Patents by Inventor Ho-Sang YUN

Ho-Sang YUN has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 10097569
    Abstract: An attack tracking system includes multiple hosts in which first event data concerning object behavior are collected and pieces of host-based event information are created therefrom; a tracking information database server storing the pieces of host-based event information; a tracking information analysis server creating behavior events by defining malware behavior from the pieces of host-based event information, retrieving targets to be analyzed from the pieces of host-based event information and the behavior events based on a preset input value, creating first tracking contexts for identifying the malware behavior by analyzing the relationship between the pieces of host-based event information and the relationship between a set of the pieces of host-based event information and a set of the behavior events, and creating second tracking contexts tracking malware routes and behavior events between the multiple hosts by analyzing the correlation between the first tracking contexts.
    Type: Grant
    Filed: September 23, 2016
    Date of Patent: October 9, 2018
    Assignee: AGENCY FOR DEFENSE DEVELOPMENT
    Inventors: Il-Hoon Jeong, Hwa-Seong Lee, Chang-Hee Choi, Ho-Sang Yun
  • Publication number: 20170374086
    Abstract: An attack tracking system includes multiple hosts in which first event data concerning object behavior are collected and pieces of host-based event information are created therefrom; a tracking information database server storing the pieces of host-based event information; a tracking information analysis server creating behavior events by defining malware behavior from the pieces of host-based event information, retrieving targets to be analyzed from the pieces of host-based event information and the behavior events based on a preset input value, creating first tracking contexts for identifying the malware behavior by analyzing the relationship between the pieces of host-based event information and the relationship between a set of the pieces of host-based event information and a set of the behavior events, and creating second tracking contexts tracking malware routes and behavior events between the multiple hosts by analyzing the correlation between the first tracking contexts.
    Type: Application
    Filed: September 23, 2016
    Publication date: December 28, 2017
    Inventors: Il-Hoon JEONG, Hwa-Seong LEE, Chang-Hee CHOI, Ho-Sang YUN