Cyber Threat Query Generation for Variant Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity technologies struggle to detect and respond to new or variant malware, decoy information, and advanced persistent threats (APT) effectively, lacking standardized description methods for malware and attack techniques, and are limited in predicting future cyber threats.

Innovation Solution

A cyber threat information processing apparatus and method utilizing natural language processing to identify malware, attack techniques, and attackers through machine learning, enabling standardized description and prediction of cyber threats, even for variants, by integrating static, dynamic, and correlation analysis with AI-based prediction.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional pattern-based detection methods are used, then detection speed and accuracy for known malware is improved, but detection capability for new or variant malware deteriorates

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection capability for new malware
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by collecting and analyzing malware samples, attack techniques, and attacker information in advance to build comprehensive databases. This preliminary data collection and analysis enables the system to detect new and variant malware through pattern recognition and correlation analysis, resolving the contradiction between detection accuracy for known malware and adaptability to new threats.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates standardized copies and representations of malware characteristics, attack techniques, and attacker profiles through structured data models. By copying and standardizing threat information into reusable formats with unique identifiers, the system maintains detection accuracy while improving adaptability to new threats through efficient pattern matching and correlation.

Inventive Principle:
Principle #26Copying

2Productivity

If AI-based malware analysis is used, then analysis capability for mass-produced malware is improved, but effectiveness against APT attacks and targeted attacks deteriorates

Engineering Contradiction:
Improveanalysis capabilityVSAvoideffectiveness against targeted attacks
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system segments threat analysis into multiple specialized components: malware sample analysis, attack technique analysis, attacker information analysis, and correlation analysis. This segmentation allows AI to efficiently process mass-produced malware while dedicated correlation analysis components handle sophisticated APT and targeted attacks by linking multiple data points, thereby maintaining both productivity and reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates a universal threat information processing framework that handles multiple attack types through integrated analysis. By universalizing the data collection and correlation mechanisms to work across different threat scenarios (mass-produced malware, APT, targeted attacks), the system maintains high productivity while ensuring reliability through comprehensive multi-functional analysis capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If standardized description methods for malware and attack techniques are implemented, then identification accuracy and prediction capability are improved, but system complexity increases

Engineering Contradiction:
Improveidentification accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system changes parameters by establishing standardized data structures, unique identifier systems, and classification schemes for malware, attack techniques, and attackers. These parameter standardizations improve identification accuracy and prediction capability while the modular implementation approach manages system complexity through organized, reusable components.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12591670B2Cyber threat information processing apparatus, cyber threat information processing method, and storage medium storing cyber threat information processing program
Publication Date: 2026.03.31 SANDS LAB INC
  • US12591670B2 patent drawing
  • US12591670B2 patent drawing
  • US12591670B2 patent drawing

AI summary

A cyber threat information processing method including receiving a CTI analysis request for a document script from a client; analyzing the document script to obtain analysis information of the CTI for the script; generating a CTI query related to the document script based on the analysis information of the CTI and delivering the CTI query to a natural language model; and providing natural language description information according to the CTI query from the analysis information of the CTI and the natural language model to the client.