IP Library Granted Patent US 12,632,548
Granted Patent B2
US 12,632,548 · App. 18/106,427 · Granted May 19, 2026

Cyber threat information processing apparatus, cyber threat information processing method, and storage medium storing cyber threat information processing program

Inventor: Ki Hong Kim (Seoul, KR)
Assignee: SANDS LAB INC.
G06F21/563G06F21/565G06F21/566G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,632,548
App. No.
18/106,427
Granted
May 19, 2026
Kind
B2
Abstract

A cyber threat information processing method, a cyber threat information processing processor, and a storage medium storing a program for processing cyber threat information may process an executable file to ensure characteristic information of the executable file, transmit the ensured characteristic information of the executable file over an independent network, and receive malware profiling information generated based on the characteristic information of the executable file over the independent network.

Claims (46)

1 . A cyber threat information processing method comprising:

receiving an executable file via a communication network;

disassembling the executable file to obtain disassembled code, and reconstructing the disassembled code to extract-a combined code for a function of the executable file,

wherein the combined code includes a set of opcode and assembly code;

converting the combined code for the function into a hash value;

generating characteristic information of the executable file based on the hash value or N-gram data obtained from the hash value, wherein the N is a natural number;

transmitting the characteristic information of the executable file over an independent communication network different from the communication network; and

receiving malware profiling information corresponding to the executable file over the independent communication network, the malware profiling information being generated by performing ensemble machine learning on the characteristic information of the executable file,

wherein the hash value or N-gram data are analyzed to remove code patterns irrelevant to an attack technique with an attack identifier defined in a standardized model and select code patterns linked to the attack identifier,

wherein the characteristic information is labeled with two parts of labels,

wherein a first part of the labels represents the attack technique and a second part of the labels represents an attacker implementing the attack technique, wherein the ensemble machine learning is performed on the selected code patterns to classify both an identifier of the attack technique and an identifier of the attacker as the malware profiling information simultaneously based on the two parts of labels, and

wherein the malware profiling information is classified by applying the characteristic information with the two parts of labels through the ensemble machine learning.

2 . The cyber threat information processing method according to claim 1 , wherein the malware profiling information includes malware similarity information generated by determining similarity between a piece of the combined code and previously-stored malware according to a natural language processing scheme.

3 . The cyber threat information processing method according to claim 1 , wherein the cyber threat information processing method is performed by a cyber threat information processing processor implemented as a system-on-chip (SoC).

4 . The cyber threat information processing method according to claim 1 , wherein the independent communication network is a communication network connected to a cyber threat information processing processor performing the cyber threat information processing method, and corresponds to at least one of an LTE, 5G, or 6G communication network.

5 . A cyber threat information processing processor comprising:

a memory configured to store an executable file via a communication network;

a processor configured to generate characteristic information of the executable file,

wherein the processor is configured to:

disassemble the executable file to obtain disassembled code;

reconstruct the disassembled code to extract combined code for a function of the executable file, wherein the combined code includes a set of opcode and assembly code;

convert the combined code for the function into a hash value;

generate characteristic information of the executable file based on the hash value or N-gram data obtained from the hash value, wherein the N is a natural number; and

a communication module configured to transmit the characteristic information of the executable file over an independent communication network, and receive malware profiling information corresponding to the executable file over the independent communication network different from the communication network,

the malware profiling information being generated by performing ensemble machine learning on the characteristic information of the executable file,

wherein the hash value or N-gram data are analyzed to remove code patterns irrelevant to an attack technique with an attack identifier defined in a standardized model and select code patterns linked to the attack identifier,

wherein the characteristic information is labeled with two parts of labels,

wherein a first part of the labels represents the attack technique and a second part of the labels represents an attacker implementing the attack technique, wherein the ensemble machine learning is performed on the selected code patterns to classify both an identifier of the attack technique and an identifier of the attacker as the malware profiling information simultaneously based on the two parts of labels, and

wherein the malware profiling information is classified by applying the characteristic information with the two parts of labels through the ensemble machine learning.

6 . The cyber threat information processing processor according to claim 5 , wherein the malware profiling information includes malware similarity information generated by determining similarity between a piece of the combined code of the N-gram data and previously-stored malware according to a natural language processing scheme.

7 . The cyber threat information processing processor according to claim 5 , wherein the cyber threat information processing processor is a system-on-chip (SoC).

8 . The cyber threat information processing processor according to claim 5 , wherein the independent communication network is a communication network connected to the cyber threat information processing processor, and corresponds to at least one of an LTE, 5G, or 6G communication network.

9 . A non-transitory storage medium that stores a computer-readable program, the non-transitory storage medium storing one or more programs for processing cyber threat information, the one or more programs including instructions executed by one or more programs of a cyber threat information processing processor, and the one or more programs causing the cyber threat information processing processor to:

receive an executable file via a communication network;

disassemble the executable file to obtain disassembled code, and reconstruct the disassembled code to extract combined code for a function of the executable file, wherein the combined code includes a set of opcode and assembly code;

convert the combined code for the function into a hash value;

generate characteristic information of the executable file based on the hash value or N-gram data obtained from the hash value, wherein the the N is a natural number;

transmit the characteristic information of the executable file over an independent communication network different from the communication network; and

receive malware profiling information corresponding to the executable file over the independent communication network, the malware profiling information being generated by performing ensemble machine learning on the characteristic information of the executable file,

wherein the hash value or N-gram data are analyzed to remove code patterns irrelevant to an attack technique with an attack identifier defined in a standardized model and select code patterns linked to the attack identifier,

wherein the characteristic information is labeled with two parts of labels,

wherein a first part of the labels represents the attack technique and a second part of the labels represents an attacker implementing the attack technique, wherein the ensemble machine learning is performed on the selected code patterns to classify both an identifier of the attack technique and an identifier of the attacker as the malware profiling information simultaneously based on the two parts of labels, and

wherein the malware profiling information is classified by applying the characteristic information with the two parts of labels through the ensemble machine learning.

10 . The non-transitory storage medium according to claim 9 , wherein the malware profiling information includes malware similarity information generated by determining similarity between a piece of the combined code and previously-stored malware according to a natural language processing scheme.

11 . The non-transitory storage medium according to claim 9 , wherein the cyber threat information processing processor is implemented as a system-on-chip (SoC).

12 . The non-transitory storage medium according to claim 9 , wherein the independent communication network is a communication network connected to the cyber threat information processing processor performing a cyber threat information processing method, and corresponds to at least one of an LTE, 5G, or 6G communication network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 7, 2023
From: KIM, KI HONG
To: SANDS LAB INC.
Reel/Frame 062611/0062 →
Priority Claims (1)
KR 10-2022-0017154 · Feb 9, 2022 · national
Continuity (1)
Related Publication 20230252144A1 · Aug 10, 2023
References Cited (15)
US 8826439B1 · Hu · 2014 [cited by examiner]
US 10133865B1 · Feinman · 2018 [cited by examiner]
US 11374946B2 · Hewlett, II · 2022 [cited by examiner]
US 11436330B1 · Jennings · 2022 [cited by examiner]
US 11636208B2 · Hewlett, II · 2023 [cited by examiner]
US 20200364334A1 · Pevny · 2020 [cited by examiner]
US 20210110037A1 · Hunt · 2021 [cited by examiner]
US 20210256160A1 · Hachey · 2021 [cited by examiner]
US 20210342447A1 · Sanzgiri · 2021 [cited by examiner]
US 20220067153A1 · Roy · 2022 [cited by examiner]
KR 101279213A · 2013 [cited by applicant]
KR 1020160082644A · 2016 [cited by applicant]
KR 102225460A · 2021 [cited by applicant]
WO WO2020047782A1 · 2020 [cited by examiner]
Bai et al., “Improving malware detection using multi-view ensemble learning,” Security and Communication Networks (2016). [cited by applicant]