Matrix-based TTP-perspective cyber intimidation display method and intimidation analysis device

The method and device enhance cyber threat analysis by classifying and displaying threat behaviors using standardized identifiers and dynamic hue changes, addressing the limitations of existing systems in identifying and classifying cyberattacks.

JP2026510115APending Publication Date: 2026-04-01クワッド マイナー カンパニー リミテッド
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-08-23
Publication Date
2026-04-01

Smart Images

  • Figure 2026510115000001_ABST
    Figure 2026510115000001_ABST
Patent Text Reader

Abstract

The present invention relates to a method for displaying intimidation behavior on a terminal, and includes a data collection step of analyzing packets within a network for a specified period of time to collect intimidation behavior data and classifying the intimidation behavior data by a standardized attack identifier, host, and attack type; a first block display step of blocking the data and displaying it in a first hue; a second block display step of classifying the data by host in a second area of ​​the screen and displaying it in a block; and a step of displaying, when a gesture to select any second block is received, the block corresponding to the intimidation behavior related to the host in the second block from the first block is displayed in a second hue. According to the present invention, security personnel can dynamically analyze intimidation behavior and more easily grasp the intimidation behavior that has been carried out, and they can also easily grasp host information and peer information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for displaying threat behaviors and a threat behavior analysis device, and more particularly to a cyber threat behavior display method and an analysis device that dynamically analyze threat behavior information in response to a user's selection and provide the analyzed information.

Background Art

[0002] The damage caused by cyber security threats, which are gradually becoming more sophisticated centering on malicious codes such as new species or variants, is increasing. In order to reduce such damage as much as possible and respond promptly, the sophistication of countermeasures is being pursued in parallel through multi-dimensional pattern configuration and various composite analyses. However, recent cyberattacks are increasing in threat day by day rather than being appropriately responded to within the control range. Such cyberattacks go beyond existing ICT (Information and Communication Technology) infrastructure facilities and pose threats to finance, transportation, environment, health, etc., which directly affect our lives.

[0003]

[0004] One of the basic technologies for detecting and responding to most existing cyber security threats is to generate a database of patterns for cyberattacks or malicious codes in advance and utilize appropriate monitoring technologies where data flow is required. However, although existing monitoring technologies can generally grasp the overall threat situation, there is a problem in that they have limitations in identifying the attacker or the target of the attack or in classifying and grasping the attacks by type.

Summary of the Invention

Problems to be Solved by the Invention

[0005] The present invention aims to provide a threat behavior display method and an analysis device that enable a user to easily grasp threat behaviors by identifying the subject and target of threat behaviors that have occurred within a certain period of time, classifying the threat behaviors, and displaying them. [Means for solving the problem]

[0006] The present invention is intended to achieve the aforementioned objectives, and the intimidation display method according to the present invention may include a data collection step of analyzing packets within a network for a specified period of time to collect intimidation data and classifying the intimidation data by a standardized attack identifier, host, and attack type; a first block display step of classifying the data by a standardized attack identifier in a first area of ​​the terminal screen, and displaying it in blocks with a first hue; a second block display step of classifying the data by host in a second area of ​​the screen, and displaying it in blocks with a second hue; and when a gesture to select any second block is received, the block corresponding to the intimidation related to the host of the second block from the first block is displayed in the second hue.

[0007] [Effects of the Invention]

[0008] This invention provides a method for displaying intimidating behavior that can dynamically analyze techniques such as miter attack (MITRE ATT&CK), thereby providing a concise context related to intimidating behavior. [Brief explanation of the drawing]

[0009] [Figure 1] This is a diagram showing the conventional MITRE ATT&CK matrix.

[0010] [Figure 2] This is a drawing illustrating the operating environment of a threat behavior analysis device according to one embodiment of the present invention.

[0011] [Figure 3] This is a drawing illustrating the configuration of a threat analysis device according to one embodiment of the present invention.

[0012] [Figure 4]This is a diagram illustrating the data processing process of a data processing unit according to one embodiment of the present invention.

[0013] [Figure 5] This is a drawing illustrating a hash map according to one embodiment of the present invention.

[0014] [Figure 6] This is a drawing illustrating a user interface according to one embodiment of the present invention.

[0015] [Figure 7] This is a flowchart of a method for displaying intimidation behavior according to one embodiment of the present invention.

[0016] [Figure 8] This is a diagram illustrating the data collection stage for intimidation behavior according to one embodiment of the present invention. [Modes for carrying out the invention]

[0017] The intimidation display method according to the present invention may include a data collection step of analyzing packets within a network for a specified period of time to collect intimidation data and classifying the intimidation data by a standardized attack identifier, host, and attack type; a first block display step of classifying the data by a standardized attack identifier in a first area of ​​the terminal screen, blocking it, and displaying it in a first hue; a second block display step of classifying the data by host in a second area of ​​the screen, blocking it, and displaying it in a second hue; and when a gesture to select any second block is received, a step of displaying the block corresponding to the intimidation activity related to the host of the second block from the first block in a second hue.

[0018] Regarding the embodiments related to the concept of the present invention disclosed in this specification or application, specific structural-functional descriptions are merely exemplified for the purpose of explaining the embodiments related to the concept of the present invention. The embodiments related to the concept of the present invention can be implemented in various forms and should not be construed as being limited to the embodiments described in this specification or application.

[0019] Since the embodiments related to the concept of the present invention can be modified in various ways and can have various forms, specific embodiments are illustrated in the drawings and will be described in detail in this specification or application. However, this is not intended to limit the embodiments related to the concept of the present invention to a specific disclosed form, and should be understood to include all modifications, equivalents, and alternatives included in the idea and technical scope of the present invention.

[0020] Unless otherwise defined, all terms used herein, including technical or scientific terms, have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present invention pertains. Terms defined in commonly used dictionaries should be interpreted as having a meaning consistent with the meaning in the context of the related art, and should not be interpreted in an ideal or overly formal sense unless clearly defined herein.

[0021] In describing the embodiments, technical content that is widely known in the technical field to which the present invention pertains and is not directly related to the present invention will be omitted from the description. This is to more clearly convey the gist of the present invention without obscuring it by omitting unnecessary descriptions.

[0022] As used herein, "threat behavior data" means data detected as a cyber security threat among the collected network packet data.

[0023] "Host" means a device that has become the target of a threat behavior or a device that has been exposed to a threat behavior among user terminals.

[0024] "Peer" refers to a device that communicates with a host and is the attacker or the entity responsible for the threatening activity.

[0025] "MITRE ATT&CK" is an example of a database compiled by a group of security experts to classify cybersecurity threats, specifically a database that classifies cybersecurity threats using a matrix. "MITRE ATT&CK" allows for the identification of attack techniques and actions in a consistent dataset format by displaying specific security attack techniques and actions using matrix-style components. "MITRE ATT&CK" can classify the content of hacker or malicious code attack techniques by attack stage and represent them in a matrix of CVE codes (Common Vulnerabilities and Exposures Codes), and can also classify and represent user-defined vulnerabilities in a matrix. User-defined vulnerabilities refer to vulnerabilities that are not CVE codes but are defined by the user as threats. In a specific example, if a web service operator attempts to connect to the administrator page from an unauthorized IP address, security equipment (such as a firewall or IDS) can detect this as a threat and classify and represent it in the "MITRE ATT&CK" matrix.

[0026] In other words, the intimidation behavior analysis device analyzes network packet data to identify specific attack behaviors from among various intimidation behaviors, and by matching the identified types of attack behaviors with attack codes actually performed that are recognized by expert organizations, the identification of attack behaviors can be classified into MITRE ATT&CK so that it is expressed using professional and commonly recognized elements. The collected intimidation behaviors can be classified into subcategories of tactic, technique, and evaluation according to the MITRE ATT&CK classification. Figure 1 is a diagram showing the conventional MITRE ATT&CK matrix, which includes 14 tactics and 222 techniques. However, the types and number of tactics and techniques may change continuously and are not limited to the conventional matrix.

[0027]

[0028] The embodiments of this invention will be described in more detail below with reference to the attached drawings.

[0029] Figure 2 is a diagram illustrating the operating environment of a threatening behavior analysis device according to one embodiment of the present invention, and Figure 3 is a diagram illustrating the configuration of a threatening behavior analysis device according to one embodiment of the present invention.

[0030]

[0031] Referring to Figures 2 and 3, the intimidation behavior analysis device 200 may be a server including a data collection unit 210, a data processing unit 220, a UI generation unit 230, a communication unit 240, and a database 300. The intimidation behavior analysis device 200 is designed to collect network packets from a host for a specified period of time, analyze the packets to detect intimidation behavior, identify the attacker and target of the detected intimidation behavior, and dynamically understand the detected intimidation behavior by categorizing it. Furthermore, the intimidation behavior analysis device 200 is designed to enable high-speed dynamic analysis of intimidation behavior data by creating a hash table that allows for high-speed searching of attackers, targets, and intimidation behavior, and by storing data in various hash map formats. The time for which the intimidation behavior analysis device 200 collects network packets may be several minutes, several hours, several days, or several weeks, and may be a time specified by the entity seeking to detect and analyze the intimidation behavior.

[0032] The data collection unit 210 collects packet data transmitted and received by the host over wired / wireless connections for a specified period of time. If necessary, the data collection unit 210 can collect packet data from multiple hosts within the enterprise.

[0033] Figure 4 is a diagram illustrating the data processing process of a data processing unit 220 according to one embodiment of the present invention.

[0034] The data processing unit 220 analyzes the collected packet data to extract intimidation data and identifies the attack technique, host, and peer information of the intimidation data. The extracted intimidation data may include host IP, information on the intimidation technique, and peer IP information.

[0035] The data processing unit 220 structures the intimidation data by host, processes it in hash table format, and stores it in memory. The data stored at this time includes the host IP address, information on the intimidation attack technique, the peer IP address, and peer DB information.

[0036] The peer database information refers to information about the sequence of peers that have engaged in threatening behavior towards a host. More specifically, when multiple peers engage in threatening behavior towards the same host, the data processing unit 220 of the present invention stores information about multiple peers sequentially in a peer array for high-speed searching. Furthermore, the data processing unit 220 improves the efficiency of dynamic analysis by including such peer database location information and the number of corresponding peers in the stored threatening behavior data.

[0037] Referring to Figure 4, the host is represented as Dev and the peer as Dev Peer in the diagram. The data processing unit 220 extracted multiple threat data. The extracted threat data is represented in a hash table and then sequentially stored on the Dev array. At this time, the data stored on the Dev array includes not only the host's IP address and attack technique information (Tech ID), but also the index address of the Dev Peer where the peers that communicated with the host are stored, and the number of peers that communicated with the host (number of index cells). In other words, the data processing unit 220 sequentially stores information of peers that communicated with a specific host on the Dev Peer array, and can quickly find peer information that communicated with a specific host using only the Dev Peer index address and number information.

[0038] More specifically, referring to the Dev 16 data in Figure 4, the peers of Dev 16, one of the hosts, are stored in the peer hash table index 3 (Dev_Peer_index:3), and two peers attacked Dev 16 (Peer_cnt:2). The two consecutive peer entries from index 3 (index 3 and index 4) represent the peers that engaged in threatening behavior towards Dev 16 (the host).

[0039] Furthermore, since peers corresponding to a specific host are arranged consecutively, if one peer attacks multiple hosts, the information of that peer may appear multiple times in the Dev Peer array. In Figure 4, the Dev Peer data displays the same peer IP address at index 0 and index 3.

[0040] Figure 5 is a diagram illustrating a hash map according to one embodiment of the present invention.

[0041] Referring to Figure 5, the data processing unit 220 can classify the extracted intimidation data into standardized attack identifiers, which can then be classified as subcategories of tactic, technique, and evaluation according to the MITREE ATT&CK classification. In addition, the data processing unit 220 can classify the intimidation data into tactic, technique, and evaluation, construct a hash map, and store it. By constructing and storing the hash map, the data processing unit 220 enables even faster dynamic analysis. Furthermore, each of these classifications can be numbered with a Tech ID and stored in the data. Figure 5 shows one example of hash map creation, illustrating the method of creating a hash map by tactic.

[0042] The intimidation behavior analysis device 200 can store and manage the processed data in the database 300.

[0043] The UI generation unit 230 generates a user interface for displaying the saved data on a web page or application program.

[0044] Figure 6 is a diagram illustrating a user interface according to one embodiment of the present invention. Referring to Figure 6, the screen displayed on the user terminal can be divided into multiple areas.

[0045] The first area of ​​the user terminal screen is an area that classifies and displays intimidation data using standardized attack identifiers, and can be displayed in one or more first blocks. More specifically, Figure 6 shows a miter attack (MITRE ATT&CK) matrix in the first area. The first area can be classified into first blocks in area (a) by tactic and in area (b) by technique. The first block may include information such as the name of the technique included in the block, the number of intimidation acts, and the number of hosts targeted by the intimidation acts.

[0046] The second area of ​​the user terminal screen can display intimidation data categorized by host in one or more second blocks. Figure 6(c) shows hosts targeted by intimidation activities, divided into blocks. The second block displays information such as the host's IP address, the number of related intimidation activities, and the number of types of intimidation activities.

[0047] If necessary, the second block can be sorted in descending order according to the degree of host intimidation. That is, the second block can be sorted by the number of hosts that were targeted by the most intimidating acts, by the number of hosts that were targeted by the most intimidating acts, or by the hosts that received the highest score when intimidation points were assigned to each type of intimidating act.

[0048] If necessary, the second block can be sorted in descending order by "number of tacticals detected per host" or "number of techniques detected per host".

[0049] If necessary, statistical data regarding threatening behavior may be displayed in the third area. More specifically, the third area of ​​the user terminal screen may display statistical data including at least one group from the following: network communication method of threatening behavior data, number of hosts, and number of threatening behaviors. Through this, the user can quickly analyze the threatening behavior.

[0050]

[0051] When the UI generation unit 230 receives a gesture from the user terminal to select a second block, it can configure the user interface to change the hue of the block in the first block that corresponds to the intimidating behavior of the selected host. In other words, when the user selects a specific host in the second block, the UI generation unit 230 can change the hue of the first block that includes the intimidating behavior associated with that host. If necessary, when the user selects multiple second blocks in succession, the UI generation unit 230 can change the hue of all first blocks that include the intimidating behavior associated with the hosts of multiple second blocks.

[0052]

[0053] When the UI generation unit 230 receives a gesture from the terminal to select at least one group containing tactical and technique lists within the first block, it can configure the user interface to change the hue of the corresponding first block to the third hue and display it. At this time, the UI generation unit 230 can list the host list of the selected first block in the second block, and use the hosts listed in the second block to change the hue of the detected first block to the fourth hue and display it.

[0054] In one embodiment, the user terminal can receive gestures to select one tactic and two techniques, and the UI generation unit 230 can change the hue of the first block that satisfies all of these and display it in white. The UI generation unit 230 can also list the host list of the selected first block in a second block, and change the hue of the first block associated with the listed host in the second block in purple and display it.

[0055]

[0056] The communication unit 240 transmits data displayed by the user interface to the user terminal. The communication unit 240 of the intimidation behavior analysis device 200 can communicate with any external device and internal server. For example, the communication unit 240 transmits the user interface generated by the UI generation unit 230 to the user terminal so that the user can analyze the intimidation behavior.

[0057]

[0058] The intimidation behavior analysis device 200 can connect to a network via the communication unit 240 to send and receive various data. The communication unit 240 can broadly include wired and wireless types. Since wired and wireless types each have their own advantages and disadvantages, the intimidation behavior analysis device 200 may be equipped with both wired and wireless types simultaneously, depending on the circumstances. In the case of the wireless type, a WLAN (Wireless Local Area Network) series communication method such as Wi-Fi can be mainly used. Alternatively, a cellular communication method, such as LTE or 5G series communication methods, can be used. However, the wireless communication protocol is not limited to the examples given above, and it is possible to use any appropriate wireless communication method. In the case of the wired type, LAN (Local Area Network) and USB (Universal Serial Bus) communication are typical examples, but other methods are also possible.

[0059]

[0060] The following briefly describes a method for displaying intimidation behavior according to one embodiment of the present invention.

[0061] A method for displaying intimidating behavior according to one embodiment of the present invention was devised to provide additional information for identifying intimidating behavior and understanding the target through dynamic miter analysis technology. Specifically, the present invention relates to a method for displaying intimidating behavior and a method for processing intimidating information that collects network packet data, analyzes it, classifies and stores it according to intimidating behavior, and helps users more easily understand intimidation through dynamic miter analysis technology.

[0062]

[0063] Figure 7 is a flowchart of a method for displaying intimidation behavior according to one embodiment of the present invention.

[0064] Referring to Figure 7, the method for displaying the server's intimidation behavior can include a data collection stage (S1100), a first block display stage (S1200), a second block display stage (S1300), and a second hue display stage (S1400).

[0065]

[0066] During the data collection phase (S1100), the server collects packets within the network for a specified period of time, and then analyzes them to collect data related to threatening behavior. The method for analyzing the collected network packets to collect data related to threatening behavior (hereinafter referred to as "threatening behavior data") uses previously published technology, and a detailed explanation of this is omitted. If necessary, the server can collect network packets from numerous devices within the enterprise. The specified period can be a few seconds, a few minutes, a few hours, a few days, a few weeks, a few tens of days, or a few years, and is a period that the user can freely specify for which they wish to analyze threatening behavior.

[0067] During the data collection phase (S1100), the server can extract the hosts included in the intimidation data and the peers that communicated with them.

[0068] Figure 8 is a diagram illustrating the data acquisition stage (S1100) according to one embodiment of the present invention.

[0069]

[0070] If necessary, the data collection stage (S1100) may include a stage (S1110) in which the collected intimidation data is analyzed and the intimidation behaviors are classified. In the intimidation behavior classification stage, the server can classify the collected intimidation behavior data into standardized attack identifiers, attack types, etc. The server can classify the intimidation behavior data by creating its own classification criteria, or by classifying it according to publicly available classification criteria.

[0071] According to one embodiment of the present invention, during the data collection stage (S1100), the server can classify intimidation behavior data using a MITRE ATT&CK matrix. The MITRE ATT&CK matrix is ​​a technique for classifying intimidation behavior according to standardized tactics, techniques, and evaluations, and since it is a known classification technique, a detailed explanation thereof will be omitted. The server can also assign a Tech_id value to each item element within the tactics, techniques, and evaluations in the MITRE ATT&CK matrix, and after classifying the collected intimidation behavior data by item, it can assign the corresponding Tech_id value to the intimidation behavior data.

[0072]

[0073] If necessary, the data collection stage (S1100) may include a hash table generation stage (S1120). In the data collection stage (S1100), the server can hash the intimidation data and generate a hash table such that at least one or more data points are arranged in a separate-changing manner.

[0074] During the hash table generation phase (S1120), the server can generate multiple hash tables, one for each host and one for each peer.

[0075] During the hash table generation phase (S1120), the server can concatenate the host hash table and the peer hash table. More specifically, the server can store each hash table in array form, and generate hash tables such that the host hash table and the peer hash table are concatenated by including the host IP, the Tech_id information of the intimidation activity, the peer IP, and the peer DB information in the stored host array.

[0076]

[0077] Furthermore, the data collection stage (S1100) may include a hash map generation stage (S1130). In the hash map generation stage (S1130), the server can generate separate hash maps for the classified intimidation data based on tactics and techniques. This is to improve the efficiency of searching by tactics or techniques during dynamic data analysis.

[0078]

[0079] In the first block display stage (S1200), the server can block the collected and classified data into a first area of ​​the terminal screen and display it in a first hue. The first block refers to the block displayed in the first area. In one specific embodiment, the server can block the intimidation data classified by the MITRE ATT&CK matrix and display it in a first hue. If necessary, the server can display at least one of the following pieces of information in the first block: the name of the technology included in the block, the number of intimidation acts, and the number of hosts targeted by the intimidation acts.

[0080]

[0081] In the second block display stage (S1300), the server can display the collected and classified data in blocks for each host in the second area of ​​the screen. The second block refers to the block displayed in the second area. If necessary, the second block may be displayed in the same hue as the first block or in a different hue. The server can generate blocks for each host that has been targeted by a threat and display host-related threat information. The second block may contain one or more pieces of information, such as the host's IP address, the number of associated threats, and the number of peers.

[0082]

[0083] If necessary, the server can sort the second block in descending order based on the host's level of intimidation. More specifically, the server can sort the second block by the number of hosts targeted by intimidation acts, by the number of hosts targeted by intimidation acts with a high degree of intimidation, or by assigning intimidation points to each intimidation act and then sorting the hosts with the highest total score.

[0084] If necessary, the second block can be sorted in descending order by "number of tacticals detected per host" or "number of techniques detected per host".

[0085]

[0086] If necessary, the intimidation behavior display method of the present invention may further include a step of displaying statistical data in a third area. The server may generate statistical data using the collected and classified intimidation behavior data and display it in the third area. The statistical data includes at least one piece of information from groups including the network communication method of the collected intimidation behavior data, the number of hosts, and the number of intimidation behaviors.

[0087]

[0088] [In the second hue display stage (S1400), when the server receives a gesture to select any second block, it can change the hue of the blocks in the first block corresponding to the threatening behavior associated with the host in the second block to the second hue. If the server receives a gesture to select multiple second blocks consecutively, it can display the hue of all first blocks, including the threatening behavior associated with the hosts in multiple second blocks, in the second hue. The second hue is a hue that is distinct from the first hue and can be selected by user specification. Through this stage, the administrator can dynamically analyze the threatening behavior data and grasp the threatening behavior directed at a host more quickly. In addition, the server can change the hue immediately when a gesture to select a block is received using the hash table and hash map of the host and peers. Through this, the administrator can quickly grasp threatening behavior by time, identify hosts with a high level of threat, and take countermeasures against them.

[0089]

[0090] The intimidation display method may include a third hue display stage. In the third hue display stage, when the server receives a gesture in the first area indicating the selection of at least one item from the tactic and technique lists within the MITRE ATT&CK matrix, it may display the corresponding first block in the third hue. If necessary, when the server receives a gesture indicating the selection of multiple conditions, it may display only the first block that satisfies all of those conditions in the third hue. The third hue refers to a hue distinct from the first hue, and a variety of colors can be selected by user specification, including the same hue as the second hue.

[0091]

[0092] According to the method for displaying threatening behavior in an embodiment of the present invention, security personnel can dynamically analyze threatening behavior to more easily identify the threatening behavior that has been carried out, and can also easily grasp host information and peer information.

[0093] The features, structures, and effects described in the embodiments above are included in at least one embodiment of the present invention and are not necessarily limited to just one embodiment. Furthermore, the features, structures, and effects exemplified in each embodiment can be combined or modified and implemented in other embodiments by a person with ordinary skill in the art to which the embodiment belongs. Therefore, it should be interpreted that such combinations and modifications are included within the scope of the present invention.

[0094] Furthermore, although the above description has focused on embodiments, these are merely illustrative examples and do not limit the present invention. A person with ordinary skill in the art to which the present invention belongs will understand that various modifications and applications not exemplified above are possible without departing from the essential characteristics of these embodiments. In other words, each component specifically shown in the embodiments can be modified and implemented. Differences related to such modifications and applications should be interpreted as being included within the scope of the present invention as defined in the appended claims.

Claims

1. In the method of displaying threatening behavior on a server, A data collection step in which packets are analyzed within the network for a specified period of time to collect intimidation data, and the intimidation data is classified by a standardized attack identifier, host, and attack type; A first block display stage in which the intimidation data classified into a first area of ​​the terminal screen is blocked and displayed in a first hue; A second block display stage in which the intimidation data is displayed in a second area of ​​the aforementioned screen, in a block format for each host; A method for displaying intimidation behavior, comprising the step of displaying in a second hue the block corresponding to the intimidation behavior associated with the host of the second block from the first block when a gesture for selecting any second block is received.

2. The aforementioned data collection stage is, The step of extracting the host and the peer that communicated with it, as included in the aforementioned intimidation data; The method for displaying intimidating behavior according to claim 1, further comprising the step of classifying the intimidating behavior data using a MITRE ATT&CK matrix.

3. The first block display stage is, The method for displaying intimidating behavior according to claim 2, further comprising the step of blocking the intimidating behavior data classified by the MITRE ATT&CK matrix and displaying it in a first hue.

4. The method for displaying a threatening act according to claim 2, further comprising the step of displaying a corresponding first block in a third hue when a gesture is received in the first area indicating the selection of at least one of the tactical and technique lists within the MITRE ATT&CK matrix.

5. The method for displaying intimidating acts according to claim 4, further comprising the step of displaying statistical data in a third area of ​​the screen, which includes at least one group including the network communication method for the intimidating acts data, the number of hosts, and the number of intimidating acts.

6. The first block contains: The method for displaying intimidation acts according to claim 2, wherein the number of intimidation acts and the number of hosts corresponding to the block are displayed.

7. The second block contains, The method for displaying threatening behavior according to claim 6, wherein at least one piece of information is displayed from a group including the host's IP address, the number of threatening behaviors associated with the host, and the number of peers.

8. The aforementioned data collection stage is, The method for displaying a threatening act according to claim 2, comprising the step (S1120) of hashing the threatening act data and generating a hash table such that at least one of the data is arranged in a separate changing manner.

9. The hash table generation step is as follows: A method for displaying a threatening act according to claim 8, comprising the step of generating a plurality of hash tables corresponding to a host and a peer, respectively.

10. The second block display stage is, The method for displaying intimidation behavior according to claim 9, further comprising the step of displaying the second block in descending order according to the degree of intimidation by the host.

11. The aforementioned data collection stage is, A method for displaying intimidating behavior according to claim 10, comprising the step (S1130) of generating separate hash maps for tactic and technique of classified intimidating behavior data.

12. A data collection unit (210) that collects packet data within the network for a specified period of time; A data processing unit (220) extracts data on intimidation behavior from the collected data and processes it in hash table format; A database (300) for storing the processed data; A UI generation unit (230) that generates a user interface for displaying the stored data on a web page or application program; Includes a communication unit 240 that transmits the data displayed by the user interface to the user terminal; The UI generation unit (230) is A threat analysis device (200) displays the data in a first area of ​​the screen displayed on the user terminal, classified by a standardized attack identifier and displayed in a first block of a first hue; displays the data in a second area of ​​the screen, classified by host and displayed in a second block; and when a gesture to select a second block is received from the terminal, the user interface is configured to change the hue of the block corresponding to the threat activity of the selected host in the first block to the second hue and display it.

13. The UI generation unit (230) is The data is classified by the MITRE ATT&CK matrix and displayed in the first area of ​​the screen displayed on the user terminal in the first block of the first hue. When a gesture is received from the terminal indicating that at least one of the groups containing tactical and technical lists within the first block is selected, The hue of the first block corresponding to the selected group is displayed in the third hue, The host list corresponding to the third hue block is displayed in the second block. The intimidation behavior analysis device (200) according to claim 12, wherein the user interface is configured to change the hue of the first block corresponding to the intimidation behavior of the second block to a fourth hue and display it.

14. A cybersecurity threat information processing application program stored on a computer-readable medium for performing the method described in any one of claims 1 to 11.

Citation Information

Patent Citations

  • Alarm display system and display method

    CN111880884A

  • Fragility evaluating program, method and system

    JP2003108521A