Cyber Threat Information Processing Using Natural Language Models

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity technologies struggle to detect and respond to new or variant malware, decoy information, and advanced persistent threat (APT) attacks, due to limitations in pattern recognition and analysis.

Innovation Solution

A cyber threat information processing apparatus and method that utilizes natural language processing and machine learning to identify and analyze malware, attack techniques, and attackers, even for variant malware, and provides standardized and normalized cyber threat information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional pattern matching technology is used for malware detection, then detection speed and accuracy are improved for known malware, but detection capability deteriorates for new or variant malware

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection capability for new malware
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by collecting and analyzing cyber threat information from multiple sources before actual malware detection is needed. It builds a comprehensive knowledge base of attack techniques, tactics, and procedures (TTPs) in advance, enabling faster and more accurate detection of both known and new malware variants without relying solely on pre-existing pattern databases.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention transitions from traditional single-dimension pattern matching to multi-dimensional analysis by examining malware through multiple lenses: attack techniques, tactics, procedures, indicators of compromise (IOCs), and threat intelligence data. This dimensional expansion enables the system to detect new and variant malware by recognizing patterns across different analytical dimensions rather than relying on exact code matching.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Productivity

If AI analysis is used for malware detection, then analysis capability is improved, but fundamental technology to counter cybersecurity threats remains lacking

Engineering Contradiction:
Improveanalysis capabilityVSAvoidfundamental countermeasure technology
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system introduces cyber threat information and threat intelligence as intermediary elements between raw malware samples and AI analysis. By incorporating structured threat intelligence data about attack techniques, tactics, and procedures as mediators, the system enhances AI analysis capability while grounding it in fundamental cybersecurity knowledge, thereby improving both productivity and reliability simultaneously.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The invention creates a composite analytical framework that combines multiple types of information: malware code analysis, threat intelligence data, attack technique databases, indicator of compromise (IOC) information, and AI processing. This composite approach integrates diverse data sources and analytical methods into a unified system that maintains both high analysis capability and fundamental reliability for countermeasure development.

Inventive Principle:
Principle #40Composite materials

3Loss of information

If standardized cyber threat information is provided, then information normalization is improved, but processing complexity increases

Engineering Contradiction:
Improveinformation normalizationVSAvoidprocessing complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system segments cyber threat information into standardized, modular components such as attack techniques, tactics, procedures, and indicators of compromise (IOCs). By dividing complex threat intelligence data into discrete, standardized segments with defined schemas, the system achieves information normalization while managing processing complexity through structured modularity rather than monolithic processing.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250028826A1Cyber threat information processing apparatus, cyber threat information processing method, and storage medium storing cyber threat information processing program
Publication Date: 2025.01.23 SANDS LAB INC
  • US20250028826A1 patent drawing
  • US20250028826A1 patent drawing
  • US20250028826A1 patent drawing

AI summary

Provided is a cyber threat information processing method including receiving a CTI analysis request for a file from a client; analyzing the file to obtain analysis information of the CTI for the file; generating a CTI query related to the file based on the analyzed CTI and delivering the CTI query to a natural language model; and providing natural language description information according to the CTI query obtained from the CTI for the analyzed file and the natural language model.