IP Library › Granted Patent US 12,639,432
Granted Patent B2
US 12,639,432 · App. 18/235,775 · Granted May 26, 2026

Cyber threat information processing apparatus, cyber threat information processing method, and storage medium storing cyber threat information processing program

Inventors: Ki Hong Kim (Seoul, KR); Sung Eun Park (Seongnam-si, KR); Min Jun Choi (Seoul, KR); Se Jun Jang (Seoul, KR); Hyun Jong Lee (Seoul, KR); Chang Gyun Kim (Paju-si, KR)
Assignee: SANDS LAB INC.
G06F21/565G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,639,432
App. No.
18/235,775
Granted
May 26, 2026
Kind
B2
Abstract

Provided is a cyber threat information processing method including receiving a CTI analysis request for a file from a client; analyzing the file to obtain analysis information of the CTI for the file; generating a CTI query related to the file based on the analyzed CTI and delivering the CTI query to a natural language model; and providing natural language description information according to the CTI query obtained from the CTI for the analyzed file and the natural language model.

Claims (47)

1 . A method of providing cyber threat information (CTI), the method comprising:

receiving a CTI analysis request for a file from a client;

analyzing the file to obtain analysis information of the CTI for the file;

generating a CTI query related to the file based on the analysis information and delivering the CTI query to a natural language model; and

providing natural language description information according to the CTI query obtained from the CTI for the analyzed file and the natural language model,

wherein the CTI query includes at least one of a keyword of the CTI, a hash value, an attack identifier, an attack group identifier, an attack technique, or attack campaign information related to the CTI, and wherein the natural language description information includes damage severity according to a degree of maliciousness, a probabilistic value of the maliciousness and a related tag of the file.

2 . The method according to claim 1 , wherein the analysis information of the CTI comprises at least one of whether the file is malicious, an attack technique related to the file, an attack group related to the file, an attack campaign related to the file, a target industry of a cyberattack related to the file, or target nation information of the cyberattack related to the file.

3 . The method according to claim 1 , further comprising:

providing evidence of answer in response to the CTI query when providing the natural language description information.

4 . The method according to claim 1 , further comprising:

generating candidate answers based on the CTI query by searching a database and providing evidence from the database for the candidate answers.

5 . The method according to claim 1 , wherein the CTI query further includes an attack group, attack technique related to a malicious action by the file, and an attack campaign according to the analysis information.

6 . The method according to claim 1 , further comprising:

obtaining visualization information of the natural language description information.

7 . An apparatus for providing cyber threat information (CTI), the apparatus comprising:

a database configured to store data; and

a processor,

wherein the processor performs operations comprising:

an operation of receiving a CTI analysis request for a file from a client;

an operation of analyzing the file to obtain analysis information of the CTI for the file;

an operation of generating a CTI query related to the file based on the analysis information and delivering the CTI query to a natural language model; and

an operation of providing natural language description information according to the CTI query obtained from the natural language model,

wherein the CTI query includes at least one of a keyword of the CTI, a hash value, an attack identifier, an attack group identifier, an attack technique, or attack campaign information related to the CTI, and

wherein the natural language description information includes damage severity according to a degree of maliciousness, a probabilistic value of the maliciousness and a related tag of the file.

8 . The apparatus according to claim 7 , wherein the analysis information of the CTI comprises at least one of whether the file is malicious, an attack technique related to the file, an attack group related to the file, an attack campaign related to the file, a target industry of a cyberattack related to the file, or target nation information of the cyberattack related to the file.

9 . The apparatus according to claim 7 , wherein the processor performs operations further comprising:

an operation of providing evidence of answer in response to the CTI query when providing the natural language description information.

10 . The apparatus according to claim 7 , wherein the processor performs operations further comprising:

an operation of generating candidate answers based on the CTI query by searching a database and providing evidence from the database for the candidate answers.

11 . The apparatus according to claim 7 , wherein the CTI query further includes an attack group, attack technique related to a malicious action by the file, and an attack campaign according to the analysis information.

12 . The apparatus according to claim 7 , wherein the processor performs operations further comprising:

an operation of obtaining visualization information of the natural language description information.

13 . A non-transitory computer-readable storage medium for storing a program for providing cyber threat information (CTI) executable by a computer, the program comprising instructions configured to:

receive a CTI analysis request for a file from a client;

analyze the file to obtain analysis information of the CTI for the file;

generate a CTI query related to the file based on the analysis information and delivering the CTI query to a natural language model; and

provide natural language description information according to the CTI query obtained from the natural language model,

wherein the CTI query includes at least one of a keyword of the CTI, a hash value, an attack identifier, an attack group identifier, an attack technique, or attack campaign information related to the CTI, and

wherein the natural language description information includes damage severity according to a degree of maliciousness, a probabilistic value of the maliciousness and a related tag of the file.

14 . The non-transitory computer-readable storage medium according to claim 13 , wherein the analysis information of the CTI comprises at least one of whether the file is malicious, an attack technique related to the file, an attack group related to the file, an attack campaign related to the file, a target industry of a cyberattack related to the file, or target nation information of the cyberattack related to the file.

15 . The non-transitory computer-readable storage medium according to claim 13 , wherein the program comprises further instructions configured to:

provide evidence of answer in response to the CTI query when providing the natural language description information.

16 . The non-transitory computer-readable storage medium according to claim 13 , wherein the program comprises further instructions configured to:

generate candidate answers based on the CTI query by searching a database and providing evidence from the database for the candidate answers.

17 . The non-transitory computer-readable storage medium according to claim 13 , wherein the CTI query further includes an attack group, attack technique related to a malicious action by the file, and an attack campaign according to the analysis information.

18 . The non-transitory computer-readable storage medium according to claim 13 , wherein the program comprises further instructions configured to:

obtain visualization information of the natural language description information.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 21, 2023
From: KIM, KI HONG; PARK, SUNG EUN; CHOI, MIN JUN; JANG, SE JUN; LEE, HYUN JONG; KIM, CHANG GYUN
To: SANDS LAB INC.
Reel/Frame 064652/0751 →
Priority Claims (1)
KR 10-2023-0093896 · Jul 19, 2023 · national
Continuity (1)
Related Publication 20250028826A1 · Jan 23, 2025
References Cited (7)
US 20230048076A1 · Kim · 2023 [cited by examiner]
US 20240411994A1 · Siracusano · 2024 [cited by examiner]
KR 102447279B1 · 2022 [cited by applicant]
KR 20230024184A · 2023 [cited by examiner]
Socradar, “ChatGPT for CTI Professionals”, Cyber Threat Intelligence, May 2023, pp. 1-8. [cited by applicant]
Kennedy et al., “Welcome to ThreatPursuit VM: A Threat Intelligence and Hunting Virtual Machine”, Threat Intelligence, Mandiant, Oct. 2020, pp. 1-17. [cited by applicant]
Office Action issued in corresponding Korean Patent Application No. 10-2023-0093896, dated Mar. 24, 2025. [cited by applicant]