Device and method for detecting cryptographic threat in network and blocking malicious attached file
The described computing device addresses the challenge of detecting and blocking malicious attachments in encrypted network traffic by using a combination of packet classification, neural networks, and encryption proxies, achieving effective cybersecurity without complex decryption processes.
Patent Information
- Application Number
- PCT/KR2023/017283
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-10-31
- Filing Date
- 2023-11-01
- Publication Date
- 2025-05-08
AI Technical Summary
Existing cybersecurity systems struggle to detect and block malicious attachments within encrypted network traffic, as they often require decryption, which can lead to packet loss and detection failures.
A computing device with a packet classification unit, threat information and policy management unit, threat detection unit, encryption proxy, attachment storage unit, and lightweight malignant detection unit, which classifies packets, extracts fingerprint and meta characteristics, and uses neural networks to detect password threats and block malicious attachments without decrypting all packets.
Enables prompt detection and blocking of malicious attachments in network traffic, even when encrypted, without the need for complex decryption processes, thereby enhancing cybersecurity without significant resource investment.
Smart Images

Figure KR2023017283_08052025_PF_FP_ABST
Abstract
Description
Device and method for detecting network cryptographic threats and blocking malicious attachments
[0001] The present disclosure relates to a device and method for detecting a cryptographic threat in a network and blocking malicious attachments, and more particularly, to a device and method for detecting a cryptographic threat and blocking malicious attachments without decryption.
[0002] Malware and ransomware attacks are rapidly mutating and, combined with APTs, pose a serious and persistent threat to society. Malicious ransomware variants have evolved, including Magniber in 2019, Ryuk, Crop, Revil, and Maze in 2021, and Darkside in 2022. Following attacks on social supply chain facilities in 2021, attacks on social infrastructure in the US, the UK, and Australia have also steadily expanded and increased in 2022.
[0003] Intrusion prevention systems and AI-based malware detection technologies being developed to block this cannot recognize payloads within encrypted packets, so separate visibility technology and equipment are required to decrypt SSL-encrypted packets.
[0004] However, this technology generates a large number of packets in real time during the decryption process, making it impossible to decrypt all packets, resulting in packet loss. Furthermore, if decryption fails, infrastructure such as security technologies operating in the backend cannot be properly detected.
[0005] The present disclosure has been devised in response to the aforementioned background technology, and in a situation where most of the Internet traffic is converted to use encryption protocols (SSL / TLS, etc.), making it difficult to detect cybersecurity threats such as malicious codes contained in encrypted traffic, the present disclosure relates to a device and method for quickly detecting encryption threats without separate decryption, and for detecting and blocking malicious attachments contained in packets classified as encryption threats in advance.
[0006] The technical problems of the present disclosure are not limited to the technical problems mentioned above, and other technical problems not mentioned will be clearly understood by those skilled in the art from the description below.
[0007] According to one embodiment of the present disclosure for solving the above-described problem, a computing device is disclosed, which includes at least one processor. The computing device includes: a packet classification unit that determines a first packet corresponding to a predefined secure channel using a protocol included in a network traffic packet flowing into the computing device; a threat information and policy management unit that receives a request from the packet classification unit to determine whether the first packet corresponds to a predefined malicious packet; a packet storage and feature extraction unit that receives the first packet from the packet classification unit and extracts fingerprint characteristics and meta characteristics of the received first packet when the first packet does not correspond to the malicious packet; a threat detection unit that determines whether the first packet is a cryptographic threat by inputting the extracted fingerprint characteristics and meta characteristics into a first artificial neural network that has been trained in advance; an encryption proxy unit that performs cryptographic authentication to extract a file attached as a payload from the first packet when it is determined that a cryptographic threat exists in the first packet; an attachment storage unit that extracts and stores an attachment included in the payload from the first packet; and a lightweight malware detection unit for determining whether the stored attached file is malicious.
[0008] Additionally, the fingerprint characteristic may include at least one of an encrypted channel protocol, an encrypted channel certificate, a source address, a destination address, port information, and header information extracted from a non-encrypted area of the network traffic or extracted in an encrypted state.
[0009] Additionally, the meta characteristics may include at least one of the total network arrival time of the packet, network latency, transmission and reception pattern of network traffic including the packet, bit per second (BPS), packet per second (PPS), connection time between packets, number of sessions per unit time, number of users per unit time, and target hit estimation of the packet.
[0010] In addition, the packet storage and characteristic extraction unit may determine whether at least one pre-stored second packet related to the first packet exists based on the extracted fingerprint characteristic and the meta characteristic, and if it is determined that the at least one second packet does not exist, store the first packet, the fingerprint characteristic, and the meta characteristic in packet characteristics within the first session related to the first packet.
[0011] Additionally, the threat information and policy management unit may configure the non-detection information indicating that at least one second packet was not detected using a threat information sharing (Cyber Threat Intelligence, CTI) protocol.
[0012] In addition, the lightweight malware detection unit can determine whether the attached file is malicious based on the output value of the second artificial neural network by inputting the attached file into a second artificial neural network trained using static and dynamic characteristics extracted from a plurality of previously detected malicious codes.
[0013] In addition, a method for detecting a network cryptographic threat and blocking a malicious attachment performed by a computing device including at least one processor may include the steps of: determining a first packet corresponding to a predefined secure channel using a protocol included in a network traffic packet flowing into the computing device; determining whether the first packet corresponds to a predefined malicious packet; extracting a fingerprint characteristic and a meta characteristic of the first packet when the first packet does not correspond to the malicious packet; determining whether the first packet is a cryptographic threat by inputting the extracted fingerprint characteristic and the meta characteristic into a first artificial neural network that has been trained in advance; performing cryptographic authentication to extract a file attached as a payload from the first packet when it is determined that a cryptographic threat exists; extracting and storing an attachment included in the payload from the first packet; and determining whether the stored attachment is malicious.
[0014] Additionally, the fingerprint characteristic may include at least one of an encrypted channel protocol, an encrypted channel certificate, a source address, a destination address, port information, and header information extracted from a non-encrypted area of the network traffic or extracted in an encrypted state.
[0015] Additionally, the meta characteristics may include at least one of the total network arrival time of the packet, network latency, transmission and reception pattern of network traffic including the packet, bit per second (BPS), packet per second (PPS), connection time between packets, number of sessions per unit time, number of users per unit time, and target hit estimation of the packet.
[0016] In addition, the step of determining a first packet corresponding to a predefined secure channel using a protocol included in a network traffic packet flowing into the computing device may further include the step of determining whether at least one pre-stored second packet related to the first packet exists based on the extracted fingerprint characteristic and the meta characteristic; and, if it is determined that the at least one second packet does not exist, the step of storing the first packet, the fingerprint characteristic, and the meta characteristic in a packet characteristic within a first session related to the first packet.
[0017] Additionally, the undetected information that at least one second packet was undetected may be configured as a Cyber Threat Intelligence (CTI) protocol.
[0018] In addition, the step of determining whether the stored attached file is malicious may include a step of determining whether the attached file is malicious based on an output value of the second artificial neural network by inputting the attached file into a second artificial neural network trained using static and dynamic characteristics extracted from a plurality of previously detected malicious codes.
[0019] The technical solutions obtainable in the present disclosure are not limited to the solutions mentioned above, and other solutions not mentioned will be clearly understood by a person having ordinary skill in the art to which the present disclosure pertains from the description below.
[0020] According to some embodiments of the present disclosure, a device and method are provided that enable rapid detection of malware, ransomware, and various variants of malware distributed in encrypted traffic on a secure channel, which is increasing explosively, without complex configuration of resources and infrastructure resources for decrypting packets in the traffic.
[0021] The present invention can supplement the vulnerable security environment of small and medium-sized enterprises, small business owners, and individual users who are exposed to the majority of malware damage, including ransomware, and can provide the effect of detecting and blocking malware in advance at the network level without large financial investment.
[0022] Additionally, in the configuration of a security model that integrates new technologies such as EDR and NDR, the scope and targets to be detected and blocked can be quickly identified and reduced in advance, enabling a more accurate and selective focus of resources to enable a more powerful response.
[0023] Furthermore, in the domestic firewall and network market worth approximately KRW 200 billion, new innovations in the firewall and UTM markets, which are key security measures for small and medium-sized businesses, can significantly contribute to cost reduction and expansion of the base for new technologies.
[0024] The effects that can be obtained from the present disclosure are not limited to the effects mentioned above, and other effects that are not mentioned will be clearly understood by a person having ordinary skill in the art to which the present disclosure pertains from the description below.
[0025] Various aspects are now described with reference to the drawings, wherein like reference numerals are used to refer to similar elements generally. In the following examples, for purposes of explanation, numerous specific details are set forth to provide a thorough understanding of one or more aspects. However, it will be apparent that such aspects may be practiced without these specific details. In other instances, well-known structures and devices are shown in block diagram form to facilitate the description of one or more aspects.
[0026] FIG. 1 illustrates an exemplary system for performing a method for detecting cryptographic threats in a network and blocking malicious attachments, according to some embodiments of the present disclosure.
[0027] FIG. 2 is a diagram illustrating an example of fingerprint characteristics and meta characteristics according to some embodiments of the present disclosure.
[0028] FIG. 3 is a flowchart illustrating an example of a method for a computing device to detect a network cryptographic threat and block a malicious attachment according to some embodiments of the present disclosure.
[0029] FIG. 4 is a flowchart illustrating an example of a method by which a packet storage and feature extraction unit determines whether at least one second packet related to a first packet exists, according to some embodiments of the present disclosure.
[0030] FIG. 5 is a diagram illustrating an example of a method for generating meta characteristics by a packet storage and feature extraction unit according to some embodiments of the present disclosure.
[0031] FIG. 6 is a flowchart illustrating an example of a computing device interworking with an endpoint terminal device according to some embodiments of the present disclosure.
[0032] FIG. 7 is a flowchart illustrating an example of a computing device interworking with cloud equipment according to some embodiments of the present disclosure.
[0033] FIG. 8 is a flowchart illustrating an example of a method for a computing device to detect a cryptographic threat in a network according to some embodiments of the present disclosure.
[0034] FIG. 9 is a flowchart illustrating an example of a method for a computing device to block malicious attachments according to some embodiments of the present disclosure.
[0035] The present invention is susceptible to various modifications and embodiments. Specific embodiments are illustrated in the drawings and described in detail in the detailed description. However, this is not intended to limit the present invention to specific embodiments, but rather to encompass all modifications, equivalents, and alternatives falling within the spirit and technical scope of the present invention. Throughout the description of each drawing, similar reference numerals have been used to designate similar components.
[0036] Terms such as "first," "second," "A," and "B" may be used to describe various components, but the components should not be limited by these terms. These terms are used solely to distinguish one component from another. For example, without departing from the scope of the present invention, the first component may be referred to as the "second component," and similarly, the second component may also be referred to as the "first component." The term "and / or" includes a combination of a plurality of related items described herein or any of a plurality of related items described herein.
[0037] When a component is referred to as being "connected" or "connected" to another component, it should be understood that it may be directly connected or connected to that other component, but that there may be other components intervening. Conversely, when a component is referred to as being "directly connected" or "connected" to another component, it should be understood that there are no other components intervening.
[0038] The terminology used in this application is only used to describe specific embodiments and is not intended to limit the present invention. The singular expression includes the plural expression unless the context clearly indicates otherwise. In this application, it should be understood that the terms "comprise" or "have" indicate the presence of a feature, number, step, operation, component, part, or combination thereof described in the specification, but do not exclude in advance the possibility of the presence or addition of one or more other features, numbers, steps, operations, components, parts, or combinations thereof.
[0039] Unless otherwise defined, all terms used herein, including technical or scientific terms, have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. Terms defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the relevant technology, and will not be interpreted in an idealized or overly formal sense unless explicitly defined herein.
[0040] In the present disclosure, a computing device can determine a packet using a protocol included in network traffic. The computing device can determine whether the determined packet corresponds to a predefined malicious packet. If the determined packet corresponds to a predefined malicious packet, the computing device can block the determined packet. However, as described above, malicious packets are constantly increasing in real time. Accordingly, it may be difficult for the computing device to predefine all malicious packets. Therefore, the computing device according to the present disclosure can perform inspection on the determined packet even if the packet does not correspond to a predefined malicious packet. Hereinafter, a method for a computing device to detect a network cryptographic threat and block a malicious attachment will be described with reference to FIGS. 1 to 9.
[0041] FIG. 1 illustrates an exemplary system for performing a method for detecting cryptographic threats in a network and blocking malicious attachments, according to some embodiments of the present disclosure.
[0042] Referring to FIG. 1, the computing device may include at least one processor (100).
[0043] A computing device may include any type of computer system or computer device, such as, for example, a microprocessor, a mainframe computer, a digital processor, a handheld device, or a device controller.
[0044] A computing device may utilize a combination of typical computer hardware (e.g., devices that may include a computer processor, memory, storage, input and output devices, and other components of a conventional computing device; electronic communication devices such as routers, switches, and the like; electronic information storage systems such as network-attached storage (NAS) and storage area networks (SAN)) and computer software (i.e., instructions that cause the computing device to function in a particular manner) to achieve desired system performance.
[0045] The processor (100) can typically handle the overall operation of a computing device. The processor (100) can process signals, data, information, etc. input or output through components of the computing device, or run application programs stored in a storage unit, thereby providing or processing appropriate information or functions to the user.
[0046] The processor (100) may be composed of one or more cores and may include a processor for data analysis, such as a central processing unit (CPU), a general purpose graphics processing unit (GPGPU), or a tensor processing unit (TPU).
[0047] In the present disclosure, the processor (100) may include a packet classification unit (110), a threat information and policy management unit (130), a packet storage and feature extraction unit (120), a threat detection unit (140), an encryption proxy unit (150), an attachment storage unit (160), and a lightweight malware detection unit (170). However, the above-described components are not essential for implementing the processor (100), and thus the processor (100) may have more or fewer components than the components listed above.
[0048] The packet classification unit (110) can determine a first packet corresponding to a predefined secure channel using a protocol included in a network traffic packet flowing into a computing device. The secure channel may be a channel utilizing the Secure Socket Layer (SSL) and Transport Layer Security (TLS) protocols. The secure channel may be a channel that provides secure private communication through ID authentication and encryption. A packet is a unit of network transmission capacity and may be a formatted block of data.
[0049] Specifically, network traffic may be introduced into the computing device from a network (200) such as the Internet, a LAN environment, a virtual network, or an external network. The packet classification unit (110) may classify packet traffic based on an encryption protocol according to the protocol of the packet for the introduced network traffic, thereby determining the first packet corresponding to a predefined secure channel.
[0050] According to one embodiment, the packet classification unit (110) can perform filtering on packets determined to contain a threat.
[0051] The threat information and policy management unit (130) may be requested by the packet classification unit (110) to determine whether the first packet corresponds to a predefined malicious packet. If the first packet corresponds to a predefined malicious packet, the threat information and policy management unit (130) may transmit a signal to the packet classification unit (110) to block the first packet.
[0052] The threat information and policy management unit (130) can store threat information and manage policies related to the threat information. The threat information and policy management unit (130) can share learning information and characteristics in a data format such as a Cyber Threat Intelligence (CTI) protocol such as Structured Threat Information eXpression (STIX) and JSON. The threat information and policy management unit (130) can share learning information and characteristics on different traffic with threat information detection modules existing in other networks, including the cloud.
[0053] The packet storage and feature extraction unit (120) can receive the first packet from the packet classification unit if the first packet does not correspond to a malicious packet that has been judged to be present even once.
[0054]
[0055] The packet storage and feature extraction unit (120) can store packets of incoming network traffic by session. The packet storage and feature extraction unit (120) can extract fingerprint characteristics and meta characteristics of the first received packet.
[0056] Fingerprint characteristics may be extracted from unencrypted areas of network traffic or extracted in an encrypted state. The packet storage and characteristic extraction unit (120) can extract fingerprint characteristics without a decryption process by extracting fingerprint characteristics from unencrypted areas of network traffic.
[0057] The fingerprint characteristics may include at least one of an encrypted channel protocol, an encrypted channel certificate, a source address, a destination address, port information, and header information. For convenience of explanation, reference may be made to FIG. 2.
[0058] FIG. 2 is a diagram illustrating an example of fingerprint characteristics and meta characteristics according to some embodiments of the present disclosure.
[0059] Referring to Figure 2, information about fingerprint characteristics and meta characteristics can be confirmed. For example, SSL / TLS Cipher suite can refer to an encrypted channel protocol (algorithm). Certificates can refer to an encrypted channel certificate. IP / Port (SRC, DST) can refer to information such as the source address, destination address, and port. Other header information, such as Client Hello and agent info, can refer to primary information included in the header.
[0060] The meta characteristics may include at least one of the total network arrival time of the packet, network latency, transmission and reception pattern of network traffic including the packet, bits per second (BPS), packets per second (PPS), connection time between packets, number of sessions per unit time, number of users per unit time, and target hit estimation of the packet.
[0061] For example, RTT may represent packet arrival time, and Latency may represent network delay. Pattern may represent a transmission and reception pattern. BPS may represent bits per second, and PPS may represent packets per second. CPS may represent the connection time between packets, and SPS may represent the number of sessions per unit time. UPS may represent the number of users per unit time, and HPS may represent the estimated target hit of a packet. In addition, connection metadata may include tran_client / server_rtt *_xx, tran_rsp_time, used_time, session_xxx, final_used_time, xxx_ups, xxx_cps, etc.
[0062] A meta-characteristic may be a characteristic that combines the characteristics of the time of packets included in a session and the characteristics that appear in the connection process of each packet. The packet storage and characteristic extraction unit (120) can generate a meta-characteristic for network traffic by tracking the amount of change over time of at least one parameter included in the first packet using the first packet and a plurality of fingerprint characteristics. In other words, the packet storage and characteristic extraction unit (120) can search for preceding packets within the same session or traffic to generate a high-dimensional meta-characteristic for the first packet transmitted from the packet classification unit (110). Hereinafter, an example of a method for determining a meta-characteristic by the packet storage and characteristic extraction unit (120) will be described with reference to FIG. 5.
[0063] Referring back to FIG. 1, the threat detection unit (140) can determine whether the first packet is a cryptographic threat by inputting fingerprint characteristics and meta characteristics into a pre-learned first artificial neural network.
[0064] The threat detection unit (140) can select groups for fingerprint characteristics and meta characteristics through a first artificial neural network including a large-capacity data classification model. The threat detection unit (140) can normalize the fingerprint characteristics and meta characteristics through a preprocessing process. The threat detection unit (140) can determine whether the corresponding characteristics are malicious traffic through a first artificial neural network trained with an ensemble of RNN (Recurrent Neural Network), LSTM (Long Short Time Memory), and CNN (Convolutional Neural Network) series.
[0065] According to one embodiment, the threat detection unit (140) can transmit the judgment result to the threat information and policy management unit (130). The threat detection unit (140) can transmit the judgment result synchronously according to the real-time (inline) configuration of the packet or asynchronously according to the mirroring configuration.
[0066] According to one embodiment, the threat detection unit (140) may transmit the judgment result to the packet classification unit (110). Based on the judgment result, the packet classification unit (110) may block or not block the first packet.
[0067] If the encryption proxy unit (150) determines that a cryptographic threat exists in the first packet, it can perform cryptographic authentication to extract a file attached as a payload in the first packet. If the encryption proxy unit (150) determines that a cryptographic threat exists in the first packet, it can forward the first packet from the packet classification unit (110).
[0068] The encryption proxy unit (150) can extract encrypted payloads through password authentication. The encryption proxy unit (150) can be pre-configured to replace encrypted communications through a certificate proxy function for all communication sessions. In other words, the encryption proxy unit (150) may have undergone a pre-proxy procedure to decrypt encrypted payloads for all communication sessions.
[0069] The attachment storage unit (160) can extract and store attachments included in the payload from the first packet. The attachment storage unit (160) can extract payloads from sessions associated with the first packet. The attachment storage unit (160) can combine the extracted payloads and store all attached files. The attachment storage unit (160) can transmit the stored attachments to the lightweight malware detection unit (170).
[0070] The lightweight malware detection unit (170) can determine whether a stored attachment file is malicious.
[0071] The lightweight malware detection unit (170) can determine whether an attachment is malicious based on the output value of the second artificial neural network by inputting the attachment file into the second artificial neural network. The second artificial neural network may be a model learned using static and dynamic characteristics extracted from a plurality of previously detected malicious codes. The second artificial neural network may be a model learned using an ensemble of RNN (Recurrent Neural Network), LSTM (Long Short Time Memory), and CNN (Convolutional Neural Network) series.
[0072] Static characteristics can be acquired without executing malicious code. Dynamic characteristics can be acquired by monitoring changes after executing malicious code.
[0073] For example, a computing device can acquire static characteristics through static analysis, which diagnoses whether malware is malicious based on its own properties without directly executing the malware. A computing device can acquire dynamic characteristics through dynamic analysis, which analyzes behavioral patterns by monitoring changes after executing malware in a virtual environment. A computing device can pre-train a second artificial neural network using static and dynamic characteristics acquired from multiple pre-detected malware.
[0074] If the lightweight malicious detection unit (170) determines that the attachment of the first packet is a malicious attachment, the threat information and policy management unit (130) can update information related to the incoming network traffic packet, such as the first packet, fingerprint characteristics, and meta characteristics.
[0075] The network (200) may be a closed network such as a Local Area Network (LAN) or a Wide Area Network (WAN), or an open network such as the Internet. The network (200) may be an external network or a virtual network. The Internet refers to a global open computer network structure that provides various services existing in the TCP / IP protocol and its upper layer, namely, Hyper Text Transfer Protocol (HTTP), Telnet, File Transfer Protocol (FTP), Domain Name System (DNS), Simple Mail Transfer Protocol (SMTP), Simple Network Management Protocol (SNMP), Network File Service (NFS), and Network Information Service (NIS).
[0076] According to the above-described configuration, the processor (100) of the computing device may include a packet classification unit (110), a threat information and policy management unit (130), a packet storage and characteristic extraction unit (120), a threat detection unit (140), an encryption proxy unit (150), an attachment storage unit (160), and a lightweight malware detection unit (170). If a predefined malicious packet exists in a network traffic packet flowing into the computing device, the processor (100) can quickly filter it through the packet classification unit (110). In addition, the processor (100) can determine whether an incoming packet is a cryptographic threat through the threat detection unit (140) even if it is not a predefined malicious packet. Accordingly, blocking of newly discovered malicious codes can also be performed.
[0077] Below we describe how computing devices can detect cryptographic threats on a network and block malicious attachments.
[0078] FIG. 3 is a flowchart illustrating an example of a method for a computing device to detect a network cryptographic threat and block a malicious attachment according to some embodiments of the present disclosure.
[0079] Referring to FIG. 3, the processor (100) of the computing device can determine a first packet corresponding to a predefined security channel by using a protocol included in a network traffic packet flowing into the computing device through a packet classification unit (110) (S110).
[0080] The processor (100) can determine whether the first packet corresponds to a predefined malicious packet through the threat information and policy management unit (130) (S120).
[0081] If the first packet does not correspond to a malicious packet that has been detected in advance, the processor (100) can extract the fingerprint characteristics and meta characteristics of the first packet through the packet storage and characteristic extraction unit (120) (S130).
[0082] According to one embodiment, the fingerprint characteristic may include at least one of an encrypted channel protocol, an encrypted channel certificate, a source address, a destination address, port information, and header information extracted from an unencrypted portion of network traffic or extracted in an encrypted state. The meta characteristic may include at least one of a total network arrival time of the packet, a network delay time, a transmission and reception pattern of network traffic including the packet, a BPS, a PPS, a connection time between packets, a number of sessions per unit time, a number of users per unit time, and an estimate of the target hit of the packet.
[0083] If the first packet corresponds to a malicious packet, the processor (100) can filter the first packet through the packet classification unit (110).
[0084] According to one embodiment, the packet storage and feature extraction unit (120) of the processor (100) can determine whether there is at least one pre-stored second packet related to the first packet based on the extracted fingerprint characteristics and meta characteristics. For example, the packet storage and feature extraction unit (120) can determine whether there is at least one second packet identical to or similar to the first packet. If there is no at least one second packet, the packet storage and feature extraction unit (120) can transmit non-detection information indicating that at least one second packet has not been detected to the threat information and policy management unit (130). The threat information and policy management unit (130) can update information related to the first packet using the first packet, the fingerprint characteristics, and the meta characteristics. Hereinafter, an example of a method by which the packet storage and feature extraction unit (120) determines at least one second packet will be described with reference to FIG. 4.
[0085] The processor (100) can determine whether the first packet is a cryptographic threat by inputting fingerprint characteristics and meta characteristics into a first artificial neural network that has been previously learned through a threat detection unit (140) (S140).
[0086] The threat detection unit (140) can generate classification indicators clustered into a large-scale classification model without labeling based on pre-collected and labeled large-scale general traffic packet data, malicious traffic packet data, and fingerprint characteristics. The threat detection unit (140) can refer to the generated classification indicators. The threat detection unit (140) can generate judgment results through a first artificial neural network utilizing fingerprint characteristics and meta characteristics.
[0087] The processor (100) can update the judgment results generated through the threat information and policy management unit (130).
[0088] If it is determined that a cryptographic threat exists in the first packet, the processor (100) may perform encryption authentication for extracting a file attached as a payload in the first packet through the encryption proxy unit (150) (S150). The encryption proxy unit (150) may perform encryption authentication for the first packet through a certificate proxy function.
[0089] The processor (100) can extract and store an attachment file included in the payload from the first packet through the attachment file storage unit (160) (S160). The attachment file may be stored in a virtual memory area or on a virtual system rather than in a storage unit within the computing device.
[0090] The processor (100) can determine whether a stored attachment is malicious through a lightweight malware detection unit (170) (S170). The lightweight malware detection unit (170) can determine whether an attachment is malicious based on the output values of a second artificial neural network trained using static and dynamic characteristics extracted from a plurality of previously detected malware codes.
[0091] If the lightweight malicious detection unit (170) determines that the attachment of the first packet is a malicious attachment, the processor (100) can update information related to the incoming network traffic packet, such as the first packet, fingerprint characteristics, and meta characteristics, through the threat information and policy management unit (130).
[0092] Meanwhile, according to some embodiments of the present disclosure, the packet storage and feature extraction unit (120) of the processor (100) can determine whether at least one second packet related to the first packet exists. Hereinafter, an example of a method by which the packet storage and feature extraction unit (120) determines whether at least one second packet related to the first packet exists will be described with reference to FIG. 4.
[0093] FIG. 4 is a flowchart illustrating an example of a method by which a packet storage and feature extraction unit determines whether at least one second packet related to a first packet exists, according to some embodiments of the present disclosure.
[0094] Referring to FIG. 4, the packet storage and characteristic extraction unit (120) of the processor (100) of the computing device can determine whether there is at least one pre-stored second packet related to the first packet based on the fingerprint characteristics and meta characteristics of the extracted first packet (S210).
[0095] For example, the packet storage and feature extraction unit (120) can determine whether there is at least one second packet that is identical to or similar to the first packet.
[0096] If it is determined that at least one second packet does not exist (S220, No), the packet storage and feature extraction unit (120) can store the first packet, fingerprint features, and meta features in the packet features within the first session related to the first packet (S230).
[0097] For example, the packet storage and feature extraction unit (120) can store packets of incoming network traffic by session. The packet storage and feature extraction unit (120) can store the first packet, fingerprint features, and meta features in the packet features of the first session related to the first packet in the database stored by session.
[0098] According to one embodiment, the packet storage and feature extraction unit (120) can transmit undetected information indicating that at least one second packet was not detected to the threat information and policy management unit (130). The threat information and policy management unit (130) can update information related to the first packet using the undetected information, the first packet, the fingerprint characteristics, and the meta characteristics.
[0099] In one embodiment, the Threat Information and Policy Management Unit (130) may configure undetected information into a Cyber Threat Intelligence (CTI) protocol. The Threat Information and Policy Management Unit (130) may share the configured threat information sharing protocol with other networks, including the cloud.
[0100] If it is determined that at least one second packet exists (S220, Yes), the packet storage and feature extraction unit (120) can transmit information related to at least one second packet to the packet classification unit (110). Then, the packet classification unit (110) can use the transmitted information to determine whether to filter the first packet.
[0101] Meanwhile, according to some embodiments of the present disclosure, the packet storage and feature extraction unit (120) can generate meta-features for network traffic by tracking the temporal variation of at least one parameter included in the first packet using the first packet and a plurality of fingerprint features. Hereinafter, an example of a method for the packet storage and feature extraction unit (120) according to the present disclosure to generate meta-features will be described with reference to FIG. 5.
[0102] FIG. 5 is a diagram illustrating an example of a method for generating meta characteristics by a packet storage and feature extraction unit according to some embodiments of the present disclosure.
[0103] Referring to FIG. 5, the packet storage and feature extraction unit (120) may include a fingerprint feature extraction unit (121) and a meta feature generation unit (122).
[0104] The fingerprint characteristic extraction unit (121) may include a fingerprint characteristic definition module (1211) and a fingerprint characteristic extraction module (1212).
[0105] The fingerprint characteristic definition module (1211) can define fingerprint characteristics.
[0106] The fingerprint feature extraction module (1212) can extract the fingerprint feature of the requested packet.
[0107] The meta-characteristic generation unit (122) may include a meta-characteristic definition module (1221) and a meta-characteristic combination module (1222).
[0108] The meta-characteristic definition module (1221) can define meta-characteristics. The meta-characteristic definition module (1221) can check whether there are previously stored related packets based on the requested packet and fingerprint characteristics.
[0109] The meta-characteristic combination module (1222) can generate meta-characteristics by combining requested packets and associated packets.
[0110] If there is no packet or fingerprint characteristic associated with the requested packet, the meta characteristic definition module (1221) can store the requested packet and the fingerprint characteristic of the requested packet in the packet characteristics within the corresponding session. The meta characteristic definition module (1221) can transmit a non-detection result indicating that the packet associated with the requested packet was not detected to the threat information and policy management unit (130).
[0111] According to one embodiment, the meta-characteristic combination module (1222) may group multiple packets executing one session from a pre-stored session list into a single group. The meta-characteristic combination module (1222) may generate changes in parameters associated with packets accumulated in each group over time as meta-characteristics.
[0112] When a packet and multiple fingerprint characteristics for new network traffic are transmitted, the meta-attribute combination module (1222) can assign the new packet to at least one of the pre-designated groups (G1, G2, G3) depending on whether the same packet or the same session exists for the packet included in the new network traffic.
[0113] For example, a first group (G1) may be defined as a group that includes packets executing a first session. Packets A and B executing a first session may be grouped in the first group (G1), and although not shown in FIG. 3, packets executing a first session among the subsequently transmitted packets may be newly assigned to the first group (G1). Packets executing a second session may be grouped in the second group (G2), such that packets B, packet C, and packet D may be grouped therein. In addition, packets executing a third session may be grouped in the third group (G3), such that packets B, packet C, and packet D may be grouped therein.
[0114] According to the above-described configuration, the meta-characteristic generation unit (122) of the packet storage and characteristic extraction unit (120) can generate the meta-characteristic of the first packet received from the packet classification unit (110). Accordingly, the meta-characteristic can have various dynamic change characteristics of the packet over time.
[0115] Meanwhile, the computing device according to the present invention can be linked with endpoint terminal equipment. The endpoint terminal equipment can be a user terminal such as a PC, mobile terminal, or IoT device. Below, an example of a computing device according to the present disclosure linking with an endpoint terminal equipment is described with reference to FIGS. 6 and 7.
[0116] FIG. 6 is a flowchart illustrating an example of a computing device interworking with an endpoint terminal device according to some embodiments of the present disclosure.
[0117] Referring to FIG. 6, the processor (100) of the computing device can be mounted on various security devices and network devices such as a firewall (FW), UTM, intrusion prevention system (IPS), and next-generation network detection (NDR). The processor (100) can provide information on whether malicious content has been detected by a security module operating in a user terminal (300) such as a PC (310), a tablet (302), a mobile terminal (303), a laptop (304), or an IoT device. For example, the processor (100) can provide information on whether malicious content has been detected for site access information, etc. in the user terminal (300). Accordingly, the security module of the user terminal (300) can block access to the corresponding site and remote location, or block execution of a downloaded file.
[0118] FIG. 7 is a flowchart illustrating an example of a computing device interworking with cloud equipment according to some embodiments of the present disclosure.
[0119] Referring to FIG. 7, the processor (100) of the computing device can be mounted on various security equipment and network equipment such as a firewall (FW), UTM, intrusion prevention system (IPS), and next-generation network detection (NDR).
[0120] The processor (100) can share packets and learning information with a malicious encryption traffic detection system (400) built in an external network environment, such as an external cloud. For example, the threat information and policy management unit (130) of the processor (100) can configure undetected information as a threat information sharing (Cyber Threat Intelligence, CTI) protocol. The threat information and policy management unit (130) can share learning information and characteristics with CTI and rental systems (SaaS), etc., using a threat information sharing protocol such as STIX and a data format such as JSON. In addition, the threat information and policy management unit (130) can train artificial neural networks according to the present disclosure using the threat information sharing protocol received from the malicious encryption traffic detection system (400).
[0121] FIG. 8 is a flowchart illustrating an example of a method for a computing device to detect a cryptographic threat in a network according to some embodiments of the present disclosure.
[0122] Referring to FIG. 8, the packet classification unit (110) of the processor (100) of the computing device can filter network traffic packets flowing into the computing device in real time (S310). The packet classification unit (110) can determine the first packet corresponding to a predefined security channel and transmit it to the threat information and policy management unit (130).
[0123] The Threat Information and Policy Management Unit (130) can compare the threat information of the transmitted first packet (S320). In other words, the Threat Information and Policy Management Unit (130) can determine whether the first packet corresponds to a predefined malicious packet.
[0124] The threat information and policy management unit (130) can compare the threat information of the first packet and transmit the result to the packet classification unit (110) (S330). Based on the comparison result, the packet classification unit (110) can block or not block the first packet.
[0125] If it is determined that no threat exists in the first packet, the packet classification unit (110) can transmit the first packet to the packet storage and feature extraction unit (120) (S340).
[0126] The packet storage and feature extraction unit (120) that receives the first packet can store packets for each session (S350). The packet storage and feature extraction unit (120) can extract fingerprint characteristics and meta characteristics of the stored first packet (S360). The packet storage and feature extraction unit (120) can transmit the extracted fingerprint characteristics and meta characteristics to the threat detection unit (140) (S370).
[0127] The threat detection unit (140) can determine whether the first packet is malicious by inputting fingerprint characteristics and meta-characteristics into a pre-trained AI model (S380). In other words, the threat detection unit (140) can determine whether the first packet poses a cryptographic threat by inputting fingerprint characteristics and meta-characteristics into a pre-trained first artificial neural network.
[0128] The threat detection unit (140) can transmit the judgment results, fingerprint characteristics, meta characteristics, etc. to the threat information and policy management unit (130) (S390). The threat information and policy management unit (130) can update information related to the first packet.
[0129] The packet classification unit (110) can classify and block the first packet as a malicious packet (S400) based on the result received from the malicious packet classification and blocking (S400).
[0130] FIG. 9 is a flowchart illustrating an example of a method for a computing device to block malicious attachments according to some embodiments of the present disclosure.
[0131] Referring to FIG. 9, the packet classification unit (110) can forward a malicious classified traffic proxy to the encryption proxy unit (150) (S410). The packet classification unit (110) can generate detailed malicious judgment results for an attached file attached as a payload to the first packet and forward packet information to the encryption proxy unit (150) to distinguish threats.
[0132] The encryption proxy unit (150) can process encryption authentication through a combination of sessions (S420). The encryption proxy unit (150) can perform encryption authentication for one packet through a certificate proxy function for the session.
[0133] The encryption proxy unit (150) can transmit the first packet on which encryption authentication has been performed to the attachment file storage unit (160) (S430).
[0134] The attachment storage unit (160) can extract characteristics of stored attachments and transmit them to the lightweight malware detection unit (170) (S440). The attachment storage unit (160) can extract payloads from sessions related to the first packet and store all attached files by combining the extracted payloads. The attachment storage unit (160) can transmit the stored attachments to the lightweight malware detection unit (170).
[0135] The lightweight malware detection unit (170) can determine whether the first packet or attachment is malicious and determine integrated characteristics using an AI model (S450). In other words, the lightweight malware detection unit (170) inputs the attachment into a second artificial neural network and determines whether the attachment is malicious based on the output value from the second artificial neural network. The second artificial neural network may be an AI model trained using static and dynamic characteristics extracted from multiple previously detected malicious codes.
[0136] The lightweight malware detection unit (170) can transmit the malware judgment results determined through the AI model to the threat information and policy management unit (130) (S460). The threat information and policy management unit (130) can use the transmitted information to update and store information related to the first packet.
[0137] The Threat Information and Policy Management Unit (130) can transmit updated malicious information to endpoint security modules (300) and cloud devices (400) (S470). In other words, the Threat Information and Policy Management Unit (130) can share the configured threat information sharing protocol with other networks, including the cloud.
[0138] The description of the disclosed embodiments is provided to enable any person skilled in the art to make or use the present disclosure. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other embodiments without departing from the scope of the present disclosure. Therefore, the present disclosure is not intended to be limited to the embodiments disclosed herein, but is to be construed in the broadest scope consistent with the principles and novel features disclosed herein.
Claims
1. A computing device comprising at least one processor, and implemented by the at least one processor: A packet classification unit that determines a first packet corresponding to a predefined security channel using a protocol included in a network traffic packet flowing into the computing device; A threat information and policy management unit that receives a request from the packet classification unit to determine whether the first packet corresponds to a predefined malicious packet; A packet storage and feature extraction unit that receives the first packet from the packet classification unit and extracts fingerprint characteristics and meta characteristics of the received first packet when the first packet does not correspond to the malicious packet; A threat detection unit that determines whether the first packet is a cryptographic threat by inputting the extracted fingerprint characteristics and the meta characteristics into a first artificial neural network that has been learned in advance; An encryption proxy unit that performs encryption authentication to extract a file attached as a payload from the first packet when it is determined that a cryptographic threat exists in the first packet; An attachment storage unit that extracts and stores an attachment included in the payload from the first packet; and A lightweight malware detection unit that determines whether the saved attachment file is malicious; A computing device comprising:
2. In paragraph 1, The above fingerprint characteristics are, At least one of an encrypted channel protocol, an encrypted channel certificate, a source address, a destination address, port information, and header information extracted from the non-encrypted area of the above network traffic or extracted in an encrypted state, Computing device.
3. In paragraph 1, The above meta characteristics are, At least one of the total network arrival time of the packet, network latency, transmission and reception pattern of network traffic including the packet, BPS (bits per second), PPS (packets per second), connection time between packets, number of sessions per unit time, number of users per unit time, and target hit estimation of the packet. Computing device.
4. In paragraph 1, The above packet storage and feature extraction unit, Based on the extracted fingerprint characteristics and the meta characteristics, it is determined whether there is at least one pre-stored second packet related to the first packet, If it is determined that at least one second packet does not exist, storing the first packet, the fingerprint characteristic and the meta characteristic in packet characteristics within the first session associated with the first packet, Computing device.
5. In paragraph 4, The above threat information and policy management department, The Cyber Threat Intelligence (CTI) protocol configures the undetected information that at least one second packet was undetected. Computing device.
6. In paragraph 1, The above lightweight malware detection unit is, By inputting the attached file into a second artificial neural network trained using static and dynamic characteristics extracted from multiple previously detected malicious codes, it is determined whether the attached file is malicious or not based on the output value of the second artificial neural network. Computing device.
7. A method for detecting a network cryptographic threat and blocking a malicious attachment performed by a computing device including at least one processor, A step of determining a first packet corresponding to a predefined security channel using a protocol included in a network traffic packet flowing into the computing device; A step of determining whether the first packet corresponds to a predefined malicious packet; A step of extracting fingerprint characteristics and meta characteristics of the first packet when the first packet does not correspond to the malicious packet; A step of determining whether the first packet is a cryptographic threat by inputting the extracted fingerprint characteristics and the meta characteristics into a first artificial neural network that has been learned in advance; A step of performing encryption authentication to extract a file attached as a payload from the first packet when it is determined that a cryptographic threat exists in the first packet; A step of extracting and storing an attachment included in the payload from the first packet; and A step of determining whether the saved attachment file is malicious; including, How to detect cryptographic threats on your network and block malicious attachments.
8. In paragraph 7, The above fingerprint characteristics are, At least one of an encrypted channel protocol, an encrypted channel certificate, a source address, a destination address, port information, and header information extracted from the non-encrypted area of the above network traffic or extracted in an encrypted state, How to detect cryptographic threats on your network and block malicious attachments.
9. In paragraph 7, The above meta characteristics are, At least one of the total network arrival time of the packet, network latency, transmission and reception pattern of network traffic including the packet, BPS (bits per second), PPS (packets per second), connection time between packets, number of sessions per unit time, number of users per unit time, and target hit estimation of the packet. How to detect cryptographic threats on your network and block malicious attachments.
10. In paragraph 7, The step of determining a first packet corresponding to a predefined security channel using a protocol included in a network traffic packet flowing into the computing device is as follows: A step of determining whether at least one pre-stored second packet related to the first packet exists based on the extracted fingerprint characteristics and the meta characteristics; and If it is determined that at least one second packet does not exist, a step of storing the first packet, the fingerprint characteristic, and the meta characteristic in packet characteristics within the first session associated with the first packet. including more, How to detect cryptographic threats on your network and block malicious attachments.
11. In paragraph 10, The undetected information that at least one second packet was undetected is configured as a Cyber Threat Intelligence (CTI) protocol. How to detect cryptographic threats on your network and block malicious attachments.
12. In paragraph 7, The step of determining whether the saved attachment file is malicious or not is as follows: A step of inputting the attached file into a second artificial neural network trained using static and dynamic characteristics extracted from multiple previously detected malicious codes, thereby determining whether the attached file is malicious based on the output value of the second artificial neural network; including, How to detect cryptographic threats on your network and block malicious attachments.
Citation Information
Patent Citations
Method for producing syngas fermentation products using highly active microorganisms
KR1020250009727A
Method and apparatus for detecting malicious traffic
KR102336605B1
Earth and sand removal device using compressed air and spring
KR102459663B1
Device and method of determining malicious packet in encrypted traffic based on artificial intelligence
KR102502475B1
Extracting Encryption Metadata and Terminating Malicious Connections Using Machine Learning
US20200007568A1