Cyber threat information processing apparatus, cyber threat information processing method, and storage medium storing cyber threat information processing program
A cyber threat information processing method, a cyber threat information processing apparatus, and a storage medium storing a cyber threat information processing program may analyze and process an executable file, perform clustering to generate one or more clusters, and determine similarity with a cluster of another user based on characteristic information of the executable file.
1 . A cyber threat information processing method comprising:
receiving a request for analysis of an executable file from a first user;
extracting a set of assembly code for a function of the executable file according to the request,
wherein the set of assembly code includes opcode which corresponds to the function and a piece of disassembled code which corresponds to an operand;
converting the extracted set of assembly code and a unit of code extracted from a second file previously requested by the first user into a first hash value;
converting the first hash value into first N-gram data, wherein the N is a natural number;
performing ensemble machine learning based on the first N-gram data and evaluating a first similarity between the extracted set of assembly code and the unit of code extracted from the second file previously requested by the first user;
generating a first cluster of code blocks for the first user based on the first similarity, wherein the first cluster of code blocks includes a portion of the extracted set of assembly code;
evaluating a second similarity between the extracted set of assembly code for the first cluster of code blocks and a second cluster of code blocks for a second user,
wherein the second cluster of code blocks includes a portion of assembly code extracted from a third file from the second user; and
providing information related to the executable file to the second user when the second similarity is greater than a preset threshold value.
2 . The cyber threat information processing method according to claim 1 , wherein the extracted set of assembly code is extracted by dissembling the executable file to obtain dissembled code and reconstructing the dissembled code.
3 . The cyber threat information processing method according to claim 1 , wherein the first cluster of code blocks is generated when the first similarity is greater than or equal to a threshold value.
4 . The cyber threat information processing method according to claim 1 , wherein the evaluating of the second similarity comprises:
converting the extracted set of assembly code and the second cluster of code blocks for the second user into a second hash value;
converting the second hash value into second N-gram data; and
performing ensemble machine learning on block-unit code of the second N-gram data.
5 . The cyber threat information processing method according to claim 1 , wherein the information related to the executable file includes the second similarity.
6 . A cyber threat information processing apparatus comprising:
a database configured to store one or more clusters for each user; and
a processor configured to analyze and process an input executable file, wherein the processor is configured to:
receive a request for analysis of an executable file from a first user;
extract a set of assembly code for a function of the executable file according to the request,
wherein the set of assembly code includes opcode which corresponds to the function and a piece of disassembled code which corresponds to an operand;
convert the extracted set of assembly code and a unit of code extracted from a second file previously requested by the first user into a first hash value;
convert the first hash value into first N-gram data, wherein the N is a natural number;
perform ensemble machine learning based on the first N-gram data and evaluating a first similarity between the extracted set of assembly code and the unit of code extracted from the second file previously requested by the first user;
generate a first cluster of code blocks for the first user based on the first similarity, wherein the first cluster of code blocks includes a portion of the extracted set of assembly code;
evaluate a second similarity between the extracted set of assembly code for the first cluster of code blocks and a second cluster of code blocks for a second user,
wherein the second cluster of code blocks includes a portion of assembly code extracted from a third file from the second user; and
provide information related to the executable file to the second user when the second similarity is greater than a preset threshold value.
7 . The cyber threat information processing apparatus according to claim 6 , wherein the processor is configured to disassemble the executable file to obtain dissembled code, and reconstruct the dissembled code to extract the assembly code.
8 . The cyber threat information processing apparatus according to claim 6 , wherein the processor is configured to generate the first cluster of code blocks when the first similarity is greater than or equal to a threshold value.
9 . The cyber threat information processing apparatus according to claim 6 , wherein the processor is configured to:
convert the extracted set of assembly code and the second cluster of code blocks for the second user into a second hash value;
convert the second hash value into second N-gram data; and
perform ensemble machine learning on block-unit code of the second N-gram data.
10 . The cyber threat information processing apparatus according to claim 6 , wherein the information related to the executable file includes the second similarity.
11 . A non-transitory storage medium that stores a computer-readable program, the non-transitory storage medium storing one or more programs for processing cyber threat information, the one or more programs including instructions executed by one or more programs of a cyber threat information processing apparatus, and the one or more programs causing the cyber threat information processing apparatus to:
receive a request for analysis of an executable file from a first user;
extract a set of assembly code for a function of the executable file by analyzing the executable file according to the request, wherein the set of assembly code includes opcode which corresponds to the function and a piece of disassembled code which corresponds to an operand;
convert the extracted set of assembly code and a unit of code extracted from a second file previously requested by the first user into a first hash value;
convert the first hash value into first N-gram data, wherein the N is a natural number;
perform ensemble machine learning based on the first N-gram data and evaluating a first similarity between the extracted set of assembly code and the unit of code extracted from the second file previously requested by the first user;
generate a first cluster of code blocks for the first user based on the first similarity, wherein the first cluster of code blocks includes a portion of the extracted set of assembly code;
evaluate a second similarity between the extracted set of assembly code for the first cluster of code blocks and a second cluster of code blocks of a second user,
wherein the second cluster of code blocks includes a portion of assembly code extracted from a third file from the second user; and
provide information related to the executable file to the second user when the second similarity is greater than a preset threshold value.