Method for providing cyber security service for detecting cyber threat to network by using virtual host and cyber security service providing server using the same

The use of virtual hosts in access switches addresses CPU and memory constraints, enhancing cyber threat detection and response in complex networks by simulating attacks and managing security through a centralized server system.

JP2026011990AActive Publication Date: 2026-01-23PIOLINK
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024137062
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-07-11
Filing Date
2024-08-16
Publication Date
2026-01-23
Estimated Expiration
2044-08-16

AI Technical Summary

Technical Problem

Existing network security systems face limitations in CPU performance and memory shortages, struggle to detect various forms of cyber threats effectively, and fail to respond efficiently to changes in cyberattacks, particularly in complex network environments with intertwined devices.

Method used

A cybersecurity service is provided using virtual hosts generated in access switches, which analyze traffic and block potential threats by simulating attacks, updating malware profiles, and managing network security through a centralized server system.

Benefits of technology

This approach enhances threat detection and response efficiency, effectively blocking cyber threats and maintaining network stability by leveraging virtual hosts to overcome CPU and memory limitations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026011990000001_ABST
    Figure 2026011990000001_ABST
Patent Text Reader

Abstract

To provide a method and a cyber security service providing server for improving a correct detection rate by conquering low CPU performance and memory shortage, and reducing the probability of non-detection by detecting various forms of threat actions occurring in a network.SOLUTION: In the cyber security service providing system 1000, the cyber security service providing server 100 acquires and registers subscription request information for a cyber security service from an arbitrary network manager terminal 210 that manages each of the plurality of networks 200, generates a plurality of virtual host iPS and a virtual host MAC address corresponding to the IP address of the virtual host VH using a host address that is not used by an active host connected to a switching port of the access switch AS so that the active host can perform communication with reference to the subscription information, and transmits the virtual host iPS and the virtual host MAC address to each access switch.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a method for providing a cybersecurity service for a network, and more particularly to a method for providing a cybersecurity service for detecting cyberthreats in a network by creating a virtual host in an access switch to which a host in the network is connected and inducing the virtual host to attempt a network attack. [Background technology]

[0002] A cyber threat is a malicious and deliberate attempt by an individual or organization to compromise the security of another individual or organization's information system, usually with the intent of disrupting the victim's network to gain some benefit.

[0003] These cyber threats come in a variety of forms, including malware, phishing, man-in-the-middle (MitM) attacks, denial-of-service (DoS) attacks, and zero-day exploits.

[0004] To prevent such cyber threats, network-based security devices such as firewalls, IPS, UTMs, and web firewalls separate external and internal networks and analyze and protect traffic flowing from the external network to the internal network and traffic flowing from the internal network to the outside, thereby protecting the entire network.

[0005] Meanwhile, to ensure the reliability of network communications by blocking harmful traffic that can infect hosts on the internal network with viruses and other infections, causing performance degradation and failures in network core devices, and to prevent secondary infection from spreading to other hosts, there is growing interest in security switches that analyze traffic generated on the internal network and block traffic at the switch level if it is determined to be harmful traffic or a cyber threat.

[0006] In such security switches, cyber threats are typically determined by detecting an action by one host searching for multiple hosts, or by detecting an action by multiple hosts sending a large amount of traffic to one host.

[0007] However, there are clear limitations to applying such security switches in a network environment where various devices and operating environments are intricately intertwined.

[0008] Furthermore, responding to cyber threats using such security switches has the limitation that it must distinguish between positive detections and situations in which a threat is actually detected, and it cannot respond to changes in the form of various cyber attacks.

[0009] In addition, low CPU performance and insufficient memory limit the ability to monitor all traffic occurring on the network.

[0010] Therefore, the present applicant proposes a method for overcoming low CPU performance and memory shortages, detecting various forms of threatening behavior occurring in a network, reducing the probability of undetection, and improving the correct detection rate. Summary of the Invention [Problem to be solved by the invention]

[0011] An object of the present invention is to solve all of the problems of the prior art described above.

[0012] Another object of the present invention is to overcome the low CPU performance and memory shortage of access switches and provide a cybersecurity service that effectively detects cyber threats occurring in the network.

[0013] It is yet another object of the present invention to provide a cybersecurity service that generates a virtual host in an access switch and detects cyber threats.

[0014] Another object of the present invention is to provide a cybersecurity service that blocks a host that poses a cyber threat from the network by making the virtual host created in the access switch pose a cyber threat.

[0015] It is yet another object of the present invention to provide a cybersecurity service that efficiently responds to changes in the form of cyberattacks by using virtual hosts. [Means for solving the problem]

[0016] In order to achieve the above-mentioned object of the present invention, the present invention has the following typical features.

[0017] According to one embodiment of the present invention, a method for providing a cybersecurity service for detecting cyberthreats to a network using a virtual host includes the steps of: (a) receiving subscription request information for a cybersecurity service from a specific network administrator terminal, which is at least one of a first network administrator terminal through an nth network administrator terminal that manages each of a first network through an nth network (where n is an integer greater than or equal to 1), constituting an independent network; and (b) receiving subscription request information for a specific cybersecurity service from a specific network administrator terminal, the cybersecurity service providing server refers to the subscription request information and registers subscription information for the specific cybersecurity service for the specific network corresponding to the specific network administrator terminal; and (i) receiving subscription information for a specific network belonging to the specific network from the specific network, the cybersecurity service providing server refers to the subscription information for the specific cybersecurity service and registers subscription information for the specific network belonging to the specific network. (ii) generating at least one specific first virtual host IP address through at least one specific m-th virtual host IP address using a specific unused host address not used by a specific active host, which is a host connected to a switching port of a specific first access switch through a specific m-th access switch (where m is an integer equal to or greater than 1) that allows a host currently connected to the specific first access switch to communicate; and generating at least one specific first virtual host MAC address corresponding to the specific first virtual host IP address through at least one specific m-th virtual host MAC address corresponding to the specific m-th virtual host IP address; (ii) transmitting the specific first virtual host IP address and the specific first virtual host MAC address through the specific first access switch through the specific m-th access switch,a step of generating at least one specific first virtual host through the specific m-th virtual host IP address corresponding to the specific first virtual host IP address and the specific first virtual host MAC address in each of the specific first security engine through the specific m-th access switch, and determining, via at least one of the specific first security engine through the specific m-th security engine, a specific active host that performs a function of scanning at least one of the specific first virtual host through the specific m-th virtual host IP address and a function of transmitting a data packet to at least one of the specific first virtual host through the specific m-th virtual host MAC address using at least one of the specific first virtual host IP address through the specific m-th virtual host IP address, and blocking the specific active host from the specific network.

[0018] In one example, before step (b), the cybersecurity service providing server generates a malware profile including the behavior pattern of the pre-confirmed malware from a malware database storing behavior patterns of the pre-confirmed malware, and transmits the malware profile for the pre-confirmed malware to the specific network controller, or transmits the malware profile to the specific network controller via the specific network administrator terminal, so that the specific network controller registers the malware profile for the pre-confirmed malware in the specific first security engine through the specific m-th security engine; and in step (b), the cybersecurity service providing server registers the data packet using any one of the specific first security engine through the specific m-th security engine. a process for analyzing a data code of a packet to check an analyzed behavior pattern obtained by analyzing the behavior pattern of the data code, (i) determining that the data code is a specific malware corresponding to the specific registered behavior pattern when a specific registered behavior pattern among registered behavior patterns corresponding to each of pre-registered malware profiles matches the analyzed behavior pattern, and blocking the specific active host from the specific network through at least one of the specific first access switch to the specific mth access switch, (ii) determining that the data code is unidentified malware when each of the registered behavior patterns does not match the analyzed behavior pattern, and (ii-1) blocking the specific active host from the specific network through at least one of the specific first access switch to the specific mth access switch, and then transmitting an alarm to the specific network controller;and (ii-2) a process for transmitting the alarm to the specific network controller while the specific active host is not blocked from the specific network.

[0019] In one example, (c) when the cybersecurity service providing server acquires a security log corresponding to the unconfirmed malware from the specific network controller or the specific network administrator terminal (the security log includes at least a portion of the host scan packet and the data packet corresponding to the unconfirmed malware), the cybersecurity service providing server updates the malware database by referring to the result of analyzing the unconfirmed malware, generates an unconfirmed malware profile for the unconfirmed malware including an operation pattern for the unconfirmed malware, and transmits malware profile update notification information to the specific network administrator terminal; and (d) acquires malware profile update request information from the specific network administrator terminal in response to the malware profile update notification information. When the method is completed, the cybersecurity service providing server refers to subscription information of the specific cybersecurity service to check whether the specific network has malware profile update authority for updating the malware profile, and if it is confirmed that the specific network has malware profile update authority, transmits the unconfirmed malware profile to the specific network controller or transmits it to the specific network controller via the specific network administrator terminal, and uses the specific network controller to update the pre-registered malware profile of the specific first security engine through the specific mth security engine.

[0020] In one example, in step (d), if the cybersecurity service providing server confirms that the specific network does not have the authority to update the malware profile, it requests an additional subscription for updating the malware profile from the specific network administrator terminal, and when additional subscription request information for updating the malware profile is obtained from the specific network administrator terminal, it updates the subscription information for the specific cybersecurity service by referring to the additional subscription request information, and transmits the unconfirmed malware profile to the specific network controller, or transmits it to the specific network controller through the specific network administrator terminal, so that the specific network controller uses the unconfirmed malware profile to update the pre-registered malware profiles of the specific first security engine to the specific mth security engine.

[0021] In one example, in step (d), if the cybersecurity service providing server determines that the unconfirmed malware profile is to be transmitted to the specific network controller through the specific network administrator terminal, the cybersecurity service providing server may transmit the unconfirmed malware profile to the specific network administrator terminal through at least one of SMS, a messaging app, and email corresponding to the specific network administrator terminal.

[0022] In one example, the method further includes the step of (e) transmitting malware profile update history information to the specific network administrator terminal when the cybersecurity service providing server completes updating the pre-registered malware profile.

[0023] In one example, the cybersecurity service providing server may transmit update history information of the malware profile to the specific network administrator terminal at a predetermined time period or at a specific time based on subscription information of the specific cybersecurity service.

[0024] In one example, in step (b), the cybersecurity service providing server can use the specific network controller to group the specific unused host addresses into groups 1_1 through 1_n, and generate the specific first virtual host IP address that references the specific unused host addresses of group 1_1 through the specific mth virtual host IP address that references the specific unused host addresses of group 1_n.

[0025] In one example, in step (b), the cybersecurity service providing server can use the specific network controller to group all specific host addresses of the specific network into groups 2_1 through 2_n, and generate the specific first virtual host IP address that references a specific unused host address among all specific host addresses of group 2_1, or the specific mth virtual host IP address that references a specific unused host address among all specific host addresses of group 2_n.

[0026] In one example, in step (b), when the number of specific virtual hosts to be generated on the specific network is k (where k is an integer greater than or equal to m), the network controller, using the specific network controller, can group all specific host addresses of the specific network into 3_1 groups through 3_m groups, generate a specific 3_1 virtual host IP address that references one specific unused host address in the 3_1 group through a specific 3_k virtual host IP address that references one specific unused host address in the 3_m group, and group the specific 3_1 virtual host IP addresses through the specific 3_k virtual host IP addresses into m groups to generate the specific 1 virtual host IP addresses through the specific m virtual host IP addresses.

[0027] According to another embodiment of the present invention, a cybersecurity service providing server for providing a cybersecurity service for detecting cyberthreats to a network using a virtual host includes: a memory storing instructions for providing a cybersecurity service for detecting cyberthreats to a network using a virtual host; and a processor that executes operations for providing a cybersecurity service for detecting cyberthreats to the network using the virtual host according to the instructions stored in the memory; wherein the processor is configured to: (I) provide a first network through an nth network (where n is an integer equal to or greater than 1) that constitute independent networks; and (II) a process for registering subscription information for a specific cybersecurity service for a specific network corresponding to the specific network administrator terminal by referring to the subscription request information when subscription request information for the cybersecurity service is obtained from a specific network administrator terminal which is at least one of the first network administrator terminal through the nth network administrator terminal that manages each of the above. And (II) a process for (i) generating at least one specific first virtual host IP address through at least one specific mth virtual host IP address by using a specific unused host address that is not used by a specific active host, which is a host connected to a switching port of a specific first access switch through a specific mth access switch (where m is an integer equal to or greater than 1) that enables hosts belonging to the specific network to communicate within the specific network, and generating at least one specific first virtual host MAC address corresponding to the specific first virtual host IP address through at least one specific mth virtual host MAC address corresponding to the specific mth virtual host IP address,(ii) transmitting the specific first virtual host IP address and the specific first virtual host MAC address through the specific m-th virtual host IP address and the specific m-th virtual host MAC address to the specific first access switch through the specific m-th access switch, respectively, and transmitting at least one specific first virtual host through the specific m-th virtual host IP address corresponding to the specific first virtual host IP address and the specific first virtual host MAC address to a specific first security engine set inside the specific first access switch through the specific m-th access switch, respectively, through the specific first access switch through the specific m-th access switch. and at least one specific m-th virtual host corresponding to the specific m-th virtual host MAC address, and a specific active host that performs a function of scanning at least one of the specific first virtual host through the specific m-th virtual host using at least one of the specific first virtual host IP address through the specific m-th virtual host IP address and a function of transmitting a data packet to at least one of the specific first virtual host through the specific m-th virtual host is determined through at least one of the specific first security engine through the specific m-th security engine, and is blocked from the specific network.

[0028] In one example, the processor, before the (II) process, generates a malware profile including the behavioral pattern of the pre-confirmed malware from a malware database storing behavioral patterns of the pre-confirmed malware, and transmits the malware profile for the pre-confirmed malware to the specific network controller, or transmits it to the specific network controller via the specific network administrator terminal, so that the specific network controller registers the malware profile for the pre-confirmed malware in the specific first security engine through the specific m-th security engine, and in the (II) process, uses any one specific security engine among the specific first security engine through the specific m-th security engine that received the data packet to analyze the data code of the data packet and confirm an analyzed behavioral pattern obtained by analyzing the behavioral pattern of the data code, (i) the pre-registered malware profile (ii) if a specific registered operation pattern among the registered operation patterns corresponding to each of the above matches with the analyzed operation pattern, the data code is determined to be specific malware corresponding to the specific registered operation pattern, and the specific active host is blocked from the specific network through at least one of the specific first access switch to the specific mth access switch; and (ii) if each of the registered operation patterns does not match with the analyzed operation pattern, the data code is determined to be unidentified malware, and one of the following processes can be executed: (ii-1) a process of blocking the specific active host from the specific network through at least one of the specific first access switch to the specific mth access switch, and then sending an alarm to the specific network controller; and (ii-2) a process of sending the alarm to the specific network controller while the specific active host is not blocked from the specific network.

[0029] In one example, the processor includes: (III) a process for updating the malware database by referring to a result of analyzing the unconfirmed malware when a security log corresponding to the unconfirmed malware (the security log includes at least a portion of the host scan packet and the data packet corresponding to the unconfirmed malware) is acquired from the specific network controller or the specific network administrator terminal; generating an unconfirmed malware profile for the unconfirmed malware including an operation pattern for the unconfirmed malware; and transmitting malware profile update notification information to the specific network administrator terminal; and (IV) a process for receiving malware profile update request information from the specific network administrator terminal in response to the malware profile update notification information. Once obtained, the process can further include referencing subscription information for the specific cybersecurity service to determine whether the specific network has malware profile update authority for updating the malware profile, and if it is determined that the specific network has malware profile update authority, transmitting the unconfirmed malware profile to the specific network controller or transmitting it to the specific network controller via the specific network administrator terminal, and using the specific network controller to update the pre-registered malware profiles of the specific first security engine through the specific mth security engine.

[0030] In one example, if the processor determines in the (IV) process that the specific network does not have the authority to update the malware profile, it requests an additional subscription for the malware profile update from the specific network administrator terminal, and when additional subscription request information for the malware profile update is obtained from the specific network administrator terminal, it updates the subscription information for the specific cybersecurity service by referring to the additional subscription request information, and transmits the unconfirmed malware profile to the specific network controller or transmits it to the specific network controller through the specific network administrator terminal, so that the specific network controller uses the unconfirmed malware profile to update the pre-registered malware profiles of the specific first security engine to the specific mth security engine.

[0031] In one example, when the processor, in the (IV) process, causes the unconfirmed malware profile to be transmitted to the specific network controller through the specific network administrator terminal, the processor may transmit the unconfirmed malware profile to the specific network administrator terminal through at least one of SMS, a messaging app, and email corresponding to the specific network administrator terminal.

[0032] In one example, the processor may further execute (V) a process of transmitting malware profile update history information to the specific network administrator terminal when the update of the pre-registered malware profile is completed.

[0033] In one example, the processor can transmit update history information of the malware profile to the specific network administrator terminal at a predetermined time period or at a specific time based on subscription information of the specific cybersecurity service.

[0034] In one example, in the (II) process, the processor can use the specific network controller to group the specific unused host addresses into groups 1_1 through 1_n, and generate the specific first virtual host IP address that references the specific unused host addresses of the 1_1 group through the specific mth virtual host IP address that references the specific unused host addresses of the 1_n group.

[0035] In one example, in the (II) process, the processor can use the specific network controller to group all specific host addresses of the specific network into 2_1 group through 2_n group, and generate the specific first virtual host IP address that references a specific unused host address among all specific host addresses of the 2_1 group through the specific mth virtual host IP address that references a specific unused host address among all specific host addresses of the 2_n group.

[0036] In one example, in the (II) process, when the number of specific virtual hosts to be generated on the specific network is k (where k is an integer greater than or equal to m), the processor, using the specific network controller, can group all specific host addresses of the specific network into 3_1 group through 3_m group, generate a specific 3_1 virtual host IP address that references one specific unused host address in the 3_1 group through a specific 3_k virtual host IP address that references one specific unused host address in the 3_m group, and group the specific 3_1 virtual host IP addresses through the specific 3_k virtual host IP addresses into m groups to generate the specific 1 virtual host IP address through the specific m virtual host IP address.

[0037] Additionally, there is further provided a computer readable recording medium for recording a computer program for performing the method of the present invention. [Effects of the Invention]

[0038] According to the present invention, it is possible to overcome the low CPU performance and memory shortage of access switches and provide a cybersecurity service that effectively detects cyber threats occurring in the network.

[0039] Furthermore, according to the present invention, it is possible to provide a cybersecurity service that detects cyber threats by generating a virtual host in an access switch.

[0040] Furthermore, according to the present invention, it is possible to provide a cybersecurity service that blocks hosts that pose cyberthreats from the network by making the virtual hosts created in the access switch pose cyberthreats.

[0041] Furthermore, according to the present invention, it is possible to provide a cybersecurity service that efficiently responds to changes in the form of cyberattacks by using virtual hosts. [Brief explanation of the drawings]

[0042] The following drawings attached for use in explaining embodiments of the present invention are only a part of the embodiments of the present invention, and a person having ordinary knowledge in the technical field to which the present invention pertains (hereinafter referred to as "ordinary engineer") can derive other drawings based on these drawings without performing any inventive work.

[0043] [Figure 1] 1 is a diagram illustrating a system for providing cybersecurity services that detect cyber threats to a network using virtual hosts according to one embodiment of the present invention. [Figure 2] FIG. 1 is a diagram illustrating an access switch that uses virtual hosts to detect cyber threats to a network according to one embodiment of the present invention. [Figure 3] 1 is a diagram illustrating a method for providing a cybersecurity service for detecting cyber threats to a network using a virtual host according to one embodiment of the present invention. [Figure 4] 1 is a diagram illustrating a process in which an access switch detects cyber threats to a network using a virtual host according to one embodiment of the present invention. [Figure 5] 1 is a diagram illustrating a malware profile update process for an access switch according to an embodiment of the present invention; DETAILED DESCRIPTION OF THE INVENTION

[0044] The following detailed description of the present invention refers to the accompanying drawings, which show, by way of illustration, specific embodiments in which the invention may be practiced. These embodiments are described in sufficient detail to enable one of ordinary skill in the art to practice the invention. It should be understood that although the various embodiments of the present invention are different from one another, they are not necessarily mutually exclusive. For example, specific shapes, structures, and characteristics described herein may be implemented differently from one embodiment to another without departing from the spirit and scope of the present invention. It should also be understood that the location or arrangement of individual components within each embodiment may be changed without departing from the spirit and scope of the present invention. Therefore, the following detailed description should not be taken in a limiting sense, and the scope of the present invention should be understood to encompass the scope of the appended claims and all equivalents thereto. In the drawings, like reference numerals indicate the same or similar components throughout the various aspects.

[0045] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS In the following, preferred embodiments of the present invention will be described in detail with reference to the accompanying drawings so that those skilled in the art can easily practice the present invention.

[0046] FIG. 1 is a diagram illustrating a system for providing cybersecurity services for detecting cyber threats to a network using a virtual host according to one embodiment of the present invention, and the overall system 1000 may include a cybersecurity service providing server 100 and at least one network 200_1 to 200_n.

[0047] First, the cybersecurity service providing server 100 provides cybersecurity services to at least one network 200_1 to 200_n that has subscribed to a cybersecurity service, and may include a memory 110 storing instructions for providing a cybersecurity service that detects cyberthreats to the network using a virtual host, and a processor 120 that performs operations for providing a cybersecurity service that detects cyberthreats to the network using a virtual host in accordance with the instructions stored in the memory 110.

[0048] Specifically, the cybersecurity service provider server 100 may typically utilize, but is not limited to, a combination of computing devices (e.g., devices that may include computer processors, memory, storage, input and output devices, and other conventional computing device components; electronic communication devices such as routers, switches, etc.; electronic information storage systems such as network-attached storage (NAS) and storage area networks (SAN)) and computer software (i.e., instructions that cause a computing device to function in a particular manner) to achieve desired system performance.

[0049] The processor of the cybersecurity service providing server 100 may include hardware components such as an MPU (Micro Processing Unit) or a CPU (Central Processing Unit), a cache memory, a data bus, etc. The cybersecurity service providing server 100 may also include software components such as an operating system and applications that perform specific purposes.

[0050] However, this does not exclude the case where the cybersecurity service providing server 100 includes an integrated processor in which a medium, a processor, and a memory for implementing the present invention are integrated.

[0051] Next, each of the first network 200_1 through the n-th network 200_n constitutes a different independent network, and by subscribing to a cybersecurity service, cyber threats occurring within each network are detected and defended against using virtual hosts, and each of the first network 200_1 through the n-th network 200_n may include a network management terminal, a network administrator terminal, and at least one access switch. In this case, the number of access switches in each of the first network 200_1 through the n-th network 200_n may be configured to differ from one another depending on the respective network environments.

[0052] As an example, a first network 200_1, which is a specific network among multiple networks, may include a first network administrator terminal 210_1, a first network controller 220_1, and at least one access switch, namely, a first access switch AS_1 to an m-th access switch AS_m.

[0053] The first network administrator terminal 210_1 is a terminal used by a first network administrator who manages a first network, and can perform operations related to the subscription of a cybersecurity service. In this case, the first network administrator terminal 210_1 may include various computing devices that perform wired or wireless communication, such as a personal computer (PC), a laptop computer, or a mobile terminal.

[0054] The first network controller 220_1 configures network security for managing the first network, stores at least one security log for cyber threats detected within the first network, and transmits the log to the cybersecurity service providing server 100. The first network controller 220_1 may include a memory storing instructions for managing the first network and a processor executing operations for managing the first network according to the instructions stored in the memory. Specifically, the first network controller 220_1 may typically achieve desired system performance using, but is not limited to, a combination of a computing device (e.g., a device that may include a computer processor, memory, storage, input and output devices, and other conventional computing device components; electronic communication devices such as routers, switches, etc.; and electronic information storage systems such as network-attached storage (NAS) and storage area networks (SANs)) and computer software (i.e., instructions that cause a computing device to function in a specific manner). The processor of the first network controller 220_1 may include hardware components such as an MPU (Micro Processing Unit) or a CPU (Central Processing Unit), a cache memory, and a data bus. The first network controller 220_1 may further include software components such as an operating system and an application that executes a specific purpose. However, this does not exclude the case where the first network controller 220_1 includes an integrated processor in which a medium, a processor, and a memory for implementing the present invention are integrated.

[0055] In addition, each of the first access switch AS_1 through the mth access switch AS_m enables the first active host AH_*_* and the first virtual host VH_*_* to communicate with each other within the first network, and may include a memory for detecting cyber threats to the first network using the virtual host VH_*_*, and a processor for performing operations for detecting cyber threats to the first network using the virtual host VH_*_* in accordance with instructions stored in the memory.

[0056] Specifically, each of the first access switch AS_1 through the mth access switch AS_m may typically utilize, but is not limited to, a combination of computing devices (e.g., devices that may include computer processors, memory, storage, input and output devices, and other conventional computing device components; electronic communication devices such as routers, switches, etc.; electronic information storage systems such as network-attached storage (NAS) and storage area networks (SAN)) and computer software (i.e., instructions that cause a computing device to function in a particular manner) to achieve the desired system performance.

[0057] Furthermore, each processor of the first access switch AS_1 to the m-th access switch AS_m may include hardware components such as an MPU (Micro Processing Unit) or a CPU (Central Processing Unit), a cache memory, a data bus, etc. Furthermore, each of the first access switch AS_1 to the m-th access switch AS_m may further include a software component of an operating system and an application that executes a specific purpose.

[0058] However, this does not exclude the case where each of the first access switch AS_1 to the m-th access switch AS_m includes an integrated processor in which a medium for implementing the present invention, a processor, and a memory are integrated.

[0059] In addition, each of the first access switch AS_1 to the mth access switch AS_m can be configured not only as a physical module that performs L2 switch functions, but also as a logical module such as a virtual switch that performs L2 switch functions in a cloud environment such as OVS (Open vSwitch).

[0060] The configuration of an access switch according to an embodiment of the present invention will be described below with reference to FIG.

[0061] The access switch AS according to an embodiment of the present invention may include switch hardware 10 , a communication packet processing module 20 , a network stack 30 , and a security engine 40 .

[0062] Specifically, the switch hardware 10 performs switching operations to forward communication packets received via the network to a destination host, and a virtual host MAC switch may be registered to forward communication packets destined for a virtual host.

[0063] The communication packet processing module 20 analyzes communication packets received via the network to determine a destination host, and refers to the determined destination host to forward the communication packet to the destination host via the switch hardware 10. If the communication packet is for a virtual host, it transmits the communication packet to the security engine 40, and if the communication packet is for broadcast, it can broadcast the communication packet to other active hosts via the network stack 30 and duplicate the communication packet to transmit it to the security engine 40. In addition, the communication packet processing module 20 can forward communication packets generated by the virtual host, i.e., the security engine 40, to the destination host via the switch hardware 10.

[0064] Furthermore, the network stack 30 can forward communication packets addressed to hosts connected to other access switches to the other access switches via the switch hardware 10 .

[0065] Meanwhile, when at least one virtual host VH is created, the security engine 40 analyzes a host scan packet transmitted to the virtual host, identifies a specific host scan method used in the host scan packet from among pre-defined host scan methods, and generates and transmits a response packet. When a data packet is transmitted to the virtual host in response to the response packet, the security engine 40 determines that the data packet is malware and blocks the specific active host that transmitted the data packet from the network to the virtual host through at least one of the access switches.

[0066] Also, although the above description has been given as an example in which the access switch AS is configured with physical modules, the present invention is not limited to this, and the access switch AS can also be configured with logical modules that perform L2 switch functions through a virtual switch such as OVS.

[0067] Referring to the system according to one embodiment of the present invention configured as above, a method for providing a cybersecurity service for detecting cyber threats to a network using a virtual host will be described below with reference to Figures 1 to 3.

[0068] First, the cybersecurity service providing server 100 can acquire subscription request information for a cybersecurity service from a specific network administrator terminal 210_1, which is at least one of the first network administrator terminals 210_1 through the n-th network administrator terminals 210_n that manage the first network 200_1 through the n-th network 200_n, which respectively constitute independent networks. For reference, the specific network administrator terminal is assumed to be the first network administrator terminal 210_1, and the following description will be given assuming that the specific network is the first network 200_1.

[0069] The cybersecurity service providing server 100 can then refer to the subscription request information for the cybersecurity service obtained from the specific network administrator terminal 210_1 and register the subscription information for the specific cybersecurity service for the specific network 200_1, thereby registering (S100) the subscription for the cybersecurity service for the specific network 200_1.

[0070] In this case, the subscription information for a specific cybersecurity service may include various information for providing cybersecurity services, such as information on the specific network 200_1, information on the specific network administrator terminal 210_1, information on the specific network administrator, information on the scope of use of cybersecurity services by the specific network 200_1, payment information, and information on terms and conditions related to the specific cybersecurity service provided to the specific network 200_1.

[0071] Thereafter, the cybersecurity service providing server 100 can provide a cybersecurity service that detects cyber threats using the virtual host to the specific network 200_1 (S200).

[0072] Specifically, the cybersecurity service providing server 100 has a specific network controller 220_1 that manages a specific network 200_1 by referring to subscription information for a specific cybersecurity service, and can generate at least one specific first virtual host IP address or at least one specific mth virtual host IP address using a specific unused host address that is not used by a specific active host AH_*_*, which is a host connected to the switching port of a specific first access switch AS_1 or a specific mth access switch AS_m that enables hosts belonging to the specific network 200_1 to communicate within the specific network 200_1, and can generate at least one specific first virtual host MAC address corresponding to the specific first virtual host IP address or at least one specific mth virtual host MAC address corresponding to the specific mth virtual host IP address. The cybersecurity service providing server 100 can then use a specific network controller 220_1 to transmit each of the specific first virtual host IP address and the specific first virtual host MAC address through the specific mth virtual host IP address and the specific mth virtual host MAC address to each of the specific first access switches AS_1 through the specific mth access switches AS_m, and generate at least one specific first virtual host VH_1_* corresponding to the specific first virtual host IP address and the specific first virtual host MAC address through the specific first access switch AS_1 through the specific mth access switch AS_m in each of the specific first security engine set inside the specific first access switch AS_1 through the specific mth security engine set inside the specific mth access switch AS_m.As a result, the cybersecurity service providing server 100 can determine a specific active host VH_1_1 that performs the function of scanning at least one of the specific first virtual hosts VH_1_* through the specific mth virtual hosts VH_m_* using at least one of the specific first virtual host IP addresses through the specific mth virtual host IP addresses, and the function of transmitting data packets to at least one of the specific first virtual hosts VH_1_* through the specific mth virtual hosts VH_m_* through the specific mth security engine, and block it from the specific network 200_1.

[0073] In other words, the cybersecurity service providing server 100 can refer to subscription information for a specific cybersecurity service, and use a specific network controller 220_1 that manages the specific network 200_1 to build a cyberthreat detection system in the specific network 200_1 for detecting cyberthreats using virtual hosts.

[0074] At this time, the process in which a specific network controller 220_1 constructs a cyber threat detection system for detecting cyber threats using a virtual host in a specific network 200_1 will be described in more detail as follows.

[0075] Each of the specific first access switch AS_1 to the specific mth access switch AS_m installed in the specific network 200_1 can monitor the ARP (Address Resolution Protocol) communication of the specific active host AH_*_* connected to the specific network 200_1, collect the IP address and MAC address of the specific active host AH_*_* connected to the specific network 200_1, and then transmit them to the specific network controller 220_1.

[0076] Then, the specific network controller 220_1 refers to the IP address and MAC address of the specific active host AH_*_* connected to the specific network 200_1, and performs active host management in real time.

[0077] Then, the specific network controller 220_1 can refer to the active host list obtained from the specific first access switch AS_1 to the specific mth access switch AS_m to identify unused IP addresses, and generate specific virtual hosts VH_*_* using the unused IP addresses.

[0078] That is, the specific network controller 220_1 generates at least one specific first virtual host IP address through at least one specific m-th virtual host IP address using unused host addresses not used by the specific active host AH_*_* among all host addresses of the specific network 200_1, and generates at least one specific first virtual host MAC address through at least one specific m-th virtual host MAC address corresponding to the specific first virtual host IP address. Then, the specific network controller 220_1 can transmit each of the specific first virtual host IP address and the specific first virtual host MAC address through the specific m-th virtual host IP address and the specific m-th virtual host MAC address to the specific first access switch AS_1 through the specific m-th access switch AS_m, respectively. Then, each of the specific first access switch AS_1 through the specific m-th access switch AS_m can generate at least one specific first virtual host VH_1_* referencing the specific first virtual host IP address and the specific first virtual host MAC address through at least one specific m-th virtual host VH_m_* referencing the specific m-th virtual host IP address and the specific m-th virtual host MAC address, in each of the specific first security engine through the specific m-th security engine set in the specific first access switch AS_1. At this time, each of the specific first access switch AS_1 through the specific m-th access switch AS_m can register the specific first virtual host MAC switch through the specific m-th virtual host MAC switch corresponding to the specific first virtual host VH_1_* through the specific m-th virtual host VH_m_*, respectively, in the respective switch hardware, so that communication packets destined for the specific first virtual host VH_1_* through the specific m-th virtual host VH_m_* can be transmitted to the specific first security engine through the specific n-th security engine, respectively.

[0079] For example, the specific network controller 220_1 may group unused host addresses into 1_1 group through 1_m group, and generate at least one specific 1st virtual host IP address by referring to the unused host addresses in the 1_1 group through at least one specific mth virtual host IP address by referring to the unused host addresses in the 1_m group. In this case, the specific network controller 220_1 may change some of the IP addresses used by the specific active hosts AH_*_* so that the specific virtual host IP addresses are evenly distributed among all the specific host addresses. Furthermore, the specific network controller 220_1 may distribute the specific virtual host IP addresses evenly among all the specific host addresses, but may also distribute them more intensively among some of the first half host addresses, the middle half host addresses, and the second half host addresses. This makes it possible to quickly detect cyber threats in situations where common cyber threats are made in a manner that attacks hosts with lower host addresses in order of address to hosts with higher addresses, or hosts with higher host addresses in order of address to hosts with lower addresses, or hosts with addresses in a specific location in order of address to hosts with lower addresses, or hosts with higher addresses in order of address to hosts with higher addresses, and to maintain a specific network 200_1 stable against cyber threats.

[0080] As another example, the specific network controller 220_1 may group all specific host addresses into a 2_1 group through a 2_m group, and generate at least one specific first virtual host IP address by referring to an unused host address among all specific host addresses in the 2_1 group through at least one specific m-th virtual host IP address by referring to an unused host address among all specific host addresses in the 2_m group. In this case, the specific network controller 220_1 may change some of the IP addresses used by specific active hosts AH_*_* so that the specific virtual host IP addresses are distributed evenly among all specific host addresses. Furthermore, the specific network controller 220_1 may distribute the specific virtual host IP addresses evenly among all specific host addresses, but may also distribute them more intensively among some of the first half host addresses, the middle half host addresses, and the second half host addresses. This makes it possible to quickly detect cyber threats in situations where common cyber threats are made in a manner that attacks hosts with lower host addresses in order of address to hosts with higher addresses, or hosts with higher host addresses in order of address to hosts with lower addresses, or hosts with addresses in a specific location in order of address to hosts with lower addresses, or hosts with higher addresses in order of address to hosts with higher addresses, and to maintain a specific network 200_1 stable against cyber threats.

[0081] As yet another example, when the number of at least one specific virtual host to be generated on the specific network 200_1 is k, the specific network controller 220_1 can group all specific host addresses into 3_1 group through 3_k group, generate a specific 3_1 virtual host IP address that references one unused host address in the 3_1 group through a specific 3_k virtual host IP address that references one unused host address in the 3_k group, and group the specific 3_1 virtual host IP addresses through the specific 3_k virtual host IP addresses into m groups to generate a specific 1 virtual host IP address through a specific m virtual host IP address.

[0082] As an example, suppose there are two access switches in a network that uses class C 192.168.0.255, and five virtual hosts are created on the network. The host addresses are the last octets, from 0 to 255. Of these, the IP address 192.168.0.0 corresponding to "0" is used as the network address, and the IP address 192.168.0.255 corresponding to "255" is used to broadcast messages to all hosts in the network. Therefore, the first and last IP addresses cannot be assigned to individual hosts. Therefore, the IP addresses that can actually be assigned to individual hosts are IP addresses from 192.168.0.1 to 192.168.0.254, so these are divided into five groups: group 3_1, "192.168.0.1 to 192.168.0.50", group 3_2, "192.168.0.51 to 192.168.0.100", group 3_3, "192.168.0.101 to 192.168.0.150", group 3_4, "192.168.0.1 to 192.168.0.150", group 3_5, "192.168.0.1 to 192.168.0.254", group 3_6, "192.168.0.1 to 192.168.0.254", group 3_7, "192.168.0.1 to 192.168.0.150", group 3_8, "192.168.0.1 to 192.168.0.150", group 3_9, "192.168.0.1 to 192.168.0.254", group 3_10, "192.168.0.1 to 192.168.0.150", group 3_11, "192.168.0.1 to 192.168.0.150", group 3_12, "192.168.0.1 to 192.168.0.150", group 3_13, "192.168.0.1 to 192.168.0.150", group 3_14, "19 After grouping the addresses into group 3_4 (192.168.0.151 to 192.168.0.200) and group 3_5 (192.168.0.201 to 192.168.0.254), one unused IP address from each of groups 3_1, 3_2, 3_3, 3_4, and 3_5 can be generated as the first virtual host IP address to the fifth virtual host IP address. Three virtual host IP addresses from the first virtual host IP address to the fifth virtual host IP address can then be used to generate three virtual hosts for the first access switch, and the remaining two virtual host IP addresses can be used to generate two virtual hosts for the second access switch.

[0083] For reference, in a specific network 200_1 which is the first network in FIG. 1, a specific first_1 active host AH_1_1 having an IP address of 192.168.0.10 and a specific first_2 active host AH_1_2 having an IP address of 192.168.0.11 are connected to a specific first access switch AS_1, and a specific first_1 virtual host VH_1_1 having a specific virtual host IP address of 192.168.0.2 is generated. A specific second access switch AS_2 has a specific second_1 active host AH_2_1 having an IP address of 192.168.0.21 and a specific second_2 active host VH_2_2 having an IP address of 192.168.0.22. 1. The diagram shows an example in which a specific 2_2 active host AH_2_2 having an IP address of 192.168.0.2 is connected to a specific m_1 access switch AS_m, and a specific 2_1 virtual host VH_2_1 having a specific virtual host IP address of 192.168.0.50 and a specific 2_2 virtual host VH_2_2 having a specific virtual host IP address of 192.168.0.100 are generated, and a specific m_1 active host AH_m_1 having an IP address of 192.168.0.32 is connected to a specific m_1 access switch AS_m, and a specific m_1 virtual host VH_m_1 having a specific virtual host IP address of 192.168.0.200 is generated.

[0084] When a specific virtual host VH_*_* is generated in a specific access switch AS_1 to AS_m of a specific network 200_1 by the above-described method, the process by which the specific access switch AS_1 to AS_m uses the virtual host to detect a cyber threat will be described below with reference to Figures 1 and 4. For reference, the specific active host posing a cyber threat in Figure 4 is assumed to be the 1_1 active host AH_1_1 in Figure 1, and the specific access switch AS in Figure 4 is assumed to be any one of the specific 1st access switch AS_1 to mth access switch AS_m in Figure 1, and it is assumed that one specific virtual host VH has been generated.

[0085] A specific active host AH_1_1 infected with malware can transmit (S210) a host scan packet to search for hosts connected to the specific network 200_1 through a specific first access switch AS_1 to a specific active host AH_*_* and a specific virtual host VH_*_* of the specific network 200_1 in order to infect other hosts connected to the specific network 200_1.

[0086] Then, the host scan packet transmitted from a specific active host AH_1_1 can be received by a specific access switch 200, which is any one of the specific first access switch AS_1 to the specific mth access switch AS_m installed in a specific network 200_1, and the specific access switch 200 that receives the host scan packet can check whether the destination IP address of the host scan packet corresponds to at least one specific virtual host IP address that has been previously set.

[0087] Then, after checking whether the destination IP address of the host scan packet corresponds to a specific virtual host IP address, if it is confirmed that the destination IP address of the host scan packet corresponds to a specific virtual host IP address, the specific access switch 200 can refer to the specific virtual host MAC address that matches the specific virtual host IP address and transmit the host scan packet to the specific virtual host VH.

[0088] In this case, the destination IP address of the host scan packet may be a specific IP address for scanning a specific host, or may be a broadcast IP address for scanning all hosts on the network.

[0089] Therefore, a specific access switch 200 can check the destination IP address of a host scan packet received from a specific active host AH_1_1, and if the destination IP address of the host scan packet is a specific virtual host IP address, it can transmit the host scan packet to a specific virtual host VH.

[0090] Alternatively, if a specific access switch 200 checks the destination IP address of a host scan packet received from a specific active host AH_1_1 and finds that the destination IP address of the host scan packet is a broadcast IP address, it can perform a process of broadcasting the host scan packet to active hosts on a specific network 200_1 via the network stack, and a process of duplicating the host scan packet and transmitting it to a specific virtual host VH.

[0091] Through the above operation, when a host scan packet is transmitted to a specific virtual host VH, i.e., when a specific access switch 200 transmits the host scan packet to a specific security engine in which the specific virtual host VH was generated, the specific security engine can generate a response packet that corresponds to the specific host scan method used in the host scan packet and includes the MAC address of the specific virtual host.

[0092] In this case, a specific security engine may store a pre-defined host scan method for checking a specific host scan method of a host scan packet. The pre-defined host scan method may include scan methods used in common networks, such as Internet Control Message Protocol (ICMP) scan and Transmission Control Protocol (TCP) scan, scan methods used by confirmed malware, such as Server Message Block (SMB) scan, NetBIOS scan, and NetBIOS Name Service (NBNS) scan, and all scan methods used by confirmed malware as well as common networks, such as ARP scan.

[0093] Then, the specific access switch 200 can transmit the response packet generated by the specific security engine to the specific active host AH_1_1 (S220). That is, the specific access switch 200 can respond to the specific virtual host VH scan performed by the specific active host AH_1_1 and execute a virtual host response so that the specific active host AH_1_1 can recognize the specific virtual host VH as a host that can be infected.

[0094] Thereafter, the specific active host AH_1_1 that receives the response packet determines that the specific virtual host VH is an infectable host, generates a data packet that includes malware for infecting the specific virtual host VH, has the specific virtual host IP address as the destination IP address and the specific virtual host MAC address as the destination MAC address, and then transmits the data packet to the specific access switch 200 (S230) (here, the data packet may be transmitted directly to the specific access switch 200, or may be transmitted to the specific access switch 200 via another access switch). In other words, the concept of the specific active host AH_1_1 generating a data packet and then transmitting it to the specific access switch 200 can be understood as an attempt to infect the specific virtual host VH.

[0095] Then, a specific access switch 200 can transmit a data packet transmitted from a specific active host AH_1_1, whose destination IP address and destination MAC address correspond to a specific virtual host IP address and a specific virtual host MAC address, to a specific virtual host VH.

[0096] Then, when a data packet is transmitted to a specific virtual host VH, i.e., when a specific access switch 200 transmits the data packet to a specific security engine in which the specific virtual host VH is generated, the specific security engine determines that the data packet is malware and blocks the specific active host AH_1_1 from the specific network 200_1 through at least one of the specific access switches AS_1 to AS_m installed in the specific network 200_1. In other words, the specific access switch 200 blocks the specific active host AH_1_1 attempting to infect the specific virtual host, thereby protecting the specific network 200_1 from cyber threats. This is based on the fact that attempts to scan and access a virtual host rather than an active host that is actually in operation are not normal behavior. By recognizing a virtual host generated at the access switch stage as an infectable host and then blocking the specific active host attempting to infect the virtual host from the specific network, cyber threats can be effectively blocked before they can be transmitted to other active hosts.

[0097] Meanwhile, a specific security engine of a specific access switch 200 can analyze the data code of the data packet and check the analyzed behavior pattern of the data code.

[0098] Then, when the analysis operation pattern for the data packet matches a specific registered operation pattern among the registered operation patterns corresponding to each of the pre-registered malware profiles, a specific security engine of a specific access switch 200 can determine that the data code is specific malware corresponding to the specific registered operation pattern, and can block the specific active host AH_1_1 from the specific network 200_1 through at least one of the specific access switches AS_1 to AS_m.

[0099] Alternatively, if the analyzed behavior pattern does not match each of the registered behavior patterns, the specific security engine of the specific access switch 200 may determine that the data code is unidentified malware, and may block the specific active host AH_1_1 from the specific network 200_1 through at least one of the specific access switches AS_1 to AS_m, and then send an alarm to the specific network controller 220_1 that manages the specific network 200_1, or may send an alarm to the specific network controller 220_1 without blocking the specific active host AH_1_1 from the specific network 200_1, so that the specific network controller 220_1 can decide whether to block the specific active host AH_1_1 from the specific network 200_1.

[0100] At this time, the cybersecurity service providing server 100 stores the behavior patterns of already confirmed malware in the malware database, and generates a malware profile including the behavior pattern of the confirmed malware from the malware database, and transmits the malware profile for the confirmed malware to a specific network controller 220_1, or transmits it to a specific network controller 220_1 via a specific network administrator terminal 210_1, so that the specific network controller 220_1 can register the malware profile for the confirmed malware in each of the specific first security engine of the specific first access switch AS_1 through the specific mth security engine of the specific mth access switch AS_m.

[0101] As an example, the malware database may be shown in Table 1 below, and may store information on behavioral patterns such as host scanning methods, protocols, and approach methods for confirmed malware. However, the present invention is not limited to this, and may include various information for confirming malware behavioral patterns.

[0102] [Table 1]

[0103] Additionally, a specific security engine of a specific access switch 200 can transmit a security log including at least one of a host scan packet and a data packet corresponding to unidentified malware to a specific network controller 220_1.

[0104] Referring again to Figures 1 to 3, the cybersecurity service providing server 100 can collect (S300) security logs including at least some of the host scan packets and data packets corresponding to unidentified malware from at least one network that subscribes to the cybersecurity service.

[0105] In other words, the cybersecurity service providing server 100 can obtain a security log including at least a portion of the host scan packets and data packets corresponding to the unconfirmed malware from a specific network controller 220_1 in a specific network 200_1 that detected the unconfirmed malware, or can obtain a security log including at least a portion of the host scan packets and data packets corresponding to the unconfirmed malware from a specific network administrator terminal 210_1 corresponding to the specific network 200_1.

[0106] The cybersecurity service providing server 100 can then add information about the unconfirmed malware to the malware database, as shown in Table 2 below.

[0107] [Table 2]

[0108] The cybersecurity service providing server 100 can then analyze the behavior patterns of unconfirmed malware and update the malware database by referring to the results of analyzing the unconfirmed malware.

[0109] Furthermore, the cybersecurity service providing server 100 can generate an unconfirmed malware profile for the unconfirmed malware, which includes an operation pattern for the unconfirmed malware (S400).

[0110] Thereafter, the cybersecurity service providing server 100 can transmit malware profile update notification information to a specific network administrator terminal 210_1, and can obtain malware profile update request information from the specific network administrator terminal 210_1 in response to the malware profile update notification information (S500).

[0111] Then, the cybersecurity service providing server 100 can confirm (S600) the malware profile update authority information for the specific network 200_1 based on the subscription information of the specific cybersecurity service for the specific network 200_1 that requested the malware profile update.

[0112] At this time, the cybersecurity service providing server 100 refers to the subscription information of a specific cybersecurity service for the specific network 200_1 and checks whether the specific network 200_1 has the authority to update the malware profile for updating the malware profile. If the specific network 200_1 has the authority to update the malware profile, the cybersecurity service providing server 100 can update the malware profile for the specific network 200_1 (S700).

[0113] As an example, referring to FIG. 5, the cybersecurity service providing server 100 can transmit an unconfirmed malware profile for unconfirmed malware to a specific network controller 220_1, or can transmit the unconfirmed malware profile to a specific network controller 220_1 via a specific network administrator terminal 210_1, so that the specific network controller 220_1 can use the unconfirmed malware profile to update the pre-registered malware profile of a specific first security engine of a specific first access switch AS_1 through a specific mth security engine of a specific mth access switch AS_m.

[0114] On the other hand, when the specific network 200_1 is confirmed to have malware profile update authority for updating the malware profile by referring to the subscription information of a specific cybersecurity service for the specific network 200_1, and it is confirmed that the specific network 200_1 does not have malware profile update authority, the cybersecurity service providing server 100 invites an additional subscription for the malware profile update from the specific network administrator terminal 210_1 (S800), and when additional subscription request information for the malware profile update is obtained from the specific network administrator terminal 210_1, the cybersecurity service providing server 100 updates the subscription information of the specific cybersecurity service by referring to the additional subscription request information, and transmits the unconfirmed malware profile to the specific network controller 220_1, or transmits it to the specific network controller 220_1 through the specific network administrator terminal 210_1, and uses the unconfirmed malware profile to update the pre-registered malware profile of the specific first security engine of the specific first access switch AS_1 to the specific mth security engine of the specific mth access switch AS_m (S700).

[0115] At this time, the cybersecurity service providing server 100 may refer to the subscription information of a specific cybersecurity service for a specific network 200_1, and if there is a remaining valid update period that has been paid for in relation to the malware profile update, the malware update operation for the specific network 200_1 may be performed without sending malware profile update notification information to the specific network administrator terminal 210_1.

[0116] In addition, the cybersecurity service providing server 100 can refer to subscription information for a specific cybersecurity service for a specific network 200_1, and even if post-payment settlement information is registered in connection with the malware profile update, perform the malware update operation for the specific network 200_1 without sending malware profile update notification information to the specific network administrator terminal 210_1.

[0117] Furthermore, when the cybersecurity service providing server 100 transmits an unconfirmed malware profile to a specific network controller 220_1 through a specific network administrator terminal 210_1, it can transmit the unconfirmed malware profile to the specific network administrator terminal 210_1 through at least one of SMS, a messaging app, and an email corresponding to the specific network administrator terminal 210_1.

[0118] Thereafter, when the cybersecurity service providing server 100 completes updating of the pre-registered malware profile in the specific network 200_1, it can transmit the update history information of the malware profile to the specific network administrator terminal 210_1.

[0119] In this case, the cybersecurity service providing server 100 can transmit the update history information of the malware profile to a specific network administrator terminal 210_1 at a predetermined time period or at a specific time based on the subscription information of a specific cybersecurity service.

[0120] On the other hand, the cybersecurity service providing server 100 collects security logs corresponding to specific malware that include at least a portion of the host scan packets and data packets corresponding to specific malware, or security logs for unconfirmed malware that include at least a portion of the host scan packets and data packets corresponding to unconfirmed malware, and classifies the security logs that include at least a portion of the data packets and host scan packets as either security logs corresponding to specific malware or security logs corresponding to unconfirmed malware, and stores and manages them as back data for subsequent analysis.

[0121] The above-described embodiments of the present invention may be embodied in the form of program instructions that can be executed by various computer components and stored on a computer-readable storage medium. The computer-readable storage medium may include, alone or in combination, program instructions, data files, data structures, and the like. The program instructions stored on the computer-readable storage medium may be specially designed and constructed for the present invention, or may be well known and available to those skilled in the art of computer software. Examples of computer-readable storage media include magnetic media such as hard disks, floppy disks, and magnetic tape; optical media such as CD-ROMs and DVDs; magneto-optical media such as floptical disks; and hardware devices specially configured to store and execute program instructions, such as ROM, RAM, and flash memory. Examples of program instructions include not only machine code, such as produced by a compiler, but also high-level language code that can be executed by a computer using an interpreter, etc. The hardware devices may be configured to operate as one or more software modules to perform processes according to the present invention, or vice versa.

[0122] Although the present invention has been described above using specific details such as concrete components and limited examples and drawings, these are merely provided to facilitate a more comprehensive understanding of the present invention, and the present invention is not limited to the above examples. Those skilled in the art will be able to make various modifications and variations from such descriptions.

[0123] Therefore, the spirit of the present invention should not be limited to the above-described embodiments, and all modifications equivalent to or equivalent to the scope of the claims, as well as the scope of the claims, are within the spirit of the present invention. [Explanation of symbols]

[0124] 1000 Cybersecurity Service Provision System 100 Cybersecurity service provider servers 200_1 to 200_n 1st network to nth network 210_1 to 210_n: first network administrator terminal to n-th network administrator terminal 220_1 to 220_n: first network controller to n-th network controller

Claims

1. A method for providing a cybersecurity service that detects cyber threats to a network using a virtual host, (a) when subscription request information for a cybersecurity service is acquired from a specific network administrator terminal which is at least one of the first network administrator terminal through the nth network administrator terminal that manages each of the first network through the nth network (where n is an integer equal to or greater than 1) that constitute an independent network, a cybersecurity service providing server refers to the subscription request information and registers subscription information for a specific cybersecurity service for a specific network corresponding to the specific network administrator terminal; (b) the cybersecurity service providing server, by referring to subscription information of the specific cybersecurity service, causes a specific network controller that manages the specific network to (i) generate at least one specific first virtual host IP address through at least one specific m-th virtual host IP address using a specific unused host address that is not used by a specific active host, which is a host connected to a switching port of a specific first access switch through a specific m-th access switch (where m is an integer of 1 or greater) that enables hosts belonging to the specific network to communicate within the specific network, and generates at least one specific first virtual host MAC address corresponding to the specific first virtual host IP address through at least one specific m-th virtual host MAC address corresponding to the specific m-th virtual host IP address; and (ii) generate at least one specific first virtual host MAC address corresponding to the specific m-th virtual host IP address using the specific unused host address that is not used by a specific active host, which is a host connected to a switching port of a specific first access switch through a specific m-th access switch (where m is an integer of 1 or greater) that enables hosts belonging to the specific network to communicate within the specific network. and transmitting the specific first virtual host IP address and the specific first virtual host MAC address through the specific m-th virtual host IP address and the specific m-th virtual host MAC address to the specific first access switch through the specific m-th access switch, respectively, and generating at least one specific first virtual host through the specific m-th virtual host IP address and at least one specific m-th virtual host corresponding to the specific first virtual host IP address and the specific first virtual host MAC address in a specific first security engine through a specific m-th security engine set in the specific first access switch through the specific m-th access switch, respectively, using at least one of the specific first virtual host IP address through the specific m-th virtual host IP address,determining a specific active host that performs a function of scanning at least one of the specific first virtual host through the specific m-th virtual host and a function of transmitting a data packet to at least one of the specific first virtual host through the specific m-th virtual host via at least one of the specific first security engine through the specific m-th security engine, and blocking the specific active host from the specific network; A method comprising:

2. Before the step (b), the cybersecurity service providing server generates a malware profile including the behavior pattern of the pre-confirmed malware from a malware database storing the behavior patterns of the pre-confirmed malware, and transmits the malware profile for the pre-confirmed malware to the specific network controller, or transmits the malware profile to the specific network controller via the specific network administrator terminal, so that the malware profile for the pre-confirmed malware is registered in the specific first security engine through the specific m-th security engine by the specific network controller; In the step (b), The cybersecurity service providing server analyzes the data code of the data packet using any one of the specific first security engine through the specific m-th security engine that has received the data packet, and checks an analyzed behavior pattern obtained by analyzing the behavior pattern of the data code, and (i) determines that the data code is specific malware corresponding to the specific registered behavior pattern when a specific registered behavior pattern among registered behavior patterns corresponding to each of pre-registered malware profiles matches the analyzed behavior pattern, and transmits the specific active malware to the specific active malware through at least one of the specific first access switch through the specific m-th access switch. The method of claim 1, further comprising: (i) determining that the data code is unidentified malware if each of the registered behavior patterns does not match the analyzed behavior pattern; and (ii-1) sending an alarm to the specific network controller after the specific active host is blocked from the specific network through at least one of the specific first access switch to the specific mth access switch; and (ii-2) sending the alarm to the specific network controller without blocking the specific active host from the specific network.

3. (c) when the cybersecurity service providing server acquires a security log corresponding to the unconfirmed malware from the specific network controller or the specific network administrator terminal (the security log includes a host scan packet corresponding to the unconfirmed malware and at least a portion of the data packet), the cybersecurity service providing server updates the malware database by referring to the results of analyzing the unconfirmed malware, generates an unconfirmed malware profile for the unconfirmed malware including an operation pattern for the unconfirmed malware, and transmits malware profile update notification information to the specific network administrator terminal; (d) when malware profile update request information is acquired from the specific network administrator terminal in response to the malware profile update notification information, the cybersecurity service providing server refers to subscription information for the specific cybersecurity service to confirm whether the specific network has malware profile update authority for updating the malware profile, and if it is confirmed that the specific network has malware profile update authority, transmits the unconfirmed malware profile to the specific network controller or transmits it to the specific network controller via the specific network administrator terminal, and uses the unconfirmed malware profile to update the pre-registered malware profiles of the specific first security engine to the specific mth security engine using the unconfirmed malware profile; The method of claim 2 further comprising:

4. In the step (d), 4. The method of claim 3, wherein, when it is confirmed that the specific network does not have the authority to update the malware profile, the cybersecurity service providing server requests an additional subscription for updating the malware profile from the specific network administrator terminal, and when additional subscription request information for updating the malware profile is obtained from the specific network administrator terminal, the cybersecurity service providing server updates the subscription information for the specific cybersecurity service by referring to the additional subscription request information, and transmits the unconfirmed malware profile to the specific network controller or transmits it to the specific network controller through the specific network administrator terminal, so that the specific network controller uses the unconfirmed malware profile to update the pre-registered malware profiles of the specific first security engine to the specific mth security engine.

5. In the step (d), The method of claim 3, wherein when the cybersecurity service providing server transmits the unconfirmed malware profile to the specific network controller through the specific network administrator terminal, the cybersecurity service providing server transmits the unconfirmed malware profile to the specific network administrator terminal through at least one of SMS, a messaging app, and email corresponding to the specific network administrator terminal.

6. (e) when the cybersecurity service providing server completes updating the pre-registered malware profile, transmitting malware profile update history information to the specific network administrator terminal. The method of claim 3 further comprising:

7. The method of claim 6, wherein the cybersecurity service providing server transmits update history information of the malware profile to the specific network administrator terminal at a predetermined time period or at a specific time based on subscription information of the specific cybersecurity service.

8. In the step (b), The method of claim 1, wherein the cybersecurity service providing server uses the specific network controller to group the specific unused host addresses into groups 1_1 through 1_n, and generates the specific first virtual host IP address that references the specific unused host addresses of the group 1_1 through the specific mth virtual host IP address that references the specific unused host addresses of the group 1_n.

9. In the step (b), The method of claim 1, wherein the cybersecurity service providing server uses the specific network controller to group all specific host addresses of the specific network into a 2_1 group through a 2_n group, and generates the specific first virtual host IP address that references a specific unused host address among all specific host addresses of the 2_1 group through the specific mth virtual host IP address that references a specific unused host address among all specific host addresses of the 2_n group.

10. In the step (b), 2. The method of claim 1, wherein, when the number of specific virtual hosts to be generated on the specific network is k (where k is an integer greater than or equal to m), the network controller uses the specific network controller to group all specific host addresses of the specific network into 3_1 group through 3_m group, generate a specific 3_1 virtual host IP address that references one specific unused host address in the 3_1 group through a specific 3_k virtual host IP address that references one specific unused host address in the 3_m group, and group the specific 3_1 virtual host IP addresses through the specific 3_k virtual host IP addresses into m groups to generate the specific 1 virtual host IP addresses through the specific m-th virtual host IP addresses.

11. A cybersecurity service provider server that uses virtual hosts to provide cybersecurity services that detect cyberthreats to networks. a memory storing instructions for providing a cybersecurity service that utilizes a virtual host to detect cyberthreats to a network; a processor that performs operations according to the instructions stored in the memory to provide a cybersecurity service utilizing the virtual host to detect cyber threats to the network; Including, The processor includes: (I) a process for registering subscription information for a specific cybersecurity service for a specific network corresponding to the specific network administrator terminal by referring to the subscription request information when subscription request information for a cybersecurity service is acquired from a specific network administrator terminal that is at least one of the first network administrator terminal through the nth network administrator terminal that manages each of the first network through the nth network (where n is an integer of 1 or more) that constitute an independent network; and (II) a process for registering subscription information for a specific cybersecurity service for a specific network corresponding to the specific network administrator terminal by referring to the subscription information for the specific cybersecurity service, using a specific network controller that manages the specific network, (i) using a specific unused host address that is not used by a specific active host that is a host connected to a switching port of a specific first access switch through a specific mth access switch (where m is an integer of 1 or more) that enables hosts belonging to the specific network to communicate within the specific network, (ii) generating at least one specific first virtual host IP address through at least one specific m-th virtual host IP address, and generating at least one specific first virtual host MAC address corresponding to the specific first virtual host IP address through at least one specific m-th virtual host MAC address corresponding to the specific m-th virtual host IP address; and (ii) transmitting the specific first virtual host IP address and the specific first virtual host MAC address through the specific m-th virtual host IP address and the specific m-th virtual host MAC address to each of the specific first access switch through the specific m-th access switch, and transmitting the specific first virtual host IP address and the specific m-th virtual host MAC address to each of the specific first access switch through the specific m-th access switch,A cybersecurity service providing server that generates at least one specific first virtual host corresponding to the specific first virtual host IP address and the specific first virtual host MAC address through the specific m-th virtual host IP address and at least one specific m-th virtual host corresponding to the specific m-th virtual host MAC address, and determines a specific active host that performs a function of scanning at least one of the specific first virtual host through the specific m-th virtual host and a function of transmitting data packets to at least one of the specific first virtual host through the specific m-th virtual host using at least one of the specific first virtual host IP address through the specific m-th virtual host IP address, and blocks the specific active host from the specific network through at least one of the specific first security engine through the specific m-th security engine.

12. The processor, before the (II) process, generates a malware profile including the behavioral pattern of the pre-confirmed malware from a malware database storing behavioral patterns of the pre-confirmed malware, and transmits the malware profile for the pre-confirmed malware to the specific network controller, or transmits the malware profile to the specific network controller via the specific network administrator terminal, so that the malware profile for the pre-confirmed malware is registered in the specific first security engine through the specific m-th security engine by the specific network controller; In the process (II), any one of the specific first security engine through the specific m-th security engine that receives the data packet is used to analyze the data code of the data packet and confirm an analyzed behavior pattern obtained by analyzing the behavior pattern of the data code, and (i) when a specific registered behavior pattern among registered behavior patterns corresponding to each of pre-registered malware profiles matches the analyzed behavior pattern, the data code is determined to be specific malware corresponding to the specific registered behavior pattern, and the specific active host is connected to the specific network through at least one of the specific first access switch through the specific m-th access switch. (ii) if each of the registered operation patterns does not match the analyzed operation pattern, determine that the data code is unidentified malware; and (ii-1) execute one of the following processes: a process of sending an alarm to the specific network controller after the specific active host is disconnected from the specific network through at least one of the specific first access switch through the specific mth access switch; and (ii-2) a process of sending the alarm to the specific network controller while the specific active host is not disconnected from the specific network.

13. The processor (III) updates the malware database by referring to a result of analyzing the unconfirmed malware when it acquires a security log corresponding to the unconfirmed malware (the security log includes at least a portion of the host scan packet and the data packet corresponding to the unconfirmed malware) from the specific network controller or the specific network administrator terminal, generates an unconfirmed malware profile for the unconfirmed malware including an operation pattern for the unconfirmed malware, and transmits malware profile update notification information to the specific network administrator terminal; and (IV) updates the malware database by referring to a result of analyzing the unconfirmed malware when it acquires a malware profile update request information from the specific network administrator terminal in response to the malware profile update notification information.

13. The cybersecurity service providing server of claim 12, further comprising: referring to subscription information for a security service to determine whether the specific network has malware profile update authority for updating a malware profile; and if it is determined that the specific network has malware profile update authority, transmitting the unconfirmed malware profile to the specific network controller or transmitting it to the specific network controller via the specific network administrator terminal, and using the specific network controller to update the pre-registered malware profiles of the specific first security engine through the specific mth security engine using the unconfirmed malware profile.

14. 14. The cybersecurity service providing server of claim 13, wherein, if it is confirmed in process (IV) that the specific network does not have the authority to update the malware profile, the processor requests an additional subscription for updating the malware profile from the specific network administrator terminal, and when additional subscription request information for updating the malware profile is obtained from the specific network administrator terminal, the processor updates the subscription information for the specific cybersecurity service by referring to the additional subscription request information, and transmits the unconfirmed malware profile to the specific network controller or transmits it to the specific network controller through the specific network administrator terminal, thereby using the specific network controller to update the pre-registered malware profiles of the specific first security engine to the specific mth security engine using the unconfirmed malware profile.

15. The cybersecurity service providing server of claim 13, wherein in the (IV) process, when the processor determines that the unconfirmed malware profile is to be transmitted to the specific network controller through the specific network administrator terminal, the processor transmits the unconfirmed malware profile to the specific network administrator terminal via at least one of SMS, a messaging app, and email corresponding to the specific network administrator terminal.

16. The cybersecurity service providing server of claim 13, wherein the processor further executes (V) a process of transmitting malware profile update history information to the specific network administrator terminal when the update of the pre-registered malware profile is completed.

17. The cybersecurity service providing server of claim 16, wherein the processor transmits update history information of the malware profile to the specific network administrator terminal at a predetermined time period or at a specific time based on subscription information of the specific cybersecurity service.

18. The cybersecurity service providing server of claim 11, wherein in the (II) process, the processor uses the specific network controller to group the specific unused host addresses into groups 1_1 through 1_n, and generates the specific first virtual host IP address that references the specific unused host addresses of the group 1_1 through the specific mth virtual host IP address that references the specific unused host addresses of the group 1_n.

19. The cybersecurity service providing server of claim 11, wherein in the (II) process, the processor uses the specific network controller to group all specific host addresses of the specific network into 2_1 group through 2_n group, and generates the specific first virtual host IP address that references a specific unused host address among all specific host addresses of the 2_1 group through the specific mth virtual host IP address that references a specific unused host address among all specific host addresses of the 2_n group.

20. 12. The cybersecurity service providing server of claim 11, wherein in the process (II), when the number of specific virtual hosts to be generated on the specific network is k (where k is an integer greater than or equal to m), the processor uses the specific network controller to group all specific host addresses of the specific network into 3_1 group through 3_m group, generate a specific 3_1 virtual host IP address that references one specific unused host address in the 3_1 group through a specific 3_k virtual host IP address that references one specific unused host address in the 3_m group, and group the specific 3_1 virtual host IP addresses through the specific 3_k virtual host IP addresses into m groups to generate the specific 1 virtual host IP addresses through the specific m-th virtual host IP addresses.