IP Library Granted Patent US 12,627,697
Granted Patent B2
US 12,627,697 · App. 18/132,953 · Granted May 12, 2026

Cyber threat information processing apparatus, cyber threat information processing method, and storage medium storing cyber threat information processing program

Inventors: Ki Hong Kim (Seoul, KR); Sung Eun Park (Seongnam-si, KR); Min Jun Choi (Seoul, KR); Hyun Jong Lee (Seoul, KR)
Assignee: SANDS LAB INC.
H04L63/1433H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,627,697
App. No.
18/132,953
Granted
May 12, 2026
Kind
B2
Abstract

Provided is a cyber threat information processing method including acquiring webpage data based on link information, and analyzing tag structure information of the webpage data, converting data included in a tag area of the webpage data into tag feature data according to the tag structure information, and training an AI model using the converted tag feature data to acquire cyber threat information of the data included in the tag area.

Claims (33)

1 . A cyber threat information processing method to provide a cyber intelligence service through Application Program Interface (API) interface, the cybersecurity threat information processing method comprising:

acquiring webpage data based on link information, and analyzing tag structure information of the webpage data;

converting hypertext markup language (HTML) data included in a tag area of the webpage data according to the tag structure information to extract tag feature data;

detecting whether the HTML data in the webpage data is malicious on multiple layers using two or more detection techniques which include antivirus-based malicious pattern detections or signature-based malicious pattern detections;

training an artificial intelligence (AI) model on the tag feature data to detect attack techniques of a malicious activity caused by the data included in the tag area,

wherein multiple attack techniques are classified with multi-labeling by using a binary vector based on multi-labeling classification;

acquiring cyber threat information on the malicious activity; and

providing the cyber intelligence service through the API interface related to the webpage data with the attack techniques classified with the multi-labeling and an attack group of the malicious activity.

2 . The cyber threat information processing method according to claim 1 , wherein the tag structure information comprises a document object model (DOM) tree structure.

3 . The cyber threat information processing method according to claim 1 , wherein, when the HTML data included in the tag area of the webpage data is converted into the tag feature data, the cyber threat information processing method is applied to user-related data in a tag except for grammar included in the webpage data.

4 . A cyber threat information processing apparatus to provide a cyber intelligence service through Application Program Interface (API) interface, the cyber threat information processing apparatus comprising:

a database configured to store webpage data; and

a processor,

wherein the processor:

acquires the webpage data based on link information, and analyzes tag structure information of the webpage data;

converts hypertext markup language (HTML) data included in a tag area of the webpage data according to the tag structure information to extract tag feature data;

detects whether the HTML data in the webpage data is malicious on multiple layers using two or more detection techniques which include antivirus-based malicious pattern detections or signature-based malicious pattern detections;

trains an AI model on the tag feature data to detect attack techniques of a malicious activity caused by the data included in the tag area,

wherein multiple attack techniques are classified with multi-labeling by using a binary vector based on multi-labeling classification;

acquires cyber threat information on the malicious activity; and

provides the cyber intelligence service through the API interface related to the webpage data with the attack techniques classified with the multi-labeling and an attack group of the malicious activity.

5 . The cyber threat information processing apparatus according to claim 4 , wherein the tag structure information comprises a DOM tree structure.

6 . The cyber threat information processing apparatus according to claim 4 , wherein, when the HTML data included in the tag area of the webpage data is converted into the tag feature data, the cyber threat information processing apparatus is applied to user-related data in a tag except for grammar included in the webpage data.

7 . A non-transitory computer-readable storage medium storing a cyber threat information processing program to provide a cyber intelligence service through Application Program Interface (API) interface, the program executing computer instructions comprising:

a module for acquiring webpage data based on link information, and analyzing tag structure information of the webpage data;

a module for converting hypertext markup language (HTML) data included in a tag area of the webpage data into tag feature data according to the tag structure information to extract tag feature data;

a module for detecting whether the HTML data in the webpage data is malicious on multiple layers using two or more detection techniques which include antivirus-based malicious pattern detections or signature-based malicious pattern detections; and

a module for training an AI model on the tag feature data to detect attack techniques of a malicious activity caused by the data included in the tag area,

wherein multiple attack techniques are classified with multi-labeling by using a binary vector based on multi-labeling classification,

acquiring cyber threat information on the malicious, and

providing the cyber intelligence service through the API interface related to the webpage data with the attack techniques classified with the multi-labeling and an attack group of the malicious activity.

8 . The non-transitory computer-readable storage medium according to claim 7 , wherein the tag structure information comprises a DOM tree structure.

9 . The non-transitory computer-readable storage medium according to claim 7 , wherein, when the HTML data included in the tag area of the webpage data is converted into the tag feature data, the cyber threat information processing program is applied to user-related data in a tag except for grammar included in the webpage data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 11, 2023
From: KIM, KI HONG; PARK, SUNG EUN; CHOI, MIN JUN; LEE, HYUN JONG
To: SANDS LAB INC.
Reel/Frame 063283/0384 →
Priority Claims (1)
KR 10-2022-0185541 · Dec 27, 2022 · national
Continuity (1)
Related Publication 20240214406A1 · Jun 27, 2024
References Cited (5)
US 10440042B1 · Stein · 2019 [cited by examiner]
US 20150302052A1 · Galarneau · 2015 [cited by examiner]
US 20220303289A1 · Townsend · 2022 [cited by examiner]
KR 101725404B1 · 2017 [cited by examiner]
KR 101899049B1 · 2018 [cited by examiner]