A threat intelligence fusion method and device, electronic equipment and storage medium
By filtering high-confidence threat intelligence data and performing type-specific data fusion, the problem of inconsistency in threat intelligence data from different sources was solved, improving the accuracy and consistency of threat intelligence data.
Patent Information
- Application Number
- CN202211325303.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-27
- Publication Date
- 2026-03-20
- Estimated Expiration
- 2042-10-27
AI Technical Summary
Because threat intelligence data from different sources are produced in different ways and have different data processing capabilities, there are differences in attributes and inconsistent judgment results, which affects the effective use of threat intelligence data.
By setting a confidence threshold for intelligence sources, high-confidence threat intelligence data is filtered out, and data fusion processing is performed according to the judgment type to generate accurate fused threat intelligence data.
It improved the accuracy of threat intelligence data, avoided the fusion of low-accuracy data, and ensured the accuracy and consistency of subsequent use.
Smart Images

Figure CN115643094B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of information security, and in particular to a threat intelligence fusion method and device, an electronic device, and a storage medium. BACKGROUND
[0002] With the diversified development of network attack means and channels, network security threats are showing a trend of diversification and complication. Threat intelligence data, as evidence-based knowledge (i.e. computer-recognizable data), has a very important value in network security threat detection, security defense, attack action or threat organization tracing, and in actual application scenarios, it plays a role in rapid and comprehensive response capability to effectively discover known or potential security threats in victim networks.
[0003] In actual application processes, due to the limited coverage of threat intelligence data provided by various threat intelligence data providers or data sources, customers usually use threat intelligence data from multiple sources in order to achieve effective network security protection. However, due to the different production methods and data processing capabilities of threat intelligence data from different sources, the attributes or description contents involved in the threat intelligence data are different, and even the determination results in the threat intelligence data corresponding to the same intelligence value produced by different sources are inconsistent. The determination result is the basis for determining the use scheme of the threat intelligence data, and if there are multiple different determination results for the same intelligence value, the use scheme of the threat intelligence data cannot be determined. SUMMARY
[0004] Therefore, the present application provides a threat intelligence fusion method, device, electronic device and storage medium, which at least partially solves the problems in the prior art.
[0005] In one aspect of the present application, a threat intelligence fusion method is provided, comprising:
[0006] Obtaining a plurality of threat intelligence data to be fused, each of which has a target intelligence value. The threat intelligence data to be fused includes an intelligence value and intelligence determination information. The intelligence determination information includes a plurality of determination values, the determination values in the same threat intelligence data to be processed correspond to different determination types, and the determination values include an intelligence source confidence value.
[0007] Determining the threat intelligence data to be fused with an intelligence source confidence value greater than a first threshold value as target threat intelligence data.
[0008] For each determination type, performing data fusion processing on the determination value corresponding to the current determination type in each target threat intelligence data to obtain a fused determination value corresponding to each determination type.
[0009] Based on the target intelligence value and each fused judgment value, fused threat intelligence data is generated.
[0010] In one exemplary embodiment of this application, before acquiring a plurality of threat intelligence data to be fused, all of which have the target intelligence value, the method further includes:
[0011] Obtain intelligence values from several threat intelligence data to be processed.
[0012] Each intelligence value is traversed. If the current intelligence value corresponds to multiple threat intelligence data to be processed, the current intelligence value is determined as the target intelligence value, and the threat intelligence data to be processed corresponding to the target intelligence value is determined as the threat intelligence data to be fused.
[0013] If the current intelligence value corresponds to only one threat intelligence data to be processed, determine whether the intelligence source confidence value of the threat intelligence data to be processed is greater than a second threshold. If it is greater, mark the threat intelligence data to be merged as first-class data; otherwise, mark it as second-class data. The data importance of first-class data is greater than that of second-class data.
[0014] In one exemplary embodiment of this application, the method further includes:
[0015] The fused threat intelligence data is labeled as the first type of data.
[0016] In one exemplary embodiment of this application, the threat intelligence data to be processed includes several intelligence attribute information that has undergone content standardization processing. The attribute types corresponding to the several intelligence attribute information within the same threat intelligence data to be processed are different.
[0017] Before generating fused threat intelligence data based on the target intelligence value and each fused determination value, the method further includes:
[0018] For each attribute type, the intelligence attribute information corresponding to the current attribute type in the threat intelligence data of each target is fused to obtain the fused intelligence attribute information corresponding to each attribute type.
[0019] Based on the target intelligence value and each fused judgment value, fused threat intelligence data is generated, including:
[0020] Based on the target intelligence value, each fused judgment value, and each fused intelligence attribute information, fused threat intelligence data is generated.
[0021] In one exemplary embodiment of this application, before acquiring a plurality of threat intelligence data to be fused, all of which have the target intelligence value, the method further includes:
[0022] Obtain a plurality of original threat intelligence data.
[0023] Format standardization processing is performed on each of the original threat intelligence data to obtain a plurality of intermediate threat intelligence data.
[0024] Content standardization processing is performed on each of the intermediate threat intelligence data to obtain a plurality of to-be-processed threat intelligence data.
[0025] Among the plurality of to-be-processed threat intelligence data, the to-be-fused threat intelligence data is included.
[0026] In an exemplary embodiment of the present application, the format standardization processing includes:
[0027] The data type of the current original threat intelligence data is determined.
[0028] According to the data type, a data template corresponding to the current original threat intelligence data is obtained.
[0029] The data in the current original threat intelligence data is filled into the data template to obtain the intermediate threat intelligence data.
[0030] In an exemplary embodiment of the present application, the intermediate threat intelligence data includes a plurality of intelligence attribute information.
[0031] The content standardization processing includes:
[0032] Through a preset standard attribute information mapping table, each intelligence attribute information in the current intermediate threat intelligence data is replaced by corresponding standard attribute information in the standard attribute information mapping table to obtain the to-be-processed threat intelligence data.
[0033] In another aspect of the present application, a threat intelligence fusion device is provided, which includes:
[0034] An acquisition module is configured to acquire a plurality of to-be-fused threat intelligence data with a target intelligence value. The to-be-fused threat intelligence data includes an intelligence value and intelligence determination information. The intelligence determination information includes a plurality of determination values. The determination values in the same to-be-processed threat intelligence data correspond to different determination types. The determination values include an intelligence source confidence value.
[0035] A selection module is configured to determine the to-be-fused threat intelligence data with an intelligence source confidence value greater than a first threshold value as target threat intelligence data.
[0036] A fusion module is configured to perform data fusion processing on the determination values corresponding to a current determination type in each target threat intelligence data for each determination type to obtain a fused determination value corresponding to each determination type.
[0037] generating module, configured to generate the fused threat intelligence data according to the target intelligence value and each fused determination value.
[0038] In another aspect of the present application, an electronic device is provided, comprising a processor and a memory;
[0039] The processor is configured to execute the steps of the method according to any one of the preceding aspects by invoking the program or instructions stored in the memory.
[0040] In another aspect of the present application, a non-transitory computer-readable storage medium is provided, which stores a program or instructions, and the program or instructions cause a computer to execute the steps of the method according to any one of the preceding aspects.
[0041] The threat intelligence fusion method provided in the present application, after obtaining a plurality of to-be-fused threat intelligence data with the same intelligence value, determines the to-be-fused threat intelligence data with a higher corresponding intelligence source confidence value as target threat intelligence data by using the first threshold, so as to determine the to-be-fused threat intelligence data with a higher accuracy according to the intelligence source confidence value and perform subsequent fusion processing, so as to avoid the to-be-fused threat intelligence data with a low accuracy from participating in the fusion processing, and thus the accuracy of the fused threat intelligence data obtained finally is greatly reduced. Meanwhile, when the target threat intelligence data is fused, each determination value corresponding to the same determination type is fused according to each determination type, so as to avoid fusion errors. Therefore, in the present application, if a plurality of to-be-fused threat intelligence data corresponding to the same intelligence value exist, the to-be-fused threat intelligence data with a higher accuracy can be screened out and fused, so that when the threat intelligence data is used subsequently, how to use the threat intelligence data can be determined according to the fused threat intelligence data corresponding to the intelligence value. BRIEF DESCRIPTION OF DRAWINGS
[0042] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed in the embodiments will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0043] Figure 1 A flowchart of a threat intelligence fusion method provided in an embodiment of the present application;
[0044] Figure 2 A structural block diagram of a threat intelligence fusion device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0045] The embodiments of the present application will be described in detail below with reference to the drawings.
[0046] It should be noted that the following embodiments and features in the embodiments can be combined with each other in the case of no conflict; and all other embodiments obtained by those skilled in the art based on the embodiments in the present disclosure without creative labor shall fall within the scope of the present disclosure.
[0047] It should be noted that various aspects of the embodiments described below are within the scope of the appended claims. As will be apparent, the aspects described herein can be implemented in various ways, and that any particular structure is merely an example. Based on this disclosure, one skilled in the art will appreciate that one aspect described herein can be implemented independently of any other aspects and that two or more of these aspects can be combined in any suitable manner. For example, an apparatus can be implemented or a method can be practiced using any number of the aspects set forth herein. In addition, such an apparatus can be implemented or such a method can be practiced using other structure and / or functionality in addition to or other than one or more of the aspects set forth herein.
[0048] Please refer to Figure 1 In one aspect of the present application, a threat intelligence fusion method is provided, comprising the following steps:
[0049] S100, obtaining a plurality of threat intelligence data to be fused, each of which has a target intelligence value.
[0050] The threat intelligence data to be fused includes intelligence values and intelligence determination information. The intelligence value refers to the intelligence itself data, such as a website information or a hash value of a file, etc. The intelligence determination information is the analysis result information obtained by processing and analyzing the intelligence value. The intelligence determination information includes a plurality of determination values, the determination types corresponding to the plurality of determination values in the same threat intelligence data to be processed are different, and the plurality of determination values include an intelligence source confidence value. The determination types can include intelligence source confidence, intelligence confidence, determination result, intelligence validity, update time, etc. For example, the determination type corresponding to the intelligence source confidence value is the intelligence source confidence.
[0051] S200, determining the threat intelligence data to be fused with the intelligence source confidence value greater than a first threshold value as target threat intelligence data.
[0052] The first threshold value can be directly set by the staff, or all intelligence sources can be arranged from high to low according to the intelligence source execution degree, and the last one of the top 20% intelligence sources in the order is selected as the first threshold value.
[0053] S300, for each determination type, performs data fusion processing on the determination value corresponding to the current determination type in each target threat intelligence data to obtain the fused determination value corresponding to each determination type.
[0054] S400, generate fused threat intelligence data based on the target intelligence value and each fused determination value.
[0055] The threat intelligence fusion method provided in this application, after acquiring several threat intelligence data to be fused with the same intelligence value, uses a first threshold to identify the threat intelligence data with a higher confidence value corresponding to the intelligence source as the target threat intelligence data. This method identifies the threat intelligence data with higher accuracy based on the intelligence source confidence value and performs subsequent fusion processing, preventing the inclusion of low-accuracy threat intelligence data in the fusion process, which could significantly reduce the accuracy of the final fused threat intelligence data. Furthermore, when fusing the target threat intelligence data, each judgment value corresponding to each judgment type is fused separately according to each judgment type to avoid fusion errors. Therefore, in this application, if the same intelligence value has multiple corresponding threat intelligence data to be fused, it can filter out the fused threat intelligence data with higher accuracy, allowing for direct determination of how to use the threat intelligence data when it is subsequently used.
[0056] In one exemplary embodiment of this application, for each determination type, the determination value corresponding to the current determination type in each target threat intelligence data is subjected to data fusion processing to obtain the fused determination value corresponding to each determination type, specifically including:
[0057] If the current judgment type is intelligence source confidence, then data fusion processing is performed using the following formula:
[0058] A = q1 × A1 + q2 × A2 + ... + q i ×A i +…+q n ×A n .
[0059] Where A is the confidence value of the merged intelligence source, and q i A is the preset weight of the intelligence source corresponding to the threat intelligence data of the i-th target. i Let be the confidence value of the intelligence source in the i-th target threat intelligence data, and n be the number of target threat intelligence data.
[0060] If the current judgment type is intelligence confidence level, then data fusion processing is performed using the following formula:
[0061] B = z1xB1+ z2xB2+... + znxBn i +... + znxBn i +... + znxBn n +... + znxBn n .
[0062] Wherein, B is the fusion intelligence confidence value, z i is the preset weight of the i-th target threat intelligence data corresponding to the intelligence source, B i is the intelligence confidence value in the i-th target threat intelligence data, and n is the number of target threat intelligence data.
[0063] If the current determination type is the determination result, it is determined whether the determination result value in each target threat intelligence data is the same, and if it is the same, the determination result value is directly used as the fusion determination result value.
[0064] Otherwise, the determination result value in the target threat intelligence data with the highest intelligence source confidence is compared with the determination result value in the target threat intelligence data with the latest update time.
[0065] If they are the same, the determination result value is selected as the fusion determination result value;
[0066] If they are not the same, the determination result value in the target threat intelligence data with the latest update time is used as the fusion determination result value.
[0067] Specifically, the determination result value can be black, white, unknown, etc.
[0068] If the current determination type is intelligence validity, it is determined whether the intelligence validity value in each target threat intelligence data is the same, and if it is the same, the intelligence validity value is directly used as the fusion intelligence validity value.
[0069] Otherwise, the intelligence validity value in the target threat intelligence data with the latest update time is used as the fusion intelligence validity value.
[0070] The intelligence validity value includes valid and invalid.
[0071] If the current determination type is the update time, the current time is determined as the fusion update time value.
[0072] In this embodiment, the fusion methods of the determination values corresponding to different determination types are different, so as to improve the accuracy of the fused threat intelligence data as much as possible. It is known through experiments that the accuracy of the fused threat intelligence data obtained by the above fusion method is higher than that of the common data fusion method.
[0073] In an example embodiment of the present application, before the several threat intelligence data to be fused are obtained, the method further comprises:
[0074] Obtaining intelligence values of several threat intelligence data to be processed. Each of the threat intelligence data to be processed has its corresponding intelligence value. The intelligence values of different threat data to be processed can be the same or different.
[0075] Traversing each intelligence value, in the case that the current intelligence value corresponds to multiple threat intelligence data to be processed, determining the current intelligence value as a target intelligence value, and determining the threat intelligence data to be processed corresponding to the target intelligence value as threat intelligence data to be fused.
[0076] In the case that the current intelligence value corresponds to only one threat intelligence data to be processed, determining whether the intelligence source confidence value of the threat intelligence data to be processed is greater than a second threshold value, if yes, marking the threat intelligence data to be fused as first type data, otherwise, marking it as second type data. The data importance of the first type data is greater than that of the second type data. The second threshold value can be directly set by the staff, or all intelligence sources can be arranged from high to low according to the intelligence source execution degree, and the last one of the top 20% intelligence sources is selected as the second threshold value.
[0077] The method further comprises:
[0078] Marking the fused threat intelligence data as first type data.
[0079] Specifically, the first type data is threat intelligence data that needs to be used when performing intelligence analysis or using, and the second type data is threat intelligence data that will not be enabled. For the second type data, it can be directly deleted, or it can be stored in the database and enabled under specific circumstances later.
[0080] In the present embodiment, the target intelligence value is determined by traversing each intelligence value, and then all threat intelligence data to be processed corresponding to each target intelligence value is determined as threat intelligence data to be fused. Thus, in subsequent processing, the threat intelligence data to be processed that needs to be fused can be screened and fused according to the target intelligence value.
[0081] At the same time, for the intelligence value corresponding to only one threat intelligence data to be processed, it is directly determined whether it is marked as first type data or second type data according to the intelligence source execution degree value in the threat intelligence data to be processed where the intelligence value is located, so as to facilitate subsequent use.
[0082] In an example embodiment of the present application, the threat intelligence data to be processed includes several intelligence attribute information processed by content standardization. The intelligence attribute information in the same threat intelligence data to be processed corresponds to different attribute types.
[0083] The intelligence attribute information is used to describe the intelligence value in the threat intelligence data to be processed, and the attribute type can include attack organization, target country, target industry, attack technique and tactics, attack action, exploit vulnerability, threat type, associated information, active time, and use equipment, etc. to clearly describe the attributes of the intelligence value from different dimensions.
[0084] Before the fusion threat intelligence data is generated according to the target intelligence value and each fusion decision value, the method further includes:
[0085] For each attribute type, the intelligence attribute information corresponding to the current attribute type in each target threat intelligence data is processed by data fusion to obtain the fusion intelligence attribute information corresponding to each attribute type.
[0086] Correspondingly, the fusion threat intelligence data is generated according to the target intelligence value and each fusion decision value, including:
[0087] The fusion threat intelligence data is generated according to the target intelligence value, each fusion decision value, and each fusion intelligence attribute information.
[0088] The intelligence attribute information of the same attribute type of the same intelligence value obtained from different intelligence sources can be different. Therefore, in the present application, when the intelligence attribute information corresponding to the current attribute type in each target threat intelligence data is processed by data fusion to obtain the fusion intelligence attribute information corresponding to each attribute type, the fusion method used is de-duplication fusion. That is, the fusion intelligence attribute information can include multiple intelligence attribute information before fusion, and are different from each other. The fusion intelligence attribute information is as accurate as possible.
[0089] In an example embodiment of the present application, before the several threat intelligence data to be fused whose intelligence values are target intelligence values are obtained, the method further includes:
[0090] Obtain several original threat intelligence data. The original threat intelligence data is the threat intelligence data sent by each intelligence source.
[0091] Format standardization processing is performed on each original threat intelligence data to obtain several intermediate threat intelligence data. The intermediate threat intelligence data between the same data type correspond to the same number of fields of the intermediate threat intelligence data. The fields can correspond to the aforementioned discrimination type and attribute type, etc. for storing the corresponding content.
[0092] The content of each intermediate threat intelligence data is standardized to obtain a plurality of to-be-processed threat intelligence data.
[0093] The to-be-processed threat intelligence data includes the to-be-fused threat intelligence data.
[0094] Due to different production methods and capabilities of threat intelligence data from different sources, the formats of the threat intelligence data are not unified, and the attributes or description contents involved in the threat intelligence data are different. For example, in the threat intelligence data of intelligence value 1 from an A intelligence source, there are only four fields, i.e., an intelligence value field, an intelligence source confidence field, an intelligence validity field, and an attack organization. In the threat intelligence data of intelligence value 1 from a B intelligence source, there are more than six fields, i.e., an intelligence value field, an intelligence source confidence field, an intelligence validity field, an update time field, an international field, and an attack organization. In this way, even if the fields provided by the two intelligence sources are corresponding to intelligence value 1, the subsequent fusion processing cannot be directly performed due to the different number of fields and different field arrangement methods. Therefore, in the embodiment, the format of each original threat intelligence data is standardized to obtain a plurality of intermediate threat intelligence data with the same number of fields and the same arrangement method.
[0095] Meanwhile, the intelligence attribute information from different intelligence sources may be different, such as downloader, downloader trojan, downloader, and downloader. Although the contents are different, they actually represent the same content. Therefore, in the embodiment, the content in each field of each intermediate threat intelligence data is standardized to make the expression method of the same content consistent in different to-be-processed threat intelligence data.
[0096] In an exemplary embodiment of the present application, the format standardization processing includes:
[0097] The data type of the current original threat intelligence data is determined.
[0098] According to the data type, a data template corresponding to the current original threat intelligence data is obtained.
[0099] The data in the current original threat intelligence data is filled into the data template to obtain the intermediate threat intelligence data.
[0100] Specifically, the data type includes a file type, a network type, and other types. The data type of each original threat intelligence data can be determined through the following classification table 1.
[0101]
[0102] Classification table 1
[0103] In the statistics and arrangement of the field of each data type of threat intelligence data of each information source in history, the full-quantity field model corresponding to each data type is obtained, and thus the data template corresponding to each data type is obtained.
[0104] Therefore, the corresponding data template of the original threat intelligence data can be determined by the data type of the original threat intelligence data, and the content in each field is filled into the data template, so that the intermediate threat intelligence data is obtained. It should be noted that since the data template is a full-quantity field, and the original threat intelligence data may only have a few fields, therefore, some fields in the intermediate threat intelligence data are allowed to be null.
[0105] In an exemplary embodiment of the present application, the intermediate threat intelligence data includes a plurality of information attribute information.
[0106] The content standardization processing includes:
[0107] By using the preset standard attribute information mapping table, each information attribute information in the current intermediate threat intelligence data is replaced by the corresponding standard attribute information in the standard attribute information mapping table, so as to obtain the to-be-processed threat intelligence data.
[0108] Specifically, the standard attribute information mapping table can be pre-set, and different information attribute information with the same meaning is mapped to the same standard attribute information when used, so as to reduce the difference between threat intelligence data of different information sources, and facilitate subsequent fusion processing.
[0109] Further, if the current information attribute information does not exist in the standard attribute information mapping table, the current information attribute information can be compared with each standard attribute information in the standard attribute information mapping table for string similarity, and the standard attribute information with a similarity greater than a third threshold value is determined as the target standard attribute information.
[0110] According to the order of the similarity corresponding to the target standard attribute information from large to small, it is determined in turn whether the current target standard attribute information is the same meaning as the current information attribute information. The specific method is:
[0111] Obtain all mapping pre-attribute information corresponding to the current target standard attribute information.
[0112] Obtain the string similarity between the current information attribute information (i.e., the information attribute information not existing in the standard attribute information mapping table) and all mapping pre-attribute information corresponding to the current target standard attribute information. If they are all greater than a fourth threshold value, the current information attribute information is added to the standard attribute information mapping table as the mapping pre-attribute information of the current target standard attribute information, so as to update the standard attribute information mapping table and determine the standard attribute information of the current information attribute information.
[0113] Otherwise, the next target standard attribute information is selected for processing.
[0114] In this way, even if there is information attribute information that does not exist in the standard attribute information mapping table, it can be successfully processed for content standardization.
[0115] Please refer to Figure 2 In another aspect of the present application, a threat information fusion device is provided, comprising:
[0116] The acquisition module is configured to acquire a plurality of threat information data to be fused, each having a target information value. The threat information data to be fused includes an information value and information determination information. The information determination information includes a plurality of determination values, and the determination values in the same threat information data to be processed correspond to different determination types. The determination values include an information source confidence value.
[0117] The selection module is configured to determine, as target threat information data, the threat information data to be fused whose information source confidence value is greater than a first threshold value.
[0118] The fusion module is configured to, for each determination type, perform data fusion processing on the determination value corresponding to the current determination type in each target threat information data, to obtain a fused determination value corresponding to each determination type.
[0119] The generation module is configured to generate fused threat information data according to the target information value and each fused determination value.
[0120] In addition, although the various steps of the methods in the present disclosure are described in a specific order in the accompanying drawings, this does not require or imply that the steps must be performed in this specific order, or that all of the steps shown must be performed to achieve the desired results. Additionally or alternatively, certain steps can be omitted, multiple steps can be combined into one step, and / or one step can be divided into multiple steps, etc.
[0121] From the above description of the embodiments, those skilled in the art can easily understand that the example embodiments described herein can be implemented by software, or by software in combination with necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a U disk, a mobile hard disk, etc.) or a network, and includes a plurality of instructions to make a computing device (which can be a personal computer, a server, a mobile terminal, or a network device, etc.) execute the method according to the embodiments of the present disclosure.
[0122] In the exemplary embodiments of the present disclosure, an electronic device capable of implementing the above method is also provided.
[0123] Those skilled in the art can understand that various aspects of the present application can be implemented as a system, a method or a program product. Therefore, various aspects of the present application can be embodied in the form of a complete hardware implementation, a complete software implementation (including firmware, microcode, etc.), or a combination of hardware and software aspects, which can be collectively referred to herein as "circuitry", "module" or "system".
[0124] An electronic device according to this embodiment of the present application. The electronic device is merely an example and should not bring any limitation to the function and use range of the embodiments of the present application.
[0125] The electronic device is in the form of a general computing device. The components of the electronic device can include, but are not limited to, the at least one processor described above, the at least one storage described above, and a bus connecting different system components, including the storage and the processor.
[0126] The storage stores program codes which can be executed by the processor, so that the processor performs the steps described in the "Exemplary Method" section of the present specification according to various exemplary embodiments of the present application.
[0127] The storage can include a readable medium in the form of a volatile storage, such as a random access memory (RAM) and / or a cache memory, and can further include a read-only memory (ROM).
[0128] The storage can further include programs / utilities with a set of (at least one) program modules, such as an operating system, one or more application programs, other program modules, and program data, each of which or some combination of which can include the implementation of a network environment.
[0129] The bus can be one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration port, a processor or a local bus using any of a variety of bus structures.
[0130] The electronic device can also communicate with one or more external devices such as a keyboard or a pointing device, through an I / O interface. The electronic device can also communicate to one or more devices that enable a user to interact with it, and / or to one or more devices (e.g., a router, a modem, a server, etc.) that enable the electronic device to communicate with one or more other computing devices. Such communication can occur via an I / O interface. Also, the electronic device can communicate to one or more networks such as a local area network (LAN), a wide area network (WAN), and / or the Internet through a network adapter. It should be appreciated that the network adapter can be collectively part of the electronic device, part of another device, or a stand-alone device. In addition, while the network adapter is illustrated as a single device, the network adapter can include any number of devices that are adapted to enable the electronic device to communicate with one or more networks.
[0131] From the above description of the embodiments, it is easy for those skilled in the art to understand that the example embodiments described herein can be implemented by software, or by software in combination with necessary hardware. Therefore, the technical solution according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a U disk, a mobile hard disk, etc.) or a network, and includes a number of instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to perform the method according to the embodiments of the present disclosure.
[0132] In the example embodiments of the present disclosure, a computer-readable storage medium is also provided, which stores a program product capable of implementing the method described above. In some possible embodiments, various aspects of the present application can also be implemented in the form of a program product, which includes program code for causing the terminal device to perform the steps described in the "example method" section of the present specification according to various example embodiments of the present application when the program product is run on the terminal device.
[0133] The program product can adopt any combination of one or more readable media. The readable medium can be a readable signal medium or a readable storage medium. The readable storage medium may, for example, be but is not limited to an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or apparatus, or any combination of the above. More specific examples (non-exhaustive list) of readable storage media include an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
[0134] Computer readable signal media can include a propagated data signal with instructions embodied in data signals. Such propagated signal can take a wide variety of forms, including but not limited to electro-magnetic signals, optical signals, and so forth. Computer readable signal media can be any medium that can be involved in providing instructions to a machine for execution.
[0135] Program code embodied on a computer readable medium can be transmitted using any appropriate medium, including but not limited to wireless, wired, optical fiber cable, RF, etc., or any suitable combination of the foregoing.
[0136] Program code, used by or in connection with the routines described herein, can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, C++ or the like and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computing device, partly on the user's computing device, as a stand-alone software package, partly on the user's computing device and partly on a remote computing device or entirely on the remote computing device or server. In the latter scenario, the remote computing device can be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computing device, such as through the Internet using an Internet Service Provider. The application is not limited to a particular programming language. The program code can be transmitted using any appropriate medium, including but not limited to wireless, wired, optical fiber cable, RF, etc., or any suitable combination of the foregoing.
[0137] Furthermore, the above-described diagrams merely illustrate a schematic of the processes included in the method according to the exemplary embodiments of the present application, and are not intended for limiting purposes. It is readily understood that the processes shown in the above-described diagrams do not indicate or limit the time sequence of these processes. In addition, it is readily understood that these processes can be executed synchronously or asynchronously, for example, in a plurality of modules.
[0138] It should be noted that, although several modules or units of the device for action execution are mentioned in the above detailed description, such a division is not mandatory. Indeed, according to an embodiment of the present disclosure, the features and functionalities of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functionalities of one module or unit described above can be further divided into embodied by a plurality of modules or units.
[0139] The above merely provides the specific implementation of the present application, but the protection scope of the present application is not limited to this. Any changes or replacements within the technical scope disclosed by the present application can be easily conceived by the person skilled in the art, and should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A threat intelligence fusion method, characterized in that, include: Acquire several threat intelligence data sets to be fused, all of which contain target intelligence values. The threat intelligence data to be merged includes intelligence values and intelligence judgment information; the intelligence judgment information includes several judgment values, and the judgment types corresponding to several judgment values in the same threat intelligence data to be processed are different, and the several judgment values include intelligence source confidence values. Threat intelligence data to be fused that has a confidence value of the intelligence source greater than the first threshold is identified as target threat intelligence data. For each judgment type, the judgment value corresponding to the current judgment type in each target threat intelligence data is fused to obtain the fused judgment value for each judgment type. Based on the target intelligence value and each fused judgment value, fused threat intelligence data is generated; For each determination type, the determination value corresponding to the current determination type in each target threat intelligence data is fused to obtain the fused determination value for each determination type, including: If the current judgment type is intelligence source confidence, then data fusion processing is performed using the following formula: ; Where A is the confidence value of the merged intelligence source, and q i A is the preset weight of the intelligence source corresponding to the threat intelligence data of the i-th target. i Let n be the source confidence value in the i-th target threat intelligence data, and n be the number of target threat intelligence data. If the current judgment type is intelligence confidence level, then data fusion processing is performed using the following formula: ; Where B is the confidence value of the fused intelligence, and z i B is the preset weight of the intelligence source corresponding to the threat intelligence data of the i-th target. i Let be the intelligence confidence value in the i-th target threat intelligence data, and n be the number of target threat intelligence data; If the current judgment type is a judgment result, then determine whether the judgment result value in each target threat intelligence data is the same. If they are the same, then directly use the judgment result value as the fused judgment result value. Otherwise, compare the judgment result value in the target threat intelligence data with the latest target threat intelligence data with the judgment result value updated by the highest confidence level of the intelligence source; If they are the same, the value of the judgment result shall be selected as the value of the judgment result after fusion. If they are different, the judgment result value in the target threat intelligence data with the latest update time will be used as the fused judgment result value.
2. The threat intelligence fusion method according to claim 1, characterized in that, Before acquiring several threat intelligence data sets whose intelligence values are all target intelligence values, the method further includes: Acquire intelligence values from several threat intelligence data to be processed; Traverse each intelligence value. If the current intelligence value corresponds to multiple threat intelligence data to be processed at the same time, determine the current intelligence value as the target intelligence value, and determine the threat intelligence data to be processed corresponding to the target intelligence value as the threat intelligence data to be fused. When the current intelligence value corresponds to only one threat intelligence data to be processed, determine whether the intelligence source confidence value of the threat intelligence data to be processed is greater than the second threshold. If it is greater, mark the threat intelligence data to be merged as the first type of data; otherwise, mark it as the second type of data. The data importance of the first type of data is greater than the data importance of the second type of data.
3. The threat intelligence fusion method according to claim 2, characterized in that, The method further includes: The fused threat intelligence data is labeled as the first type of data.
4. The threat intelligence fusion method according to claim 2, characterized in that, The threat intelligence data to be processed includes several intelligence attribute information that has undergone content standardization; the attribute types corresponding to several intelligence attribute information in the same threat intelligence data to be processed are different. Before generating fused threat intelligence data based on the target intelligence value and each fused determination value, the method further includes: For each attribute type, the intelligence attribute information corresponding to the current attribute type in each target threat intelligence data is fused to obtain the fused intelligence attribute information corresponding to each attribute type. Based on the target intelligence value and each fused judgment value, fused threat intelligence data is generated, including: Based on the target intelligence value, each fused judgment value, and each fused intelligence attribute information, fused threat intelligence data is generated.
5. The threat intelligence fusion method according to claim 1, characterized in that, Before acquiring several threat intelligence data sets whose intelligence values are all target intelligence values, the method further includes: Acquire some raw threat intelligence data; Each raw threat intelligence data is standardized in format to obtain several intermediate threat intelligence data. Each intermediate threat intelligence data point is standardized to obtain several threat intelligence data points to be processed. Among them, the threat intelligence data to be merged is included in a number of threat intelligence data to be processed.
6. The threat intelligence fusion method according to claim 5, characterized in that, The format standardization process includes: Determine the data type of the current raw threat intelligence data; Based on the data type, obtain the data template corresponding to the current raw threat intelligence data; The intermediate threat intelligence data is obtained by filling the data template with the data from the current raw threat intelligence data.
7. The threat intelligence fusion method according to claim 5, characterized in that, The intermediate threat intelligence data includes several intelligence attribute information; The content standardization process includes: By using a preset standard attribute information mapping table, each intelligence attribute in the current intermediate threat intelligence data is replaced with the corresponding standard attribute information in the standard attribute information mapping table to obtain the threat intelligence data to be processed.
8. A threat intelligence fusion device, characterized in that, include: The acquisition module is used to acquire several threat intelligence data to be fused, all of which have the target intelligence value. The threat intelligence data to be merged includes intelligence values and intelligence judgment information; the intelligence judgment information includes several judgment values, and the judgment types corresponding to several judgment values in the same threat intelligence data to be processed are different, and the several judgment values include intelligence source confidence values. The selection module is used to identify threat intelligence data to be fused that has a confidence value of the intelligence source greater than a first threshold as target threat intelligence data; The fusion module is used to perform data fusion processing on the judgment values in each target threat intelligence data corresponding to the current judgment type for each judgment type, so as to obtain the fused judgment value corresponding to each judgment type. The generation module is used to generate fused threat intelligence data based on the target intelligence value and each fused judgment value; For each determination type, the determination value corresponding to the current determination type in each target threat intelligence data is fused to obtain the fused determination value for each determination type, including: If the current judgment type is intelligence source confidence, then data fusion processing is performed using the following formula: ; Where A is the confidence value of the merged intelligence source, and q i A is the preset weight of the intelligence source corresponding to the threat intelligence data of the i-th target. i Let n be the source confidence value in the i-th target threat intelligence data, and n be the number of target threat intelligence data. If the current judgment type is intelligence confidence level, then data fusion processing is performed using the following formula: ; Where B is the confidence value of the fused intelligence, and z i B is the preset weight of the intelligence source corresponding to the threat intelligence data of the i-th target. i Let be the intelligence confidence value in the i-th target threat intelligence data, and n be the number of target threat intelligence data; If the current judgment type is a judgment result, then determine whether the judgment result value in each target threat intelligence data is the same. If they are the same, then directly use the judgment result value as the fused judgment result value. Otherwise, compare the judgment result value in the target threat intelligence data with the latest target threat intelligence data with the judgment result value updated by the highest confidence level of the intelligence source; If they are the same, the value of the judgment result shall be selected as the value of the judgment result after fusion. If they are different, the judgment result value in the target threat intelligence data with the latest update time will be used as the fused judgment result value.
9. An electronic device, characterized in that, Including processor and memory; The processor executes the steps of the method as described in any one of claims 1 to 7 by invoking programs or instructions stored in the memory.
10. A non-transitory computer-readable storage medium, characterized in that, The non-transitory computer-readable storage medium stores a program or instructions that cause a computer to perform the steps of the method as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Multi-source entity data fusion method, device and equipment
CN110516011A
Threat intelligence acquisition method and device based on endogenous security
CN114003785A