Information display device, information display method, and program

The information presentation device accurately extracts and presents security entities from cybersecurity documents using a large-scale language model, addressing the limitations of existing methods by improving entity identification and presentation.

JP2026136566APending Publication Date: 2026-08-26NEC CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2025022135
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-02-14
Publication Date
2026-08-26

AI Technical Summary

Technical Problem

Existing methods, such as those described in Patent Document 1, struggle to accurately extract security-related entities from cybersecurity documents, necessitating large amounts of training data for machine learning or natural language processing.

Method used

An information presentation device that includes an acquisition unit, extraction unit, search unit, generation unit, and output unit, utilizing a large-scale language model (LLM) to identify and present security entities by generating prompts and extracting relevant information from cybersecurity documents.

Benefits of technology

Enables accurate identification and presentation of security entities within cybersecurity documents, preventing misidentification of entities and enhancing the understanding of cyberattack details.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026136566000001_ABST
    Figure 2026136566000001_ABST
Patent Text Reader

Abstract

To provide an information presentation device that can accurately present entities contained in cybersecurity documents. [Solution] The information presentation device comprises: an acquisition unit that acquires document data related to cybersecurity; an extraction unit that extracts candidate entities related to cybersecurity from the acquired document data; a search unit that searches for related information linked to the extracted candidates; a generation unit that generates instructions to identify security entities contained in the document data using the document data and the related information extracted for each candidate; and an output unit that outputs attack information including entities output from a model in response to the instructions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an information presentation device, an information presentation method, and a program.

Background Art

[0002] With the increasing importance of cybersecurity (also referred to as security), it is required to quickly detect the occurrence of security-related attacks and take appropriate countermeasures. For example, a security report (also referred to as a document) includes security-related entities such as the name of the victim, the name of the attacker, the name of the campaign, the exploited vulnerability, the targeted software, the attack tool, and the attack method. If security-related entities can be extracted from such a report, it becomes possible to analyze the attack and formulate countermeasures.

[0003] Patent Document 1 discloses a search device that searches for a document in which information related to an attack is described using the behavior of an attacker. The search device of Patent Document 1 extracts natural language from a document in which information related to an attack is described. When the similarity between a phrase included in the extracted natural language and a natural language representing the behavior of an attacker is greater than or equal to a predetermined threshold value, the search device of Patent Document 1 generates a label indicating that the document includes the behavior of the attacker to be assigned to the document. The search device of Patent Document 1 uses, as training data, a document to which a label indicating that it includes the behavior of an attacker is assigned, and learns a model that outputs the degree of relevance of the document to the behavior of the attacker. The search device of Patent Document 1 uses the learned model to output the degree of relevance of the search target document to the behavior of the attacker, and searches for a document including the behavior of the attacker from the search target document for the behavior of the attacker specified as a search query.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

[0005] The method described in Patent Document 1 uses a model to search for documents containing information about attacker behavior from a target document. However, the method described in Patent Document 1 was unable to extract security-related entities from the retrieved documents. For example, security-related entities can be extracted from documents using machine learning or natural language processing techniques. However, when using machine learning or natural language processing techniques, it was necessary to prepare a large amount of training data in order to accurately extract entities from documents.

[0006] The purpose of this disclosure is to provide information presentation devices, information presentation methods, and programs that can accurately present entities contained in cybersecurity documents. [Means for solving the problem]

[0007] An information presentation device in one aspect of this disclosure includes: an acquisition unit that acquires document data relating to cybersecurity; an extraction unit that extracts candidate entities relating to cybersecurity from the acquired document data; a search unit that searches for related information associated with the extracted candidates; a generation unit that generates instructions to identify security entities contained in the document data using the document data and the related information extracted for each candidate; and an output unit that outputs attack information including entities output from a model in response to the instructions.

[0008] In one aspect of the information presentation method of this disclosure, a computer acquires document data relating to cybersecurity, extracts candidate entities relating to cybersecurity from the acquired document data, searches for related information associated with the extracted candidates, generates instructions to identify security entities from among the candidates using the document data and the related information extracted for each candidate, and outputs attack information including entities output from a model in accordance with the instructions.

[0009] A program in one aspect of this disclosure causes a computer to perform the following processes: acquiring document data relating to cybersecurity; extracting candidate entities relating to cybersecurity from the acquired document data; searching for related information associated with the extracted candidates; generating instructions for identifying security entities from among the candidates using the document data and the related information extracted for each candidate; and outputting attack information including entities output from a model in accordance with the instructions. [Effects of the Invention]

[0010] This disclosure makes it possible to provide information presentation devices, information presentation methods, and programs that can accurately present entities contained in cybersecurity documents. [Brief explanation of the drawing]

[0011] [Figure 1] This block diagram shows an example of a configuration related to an information presentation device in this disclosure. [Figure 2] This block diagram shows an example of the configuration of an information presentation device in this disclosure. [Figure 3] This is a conceptual diagram illustrating an example of a security attack report obtained by the information presentation device described in this disclosure. [Figure 4] This table shows an example of the knowledge that the information presentation device in this disclosure retrieves. [Figure 5]It is a conceptual diagram showing an example of a prompt generated by an information presentation device in the present disclosure. [Figure 6] It is a conceptual diagram showing an example of a prompt generated by an information presentation device in the present disclosure. [Figure 7] It is a conceptual diagram showing an example of the display of an entity output from an information presentation device in the present disclosure. [Figure 8] It is a flowchart showing an example of the operation of an information presentation device in the present disclosure. [Figure 9] It is a flowchart showing an example of a specific process by an information presentation device in the present disclosure. [Figure 10] It is a conceptual diagram showing an example of a report on a security attack acquired by an information presentation device in the present disclosure. [Figure 11] It is a table showing an example of knowledge searched by an information presentation device in the present disclosure. [Figure 12] It is a conceptual diagram showing an example of a prompt generated by an information presentation device in the present disclosure. [Figure 13] It is a conceptual diagram showing an example of a prompt generated by an information presentation device in the present disclosure. [Figure 14] It is a conceptual diagram showing an example of the display of an entity output from an information presentation device in the present disclosure. [Figure 15] It is a block diagram showing an example of the configuration of an information presentation device in the present disclosure. [Figure 16] It is a conceptual diagram showing an example of a report on a security attack acquired by an information presentation device in the present disclosure. [Figure 17] It is a table showing an example of knowledge searched by an information presentation device in the present disclosure. [Figure 18] It is a conceptual diagram showing an example of a knowledge graph referred to by an information presentation device in the present disclosure. [Figure 19] It is a conceptual diagram showing an example of related information searched by an information presentation device in the present disclosure. [Figure 20] It is a conceptual diagram showing an example of a prompt generated by an information presentation device in the present disclosure. [Figure 21] It is a conceptual diagram showing an example of a prompt generated by the information presentation device in the present disclosure. [Figure 22] It is a conceptual diagram showing a display example of an entity output from the information presentation device in the present disclosure. [Figure 23] It is a flowchart showing an example of the operation of the information presentation device in the present disclosure. [Figure 24] It is a flowchart showing an example of a specific process by the information presentation device in the present disclosure. [Figure 25] It is a block diagram showing an example of the configuration of the information presentation device in the present disclosure. [Figure 26] It is a flowchart showing an example of the operation of the information presentation device in the present disclosure. [Figure 27] It is a block diagram showing an example of a hardware configuration for executing the process in the present disclosure.

Embodiments for Carrying Out the Invention

[0012] Hereinafter, embodiments for carrying out the present disclosure will be described with reference to the drawings. In the present disclosure, the drawings used in the description of each embodiment are associated with one or more embodiments. Also, the elements included in each drawing may apply to one or more embodiments. The embodiments described below have technically preferable limitations for carrying out the present disclosure, but do not limit the scope of the disclosure below. In all the drawings used in the following description of the embodiments, the same reference numerals are given to the same parts unless otherwise specified. In the following embodiments, repeated descriptions of the same configurations and operations may be omitted. The directions of the arrows in the drawings indicate an example of the flow of signals, data, etc., and do not limit the flow of signals, data, etc.

[0013] (First Embodiment) First, the information presentation device according to the first embodiment will be described with reference to the drawings. The information presentation device of this embodiment acquires reports (also called documents) related to cybersecurity (also called security) attacks. The information presentation device of this embodiment extracts security-related entities from the acquired reports. Security-related entities refer to elements related to cyberattacks. For example, a report (document) on a security attack includes security-related entities such as the victim's name, the attacker's name, the campaign name, the vulnerabilities used, the targeted software, the attack tools, and the attack methods. Security-related entities are used for detailed analysis of cyberattacks and the planning of countermeasures.

[0014] (composition) Figure 1 is a block diagram showing an example of the configuration related to the information presentation device in this disclosure. The information presentation device 10 is connected to the terminal device 180 and the LLM system 150 via a network 140 such as the Internet or an intranet. The information presentation device 10 is also connected to external information sources such as websites via the network 140.

[0015] Terminal device 180 is an information processing device (computer) used by users performing cybersecurity tasks. Terminal device 180 provides an interface for performing security tasks. Application software for executing security tasks is installed on terminal device 180. Terminal device 180 executes tasks set by the user. For example, terminal device 180 may be implemented in the cloud or on a server. The functionality of the application software for executing security tasks may be built on a server or cloud accessible from terminal device 180. Terminal device 180 may be implemented by a general-purpose computer. Alternatively, terminal device 180 may be implemented by a dedicated computer for executing security tasks.

[0016] Terminal device 180 obtains attack information (attack data) from information display device 10, which includes security entities extracted from a report on a security attack. Terminal device 180 displays the entities included in the obtained attack information (attack data) on its screen.

[0017] The LLM system 150 is a system that performs processing using a large-scale language model (not shown). The large-scale language model (also called a model) is a deep learning model trained on a large-scale language dataset. The LLM system 150 uses the large-scale language model to output text information corresponding to the content of text information composed of natural language. The LLM system 150 may also be a model capable of inputting and outputting images and audio. For example, the LLM system 150 is a system that can be used via an API (Application Programming Interface). The LLM system 150 may also be configured to use a dedicated model built to perform security-related processing. As long as it can be accessed from the information presentation device 10, there are no limitations on the type of large-scale language model used by the LLM system 150 or the location where the LLM system 150 is deployed.

[0018] [Information presentation device] Next, an example of the configuration of the information presentation device 10 will be described with reference to the drawings. Figure 2 is a block diagram showing an example of the configuration of the information presentation device in this disclosure. The information presentation device 10 includes an acquisition unit 11, an extraction unit 12, a storage unit 13, a search unit 14, an instruction unit 15, a specification unit 16, and an output unit 17. The instruction unit 15 is connected to the LLM system 150.

[0019] The acquisition unit 11 acquires reports (also called document data) related to security attacks from external websites and other sources. For example, reports are security-related documents such as security news, threat reports, and damage reports. Reports include security entities. Reports are not limited to news, threat reports, and damage reports, as long as they contain information about security attacks.

[0020] Figure 3 is a conceptual diagram showing an example of a security attack report acquired by the information presentation device in this disclosure. Report R1-1 includes security-related information such as, "Phishing attacks impersonating Company A are becoming more frequent, resulting in a loss of 10 billion yen at Company N..."

[0021] The extraction unit 12 extracts candidate security entities from the acquired report. For example, the entities to be extracted may relate to attackers, attacks, vulnerabilities, victims, and targets. For example, entities related to attackers include the names of attackers and campaigns. For example, entities related to attacks include attack methods and malware names. For example, entities related to vulnerabilities include the names of vulnerabilities. For example, entities related to victims include the names of victims, the amount of damage, and the details of the damage. For example, entities related to targets include the names of the software that was attacked. Security entities are not limited to the examples given here.

[0022] For example, the extraction unit 12 extracts keywords that match keywords or regular expressions included in a pre-prepared dictionary as entity candidates. For example, the extraction unit 12 is configured to extract entity candidates using NER (Named Entity Recognition) with a trained model. For example, the extraction unit 12 is configured to extract nouns as entity candidates by morphological analysis. For example, the extraction unit 12 may be configured to extract entity candidates using an LLM system 150 that includes a large-scale language model.

[0023] In the example in Figure 3, the report R1-1 extracts the following candidate entities: "Company A," "Phishing Attack," "Company N," and "10 Billion Yen." "Phishing Attack" corresponds to the name of the attack method. "Company N" corresponds to the name of the victim. "10 Billion Yen" corresponds to the amount of damage. The candidate entities "Phishing Attack," "Company N," and "10 Billion Yen" are all entities related to security. On the other hand, "Company A" is the name of a company that was misused as the name of the attacker, and is not an entity that can be extracted from report R1-1.

[0024] The memory unit 13 stores knowledge associated with security-related subjects. Security-related subjects include victim names, damage details, damage amounts, attacker names, attack method names, attack tools, attack techniques, malware, campaign names, exploited vulnerabilities, and targeted software. These subjects correspond to entities. Knowledge associated with security-related subjects is pre-stored in the memory unit 13. When searching for knowledge published over the network, the memory unit 13 may be omitted.

[0025] Figure 4 is a table showing an example of the knowledge retrieved by the information presentation device in this disclosure. Knowledge table N1-1 contains related information for each entity. Related information includes a description (knowledge) of the entity. For example, for "Company A," the knowledge associated is "Company A is a company headquartered in City A and is the largest provider of internet services and e-commerce." For example, for "Company N," the knowledge associated is "Company N is a company that develops, manufactures, sells, and maintains computer-related products and services in Country N." For example, for "Phishing Attack," the knowledge associated is "Phishing is an attack method that steals information from victims by impersonating a trusted organization. A typical method is sending emails containing malicious files or links."

[0026] The search unit 14 uses the entity candidates extracted by the extraction unit 12 as keys to search the storage unit 13 for knowledge (related information) corresponding to the value associated with those entity candidates. The search unit 14 may be configured to search for related information associated with the entity candidates extracted by the extraction unit 12 via a network. For example, the search unit 14 may be configured to extract publicly available knowledge using a search engine available via the network.

[0027] The instruction unit 15 retrieves the body (document data) of the acquired report. The instruction unit 15 also retrieves related information associated with the entity candidates extracted from the report. Using the related information associated with the entity candidates extracted from the report and the body of the report, the instruction unit 15 generates a prompt (also called an instruction) for identifying security-related entities. The functional configuration of the instruction unit 15 that generates the prompt (instruction) is also called the generation unit. The instruction unit 15 inputs the generated prompt to the LLM system 150. In this embodiment, the instruction unit 15 generates a first prompt and a second prompt. The instruction unit 15 may treat the report title, appendix, or summary as document data instead of the acquired report body. Alternatively, the instruction unit 15 may treat at least one combination of the report body, title, appendix, and summary as document data.

[0028] The instruction unit 15 generates a first prompt for inputting the knowledge associated with the entity candidate into the LLM system 150. The first prompt includes the knowledge for each entity candidate. The instruction unit 15 generates the first prompt using a pre-configured template. The template for generating the first prompt includes an instruction statement that instructs setting the knowledge associated with the entity candidate as a prerequisite. The instruction unit 15 inputs the generated first prompt into the LLM system 150.

[0029] The instruction unit 15 acquires text information output from the LLM system 150 in response to the input of the first prompt. The text information output from the LLM system 150 in response to the input of the first prompt corresponds to the answer to the first prompt. The answer to the first prompt becomes a trigger for the information presentation device 10 to input the second prompt to the LLM system 150.

[0030] Figure 5 is a conceptual diagram showing an example of a prompt generated by the information presentation device in this disclosure. Figure 5 shows an example of the first prompt P1-11 generated by the information presentation device 10. The first prompt P1-11 includes an instruction and knowledge for each candidate entity. The instruction includes the text information, "Please understand the following description." The knowledge for each candidate entity includes the description exemplified in the knowledge table N1-1 in Figure 4. Figure 5 also shows the response A1-11 output from the LLM system 150 in response to the input of the first prompt P1-11. Response A1-11 includes the text information, "I understand," indicating that the content of the first prompt P1-11 has been set as a prerequisite in the LLM system 150.

[0031] Furthermore, the instruction unit 15 generates a second prompt instructing the LLM system 150 to extract entities from the body of the report. The second prompt includes instructions to extract entities from the body of the report. The second prompt may also include instructions to extract entities from the report title, appendices, or summary instead of the body of the report. Alternatively, the second prompt may include instructions to extract entities from at least one combination of the body of the report, title, appendices, and summary. The instruction unit 15 generates the second prompt using a pre-configured template. The instruction unit 15 inputs the generated second prompt to the LLM system 150. The instruction unit 15 may be configured to generate a prompt in which the content of the first and second prompts are unified. In that case, the prompt includes instructions to set knowledge for each candidate entity as a prerequisite and instructions to extract entities from the body of the report.

[0032] For example, the instruction unit 15 is configured to generate prompts that include instructions for extracting multiple entity types at once. For example, the instruction unit 15 is configured to generate prompts that include instructions for extracting an entity for each entity type. For example, the instruction unit 15 may be configured to input a prompt to the LLM system 150 that includes instructions for extracting "attacker name" for the same report, and then input a prompt to the LLM system 150 that includes instructions for extracting "victim name". In other words, the instruction unit 15 may be configured to input prompts to the LLM system 150 that include instructions for sequentially extracting related information for multiple entities for the same report. Also, in the first prompt, if there is multiple pieces of related information associated with an entity candidate, multiple pieces of related information may be input to the LLM system 150 in a single prompt, or multiple pieces of related information may be input to the LLM system 150 sequentially.

[0033] The instruction unit 15 acquires text information output from the LLM system 150 in response to the input of the second prompt. The text information output from the LLM system 150 in response to the input of the second prompt corresponds to the answer to the second prompt. The text information includes entities extracted from the report.

[0034] Figure 6 is a conceptual diagram showing an example of a prompt generated by the information presentation device in this disclosure. Figure 6 shows an example of the second prompt P1-12 generated by the information presentation device 10. The second prompt P1-12 includes an instruction and the body of report R1-1. The instruction includes the text information, "Please extract the victim's name, the amount of damage, and the attack method from the following report." The report body includes the body of report R1-1 exemplified in Figure 3. Figure 6 also shows the response A1-12 output from the LLM system 150 in response to the input of the second prompt P1-12. Response A1-12 includes the text information, "The victim's name is Company N, the amount of damage is 10 billion yen, and the attack method is a phishing attack." Response A1-12 includes entities extracted based on the relevant information entered by the first prompt P1-11.

[0035] In the above description, the instruction unit 15 inputs information to the LLM system 150 using the first prompt and the second prompt to obtain entities included in the report body, but is not limited to this. For example, instead of the first prompt in the above description, the instruction unit 15 may input information to the LLM system 150 using RAG (Retrieval-Augmented Generation) or fine tuning. For example, the instruction unit 15 may generate a single prompt that includes both the information included in the first prompt and the information included in the second prompt. In that case, the instruction unit 15 inputs the single prompt to the LLM system 150 to obtain text information about entities output from the LLM system 150.

[0036] The identification unit 16 obtains text information containing entities extracted from the report. The identification unit 16 identifies the entities contained in the text information. The text information containing entities extracted from the report may be configured to be output to the output unit 17. In that case, the identification unit 16 may be omitted.

[0037] The output unit 17 is connected to a terminal device 180 used by the user. The output unit 17 acquires identified entities. The output unit 17 outputs attack information (attack data) including the acquired entities to the terminal device 180. The entities included in the attack information output to the terminal device 180 are displayed on the screen of the terminal device 180. The output unit 17 may also be configured to save the attack information containing the entities to a database (not shown).

[0038] Figure 7 is a conceptual diagram showing an example of the display of entities output from the information display device in this disclosure. The screen of terminal device 180 displays text information representing the body of the report, which reads, "Phishing attacks impersonating Company A are becoming more active, and Company N has suffered losses of 10 billion yen..." The screen of terminal device 180 also displays an entity extracted from the report: "Victim name: Company N, Amount of loss: 10 billion yen, Attack method: Phishing attack." In general entity extraction, Company A was sometimes mistakenly identified as the victim name. According to this embodiment, by using the related information (meaning) of the entity candidates extracted from the report, it is possible to prevent Company A from being mistakenly identified as the victim name. Therefore, according to this embodiment, the entities included in the report are accurately identified. Users can accurately understand the entities included in the report by viewing the information displayed on the screen of terminal device 180.

[0039] (operation) Next, an example of the operation of the information presentation device in this disclosure will be described with reference to the drawings. Figure 8 is a flowchart of an example of the operation of the information presentation device in this disclosure. In the explanation of the process according to the flowchart in Figure 8, the components of the information presentation device 10 will be considered the operating entities. The operating entities of the process according to the flowchart in Figure 8 may also be the information presentation device 10. For example, the process according to the flowchart in Figure 8 is realized by a processor executing a program stored in the memory installed in a computer (not shown) on which the information presentation device 10 is implemented.

[0040] In Figure 8, first, the acquisition unit 11 acquires a security-related report (step S11).

[0041] Next, the extraction unit 12 extracts candidate entities from the acquired report (step S12).

[0042] Next, the search unit 14 searches for related information associated with the extracted entity candidates (step S13). For example, the search unit 14 is configured to search for related information from a dedicated database built to extract entities. For example, the search unit 14 may be configured to search for related information via the internet.

[0043] Next, the instruction unit 15 executes a specific process (step S14). Details of the specific process in step S14 will be described later.

[0044] Next, the output unit 17 outputs attack information including the identified entity (step S15). The attack information output from the information display device 10 is displayed on the screen of the terminal device 180 used by the user.

[0045] [Specific processing] Next, an example of the identification process by the information presentation device in this disclosure (step S14 in Figure 8) will be described with reference to the drawings. Figure 9 is a flowchart of an example of the identification process by the information presentation device in this disclosure. In the explanation of the process according to the flowchart in Figure 9, the components of the information presentation device 10 (indicator unit 15) will be considered the main operating entity. The main operating entity of the process according to the flowchart in Figure 9 may also be the information presentation device 10.

[0046] In Figure 9, first, the instruction unit 15 generates a first prompt for inputting knowledge into the LLM system 150 (step S141).

[0047] Next, the instruction unit 15 inputs the generated first prompt to the LLM system 150 (step S142). The instruction unit 15 then retrieves the text information output from the LLM system 150 in response to the input of the first prompt.

[0048] Next, the instruction unit 15 generates a second prompt instructing the LLM system to identify the entity (step S143).

[0049] Next, the instruction unit 15 inputs the generated second prompt to the LLM system 150 (step S144).

[0050] Next, the instruction unit 15 acquires the entities output from the LLM system 150 (step S145). Following step S145, the process proceeds to step S15 in the flowchart of Figure 8.

[0051] (modified version) Next, modifications of this embodiment will be described with reference to the drawings. The following modifications are examples of processing by the information display device of this embodiment and do not limit the processing by the information display device of this embodiment.

[0052] Figures 10-14 are conceptual diagrams relating to this modified example. This modified example is an example with different reports and entities.

[0053] Figure 10 is a conceptual diagram showing an example of a security attack report acquired by the information presentation device in this disclosure. Report R1-2 contains security-related content such as, "A large-scale cyberattack by malware M occurred, resulting in the leakage of personal information of 1 million people at company N..." From report R1-2, the entity candidates "malware M" and "company N" are extracted.

[0054] Figure 11 is a table showing an example of the knowledge retrieved by the information presentation device in this disclosure. Knowledge table N1-2 stores names that represent candidate entities and descriptions (knowledge) related to those candidate entities. The names that represent candidate entities are associated with the knowledge related to those candidate entities. For example, for "Company N", the knowledge associated is "Company N is a company that develops, manufactures, sells, and maintains computer-related products and services in Country N." For example, for "Malware M", the knowledge associated is "Malware M is a type of banking Trojan horse. Malware M has the function of stealing online banking usernames and passwords from infected computers."

[0055] Figure 12 is a conceptual diagram showing an example of a prompt generated by the information presentation device in this disclosure. Figure 12 shows an example of a first prompt P1-21 generated by the information presentation device 10. The first prompt P1-21 includes an instruction and knowledge for each candidate entity. The instruction includes the text information, "Please understand the following description." The knowledge for each candidate entity includes the description exemplified in knowledge table N1-2 in Figure 11. Figure 12 also shows the response A1-21 output from the LLM system 150 in response to the input of the first prompt P1-21. Response A1-21 includes the text information, "I understand," indicating that the content of the first prompt P1-21 was input to the LLM system 150 as a prerequisite.

[0056] Figure 13 is a conceptual diagram showing an example of a prompt generated by the information presentation device in this disclosure. Figure 13 shows an example of a second prompt P1-22 generated by the information presentation device 10. The second prompt P1-22 includes an instruction and the body of a report. The instruction includes the text information, "Extract the attacker, malware name, and victim name from the following report." The body of the report includes the body of report R1-2 exemplified in Figure 10. Figure 13 also shows the response A1-22 output from the LLM system 150 in response to the input of the second prompt P1-22. Response A1-22 includes the text information, "Attacker not listed, malware name is malware M, victim name is N company." Response A1-22 includes entities extracted based on the knowledge entered by the first prompt P1-21.

[0057] Figure 14 is a conceptual diagram showing an example of the display of entities output from the information presentation device in this disclosure. The screen of terminal device 180 displays text information representing the body of the report, which reads, "A large-scale cyberattack by malware M occurred, resulting in the leakage of personal information of 1 million people at company N..." The screen of terminal device 180 also displays the entity extracted from the report, which reads, "Malware name: Malware M, Victim name: Company N." By viewing the information displayed on the screen of terminal device 180, users can accurately understand the entities included in the report.

[0058] As described above, the information presentation device of this embodiment comprises an acquisition unit, an extraction unit, a search unit, an identification unit, an instruction unit, and an output unit. The acquisition unit acquires cybersecurity reports (document data). The extraction unit extracts candidate cybersecurity entities from the acquired document data. The search unit searches for related information associated with the extracted candidates. The search unit searches for related information associated with the candidates by referring to a table in which related information is linked for each entity. The instruction unit (generation unit) uses the document data and the related information extracted for each candidate to generate instructions (prompts) requesting the identification of security entities contained in the document data. The instruction unit inputs the generated instructions into a model (large-scale language model). The identification unit identifies the entities output from the model according to the instructions. The output unit outputs attack information including the identified entities.

[0059] In this embodiment, entities included in document data are identified based on related information linked to candidate entities extracted from cybersecurity-related document data. Therefore, according to this embodiment, entities included in cybersecurity-related documents can be accurately presented.

[0060] In one embodiment of this system, the extraction unit extracts candidate entities related to attackers, attacks, vulnerabilities, victims, and targets from the document data. In this embodiment, entities included in the document data are identified based on related information associated with the candidate entities related to attackers, attacks, vulnerabilities, victims, and targets. According to this embodiment, entities related to attackers, attacks, vulnerabilities, victims, and targets can be accurately presented.

[0061] In one embodiment of this design, the generation unit generates instructions to extract entities for each entity type. According to this design, by extracting entities for each entity type, entities included in the document data can be identified more accurately.

[0062] In one embodiment of this system, the search unit searches for related information linked to candidates by referring to publicly available external data. According to this embodiment, it is possible to search for related information linked to candidate entities included in document data without having to prepare a table in advance that summarizes related information for each entity.

[0063] In one embodiment of this design, the output unit displays information about entities included in the attack information on the screen of the terminal device used by the user. According to this design, by viewing the information displayed on the terminal device screen, the entities included in the report can be accurately understood.

[0064] (Second Embodiment) Next, the information presentation device according to the second embodiment will be described with reference to the drawings. The information presentation device of this embodiment differs from the first embodiment in that, instead of describing entities, it uses information showing the relationships between entities (knowledge graph) as knowledge.

[0065] The information display device of this embodiment is connected to a terminal device and LLM system similar to those of the first embodiment via a network such as the Internet or an intranet. In this embodiment, details of the terminal device and LLM system are omitted from the description. Furthermore, in this embodiment, content that overlaps with the first embodiment will be described in a simplified manner.

[0066] (composition) Figure 15 is a block diagram showing an example of the configuration of an information presentation device in this disclosure. The information presentation device 20 comprises an acquisition unit 21, an extraction unit 22, a storage unit 23, a search unit 24, an instruction unit 25, a specification unit 26, and an output unit 27. The instruction unit 25 is connected to the LLM system 250.

[0067] The acquisition unit 21 has the same configuration as the acquisition unit 11 in the first embodiment. The acquisition unit 21 acquires reports on security attacks from external websites and the like. For example, the reports are security-related documents such as security news, threat reports, and damage reports. The reports are not limited to news, threat reports, and damage reports, as long as they include information about security attacks.

[0068] Figure 16 is a conceptual diagram showing an example of a security attack report acquired by the information presentation device in this disclosure. Report R2 includes security-related information such as, "Malware e has been discovered within Company X, and shipments of the company's products have been suspended. Attacker C has been increasingly active this month..."

[0069] The extraction unit 22 has the same configuration as the extraction unit 12 in the first embodiment. The extraction unit 22 extracts security-related entity candidates from the acquired report. In the example in Figure 16, the entity candidates "Company X", "Malware e", and "Attacker C" are extracted from report R2.

[0070] The memory unit 23 stores a knowledge graph containing knowledge associated with security-related targets. Security-related targets include entities such as victim names, damage details, damage amounts, attacker names, attack method names, attack tools, attack techniques, malware, campaign names, exploited vulnerabilities, and targeted software. The knowledge graph is pre-stored in the memory unit 23. When searching for a knowledge graph published over the network, the memory unit 23 may be omitted.

[0071] Figure 17 is a table showing an example of the knowledge retrieved by the information presentation device in this disclosure. Knowledge table N2 contains related information for each entity. The related information includes the name of the entity and the attribute names and values ​​associated with those entities. For example, for the entity "Attacker C", the attribute names "Attack Method Used", "Malware Used", and "Main Target" are associated. For example, the value "Malware e" is associated with "Malware Used" for "Attacker C". "Malware e" is also an entity. In this case, "Malware e" corresponds to a second entity related to the first entity "Attacker C".

[0072] Figure 18 is a conceptual diagram showing an example of a knowledge graph referenced by the information presentation device in this disclosure. Figure 18 shows the correlation of entities included in knowledge table N2 in Figure 17. For example, attacker C is associated with the values ​​attack method 1, attack method 2, malware e, and company X (healthcare industry). Malware e is also an entity. The entity malware e is associated with the values ​​"software g" and "CVE-YYYY-NNNN". Also, "attack method 2" is associated with the entity "attacker D". In this way, multiple entities are correlated with each other.

[0073] The search unit 24 uses the entity candidate extracted by the extraction unit 22 as a key to search the storage unit 23 for knowledge corresponding to the value associated with that entity candidate. In this embodiment, the search unit 24 refers to a knowledge graph, which is information showing the relationships between entities, as knowledge. The knowledge graph is stored in the storage unit 23 in advance. The search unit 24 extracts a second entity associated with the entity candidate from the knowledge graph as related information. If there is a third entity associated with the second entity extracted as related information, the search unit 24 may also extract the third entity as related information. In this way, the search unit 24 may be configured to extract related information in a chain reaction using the knowledge graph. The search unit 24 may be configured to search for information associated with the entity candidate extracted by the extraction unit 22 via a network. For example, the search unit 24 may be configured to refer to a publicly available knowledge graph using a search engine that can be used via a network.

[0074] Figure 19 is a conceptual diagram showing an example of related information retrieved by the information presentation device in this disclosure. Related information K includes attribute names and values ​​associated with the entity candidates extracted from report R2 in Figure 16. From report R2, the entity candidates "Attacker C," "Malware e," and "Company X" are extracted. Related information K is associated with each of the entity candidates "Attacker C," "Malware e," and "Company X."

[0075] The instruction unit 25 retrieves the body (document data) of the acquired report. The instruction unit 25 also retrieves related information associated with the entity candidates extracted from the report. Using the related information associated with the entity candidates extracted from the report and the body of the report, the instruction unit 25 generates prompts (also called instructions) for identifying security-related entities. The functional configuration of the instruction unit 25 that generates prompts (instructions) is also called the generation unit. The instruction unit 25 inputs the generated prompts to the LLM system 250. In this embodiment, the instruction unit 25 generates a first prompt and a second prompt. The instruction unit 25 may treat the report title, appendix, or summary as document data instead of the acquired report body. Alternatively, the instruction unit 25 may treat at least one combination of the report body, title, appendix, and summary as document data.

[0076] The instruction unit 25 generates a first prompt for inputting related information associated with the entity candidate into the LLM system 250. The first prompt includes related information for each entity candidate. The instruction unit 25 generates the first prompt using a pre-configured template. The template for generating the first prompt includes instruction statements that instruct the input of related information associated with the entity candidate as a prerequisite. The instruction unit 25 may document the related information using a pre-configured template and generate a first prompt containing the documented related information. The instruction unit 25 inputs the generated first prompt into the LLM system 250.

[0077] The instruction unit 25 acquires text information output from the LLM system 250 in response to the input of the first prompt. The text information output from the LLM system 250 in response to the input of the first prompt corresponds to the answer to the first prompt. The answer to the first prompt triggers the information presentation device 20 to input the second prompt to the LLM system 250.

[0078] Figure 20 is a conceptual diagram showing an example of a prompt generated by the information presentation device in this disclosure. Figure 20 shows an example of a first prompt P2-1 generated by the information presentation device 20. The first prompt P2-1 includes an instruction and relevant information for each candidate entity. The instruction includes the text information, "Please understand the following description." The relevant information for each candidate entity includes the relevant information K shown in Figure 19. Figure 20 also shows the response A2-1 output from the LLM system 250 in response to the input of the first prompt P2-1. Response A2-1 includes the text information, "I understand," indicating that the content of the first prompt P2-1 was input to the LLM system 250 as a prerequisite.

[0079] Furthermore, the instruction unit 25 generates a second prompt instructing the LLM system 250 to extract entities from the body of the report. The second prompt includes instructions to extract entities from the body of the report. The second prompt may also include instructions to extract entities from the report title, appendices, or summary instead of the body of the report. Alternatively, the second prompt may include instructions to extract entities from at least one combination of the body of the report, title, appendices, and summary. The instruction unit 25 generates the second prompt using a pre-configured template. The instruction unit 25 inputs the generated second prompt to the LLM system 250. The instruction unit 25 may be configured to generate a prompt in which the content of the first and second prompts are unified. In that case, the prompt includes instructions to input knowledge for each candidate entity as a prerequisite, and instructions to extract entities from the body of the report.

[0080] The instruction unit 25 acquires text information output from the LLM system 250 in response to the input of the second prompt. The text information output from the LLM system 250 in response to the input of the second prompt corresponds to the answer to the second prompt. The text information includes entities extracted from the report.

[0081] Figure 21 is a conceptual diagram showing an example of a prompt generated by the information presentation device in this disclosure. Figure 21 shows an example of a second prompt P2-2 generated by the information presentation device 20. The second prompt P2-2 includes an instruction and the body of a report. The instruction includes the text information, "Extract the attacker name, malware name, and victim name from the following report." The body of the report includes the body of report R2 exemplified in Figure 16. Figure 21 also shows the response A2-2 output from the LLM system 250 in response to the input of the second prompt P2-2. Response A2-2 includes the text information, "The attacker is attacker A, the malware name is malware e, and the victim name is Company X." Response A2-2 includes entities extracted based on the relevant information entered by the first prompt P2-1.

[0082] In the above description, the instruction unit 25 inputs information to the LLM system 250 using the first prompt and the second prompt to obtain entities included in the report body, but is not limited to this. For example, instead of the first prompt in the above description, the instruction unit 25 may input information to the LLM system 250 using RAG (Retrieval-Augmented Generation) or fine tuning. For example, the instruction unit 25 may generate a single prompt that includes both the information included in the first prompt and the information included in the second prompt. In that case, the instruction unit 25 inputs the single prompt to the LLM system 250 to obtain text information about entities output from the LLM system 250.

[0083] The identification unit 26 has the same configuration as the identification unit 16 of the first embodiment. The identification unit 26 acquires text information containing entities extracted from the report. The identification unit 26 identifies the entities contained in the text information. The text information containing entities extracted from the report may be configured to be output to the output unit 27. In that case, the identification unit 26 may be omitted.

[0084] The output unit 27 is connected to a terminal device 280 used by the user. The output unit 27 retrieves entities extracted from the body of the report. The output unit 27 outputs attack information (attack data) containing the retrieved entities to the terminal device 280. The entities included in the attack information output to the terminal device 280 are displayed on the screen of the terminal device 280. The output unit 27 may also be configured to save the attack information containing the entities to a database (not shown).

[0085] Figure 22 is a conceptual diagram showing an example of the display of entities output from the information display device in this disclosure. The screen of terminal device 280 displays text information representing the body of the report, which reads, "Malware e has been discovered within Company X, and shipments of the company's products have been suspended. Attacker C's activity has become more active since the beginning of this month..." The screen of terminal device 280 also displays entities extracted from the report, which are "Attacker name: Attacker C, Malware name: Malware e, Victim name: Company X". In general entity extraction, malware M was sometimes mistakenly identified as the attacker name. According to this embodiment, by using the related information (meaning) of the entity candidates extracted from the report, it is possible to prevent malware M from being mistakenly identified as the attacker name. Therefore, according to this embodiment, the entities included in the report are accurately identified. Users can accurately understand the entities included in the report by viewing the information displayed on the screen of terminal device 280.

[0086] (operation) Next, an example of the operation of the information presentation device in this disclosure will be described with reference to the drawings. Figure 23 is a flowchart of an example of the operation of the information presentation device in this disclosure. In the explanation of the process according to the flowchart in Figure 23, the components of the information presentation device 20 will be considered the operating entities. The operating entities of the process according to the flowchart in Figure 23 may also be the information presentation device 20. For example, the process according to the flowchart in Figure 23 is realized by a processor executing a program stored in the memory installed in a computer (not shown) on which the information presentation device 20 is implemented.

[0087] In Figure 23, first, the acquisition unit 21 acquires a security-related report (step S21).

[0088] Next, the extraction unit 22 extracts candidate entities from the acquired report (step S22).

[0089] Next, the search unit 24 searches for related information associated with the extracted entity candidates (step S23). For example, the search unit 24 may be configured to search for related information from a dedicated database built to extract entities. For example, the search unit 24 may be configured to search for related information via the internet.

[0090] Next, the instruction unit 25 executes a specific process (step S24). Details of the specific process in step S24 will be described later.

[0091] Next, the output unit 27 outputs attack information including the identified entity (step S25). The attack information output from the information display device 20 is displayed on the screen of the terminal device 280 used by the user.

[0092] [Specific processing] Next, an example of the identification process by the information presentation device in this disclosure (step S24 in Figure 23) will be described with reference to the drawings. Figure 24 is a flowchart of an example of the identification process by the information presentation device in this disclosure. In the explanation of the process according to the flowchart in Figure 24, the components of the information presentation device 20 (indicator unit 25) will be considered the main operating entity. The main operating entity of the process according to the flowchart in Figure 24 may also be the information presentation device 20.

[0093] In Figure 24, first, the instruction unit 25 generates a first prompt for inputting knowledge into the LLM system 250 (step S241).

[0094] Next, the instruction unit 25 inputs the generated first prompt to the LLM system 250 (step S242). The instruction unit 25 then retrieves the text information output from the LLM system 250 in response to the input of the first prompt.

[0095] Next, the instruction unit 25 generates a second prompt instructing the LLM system to identify the entity (step S243).

[0096] Next, the instruction unit 25 inputs the generated second prompt to the LLM system 250 (step S244).

[0097] Next, the instruction unit 25 acquires the entities output from the LLM system 250 (step S245). Following step S245, the process proceeds to step S25 in the flowchart of Figure 23.

[0098] As described above, the information presentation device of this embodiment comprises an acquisition unit, an extraction unit, a search unit, an identification unit, an instruction unit, and an output unit. The acquisition unit acquires cybersecurity reports (document data). The extraction unit extracts candidate cybersecurity entities from the acquired document data. The search unit searches for related information associated with the extracted candidates. The search unit searches for related information associated with the candidates by referring to a knowledge graph that shows the relationships between multiple entities. The instruction unit (generation unit) generates instructions for identifying security entities contained in the document data using the document data and the related information extracted from the knowledge graph. The instruction unit inputs the generated instructions into a model (large-scale language model). The identification unit identifies entities output from the model according to the instructions. The output unit outputs attack information including the identified entities.

[0099] In this embodiment, a knowledge graph showing the relationships between multiple entities is referenced to search for related information linked to the candidates. Therefore, according to this embodiment, entities included in document data can be accurately identified by referencing the knowledge graph.

[0100] In one embodiment of this system, the search unit refers to a knowledge graph to search for related information linked to entities included in the related information linked to the candidate. According to this embodiment, entities included in the document data can be identified more accurately by sequentially extracting entities included in the document data.

[0101] (Third embodiment) Next, the information presentation device in the third embodiment will be described with reference to the drawings. The information presentation device in this embodiment has a simplified configuration compared to the information presentation devices in the first and second embodiments. For example, the functions of the components of the information presentation device in this embodiment are realized by the functions of the components of the information presentation devices in the first and second embodiments.

[0102] (composition) Figure 25 is a block diagram showing an example of the configuration of an information presentation device in this disclosure. The information presentation device 30 comprises an acquisition unit 31, an extraction unit 32, a search unit 34, a generation unit 35, and an output unit 37.

[0103] The acquisition unit 31 acquires document data related to cybersecurity. The extraction unit 32 extracts candidate cybersecurity entities from the acquired document data. The search unit 34 searches for related information associated with the extracted candidates. The generation unit 35 uses the document data and the related information extracted for each candidate to generate instructions that request the identification of security entities contained in the document data. The output unit 37 outputs attack information including entities output from the model in accordance with the instructions.

[0104] (operation) Figure 26 is a flowchart illustrating an example of the operation of the information presentation device in this disclosure. In describing the process according to the flowchart in Figure 26, the components of the information presentation device 30 are considered the operating entities. The operating entities of the process according to the flowchart in Figure 26 may also be the information presentation device 30.

[0105] The acquisition unit 31 acquires document data related to cybersecurity (step S31).

[0106] The extraction unit 32 extracts candidate entities related to cybersecurity from the acquired document data (step S32).

[0107] The search unit 34 searches for related information associated with the extracted candidates (step S33).

[0108] The generation unit 35 uses the document data and the relevant information extracted for each candidate to generate instructions requesting the identification of security entities contained in the document data (step S34).

[0109] The output unit 37 outputs attack information, including entities output from the model, in accordance with the instructions (step S35).

[0110] In this embodiment, entities included in document data are identified based on related information linked to candidate entities extracted from cybersecurity-related document data. Therefore, according to this embodiment, entities included in cybersecurity-related documents can be accurately presented.

[0111] (Hardware) Next, the hardware configuration for performing the processing described in this disclosure will be described with reference to the drawings. Figure 27 is a block diagram showing an example of a hardware configuration for performing the processing described in this disclosure. Here, an information processing device 90 (computer) is shown as an example of a hardware configuration. The information processing device in Figure 27 is an example configuration for performing the processing described in this disclosure and does not limit the scope of this disclosure.

[0112] As shown in Figure 27, the information processing device 90 comprises a processor 91, memory 92, auxiliary storage device 93, input / output interface 95, and communication interface 96. In Figure 27, interface is abbreviated as I / F (Interface). The information processing device 90 may include at least one or more of the processor 91, memory 92, auxiliary storage device 93, input / output interface 95, and communication interface 96. The processor 91, memory 92, auxiliary storage device 93, input / output interface 95, and communication interface 96 are connected to each other via a bus 98 so that they can communicate data. In addition, the processor 91, memory 92, auxiliary storage device 93, and input / output interface 95 are connected to a network such as the Internet or an intranet via the communication interface 96.

[0113] The processor 91 loads a program (instruction) stored in an auxiliary storage device 93 or the like into memory 92. For example, the program is a software program for executing the processing described in this disclosure. The processor 91 executes the program loaded into memory 92. The processor 91 executes the processing described in this disclosure by executing the program. The processor 91 may be composed of a single piece of hardware or of multiple pieces of hardware.

[0114] Memory 92 is a storage device having an area where programs are deployed. The processor 91 deploys programs stored in auxiliary storage devices 93, etc., into memory 92. Memory 92 can be implemented using volatile memory such as DRAM (Dynamic Random Access Memory). Alternatively, non-volatile memory such as MRAM (Magnetoresistive Random Access Memory) may be used as memory 92. Memory 92 may be composed of a single piece of hardware or multiple pieces of hardware.

[0115] The auxiliary storage device 93 stores various data, such as programs. For example, the auxiliary storage device 93 can be implemented by a local disk such as a hard disk or flash memory. The auxiliary storage device 93 may be configured by a single piece of hardware or by multiple pieces of hardware. The auxiliary storage device 93 may also be configured as external hardware. It is also possible to configure the system to store various data in memory 92 and omit the auxiliary storage device 93.

[0116] The input / output interface 95 is an interface for connecting the information processing device 90 to peripheral devices based on standards and specifications. The communication interface 96 is an interface for connecting to external systems and devices via a network such as the Internet or an intranet, based on standards and specifications. The input / output interface 95 may be composed of a single piece of hardware or multiple pieces of hardware. The input / output interface 95 and the communication interface 96 may be common as interfaces for connecting to external devices.

[0117] The information processing device 90 may be connected to input devices such as a keyboard, mouse, or touch panel, as needed. These input devices are used to input information and settings. When a touch panel is used as an input device, the screen with touch panel functionality serves as the interface. The processor 91 and the input devices are connected via an input / output interface 95.

[0118] The information processing device 90 may be equipped with a display device for displaying information. If a display device is provided, the information processing device 90 is equipped with a display control device (not shown) for controlling the display of the display device. The information processing device 90 and the display device are connected via an input / output interface 95.

[0119] The information processing device 90 may be equipped with a drive device. The drive device mediates between the processor 91 and the recording medium (program recording medium) by reading data and programs stored on the recording medium and writing the processing results of the information processing device 90 to the recording medium. The information processing device 90 and the drive device are connected via an input / output interface 95.

[0120] The above is an example of a hardware configuration that enables the processing described in this disclosure. The hardware configuration in Figure 27 is an example of a hardware configuration for executing the processing described in this disclosure and does not limit the scope of this disclosure. A program that causes a computer to execute the processing described in this disclosure is also included in the scope of this disclosure.

[0121] A program recording medium that stores a program for performing the processing in this embodiment is also included in the scope of the present invention. For example, the program recording medium is a computer-readable, non-transient recording medium. The recording medium can be implemented as an optical recording medium such as a CD (Compact Disc) or DVD (Digital Versatile Disc). The recording medium may also be implemented as a semiconductor recording medium such as a USB (Universal Serial Bus) memory or an SD (Secure Digital) card. Furthermore, the recording medium may be implemented as a magnetic recording medium such as a flexible disk, or other recording media.

[0122] The components in this disclosure may be combined in any way. The components in this disclosure may be implemented by software. The components in this disclosure may be implemented by circuitry. The components in this disclosure may be implemented by cloud computing.

[0123] Although the present disclosure has been described above with reference to embodiments, the present disclosure is not limited to the embodiments described above. Various modifications to the structure and details of the present disclosure can be made as can be understood by those skilled in the art within the scope of the present disclosure. Furthermore, each embodiment can be combined with other embodiments as appropriate.

[0124] Some or all of the above embodiments may also be described as follows, but are not limited to the following. In the following appendices, the dependents of each category may also be dependent on other categories. The descriptions included in the following appendices are significant as grounds for amendment. (Note 1) An acquisition unit that acquires document data related to cybersecurity, An extraction unit that extracts candidate entities related to cybersecurity from the acquired document data, A search unit that searches for related information associated with the extracted candidates, A generation unit generates instructions to identify security entities contained in the document data, using the document data and related information extracted for each candidate. An information presentation device comprising: an output unit that outputs attack information including entities output from a model in response to the aforementioned instructions. (Note 2) The aforementioned search unit, An information presentation device as described in Appendix 1, which searches for the associated information associated with the candidate by referring to a table in which related information is linked for each entity. (Note 3) The generating unit is An information presentation device as described in Appendix 2, which generates instructions to extract entities for each entity type. (Note 4) The aforementioned search unit, Referencing a knowledge graph that shows the relationships between multiple entities, search for related information linked to the aforementioned candidate. The generating unit is An information presentation device according to Appendix 1, which generates instructions for identifying security entities contained in the document data using the document data and related information extracted from the knowledge graph. (Note 5) The aforementioned search unit, An information presentation device as described in Appendix 4, which refers to the knowledge graph and searches for related information associated with entities included in the related information associated with the candidate. (Note 6) The aforementioned search unit, An information presentation device as described in Appendix 1, which searches for related information linked to the aforementioned candidates by referring to publicly available external data. (Note 7) The extraction unit is An information presentation device according to Appendix 1, which extracts the aforementioned candidates for entities relating to at least one of attackers, attacks, vulnerabilities, victims, and targets of attacks from the document data. (Note 8) The output unit is, An information display device according to any one of the appendices 1 to 7, which displays information relating to the entity included in the attack information on the screen of a terminal device used by the user. (Note 9) Computers We obtain document data related to cybersecurity, From the acquired document data, we extract candidate entities related to cybersecurity, Search for related information associated with the extracted candidates, Using the document data and the relevant information extracted for each candidate, instructions are generated to identify a security-related entity from among the candidates. An information presentation method that outputs attack information including the entity output from the model in accordance with the aforementioned instructions. (Note 10) On the computer, The process of acquiring document data related to cybersecurity, A process for extracting candidate entities related to cybersecurity from the acquired document data, A process to search for related information associated with the extracted candidates, A process for generating instructions to identify a security-related entity from among the candidates, using the document data and related information extracted for each candidate, A program that causes a computer to perform a process that outputs attack information, including the entities output from the model in response to the aforementioned instructions. Furthermore, some or all of the configurations described in Appendices 2 to 8, which are subordinate to Appendice 1 above, may also be subordinate to Appendices 9 and 10 in the same way as those described in Appendices 2 to 8. Moreover, not limited to Appendices 1, 9, and 10, some or all of the configurations described as appendices may also be subordinate to various hardware, software, various recording means for recording software, or systems, without departing from the embodiments described above. [Explanation of Symbols]

[0125] 10, 20, 30 Information presentation device 11, 21, 31 Acquisition part 12, 22, 32 Extraction part 13, 23 Storage section 14, 24, 34 Search section 15, 25 Instruction section 16, 26 Specific part 17, 27, 37 Output section 35 Generation part 150, 250 LLM system 180, 280 terminal devices

Claims

1. An acquisition unit that acquires document data related to cybersecurity, An extraction unit that extracts candidate entities related to cybersecurity from the acquired document data, A search unit that searches for related information associated with the extracted candidates, A generation unit generates instructions to identify security entities contained in the document data, using the document data and related information extracted for each candidate. An information presentation device comprising: an output unit that outputs attack information including entities output from a model in response to the aforementioned instructions.

2. The aforementioned search unit, The information presentation device according to claim 1, which searches for the associated information associated with the candidate by referring to a table in which related information is linked for each entity.

3. The generating unit is The information presentation device according to claim 2, which generates instructions for extracting entities for each type of entity.

4. The aforementioned search unit, Referencing a knowledge graph that shows the relationships between multiple entities, search for related information linked to the aforementioned candidate. The generating unit is The information presentation device according to claim 1, which generates instructions for identifying security entities contained in the document data using the document data and related information extracted from the knowledge graph.

5. The aforementioned search unit, The information presentation device according to claim 4, which refers to the knowledge graph and searches for related information associated with entities included in the related information associated with the candidate.

6. The aforementioned search unit, The information presentation device according to claim 1, which searches for related information linked to the candidate by referring to publicly available external data.

7. The extraction unit is The information presentation device according to claim 1, which extracts from the document data the aforementioned candidates for entities relating to at least one of attackers, attacks, vulnerabilities, victims, and targets of attacks.

8. The output unit is, An information display device according to any one of claims 1 to 7, which displays information relating to the entity included in the attack information on the screen of a terminal device used by a user.

9. Computers We obtain document data related to cybersecurity, From the acquired document data, we extract candidate entities related to cybersecurity, Search for related information associated with the extracted candidates, Using the document data and the relevant information extracted for each candidate, instructions are generated to identify a security-related entity from among the candidates. An information presentation method that outputs attack information including the entity output from the model in accordance with the aforementioned instructions.

10. On the computer, The process of acquiring document data related to cybersecurity, A process for extracting candidate entities related to cybersecurity from the acquired document data, A process to search for related information associated with the extracted candidates, A process for generating instructions to identify a security-related entity from among the candidates, using the document data and related information extracted for each candidate, A program that causes a computer to perform a process that outputs attack information, including the entities output from the model in response to the aforementioned instructions.

Citation Information

Patent Citations

  • Search device, search method, and search program

    WO2022176209A1