Cyber Threat Information Processing Using Natural Language Models

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity technologies struggle to detect and respond to new or variant malware, as well as advanced persistent threat (APT) attacks, due to limitations in pattern recognition and analysis, leading to delayed detection and confusion in identifying attackers and attack techniques.

Innovation Solution

A cyber threat information processing apparatus and method that utilizes natural language processing and machine learning to analyze and identify malware, attack techniques, and attackers, even for variant malware, by processing cyber threat information related to input files and providing standardized and normalized descriptions of cyber threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional pattern recognition and monitoring technologies are used to detect malware, then detection speed and accuracy are improved for known threats, but the ability to detect new or variant malware deteriorates

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection capability for new malware
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by pre-defining attack techniques and building knowledge bases before threats occur. It analyzes malware samples in advance to extract features and patterns, creating a foundation for detecting both known and unknown threats. This preliminary preparation enables the system to recognize new malware variants based on their attack technique characteristics rather than requiring pre-existing specific patterns.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes the detection parameters from static pattern matching to dynamic attack technique analysis. Instead of relying on fixed malware signatures, it transforms malware characteristics into standardized attack technique parameters, allowing flexible detection across different malware variants and types while maintaining consistent identification criteria.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If AI analysis is used to detect and analyze malware, then analysis capability is improved, but the ability to address new or variant malware deteriorates due to reliance on learned patterns

Engineering Contradiction:
Improveanalysis capabilityVSAvoidresponse to new malware variants
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary action by pre-establishing attack technique knowledge bases and analysis frameworks before encountering new malware. It prepares standardized classification criteria and attack technique definitions in advance, enabling rapid identification of new variants without requiring retraining of AI models. This preliminary knowledge structure allows the system to handle novel threats effectively.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces attack technique analysis as an intermediary layer between raw malware data and final detection conclusions. This intermediary framework translates diverse malware characteristics into standardized attack technique categories, serving as a mediator that enables consistent analysis and response to new variants while maintaining the productivity benefits of AI processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Speed

If decentralized malware detection methods are used, then local response speed is improved, but standardization of attack technique descriptions deteriorates

Engineering Contradiction:
Improvelocal response speedVSAvoidstandardization of attack descriptions
Core Design Contradiction:
SpeedVSLoss of information

Solution Approach 1:

The system implements universality by establishing a common attack technique knowledge base that serves multiple functions: local rapid detection, standardized description generation, and centralized coordination. This universal framework operates at both local and central levels, enabling decentralized quick response while maintaining consistent standardized descriptions through the shared knowledge structure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system employs feedback mechanisms where local detection results are fed back into the centralized knowledge base, and standardized attack technique descriptions are continuously refined based on actual detection data. This feedback loop ensures that local response speed is maintained while progressively improving standardization through real-world validation and correction of attack technique classifications.

Inventive Principle:
Principle #23Feedback

4Measurement precision

If focus is placed on detecting malware itself, then malware identification is improved, but the ability to identify attackers and attack techniques deteriorates

Engineering Contradiction:
Improvemalware identification accuracyVSAvoidattacker and attack technique identification
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The system applies segmentation by dividing malware analysis into distinct components: malware identification, attack technique characterization, and attacker attribution. This segmentation allows each component to be analyzed and identified independently with specialized methods, improving overall precision while enabling comprehensive identification of all three elements rather than focusing on malware alone.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system adds another dimension to malware analysis by transitioning from single-dimensional malware signature matching to multi-dimensional attack technique analysis. This dimensional expansion incorporates attacker behavior patterns, attack methodology, and contextual information alongside traditional malware characteristics, enabling simultaneous identification of malware, attackers, and techniques through enriched analysis layers.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS20250028818A1Cyber threat information processing apparatus, cyber threat information processing method, and storage medium storing cyber threat information processing program
Publication Date: 2025.01.23 SANDS LAB INC
  • US20250028818A1 patent drawing
  • US20250028818A1 patent drawing
  • US20250028818A1 patent drawing

AI summary

Provided is a cyber threat information processing method including receiving a CTI analysis request for a document script included in a file from a client; analyzing the document script to obtain analysis information of the CTI for the document script; generating a CTI query related to the document script based on the analysis information of the CTI and delivering the CTI query to a natural language model; and providing natural language description information according to the CTI query from the analysis information of the CTI and the natural language model to the client as visualization information.