Electronic device for calculating risk of event occurring in target device and operation method thereof

The electronic device addresses imprecise risk assessments by analyzing event data and device status to provide a comprehensive risk evaluation, facilitating timely preventive measures.

WO2026155521A1PCT designated stage Publication Date: 2026-07-23AHNLAB INC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
AHNLAB INC
Filing Date
2026-01-13
Publication Date
2026-07-23

AI Technical Summary

Technical Problem

Existing risk assessment systems fail to comprehensively evaluate the impact of device events due to a lack of consideration for the correlation between event types and device status, leading to imprecise risk evaluations.

Method used

An electronic device that calculates the risk level by analyzing event data, considering the type and frequency of events, and incorporating device status information, including communication status, operation time, load, and user interaction, to provide a comprehensive risk assessment.

Benefits of technology

Enables precise risk level calculation, allowing for early identification of potential device risks and enabling appropriate preventive measures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2026000731_23072026_PF_FP_ABST
    Figure KR2026000731_23072026_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed are an electronic device and an operation method thereof. The electronic device according to the present disclosure comprises: a memory for storing at least one instruction; and a processor connected to the memory and capable of executing the at least one instruction, wherein the processor may, when an event for a target device is identified, calculate the degree of influence of the identified event on the target device on the basis of the type and frequency of the identified event, acquire state information of the target device corresponding to the identified event, and acquire the risk of the identified event on the basis of the calculated degree of influence and the acquired state information.
Need to check novelty before this filing date? Find Prior Art

Description

Electronic device for calculating the risk level of an event occurring in a target device and a method of operation thereof

[0001] The present disclosure relates to a technology for evaluating the risk level of a target device by analyzing event data and device status information, and more specifically, to an electronic device that calculates the risk level by comprehensively considering the type and frequency of events and the device status.

[0002] With the advancement of communication and network technologies, various systems have been developed that can manage personal information, user information, and the like on servers.

[0003] User terminal devices such as smartphones and tablet PCs have become widely available, and multiple user terminals can individually establish communication connections with a server to transmit various information requests to the server, and provide visual and auditory information to users based on the information received from the server.

[0004] Electronic devices are exposed to events occurring in various environments, and these events can affect the device's performance, stability, and security. Evaluating the risk level of a device based on event data can provide important information for identifying problems in advance and taking appropriate measures.

[0005] The type and frequency of events are important indicators of their impact on a device. Furthermore, status information of the target device is necessary to analyze vulnerabilities caused by events and to assess the severity of potential problems. Existing risk assessment systems often focus merely on whether events occur or analyze device status information individually, making it difficult to conduct a comprehensive and precise evaluation.

[0006] Existing technologies primarily involved collecting basic logs when device events occurred or providing simple warnings based on predefined rules, but this had limitations in that it could not consider the correlation between complex events and device status.

[0007] The present invention provides an electronic device capable of analyzing event data regarding a target device, calculating the impact on the device based on the type and frequency of events, and evaluating the risk level by comprehensively considering device status information. This enables the early identification of potential risks to the target device and allows for appropriate preventive measures.

[0008] The purposes of the present disclosure are not limited to those mentioned above, and other purposes and advantages of the present disclosure not mentioned may be understood from the following description and will be more clearly understood by the embodiments of the present disclosure. Furthermore, it will be readily apparent that the purposes and advantages of the present disclosure can be realized by the means and combinations thereof set forth in the claims.

[0009] An electronic device according to one embodiment of the present disclosure may include a memory for storing at least one instruction and a processor connected to the memory and capable of executing the at least one instruction. When an event regarding a target device is identified, the processor may calculate the degree of impact of the identified event on the target device based on the type and frequency of the identified event, obtain state information of the target device corresponding to the identified event, and obtain the risk level of the identified event based on the calculated degree of impact and the obtained state information.

[0010] The above status information may include at least one of the communication status, operation time, load, and user interaction with the target device.

[0011] The processor can update the risk level of the event based on user interaction information regarding the target device associated with the identified event.

[0012] The processor can input the identified event information into an interaction prediction model to obtain prediction information regarding user interaction with the target device following the identified event, and update the risk level of the identified event based on the obtained prediction information.

[0013] The above prediction model can be learned based on the history information of the identified event and the user interaction with the target device that followed the identified event.

[0014] The above target device may include a plurality of devices, and the processor may identify at least one event for each of the plurality of devices.

[0015] A method of operating an electronic device according to one embodiment of the present disclosure may include, when an event regarding a target device is identified, an operation of calculating the degree of influence of the identified event on the target device based on the type and frequency of the identified event; an operation of obtaining state information of the target device corresponding to the identified event; and an operation of obtaining the risk level of the identified event based on the calculated degree of influence and the obtained state information.

[0016] A non-transient computer-readable recording medium according to one embodiment of the present disclosure may store at least one instruction that is executed by a processor of an electronic device to perform a method of operation of the electronic device.

[0017] Through the present invention, the impact of events on a target device can be precisely calculated based on the type and frequency of events occurring in the target device. Furthermore, by evaluating the overall risk level by additionally considering the status information of the target device, the stability of the device can be maintained and potential problems can be prevented.

[0018] Aspects, features, and advantages of specific embodiments of the present disclosure will become more apparent from the following description with reference to the accompanying drawings.

[0019] FIG. 1 is a system diagram illustrating an electronic device and a target device according to one embodiment of the present disclosure.

[0020] FIG. 2 is a block diagram for explaining the configuration of an electronic device according to one embodiment of the present disclosure.

[0021] FIG. 3 is a flowchart for explaining the operation of an electronic device according to one embodiment of the present disclosure.

[0022] FIG. 4 is a block diagram for explaining state information of a target device according to one embodiment of the present disclosure.

[0023] FIG. 5 is a block diagram illustrating a process for obtaining predicted information on user interaction for a target device following an event using an interaction prediction model according to one embodiment of the present disclosure.

[0024] The embodiments are subject to various modifications and may have various forms; therefore, specific embodiments are illustrated in the drawings and described in detail. However, this is not intended to limit the scope of specific embodiments and should be understood to include various modifications, equivalents, and / or alternatives of the embodiments of the present disclosure. In relation to the description of the drawings, similar reference numerals may be used for similar components.

[0025] In describing the present disclosure, if it is determined that a detailed description of related known functions or configurations could unnecessarily obscure the essence of the present disclosure, such detailed description is omitted.

[0026] Additionally, the following embodiments may be modified in various other forms, and the scope of the technical concept of the present disclosure is not limited to the following embodiments. Rather, these embodiments are provided to make the present disclosure more faithful and complete and to fully convey the technical concept of the present disclosure to those skilled in the art.

[0027] The terms used in this disclosure are used merely to describe specific embodiments and are not intended to limit the scope of the rights. The singular expression includes the plural expression unless the context clearly indicates otherwise.

[0028] In the present disclosure, expressions such as “have,” “may have,” “include,” or “may include” indicate the presence of such features (e.g., numerical values, functions, actions, or components such as parts) and do not exclude the presence of additional features.

[0029] In the present disclosure, expressions such as “A or B,” “at least one of A or / and B,” or “one or more of A or / and B” may include all possible combinations of items listed together. For example, “A or B,” “at least one of A and B,” or “at least one of A or B” may refer to cases including (1) at least one A, (2) at least one B, or (3) both at least one A and at least one B.

[0030] Expressions such as "first," "second," "first," or "second" used in this disclosure may modify various components regardless of order and / or importance, and are used only to distinguish one component from another and do not limit said components.

[0031] Where it is stated that a component (e.g., Component 1) is "(operatively or communicatively) coupled with / to" or "connected to" another component (e.g., Component 2), it should be understood that the component may be directly connected to the other component or connected through the other component (e.g., Component 3).

[0032] On the other hand, when it is stated that a certain component (e.g., a first component) is "directly connected" or "directly coupled" to another component (e.g., a second component), it may be understood that no other component (e.g., a third component) exists between the certain component and the other component.

[0033] As used in this disclosure, the expression “configured to” may be replaced, depending on the context, with, for example, “suitable for,” “having the capacity to,” “designed to,” “adapted to,” “made to,” or “capable of.” The term “configured to” does not mean only “specifically designed to” in hardware.

[0034] Instead, in some situations, the expression “device configured to do something” may mean that the device is “capable of doing something” together with other devices or components. For example, the phrase “processor configured (or set) to perform A, B, and C” may mean a dedicated processor for performing those operations (e.g., an embedded processor), or a generic-purpose processor (e.g., a CPU or application processor) capable of performing those operations by executing one or more software programs stored in a memory device.

[0035] In the embodiments, a 'module' or 'part' performs at least one function or operation and may be implemented in hardware or software, or a combination of hardware and software. Additionally, a plurality of 'modules' or a plurality of 'parts' may be integrated into at least one module and implemented by at least one processor, except for a 'module' or 'part' that needs to be implemented in specific hardware.

[0036] Meanwhile, the various elements and areas in the drawings are depicted schematically. Accordingly, the technical concept of the present invention is not limited by the relative sizes or spacing depicted in the attached drawings.

[0037] Hereinafter, embodiments according to the present disclosure are described in detail with reference to the attached drawings so that those skilled in the art can easily implement them.

[0038] An electronic device may be a computing device capable of performing operations, processing, and handling operations on data, information, and signals.

[0039] The electronic device may be a computing device capable of performing an operation to calculate the risk level of an event that occurred in the target device.

[0040] FIG. 1 is a system diagram illustrating an electronic device and a target device according to one embodiment of the present disclosure.

[0041] Referring to FIG. 1, the electronic device (100) may be a server, for example, a computer that provides services to a client over a network. The server may be an FTP server, a web server, a database server, or a cloud server, and the server may be built with an operating system such as Linux.

[0042] A server may include multiple different functions and is not necessarily a single device; instead, each function may be implemented across multiple devices.

[0043] The target device (200) may be a user terminal device. The user terminal device may include, for example, at least one of a smartphone, a tablet PC, a laptop PC, a netbook computer, a mobile device, and a wearable device, but is not limited thereto.

[0044] However, not limited thereto, the electronic device (100) may be a user terminal device in addition to a server, and the target device (200) may also be a server in addition to a user terminal device.

[0045] An electronic device (100) according to one embodiment of the present disclosure is not limited to the above-described device, and the electronic device (100) may be implemented as an electronic device (100) having two or more functions of the above-described devices.

[0046] FIG. 2 is a block diagram for explaining the configuration of an electronic device (100) according to one embodiment of the present disclosure.

[0047] Referring to FIG. 2, the electronic device (100) may include a communication interface (110), a memory (120), and a processor (130). However, the configuration of the electronic device (100) is not limited thereto and may be configured with some configurations omitted or other additional configurations added.

[0048] The communication interface (110) may include a wireless communication interface (110), a wired communication interface (110), or an input interface. The wireless communication interface (110) may communicate with various external devices using wireless communication technology or mobile communication technology. Such wireless communication technologies may include, for example, Bluetooth, Bluetooth Low Energy, CAN communication, Wi-Fi, Wi-Fi Direct, ultrawide band (UWB), Zigbee, infrared data association (IrDA), or near field communication (NFC), and mobile communication technologies may include 3GPP, Wi-Max, LTE (Long Term Evolution), 5G, etc.

[0049] The wireless communication interface (110) can be implemented using an antenna, a communication chip, a substrate, etc., capable of transmitting electromagnetic waves to the outside or receiving electromagnetic waves transmitted from the outside.

[0050] The wired communication interface (110) can communicate with various devices based on a wired communication network. Here, the wired communication network can be implemented using physical cables, such as, for example, a pair cable, a coaxial cable, a fiber optic cable, or an Ethernet cable.

[0051] Depending on the embodiment, either the wireless communication interface (110) or the wired communication interface (110) may be omitted. Accordingly, the electronic device (100) may include only the wireless communication interface (110) or only the wired communication interface (110). In addition, the electronic device (100) may be equipped with an integrated communication interface (110) that supports both wireless connection via the wireless communication interface (110) and wired connection via the wired communication interface (110).

[0052] The electronic device (100) is not limited to having one communication interface (110) that performs a communication connection in one manner, but may include a plurality of communication interfaces (110) that perform communication connections in multiple manners.

[0053] The processor (130) can receive status information (20) of the target device (200), event information (31) that occurred in the target device (200), etc. from the target device (200) through the communication interface (110).

[0054] The processor (130) can transmit risk information of an event corresponding to the target device (200) to an external device (target device (200) or server) through a communication interface (110).

[0055] In addition, the processor (130) can transmit or receive various information through the communication interface (110).

[0056] The memory (120) stores various programs or data temporarily or non-temporarily and transmits the stored information to the processor (130) upon the call of the processor (130). Additionally, the memory (120) can store various information required for the operation, processing, or control operation of the processor (130) in an electronic format.

[0057] The memory (120) may include, for example, at least one of a main memory and an auxiliary memory. The main memory may be implemented using a semiconductor storage medium such as ROM and / or RAM. The ROM may include, for example, a conventional ROM, EPROM, EEPROM and / or MASK-ROM. The RAM may include, for example, a DRAM and / or SRAM. The auxiliary memory may be implemented using at least one storage medium capable of storing data permanently or semi-permanently, such as a flash memory (120) device, an SD (Secure Digital) card, a solid state drive (SSD), a hard disk drive (HDD), an optical recording medium such as a magnetic drum, a compact disc (CD), a DVD, or a laser disc, a magnetic tape, a magneto-optical disc and / or a floppy disk.

[0058] The memory (120) can store state information (20) of the target device (200), for example, the communication status (21) of the target device (200), the operation time (22), the load (23), and user interaction information for the target device (200).

[0059] The memory (120) can store information about events (31) that occurred in the target device (200), for example, information about the type and frequency of the events.

[0060] The memory (120) can store user interaction information for the target device (200) that follows the event.

[0061] The memory (120) can store an interaction prediction model (30) that outputs user interaction information for a target device (200) following an event. The memory (120) can store user interaction prediction information (32) for a target device (200).

[0062] The processor (130) controls the overall operation of the electronic device (100). Specifically, the processor (130) is connected to the configuration of the electronic device (100) including the memory (120) as described above, and can control the overall operation of the electronic device (100) by executing at least one instruction stored in the memory (120) as described above. In particular, the processor (130) can be implemented as a single processor (130) as well as as a plurality of processors (130).

[0063] The processor (130) may be implemented in various ways. For example, one or more processors (130) may include one or more of a CPU (Central Processing Unit), GPU (Graphics Processing Unit), APU (Accelerated Processing Unit), MIC (Many Integrated Core), DSP (Digital Signal Processor), NPU (Neural Processing Unit), hardware accelerator, or machine learning accelerator. One or more processors (130) may control one or any combination of other components of the electronic device (100) and may perform operations or data processing related to communication. One or more processors (130) may execute one or more programs or instructions stored in memory (120). For example, one or more processors (130) may perform a method according to one embodiment of the present disclosure by executing one or more instructions stored in memory (120).

[0064] In the case where a method according to one embodiment of the present disclosure includes a plurality of operations, the plurality of operations may be performed by a single processor (130) or by a plurality of processors (130). For example, when a first operation, a second operation, and a third operation are performed by a method according to one embodiment, the first operation, the second operation, and the third operation may all be performed by a first processor (130), or the first operation and the second operation may be performed by a first processor (130) (e.g., a general-purpose processor (130)) and the third operation may be performed by a second processor (130) (e.g., an artificial intelligence dedicated processor (130)).

[0065] One or more processors (130) may be implemented as a single-core processor (130) including one core, or as one or more multi-core processors (130) including multiple cores (e.g., homogeneous multi-core or heterogeneous multi-core). When one or more processors (130) are implemented as multi-core processors (130), each of the multiple cores included in the multi-core processor (130) may include internal memory (120) of the processor (130), such as on-chip memory (120), and a common cache shared by the multiple cores may be included in the multi-core processor (130). Additionally, each of the multiple cores (or some of the multiple cores) included in the multi-core processor (130) may independently read and execute program instructions for implementing a method according to one embodiment of the present disclosure, or all (or some) of the multiple cores may be linked together to read and execute program instructions for implementing a method according to one embodiment of the present disclosure.

[0066] When a method according to one embodiment of the present disclosure includes a plurality of operations, the plurality of operations may be performed by one of the plurality of cores included in the multi-core processor (130), or may be performed by a plurality of cores. For example, when a first operation, a second operation, and a third operation are performed by a method according to one embodiment, the first operation, the second operation, and the third operation may all be performed by a first core included in the multi-core processor (130), or the first operation and the second operation may be performed by a first core included in the multi-core processor (130) and the third operation may be performed by a second core included in the multi-core processor (130).

[0067] In embodiments of the present disclosure, the processor (130) may mean a system-on-chip (SoC) in which one or more processors (130) and other electronic components are integrated, a single-core processor (130), a multi-core processor (130), or a core included in a single-core processor (130) or a multi-core processor (130), wherein the core may be implemented as a CPU, GPU, APU, MIC, DSP, NPU, hardware accelerator or machine learning accelerator, etc., but the embodiments of the present disclosure are not limited thereto.

[0068] The processor (130) can obtain the risk level of an event that occurred in the target device (200) based on the event for the target device (200) and the state information (20) of the target device (200).

[0069] A more specific control operation of the electronic device (100) of the processor (130) is explained together with FIGS. 3 to 5.

[0070] FIG. 3 is a flowchart for explaining the operation of an electronic device (100) according to one embodiment of the present disclosure.

[0071] Referring to FIG. 3, when an event regarding a target device (200) is identified, the processor (130) can calculate the degree of impact on the target device (200) based on the type and frequency of the event (S10).

[0072] For example, the types of events may include various forms such as external security threats, hacking attempts, device overheating, voltage fluctuations, and network failures.

[0073] The frequency of an event indicates how often a specific event occurs, and this serves as an important indicator for evaluating the impact on the stability of the device.

[0074] The processor (130) can analyze the possibility of performance degradation or failure of the device by combining event type and frequency data.

[0075] The processor (130) can calculate the degree of influence as a larger value when the event occurring in the target device (200) is related to the power on / off or information security of the target device (200), and as a smaller value when the event is related to the power on / off or information security of the target device (200).

[0076] According to various embodiments, the target device (200) may include a plurality of devices, and the processor (130) may identify at least one event for each of the plurality of devices. Here, the plurality of devices may be a set of devices that perform different functions or operate in different environments, and examples may include a smart home lighting system, a heating and cooling system, a security camera, etc.

[0077] The processor (130) can individually monitor and identify events that occur for each device. For example, it can identify an event of increased power consumption in a lighting system, a temperature change event in a heating and cooling system, and a motion detection event in a security camera. This allows for effective management of the status of each device and supports integrated operation of the entire system.

[0078] The processor (130) can obtain state information (20) of the target device (200) corresponding to the event (S20).

[0079] FIG. 4 is a block diagram for explaining state information (20) of a target device (200) according to one embodiment of the present disclosure.

[0080] Referring to FIG. 4, the status information (20) of the target device (200) may include information regarding the communication status (21) of the target device (200), the operation time (22), the load (23), and the user interaction (first user interaction information) (24) for the target device (200).

[0081] Here, the first user interaction information (24) may refer to user input to the target device (200) up to the point in time when an event occurs to the target device (200), but is not limited thereto, and includes data on how the user interacted with the device, for example, the first user interaction information (24) may include numerical values ​​entered by the user, user operations, user input, user control commands, etc.

[0082] The processor (130) can obtain the risk level of an event by combining the calculated degree of impact and the acquired state information (20). The risk level may be a score corresponding to the degree of risk and indicates the severity of the problem that the device may experience due to the event.

[0083] For example, the processor (130) can calculate a risk level as high as the frequency of security threats, hacking attempts, and intrusion attempts against the target device (200) increases.

[0084] In addition, the processor (130) can calculate a higher risk as the frequency of overheating events, in which the temperature of the target device (200) is close to a pre-set difference from the critical temperature, increases, and can calculate a higher risk as the frequency of fluctuation events of the circuit constituting the target device (200) or the voltage supplied to the target device (200) increases.

[0085] The processor (130) can calculate a higher risk as the frequency of network failures of the target device (200) increases.

[0086] According to various embodiments, the processor (130) can update the risk level of an event based on user interaction information (second user interaction information) of a target device (200) associated with an identified event.

[0087] Here, the second user interaction information may be a user's response action, response sequence, or response plan for the target device (200) after an event occurs, and may include, for example, user input for the target device (200), data on how the user interacted with the device, and may include numerical values ​​entered by the user after an event occurred on the target device (200), user operations, user input, user control commands, etc.

[0088] The processor (130) can input the identified event information (31) into the interaction prediction model (30) to obtain prediction information (32) about the user interaction of the target device (200) that will follow the identified event.

[0089] FIG. 5 is a block diagram illustrating the process of obtaining prediction information (32) of user interaction for a target device (200) following an event using an interaction prediction model (30) according to one embodiment of the present disclosure.

[0090] Referring to FIG. 5, the interaction prediction model (30) may be a model that learns the context of the event and the user's past behavior data to predict user behavior that is likely to occur in the future.

[0091] Here, the prediction model (30) may be learned based on history information of the identified event and the user interaction with the target device (200) that followed the identified event.

[0092] More specifically, for example, the processor (130) inputs event information (31) regarding security threats, hacking attempts, intrusion attempts, etc., to the interaction prediction model (30) to obtain user interaction prediction information (32) regarding measures that the user may subsequently take regarding security threats, hacking attempts, intrusion attempts, such as activating a firewall or improving the security level.

[0093] Additionally, the processor (130) can input information about cases where an energy saving mode is automatically executed in a smart home appliance with rapidly increased power consumption into an interaction prediction model (30) to obtain user input for monitoring and verifying energy usage as user interaction prediction information (32).

[0094] The processor (130) can update the risk level of the identified event based on the prediction information (32).

[0095] Specifically, the processor (130) updates the risk level of the event to a lower value as the amount of data processed per unit time according to the user interaction prediction information (32) for the event that occurred in the target device (200) is lower, and the processor (130) updates the risk level of the event to a higher value as the amount of data processed per unit time according to the user interaction prediction information (32) is higher.

[0096] According to various embodiments, the processor (130) can update the risk level of an event based on user interaction information (second user interaction information) of a target device (200) associated with an identified event.

[0097] Here, the second user interaction information may include user input to the target device (200) after an event occurs, and data on how the user interacted with the device. For example, the second user interaction information may include numerical values ​​entered by the user after an event occurred on the device, user operations, user input, user control commands, etc.

[0098] Specifically, the processor (130) updates the risk level of the event to a lower value as the amount of data processed per unit time according to the second user interaction for the event that occurred in the target device (200) is lower, and the processor (130) updates the risk level of the event to a higher value as the amount of data processed per unit time according to the second user interaction is higher.

[0099] If the updated risk level is above a threshold, the processor (130) inputs the event information (31) into the interaction prediction model (30) to obtain additional prediction information (32) for the third user interaction of the target device (200) that follows the identified event.

[0100] The processor (130) can update the risk level based on user interaction information corresponding to the smaller value between the first unit time data throughput based on the second user interaction and the second unit time data throughput based on the third user interaction based on additional prediction information (32).

[0101] Therefore, by identifying user interactions with lower data throughput per unit of time among various user interactions for an event and enabling a response to the event, the risk of the event can be reduced.

[0102] According to one embodiment, the method according to the various embodiments disclosed herein may be provided by being included in a computer program product. The computer program product may be traded between a seller and a buyer as a product. The computer program product may be distributed in the form of a device-readable storage medium (e.g., compact disc read-only memory (CD-ROM)), or distributed online (e.g., download or upload) through an application store (e.g., Play Store™) or directly between two user devices (e.g., smartphones). In the case of online distribution, at least a portion of the computer program product (e.g., downloadable app) may be temporarily stored or temporarily created on a device-readable storage medium, such as the memory of a manufacturer's server, an application store's server, or a relay server.

[0103] Although preferred embodiments of the present disclosure have been illustrated and described above, the present disclosure is not limited to the specific embodiments described above. It is understood that various modifications can be made by those skilled in the art without departing from the essence of the present disclosure as claimed in the claims, and such modifications should not be understood individually from the technical spirit or perspective of the present disclosure.

Claims

1. In an electronic device, Memory for storing at least one instruction; and A processor connected to the memory and capable of executing at least one instruction; comprising The above processor is, When an event regarding a target device is identified, the degree of impact of the identified event on the target device is calculated based on the type and frequency of the identified event, and Obtaining state information of the target device corresponding to the identified event, and An electronic device that obtains the risk level of the identified event based on the calculated degree of influence and the obtained state information.

2. In Paragraph 1, The above status information is, An electronic device comprising at least one of the communication status, operation time, load level, and a first user interaction with the target device.

3. In Paragraph 1, The above processor is, An electronic device that updates the risk level of an event based on second user interaction information regarding the target device related to the identified event.

4. In Paragraph 1, The above processor is, The above-mentioned identified event information is input into an interaction prediction model to obtain prediction information regarding user interaction with the target device following the above-mentioned identified event, and An electronic device that updates the risk level of the identified event based on the above-mentioned acquired prediction information.

5. In Paragraph 4, The above prediction model is, An electronic device that has been learned based on the history information of the identified event and the second user interaction with the target device that followed the identified event.

6. In Paragraph 1, The above-mentioned target device is, It includes a plurality of devices, and The above processor is, An electronic device that identifies at least one event for each of the plurality of devices.

7. In a method of operating an electronic device, When an event regarding a target device is identified, an operation to calculate the degree of influence of the identified event on the target device based on the type and frequency of the identified event; An operation to obtain state information of the target device corresponding to the identified event; and A method of operation comprising: acquiring the risk level of the identified event based on the calculated degree of influence and the acquired state information.

8. A non-transient computer-readable recording medium storing at least one instruction executed by a processor of an electronic device to cause said electronic device to perform the method of operation of claim 7.