Method of providing specific threat response playbooks for coping with specific threat events and computing device using the same

The threat detection model addresses the limitations of conventional frameworks by analyzing threat rule sets to generate context-aware countermeasures, enhancing response efficiency to new cyber threats.

KR102996807B1Active Publication Date: 2026-07-29SECULAYER CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
KR · KR
Patent Type
Patents
Current Assignee / Owner
SECULAYER CO LTD
Filing Date
2025-10-14
Publication Date
2026-07-29

AI Technical Summary

Technical Problem

Conventional SIEM solutions and SOAR frameworks struggle to respond effectively to new cyber threats, require manual intervention, and lack context-aware responses, leading to inefficient or excessive countermeasures.

Method used

A threat detection model that analyzes the association between elements in a threat detection rule set and generates a specific countermeasure playbook by evaluating the context of a threat event, using a rule set-playbook matching module to create or match a response to the threat.

Benefits of technology

The model enables context-aware responses to previously unseen threats and optimizes playbook generation, reducing reliance on manual intervention and improving response efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 112025114626214-PAT00001_ABST
    Figure 112025114626214-PAT00001_ABST
Patent Text Reader

Abstract

According to the present invention, a method for providing a specific threat countermeasure playbook for responding to a specific threat event comprises: (a) detecting that a specific threat detection ruleset corresponding to a condition for detecting a specific threat event is input from a user terminal corresponding to a user, wherein a computing device inputs the specific threat detection ruleset to a ruleset analysis module, thereby causing the ruleset analysis module to extract each of: (i) specific threat description data including one or more elements for describing the specific threat event; (ii) specific threat query data including one or more elements determined for the purpose of searching for a specific threat log corresponding to the specific threat event in a log database in which logs of a system operated by the user are recorded; and (iii) specific threat detection option data which is data regarding one or more elements to be referenced as a criterion for searching for the specific threat log; and determining a specific threat detection ruleset structure including the specific threat description data, the specific threat query data, and the specific threat detection option data. (b) a step in which the computing device inputs the specific threat detection rule set structure into a threat detection model, thereby causing the threat detection model to determine the association between at least some of the elements of the specific threat description data, at least some of the elements of the specific threat query data, and at least some of the elements of the specific threat detection option data, and to determine the specific rule set analysis data by reference thereof; and (c) a step in which the computing device inputs the specific rule set analysis data obtained from the threat detection model into a rule set-playbook matching module, thereby causing the rule set-playbook matching module to determine a specific threat countermeasure playbook, which is a response method for the specific threat event corresponding to the specific rule set analysis data, and to provide the specific threat countermeasure playbook; the method is provided.
Need to check novelty before this filing date? Find Prior Art

Description

Technology Field

[0001] The present invention relates to a method for providing a specific threat countermeasure playbook for responding to a specific threat event and a computing device using the same. More specifically, the invention relates to a method in which a playbook that receives a rule set corresponding to conditions for detecting a specific threat event automatically determines and provides a specific threat countermeasure playbook necessary to deal with the specific threat event, and a computing device using the same. Background Technology

[0002] In the field of cybersecurity, various methods are being developed to respond to cyber attacks that evolve at every moment. Representative examples of these methods include Security Information and Event Management (SIEM) solutions and Security Orchestration Automation and Response (SOAR) frameworks.

[0003] First, a SIEM solution is a solution that manages the overall system necessary to recognize potential security threats by collecting and analyzing records, such as logs, generated throughout the IT infrastructure operated by the user. By analyzing logs generated throughout the IT infrastructure, such a SIEM solution performs the role of determining a ruleset, which is a set containing organized regularities for detecting cyber attacks, and users are able to detect potential security threats by referring to the organized ruleset.

[0004] Next, the SOAR framework is a framework designed to prevent cyber attacks on each element of the IT infrastructure in advance and to automatically respond when an attack is detected. Here, when a component of the SOAR framework detects a specific type of cyber attack attempt (for example, by referring to the rule set of the SIEM solution described above), other components of the SOAR framework perform an automated response to the cyber attack by operating according to a predetermined playbook to respond to that specific type of attack.

[0005] However, conventional SIEM solutions and SOAR frameworks have several drawbacks. For example, as mentioned earlier, since the specific playbook to follow for a particular type of cyber attack must be determined in advance, SOAR frameworks cannot respond to new types of cyber attacks. Conversely, even for types of cyber attacks that can be handled by existing playbooks, there is a problem in that the response may be excessive or insufficient because the importance or context of the situation in which the attack occurred is not taken into account. Furthermore, because IT infrastructure security personnel must specify the playbook for each situation, the performance of SOAR frameworks is significantly affected by their intervention or errors, leading to the issue of requiring continuous maintenance by security personnel.

[0006] Accordingly, the applicant intends to propose the present invention as a method to solve the disadvantages of the aforementioned conventional SIEM solutions and SOAR frameworks. Prior art literature

[65535] Patent Registration Publication No. 10-2845534 (August 12, 2025) The problem to be solved

[0007] The present invention aims to solve all of the aforementioned problems.

[0008] Another objective of the present invention is to provide a threat detection model capable of performing analysis while maintaining the context of a specific threat detection rule set by training the threat detection model to evaluate the degree of association between elements included in each of the specific threat description data, which is natural language text corresponding to a specific threat event included in a specific threat detection rule set; the specific threat query data determined for the purpose of searching for logs associated with the specific threat event; and the specific threat detection option data referenced as a criterion for searching for logs associated with the specific threat event.

[0009] Another objective of the present invention is to provide a framework capable of responding to threat events for which no playbook has been previously created, by having a rule set-playbook matching module, which receives specific rule set analysis data resulting from the analysis of a specific threat detection rule set, match or create a specific threat countermeasure playbook to respond to a specific threat event. means of solving the problem

[0010] As stated above, the characteristic configuration of the present invention for achieving the objective of the present invention and realizing the characteristic effects of the present invention described below is as follows.

[0011] According to one aspect of the present invention, a method for providing a specific threat countermeasure playbook for responding to a specific threat event comprises: (a) detecting that a specific threat detection ruleset corresponding to a condition for detecting a specific threat event is input from a user terminal corresponding to a user, wherein a computing device inputs the specific threat detection ruleset to a ruleset analysis module, thereby causing the ruleset analysis module to extract each of: (i) specific threat description data including one or more elements for describing the specific threat event; (ii) specific threat query data including one or more elements determined for the purpose of searching for a specific threat log corresponding to the specific threat event in a log database in which logs of a system operated by the user are recorded; and (iii) specific threat detection option data which is data regarding one or more elements to be referenced as a criterion for searching for the specific threat log; and determining a specific threat detection ruleset structure including the specific threat description data, the specific threat query data, and the specific threat detection option data. (b) a step in which the computing device inputs the specific threat detection rule set structure into a threat detection model, thereby causing the threat detection model to determine the association between each of at least some of the elements of the specific threat description data, each of at least some of the elements of the specific threat query data, and each of at least some of the elements of the specific threat detection option data, and to determine the specific rule set analysis data by reference thereof; and (c) a step in which the computing device inputs the specific rule set analysis data obtained from the threat detection model into a rule set-playbook matching module, thereby causing the rule set-playbook matching module to determine a specific threat countermeasure playbook, which is a response method for the specific threat event corresponding to the specific rule set analysis data, and to provide the specific threat countermeasure playbook; the method is disclosed.

[0012] As an example, prior to step (a) above, in a state where each of a plurality of learning threat detection rule sets corresponding to each of a plurality of learning threat events is determined (a01), the computing device inputs each of the plurality of learning threat detection rule sets into the rule set analysis module, thereby causing the rule set analysis module to extract, for each of the plurality of learning threat detection rule sets, (i) learning threat description data including one or more elements for describing the learning threat event, (ii) learning threat query data including one or more elements determined for the purpose of searching for a learning threat log corresponding to the learning threat event in the log database in which the log of the system operated by the user is recorded, and (iii) learning threat detection option data which is data regarding one or more elements to be referenced as a criterion for searching the learning threat log, and determine each of a plurality of learning threat detection rule set structure corresponding to each of the plurality of learning threat events by referencing each of the learning threat description data, each of the learning threat query data, and each of the learning threat detection option data;A method is disclosed, further comprising: (a02) a step in which the computing device inputs each of the plurality of training threat detection rule set structures into the threat detection model, thereby causing the threat detection model to perform, for each of the plurality of training threat detection rule set structures, (i) a subprocess of predicting each training description-query element pair data composed of each element whose association is greater than or equal to a pre-set training description-query threshold similarity by evaluating each of the associations between each element included in each of the training threat description data and each of the elements included in each of the training threat query data, and (ii) a subprocess of predicting each training description-option pair data composed of each element whose association is greater than or equal to a pre-set training description-option threshold similarity by evaluating each of the associations between each of the elements included in each of the training threat description data and each of the elements included in each of the training threat detection option data, and training the threat detection model by reference to each of the training description-query pair data and each of the description-option pair data.

[0013] As an example, in step (a01) above, the computing device further acquires each of a plurality of GT threat classification data comprising at least a portion of each GT threat event type which is the correct answer type for each of the plurality of learning threat events, each GT threat event target which is the correct answer target attacked in each of the plurality of learning threat events, each GT threat event risk which is the correct answer result of evaluating the risk of each of the plurality of learning threat events, and each GT threat event framework data which is the correct answer framework data for classifying each of the plurality of learning threat events, and in step (a02), (a021) the computing device causes the threat detection model to, by reference to each element included in the learning description-query pair data and each element included in the learning description-option pair data for each of the plurality of learning threat detection rule set structures, for each of the plurality of learning threat detection rule set structures, each of the plurality of learning threat event prediction types which is the result of predicting the type of each of the plurality of learning threat events, each of the plurality of learning threat event prediction targets which is the result of predicting the target attacked in each of the plurality of learning threat events, and the risk of each of the plurality of learning threat events A step of outputting each of the learning threat event prediction risk, which is the predicted result, and each of the learning threat event prediction framework data, which is the predicted result, of the framework data classifying each of the plurality of learning threat events;and (a022) a method is disclosed comprising the step of the computing device causing the threat detection model to calculate, for each event type loss which is a loss between each of the training threat event prediction types corresponding to each of the plurality of training threat detection rule set structures and each of the GT threat event types, for each event target loss which is a loss between each of the training threat event prediction targets and each of the GT threat event targets, for each risk loss which is a loss between each of the training threat event prediction risks and each of the GT threat event risks, and for each framework data loss which is a loss between each of the training threat event prediction framework data and each of the GT threat event framework data, and to train the threat detection model by reference to at least some of the event type loss, the event target loss, the risk loss, and the framework data loss.

[0014] As an example, in step (b) above, (b1) the computing device performs a subprocess in which the threat detection model, upon detecting that the specific threat detection rule set structure has been input, (i) evaluates each of the associations between at least some of the elements of the specific threat description data and each of at least some of the elements of the specific threat query data to predict specific description-query element pair data composed of each of the elements whose associations are greater than or equal to a pre-established specific description-query threshold similarity, and (ii) evaluates each of the associations between at least some of the elements of the specific threat description data and each of at least some of the elements of the specific threat detection option data to predict specific description-option element pair data composed of each of the elements whose associations are greater than or equal to a pre-established specific description-option threshold similarity; and (b2) a method further comprising the step of: the computing device causing the threat detection model to output a specific threat event prediction type, which is the result of predicting the type of the specific threat event by referring to each of the specific description-query element pair data and the specific description-option element pair data, a specific threat event prediction target, which is the result of predicting the target to be attacked in the specific threat event, a specific threat event prediction risk, which is the result of predicting the risk of the specific threat event, and a specific threat event prediction framework data, which is the result of predicting framework data for classifying the specific threat event, and determining the specific rule set analysis data by referring to at least some of the specific threat event prediction type, the specific threat event prediction target, the specific threat event prediction risk, and the specific threat event prediction framework data.

[0015] As an example, in step (c) above, (c1) the computing device causes the rule set-playbook matching module, which detects that the specific rule set analysis data has been input, to generate at least some of a specific threat event type vector, a specific threat event target vector, a specific threat event risk vector, and a specific threat event framework vector by embedding each of at least some of the specific threat event prediction type, the specific threat event prediction target, the specific threat event prediction risk, and the specific threat event prediction framework data included in the specific rule set analysis data, and to determine a specific rule set analysis vector corresponding to the specific rule set analysis data by referencing each of at least some of the specific threat event type vector, the specific threat event target vector, the specific threat event risk vector, and the specific threat event framework vector;and (c2) with each of the multiple threat countermeasure playbook candidate vectors, which are the results of embedding each of the multiple threat countermeasure playbook candidates determined as countermeasures for each of the multiple threat event candidates, recorded in the playbook database, the computing device causes the rule set-playbook matching module to evaluate each of the similarity between each of at least some of the multiple threat countermeasure playbook candidate vectors and the specific rule set analysis vector, and (i) when detecting that there is one or more first threat countermeasure playbooks which are at least some of the multiple threat countermeasure playbook candidates corresponding to at least some of the multiple threat countermeasure playbook candidate vectors where the similarity between the specific rule set analysis vector and the first threat countermeasure playbook candidate vector is greater than or equal to a preset rule set-playbook threshold similarity, the subprocess of determining the specific threat countermeasure playbook by reference to the first threat countermeasure playbook; and (ii) when detecting that the first threat countermeasure playbook candidate does not exist, the subprocess of generating a second threat countermeasure playbook corresponding to the specific threat event by reference to the specific rule set analysis vector and determining the specific threat countermeasure playbook by reference to the second threat countermeasure playbook. A method is disclosed that further comprises the step of performing any one of the sub-processes.

[0016] As an example, in (ii) of step (c2) above. With each of the following recorded in the state in which, for each type of each threat event included in each of the plurality of threat event candidates, a second threat countermeasure playbook action candidate group comprising a plurality of playbook actions which are each action executed through the second threat countermeasure playbook, a second threat countermeasure playbook condition candidate group comprising each playbook execution condition which is each condition for each of the plurality of playbook actions to be executed, and a second threat countermeasure playbook input value candidate group comprising a plurality of playbook input values ​​corresponding to each value required for the execution of each of the plurality of playbook execution actions are recorded, the computing device causes the rule set-playbook matching module to: (i) determine as second threat countermeasure playbook prediction conditions at least some of the plurality of playbook execution conditions included in the second threat countermeasure playbook condition candidate group that are predicted to correspond to the specific rule set analysis vector; (ii) determine as second threat countermeasure playbook actions at least some of the plurality of playbook actions included in the second threat countermeasure playbook action candidate group that correspond to the specific rule set analysis vector and satisfy the second threat countermeasure playbook condition; (iii) the second threat countermeasure playbook A method is disclosed in which a subprocess is performed to determine as a second threat countermeasure playbook input value at least a portion of the plurality of playbook input values ​​included in the condition candidate group that corresponds to the specific rule set analysis vector and is required for the execution of the second threat countermeasure playbook action, and a second threat countermeasure playbook corresponding to the specific rule set analysis data is generated by referring to each of the second threat countermeasure playbook action, the second threat countermeasure playbook condition, and the second threat countermeasure playbook input value.

[0017] As an example, a method is disclosed in which, with a predetermined playbook action priority determined as a priority for each of the plurality of playbook actions included in the second threat countermeasure playbook action candidate group, the computing device causes the rule set-playbook matching module to generate the second threat countermeasure playbook by further referring to second threat countermeasure playbook ranking information, which is the result of arranging at least some of the plurality of playbook actions included in the second threat countermeasure playbook action according to the playbook action priority.

[0018] As an example, a method is disclosed in which, in step (b2) above, the computing device causes the rule set-playbook matching module to generate the specific rule set analysis vector through a weighted sum of the specific threat event type vector, the specific threat event target vector, the specific threat event risk vector, and the specific threat event framework vector.

[0019] As an example, a method is disclosed in which, in step (a) above, the computing device displays a rule set input interface on the screen of the user terminal, thereby enabling the user to input the specific threat description data, the specific threat query data, and the specific threat detection option data included in the specific rule set analysis data.

[0020] As an example, a method is disclosed in which, in step (c) above, the computing device displays a rule set-playbook linkage status interface on the screen of the user terminal, thereby enabling the user to confirm that the specific threat detection rule set entered by the user and the specific threat countermeasure playbook determined by the rule set-playbook matching module are linked to each other, and to enable the user to review the linked specific threat countermeasure playbook and the specific threat detection rule set.

[0021] According to another aspect of the present invention, a computing device for providing a specific threat countermeasure playbook for responding to a specific threat event comprises: at least one memory for storing instructions; and at least one processor configured to execute said instructions; wherein the processor comprises: (I) a process of inputting a specific threat detection ruleset corresponding to a condition for detecting a specific threat event from a user terminal corresponding to a user, thereby inputting said specific threat detection ruleset into a ruleset analysis module, so as to cause the ruleset analysis module to extract each of: (i) specific threat description data including one or more elements for describing said specific threat event; (ii) specific threat query data including one or more elements determined for the purpose of searching for a specific threat log corresponding to said specific threat event in a log database in which logs of a system operated by said user are recorded; and (iii) specific threat detection option data which is data regarding one or more elements to be referenced as a criterion for searching said specific threat log, and determining a specific threat detection ruleset structure including said specific threat description data, said specific threat query data, and said specific threat detection option data. (II) A process of inputting the above-mentioned specific threat detection rule set structure into a threat detection model, thereby causing the threat detection model to determine the association between at least some of the elements of the specific threat description data, at least some of the elements of the specific threat query data, and at least some of the elements of the specific threat detection option data, and to determine the specific rule set analysis data by reference thereof;and (III) a process of inputting the specific rule set analysis data obtained from the threat detection model into the rule set-playbook matching module, thereby causing the rule set-playbook matching module to determine a specific threat countermeasure playbook, which is a response method for the specific threat event corresponding to the specific rule set analysis data, and providing the specific threat countermeasure playbook; is disclosed.;

[0022] As an example, prior to the above process (I), the processor inputs each of the plurality of learning threat detection rule sets corresponding to each of the plurality of learning threat events into the rule set analysis module, with each of the plurality of learning threat detection rule sets determined (I01), thereby causing the rule set analysis module to extract, for each of the plurality of learning threat detection rule sets, (i) learning threat description data including one or more elements for describing the learning threat event, (ii) learning threat query data including one or more elements determined for the purpose of searching for a learning threat log corresponding to the learning threat event in the log database in which the log of the system operated by the user is recorded, and (iii) learning threat detection option data which is data regarding one or more elements to be referenced as a criterion for searching the learning threat log, and determines each of the plurality of learning threat detection rule set structures corresponding to each of the plurality of learning threat events by referencing each of the learning threat description data, each of the learning threat query data, and each of the learning threat detection option data;A computing device is disclosed, further comprising: (I02) inputting each of the plurality of learning threat detection rule set structures into the threat detection model, thereby causing the threat detection model to perform, for each of the plurality of learning threat detection rule set structures, (i) a sub-process of predicting each of the learning description-query element pair data composed of each element whose association is greater than or equal to a pre-set learning description-query threshold similarity by evaluating each of the associations between each of the elements included in each of the learning threat description data and each of the elements included in each of the learning threat query data, and (ii) a sub-process of predicting each of the learning description-option pair data composed of each element whose association is greater than or equal to a pre-set learning description-option threshold similarity by evaluating each of the associations between each of the elements included in each of the learning threat description data and each of the elements included in each of the learning threat detection option data, and training the threat detection model by reference to each of the learning description-query pair data and each of the description-option pair data.

[0023] For example, in the above process (I01), the processor further acquires each of a plurality of GT threat classification data comprising at least a portion of each GT threat event type which is the correct answer type for each of the plurality of learning threat events, each GT threat event target which is the correct answer target attacked in each of the plurality of learning threat events, each GT threat event risk which is the correct answer result of evaluating the risk of each of the plurality of learning threat events, and each GT threat event framework data which is the correct answer framework data for classifying each of the plurality of learning threat events, and in the above process (I02), the processor causes the threat detection model to (I021) refer to each element included in the learning description-query pair data and each element included in the learning description-option pair data for each of the plurality of learning threat detection rule set structures, for each of the plurality of learning threat detection rule set structures, each of the plurality of learning threat event prediction types which is the result of predicting the type of each of the plurality of learning threat events, each of the plurality of learning threat event prediction targets which is the result of predicting the target attacked in each of the plurality of learning threat events, and the risk of each of the plurality of learning threat events A process for outputting each of the predicted learning threat event prediction risks and each of the predicted learning threat event prediction framework data, which are the predicted results of the framework data for classifying each of the plurality of learning threat events;A computing device is disclosed, comprising: (I022) a process of causing the threat detection model to calculate, for each event type loss which is a loss between each of the learning threat event prediction types corresponding to each of the plurality of learning threat detection rule set structures and each of the GT threat event types, for each event target loss which is a loss between each of the learning threat event prediction targets and each of the GT threat event targets, for each risk loss which is a loss between each of the learning threat event prediction risks and each of the GT threat event risks, and for each framework data loss which is a loss between each of the learning threat event prediction framework data and each of the GT threat event framework data, and to train the threat detection model by reference to at least some of the event type loss, the event target loss, the risk loss, and the framework data loss.

[0024] As an example, in the above process (II), the processor performs a process in which the threat detection model, upon detecting that the specific threat detection rule set structure is input, (II1) performs a subprocess of (i) predicting specific description-query element pair data composed of each element whose association is greater than or equal to a pre-set specific description-query threshold similarity by evaluating each of the associations between at least some of the elements of the specific threat description data and at least some of the elements of the specific threat query data, and (ii) performs a subprocess of (ii) predicting specific description-option element pair data composed of each element whose association is greater than or equal to a pre-set specific description-option threshold similarity by evaluating each of the associations between at least some of the elements of the specific threat description data and at least some of the elements of the specific threat detection option data; and (II2) a computing device is disclosed that further performs the process of the processor causing the threat detection model to output a specific threat event prediction type, which is the result of predicting the type of the specific threat event, a specific threat event prediction target, which is the result of predicting the target to be attacked in the specific threat event, a specific threat event prediction risk, which is the result of predicting the risk of the specific threat event, and a specific threat event prediction framework data, which is the result of predicting the framework data for classifying the specific threat event, by referring to each of the specific description-query element pair data and the specific description-option element pair data, and determining the specific rule set analysis data by referring to at least some of the specific threat event prediction type, the specific threat event prediction target, the specific threat event prediction risk, and the specific threat event prediction framework data.

[0025] As an example, in the above process (III), the processor causes the rule set-playbook matching module, which detects that the specific rule set analysis data has been input (III1), to generate at least some of a specific threat event type vector, a specific threat event target vector, a specific threat event risk vector, and a specific threat event framework vector by embedding each of at least some of the specific threat event prediction type, the specific threat event prediction target, the specific threat event prediction risk, and the specific threat event prediction framework data included in the specific rule set analysis data, and to determine a specific rule set analysis vector corresponding to the specific rule set analysis data by referencing each of the specific threat event type vector, the specific threat event target vector, the specific threat event risk vector, and the specific threat event framework vector;and (III2) in a state where each of the multiple threat countermeasure playbook candidate vectors, which are the results of embedding each of the multiple threat countermeasure playbook candidates determined as countermeasures for each of the multiple threat event candidates, is recorded in the playbook database, the rule set-playbook matching module evaluates each of the similarity between each of at least some of the multiple threat countermeasure playbook candidate vectors and the specific rule set analysis vector, and (i) when it is detected that there is one or more first threat countermeasure playbooks which are at least some of the multiple threat countermeasure playbook candidates corresponding to at least some of the multiple threat countermeasure playbook candidate vectors where the similarity between the specific rule set analysis vector and the first threat countermeasure playbook candidate vector is greater than or equal to a preset rule set-playbook threshold similarity, the subprocess determines the specific threat countermeasure playbook by reference to the first threat countermeasure playbook, and (ii) when it is detected that the first threat countermeasure playbook candidate does not exist, generates a second threat countermeasure playbook corresponding to the specific threat event by reference to the specific rule set analysis vector, and determines the specific threat countermeasure playbook by reference to the second threat countermeasure playbook, among A computing device that further performs a process of performing one of the above is disclosed.

[0026] As an example, in (ii) of the above (III2) process. With each of the following recorded in the state in which, for each type of each threat event included in each of the plurality of threat event candidates, a second threat countermeasure playbook action candidate group comprising a plurality of playbook actions which are each action executed through the second threat countermeasure playbook, a second threat countermeasure playbook condition candidate group comprising each playbook execution condition which is each condition for each of the plurality of playbook actions to be executed, and a second threat countermeasure playbook input value candidate group comprising a plurality of playbook input values ​​corresponding to each value required for the execution of each of the plurality of playbook execution actions are recorded, the processor causes the rule set-playbook matching module to: (i) determine as second threat countermeasure playbook prediction conditions at least some of the plurality of playbook execution conditions included in the second threat countermeasure playbook condition candidate group that are predicted to correspond to the specific rule set analysis vector; (ii) determine as second threat countermeasure playbook actions at least some of the plurality of playbook actions included in the second threat countermeasure playbook action candidate group that correspond to the specific rule set analysis vector and satisfy the second threat countermeasure playbook condition; and (iii) the second threat countermeasure playbook A computing device is disclosed, comprising: (iv) a subprocess for determining as a second threat countermeasure playbook input value at least a portion of the plurality of playbook input values ​​included in the condition candidate group that correspond to the specific rule set analysis vector and is required for the execution of the second threat countermeasure playbook action; and (iv) a subprocess for generating the second threat countermeasure playbook corresponding to the specific rule set analysis data by referring to each of the second threat countermeasure playbook action, the second threat countermeasure playbook condition, and the second threat countermeasure playbook input value.

[0027] As an example, a computing device is disclosed in which, when a predetermined playbook action priority is determined as a priority for each of the plurality of playbook actions included in the second threat countermeasure playbook action candidate group, the processor causes the rule set-playbook matching module to generate the second threat countermeasure playbook by further referring to second threat countermeasure playbook ranking information, which is the result of aligning at least some of the plurality of playbook actions included in the second threat countermeasure playbook action according to the playbook action priority.

[0028] As an example, in the above (II2) process, a computing device is disclosed in which the processor causes the rule set-playbook matching module to generate the specific rule set analysis vector through a weighted sum of the specific threat event type vector, the specific threat event target vector, the specific threat event risk vector, and the specific threat event framework vector.

[0029] As an example, in the above process (I), a computing device is disclosed that supports the user to input the specific threat description data, the specific threat query data, and the specific threat detection option data included in the specific rule set analysis data by displaying a rule set input interface on the screen of the user terminal.

[0030] As an example, in the above process (III), a computing device is disclosed in which the processor displays a rule set-playbook linkage status interface on the screen of the user terminal, thereby enabling the user to confirm that the specific threat detection rule set entered by the user and the specific threat countermeasure playbook determined by the rule set-playbook matching module are linked to each other, and to enable the user to review the linked specific threat countermeasure playbook and the specific threat detection rule set. Effects of the invention

[0031] The present invention has the effect of providing a threat detection model capable of performing analysis while maintaining the context of a specific threat detection rule set by training the threat detection model to evaluate the degree of association between elements included in each of the specific threat description data, which is natural language text corresponding to a specific threat event included in a specific threat detection rule set, the specific threat query data determined for the purpose of searching for logs associated with the specific threat event, and the specific threat detection option data referenced as a criterion for searching for logs associated with the specific threat event.

[0032] The present invention has another effect of providing a framework capable of responding to threat events for which no playbook has been previously created by having a rule set-playbook matching module, which receives specific rule set analysis data resulting from the analysis of a specific threat detection rule set, match or generate a specific threat countermeasure playbook to respond to a specific threat event. Brief explanation of the drawing

[0033] The drawings attached below for use in describing embodiments of the present invention are merely some of the embodiments of the present invention, and other drawings can be obtained based on these drawings without inventive work by a person skilled in the art to which the present invention pertains (hereinafter "person skilled in the art"). FIG. 1 schematically illustrates an overall system for providing a specific threat countermeasure playbook for responding to a specific threat event according to an embodiment of the present invention, and FIG. 2 is a flowchart illustrating a method for providing a specific threat countermeasure playbook to respond to a specific threat event according to an embodiment of the present invention, and FIG. 3 schematically illustrates a user interface that supports a user in inputting a specific threat detection rule set to provide a specific threat countermeasure playbook for responding to a specific threat event according to an embodiment of the present invention. FIG. 4 schematically illustrates a lookup table including playbook conditions, playbook actions, and playbook input values ​​necessary to generate a specific threat countermeasure playbook for responding to a specific threat event according to an embodiment of the present invention. FIG. 5a schematically illustrates a rule set-playbook linkage status interface that displays to a user, in a table format, the state in which a specific threat detection rule set corresponding to a specific threat event and a specific threat countermeasure playbook are linked according to an embodiment of the invention. FIG. 5b schematically illustrates a rule set-playbook linkage status interface that displays to a user, in a graph format, the state in which a specific threat detection rule set corresponding to a specific threat event and a specific threat countermeasure playbook are linked according to one embodiment of the invention. Specific details for implementing the invention

[0034] The following detailed description of the present invention refers to the accompanying drawings, which illustrate specific embodiments in which the present invention can be practiced in order to clarify the objects, technical solutions, and advantages of the present invention. These embodiments are described in sufficient detail to enable a person skilled in the art to practice the present invention.

[0035] Furthermore, throughout the detailed description and claims of the invention, the word “comprising” and its variations are not intended to exclude other technical features, additions, components, or parts. Other objects, advantages, and characteristics of the invention will become apparent to a person skilled in the art, in part from this description and in part from the practice of the invention. The following examples and drawings are provided by way of example and are not intended to limit the invention.

[0036] Furthermore, the present invention encompasses all possible combinations of the embodiments set forth in this specification. It should be understood that various embodiments of the present invention are different but need not be mutually exclusive. For example, specific shapes, structures, and characteristics described herein may be implemented in other embodiments without departing from the spirit and scope of the invention in relation to one embodiment. It should also be understood that the location or arrangement of individual components within each disclosed embodiment may be changed without departing from the spirit and scope of the invention. Accordingly, the following detailed description is not intended to be limiting, and the scope of the invention is limited only by the appended claims, including all equivalents to those claimed therein, provided appropriately described. Similar reference numerals in the drawings refer to the same or similar functions across various aspects.

[0037] Hereinafter, in order to enable a person skilled in the art to easily practice the present invention, preferred embodiments of the present invention will be described in detail with reference to the attached drawings.

[0038] FIG. 1 schematically illustrates an overall system that provides a specific threat countermeasure playbook for responding to a specific threat event according to one embodiment of the present invention.

[0039] Referring to FIG. 1, a computing device (100) that provides a specific threat countermeasure playbook for responding to a specific threat event may include a memory (110) and a processor (120). At this time, the computing device (100) may be a server computer, but is not limited thereto, and may include various computing devices.

[0040] First, the memory (110) of a computing device (100) that provides a specific threat countermeasure playbook for responding to a specific threat event may store instructions to be executed by a processor (120). Specifically, the instructions are code generated for the purpose of causing the computing device (100) that provides a specific threat countermeasure playbook for responding to a specific threat event to function in a specific manner, and the memory (110) for storing them may be a computer-readable or computer-accessible memory that may be directed toward a computer or other programmable data processing equipment. The instructions may correspond to a process for executing the functions described in the specification of the present invention.

[0041] And the processor (120) of the computing device (100) may include hardware configurations such as an MPU (Micro Processing Unit) or CPU (Central Processing Unit), cache memory, and data bus. Additionally, the computing device (100) may further include software configurations such as an operating system and an application for a specific purpose.

[0042] However, this does not exclude the case where the processor (120) of the computing device (100) includes an integrated processor in which the medium, processor, and memory for carrying out the present invention are integrated.

[0043] Additionally, with reference to the example disclosed in FIG. 1, the computing device (100) may further include several modules that perform a process for determining a specific threat countermeasure playbook to be provided to a user. Specifically, with reference to FIG. 1, the computing device (100) may further include a rule set analysis module (210) that extracts specific threat description data, specific threat query data, and specific threat detection option data, respectively, from a specific threat detection rule set received from a user; a threat detection model (220) that receives a specific threat detection rule set structure determined by the computing device (100) with reference to the specific threat description data, specific threat query data, and specific threat detection option data, and determines specific rule set analysis data; and a rule set-playbook matching module (230) that receives the specific rule set analysis data determined by the threat detection model (220) and determines a specific threat countermeasure playbook, which is a response method for a specific threat event.

[0044] However, this is merely an example, and if the rule set analysis module (210), the threat detection model (220), and the rule set-playbook matching module (230) are each located outside the computing device (100), the rule set analysis module (210), the threat detection model (220), and the rule set-playbook matching module (230) may each be interconnected with the computing device (100). Then, the computing device (100) transmits input data required by each of the rule set analysis module (210), the threat detection model (220), and the rule set-playbook matching module (230), and receives output data output by each.

[0045] It may further include hardware and software configurations. Specific processes performed in each of the rule set analysis module (210), threat detection model (220), and rule set-playbook matching module (230) will be described later.

[0046] In addition, the computing device (100) may further include hardware and / or software configurations for communicating with a database, such as a log database (600) in which logs of a system currently being operated by a user are stored, and a playbook database (700) in which predetermined playbooks are stored, or with a user terminal (800) corresponding to a user who wishes to receive a specific threat countermeasure playbook to respond to a specific threat event.

[0047] At this time, the hardware configuration of each of the log database (600) and the playbook database (700) may include at least one type of storage medium among flash memory type, hard disk type, multimedia card micro type, card type memory (e.g., SD or XD memory), RAM (Random Access Memory), SRAM (Static Random Access Memory), ROM (ReadOnly Memory), EEPROM (Electrically Erasable Programmable ReadOnly Memory), PROM (Programmable ReadOnly Memory), magnetic memory, magnetic disk, and optical disk, but is not limited thereto and may include any medium capable of storing data. Additionally, the software configuration of each of the log database (600) and playbook database (700) may be a configuration for storing and managing logs and playbooks as strings, etc., or may include a text embedding model that embeds text data constituting logs and playbooks into vectors, such as Gecko, or a configuration for storing and managing embedded log and playbook data, such as ChromaDB.

[0048] A detailed description of a method for generating a specific threat countermeasure playbook using a computing device (100) that provides a specific threat countermeasure playbook to respond to a specific threat event described with reference to FIG. 1 is further described with reference to FIG. 2 to 4.

[0049] FIG. 2 is a flowchart illustrating a method for providing a specific threat countermeasure playbook to respond to a specific threat event according to an embodiment of the present invention.

[0050] Referring to FIG. 2, in step S210, when a specific threat detection rule set corresponding to a condition for detecting a specific threat event is detected from a user terminal (800) corresponding to a user, the computing device (100) may input the specific threat detection rule set into a rule set analysis module (210), and the rule set analysis module (210) that receives the specific threat detection rule set may extract each of: (i) specific threat description data including one or more elements for describing a specific threat event; (ii) specific threat query data including one or more elements determined for the purpose of searching for a specific threat log corresponding to a specific threat event in a log database (600) in which logs of a system operated by a user are recorded; and (iii) specific threat detection option data which is data for one or more elements to be referenced as a criterion for searching for a specific threat log.

[0051] At this time, the computing device (100) can support a user of the user terminal (800) in inputting a specific threat detection rule set by displaying a rule set input interface on the screen of the user terminal (800). Descriptions of this rule set input interface and the specific threat description data, specific threat query data, and specific threat detection option data input through the rule set input interface are provided with reference to FIG. 3.

[0052] FIG. 3 schematically illustrates a rule set input interface, which is a user interface displayed on the screen of a user who wishes to receive a specific threat countermeasure playbook for responding to a specific threat event according to one embodiment of the present invention.

[0053] Referring to FIG. 3, the rule set input interface (300) may include a threat description input field (310) for receiving specific threat description data, a threat query input field (320) for receiving specific threat query data, and a detection option input field (330) for receiving specific threat detection option data. By displaying this rule set input interface (300) on the screen of a user terminal (800), the computing device (100) enables the user to input a specific threat detection rule set including specific threat description data, specific threat query data, and specific threat detection option data. The specific threat description data, specific threat query data, and specific threat detection option data are described in detail as follows.

[0054] First, specific threat description data entered through the threat description input field (310) can correspond to natural language text data entered by the user. For example, as in the example of FIG. 3, the user can enter natural language text "MySQL Port Scan From Blacklisted IP" into the threat description input field (310) as specific threat description data. In this example, each of the various elements included in the specific threat description data can support a target capable of understanding natural language, that is, a security officer capable of accessing the operating system or a threat detection model (220) to be described later, in verifying various matters regarding a specific threat event corresponding to a specific threat detection rule set.

[0055] Specifically, in the example of FIG. 3, the element "MySQL" included in the specific threat description data indicates that the target of the specific threat event is a relational database built using a database management system called MySQL, the element "Port Scan" indicates that the type of the specific threat event is associated with scanning ports to access "MySQL," and the element "Blacklisted IP" indicates that the entity performing the specific threat event corresponds to an IP address listed on a blacklist. This specific threat description data may correspond to full-text data entered by the user (i.e., "MySQL Port Scan From Blacklisted IP" in the example above), but is not limited thereto. As another example, if a user inputs only some elements of specific threat description data (e.g., "Port Scan" of the previous example), the computing device (100) may recommend keywords that are highly associated with the elements input by the user (e.g., "MySQL" and "Blacklisted IP" of the previous example) through the threat description input field (310), and thereby support the operation of the threat detection model (220) to be described later.

[0056] Next, the specific threat query data entered through the threat query input field (320) may correspond to artificial language data designed for the purpose of describing data to be searched in the log database (600), such as conventional SQL (Standard Query Language). For example, in the example of FIG. 3, the user inputs the string "src_ip: 192.0.2.1 AND prtc:tcp AND dstn_asset_id:* AND dstn_port:3306 AND src_blackip:1" as specific threat query data into the threat query input field (320). A computing device (100), etc., that receives the specific threat query data can search the log database (600) for logs related to an event in which an attacker using the IP (192.0.2.1) listed in the blacklist accessed port 3306 using the TCP protocol.

[0057] In this case, each element included in the specific threat query data composed of artificial language also shares commonalities with the specific threat description data composed of natural language in that it corresponds to each component associated with the manner in which the specific threat event is performed. However, because the specific threat query data and the specific threat description data are text data written in artificial or natural language, respectively, each element of the specific threat query data and the specific threat description data may correspond to a different mode of representation.

[0058] For example, in a MySQL-based relational database, the port number 3306 is assigned by default to the port for accessing the database. Therefore, in the example of FIG. 3, "MySQL Port," which is an element of specific threat description data, can refer to a component with the same meaning as "dstn_port:3306," which is an element of specific threat query data. However, the element of specific threat description data corresponds to an expression that enables humans or LLMs capable of understanding natural language (such as in the example of "MySQL Port Scan") to understand a specific threat event or the intention of an attacker performing said specific threat event, and the corresponding element of specific threat query data corresponds to a standardized expression determined by an attacker to technically implement a specific threat event or by a user to detect a specific threat event (such as the component "MySQL port" being implemented as an integer type value of 3306 in programming code).

[0059] Finally, the specific threat detection option data entered through the detection option input field (330) can serve to further limit the search results through the specific threat query data described above. Specifically, in the detection option input field (330) of FIG. 3, as specific threat detection option data, the overtime for the detection option is 1 minute and the threshold count is 3 times, and the Group_by field, which is the field serving as the search standard, is described as the source IP and destination IP. At this time, as described above, when the computing device (100) performs a search of the log database (600) based on the specific threat detection option data, the computing device (100) can determine that only logs in which the same event occurred 3 or more times within 1 minute based on the source IP and destination IP are logs corresponding to the specific threat event by first analyzing the logs searched in the log database (600) additionally.

[0060] These specific threat detection option data can provide information about the nature and scale of specific threat events. For example, if the Group_by field contains only destination IPs, it may indicate an attack in which an attacker mobilizes multiple source IPs, such as in the example of DDoS. As another example, if the threshold Count shown in Fig. 3 increases from 3 to 100—that is, if the same event must occur 100 times in one minute to be determined as a specific threat event—the corresponding specific threat event may correspond to a cyber attack intended to overload the system being operated by the user.

[0061] However, the present invention is not limited thereto, and the rule set input interface (300) may include only at least some of the threat description input field (310), the threat query input field (320), and the detection option input field (330) to support the user in inputting only at least some of the specific threat description data, specific threat query data, and specific threat detection option data corresponding to each of at least some of each, and the remaining parts not input by the user may be determined by the computing device (100), or conversely, it may additionally include an input field that can receive any data if it relates to a specific threat event. For example, for the purpose of supporting cases where traffic corresponding to an attack may include image and / or video data, such as when the system operated by the user includes a configuration that processes images and / or videos like a vision model, the rule set input interface (300) may additionally include an input field that can input images or videos corresponding to a specific threat event.

[0062] Additionally, the rule set input interface (300) may further include a configuration to support a user in selecting specific threat description data, specific threat query data, and specific threat detection option data. For example, when the computing device (100) analyzes the specific threat description data entered by the user and determines recommended data for the specific threat query data and / or specific threat detection option data, the rule set input interface (300) may further include an input data recommendation display window (not shown) for displaying the recommended data determined by the computing device (100). As another example, various variations of the rule set input interface (300) may be possible, such as when the computing device (100) or the threat detection model (220) to be described later compares each of the specific threat description data and specific threat query data and / or specific threat detection option data entered by the user with each other, and detects that each of the entered specific threat description data and specific threat query data and / or specific threat detection option data corresponds to a different specific threat event, the computing device (100) may request the user to modify the specific threat detection rule set entered by displaying a rule set modification request window (not shown) on the rule set input interface (300).

[0063] Referring again to FIG. 2, in step S210, the rule set analysis module (210), which receives a specific threat detection rule set, can determine a specific threat detection rule set structure, which is structured data including specific threat description data, specific threat query data, and specific threat detection option data. At this time, the specific threat detection rule set structure may be a JSON file that includes at least some of the specific threat description data, specific threat query data, and specific threat detection option data exactly as they were entered by the user through the rule set input interface (300), and for the remaining parts, extracts and includes only some of the components necessary to describe a specific threat event, but is not limited thereto.

[0064] For example, the rule set analysis module (210) can determine a specific threat detection rule set structure such that natural language text "MySQL Port Scan From Blacklisted IP" entered by a user, as mentioned in the example of FIG. 3, is included as specific threat description data. As another example, if a user enters a complex sentence as specific threat description data, the rule set analysis module (210) may divide the specific threat description data entered by the user into multiple specific threat description tokens and determine that the specific threat detection rule set structure includes them as specific threat description data. As another example, since the example query of the specific threat query data mentioned in FIG. 3 is written in a query language (i.e., since each element is listed in a structured state), the rule set analysis module (210) may extract "src_ip: 192.0.2.1", "prtc:tcp", "dstn_asset_id:*", "dstn_port:3306", "src_blackip:1", etc., in accordance with the key:value format of a JSON file, and the specific threat detection rule set structure may determine to include each of the extracted elements as specific threat query data.

[0065] Subsequently, in step S220, the computing device (100) inputs the specific threat detection rule set structure determined in step S210 into the threat detection model (220), thereby enabling the threat detection model (220) to determine the association between at least some of the elements of the specific threat description data, at least some of the elements of the specific threat query data, and at least some of the elements of the specific threat detection option data. To this end, the threat detection model (220) may be in a pre-learned state to determine the association between at least some of the elements of the specific threat description data, at least some of the elements of the specific threat query data, and at least some of the elements of the specific threat detection option data.

[0066] The method of pre-training a threat detection model (220) to determine the relationship between at least some of the elements of specific threat description data, at least some of the elements of specific threat query data, and at least some of the elements of specific threat detection option data is described in detail as follows. First, with each of a plurality of learning threat detection rule sets corresponding to each of a plurality of learning threat events determined, a computing device (100) can input each of the plurality of learning threat detection rule sets into a rule set analysis module (210), and thereby the rule set analysis module (210) can perform a process of extracting each of the following for each of the plurality of learning threat detection rule sets: (i) learning threat description data including one or more elements for describing a learning threat event, (ii) learning threat query data including one or more elements determined for the purpose of searching for a learning threat log corresponding to the learning threat event in a log database (600) in which logs of a system operated by a user are recorded, and (iii) learning threat detection option data which is data for one or more elements to be referenced as a criterion for searching for a learning threat log. Specific descriptions of the learning threat description data, learning threat query data, and learning threat detection option data, respectively, will be substituted by the descriptions of the specific threat description data, specific threat query data, and specific threat detection option data in the example provided with reference to step S210 and Figure 3.

[0067] Then, the computing device (100) can determine each of a plurality of learning threat detection rule set structures corresponding to each of a plurality of learning threat events by referring to each of the learning threat description data, each of the learning threat query data, and each of the learning threat detection option data. A specific description of the learning threat detection rule set structures is also substituted with a description of a specific threat detection rule set structure.

[0068] Subsequently, the computing device (100) can input each of a plurality of learning threat detection rule set structures into the threat detection model (220). Then, for each of the plurality of learning threat detection rule set structures, the threat detection model (220) can perform a sub-process of (i) predicting each of the learning description-query element pair data composed of each element whose association is equal to or greater than a pre-set learning description-query threshold similarity by evaluating each of the associations between each element included in each of the learning threat description data and each of the elements included in each of the learning threat query data, and (ii) predicting each of the learning description-option pair data composed of each element whose association is equal to or greater than a pre-set learning description-option threshold similarity by evaluating each of the associations between each of the elements included in each of the learning threat description data and each of the elements included in each of the learning threat detection option data.

[0069] Here, assuming for convenience that the specific threat description data "MySQL Port Scan From Blacklisted IP" mentioned in Fig. 3 is the training threat description data and the specific threat query data "src_ip: 192.0.2.1 AND prtc:tcp AND dstn_asset_id:* AND dstn_port:3306 AND src_blackip:1" is the training threat query data, the training description-query element pair data consists of pair data composed of each element constituting the training threat description data, namely "MySQL", "Port Scan", and "Blacklisted IP" respectively, and each element constituting the training threat query data, namely "src_ip: 192.0.2.1", "prtc:tcp", "dstn_asset_id:*", "dstn_port:3306", and "src_blackip:1" respectively, wherein the similarity between the included elements is greater than or equal to the description-query threshold similarity, i.e., It may correspond to pair data where the included elements are judged to be sufficiently similar.

[0070] For example, as previously mentioned, the default port of a standard MySQL database is 3306, so the element "MySQL" in the training threat description data may be an element corresponding to "dstn_port:3306" in the training threat query data. In this case, the computing device (100) can train the threat detection model (220) to evaluate the similarity between "MySQL" and "dstn_port:3306" as being greater than or equal to the training description-query threshold similarity and to predict this as training description-query pair element data.

[0071] Likewise, if the training threat description data includes elements such as "source IP and destination IP," the computing device (100) can train the threat detection model (220) to evaluate that the similarity between the "Group_by" field (including source IP and destination IP) of the training threat detection option data and the "source IP and destination IP" elements of the training threat description data is greater than or equal to the description-option threshold similarity, and to predict this as training description-option pair element data.

[0072] At this time, the computing device (100) may have further acquired each of a plurality of GT threat classification data, each comprising at least a portion of the following: each GT threat event type which is the correct answer type for each of the plurality of training threat events, each GT threat event target which is the correct answer target attacked in each of the plurality of training threat events, each GT threat event risk which is the correct answer result that evaluates the risk of each of the plurality of training threat events, and each GT threat event framework data which is the correct answer framework data that classifies each of the plurality of training threat events, in order to evaluate each of the training explanation-query pair element data and training explanation-option pair element data predicted by the threat detection model (220).

[0073] Specifically, assuming, for instance, that a training threat event corresponds to a brute-force attack on a MySQL port, the GT threat event type is a brute-force attack, and the GT threat event target may be a port assigned to the MySQL database of the system being operated by the user. Additionally, if the data stored in the MySQL database is sensitive information, such as personal information, the GT threat event risk of that training threat event may be determined to be high. Finally, regarding the GT threat event framework data, it may be framework data that has been researched in advance for each threat event, such as the MITRE ATT&CK framework.

[0074] In this state, having obtained each of the multiple GT threat classification data corresponding to each of the multiple learning threat events, the computing device (100) can cause the threat detection model (220) to output, by referencing each of the elements included in the learning description-query element pair data and each of the elements included in the learning description-option element pair data of each of the multiple learning threat detection rule set structures, each of the multiple learning threat event prediction types which are the result of predicting each of the type of each of the multiple learning threat events, each of the multiple learning threat event prediction targets which are the result of predicting the target to be attacked in each of the multiple learning threat events, each of the learning threat event prediction risks which are the result of predicting the risk of each of the multiple learning threat events, and each of the multiple learning threat event prediction framework data which are the result of predicting the framework data for classifying each of the multiple learning threat events.

[0075] Then, the computing device (100) can cause the threat detection model (220) to calculate a loss by comparing each of the multiple learning threat event prediction types, each of the multiple learning threat event prediction targets, each of the multiple learning threat event prediction risks, and each of the multiple learning threat event prediction framework data with the corresponding correct answer data.

[0076] That is, the computing device (100) can cause the threat detection model (220) to calculate each event type loss, which is a loss between each training threat event prediction type and each GT threat event type corresponding to each of the plurality of training threat detection rule set structures; each event target loss, which is a loss between each of the plurality of training threat event prediction targets and each GT threat event target; each risk loss, which is a loss between each of the plurality of training threat event prediction risks and each GT threat event risk; and each framework data loss, which is a loss between each of the plurality of training threat event prediction framework data and each GT threat event framework data. Subsequently, the computing device (100) can train the threat detection model (220) by reference to each of the event type loss, event target loss, risk loss, and framework data loss.

[0077] Through this learning process, the threat detection model (220) of the present invention can be trained not merely as an artificial intelligence model specialized in interpreting either natural language or query statements, but as an artificial intelligence model that comprehensively considers various elements for explaining threat events (i.e., natural language descriptions) and formalized elements for technically implementing or detecting them (i.e., query statements).

[0078] Referring again to FIG. 2, at step S220, when a computing device (100) inputs a specific threat detection rule set structure to a learned threat detection model (220), the learned threat detection model (220) may perform a sub-process of predicting specific description-query element pair data composed of each element whose association is greater than or equal to a specific description-query threshold similarity by evaluating each of the associations between at least some of the elements of specific threat description data and at least some of the elements of specific threat query data, and a sub-process of predicting specific description-option element pair data composed of each element whose association is greater than or equal to a specific description-option threshold similarity by evaluating each of the associations between at least some of the elements of specific threat description data and at least some of the elements of specific threat detection option data.

[0079] At this time, the specific description-query threshold similarity and the specific description-option threshold similarity, respectively, may have the same value as the training description-query threshold similarity and the training description-option threshold similarity used in the training of the threat detection model (220), respectively, but are not limited thereto.

[0080] Subsequently, as in the learning process, the threat detection model (220) can output a specific threat event prediction type, which is the result of predicting the type of a specific threat event by referring to each of the specific description-query element pair data and the specific description-option element pair data; a specific threat event prediction target, which is the result of predicting the target to be attacked in the specific threat event; a specific threat event prediction risk, which is the result of predicting the risk of the specific threat event; and a specific threat event prediction framework data, which is the result of predicting the framework data for classifying the specific threat event. Then, the computing device (100) can determine specific rule set analysis data by referring to at least some of the specific threat event prediction type, specific threat event prediction target, specific threat event prediction risk, and the specific threat event prediction framework data.

[0081] Subsequently, in S230, the computing device (100) inputs specific rule set analysis data into the rule set-playbook matching module (230), thereby causing the rule set-playbook matching module (230) to determine a specific threat countermeasure playbook, which is a response method for a specific threat event corresponding to the specific rule set analysis data.

[0082] Specifically, the following applies. First, when a computing device (100) inputs specific rule set analysis data into a rule set-playbook matching module (230), the rule set-playbook matching module (230) can generate at least some of a specific threat event type vector, a specific threat event target vector, a specific threat event risk vector, and a specific threat event framework vector by embedding at least some of the specific threat event prediction type, specific threat event prediction target, specific threat event prediction risk, and specific threat event prediction framework data included in the specific rule set analysis data. Then, the rule set-playbook matching module (230) can determine a specific rule set analysis vector corresponding to the specific rule set analysis data by referencing at least some of the specific threat event type vector, specific threat event target vector, specific threat event risk vector, and specific threat event framework vector.

[0083] At this time, the specific rule set analysis vector can be generated through a weighted sum of the specific threat event type vector, the specific threat event target vector, the specific threat event risk vector, and the specific threat event framework vector, and the weights for the weighted sum may be the result of evaluating the importance of each of the specific threat event type, specific threat event target, specific threat event risk, and specific threat event framework data corresponding to each of the specific threat event type vector, specific threat event target vector, specific threat event risk vector, and specific threat event framework vector.

[0084] Meanwhile, a plurality of threat countermeasure playbook candidate vectors, each resulting from embedding a plurality of threat countermeasure playbook candidate determined as a countermeasure for each threat event candidate, may be recorded in the playbook database (600). In this state, the rule set-playbook matching module (230) can evaluate the similarity between a specific rule set analysis vector and each of the plurality of threat countermeasure playbook candidate vectors. At this time, the similarity evaluation method may be cosine similarity, but is not limited thereto. Furthermore, it is obvious that other similarities can be evaluated in addition to the vector similarity between the specific rule set analysis vector and the plurality of threat countermeasure playbook candidate vectors. For example, if a string of each of the threat countermeasure playbook candidate is additionally recorded in the playbook database (600), the rule set-playbook matching module (230) may additionally consider the degree of agreement between each string constituting the specific rule set analysis data and each string of each of the threat countermeasure playbook candidate.

[0085] Subsequently, with the similarity between each of the specific rule set analysis vector and each of the multiple threat countermeasure playbook candidate vectors evaluated, the rule set-playbook matching module (230) can determine whether there is at least one first threat countermeasure playbook, which is at least some of the multiple threat countermeasure playbook candidates that correspond to at least some of the multiple threat countermeasure playbook candidate vectors whose similarity with the specific rule set analysis vector is greater than or equal to the rule set-playbook threshold similarity. Through this, the rule set-playbook matching module (230) can determine whether there is at least one threat countermeasure playbook candidate vector among the threat countermeasure playbook candidate vectors previously recorded in the playbook database (600) that corresponds to a playbook capable of responding to a specific threat event in the current situation (i.e., the first threat countermeasure playbook), and if the first threat countermeasure playbook exists, the rule set-playbook matching module (230) can determine a specific threat countermeasure playbook to respond to a specific threat event by referring to the first threat countermeasure playbook.

[0086] At this time, if there are multiple first threat countermeasure playbooks, the rule set-playbook matching module (230) may determine the first threat countermeasure playbook corresponding to any one of the threat countermeasure playbook candidate vectors with the highest similarity to the specific rule set analysis vector as the specific threat countermeasure playbook, but is not limited thereto.

[0087] Meanwhile, if it is detected that the first threat countermeasure playbook does not exist, that is, if it is detected that there is no playbook corresponding to a specific threat detection rule set among the playbooks previously recorded in the playbook database (600), the rule set-playbook matching module (230) can generate a second threat countermeasure playbook corresponding to a specific threat event by referencing a specific rule set analysis vector, and determine the specific threat countermeasure playbook by referencing this. This is explained with reference to FIG. 4.

[0088] FIG. 4 schematically illustrates a lookup table including playbook conditions, playbook actions, and playbook input values ​​necessary to generate a specific threat countermeasure playbook for responding to a specific threat event according to an embodiment of the present invention.

[0089] Referring to FIG. 4, a lookup table (400) for generating a specific threat countermeasure playbook may include, for an attack type (410) corresponding to a type of threat event, a plurality of playbook execution condition candidate groups (420), a playbook action candidate group (430) including a plurality of playbook actions, and a second threat countermeasure playbook input value candidate group (440) including a plurality of playbook input values ​​corresponding to each of the values ​​required for the execution of each of the plurality of playbook execution actions. Such a lookup table (400) may be recorded in the memory (110) of a computing device (100).

[0090] At this time, for the convenience of explanation, the lookup table (400) of FIG. 4 is illustrated only when the attack type (410) of the threat event corresponds to the T1110 Brute force of the MITRE ATT&CK framework, that is, when the attack type (410) of the threat event is a brute force attack; however, it is obvious that depending on the environment in which the invention is executed, for each of the multiple attack types (410), multiple playbook condition candidate groups (420), multiple playbook action candidate groups (430), and multiple playbook input value candidate groups (440) may be set and included in the lookup table (400). Meanwhile, the lookup table (400) of FIG. 4 is illustrated as further including a remark (450) containing reference information for each element included in each of the playbook condition candidate group (420), playbook action candidate group (430), and playbook input value candidate group (440), but is not limited thereto.

[0091] In this state, the rule set-playbook matching module (230), which receives specific rule set analysis data, can generate a second threat countermeasure playbook by comparing each element included in the specific rule set analysis data with the lookup table (400). At this time, the rule set-playbook matching module (230) may perform a sub-process of determining at least some of the multiple playbook execution conditions (421 to 424) included in the second threat countermeasure playbook condition candidate group (420) that are predicted to correspond to the specific rule set analysis vector as the second threat countermeasure playbook prediction conditions; (ii) a sub-process of determining at least some of the multiple playbook actions (431 to 434) included in the second threat countermeasure playbook action candidate group (430) that correspond to the specific rule set analysis vector and satisfy the second threat countermeasure playbook conditions as the second threat countermeasure playbook actions; and (iii) a sub-process of determining at least some of the multiple playbook input values ​​(441 to 444) included in the second threat countermeasure playbook input value candidate group that correspond to the specific rule set analysis vector and are required for the execution of the second threat countermeasure playbook action as the second threat countermeasure playbook input values.

[0092] For a specific example, I will proceed with the explanation assuming example specific rule set analysis data that includes a brute-force attack as an example specific threat event prediction type, a Production DB as an example specific threat event prediction target, and an example specific threat event prediction risk determined to be High.

[0093] First, referring to the first row of the lookup table (400) in FIG. 4, it can be seen that the playbook condition (421) corresponding to the first row is listed as (default). The fact that the playbook condition (421) is listed as (default) may mean that if the attack type (410) is a brute-force attack, the playbook action (431) of the corresponding row must be performed unconditionally.

[0094] That is, the rule set-playbook matching module (230) referencing the lookup table (400) disclosed in FIG. 4 can determine that if the example specific threat event prediction type of the example specific rule set analysis data is a brute-force attack, regardless of other conditions, the block_ip playbook action (431) for blocking the IP address of the attacker performing the brute-force attack is included in the second example threat countermeasure playbook corresponding to the example specific rule set analysis data. At this time, event.src_ip in FIG. 4, that is, the IP address of the attacker performing the brute-force attack, corresponds to the playbook input value (441) for performing the playbook action (431) called block_ip.

[0095] Next, in the second row of the lookup table (400), the playbook condition (422) is stated as the target of the threat event being the Production DB. At this time, since the target of the example specific threat event prediction included in the example specific rule set analysis data is also the Production DB, the second example threat countermeasure playbook may include the account locking measure (lock_account), which is a playbook action (432) with the account ID (event.user_id) of the user used in the attack as the playbook input value (442). On the other hand, in the playbook condition (423) of the third row of the lookup table (400), the target of the threat event is stated as the Development Server, and since this is not the target of the example specific threat event prediction, the second example threat countermeasure playbook may not include the development team alert sending (send_alert_to_devteam), which is a playbook action (433) with the development team contact information and the attacker's IP address as the playbook input value (443).

[0096] Meanwhile, the playbook condition included in the playbook condition candidate group (420) may correspond to multiple elements included in the specific rule set analysis data. Referring to the fourth row of the lookup table (400), the playbook condition (424) of the fourth row signifies a case where the target is a Production DB and the risk level is High, which may correspond to the example specific threat event prediction target and example specific threat event prediction risk included in the example specific rule set analysis data. The example second threat countermeasure playbook generated by referencing this example specific rule set analysis data may include a playbook action (434) that isolates the server (isolate_host) by using the host name (event.dstn_hostname) of the server being attacked as the playbook input value (444).

[0097] The example second threat countermeasure playbook determined in this manner is in a state that includes the actions of block_ip, lock_account, and isolate_host, i.e., multiple playbook actions. At this time, the example second threat countermeasure playbook containing multiple playbook actions may further include elements to be additionally referenced while the multiple playbook actions included in the example second threat countermeasure playbook are executed.

[0098] For example, in addition to the lookup table (400) disclosed in FIG. 4, a predetermined playbook action ranking, which is the priority for each of the multiple playbook actions included in the multiple playbook action candidate group, may be determined. Then, the computing device (100) may cause the rule set-playbook matching module (230) to generate a second threat countermeasure playbook by further referring to playbook ranking information, which is the result of sorting at least some of the playbook actions included in the threat countermeasure playbook action candidate group. That is, the order in which the playbook actions named block_ip, lock_account, and isolate_host included in the example second threat countermeasure playbook generated through the example described above are executed may be determined by referring to the playbook ranking information. At this time, the playbook ranking information may be determined in various ways, such as by referring to the strength of the action for each of the multiple playbook actions, or by determining that the one that can be performed quickly on the system operated by the user is executed first.

[0099] Thus, when the rule set-playbook matching module determines either the first threat countermeasure playbook (i.e., a playbook corresponding to specific rule set analysis data among existing recorded playbooks) or the second threat countermeasure playbook (i.e., a playbook generated by the rule set analysis module by referencing the lookup table (400)) as the specific threat countermeasure playbook in step S230, the computing device (100) can provide the specific threat countermeasure playbook to the user terminal (800). At this time, an example of providing the user terminal (800) with a state in which the specific threat detection rule set entered by the user and the specific threat countermeasure playbook provided to the user are linked is provided with reference to FIGS. 5a and 5b.

[0100] FIG. 5a schematically illustrates a rule set-playbook linkage status interface that displays to a user, in a table format, the state in which a specific threat detection rule set corresponding to a specific threat event and a specific threat countermeasure playbook are linked according to one embodiment of the invention, and FIG. 5b schematically illustrates a rule set-playbook linkage status interface that displays to a user, in a graph format, the state in which a specific threat detection rule set corresponding to a specific threat event and a specific threat countermeasure playbook are linked according to one embodiment of the invention.

[0101] Specifically, the computing device (100) can support confirming that a specific threat detection rule set entered by a user (e.g., using the user interface described through FIG. 3) and a specific threat countermeasure playbook determined by the rule set-playbook matching module in step S230 (as described with reference to FIG. 2 and FIG. 4) are linked with each other through a rule set-playbook linkage status interface such as the example shown in FIG. 5a and 5b.

[0102] First, referring to FIG. 5a, the table-format rule set-playbook linkage status interface (500_a) includes a rule set column (510_a) containing a rule set, a playbook column (520_a) containing a linked playbook, a rule set-playbook linkage method column (530_a) displaying the method of linking the rule set and the playbook with an icon, and a reference information column (540_a) displaying information for the user to refer to for review.

[0103] At this time, as shown in the table-format rule set-playbook linkage status interface (500_a) of FIG. 5a, each rule set (511_a, 512_a, 513_a) displayed in the rule set column (510_a) may be represented as natural language text describing a specific threat event corresponding to each rule set, that is, specific threat description data corresponding to each rule set, but is not limited thereto. Additionally, each playbook (521_a, 522_a, 523_a) displayed in the playbook column (520_a) may be represented as text data associated with the type of specific threat event to be dealt with through the playbook, such as "PB-001: Brute Force Response Playbook" (521_a) in the first row, or as text data associated with the method by which the playbook deals with a specific threat event, such as "PB-AI-012: Novel Threat Isolation" (522_a) in the second row.

[0104] Next, as shown in the rule set-playbook linkage method column (530_a) of FIG. 5a, the computing device (100) can display, through an icon, a method in which the rule set and playbook are linked, that is, a method in which the rule set-playbook matching module (230) matches a specific threat detection rule set with a specific threat countermeasure playbook.

[0105] At this time, to briefly mention again the method by which the rule set-playbook matching module (230) of the present invention matches a specific threat detection rule set with a specific threat countermeasure playbook, the rule set-playbook matching module (230) of the present invention determines a specific threat countermeasure playbook that matches the specific threat detection rule set by referencing the first threat countermeasure playbook if there is one or more first threat countermeasure playbooks among the playbooks recorded in the playbook database (600) that have a similarity with the specific threat detection rule set entered by the user that is greater than or equal to a preset rule set-playbook threshold similarity, that is, if there is a playbook corresponding to the specific threat detection rule set among the playbooks previously recorded in the playbook database (700). Here, as a method for the computing device (100) to indicate the specific threat countermeasure playbook determined by referencing the first threat countermeasure playbook, a lightning bolt icon (531_a) in the first row of the rule set-playbook linkage method column (530_a) may be displayed.

[0106] Next, the rule set-playbook matching module (230) can determine a specific threat countermeasure playbook that matches a specific threat detection rule set by creating a second threat countermeasure playbook if the first threat countermeasure playbook does not exist. At this time, as a method of the computing device (100) indicating the specific threat countermeasure playbook determined by referring to the second threat countermeasure playbook, a star-shaped icon (532_a) in the second row of the rule set-playbook linkage method column (530_a) may be displayed.

[0107] Finally, as with conventional technology, the security manager of the system being operated by the user may directly match a specific threat detection rule set with a specific threat countermeasure playbook without using the rule set-playbook matching module (230) of the present invention. As a method of indicating that a person has directly matched a specific threat countermeasure playbook to a specific threat detection rule set, a person-shaped icon (533_a) in the third row of the rule set-playbook linkage method column (530_a) may be displayed.

[0108] Next, referring to FIG. 5b, the computing device (100) can support a user in verifying and reviewing the status of linkage between each specific threat detection rule set and each specific threat countermeasure playbook by displaying a relational node graph in which each of the multiple specific threat detection rule sets and multiple specific threat countermeasure playbooks are nodes and the linked relationship between them is an edge through a graph-format rule set-playbook linkage status interface (500_b).

[0109] At this time, the graph-format rule set-playbook linkage status interface (500_b) illustrated in FIG. 5b displays nodes (511_b, 512_b, 513_b, 514_b) corresponding to a specific threat detection rule set and nodes corresponding to a specific threat countermeasure playbook (521_b, 522_b, 523_b) in different colors, but is not limited thereto. In addition, unlike the icons (531_a, 532_a, 533_a) in the rule set-playbook linkage method column (530_a) of the table-format rule set-playbook linkage status interface (500_a), the method by which the rule set-playbook matching module (230) matches a specific threat detection rule set with a specific threat countermeasure playbook is illustrated as being expressed in text such as “AI Match”, “AI Generation”, and “Manual Designation” (531_b, 532_b, 533_b, 534_b), but is not limited thereto.

[0110] The embodiments according to the present invention described above may be implemented in the form of program instructions that can be executed through various computer components and recorded on a computer-readable recording medium. The computer-readable recording medium may include program instructions, data files, data structures, etc., either alone or in combination. The program instructions recorded on the computer-readable recording medium may be those specifically designed and configured for the present invention, or they may be those known and available to those skilled in the art of computer software. Examples of computer-readable recording media include magnetic media such as hard disks, floppy disks, and magnetic tapes; optical recording media such as CD-ROMs and DVDs; magneto-optical media such as floptical disks; and hardware devices specifically configured to store and execute program instructions, such as ROM, RAM, and flash memory. Examples of program instructions include machine code, such as that generated by a compiler, as well as high-level language code that can be executed by a computer using an interpreter, etc. The hardware device may be configured to operate as one or more software modules to perform processing according to the present invention, and vice versa.

[0111] Although the present invention has been described above with specific details such as specific components, limited embodiments, and drawings, this is provided only to aid in a more comprehensive understanding of the invention, and the invention is not limited to the above embodiments, and a person skilled in the art to which the invention belongs can make various modifications and variations from this description.

[0112] Accordingly, the scope of the present invention should not be limited to the embodiments described above, and all modifications equivalent to or equivalent to the claims set forth below, as well as the claims described below, shall be considered to fall within the scope of the concept of the present invention.

Claims

Claim 1 A method for providing a specific threat countermeasure playbook for responding to a specific threat event, wherein: (a) when a computing device detects that a specific threat detection ruleset corresponding to a condition for detecting a specific threat event has been input from a user terminal corresponding to a user, the computing device inputs the specific threat detection ruleset into a ruleset analysis module, thereby causing the ruleset analysis module to extract each of: (i) specific threat description data including one or more elements for describing the specific threat event; (ii) specific threat query data including one or more elements determined for the purpose of searching for a specific threat log corresponding to the specific threat event in a log database in which logs of a system operated by the user are recorded; and (iii) specific threat detection option data which is data regarding one or more elements to be referenced as a criterion for searching for the specific threat log; and determines a specific threat detection ruleset structure including the specific threat description data, the specific threat query data, and the specific threat detection option data; (b) when the computing device inputs the specific threat detection ruleset structure into a threat detection model, the threat detection model causes at least some of the elements of the specific threat description data, and each of the specific threat query data A method comprising: (c) determining a relationship between each of at least some of the elements and each of at least some of the elements of the specific threat detection option data, and determining specific rule set analysis data by reference; and (c) the computing device inputting the specific rule set analysis data obtained from the threat detection model into a rule set-playbook matching module, thereby causing the rule set-playbook matching module to determine a specific threat countermeasure playbook, which is a response method for the specific threat event corresponding to the specific rule set analysis data, and providing the specific threat countermeasure playbook. Claim 2 In claim 1, prior to step (a), (a01) in a state where each of a plurality of learning threat detection rule sets corresponding to each of a plurality of learning threat events is determined, the computing device inputs each of the plurality of learning threat detection rule sets into the rule set analysis module, thereby causing the rule set analysis module to extract, for each of the plurality of learning threat detection rule sets, (i) learning threat description data including one or more elements for describing the learning threat event, (ii) learning threat query data including one or more elements determined for the purpose of searching for a learning threat log corresponding to the learning threat event in the log database in which the log of the system operated by the user is recorded, and (iii) learning threat detection option data which is data regarding one or more elements to be referenced as a criterion for searching the learning threat log, and determine each of a plurality of learning threat detection rule set structure corresponding to each of the plurality of learning threat events by referencing each of the learning threat description data, each of the learning threat query data, and each of the learning threat detection option data;and (a02) a step further comprising: a step in which the computing device inputs each of the plurality of training threat detection rule set structures into the threat detection model, thereby causing the threat detection model to perform, for each of the plurality of training threat detection rule set structures, (i) a subprocess of predicting each training explanation-query element pair data composed of each element whose association is greater than or equal to a pre-set training explanation-query threshold similarity by evaluating each of the associations between each element included in each of the training threat explanation data and each of the elements included in each of the training threat query data, and (ii) a subprocess of predicting each training explanation-option pair element data composed of each element whose association is greater than or equal to a pre-set training explanation-option threshold similarity by evaluating each of the associations between each of the elements included in each of the training threat explanation data and each of the elements included in each of the training threat detection option data, and training the threat detection model by reference to each of the training explanation-query element pair data and each of the explanation-option element pair data; Claim 3 In paragraph 2, in step (a01), the computing device further acquires each of a plurality of GT threat classification data comprising at least a portion of each GT threat event type which is the correct answer type for each of the plurality of learning threat events, each GT threat event target which is the correct answer target attacked in each of the plurality of learning threat events, each GT threat event risk which is the correct answer result of evaluating the risk of each of the plurality of learning threat events, and each GT threat event framework data which is the correct answer framework data for classifying each of the plurality of learning threat events; and in step (a02), (a021) the computing device causes the threat detection model to, by reference to each element included in the learning description-query element pair data and each element included in the learning description-option element pair data for each of the plurality of learning threat detection rule set structures, each of a plurality of learning threat event prediction type which is the result of predicting the type of each of the plurality of learning threat events for each of the plurality of learning threat detection rule set structures, each of a plurality of learning threat event prediction target which is the result of predicting the target attacked in each of the plurality of learning threat events, and each of the plurality of learning threat events A step of outputting each of a plurality of learning threat event prediction risks, which are the results of predicting risks, and each of a plurality of learning threat event prediction framework data, which are the results of predicting framework data for classifying each of the plurality of learning threat events;and (a022) the computing device causes the threat detection model to calculate each event type loss, which is a loss between each of the training threat event prediction types and each of the GT threat event types corresponding to each of the plurality of training threat detection rule set structures; each event target loss, which is a loss between each of the training threat event prediction targets and each of the GT threat event targets; each risk loss, which is a loss between each of the training threat event prediction risks and each of the GT threat event risks; and each framework data loss, which is a loss between each of the training threat event prediction framework data and each of the GT threat event framework data; and the threat detection model is trained by reference to at least some of the event type loss, the event target loss, the risk loss, and the framework data loss; a method comprising; Claim 4 In claim 1, in step (b), the computing device performs a subprocess of: (b1) causing the threat detection model, which detects that the specific threat detection rule set structure has been input, to: (i) predict specific description-query element pair data composed of each element whose association is greater than or equal to a pre-established specific description-query threshold similarity by evaluating each association between at least some elements of the specific threat description data and at least some elements of the specific threat query data; and (ii) predict specific description-option element pair data composed of each element whose association is greater than or equal to a pre-established specific description-option similarity by evaluating each association between at least some elements of the specific threat description data and at least some elements of the specific threat detection option data; and (b2) the computing device causes the threat detection model to output a specific threat event prediction type, which is the result of predicting the type of the specific threat event by referring to each of the specific description-query element pair data and the specific description-option element pair data, a specific threat event prediction target, which is the result of predicting the target to be attacked in the specific threat event, a specific threat event prediction risk, which is the result of predicting the risk of the specific threat event, and a specific threat event prediction framework data, which is the result of predicting the framework data for classifying the specific threat event, and further comprises the step of determining the specific rule set analysis data by referring to at least some of the specific threat event prediction type, the specific threat event prediction target, the specific threat event prediction risk, and the specific threat event prediction framework data. Claim 5 In claim 4, in step (c) above, (c1) the computing device causes the rule set-playbook matching module, which detects that the specific rule set analysis data has been input, to generate at least some of a specific threat event type vector, a specific threat event target vector, a specific threat event risk vector, and a specific threat event framework vector by embedding each of at least some of the specific threat event prediction type, the specific threat event prediction target, the specific threat event prediction risk, and the specific threat event prediction framework data included in the specific rule set analysis data, and to determine a specific rule set analysis vector corresponding to the specific rule set analysis data by referencing each of the specific threat event type vector, the specific threat event target vector, the specific threat event risk vector, and the specific threat event framework vector;and (c2) with each of the multiple threat countermeasure playbook candidate vectors, which are the results of embedding each of the multiple threat countermeasure playbook candidates determined as countermeasures for each of the multiple threat event candidates, recorded in the playbook database, the computing device causes the rule set-playbook matching module to evaluate each of the similarity between each of at least some of the multiple threat countermeasure playbook candidate vectors and the specific rule set analysis vector, and (i) when detecting that there is one or more first threat countermeasure playbooks which are at least some of the multiple threat countermeasure playbook candidates corresponding to at least some of the multiple threat countermeasure playbook candidate vectors where the similarity between the specific rule set analysis vector and the first threat countermeasure playbook is greater than or equal to a preset rule set-playbook threshold similarity, the subprocess of determining the specific threat countermeasure playbook by reference to the first threat countermeasure playbook; and (ii) when detecting that the first threat countermeasure playbook does not exist, the subprocess of generating a second threat countermeasure playbook corresponding to the specific threat event by reference to the specific rule set analysis vector and determining the specific threat countermeasure playbook by reference to the second threat countermeasure playbook. A method further comprising a step of performing any one of the subprocesses.; Claim 6 In claim 5, in (ii) of step (c2) above, with each of the following recorded: a second threat countermeasure playbook action candidate group comprising a plurality of playbook actions, each of which is an action executed through the second threat countermeasure playbook for each type of threat event included in each of the plurality of threat event candidates; a second threat countermeasure playbook condition candidate group comprising a plurality of playbook execution conditions, each of which is a condition for each of the plurality of playbook actions to be executed; and a second threat countermeasure playbook input value candidate group comprising a plurality of playbook input values ​​corresponding to each of the values ​​required for the execution of each of the plurality of playbook execution actions, the computing device causes the rule set-playbook matching module to determine as a second threat countermeasure playbook prediction condition at least some of the plurality of playbook execution conditions included in the second threat countermeasure playbook condition candidate group that are predicted to correspond to the specific rule set analysis vector; and (ii) at least some of the plurality of playbook actions included in the second threat countermeasure playbook action candidate group that correspond to the specific rule set analysis vector and satisfy the second threat countermeasure playbook condition, the second threat countermeasure playbook A method comprising: (iii) performing a subprocess to determine as an action; (iii) performing a subprocess to determine as a second threat countermeasure playbook input value at least a portion of the plurality of playbook input values ​​included in the second threat countermeasure playbook input value candidate group that correspond to the specific rule set analysis vector and are required for the execution of the second threat countermeasure playbook action; and generating the second threat countermeasure playbook corresponding to the specific rule set analysis data by referring to each of the second threat countermeasure playbook action, the second threat countermeasure playbook condition, and the second threat countermeasure playbook input value. Claim 7 A method according to claim 6, wherein, in a state where a predetermined playbook action priority is determined as a priority for each of the plurality of playbook actions included in the second threat countermeasure playbook action candidate group, the computing device causes the rule set-playbook matching module to generate the second threat countermeasure playbook by further referring to second threat countermeasure playbook ranking information, which is the result of arranging at least some of the plurality of playbook actions included in the second threat countermeasure playbook action according to the playbook action priority. Claim 8 A method according to claim 5, wherein, in step (b2), the computing device causes the rule set-playbook matching module to generate the specific rule set analysis vector through a weighted sum of the specific threat event type vector, the specific threat event target vector, the specific threat event risk vector, and the specific threat event framework vector. Claim 9 A method according to claim 1, wherein, in step (a), the computing device supports the user in inputting the specific threat description data, the specific threat query data, and the specific threat detection option data included in the specific rule set analysis data by displaying a rule set input interface on the screen of the user terminal. Claim 10 A method according to claim 1, wherein in step (c), the computing device displays a rule set-playbook linkage status interface on the screen of the user terminal, thereby enabling the user to confirm that the specific threat detection rule set entered by the user and the specific threat countermeasure playbook determined by the rule set-playbook matching module are linked to each other, and to enable the user to review the linked specific threat countermeasure playbook and the specific threat detection rule set. Claim 11 A computing device for providing a specific threat countermeasure playbook for responding to a specific threat event comprises: at least one memory for storing instructions; and at least one processor configured to execute said instructions; wherein the processor comprises: (I) a process in which, upon detecting that a specific threat detection ruleset corresponding to a condition for detecting a specific threat event is input from a user terminal corresponding to a user, the specific threat detection ruleset is input to a ruleset analysis module, thereby causing the ruleset analysis module to extract each of: (i) specific threat description data including one or more elements for describing said specific threat event; (ii) specific threat query data including one or more elements determined for the purpose of searching for a specific threat log corresponding to said specific threat event in a log database in which logs of a system operated by said user are recorded; and (iii) specific threat detection option data which is data regarding one or more elements to be referenced as a criterion for searching said specific threat log, and a specific threat detection ruleset structure including said specific threat description data, said specific threat query data, and said specific threat detection option data. (II) A process of inputting the above-mentioned specific threat detection rule set structure into a threat detection model, thereby causing the threat detection model to determine the association between at least some of the elements of the specific threat description data, at least some of the elements of the specific threat query data, and at least some of the elements of the specific threat detection option data, and to determine the specific rule set analysis data by reference thereof;and (III) a process of inputting the specific rule set analysis data obtained from the threat detection model into the rule set-playbook matching module, thereby causing the rule set-playbook matching module to determine a specific threat countermeasure playbook, which is a response method for the specific threat event corresponding to the specific rule set analysis data, and providing the specific threat countermeasure playbook; a computing device that performs the process. Claim 12 In claim 11, prior to the above process (I), the processor inputs each of the plurality of learning threat detection rule sets corresponding to each of the plurality of learning threat events into the rule set analysis module while (I01) each of the plurality of learning threat detection rule sets corresponding to each of the plurality of learning threat events is determined, thereby causing the rule set analysis module to extract, for each of the plurality of learning threat detection rule sets, (i) learning threat description data including one or more elements for describing the learning threat event, (ii) learning threat query data including one or more elements determined for the purpose of searching for a learning threat log corresponding to the learning threat event in the log database in which the log of the system operated by the user is recorded, and (iii) learning threat detection option data which is data regarding one or more elements to be referenced as a criterion for searching the learning threat log, and determines each of the plurality of learning threat detection rule set structures corresponding to each of the plurality of learning threat events by referencing each of the learning threat description data, each of the learning threat query data, and each of the learning threat detection option data;and (I02) a process of further performing the following steps by inputting each of the plurality of training threat detection rule set structures into the threat detection model, thereby causing the threat detection model to perform, for each of the plurality of training threat detection rule set structures, (i) a sub-process of predicting each training explanation-query element pair data composed of each element whose association is greater than or equal to a pre-set training explanation-query threshold similarity by evaluating each of the associations between each element included in each of the training threat explanation data and each of the elements included in each of the training threat query data, and (ii) a sub-process of predicting each training explanation-option element pair data composed of each element whose association is greater than or equal to a pre-set training explanation-option threshold similarity by evaluating each of the associations between each of the elements included in each of the training threat explanation data and each of the elements included in each of the training threat detection option data, and training the threat detection model by reference to each of the training explanation-query element pair data and each of the explanation-option element pair data; a computing device. Claim 13 In claim 12, in the above process (I01), the processor further acquires each of a plurality of GT threat classification data comprising at least a portion of each GT threat event type which is the correct answer type for each of the plurality of learning threat events, each GT threat event target which is the correct answer target attacked in each of the plurality of learning threat events, each GT threat event risk which is the correct answer result of evaluating the risk of each of the plurality of learning threat events, and each GT threat event framework data which is the correct answer framework data for classifying each of the plurality of learning threat events; and in the above process (I02), the processor causes the threat detection model to (I021) refer to each element included in the learning description-query element pair data and each element included in the learning description-option element pair data for each of the plurality of learning threat detection rule set structures, and for each of the plurality of learning threat detection rule set structures, each of a plurality of learning threat event prediction types which is the result of predicting the type of each of the plurality of learning threat events, each of a plurality of learning threat event prediction targets which is the result of predicting the target attacked in each of the plurality of learning threat events, and the plurality of learning threats A process for outputting each learning threat event prediction risk, which is the result of predicting the risk of each event, and each learning threat event prediction framework data, which is the result of predicting framework data for classifying each of the plurality of learning threat events;and (I022) a process of causing the threat detection model to calculate, for each event type loss which is a loss between each of the learning threat event prediction types corresponding to each of the plurality of learning threat detection rule set structures and each of the GT threat event types, for each event target loss which is a loss between each of the learning threat event prediction targets and each of the GT threat event targets, for each risk loss which is a loss between each of the learning threat event prediction risks and each of the GT threat event risks, and for each framework data loss which is a loss between each of the learning threat event prediction framework data and each of the GT threat event framework data, and to train the threat detection model by reference to at least some of the event type loss, the event target loss, the risk loss, and the framework data loss; a computing device. Claim 14 In claim 11, in the above process (II), the processor performs a process in which the threat detection model, having detected that the specific threat detection rule set structure has been input, (II1) performs a subprocess of (i) predicting specific description-query element pair data composed of each element whose association is greater than or equal to a pre-established specific description-query threshold similarity by evaluating each association between at least some elements of the specific threat description data and at least some elements of the specific threat query data, and (ii) performs a subprocess of (ii) predicting specific description-option element pair data composed of each element whose association is greater than or equal to a pre-established specific description-option threshold similarity by evaluating each association between at least some elements of the specific threat description data and at least some elements of the specific threat detection option data; and (II2) a process in which the processor causes the threat detection model to output a specific threat event prediction type, which is the result of predicting the type of the specific threat event by referring to each of the specific description-query element pair data and the specific description-option element pair data, a specific threat event prediction target, which is the result of predicting the target to be attacked in the specific threat event, a specific threat event prediction risk, which is the result of predicting the risk of the specific threat event, and a specific threat event prediction framework data, which is the result of predicting the framework data for classifying the specific threat event, and determines the specific rule set analysis data by referring to at least some of the specific threat event prediction type, the specific threat event prediction target, the specific threat event prediction risk, and the specific threat event prediction framework data; further performing a computing device. Claim 15 In claim 14, in the above process (III), the processor causes the rule set-playbook matching module, which detects that the specific rule set analysis data has been input (III1), to generate at least some of a specific threat event type vector, a specific threat event target vector, a specific threat event risk vector, and a specific threat event framework vector by embedding each of at least some of the specific threat event prediction type, the specific threat event prediction target, the specific threat event prediction risk, and the specific threat event prediction framework data included in the specific rule set analysis data, and to determine a specific rule set analysis vector corresponding to the specific rule set analysis data by reference to each of the specific threat event type vector, the specific threat event target vector, the specific threat event risk vector, and the specific threat event framework vector;and (III2) in a state where each of the multiple threat countermeasure playbook candidate vectors, which are the results of embedding each of the multiple threat countermeasure playbook candidates determined as countermeasures for each of the multiple threat event candidates, is recorded in the playbook database, the rule set-playbook matching module evaluates each of the similarity between each of at least some of the multiple threat countermeasure playbook candidate vectors and the specific rule set analysis vector, and (i) when it is detected that there is one or more first threat countermeasure playbooks which are at least some of the multiple threat countermeasure playbook candidates corresponding to at least some of the multiple threat countermeasure playbook candidate vectors where the similarity between the specific rule set analysis vector and the first threat countermeasure playbook candidate vector is greater than or equal to a preset rule set-playbook threshold similarity, the subprocess determines the specific threat countermeasure playbook by reference to the first threat countermeasure playbook, and (ii) when it is detected that the first threat countermeasure playbook candidate does not exist, generates a second threat countermeasure playbook corresponding to the specific threat event by reference to the specific rule set analysis vector, and determines the specific threat countermeasure playbook by reference to the second threat countermeasure playbook, among A computing device that further performs a process of performing one of the following: Claim 16 In paragraph 15, in (ii) of the above (III2) process, with each of the following recorded: a second threat countermeasure playbook action candidate group comprising a plurality of playbook actions, each of which is an action executed through the second threat countermeasure playbook for each type of threat event included in each of the plurality of threat event candidates; a second threat countermeasure playbook condition candidate group comprising a plurality of playbook execution conditions, each of which is a condition for each of the plurality of playbook actions to be executed; and a second threat countermeasure playbook input value candidate group comprising a plurality of playbook input values ​​corresponding to each of the values ​​required for the execution of each of the plurality of playbook execution actions, the processor causes the rule set-playbook matching module to: (i) determine as a second threat countermeasure playbook prediction condition at least some of the plurality of playbook execution conditions included in the second threat countermeasure playbook condition candidate group that are predicted to correspond to the specific rule set analysis vector; and (ii) at least some of the plurality of playbook actions included in the second threat countermeasure playbook action candidate group that correspond to the specific rule set analysis vector and satisfy the second threat countermeasure playbook condition, the second threat countermeasure playbook A computing device performing a subprocess that determines as an action; (iii) a subprocess that determines as a second threat countermeasure playbook input value at least a portion of the plurality of playbook input values ​​included in the second threat countermeasure playbook condition candidate group that corresponds to the specific rule set analysis vector and is required for the execution of the second threat countermeasure playbook action; and (iv) a subprocess that generates the second threat countermeasure playbook corresponding to the specific rule set analysis data by referring to each of the second threat countermeasure playbook action, the second threat countermeasure playbook condition, and the second threat countermeasure playbook input value. Claim 17 A computing device according to claim 16, wherein, in a state where a predetermined playbook action priority is determined as a priority for each of the plurality of playbook actions included in the second threat countermeasure playbook action candidate group, the processor causes the rule set-playbook matching module to generate the second threat countermeasure playbook by further referring to second threat countermeasure playbook ranking information, which is the result of arranging at least some of the plurality of playbook actions included in the second threat countermeasure playbook action according to the playbook action priority. Claim 18 A computing device according to claim 15, wherein in the above (II2) process, the processor causes the rule set-playbook matching module to generate the specific rule set analysis vector through a weighted sum of the specific threat event type vector, the specific threat event target vector, the specific threat event risk vector, and the specific threat event framework vector. Claim 19 A computing device according to claim 11, wherein in the above process (I), the processor supports the user in inputting the specific threat description data, the specific threat query data, and the specific threat detection option data included in the specific rule set analysis data by displaying a rule set input interface on the screen of the user terminal. Claim 20 A computing device according to claim 11, wherein in the above process (III), the processor supports the user in confirming that the specific threat detection rule set entered by the user and the specific threat countermeasure playbook determined by the rule set-playbook matching module are linked with each other by displaying a rule set-playbook linkage status interface on the screen of the user terminal, and supports the user in reviewing the linked specific threat countermeasure playbook and the specific threat detection rule set.