Cyber Threat Information Processing with NLP for New Malware

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity technologies struggle to detect and respond to new or variant malware, decoy information, and advanced persistent threats, lacking standardization in malware description and attacker identification, and are ineffective in predicting future cyber threats.

Innovation Solution

A cyber threat information processing apparatus and method utilizing natural language processing, machine learning, and AI to identify malware, attackers, and predict future attacks, providing normalized and standardized cyber threat information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional pattern-matching detection methods are used, then detection speed and accuracy are improved for known malware, but detection capability deteriorates for new or variant malware without established patterns

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection capability for new malware
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by collecting and analyzing malware samples, attacker infrastructure data, and attack patterns in advance to build comprehensive threat intelligence databases. This enables the system to detect new malware variants by comparing them against known attacker patterns and infrastructure, even when exact pattern matches don't exist

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces intermediary elements including natural language processing layers that translate technical cyber threat data into standardized, interpretable formats, and multi-layered analysis frameworks that bridge pattern-matching detection and AI-based behavioral analysis. These intermediaries enable seamless transition between detecting known patterns and identifying new threats

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If AI analysis is used to detect and analyze malware, then analysis capability is improved, but fundamental technology to counter cybersecurity threats remains lacking

Engineering Contradiction:
Improveanalysis capabilityVSAvoidfundamental countermeasure technology
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system combines multiple analytical approaches into a composite detection framework: pattern-matching algorithms for known threats, AI-based behavioral analysis for anomaly detection, natural language processing for threat intelligence extraction, and correlation engines for contextualizing findings. This composite approach maintains high productivity while establishing reliable fundamental countermeasure capabilities

Inventive Principle:
Principle #40Composite materials

Solution Approach 2:

The system creates universal, standardized technologies for cyber threat detection including normalized data schemas, standardized threat classification frameworks, and multi-purpose analysis engines that can handle diverse threat types (malware, phishing, APTs) through unified methodologies, making fundamental countermeasure technology applicable across different security contexts

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If decoy information or fake information is used to deceive detection systems, then attacker success rate is improved, but detection system reliability deteriorates due to confusion

Engineering Contradiction:
Improveattacker deception capabilityVSAvoiddetection system reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system implements feedback mechanisms where detected decoy information and fake data are analyzed to understand attacker deception patterns. This feedback is then used to refine detection algorithms, improve pattern recognition accuracy, and update threat intelligence databases, thereby maintaining reliability even when attackers use sophisticated deception techniques

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system converts harmful decoy information and fake data into beneficial intelligence by analyzing these deceptive elements to identify attacker patterns, tactics, and infrastructure. Rather than being misled, the system uses decoys as additional data points to improve detection capabilities and understand attacker methodologies

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

4Adaptability or versatility

If malware detection names and attack techniques are not unified, then flexibility in description is improved, but identification accuracy and standardization deteriorate

Engineering Contradiction:
Improvedescription flexibilityVSAvoididentification accuracy
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The system changes parameters by implementing standardized naming conventions and classification frameworks for malware and attack techniques. These standardized parameters enable precise identification and consistent classification across different threats while maintaining the ability to describe diverse attack vectors through a unified taxonomy

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12411946B2Cyber threat information processing apparatus, cyber threat information processing method, and storage medium storing cyber threat information processing program
Publication Date: 2025.09.09 SANDS LAB INC
  • US12411946B2 patent drawing
  • US12411946B2 patent drawing
  • US12411946B2 patent drawing

AI summary

Provided is a cyber threat information processing method including receiving input of a file or information on the file from a user through at least one interface; processing cyber threat information related to the received or input file or the information on the file; providing the processed cyber threat information to the user through a user interface; and performing natural language processing on the processed cyber threat information.