Cyber threat information processing apparatus, cyber threat information processing method, and storage medium storing program for processing cyber threat information

The cyber threat information processing device addresses the challenge of comprehensive threat analysis across IT, OT, and IoT assets by utilizing a high-speed packet collection engine and AI-based detection for real-time threat identification and response.

WO2026054186A1PCT designated stage Publication Date: 2026-03-12SANDS LAB INC
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-12-19
Publication Date
2026-03-12

AI Technical Summary

Technical Problem

Existing cybersecurity measures struggle to comprehensively analyze cyber threat information across various assets, including IT, OT, and IoT devices, and fail to detect threats in real-time, particularly for zero-day cyberattacks and network abnormalities, with limited visibility and response capabilities.

Method used

A cyber threat information processing device that collects, analyzes, and detects network traffic data using a high-speed packet collection engine, deep packet inspection, and AI-based threat detection, generating metadata and threat information for real-time analysis and response.

Benefits of technology

Enables comprehensive and real-time analysis of cyber threats across diverse assets, identifying abnormal symptoms and zero-day attacks, and providing timely responses to network anomalies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024020664_12032026_PF_FP_ABST
    Figure KR2024020664_12032026_PF_FP_ABST
Patent Text Reader

Abstract

A disclosed embodiment provides a cyber threat information processing method comprising the steps of: collecting packet data included in network traffic; analyzing the packet data by using a detection rule; and when an abnormal sign having a potential threat is detected in a first session in the packet data on the basis of the analysis, providing threat information corresponding to the abnormal sign. Accordingly, an embodiment enables comprehensive and visual analysis of cyber threat information from network-based traffic.
Need to check novelty before this filing date? Find Prior Art

Description

Cyber ​​threat information processing device, cyber threat information processing method, and storage medium storing a cyber threat information processing program

[0001] The disclosed embodiments relate to a cyber threat information processing device, a cyber threat information processing method, and a storage medium storing a cyber threat information processing program.

[0002]

[0003] The damage from increasingly sophisticated cybersecurity threats, particularly those involving new or variant malware, is increasing. To mitigate these damages and respond quickly, we are continuously improving our response technologies through multidimensional pattern composition and various complex analyses.

[0004] To date, companies have focused on perimeter-based security, detecting and blocking internal and external traffic through technologies like VPNs, firewalls, and IDS / IPS. However, the increasing complexity of technology, the diversity of attacks, and the increasing number of attack points have made security measures difficult.

[0005] In order to respond to cyber threats through network-based traffic, traffic analysis based on the network layer or transport layer had the problem of not being able to comprehensively and visually analyze threat information.

[0006] For example, it was difficult to secure network visibility when abnormal behavior was included in metadata about data or payload according to the protocol through the network layer or transport layer.

[0007] Therefore, the detection of cyber threats through network-based traffic has the problem of targeting only IT assets and not detecting or identifying threats to operational technology (OT) assets or IoT devices.

[0008] There was a problem that the analysis of cyber threats through network-based traffic was fragmentary and only possible after a breach incident, making it difficult to analyze large amounts of network traffic in real time and respond to cyber threats.

[0009] In addition to malware threats, there was a problem of difficulty in identifying abnormal symptoms within network events, such as zero-day cyberattacks, including difficult-to-identify network abnormalities.

[0010] And in systems that record all data on the network without loss for a certain period of time, such as vehicle black boxes or surveillance cameras, there were no threatening or abnormal signs when network packets were input or output, but there was no way to appropriately respond to threatening or abnormal signs at a certain point in time.

[0011]

[0012] The purpose of the embodiment disclosed below is to solve the above problems and to provide a cyber threat information processing device capable of performing comprehensive and visible analysis of cyber threat information through network-based traffic, a cyber threat information processing method, and a storage medium storing a cyber threat information processing program.

[0013] Another object of the embodiment is to provide a cyber threat information processing device capable of detecting or identifying cyber threats to various assets such as IT assets, operational technology (OT) assets, IoT devices, and the like, a cyber threat information processing method, and a storage medium storing a cyber threat information processing program.

[0014] Another object of the embodiment is to provide a cyber threat information processing device capable of analyzing network traffic in real time and responding to cyber threats, a cyber threat information processing method, and a storage medium storing a cyber threat information processing program.

[0015] Another object of the embodiment is to provide a cyber threat information processing device capable of identifying abnormal symptoms within a network event, such as a zero-day cyber attack, including a threat of malware, a network abnormality symptom that is difficult to identify, a cyber threat information processing method, and a storage medium storing a cyber threat information processing program.

[0016] Another purpose of the embodiment is to provide a cyber threat information processing device, a cyber threat information processing method, and a storage medium storing a cyber threat information processing program, which can appropriately respond to a threat or anomaly at a specific point in time after a network packet input / output without a threat or anomaly.

[0017]

[0018] An embodiment of the present disclosure provides a method for processing cyber threat information, comprising: collecting packet data included in network traffic; analyzing the packet data using a detection rule; and, if an anomaly indicating a possible threat is detected in a first session within the packet data based on the analysis, providing threat information corresponding to the anomaly.

[0019] The above threat information is characterized in that it includes at least one of the occurrence date of the above abnormal symptom, the detection date of the above abnormal symptom, the source IP, the source port, the destination IP, the destination port, the number of rules detected in the first session, information set in the rule, and packet data corresponding to the first session.

[0020] The above cyber threat information processing method generates vulnerability information based on the threat information, wherein the vulnerability information corresponds to flow information including at least one of an IP and a port of a source and a destination, and at least one of a protocol, an application, and metadata for the network traffic.

[0021] The above cyber threat information processing method is characterized by further including a step of inputting the threat information into a natural language model to provide descriptive information corresponding to the threat information.

[0022] One embodiment of the disclosure provides a cyber threat information processing device, comprising: a database for storing data; and a processor for processing the data, wherein the processor collects packet data included in network traffic, analyzes the packet data using a detection rule, and, if an anomaly indicating a possible threat is detected in a first session within the packet data based on the analysis, provides threat information corresponding to the anomaly.

[0023] An embodiment of the present disclosure provides a storage medium storing a program for processing cyber threat information, the program comprising: collecting packet data included in network traffic; analyzing the packet data using a detection rule; and, if an anomaly indicating a possible threat is detected in a first session within the packet data based on the analysis, providing threat information corresponding to the anomaly.

[0024]

[0025] According to the disclosed embodiment, it is possible to comprehensively and visually analyze cyber threat information through network-based traffic.

[0026] According to the disclosed embodiment, cyber threats to various assets, such as IT assets, operational technology (OT) assets, and IoT devices, can be detected or identified.

[0027] According to the disclosed embodiment, network traffic can be analyzed in real time and cyber threats can be responded to.

[0028] According to the disclosed embodiment, it is possible to identify abnormal symptoms within network events, including malware threats, difficult-to-identify network anomalies, and zero-day cyber attacks.

[0029] According to the disclosed embodiment, there is no threat or abnormality at the time of network packet input / output, but it is possible to appropriately respond to threat or abnormality at a specific point in time thereafter.

[0030]

[0031] FIG. 1 is a drawing disclosing one embodiment of a cyber threat information processing method according to an embodiment.

[0032] FIG. 2 is a drawing showing an example of using a cyber threat information processing device according to an embodiment.

[0033] FIG. 3 is a drawing disclosing an example of a cyber threat information processing device according to an embodiment.

[0034] FIG. 4 is a drawing disclosing one embodiment of a collection unit of a cyber threat information processing device according to an embodiment.

[0035] FIG. 5 is a drawing disclosing one embodiment of a cyber threat information processing device according to an embodiment.

[0036] FIG. 6 is a drawing disclosing another embodiment of a cyber threat information processing device according to an embodiment.

[0037] Figure 7 is a diagram disclosing another embodiment of a cyber threat information processing policy according to an embodiment.

[0038] FIG. 8 is a drawing disclosing an embodiment of a high-speed packet collection engine according to an embodiment.

[0039] FIG. 9 is a diagram disclosing one embodiment of a cyber threat information processing method according to an embodiment.

[0040] FIG. 10 is a drawing disclosing another embodiment of a cyber threat information processing device according to an embodiment.

[0041] FIG. 11 is a diagram disclosing an example of metadata extraction of a DPI engine according to an embodiment.

[0042] FIG. 12 is a diagram disclosing an embodiment of OT network metadata extracted from a DPI engine according to an embodiment.

[0043] FIG. 13 is a diagram disclosing another embodiment of OT network metadata extracted from a DPI engine according to an embodiment.

[0044] Figure 14 is a drawing explaining information provided by a cyber threat information processing device according to an embodiment.

[0045] Figure 15 is a flowchart illustrating an embodiment of a method for processing cyber threat information according to an embodiment.

[0046] Figure 16 is a diagram disclosing another embodiment of a cyber threat information processing policy according to an embodiment.

[0047] FIG. 17 is a diagram disclosing an embodiment of active ASM execution based on network traffic collection according to an embodiment.

[0048] FIG. 18 is a diagram disclosing another embodiment of active ASM execution based on network traffic collection according to an embodiment.

[0049] Figure 19 is a flowchart illustrating one embodiment of a method for processing cyber threat information according to an embodiment.

[0050] FIG. 20 is a drawing disclosing another embodiment of a cyber threat information processing device according to an embodiment.

[0051] FIG. 21 is a drawing disclosing another embodiment of a cyber threat information processing device according to an embodiment.

[0052] Figure 22 is a drawing disclosing one embodiment of a network black box according to an embodiment.

[0053] FIG. 23 is a diagram disclosing an example of threat information provided by a network black box according to an embodiment.

[0054] FIG. 24 is a diagram disclosing an example of threat information provided by a network black box according to an embodiment.

[0055] Figure 25 is a flowchart disclosing one embodiment of a cyber threat information processing method according to an embodiment.

[0056]

[0057] Hereinafter, embodiments will be described in detail with reference to the attached drawings.

[0058] In embodiments, the engine or various analysis tools, modules, etc. may be implemented as a physical device, a device combined with the physical device, or software.

[0059] If the embodiment is implemented as software, it can be stored in a storage medium and installed in a computer or the like and executed by a processor.

[0060] The following embodiments can be implemented in network equipment to which a wired or wireless communication network is connected, and can be implemented in network equipment such as artificial satellites or space vehicles according to the same features and principles.

[0061] Also, directly connected to the network, such as a network black box or camera device

[0062] Embodiments of a cyber threat information processing device and a cyber threat information processing method are disclosed in detail as follows.

[0063]

[0064] FIG. 1 discloses one embodiment of a cyber threat information processing method according to an embodiment.

[0065] One embodiment of the disclosed cyber threat information processing method can collect, analyze, and detect data based on communication network traffic, manage cyber threat information based on the results, and respond to cyber threats.

[0066] Collect data packets included in network traffic (S1000).

[0067] The embodiment can process a large volume of network packets from a network without loss and enable the operating system to process the packets quickly. Here, the embodiment can process packets that were previously performed in the operating system kernel in user space (User Space / Land / Area).

[0068] That is, it can process packets received from a network card quickly without using a dedicated processor core allocation method by processing packets in a software manner that processes network packets on behalf of the operating system kernel.

[0069] To elaborate, when the operating system kernel processes packets collected via a network card, it must collect and analyze packets that have passed through various software and library layers, such as the TCP / IP stack, existing on the kernel. In this case, packet loss due to processor scheduling can occur.

[0070] Therefore, when the disclosed embodiment collects data packets, the embodiment can process the packets collected from the network card in a separate engine that operates in user space without going through the kernel of the operating system, and can provide an interface that can directly control the packets.

[0071] This interface ensures that other operating systems or software cannot share the resources of the processor other than the processor's network packet processing thread.

[0072]

[0073] At this point, the abstraction layer of the user application's libraries and resources provides a channel to access the network interface card directly instead of the kernel.

[0074] A detailed embodiment of collecting data packets is disclosed below.

[0075]

[0076] Analyze data contained in continuously collected packets according to protocol or application (S2000)

[0077] Network traffic can be inspected and filtered based on collected packets. An example embodiment allows for protocol-based inspection of data content up to Layer 7 of packet data passing through network equipment and extraction of metadata.

[0078] For example, you can monitor all packets between the source and destination of a packet and reorder those packets using a capture method such as Portable Packet Capturing Library (PCAP).

[0079] It is possible to temporarily store rearranged packets in separate buffers for the client and server and generate metadata by processing the transmitted and received packets as a single session.

[0080] In the analysis step according to the embodiment, the rearranged packets can be converted into packets containing complete information that are transmitted by reassembling the fragmented packet pieces to be transmitted in frame units.

[0081] Additionally, files associated with packets can be extracted, information about the operating system, applications, etc. can be detected based on packet characteristics, and metadata corresponding to protocols or applications can be generated. For example, it can identify HTTP protocols within packets, as well as application browsers running HTTP protocols.

[0082]

[0083] Cyber ​​threat information is detected from data according to the above analyzed protocol or application (S3000).

[0084] Cyber ​​threat information can be detected from various perspectives and methods based on data derived from the analysis of at least one of the analyzed protocols or applications. For example, cyber threat information can be detected using a specific rule-based detection method, an artificial intelligence (AI)-based method, or a combination of the two, based on behavioral analysis of the attacker's tactics, techniques, and procedures (TTPs). Detailed examples of this are described below.

[0085]

[0086] Provides analysis or response information on detected cyber threat information (S4000).

[0087] It can provide network users or administrators with visualized analysis information or response information on detected cyber threat information.

[0088] Detected cyber threat information can be provided based on a timeline or statistics for a specific period.

[0089] Cyber ​​threat information can be provided based on analyzed network-related information such as IP addresses, protocols, or applications, and can provide response information to manage threat factors through various insights into cyber threat information.

[0090] Additionally, various other intelligence methods can be integrated to provide cyber threat intelligence. Detailed examples of this are provided below.

[0091]

[0092] FIG. 2 discloses an example of using a cyber threat information processing device according to an embodiment.

[0093] This drawing example discloses an example in which a cyber threat information processing device (1000) processes cyber threat information from network traffic flowing into an intranet equipped with a firewall (10).

[0094] However, the present invention is not limited to the examples disclosed in this drawing, and the following embodiments may be applied to any device that is connected to a wired or wireless network other than an intranet and communicates with the cyber threat information processing device (1000).

[0095] For example, the cyber threat information processing device (1000) can process cyber threat information from network communication, even in the case of mobile devices, robot systems, computer servers, aircraft such as drones, or even artificial satellites on a wired or wireless network.

[0096] A firewall (10) can generally block external attacks via network packets coming from the Internet. The firewall (10) can analyze network packets to block or bypass specific hosts (IPs), or control application access.

[0097]

[0098] Traffic mirroring (100) can mirror packet traffic input through a firewall (10) and transmit it to a cyber threat information processing device (1000).

[0099] The cyber threat information processing device (1000) can collect and reassemble packet traffic and then detect cyber threat information based on the extracted files and protocols.

[0100] The cyber threat information processing device (1000) can provide the monitoring results of threat information to the user through the monitoring unit (2000).

[0101] The cyber threat information processing device (1000) transmits the analyzed packets to the network, and the switch unit (120) can switch the L2 (layer 2) information of the packets transmitted through the cyber threat information processing device (1000) and transmit it to the user (210, 220, 230).

[0102] The cyber threat information processing device (1000) can collect and analyze all traffic on the network of Internet of Things (IoT) and operational technology (OT) devices as well as information technology (IT) infrastructure traffic and detect cyber threat information.

[0103] Cyber ​​threat information processing device (1000) is not connected to the intranet

[0104] The cyber threat information processing device (1000) can manage and respond to cyber threat information on the network by providing network packets and cyber threat information collected, detected, and analyzed through the monitoring unit (2000) to the user.

[0105] For example, the cyber threat information processing device (1000) can identify real-time assets in packets and proactively respond to vulnerability information. The cyber threat information processing device (1000) can automatically detect abnormal traffic behavior and analyze whether it represents a real-world threat. Furthermore, the cyber threat information processing device (1000) analyzes traffic anomalies and Advanced Persistent Threats (APTs), and provides a means for post-event response in conjunction with other security solutions.

[0106] Below, several embodiments of a cyber threat information processing device are disclosed.

[0107]

[0108] FIG. 3 discloses an example of a cyber threat information processing device according to an embodiment.

[0109] An example of a disclosed cyber threat information processing device (1000) includes a collection unit (1100), an analysis unit (1200), and a detection unit (1300).

[0110] The collection unit (1100) includes a packet collector, which can collect various metadata to enhance security from collected packet data without loss.

[0111] By having the packet collector of the collection unit (1100) collect various metadata from packets, the analysis unit (1200) can efficiently process a large number of packets and pre-allocate packets to memory to avoid unnecessary waiting time.

[0112] A detailed description of an embodiment of the collection unit (1100) of the cyber threat information processing device is described below.

[0113] The analysis unit (1200) can inspect, manage, and filter packets collected by the collection unit (1100) using Deep Packet Inspection (DPI). DPI can inspect the content of collected packets in detail, down to Layer 7. This allows DPI to not only identify the overall characteristics of network data, but also control potential malicious traffic.

[0114] The DPI engine, which performs the DPI method, monitors and reassembles collected packets between the source and destination, then inputs them into a separate buffer. The DPI engine then forms a single session with these packets, allowing it to generate metadata based on this session.

[0115] A detailed description of an embodiment of the analysis unit (1200) of the cyber threat information processing device is described below.

[0116]

[0117] The detection unit (1300) can detect threats based on metadata added by the analysis unit (1200), files within packets, and relocated PCAP packet files. The detection unit (1300) can detect abnormal behavior through profiling event characteristics such as file types, attack behavior types, and OT types.

[0118] For example, the detection unit (1300) can detect malware using at least one of an indicator of compromise (IoC), a rule-based malware detection tool such as YARA rule, and machine learning.

[0119] The detection unit (1300) can detect abnormal behavior through various rules and artificial intelligence (AI)-based behavioral analysis that can find out the attacker's tactics, techniques, and procedures (TTP) according to the attack life cycle.

[0120] The detection unit (1300) can detect anomalies in the operational technology (OT) environment within the corporate network.

[0121] The detection unit (1300) loads the extracted event features and applies an AI algorithm to generate a behavior profile, and can detect risk factors by calculating a risk score using weights, etc. based on the confidence score of the generated behavior profile model.

[0122] Through this step-by-step and comprehensive approach, the detection unit (1300) can reduce the false detection rate and enable users to efficiently investigate and respond to risk factors.

[0123] A detailed description of an embodiment of the detection unit (1300) of the cyber threat information processing device is described below.

[0124]

[0125] FIG. 4 discloses an embodiment of a collection unit of a cyber threat information processing device according to an embodiment.

[0126] An embodiment of a collection unit of a cyber threat information processing device may include an engine for collecting packets at high speed.

[0127] Typically, the packet processing speed of an operating system often lags behind that of a network interface card (NIC). One embodiment allows packet processing performed in the operating system kernel to be handled in user space using a high-speed processing library.

[0128] One embodiment of the collection unit allows an operating system process to quickly read data by polling packets received on a network interface card using a high-speed processing library, without involving the kernel. Therefore, the collection unit embodiment can reduce idle time that occurs during the process in which the operating system kernel reads packets received on the network interface card and transmits them to the operating system process.

[0129] In the disclosed embodiment, the collection unit (1100) may include a network interface card (1110) and a packet collector (1120). The packet collector (1120) may include a receiving core (1121), a memory (1125), and a copy core (1128).

[0130] The network interface card (1110) can receive network packets at high speed.

[0131] The packet collector (1120) reads received packets and transmits them to the processor without going through the kernel using a polling method. The concept of reading packets at high speed using a polling method is schematically illustrated at the top of this diagram.

[0132] The receiving core (1121) can store packets received at high speed using a polling method in a large memory (1125). The receiving core (1121) uses a dedicated core of the processor to perform isolated tasks so as to protect malicious software included in high-speed received packets from affecting related processes.

[0133] The receiving core (1121) can protect the computer operating system and enhance security functions even when receiving packets at high speeds. The memory (1125) can utilize large-capacity memory that can reduce management overhead, such as memory faults, depending on the computer system's memory management function. The memory (1125) may or may not be configured as large-capacity memory, depending on the operating system's settings.

[0134] And, the copy core (1128) can copy and output packets stored in the memory (1125).

[0135]

[0136] FIG. 5 discloses an embodiment of a cyber threat information processing device according to an embodiment.

[0137] This drawing discloses in detail an embodiment of an analysis unit (1200) and a detection unit (1300) of a cyber threat information processing device.

[0138] Packets output from the collection unit (1100) are analyzed by the analysis DPI engine (1210) and stored in the queue storage unit (1220) according to the analyzed content and then output.

[0139] The queue storage unit (1220) illustrated can synchronize memory access by completing calls in a set time unit when data is called simultaneously by multiple threads.

[0140] This example illustrates a case where the data analyzed in the analysis unit (1200) is metadata, a file, a file of PCAP packets, etc., and problems related to system synchronization can be solved by using multiple queue storage units (1220) even in a multi-threaded environment.

[0141] The DPI engine (1210) pre-allocates internal memory (1211) to store data and stores data output by the collection unit (1100).

[0142] The DPI engine (1210) can perform detailed syntax analysis and extract files in real time for stored data.

[0143] The DPI engine (1210) can extract metadata of data across all layers, including layers L2 to L4 as well as the application layer of layer 7. The data extracted by the DPI engine (1210) is as follows.

[0144] For example, the DPI engine (1210) can obtain application layer information within the payload of the packet, rather than simply obtaining transport layer information such as Internet Protocol or TCP / UDP of the Source IP and Destination IP from the head of the packet.

[0145] The DPI engine (1210) can extract metadata of application protocols required for network threat detection, such as HTTP, SSL, SSH, FTP, SMB, and DNS, as well as metadata related to content, such as web pages, file names, User Agent Strings, Java Script, and images.

[0146] The DPI engine (1210) can also extract metadata for OT protocols such as industrial application protocols or engineering protocols.

[0147] For example, it can also generate metadata for MODBUS, a network communication protocol encapsulated in the payload of TCP, DNP3, widely used in the energy sector, and BACnet and KNX protocols, which are mainly used in smart buildings.

[0148] The core engine (1212) can separate data transmitted within a packet according to a layer or industry-specific protocol by type and transmit the data to a queue storage unit (1220) according to the data type. The queue storage unit (1220) is arranged in parallel according to the data, so that horizontal scalability is possible according to the data type and size.

[0149]

[0150] The detection unit (1300) performs malware analysis, behavior analysis, and OT anomaly analysis from metadata, files, and PCAP packet files output by the analysis unit (1200) to profile malware, malicious behavior, etc., and can identify threats from each data.

[0151] The detection unit (1300) can identify threats using a score method of a correlation analysis threat identification method, thereby reducing errors and detecting stable and accurate threats.

[0152] For example, the detection unit (1300) can identify threat factors by accumulating scores based on correlation and statistical analysis of each threat factor of metadata, files, and PCAP packet files.

[0153]

[0154] FIG. 6 discloses another embodiment of a cyber threat information processing device according to an embodiment.

[0155] Another embodiment of the cyber threat information processing device (1000) in this drawing may include a high-speed packet collection engine (1150), a protocol data analysis unit (1250), a threat detection unit (1350), a threat information management unit (1380), and an intelligence processing unit (1400).

[0156] The high-speed packet collection engine (1150) can collect packets in real time at high speed.

[0157] The high-speed packet collection engine (1150) utilizes the processor's core separation technology so that when the kernel schedules other processes, it can use the separated processor core exclusively without using the processor.

[0158] The high-speed packet collection engine (1150) can store collected packets in shared memory so that the protocol data analysis unit (1250) can process them in parallel.

[0159]

[0160] The protocol data analysis unit (1250) can secure visibility into data of all layers according to the packet structure according to the characteristics of the network protocol.

[0161] The protocol data analysis unit (1250) can extract data and metadata on the protocol of IT networks and OT networks.

[0162] The protocol data analysis unit (1250) can classify data according to the protocol and classify metadata and files accordingly, and can change data of the same source / destination into a file of a PCAP packet of a single session and then generate and store metadata according to the PCAP packet.

[0163]

[0164] The threat detection unit (1350) can identify and detect threat factors from data analyzed by the protocol data analysis unit (1250) and provide the results to the monitoring unit (2000).

[0165] When the threat detection unit (1350) identifies a threat element from abnormal events in the metadata extracted or generated as above and data within the payload of a packet, it can perform highly reliable threat element detection by evaluating the threat and threat level based on contextual information based on correlation analysis.

[0166] The threat detection unit (1350) can perform malware detection, behavior analysis-based detection, and OT anomaly detection from input network traffic.

[0167] (a) Malware detection

[0168] The threat detection unit (1350) can detect known malware using indicators of compromise (IoCs) from network traffic. Furthermore, the threat detection unit (1350) can detect unknown malware using machine learning techniques.

[0169] The threat detection unit (1350) disassembles files within network traffic into binary data, converts them, and uses machine learning to identify attackers and attack behaviors in unknown files. The threat detection unit (1350) can detect malware using a learning model based on the Random Forest algorithm, based on the characteristics of the binary data in the files.

[0170] And it can identify advanced persistent threats (APTs) based on defined rules such as YARA rules.

[0171] The threat detection unit (1350) can classify predefined signatures as malware based on defined rule-based strings or binary patterns (hex strings). The threat detection unit (1350) can identify malware by specifying a specific entry point value or using pattern matching based on regular expressions such as file offsets or virtual memory addresses.

[0172] (b) Behavior analysis-based detection

[0173] The threat detection unit (1350) can detect attack tactics, techniques, and procedures (TTPs) based on behavioral analysis of data included in network traffic.

[0174] The threat detection unit (1350) can detect attacks based on behavioral analysis through threat detection according to multiple behavioral rules. The threat detection unit (1350) applies various AI-based anomaly detection techniques to numerous features extracted from network traffic. Furthermore, the threat detection unit (1350) can evaluate network traffic for anomalies by generating hundreds or more anomaly models profiled through entity modeling at the device / peer group / network level.

[0175] The threat detection unit (1350) can evaluate whether an anomaly exists by comparing the extracted features with the device's past patterns (device modeling), evaluating distinctiveness within a cluster (peer group modeling), investigating rarity across the entire network, and calculating an anomaly score using an anomaly model.

[0176] The threat detection unit (1350) can detect threat factors in an abnormality model by calculating a threat score for one or more abnormal events through a threat detector.

[0177] (c) OT anomaly detection

[0178] The Threat Detection Unit (1350) exists to manage physical operations in OT environments designed to maintain safety, uptime, and productivity, particularly in various industrial sectors that benefit from automation and mechanization. The Threat Detection Unit (1350) can detect threats using whitelist-based anomaly detection technology and ML-based anomaly detection technology for process values ​​in time series to detect anomalies in OT environments designed to maintain safety, uptime, and productivity.

[0179] The threat detection unit (1350) can detect threat factors based on a whitelist and a sensor time series.

[0180] When the threat detection unit (1350) analyzes whitelist-based data, it can extract the command fields of the protocols contained in the data to detect threats such as malformed communication or application misuse. Additionally, the threat detection unit (1350) can understand the specialized meaning of each OT protocol, map and analyze detailed message fields for each command, as well as request and response messages, into a pair of sessions, and statistically select acceptable packets.

[0181] When the threat detection unit (1350) detects a threat element based on the sensor's time series, it can configure a specific process value extracted from the packet into a time series and compare it with a model trained through machine learning to check for abnormalities.

[0182] The threat detection unit (1350) allows the administrator to conduct preliminary tests on models created through selective machine learning of specific processes to verify accuracy performance.

[0183] (d) Correlation analysis

[0184] When the threat detection unit (1350) detects a threat by performing malware detection, behavior analysis-based detection, and OT anomaly detection on packet metadata and payload data, it is possible to identify whether the detected threat is an actual threat technology through correlation analysis.

[0185] The threat detection unit (1350) may include multiple threat detectors for correlation analysis. These multiple threat detectors can perform multiple artificial intelligence (AI)-based anomaly detections and perform correlation analysis across various contexts to identify threat techniques using defined rules.

[0186]

[0187] Meanwhile, the intelligence processing unit (1400) can receive executable or non-executable files included in the payload of a packet from the protocol data analysis unit (1250). In addition, the intelligence processing unit (1400) can receive files, metadata, applications, etc. analyzed from network traffic from the threat detection unit (1350).

[0188] The intelligence processing unit (1400) may, when seeking to detect and identify detailed cyber threat information based on an executable file or non-executable file, transmit the executable file or non-executable file, or its analyzed metadata, to the cyber threat intelligence system.

[0189] The cyber threat intelligence system can identify attack tactics, techniques, and procedures (TTPs) for received files, and provide profiling results such as attackers of advanced persistent threats (APTs) and identifiers of attack behaviors (including attack behavior identifiers based on the MITRE ATT&CK Matrix).

[0190]

[0191] The threat information management department (1380) can derive risk factors for assets including IT assets, OT infrastructure, and IoT devices, which are the objects of information acquisition through examples of cyber threat information devices, and produce protection measures and visualization information.

[0192] The threat information management unit (1380) provides a means for building and monitoring management information on various assets related to network traffic analyzed by an embodiment of the cyber threat information device.

[0193] For example, the Threat Information Management Unit (1380) can build a list of managed assets and detailed information related to threat information. The Threat Information Management Unit (1380) can build the IP / MAC address, vendor and type information, model serial information, and firmware information for each asset, and monitor software versions.

[0194] The threat information management department (1380) can build a network map of managed assets and provide visualization information through the monitoring department (2000).

[0195] The threat information management department (1380) can identify vulnerabilities in each managed asset and provide the vulnerability information through the monitoring department (2000).

[0196]

[0197] Figure 7 discloses another embodiment of a cyber threat information processing policy according to an embodiment.

[0198] Another embodiment of the cyber threat information processing device (1000) of this drawing may include a high-speed packet collection engine (1150), a protocol data analysis unit (1250), and a threat detection unit (1350). In addition, the cyber threat information processing device (1000) may utilize data and applications stored in a separate storage / database under the control of a computing server responsible for data processing. Here, the storage primarily uses a hard disk or SSD to store data, and the database manages structured data and can perform tasks such as searching and modifying. In this case, the functions performed by the cyber threat information processing device (1000) may be performed by the processor of the computing server. Hereinafter, the details described above with reference to FIG. 6 will be omitted.

[0199] The cyber threat information processing device (1000) can collect packets in real time from an enterprise network (IT) and an OT / IT smart convergence network. Here, the enterprise network is generally a network used in offices, data centers, cloud services, etc., and may include servers, workstations, routers, and switches, while the OT / IT smart convergence network is a convergence of OT (Operational Technology) networks and IT networks used in all industrial fields such as manufacturing, energy, and transportation, and may include PLC (Programmable Logic Controller), SCADA systems, and IoT devices.

[0200] The cyber threat information processing device (1000) can collect packets through a high-speed packet collection engine (1150) and analyze the collected packets through a protocol data analysis unit (1250).

[0201] More specifically, the protocol data analysis unit (1250) may include an IT protocol metadata extraction unit and an OT protocol metadata extraction unit.

[0202] The IT protocol metadata extraction unit can capture packets, extract metadata, and analyze payloads through a network packet capture tool (e.g., PCAP library) and a high-speed packet collection engine (1150). For example, the IT protocol metadata extraction unit can extract metadata for each protocol, such as ARP, DHCP, DNS, HTTP, IMAP, POP3, NFS, ICMP, FTP, VNC, NETIOS, MS-SQL, MYSQL, NTP, MDNS, and XDMCP.

[0203] The OT protocol metadata extraction unit can extract metadata from packets by applying different packet analysis techniques based on manufacturer-specific protocols and network settings in industrial control systems.

[0204] The asset management department, threat detection department (1350), and threat response department can receive data collected and analyzed through the high-speed packet collection engine (1150) and the protocol data analysis department (1250).

[0205] The asset management unit can perform asset management and vulnerability management based on analyzed network connection information and metadata. More specifically, the asset management unit can create and manage a list of devices connected to the network, check the software and firmware versions of the devices, and check for known vulnerabilities.

[0206] The threat detection unit (1350) can perform malware detection, behavioral analysis-based detection, OT anomaly detection, and correlation analysis-based threat identification based on analyzed metadata and payloads. For more information, please refer to the above-mentioned information.

[0207] Additionally, the threat response unit can conduct investigations / forensics and analyze APTs based on analyzed metadata, payloads, and raw packets. More specifically, the threat response unit detects events (e.g., abnormal traffic), collects metadata from the detected events, analyzes detailed packets based on the collected metadata, and analyzes the root cause of security incidents through forensic investigations of the analyzed packets. Furthermore, it can identify and analyze Advanced Persistent Threats (APTs) to respond to detected threats.

[0208]

[0209] FIG. 8 discloses an embodiment of a high-speed packet collection engine according to an embodiment.

[0210] The high-speed packet collection engine (1150) of this drawing can process packet processing that was performed in kernel space in user space.

[0211] The high-speed packet collection engine (1150) provides software that processes network packets in place of the operating system kernel. By allocating dedicated CPU cores, it can directly receive packets received from the network interface card without going through the kernel. This allows for high-speed, real-time packet collection, overcoming the packet processing speed of the operating system.

[0212] The high-speed packet collection engine (1150) can directly manage hardware resources such as network interface cards (NICs). More specifically, the high-speed packet collection engine (1150) can provide a channel for direct access to the network interface card by passing through the Linux kernel using an environment abstraction layer (EAL).

[0213] In one embodiment, a cyber threat information processing device utilizing a high-speed packet collection engine (1150) may implement batch packet processing technology, an I / O optimization technology for processing multiple packets. More specifically, the analysis unit of the cyber threat information processing device may improve performance by reducing the number of transmissions between the CPU and memory by using a batch method of enqueue and dequeue, which processes multiple packets at once rather than processing them one by one.

[0214] The collection unit of the cyber threat information processing device can use large memory pages of 1GB in size to reduce TLB misses (Translation Lookaside Buffer Misses).

[0215] The collection unit of the cyber threat information processing device can utilize an optimized, pool-based NIC driver. More specifically, unlike interrupt-based drivers, the cyber threat information processing device uses a polling-based driver. This allows the CPU to periodically poll the NIC status and process packets, maintaining stable performance even in high network traffic situations.

[0216] The collection unit of a cyber threat information processing device can utilize CPU core isolation technology. More specifically, the cyber threat information processing device can guarantee CPU resources for specific tasks and reduce thread switching overhead by dedicating specific CPU cores to specific tasks and excluding them from other general tasks.

[0217] The analysis unit of a cyber threat information processing device can pre-allocate fixed-length memory for network packets. More specifically, dynamic memory allocation and deallocation can be time-consuming. To overcome this, the cyber threat information processing device can reduce overhead by pre-allocating fixed-length memory. In one embodiment, the cyber threat information processing device can manage fixed-length packet buffers using structures called a memory pool and a memory buffer. Here, the memory pool is a set of fixed-length buffers, and the memory buffer corresponds to a basic unit for storing packet data.

[0218] The analysis unit of a cyber threat information processing device can implement a lockless or lock-free queue to prevent unnecessary waiting time. More specifically, the cyber threat information processing device can implement a lockless queue by accessing a shared data structure to accelerate packet processing. Here, a lockless queue is a queue that operates without using locks even when multiple threads or processes access data simultaneously, thereby reducing bottlenecks that occur during the process of acquiring and releasing locks. The lockless queue can be implemented using atomic operations, compare-and-swap (CAS) operations, or memory barriers.

[0219] The analysis unit of a cyber threat information processing device can provide horizontal scalability through a run-to-complete model. More specifically, the analysis unit of the cyber threat information processing device can store collected packets in distributed queue storage units (not shown) to analyze them. The stored data enables high-performance packet processing through each core. For example, the metadata core can create, manage, and store metadata related to packet data; the file core can store packet data in a file system or read data from a file; and the PCAP core can capture packets and record them in a PCAP file.

[0220] For this, please refer to the contents described above in FIGS. 4 and 5.

[0221]

[0222] FIG. 9 discloses an embodiment of a cyber threat information processing method according to an embodiment.

[0223] A method for processing cyber threat information according to one embodiment can collect packets from network traffic (S1110). The embodiment can collect packets in real time from an enterprise network (IT) and an OT / IT smart convergence network. For a detailed description, please refer to the description above in FIG. 7.

[0224] A method for processing cyber threat information according to an embodiment may provide a path for accessing a network interface card via a high-speed processing library and an abstraction layer (S1120). The embodiment provides a high-speed processing library, which is software for processing network packets, instead of an operating system kernel, and directly receives packets received from a network interface card via an abstraction layer that connects the software high-speed processing library and the hardware network interface card. For a detailed description thereof, please refer to the description above in FIG. 8.

[0225] According to one embodiment, a method for processing cyber threat information can process data packets collected from an accessed network interface card using software (S1130). At this time, the data packets collected from the network interface card are received using a polling method without passing through a kernel. Furthermore, the data packets received using the polling method are allocated to a first CPU core, and the first CPU core processes only the data packets. In the embodiment, the collected data packets are stored in memory pages larger than a first size. For a detailed description thereof, please refer to the description given above in FIG. 8.

[0226] A method for processing cyber threat information according to one embodiment may analyze data contained in collected packets according to a protocol or application, detect cyber threat information from the data according to the analyzed protocol, and then provide analysis information on the detected cyber threat information. For a detailed description, please refer to the descriptions provided above in FIGS. 1 through 6.

[0227]

[0228] FIG. 10 is a drawing disclosing another embodiment of a cyber threat information processing device according to an embodiment.

[0229] The cyber threat information processing device (1000) collects and analyzes various network traffic in real time to detect and respond to potential security threats. In particular, the cyber threat information processing device (1000) analyzes traffic generated in IT and OT environments and can detect APT attacks.

[0230] In one embodiment, the cyber threat information processing device (1000) includes an APT response system and 3 in addition to a cyber threat intelligence system. rd It can be integrated with party software.

[0231] More specifically, the cyber threat information processing device (1000) can collect AI insights, network black boxes, and threat information based on the above-described embodiment. The cyber threat information processing device (1000) can transmit the collected information to a cyber threat intelligence system, an APT response system, and 3, which are systems linked to the cyber threat information processing device (1000). rd It can be analyzed through at least one of the party software.

[0232] For example, the cyber threat information processing device (1000) can analyze the threat type, vulnerability (CVE-ID), and tag (characteristic information) of the collected file in conjunction with the cyber threat intelligence system, and can analyze the attack group, campaign, target country of attack, target industry information, occurrence time information, etc. associated with the collected file.

[0233] In addition, as another example, the cyber threat information processing device (1000) is provided by another cyber security company. rd It can be integrated with third-party software to provide additional analysis information along with anti-virus engine detection information.

[0234] The cyber threat information processing device (1000) collects data according to the above-described embodiment and transmits it to a cyber threat intelligence system, an APT response system, and other 3 linked systems. rd After analysis through party software, the analyzed information can be generated and provided as malware file analysis information, used for in-depth analysis of malware and abnormal behavior, or used for detailed analysis of network packets.

[0235] Through this, the cyber threat information processing device (1000) can respond to cyber threats by collecting information from network traffic, identifying and analyzing it, and providing cyber threat information in conjunction with other external systems.

[0236]

[0237] FIG. 11 is a diagram disclosing an example of metadata extraction of a DPI engine according to an embodiment.

[0238] The DPI (Deep Packet Inspection) engine within the cyber threat information processing device (1000) extracts metadata (IP, protocol, application, event data, etc.) from network packets collected according to the above-described embodiment, stores them in a database, and then analyzes the binary data of the packets to determine whether they are malicious.

[0239] More specifically, the DPI engine (1210) can inspect the contents of packet data passing through the network up to the Layer 7 (L7) level, unlike existing packet filtering that only inspects packet headers at the Layer 2 (L2) to Layer 4 (L4) level. That is, the DPI engine can analyze L7 protocols (e.g., HTTP, FTP, SMTP, POP3, IMAP, SMB protocols) to extract files being transmitted and received, and distinguish applications using L7 protocols. In addition, the DPI engine (1210) can analyze the characteristics of packets to identify the operating system.

[0240] The DPI engine (1210) can check detailed traffic information by providing the IP address of the source that started the session (SRC IP), the IP address of the destination of the session (DST IP), protocol, and application information for each session, which is a connection between two endpoints.

[0241] More specifically, the DPI engine (1210) can rearrange and store the order of packets. The cyber threat information processing device (1000) can separately capture and store packets traveling between two endpoints (e.g., P1 and P2) during the network packet collection phase. That is, the DPI engine (1210) can store all packets traveling from P1 to P2 in one PCAP file, and all packets traveling from P2 to P1 in another PCAP file. The DPI engine (1210) can analyze the contents of the packets by reading each PCAP and rearranging the order of the packets.

[0242] Due to limitations on the maximum frame size of data that can be transmitted in an Ethernet network, data must be transmitted in fragmented packets. In one embodiment, the DPI engine (1210) can reassemble the fragmented packets into complete information.

[0243] In one embodiment, the DPI engine (1210) may monitor and reassemble all packets traveling between each source and destination, and then store the packets in separate buffers for the client and server. The DPI engine (1210) may process all transmitted and received packets as a single session to generate metadata.

[0244] For example, the DPI engine (1210) can extract IT network metadata such as the following.

[0245] (1) Web Application

[0246] The URL of the webpage the user visited, the name of the file downloaded or uploaded, information about the browser and operating system used by the user, the JavaScript code executed on the webpage, and the image files included in the webpage.

[0247] (2) Email (SMTP, IMAP, etc.)

[0248] The email address of the sender of the email, the email address of the recipient, the subject of the email, the name and contents of any files attached to the email, and the email client information.

[0249] (3) Internal file sharing (SMB, etc.)

[0250] Information about the client accessing the file sharing server (IP address, etc.), the file sharing path and file name accessed by the user.

[0251] (4) Documents (MS Office, PDF, HWP, etc.)

[0252] The URL of the webpage that contains the document, the document file name, information about the software used to open the document file, any JavaScript code executed within the document, and any image files contained within the document.

[0253] (5) Executable file

[0254] The executable file name, a hash value (MD5, SHA-1, etc.) to uniquely identify the file, the date the file was created, and information about the operating system on which the file is being run.

[0255] (6) Certificate

[0256] The type of certificate (SSL / TLS, code signing, etc.), the authority that issued the certificate, and the name of the certificate owner.

[0257] (7) Other

[0258] Flash objects executed, JavaScript code executed within a web page or application, or XML data exchanged.

[0259] The OT network metadata extracted by the DPI engine (1210) will be described later.

[0260]

[0261] FIG. 12 is a diagram disclosing an example of OT network metadata extracted from a DPI engine according to an embodiment.

[0262] The DPI engine can extract the following OT network metadata (12101a, 12101b) from the OT protocol packets (12100a, 12100b) based on the above-described embodiment. This drawing illustrates an example of metadata extracted by the DPI engine based on an industrial control protocol standard, but the metadata extracted by the DPI engine of the present invention is not limited thereto.

[0263] - For MODBUS, the type of command, the starting address of the data, the length of the data, the number of requested data, and the data value actually transmitted.

[0264] - For DNP3, the type of command, the group type of data, the transformation type of data, the qualifier information of the data, and the actual data value transmitted.

[0265] - For BACnet, the type of object, the instance number of the object, the ID of the attribute, the value of the attribute, and the type of service request.

[0266] - For KNX, group address, application command, transmitted data value, device address

[0267] At this time, the DPI engine can reconstruct (12102a, 12102b) the extracted metadata by considering the context for each protocol, rather than simply parsing the syntax for various industrial control protocols. In one embodiment, the DPI engine can analyze the meaning of each field of the extracted metadata to generate semantic metadata (12102a, 12102b) that reconstructs items corresponding to commands, process variables, and values, which are structures defined for OT anomaly analysis.

[0268]

[0269] FIG. 13 is a diagram disclosing another embodiment of OT network metadata extracted from a DPI engine according to an embodiment.

[0270] The DPI engine can extract engineering protocol metadata from OT network metadata. This drawing illustrates an example of metadata extracted by the DPI engine based on OT network protocol standards, but the metadata extracted by the DPI engine of the present invention is not limited to this.

[0271] More specifically, the DPI engine can extract detailed information from major manufacturers about the communication protocols their systems use. This detailed information can include technical specifications for how each device or system exchanges data.

[0272] In one embodiment, the DPI engine may monitor PLC (Programmable Logic Controller) events of an industrial control system that controls and automates machinery, extracting metadata associated with events such as which IP address restarted or stopped the PLC, or which user downloaded firmware.

[0273] The cyber threat information processing device (1000) processes the extracted metadata into the cyber threat intelligence system, APT response system, and 3 rd It is possible to respond to cyber threats by linking with party software.

[0274]

[0275] Figure 14 is a drawing explaining information provided by a cyber threat information processing device according to an embodiment.

[0276] The cyber threat information processing device extracts metadata based on the above-described embodiment, and transmits it to the linked cyber intelligence system, APT response system, and 3 rd It can analyze information on cyber threats and provide analyzed information by linking with party software.

[0277] In one embodiment, the cyber threat information processing device may provide information identified by IP, information identified by protocol, and information identified by application from the extracted metadata. In this case, the cyber threat information processing device may provide a list by IP (20001), a list by protocol (20002), and a list by application (20003), enabling network information to be verified based on each piece of information.

[0278] The cyber threat information processing device can provide a filtered list of source and target IP information, protocols, and applications from the entire network information collected through the DPI engine. To achieve this, the cyber threat information processing device can structure and store the entire collected network traffic information in a database and retrieve statistical data and lists for each classification value.

[0279] Each list contains the following information:

[0280] (1) IP List (20001): Session-specific information identified by IP, full IP list and IP-specific statistics and session information.

[0281] (2) Protocol List (20002): Protocol list and protocol-specific statistics and session information

[0282] (3) Application List (20003): Application list and session information for each identified application.

[0283] Through this, users can monitor all network traffic information by visualizing the invisible network at a glance.

[0284]

[0285] Figure 15 is a flowchart illustrating an embodiment of a cyber threat information processing method according to an embodiment.

[0286] In one embodiment, the cyber threat information processing method can collect data packets contained in network traffic (S1210). For more information, please refer to the details described above in FIG. 7.

[0287] In one embodiment, a method for processing cyber threat information may analyze a data packet according to the layers of an open system interconnection model, and extract metadata from the session layer, presentation layer, and application layer of the data packet (S1220). In one embodiment, the method for processing cyber threat information may analyze the meaning of fields of the extracted metadata and reconstruct items corresponding to commands, process variables, and values, which are defined structures, to generate semantic metadata. In one embodiment, the extracted metadata is characterized as metadata related to events for a control device within an industrial operations management computing system. For this, refer to the contents described above with reference to FIGS. 11 to 13.

[0288] In one embodiment, the cyber threat information processing method can detect cyber threat information based on analyzed data packets (S1230). In one embodiment, the cyber threat information processing method can detect cyber threat information by interfacing with an external system, transmitting extracted metadata to the external system, and receiving analysis results from the external system. For further details, please refer to the details described above in FIG. 10.

[0289] In one embodiment, the cyber threat information processing method may provide analysis information on detected cyber threat information (S1240). In one embodiment, the cyber threat information processing method may provide information identified by IP, protocol, and application among the extracted metadata. For more information, please refer to the details described above in FIG. 14.

[0290]

[0291] Figure 16 discloses another embodiment of a cyber threat information processing policy according to an embodiment.

[0292] Another embodiment of the cyber threat information processing device (1000) of this drawing may include a high-speed packet collection engine (1150), a protocol data analysis unit (1250), a threat detection unit (1350), and a threat information management unit (1380). In one embodiment, the high-speed packet collection engine (1150) may be described as an embodiment of the collection unit (1100) of the cyber threat information processing device (1000), the protocol data analysis unit (1250) may be described as an embodiment of the analysis unit (1200), and the threat detection unit (1350) may be described as an embodiment of the detection unit (1300).

[0293] The high-speed packet collection engine (1150) can collect packet data included in network traffic between a source (SRC) and a destination (DST). In one embodiment, the high-speed packet collection engine (1150) can collect packet data at high speed by polling packets received on a network interface card without using a kernel using a high-speed processing library.

[0294] The protocol data analysis unit (1250) can analyze packet data to extract flow information about the packet data. In one embodiment, the protocol data analysis unit (1250) can analyze data included in the packet data according to a protocol or application. In one embodiment, the protocol data analysis unit (1250) can generate metadata corresponding to the protocol or application. In one embodiment, the flow information can include at least one of an IP and a port of a source and a destination, and at least one of a protocol, application, and metadata about network traffic.

[0295] In one embodiment, the flow information may further include at least one of host information and operating system information. Here, the host information may include identification information and version information about a host (e.g., a computer, server, device, etc.) that includes a source and destination connected to the network. For example, the server may include a server operated by an organization corresponding to the source or destination, such as a server that is an internal asset.

[0296] In one embodiment, the protocol data analysis unit (1250) can check the status of the corresponding port to determine which ports are open at the source and destination, and their status. Here, the open port can be used for network communication, and can be used to determine which application-based service is running.

[0297] In one embodiment, the protocol data analysis unit (1250) can identify which application-based services or protocols are running at the source and destination through open ports. In one embodiment, the protocol data analysis unit (1250) can determine which server is operating at which version based on flow information.

[0298] In one embodiment, the monitoring target of ASM may include internal assets and information about the internal assets, such as applications that directly operate services via servers corresponding to IPs and internal assets. In one embodiment, the protocol data analysis unit (1250) may identify vulnerabilities in assets operated by an organization corresponding to at least one of the source and destination, or assets that are not owned by the organization but are part of the organization's infrastructure or supply chain (e.g., cloud). In one embodiment, the monitoring target of ASM may include applications that directly operate services via servers.

[0299] The threat detection unit (1350) can generate vulnerability information corresponding to flow information based on vulnerability-related information contained in a predefined vulnerability database. In one embodiment, the threat detection unit (1350) can generate vulnerability information by performing ASM (Attack Surface Management) using flow information based on network traffic collection. According to the present invention, ports or vulnerabilities with potential attacks can be discovered and managed through ASM.

[0300] In one embodiment, vulnerability information may include at least one of information on the presence or absence of a vulnerability, vulnerability type, and vulnerability details for the corresponding flow information. For example, the threat detection unit (1350) may determine whether a port included in the flow information has a vulnerability.

[0301] The threat detection unit (1350) can generate vulnerability information by comparing flow information with an external vulnerability database or a vulnerability database stored in a cyber threat information processing device (1000). In one embodiment, the vulnerability database may follow standards such as Common Vulnerabilities and Exposures (CVE) and may include various vulnerability-related information. In one embodiment, the vulnerability-related information included in the vulnerability database may include a CVE (Common Vulnerabilities and Exposures) number for the vulnerability type, vulnerability details, and vulnerability severity information. In one embodiment, the vulnerability-related information included in the vulnerability database may include information on various vulnerabilities and risks, including assets that are leaked and exploited.

[0302] The threat information management unit (1380) can provide users with identified vulnerability information. In one embodiment, the threat information management unit (1380) can provide vulnerability information in various visual formats, such as text or graphs.

[0303] In one embodiment, the cyber threat information processing device (1000) may utilize data and applications stored in a separate storage / database under the control of a computing server responsible for data processing. Here, the storage primarily uses a hard disk or SSD to store data, and the database manages structured data and can perform tasks such as searching and modifying. In this case, the functions performed by the cyber threat information processing device (1000) may be performed by the processor of the computing server. The details described in FIG. 6 (base specification) will be omitted below.

[0304] According to one embodiment of the present disclosure, ASM can be used to identify asset vulnerabilities, thereby enabling the application of security controls and the strengthening of cybersecurity strategies and policies for these assets. In one embodiment, identifying asset vulnerabilities can be used to strengthen cybersecurity strategies and policies for these assets, such as the application of security controls (e.g., operating system or software patches), the establishment and disposal of security standards for unknown or unmanaged assets, and the removal of malicious assets.

[0305]

[0306] FIG. 17 discloses an embodiment of active ASM execution based on network traffic collection according to an embodiment.

[0307] In one embodiment, the cyber threat information processing device (1000) can acquire network traffic transmitted by a source and a DST. Furthermore, the cyber threat information processing device (1000) can perform a DPI (Depth Packet Inspection) analysis on packet data included in the acquired network traffic to generate flow information.

[0308] In this case, DPI can deeply analyze packet data on the network to identify protocols or applications related to the packet data or collect metadata. Based on the protocols, applications, or collected metadata identified through DPI, security vulnerabilities, malicious activity, and abnormal traffic can be detected. For more information, see the above.

[0309] In one embodiment, the flow information may include at least one of an IP address and port of a source and a destination, and at least one of a protocol, application, and metadata for the network traffic. Accordingly, the cyber threat information processing device (1000) can identify which source and destination use which protocol and application based on which IP address and port through the flow information.

[0310] In one embodiment, the cyber threat information processing device (1000) can provide vulnerability information corresponding to flow information. That is, elements with a high possibility of external attack can be identified, and vulnerabilities for those elements can be preliminarily reviewed and managed.

[0311] In other words, the existing ASM performs a port and IP scan when all network IP ranges are entered, and checks which ports are open and which vulnerabilities exist. In this case, network resources are severely consumed, and if the IP input range is entered incorrectly, the problem of scanning external third-party networks may occur, and if the actual port or service is not open at the time of scanning, the problem of not being able to scan may occur. Furthermore, the scan may not be performed properly due to firewalls, network configurations, etc.

[0312] Accordingly, according to the present disclosure, without the need to perform a network scan, the cyber threat information processing device (1000) can receive network traffic, identify flows, protocols, and applications from packet data, and accumulate and manage which ports each IP has, which protocols it has, and which services it provides.

[0313] In one embodiment, when the first handshaking between the source and the destination, i.e., when this session is first created, the version of the server (server providing content service) of the port servicing the application can be identified through the protocol by checking the first few bytes of a certain number. In one embodiment, the bytes may include bytes of packets transmitted and received during handshaking for communication between the source and the destination. In this case, by analyzing the first few bytes (or packets) of a certain number (e.g., N) of bytes during the handshaking process for creating a session, a certain pattern of the bytes can be determined, and flow information such as a server or service corresponding to the certain pattern can be identified. In one embodiment, at least one of server identification information and the server version can be identified by analyzing the first few bytes of a certain number of service-specific banner messages or Hello messages transmitted and received between the source and the destination. In this case, information about the counterpart server can be acquired during the handshaking process. When extracting metadata like this, you can compare it with a vulnerability database to determine what vulnerabilities the server you are actually servicing has and provide that information.

[0314] In this way, according to the present disclosure, even without performing a network scan, the effect of performing a network scan from packet data can be achieved by confirming transmitted and received packet data.

[0315] In one embodiment, after identifying a system or service with a high attack potential, DPI can be performed to deeply analyze traffic to that system or service, enabling detection and response to security threats. Furthermore, security vulnerabilities in areas with a high attack potential identified through ASM can be verified and supplemented through DPI analysis of actual traffic. In one embodiment, threats to points identified through ASM can be analyzed and detected through DPI, and descriptions of the points detected after DPI analysis can be supplemented with ASM.

[0316]

[0317] FIG. 18 discloses another embodiment of active ASM performance based on network traffic collection according to an embodiment.

[0318] In one embodiment, the cyber threat information processing device (1000) can analyze packet data to extract flow information about the packet data. In one embodiment, information about the destination IP (DSP IP), destination port (DST Port), protocol, and application can be extracted.

[0319] For example, the destination IP address might be 142.25.66.35, the destination port might be 443, the protocol might be QUIC, and the application might be a Shared Services or Static application. In this case, flow information might be accumulated based on data transmission and reception between the source and destination.

[0320] In one embodiment, according to the present disclosure, a service server can be identified without actually scanning. For example, the cyber threat information processing device (1000) can identify the server version of a web server providing a statistics application service via port 443.

[0321] In one embodiment, the cyber threat information processing device (1000) can compare the server version and port with a vulnerability database to determine whether there is a vulnerability.

[0322]

[0323] Figure 19 is a flowchart illustrating one embodiment of a cyber threat information processing method according to an embodiment.

[0324] Collect packet data contained in network traffic between a source and a destination (S1310). In one embodiment, packet data can be collected at high speed by polling packets received on a network interface card without using the kernel using a high-speed processing library. For a detailed description of this, please refer to the description above in FIG. 16.

[0325] Packet data is analyzed to extract flow information about the packet data (S1320). In one embodiment, the flow information may include at least one IP and port of the source and destination, a protocol for network traffic, an application, and at least one of metadata. In one embodiment, an open port for at least one IP of the source and destination may be determined, and at least one of the protocol, application, and metadata may be identified based on the open port. For a detailed description thereof, please refer to the contents described above in FIGS. 16 to 18.

[0326] In one embodiment, at least a portion of packet data included in network traffic according to handshaking of a source and a destination may be analyzed, and flow information including a server version of at least one of the source and the destination corresponding to a port servicing an application through a protocol for the network traffic may be extracted based on the analysis result.

[0327] Vulnerability information corresponding to the flow information is provided based on vulnerability-related information contained in a predefined vulnerability database (S1330). In one embodiment, when vulnerability-related information for flow information is retrieved from the predefined vulnerability database, vulnerability information corresponding to the flow information may be provided. For a detailed description thereof, please refer to the contents described above in FIGS. 16 to 18.

[0328]

[0329] FIG. 20 is a drawing disclosing another embodiment of a cyber threat information processing device according to an embodiment.

[0330] The cyber threat information processing device (1000) may further include a natural language model (LLM / sLLM, 2320) within the intelligence processing unit (1400). At this time, the natural language model (2320) may be located within or outside the intelligence processing unit (1400). Even if the natural language model (2320) is located outside the intelligence processing unit (1400), the cyber threat information processing device (1000) can of course utilize the functions of the natural language model (2320).

[0331] The intelligence processing unit (1400) can generate explanatory information or threat query answers of profiled threat information using data analyzed in relation to intelligence profiling processing using an artificial intelligence-based natural language model.

[0332] The natural language model (2320) of the intelligence processing unit (1400) can generate natural language answers to threat queries based on network protocol / application data, files, and various cyber threat information (threats) analyzed by the cyber threat information processing device (1000).

[0333] The natural language responses generated thereafter can be transmitted to the client system via an application program interface (API, not shown). The natural language threat query responses generated by the natural language model (2320) can be provided to the client system along with the threat analysis results generated in this manner.

[0334] The threat query response includes a natural language description of the cyber threat information (threat) inquired about in relation to data analyzed and extracted from network traffic by the cyber threat information processing device (1000), including whether the information is malicious, an attack action, an attack technique, an attack group, or an attack campaign in which multiple attack actions are linked.

[0335] In addition, for inquiries about binary data such as the assembly code of a file included in network traffic and the functions included in that data, explanatory information can be provided as to whether it is related to malware or not based on the results of analysis by a client system (e.g., a cyber threat intelligence system).

[0336] Additionally, the natural language model (2320) generates natural language explanations for threat queries submitted by the client system and additional threat queries provided by the framework (2200), and provides natural language answers related to threat queries to the user of the client system.

[0337] In the embodiment, since the cyber threat information processing device (1000) provides analyzed or pre-analyzed information along with natural language, even if the user is a non-expert, easy and accurate information transmission and response to cyber threat information are possible.

[0338]

[0339] More specifically, the application program interface (API, not shown) of the cyber threat information processing device (1000) can receive a file, a request for analysis of cyber threat information (CTI) related to a file, or a query related to CTI from a client system.

[0340] The framework (2200) of the application programming interface may include multiple analysis modules or prediction modules (referred to as N modules in the drawing, 2220). When the framework (2200) receives a file from a client system, it may obtain binary data at the assembly level through disassembly. Based on this, the framework (2200) may perform analysis of functions related to whether or not the file is malicious, analysis of attack behavior or attack techniques, analysis of attack groups, and analysis of sequences of binary data blocks (hereinafter referred to as instruction sequences) according to call correlations of functions included in the binary data.

[0341] The framework (2200) can analyze whether the input file is a non-executable file such as a document file, whether the file is malicious, the attack behavior or attack technique, and the attack group.

[0342] The server (2800), whether an on-premise server or a cloud server, performs crawling to collect web pages on the Internet, and the framework (2200) can analyze whether the collected web pages are malicious, perform attack actions or attack techniques, and analyze attack groups.

[0343] The database (2700) can classify and store the results of analysis by the framework (2200) of the cyber threat information processing device (1000), for example, functions of assembly codes generated in the process of analyzing files, whether the functions are malicious, hash codes, instruction sequences, static analysis, dynamic analysis, mild-dynamic analysis, and predictive analysis results, whether partial tags of web pages are malicious, attack techniques corresponding to MITRE ATT&CK, information on attack behavior and attack groups, attack campaigns related to files, attack countries, attack industries, etc.

[0344] Meanwhile, the query module (2230) of the framework (2200) transmits a CTI natural language query with a request for analysis of cyber threat information (CTI) for a specific file, web page, etc., to the natural language model (2320) of the artificial intelligence processing unit (2300).

[0345] The natural language model (2320) may be a natural language model (NLP), a large language model (LLM), or a smaller Large Language Model (sLLM) related to cyber threats or security.

[0346] A request may be made for CTI analysis or prediction related to a file in the client system, or a general natural language CTI query unrelated to the file may be requested. Accordingly, the query module (2230) generates a CTI query or supplementary query based on the cyber threat information (CTI) analyzed by the framework (2200) and transmits it to the natural language model (2320).

[0347] If the client system requests a CTI query unrelated to a file, the query module (2230) passes the CTI query to the natural language model (2320).

[0348] The CTI query language processing unit (2321) can analyze a CTI query using the syntax analysis technology included in the CTI query.

[0349] The CTI query processed in the CTI query language processing unit (2321) is transmitted to the CTI query interpretation unit (2323).

[0350] The CTI query interpretation unit (2323) can perform the function of distinguishing questions based on the sentence structure and meaning of the CTI query processed by the CTI query language processing unit (2321) and recognizing sub-question types and relationships between sub-questions.

[0351] The CTI query interpretation unit (2323) may include a CTI query decomposition unit (2324) and a CTI query analysis unit (2325).

[0352] The CTI query decomposition unit (2324) can perform the function of classifying questions based on the sentence structure and meaning included in the CTI query, classifying sub-question types, and recognizing relationships between classified sub-questions.

[0353] The CTI query analysis unit (2325) can classify the types of distinct sub-questions. Furthermore, the CTI query analysis unit (2325) can identify the core of a question based on the reliability of words or phrases that can be replaced by candidate answers, based on the classified types of sub-questions.

[0354] If the CTI query analysis unit (2325) has a reliability that cannot recognize the core of the question, the CTI query decomposition unit (2324) can be made to reclassify the sub-question types.

[0355] Through the repeated processing of the CTI query decomposition unit (2324) and the CTI query analysis unit (2325), the CTI query analysis unit (2325) can detect and confirm the subject of a CTI-related question.

[0356] The CTI question-answer generation unit (2326) can generate all possible answer candidates from structured or unstructured resources based on CTI questions and question classification information. The CTI question-answer generation unit (2326) may include a CTI answer candidate group generation unit (2327), a CTI answer verification unit (2328), and a CTI answer provision unit (2329).

[0357] The CTI answer candidate generation unit (2327) can perform indexing and search functions from a database (2700) containing cyber threat information (CTI) and generate candidate answers based on the search results. The CTI answer candidate generation unit (2327) generates all possible answer candidates from the database containing cyber threat information (CTI) based on questions and question classification information. Here, the database containing cyber threat information (CTI) includes the database (2700) of the cyber threat information processing device (1000). The CTI answer candidate generation unit (2327) can also collect evidence regarding answer candidates from the database (2700) containing cyber threat information (CTI). This will be described later.

[0358] The CTI Answer Verification Unit (2328) performs the functions of the Answer Inference and Generation Module and can determine and generate the best answer. The CTI Answer Verification Unit (2328) measures the reliability of the answer candidates based on the filtered answer candidates and the inferred answer candidates, thereby determining the ranking of the answer candidates.

[0359] The CTI Answer Verification Unit (2328) can filter answer candidates using inductive, deductive, or abductive reasoning based on the similarity between the query and the answer candidates. Furthermore, the CTI Answer Verification Unit (2328) can compare the confidence ratios of the answer candidates with a threshold value to reorder the answer candidates, thereby selecting the optimal CTI answer.

[0360] The CTI answer provision unit (2329) transmits the CTI answer verified by the CTI answer verification unit (2328) to the cyber threat information processing device (1000) to provide natural language explanation information for the CTI question answer.

[0361] When a client system queries cyber threat information (CTI) together with or separately from a request for cyber threat information (CTI) related to a file, the cyber threat information processing device (1000) can provide information about information related to the CTI file (whether malicious, hash value, attack technique, attack group, attack campaign, etc.), its natural language description, and evidence collected as a basis for the information.

[0362] For example, if a client system makes a query related to the analysis request result of a specific file, the visualization information exemplified above can provide information on which MITRE ATT&CK attack technique by which attack group caused the malicious activity caused by the file, and which attack campaign (a series of mechanisms of one or more attacks) it is connected to. In addition, the cyber threat information processing device (1000) can provide a natural language explanation generated by a natural language model along with the visualization information, and can provide valid digital analysis evidence for the analysis result and natural language explanation analysis evidence for the digital analysis evidence.

[0363] When a client system queries cyber threat intelligence (CTI) unrelated to a file, the CTI query response, a natural language explanation of the CTI query generated by the natural language model, and evidence collected as a basis for the response can be provided.

[0364] The cyber threat information processing device (1000) can provide a client system with a natural language answer or explanation information for a query about the cyber threat information (CTI) analyzed or predicted by the framework (2200) and the cyber threat information (CTI) provided by the self-language model (2320).

[0365]

[0366] The cyber threat information processing device (1000) may include a database (2700) and a server (2800) including a processor.

[0367] A processor driving a cyber threat information processing device (1000) can receive a request for cyber threat information (CTI) analysis on data related to a file from a client system, analyze the requested cyber threat information (CTI), and transmit a first cyber threat information (CTI) query generated based on the analyzed cyber threat information (CTI) to a natural language model (2320).

[0368] And the processor driving the cyber threat information processing device (1000) can provide the analyzed cyber threat information (CTI) and the description information of the analyzed cyber threat information (CTI) generated by the natural language model (2320).

[0369] When a processor driving a cyber threat information processing device (1000) receives a second cyber threat information (CTI) query from a client system, the processor may transmit the second cyber threat information (CTI) query to a natural language model and provide explanatory information for the cyber threat information (CTI) query generated by the natural language model.

[0370] The operations performed by the above physical devices may also be executed by a program that implements the embodiments in software.

[0371]

[0372] FIG. 21 is a drawing disclosing another embodiment of a cyber threat information processing device according to an embodiment.

[0373] The cyber threat information processing device (1000) can provide a detected rule and a description of the threat when a threat is detected by the network black box (1500). Here, the network black box (1500) corresponds to a detection module that detects threats using collected packet data and network rules. At this time, the cyber threat information processing device (1000) can collect all network traffic information and detect threats using packet data among the collected traffic information. That is, the network black box (1500) collects and records all packet data for the purpose of detecting threats using packet data and detection rules, and can trace threats back using the recorded files. At this time, the network black box (1500) can be located outside the cyber threat information processing device (1000) as in the above-described embodiment, or can be located inside as in this drawing.

[0374] The network black box (1500) can receive packet data among network traffic from the cyber threat information processing device (1000) and inspect the packet data using detection rules.

[0375] More specifically, the cyber threat information processing device (1000) can provide usage information for each network session to the network black box (1500). At this time, the cyber threat information processing device (1000) can store packet data for each session and provide the stored packet data to the network black box (1500). Here, the packet data can include a PCAP file.

[0376] In one embodiment, the network black box (1500) can inspect collected packet data using rules registered by the user. At this time, the user can register, for example, either a snort rule or a suricata rule in the network black box (1500). At this time, snort and suricata correspond to programs widely used for network intrusion detection.

[0377] In one embodiment, the network black box (1500) can detect network anomalies by performing pattern matching on collected or stored packet data using registered suricata rules. Furthermore, when the network black box (1500) detects threat traffic, which is one of the network anomalies, the network black box (1500) registers the detected content in the network black box (1500) and transmits it to AI insight, which manages threats in an integrated manner, thereby providing an alarm to the user and enabling them to respond to the threat.

[0378] At this time, AI insight is a separate threat integration management module from the network black box (1500), and the cyber threat information processing device (1000) can determine abnormal signs that may be actual threats based on threat information detected by the network black box (1500) and transmit the actual threats to AI insight. In other words, the network black box (1500) can determine a primary threat and determine a secondary threat using the primary threat.

[0379] For example, in the case of a port scan, the network black box (1500) can transmit information to AI insight if the port scan being detected exceeds a preset threshold. In other words, the network black box (1500) can send abnormal signs that may constitute an actual threat to AI insight, and AI insight can alert the administrator of information that constitutes an actual threat.

[0380] In one embodiment, the network black box (1500) can analyze collected packet data using rules to output detected threat information. Here, the output threat information can include at least one of the session occurrence date (collection date), detection date, source IP, source port, destination IP, destination port, number of detections (number of rules detected in one session), information set in the rule (priority, class, message, sid), and packet data corresponding to the session. In addition, the network black box (1500) can detect threat information by analyzing IP, protocol, application, binary, URL, event data, etc. included in the packet data.

[0381] In one embodiment, the network black box (1500) can track the internal / external IP address or file connected to the internal IP address exposed to the threat when a specific session is detected. At this time, the network black box (1500) can use stored packet data to trace back the time and method of the threat. The network black box (1500) can trace the current threat back to the time of detection, find the link, and determine where the threat originated.

[0382] That is, the network black box (1500) of the present invention can perform regression analysis to trace back threats using the entire data of collected packet data rather than using specific input values.

[0383] At this time, regression analysis is explained in detail as follows.

[0384] First, the network black box (1500) can examine packet data collected in real time using rules. Then, when a rule is registered at a specific point in time, the network black box (1500) can use the registered rule to backtrack and examine all previously stored packet data. At this time, the network black box (1500) can backtrack to determine when threatening behavior (or abnormal signs corresponding to abnormal behavior) began for previously stored packet data.

[0385] Additionally, the network black box (1500) can use rules to examine packet data to provide additional meaning to detected sessions. For example, the network black box (1500) can identify the first session as a threat activity. In this case, if similar threat activities are detected multiple times, the network black box (1500) can identify external / internal ports, web vulnerability scans, etc., and can determine whether an internal infection is leading to an external attack.

[0386] For example, the network black box (1500) can identify when a scan occurs from an external IP to an internal IP range via internal ports 22 (SSH) / 3389 (RDP). In other words, the network black box (1500) can identify when such a session is infected with malware and scans internal assets externally.

[0387] Additionally, in one embodiment, the network black box (1500) can analyze threat information using information such as IP, protocol, application, binary, URL, and event data.

[0388] The threat detection unit can detect threats based on threat information analyzed and output through the network black box (1500). In one embodiment, the threat detection unit can generate vulnerability information based on threats detected through the network black box (1500). For details, refer to the embodiment described above in DP24-0036.

[0389] Additionally, the description provider (1600) may provide a description to the user based on threat information output through the network black box (1500). In one embodiment, the description provider (1600) may provide the user with anomaly symptom information that may actually be a threat, analyzed through the network black box (1500), in natural language. For example, if an action of scanning a specific internal port from the outside is identified multiple times through the network black box (1500), the description provider (1600) may provide the user with this information in natural language. For this, please refer to the above-described embodiment.

[0390]

[0391] FIG. 22 is a drawing disclosing one embodiment of a network black box according to an embodiment.

[0392] The network black box (1500) may include a session detection unit (1510), an IP / file tracking unit (1520), and a threat information provision unit (1530). At this time, as described above, the network black box (1500) is one of the internal modules of the cyber threat information processing device, and the session detection unit (1510), the IP / file tracking unit (1520), and the threat information provision unit (1530) described below are merely separated to perform the function of the network black box, but it goes without saying that the network black box (1500) itself can perform the functions of each unit at once.

[0393] The session detection unit (1510) can detect specific sessions by examining packet data collected by the cyber threat information processing device (1000). In one embodiment, the session detection unit (1510) can examine all sessions within the packet data and detect specific sessions that may pose a threat, such as those exhibiting abnormalities. Here, the specific sessions may include sessions that may pose a threat or sessions that are currently posing a threat.

[0394] In one embodiment, the session detection unit (1510) may utilize a network intrusion detection program, such as the suricata rule, to determine anomalies. Furthermore, the session detection unit (1510) may apply various detection rules other than the suricata rule to identify potentially threatening characteristics (e.g., traces of attacks within a company or organization).

[0395] The IP / file tracking unit (1520) can reverse-trace threats. More specifically, the currently occurring (detected) threat does not occur as a single threat, but generally occurs together with pre-tasks associated with the threat (e.g., pre-infiltration tasks to identify vulnerabilities, such as port scanning). Therefore, the IP / file tracking unit (1520) can reverse-analyze all previously collected traffic using the detected threat to reverse-trace the threat, including when and in which session the threat initially started, and what path it took to reach the current threat. In other words, the IP / file tracking unit (1520) can trace threats using the entire collected packet data, rather than using specific input values.

[0396] The threat information provision unit (1530) can provide tracked threat information to AI Insight. More specifically, the cyber threat information processing device can collect network traffic according to the above-described embodiment and detect threats using detection rules (e.g., suricata rules) on the collected network traffic. In other words, the network black box (1500) can detect abnormal signs that may actually be threats using the collected network traffic and detection rules. Thereafter, the network black box (1500) can provide information on the abnormal signs to AI Insight.

[0397]

[0398] FIG. 23 is a diagram disclosing an example of threat information provided by a network black box according to an embodiment.

[0399] The cyber threat information processing device utilizes a network black box to analyze all network traffic generated over a preset period (e.g., the last 90 days, the last 30 days). Analysis is performed regularly based on user-registered rules (e.g., suricata rules), and threat information can be provided to the user upon completion of the analysis.

[0400] This diagram shows the collected network session information provided by the network black box.

[0401] Here, the collected network session information may include the total number of sessions, the number of detected sessions, and the number of detected IPs based on a reference date (e.g., 1 day) over a set period (e.g., 1 month). Here, the detected sessions may include sessions that are potentially threatening or are currently posing a threat. Additionally, the number of detected IPs indicates the number of IPs detected in the detected sessions.

[0402] In one embodiment, the network blackbox can provide statistics on the total number of sessions and the number of detected sessions over the past year in graph form. Additionally, the network blackbox can provide detected threats in a timeline format. This allows users to detect threats in real time and gain visibility into the number of sessions and detected sessions.

[0403] In one embodiment, a network black box performs reverse tracing analysis upon a security breach, storing all traffic to trace the threat back to its origin and pinpoint the exact time of threat occurrence. Accordingly, the network black box can provide detected threat information, detection rules, and packet data at the time of the threat occurrence. The detection rules correspond to the rules used to detect the threat, and for information on detected threat information, refer to the aforementioned embodiment.

[0404]

[0405] FIG. 24 is a diagram disclosing an example of threat information provided by a network black box according to an embodiment.

[0406] A cyber threat information processing device can perform reverse tracing analysis using a network black box. In one embodiment, the cyber threat information processing device can store all collected traffic and trace the time of the threat.

[0407] This diagram shows the network abnormality detection information provided by the network black box.

[0408] The network black box can provide statistics on detected threat information for a preset period (e.g., the last 30 days). The detected threat information may include at least one of the following: session occurrence date (collection date), detection date, source IP, source port, destination IP, destination port, number of detections (the number of rules detected in a single session), information set in the rule (priority, class, message, sid), and packet data for the corresponding session.

[0409] Additionally, the network blackbox can provide the number of detected rules per IP address. Multiple rules can be detected in a single session, which can lead to the assumption that multiple rules were detected from a single IP address. Therefore, the network blackbox can provide the number of detected rules per IP address.

[0410] In one embodiment, the network black box may provide a list of IP address detections in sessions collected within a preset period. For example, the network black box may output a list indicating that IP address 10.10.0.43 was detected 32,672 times, IP address 10.10.0.12 was detected 16,414 times, etc. during a selected detection period (e.g., from July 12, 2024 to July 27, 2024).

[0411] Additionally, network black boxes can provide detected threats as a timeline graph. This allows for quick and convenient regression analysis in the event of a security breach.

[0412]

[0413] FIG. 25 is a flowchart disclosing one embodiment of a cyber threat information processing method according to an embodiment.

[0414] In one embodiment, the cyber threat information processing method can collect packet data contained in network traffic (S1410). For details, refer to the details described above in FIGS. 1 to 8.

[0415] In one embodiment, the cyber threat information processing method can collect various network traffic and packet data contained in the network traffic according to the above-described embodiment. At this time, the cyber threat information processing method can analyze the collected packet data using detection rules (S1420). For more information, please refer to the details described in FIG. 21.

[0416] In one embodiment, a method for processing cyber threat information may provide anomaly information corresponding to an anomaly when an anomaly indicating a potential threat is detected in a first session within packet data based on analysis (S1430). Here, if n sessions exist within the packet data, and an anomaly indicating a potential threat is detected in the first session, threat information corresponding to the anomaly may be provided in the first session.

[0417] Here, the threat information may include at least one of the occurrence date of the anomaly, the detection date of the anomaly, the source IP, the source port, the destination IP, the destination port, the number of rules detected in the first session, information set in the rule, and packet data corresponding to the first session. For example, multiple suricata rules may be detected in one session. Therefore, the number of rules detected in the first session indicates how many suricata rules were detected in the first session. For this, please refer to the contents described above in FIGS. 21 to 24.

[0418] In one embodiment, a method for processing cyber threat information generates vulnerability information based on threat information, wherein the vulnerability information corresponds to flow information including at least one IP and port of a source and a destination, and at least one protocol, application, and metadata for the network traffic. For further details, please refer to the descriptions given above in FIGS. 16 to 19.

[0419] In one embodiment, a method for processing cyber threat information may input threat information into a natural language model to provide descriptive information corresponding to the threat information. For details, please refer to the description provided above in FIG. 20.

Claims

1. A step of collecting packet data included in network traffic; A step of analyzing the above packet data using a detection rule; and A method for processing cyber threat information, comprising the step of providing threat information corresponding to an anomaly detected in the first session within the packet data based on the above analysis.

2. In paragraph 1, A method for processing cyber threat information, wherein the threat information includes at least one of the occurrence date of the abnormal symptom, the detection date of the abnormal symptom, a source IP, a source port, a destination IP, a destination port, the number of rules detected in the first session, information set in the rule, and packet data corresponding to the first session.

3. In paragraph 1, Generate vulnerability information based on the above threat information, A method for processing cyber threat information, characterized in that the vulnerability information corresponds to flow information including at least one of an IP and a port of a source and a destination, and at least one of a protocol, application, and metadata for the network traffic.

4. In paragraph 1, A method for processing cyber threat information, further comprising the step of inputting the above threat information into a natural language model and providing descriptive information corresponding to the threat information.

5. A database that stores data; and Including a processor for processing the above data, The above processor, Collect packet data contained in network traffic, Analyze the above packet data using detection rules, A cyber threat information processing device that provides threat information corresponding to an abnormality when an abnormality with a possibility of a threat is detected in the first session within the packet data based on the above analysis.

6. Step of collecting packet data included in network traffic; A step of analyzing the above packet data using a detection rule; and A storage medium storing a program for processing cyber threat information, comprising a step of providing threat information corresponding to an abnormality detected in the first session within the packet data based on the above analysis.

Citation Information

Patent Citations

  • Method and apparatus for detecting network attack basedon network abnormal behavior

    KR100767803B1

  • Network traffic monitoring system based on step-by-step flow information

    KR100934714B1

  • System for implementing Deep Packet Inspection Simulation for detecting and analyzing cyber attack in electronic warfare and Method thereof

    KR101615587B1

  • Method, apparatus and computer program for analzing vulnerability of software defined network

    KR1020160145373A