Apparatus for processing cyber threat information, method for processing cyber threat information, and medium for storing a program processing cyber threat information
A cyber threat information processing method, a device for processing cyber threat information, and a storage medium that stores a program for processing cyber threat information according to embodiments may generates one or more clusters of malware by analyzing and processing an executable file and performing clustering, and may provide information about the malware cluster related to a specific network based on a data set of network behavior information for each malware cluster, which is generated by performing dynamic analysis for the malware cluster.
1 . A method for processing cyber threat information, the method comprising:
disassembling an executable file to obtain a disassembled code;
extracting a set of combined codes from the disassembled code,
wherein the set of combined codes includes operation code (OP-CODE) and a part of assembly code excluding operation code (ASM-CODE) per function in the disassembled code in which the operation code is excluded from the disassembled code,
wherein the operation code (OP-CODE) corresponds to a remaining function after basic functions of an operating system (OS) are removed from the disassembled code;
converting the set of combined codes into N-gram data, wherein the N is a natural number;
labeling the N-gram data with an attack identifier and an attack group;
performing a first machine learning model on the labeled N-gram data to classify one or more malwares,
wherein the one or more malwares are classified and profiled for the set of combined codes with the attack identifier and the attack group based on the first machine learning model;
generating one or more malware clusters based on a function in the set of combined codes;
storing PCAP (PACKET CAPTURE) files from a connected network and generating network packet information extracted from the PCAP (PACKET CAPTURE) files;
performing dynamic analysis on the malware clusters to generate network behavior information of respective data sets of the malware clusters;
assigning labels to the network packet information of the malware clusters;
performing a second machine learning on the assigned labels to determine similarity of the network packet information extracted from the PCAP files and the network behavior information of the respective data sets of the malware clusters; and
in response to the similarity that is greater than or equal to a threshold value, providing cyber threat information related to a first malware cluster among the malware clusters to users based on a cyber threat intelligence platform,
wherein the cyber threat information provides the network packet information relevant to the first malware cluster being profiled from the set of combined codes with the attacker identifier and the attack group.
2 . The method of claim 1 , wherein the cyber threat information further includes a name of the first malware cluster and the similarity.
3 . A device for processing cyber threat information, the device comprising:
a database configured to store at least one malware;
a network packet parser configured to extract network packet information; and
a processor configured to process at least one executable file, wherein the processor performs processes, the processes including:
disassembling an executable file to obtain a disassembled code;
extracting a set of combined codes from the disassembled code, wherein the set of combined codes includes operation code (OP-CODE) and a part of assembly code in which the operation code is excluded from the disassembled code,
wherein the operation code (OP-CODE) corresponds to a remaining function after basic functions of an operating system (OS) are removed from the disassembled code;
converting the set of combined codes into a hash value and converting the hash value into N-gram data, wherein the N is a natural number;
labeling the N-gram data with an attack identifier and an attack group;
performing a first machine learning model on the labeled N-gram data to classify one or more malwares,
wherein the one or more malwares are classified and profiled for the set of combined codes with the attack identifier and the attack group based on the first machine learning model;
generating one or more malware clusters based on a function in the set of combined codes; and
storing PCAP (PACKET CAPTURE) files from a connected network and generating network packet information extracted from the PCAP (PACKET CAPTURE) files;
performing dynamic analysis on the malware clusters to generate network behavior information of respective data sets of the malware clusters;
assigning labels to the network packet information of the malware clusters;
performing a second machine learning on the assigned labels to determine similarity of the network packet information extracted from the PCAP files and the network behavior information of the respective data sets of the malware clusters;
in response to the similarity that is greater than or equal to a threshold value, providing cyber threat information related to a first malware cluster of among the malware clusters to users based on a cyber threat intelligence platform,
wherein the cyber threat information provides the network packet information relevant to the first malware cluster being profiled from the set of combined codes with the attacker identifier and the attack group.
4 . The device of claim 3 , wherein the cyber threat information further includes a name of the first malware cluster and the similarity.
5 . A non-transitory computer-readable storage medium for storing one or more programs for processing cyber threat information, the one or more programs including instructions executing processes, the processes comprising:
disassembling an executable file to obtain a disassembled code;
extracting a set of combined codes from the disassembled code,
wherein the set of combined codes includes operation code (OP-CODE) and a part of assembly code excluding operation code in which the operation code is excluded from the disassembled code,
wherein the operation code (OP-CODE) corresponds to a remaining function after basic functions of an operating system (OS) are removed from the disassembled code;
converting the set of combined codes into a hash value and converting the hash value into N-gram data, wherein the N is a natural number;
labeling the N-gram data with an attack identifier and an attack group;
performing a first machine learning model on the labeled N-gram data to classify one or more malwares,
wherein the one or more malwares are classified and profiled for the set of combined codes with the attack identifier and the attack group based on the first machine learning model;
generating one or more malware clusters based on a function in the set of combined codes;
storing PCAP (PACKET CAPTURE) files from a connected network and generating network packet information extracted from the PCAP (PACKET CAPTURE) files;
performing dynamic analysis on the malware clusters to generate network behavior information of respective data sets of the malware clusters;
assigning labels to the network packet information of the malware clusters;
performing a second machine learning on the assigned labels to determine similarity of the network packet information extracted from the PCAP files and the network behavior information of the respective data sets of the malware clusters; and
in response to the similarity that is greater than or equal to a threshold value, providing cyber threat information related to a first malware cluster among the malware clusters to users based on a cyber threat intelligence platform,
wherein the cyber threat information provides the network packet information relevant to the first malware cluster being profiled from the set of combined codes with the attacker identifier and the attack group.