Operation method of electronic device for detecting new undefined threat
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- AHNLAB INC
- Filing Date
- 2026-01-20
- Publication Date
- 2026-07-30
Smart Images

Figure KR2026001149_30072026_PF_FP_ABST
Abstract
Description
Method of operation of an electronic device for detecting new, undefined threats
[0001] The present disclosure relates to a method of operation of an electronic device for detecting threats, and more specifically, to a method of operation of an electronic device capable of identifying new threats that have not been detected in the past.
[0002] Threat detection utilizing log data plays a crucial role in the field of security. Since log data contains records of all activities occurring within systems and networks, analyzing it can be useful for identifying and responding to security threats.
[0003] Existing threat detection mainly corresponds to rule-based or artificial intelligence model-based anomaly / threat detection, and there are technologies that statistically distinguish between normal and abnormal patterns, technologies that detect potential threats by comparing with scenarios defined according to rules, and technologies that determine the risk level of logs based on artificial intelligence models.
[0004] However, the aforementioned technologies are based on the premise that threat patterns or rules are defined, established, or learned according to previously identified log history, and thus have a vulnerability to new and modified forms of threats that have not existed before.
[0005] The present disclosure provides a method of operation for an electronic device to detect whether log data is normal or a threat, as well as to determine the possibility that the log data corresponds to a new threat that has not previously been identified.
[0006] The purposes of the present disclosure are not limited to those mentioned above, and other purposes and advantages of the present disclosure not mentioned may be understood from the following description and will be more clearly understood by the embodiments of the present disclosure. Furthermore, it will be readily apparent that the purposes and advantages of the present disclosure can be realized by the means and combinations thereof set forth in the claims.
[0007] A method of operation of an electronic device according to one embodiment of the present disclosure comprises: a step of identifying whether the target log is a normal log by comparing a plurality of normal logs with a target log; a step of identifying whether the target log is a threat log based on a plurality of existing threat logs corresponding to a threat when the target log is identified as not being a normal log; and a step of identifying whether the target log corresponds to a new threat through an artificial intelligence model for predicting a new threat when the target log is identified as not being a threat when determined based on the plurality of existing threat logs.
[0008] The method of operation of the electronic device may include the step of training the artificial intelligence model based on training data comprising a plurality of pairs of threat logs before and after modification. Furthermore, the step of identifying whether the target log corresponds to a new threat may include the step of inputting the plurality of threat logs into the artificial intelligence model to generate at least one predicted threat log, and the step of comparing the at least one predicted threat log with the target log to determine whether the target log is a new threat.
[0009] At this time, the threat log before modification and the threat log after modification constituting the threat logs before and after modification may include at least one of the same attacker and the same action sequence.
[0010] Meanwhile, the step of comparing at least one predicted threat log with the target log to determine whether the target log is a new threat involves inputting each of the plurality of threat logs into the artificial intelligence model to generate a plurality of predicted threat logs, comparing each of the generated logs with the target log to calculate a similarity, and determining whether the target log is a new threat based on the similarity between the at least one predicted threat log with the highest similarity among the plurality of predicted threat logs and the target log.
[0011] In this case, the step of comparing at least one predicted threat log with the target log to determine whether the target log is a new threat may be determined as not being a new threat if the similarity between the predicted threat log with the highest similarity and the target log is less than a first threshold similarity, and determined as being a new threat if the similarity between the predicted threat log with the highest similarity and the target log is greater than or equal to a second threshold similarity, which is greater than the first threshold similarity.
[0012] Here, the method of operation of the electronic device may include the step of calculating a risk level according to at least one of the complexity, format, and operation pattern of the target log when the similarity between the predicted threat log with the highest similarity and the target log is greater than or equal to the first threshold similarity and less than the second threshold similarity.
[0013] The method of operation of an electronic device according to the present disclosure has the effect of being able to predict and detect new types of threats that have not previously been monitored or defined.
[0014] FIG. 1 is a block diagram for explaining the configuration of an electronic device according to one embodiment of the present disclosure,
[0015] FIG. 2 is an algorithm for explaining a process in which an electronic device according to one embodiment of the present disclosure sequentially performs processes such as identifying whether it is a normal login, identifying whether it is a threat login, identifying whether it is a new threat, etc.
[0016] FIG. 3 is a flowchart illustrating an operation in which an electronic device according to one embodiment of the present disclosure determines whether a target log is a new threat, and
[0017] FIG. 4 is a block diagram illustrating the configuration of an electronic device according to various embodiments of the present disclosure.
[0018] Before specifically describing the present disclosure, the method of description in the specification and drawings is described.
[0019] First, the terms used in this specification and claims have been selected based on general terms considering their functions in the various embodiments of this disclosure. However, these terms may vary depending on the intent of those skilled in the art, legal or technical interpretations, and the emergence of new technologies. Additionally, some terms have been arbitrarily selected by the applicant. Such terms may be interpreted according to the meanings defined in this specification; in the absence of specific definitions, they may be interpreted based on the overall content of this specification and the ordinary technical knowledge of the relevant field.
[0020] In addition, the same reference numbers or symbols described in each drawing attached to this specification represent parts or components that perform substantially the same function. For convenience of explanation and understanding, the same reference numbers or symbols are used in different embodiments. That is, even if components having the same reference number are all depicted in multiple drawings, the multiple drawings do not imply a single embodiment.
[0021] Additionally, in this specification and claims, terms including ordinal numbers, such as "first," "second," etc., may be used to distinguish between components. These ordinal numbers are used to distinguish identical or similar components from one another, and the meaning of the terms should not be limited by the use of such ordinal numbers. For example, the order of use or arrangement of components combined with such ordinal numbers should not be restricted by the number. If necessary, each ordinal number may be used interchangeably.
[0022] In this specification, singular expressions include plural expressions unless the context clearly indicates otherwise. In this application, terms such as "comprising" or "consisting of" are intended to specify the existence of the features, numbers, steps, actions, components, parts, or combinations thereof described in the specification, and should be understood as not precluding the existence or addition of one or more other features, numbers, steps, actions, components, parts, or combinations thereof.
[0023] In embodiments of the present disclosure, terms such as "module," "unit," "part," etc. are used to refer to a component that performs at least one function or operation, and such component may be implemented in hardware or software, or a combination of hardware and software. Additionally, a plurality of "modules," "units," "parts," etc. may be integrated into at least one module or chip and implemented as at least one processor, except where each needs to be implemented in specific individual hardware.
[0024] Furthermore, in the embodiments of the present disclosure, when a part is described as being connected to another part, this includes not only a direct connection but also an indirect connection through another medium. Additionally, the meaning that a part includes a certain component implies that, unless specifically stated otherwise, it does not exclude other components but may include additional components.
[0025] FIG. 1 is a block diagram for explaining the configuration of an electronic device according to one embodiment of the present disclosure.
[0026] The electronic device (100) may be implemented as a device or system composed of at least one computer equipped to perform the collection of log data, monitoring, and threat detection related to a target system requiring prior detection of threats. The target system may be a system of various targets or groups, such as individuals, companies, or institutions, or may correspond to a system environment composed of one or more electronic devices or facilities. The target system may be composed of the electronic device (100) alone, may be composed of multiple electronic devices including the electronic device (100), or may be implemented as a separate system that does not include the electronic device (100).
[0027] For example, the electronic device (100) may be implemented as a server, gateway, firewall device, routing device, etc., or as a POS system, payment device, vehicle terminal, smart home appliance, desktop PC, laptop PC, smartphone, tablet PC, console, etc., and may also be implemented as various other devices.
[0028] Referring to FIG. 1, the electronic device (100) may include memory (110) and a processor (120), etc.
[0029] The memory (110) is configured to store at least one instruction or data related to an operating system (OS) for controlling the overall operation of the components of the electronic device (100) and the components of the electronic device (100).
[0030] The memory (110) may include non-volatile memory such as ROM or flash memory, and may include volatile memory such as DRAM. Additionally, the memory (120) may include an auxiliary storage device such as a hard disk or an SSD (Solid State Drive).
[0031] Referring to FIG. 1, the memory (110) may include at least one artificial intelligence model (111) for predicting new threats that have not previously been monitored.
[0032] The artificial intelligence model (111) can be trained based on training data comprising multiple pairs of threat logs before and after modification. For example, it can be trained based on pairs of various threat logs before and after modification, such as a first pair consisting of threat log A before modification and threat log A' after threat log A has been modified, and a second pair consisting of threat log B before modification and threat log B' after threat log B has been modified. At this time, the threat log before modification can be matched to the input of the artificial intelligence model (111), and the threat log after modification can be matched to the output of the artificial intelligence model (111). The threat log before modification and the threat log after modification constituting the threat log before and after modification may have at least one of the same attacker and the same action sequence in common.
[0033] The training process of such artificial intelligence model (111) may be performed by a processor (120) on an electronic device (100), or it may be performed by at least one external device.
[0034] As a result of the training described above, for example, when at least one (previously monitored) threat log is input into the artificial intelligence model (111), the artificial intelligence model (111) can generate at least one predicted threat log that can be generated by modifying the input threat log.
[0035] To this end, the artificial intelligence model (111) can be implemented as a Recurrent Neural Network (RNN) or Long Short-Term Memory (LSTM) model to predict changes in threat logs over time.
[0036] Alternatively, the artificial intelligence model (111) may be implemented as a generative model for generating a new threat log by modifying a previously monitored threat log. In this case, the generative model may be implemented as a transformer, an autoencoder, etc., but is not limited thereto.
[0037] Meanwhile, unlike FIG. 1 where an artificial intelligence model (111) is stored in the memory (110) of the electronic device (100), the electronic device (100) may communicate with an external device (e.g., an external server) through a communication interface (130) to be described later, and may use the artificial intelligence model (111) stored in the external device.
[0038] The processor (120) is configured to control the overall configuration and operation of the electronic device (100).
[0039] The processor (120) is connected to the memory (110) and can control the electronic device (100) by executing at least one instruction stored in the memory (110).
[0040] To this end, the processor (120) may be implemented as a general-purpose processor such as a CPU (Central Processing Unit) or AP (Application Processor), a graphics-dedicated processor such as a GPU (Graphic Processing Unit) or VPU (Vision Processing Unit), or an artificial intelligence-dedicated processor such as an NPU (Neural Processing Unit). The processor (120) may include volatile memory such as SRAM.
[0041] When a method according to one embodiment of the present disclosure includes a plurality of operations, the plurality of operations may be performed by a single processor (120) or by a plurality of processors (120) included in an electronic device (100). For example, when a first operation, a second operation, and a third operation are performed by a method according to one embodiment, the first operation, the second operation, and the third operation may all be performed by a first processor, or the first operation and the second operation may be performed by a first processor (e.g., a general-purpose processor) and the third operation may be performed by a second processor (e.g., an artificial intelligence dedicated processor).
[0042] One or more processors (120) may be implemented as a single-core processor including one core, or as one or more multicore processors including multiple cores (e.g., homogeneous multicore or heterogeneous multicore). When one or more processors (120) are implemented as multicore processors, each of the multiple cores included in the multicore processor may include internal processor memory such as on-chip memory (110), and a common cache shared by the multiple cores may be included in the multicore processor (120). Additionally, each of the multiple cores included in the multicore processor (120) (or some of the multiple cores) may independently read and execute program instructions for implementing a method according to one embodiment of the present disclosure, or all (or some) of the multiple cores may be linked together to read and execute program instructions for implementing a method according to one embodiment of the present disclosure.
[0043] When a method according to one embodiment of the present disclosure includes a plurality of operations, the plurality of operations may be performed by one of the plurality of cores included in a multi-core processor, or may be performed by a plurality of cores. For example, when a first operation, a second operation, and a third operation are performed by a method according to one embodiment, the first operation, the second operation, and the third operation may all be performed by a first core included in a multi-core processor, or the first operation and the second operation may be performed by a first core included in a multi-core processor and the third operation may be performed by a second core included in a multi-core processor.
[0044] In embodiments of the present disclosure, the processor (120) may mean a system-on-chip (SoC) in which one or more processors (120) and other electronic components are integrated, a single-core processor, a multi-core processor, or a core included in a single-core processor or a multi-core processor, wherein the core may be implemented as a CPU, GPU, APU, MIC, DSP, NPU, hardware accelerator or machine learning accelerator, etc., but the embodiments of the present disclosure are not limited thereto.
[0045] Referring to FIG. 1, the processor (120) can control a plurality of discrimination modules (131, 132, 133) for performing analysis on a target log (log data) corresponding to at least one of a plurality of logs monitored in real time. Each of these discrimination modules (131, 132, 133) may correspond to a functional unit module implemented in software and / or hardware.
[0046] The first determination module (121) is a module for determining whether a target log is a normal log. The first determination module (121) can identify whether a target log is a normal log based on a plurality of normal logs (past) corresponding to normal. That is, the first determination module (121) compares each of the plurality of normal logs with the target log to identify whether there exists at least one normal log that matches the target log or has a similarity value greater than a certain amount, and if there exists, the target log can be identified as a normal log.
[0047] The second determination module (122) is a module for determining whether the target log is a threat log. The threat log may include, but is not limited to, a log containing a security threat, a log with a high probability of containing a threat, or a log with a high probability of leading to the next log containing a threat. The second determination module (131) can determine whether the target log is a threat log based on the premise that the target log is not identified as a normal log by the first determination module (121) (e.g., when there is no normal log among multiple past normal logs that has a similarity to the target log above a certain value).
[0048] Specifically, the second determination module (122) can identify whether a target log is a threat log based on multiple (past) threat logs corresponding to the threat. That is, the second determination module (122) compares each of the multiple threat logs with the target log to identify whether there is at least one threat log that matches the target log or has a similarity value greater than a certain threshold, and if there is, it can identify the target log as a threat log.
[0049] The third determination module (123) is a module for determining whether the target log is a new threat that has not been previously defined. The third determination module (123) can determine whether the target log is a new threat based on the premise that the target log is not identified as a threat log by the second determination module (122) (e.g., when there is no threat log among multiple past threat logs that has a similarity to the target log above a certain value).
[0050] To this end, the third determination module (123) can acquire at least one predicted threat log generated by the artificial intelligence model (111) described above and determine whether the target log is a new threat by comparing each predicted threat log with the target log. At this time, if the similarity to at least one predicted threat log is greater than a certain value, the target log can be identified as a new threat.
[0051] FIG. 2 is an algorithm for explaining the process of sequentially performing the following steps: identifying whether an electronic device according to one embodiment of the present disclosure is a normal login, identifying whether it is a threat login, identifying whether it is a new threat, etc.
[0052] Referring to FIG. 2, the electronic device (100) can acquire a target log corresponding to the inspection target (S210). For example, the electronic device (100) may monitor log data on a target system that is the target of threat detection in real time and select at least one log as a target log every hourly interval, but is not limited thereto.
[0053] Referring to FIG. 2, first, the electronic device (100) can identify whether the target log corresponds to a normal log by using the first discrimination module (121) described above (S220). Specifically, the electronic device (100) can identify whether there is at least one normal log that matches the target log or has a similarity value greater than a certain amount by comparing each of the multiple normal logs monitored in the past with the target log, and if there is, the target log can be identified as a normal log.
[0054] In this case, the similarity between logs can be calculated based on the distance between vectors derived from the vector transformation (e.g., embedding models) of the text or computing language constituting the logs, but is not limited thereto.
[0055] If the target log is identified as a normal log (S220 - Y), the algorithm of FIG. 2 terminates by defining the target log as a normal log.
[0056] However, if the target log is identified as not being a normal log (S220 - N), that is, if there has not been at least one normal log in the past that matches the target log or has a similarity value of at least a certain amount, the electronic device (100) can identify whether the target log corresponds to a threat log through the second determination module (122) (S230). Specifically, the electronic device (100) compares each of the multiple threat logs monitored in the past with the target log to identify whether there is at least one threat log that matches the target log or has a similarity value of at least a certain amount, and if there is, the target log can be identified as a threat log.
[0057] If the target log is identified as a threat log (S230 - Y), the algorithm of FIG. 2 terminates by defining the target log as a threat log.
[0058] However, if the target log is identified as not being a threat log (S230 - N), that is, if there has not been at least one threat log in the past that matches the target log or has a similarity value greater than a certain amount, the electronic device (100) can identify whether the target log corresponds to a new threat or not through the third determination module (123) (S240).
[0059] To this end, the electronic device (100) can generate at least one new predicted threat log through an artificial intelligence model (111) and compare the generated predicted threat log with the target log.
[0060] Specifically, with reference to FIG. 3, the electronic device (100) can calculate a similarity by comparing each of a plurality of predicted threat logs, generated as a result of each of a plurality of previously monitored threat logs being input into an artificial intelligence model (111), with a target log. Here, it can determine whether the target log is a new threat based on the similarity between the target log and at least one predicted threat log with the highest similarity among the plurality of predicted threat logs.
[0061] For example, the electronic device (100) may determine that the target log is not a new threat if the similarity between the predicted threat log with the highest similarity and the target log is less than a first threshold similarity, and determine that the target log is a new threat if the similarity between the predicted threat log with the highest similarity and the target log is greater than or equal to a second threshold similarity, which is greater than the first threshold similarity. Thus, when the target log is identified as a new threat or is identified as not being a new threat (S240 - Y), the algorithm of FIG. 2 may be terminated.
[0062] However, if it is impossible to identify whether the target log is a new threat or not (S240 - N), the electronic device (100) may separately perform a risk analysis on the target log (S250).
[0063] Specifically, if the similarity between the predicted threat log with the highest similarity and the target log is greater than or equal to the first threshold similarity and less than the second threshold similarity, the determination of whether the target log is a new threat may not be clearly made.
[0064] In this case, the electronic device (100) can substitute the above-described judgment (e.g., whether it is a normal log, a threat log, a new threat, etc.) by providing the risk analysis result of the target log.
[0065] In this case, the electronic device (100) can calculate the risk level according to at least one of the complexity, format, and operation pattern of the target log.
[0066] Meanwhile, FIG. 3 is a flowchart illustrating the operation of an electronic device according to one embodiment of the present disclosure to determine whether a target log is a new threat. For example, for a target log that is not identified as either a normal log or a threat log, determination can be performed by the third determination module (123) described above.
[0067] Referring to FIG. 3, the electronic device (100) can first input a plurality of threat logs into an artificial intelligence model (111) to generate at least one predicted threat log (S310). Specifically, for each of the plurality of threat logs, at least one predicted threat log in which a variation is predicted can be generated.
[0068] And, the electronic device (100) can compare at least one predicted threat log with a target log (S320). At this time, the similarity between each predicted threat log and the target log can be calculated.
[0069] Here, the electronic device (100) can determine whether the target log is a new threat based on the comparison result described above (S330).
[0070] Specifically, the electronic device (100) can determine whether the target log is a new threat based on the similarity of the predicted threat log with the highest similarity to the target log (e.g., first mode). For example, if the similarity is less than the first threshold described above, it is identified as not being a new threat, and if the similarity is greater than or equal to the second threshold described above, it is identified as being a new threat.
[0071] If the target log is determined to be a new threat based on the predicted threat log with the highest similarity to the target log (e.g., similarity is above a second threshold), the electronic device (100) can input the predicted threat log back into the artificial intelligence model (111) to generate additional predicted threat logs.
[0072] Alternatively, the electronic device (100) may select predicted threat logs in which the similarity to the target log corresponds to a minimum threshold value or higher, and determine whether the target log is a new threat based on the average similarity of the selected predicted threat logs (e.g., second mode). For example, if the average similarity is less than the first threshold described above, it may be identified as not being a new threat, and if the average similarity is greater than or equal to the second threshold described above, it may be identified as being a new threat.
[0073] In this regard, whether the aforementioned first mode, in which only the highest similarity is used, or the aforementioned second mode, in which the average similarity is used, is activated may vary depending on the settings of the electronic device (100). In one embodiment, the electronic device (100) can calculate the standard deviation of the similarity for each target log of the generated predicted threat logs, and if the standard deviation is greater than or equal to a threshold deviation, it can determine whether there is a new threat using the first mode, and if the standard deviation is less than the threshold deviation, it can determine whether there is a new threat using the second mode.
[0074] A relatively large standard deviation of similarity indicates that the target log is more likely to be particularly similar to a specific predicted threat log, and thus the similarity of the most similar specific predicted threat log is utilized (Mode 1); on the other hand, a small standard deviation of similarity indicates that the target log is more likely to possess common characteristics of multiple predicted threat logs rather than the unique characteristics of a single specific predicted threat log, and thus the average similarity of multiple predicted threat logs is utilized (Mode 2).
[0075] Meanwhile, according to one embodiment of the present disclosure, in relation to step S310, the electronic device (100) may periodically generate a plurality of predicted threat logs by inputting each monitored threat log into an artificial intelligence model (111) at regular intervals, and may store the generated predicted threat logs in memory (110) or in at least one external database. Here, logs identified as 'new threats' may also be input into the artificial intelligence model (111) and utilized to generate predicted threat logs.
[0076] The group composed of the predicted threat logs stored in this way can be utilized for each target log in the process S320 of Fig. 3 described above. That is, the similarity between each target log and the predicted threat logs included in the group can be calculated.
[0077] However, as new predicted threat logs are continuously added, a problem may arise where storage space becomes insufficient. In this regard, the electronic device (100) may delete predicted threat logs for which a certain period has elapsed since their creation, depending on whether there is a usage history regarding the detection process of new threats.
[0078] Specifically, when a predicted threat log is identified after a certain period has elapsed since its creation, the electronic device (100) can identify whether the predicted threat log has been selected as the predicted threat log with the highest similarity to at least one target log and whether there is a history of the target log actually being judged as a 'new threat'. If such a history exists, the predicted threat log may not be deleted even after a certain period has elapsed. This is based on the consideration that a predicted threat log that has a history of actually being used to detect new threats may have further value for detecting other new threats in the future. On the other hand, if such a history does not exist, the predicted threat log is deleted after a certain period has elapsed, thereby reducing the use of memory space.
[0079] Meanwhile, FIG. 4 is a block diagram for explaining the configuration of an electronic device according to various embodiments of the present disclosure.
[0080] In addition to the memory (110) and processor (120) described above, the electronic device (100) may further include a communication interface (130), a user input interface (140), an output interface (150), etc.
[0081] The communication interface (120) can be connected to an external server and / or terminal device through one or more networks, and can exchange data through various wired and wireless communication methods.
[0082] Wireless communication may include at least one of the following communication methods: LTE (long-term evolution), LTE-A (LTE Advance), 5G (5th Generation) mobile communication, CDMA (code division multiple access), WCDMA (wideband CDMA), UMTS (universal mobile telecommunications system), WiBro (Wireless Broadband), GSM (Global System for Mobile Communications), DMA (Time Division Multiple Access), WiFi (Wi-Fi), WiFi Direct, Bluetooth, NFC (near field communication), Zigbee, etc.
[0083] Wired communication may include at least one of communication methods such as Ethernet, optical network, USB (Universal Serial Bus), Thunderbolt, and HDMI (High Definition Multimedia Interface).
[0084] Meanwhile, communication methods are not limited to the examples described above and may include new communication methods that emerge with technological advancements.
[0085] In one embodiment, the electronic device (100) can connect to at least one network environment to obtain log data. Specifically, the electronic device (100) can receive log data from at least one external electronic device or external terminal through a communication interface (120). Additionally, the electronic device (100) may collect log data generated on the electronic device (100).
[0086] The user input interface (140) is configured to receive user input or user commands and may include, but is not limited to, at least one button, keypad, touchpad (e.g., touchscreen), microphone, camera, other sensor, etc. Alternatively, the electronic device (100) may receive user input from at least one user input device (e.g., pad device, mouse, keyboard, remote controller, etc.) through the communication interface (130).
[0087] The output interface (150) is configured to output various information and may include a display, a speaker, an earphone / headphone jack, etc.
[0088] In one embodiment, the electronic device (100) may perform the process of FIG. 2 described above by selecting at least one target log according to user input received through the user input interface (140). Additionally, the electronic device (100) may provide information about the type of the target log (e.g., normal log, threat log, or new threat, etc.) or provide a risk level of the target log through the output interface (150).
[0089] Meanwhile, the various embodiments described above may be implemented by combining two or more embodiments, provided that they do not conflict or contradict each other.
[0090] Meanwhile, the various embodiments described above may be implemented in a recording medium readable by a computer or a similar device using software, hardware, or a combination thereof.
[0091] According to hardware implementation, the embodiments described in this disclosure may be implemented using at least one of ASICs (Application Specific Integrated Circuits), DSPs (digital signal processors), DSPDs (digital signal processing devices), PLDs (programmable logic devices), FPGAs (field programmable gate arrays), processors, controllers, microcontrollers, microprocessors, and other electrical units for performing functions.
[0092] In some cases, the embodiments described herein may be implemented as the processor itself. In a software implementation, embodiments such as the procedures and functions described herein may be implemented as separate software modules. Each of the aforementioned software modules may perform one or more of the functions and operations described herein.
[0093] Meanwhile, computer instructions or computer programs for performing processing operations in electronic devices, etc., according to the various embodiments of the present disclosure described above may be stored in a non-transitory computer-readable medium. When such computer instructions or computer programs stored in the non-transitory computer-readable medium are executed by a processor of a specific device, the specific device described above performs processing operations in electronic devices, etc., according to the various embodiments described above.
[0094] A non-transient computer-readable medium refers to a medium that stores data semi-permanently and can be read by a device, unlike media that store data for a short period of time such as registers, caches, and memory. Specific examples of non-transient computer-readable media include CDs, DVDs, hard disks, Blu-ray discs, USBs, memory cards, and ROMs.
[0095] Although preferred embodiments of the present disclosure have been illustrated and described above, the present disclosure is not limited to the specific embodiments described above. Various modifications are possible by those skilled in the art without departing from the essence of the present disclosure as claimed in the claims, and such modifications should not be understood individually from the technical spirit or perspective of the present disclosure.
Claims
1. In a method of operating an electronic device, A step of comparing a plurality of normal logs with a target log to identify whether the target log is a normal log; If the above target log is identified as not being a normal log, a step of identifying whether the above target log is a threat log based on a plurality of threat logs corresponding to the threat; and A method of operation of an electronic device comprising: a step of identifying whether the target log corresponds to a new threat through an artificial intelligence model for predicting new threats when the target log is identified as not being a threat based on the plurality of threat logs above.
2. In Paragraph 1, The method of operation of the above electronic device is, The method includes the step of training the artificial intelligence model based on training data comprising multiple pairs of threat logs before and after transformation; and The step of identifying whether the above target log corresponds to a new threat is, The step of inputting the plurality of threat logs into the artificial intelligence model to generate at least one predicted threat log; and A method of operating an electronic device comprising the step of comparing at least one predicted threat log with the target log to determine whether the target log is a new threat.
3. In Paragraph 2, A method of operation of an electronic device in which the threat log before and after the above modification, constituting the threat log before and after the modification, includes at least one of the same attacker and the same action sequence.
4. In Paragraph 2, The step of comparing the above at least one predicted threat log with the above target log to determine whether the above target log is a new threat is, Each of the plurality of threat logs above is input into the artificial intelligence model to generate each of the plurality of predicted threat logs, and the similarity is calculated by comparing each of the generated logs with the target log, and A method of operation of an electronic device for determining whether a target log is a new threat based on the similarity between at least one predicted threat log with the highest similarity among the plurality of predicted threat logs and the target log.
5. In Paragraph 4, The step of comparing the above at least one predicted threat log with the above target log to determine whether the above target log is a new threat is, If the similarity between the predicted threat log with the highest similarity and the target log is less than the first threshold similarity, the target log is determined not to be a new threat, and A method of operation of an electronic device, wherein if the similarity between the predicted threat log with the highest similarity and the target log is greater than or equal to a second threshold similarity which is greater than the first threshold similarity, the target log is determined to be a new threat.
6. In Paragraph 5, The method of operation of the above electronic device is, A method of operating an electronic device, comprising the step of calculating a risk level according to at least one of the complexity, format, and operation pattern of the target log when the similarity between the predicted threat log with the highest similarity and the target log is greater than or equal to the first threshold similarity and less than the second threshold similarity.