system
The AI-powered malware detection and analysis system addresses the challenge of identifying unknown malware by using a collection, analysis, and defense unit to provide detailed insights and adaptive security measures, ensuring robust defense against evolving cyber threats.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- SOFTBANK GROUP CORP
- Filing Date
- 2024-11-12
- Publication Date
- 2026-05-22
Smart Images

Figure 2026084811000001_ABST
Abstract
Description
Technical Field
[0001] The technology of the present disclosure relates to a system.
Background Art
[0002] Patent Document 1 discloses a method for controlling a persona chatbot, which is performed by at least one processor, and includes steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to an explanation of a character of the chatbot, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance in response to the user utterance.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] In the conventional technology, there is a problem that it is difficult to detect unknown malware and sophisticatedly crafted malicious programs with high accuracy and analyze them in detail.
[0005] The system according to the embodiment aims to detect unknown malware and sophisticatedly crafted malicious programs with high accuracy and analyze them in detail.
Means for Solving the Problems
[0006] The system according to the embodiment includes a collection unit, an analysis unit, and a defense unit. The collection unit collects data. The analysis unit analyzes the data collected by the collection unit. The defense unit takes defensive measures based on the analysis results obtained by the analysis unit.
Effects of the Invention
[0007] The system according to this embodiment can detect unknown malware and cleverly crafted malicious programs with high accuracy and analyze them in detail. [Brief explanation of the drawing]
[0008] [Figure 1] This is a conceptual diagram showing an example of the configuration of a data processing system according to the first embodiment. [Figure 2] This is a conceptual diagram showing an example of the essential functions of a data processing device and a smart device according to the first embodiment. [Figure 3] This is a conceptual diagram showing an example of the configuration of a data processing system according to the second embodiment. [Figure 4] This is a conceptual diagram showing an example of the main functions of a data processing device and smart glasses according to the second embodiment. [Figure 5] This is a conceptual diagram showing an example of the configuration of a data processing system according to the third embodiment. [Figure 6] This is a conceptual diagram showing an example of the main functions of a data processing device and a headset-type terminal according to the third embodiment. [Figure 7] This is a conceptual diagram showing an example of the configuration of a data processing system according to the fourth embodiment. [Figure 8] This is a conceptual diagram showing an example of the main functions of a data processing device and a robot according to the fourth embodiment. [Figure 9] This shows an emotion map where multiple emotions are mapped. [Figure 10] This shows an emotion map where multiple emotions are mapped. [Modes for carrying out the invention]
[0009] Hereinafter, an example of an embodiment of the system relating to the technology of this disclosure will be described with reference to the attached drawings.
[0010] First, let's explain the terminology used in the following explanation.
[0011] In the following embodiments, the signed processor (hereinafter simply referred to as "processor") may be a single arithmetic unit or a combination of multiple arithmetic units. Furthermore, the processor may be a single type of arithmetic unit or a combination of multiple types of arithmetic units. Examples of arithmetic units include CPU (Central Processing Unit), GPU (Graphics Processing Unit), GPGPU (General-Purpose computing on Graphics Processing Units), APU (Accelerated Processing Unit), or TPU (Tensor Processing Unit).
[0012] In the following embodiments, signed RAM (Random Access Memory) is a memory that temporarily stores information and is used as work memory by the processor.
[0013] In the following embodiments, the signed storage is one or more non-volatile storage devices that store various programs and various parameters. Examples of non-volatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), or magnetic tapes.
[0014] In the following embodiments, the signed communication interface (I / F) is an interface that includes a communication processor and an antenna. The communication interface manages communication between multiple computers. Examples of communication standards applicable to the communication interface include wireless communication standards such as 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), or Bluetooth (registered trademark).
[0015] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B". That is, "A and / or B" means that it may be only A, only B, or a combination of A and B. Also, in this specification, when expressing three or more matters connected by "and / or", the same concept as "A and / or B" is applied.
[0016] [First Embodiment] FIG. 1 shows an example of the configuration of a data processing system 10 according to the first embodiment.
[0017] As shown in FIG. 1, the data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.
[0018] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. Also, the database 24 and the communication I / F 26 are connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0019] The smart device 14 includes a computer 36, a reception device 38, an output device 40, a camera 42, and a communication I / F 44. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. Also, the reception device 38, the output device 40, and the camera 42 are connected to the bus 52.
[0020] The reception device 38 is equipped with a touch panel 38A and a microphone 38B, and accepts user input. The touch panel 38A accepts user input via touch by detecting contact with an object (e.g., a pen or finger). The microphone 38B accepts user input via voice by detecting the user's voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and microphone 38B to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 (see Figure 2) acquires the data indicating the user input.
[0021] The output device 40 includes a display 40A and a speaker 40B, and presents data to the user by outputting the data in a form perceptible to the user (e.g., audio and / or text). The display 40A displays visible information such as text and images according to instructions from the processor 46. The speaker 40B outputs audio according to instructions from the processor 46. The camera 42 is a small digital camera equipped with an optical system such as a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.
[0022] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various types of information between processor 46 and processor 28 via network 54.
[0023] Figure 2 shows an example of the main functions of the data processing device 12 and the smart device 14.
[0024] As shown in Figure 2, in the data processing device 12, a specific processing is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" related to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.
[0025] Storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotions using the emotion identification model 59 and perform identification processing using the user's emotions. The emotion estimation function (emotion identification function) using the emotion identification model 59 performs various estimations and predictions regarding the user's emotions, including but not limited to these examples. Furthermore, emotion estimation and prediction also include, for example, emotion analysis.
[0026] In the smart device 14, specific processing is performed by the processor 46. The storage 50 stores a specific processing program 60. The specific processing program 60 is used in conjunction with the specific processing program 56 by the data processing system 10. The processor 46 reads the specific processing program 60 from the storage 50 and executes the read specific processing program 60 on the RAM 48. The specific processing is realized by the processor 46 operating as a control unit 46A according to the specific processing program 60 executed on the RAM 48. The smart device 14 also has a data generation model 58 and an emotion identification model 59, similar to the data generation model and emotion identification model 59, and can perform processing similar to that of the specific processing unit 290 using these models.
[0027] Furthermore, other devices besides the data processing device 12 may also have the data generation model 58. For example, a server device (e.g., a generation server) may have the data generation model 58. In this case, the data processing device 12 obtains processing results (such as prediction results) using the data generation model 58 by communicating with the server device having the data generation model 58. The data processing device 12 may also be a server device or a terminal device owned by a user (e.g., a mobile phone, robot, home appliance, etc.). Next, an example of processing by the data processing system 10 according to the first embodiment will be described.
[0028] (Example of form 1) The malware detection and analysis security system according to an embodiment of the present invention is a solution that leverages generative AI technology to bring new possibilities to the field of cybersecurity. This system surpasses the limitations of conventional signature-based antivirus software and has the ability to detect unknown malware and cleverly crafted malicious programs with high accuracy and analyze them in detail. The system processes vast amounts of data at high speed and identifies subtle behaviors and patterns that differ from normal programs. This enables effective defense not only against known threats but also against new types of malware and variants. Furthermore, the system's learning ability allows it to maintain an up-to-date defense posture against ever-evolving cyber threats. A notable feature of this system is its ability to perform detailed analysis of detected malware, not just detection. The system quickly analyzes the structure, operating mechanisms, and potential impact of malware, providing valuable insights to security professionals. This enables organizations to take faster and more effective countermeasures, minimizing damage and strengthening preparedness for future attacks. For example, the system processes large amounts of data and identifies abnormal patterns and behaviors. For instance, it can detect communication patterns and file operations that differ from normal programs. This enables effective defense against new types of malware that cannot be detected by conventional signature-based antivirus software. Next, the system performs a detailed analysis of the detected malware. It analyzes the malware's code, revealing its structure and operating mechanisms. For example, it can identify how the malware infiltrates the system and what operations it performs. This allows security professionals to take swift and effective countermeasures. Furthermore, the system possesses learning capabilities, constantly maintaining an up-to-date defense against ever-evolving cyber threats. For instance, it can learn new malware patterns, improving detection accuracy in subsequent instances. This ensures that organizations can always effectively defend against the latest threats. This system is extremely useful for security providers offering enterprise security solutions, large corporations, financial institutions, and government agencies.Traditional security systems struggle to cope with rapidly evolving malware. This system strengthens organizational security by using AI to detect evolving malware patterns and immediately implement countermeasures. Furthermore, automated analysis by the system enables malware analysis even without specialized knowledge, allowing for rapid response. As a result, this malware detection and analysis security system provides effective defense against cyber threats and enhances organizational security.
[0029] The malware detection and analysis security system according to this embodiment comprises a collection unit, an analysis unit, and a defense unit. The collection unit collects data. The collection unit can collect, for example, network traffic data, log data, user data, etc. The collection unit can, for example, monitor network traffic data in real time and detect abnormal patterns. The collection unit can also periodically collect log data and identify abnormal behavior. Furthermore, the collection unit can collect user data and detect abnormal actions. For example, the collection unit monitors network traffic data in real time and detects abnormal packets. The collection unit can also periodically collect log data and identify abnormal login attempts. The collection unit can also collect user data and detect abnormal access patterns. The analysis unit analyzes the data collected by the collection unit. The analysis unit can, for example, use AI to analyze the data and identify abnormal patterns and behaviors. For example, the analysis unit can use AI to analyze network traffic data and identify abnormal communication patterns. Furthermore, the analysis unit can use AI to analyze log data and identify abnormal login attempts. Furthermore, the analysis unit can use AI to analyze user data and identify abnormal access patterns. For example, the analysis unit uses AI to analyze network traffic data and identify abnormal packets. The analysis unit can also use AI to analyze log data and identify abnormal login attempts. The analysis unit can also use AI to analyze user data and identify abnormal access patterns. The defense unit takes defensive measures based on the analysis results obtained by the analysis unit. The defense unit implements defensive measures such as firewall configuration, access control, and intrusion detection systems. For example, the defense unit can change firewall settings to block abnormal communications. The defense unit can also strengthen access control to prevent abnormal login attempts. Furthermore, the defense unit can use intrusion detection systems to detect abnormal access patterns and take defensive measures. For example, the defense unit can change firewall settings to block abnormal communications. The defense unit can also strengthen access control to prevent abnormal login attempts.The defense unit can also use an intrusion detection system to detect abnormal access patterns and implement defensive measures. As a result, the malware detection and analysis security system according to this embodiment enables efficient cybersecurity measures because data collection, analysis, and execution of defensive measures are performed in a continuous flow.
[0030] The data collection unit collects data. For example, it can collect network traffic data, log data, and user data. Specifically, network traffic data is monitored in real time using packet capture tools to detect abnormal patterns and malicious communications. This includes large data transmissions from specific IP addresses and the use of protocols different from normal communication patterns. Log data records the operation history of systems and applications and is collected periodically. This allows for the identification of traces of abnormal login attempts or malicious operations. For example, this includes login attempts made outside of normal business hours or a large number of login failures in a short period. User data records the user's behavior history and access patterns, and abnormal behavior is detected by analyzing this data. For example, access to files or directories not normally accessed, or downloading a large number of files in a short period, are considered abnormal. The data collection unit centrally manages this data and transmits it to a central database in real time. This allows the data collection unit to collect a wide range of data from diverse data sources and quickly detect anomalies. Furthermore, the data collection unit can adjust the frequency and accuracy of data collection, enabling flexible responses to specific situations and conditions. For example, by enhancing data collection during specific time periods or when events occur, more detailed information can be obtained. This allows the data collection unit to collect data efficiently and effectively, improving the overall security of the system.
[0031] The Analysis Department analyzes the data collected by the Data Collection Department. For example, the Analysis Department uses AI to analyze the data and identify abnormal patterns and behaviors. Specifically, the AI uses machine learning algorithms to analyze network traffic data and identify abnormal communications that deviate from normal communication patterns. For example, it can detect abnormally high data transfer volumes or malicious communications using specific protocols. In log data analysis, the AI learns past login attempts and operation history to identify abnormal login attempts and malicious operations. For example, login attempts made outside of normal business hours or a large number of login failures in a short period of time are considered abnormal. In user data analysis, the AI learns the user's behavior history to identify abnormal behaviors that deviate from normal behavior patterns. For example, accessing files or directories that are not normally accessed, or downloading a large number of files in a short period of time are considered abnormal. Furthermore, the Analysis Department can also utilize historical data and statistical information to conduct long-term risk assessments and trend analyses. For example, based on past malware infection data, it can predict risk fluctuations in specific periods or regions and formulate future countermeasures. Furthermore, the analysis unit can use anomaly detection algorithms to detect unusual patterns and abnormal data, enabling it to issue warnings early. This allows the analysis unit to not only grasp the situation in real time but also to handle long-term risk management and anomaly detection, thereby improving the reliability and safety of the entire system.
[0032] The Defense Department implements defensive measures based on the analysis results obtained by the Analysis Department. For example, the Defense Department implements defensive measures such as firewall configuration, access control, and intrusion detection systems. Specifically, it modifies firewall settings to block abnormal communications. For example, it blocks unauthorized access from specific IP addresses to enhance the security of the entire network. The Defense Department can also strengthen access control and prevent abnormal login attempts. For example, it automatically blocks login attempts made outside of normal business hours and notifies users. Furthermore, the Defense Department can use intrusion detection systems to detect abnormal access patterns and implement defensive measures. For example, if abnormal access is detected, it automatically issues an alert and notifies administrators. The Defense Department can also continuously modify defensive measures based on real-time updated data to respond to the latest threats. For example, it can quickly update firewall settings and access control policies in response to the emergence of new malware or changes in attack methods. The Defense Department can also collect user feedback to continuously improve the accuracy and effectiveness of defensive measures. For example, it can review settings and introduce new countermeasures based on user feedback after the implementation of defensive measures. This allows the defense unit to implement defensive measures quickly and effectively, improving the overall security of the system.
[0033] The analysis unit can perform a detailed analysis of detected malware. For example, the analysis unit can analyze the malware's code using static analysis. For instance, the analysis unit can disassemble the malware's code to reveal its structure. The analysis unit can also analyze the malware's behavior using dynamic analysis. For example, the analysis unit can run the malware in a sandbox environment and observe its behavior. Furthermore, the analysis unit can analyze the malware's code using disassembly to reveal its operating mechanism. For example, the analysis unit can disassemble the malware's code to identify its operating mechanism. This allows the analysis unit to perform a detailed analysis of the malware and implement more effective defense measures.
[0034] The analysis department can analyze malware code to reveal its structure and operating mechanisms. For example, the analysis department can disassemble malware code to reveal its structure. For example, the analysis department can analyze malware code to identify the techniques and attack vectors used. The analysis department can also analyze the operating mechanisms of malware to reveal its attack methods. For example, the analysis department can analyze malware code to identify its operational flow. Furthermore, the analysis department can analyze malware code to identify its attack vectors. For example, the analysis department can analyze malware code to identify its attack methods. By revealing the structure and operating mechanisms of malware, the analysis department can take swift and effective countermeasures.
[0035] The defense unit can evolve the system by leveraging the learning capabilities of AI. For example, the defense unit can learn new malware patterns using machine learning algorithms. For instance, the defense unit can train AI using training datasets to learn new malware patterns. The defense unit can also automatically generate defensive measures to respond to new threats using AI. For example, the defense unit can generate defensive measures to respond to new threats using AI, thereby evolving the system. Furthermore, the defense unit can use AI to keep the system's defense posture constantly up-to-date. For example, the defense unit can generate defensive measures to respond to new threats using AI, thereby evolving the system. In this way, the defense unit can leverage the learning capabilities of AI to continuously evolve the system and respond to the latest threats.
[0036] The defense unit can learn new malware patterns and improve detection accuracy in subsequent instances. For example, the defense unit can learn new malware patterns using feature extraction algorithms. For instance, it can use AI to extract features of new malware and improve detection accuracy in subsequent instances. Furthermore, the defense unit can learn new malware patterns using pattern recognition algorithms. For example, it can use AI to recognize new malware patterns and improve detection accuracy in subsequent instances. In addition, the defense unit can use AI to learn new malware patterns and improve detection accuracy in subsequent instances. For example, it can use AI to learn new malware patterns and improve detection accuracy in subsequent instances. As a result, the defense unit improves detection accuracy in subsequent instances by learning new malware patterns.
[0037] The data collection unit can collect data to identify abnormal patterns and behaviors. For example, the data collection unit can identify abnormal patterns using anomaly detection algorithms. For example, the data collection unit can collect network traffic data and identify abnormal communication patterns. The data collection unit can also collect log data and identify abnormal login attempts. Furthermore, the data collection unit can collect user data and identify abnormal access patterns. For example, the data collection unit can collect network traffic data and identify abnormal packets. The data collection unit can also collect log data and identify abnormal login attempts. The data collection unit can also collect user data and identify abnormal access patterns. As a result, the data collection unit can detect unknown malware by collecting data to identify abnormal patterns and behaviors.
[0038] The data collection unit can analyze past cyberattack history and select the optimal data collection method. For example, the data collection unit can analyze past cyberattack history and identify trends where attacks are concentrated during specific time periods. For example, the data collection unit can analyze past cyberattack history and intensify data collection during specific time periods. The data collection unit can also focus data collection on specific network segments or devices based on past attack patterns. For example, the data collection unit can analyze past cyberattack history and intensify data collection for specific network segments. Furthermore, the data collection unit can analyze past attack history and select an effective data collection method for specific attack techniques. For example, the data collection unit can analyze past cyberattack history and select an effective data collection method for specific attack techniques. In this way, by analyzing past cyberattack history, the data collection unit can select the optimal data collection method and achieve effective data collection.
[0039] The data collection unit can filter data based on specific network segments or devices during data collection. For example, the data collection unit can prioritize collecting data to detect abnormal traffic from specific network segments. The data collection unit can also filter communications from specific devices to collect data to detect abnormal behavior. Furthermore, the data collection unit can monitor network-wide traffic and focus data collection on specific segments or devices. This allows the data collection unit to efficiently collect data by filtering based on specific network segments or devices.
[0040] The data collection unit can prioritize the collection of highly relevant data by considering geographical location information during data collection. For example, the data collection unit can prioritize the collection of data from a specific region in response to cyberattacks occurring in that region. The data collection unit can also prioritize the collection of data from a specific country or region based on geographical location information. Furthermore, the data collection unit can prioritize the collection of data to detect unusual activity in a specific city or region by considering geographical location information. In this way, the data collection unit can effectively collect data by prioritizing the collection of highly relevant data by considering geographical location information.
[0041] The data collection unit can analyze social media activity and collect relevant data during data collection. For example, the data collection unit can detect unusual activity on social media and collect data related to that activity. The data collection unit can also collect relevant data based on specific keywords or hashtags on social media. Furthermore, the data collection unit can analyze user behavior patterns on social media and collect relevant data. In this way, the data collection unit can efficiently collect relevant data by analyzing social media activity.
[0042] The analysis unit can adjust the level of detail of the analysis based on the importance of the data during the analysis. For example, the analysis unit can assess the importance of the data and perform a detailed analysis on the data with high importance. The analysis unit can also assess the importance of the data and perform a simplified analysis on the data with low importance. Furthermore, the analysis unit can dynamically adjust the level of detail of the analysis according to the importance of the data. For example, the analysis unit can assess the importance of the data and dynamically adjust the level of detail of the analysis according to its importance. This allows the analysis unit to perform efficient analysis by adjusting the level of detail of the analysis based on the importance of the data.
[0043] The analysis unit can apply different analysis algorithms depending on the data category during analysis. For example, the analysis unit can select the optimal analysis algorithm depending on the type of malware. Furthermore, the analysis unit can apply different analysis methods based on the data category. For example, the analysis unit can apply different analysis methods based on the data category. In addition, the analysis unit can dynamically select the optimal analysis algorithm depending on the data characteristics. For example, the analysis unit can dynamically select the optimal analysis algorithm depending on the data characteristics. This allows the analysis unit to provide optimal analysis results by applying different analysis algorithms depending on the data category.
[0044] The analysis department can determine the priority of analysis based on the data collection timing. For example, the analysis department can prioritize the analysis of the latest data to enable a rapid response. The analysis department can also analyze long-term trends based on historical data. Furthermore, the analysis department can dynamically adjust the priority of analysis according to the data collection timing. For example, the analysis department can dynamically adjust the priority of analysis according to the data collection timing. This allows the analysis department to determine the priority of analysis based on the data collection timing, enabling a rapid response.
[0045] The analysis unit can adjust the order of analysis based on the relevance of the data during the analysis process. For example, the analysis unit can prioritize the analysis of highly relevant data, enabling a quick response. Furthermore, the analysis unit can postpone the analysis of less relevant data to ensure efficient analysis. In addition, the analysis unit can dynamically adjust the order of analysis based on the relevance of the data. This allows the analysis unit to perform efficient analysis by adjusting the order of analysis based on the relevance of the data.
[0046] The defense unit can analyze past defense history and select the optimal defense method when implementing a defense measure. For example, the defense unit can analyze past defense history and select an effective defense method. For example, the defense unit can analyze past defense history and select an effective defense method. The defense unit can also select the optimal defense method for a specific attack method based on past defense history. For example, the defense unit can select the optimal defense method for a specific attack method based on past defense history. Furthermore, the defense unit can analyze past defense history and dynamically select the most effective defense method. For example, the defense unit analyzes past defense history and dynamically selects the most effective defense method. As a result, the defense unit can select the optimal defense method by analyzing past defense history, enabling effective defense.
[0047] The defense unit can customize its defense measures based on specific network segments or devices when executing defense measures. For example, the defense unit can provide optimal defense measures for a specific network segment. Furthermore, the defense unit can provide customized defense measures for specific devices. In addition, the defense unit can monitor network-wide traffic and provide focused defense measures for specific segments or devices. This allows the defense unit to provide efficient defense by customizing its defense measures based on specific network segments or devices.
[0048] The defense unit can select the optimal defense method by considering geographical location information when implementing defense measures. For example, the defense unit can provide the most suitable defense method for a particular region in response to cyberattacks occurring in that region. The defense unit can also provide the most suitable defense method for a particular country or region based on geographical location information. Furthermore, the defense unit can consider geographical location information and provide focused defense measures for a particular city or region. As a result, the defense unit can achieve effective defense by selecting the optimal defense method by considering geographical location information.
[0049] The defense unit can analyze social media activity and propose defense measures when implementing defense strategies. For example, the defense unit can detect unusual activity on social media and provide the most appropriate defense measures for that activity. The defense unit can also propose defense measures based on specific keywords or hashtags on social media. Furthermore, the defense unit can analyze user behavior patterns on social media and provide the most appropriate defense measures. In this way, the defense unit can efficiently propose relevant defense measures by analyzing social media activity.
[0050] The system according to the embodiment is not limited to the example described above, and various modifications are possible, for example, as follows.
[0051] The data collection unit can analyze past cyberattack history and select the optimal data collection method. For example, it can analyze past cyberattack history to identify trends where attacks are concentrated during specific time periods. For example, it can analyze past cyberattack history and intensify data collection during specific time periods. Furthermore, based on past attack patterns, the data collection unit can focus data collection on specific network segments or devices. In this way, by analyzing past cyberattack history, the data collection unit can select the optimal data collection method and achieve effective data collection.
[0052] The analysis unit can adjust the level of detail of the analysis based on the importance of the data during the analysis process. For example, the analysis unit can assess the importance of the data and perform a detailed analysis on the most important data. Alternatively, the analysis unit can assess the importance of the data and perform a simplified analysis on the less important data. Furthermore, the analysis unit can dynamically adjust the level of detail of the analysis according to the importance of the data. This allows the analysis unit to perform efficient analysis by adjusting the level of detail based on the importance of the data.
[0053] The defense unit can analyze past defense history and select the optimal defense method when implementing a defense measure. For example, the defense unit can analyze past defense history and select an effective defense method. Furthermore, the defense unit can select the optimal defense method for a specific attack method based on past defense history. In addition, the defense unit can dynamically select the most effective defense method by analyzing past defense history. This enables the defense unit to select the optimal defense method and achieve effective defense by analyzing past defense history.
[0054] The data collection unit can prioritize the collection of highly relevant data by considering geographical location information during data collection. For example, the data collection unit can prioritize the collection of data from a specific region in response to cyberattacks occurring in that region. Furthermore, the data collection unit can prioritize the collection of data from a specific country or region based on geographical location information. In addition, the data collection unit can prioritize the collection of data to detect unusual activity in a specific city or region, taking geographical location information into consideration. This enables effective data collection by prioritizing the collection of highly relevant data while considering geographical location information.
[0055] The defense unit can customize its defense measures based on specific network segments and devices when executing defense strategies. For example, it can provide optimal defense measures for a particular network segment. It can also provide customized defense measures for specific devices. Furthermore, the defense unit can monitor network-wide traffic and provide focused defense measures for specific segments and devices. This enables efficient defense by customizing defense measures based on specific network segments and devices.
[0056] The following briefly describes the processing flow for example form 1.
[0057] Step 1: The collection unit collects data. The collection unit can collect, for example, network traffic data, log data, and user data. The collection unit monitors network traffic data in real time and detects abnormal patterns. The collection unit can also periodically collect log data and identify abnormal behavior. Furthermore, the collection unit can collect user data and detect abnormal behavior. Step 2: The analysis unit analyzes the data collected by the collection unit. The analysis unit uses AI to analyze the data and identify abnormal patterns and behaviors. For example, the analysis unit can use AI to analyze network traffic data and identify abnormal communication patterns. The analysis unit can also use AI to analyze log data and identify abnormal login attempts. Furthermore, the analysis unit can use AI to analyze user data and identify abnormal access patterns. Step 3: The defense unit implements defensive measures based on the analysis results obtained by the analysis unit. The defense unit implements defensive measures such as firewall configuration, access control, and intrusion detection systems. For example, the defense unit modifies firewall settings to block abnormal communications. The defense unit can also strengthen access control to prevent abnormal login attempts. Furthermore, the defense unit can use intrusion detection systems to detect abnormal access patterns and implement defensive measures.
[0058] (Example of form 2) The malware detection and analysis security system according to an embodiment of the present invention is a solution that leverages generative AI technology to bring new possibilities to the field of cybersecurity. This system surpasses the limitations of conventional signature-based antivirus software and has the ability to detect unknown malware and cleverly crafted malicious programs with high accuracy and analyze them in detail. The system processes vast amounts of data at high speed and identifies subtle behaviors and patterns that differ from normal programs. This enables effective defense not only against known threats but also against new types of malware and variants. Furthermore, the system's learning ability allows it to maintain an up-to-date defense posture against ever-evolving cyber threats. A notable feature of this system is its ability to perform detailed analysis of detected malware, not just detection. The system quickly analyzes the structure, operating mechanisms, and potential impact of malware, providing valuable insights to security professionals. This enables organizations to take faster and more effective countermeasures, minimizing damage and strengthening preparedness for future attacks. For example, the system processes large amounts of data and identifies abnormal patterns and behaviors. For instance, it can detect communication patterns and file operations that differ from normal programs. This enables effective defense against new types of malware that cannot be detected by conventional signature-based antivirus software. Next, the system performs a detailed analysis of the detected malware. It analyzes the malware's code, revealing its structure and operating mechanisms. For example, it can identify how the malware infiltrates the system and what operations it performs. This allows security professionals to take swift and effective countermeasures. Furthermore, the system possesses learning capabilities, constantly maintaining an up-to-date defense against ever-evolving cyber threats. For instance, it can learn new malware patterns, improving detection accuracy in subsequent instances. This ensures that organizations can always effectively defend against the latest threats. This system is extremely useful for security providers offering enterprise security solutions, large corporations, financial institutions, and government agencies.Traditional security systems struggle to cope with rapidly evolving malware. This system strengthens organizational security by using AI to detect evolving malware patterns and immediately implement countermeasures. Furthermore, automated analysis by the system enables malware analysis even without specialized knowledge, allowing for rapid response. As a result, this malware detection and analysis security system provides effective defense against cyber threats and enhances organizational security.
[0059] The malware detection and analysis security system according to this embodiment comprises a collection unit, an analysis unit, and a defense unit. The collection unit collects data. The collection unit can collect, for example, network traffic data, log data, user data, etc. The collection unit can, for example, monitor network traffic data in real time and detect abnormal patterns. The collection unit can also periodically collect log data and identify abnormal behavior. Furthermore, the collection unit can collect user data and detect abnormal actions. For example, the collection unit monitors network traffic data in real time and detects abnormal packets. The collection unit can also periodically collect log data and identify abnormal login attempts. The collection unit can also collect user data and detect abnormal access patterns. The analysis unit analyzes the data collected by the collection unit. The analysis unit can, for example, use AI to analyze the data and identify abnormal patterns and behaviors. For example, the analysis unit can use AI to analyze network traffic data and identify abnormal communication patterns. Furthermore, the analysis unit can use AI to analyze log data and identify abnormal login attempts. Furthermore, the analysis unit can use AI to analyze user data and identify abnormal access patterns. For example, the analysis unit uses AI to analyze network traffic data and identify abnormal packets. The analysis unit can also use AI to analyze log data and identify abnormal login attempts. The analysis unit can also use AI to analyze user data and identify abnormal access patterns. The defense unit takes defensive measures based on the analysis results obtained by the analysis unit. The defense unit implements defensive measures such as firewall configuration, access control, and intrusion detection systems. For example, the defense unit can change firewall settings to block abnormal communications. The defense unit can also strengthen access control to prevent abnormal login attempts. Furthermore, the defense unit can use intrusion detection systems to detect abnormal access patterns and take defensive measures. For example, the defense unit can change firewall settings to block abnormal communications. The defense unit can also strengthen access control to prevent abnormal login attempts.The defense unit can also use an intrusion detection system to detect abnormal access patterns and implement defensive measures. As a result, the malware detection and analysis security system according to this embodiment enables efficient cybersecurity measures because data collection, analysis, and execution of defensive measures are performed in a continuous flow.
[0060] The data collection unit collects data. For example, it can collect network traffic data, log data, and user data. Specifically, network traffic data is monitored in real time using packet capture tools to detect abnormal patterns and malicious communications. This includes large data transmissions from specific IP addresses and the use of protocols different from normal communication patterns. Log data records the operation history of systems and applications and is collected periodically. This allows for the identification of traces of abnormal login attempts or malicious operations. For example, this includes login attempts made outside of normal business hours or a large number of login failures in a short period. User data records the user's behavior history and access patterns, and abnormal behavior is detected by analyzing this data. For example, access to files or directories not normally accessed, or downloading a large number of files in a short period, are considered abnormal. The data collection unit centrally manages this data and transmits it to a central database in real time. This allows the data collection unit to collect a wide range of data from diverse data sources and quickly detect anomalies. Furthermore, the data collection unit can adjust the frequency and accuracy of data collection, enabling flexible responses to specific situations and conditions. For example, by enhancing data collection during specific time periods or when events occur, more detailed information can be obtained. This allows the data collection unit to collect data efficiently and effectively, improving the overall security of the system.
[0061] The Analysis Department analyzes the data collected by the Data Collection Department. For example, the Analysis Department uses AI to analyze the data and identify abnormal patterns and behaviors. Specifically, the AI uses machine learning algorithms to analyze network traffic data and identify abnormal communications that deviate from normal communication patterns. For example, it can detect abnormally high data transfer volumes or malicious communications using specific protocols. In log data analysis, the AI learns past login attempts and operation history to identify abnormal login attempts and malicious operations. For example, login attempts made outside of normal business hours or a large number of login failures in a short period of time are considered abnormal. In user data analysis, the AI learns the user's behavior history to identify abnormal behaviors that deviate from normal behavior patterns. For example, accessing files or directories that are not normally accessed, or downloading a large number of files in a short period of time are considered abnormal. Furthermore, the Analysis Department can also utilize historical data and statistical information to conduct long-term risk assessments and trend analyses. For example, based on past malware infection data, it can predict risk fluctuations in specific periods or regions and formulate future countermeasures. Furthermore, the analysis unit can use anomaly detection algorithms to detect unusual patterns and abnormal data, enabling it to issue warnings early. This allows the analysis unit to not only grasp the situation in real time but also to handle long-term risk management and anomaly detection, thereby improving the reliability and safety of the entire system.
[0062] The Defense Department implements defensive measures based on the analysis results obtained by the Analysis Department. For example, the Defense Department implements defensive measures such as firewall configuration, access control, and intrusion detection systems. Specifically, it modifies firewall settings to block abnormal communications. For example, it blocks unauthorized access from specific IP addresses to enhance the security of the entire network. The Defense Department can also strengthen access control and prevent abnormal login attempts. For example, it automatically blocks login attempts made outside of normal business hours and notifies users. Furthermore, the Defense Department can use intrusion detection systems to detect abnormal access patterns and implement defensive measures. For example, if abnormal access is detected, it automatically issues an alert and notifies administrators. The Defense Department can also continuously modify defensive measures based on real-time updated data to respond to the latest threats. For example, it can quickly update firewall settings and access control policies in response to the emergence of new malware or changes in attack methods. The Defense Department can also collect user feedback to continuously improve the accuracy and effectiveness of defensive measures. For example, it can review settings and introduce new countermeasures based on user feedback after the implementation of defensive measures. This allows the defense unit to implement defensive measures quickly and effectively, improving the overall security of the system.
[0063] The analysis unit can perform a detailed analysis of detected malware. For example, the analysis unit can analyze the malware's code using static analysis. For instance, the analysis unit can disassemble the malware's code to reveal its structure. The analysis unit can also analyze the malware's behavior using dynamic analysis. For example, the analysis unit can run the malware in a sandbox environment and observe its behavior. Furthermore, the analysis unit can analyze the malware's code using disassembly to reveal its operating mechanism. For example, the analysis unit can disassemble the malware's code to identify its operating mechanism. This allows the analysis unit to perform a detailed analysis of the malware and implement more effective defense measures.
[0064] The analysis department can analyze malware code to reveal its structure and operating mechanisms. For example, the analysis department can disassemble malware code to reveal its structure. For example, the analysis department can analyze malware code to identify the techniques and attack vectors used. The analysis department can also analyze the operating mechanisms of malware to reveal its attack methods. For example, the analysis department can analyze malware code to identify its operational flow. Furthermore, the analysis department can analyze malware code to identify its attack vectors. For example, the analysis department can analyze malware code to identify its attack methods. By revealing the structure and operating mechanisms of malware, the analysis department can take swift and effective countermeasures.
[0065] The defense unit can evolve the system by leveraging the learning capabilities of AI. For example, the defense unit can learn new malware patterns using machine learning algorithms. For instance, the defense unit can train AI using training datasets to learn new malware patterns. The defense unit can also automatically generate defensive measures to respond to new threats using AI. For example, the defense unit can generate defensive measures to respond to new threats using AI, thereby evolving the system. Furthermore, the defense unit can use AI to keep the system's defense posture constantly up-to-date. For example, the defense unit can generate defensive measures to respond to new threats using AI, thereby evolving the system. In this way, the defense unit can leverage the learning capabilities of AI to continuously evolve the system and respond to the latest threats.
[0066] The defense unit can learn new malware patterns and improve detection accuracy in subsequent instances. For example, the defense unit can learn new malware patterns using feature extraction algorithms. For instance, it can use AI to extract features of new malware and improve detection accuracy in subsequent instances. Furthermore, the defense unit can learn new malware patterns using pattern recognition algorithms. For example, it can use AI to recognize new malware patterns and improve detection accuracy in subsequent instances. In addition, the defense unit can use AI to learn new malware patterns and improve detection accuracy in subsequent instances. For example, it can use AI to learn new malware patterns and improve detection accuracy in subsequent instances. As a result, the defense unit improves detection accuracy in subsequent instances by learning new malware patterns.
[0067] The data collection unit can collect data to identify abnormal patterns and behaviors. For example, the data collection unit can identify abnormal patterns using anomaly detection algorithms. For example, the data collection unit can collect network traffic data and identify abnormal communication patterns. The data collection unit can also collect log data and identify abnormal login attempts. Furthermore, the data collection unit can collect user data and identify abnormal access patterns. For example, the data collection unit can collect network traffic data and identify abnormal packets. The data collection unit can also collect log data and identify abnormal login attempts. The data collection unit can also collect user data and identify abnormal access patterns. As a result, the data collection unit can detect unknown malware by collecting data to identify abnormal patterns and behaviors.
[0068] The data collection unit can estimate the user's emotions and adjust the timing of data collection based on the estimated emotions. For example, the data collection unit can estimate the user's emotions using an emotion analysis algorithm. For instance, it can collect the user's facial expression data and estimate the emotions using an emotion analysis algorithm. It can also collect the user's voice data and estimate the emotions using an emotion analysis algorithm. Furthermore, it can collect the user's biometric data and estimate the emotions using an emotion analysis algorithm. This allows the data collection unit to reduce system load and enable efficient data collection by adjusting the timing of data collection according to the user's emotions.
[0069] The data collection unit can analyze past cyberattack history and select the optimal data collection method. For example, the data collection unit can analyze past cyberattack history and identify trends where attacks are concentrated during specific time periods. For example, the data collection unit can analyze past cyberattack history and intensify data collection during specific time periods. The data collection unit can also focus data collection on specific network segments or devices based on past attack patterns. For example, the data collection unit can analyze past cyberattack history and intensify data collection for specific network segments. Furthermore, the data collection unit can analyze past attack history and select an effective data collection method for specific attack techniques. For example, the data collection unit can analyze past cyberattack history and select an effective data collection method for specific attack techniques. In this way, by analyzing past cyberattack history, the data collection unit can select the optimal data collection method and achieve effective data collection.
[0070] The data collection unit can filter data based on specific network segments or devices during data collection. For example, the data collection unit can prioritize collecting data to detect abnormal traffic from specific network segments. The data collection unit can also filter communications from specific devices to collect data to detect abnormal behavior. Furthermore, the data collection unit can monitor network-wide traffic and focus data collection on specific segments or devices. This allows the data collection unit to efficiently collect data by filtering based on specific network segments or devices.
[0071] The data collection unit can estimate the user's emotions and determine the priority of data to collect based on the estimated emotions. For example, the data collection unit can estimate the user's emotions using an emotion analysis algorithm. For instance, it can collect the user's facial expression data and estimate the emotions using an emotion analysis algorithm. It can also collect the user's voice data and estimate the emotions using an emotion analysis algorithm. Furthermore, it can collect the user's biometric data and estimate the emotions using an emotion analysis algorithm. This allows the data collection unit to efficiently collect data by determining the priority of data to collect according to the user's emotions.
[0072] The data collection unit can prioritize the collection of highly relevant data by considering geographical location information during data collection. For example, the data collection unit can prioritize the collection of data from a specific region in response to cyberattacks occurring in that region. The data collection unit can also prioritize the collection of data from a specific country or region based on geographical location information. Furthermore, the data collection unit can prioritize the collection of data to detect unusual activity in a specific city or region by considering geographical location information. In this way, the data collection unit can effectively collect data by prioritizing the collection of highly relevant data by considering geographical location information.
[0073] The data collection unit can analyze social media activity and collect relevant data during data collection. For example, the data collection unit can detect unusual activity on social media and collect data related to that activity. The data collection unit can also collect relevant data based on specific keywords or hashtags on social media. Furthermore, the data collection unit can analyze user behavior patterns on social media and collect relevant data. In this way, the data collection unit can efficiently collect relevant data by analyzing social media activity.
[0074] The analysis unit can estimate the user's emotions and adjust the presentation of the analysis based on the estimated emotions. For example, the analysis unit can estimate the user's emotions using an emotion analysis algorithm. For example, the analysis unit can collect the user's facial expression data and estimate the emotions using an emotion analysis algorithm. The analysis unit can also collect the user's voice data and estimate the emotions using an emotion analysis algorithm. Furthermore, the analysis unit can collect the user's biometric data and estimate the emotions using an emotion analysis algorithm. This allows the analysis unit to provide more appropriate analysis results by adjusting the presentation of the analysis according to the user's emotions.
[0075] The analysis unit can adjust the level of detail of the analysis based on the importance of the data during the analysis. For example, the analysis unit can assess the importance of the data and perform a detailed analysis on the data with high importance. The analysis unit can also assess the importance of the data and perform a simplified analysis on the data with low importance. Furthermore, the analysis unit can dynamically adjust the level of detail of the analysis according to the importance of the data. For example, the analysis unit can assess the importance of the data and dynamically adjust the level of detail of the analysis according to its importance. This allows the analysis unit to perform efficient analysis by adjusting the level of detail of the analysis based on the importance of the data.
[0076] The analysis unit can apply different analysis algorithms depending on the data category during analysis. For example, the analysis unit can select the optimal analysis algorithm depending on the type of malware. Furthermore, the analysis unit can apply different analysis methods based on the data category. For example, the analysis unit can apply different analysis methods based on the data category. In addition, the analysis unit can dynamically select the optimal analysis algorithm depending on the data characteristics. For example, the analysis unit can dynamically select the optimal analysis algorithm depending on the data characteristics. This allows the analysis unit to provide optimal analysis results by applying different analysis algorithms depending on the data category.
[0077] The analysis unit can estimate the user's emotions and adjust the length of the analysis based on the estimated emotions. For example, the analysis unit can estimate the user's emotions using an emotion analysis algorithm. For instance, it can collect the user's facial expression data and estimate the emotions using an emotion analysis algorithm. It can also collect the user's voice data and estimate the emotions using an emotion analysis algorithm. Furthermore, it can collect the user's biometric data and estimate the emotions using an emotion analysis algorithm. This allows the analysis unit to provide more appropriate analysis results by adjusting the length of the analysis according to the user's emotions.
[0078] The analysis department can determine the priority of analysis based on the data collection timing. For example, the analysis department can prioritize the analysis of the latest data to enable a rapid response. The analysis department can also analyze long-term trends based on historical data. Furthermore, the analysis department can dynamically adjust the priority of analysis according to the data collection timing. For example, the analysis department can dynamically adjust the priority of analysis according to the data collection timing. This allows the analysis department to determine the priority of analysis based on the data collection timing, enabling a rapid response.
[0079] The analysis unit can adjust the order of analysis based on the relevance of the data during the analysis process. For example, the analysis unit can prioritize the analysis of highly relevant data, enabling a quick response. Furthermore, the analysis unit can postpone the analysis of less relevant data to ensure efficient analysis. In addition, the analysis unit can dynamically adjust the order of analysis based on the relevance of the data. This allows the analysis unit to perform efficient analysis by adjusting the order of analysis based on the relevance of the data.
[0080] The defense unit can estimate the user's emotions and adjust the execution method of defense measures based on the estimated user emotions. For example, the defense unit can estimate the user's emotions using an emotion analysis algorithm. For example, the defense unit can collect the user's facial expression data and estimate the emotions using an emotion analysis algorithm. The defense unit can also collect the user's voice data and estimate the emotions using an emotion analysis algorithm. Furthermore, the defense unit can collect the user's biometric data and estimate the emotions using an emotion analysis algorithm. For example, the defense unit can collect the user's facial expression data and estimate the emotions using an emotion analysis algorithm. The defense unit can also collect the user's voice data and estimate the emotions using an emotion analysis algorithm. The defense unit can also collect the user's biometric data and estimate the emotions using an emotion analysis algorithm. This allows the defense unit to provide more appropriate defense measures by adjusting the execution method of defense measures according to the user's emotions.
[0081] The defense unit can analyze past defense history and select the optimal defense method when implementing a defense measure. For example, the defense unit can analyze past defense history and select an effective defense method. For example, the defense unit can analyze past defense history and select an effective defense method. The defense unit can also select the optimal defense method for a specific attack method based on past defense history. For example, the defense unit can select the optimal defense method for a specific attack method based on past defense history. Furthermore, the defense unit can analyze past defense history and dynamically select the most effective defense method. For example, the defense unit analyzes past defense history and dynamically selects the most effective defense method. As a result, the defense unit can select the optimal defense method by analyzing past defense history, enabling effective defense.
[0082] The defense unit can customize its defense measures based on specific network segments or devices when executing defense measures. For example, the defense unit can provide optimal defense measures for a specific network segment. Furthermore, the defense unit can provide customized defense measures for specific devices. In addition, the defense unit can monitor network-wide traffic and provide focused defense measures for specific segments or devices. This allows the defense unit to provide efficient defense by customizing its defense measures based on specific network segments or devices.
[0083] The defense unit can estimate the user's emotions and determine the priority of defense measures based on the estimated user emotions. For example, the defense unit can estimate the user's emotions using an emotion analysis algorithm. For example, the defense unit can collect the user's facial expression data and estimate the emotions using an emotion analysis algorithm. The defense unit can also collect the user's voice data and estimate the emotions using an emotion analysis algorithm. Furthermore, the defense unit can collect the user's biometric data and estimate the emotions using an emotion analysis algorithm. For example, the defense unit can collect the user's facial expression data and estimate the emotions using an emotion analysis algorithm. The defense unit can also collect the user's voice data and estimate the emotions using an emotion analysis algorithm. The defense unit can also collect the user's biometric data and estimate the emotions using an emotion analysis algorithm. This allows the defense unit to provide more appropriate defense measures by determining the priority of defense measures according to the user's emotions.
[0084] The defense unit can select the optimal defense method by considering geographical location information when implementing defense measures. For example, the defense unit can provide the most suitable defense method for a particular region in response to cyberattacks occurring in that region. The defense unit can also provide the most suitable defense method for a particular country or region based on geographical location information. Furthermore, the defense unit can consider geographical location information and provide focused defense measures for a particular city or region. As a result, the defense unit can achieve effective defense by selecting the optimal defense method by considering geographical location information.
[0085] The defense unit can analyze social media activity and propose defense measures when implementing defense strategies. For example, the defense unit can detect unusual activity on social media and provide the most appropriate defense measures for that activity. The defense unit can also propose defense measures based on specific keywords or hashtags on social media. Furthermore, the defense unit can analyze user behavior patterns on social media and provide the most appropriate defense measures. In this way, the defense unit can efficiently propose relevant defense measures by analyzing social media activity.
[0086] The system according to the embodiment is not limited to the example described above, and various modifications are possible, for example, as follows.
[0087] The data collection unit can estimate the user's emotions and adjust the timing of data collection based on the estimated emotions. For example, the data collection unit can estimate the user's emotions using an emotion analysis algorithm. For instance, the data collection unit can collect the user's facial expression data and estimate their emotions using an emotion analysis algorithm. The data collection unit can also collect the user's voice data and estimate their emotions using an emotion analysis algorithm. Furthermore, the data collection unit can collect the user's biometric data and estimate their emotions using an emotion analysis algorithm. This allows the data collection unit to reduce the system load and enable efficient data collection by adjusting the timing of data collection according to the user's emotions.
[0088] The analysis unit can estimate the user's emotions and adjust the presentation of the analysis based on the estimated emotions. For example, the analysis unit can estimate the user's emotions using an emotion analysis algorithm. For example, the analysis unit can collect the user's facial expression data and estimate the emotions using an emotion analysis algorithm. The analysis unit can also collect the user's voice data and estimate the emotions using an emotion analysis algorithm. Furthermore, the analysis unit can collect the user's biometric data and estimate the emotions using an emotion analysis algorithm. As a result, the analysis unit can provide more appropriate analysis results by adjusting the presentation of the analysis according to the user's emotions.
[0089] The defense unit can estimate the user's emotions and adjust the execution method of defense measures based on the estimated user emotions. For example, the defense unit can estimate the user's emotions using an emotion analysis algorithm. For example, the defense unit can collect the user's facial expression data and estimate emotions using an emotion analysis algorithm. The defense unit can also collect the user's voice data and estimate emotions using an emotion analysis algorithm. Furthermore, the defense unit can collect the user's biometric data and estimate emotions using an emotion analysis algorithm. As a result, the defense unit can provide more appropriate defense measures by adjusting the execution method of defense measures according to the user's emotions.
[0090] The data collection unit can analyze past cyberattack history and select the optimal data collection method. For example, it can analyze past cyberattack history to identify trends where attacks are concentrated during specific time periods. For example, it can analyze past cyberattack history and intensify data collection during specific time periods. Furthermore, based on past attack patterns, the data collection unit can focus data collection on specific network segments or devices. In this way, by analyzing past cyberattack history, the data collection unit can select the optimal data collection method and achieve effective data collection.
[0091] The analysis unit can adjust the level of detail of the analysis based on the importance of the data during the analysis process. For example, the analysis unit can assess the importance of the data and perform a detailed analysis on the most important data. Alternatively, the analysis unit can assess the importance of the data and perform a simplified analysis on the less important data. Furthermore, the analysis unit can dynamically adjust the level of detail of the analysis according to the importance of the data. This allows the analysis unit to perform efficient analysis by adjusting the level of detail based on the importance of the data.
[0092] The defense unit can analyze past defense history and select the optimal defense method when implementing a defense measure. For example, the defense unit can analyze past defense history and select an effective defense method. Furthermore, the defense unit can select the optimal defense method for a specific attack method based on past defense history. In addition, the defense unit can dynamically select the most effective defense method by analyzing past defense history. This enables the defense unit to select the optimal defense method and achieve effective defense by analyzing past defense history.
[0093] The data collection unit can prioritize the collection of highly relevant data by considering geographical location information during data collection. For example, the data collection unit can prioritize the collection of data from a specific region in response to cyberattacks occurring in that region. Furthermore, the data collection unit can prioritize the collection of data from a specific country or region based on geographical location information. In addition, the data collection unit can prioritize the collection of data to detect unusual activity in a specific city or region, taking geographical location information into consideration. This enables effective data collection by prioritizing the collection of highly relevant data while considering geographical location information.
[0094] The analysis unit can estimate the user's emotions and adjust the length of the analysis based on the estimated emotions. For example, the analysis unit can estimate the user's emotions using an emotion analysis algorithm. For example, the analysis unit can collect the user's facial expression data and estimate the emotions using an emotion analysis algorithm. The analysis unit can also collect the user's voice data and estimate the emotions using an emotion analysis algorithm. Furthermore, the analysis unit can collect the user's biometric data and estimate the emotions using an emotion analysis algorithm. As a result, the analysis unit can provide more appropriate analysis results by adjusting the length of the analysis according to the user's emotions.
[0095] The defense unit can customize its defense measures based on specific network segments and devices when executing defense strategies. For example, it can provide optimal defense measures for a particular network segment. It can also provide customized defense measures for specific devices. Furthermore, the defense unit can monitor network-wide traffic and provide focused defense measures for specific segments and devices. This enables efficient defense by customizing defense measures based on specific network segments and devices.
[0096] The defense unit can estimate the user's emotions and determine the priority of defense measures based on the estimated user emotions. For example, the defense unit can estimate the user's emotions using an emotion analysis algorithm. For example, the defense unit can collect the user's facial expression data and estimate emotions using an emotion analysis algorithm. The defense unit can also collect the user's voice data and estimate emotions using an emotion analysis algorithm. Furthermore, the defense unit can collect the user's biometric data and estimate emotions using an emotion analysis algorithm. As a result, the defense unit can provide more appropriate defense measures by determining the priority of defense measures according to the user's emotions.
[0097] The following briefly describes the processing flow for example form 2.
[0098] Step 1: The collection unit collects data. The collection unit can collect, for example, network traffic data, log data, and user data. The collection unit monitors network traffic data in real time and detects abnormal patterns. The collection unit can also periodically collect log data and identify abnormal behavior. Furthermore, the collection unit can collect user data and detect abnormal behavior. Step 2: The analysis unit analyzes the data collected by the collection unit. The analysis unit uses AI to analyze the data and identify abnormal patterns and behaviors. For example, the analysis unit can use AI to analyze network traffic data and identify abnormal communication patterns. The analysis unit can also use AI to analyze log data and identify abnormal login attempts. Furthermore, the analysis unit can use AI to analyze user data and identify abnormal access patterns. Step 3: The defense unit implements defensive measures based on the analysis results obtained by the analysis unit. The defense unit implements defensive measures such as firewall configuration, access control, and intrusion detection systems. For example, the defense unit modifies firewall settings to block abnormal communications. The defense unit can also strengthen access control to prevent abnormal login attempts. Furthermore, the defense unit can use intrusion detection systems to detect abnormal access patterns and implement defensive measures.
[0099] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.
[0100] Data generation model 58 is a form of so-called generative AI (Artificial Intelligence). An example of data generation model 58 is ChatGPT (registered trademark) (Internet search).<URL: https: / / openai.com / blog / chatgpt> Examples of generative AI include text generation AI, image generation AI, and multimodal generation AI. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images (e.g., still image data or video data). The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference result in one or more data formats from audio data, text data, and image data. The data generation model 58 includes, for example, text generation AI, image generation AI, and multimodal generation AI. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The specific processing unit 290 performs the specific processing described above using the data generation model 58. The data generation model 58 may be a fine-tuned model that outputs inference results from prompts that do not contain instructions, in which case the data generation model 58 can output inference results from prompts that do not contain instructions. In the data processing device 12, etc., there are multiple types of data generation models 58, and the data generation model 58 includes AI other than generative AI. AI other than generative AI includes, for example, linear regression, logistic regression, decision trees, random forests, support vector machines (SVMs), k-means clustering, convolutional neural networks (CNNs), recurrent neural networks (RNNs), generative adversarial networks (GANs), or naive Bayes, and can perform various processes, but is not limited to these examples. Also, the AI may be an AI agent. Furthermore, when the processing of each of the above parts is performed by the AI, the processing may be performed by the AI in part or in whole, but is not limited to this example.Furthermore, processing performed by AI, including generative AI, may be replaced with rule-based processing, and rule-based processing may be replaced with processing performed by AI, including generative AI.
[0101] Furthermore, the processing performed by the data processing system 10 described above is carried out by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the smart device 14, but it may also be carried out by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the smart device 14. In addition, the specific processing unit 290 of the data processing device 12 acquires or collects information necessary for processing from the smart device 14 or an external device, and the smart device 14 acquires or collects information necessary for processing from the data processing device 12 or an external device.
[0102] Each of the multiple elements described above, including the data collection unit, analysis unit, and defense unit, is implemented in at least one of the smart device 14 and the data processing unit 12. For example, the data collection unit collects network traffic data and log data using the camera 42 and communication I / F 44 of the smart device 14. The analysis unit is implemented in the specific processing unit 290 of the data processing unit 12, which analyzes the collected data using AI to identify abnormal patterns and behaviors. The defense unit is implemented in the specific processing unit 290 of the data processing unit 12, which performs firewall settings and access control based on the analysis results. The correspondence between each unit and the device or control unit is not limited to the example described above and can be modified in various ways.
[0103] [Second Embodiment] Figure 3 shows an example of the configuration of the data processing system 210 according to the second embodiment.
[0104] As shown in Figure 3, the data processing system 210 includes a data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.
[0105] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN and / or LAN.
[0106] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication interface 44. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, and camera 42 are also connected to the bus 52.
[0107] The microphone 238 receives voice signals from the user and accepts instructions from the user. The microphone 238 captures the voice signals from the user, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0108] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, which captures images of the area around the user (for example, an imaging range defined by a field of view equivalent to the field of vision of a typical healthy person).
[0109] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0110] Figure 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Figure 4, the data processing device 12 performs specific processing by the processor 28. The storage 32 stores the specific processing program 56.
[0111] The processor 28 reads a specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 acting as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.
[0112] Storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotions using the emotion identification model 59 and perform identification processing using the user's emotions. The emotion estimation function (emotion identification function) using the emotion identification model 59 performs various estimations and predictions regarding the user's emotions, including but not limited to these examples. Furthermore, emotion estimation and prediction also include, for example, emotion analysis.
[0113] In the smart glasses 214, specific processing is performed by the processor 46. The storage 50 stores a specific processing program 60. The processor 46 reads the specific processing program 60 from the storage 50 and executes the read specific processing program 60 on the RAM 48. The specific processing is realized by the processor 46 acting as a control unit 46A according to the specific processing program 60 executed on the RAM 48. The smart glasses 214 also have a data generation model 58 and an emotion identification model 59, similar to the data generation model and emotion identification model 59, and can perform processing similar to that of the specific processing unit 290 using these models.
[0114] Furthermore, other devices besides the data processing device 12 may also have the data generation model 58. For example, a server device may have the data generation model 58. In this case, the data processing device 12 obtains processing results (such as prediction results) using the data generation model 58 by communicating with the server device that has the data generation model 58. Also, the data processing device 12 may be a server device or a terminal device owned by the user (for example, a mobile phone, robot, home appliance, etc.).
[0115] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0116] The data generation model 58 is a so-called generative AI. An example of a data generation model 58 is a generative AI such as ChatGPT. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and inference data such as audio data representing speech, text data representing text, and image data representing images (e.g., still image data or video data). The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference result in one or more data formats such as audio data, text data, and image data. The data generation model 58 includes, for example, text generation AI, image generation AI, and multimodal generation AI. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The specific processing unit 290 performs the specific processing described above using the data generation model 58. The data generation model 58 may be a fine-tuned model that outputs inference results from prompts that do not contain instructions, in which case the data generation model 58 can output inference results from prompts that do not contain instructions. In the data processing device 12, etc., there are multiple types of data generation models 58, and the data generation model 58 includes AI other than generative AI. AI other than generative AI includes, for example, linear regression, logistic regression, decision trees, random forests, support vector machines (SVM), k-means clustering, convolutional neural networks (CNN), recurrent neural networks (RNN), generative adversarial networks (GAN), or naive Bayes, and can perform various processes, but is not limited to these examples. Also, the AI may be an AI agent. Furthermore, when the processing of each part described above is performed by the AI, the processing may be performed by the AI in part or in whole, but is not limited to this example. Also, processing performed by an AI including a generative AI may be replaced by rule-based processing, and rule-based processing may be replaced by processing performed by an AI including a generative AI.
[0117] The data processing system 210 according to the second embodiment performs the same processing as the data processing system 10 according to the first embodiment. The processing by the data processing system 210 is performed by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the smart glasses 214, but it may also be performed by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the smart glasses 214. In addition, the specific processing unit 290 of the data processing device 12 acquires or collects information necessary for processing from the smart glasses 214 or an external device, and the smart glasses 214 acquires or collects information necessary for processing from the data processing device 12 or an external device.
[0118] Each of the multiple elements described above, including the data collection unit, analysis unit, and defense unit, is implemented, for example, in at least one of the smart glasses 214 and the data processing unit 12. For example, the data collection unit collects network traffic data and log data using the camera 42 and communication I / F 44 of the smart glasses 214. The analysis unit is implemented, for example, in the identification processing unit 290 of the data processing unit 12, which analyzes the collected data using AI to identify abnormal patterns and behaviors. The defense unit is implemented, for example, in the identification processing unit 290 of the data processing unit 12, which performs firewall settings and access control based on the analysis results. The correspondence between each unit and the device or control unit is not limited to the example described above, and various changes are possible.
[0119] [Third Embodiment] Figure 5 shows an example of the configuration of the data processing system 310 according to the third embodiment.
[0120] As shown in Figure 5, the data processing system 310 includes a data processing device 12 and a headset terminal 314. An example of the data processing device 12 is a server.
[0121] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN and / or LAN.
[0122] The headset terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a display 343. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and display 343 are also connected to the bus 52.
[0123] The microphone 238 receives voice signals from the user and accepts instructions from the user. The microphone 238 captures the voice signals from the user, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0124] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, which captures images of the area around the user (for example, an imaging range defined by a field of view equivalent to the field of vision of a typical healthy person).
[0125] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0126] Figure 6 shows an example of the main functions of the data processing device 12 and the headset terminal 314. As shown in Figure 6, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.
[0127] The processor 28 reads a specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 acting as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.
[0128] Storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotions using the emotion identification model 59 and perform identification processing using the user's emotions. The emotion estimation function (emotion identification function) using the emotion identification model 59 performs various estimations and predictions regarding the user's emotions, including but not limited to these examples. Furthermore, emotion estimation and prediction also include, for example, emotion analysis.
[0129] In the headset terminal 314, specific processing is performed by the processor 46. The storage 50 stores a specific program 60. The processor 46 reads the specific program 60 from the storage 50 and executes the read specific program 60 on the RAM 48. The specific processing is realized by the processor 46 acting as a control unit 46A according to the specific program 60 executed on the RAM 48. The headset terminal 314 also has a data generation model 58 and an emotion identification model 59, similar to the data generation model and emotion identification model 59, and can perform processing similar to that of the specific processing unit 290 using these models.
[0130] Furthermore, other devices besides the data processing device 12 may also have the data generation model 58. For example, a server device may have the data generation model 58. In this case, the data processing device 12 obtains processing results (such as prediction results) using the data generation model 58 by communicating with the server device that has the data generation model 58. Also, the data processing device 12 may be a server device or a terminal device owned by the user (for example, a mobile phone, robot, home appliance, etc.).
[0131] The specific processing unit 290 transmits the result of the specific processing to the headset terminal 314. In the headset terminal 314, the control unit 46A causes the speaker 240 and display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0132] The data generation model 58 is a so-called generative AI. An example of a data generation model 58 is a generative AI such as ChatGPT. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and inference data such as audio data representing speech, text data representing text, and image data representing images (e.g., still image data or video data). The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference result in one or more data formats such as audio data, text data, and image data. The data generation model 58 includes, for example, text generation AI, image generation AI, and multimodal generation AI. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The specific processing unit 290 performs the specific processing described above using the data generation model 58. The data generation model 58 may be a fine-tuned model that outputs inference results from prompts that do not contain instructions, in which case the data generation model 58 can output inference results from prompts that do not contain instructions. In the data processing device 12, etc., there are multiple types of data generation models 58, and the data generation model 58 includes AI other than generative AI. AI other than generative AI includes, for example, linear regression, logistic regression, decision trees, random forests, support vector machines (SVM), k-means clustering, convolutional neural networks (CNN), recurrent neural networks (RNN), generative adversarial networks (GAN), or naive Bayes, and can perform various processes, but is not limited to these examples. Also, the AI may be an AI agent. Furthermore, when the processing of each part described above is performed by the AI, the processing may be performed by the AI in part or in whole, but is not limited to this example. Also, processing performed by an AI including a generative AI may be replaced by rule-based processing, and rule-based processing may be replaced by processing performed by an AI including a generative AI.
[0133] The data processing system 310 according to the third embodiment performs the same processing as the data processing system 10 according to the first embodiment. The processing by the data processing system 310 is performed by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the headset terminal 314, but may also be performed by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the headset terminal 314. In addition, the specific processing unit 290 of the data processing device 12 acquires or collects information necessary for processing from the headset terminal 314 or an external device, and the headset terminal 314 acquires or collects information necessary for processing from the data processing device 12 or an external device.
[0134] Each of the multiple elements described above, including the data collection unit, analysis unit, and defense unit, is implemented in at least one of the headset terminal 314 and the data processing unit 12. For example, the data collection unit collects network traffic data and log data using the camera 42 and communication I / F 44 of the headset terminal 314. The analysis unit is implemented in the specific processing unit 290 of the data processing unit 12, which analyzes the collected data using AI to identify abnormal patterns and behaviors. The defense unit is implemented in the specific processing unit 290 of the data processing unit 12, which performs firewall settings and access control based on the analysis results. The correspondence between each unit and the device or control unit is not limited to the example described above and can be modified in various ways.
[0135] [Fourth Embodiment] Figure 7 shows an example of the configuration of the data processing system 410 according to the fourth embodiment.
[0136] As shown in Figure 7, the data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.
[0137] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN and / or LAN.
[0138] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a controlled object 443. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and controlled object 443 are also connected to the bus 52.
[0139] The microphone 238 receives voice signals from the user and accepts instructions from the user. The microphone 238 captures the voice signals from the user, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0140] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS image sensor or CCD image sensor, which captures images of the area around the user (for example, an imaging range defined by a field of view equivalent to the field of vision of a typical healthy person).
[0141] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0142] The controlled object 443 includes a display device, LEDs in the eyes, and motors that drive the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the robot 414's emotions can be expressed by controlling these motors. The robot 414's facial expressions can also be expressed by controlling the illumination state of the LEDs in its eyes.
[0143] Figure 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Figure 8, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.
[0144] The processor 28 reads a specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 acting as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.
[0145] Storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotions using the emotion identification model 59 and perform identification processing using the user's emotions. The emotion estimation function (emotion identification function) using the emotion identification model 59 performs various estimations and predictions regarding the user's emotions, including but not limited to these examples. Furthermore, emotion estimation and prediction also include, for example, emotion analysis.
[0146] In robot 414, specific processing is performed by processor 46. A specific program 60 is stored in storage 50. Processor 46 reads the specific program 60 from storage 50 and executes it on RAM 48. The specific processing is achieved by processor 46 acting as a control unit 46A according to the specific program 60 executed on RAM 48. Robot 414 also has data generation model 58 and emotion identification model 59, similar to those of the robot, and can perform processing similar to that of the specific processing unit 290 using these models.
[0147] Furthermore, other devices besides the data processing device 12 may also have the data generation model 58. For example, a server device may have the data generation model 58. In this case, the data processing device 12 obtains processing results (such as prediction results) using the data generation model 58 by communicating with the server device that has the data generation model 58. Also, the data processing device 12 may be a server device or a terminal device owned by the user (for example, a mobile phone, robot, home appliance, etc.).
[0148] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the controlled object 443 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0149] The data generation model 58 is a so-called generative AI. An example of a data generation model 58 is a generative AI such as ChatGPT. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and inference data such as audio data representing speech, text data representing text, and image data representing images (e.g., still image data or video data). The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference result in one or more data formats such as audio data, text data, and image data. The data generation model 58 includes, for example, text generation AI, image generation AI, and multimodal generation AI. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The specific processing unit 290 performs the specific processing described above using the data generation model 58. The data generation model 58 may be a fine-tuned model that outputs inference results from prompts that do not contain instructions, in which case the data generation model 58 can output inference results from prompts that do not contain instructions. In the data processing device 12, etc., there are multiple types of data generation models 58, and the data generation model 58 includes AI other than generative AI. AI other than generative AI includes, for example, linear regression, logistic regression, decision trees, random forests, support vector machines (SVM), k-means clustering, convolutional neural networks (CNN), recurrent neural networks (RNN), generative adversarial networks (GAN), or naive Bayes, and can perform various processes, but is not limited to these examples. Also, the AI may be an AI agent. Furthermore, when the processing of each part described above is performed by the AI, the processing may be performed by the AI in part or in whole, but is not limited to this example. Also, processing performed by an AI including a generative AI may be replaced by rule-based processing, and rule-based processing may be replaced by processing performed by an AI including a generative AI.
[0150] The data processing system 410 according to the fourth embodiment performs the same processing as the data processing system 10 according to the first embodiment. The processing by the data processing system 410 is performed by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the robot 414, but it may also be performed by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the robot 414. In addition, the specific processing unit 290 of the data processing device 12 acquires or collects information necessary for processing from the robot 414 or an external device, and the robot 414 acquires or collects information necessary for processing from the data processing device 12 or an external device.
[0151] Each of the multiple elements described above, including the data collection unit, analysis unit, and defense unit, is implemented in at least one of the robot 414 and the data processing unit 12. For example, the data collection unit collects network traffic data and log data using the camera 42 and communication I / F 44 of the robot 414. The analysis unit is implemented in the specific processing unit 290 of the data processing unit 12, which analyzes the collected data using AI to identify abnormal patterns and behaviors. The defense unit is implemented in the specific processing unit 290 of the data processing unit 12, which performs firewall settings and access control based on the analysis results. The correspondence between each unit and the device or control unit is not limited to the example described above and can be modified in various ways.
[0152] Furthermore, the emotion identification model 59, acting as an emotion engine, may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to a specific mapping, which is an emotion map (see Figure 9). Similarly, the emotion identification model 59 may also determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.
[0153] Figure 9 shows the emotion map 400, in which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. The closer to the center of the concentric circles, the more primitive the emotions are located. Further out of the concentric circles, emotions representing states and actions arising from mental states are located. Emotion is a concept that includes feelings and mental states. On the left side of the concentric circles, emotions that are generally generated from reactions occurring in the brain are located. On the right side of the concentric circles, emotions that are generally induced by situational judgment are located. Above and below the concentric circles, emotions that are generally generated from reactions occurring in the brain and induced by situational judgment are located. In addition, the emotion of "pleasure" is located on the upper side of the concentric circles, and the emotion of "displeasure" is located on the lower side. Thus, in the emotion map 400, multiple emotions are mapped based on the structure in which emotions arise, and emotions that are likely to occur simultaneously are mapped close together.
[0154] These emotions are distributed at the 3 o'clock position on the Emotion Map 400, and usually fluctuate between feelings of security and anxiety. In the right half of the Emotion Map 400, situational awareness takes precedence over internal feelings, resulting in a calm impression.
[0155] The inside of the Emotion Map 400 represents inner thoughts, while the outside represents actions. Therefore, the further you go from the outside of the Emotion Map 400, the more visible (expressed in actions) your emotions become.
[0156] Here, human emotions are based on various balances, such as posture and blood sugar levels. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. Similarly, in robots, cars, and motorcycles, emotions can be created based on various balances, such as posture and battery level. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. The emotion map can be generated based, for example, on Dr. Mitsuyoshi's emotion map (Research on a system for analyzing brain physiological signals of speech emotion recognition and emotion, Tokushima University, doctoral dissertation: https: / / ci.nii.ac.jp / naid / 500000375379). The left half of the emotion map contains emotions belonging to a region called "response," where sensation is dominant. The right half of the emotion map contains emotions belonging to a region called "situation," where situational awareness is dominant.
[0157] The emotion map defines two emotions that promote learning. One is the emotion around the middle of the negative "repentance" and "reflection" on the situation side. In other words, it is when the robot experiences negative emotions such as "I never want to feel this way again" or "I don't want to be scolded again." The other is the emotion around the positive "desire" on the reaction side. In other words, it is when the robot has positive feelings such as "I want more" or "I want to know more."
[0158] The emotion identification model 59 inputs user input into a pre-trained neural network, obtains emotion values representing each emotion shown in the emotion map 400, and determines the user's emotion. This neural network is pre-trained based on multiple training data sets, which are combinations of user input and emotion values representing each emotion shown in the emotion map 400. Furthermore, this neural network is trained so that emotions located close together have similar values, as shown in the emotion map 900 in Figure 10. Figure 10 shows an example where multiple emotions such as "reassured," "calm," and "confident" have similar emotion values.
[0159] In the above embodiment, an example was given in which a specific process is performed by a single computer 22. However, the technology of this disclosure is not limited thereto, and a distributed processing method for the specific process may be used, which includes computer 22 and multiple other computers.
[0160] In the above embodiment, an example was given in which the specific processing program 56 is stored in the storage 32, but the technology of this disclosure is not limited thereto. For example, the specific processing program 56 may be stored in a portable, computer-readable, non-temporary storage medium such as a USB (Universal Serial Bus) memory. The specific processing program 56 stored in the non-temporary storage medium is installed in the computer 22 of the data processing device 12. The processor 28 executes specific processing according to the specific processing program 56.
[0161] Alternatively, the specific processing program 56 may be stored in a storage device such as a server connected to the data processing device 12 via the network 54, and the specific processing program 56 may be downloaded and installed on the computer 22 in response to a request from the data processing device 12.
[0162] Furthermore, it is not necessary to store the entirety of the specific processing program 56 in a storage device such as a server connected to the data processing device 12 via the network 54, or to store the entirety of the specific processing program 56 in the storage 32; it is acceptable to store only a portion of the specific processing program 56.
[0163] The following types of processors can be used as hardware resources to perform specific processing. Examples of processors include a CPU, a general-purpose processor that functions as a hardware resource to perform specific processing by executing software, i.e., a program. Other examples of processors include dedicated electrical circuits, such as FPGAs (Field-Programmable Gate Arrays), PLDs (Programmable Logic Devices), or ASICs (Application Specific Integrated Circuits), which have circuit configurations specifically designed to perform specific processing. All of these processors have built-in or connected memory, and all of them perform specific processing by using memory.
[0164] The hardware resource that performs a specific process may consist of one of these various processors, or it may consist of a combination of two or more processors of the same or different types (for example, a combination of multiple FPGAs, or a combination of a CPU and an FPGA). Alternatively, the hardware resource that performs a specific process may consist of a single processor.
[0165] Examples of configurations using a single processor include, firstly, a configuration in which one or more CPUs and software are combined to form a single processor, and this processor functions as a hardware resource that performs a specific process. Secondly, there is a configuration using a processor that realizes the functions of the entire system, including multiple hardware resources that perform a specific process, on a single IC chip, as exemplified by SoCs (System-on-a-chip). In this way, a specific process is realized using one or more of the above types of processors as hardware resources.
[0166] Furthermore, the hardware structure of these various processors can more specifically utilize electrical circuits that combine circuit elements such as semiconductor devices. Also, the specific processing described above is merely an example. Therefore, it goes without saying that unnecessary steps can be deleted, new steps added, or the processing order rearranged, as long as it does not deviate from the main purpose.
[0167] Furthermore, although the above-described examples were divided into four embodiments, some or all of these embodiments may be combined. Also, the smart device 14, smart glasses 214, headset terminal 314, and robot 414 are just examples, and they may be combined, or other devices may be used. Also, although the above-described examples were divided into two embodiments, Embodiment 1 and Embodiment 2, these may be combined.
[0168] The descriptions and illustrations presented above are detailed explanations of the technical aspects of this disclosure and are merely examples of the technical aspects. For example, the above descriptions of the structure, function, operation, and effect are examples of the structure, function, operation, and effect of the technical aspects of this disclosure. Therefore, it goes without saying that you may delete unnecessary parts, add new elements, or replace elements in the descriptions and illustrations presented above, as long as you do not deviate from the essence of the technical aspects of this disclosure. Furthermore, in order to avoid confusion and facilitate understanding of the technical aspects of this disclosure, explanations of common technical knowledge and other things that do not require special explanation to enable the implementation of the technical aspects of this disclosure have been omitted from the descriptions and illustrations presented above.
[0169] All documents, patent applications, and technical standards described herein are incorporated by reference to the same extent as if each individual document, patent application, and technical standard were specifically and individually noted to be incorporated by reference.
[0170] (Note 1) A data collection unit that collects data, An analysis unit analyzes the data collected by the aforementioned collection unit, The system includes a defense unit that takes defensive measures based on the analysis results obtained by the aforementioned analysis unit. A system characterized by the following features. (Note 2) The aforementioned analysis unit is Perform a detailed analysis of the detected malware. The system described in Appendix 1, characterized by the features described herein. (Note 3) The aforementioned analysis unit is Analyze malware code to reveal its structure and operating mechanisms. The system described in Appendix 1, characterized by the features described herein. (Note 4) The aforementioned protective section is Leveraging AI's learning capabilities to evolve the system. The system described in Appendix 1, characterized by the features described herein. (Note 5) The aforementioned protective section is Learn new malware patterns to improve detection accuracy in the future. The system described in Appendix 1, characterized by the features described herein. (Note 6) The aforementioned collection unit is Collect data to identify abnormal patterns and behaviors. The system described in Appendix 1, characterized by the features described herein. (Note 7) The aforementioned collection unit is We estimate the user's emotions and adjust the timing of data collection based on those estimated emotions. The system described in Appendix 1, characterized by the features described herein. (Note 8) The aforementioned collection unit is Analyze past cyberattack history and select the optimal data collection method. The system described in Appendix 1, characterized by the features described herein. (Note 9) The aforementioned collection unit is When collecting data, filtering is performed based on specific network segments or devices. The system described in Appendix 1, characterized by the features described herein. (Note 10) The aforementioned collection unit is It estimates the user's emotions and prioritizes the data to collect based on those estimated emotions. The system described in Appendix 1, characterized by the features described herein. (Note 11) The aforementioned collection unit is When collecting data, prioritize the collection of highly relevant data, taking geographical location information into consideration. The system described in Appendix 1, characterized by the features described herein. (Note 12) The aforementioned collection unit is During data collection, social media activity is analyzed and relevant data is gathered. The system described in Appendix 1, characterized by the features described herein. (Note 13) The aforementioned analysis unit is It estimates the user's emotions and adjusts the way the analysis is presented based on the estimated user emotions. The system described in Appendix 1, characterized by the features described herein. (Note 14) The aforementioned analysis unit is During analysis, adjust the level of detail based on the importance of the data. The system described in Appendix 1, characterized by the features described herein. (Note 15) The aforementioned analysis unit is During analysis, different analytical algorithms are applied depending on the data category. The system described in Appendix 1, characterized by the features described herein. (Note 16) The aforementioned analysis unit is It estimates the user's emotions and adjusts the length of the analysis based on the estimated user emotions. The system described in Appendix 1, characterized by the features described herein. (Note 17) The aforementioned analysis unit is During analysis, prioritize the analysis based on when the data was collected. The system described in Appendix 1, characterized by the features described herein. (Note 18) The aforementioned analysis unit is During analysis, adjust the order of analysis based on the relevance of the data. The system described in Appendix 1, characterized by the features described herein. (Note 19) The aforementioned protective section is It estimates the user's emotions and adjusts how defensive measures are implemented based on those estimated emotions. The system described in Appendix 1, characterized by the features described herein. (Note 20) The aforementioned protective section is When implementing defensive measures, the optimal defensive method is selected by analyzing past defensive history. The system described in Appendix 1, characterized by the features described herein. (Note 21) The aforementioned protective section is When implementing defensive measures, customize the defensive measures based on specific network segments or devices. The system described in Appendix 1, characterized by the features described herein. (Note 22) The aforementioned protective section is It estimates the user's emotions and determines the priority of defensive measures based on the estimated user emotions. The system described in Appendix 1, characterized by the features described herein. (Note 23) The aforementioned protective section is When implementing defensive measures, the optimal defensive method is selected considering geographical location information. The system described in Appendix 1, characterized by the features described herein. (Note 24) The aforementioned protective section is When implementing defensive measures, we analyze social media activity and propose defensive strategies. The system described in Appendix 1, characterized by the features described herein. [Explanation of Symbols]
[0171] 10, 210, 310, 410 Data Processing Systems 12 Data Processing Devices 14 Smart Devices 214 Smart Glasses 314 Headset-type terminal 414 Robots
Claims
1. A data collection unit that collects data, An analysis unit analyzes the data collected by the aforementioned collection unit, The system includes a defense unit that takes defensive measures based on the analysis results obtained by the aforementioned analysis unit. A system characterized by the following features.
2. The aforementioned analysis unit is Perform a detailed analysis of the detected malware. The system according to feature 1.
3. The aforementioned analysis unit is Analyze malware code to reveal its structure and operating mechanisms. The system according to feature 1.
4. The aforementioned protective section is Leveraging AI's learning capabilities to evolve the system. The system according to feature 1.
5. The aforementioned protective section is Learn new malware patterns to improve detection accuracy in the future. The system according to feature 1.
6. The aforementioned collection unit is Collect data to identify abnormal patterns and behaviors. The system according to feature 1.
7. The aforementioned collection unit is We estimate the user's emotions and adjust the timing of data collection based on those estimated emotions. The system according to feature 1.
8. The aforementioned collection unit is Analyze past cyberattack history and select the optimal data collection method. The system according to feature 1.