Cyber Threat Information Processing Using Natural Language Models
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cybersecurity technologies struggle to detect and respond to new or variant malware, decoy information, and advanced persistent threat (APT) attacks, due to limitations in pattern recognition and analysis.
Innovation Solution
A cyber threat information processing apparatus and method that utilizes natural language processing and machine learning to identify and analyze malware, attack techniques, and attackers, even for variant malware, and provides standardized and normalized cyber threat information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional pattern matching technology is used for malware detection, then detection speed and accuracy are improved for known malware, but detection capability deteriorates for new or variant malware
Solution Approach 1:
The system performs preliminary actions by collecting and analyzing cyber threat information from multiple sources before actual malware detection is needed. It builds a comprehensive knowledge base of attack techniques, tactics, and procedures (TTPs) in advance, enabling faster and more accurate detection of both known and new malware variants without relying solely on pre-existing pattern databases.
Solution Approach 2:
The invention transitions from traditional single-dimension pattern matching to multi-dimensional analysis by examining malware through multiple lenses: attack techniques, tactics, procedures, indicators of compromise (IOCs), and threat intelligence data. This dimensional expansion enables the system to detect new and variant malware by recognizing patterns across different analytical dimensions rather than relying on exact code matching.
2Productivity
If AI analysis is used for malware detection, then analysis capability is improved, but fundamental technology to counter cybersecurity threats remains lacking
Solution Approach 1:
The system introduces cyber threat information and threat intelligence as intermediary elements between raw malware samples and AI analysis. By incorporating structured threat intelligence data about attack techniques, tactics, and procedures as mediators, the system enhances AI analysis capability while grounding it in fundamental cybersecurity knowledge, thereby improving both productivity and reliability simultaneously.
Solution Approach 2:
The invention creates a composite analytical framework that combines multiple types of information: malware code analysis, threat intelligence data, attack technique databases, indicator of compromise (IOC) information, and AI processing. This composite approach integrates diverse data sources and analytical methods into a unified system that maintains both high analysis capability and fundamental reliability for countermeasure development.
3Loss of information
If standardized cyber threat information is provided, then information normalization is improved, but processing complexity increases
Solution Approach 1:
The system segments cyber threat information into standardized, modular components such as attack techniques, tactics, procedures, and indicators of compromise (IOCs). By dividing complex threat intelligence data into discrete, standardized segments with defined schemas, the system achieves information normalization while managing processing complexity through structured modularity rather than monolithic processing.
Data Source
AI summary
Provided is a cyber threat information processing method including receiving a CTI analysis request for a file from a client; analyzing the file to obtain analysis information of the CTI for the file; generating a CTI query related to the file based on the analyzed CTI and delivering the CTI query to a natural language model; and providing natural language description information according to the CTI query obtained from the CTI for the analyzed file and the natural language model.


