IP Library › Granted Patent US 12,587,567
Granted Patent B2
US 12,587,567 · App. 18/517,803 · Granted Mar 24, 2026

Electronic apparatus for implementing honeypot control system and control method thereof

Inventors: Seung Won Shin (Daejeon, KR); Dong Min Choi (Daejeon, KR); Hyun Min Seo (Daejeon, KR); Sang Duk Suh (Seongnam-si, KR); Jae Ki Kim (Changwon-si, KR)
Assignees: KOREA ADVANCED INSTITUTE OF SCIENCE AND TECHNOLOGY; S2W INC.
H04L63/1491
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,587,567
App. No.
18/517,803
Granted
Mar 24, 2026
Kind
B2
Abstract

Disclosed is an electronic apparatus for implementing a honeypot control system. The electronic apparatus includes a communication interface, a memory configured to store execution information including information on a virtual machine built on a cloud server, information on a running service, and information on an open port, and a processor configured to functionally control the communication interface and the memory, wherein the processor is configured to transmit execution information obtained based on information stored in the memory to each of a plurality of cloud servers in different Internet Protocol (IP) bands through the communication interface, when log information is received from each of the plurality of cloud servers that have received the execution information through the communication interface, normalize the received log information, and obtain malicious code information using the normalized log information.

Claims (40)

1 . An electronic apparatus for implementing a honeypot control system, the electronic apparatus comprising:

a communication interface;

a memory configured to store execution information including information on a virtual machine built on a cloud server, information on a running service, and information on an open port; and

a processor configured to functionally control the communication interface and the memory,

wherein the processor is configured to:

transmit execution information obtained based on information stored in the memory to each of a plurality of cloud servers in different Internet Protocol (IP) bands through the communication interface,

when log information is received from each of the plurality of cloud servers that have received the execution information through the communication interface, normalize the received log information, and

obtain malicious code information using the normalized log information,

wherein the plurality of cloud servers are implemented as different types of honeypot platforms, and

wherein the processor is further configured to:

when log information of different log types is received from each of the plurality of cloud servers implemented as different types of honeypot platforms, parse and normalize the received log information of different log types by item, and

index the normalized log information of different log types and store the indexed log information in the memory.

2 . The electronic apparatus of claim 1 , wherein the processor is further configured to identify statistical data by item on the basis of the log information stored in the memory, and

provide a user interface (UI) including the identified statistical data.

3 . The electronic apparatus of claim 1 , wherein, in the plurality of cloud servers, a plurality of servers are communicatively connected to each other to be implemented as a single cluster and different regions are assigned to each of the plurality of servers.

4 . A honeypot system including a plurality of cloud servers and an electronic apparatus,

wherein the electronic apparatus is configured to transmit execution information including information on a virtual machine built on a cloud server, information on a running service, and information on an open port to each of the plurality of cloud servers, when log information is received from each of the plurality of cloud servers that have received the execution information, normalize the received log information, and obtain malicious code information using the normalized log information, and

wherein the plurality of cloud servers are configured to build one or more virtual machines on the basis of the execution information received from the electronic apparatus, execute at least one service corresponding to each of the one or more built virtual machines, and transmit the log information obtained through the running service to the electronic apparatus,

wherein the plurality of cloud servers are implemented as cloud servers in different IP bands,

wherein the plurality of cloud servers are implemented as different types of honeypot platforms, and

wherein the electronic apparatus is further configured to:

when log information of different log types is received from each of the plurality of cloud servers implemented as different types of honeypot platforms, parse and normalize the received log information of different log types by item, and

index the normalized log information of different log types and store the indexed log information in a memory.

5 . A control method of an electronic apparatus for implementing a honeypot control system, the control method comprising:

transmitting execution information including information on a virtual machine built on a cloud server, information on a running service, and information on an open port to each of a plurality of cloud servers in different Internet Protocol (IP) bands;

when log information is received from each of the plurality of cloud servers that have received the execution information, normalizing the received log information; and

obtaining malicious code information using the normalized log information, wherein the plurality of cloud servers are implemented as different types of honeypot platforms,

wherein the normalizing of the received log information includes, when log information of different log types is received from each of the plurality of cloud servers implemented as different types of honeypot platforms, parsing and normalizing the received log information of different log types by item, and

wherein the control method further includes indexing the normalized log information of different log types and storing the indexed log information in a memory.

6 . The control method of claim 5 , further comprising:

identifying statistical data by item on the basis of the log information stored in the memory; and

providing a user interface (UI) including the identified statistical data.

7 . The control method of claim 5 , wherein, in the plurality of cloud servers, a plurality of servers are communicatively connected to each other to be implemented as a single cluster and different regions are assigned to each of the plurality of servers.

8 . A non-transitory computer-readable recording medium for storing a computer program executed by a processor of an electronic apparatus for implementing a honeypot control system to perform a control method including:

transmitting execution information including information on a virtual machine built on a cloud server, information on a running service, and information on an open port to each of a plurality of cloud servers in different Internet Protocol (IP) bands;

when log information is received from each of the plurality of cloud servers that have received the execution information, normalizing the received log information; and

obtaining malicious code information using the normalized log information,

wherein the plurality of cloud servers are implemented as different types of honeypot platforms,

wherein the normalizing of the received log information includes, when log information of different log types is received from each of the plurality of cloud servers implemented as the different types of honeypot platforms, parsing and normalizing the received log information of different log types by item, and

wherein the control method further includes indexing the normalized log information of different log types and storing the indexed log information in a memory.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 22, 2023
From: SHIN, SEUNG WON; CHOI, DONG MIN; SEO, HYUN MIN; SUH, SANG DUK; KIM, JAE KI
To: KOREA ADVANCED INSTITUTE OF SCIENCE AND TECHNOLOGY; S2W INC.
Reel/Frame 065649/0352 →
Priority Claims (1)
KR 10-2022-0162484 · Nov 29, 2022 · national
Continuity (1)
Related Publication 20240283823A1 · Aug 22, 2024
References Cited (6)
US 10178119B1 · Brandwine · 2019 [cited by examiner]
US 20180124073A1 · Scherman · 2018 [cited by examiner]
KR 1020170055053A · 2017 [cited by applicant]
KR 1020190029486A · 2019 [cited by applicant]
Woo-sik Jung, et al., “Design of Log Analysis System for Enterprise IDS/Firewall/Router”, DBPia, Mar. 31, 2003 (7 pages). [cited by applicant]
Korean Office Action dated May 29, 2024 in Application No. 10-2022-0162484. [cited by applicant]