Security Incident Information Extraction Using Generative AI

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to efficiently collect information related to security incidents using generative artificial intelligence, particularly in identifying organizations involved and the type of incidents, requiring significant manpower and time.

Innovation Solution

An information processing apparatus and method utilizing a generative AI model to collect and extract information about security incidents, including instruction information to determine incident type, organization, and timing, with analysis functions for visualization and filtering.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual analysis is used to grasp organization and security incident type, then analysis accuracy can be maintained, but significant manpower and time are required

Engineering Contradiction:
Improveinformation collection efficiencyVSAvoidtime required for analysis
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical analysis with an automated information processing system that uses natural language processing and machine learning models to extract security incident information from text data, thereby substituting human labor with automated computational processes

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service by automatically collecting, processing, and analyzing security incident information without requiring human intervention for each analysis task, allowing the system to serve itself in gathering and processing data

Inventive Principle:
Principle #25Self-service

2Extent of automation

If existing machine learning techniques are used to extract security entities, then automation is achieved, but information collection efficiency is insufficient

Engineering Contradiction:
Improveautomation levelVSAvoidinformation collection efficiency
Core Design Contradiction:
Extent of automationVSProductivity

Solution Approach 1:

The patent changes the parameters of the machine learning approach by using fine-tuned large language models with specific prompt engineering techniques, adjusting the model's behavior and output format to improve information extraction efficiency and quality

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system performs preliminary actions by pre-processing text data, setting up structured prompts, and preparing the model configuration before actual information extraction, thereby streamlining the overall process and improving efficiency

Inventive Principle:
Principle #10Preliminary action

3Loss of information

If manual analysis is used to identify security incidents, then comprehensive information can be obtained, but significant manpower is required

Engineering Contradiction:
Improvecompleteness of informationVSAvoidmanpower requirement
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The patent creates a universal system that can handle multiple types of security incident analysis and information extraction tasks through a single automated platform, making the system applicable to various scenarios without requiring separate manual analysis processes

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20260064838A1Information processing apparatus, information processing method, and computer-readable recording medium
Publication Date: 2026.03.05 NEC CORP
  • US20260064838A1 patent drawing
  • US20260064838A1 patent drawing
  • US20260064838A1 patent drawing

AI summary

An information processing apparatus includes a collection unit for inputting instruction information used to collect information related to a security incident, into a model that generates and outputs an answer based on an input instruction and causing the model to collect answer information related to the security incident and an extraction unit for extracting information indicating the security incident and information indicating an organization to be a subject of the security incident, based on the answer information.