-
公开(公告)号:US10404782B2
公开(公告)日:2019-09-03
申请号:US15331436
申请日:2016-10-21
Inventor: Yang-Seo Choi , Jong-Hyun Kim , Joo-Young Lee , Sun-Oh Choi , Ik-Kyun Kim , Dae-Sung Moon
IPC: H04L12/26 , H04L29/08 , H04L12/851 , H04L12/861
Abstract: Disclosed are an apparatus and method for reconstructing a transmitted file with high performance in real time, which select analysis target packets for reconstruction by first checking using hardware whether data file-related information is present in packets transmitted via large-capacity traffic over a broadband network, and which reconstruct a file in real time only from the selected analysis target packets. The file reconstruction apparatus for reconstructing a data file from packets on a network includes a packet monitoring unit for extracting packets on the network, a collected packet selection unit for determining whether, for the extracted packets, each packet is a reconstruction target based on flow information, and selecting a reconstruction target packet, and a file reconstruction unit for performing file reconstruction by extracting data from the reconstruction target packet and by storing the extracted data as data of a reconstructed file in a relevant flow.
-
公开(公告)号:US12026181B2
公开(公告)日:2024-07-02
申请号:US17552328
申请日:2021-12-15
Inventor: Joo-Young Lee , Ki-Jong Koo , Ik-Kyun Kim , Dae-Sung Moon , Kyung-Min Park
CPC classification number: G06F16/29 , G06F16/2246 , G06F16/2255
Abstract: Disclosed herein are a network environment synchronization apparatus and method. The network environment synchronization apparatus includes one or more processors, and execution memory for storing at least one program that is executed by the one or more processors, wherein the at least one program is configured to collect data from a network environment and generate a management structure in which collected data is distributed into preset respective group units, generate data discriminators for respective group units using a preset hash function, determine whether data of the management structure has changed with reference to data newly collected from the network environment based on the data discriminators, and when it is determined whether data of the management structure has changed, update the data of the management structure with the newly collected data.
-
3.
公开(公告)号:US11790085B2
公开(公告)日:2023-10-17
申请号:US17461337
申请日:2021-08-30
Inventor: Jung-Tae Kim , Ji-Hyeon Song , Jong-Hyun Kim , Sang-Min Lee , Ik-Kyun Kim , Dae-Sung Moon
CPC classification number: G06F21/564 , G06N20/00
Abstract: Disclosed herein are an apparatus for detecting unknown malware using a variable-length operation code (opcode) and a method using the apparatus. The method includes collecting opcode information from a detection target, generating a multi-pixel image having a variable length by performing feature engineering on the opcode information; and detecting unknown malware by inputting the multi-pixel image to a deep-learning model based on AI.
-
4.
公开(公告)号:US11171915B2
公开(公告)日:2021-11-09
申请号:US16452682
申请日:2019-06-26
Inventor: Kyung-Min Park , Samuel Woo , Dae-Sung Moon , Ki-Jong Koo , Ik-Kyun Kim , Joo-Young Lee
Abstract: Disclosed herein are a server apparatus, a client apparatus, and a method for communication based on network address mutation. The method for communication based on network address mutation, performed by the server apparatus and the client apparatus, includes setting the external address of a network interface for receiving a packet from the client apparatus; setting the internal address of a hidden interface in order to forward the packet received through the network interface to the hidden interface; modifying the external address based on a preset network address mutation rule; and communicating with the client apparatus by forwarding the packet, received from the client apparatus based on the modified external address, to the hidden interface.
-
公开(公告)号:US10785252B2
公开(公告)日:2020-09-22
申请号:US15985452
申请日:2018-05-21
Inventor: Jooyoung Lee , Dae-Sung Moon , Kyung-Min Park , Samuel Woo , Ho Hwang , Ik-Kyun Kim , Seung-Hun Jin
IPC: H04L29/06
Abstract: Disclosed herein is an apparatus for enhancing network security, which includes an information collection unit for collecting information about states of hosts that form a network and information about connectivity in the network; an attack surface analysis unit for analyzing attack surfaces by creating an attack graph using the information about the states and the information about connectivity; a security-enhancing strategy establishment unit for establishing a security-enhancing strategy based on the attack graph; and a security-enhancing strategy implementation unit for delivering a measure based on the security-enhancing strategy to a corresponding host, thereby taking a security-enhancing measure.
-
-
-
-