoring unit, detection unit, countermeasure unit, and analysis unit, is implemented in at least one of the robot 414 and the data processing unit 12. For example, the monitoring unit monitors network traffic using the robot 414's communication I / F 44 and analyzes data packets using the processor 46. The detection unit is implemented in the data processing unit 12, for example, by the specific processing unit 290, and detects unauthorized access and system intrusion using generated AI. The countermeasure unit is implemented in the robot 414, for example, by the control unit 46A, and takes appropriate countermeasures against detected cyberattacks. The analysis unit is implemented in the data processing unit 12, for example, by the specific processing unit 290, and analyzes past attack methods and predicts future attacks. The correspondence between each unit and the devices and control units is not limited to the examples described above and can be modified in various ways.
[0164] Furthermore, the emotion identification model 59, acting as an emotion engine, may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to a specific mapping, which is an emotion map (see Figure 9). Similarly, the emotion identification model 59 may also determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.
[0165] Figure 9 shows the emotion map 400, in which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. The closer to the center of the concentric circles, the more primitive the emotions are located. Further out of the concentric circles, emotions representing states and actions arising from mental states are located. Emotion is a concept that includes feelings and mental states. On the left side of the concentric circles, emotions that are generally generated from reactions occurring in the brain are located. On the right side of the concentric circles, emotions that are generally induced by situational judgment are located. Above and below the concentric circles, emotions that are generally generated from reactions occurring in the brain and induced by situational judgment are located. In addition, the emotion of "pleasure" is located on the upper side of the concentric circles, and the emotion of "displeasure" is located on the lower side. Thus, in the emotion map 400, multiple emotions are mapped based on the structure in which emotions arise, and emotions that are likely to occur simultaneously are mapped close together.
[0166] These emotions are distributed at the 3 o'clock position on the Emotion Map 400, and usually fluctuate between feelings of security and anxiety. In the right half of the Emotion Map 400, situational awareness takes precedence over internal feelings, resulting in a calm impression.
[0167] The inside of the Emotion Map 400 represents inner thoughts, while the outside represents actions. Therefore, the further you go from the outside of the Emotion Map 400, the more visible (expressed in actions) your emotions become.
[0168] Here, human emotions are based on various balances, such as posture and blood sugar levels. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. Similarly, in robots, cars, and motorcycles, emotions can be created based on various balances, such as posture and battery level. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. The emotion map can be generated based, for example, on Dr. Mitsuyoshi's emotion map (Research on a system for analyzing brain physiological signals of speech emotion recognition and emotion, Tokushima University, doctoral dissertation: https: / / ci.nii.ac.jp / naid / 500000375379). The left half of the emotion map contains emotions belonging to a region called "response," where sensation is dominant. The right half of the emotion map contains emotions belonging to a region called "situation," where situational awareness is dominant.
[0169] The emotion map defines two emotions that promote learning. One is the emotion around the middle of the negative "repentance" and "reflection" on the situation side. In other words, it is when the robot experiences negative emotions such as "I never want to feel this way again" or "I don't want to be scolded again." The other is the emotion around the positive "desire" on the reaction side. In other words, it is when the robot has positive feelings such as "I want more" or "I want to know more."
[0170] The emotion identification model 59 inputs user input into a pre-trained neural network, obtains emotion values representing each emotion shown in the emotion map 400, and determines the user's emotion. This neural network is pre-trained based on multiple training data sets, which are combinations of user input and emotion values representing each emotion shown in the emotion map 400. Furthermore, this neural network is trained so that emotions located close together have similar values, as shown in the emotion map 900 in Figure 10. Figure 10 shows an example where multiple emotions such as "reassured," "calm," and "confident" have similar emotion values.
[0171] In the above embodiment, an example was given in which a specific process is performed by a single computer 22. However, the technology of this disclosure is not limited thereto, and a distributed processing method for the specific process may be used, which includes computer 22 and multiple other computers.
[0172] In the above embodiment, an example was given in which the specific processing program 56 is stored in the storage 32, but the technology of this disclosure is not limited thereto. For example, the specific processing program 56 may be stored in a portable, computer-readable, non-temporary storage medium such as a USB (Universal Serial Bus) memory. The specific processing program 56 stored in the non-temporary storage medium is installed in the computer 22 of the data processing device 12. The processor 28 executes specific processing according to the specific processing program 56.
[0173] Alternatively, the specific processing program 56 may be stored in a storage device such as a server connected to the data processing device 12 via the network 54, and the specific processing program 56 may be downloaded and installed on the computer 22 in response to a request from the data processing device 12.
[0174] Furthermore, it is not necessary to store the entirety of the specific processing program 56 in a storage device such as a server connected to the data processing device 12 via the network 54, or to store the entirety of the specific processing program 56 in the storage 32; it is acceptable to store only a portion of the specific processing program 56.
[0175] The following types of processors can be used as hardware resources to perform specific processing. Examples of processors include a CPU, a general-purpose processor that functions as a hardware resource to perform specific processing by executing software, i.e., a program. Other examples of processors include dedicated electrical circuits, such as FPGAs (Field-Programmable Gate Arrays), PLDs (Programmable Logic Devices), or ASICs (Application Specific Integrated Circuits), which have circuit configurations specifically designed to perform specific processing. All of these processors have built-in or connected memory, and all of them perform specific processing by using memory.
[0176] The hardware resource that performs a specific process may consist of one of these various processors, or it may consist of a combination of two or more processors of the same or different types (for example, a combination of multiple FPGAs, or a combination of a CPU and an FPGA). Alternatively, the hardware resource that performs a specific process may consist of a single processor.
[0177] Examples of configurations using a single processor include, firstly, a configuration in which one or more CPUs and software are combined to form a single processor, and this processor functions as a hardware resource that performs a specific process. Secondly, there is a configuration using a processor that realizes the functions of the entire system, including multiple hardware resources that perform a specific process, on a single IC chip, as exemplified by SoCs (System-on-a-chip). In this way, a specific process is realized using one or more of the above types of processors as hardware resources.
[0178] Furthermore, the hardware structure of these various processors can more specifically utilize electrical circuits that combine circuit elements such as semiconductor devices. Also, the specific processing described above is merely an example. Therefore, it goes without saying that unnecessary steps can be deleted, new steps added, or the processing order rearranged, as long as it does not deviate from the main purpose.
[0179] Furthermore, although the above-described examples were divided into four embodiments, some or all of these embodiments may be combined. Also, the smart device 14, smart glasses 214, headset terminal 314, and robot 414 are just examples, and they may be combined, or other devices may be used. Also, although the above-described examples were divided into two embodiments, Embodiment 1 and Embodiment 2, these may be combined.
[0180] The descriptions and illustrations presented above are detailed explanations of the technical aspects of this disclosure and are merely examples of the technical aspects. For example, the above descriptions of the structure, function, operation, and effect are examples of the structure, function, operation, and effect of the technical aspects of this disclosure. Therefore, it goes without saying that you may delete unnecessary parts, add new elements, or replace elements in the descriptions and illustrations presented above, as long as you do not deviate from the essence of the technical aspects of this disclosure. Furthermore, in order to avoid confusion and facilitate understanding of the technical aspects of this disclosure, explanations of common technical knowledge and other things that do not require special explanation to enable the implementation of the technical aspects of this disclosure have been omitted from the descriptions and illustrations presented above.
[0181] All documents, patent applications, and technical standards described herein are incorporated by reference to the same extent as if each individual document, patent application, and technical standard were specifically and individually noted to be incorporated by reference.
[0182] (Note 1) A monitoring unit that monitors network traffic, A detection unit detects unauthorized access and system intrusion from the traffic monitored by the aforementioned monitoring unit, A countermeasures unit that takes appropriate measures against cyberattacks detected by the aforementioned detection unit, It includes an analysis unit that analyzes past attack methods and predicts future attacks. A system characterized by the following features. (Note 2) The aforementioned monitoring unit, Analyze data packets in real time. The system described in Appendix 1, characterized by the features described herein. (Note 3) The detection unit is Detects account information theft and guessing, brute-force attacks, attacks exploiting software flaws and vulnerabilities, and fraudulent means of manipulation. The system described in Appendix 1, characterized by the features described herein. (Note 4) The aforementioned countermeasures unit, If unauthorized access is detected, access will be blocked and the system administrator will be notified. The system described in Appendix 1, characterized by the features described herein. (Note 5) The aforementioned countermeasures unit, If a malware infection is detected, we will identify the infection route and implement measures to prevent further spread. The system described in Appendix 1, characterized by the features described herein. (Note 6) The aforementioned analysis unit is Based on data from past cyberattacks, we predict future attack patterns and take preventative measures. The system described in Appendix 1, characterized by the features described herein. (Note 7) The aforementioned monitoring unit, It estimates the user's emotions and adjusts the monitoring frequency based on the estimated emotions. The system described in Appendix 1, characterized by the features described herein. (Note 8) The aforementioned monitoring unit, When monitoring network traffic, change the monitoring intensity based on specific time periods or days of the week. The system described in Appendix 1, characterized by the features described herein. (Note 9) The aforementioned monitoring unit, During monitoring, prioritize monitoring of specific protocols and ports. The system described in Appendix 1, characterized by the features described herein. (Note 10) The aforementioned monitoring unit, It estimates user sentiment and determines the priority of traffic to monitor based on the estimated user sentiment. The system described in Appendix 1, characterized by the features described herein. (Note 11) The aforementioned monitoring unit, During monitoring, customize the monitoring method based on the type of device in the network. The system described in Appendix 1, characterized by the features described herein. (Note 12) The aforementioned monitoring unit, During monitoring, adjust the monitoring range considering the geographical distribution of the network. The system described in Appendix 1, characterized by the features described herein. (Note 13) The detection unit is It estimates the user's emotions and adjusts the detection threshold based on the estimated emotions. The system described in Appendix 1, characterized by the features described herein. (Note 14) The detection unit is When detection occurs, the detection algorithm is optimized by referring to past attack patterns. The system described in Appendix 1, characterized by the features described herein. (Note 15) The detection unit is When detection occurs, different detection algorithms are applied to specific attack methods. The system described in Appendix 1, characterized by the features described herein. (Note 16) The detection unit is It estimates the user's emotions and adjusts how the detection results are displayed based on the estimated emotions. The system described in Appendix 1, characterized by the features described herein. (Note 17) The detection unit is When detecting a device, the accuracy of the detection is improved by considering the attribute information of the devices within the network. The system described in Appendix 1, characterized by the features described herein. (Note 18) The detection unit is When detection occurs, the detection range is adjusted by referring to the network topology information. The system described in Appendix 1, characterized by the features described herein. (Note 19) The aforementioned countermeasures unit, It estimates user sentiment and determines the priority of countermeasures based on the estimated user sentiment. The system described in Appendix 1, characterized by the features described herein. (Note 20) The aforementioned countermeasures unit, When implementing countermeasures, refer to past countermeasure history to select the most appropriate method. The system described in Appendix 1, characterized by the features described herein. (Note 21) The aforementioned countermeasures unit, When implementing countermeasures, different countermeasures should be applied to specific attack methods. The system described in Appendix 1, characterized by the features described herein. (Note 22) The aforementioned countermeasures unit, We estimate the user's emotions and adjust the timing of countermeasures based on the estimated user emotions. The system described in Appendix 1, characterized by the features described herein. (Note 23) The aforementioned countermeasures unit, When implementing countermeasures, customize the countermeasures based on the type of device in the network. The system described in Appendix 1, characterized by the features described herein. (Note 24) The aforementioned countermeasures unit, When implementing countermeasures, adjust the scope of the countermeasures considering the geographical distribution of the network. The system described in Appendix 1, characterized by the features described herein. (Note 25) The aforementioned analysis unit is It estimates the user's emotions and adjusts the level of detail of the analysis based on the estimated user emotions. The system described in Appendix 1, characterized by the features described herein. (Note 26) The aforementioned analysis unit is During analysis, the analysis algorithm is optimized by referring to past attack data. The system described in Appendix 1, characterized by the features described herein. (Note 27) The aforementioned analysis unit is During analysis, different analytical methods are applied to specific attack patterns. The system described in Appendix 1, characterized by the features described herein. (Note 28) The aforementioned analysis unit is It estimates the user's emotions and adjusts how the analysis results are displayed based on those estimated emotions. The system described in Appendix 1, characterized by the features described herein. (Note 29) The aforementioned analysis unit is During analysis, consider the attribute information of devices within the network to improve the accuracy of the analysis. The system described in Appendix 1, characterized by the features described herein. (Note 30) The aforementioned analysis unit is During analysis, the analysis scope is adjusted by referring to the network topology information. The system described in Appendix 1, characterized by the features described herein. [Explanation of Symbols]
[0183] 10, 210, 310, 410 Data Processing Systems 12 Data Processing Devices 14 Smart Devices 214 Smart Glasses 314 Headset-type terminal 414 Robots
Claims
1. A monitoring unit that monitors network traffic, A detection unit detects unauthorized access and system intrusion from the traffic monitored by the aforementioned monitoring unit, A countermeasures unit that takes appropriate measures against cyberattacks detected by the aforementioned detection unit, It includes an analysis unit that analyzes past attack methods and predicts future attacks. A system characterized by the following features.
2. The aforementioned monitoring unit, Analyze data packets in real time. The system according to feature 1.
3. The detection unit is Detects account information theft and guessing, brute-force attacks, attacks exploiting software flaws and vulnerabilities, and fraudulent means of manipulation. The system according to feature 1.
4. The aforementioned countermeasures unit, If unauthorized access is detected, access will be blocked and the system administrator will be notified. The system according to feature 1.
5. The aforementioned countermeasures unit, If a malware infection is detected, we will identify the infection route and implement measures to prevent further spread. The system according to feature 1.
6. The aforementioned analysis unit is Based on data from past cyberattacks, we predict future attack patterns and take preventative measures. The system according to feature 1.
7. The aforementioned monitoring unit, It estimates the user's emotions and adjusts the monitoring frequency based on the estimated emotions. The system according to feature 1.
8. The aforementioned monitoring unit, When monitoring network traffic, change the monitoring intensity based on specific time periods or days of the week. The system according to feature 1.
Citation Information
Patent Citations
Persona chatbot control method and system
JP2022180282A