Patents by Inventor Sae Woom LEE
Sae Woom LEE has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 12657292Abstract: Disclosed are a system and method for automatically generating a playbook and verifying validity of a playbook based on artificial intelligence, wherein the system present invention includes a system for automatically generating a playbook that automatically generates the playbook, and a system for verifying validity of a playbook that is connected to the system for automatically generating a playbook through a network to perform the verification of the validity on the playbook received from the system for automatically generating a playbook.Type: GrantFiled: October 31, 2023Date of Patent: June 16, 2026Assignee: Korea Internet & Security AgencyInventors: Do Won Kim, Tae Eun Kim, Ki Jong Son, Sae Woom Lee, Seul Ki Choi, Tae Hyeon Kim, Gyeong Jin Na
-
Patent number: 12651079Abstract: A method and system of enhancing cyber resilience performed by a computing system is disclosed. According to one embodiment of the present disclosure, the method may comprise a step of acquiring vulnerability data of a target system based on resilience feature data including a quantitative assessment vector and a non-quantitative assessment text of the target system, a step of inputting input data including the vulnerability data into an artificial intelligence model and generating an enhancement strategy for the target system based on output of the artificial intelligence model and a step of controlling a security layer of the target system based on the enhancement strategy.Type: GrantFiled: January 27, 2026Date of Patent: June 9, 2026Assignee: KOREA INTERNET & SECURITY AGENCYInventors: Seul Ki Choi, Joon Hyung Lim, Dong Hwan Oh, Tae Eun Kim, Sae Woom Lee, Tae Hyeon Kim, Seo Yeon Kim
-
Patent number: 12452295Abstract: There is provided a method for automatically generating a cyber crisis scenario, performed by a computing system. The method may comprise classifying types of content included in a cyber crisis report and extracting image data and text data from the cyber crisis report, inputting the image data into an image processing model and extracting attack procedure/behavior information included in the image data, inputting the text data into a text processing model and generating structured attack procedure-related data from each attack procedure included in the text data, generating threat behavior data corresponding to the attack procedure-related data, and merging the threat behavior data with the attack procedure-related data, matching the attack procedure-related data to the attack procedure/behavior information and generating a cyber crisis scenario template and automatically generating a cyber crisis scenario based on the attack procedure-related data and the cyber crisis scenario template.Type: GrantFiled: April 18, 2025Date of Patent: October 21, 2025Assignee: KOREA INTERNET & SECURITY AGENCYInventors: Seo Yeon Kim, Joon Hyung Lim, Dong Hwan Oh, Tae Eun Kim, Sae Woom Lee, Seul Ki Choi, Tae Hyeon Kim
-
Patent number: 12393683Abstract: A method of supporting decision-making of security control includes: (a) when an system for automatically analyzing a security threat receives a security warning from a security device, collecting security threat events generating the security warning from the security device; (b) when the collected security threat events exceed a preset event processing threshold, generating, by the system for automatically analyzing a security threat, a first request message for preferentially processing a security event; (c) when receiving the first request message generated from the system, determining, by the system for supporting priority of security control, a priority processing order of the security threat events, and notifying the system; and (d) when receiving the second request message generated from the system, determining, by the system for supporting priority of security control, a priority processing order and notifying the system for automatically analyzing a security threat of the determined priority processType: GrantFiled: October 31, 2023Date of Patent: August 19, 2025Assignee: Korea Internet & Security AgencyInventors: Do Won Kim, Tae Eun Kim, Ki Jong Son, Sae Woom Lee, Seul Ki Choi, Tae Hyeon Kim, Gyeong Jin Na
-
Patent number: 12124573Abstract: An event processing method performed by a computing device is provided. The method may comprise receiving a plurality of events and generating a first event sequence in which the received events are sequentially arranged, determining first priorities for the events included in the first event sequence, using data output from a previously trained priority decision model, verifying the first priorities by comparing the first priorities with second priorities for the events included in the first event sequence, determining a feedback score for the first priorities based on results of the verification; and reinforcing the training of the priority decision model using the feedback score.Type: GrantFiled: January 24, 2024Date of Patent: October 22, 2024Assignee: KOREA INTERNET & SECURITY AGENCYInventors: Joon Hyung Lim, Tae Eun Kim, Ki Jong Son, Sae Woom Lee, Seul Ki Choi, Tae Hyeon Kim
-
Patent number: 12107899Abstract: The method for automatically generating a playbook performed by a computing apparatus according to the present disclosure comprises periodically collecting asset information and CTI (Cyber Threat Intelligence) information of a target network, extracting TTP (Tactics, Techniques, Procedure) information using the collected asset information and the collected CTI information, retrieving a data source of the extracted TTP information, generating a temporary playbook including a data component matching a detection method of the extracted TTP information among a plurality of data components of the retrieved data source, verifying validity of the temporary playbook based on data component order information of the temporary playbook and determining whether rearrangement of data components included in the temporary playbook is needed, and rearranging data components included in the temporary playbook, and storing it as a final playbook.Type: GrantFiled: January 23, 2024Date of Patent: October 1, 2024Assignee: KOREA INTERNET & SECURITY AGENCYInventors: Joon Hyung Lim, Tae Eun Kim, Ki Jong Son, Sae Woom Lee, Seul Ki Choi, Tae Hyeon Kim
-
Publication number: 20240152608Abstract: A method of supporting decision-making of security control includes: (a) when an system for automatically analyzing a security threat receives a security warning from a security device, collecting security threat events generating the security warning from the security device; (b) when the collected security threat events exceed a preset event processing threshold, generating, by the system for automatically analyzing a security threat, a first request message for preferentially processing a security event; (c) when receiving the first request message generated from the system, determining, by the system for supporting priority of security control, a priority processing order of the security threat events, and notifying the system; and (d) when receiving the second request message generated from the system, determining, by the system for supporting priority of security control, a priority processing order and notifying the system for automatically analyzing a security threat of the determined priority processType: ApplicationFiled: October 31, 2023Publication date: May 9, 2024Applicant: Korea Internet & Security AgencyInventors: Do Won KIM, Tae Eun KIM, Ki Jong SON, Sae Woom LEE, Seul Ki CHOI, Tae Hyeon KIM, Gyeong Jin NA
-
Publication number: 20240154990Abstract: A device for automatically sorting a cyber attack includes an event feature generator that extracts a unique attacker IP by analyzing attacker IPs for each of the different kinds of security devices, and generates AI learning features of the security events of the different kinds of security devices including feature numerical data quantifying at least two or more features through attack information analysis recorded in the different kinds of security devices based on the information on the security events of the different kinds of security devices mapped to the extracted unique attacker IP, and an attack type sorter that learns the generated feature numerical data using an unsupervised learning algorithm, generates clustering data by sorting the feature numerical data into similar attack data and clustering sorted feature numerical data, and then analyzes the generated clustering data to identify a short-term or long-term attacker's cyber attack type.Type: ApplicationFiled: October 31, 2023Publication date: May 9, 2024Applicant: Korea Internet & Security AgencyInventors: Do Won KIM, Tae Eun KIM, Ki Jong SON, Sae Woom LEE, Seul Ki CHOI, Tae Hyeon KIM, Gyeong Jin NA
-
Publication number: 20240152604Abstract: Disclosed are a system and method for automatically generating a playbook and verifying validity of a playbook based on artificial intelligence, wherein the system present invention includes a system for automatically generating a playbook that automatically generates the playbook, and a system for verifying validity of a playbook that is connected to the system for automatically generating a playbook through a network to perform the verification of the validity on the playbook received from the system for automatically generating a playbook.Type: ApplicationFiled: October 31, 2023Publication date: May 9, 2024Applicant: Korea Internet & Security AgencyInventors: Do Won KIM, Tae Eun KIM, Ki Jong SON, Sae Woom LEE, Seul Ki CHOI, Tae Hyeon KIM, Gyeong Jin NA
-
Publication number: 20110128131Abstract: The present invention relates to a wireless sensor network, and more particularly, to a head node selection method for clustering in a wireless sensor network and a wireless sensor network. The wireless sensor network for determining a head node that includes: a first node; and a second node wirelessly being in communication with the first node, wherein the first node broadcasts a final head node message which is a message indicating that the first node itself is a final head node to the second node if the residual energy of the first node is larger than the residual energy of the neighboring nodes. It is therefore possible to minimize clustering process time.Type: ApplicationFiled: November 29, 2010Publication date: June 2, 2011Applicant: Gwangju Institute of Science TechnologyInventors: Ki Seon KIM, Jeong Hwan YOON, Sae Woom LEE