Assembly-Code CTI Analysis for Novel Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity technologies struggle to detect and respond to new or variant malware, decoy information, and advanced persistent threats (APT) effectively, lacking standardized description methods for malware and attack techniques, which leads to delayed detection and confusion among experts.

Innovation Solution

A cyber threat information processing apparatus and method utilizing natural language processing to identify malware, attack techniques, and attackers through machine learning, enabling rapid detection and prediction of future threats, even for variants, with standardized information provision.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional pattern-based detection methods are used, then detection speed and accuracy are improved for known malware, but detection capability deteriorates for new or variant malware

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection capability for new threats
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by collecting and analyzing multiple types of information (malware characteristics, attack techniques, attacker profiles) before new threats emerge. This advance preparation enables the system to detect novel threats by comparing them against pre-collected behavioral patterns and attacker methodologies, rather than relying solely on pre-defined malware signatures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent transitions from traditional single-dimension pattern matching to multi-dimensional analysis by integrating malware characteristics, attack techniques (TTPs), and attacker information. This dimensional expansion allows the system to detect threats through multiple angles simultaneously, improving both accuracy for known threats and adaptability to new threats.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Difficulty of detecting and measuring

If AI analysis is used to detect and analyze malware, then analysis capability is improved, but fundamental countermeasure technology remains lacking

Engineering Contradiction:
Improvemalware analysis capabilityVSAvoidfundamental countermeasure technology
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

The system introduces an intermediary layer of standardized information processing between AI analysis and threat detection. By establishing standardized schemas for malware characteristics, attack techniques, and attacker profiles, the system mediates between raw AI analysis results and actionable threat intelligence, making the overall system more reliable and interpretable.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes parameters by transforming unstructured AI analysis outputs into structured information with defined parameters and schemas. This parameter standardization enables consistent processing and comparison of threat intelligence across different AI models and analysis methods, improving reliability.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If decoy information is introduced to deceive detection systems, then attacker success rate is improved, but detection system reliability deteriorates

Engineering Contradiction:
Improveattacker success rateVSAvoiddetection system reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements feedback mechanisms by continuously monitoring detection results and comparing them against collected attacker information and TTPs. When decoy information or false positives are detected, the system learns from these patterns and adjusts its analysis, providing feedback that improves reliability over time rather than being permanently deceived.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary analysis of information sources and channels before processing threat data. By establishing baseline characteristics of legitimate vs. deceptive information sources in advance, the system can identify and filter decoy information, maintaining reliability even when attackers introduce deception.

Inventive Principle:
Principle #10Preliminary action

4Ease of operation

If different description methods are used by analysts, then individual analysis flexibility is improved, but information standardization deteriorates

Engineering Contradiction:
Improveanalysis flexibilityVSAvoidinformation standardization
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The system creates universal schemas that can accommodate multiple analysis perspectives and methodologies. The standardized information structures are designed to be multi-functional, supporting different analysis approaches while maintaining consistent data formats, thus preserving both flexibility and standardization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments information into distinct, standardized components (malware characteristics, attack techniques, attacker profiles) that can be independently analyzed and recombined. This segmentation allows analysts to work flexibly with specific components while the overall structure maintains standardization through defined relationships between segments.

Inventive Principle:
Principle #1Segmentation

5Measurement precision

If focused detection on individual malware cases is performed, then detection precision for specific threats is improved, but prediction capability for future threats deteriorates

Engineering Contradiction:
Improvedetection precisionVSAvoidprediction capability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system merges information from multiple individual case analyses by collecting and correlating data across different malware incidents, attack techniques, and attacker campaigns. This aggregation transforms isolated detection precision into collective intelligence that enables prediction of future threats through pattern recognition across merged datasets.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

By collecting and analyzing information from multiple cases in advance, the system performs preliminary action that builds a knowledge base for future prediction. The accumulated data on attacker behaviors, TTPs, and malware characteristics creates a foundation for predicting emerging threats before they fully manifest.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12450348B2Cyber threat information processing apparatus, cyber threat information processing method, and storage medium storing cyber threat information processing program
Publication Date: 2025.10.21 SANDS LAB INC
  • US12450348B2 patent drawing
  • US12450348B2 patent drawing
  • US12450348B2 patent drawing

AI summary

Provided is a cyber threat information processing method including receiving a CTI analysis request for assembly code from a client; analyzing the assembly code to obtain analysis information of the CTI for the assembly code; generating a CTI query related to a file based on the analyzed CTI and delivering the CTI query to a natural language model; and providing natural language description information according to the CTI query obtained from the CTI for the assembly code and the natural language model.