IP Library › Granted Patent US 12,549,583
Granted Patent B2
US 12,549,583 · App. 19/268,121 · Granted Feb 10, 2026

Electronic apparatus for performing log lightweighting using extended bloom filter, and operation method thereof

Inventors: Icksun Kong (Yongin-si, KR); Subin Park (Seongnam-si, KR); Hyunsook Jang (Seongnam-si, KR)
Assignee: Ahnlab, Inc.
H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,549,583
App. No.
19/268,121
Granted
Feb 10, 2026
Kind
B2
Abstract

An operation method of an electronic apparatus is disclosed. The operation method according to the present disclosure comprises extracting item-specific data that matches a plurality of preconfigured items from within log data, applying the extracted item-specific data to a hash function corresponding to each item to obtain an item-specific hash value and checking for duplication of the log data based on whether the item-specific hash value is duplicated, updating a duplication count based on the checked duplication status, and detecting a threat based on the identified item-specific data and the updated duplication count.

Claims (23)

1 . An operation method of an electronic apparatus, the method comprising:

extracting item-specific data that matches a plurality of preconfigured items from within log data by the electronic apparatus;

applying the extracted item-specific data to a hash function corresponding to each item to obtain item-specific hash values and checking for duplication of the log data based on whether the item-specific hash values are duplicated by the electronic apparatus;

updating a duplication count based on the checked duplication status by the electronic apparatus by the electronic apparatus; and

detecting a threat based on the identified item-specific data and the updated duplication count by the electronic apparatus,

wherein the checking for duplication of the log data inputs the item-specific hash values corresponding to each of the plurality of items that constitute the log data into an extended Bloom filter in which item-specific hash values of at least one prior log data are stored and identifies the duplication status of the log data based on whether each of item-specific hash values is duplicated,

wherein the checking for duplication of the log data determines the log data as duplicated if each of the hash values of the plurality of items that constitute the log data is identified as matching the item-specific hash values of the prior log data,

wherein the extended Bloom filter includes hash functions to be applied to each of the plurality of preconfigured items according to detection rules related to threat detection, and

wherein the updating of the duplication count counts the number of times the log data, identified through the extended Bloom filter, is duplicated within a predetermined period.

2 . The method of claim 1 , wherein the updating of the duplication count counts the number of times the log data, identified through the extended Bloom filter, is duplicated within a predetermined period.

3 . The method of claim 1 , when each of the hash values of the plurality of items that constitute the log data is identified as not matching any pre-stored item-specific hash value of at least one prior log data, including setting the duplication count of the log data to one and storing the hash value of each of the plurality of items in the extended Bloom filter.

4 . The method of claim 3 , wherein the detecting of the threat detects a threat based on the log data and the duplication count of the log data when a time point set according to a predetermined period is reached.

5 . The method of claim 4 , wherein, when a time point set according to the predetermined period is reached, the method further comprises:

returning the duplication count of the log data within the extended Bloom filter; and

deleting the hash value of each of the plurality of items that constitute the log data.

6 . A system comprising:

a normalization module that extracts item-specific data matching a plurality of preconfigured items from log data;

a log compression module that applies the extracted item-specific data to hash functions corresponding to each item to obtain item-specific hash values and checks for duplication of the log data based on whether the item-specific hash values are duplicated, and updates a duplication count based on the checked duplication status; and

a threat detection module that detects threats based on the extracted item-specific data and the updated duplication count,

wherein the log compression module inputs the item-specific hash values corresponding to each of the plurality of items that constitute the log data into an extended Bloom filter in which item-specific hash values of at least one prior log data are stored and identifies the duplication status of the log data as based on whether each of the item-specific hash values is duplicated,

wherein the log compression module determines the log data as duplicated if each of the hash values of the plurality of items that constitute the log data is identified as matching the item-specific hash values of the prior log data, and

wherein the extended Bloom filter includes hash functions to be applied to each of the plurality of preconfigured items according to detection rules related to threat detection and

wherein the updating of the duplication count counts the number of times the log data, identified through the extended Bloom filter, is duplicated within a predetermined period.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 14, 2025
From: KONG, ICKSUN; PARK, SUBIN; JANG, HYUNSOOK
To: AHNLAB, INC.
Reel/Frame 071694/0943 →
Priority Claims (1)
KR 10-2024-0093275 · Jul 15, 2024 · national
Continuity (1)
Related Publication 20260019437A1 · Jan 15, 2026
References Cited (23)
US 8037476B1 · Shavit · 2011 [cited by examiner]
US 8850263B1 · Yourtee · 2014 [cited by examiner]
US 9092447B1 · Anderson · 2015 [cited by examiner]
US 11057414B1 · Giorgio · 2021 [cited by examiner]
US 20160253425A1 · Stoops · 2016 [cited by examiner]
US 20180232488A1 · Jafer · 2018 [cited by examiner]
US 20190347360A1 · Bortnikov · 2019 [cited by examiner]
US 20200099721A1 · Golan · 2020 [cited by examiner]
US 20210226974A1 · Hirano · 2021 [cited by examiner]
US 20220405160A1 · Datar · 2022 [cited by examiner]
KR 101540343B1 · 2015 [cited by applicant]
KR 101701310B1 · 2017 [cited by applicant]
KR 101787900B1 · 2017 [cited by applicant]
KR 1020190109151A · 2019 [cited by applicant]
KR 1020220077184A · 2022 [cited by applicant]
KR 102780773B1 · 2022 [cited by applicant]
KR 102598126B1 · 2023 [cited by applicant]
Shao et al., “Low-Latency Dimensional Expansion and Anomaly Detection Empowered Secure loT Network,” IEEE Transactions on Network and Service Management Year: 2023 | vol. 20, Issue: 3 | Journal Article | Publisher: IEEE. [cited by examiner]
Shao et al., “Low-Latency Dimensional Expansion and Anomaly Detection Empowered Secure IoT Network,” IEEE Transactions on Network and Service Management Year: 2023 | vol. 20, Issue: 3 | Journal Article | Publisher: IEEE. [cited by examiner]
Thang et al., “Synflood Spoofed Source DDoS Attack Defense Based on Packet ID Anomaly Detection with Bloom Filter,” 2018 5th Asian Conference on Defense Technology (ACDT) Year: 2018 | Conference Paper | Publisher: IEEE. [cited by examiner]
Atifi et al., “On correlating network traffic for cyber threat intelligence: A Bloom filter approach,” 2017 13th International Wireless Communications and Mobile Computing Conference (IWCMC) Year: 2017 | Conference Pape… [cited by examiner]
Korean Office Action on Sep. 20, 2024 in corresponding Korean Patent Application No. 319999028822 (6 pages in English, 7 pages in Korean). [cited by applicant]
Korean Office Action on Mar. 4, 2025 in corresponding Korean Patent Application No. 319999028822 (3 pages in English, 2 pages in Korean). [cited by applicant]