IP Library Granted Patent US 11,956,264
Granted Patent B2
US 11,956,264 · App. 16/403,994 · Granted Apr 9, 2024

Method and system for verifying validity of detection result

Inventors: Juho Yun (Seongnam-si, KR); Seongho Ka (Seongnam-si, KR)
Assignee: LINE CORPORATION
H04L63/1433H04L9/40H04L63/1425H04L63/20H04L69/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,956,264
App. No.
16/403,994
Granted
Apr 9, 2024
Kind
B2
Abstract

A validity verification method may include receiving an event to be analyzed from a security information & event management (SIEM) server, the event to be analyzed selected by the SIEM server from a plurality of events detected by different security devices based on a desired correlation rule; registering the event to be analyzed; collecting raw data associated with the registered event from a security device corresponding to the registered event among the different security devices; acquiring location information of an intended network location associated with an attack based on the collected raw data; determining a validity status of the registered event based on the acquired location information; generating an exceptional processing message of the registered event; and transmitting the generated exceptional processing message to the SIEM server based on results of the determining the validity status of the registered event.

Claims (74)

1. A validity verification method comprising:

receiving, using at least one processor, an event to be analyzed from a security information & event management (SIEM) server, the event to be analyzed corresponding to a potential attack, the event to be analyzed selected by the SIEM server from a plurality of events detected by different security devices based on a desired correlation rule used to filter the plurality of events received by the different security devices;

registering, using the at least one processor, the event to be analyzed;

collecting, using the at least one processor, raw data associated with the registered event from a security device corresponding to the registered event among the different security devices in response to the registration of the event;

acquiring, using the at least one processor, location information of an intended network location associated with a network attack based on the collected raw data;

simulating, using the at least one processor, a network attack using the acquired location information based on the network attack corresponding to the registered event;

determining, using the at least one processor, a validity status of the registered event based on the simulated network attack;

generating, using the at least one processor, an exceptional processing message of the registered event based on results of the determining the validity status of the registered event; and

transmitting, using the at least one processor, the generated exceptional processing message to the SIEM server.

2. The method of claim 1 , wherein in response to the registered event corresponding to the exceptional processing message being redetected and received by the different security devices, the SIEM server is caused to update the correlation rule to automatically process the redetected and received event.

3. The method of claim 1 , further comprising:

transmitting, using the at least one processor, a validity message of the registered event to the SIEM server indicating the registered event is valid based on the results of the determining the validity status; and

receiving, using the at least one processor, from the SIEM server, an alert message generated by the SIEM server in response to the event corresponding to the validity message being redetected and received by the SIEM server by the different security devices.

4. The method of claim 1 , wherein the determining the validity status comprises:

determining the validity status of the registered event based on a response to the simulated network attack received from a computer system corresponding to the acquired location information.

5. The method of claim 1 , wherein

the acquired location information comprises a uniform resource identifier (URI) for a webpage of a network; and

the determining comprises,

receiving a response code for a state of the webpage through a connection to the webpage using the URI,

analyzing the received response code, and

determining the validity status of the registered event based on results of the analysis of the received response code.

6. The method of claim 1 , further comprising:

providing, using at least one processor, a user interface for designating a validity status for the registered event.

7. The method of claim 1 , wherein the collecting the raw data associated with the registered event further includes:

collecting the raw data associated with the registered event from a database included in the security device corresponding to the registered event.

8. A validity verification server, comprising:

at least one processor configured to execute computer-readable instructions to,

receive an event to be analyzed from a security information & event management (SIEM) server, the event to be analyzed corresponding to a potential attack, the event to be analyzed selected by the SIEM server from a plurality of events detected by different security devices based on a desired correlation rule used to filter the plurality of events received by the different security devices;

register the event to be analyzed;

collect raw data associated with the registered event from a security device corresponding to the registered event among the different security devices in response to the registration of the event;

acquire location information of an intended network location associated with a network attack based on the collected raw data;

simulating a network attack using the acquired location information based on the network attack corresponding to the registered event;

determine a validity status of the registered event based on the simulated network attack;

generate an exceptional processing message of the registered event based on results of the determining the validity status of the registered event; and

transmit the generated exceptional processing message to the SIEM server.

9. The validity verification server of claim 8 , wherein, in response to the event corresponding to the exceptional processing message being redetected and received by different security devices, the SIEM server is caused to update the correlation rule to automatically process the redetected and received event.

10. The validity verification server of claim 8 , wherein the at least one processor is further configured to:

transmit a validity message of the registered event to the SIEM server indicating the registered event is valid based on the results of the determining the validity status; and

receive, from the SIEM server, an alert message generated by the SIEM in response to the event corresponding to the validity message being redetected and received by the SIEM server by the different security devices.

11. The validity verification server of claim 8 , wherein, the determining the validity status of the registered event further includes:

determining the validity status of the registered event based on a response to the simulated network attack received from a computer system corresponding to the acquired location information.

12. The validity verification server of claim 8 , wherein

the acquired location information comprises a uniform resource identifier (URI) for a webpage of a network; and

the determining the validity status of the registered event includes,

receiving a response code for a state of the webpage through a connection to the webpage using the URI,

analyzing the received response code, and

determine the validity status of the registered event based on results of the analysis of the received response code.

13. The validity verification server of claim 8 , wherein the at least one processor is further configured to provide a user interface for designating a validity status for the registered event.

14. The validity verification server of claim 8 , wherein the collecting the raw data associated with the registered event further includes:

collecting the raw data associated with the registered event from a database included in the security device corresponding to the registered event.

15. A non-transitory computer readable medium storing computer readable instructions which, when executed by at least one processor, cause the at least one processor to perform a method comprising:

receiving an event to be analyzed from a security information & event management (SIEM) server, the event to be analyzed corresponding to a potential attack, the event to be analyzed selected by the SIEM server from a plurality of events detected by different security devices based on a desired correlation rule used to filter the plurality of events received by the different security devices;

registering the event to be analyzed;

collecting raw data associated with the registered event from a security device corresponding to the registered event among the different security devices in response to the registration of the event;

acquiring location information of an intended network location associated with a network attack based on the collected raw data;

simulating a network attack using the acquired location information based on the network attack corresponding to the registered event;

determining a validity status of the registered event based on the simulated network attack;

generating an exceptional processing message of the registered event based on results of the determining the validity status of the registered event; and

transmitting the generated exceptional processing message to the SIEM server.

16. The non-transitory computer readable medium of claim 15 , wherein the method further comprises:

in response to the event corresponding to the exceptional processing message being redetected and received by different security devices, updating the correlation rule to automatically process the redetected and received event.

17. The non-transitory computer readable medium of claim 15 , wherein the method further comprises:

transmitting a validity message of the registered event to the SIEM server indicating the registered event is valid based on the results of the determining the validity status; and

receiving, from the SIEM server, an alert message generated by the SIEM in response to the event corresponding to the validity message being redetected and received by the SIEM server by the different security devices.

18. The non-transitory computer readable medium of claim 15 , wherein, the determining the validity status of the registered event further includes:

determining the validity status of the registered event based on a response to the simulated network attack received from a computer system corresponding to the acquired location information.

19. The non-transitory computer readable medium of claim 15 , wherein

the acquired location information comprises a uniform resource identifier (URI) for a webpage of a network; and

the determining the validity status of the registered event includes,

receiving a response code for a state of the webpage through a connection to the webpage using the URI,

analyzing the received response code, and

determine the validity status of the registered event based on results of the analysis of the received response code.

20. The non-transitory computer readable medium of claim 15 , wherein the method further comprises:

providing a user interface for designating a validity status for the registered event.

Assignments (7)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 12, 2024
From: Z INTERMEDIATE GLOBAL CORPORATION
To: LY CORPORATION
Reel/Frame 067086/0491 →
CHANGE OF NAME Recorded Apr 12, 2024
From: LINE CORPORATION
To: Z INTERMEDIATE GLOBAL CORPORATION
Reel/Frame 067097/0858 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE CITY SHOULD BE SPELLED AS TOKYO PREVIOUSLY RECORDED AT REEL: 058597 FRAME: 0141. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 17, 2023
From: LINE CORPORATION
To: A HOLDINGS CORPORATION
Reel/Frame 062401/0328 →
CORRECTIVE ASSIGNMENT TO CORRECT THE SPELLING OF THE ASSIGNEES CITY IN THE ADDRESS SHOULD BE TOKYO, JAPAN PREVIOUSLY RECORDED AT REEL: 058597 FRAME: 0303. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 17, 2023
From: A HOLDINGS CORPORATION
To: LINE CORPORATION
Reel/Frame 062401/0490 →
CHANGE OF NAME Recorded Dec 28, 2021
From: LINE CORPORATION
To: A HOLDINGS CORPORATION
Reel/Frame 058597/0141 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 28, 2021
From: A HOLDINGS CORPORATION
To: LINE CORPORATION
Reel/Frame 058597/0303 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 8, 2019
From: YUN, JUHO; KA, SEONGHO
To: LINE CORPORATION
Reel/Frame 049110/0330 →
Continuity (2)
Continuation PCTKR2016013526 · Nov 23, 2016
Related Publication 20190260797A1 · Aug 22, 2019