首页> 外国专利> APPARATUS FOR PROCESSING CYBER THREAT INFORMATION, METHOD FOR PROCESSING CYBER THREAT INFORMATION, AND MEDIUM FOR STORING A PROGRAM PROCESSING CYBER THREAT INFORMATION

APPARATUS FOR PROCESSING CYBER THREAT INFORMATION, METHOD FOR PROCESSING CYBER THREAT INFORMATION, AND MEDIUM FOR STORING A PROGRAM PROCESSING CYBER THREAT INFORMATION

机译:用于处理网络威胁信息的装置,用于处理网络威胁信息的方法,以及存储处理网络威胁信息的程序的媒介

摘要

The disclosed embodiment provides a cyber threat information processing apparatus, a cyber threat information processing method, and a storage medium storing a cyber threat information processing program. As an embodiment of the present invention, the method comprising: disassembling an input executable file to obtain disassembled code, and reconstructing the disassembled code to obtain a reconstructed disassembled code; converting the reconstructed disassembled code into a hash function and converting the hash function into N-gram (N-gram, N is a natural number) data; and an identifier of an attack technique in which the block unit code performs the block unit code by performing ensemble machine learning on the block unit code of the converted N-gram data, and the block unit code. It is possible to provide a method for processing cyber security threat information, including a step of profiling with the generated attacker's identifier. According to the embodiment, it is possible to detect and respond to malicious code that does not exactly match the data learned by artificial intelligence, and to respond to a variant of the malicious code. method can be identified.
机译:所公开的实施例提供了一种网络威胁信息处理装置,网络威胁信息处理方法和存储网络威胁信息处理程序的存储介质。作为本发明的一个实施例,该方法包括:拆卸输入可执行文件以获得分解代码,并重建分解代码以获得重建的分解代码;将重建的分解代码转换为哈希函数并将哈希函数转换为n克(n-gram,n是自然数)数据;和攻击技术的标识符,其中块单元代码通过对转换的n-gram数据的块单元代码和块单元代码执行集合机器学习来执行块单元代码。可以提供用于处理网络安全威胁信息的方法,包括与生成的攻击者的标识符分析的步骤。根据该实施例,可以检测和响应与人工智能学到的数据不完全匹配的恶意代码,并响应恶意代码的变体。可以识别方法。

著录项

  • 公开/公告号KR102362516B1

    专利类型

  • 公开/公告日2022-02-15

    原文格式PDF

  • 申请/专利权人

    申请/专利号KR1020210106217

  • 发明设计人 김기홍;어성율;박성은;이현종;

    申请日2021-08-11

  • 分类号G06F21/56;G06N20;

  • 国家 KR

  • 入库时间 2022-08-24 23:38:44

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号