system

A system with generative AI for attack and defense units iteratively identifies vulnerabilities and generates countermeasures, enhancing security by analyzing system components and providing feedback, thus improving security from both offensive and defensive perspectives.

JP7852003B2Active Publication Date: 2026-04-27SOFTBANK GROUP CORP
View PDF 7 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
SOFTBANK GROUP CORP
Filing Date
2024-09-19
Publication Date
2026-04-27

Smart Images

  • Figure 0007852003000001
    Figure 0007852003000001
  • Figure 0007852003000002
    Figure 0007852003000002
  • Figure 0007852003000003
    Figure 0007852003000003
Patent Text Reader

Abstract

To provide a system that effectively searches for vulnerabilities in the system and generates and evaluates defensive measures.SOLUTION: A system according to the embodiment comprises an attack unit, a defense unit, and a feedback unit. The attack unit searches for vulnerabilities in the system. The defense unit generates defensive measures based on an attack scenario generated by the attack unit. The feedback unit evaluates the effectiveness of the defensive measures generated by the defense unit, and generates a new attack scenario.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The technology of the present disclosure relates to a system.

Background Art

[0002] Patent Document 1 discloses a method for controlling a persona chatbot, which is performed by at least one processor and includes steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to the description of the chatbot character, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance in response to the user utterance.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] In the prior art, the process of effectively exploring the vulnerabilities of a system and generating countermeasures is complex, and there is room for improvement.

[0005] The system according to the embodiment aims to effectively explore the vulnerabilities of the system and generate and evaluate countermeasures.

Means for Solving the Problems

[0006] The system according to the embodiment includes an attack unit, a defense unit, and a feedback unit. The attack unit explores the vulnerabilities of the system. The defense unit generates countermeasures based on the attack scenarios generated by the attack unit. The feedback unit evaluates the effectiveness of the countermeasures generated by the defense unit and generates new attack scenarios. [Effects of the Invention]

[0007] The system according to this embodiment can effectively search for system vulnerabilities and generate and evaluate countermeasures. [Brief explanation of the drawing]

[0008] [Figure 1] This is a conceptual diagram showing an example of the configuration of a data processing system according to the first embodiment. [Figure 2] This is a conceptual diagram showing an example of the essential functions of a data processing device and a smart device according to the first embodiment. [Figure 3] This is a conceptual diagram showing an example of the configuration of a data processing system according to the second embodiment. [Figure 4] This is a conceptual diagram showing an example of the main functions of a data processing device and smart glasses according to the second embodiment. [Figure 5] This is a conceptual diagram showing an example of the configuration of a data processing system according to the third embodiment. [Figure 6] This is a conceptual diagram showing an example of the main functions of a data processing device and a headset-type terminal according to the third embodiment. [Figure 7] This is a conceptual diagram showing an example of the configuration of a data processing system according to the fourth embodiment. [Figure 8] This is a conceptual diagram showing an example of the main functions of a data processing device and a robot according to the fourth embodiment. [Figure 9] This shows an emotion map where multiple emotions are mapped. [Figure 10] This shows an emotion map where multiple emotions are mapped. [Modes for carrying out the invention]

[0009] Hereinafter, an example of an embodiment of the system relating to the technology of this disclosure will be described with reference to the attached drawings.

[0010] First, let's explain the terminology used in the following explanation.

[0011] In the following embodiments, the signed processor (hereinafter simply referred to as "processor") may be a single arithmetic unit or a combination of multiple arithmetic units. Furthermore, the processor may be a single type of arithmetic unit or a combination of multiple types of arithmetic units. Examples of arithmetic units include CPU (Central Processing Unit), GPU (Graphics Processing Unit), GPGPU (General-Purpose computing on Graphics Processing Units), APU (Accelerated Processing Unit), or TPU (Tensor Processing Unit).

[0012] In the following embodiments, signed RAM (Random Access Memory) is a memory that temporarily stores information and is used as work memory by the processor.

[0013] In the following embodiments, the signed storage is one or more non-volatile storage devices that store various programs and various parameters. Examples of non-volatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), or magnetic tapes.

[0014] In the following embodiments, the signed communication interface (I / F) is an interface that includes a communication processor and an antenna. The communication interface manages communication between multiple computers. Examples of communication standards applicable to the communication interface include wireless communication standards such as 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), or Bluetooth (registered trademark).

[0015] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B". That is, "A and / or B" means that it may be only A, only B, or a combination of A and B. Also, in this specification, when expressing three or more matters connected by "and / or", the same concept as "A and / or B" is applied.

[0016] [First Embodiment] FIG. 1 shows an example of the configuration of a data processing system 10 according to the first embodiment.

[0017] As shown in FIG. 1, the data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.

[0018] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. Also, the database 24 and the communication I / F 26 are connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0019] The smart device 14 includes a computer 36, a reception device 38, an output device 40, a camera 42, and a communication I / F 44. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. Also, the reception device 38, the output device 40, and the camera 42 are connected to the bus 52.

[0020] The reception device 38 is equipped with a touch panel 38A and a microphone 38B, and accepts user input. The touch panel 38A accepts user input via touch by detecting contact with an object (e.g., a pen or finger). The microphone 38B accepts user input via voice by detecting the user's voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and microphone 38B to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 (see Figure 2) acquires the data indicating the user input.

[0021] The output device 40 includes a display 40A and a speaker 40B, and presents data to the user by outputting the data in a form perceptible to the user (e.g., audio and / or text). The display 40A displays visible information such as text and images according to instructions from the processor 46. The speaker 40B outputs audio according to instructions from the processor 46. The camera 42 is a small digital camera equipped with an optical system such as a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.

[0022] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various types of information between processor 46 and processor 28 via network 54.

[0023] Figure 2 shows an example of the main functions of the data processing device 12 and the smart device 14.

[0024] As shown in Figure 2, in the data processing device 12, a specific processing is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" related to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.

[0025] Storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotions using the emotion identification model 59 and perform identification processing using the user's emotions. The emotion estimation function (emotion identification function) using the emotion identification model 59 performs various estimations and predictions regarding the user's emotions, including but not limited to these examples. Furthermore, emotion estimation and prediction also include, for example, emotion analysis.

[0026] In the smart device 14, specific processing is performed by the processor 46. The storage 50 stores a specific processing program 60. The specific processing program 60 is used in conjunction with the specific processing program 56 by the data processing system 10. The processor 46 reads the specific processing program 60 from the storage 50 and executes the read specific processing program 60 on the RAM 48. The specific processing is realized by the processor 46 operating as a control unit 46A according to the specific processing program 60 executed on the RAM 48. The smart device 14 also has a data generation model 58 and an emotion identification model 59, similar to the data generation model and emotion identification model 59, and can perform processing similar to that of the specific processing unit 290 using these models.

[0027] Furthermore, other devices besides the data processing device 12 may also have the data generation model 58. For example, a server device (e.g., a generation server) may have the data generation model 58. In this case, the data processing device 12 obtains processing results (such as prediction results) using the data generation model 58 by communicating with the server device having the data generation model 58. The data processing device 12 may also be a server device or a terminal device owned by a user (e.g., a mobile phone, robot, home appliance, etc.). Next, an example of processing by the data processing system 10 according to the first embodiment will be described.

[0028] (Example of form 1) The penetration testing support system according to an embodiment of the present invention is a system that supports penetration testing using a generative AI that has been trained in two patterns, one for an attack team and one for a defense team. In this system, the generative AI for the attack team searches for vulnerabilities in the system and generates attack scenarios. Next, the generative AI for the defense team generates countermeasures against those attack scenarios. This makes it possible to strengthen the security of the system from both offensive and defensive perspectives. For example, the generative AI for the attack team analyzes each component of the system in detail and identifies potential vulnerabilities. For example, outdated software or improper configuration may be cited as vulnerabilities. Next, the generative AI generates attack scenarios based on the identified vulnerabilities. For example, attack methods such as SQL injection and cross-site scripting (XSS) may be included. Next, the generative AI for the defense team generates countermeasures against the attack scenarios. The generative AI analyzes the attack scenarios and proposes the optimal countermeasures. For example, firewall configuration changes or software updates may be cited as countermeasures. Furthermore, the generative AI for the defense team simulates the effectiveness of the proposed countermeasures and evaluates their actual effectiveness. Finally, the generative AIs for the attack team and the defense team provide feedback to each other. The generation AI for the attack team evaluates the effectiveness of defensive measures and generates new attack scenarios. Meanwhile, the generation AI for the defense team generates defensive measures again for the new attack scenarios. By repeating this process, the system's security can be continuously improved. This strengthens the system's security from both offensive and defensive perspectives. For example, if the generation AI for the attack team discovers a new vulnerability, the generation AI for the defense team can immediately propose countermeasures, rapidly improving the system's security. Furthermore, through this feedback loop, offensive and defensive skills improve, enabling more advanced security measures. In this way, the penetration testing support system can strengthen the system's security from both offensive and defensive perspectives.

[0029] The penetration testing support system according to the embodiment comprises an attack unit, a defense unit, and a feedback unit. The attack unit searches for vulnerabilities in the system. The attack unit, for example, analyzes each component of the system in detail and identifies potential vulnerabilities. For example, the attack unit can identify outdated software or improper configurations as vulnerabilities. The attack unit also generates attack scenarios based on the identified vulnerabilities. For example, the attack unit can generate attack scenarios that include attack methods such as SQL injection and cross-site scripting (XSS). The defense unit generates defensive measures based on the attack scenarios. The defense unit, for example, analyzes the attack scenarios and proposes the optimal defensive measures. For example, the defense unit can propose firewall configuration changes or software updates as defensive measures. The defense unit also simulates the effectiveness of the proposed defensive measures and evaluates their actual effectiveness. For example, the defense unit can test the effectiveness of the defensive measures in a virtual environment and evaluate the results. The feedback unit evaluates the effectiveness of the defensive measures and generates new attack scenarios. The feedback unit can evaluate the effectiveness of the defensive measures and generate new attack scenarios based on the results. As a result, the penetration testing support system according to this embodiment can enhance the security of the system from both offensive and defensive perspectives. For example, the attack unit searches for vulnerabilities in the system and generates attack scenarios. The defense unit generates defensive measures based on the attack scenarios and evaluates their effectiveness. The feedback unit evaluates the effectiveness of the defensive measures and generates new attack scenarios. As a result, the penetration testing support system can continuously improve the security of the system.

[0030] The attack team explores the system's vulnerabilities. For example, they analyze each component of the system in detail to identify potential vulnerabilities. Specifically, they analyze the system's source code using static analysis tools to detect vulnerabilities in the code. They can also use dynamic analysis tools to monitor the system's behavior while it is running and detect abnormal behavior or unauthorized access. Furthermore, they use network scanners to analyze the system's network configuration and identify open ports and services. This allows them to identify vulnerabilities such as outdated software or improper configurations. The attack team also generates attack scenarios based on the identified vulnerabilities. For example, they can generate attack scenarios that include attack methods such as SQL injection and cross-site scripting (XSS). These attack scenarios are used to simulate actual attacks and are an important means of evaluating the system's defensive capabilities. The attack team executes the generated attack scenarios and evaluates the impact by actually attacking the system's vulnerabilities. This allows the attack team to gain a detailed understanding of the system's vulnerabilities and verify them using specific attack methods.

[0031] The defense department generates defensive measures based on attack scenarios. For example, the defense department analyzes attack scenarios and proposes optimal defensive measures. Specifically, the defense department analyzes the content of attack scenarios in detail and identifies attack methods and attack paths. This clarifies the source and objective of the attack and allows for the formulation of optimal defensive measures. For example, the defense department may propose measures such as changing firewall settings or updating software. Changing firewall settings can restrict access from specific ports or IP addresses, preventing unauthorized access. Software updates can fix known vulnerabilities and strengthen system security. Furthermore, the defense department simulates the effectiveness of the proposed defensive measures and evaluates their actual effectiveness. For example, the defense department can test the effectiveness of defensive measures in a virtual environment and evaluate the results. In a virtual environment, the effectiveness of defensive measures can be verified without affecting the actual system. This allows the defense department to confirm whether the proposed defensive measures are actually effective and modify them as needed. The defense department can continuously review defensive measures to strengthen system security and provide optimal defensive measures.

[0032] The feedback unit evaluates the effectiveness of defensive measures and generates new attack scenarios. For example, the feedback unit can evaluate the effectiveness of defensive measures and generate new attack scenarios based on the results. Specifically, the feedback unit monitors the system's security status after the implementation of defensive measures and evaluates how effective the measures are. For example, it analyzes the results of attack simulations conducted after the implementation of defensive measures and evaluates how well the measures prevented attacks. This allows for confirmation of the effectiveness of the defensive measures and modification of them as needed. The feedback unit also generates new attack scenarios based on the evaluation of the effectiveness of the defensive measures. For example, if a defensive measure proves effective against a particular attack method, it can generate a new attack scenario that avoids that attack method. This allows for the continuous strengthening of the system's security. Furthermore, the feedback unit can store past attack scenarios and the effectiveness of defensive measures in a database and utilize this data for generating future attack scenarios and formulating defensive measures. This allows the feedback unit to continuously improve the system's security and strengthen it from both offensive and defensive perspectives.

[0033] The attack unit can analyze each component of the system in detail and identify potential vulnerabilities. It is necessary to clarify the specific methods and criteria for this detailed analysis. For example, the attack unit can perform code reviews to identify vulnerabilities in the source code. The attack unit can also conduct penetration testing to identify system vulnerabilities. For example, the attack unit can analyze each component of the system in detail to identify unpatched bugs and known security holes. This allows for the identification of potential vulnerabilities through a detailed analysis of each component of the system. Some or all of the above processes performed by the attack unit may be carried out using, for example, generative AI, or without generative AI. For example, the attack unit can input data for each component of the system into a generative AI and have the generative AI perform vulnerability identification.

[0034] The attack unit can generate attack scenarios based on identified vulnerabilities. The specific types of vulnerabilities and methods of identification must be clearly defined. For example, the attack unit can identify vulnerabilities such as SQL injection and cross-site scripting (XSS) and generate attack scenarios based on them. The specific content and generation methods of the attack scenarios must also be clearly defined. For example, the attack unit can generate a SQL injection attack scenario based on identified vulnerabilities. The attack unit can also generate a cross-site scripting (XSS) attack scenario. This allows for the creation of effective attack scenarios by generating them based on identified vulnerabilities. Some or all of the above-described processes in the attack unit may be performed using, for example, a generation AI, or without a generation AI. For example, the attack unit can input data on identified vulnerabilities into a generation AI and have the generation AI generate attack scenarios.

[0035] The defense unit can analyze attack scenarios and propose appropriate defense measures. It is necessary to clarify the specific content and method of proposing appropriate defense measures. For example, the defense unit can analyze attack scenarios and propose changes to firewall settings. It can also propose software updates. This allows the optimal defense measures to be proposed by analyzing attack scenarios. Some or all of the above-described processes in the defense unit may be performed using, for example, a generative AI, or without a generative AI. For example, the defense unit can input attack scenario data into a generative AI and have the generative AI execute the proposal of defense measures.

[0036] The defense unit can simulate the effectiveness of proposed defense measures and evaluate their actual effects. It is necessary to clarify the specific methods and criteria for simulating the effects. For example, the defense unit can test the effectiveness of defense measures in a virtual environment and evaluate the results. Alternatively, the defense unit can conduct scenario-based simulations to evaluate the effectiveness of defense measures. This allows for the evaluation of actual effects by simulating the effectiveness of proposed defense measures. Some or all of the above-described processes in the defense unit may be performed using, for example, a generative AI, or without a generative AI. For example, the defense unit can input data on defense measures into a generative AI and have the generative AI perform an effect simulation.

[0037] The feedback unit can evaluate the effectiveness of defensive measures and generate new attack scenarios. It is necessary to clarify the specific content and generation method of these new attack scenarios. For example, the feedback unit can evaluate the effectiveness of defensive measures and generate new attack scenarios based on the results. For example, the feedback unit can generate attack scenarios that incorporate new attack methods. Furthermore, the feedback unit can generate attack scenarios that improve upon existing scenarios. This allows for the generation of new attack scenarios by evaluating the effectiveness of defensive measures. Some or all of the above-described processes in the feedback unit may be performed using, for example, a generation AI, or without a generation AI. For example, the feedback unit can input data on the effectiveness of defensive measures into a generation AI and have the generation AI generate new attack scenarios.

[0038] The attack unit can analyze the system's past attack history and select the most effective vulnerability detection method. It is necessary to clarify the specific content and analysis methods of the past attack history. For example, the attack unit can analyze log data and search for similar vulnerabilities based on past successful attack methods. The attack unit can also prioritize the search for vulnerabilities that are frequently targeted based on past attack history. Furthermore, the attack unit can analyze past attack history to explore new attack methods. This allows the attack unit to select the most effective vulnerability detection method by analyzing past attack history. Some or all of the above processing in the attack unit may be performed using, for example, a generative AI, or without one. For example, the attack unit can input past attack history data into a generative AI and have the generative AI select a vulnerability detection method.

[0039] The attack unit can adjust its vulnerability search methods based on the system's operating status and load during vulnerability scanning. It is necessary to clearly define specific measurement methods and criteria for operating status and load. For example, the attack unit can monitor CPU usage and memory usage, and use a lightweight search method when the system is under high load. Conversely, it can use a more detailed search method when the system is under low load. Furthermore, the attack unit can dynamically switch search methods depending on the system's operating status. This allows for efficient vulnerability scanning by adjusting the search method based on the system's operating status and load. Some or all of the above-described processes in the attack unit may be performed using, for example, a generative AI, or without one. For example, the attack unit can input system operating status data into a generative AI and have the generative AI adjust the search method.

[0040] The attack unit can optimize its vulnerability search methods by considering the geographical distribution of the system. The specific details and methods of considering geographical distribution need to be clearly defined. For example, the attack unit can consider the location of data centers and users, and use search methods that take into account the characteristics of each region for geographically dispersed systems. The attack unit can also use search methods that simulate a concentrated attack for geographically concentrated systems. Furthermore, the attack unit can dynamically adjust the search methods based on geographical distribution. This allows for the selection of the optimal search method by considering the geographical distribution of the system. Some or all of the above processing in the attack unit may be performed using, for example, generative AI, or without generative AI. For example, the attack unit can input geographical distribution data of the system into a generative AI and have the generative AI optimize the search method.

[0041] The attack unit can improve the accuracy of its vulnerability search by referring to relevant system documentation during vulnerability scanning. It is necessary to clarify the specific types of relevant documentation and how to refer to them. For example, the attack unit can update its vulnerability scanning methods by referring to the latest security research. It can also optimize its vulnerability scanning methods by referring to past security incident reports. Furthermore, the attack unit can strengthen its vulnerability scanning methods for specific vulnerabilities by referring to relevant system documentation. This allows for improved scanning accuracy by referring to relevant system documentation. Some or all of the above processes in the attack unit may be performed using, for example, a generative AI, or without one. For example, the attack unit can input relevant documentation data into a generative AI and have the generative AI perform the scanning accuracy improvement.

[0042] The defense unit can select the optimal defense measure by referring to past defense history when generating defense measures. It is necessary to clarify the specific content and method of referencing past defense history. For example, the defense unit can analyze log data and select defense measures against similar attacks based on past successful defense measures. The defense unit can also prioritize frequently used defense measures from past defense history. Furthermore, the defense unit can analyze past defense history to explore new defense measures. This allows for the selection of the optimal defense measure by referring to past defense history. Some or all of the above-described processes in the defense unit may be performed using, for example, a generation AI, or without a generation AI. For example, the defense unit can input past defense history data into a generation AI and have the generation AI select defense measures.

[0043] The defense unit can customize defense measures based on the system's current security policy when generating them. It is necessary to clarify the specific content and reference methods of the current security policy. For example, the defense unit can refer to corporate security guidelines and industry standards to select appropriate defense measures. Furthermore, the defense unit can dynamically adjust defense measures in response to changes in the security policy. In addition, the defense unit can determine the priority of defense measures based on the security policy. This allows for the provision of more effective defense measures by customizing them based on the current security policy. Some or all of the above processes in the defense unit may be performed using, for example, a generation AI, or not. For example, the defense unit can input security policy data into a generation AI and have the generation AI perform the customization of defense measures.

[0044] The defense unit can optimize defense measures by considering the geographical distribution of the system when generating them. The specific details and methods of considering geographical distribution need to be clearly defined. For example, the defense unit can consider the location of data centers and users, and propose defense measures that take into account the characteristics of each region for geographically dispersed systems. It can also propose defense measures to prevent concentrated attacks for geographically concentrated systems. Furthermore, the defense unit can dynamically adjust defense measures based on geographical distribution. This allows for the provision of optimal defense measures by considering the geographical distribution of the system. Some or all of the above processing in the defense unit may be performed using, for example, a generation AI, or without a generation AI. For example, the defense unit can input geographical distribution data of the system into a generation AI and have the generation AI perform the optimization of defense measures.

[0045] The defense unit can improve the accuracy of defense measures by referring to relevant system literature when generating them. It is necessary to clarify the specific types of relevant literature and how to refer to them. For example, the defense unit can update defense measures by referring to the latest security research. It can also optimize defense measures by referring to past security incident reports. Furthermore, the defense unit can strengthen defense measures against specific attacks by referring to relevant system literature. This allows for improved accuracy of defense measures by referring to relevant system literature. Some or all of the above processes in the defense unit may be performed using, for example, a generation AI, or without a generation AI. For example, the defense unit can input relevant literature data into a generation AI and have the generation AI perform the task of improving the accuracy of defense measures.

[0046] The feedback unit can select the optimal feedback method by referring to past feedback history when providing feedback. It is necessary to clarify the specific content and method of referencing past feedback history. For example, the feedback unit can analyze log data and select feedback for similar situations based on past successful feedback methods. The feedback unit can also prioritize frequently used feedback methods from past feedback history. Furthermore, the feedback unit can analyze past feedback history to explore new feedback methods. This allows for the selection of the optimal feedback method by referring to past feedback history. Some or all of the above processing in the feedback unit may be performed using, for example, a generative AI, or without a generative AI. For example, the feedback unit can input past feedback history data into a generative AI and have the generative AI select the feedback method.

[0047] The feedback unit can customize the feedback content based on the current state of the system when providing feedback. It is necessary to clearly define the specific content and measurement method of the current state. For example, the feedback unit can monitor the system's operational status and security level and provide appropriate feedback based on the current system state. Furthermore, the feedback unit can dynamically adjust the feedback content in response to changes in the system state. In addition, the feedback unit can determine the priority of feedback based on the system state. This allows for the provision of more appropriate feedback by customizing the feedback content based on the current state of the system. Some or all of the above-described processes in the feedback unit may be performed using, for example, a generative AI, or without a generative AI. For example, the feedback unit can input system state data into a generative AI and have the generative AI perform the customization of the feedback content.

[0048] The feedback unit can optimize the feedback method by considering the geographical distribution of the system during the feedback process. The specific details and methods of considering geographical distribution need to be clearly defined. For example, the feedback unit can consider the location of data centers and users, and provide feedback to geographically dispersed systems that takes into account the characteristics of each region. The feedback unit can also provide feedback to geographically concentrated systems to prevent concentrated attacks. Furthermore, the feedback unit can dynamically adjust the feedback method based on geographical distribution. This allows for the provision of an optimal feedback method by considering the geographical distribution of the system. Some or all of the above processing in the feedback unit may be performed using, for example, a generative AI, or without a generative AI. For example, the feedback unit can input geographical distribution data of the system into a generative AI and have the generative AI optimize the feedback method.

[0049] The feedback unit can improve the accuracy of its feedback by referring to relevant system literature during the feedback process. It is necessary to clarify the specific types of relevant literature and how to refer to them. For example, the feedback unit can update its feedback by referring to the latest security research. It can also optimize its feedback by referring to past security incident reports. Furthermore, the feedback unit can strengthen its feedback against specific attacks by referring to relevant system literature. This allows for improved feedback accuracy by referring to relevant system literature. Some or all of the above processing in the feedback unit may be performed using, for example, a generative AI, or without a generative AI. For example, the feedback unit can input relevant literature data into a generative AI and have the generative AI perform the feedback accuracy improvement.

[0050] The system according to the embodiment is not limited to the example described above, and various modifications are possible, for example, as follows.

[0051] The attack unit can analyze real-time user activity logs when searching for system vulnerabilities, prioritizing vulnerability discovery based on user behavior patterns. For example, it can prioritize vulnerability searches for functions and pages that users frequently access. Furthermore, if a specific operation occurs frequently in the user activity logs, it can prioritize vulnerability searches related to that operation. Additionally, by analyzing user activity logs, it can prioritize vulnerability discovery during specific time periods. This allows for more efficient vulnerability discovery based on user behavior patterns.

[0052] When searching for system vulnerabilities, the attack unit can automatically collect system configuration information and prioritize vulnerability discovery based on that information. For example, it can identify specific software versions or settings as vulnerable from the system configuration information and prioritize searching those parts. It can also prioritize searching for vulnerabilities against specific network segments or servers by analyzing the system configuration information. Furthermore, it can prioritize searching for vulnerabilities against specific devices or applications based on the system configuration information. This makes vulnerability discovery more efficient based on system configuration information.

[0053] When exploring for system vulnerabilities, the attack unit can refer to external threat intelligence data and prioritize vulnerability discovery based on the latest threat information. For example, it can obtain the latest attack methods and vulnerability information from external threat intelligence data and use that information to explore for vulnerabilities. Furthermore, by analyzing external threat intelligence data, it can prioritize the exploration of vulnerabilities against methods used by specific attacker groups. In addition, it can prioritize the exploration of vulnerabilities in specific industries or regions based on external threat intelligence data. This makes vulnerability discovery more efficient based on the latest threat information.

[0054] When analyzing attack scenarios, the defense unit can refer to the system's past defense history and prioritize suggesting defense measures that were effective in the past. For example, it can identify defense measures that were effective against a specific attack method from past defense history and prioritize suggesting those measures. Furthermore, by analyzing past defense history, it can also prioritize suggesting defense measures that were effective against a specific system configuration or setting. In addition, based on past defense history, it can prioritize suggesting defense measures that were effective during a specific time period or situation. This makes the suggestion of defense measures based on past defense history more efficient.

[0055] The defense system can simulate the effectiveness of proposed defense measures while considering the system's current operating status and load. For example, if the system is under high load, it can prioritize simulating lighter defense measures. Conversely, if the system is under low load, it can simulate more detailed defense measures. Furthermore, it can dynamically adjust the simulation priority according to the system's operating status and load. This makes the simulation of defense measures more efficient based on the system's operating status and load.

[0056] The following briefly describes the processing flow for example form 1.

[0057] Step 1: The attack team explores the system for vulnerabilities. The attack team analyzes each component of the system in detail to identify potential vulnerabilities. For example, outdated software or improper configurations can be identified as vulnerabilities. The attack team also generates attack scenarios based on the identified vulnerabilities. For example, attack scenarios can be generated that include attack methods such as SQL injection or cross-site scripting (XSS). Step 2: The defense unit generates defensive measures based on the attack scenario. The defense unit analyzes the attack scenario and proposes the optimal defensive measures. For example, it may propose measures such as changing firewall settings or updating software. The defense unit also simulates the effectiveness of the proposed defensive measures and evaluates their actual effectiveness. For example, it can test the effectiveness of the defensive measures in a virtual environment and evaluate the results. Step 3: The feedback unit evaluates the effectiveness of the defensive measures and generates new attack scenarios. The feedback unit can evaluate the effectiveness of the defensive measures and generate new attack scenarios based on the results. This allows the penetration testing support system to enhance the security of the system from both offensive and defensive perspectives.

[0058] (Example of form 2) The penetration testing support system according to an embodiment of the present invention is a system that supports penetration testing using a generative AI that has been trained in two patterns, one for an attack team and one for a defense team. In this system, the generative AI for the attack team searches for vulnerabilities in the system and generates attack scenarios. Next, the generative AI for the defense team generates countermeasures against those attack scenarios. This makes it possible to strengthen the security of the system from both offensive and defensive perspectives. For example, the generative AI for the attack team analyzes each component of the system in detail and identifies potential vulnerabilities. For example, outdated software or improper configuration may be cited as vulnerabilities. Next, the generative AI generates attack scenarios based on the identified vulnerabilities. For example, attack methods such as SQL injection and cross-site scripting (XSS) may be included. Next, the generative AI for the defense team generates countermeasures against the attack scenarios. The generative AI analyzes the attack scenarios and proposes the optimal countermeasures. For example, firewall configuration changes or software updates may be cited as countermeasures. Furthermore, the generative AI for the defense team simulates the effectiveness of the proposed countermeasures and evaluates their actual effectiveness. Finally, the generative AIs for the attack team and the defense team provide feedback to each other. The generation AI for the attack team evaluates the effectiveness of defensive measures and generates new attack scenarios. Meanwhile, the generation AI for the defense team generates defensive measures again for the new attack scenarios. By repeating this process, the system's security can be continuously improved. This strengthens the system's security from both offensive and defensive perspectives. For example, if the generation AI for the attack team discovers a new vulnerability, the generation AI for the defense team can immediately propose countermeasures, rapidly improving the system's security. Furthermore, through this feedback loop, offensive and defensive skills improve, enabling more advanced security measures. In this way, the penetration testing support system can strengthen the system's security from both offensive and defensive perspectives.

[0059] The penetration testing support system according to the embodiment comprises an attack unit, a defense unit, and a feedback unit. The attack unit searches for vulnerabilities in the system. The attack unit, for example, analyzes each component of the system in detail and identifies potential vulnerabilities. For example, the attack unit can identify outdated software or improper configurations as vulnerabilities. The attack unit also generates attack scenarios based on the identified vulnerabilities. For example, the attack unit can generate attack scenarios that include attack methods such as SQL injection and cross-site scripting (XSS). The defense unit generates defensive measures based on the attack scenarios. The defense unit, for example, analyzes the attack scenarios and proposes the optimal defensive measures. For example, the defense unit can propose firewall configuration changes or software updates as defensive measures. The defense unit also simulates the effectiveness of the proposed defensive measures and evaluates their actual effectiveness. For example, the defense unit can test the effectiveness of the defensive measures in a virtual environment and evaluate the results. The feedback unit evaluates the effectiveness of the defensive measures and generates new attack scenarios. The feedback unit can evaluate the effectiveness of the defensive measures and generate new attack scenarios based on the results. As a result, the penetration testing support system according to this embodiment can enhance the security of the system from both offensive and defensive perspectives. For example, the attack unit searches for vulnerabilities in the system and generates attack scenarios. The defense unit generates defensive measures based on the attack scenarios and evaluates their effectiveness. The feedback unit evaluates the effectiveness of the defensive measures and generates new attack scenarios. As a result, the penetration testing support system can continuously improve the security of the system.

[0060] The attack team explores the system's vulnerabilities. For example, they analyze each component of the system in detail to identify potential vulnerabilities. Specifically, they analyze the system's source code using static analysis tools to detect vulnerabilities in the code. They can also use dynamic analysis tools to monitor the system's behavior while it is running and detect abnormal behavior or unauthorized access. Furthermore, they use network scanners to analyze the system's network configuration and identify open ports and services. This allows them to identify vulnerabilities such as outdated software or improper configurations. The attack team also generates attack scenarios based on the identified vulnerabilities. For example, they can generate attack scenarios that include attack methods such as SQL injection and cross-site scripting (XSS). These attack scenarios are used to simulate actual attacks and are an important means of evaluating the system's defensive capabilities. The attack team executes the generated attack scenarios and evaluates the impact by actually attacking the system's vulnerabilities. This allows the attack team to gain a detailed understanding of the system's vulnerabilities and verify them using specific attack methods.

[0061] The defense department generates defensive measures based on attack scenarios. For example, the defense department analyzes attack scenarios and proposes optimal defensive measures. Specifically, the defense department analyzes the content of attack scenarios in detail and identifies attack methods and attack paths. This clarifies the source and objective of the attack and allows for the formulation of optimal defensive measures. For example, the defense department may propose measures such as changing firewall settings or updating software. Changing firewall settings can restrict access from specific ports or IP addresses, preventing unauthorized access. Software updates can fix known vulnerabilities and strengthen system security. Furthermore, the defense department simulates the effectiveness of the proposed defensive measures and evaluates their actual effectiveness. For example, the defense department can test the effectiveness of defensive measures in a virtual environment and evaluate the results. In a virtual environment, the effectiveness of defensive measures can be verified without affecting the actual system. This allows the defense department to confirm whether the proposed defensive measures are actually effective and modify them as needed. The defense department can continuously review defensive measures to strengthen system security and provide optimal defensive measures.

[0062] The feedback unit evaluates the effectiveness of defensive measures and generates new attack scenarios. For example, the feedback unit can evaluate the effectiveness of defensive measures and generate new attack scenarios based on the results. Specifically, the feedback unit monitors the system's security status after the implementation of defensive measures and evaluates how effective the measures are. For example, it analyzes the results of attack simulations conducted after the implementation of defensive measures and evaluates how well the measures prevented attacks. This allows for confirmation of the effectiveness of the defensive measures and modification of them as needed. The feedback unit also generates new attack scenarios based on the evaluation of the effectiveness of the defensive measures. For example, if a defensive measure proves effective against a particular attack method, it can generate a new attack scenario that avoids that attack method. This allows for the continuous strengthening of the system's security. Furthermore, the feedback unit can store past attack scenarios and the effectiveness of defensive measures in a database and utilize this data for generating future attack scenarios and formulating defensive measures. This allows the feedback unit to continuously improve the system's security and strengthen it from both offensive and defensive perspectives.

[0063] The attack unit can analyze each component of the system in detail and identify potential vulnerabilities. It is necessary to clarify the specific methods and criteria for this detailed analysis. For example, the attack unit can perform code reviews to identify vulnerabilities in the source code. The attack unit can also conduct penetration testing to identify system vulnerabilities. For example, the attack unit can analyze each component of the system in detail to identify unpatched bugs and known security holes. This allows for the identification of potential vulnerabilities through a detailed analysis of each component of the system. Some or all of the above processes performed by the attack unit may be carried out using, for example, generative AI, or without generative AI. For example, the attack unit can input data for each component of the system into a generative AI and have the generative AI perform vulnerability identification.

[0064] The attack unit can generate attack scenarios based on identified vulnerabilities. The specific types of vulnerabilities and methods of identification must be clearly defined. For example, the attack unit can identify vulnerabilities such as SQL injection and cross-site scripting (XSS) and generate attack scenarios based on them. The specific content and generation methods of the attack scenarios must also be clearly defined. For example, the attack unit can generate a SQL injection attack scenario based on identified vulnerabilities. The attack unit can also generate a cross-site scripting (XSS) attack scenario. This allows for the creation of effective attack scenarios by generating them based on identified vulnerabilities. Some or all of the above-described processes in the attack unit may be performed using, for example, a generation AI, or without a generation AI. For example, the attack unit can input data on identified vulnerabilities into a generation AI and have the generation AI generate attack scenarios.

[0065] The defense unit can analyze attack scenarios and propose appropriate defense measures. It is necessary to clarify the specific content and method of proposing appropriate defense measures. For example, the defense unit can analyze attack scenarios and propose changes to firewall settings. It can also propose software updates. This allows the optimal defense measures to be proposed by analyzing attack scenarios. Some or all of the above-described processes in the defense unit may be performed using, for example, a generative AI, or without a generative AI. For example, the defense unit can input attack scenario data into a generative AI and have the generative AI execute the proposal of defense measures.

[0066] The defense unit can simulate the effectiveness of proposed defense measures and evaluate their actual effects. It is necessary to clarify the specific methods and criteria for simulating the effects. For example, the defense unit can test the effectiveness of defense measures in a virtual environment and evaluate the results. Alternatively, the defense unit can conduct scenario-based simulations to evaluate the effectiveness of defense measures. This allows for the evaluation of actual effects by simulating the effectiveness of proposed defense measures. Some or all of the above-described processes in the defense unit may be performed using, for example, a generative AI, or without a generative AI. For example, the defense unit can input data on defense measures into a generative AI and have the generative AI perform an effect simulation.

[0067] The feedback unit can evaluate the effectiveness of defensive measures and generate new attack scenarios. It is necessary to clarify the specific content and generation method of these new attack scenarios. For example, the feedback unit can evaluate the effectiveness of defensive measures and generate new attack scenarios based on the results. For example, the feedback unit can generate attack scenarios that incorporate new attack methods. Furthermore, the feedback unit can generate attack scenarios that improve upon existing scenarios. This allows for the generation of new attack scenarios by evaluating the effectiveness of defensive measures. Some or all of the above-described processes in the feedback unit may be performed using, for example, a generation AI, or without a generation AI. For example, the feedback unit can input data on the effectiveness of defensive measures into a generation AI and have the generation AI generate new attack scenarios.

[0068] The attack unit can estimate the user's emotions and adjust the priority of vulnerability exploration based on the estimated emotions. It is necessary to clarify how the user's emotions are estimated. For example, the attack unit can estimate the user's emotions by conducting a survey. Alternatively, the attack unit can estimate the user's emotions by performing behavioral analysis. For example, if the attack unit is feeling anxious, it can prioritize exploring the most serious vulnerabilities. If the attack unit is relaxed, it can explore vulnerabilities in a balanced manner across the board. Furthermore, if the attack unit is in a hurry, it can prioritize exploring vulnerabilities that can be found quickly. By adjusting the priority of vulnerability exploration based on the user's emotions, more effective vulnerability exploration becomes possible. Emotion estimation is achieved using emotion estimation functions, such as an emotion engine or generative AI. Generative AI includes, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above processing in the attack unit may be performed using, for example, generative AI, or not using generative AI. For example, the attack unit can input user emotion data into a generating AI and have the AI ​​adjust the priority of vulnerability searches.

[0069] The attack unit can analyze the system's past attack history and select the most effective vulnerability detection method. It is necessary to clarify the specific content and analysis methods of the past attack history. For example, the attack unit can analyze log data and search for similar vulnerabilities based on past successful attack methods. The attack unit can also prioritize the search for vulnerabilities that are frequently targeted based on past attack history. Furthermore, the attack unit can analyze past attack history to explore new attack methods. This allows the attack unit to select the most effective vulnerability detection method by analyzing past attack history. Some or all of the above processing in the attack unit may be performed using, for example, a generative AI, or without one. For example, the attack unit can input past attack history data into a generative AI and have the generative AI select a vulnerability detection method.

[0070] The attack unit can adjust its vulnerability search methods based on the system's operating status and load during vulnerability scanning. It is necessary to clearly define specific measurement methods and criteria for operating status and load. For example, the attack unit can monitor CPU usage and memory usage, and use a lightweight search method when the system is under high load. Conversely, it can use a more detailed search method when the system is under low load. Furthermore, the attack unit can dynamically switch search methods depending on the system's operating status. This allows for efficient vulnerability scanning by adjusting the search method based on the system's operating status and load. Some or all of the above-described processes in the attack unit may be performed using, for example, a generative AI, or without one. For example, the attack unit can input system operating status data into a generative AI and have the generative AI adjust the search method.

[0071] The attack unit can estimate the user's emotions and adjust the vulnerability reporting method based on the estimated emotions. It is necessary to clarify how the user's emotions will be estimated. For example, the attack unit can estimate the user's emotions by conducting a survey. Alternatively, the attack unit can estimate the user's emotions by performing behavioral analysis. For example, if the attack unit is feeling anxious, it can provide a detailed report to reassure the user. If the user is relaxed, it can provide a concise report to encourage a quick response. Furthermore, if the user is in a hurry, it can provide a to-the-point report to encourage a quick response. By adjusting the vulnerability reporting method based on the user's emotions, more appropriate reporting becomes possible. Emotion estimation is achieved using emotion estimation functions, such as an emotion engine or generative AI. Generative AI includes, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above processing in the attack unit may be performed using, for example, generative AI, or not using generative AI. For example, the attack unit can input user emotion data into a generating AI and have the AI ​​adjust the method for reporting vulnerabilities.

[0072] The attack unit can optimize its vulnerability search methods by considering the geographical distribution of the system. The specific details and methods of considering geographical distribution need to be clearly defined. For example, the attack unit can consider the location of data centers and users, and use search methods that take into account the characteristics of each region for geographically dispersed systems. The attack unit can also use search methods that simulate a concentrated attack for geographically concentrated systems. Furthermore, the attack unit can dynamically adjust the search methods based on geographical distribution. This allows for the selection of the optimal search method by considering the geographical distribution of the system. Some or all of the above processing in the attack unit may be performed using, for example, generative AI, or without generative AI. For example, the attack unit can input geographical distribution data of the system into a generative AI and have the generative AI optimize the search method.

[0073] The attack unit can improve the accuracy of its vulnerability search by referring to relevant system documentation during vulnerability scanning. It is necessary to clarify the specific types of relevant documentation and how to refer to them. For example, the attack unit can update its vulnerability scanning methods by referring to the latest security research. It can also optimize its vulnerability scanning methods by referring to past security incident reports. Furthermore, the attack unit can strengthen its vulnerability scanning methods for specific vulnerabilities by referring to relevant system documentation. This allows for improved scanning accuracy by referring to relevant system documentation. Some or all of the above processes in the attack unit may be performed using, for example, a generative AI, or without one. For example, the attack unit can input relevant documentation data into a generative AI and have the generative AI perform the scanning accuracy improvement.

[0074] The defense unit can estimate the user's emotions and adjust the method of suggesting defense measures based on the estimated user emotions. It is necessary to clarify how the user's emotions are estimated. For example, the defense unit can estimate the user's emotions by conducting a survey. Alternatively, the defense unit can estimate the user's emotions by performing behavioral analysis. For example, if the user is feeling anxious, the defense unit can suggest detailed defense measures to provide reassurance. If the user is relaxed, the defense unit can suggest concise defense measures to encourage a quick response. Furthermore, if the user is in a hurry, the defense unit can suggest concise defense measures to encourage a quick response. By adjusting the method of suggesting defense measures based on the user's emotions, more appropriate defense measures can be suggested. Emotion estimation is achieved using an emotion estimation function, for example, using an emotion engine or generative AI. Generative AI is, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above processing in the defense unit may be performed using, for example, generative AI, or not using generative AI. For example, the defense unit can input user emotion data into a generating AI and have the AI ​​adjust how it proposes defense measures.

[0075] The defense unit can select the optimal defense measure by referring to past defense history when generating defense measures. It is necessary to clarify the specific content and method of referencing past defense history. For example, the defense unit can analyze log data and select defense measures against similar attacks based on past successful defense measures. The defense unit can also prioritize frequently used defense measures from past defense history. Furthermore, the defense unit can analyze past defense history to explore new defense measures. This allows for the selection of the optimal defense measure by referring to past defense history. Some or all of the above-described processes in the defense unit may be performed using, for example, a generation AI, or without a generation AI. For example, the defense unit can input past defense history data into a generation AI and have the generation AI select defense measures.

[0076] The defense unit can customize defense measures based on the system's current security policy when generating them. It is necessary to clarify the specific content and reference methods of the current security policy. For example, the defense unit can refer to corporate security guidelines and industry standards to select appropriate defense measures. Furthermore, the defense unit can dynamically adjust defense measures in response to changes in the security policy. In addition, the defense unit can determine the priority of defense measures based on the security policy. This allows for the provision of more effective defense measures by customizing them based on the current security policy. Some or all of the above processes in the defense unit may be performed using, for example, a generation AI, or not. For example, the defense unit can input security policy data into a generation AI and have the generation AI perform the customization of defense measures.

[0077] The defense unit can estimate the user's emotions and prioritize defensive measures based on those estimated emotions. It is necessary to clarify how the user's emotions are estimated. For example, the defense unit can estimate user emotions by conducting surveys. Alternatively, the defense unit can estimate user emotions by performing behavioral analysis. For example, if the user is feeling anxious, the defense unit can prioritize defensive measures against the most serious attacks. If the user is relaxed, the defense unit can also propose a balanced set of overall defensive measures. Furthermore, if the user is in a hurry, the defense unit can prioritize defensive measures that can be implemented quickly. This allows for the provision of more effective defensive measures by prioritizing defensive measures based on the user's emotions. Emotion estimation is achieved using an emotion estimation function, for example, using an emotion engine or generative AI. Generative AI includes, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above-described processes in the defense unit may be performed using, for example, generative AI, or not using generative AI. For example, the defense unit can input user emotion data into a generating AI and have the AI ​​determine the priority of defensive measures.

[0078] The defense unit can optimize defense measures by considering the geographical distribution of the system when generating them. The specific details and methods of considering geographical distribution need to be clearly defined. For example, the defense unit can consider the location of data centers and users, and propose defense measures that take into account the characteristics of each region for geographically dispersed systems. It can also propose defense measures to prevent concentrated attacks for geographically concentrated systems. Furthermore, the defense unit can dynamically adjust defense measures based on geographical distribution. This allows for the provision of optimal defense measures by considering the geographical distribution of the system. Some or all of the above processing in the defense unit may be performed using, for example, a generation AI, or without a generation AI. For example, the defense unit can input geographical distribution data of the system into a generation AI and have the generation AI perform the optimization of defense measures.

[0079] The defense unit can improve the accuracy of defense measures by referring to relevant system literature when generating them. It is necessary to clarify the specific types of relevant literature and how to refer to them. For example, the defense unit can update defense measures by referring to the latest security research. It can also optimize defense measures by referring to past security incident reports. Furthermore, the defense unit can strengthen defense measures against specific attacks by referring to relevant system literature. This allows for improved accuracy of defense measures by referring to relevant system literature. Some or all of the above processes in the defense unit may be performed using, for example, a generation AI, or without a generation AI. For example, the defense unit can input relevant literature data into a generation AI and have the generation AI perform the task of improving the accuracy of defense measures.

[0080] The feedback unit can estimate the user's emotions and adjust the feedback method based on the estimated emotions. It is necessary to clarify how the user's emotions are estimated. For example, the feedback unit can estimate the user's emotions by conducting a survey. Alternatively, the feedback unit can estimate the user's emotions by performing behavioral analysis. For example, if the user is feeling anxious, the feedback unit can provide detailed feedback to reassure them. If the user is relaxed, the feedback unit can provide concise feedback to encourage a quick response. Furthermore, if the user is in a hurry, the feedback unit can provide concise feedback to encourage a quick response. In this way, by adjusting the feedback method based on the user's emotions, more appropriate feedback can be provided. Emotion estimation is achieved using an emotion estimation function, for example, using an emotion engine or generative AI. Generative AI is, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above processing in the feedback unit may be performed using, for example, generative AI, or not using generative AI. For example, the feedback unit can input user emotion data into a generating AI and have the generating AI adjust the feedback method.

[0081] The feedback unit can select the optimal feedback method by referring to past feedback history when providing feedback. It is necessary to clarify the specific content and method of referencing past feedback history. For example, the feedback unit can analyze log data and select feedback for similar situations based on past successful feedback methods. The feedback unit can also prioritize frequently used feedback methods from past feedback history. Furthermore, the feedback unit can analyze past feedback history to explore new feedback methods. This allows for the selection of the optimal feedback method by referring to past feedback history. Some or all of the above processing in the feedback unit may be performed using, for example, a generative AI, or without a generative AI. For example, the feedback unit can input past feedback history data into a generative AI and have the generative AI select the feedback method.

[0082] The feedback unit can customize the feedback content based on the current state of the system when providing feedback. It is necessary to clearly define the specific content and measurement method of the current state. For example, the feedback unit can monitor the system's operational status and security level and provide appropriate feedback based on the current system state. Furthermore, the feedback unit can dynamically adjust the feedback content in response to changes in the system state. In addition, the feedback unit can determine the priority of feedback based on the system state. This allows for the provision of more appropriate feedback by customizing the feedback content based on the current state of the system. Some or all of the above-described processes in the feedback unit may be performed using, for example, a generative AI, or without a generative AI. For example, the feedback unit can input system state data into a generative AI and have the generative AI perform the customization of the feedback content.

[0083] The feedback unit can estimate the user's emotions and prioritize feedback based on those emotions. It is necessary to clarify how the user's emotions are estimated. For example, the feedback unit can estimate user emotions by conducting surveys. Alternatively, it can estimate user emotions through behavioral analysis. For instance, if the user is feeling anxious, the feedback unit can prioritize the most important feedback. If the user is relaxed, it can provide a balanced overall feedback. Furthermore, if the user is in a hurry, it can prioritize feedback that can be addressed quickly. This allows for more effective feedback by prioritizing feedback based on the user's emotions. Emotion estimation is achieved using an emotion estimation function, such as an emotion engine or generative AI. Generative AI includes, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above-described processes in the feedback unit may be performed using, for example, generative AI, or without generative AI. For example, the feedback unit can input user emotion data into a generating AI and have the generating AI determine the priority of the feedback.

[0084] The feedback unit can optimize the feedback method by considering the geographical distribution of the system during the feedback process. The specific details and methods of considering geographical distribution need to be clearly defined. For example, the feedback unit can consider the location of data centers and users, and provide feedback to geographically dispersed systems that takes into account the characteristics of each region. The feedback unit can also provide feedback to geographically concentrated systems to prevent concentrated attacks. Furthermore, the feedback unit can dynamically adjust the feedback method based on geographical distribution. This allows for the provision of an optimal feedback method by considering the geographical distribution of the system. Some or all of the above processing in the feedback unit may be performed using, for example, a generative AI, or without a generative AI. For example, the feedback unit can input geographical distribution data of the system into a generative AI and have the generative AI optimize the feedback method.

[0085] The feedback unit can improve the accuracy of its feedback by referring to relevant system literature during the feedback process. It is necessary to clarify the specific types of relevant literature and how to refer to them. For example, the feedback unit can update its feedback by referring to the latest security research. It can also optimize its feedback by referring to past security incident reports. Furthermore, the feedback unit can strengthen its feedback against specific attacks by referring to relevant system literature. This allows for improved feedback accuracy by referring to relevant system literature. Some or all of the above processing in the feedback unit may be performed using, for example, a generative AI, or without a generative AI. For example, the feedback unit can input relevant literature data into a generative AI and have the generative AI perform the feedback accuracy improvement.

[0086] The system according to the embodiment is not limited to the example described above, and various modifications are possible, for example, as follows.

[0087] The attack unit can analyze real-time user activity logs when searching for system vulnerabilities, prioritizing vulnerability discovery based on user behavior patterns. For example, it can prioritize vulnerability searches for functions and pages that users frequently access. Furthermore, if a specific operation occurs frequently in the user activity logs, it can prioritize vulnerability searches related to that operation. Additionally, by analyzing user activity logs, it can prioritize vulnerability discovery during specific time periods. This allows for more efficient vulnerability discovery based on user behavior patterns.

[0088] When searching for system vulnerabilities, the attack unit can automatically collect system configuration information and prioritize vulnerability discovery based on that information. For example, it can identify specific software versions or settings as vulnerable from the system configuration information and prioritize searching those parts. It can also prioritize searching for vulnerabilities against specific network segments or servers by analyzing the system configuration information. Furthermore, it can prioritize searching for vulnerabilities against specific devices or applications based on the system configuration information. This makes vulnerability discovery more efficient based on system configuration information.

[0089] When exploring for system vulnerabilities, the attack unit can refer to external threat intelligence data and prioritize vulnerability discovery based on the latest threat information. For example, it can obtain the latest attack methods and vulnerability information from external threat intelligence data and use that information to explore for vulnerabilities. Furthermore, by analyzing external threat intelligence data, it can prioritize the exploration of vulnerabilities against methods used by specific attacker groups. In addition, it can prioritize the exploration of vulnerabilities in specific industries or regions based on external threat intelligence data. This makes vulnerability discovery more efficient based on the latest threat information.

[0090] When analyzing attack scenarios, the defense unit can refer to the system's past defense history and prioritize suggesting defense measures that were effective in the past. For example, it can identify defense measures that were effective against a specific attack method from past defense history and prioritize suggesting those measures. Furthermore, by analyzing past defense history, it can also prioritize suggesting defense measures that were effective against a specific system configuration or setting. In addition, based on past defense history, it can prioritize suggesting defense measures that were effective during a specific time period or situation. This makes the suggestion of defense measures based on past defense history more efficient.

[0091] The defense system can simulate the effectiveness of proposed defense measures while considering the system's current operating status and load. For example, if the system is under high load, it can prioritize simulating lighter defense measures. Conversely, if the system is under low load, it can simulate more detailed defense measures. Furthermore, it can dynamically adjust the simulation priority according to the system's operating status and load. This makes the simulation of defense measures more efficient based on the system's operating status and load.

[0092] The feedback unit can estimate the user's emotions when evaluating the effectiveness of protective measures and adjust the evaluation criteria based on those estimated emotions. For example, if the user is feeling anxious, detailed evaluation criteria can be used to assess the effectiveness of protective measures. If the user is relaxed, concise evaluation criteria can be used. Furthermore, if the user is in a hurry, criteria that can be quickly evaluated can be used to assess the effectiveness of protective measures. This makes it possible to streamline the evaluation of protective measures' effectiveness based on the user's emotions.

[0093] The attack unit can estimate the user's emotions and adjust the priority of vulnerability exploration based on those emotions. For example, if the user is feeling anxious, it can prioritize exploring the most serious vulnerabilities. If the user is relaxed, it can explore vulnerabilities in a balanced manner across the board. Furthermore, if the user is in a hurry, it can prioritize exploring vulnerabilities that can be found quickly. By adjusting the priority of vulnerability exploration based on the user's emotions, more effective vulnerability exploration becomes possible.

[0094] The defense system can estimate the user's emotions and adjust how it proposes defense measures based on those emotions. For example, if the user is feeling anxious, it can propose detailed defense measures to provide reassurance. If the user is relaxed, it can propose concise defense measures to encourage a quick response. Furthermore, if the user is in a hurry, it can propose concise defense measures to encourage a quick response. In this way, by adjusting how defense measures are proposed based on the user's emotions, more appropriate defense measures can be suggested.

[0095] The feedback unit can estimate the user's emotions and adjust the feedback method based on those emotions. For example, if the user is feeling anxious, it can provide detailed feedback to reassure them. If the user is relaxed, it can provide concise feedback to encourage a quick response. Furthermore, if the user is in a hurry, it can provide concise feedback to encourage a quick response. In this way, by adjusting the feedback method based on the user's emotions, more appropriate feedback can be provided.

[0096] The defense system can estimate the user's emotions and prioritize defensive measures based on those emotions. For example, if the user is feeling anxious, it can prioritize defensive measures against the most serious attacks. If the user is relaxed, it can suggest a balanced set of defensive measures. Furthermore, if the user is in a hurry, it can prioritize defensive measures that can be implemented quickly. By prioritizing defensive measures based on the user's emotions, it can provide more effective defenses.

[0097] The following briefly describes the processing flow for example form 2.

[0098] Step 1: The attack team explores the system for vulnerabilities. The attack team analyzes each component of the system in detail to identify potential vulnerabilities. For example, outdated software or improper configurations can be identified as vulnerabilities. The attack team also generates attack scenarios based on the identified vulnerabilities. For example, attack scenarios can be generated that include attack methods such as SQL injection or cross-site scripting (XSS). Step 2: The defense unit generates defensive measures based on the attack scenario. The defense unit analyzes the attack scenario and proposes the optimal defensive measures. For example, it may propose measures such as changing firewall settings or updating software. The defense unit also simulates the effectiveness of the proposed defensive measures and evaluates their actual effectiveness. For example, it can test the effectiveness of the defensive measures in a virtual environment and evaluate the results. Step 3: The feedback unit evaluates the effectiveness of the defensive measures and generates new attack scenarios. The feedback unit can evaluate the effectiveness of the defensive measures and generate new attack scenarios based on the results. This allows the penetration testing support system to enhance the security of the system from both offensive and defensive perspectives.

[0099] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[0100] Data generation model 58 is a form of so-called generative AI (Artificial Intelligence). An example of data generation model 58 is ChatGPT (registered trademark) (Internet search).<URL: https: / / openai.com / blog / chatgpt> Examples of generative AI include text generation AI, image generation AI, and multimodal generation AI. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images (e.g., still image data or video data). The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference result in one or more data formats from audio data, text data, and image data. The data generation model 58 includes, for example, text generation AI, image generation AI, and multimodal generation AI. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The specific processing unit 290 performs the specific processing described above using the data generation model 58. The data generation model 58 may be a fine-tuned model that outputs inference results from prompts that do not contain instructions, in which case the data generation model 58 can output inference results from prompts that do not contain instructions. In the data processing device 12, etc., there are multiple types of data generation models 58, and the data generation model 58 includes AI other than generative AI. AI other than generative AI includes, for example, linear regression, logistic regression, decision trees, random forests, support vector machines (SVMs), k-means clustering, convolutional neural networks (CNNs), recurrent neural networks (RNNs), generative adversarial networks (GANs), or naive Bayes, and can perform various processes, but is not limited to these examples. Also, the AI ​​may be an AI agent. Furthermore, when the processing of each of the above parts is performed by the AI, the processing may be performed by the AI ​​in part or in whole, but is not limited to this example.Furthermore, processing performed by AI, including generative AI, may be replaced with rule-based processing, and rule-based processing may be replaced with processing performed by AI, including generative AI.

[0101] Furthermore, the processing performed by the data processing system 10 described above is carried out by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the smart device 14, but it may also be carried out by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the smart device 14. In addition, the specific processing unit 290 of the data processing device 12 acquires or collects information necessary for processing from the smart device 14 or an external device, and the smart device 14 acquires or collects information necessary for processing from the data processing device 12 or an external device.

[0102] Each of the multiple elements described above, including the attack unit, defense unit, and feedback unit, is implemented in at least one of the smart device 14 and the data processing unit 12. For example, the attack unit is implemented by the processor 46 of the smart device 14, which searches for system vulnerabilities and generates attack scenarios. The defense unit is implemented by the specific processing unit 290 of the data processing unit 12, which generates defensive measures based on the attack scenarios and simulates their effectiveness. The feedback unit is implemented by the control unit 46A of the smart device 14, which evaluates the effectiveness of the defensive measures and generates new attack scenarios. The correspondence between each unit and the device or control unit is not limited to the example described above and can be modified in various ways.

[0103] [Second Embodiment] Figure 3 shows an example of the configuration of the data processing system 210 according to the second embodiment.

[0104] As shown in Figure 3, the data processing system 210 includes a data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.

[0105] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN and / or LAN.

[0106] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication interface 44. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, and camera 42 are also connected to the bus 52.

[0107] The microphone 238 receives voice signals from the user and accepts instructions from the user. The microphone 238 captures the voice signals from the user, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.

[0108] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, which captures images of the area around the user (for example, an imaging range defined by a field of view equivalent to the field of vision of a typical healthy person).

[0109] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.

[0110] Figure 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Figure 4, the data processing device 12 performs specific processing by the processor 28. The storage 32 stores the specific processing program 56.

[0111] The processor 28 reads a specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 acting as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.

[0112] Storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotions using the emotion identification model 59 and perform identification processing using the user's emotions. The emotion estimation function (emotion identification function) using the emotion identification model 59 performs various estimations and predictions regarding the user's emotions, including but not limited to these examples. Furthermore, emotion estimation and prediction also include, for example, emotion analysis.

[0113] In the smart glasses 214, specific processing is performed by the processor 46. The storage 50 stores a specific processing program 60. The processor 46 reads the specific processing program 60 from the storage 50 and executes the read specific processing program 60 on the RAM 48. The specific processing is realized by the processor 46 acting as a control unit 46A according to the specific processing program 60 executed on the RAM 48. The smart glasses 214 also have a data generation model 58 and an emotion identification model 59, similar to the data generation model and emotion identification model 59, and can perform processing similar to that of the specific processing unit 290 using these models.

[0114] Furthermore, other devices besides the data processing device 12 may also have the data generation model 58. For example, a server device may have the data generation model 58. In this case, the data processing device 12 obtains processing results (such as prediction results) using the data generation model 58 by communicating with the server device that has the data generation model 58. Also, the data processing device 12 may be a server device or a terminal device owned by the user (for example, a mobile phone, robot, home appliance, etc.).

[0115] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.

[0116] The data generation model 58 is a so-called generative AI. An example of a data generation model 58 is a generative AI such as ChatGPT. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and inference data such as audio data representing speech, text data representing text, and image data representing images (e.g., still image data or video data). The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference result in one or more data formats such as audio data, text data, and image data. The data generation model 58 includes, for example, text generation AI, image generation AI, and multimodal generation AI. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The specific processing unit 290 performs the specific processing described above using the data generation model 58. The data generation model 58 may be a fine-tuned model that outputs inference results from prompts that do not contain instructions, in which case the data generation model 58 can output inference results from prompts that do not contain instructions. In the data processing device 12, etc., there are multiple types of data generation models 58, and the data generation model 58 includes AI other than generative AI. AI other than generative AI includes, for example, linear regression, logistic regression, decision trees, random forests, support vector machines (SVM), k-means clustering, convolutional neural networks (CNN), recurrent neural networks (RNN), generative adversarial networks (GAN), or naive Bayes, and can perform various processes, but is not limited to these examples. Also, the AI ​​may be an AI agent. Furthermore, when the processing of each part described above is performed by the AI, the processing may be performed by the AI ​​in part or in whole, but is not limited to this example. Also, processing performed by an AI including a generative AI may be replaced by rule-based processing, and rule-based processing may be replaced by processing performed by an AI including a generative AI.

[0117] The data processing system 210 according to the second embodiment performs the same processing as the data processing system 10 according to the first embodiment. The processing by the data processing system 210 is performed by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the smart glasses 214, but it may also be performed by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the smart glasses 214. In addition, the specific processing unit 290 of the data processing device 12 acquires or collects information necessary for processing from the smart glasses 214 or an external device, and the smart glasses 214 acquires or collects information necessary for processing from the data processing device 12 or an external device.

[0118] Each of the multiple elements described above, including the attack unit, defense unit, and feedback unit, is implemented in at least one of the smart glasses 214 and the data processing unit 12. For example, the attack unit is implemented by the processor 46 of the smart glasses 214, which searches for system vulnerabilities and generates attack scenarios. The defense unit is implemented by the specific processing unit 290 of the data processing unit 12, which generates defensive measures based on the attack scenarios and simulates their effectiveness. The feedback unit is implemented by the control unit 46A of the smart glasses 214, which evaluates the effectiveness of the defensive measures and generates new attack scenarios. The correspondence between each unit and the device or control unit is not limited to the example described above and can be modified in various ways.

[0119] [Third Embodiment] Figure 5 shows an example of the configuration of the data processing system 310 according to the third embodiment.

[0120] As shown in Figure 5, the data processing system 310 includes a data processing device 12 and a headset terminal 314. An example of the data processing device 12 is a server.

[0121] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN and / or LAN.

[0122] The headset terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a display 343. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and display 343 are also connected to the bus 52.

[0123] The microphone 238 receives voice signals from the user and accepts instructions from the user. The microphone 238 captures the voice signals from the user, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.

[0124] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, which captures images of the area around the user (for example, an imaging range defined by a field of view equivalent to the field of vision of a typical healthy person).

[0125] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.

[0126] Figure 6 shows an example of the main functions of the data processing device 12 and the headset terminal 314. As shown in Figure 6, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.

[0127] The processor 28 reads a specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 acting as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.

[0128] Storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotions using the emotion identification model 59 and perform identification processing using the user's emotions. The emotion estimation function (emotion identification function) using the emotion identification model 59 performs various estimations and predictions regarding the user's emotions, including but not limited to these examples. Furthermore, emotion estimation and prediction also include, for example, emotion analysis.

[0129] In the headset terminal 314, specific processing is performed by the processor 46. The storage 50 stores a specific program 60. The processor 46 reads the specific program 60 from the storage 50 and executes the read specific program 60 on the RAM 48. The specific processing is realized by the processor 46 acting as a control unit 46A according to the specific program 60 executed on the RAM 48. The headset terminal 314 also has a data generation model 58 and an emotion identification model 59, similar to the data generation model and emotion identification model 59, and can perform processing similar to that of the specific processing unit 290 using these models.

[0130] Furthermore, other devices besides the data processing device 12 may also have the data generation model 58. For example, a server device may have the data generation model 58. In this case, the data processing device 12 obtains processing results (such as prediction results) using the data generation model 58 by communicating with the server device that has the data generation model 58. Also, the data processing device 12 may be a server device or a terminal device owned by the user (for example, a mobile phone, robot, home appliance, etc.).

[0131] The specific processing unit 290 transmits the result of the specific processing to the headset terminal 314. In the headset terminal 314, the control unit 46A causes the speaker 240 and display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.

[0132] The data generation model 58 is a so-called generative AI. An example of a data generation model 58 is a generative AI such as ChatGPT. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and inference data such as audio data representing speech, text data representing text, and image data representing images (e.g., still image data or video data). The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference result in one or more data formats such as audio data, text data, and image data. The data generation model 58 includes, for example, text generation AI, image generation AI, and multimodal generation AI. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The specific processing unit 290 performs the specific processing described above using the data generation model 58. The data generation model 58 may be a fine-tuned model that outputs inference results from prompts that do not contain instructions, in which case the data generation model 58 can output inference results from prompts that do not contain instructions. In the data processing device 12, etc., there are multiple types of data generation models 58, and the data generation model 58 includes AI other than generative AI. AI other than generative AI includes, for example, linear regression, logistic regression, decision trees, random forests, support vector machines (SVM), k-means clustering, convolutional neural networks (CNN), recurrent neural networks (RNN), generative adversarial networks (GAN), or naive Bayes, and can perform various processes, but is not limited to these examples. Also, the AI ​​may be an AI agent. Furthermore, when the processing of each part described above is performed by the AI, the processing may be performed by the AI ​​in part or in whole, but is not limited to this example. Also, processing performed by an AI including a generative AI may be replaced by rule-based processing, and rule-based processing may be replaced by processing performed by an AI including a generative AI.

[0133] The data processing system 310 according to the third embodiment performs the same processing as the data processing system 10 according to the first embodiment. The processing by the data processing system 310 is performed by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the headset terminal 314, but may also be performed by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the headset terminal 314. In addition, the specific processing unit 290 of the data processing device 12 acquires or collects information necessary for processing from the headset terminal 314 or an external device, and the headset terminal 314 acquires or collects information necessary for processing from the data processing device 12 or an external device.

[0134] Each of the multiple elements described above, including the attack unit, defense unit, and feedback unit, is implemented in at least one of the headset terminal 314 and the data processing unit 12. For example, the attack unit is implemented by the processor 46 of the headset terminal 314, which searches for system vulnerabilities and generates attack scenarios. The defense unit is implemented by the specific processing unit 290 of the data processing unit 12, which generates defensive measures based on the attack scenarios and simulates their effectiveness. The feedback unit is implemented by the control unit 46A of the headset terminal 314, which evaluates the effectiveness of the defensive measures and generates new attack scenarios. The correspondence between each unit and the device or control unit is not limited to the example described above and can be modified in various ways.

[0135] [Fourth Embodiment] Figure 7 shows an example of the configuration of the data processing system 410 according to the fourth embodiment.

[0136] As shown in Figure 7, the data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.

[0137] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN and / or LAN.

[0138] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a controlled object 443. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and controlled object 443 are also connected to the bus 52.

[0139] The microphone 238 receives voice signals from the user and accepts instructions from the user. The microphone 238 captures the voice signals from the user, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.

[0140] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS image sensor or CCD image sensor, which captures images of the area around the user (for example, an imaging range defined by a field of view equivalent to the field of vision of a typical healthy person).

[0141] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.

[0142] The controlled object 443 includes a display device, LEDs in the eyes, and motors that drive the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the robot 414's emotions can be expressed by controlling these motors. The robot 414's facial expressions can also be expressed by controlling the illumination state of the LEDs in its eyes.

[0143] Figure 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Figure 8, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.

[0144] The processor 28 reads a specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 acting as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.

[0145] Storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotions using the emotion identification model 59 and perform identification processing using the user's emotions. The emotion estimation function (emotion identification function) using the emotion identification model 59 performs various estimations and predictions regarding the user's emotions, including but not limited to these examples. Furthermore, emotion estimation and prediction also include, for example, emotion analysis.

[0146] In robot 414, specific processing is performed by processor 46. A specific program 60 is stored in storage 50. Processor 46 reads the specific program 60 from storage 50 and executes it on RAM 48. The specific processing is achieved by processor 46 acting as a control unit 46A according to the specific program 60 executed on RAM 48. Robot 414 also has data generation model 58 and emotion identification model 59, similar to those of the robot, and can perform processing similar to that of the specific processing unit 290 using these models.

[0147] Furthermore, other devices besides the data processing device 12 may also have the data generation model 58. For example, a server device may have the data generation model 58. In this case, the data processing device 12 obtains processing results (such as prediction results) using the data generation model 58 by communicating with the server device that has the data generation model 58. Also, the data processing device 12 may be a server device or a terminal device owned by the user (for example, a mobile phone, robot, home appliance, etc.).

[0148] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the controlled object 443 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.

[0149] The data generation model 58 is a so-called generative AI. An example of a data generation model 58 is a generative AI such as ChatGPT. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and inference data such as audio data representing speech, text data representing text, and image data representing images (e.g., still image data or video data). The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference result in one or more data formats such as audio data, text data, and image data. The data generation model 58 includes, for example, text generation AI, image generation AI, and multimodal generation AI. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The specific processing unit 290 performs the specific processing described above using the data generation model 58. The data generation model 58 may be a fine-tuned model that outputs inference results from prompts that do not contain instructions, in which case the data generation model 58 can output inference results from prompts that do not contain instructions. In the data processing device 12, etc., there are multiple types of data generation models 58, and the data generation model 58 includes AI other than generative AI. AI other than generative AI includes, for example, linear regression, logistic regression, decision trees, random forests, support vector machines (SVM), k-means clustering, convolutional neural networks (CNN), recurrent neural networks (RNN), generative adversarial networks (GAN), or naive Bayes, and can perform various processes, but is not limited to these examples. Also, the AI ​​may be an AI agent. Furthermore, when the processing of each part described above is performed by the AI, the processing may be performed by the AI ​​in part or in whole, but is not limited to this example. Also, processing performed by an AI including a generative AI may be replaced by rule-based processing, and rule-based processing may be replaced by processing performed by an AI including a generative AI.

[0150] The data processing system 410 according to the fourth embodiment performs the same processing as the data processing system 10 according to the first embodiment. The processing by the data processing system 410 is performed by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the robot 414, but it may also be performed by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the robot 414. In addition, the specific processing unit 290 of the data processing device 12 acquires or collects information necessary for processing from the robot 414 or an external device, and the robot 414 acquires or collects information necessary for processing from the data processing device 12 or an external device.

[0151] Each of the multiple elements described above, including the attack unit, defense unit, and feedback unit, is implemented in at least one of the robot 414 and the data processing unit 12. For example, the attack unit is implemented by the processor 46 of the robot 414, which searches for system vulnerabilities and generates attack scenarios. The defense unit is implemented by the specific processing unit 290 of the data processing unit 12, which generates defensive measures based on the attack scenarios and simulates their effectiveness. The feedback unit is implemented by the control unit 46A of the robot 414, which evaluates the effectiveness of the defensive measures and generates new attack scenarios. The correspondence between each unit and the device or control unit is not limited to the example described above and can be modified in various ways.

[0152] Furthermore, the emotion identification model 59, acting as an emotion engine, may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to a specific mapping, which is an emotion map (see Figure 9). Similarly, the emotion identification model 59 may also determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.

[0153] Figure 9 shows the emotion map 400, in which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. The closer to the center of the concentric circles, the more primitive the emotions are located. Further out of the concentric circles, emotions representing states and actions arising from mental states are located. Emotion is a concept that includes feelings and mental states. On the left side of the concentric circles, emotions that are generally generated from reactions occurring in the brain are located. On the right side of the concentric circles, emotions that are generally induced by situational judgment are located. Above and below the concentric circles, emotions that are generally generated from reactions occurring in the brain and induced by situational judgment are located. In addition, the emotion of "pleasure" is located on the upper side of the concentric circles, and the emotion of "displeasure" is located on the lower side. Thus, in the emotion map 400, multiple emotions are mapped based on the structure in which emotions arise, and emotions that are likely to occur simultaneously are mapped close together.

[0154] These emotions are distributed at the 3 o'clock position on the Emotion Map 400, and usually fluctuate between feelings of security and anxiety. In the right half of the Emotion Map 400, situational awareness takes precedence over internal feelings, resulting in a calm impression.

[0155] The inside of the Emotion Map 400 represents inner thoughts, while the outside represents actions. Therefore, the further you go from the outside of the Emotion Map 400, the more visible (expressed in actions) your emotions become.

[0156] Here, human emotions are based on various balances, such as posture and blood sugar levels. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. Similarly, in robots, cars, and motorcycles, emotions can be created based on various balances, such as posture and battery level. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. The emotion map can be generated based, for example, on Dr. Mitsuyoshi's emotion map (Research on a system for analyzing brain physiological signals of speech emotion recognition and emotion, Tokushima University, doctoral dissertation: https: / / ci.nii.ac.jp / naid / 500000375379). The left half of the emotion map contains emotions belonging to a region called "response," where sensation is dominant. The right half of the emotion map contains emotions belonging to a region called "situation," where situational awareness is dominant.

[0157] The emotion map defines two emotions that promote learning. One is the emotion around the middle of the negative "repentance" and "reflection" on the situation side. In other words, it is when the robot experiences negative emotions such as "I never want to feel this way again" or "I don't want to be scolded again." The other is the emotion around the positive "desire" on the reaction side. In other words, it is when the robot has positive feelings such as "I want more" or "I want to know more."

[0158] The emotion identification model 59 inputs user input into a pre-trained neural network, obtains emotion values ​​representing each emotion shown in the emotion map 400, and determines the user's emotion. This neural network is pre-trained based on multiple training data sets, which are combinations of user input and emotion values ​​representing each emotion shown in the emotion map 400. Furthermore, this neural network is trained so that emotions located close together have similar values, as shown in the emotion map 900 in Figure 10. Figure 10 shows an example where multiple emotions such as "reassured," "calm," and "confident" have similar emotion values.

[0159] In the above embodiment, an example was given in which a specific process is performed by a single computer 22. However, the technology of this disclosure is not limited thereto, and a distributed processing method for the specific process may be used, which includes computer 22 and multiple other computers.

[0160] In the above embodiment, an example was given in which the specific processing program 56 is stored in the storage 32, but the technology of this disclosure is not limited thereto. For example, the specific processing program 56 may be stored in a portable, computer-readable, non-temporary storage medium such as a USB (Universal Serial Bus) memory. The specific processing program 56 stored in the non-temporary storage medium is installed in the computer 22 of the data processing device 12. The processor 28 executes specific processing according to the specific processing program 56.

[0161] Alternatively, the specific processing program 56 may be stored in a storage device such as a server connected to the data processing device 12 via the network 54, and the specific processing program 56 may be downloaded and installed on the computer 22 in response to a request from the data processing device 12.

[0162] Furthermore, it is not necessary to store the entirety of the specific processing program 56 in a storage device such as a server connected to the data processing device 12 via the network 54, or to store the entirety of the specific processing program 56 in the storage 32; it is acceptable to store only a portion of the specific processing program 56.

[0163] The following types of processors can be used as hardware resources to perform specific processing. Examples of processors include a CPU, a general-purpose processor that functions as a hardware resource to perform specific processing by executing software, i.e., a program. Other examples of processors include dedicated electrical circuits, such as FPGAs (Field-Programmable Gate Arrays), PLDs (Programmable Logic Devices), or ASICs (Application Specific Integrated Circuits), which have circuit configurations specifically designed to perform specific processing. All of these processors have built-in or connected memory, and all of them perform specific processing by using memory.

[0164] The hardware resource that performs a specific process may consist of one of these various processors, or it may consist of a combination of two or more processors of the same or different types (for example, a combination of multiple FPGAs, or a combination of a CPU and an FPGA). Alternatively, the hardware resource that performs a specific process may consist of a single processor.

[0165] Examples of configurations using a single processor include, firstly, a configuration in which one or more CPUs and software are combined to form a single processor, and this processor functions as a hardware resource that performs a specific process. Secondly, there is a configuration using a processor that realizes the functions of the entire system, including multiple hardware resources that perform a specific process, on a single IC chip, as exemplified by SoCs (System-on-a-chip). In this way, a specific process is realized using one or more of the above types of processors as hardware resources.

[0166] Furthermore, the hardware structure of these various processors can more specifically utilize electrical circuits that combine circuit elements such as semiconductor devices. Also, the specific processing described above is merely an example. Therefore, it goes without saying that unnecessary steps can be deleted, new steps added, or the processing order rearranged, as long as it does not deviate from the main purpose.

[0167] Furthermore, although the above-described examples were divided into four embodiments, some or all of these embodiments may be combined. Also, the smart device 14, smart glasses 214, headset terminal 314, and robot 414 are just examples, and they may be combined, or other devices may be used. Also, although the above-described examples were divided into two embodiments, Embodiment 1 and Embodiment 2, these may be combined.

[0168] The descriptions and illustrations presented above are detailed explanations of the technical aspects of this disclosure and are merely examples of the technical aspects. For example, the above descriptions of the structure, function, operation, and effect are examples of the structure, function, operation, and effect of the technical aspects of this disclosure. Therefore, it goes without saying that you may delete unnecessary parts, add new elements, or replace elements in the descriptions and illustrations presented above, as long as you do not deviate from the essence of the technical aspects of this disclosure. Furthermore, in order to avoid confusion and facilitate understanding of the technical aspects of this disclosure, explanations of common technical knowledge and other things that do not require special explanation to enable the implementation of the technical aspects of this disclosure have been omitted from the descriptions and illustrations presented above.

[0169] All documents, patent applications, and technical standards described herein are incorporated by reference to the same extent as if each individual document, patent application, and technical standard were specifically and individually noted to be incorporated by reference.

[0170] (Note 1) The attack team searches for vulnerabilities in the system, A defense unit that generates a defense strategy based on an attack scenario generated by the aforementioned attack unit, The system includes a feedback unit that evaluates the effectiveness of the defensive measures generated by the defense unit and generates a new attack scenario. A system characterized by the following features. (Note 2) The aforementioned attack unit, Analyze each component of the system in detail and identify potential vulnerabilities. The system described in Appendix 1, characterized by the features described herein. (Note 3) The aforementioned attack unit, Generate attack scenarios based on identified vulnerabilities. The system described in Appendix 1, characterized by the features described herein. (Note 4) The aforementioned protective section is We analyze attack scenarios and propose appropriate defensive measures. The system described in Appendix 1, characterized by the features described herein. (Note 5) The aforementioned protective section is Simulate the effectiveness of the proposed defensive measures and evaluate their actual effects. The system described in Appendix 1, characterized by the features described herein. (Note 6) The aforementioned feedback unit is Evaluate the effectiveness of defensive measures and generate new attack scenarios. The system described in Appendix 1, characterized by the features described herein. (Note 7) The aforementioned attack unit, It estimates user sentiment and adjusts vulnerability exploration priorities based on the estimated user sentiment. The system described in Appendix 1, characterized by the features described herein. (Note 8) The aforementioned attack unit, Analyze the system's past attack history and select the most effective vulnerability detection method. The system described in Appendix 1, characterized by the features described herein. (Note 9) The aforementioned attack unit, During vulnerability scanning, the scanning method is adjusted based on the system's operating status and load. The system described in Appendix 1, characterized by the features described herein. (Note 10) The aforementioned attack unit, We estimate user sentiment and adjust vulnerability reporting methods based on the estimated user sentiment. The system described in Appendix 1, characterized by the features described herein. (Note 11) The aforementioned attack unit, When searching for vulnerabilities, adjust the search methodology to take into account the geographical distribution of the system. The system described in Appendix 1, characterized by the features described herein. (Note 12) The aforementioned attack unit, When searching for vulnerabilities, refer to relevant system documentation to improve the accuracy of the search. The system described in Appendix 1, characterized by the features described herein. (Note 13) The aforementioned protective section is It estimates the user's emotions and adjusts the method of suggesting defensive measures based on the estimated user emotions. The system described in Appendix 1, characterized by the features described herein. (Note 14) The aforementioned protective section is When generating defensive measures, the system selects the optimal measures by referring to past defensive history. The system described in Appendix 1, characterized by the features described herein. (Note 15) The aforementioned protective section is When generating defenses, customize the defenses based on the system's current security policy. The system described in Appendix 1, characterized by the features described herein. (Note 16) The aforementioned protective section is It estimates the user's emotions and determines the priority of defensive measures based on the estimated user emotions. The system described in Appendix 1, characterized by the features described herein. (Note 17) The aforementioned protective section is When generating defense strategies, optimize them by considering the geographical distribution of the system. The system described in Appendix 1, characterized by the features described herein. (Note 18) The aforementioned protective section is When generating defensive measures, we improve the accuracy of those measures by referring to relevant system documentation. The system described in Appendix 1, characterized by the features described herein. (Note 19) The aforementioned feedback unit is It estimates the user's emotions and adjusts the feedback method based on the estimated user emotions. The system described in Appendix 1, characterized by the features described herein. (Note 20) The aforementioned feedback unit is When providing feedback, refer to past feedback history to select the most suitable feedback method. The system described in Appendix 1, characterized by the features described herein. (Note 21) The aforementioned feedback unit is When providing feedback, customize the feedback content based on the current state of the system. The system described in Appendix 1, characterized by the features described herein. (Note 22) The aforementioned feedback unit is It estimates the user's emotions and prioritizes feedback based on those estimated emotions. The system described in Appendix 1, characterized by the features described herein. (Note 23) The aforementioned feedback unit is When providing feedback, optimize the feedback method by considering the geographical distribution of the system. The system described in Appendix 1, characterized by the features described herein. (Note 24) The aforementioned feedback unit is When providing feedback, we refer to relevant system documentation to improve the accuracy of the feedback. The system described in Appendix 1, characterized by the features described herein. [Explanation of symbols]

[0171] 10, 210, 310, 410 Data Processing Systems 12 Data Processing Devices 14 Smart Devices 214 Smart Glasses 314 Headset-type terminal 414 Robots

Claims

1. The attack team searches for vulnerabilities in the system, A defense unit that generates a defense strategy based on an attack scenario generated by the aforementioned attack unit, The system includes a feedback unit that evaluates the effectiveness of the defensive measures generated by the defense unit and generates a new attack scenario. A system characterized by the following features.

2. The aforementioned attack unit, Generate attack scenarios based on identified vulnerabilities. The system according to feature 1.

3. The aforementioned protective section is Simulate the effectiveness of the proposed defensive measures and evaluate their actual effects. The system according to feature 1.

4. The aforementioned feedback unit is Evaluate the effectiveness of defensive measures and generate new attack scenarios. The system according to feature 1.

5. The aforementioned attack unit, It estimates user sentiment and adjusts vulnerability exploration priorities based on the estimated user sentiment. The system according to feature 1.

6. The aforementioned attack unit, Analyze the system's past attack history and select the most effective vulnerability detection method. The system according to feature 1.

Citation Information

Patent Citations

  • Security management system, security management method, and program

    JP2005228177A

  • Vulnerability risk evaluation system and method

    JP2017224053A

  • On-vehicle device and incident monitoring method

    JP2019133599A

  • Attack scenario simulation device, attack scenario generation system, and attack scenario generation method

    JP2022033570A

  • Persona chatbot control method and system

    JP2022180282A