IP Library › Granted Patent US 12,587,556
Granted Patent B2
US 12,587,556 · App. 18/397,548 · Granted Mar 24, 2026

Server and method for storing and managing online threat data

Inventors: Soo Yeon Park (Seoul, KR); Sang Duk Suh (Seongnam-si, KR); Jae Ki Kim (Changwon-si, KR)
Assignee: S2W INC.
H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,587,556
App. No.
18/397,548
Granted
Mar 24, 2026
Kind
B2
Abstract

A server for storing and managing online threat data according to an embodiment of the present disclosure includes: an online threat data collection unit that collects online threat data from an online threat data providing server; an online threat data analysis unit that analyzes the online threat data to extract an online threat string, and uses the online threat string as an index to generate information for retrieving the online threat data; and a database in which information generated by the online threat data analysis unit is stored.

Claims (28)

1 . A server for storing and managing online threat data, the server comprising:

a database;

a processor; and

a memory storing instructions executable by the processor,

wherein the processor is configured to execute the instructions to:

collect the online threat data from an online threat data providing server,

analyze the online threat data to extract an online threat string, and use the online threat string as an index to generate information for retrieving the online threat data, and

store the generated information in the database,

wherein the processor is further configured to execute the instructions to:

extract tokens from the online threat string based on spaces in the online threat string,

determine whether the extracted tokens are stored as indexes in the database,

based on a token among the extracted tokens being stored as an index in the database, store an identifier of the online threat string in an identifier item corresponding to the index of the token in the database, and

assign a label indicating a frequency to each index of the indexes in the database and then sort the indexes according to the frequency to update the database.

2 . The server of claim 1 , wherein the processor is further configured to execute the instructions to, based on an online threat data retrieval request message being received from a user terminal, extract online threat data including a specific threat indicator word from the database based on the online threat data retrieval request message and provide the extracted online threat data to the user terminal.

3 . A method of storing and managing online threat data, which is executed on a server for storing and managing the online threat data, the method comprising:

collecting the online threat data from an online threat data providing server;

analyzing the online threat data to extract an online threat string, and using the online threat string as an index to generate information for retrieving the online threat data; and

building a database using the generated information,

wherein the method further comprises:

extracting tokens from the online threat string based on spaces in the online threat string,

determining whether the extracted tokens are stored as indexes in the database,

based on a token among the extracted tokens being stored as an index in the database, storing an identifier of the online threat string in an identifier item corresponding to the index of the token in the database, and

assigning a label indicating a frequency to each index of the indexes in the database and then sorting the indexes according to the frequency to update the database.

4 . The method of claim 3 , further comprising:

receiving an online threat data retrieval request message from a user terminal; and

extracting online threat data including a specific threat indicator word from the database based on the online threat data retrieval request message and providing the extracted online threat data to the user terminal.

5 . The server of claim 1 , wherein the processor is further configured to execute the instructions to: based on a token among the extracted tokens not being stored as an index in the database, store, as an index in the database, the unstored token in the database and store the identifier of the online threat string in an identifier item corresponding to the index of the unstored token in the database.

6 . The method of claim 3 , further comprising: based on a token among the extracted tokens not being stored as an index in the database, storing, as an index in the database, the unstored token in the database and storing the identifier of the online threat string in an identifier item corresponding to the index of the unstored token in the database.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 29, 2024
From: PARK, SOO YEON; SUH, SANG DUK; KIM, JAE KI
To: S2W INC.
Reel/Frame 067254/0747 →
Priority Claims (1)
KR 10-2022-0189561 · Dec 29, 2022 · national
Continuity (1)
Related Publication 20240250972A1 · Jul 25, 2024
References Cited (7)
US 8701162B1 · Pedersen · 2014 [cited by examiner]
US 10972484B1 · Swackhamer · 2021 [cited by examiner]
US 11729197B2 · Cruz · 2023 [cited by examiner]
US 20180115570A1 · Ollmann · 2018 [cited by examiner]
KR 1020160109870A · 2016 [cited by applicant]
KR 1020210083936A · 2021 [cited by applicant]
Communication issued Mar. 7, 2025 in Korean Patent Application No. 10-2022-0189561. [cited by applicant]