IP Library Granted Patent US 12,591,670
Granted Patent B2
US 12,591,670 · App. 18/452,199 · Granted Mar 31, 2026

Cyber threat information processing apparatus, cyber threat information processing method, and storage medium storing cyber threat information processing program

Inventors: Ki Hong Kim (Seoul, KR); Sung Eun Park (Gyeonggi-do, KR); Min Jun Choi (Seoul, KR); Se Jun Jang (Seoul, KR); Hyun Jong Lee (Seoul, KR); Chang Gyun Kim (Gyeonggi-do, KR)
Assignee: SANDS LAB INC.
G06F21/56G06F21/552G06F21/564G06F21/577G06F40/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,591,670
App. No.
18/452,199
Granted
Mar 31, 2026
Kind
B2
Abstract

A cyber threat information processing method including receiving a CTI analysis request for a document script from a client; analyzing the document script to obtain analysis information of the CTI for the script; generating a CTI query related to the document script based on the analysis information of the CTI and delivering the CTI query to a natural language model; and providing natural language description information according to the CTI query from the analysis information of the CTI and the natural language model to the client.

Claims (39)

1 . A method of providing cyber threat information (CTI), the method comprising:

receiving a CTI analysis request for a document script from a client;

analyzing the document script to obtain analysis information of the CTI for the document script;

generating a CTI query related to the document script based on the analysis information of the CTI and delivering the CTI query to a natural language model;

acquiring natural language description information describing a cyber threat mechanism related to the document script based on the natural language model; and

providing the natural language description information to the client,

wherein the cyber threat mechanism includes one or more functions being operated when the document script is executed,

wherein the natural language description information describes an instruction, a variable, or a path that the one or more functions execute, and

wherein the natural language description information further describes a code in the document script, a language in which the code is written, subroutines that exist in the code, and a function executed by the subroutines.

2 . The method according to claim 1 , wherein the CTI query comprises at least one of a keyword of the CTI, a hash value related to the CTI, an attack identifier related to the CTI, an attack group identifier related to the CTI, an attack technique related to the CTI, or attack campaign information related to the CTI.

3 . The method according to claim 1 , further comprising:

generating candidate answers based on the CTI query by searching a database and providing evidence from the database for the candidate answers.

4 . An apparatus for providing cyber threat information (CTI), the apparatus comprising:

a database configured to store data; and

a processor,

wherein the processor performs operations comprising:

an operation of receiving a CTI analysis request for a document script from a client;

an operation of analyzing the document script to obtain analysis information of the CTI for the document script;

an operation of generating a CTI query related to the document script based on the analysis information of the CTI and delivering the CTI query to a natural language model;

an operation of acquiring natural language description information describing a cyber threat mechanism related to the document script based on the natural language model; and

an operation of providing the natural language description information to the client,

wherein the cyber threat mechanism includes one or more functions being operated when the document script is executed,

wherein the natural language description information describes an instruction, a variable, or a path that the one or more functions execute, and

wherein the natural language description information further describes a code in the document script, a language in which the code is written, subroutines that exist in the code, and a function executed by the subroutines.

5 . The apparatus according to claim 4 , wherein the CTI query comprises at least one of a keyword of the CTI, a hash value related to the CTI, an attack identifier related to the CTI, an attack group identifier related to the CTI, an attack technique related to the CTI, or attack campaign information related to the CTI.

6 . The apparatus according to claim 4 , wherein the processor performs operations further comprising:

an operation of generating candidate answers based on the CTI query by searching the database and providing evidence from the database for the candidate answers.

7 . A non-transitory computer-readable storage medium for storing a program for providing cyber threat information (CTI) executable by a computer, the program operating instructions of:

receiving a CTI analysis request for a document script from a client;

analyzing the document script to obtain analysis information of the CTI for the document script;

generating a CTI query related to the document script based on the analysis information of the CTI and delivering the CTI query to a natural language model;

acquiring natural language description information describing a cyber threat mechanism related to the document script based on the natural language model; and

providing a natural language description information to the client,

wherein the cyber threat mechanism includes one or more functions being operated when the document script is executed,

wherein the natural language description information describes an instruction, a variable, or a path that the one or more functions execute, and

wherein the natural language description information further describes a code in the document script, a language in which the code is written, subroutines that exist in the code, and a function executed by the subroutines.

8 . The non-transitory computer-readable storage medium according to claim 7 , wherein the CTI query comprises at least one of a keyword of the CTI, a hash value related to the CTI, an attack identifier related to the CTI, an attack group identifier related to the CTI, an attack technique related to the CTI, or attack campaign information related to the CTI.

9 . The non-transitory computer-readable storage medium according to claim 7 , the program further executing an instruction of:

generating candidate answers based on the CTI query by searching a database and provide evidence from the database for the candidate answers.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 21, 2023
From: KIM, KI HONG; PARK, SUNG EUN; CHOI, MIN JUN; JANG, SE JUN; LEE, HYUN JONG; KIM, CHANG GYUN
To: SANDS LAB INC.
Reel/Frame 064644/0480 →
Priority Claims (1)
KR 10-2023-0093881 · Jul 19, 2023 · national
Continuity (1)
Related Publication 20250028825A1 · Jan 23, 2025
References Cited (13)
US 12158950B1 · Lee · 2024 [cited by examiner]
US 20140282403A1 · Frenkiel · 2014 [cited by examiner]
US 20190260764A1 · Humphrey · 2019 [cited by examiner]
US 20200065482A1 · Taniguchi · 2020 [cited by examiner]
US 20210286879A1 · Zeng · 2021 [cited by examiner]
US 20220004642A1 · Pujar · 2022 [cited by examiner]
US 20220197923A1 · Jeong · 2022 [cited by examiner]
US 20230095415A1 · Boyer · 2023 [cited by examiner]
KR 1020200088587 · 2020 [cited by applicant]
KR 102447279 · 2022 [cited by applicant]
Zhou, Yinghai, et al. “CTI view: APT threat intelligence analysis system.” Security and Communication Networks 2022.1 (2022): 9875199. (Year: 2022). [cited by examiner]
KIPO, Office Action of KR 10-2023-0093881 dated Mar. 24, 2025, total 10 pages. [cited by applicant]
Anonymous, “ChatGPT for CTI Professionals”, SOCRadar, May 23, 2023, total 8 pages. [cited by applicant]