Cyber Threat Intelligence Processing for Variant Malware Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cybersecurity technologies struggle to detect and respond to new or variant malware, decoy information, and advanced persistent threats (APT) effectively, lacking standardized methods for describing malware and attack techniques, and failing to identify attackers accurately.
Innovation Solution
A cyber threat information processing apparatus and method that utilizes a framework with static, dynamic, and correlation analysis, combined with AI, to process cyber threat information, including executable and non-executable files, and provides normalized and standardized cyber threat intelligence.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional pattern-based detection methods are used, then detection speed and accuracy are improved for known malware, but detection capability deteriorates for new or variant malware
Solution Approach 1:
The system performs preliminary actions by collecting and analyzing multiple types of data (static analysis results, dynamic analysis results, threat intelligence) before detection is needed. This creates a comprehensive baseline of known malware patterns and behaviors that enables both fast pattern matching and informed analysis of new threats.
Solution Approach 2:
The system transitions from single-dimension pattern matching to multi-dimensional analysis by integrating static analysis, dynamic analysis, and threat intelligence data. This dimensional expansion allows the system to detect malware through multiple indicators simultaneously, improving both accuracy for known threats and adaptability to new threats.
2Productivity
If AI-based malware analysis is used, then analysis capability is improved, but fundamental technology to counter new threats is lacking
Solution Approach 1:
The system introduces threat intelligence as an intermediary layer between AI analysis and detection decisions. This intermediary provides contextual information about emerging threats, attack patterns, and indicators of compromise that guides AI analysis and enables reliable detection of new threats even when training data is limited.
Solution Approach 2:
The system creates a composite detection approach by combining AI-based static analysis, dynamic analysis, and threat intelligence data. This composite methodology leverages the strengths of each component: AI provides automated analysis capability, dynamic analysis provides behavioral evidence, and threat intelligence provides contextual awareness of new threats.
3Loss of information
If standardized description methods are implemented, then information normalization is improved, but system complexity increases
Solution Approach 1:
The system implements universal data structures and standardized fields that serve multiple functions: they normalize information from diverse sources, enable consistent storage and retrieval, support various analysis methods, and facilitate threat intelligence sharing. This multi-functionality reduces the need for separate systems for each purpose.
Data Source
AI summary
A cyber threat information processing method including receiving input of a file or information on the file from a user through at least one interface; processing cyber threat information related to the received or input file or the information on the file; and providing the processed cyber threat information to the user through a user interface. The cyber threat information includes a dataset package.


