IP Library › Granted Patent US 12,411,946
Granted Patent B2
US 12,411,946 · App. 18/138,447 · Granted Sep 9, 2025

Cyber threat information processing apparatus, cyber threat information processing method, and storage medium storing cyber threat information processing program

Inventor: Ki Hong Kim (Seoul, KR)
Assignee: SANDS LAB INC.
G06F21/554G06F21/552G06F21/577G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,411,946
App. No.
18/138,447
Granted
Sep 9, 2025
Kind
B2
Abstract

Provided is a cyber threat information processing method including receiving input of a file or information on the file from a user through at least one interface; processing cyber threat information related to the received or input file or the information on the file; providing the processed cyber threat information to the user through a user interface; and performing natural language processing on the processed cyber threat information.

Claims (32)

1. A method of processing cyber threat information, the method comprising:

receiving a file or information on the file from a user through at least one interface,

wherein the file includes either an executable file or non-executable file;

processing cyber threat information on advanced persistent threat (APT) attacks related to the received file or the information on the file,

wherein when the received file is the executable file, a first cyber threat feature being extracted from one or more functions in the file is classified into a first attack technique identifier and a first attack group identifier, and

when the received file is the non-executable file, a second cyber threat feature is extracted from memory data in a suspended state of an application of the non-executable file at the time of executing the application in a kernel area, and the extracted second cyber threat feature is classified into a second attack technique identifier and a second attack group identifier, and

wherein the cyber threat information is generated based on the first or second attack technique identifier and the first or second attack group identifier;

and

performing natural language processing on the cyber threat information and providing a real-time intelligence line feed service on the APT attacks based on the natural language through a user interface.

2. The method according to claim 1 , wherein the real-time intelligence line feed service includes a probability that the file is to be malicious.

3. An apparatus for processing cyber threat information, the apparatus comprising:

a database configured to store data; and

a server comprising a processor, wherein:

the server receives a file or information on the file from a user through at least one interface, wherein the file includes either an executable file or non-executable file, and

the processor:

processes cyber threat information on advanced persistent threat (APT) attacks related to the received file or the information on the file,

wherein when the received file is the executable file, a first cyber threat feature being extracted from one or more functions in the file is classified into a first attack technique identifier and a first attack group identifier, and

when the received file is the non-executable file, a second cyber threat feature is extracted from memory data in a suspended state of an application of the non-executable file at the time of executing the application in a kernel area, and the extracted second cyber threat feature is classified into a second attack technique identifier and a second attack group identifier, and

wherein the cyber threat information is generated based on the first or second attack technique identifier and the first or second attack group identifier;

and

performs natural language processing on the cyber threat information and provides a real-time intelligence line feed service on the APT attacks based on the natural language through a user interface.

4. The apparatus according to claim 3 , wherein the real-time intelligence line feed service includes a probability that the file is to be malicious.

5. A non-transitory computer-readable storage medium storing a cyber threat information processing program that executes computer instructions for:

receiving input of a file or information on the file from a user through at least one interface,

wherein the file includes either an executable file or non-executable file;

processing cyber threat information on advanced persistent threat (APT) attacks related to the received file or the information on the file,

wherein when the received file is the executable file, a first cyber threat feature being extracted from one or more functions in the file is classified into a first attack technique identifier and a first attack group identifier, and

when the received file is the non-executable file, a second cyber threat feature is extracted from memory data in a suspended state of an application of the non-executable file at the time of executing the application in a kernel area, and the extracted second cyber threat feature is classified into a second attack technique identifier and a second attack group identifier, and

wherein the cyber threat information is generated based on the first or second attack technique identifier and the first or second attack group identifier;

and

performing natural language processing on the cyber threat information and providing a real-time intelligence line feed service on the APT attacks based on the natural language through a user interface.

6. The non-transitory computer-readable storage medium according to claim 5 , wherein the real-time intelligence line feed service includes a probability that the file is to be malicious.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 24, 2023
From: KIM, KI HONG
To: SANDS LAB INC.
Reel/Frame 063421/0575 →
Priority Claims (1)
KR 10-2023-0047990 · Apr 12, 2023 · national
Continuity (1)
Related Publication 20240346135A1 · Oct 17, 2024
References Cited (16)
US 11443045B2 · Rahnama-Moghaddam · 2022 [cited by examiner]
US 20200358829A1 · Vo · 2020 [cited by examiner]
US 20210097176A1 · Mathews · 2021 [cited by examiner]
US 20220207142A1 · Gupta · 2022 [cited by examiner]
US 20220309166A1 · Shenoy · 2022 [cited by examiner]
US 20230009127A1 · Boyer · 2023 [cited by examiner]
US 20230038196A1 · Labreche · 2023 [cited by examiner]
US 20230179622A1 · Underwood · 2023 [cited by examiner]
US 20240056458A1 · Lee · 2024 [cited by examiner]
US 20240070261A1 · Bin Huraib · 2024 [cited by examiner]
US 20240070273A1 · Almogbil · 2024 [cited by examiner]
US 20240107344A1 · Papanikitas · 2024 [cited by examiner]
US 20240411896A1 · Myers · 2024 [cited by examiner]
KR 102447279B1 · 2022 [cited by applicant]
Edwin K., “Track Emerging Threats With Feedly AI”, Threat Intelligence, Ransomware Attacks, Mar. 2022, pp. 1-13. [cited by applicant]
Office Action issued in corresponding Korean Patent Application No. 10-2023-0047990, dated Feb. 5, 2025. [cited by applicant]