Information security processing device and system
Patent Information
- Application Number
- TW115206316
- Authority / Receiving Office
- TW · TW
- Patent Type
- Utility models
- Current Assignee / Owner
- Filing Date
- 2026-07-06
- Publication Date
- 2026-09-11
- Estimated Expiration
- 2036-07-05
Smart Images

Figure TWG2TB001911372_001 
Figure TWG2TB001911372_002 
Figure TWG2TB001911372_003
Abstract
Claims
1. An information security processing device, deployed in a serverless execution environment provided by a cloud computing platform, comprising: a motherboard disposed within a chassis; a memory disposed on the motherboard and configured to store a plurality of program instructions; a network card disposed on the motherboard and configured to periodically receive a plurality of cybersecurity event data transmitted by a plurality of heterogeneous endpoint detection and response systems; and a processor unit disposed on the motherboard and electrically connected to the memory and the network card, configured to execute the plurality of program instructions to analyze the plurality of cybersecurity event data; wherein, The processor unit includes: a data standardization circuit configured to perform data standardization processing on the plurality of cybersecurity incident data according to a unified data model to generate standardized data; a risk analysis circuit configured to perform threat analysis and risk assessment on the standardized data using a generative artificial intelligence model to generate a corresponding threat type and a risk level; and an automation control circuit configured to generate an automation script based on the threat type and the risk level using the generative artificial intelligence model to execute a cybersecurity incident response operation, and to establish a work order corresponding to the cybersecurity incident and integrate the work order into a work order system.
2. The information security processing apparatus as described in claim 1, wherein the processor unit further includes an orchestrator configured to control the execution order of a plurality of artificial intelligence agents, the plurality of artificial intelligence agents including a classification agent, a context reinforcement agent, a threat reasoning agent, a cross-source association agent, a response planning agent and a review agent.
3. The information security processing apparatus as described in claim 2, wherein the risk analysis circuit is further configured to perform the classification agent, the context reinforcement agent, the threat inference agent, and the cross-source association agent, and the automation control circuit is further configured to perform the action planning agent and the review agent.
4. The information security processing apparatus as described in claim 1, further comprising: a display electrically connected to the processor unit and configured to display a web-based user interface, the web-based user interface including a monitoring dashboard and a custom configuration panel, the monitoring dashboard being configured to display the information security incident data, the threat type, and the risk level, and the custom configuration panel being configured to provide customized alarm rule settings and script management functions.
5. The information security processing apparatus as described in claim 1, wherein the processor unit is further configured to execute an information security processing system, the information security processing system adopting a layered architecture design, the layered architecture including a front-end presentation layer, an API service layer, a data processing layer and an integration interface layer.
6. An information security processing system, deployed in a serverless execution environment provided by a cloud computing platform, comprising: a data standardization module configured to periodically receive a plurality of cybersecurity event data transmitted by a plurality of heterogeneous endpoint detection and response systems, and perform data standardization processing on the plurality of cybersecurity event data according to a unified data model to generate standardized data; a risk analysis module electrically connected to the data standardization module, configured to perform threat analysis and risk assessment on the standardized data using a plurality of artificial intelligence agents and a generative artificial intelligence model to generate a corresponding threat type and a risk level; and an automation control module electrically connected to the risk analysis module, configured to generate and execute an automation script according to the threat type and the risk level to perform a cybersecurity event response operation, and establish a work order corresponding to the cybersecurity event and integrate the work order into a work order system.
7. The information security processing system as described in claim 6, further comprising an orchestrator configured to control the execution order of the plurality of artificial intelligence agents, the plurality of artificial intelligence agents including a classification agent, a context reinforcement agent, a threat reasoning agent, a cross-source association agent, a disposition planning agent and a review agent.
8. The information security processing system as described in claim 7, wherein the risk analysis module is further configured to execute the classification agent, the context reinforcement agent, the threat inference agent, and the cross-source association agent, and the automation control module is further configured to execute the action planning agent and the review agent.
9. The information security processing system as described in claim 6, further comprising: a front-end display module electrically connected to the risk analysis module and the automation control module, configured to provide a web-based user interface, the web-based user interface including a monitoring dashboard and a customized configuration panel, the monitoring dashboard being configured to display the information security incident data, the threat type, and the risk level, and the customized configuration panel being configured to provide customized alarm rule settings and script management functions.
10. The information security processing system as described in claim 6, wherein the information security processing system adopts a layered architecture design, the layered architecture including a front-end presentation layer, an API service layer, a data processing layer and an integration interface layer.