IP Library › Granted Patent US 12,739,277
Granted Patent B2
US 12,739,277 · App. 17/721,752 · Granted Sep 15, 2026

Apparatus for processing cyber threat information, method for processing cyber threat information, and medium for storing a program processing cyber threat information

Inventor: Kihong Kim (Seoul, KR)
Assignee: SANDS LAB INC.
H04L63/145H04L63/1416H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,739,277
App. No.
17/721,752
Filed
Apr 15, 2022
Granted
Sep 15, 2026
Kind
B2
Art Unit
2435
USPC
726/22
Abstract

A cyber threat information processing method, a device for processing cyber threat information, and a storage medium that stores a program for processing cyber threat information according to embodiments may generates one or more clusters of malware by analyzing and processing an executable file and performing clustering, and may provide information about the malware cluster related to a specific network based on a data set of network behavior information for each malware cluster, which is generated by performing dynamic analysis for the malware cluster.

Claims (52)

1 . A method for processing cyber threat information, the method comprising:

disassembling an executable file to obtain a disassembled code;

extracting a set of combined codes from the disassembled code,

wherein the set of combined codes includes operation code (OP-CODE) and a part of assembly code excluding operation code (ASM-CODE) per function in the disassembled code in which the operation code is excluded from the disassembled code,

wherein the operation code (OP-CODE) corresponds to a remaining function after basic functions of an operating system (OS) are removed from the disassembled code;

converting the set of combined codes into N-gram data, wherein the N is a natural number;

labeling the N-gram data with an attack identifier and an attack group;

performing a first machine learning model on the labeled N-gram data to classify one or more malwares,

wherein the one or more malwares are classified and profiled for the set of combined codes with the attack identifier and the attack group based on the first machine learning model;

generating one or more malware clusters based on a function in the set of combined codes;

storing PCAP (PACKET CAPTURE) files from a connected network and generating network packet information extracted from the PCAP (PACKET CAPTURE) files;

performing dynamic analysis on the malware clusters to generate network behavior information of respective data sets of the malware clusters;

assigning labels to the network packet information of the malware clusters;

performing a second machine learning on the assigned labels to determine similarity of the network packet information extracted from the PCAP files and the network behavior information of the respective data sets of the malware clusters; and

in response to the similarity that is greater than or equal to a threshold value, providing cyber threat information related to a first malware cluster among the malware clusters to users based on a cyber threat intelligence platform,

wherein the cyber threat information provides the network packet information relevant to the first malware cluster being profiled from the set of combined codes with the attacker identifier and the attack group.

2 . The method of claim 1 , wherein the cyber threat information further includes a name of the first malware cluster and the similarity.

3 . A device for processing cyber threat information, the device comprising:

a database configured to store at least one malware;

a network packet parser configured to extract network packet information; and

a processor configured to process at least one executable file, wherein the processor performs processes, the processes including:

disassembling an executable file to obtain a disassembled code;

extracting a set of combined codes from the disassembled code, wherein the set of combined codes includes operation code (OP-CODE) and a part of assembly code in which the operation code is excluded from the disassembled code,

wherein the operation code (OP-CODE) corresponds to a remaining function after basic functions of an operating system (OS) are removed from the disassembled code;

converting the set of combined codes into a hash value and converting the hash value into N-gram data, wherein the N is a natural number;

labeling the N-gram data with an attack identifier and an attack group;

performing a first machine learning model on the labeled N-gram data to classify one or more malwares,

wherein the one or more malwares are classified and profiled for the set of combined codes with the attack identifier and the attack group based on the first machine learning model;

generating one or more malware clusters based on a function in the set of combined codes; and

storing PCAP (PACKET CAPTURE) files from a connected network and generating network packet information extracted from the PCAP (PACKET CAPTURE) files;

performing dynamic analysis on the malware clusters to generate network behavior information of respective data sets of the malware clusters;

assigning labels to the network packet information of the malware clusters;

performing a second machine learning on the assigned labels to determine similarity of the network packet information extracted from the PCAP files and the network behavior information of the respective data sets of the malware clusters;

in response to the similarity that is greater than or equal to a threshold value, providing cyber threat information related to a first malware cluster of among the malware clusters to users based on a cyber threat intelligence platform,

wherein the cyber threat information provides the network packet information relevant to the first malware cluster being profiled from the set of combined codes with the attacker identifier and the attack group.

4 . The device of claim 3 , wherein the cyber threat information further includes a name of the first malware cluster and the similarity.

5 . A non-transitory computer-readable storage medium for storing one or more programs for processing cyber threat information, the one or more programs including instructions executing processes, the processes comprising:

disassembling an executable file to obtain a disassembled code;

extracting a set of combined codes from the disassembled code,

wherein the set of combined codes includes operation code (OP-CODE) and a part of assembly code excluding operation code in which the operation code is excluded from the disassembled code,

wherein the operation code (OP-CODE) corresponds to a remaining function after basic functions of an operating system (OS) are removed from the disassembled code;

converting the set of combined codes into a hash value and converting the hash value into N-gram data, wherein the N is a natural number;

labeling the N-gram data with an attack identifier and an attack group;

performing a first machine learning model on the labeled N-gram data to classify one or more malwares,

wherein the one or more malwares are classified and profiled for the set of combined codes with the attack identifier and the attack group based on the first machine learning model;

generating one or more malware clusters based on a function in the set of combined codes;

storing PCAP (PACKET CAPTURE) files from a connected network and generating network packet information extracted from the PCAP (PACKET CAPTURE) files;

performing dynamic analysis on the malware clusters to generate network behavior information of respective data sets of the malware clusters;

assigning labels to the network packet information of the malware clusters;

performing a second machine learning on the assigned labels to determine similarity of the network packet information extracted from the PCAP files and the network behavior information of the respective data sets of the malware clusters; and

in response to the similarity that is greater than or equal to a threshold value, providing cyber threat information related to a first malware cluster among the malware clusters to users based on a cyber threat intelligence platform,

wherein the cyber threat information provides the network packet information relevant to the first malware cluster being profiled from the set of combined codes with the attacker identifier and the attack group.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2022
From: KIM, KIHONG
To: SANDS LAB INC.
Reel/Frame 060333/0553 →
Priority Claims (1)
KR 10-2022-0017166 · Feb 9, 2022 · national
Continuity (1)
Related Publication 20230254340A1 · Aug 10, 2023
References Cited (19)
US 8578491B2 · McNamee et al. · 2013 [cited by applicant]
US 9948671B2 · Perdisci et al. · 2018 [cited by applicant]
US 11042637B1 · Davis · 2021 [cited by examiner]
US 20100154059A1 · McNamee · 2010 [cited by examiner]
US 20100235913A1 · Craioveanu · 2010 [cited by examiner]
US 20150052611A1 · Wang et al. · 2015 [cited by applicant]
US 20150186296A1 · Guidry · 2015 [cited by applicant]
US 20160094564A1 · Mohandas · 2016 [cited by examiner]
US 20160357966A1 · Porat et al. · 2016 [cited by applicant]
US 20170147815A1 · Pedersen et al. · 2017 [cited by applicant]
US 20170262633A1 · Miserendino · 2017 [cited by examiner]
US 20180041536A1 · Berlin · 2018 [cited by examiner]
US 20230418943A1 · Han · 2023 [cited by examiner]
KR 1020160082644A · 2016 [cited by applicant]
KR 102068605B1 · 2020 [cited by applicant]
KR 20210092464A · 2021 [cited by applicant]
Improving malware detection using multi-view ensemble learning/Jinrong Bai (Year: 2016). [cited by examiner]
Improving malware detection using multi-view ensemble learning/Jinrong Bai (Year: 2016) (Year: 2016). [cited by examiner]
Bai et al., “Improving malware detection using multi-view ensemble learning” Security and Communications Networks, (Nov. 2016). [cited by applicant]