Cyber Threat Intelligence Processing for Variant Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity technologies struggle to detect and respond to new or variant malware, decoy information, and advanced persistent threats (APT) effectively, lacking standardized methods for describing malware and attack techniques, and failing to identify attackers accurately.

Innovation Solution

A cyber threat information processing apparatus and method that utilizes a framework with static, dynamic, and correlation analysis, combined with AI, to process cyber threat information, including executable and non-executable files, and provides normalized and standardized cyber threat intelligence.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional pattern-based detection methods are used, then detection speed and accuracy are improved for known malware, but detection capability deteriorates for new or variant malware

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection capability for new malware
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by collecting and analyzing multiple types of data (static analysis results, dynamic analysis results, threat intelligence) before detection is needed. This creates a comprehensive baseline of known malware patterns and behaviors that enables both fast pattern matching and informed analysis of new threats.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system transitions from single-dimension pattern matching to multi-dimensional analysis by integrating static analysis, dynamic analysis, and threat intelligence data. This dimensional expansion allows the system to detect malware through multiple indicators simultaneously, improving both accuracy for known threats and adaptability to new threats.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Productivity

If AI-based malware analysis is used, then analysis capability is improved, but fundamental technology to counter new threats is lacking

Engineering Contradiction:
Improveanalysis capabilityVSAvoideffectiveness against new threats
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system introduces threat intelligence as an intermediary layer between AI analysis and detection decisions. This intermediary provides contextual information about emerging threats, attack patterns, and indicators of compromise that guides AI analysis and enables reliable detection of new threats even when training data is limited.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a composite detection approach by combining AI-based static analysis, dynamic analysis, and threat intelligence data. This composite methodology leverages the strengths of each component: AI provides automated analysis capability, dynamic analysis provides behavioral evidence, and threat intelligence provides contextual awareness of new threats.

Inventive Principle:
Principle #40Composite materials

3Loss of information

If standardized description methods are implemented, then information normalization is improved, but system complexity increases

Engineering Contradiction:
Improveinformation normalizationVSAvoidstandardization system complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system implements universal data structures and standardized fields that serve multiple functions: they normalize information from diverse sources, enable consistent storage and retrieval, support various analysis methods, and facilitate threat intelligence sharing. This multi-functionality reduces the need for separate systems for each purpose.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12572654B2Cyber threat information processing apparatus, cyber threat information processing method, and storage medium storing cyber threat information processing program
Publication Date: 2026.03.10 SANDS LAB INC
  • US12572654B2 patent drawing
  • US12572654B2 patent drawing
  • US12572654B2 patent drawing

AI summary

A cyber threat information processing method including receiving input of a file or information on the file from a user through at least one interface; processing cyber threat information related to the received or input file or the information on the file; and providing the processed cyber threat information to the user through a user interface. The cyber threat information includes a dataset package.