Patents Assigned to Korea Internet & Security Agency
  • Publication number: 20130151526
    Abstract: A social networking service (SNS) trap collection system capable of accurately and effectively extracting and collecting information including a malicious code among information exchanged in an SNS, and a uniform resource location (URL) collection method by the same. URL information for a malicious code included in post (a bulletin script, a message, a note, or the like) exchanged is effectively collected by using an account IDD and a password of account information and utilized for detecting a malicious code in the SNS, thus significantly reducing damage to users due to infection of a malicious code.
    Type: Application
    Filed: November 12, 2012
    Publication date: June 13, 2013
    Applicant: KOREA INTERNET & SECURITY AGENCY
    Inventor: KOREA INTERNET & SECURITY AGENCY
  • Patent number: 8438639
    Abstract: Disclosed is a DDoS attack detection and response apparatus. The DDoS attack detection and response apparatus comprises: a receiver unit receiving HTTP requests from a client terminal which is characterized as an IP address; a data measuring unit computing the number of HTTP requests by IP and the number of URIs per HTTP over a certain time period; a DDoS discrimination unit comparing the number of HTTPs per URI with a threshold value and defining an access of the client terminal having the IP address as a DDoS attack when the number of HTTPs per URI is larger than the threshold value; and a blocking unit blocking packets from the IP address when the DDoS discrimination unit detects a DDoS attack.
    Type: Grant
    Filed: October 20, 2010
    Date of Patent: May 7, 2013
    Assignee: Korea Internet & Security Agency
    Inventors: Tai Jin Lee, YongGeun Won, ChaeTae Im, HyunChul Jeong
  • Patent number: 8375428
    Abstract: The present invention relates to a password input algorithm, more particularly to a password input system and method using alphanumeric matrices. An aspect of the invention can provide a password input system and method using alphanumeric matrices that can defend against keylogging attacks and shoulder surfing attacks by including a movable second alphanumeric matrix and a fixed first alphanumeric matrix and enabling a user to input a password by moving the password letters of the second alphanumeric matrix to the user-defined value of the first alphanumeric matrix. Another aspect of the invention can provide a password input system and method using alphanumeric matrices that can defend against shoulder surfing attacks by enabling a user to input a password by dividing the password by every two digits and moving the cross-points for the two digits, respectively, to the user-defined value of the first alphanumeric matrix.
    Type: Grant
    Filed: June 28, 2010
    Date of Patent: February 12, 2013
    Assignee: Korea Internet & Security Agency
    Inventors: Yoo-Jae Won, Hyun-Cheol Jeong, Hwan-Jin Lee, Byoung-Jin Han
  • Publication number: 20120311709
    Abstract: An automatic management system includes a malicious code group-mutant storage module that receives a malicious codes analysis result from a malicious code collection-analysis system and extracts group information and mutant information of the malicious codes based on the malicious code analysis result, a malicious code group-mutant DB that stores the extracted group information and mutant information, a malicious code group-mutant management module that provides interface to allow a user to detect the group information and mutant information stored in the malicious code group-mutant DB, and a visualizing module that outputs the detection result to the user, wherein the malicious code group-mutant management module that groups malicious codes having action associations using the group information and mutant information stored in the malicious code group-mutant DB, outputs the group information through the visualizing module and outputs the mutant information based on CFG similarity and string similarity throug
    Type: Application
    Filed: November 28, 2011
    Publication date: December 6, 2012
    Applicant: KOREA INTERNET & SECURITY AGENCY
    Inventors: Hong-Koo Kang, Chae-Tae Im, Joo-Hyung Oh, Jong-Il Jeong, Jin-Kyung Lee, Byoung-Ik Kim, Hyun-Cheol Jeong, Seung-Goo Ji, Tai-Jin Lee
  • Patent number: 8259723
    Abstract: A statistical information generator for VoIP traffic analysis is provided, which comprises a packet collection module collecting packets from a network; and a statistical information generation module analyzing information of a call setup packet or a media packet among the packets collected by the packet collection module, and generating statistical information of the network; wherein if the packet collected by the packet collection module is the call setup packet, the statistical information generation module generates the statistical information of the network using at least one of transmitter identification information, receiver identification information, and call identification information among information of the call setup packet as a key value, while if the packet collected by the packet collection module is the media packet, the statistical information generation module generates the statistical information of the network using media session identification information among information of the media p
    Type: Grant
    Filed: December 23, 2009
    Date of Patent: September 4, 2012
    Assignee: Korea Internet & Security Agency
    Inventors: Chang-Yong Lee, Hwan-Kuk Kim, Kyoung-Hee Ko, Hyun-Cheol Jeong
  • Publication number: 20120167220
    Abstract: Provided is seed information collecting device for detecting malicious code landing/hopping/distribution sites. The device comprises: a seed information collecting module collecting social issue keywords from a seed information collecting channel and collecting address information of potential malicious code landing/hopping/distribution sites using the collected social issue keywords; a web source code collecting module collecting web source code of the potential malicious code landing/hopping/distribution sites using the address information of the potential malicious code landing/hopping/distribution sites collected by the seed information collecting module; and a policy management module managing collection policies of the seed information collecting module and the web source code collecting module.
    Type: Application
    Filed: November 28, 2011
    Publication date: June 28, 2012
    Applicant: KOREA INTERNET & SECURITY AGENCY
    Inventors: Jong-Il Jeong, Chae-Tae Im, Joo-Hyung Oh, Hong-Koo Kang, Jin-Kyung Lee, Byoung-Ik Kim, Seung-Goo Ji, Tai-Jin Lee, Hyun-Cheol Jeong
  • Publication number: 20120159625
    Abstract: The present invention provides a malicious code detection and classification system using a string comparison technique, including a string extracting unit configured to extract all expressed strings existing in a binary file from the malicious code binary file; a string refining unit configured to refine elements obstructing malicious code detection and classification in the strings extracted from the string extracting unit; and a string comparison unit configured to determine how similar one binary is to another binary by comparing strings refined from the string refining unit.
    Type: Application
    Filed: October 27, 2011
    Publication date: June 21, 2012
    Applicant: KOREA INTERNET & SECURITY AGENCY
    Inventors: Hyun-Cheol JEONG, Seung-Goo JI, Tai Jin LEE, Jong-Il JEONG, Hong-Koo KANG, Byung-Ik KIM
  • Publication number: 20120159621
    Abstract: The present invention provides a detection system of a suspicious malicious website using the analysis of a JavaScript obfuscation strength, which includes: an entropy measuring block of measuring an entropy of an obfuscated JavaScript present in the website, a special character entropy, and a variable/function name entropy; a frequency measuring block of measuring a specific function frequency, an encoding mark frequency and a % symbol frequency of the JavaScript; a density measuring block of measuring the maximum length of a single character string of the JavaScript; and a malicious website confirming block of determining whether the relevant website is malicious by comparing an obfuscation strength value, measured by the entropy measuring block, the frequency measuring block and the density measuring block, with a threshold value.
    Type: Application
    Filed: October 27, 2011
    Publication date: June 21, 2012
    Applicant: KOREA INTERNET & SECURITY AGENCY
    Inventors: Hyun-Cheol Jeong, Seung-Goo Ji, Tai Jin Lee, Jong-II Jeong, Hong-Koo Kang, Byung-Ik Kim
  • Publication number: 20110103583
    Abstract: A method and a system for preserving sensor data based on a time key, and a recording medium thereof are provided. The time key based sensor data security preserving method includes encrypting the sensor data with an encryption key obtained using a time key based polynomial derived using random numbers and a secret key which is shared by a sensor node and an application system; and decrypting the encrypted sensor data with a decryption key obtained by deriving the same polynomial as the time key based polynomial using the random numbers and the secret key. Thus, integrity and confidentiality of the sensor data can be preserved.
    Type: Application
    Filed: October 28, 2010
    Publication date: May 5, 2011
    Applicant: KOREA INTERNET & SECURITY AGENCY
    Inventors: Mi Yeon Yoon, Mi Joo Kim, Hyun Cheol Jeong