IP Library › Granted Patent US 12,619,722
Granted Patent B2
US 12,619,722 · App. 18/106,024 · Granted May 5, 2026

Cyber threat information processing apparatus, cyber threat information processing method, and storage medium storing cyber threat information processing program

Inventor: Ki Hong Kim (Seoul, KR)
Assignee: SANDS LAB INC.
G06F21/563G06F21/565G06F21/566G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,619,722
App. No.
18/106,024
Granted
May 5, 2026
Kind
B2
Abstract

A cyber threat information processing method, a cyber threat information processing apparatus, and a storage medium storing a cyber threat information processing program may analyze and process an executable file, perform clustering to generate one or more clusters, and determine similarity with a cluster of another user based on characteristic information of the executable file.

Claims (48)

1 . A cyber threat information processing method comprising:

receiving a request for analysis of an executable file from a first user;

extracting a set of assembly code for a function of the executable file according to the request,

wherein the set of assembly code includes opcode which corresponds to the function and a piece of disassembled code which corresponds to an operand;

converting the extracted set of assembly code and a unit of code extracted from a second file previously requested by the first user into a first hash value;

converting the first hash value into first N-gram data, wherein the N is a natural number;

performing ensemble machine learning based on the first N-gram data and evaluating a first similarity between the extracted set of assembly code and the unit of code extracted from the second file previously requested by the first user;

generating a first cluster of code blocks for the first user based on the first similarity, wherein the first cluster of code blocks includes a portion of the extracted set of assembly code;

evaluating a second similarity between the extracted set of assembly code for the first cluster of code blocks and a second cluster of code blocks for a second user,

wherein the second cluster of code blocks includes a portion of assembly code extracted from a third file from the second user; and

providing information related to the executable file to the second user when the second similarity is greater than a preset threshold value.

2 . The cyber threat information processing method according to claim 1 , wherein the extracted set of assembly code is extracted by dissembling the executable file to obtain dissembled code and reconstructing the dissembled code.

3 . The cyber threat information processing method according to claim 1 , wherein the first cluster of code blocks is generated when the first similarity is greater than or equal to a threshold value.

4 . The cyber threat information processing method according to claim 1 , wherein the evaluating of the second similarity comprises:

converting the extracted set of assembly code and the second cluster of code blocks for the second user into a second hash value;

converting the second hash value into second N-gram data; and

performing ensemble machine learning on block-unit code of the second N-gram data.

5 . The cyber threat information processing method according to claim 1 , wherein the information related to the executable file includes the second similarity.

6 . A cyber threat information processing apparatus comprising:

a database configured to store one or more clusters for each user; and

a processor configured to analyze and process an input executable file, wherein the processor is configured to:

receive a request for analysis of an executable file from a first user;

extract a set of assembly code for a function of the executable file according to the request,

wherein the set of assembly code includes opcode which corresponds to the function and a piece of disassembled code which corresponds to an operand;

convert the extracted set of assembly code and a unit of code extracted from a second file previously requested by the first user into a first hash value;

convert the first hash value into first N-gram data, wherein the N is a natural number;

perform ensemble machine learning based on the first N-gram data and evaluating a first similarity between the extracted set of assembly code and the unit of code extracted from the second file previously requested by the first user;

generate a first cluster of code blocks for the first user based on the first similarity, wherein the first cluster of code blocks includes a portion of the extracted set of assembly code;

evaluate a second similarity between the extracted set of assembly code for the first cluster of code blocks and a second cluster of code blocks for a second user,

wherein the second cluster of code blocks includes a portion of assembly code extracted from a third file from the second user; and

provide information related to the executable file to the second user when the second similarity is greater than a preset threshold value.

7 . The cyber threat information processing apparatus according to claim 6 , wherein the processor is configured to disassemble the executable file to obtain dissembled code, and reconstruct the dissembled code to extract the assembly code.

8 . The cyber threat information processing apparatus according to claim 6 , wherein the processor is configured to generate the first cluster of code blocks when the first similarity is greater than or equal to a threshold value.

9 . The cyber threat information processing apparatus according to claim 6 , wherein the processor is configured to:

convert the extracted set of assembly code and the second cluster of code blocks for the second user into a second hash value;

convert the second hash value into second N-gram data; and

perform ensemble machine learning on block-unit code of the second N-gram data.

10 . The cyber threat information processing apparatus according to claim 6 , wherein the information related to the executable file includes the second similarity.

11 . A non-transitory storage medium that stores a computer-readable program, the non-transitory storage medium storing one or more programs for processing cyber threat information, the one or more programs including instructions executed by one or more programs of a cyber threat information processing apparatus, and the one or more programs causing the cyber threat information processing apparatus to:

receive a request for analysis of an executable file from a first user;

extract a set of assembly code for a function of the executable file by analyzing the executable file according to the request, wherein the set of assembly code includes opcode which corresponds to the function and a piece of disassembled code which corresponds to an operand;

convert the extracted set of assembly code and a unit of code extracted from a second file previously requested by the first user into a first hash value;

convert the first hash value into first N-gram data, wherein the N is a natural number;

perform ensemble machine learning based on the first N-gram data and evaluating a first similarity between the extracted set of assembly code and the unit of code extracted from the second file previously requested by the first user;

generate a first cluster of code blocks for the first user based on the first similarity, wherein the first cluster of code blocks includes a portion of the extracted set of assembly code;

evaluate a second similarity between the extracted set of assembly code for the first cluster of code blocks and a second cluster of code blocks of a second user,

wherein the second cluster of code blocks includes a portion of assembly code extracted from a third file from the second user; and

provide information related to the executable file to the second user when the second similarity is greater than a preset threshold value.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2023
From: KIM, KI HONG
To: SANDS LAB INC.
Reel/Frame 062606/0991 →
Priority Claims (1)
KR 10-2022-0017168 · Feb 9, 2022 · national
Continuity (1)
Related Publication 20230306113A1 · Sep 28, 2023
References Cited (13)
US 8826439B1 · Hu · 2014 [cited by examiner]
US 20110219002A1 · Bartram · 2011 [cited by examiner]
US 20150186649A1 · Humble · 2015 [cited by examiner]
US 20200019389A1 · Durvasula · 2020 [cited by examiner]
US 20200042701A1 · Yang · 2020 [cited by examiner]
US 20200250309A1 · Harang · 2020 [cited by examiner]
US 20220138319A1 · Kim · 2022 [cited by examiner]
CN 109977976A · 2019 [cited by examiner]
KR 1020160082644A · 2016 [cited by applicant]
Translation of CN109977976A. [cited by examiner]
Bai et al., “Improving malware detection using multi-view ensemble learning,” Security and Communication Networks (2016). [cited by applicant]
Lee et al., “DEXOFUZZY: Android Malware Similarity Clustering Method using Opcode Sequence,” Virus Bulletin (2019). [cited by applicant]
MISP project, “MISP—Open Source Threat Intelligence Platform and Open Standards For Threat Information Sharing”(2021). [cited by applicant]