Cyber Threat Information Processing via Natural Language Models

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity technologies struggle to detect and respond to new or variant malware, as well as advanced persistent threat (APT) attacks, due to limitations in pattern recognition and analysis, leading to delayed detection and confusion in identifying attackers and attack techniques.

Innovation Solution

A cyber threat information processing apparatus and method that utilizes natural language processing and machine learning to analyze and identify malware, attack techniques, and attackers, even for variant malware, by processing cyber threat information related to input files and providing standardized and normalized information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If conventional pattern-based detection methods are used, then detection speed is improved for known threats, but detection capability deteriorates for new or variant malware

Engineering Contradiction:
Improvedetection speedVSAvoiddetection capability for new threats
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The system dynamically adapts its analysis approach based on the threat being detected. For known threats, it uses rapid pattern matching; for new or variant malware, it automatically employs more comprehensive static and dynamic analysis methods, allowing the detection system to flexibly adjust its behavior to match the nature of the threat encountered

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes multiple parameters simultaneously including analysis depth, data collection scope, and processing methods. It transitions from shallow pattern matching to deep static and dynamic analysis when dealing with new threats, fundamentally altering how the system processes and evaluates malware samples

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If AI-based malware analysis is used, then analysis capability is improved, but response time deteriorates due to lack of fundamental countermeasure technology

Engineering Contradiction:
Improveanalysis capabilityVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-collecting and organizing vast amounts of malware data, attack patterns, and threat intelligence before actual detection is needed. This preparatory work enables faster response times during actual threats while maintaining high analysis capability through pre-processed information

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates a universal framework that handles multiple types of threats (new malware, variant malware, APT attacks) using integrated methods. It combines pattern recognition, static analysis, dynamic analysis, and threat intelligence into a single multi-functional system that can respond to diverse threats efficiently

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If standardized cyber threat information processing is implemented, then information accuracy is improved, but processing complexity increases

Engineering Contradiction:
Improveinformation accuracyVSAvoidprocessing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system applies homogeneity by standardizing the processing of cyber threat information across all threat types. It uses uniform data structures, consistent analysis methodologies, and standardized output formats for malware detection, attack technique identification, and attacker profiling, making complex processing manageable through consistent patterns

Inventive Principle:
Principle #33Homogeneity

Data Source

PatentUS20250028827A1Cyber threat information processing apparatus, cyber threat information processing method, and storage medium storing cyber threat information processing program
Publication Date: 2025.01.23 SANDS LAB INC
  • US20250028827A1 patent drawing
  • US20250028827A1 patent drawing
  • US20250028827A1 patent drawing

AI summary

Provided is a cyber threat information processing method including receiving a CTI analysis request for a file from a client; analyzing the file to obtain analysis information of the CTI for the file; generating a CTI query related to the file based on the analyzed CTI and delivering the CTI query to a natural language model; and providing natural language description information according to the CTI query obtained from the CTI for the analyzed file and the natural language model to the client as visualization information based on a Web service.