Method for generating threat intelligence data and related device

By performing in-depth feature analysis and confidence weight calibration on multi-source heterogeneous alarm data, attack capability scores and comprehensive risk scores are generated, solving the problem of low accuracy of threat intelligence data in existing technologies, realizing the generation of high-confidence threat intelligence, and supporting high-value security decisions.

CN122339724APending Publication Date: 2026-07-03PENG CHENG LAB
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610249461.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-03-02
Publication Date
2026-07-03

Smart Images

  • Figure CN122339724A_ABST
    Figure CN122339724A_ABST
Patent Text Reader

Abstract

The threat intelligence data generation method and related equipment provided by the embodiments of the present application, the method comprises the following steps: firstly, acquiring multi-source heterogeneous alarm data and external multi-source intelligence data; then, performing feature analysis based on the multi-source heterogeneous alarm data to obtain an attack capability score of an attack end and a comprehensive risk score of a target side, and obtaining enhanced intelligence data based on the attack capability score and the comprehensive risk score; next, performing matching retrieval on the external multi-source intelligence data based on the enhanced intelligence data to obtain a matching degree, and obtaining an update credibility weight of each external intelligence source in the external multi-source intelligence data based on the matching degree; then, performing weighted fusion on the external multi-source intelligence data based on the update credibility weight to generate an external comprehensive threat score; finally, obtaining target threat intelligence data based on the enhanced intelligence data and the external comprehensive threat score, so that accurate data support can be provided for a defense system, and high-value security decisions can be effectively assisted.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network data processing technology, and in particular to methods and equipment for generating threat intelligence data. Background Technology

[0002] As cyberattack techniques become increasingly complex and covert, threat intelligence has become a core element in building proactive defense systems. In current cybersecurity operations, related technologies typically acquire internal alert data by deploying intrusion detection systems (IDS), firewalls, and other devices, and subscribe to external commercial threat intelligence (TI) from multiple sources to obtain attack indicators (IOCs). The aim is to quickly discover and respond to known threats by correlating and matching internal alerts with external intelligence, thereby attempting to block attacks before they cause substantial damage.

[0003] However, this approach of discovering threats by overlaying internal and external data has limitations when dealing with real-world business scenarios. It ignores the contextual relationship between the specific business attributes of the victim assets (such as system criticality and data sensitivity) and the attack behavior, making it impossible to accurately assess the true risk level of the threat from a business impact perspective. Ultimately, this results in low accuracy of the generated intelligence data, making it difficult to support high-value security decisions. Summary of the Invention

[0004] This application provides a method and related equipment for generating threat intelligence data, which can improve the accuracy of the generated final intelligence data.

[0005] To achieve the above objectives, a first aspect of this application proposes a method for generating threat intelligence data, the method comprising: Acquire multi-source heterogeneous alarm data and external multi-source intelligence data; Based on the multi-source heterogeneous alarm data, feature analysis is performed to obtain the attack capability score of the attacking end and the comprehensive risk score of the target side, and enhanced intelligence data is obtained based on the attack capability score and the comprehensive risk score. Based on the enhanced intelligence data, the external multi-source intelligence data is matched and retrieved to obtain the matching degree, and the update credibility weight of each external intelligence source in the external multi-source intelligence data is obtained based on the matching degree. Based on the updated credibility weights, the external multi-source intelligence data is weighted and fused to generate an external comprehensive threat score. Based on the enhanced intelligence data and the external comprehensive threat score, target threat intelligence data is obtained.

[0006] In some embodiments, the step of performing feature analysis based on the multi-source heterogeneous alarm data to obtain the attack capability score of the attacker and the comprehensive risk score of the target includes: Based on a pre-defined adversarial tactical framework, the attack behavior data in the multi-source heterogeneous alarm data is analyzed to obtain the attack tactical stages and attack tools. Determine the number of tools in the attack tool and the number of stages in the attack tactical phase; Based on the number of tools and the number of stages, the attack capability score of the attacking terminal is calculated; The system acquires internal asset information data and, based on the victim target identifier in the multi-source heterogeneous alarm data and the internal asset information data, obtains the comprehensive risk score for the target side.

[0007] In some embodiments, obtaining the comprehensive risk score on the target side based on the victim target identifier in the multi-source heterogeneous alarm data and the internal asset information data includes: Based on the victim target identifier, a query is performed in the internal asset information data to obtain the vulnerability status information, network topology location information, and business attribute information of the target side; A basic risk score is calculated based on the vulnerability status information. Calculate the exposure risk score based on the network topology location information; The criticality level and data sensitivity level of the business system corresponding to the target side contained in the business attribute information are determined, and the impact risk score is calculated based on the criticality level and the sensitivity level. The comprehensive risk score of the target side is obtained by weighted summation of the basic risk score, the exposure risk score, and the impact risk score.

[0008] In some embodiments, the step of matching and retrieving the external multi-source intelligence data based on the enhanced intelligence data to obtain a matching degree includes: The attack source IP address and attack type are determined from the enhanced intelligence data; Based on the IP address of the attack source, a search is performed in the external multi-source intelligence data to obtain the corresponding external judgment record; The matching degree is obtained by performing consistency matching between the attack type corresponding to the external judgment record and the attack behavior type.

[0009] In some embodiments, obtaining the updated credibility weight of each external intelligence source in the external multi-source intelligence data based on the matching degree includes: Obtain the historical rating and preset authority level of each of the aforementioned external intelligence sources; The historical scores are corrected based on the matching degree to obtain a dynamic score; The dynamic score and the authority level are weighted and calculated to obtain the update credibility weight corresponding to each external intelligence source.

[0010] In some embodiments, the step of weighting and fusing the external multi-source intelligence data based on the updated credibility weights to generate an external comprehensive threat score includes: The threat confidence score corresponding to each external intelligence source is multiplied by the corresponding update confidence weight to obtain a weighted score; The weighted scores of all external intelligence sources are summed to obtain the comprehensive external threat score.

[0011] In some embodiments, acquiring multi-source heterogeneous alarm data includes: Acquire initial multi-source heterogeneous alarm data, and extract feature information from the initial multi-source heterogeneous alarm data; Based on the aforementioned feature information, similarity aggregation is performed to obtain multiple composite security events; Based on the victim target identifier in each of the composite security events, a query is performed in the internal asset information data to obtain the asset criticality score corresponding to each of the composite security events; A comprehensive evaluation is conducted based on the attack severity level corresponding to the attack characteristics of the composite security incident, the asset criticality score, and the attack frequency of the composite security incident to obtain a comprehensive evaluation score for each composite security incident. The composite security events whose comprehensive evaluation score exceeds the preset evaluation score are selected from the multiple composite security events and used as the multi-source heterogeneous alarm data.

[0012] In some embodiments, the method further includes: Analyze the target threat intelligence data to extract target-side features and attack source features; Identify groups of similar risky assets within the internal network that have configurations similar to the target side characteristics; Generate blocking strategies targeting the attack source characteristics, and generate preventative protection strategies targeting the similar risk asset groups; The blocking strategy and the preventative protection strategy are sent to the network security devices associated with the similar risk asset group.

[0013] To achieve the above objectives, a second aspect of this application provides an apparatus for generating threat intelligence data, the apparatus comprising: The acquisition module is used to acquire multi-source heterogeneous alarm data and external multi-source intelligence data; The feature analysis module is used to perform feature analysis based on the multi-source heterogeneous alarm data to obtain the attack capability score of the attacking end and the comprehensive risk score of the target side, and to obtain enhanced intelligence data based on the attack capability score and the comprehensive risk score. The matching credibility calculation module is used to perform matching retrieval on the external multi-source intelligence data based on the enhanced intelligence data, obtain the matching degree, and obtain the updated credibility weight of each external intelligence source in the external multi-source intelligence data based on the matching degree. An external scoring module is used to perform weighted fusion of the external multi-source intelligence data based on the updated credibility weights to generate an external comprehensive threat score. The target data generation module is used to obtain target threat intelligence data based on the enhanced intelligence data and the external comprehensive threat score.

[0014] To achieve the above objectives, a third aspect of this application provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the threat intelligence data generation method as described in the first aspect.

[0015] To achieve the above objectives, a fourth aspect of the present application provides a storage medium, which is a computer-readable storage medium storing a computer program that, when executed by a processor, implements the threat intelligence data generation method described in the first aspect.

[0016] The method and related equipment for generating threat intelligence data proposed in this application include: First, acquiring multi-source heterogeneous alarm data and external multi-source intelligence data; then, performing feature analysis based on the multi-source heterogeneous alarm data to obtain an attack capability score for the attacker and a comprehensive risk score for the target, and obtaining enhanced intelligence data based on the attack capability score and the comprehensive risk score; next, performing matching retrieval on the external multi-source intelligence data based on the enhanced intelligence data to obtain a matching degree, and obtaining an update credibility weight for each external intelligence source in the external multi-source intelligence data based on the matching degree; then, performing weighted fusion on the external multi-source intelligence data based on the update credibility weight to generate an external comprehensive threat score; finally, obtaining target threat intelligence data based on the enhanced intelligence data and the external comprehensive threat score. This application's embodiments, through in-depth feature analysis of multi-source heterogeneous alarm data, can generate context-enhanced intelligence from two dimensions: the attacker's attack capabilities and the target's comprehensive risks (covering business attributes such as system criticality and data sensitivity). This introduces a business impact perspective into the threat discovery phase, solving the risk assessment distortion problem caused by traditional solutions ignoring business contextual relationships. Simultaneously, this application's solution uses internally generated enhanced intelligence as actual data to dynamically match, retrieve, and calibrate the credibility weights of external multi-source intelligence. This achieves automatic cleaning and optimization of external intelligence sources based on the local business environment, effectively eliminating low-quality intelligence interference that does not conform to the actual scenario. The resulting target threat intelligence data possesses both business awareness and high confidence, thus providing accurate data support for the defense system and effectively assisting in high-value security decisions.

[0017] Other features and advantages of this application will be set forth in the description which follows, and will be apparent in part from the description, or may be learned by practicing the application. The objectives and other advantages of this application may be realized and obtained by means of the structures particularly pointed out in the description, claims and drawings. Attached Figure Description

[0018] Figure 1 This is a flowchart of a method for generating threat intelligence data according to an embodiment of this application.

[0019] Figure 2 yes Figure 1 The flowchart for step 101.

[0020] Figure 3 yes Figure 1 The flowchart for step 102.

[0021] Figure 4 yes Figure 3 The flowchart for step 304.

[0022] Figure 5 yes Figure 1The flowchart for step 103.

[0023] Figure 6 yes Figure 1 Another flowchart for step 103.

[0024] Figure 7 This is an example diagram of multi-dimensional evaluation data from an external intelligence source provided in another embodiment of this application.

[0025] Figure 8 yes Figure 1 The flowchart for step 104.

[0026] Figure 9 This is an execution flowchart of a strategy generation provided in another embodiment of this application.

[0027] Figure 10 This is a detailed flowchart illustrating the operation of a collaborative defense implementation module provided in another embodiment of this application.

[0028] Figure 11 This is a schematic diagram of the overall architecture of a threat intelligence generation and sharing method provided in another embodiment of this application.

[0029] Figure 12 This is a schematic diagram of the structure of a threat intelligence data generation device provided in another embodiment of this application.

[0030] Figure 13 This is a schematic diagram of the hardware structure of an electronic device provided in another embodiment of this application. Detailed Implementation

[0031] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0032] It should be noted that although functional modules are divided in the device schematic diagram and the logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than the module division in the device or the order in the flowchart.

[0033] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.

[0034] As cyberattack techniques become increasingly complex and covert, threat intelligence has become a core element in building proactive defense systems. In current cybersecurity operations, related technologies typically acquire internal alert data by deploying intrusion detection systems (IDS), firewalls, and other devices, and subscribe to external commercial threat intelligence (TI) from multiple sources to obtain attack indicators (IOCs). The aim is to quickly discover and respond to known threats by correlating and matching internal alerts with external intelligence, thereby attempting to block attacks before they cause substantial damage.

[0035] However, this approach of discovering threats by overlaying internal and external data has limitations when dealing with real-world business scenarios. It ignores the contextual relationship between the specific business attributes of the victim assets (such as system criticality and data sensitivity) and the attack behavior, making it impossible to accurately assess the true risk level of the threat from a business impact perspective. Ultimately, this results in low accuracy of the generated intelligence data, making it difficult to support high-value security decisions.

[0036] To improve the accuracy of the generated final intelligence data, this application embodiment performs in-depth feature analysis on multi-source heterogeneous alarm data. This enables the generation of context-enhanced intelligence from two dimensions: the attacker's attack capabilities and the target's comprehensive risks (covering business attributes such as system criticality and data sensitivity). This introduces a business impact perspective into the threat discovery stage, solving the risk assessment distortion problem caused by neglecting business context in traditional solutions. Simultaneously, this application's solution uses internally generated enhanced intelligence as actual data to dynamically match, retrieve, and calibrate the credibility weights of external multi-source intelligence. This achieves automatic cleaning and optimization of external intelligence sources based on the local business environment, effectively eliminating low-quality intelligence interference that is inconsistent with the actual scenario. The resulting target threat intelligence data possesses both business awareness and high confidence, providing accurate data support for the defense system and effectively assisting in high-value security decisions.

[0037] The method for generating threat intelligence data and related equipment provided in the embodiments of this application will be further described below. The method for generating threat intelligence data provided in the embodiments of this application can be applied to any processing system with computing resources (such as smart terminals, servers, computers, etc.).

[0038] To address the key shortcomings of traditional threat intelligence systems, the processing system implementing the threat intelligence data generation method proposed in this application mainly comprises four parts: The first part is an alarm processing module, which continuously connects to internal network security alarm data, aggregates alarms based on features, automatically associates asset information, and extracts high-value alarms based on key conditions; the second part is a context-enhanced analysis module, which distinguishes between the attacker's (i.e., the attacking end) and the victim's (i.e., the target end) perspectives, extracts attack techniques and constructs a victim profile, analyzes business risks, and generates intelligence data with context; the third part is an intelligence fusion and verification module, which performs external intelligence queries on context intelligence, scores the credibility of each intelligence source in real time based on actual internal attack behavior, and outputs fused intelligence calibrated for business scenarios; the fourth part is a collaborative defense implementation module, which identifies groups of assets with the same risk based on the victim asset information in the fused intelligence, extracts high-risk IPs for multi-subnet protection push, and achieves internal protection and external blocking.

[0039] Reference Figure 1 This is an optional flowchart of the threat intelligence data generation method provided in the embodiments of this application. Figure 1 The method may include, but is not limited to, steps 101 to 105. It is also understood that this embodiment... Figure 1 The order of steps 101 to 105 is not specifically limited. The order of steps can be adjusted or some steps can be reduced or added according to actual needs.

[0040] Step 101: Obtain multi-source heterogeneous alarm data and external multi-source intelligence data.

[0041] Step 101 will be described in detail below.

[0042] In step 101 of some embodiments, multi-source heterogeneous alarm data and external multi-source intelligence data are acquired. This step is mainly performed by the alarm processing module of the processing system, aiming to establish a comprehensive and multi-dimensional initial data pool. This alarm processing module includes five sub-functions: data access, feature extraction, aggregation processing, asset association, and high-value alarm filtering. The data access sub-function supports two real-time access methods: Kafka and Syslog, and performs standardized formatting processing on the raw alarm data. The feature extraction sub-function performs multi-dimensional feature analysis on the standardized alarm data, including: IP features (source / destination IP, internal / external network location identifiers), attack features (attack behavior type, associated vulnerability ID, protocol type, attack severity level), and time features (occurrence timestamp, duration). The aggregation processing sub-function, based on the extracted feature information, uses a similarity matching algorithm to aggregate related alarms into composite security events. The asset association sub-function obtains detailed asset information (business affiliation, open ports, system configuration, etc.) through internal IP mapping and calculates the asset criticality score.

[0043] "Multi-source heterogeneous alert data" refers to logs and alerts from different security devices or systems within the network, including but not limited to Intrusion Detection Systems (IDS), Intrusion Prevention Systems (IPS), Endpoint Detection and Response Systems (EDR), security gateways, and firewalls. Because different vendors and types of devices output data in different formats (such as Syslog, JSON, CEF, etc.), it is termed "multi-source heterogeneous," and data cleaning and standardization preprocessing are typically involved after acquisition. "External multi-source intelligence data" refers to threat intelligence feeds subscribed to or collected from outside the enterprise network boundary. These sources include commercial intelligence vendors, the Open Source Intelligence Community (OSINT), and notifications issued by government regulatory agencies. This data typically contains known malicious IPs, domain names, file hashes, and other attack indicators (IOCs) along with their confidence levels.

[0044] In some embodiments, in order to filter out key events with real threat analysis value from massive amounts of raw logs, this application achieves accurate extraction of high-value security events by performing noise reduction and aggregation on initial alarms and multi-dimensional value assessment based on the criticality of business assets.

[0045] Reference Figure 2 To obtain multi-source heterogeneous alarm data, the steps 201 to 205 are as follows.

[0046] Step 201: Obtain initial multi-source heterogeneous alarm data and extract feature information from the initial multi-source heterogeneous alarm data.

[0047] Step 202: Perform similarity aggregation based on feature information to obtain multiple composite security events.

[0048] Step 203: Based on the victim target identifier in each composite security event, query the internal asset information data to obtain the asset criticality score corresponding to each composite security event.

[0049] Step 204: Based on the attack severity level, asset criticality score, and attack frequency of the composite security incidents, a comprehensive evaluation is conducted to obtain the comprehensive evaluation score for each composite security incident.

[0050] Step 205: Select composite security events from multiple composite security events whose comprehensive evaluation score exceeds the preset evaluation score as multi-source heterogeneous alarm data.

[0051] Steps 201 to 205 are described in detail below.

[0052] In step 201 of some embodiments, the processing system acquires initial multi-source heterogeneous alarm data and extracts feature information from it. This step is the entry point for data processing, aiming to solve the problem of accessing and standardizing raw data. Specifically, the processing system can access raw alarm logs from various devices such as Intrusion Detection Systems (IDS), Intrusion Prevention Systems (IPS), Endpoint Detection and Response (EDR), and security gateways through real-time channels such as Kafka message queues or Syslog log services. This raw data is the "initial multi-source heterogeneous alarm data," and its format often varies. The processing system formats and cleans this data, and then performs the "feature information extraction" operation to parse multi-dimensional key fields from the standardized logs. These feature information specifically include: IP characteristics (such as source IP, destination IP, and internal / external network location identifiers), attack characteristics (such as attack behavior type, associated vulnerability ID, protocol type, and attack severity level), and time characteristics (such as the timestamp and duration of the attack). These features constitute the basic data dimensions for subsequent analysis.

[0053] In step 202 of some embodiments, the processing system performs similarity aggregation based on feature information to obtain multiple composite security events. Since network attacks are often accompanied by numerous repeated probes or continuous attempts, directly processing discrete single alarms would waste computational resources and make it difficult to see the full picture of the attack. Therefore, this step utilizes the feature information extracted in the previous step and employs a preset similarity matching algorithm to logically merge alarm records with highly correlated features within a short period (e.g., continuous attacks from the same source IP against the same destination IP, or repeated triggering of the same type of attack). The resulting "composite security event" is no longer an isolated log entry, but represents a complete set of attack behaviors with spatiotemporal correlation, thereby significantly reducing the redundancy of alarm data and achieving initial data noise reduction.

[0054] In step 203 of some embodiments, the processing system queries internal asset information data based on the victim target identifier in each composite security event to obtain an asset criticality score corresponding to each composite security event. This step aims to introduce a business perspective to identify the value of the attacked object. The processing system extracts the "victim target identifier" (usually the destination IP address) from the composite security event and uses it as an index key to perform a mapping query in the enterprise's "internal asset information data" (such as CMDB or asset ledger). Through the query, the processing system can not only obtain detailed information such as the business ownership, open ports, and system configuration of the asset, but also obtain a predefined "asset criticality score." This score quantifies the importance of the asset to business continuity (for example, the score of a core database server is much higher than that of a visitor terminal in the office area), thereby providing benchmark data from the business side for judging the potential harm of an attack.

[0055] In step 204 of some embodiments, the processing system performs a comprehensive evaluation based on the attack severity level, asset criticality score, and attack frequency of the composite security event, corresponding to the attack characteristics of the composite security event, to obtain a comprehensive evaluation score for each composite security event. This step constructs a multi-dimensional value assessment model to calculate the priority of security events. The system comprehensively considers three core indicators: first, "attack severity level," reflecting the technical harm of the attack method itself; second, "asset criticality score," reflecting the business importance of the victim; and third, "attack frequency," reflecting the activity level and persistence of the attack. A specific algorithm model is used to weight and calculate the above indicators, outputting a quantitative "comprehensive evaluation score." This score objectively reflects the actual threat priority of the composite security event in the current network environment and business context, avoiding misjudgments caused by relying solely on the technical severity indicator.

[0056] In step 205 of some embodiments, the processing system selects composite security events from multiple composite security events whose overall evaluation score exceeds a preset evaluation score as multi-source heterogeneous alarm data. This is the final step in data preprocessing, namely "high-value filtering." The processing system compares the overall evaluation score of each event with a system-set "preset evaluation score" (threshold) and eliminates low-value events with lower scores (such as low-risk scans of non-critical assets). The events that are ultimately retained and whose scores exceed the threshold are identified as high-value alarms and output as the final "multi-source heterogeneous alarm data" for use by the subsequent context analysis module.

[0057] Through steps 201 to 205 above, a multi-layered filtering mechanism—from raw data access to feature extraction, aggregation and noise reduction, asset association, and multi-dimensional value assessment—effectively solves the technical challenges of "high noise, low value, and disconnect from business" in traditional massive alarm data. This process not only significantly reduces the amount of data processing required for subsequent analysis but also ensures that the final "multi-source heterogeneous alarm data" focuses on high-risk events that truly threaten core business by introducing asset criticality scoring, laying a solid data foundation for generating high-quality internal threat intelligence.

[0058] Step 102: Perform feature analysis based on multi-source heterogeneous alarm data to obtain the attack capability score of the attacking end and the comprehensive risk score of the target side, and obtain enhanced intelligence data based on the attack capability score and the comprehensive risk score.

[0059] Step 102 is described in detail below.

[0060] In step 102 of some embodiments, feature analysis is performed based on multi-source heterogeneous alarm data to obtain the attacker's attack capability score and the target's comprehensive risk score. Enhanced intelligence data is then derived based on these scores. This step is primarily executed by the context-enhanced analysis module of the processing system, aiming to construct intelligence with business context from an internal perspective. The context-enhanced analysis module includes two sub-functions: attack technique analysis and victim profiling. The attack technique analysis sub-function, based on the ATT&CK framework, performs tactical and technical analysis on attack behaviors in high-value alarms and calculates the attacker's capability score based on the attacker capability scoring formula. The victim profiling sub-function conducts risk assessment from three dimensions: basic risk based on asset vulnerability status, exposure risk based on network topology location, and impact risk based on business criticality, ultimately generating a comprehensive risk score.

[0061] Based on this, the processing system performs in-depth analysis of standardized alert data, extracting features such as the attack source IP, attack type, and victim target IP. For the "attack capability score," the system analyzes the technical complexity and tactical breadth (e.g., mapped to the ATT&CK framework) exhibited by the attacker in the alert event. The more attack tools used and the more complete the attack stages covered, the higher the score, thus quantifying the attacker's technical level. For the "comprehensive risk score on the target side," the system combines an internal asset information database to identify the target's (i.e., the target's) business attributes in the network, comprehensively considering the severity of its system vulnerabilities, network exposure surface (e.g., whether it is in the DMZ), and business criticality (e.g., whether it is a core database), thus quantifying the potential actual business losses if the target is compromised. Finally, the scores from these two dimensions are structurally integrated to generate "enhanced intelligence data," which not only contains information about the threat itself but also integrates attacker profiles and victim risk profiles.

[0062] In some embodiments, in order to achieve in-depth modeling of the threat level through a combination of qualitative and quantitative analysis, this application conducts a two-way assessment from two dimensions: the attacker's technical and tactical level and the risk of business damage to the victim, in order to generate intelligence evaluation indicators with high discriminative power.

[0063] Based on this, refer to Figure 3 Based on multi-source heterogeneous alarm data, feature analysis is performed to obtain the attack capability score of the attacking end and the comprehensive risk score of the target side, including the following steps 301 to 304.

[0064] Step 301: Based on the preset adversarial tactical technology framework, analyze the attack behavior data in the multi-source heterogeneous alarm data to obtain the attack tactical stage and attack tools.

[0065] Step 302: Determine the number of attack tools and the number of stages in the attack tactics.

[0066] Step 303: Calculate the attack capability score of the attacking end based on the number of tools and the number of stages.

[0067] Step 304: Obtain internal asset information data, and based on the victim target identifier and internal asset information data in the multi-source heterogeneous alarm data, obtain the comprehensive risk score of the target side.

[0068] Steps 301 to 304 are described in detail below.

[0069] In step 301 of some embodiments, the processing system, based on a preset adversarial tactical framework, parses attack behavior data in multi-source heterogeneous alarm data to obtain attack tactical stages and attack tools. This step aims to transform the underlying alarm logs into standardized tactical language. The processing system uses an industry-standard network security adversarial framework (such as the MITRE ATT&CK framework) as the "preset adversarial tactical framework" to semantically map the attack commands, payloads, or behavioral characteristics recorded in the "multi-source heterogeneous alarm data." Here, "attack tactical stage" refers to the attacker's macro-level tactical objectives during the intrusion process (such as reconnaissance, execution, persistence, lateral movement, etc.), reflecting the depth of the attack's progress; "attack tools" refers to the specific software, scripts, or malware families used by the attacker. Through this parsing process, scattered alarms are structured into descriptions of attack behaviors with tactical intent.

[0070] In step 302 of some embodiments, the processing system determines the number of attack tools and the number of attack tactical phases. After completing the qualitative analysis of the attack behavior, this step performs quantitative statistical work. The processing system deduplicatively counts all "attack tools" associated with the same attack event or the same attack source within a specific time window, obtaining the "number of tools" N (e.g., using 2 different scanners and 1 exploit tool). Simultaneously, the system also counts the unique "attack tactical phases" covered by the attack behavior, obtaining the "number of phases" L (e.g., covering 5 phases from initial access to data theft). These two quantitative indicators intuitively reflect the richness and completeness of the attack activity.

[0071] In step 303 of some embodiments, the processing system calculates an attack capability score based on the number of tools and the number of stages. This step utilizes the two quantitative indicators mentioned above to construct an evaluation model to calculate the attacker's threat level. Typically, the processing system uses a positive correlation logic for calculation: the more "tools" there are, the richer the attacker's resources and the more diverse their methods; the more "stages" there are, the more complete the attack chain and the deeper the penetration. The system can perform comprehensive calculations on these two parameters using a preset mathematical model (such as an exponential growth model or a weighted summation formula) to ultimately output a numerical "attack capability score." This score objectively characterizes the technical strength and harm potential of the "attacker" (i.e., the attacking party); the higher the score, the more professional and dangerous the adversary.

[0072] The attacker's capability scoring formula is shown below.

[0073]

[0074] Where N is the number of attack tools (i.e., the number of tools), and L is the number of ATT&CK tactics covered (i.e., the number of phases).

[0075] In one example, an attack uses two tools and is designed with three tactical phases. The corresponding attack capability score is shown in the following formula.

[0076]

[0077] In step 304 of some embodiments, the processing system acquires internal asset information data and, based on the victim target identifier and internal asset information data from multi-source heterogeneous alarm data, obtains a comprehensive risk score for the target side. This step assesses the issue from the victim's perspective. The processing system first extracts the "victim target identifier" (usually the destination IP address) from the alarm data and uses it as an index to perform a correlation query in pre-built "internal asset information data" (such as an asset management database) to obtain detailed attributes of the target asset (such as system configuration, network area, business affiliation, etc.). Subsequently, based on this attribute information, the processing system comprehensively assesses the issue from multiple dimensions, including basic security (such as vulnerability severity), network environment (such as whether it is exposed to the public network), and business impact (such as whether it carries core data), and calculates the "comprehensive risk score for the target side." This score quantifies the actual risk exposure to the entire organization should the asset be compromised, as described below.

[0078] Reference Figure 4 Based on the victim target identifier and internal asset information data in the multi-source heterogeneous alarm data, a comprehensive risk score is obtained on the target side, including the following steps 401 to 405.

[0079] Step 401: Based on the victim target identifier, query the internal asset information data to obtain the vulnerability status information, network topology location information, and business attribute information of the target side.

[0080] Step 402: Calculate the basic risk score based on the vulnerability status information.

[0081] Step 403: Calculate the exposure risk score based on network topology location information.

[0082] Step 404: Determine the criticality level and data sensitivity level of the business system corresponding to the target side contained in the business attribute information, and calculate the impact risk score based on the criticality level and sensitivity level.

[0083] Step 405: Based on the basic risk score, exposure risk score, and impact risk score, perform a weighted summation to obtain the comprehensive risk score on the target side.

[0084] Steps 401 to 405 are described in detail below.

[0085] In step 401 of some embodiments, the processing system queries the internal asset information data based on the victim target identifier to obtain vulnerability status information, network topology location information, and business attribute information of the target side. This step is the data preparation stage for risk assessment. The processing system first parses the "victim target identifier" (usually the IP address or unique device ID of the victim host) from the alarm data and uses it as a retrieval key to perform a matching query in the pre-built "internal asset information data" (such as the enterprise's configuration management database CMDB or asset ledger). Through this operation, the system can extract a three-dimensional feature profile of the "target side" entity from the static asset database: first, "vulnerability status information," that is, the list of unpatched vulnerabilities currently existing in the asset and their severity; second, "network topology location information," that is, the network area (such as DMZ, core intranet area, or office area) where the asset is located and its network interconnection relationship; and third, "business attribute information," that is, the name of the business system to which the asset belongs, the department to which it belongs, and the description of the business functions it carries.

[0086] In step 402 of some embodiments, the processing system calculates a basic risk score based on the vulnerability status information. This step focuses on assessing the inherent technical vulnerabilities of the asset. The processing system performs quantitative analysis on the extracted "vulnerability status information," typically based on common vulnerability scoring standards (such as the CVSS score, i.e., ...). The base severity value of a vulnerability is determined by combining it with its exploitability (e.g., the existence of publicly available exploit scripts or the difficulty of exploiting the vulnerability in the current network environment). The "base risk score" is calculated by multiplying or weighting the vulnerability's severity with its exposure coefficient. This score reflects the technical probability that an asset can be compromised due to its own software defects, and the corresponding formula is shown below.

[0087]

[0088] in, This is the vulnerability exposure coefficient (i.e., vulnerability status information).

[0089] In step 403 of some embodiments, the processing system calculates an exposure risk score based on network topology location information. This step focuses on assessing the size of the external attack surface faced by an asset due to its different network location. The processing system determines the network security domain in which the asset resides based on the "network topology location information" and assigns corresponding weights to different zones. For example, DMZ zone assets that directly expose services to the Internet typically have a higher zone weight, while core internal network database assets protected by multiple firewalls have a lower zone weight. The system combines this zone weight with the asset's port exposure score to calculate the "exposure risk score." This score quantifies how easy it is for an attacker to reach the asset via a network path, as shown in the following formula.

[0090]

[0091] Where W is the network area weight and A is the exposure score (which is determined by network topology location information).

[0092] In step 404 of some embodiments, the processing system determines the criticality level and data sensitivity level of the target-side business system contained in the business attribute information, and calculates an impact risk score based on the criticality level and sensitivity level. This step focuses on assessing the actual losses to the business after the asset is compromised. The processing system parses two core dimensions from the "business attribute information": one is the "criticality level," which refers to the importance of the asset to maintaining business continuity (such as a core transaction system or an edge testing system); the other is the "data sensitivity level," which refers to the confidentiality requirements of the data stored or processed by the asset (such as user privacy data or public data). Based on the logic that the higher the level, the greater the risk, the system calculates the "impact risk score." This leads to the introduction of risk measurement from a business perspective, as shown in the following formula.

[0093]

[0094] Where K represents business criticality (i.e., criticality level) and S represents data sensitivity (i.e., sensitivity level).

[0095] In step 405 of some embodiments, a weighted sum is performed based on the basic risk score, exposure risk score, and impact risk score to obtain the comprehensive risk score for the target side. This step is the final synthesis of the risks from the above three dimensions. The system assigns preset weight coefficients (e.g., 0.5, 0.3, and 0.2 weights respectively) to the "basic risk score," "exposure risk score," and "impact risk score," and calculates a single numerical indicator, namely the "comprehensive risk score" R, through weighted summation. This score not only considers the severity of technical vulnerabilities but also fully integrates the exposure of the network environment and the importance of business assets, as shown in the following formula.

[0096]

[0097] In one example, a host in a DMZ area (exposed risk: 0.8) has a vulnerability risk (basic risk: 6.0) and runs core business operations (impact risk: 1.0). Its corresponding comprehensive risk score is: .

[0098] Through steps 401 to 405 above, a comprehensive asset risk assessment model is constructed by breaking down risk assessment into three orthogonal dimensions: technical vulnerability, network exposure surface, and business impact. This model can accurately identify high-risk assets from a massive number of alert targets, ensuring that the final comprehensive risk score truly reflects the actual impact of threats on the enterprise's core business. This provides a scientific and quantitative basis for subsequent prioritization and defense resource allocation.

[0099] Through steps 301 to 304 above, by introducing a "pre-defined adversarial tactical framework" and "internal asset information data," bidirectional feature analysis is achieved from both the "attack end" and the "target side." On the one hand, by quantifying attack tools and tactical stages, the attacker's technical profile and capability level are accurately depicted; on the other hand, by associating internal asset attributes, the actual risk value of the victim target is clarified from a business perspective. This dual-perspective analysis mechanism ensures that the final "enhanced intelligence data" not only understands the external form of the threat but also its internal impact, significantly improving the adaptability and guiding significance of intelligence for actual defense scenarios.

[0100] In addition, this module integrates spatiotemporal analysis data (temporal features such as attack frequency and target distribution) and outputs structured intelligence containing both attacker and victim profiles. An example of the dual-perspective profile output is shown in the code below.

[0101] { "attacker": { "techniques": ["T1059.001", "T1021.002"], / / List of attack techniques "capability_score": 0.47, / / Attack capability score "tactics": ["Execution", "Persistence"], / / List of attack tactics "behavior": { "first_seen_time": "2025-06-15 T14:22:03Z", / / First attack time "last_seen_time": "2025-07-24T09:45:37Z", / / Last active time "attack_count": 12, / / Total number of attacks "compromised_asset_count": 5, / / Total number of compromised assets "compromised_assets": [ "asset-1","asset-2","asset-3","asset-4"] / / List of attacked assets } }, "victim": { "asset_id":"asset_1", / / Victim's asset ID "risk_breakdown": {"base": 6, "exposure": 0.8, "impact": 1.0}, / / Risk ratings for various types of affected assets "composite_risk": 3.44, / / Comprehensive risk score "compromise_count": 5, / / Number of times attacked "attacker_ips": ["45.33.12.78", "185.143.223.91"] / / List of attacking IPs }, } Understandably, the example code above demonstrates a structured intelligence example output by the context-enhanced analysis module in this application embodiment. Its core lies in achieving deep integration of threat intelligence and internal business scenarios through dual-perspective profiling of "attacker" and "victim." In the attacker profile, the processing system not only records the list of attack techniques, tactical stages, and behavioral timing characteristics, but also quantifies the threat level of the attacking end through a specific capability scoring formula. In the victim profile, by linking internal asset information data, it displays the victim asset ID and its comprehensive risk score in detail, and provides scoring items including basic risk, exposure risk, and impact risk, thus providing a quantitative reference for assessing the impact of threats on actual business operations.

[0102] This structured intelligence serves as the foundation for intelligence fusion calibration, providing precise internal evidence support for subsequent cross-dimensional data verification. By comparing this enhanced intelligence data, rich in business context, with external multi-source intelligence, the processing system can calculate the matching degree of external intelligence sources in the current business environment, and then dynamically adjust the credibility weight of each intelligence source. This intelligence output with dual-perspective profiling not only breaks the limitation of traditional intelligence focusing solely on Indicators of Compromise (IOC), but also provides structured data guidance for the collaborative defense implementation module to issue precise blocking and hardening strategies by clearly defining the risk composition of victim assets and the technical characteristics of attackers.

[0103] Step 103: Based on the enhanced intelligence data, perform matching and retrieval on the external multi-source intelligence data to obtain the matching degree, and obtain the update credibility weight of each external intelligence source in the external multi-source intelligence data based on the matching degree.

[0104] Step 103 will be described in detail below.

[0105] In step 103 of some embodiments, external multi-source intelligence data is matched and retrieved based on enhanced intelligence data to obtain a matching degree, and an updated credibility weight for each external intelligence source in the external multi-source intelligence data is obtained based on the matching degree. This step is mainly performed by the intelligence fusion verification module of the processing system, which aims to use internally confirmed combat data (i.e., enhanced intelligence data) as matching data to dynamically verify the quality of external intelligence sources. The intelligence fusion verification module includes three sub-functions: multi-source intelligence query, credibility assessment, and intelligence calibration fusion. The multi-source intelligence query sub-function performs cross-platform intelligence retrieval on key threat indicators (such as malicious IPs) to obtain the judgment results of each intelligence source. The credibility assessment sub-function establishes a dynamic weight allocation mechanism by comparing the degree of consistency between internally confirmed attack behaviors and external intelligence: intelligence sources with high matching degrees are assigned higher credibility scores, and intelligence sources with deviations are weighted lower. The intelligence calibration fusion sub-function integrates multi-source external intelligence based on the weight allocation results to calculate the comprehensive threat score of the attacking IP.

[0106] Based on this, the processing system extracts key threat characteristics (such as IP addresses identified as malicious attack sources) from the enhanced intelligence data and performs reverse queries on multiple external intelligence source databases. If an external intelligence source also records the threat and its assessment is consistent with the internal analysis, it is considered to have a high "match." Subsequently, the weights of each intelligence source are adjusted based on this match; the weight of a source with a high match is increased, and vice versa. Here, the "updated credibility weight" is a dynamically changing value that reflects the accuracy and reliability of each external intelligence source relative to the actual internal attack situation within the current specific business environment and time window.

[0107] The following section first describes how to determine the matching degree.

[0108] Reference Figure 5 The matching and retrieval of external multi-source intelligence data based on enhanced intelligence data to obtain the matching degree includes the following steps 501 to 503.

[0109] Step 501: Determine the source IP address and attack type from the enhanced intelligence data.

[0110] Step 502: Based on the attack source IP address, search in external multi-source intelligence data to obtain the corresponding external judgment record.

[0111] Step 503: Perform consistency matching based on the attack type and attack behavior type corresponding to the external judgment record to obtain the matching degree.

[0112] Steps 501 to 503 are described in detail below.

[0113] In step 501 of some embodiments, the processing system determines the attack source IP address and attack behavior type from the enhanced intelligence data. This step is a preparatory phase for initiating intelligence verification, aiming to extract key index information for cross-domain comparison from internally generated structured intelligence. The processing system parses the "enhanced intelligence data" generated in the preceding steps, which contains an attacker profile verified by the internal business environment. The extracted "attack source IP address" refers to the network identifier of the device initiating malicious activities in the internal network (e.g., a public IPv4 address), which is the unique primary key for cross-platform retrieval; the "attack behavior type" refers to a description of the specific attack method detected internally by the system (e.g., "SSH brute-force attack," "SQL injection," or a specific technical number mapped to the ATT&CK framework, such as T1059.001). These two features together constitute factual evidence data from an internal perspective.

[0114] In step 502 of some embodiments, the processing system searches external multi-source intelligence data based on the attack source IP address to obtain the corresponding external judgment record. This step performs a cross-domain intelligence query operation. The processing system uses the extracted "attack source IP address" as the search key to perform parallel queries in the accessed "external multi-source intelligence data" database. These external intelligence sources may cover commercial threat intelligence feeds, open-source community blacklists, or government notification data. The purpose of the query is to confirm the external world's awareness of the IP address. The query results are called "external judgment records," which typically contain a qualitative description of the IP from the external intelligence sources (such as whether it is marked as malicious), threat tags (such as "botnet," "scanner"), and related attack type descriptions.

[0115] In step 503 of some embodiments, the processing system performs consistency matching based on the attack type and attack behavior type corresponding to the external judgment record to obtain a matching degree. This step is the core verification logic, aiming to quantify the accuracy of external intelligence by comparing the "difference between internal and external cognition." At this time, the processing system performs semantic comparison or feature matching between the internal "attack behavior type" extracted in step 501 and the "attack type" in the external judgment record obtained in step 502. If the two are highly consistent (for example, the internal system discovers that the IP is performing port scanning, and the external intelligence also marks it as a scanning source), a high "matching degree" is calculated; if the two conflict or the external intelligence lacks relevant records, the matching degree is reduced. This "matching degree" M is a quantitative value that intuitively reflects the accuracy of the external intelligence source in the current specific attack event.

[0116] Through steps 501 to 503 above, an automated process of "extracting key features - external targeted retrieval - consistency comparison" is constructed, using internally captured real attack behaviors as "benchmark truth values" to perform reverse verification of external multi-source intelligence. This mechanism breaks the traditional passive mode of one-way reception of external intelligence, and can accurately identify which external intelligence sources are accurate and reliable in the current business scenario. This provides an objective and real-time "matching degree" basis for the subsequent dynamic adjustment of intelligence source weights, ensuring a high degree of confidence in the final fused intelligence.

[0117] The following section will further describe how to determine the updated credibility weights.

[0118] Reference Figure 6 The update credibility weight of each external intelligence source in the external multi-source intelligence data is obtained based on the matching degree, including the following steps 601 to 603.

[0119] Step 601: Obtain the historical rating and preset authority level of each external intelligence source.

[0120] Step 602: Correct the historical scores based on the matching degree to obtain the dynamic scores.

[0121] Step 603: Perform a weighted calculation on the dynamic score and authority level to obtain the update credibility weight corresponding to each external intelligence source.

[0122] Steps 601 to 603 are described in detail below.

[0123] In step 601 of some embodiments, the processing system acquires the historical score and preset authority level of each external intelligence source. This step prepares the basic data for dynamic adjustment of the weights. The processing system reads two types of key indicators from a database or configuration file: one is the "historical score" H, which characterizes the average degree of agreement (i.e., matching degree) between the external intelligence source and the actual internal attack data over a period of time (e.g., the last 30 days), reflecting the stability of its long-term performance; the other is the "preset authority level" S, which is a static coefficient pre-assigned based on the nature of the intelligence source. For example, government security agencies or authoritative commercial vendors are usually assigned a higher authority level (e.g., 1.0), commercial platforms a medium authority level (e.g., 0.6), and anonymous open-source communities a lower level (e.g., 0.2); in addition, there is a preset authority weight coefficient (e.g., 0.3, an adjustable parameter). These two types of data together constitute the benchmark for evaluating the credibility of the intelligence source.

[0124] In step 602 of some embodiments, the processing system corrects the historical score based on the matching degree to obtain a dynamic score. This step introduces real-time practical verification results. The processing system uses the "matching degree" (i.e., the proportion of agreement between the evidence of this internal attack and external intelligence) calculated in the previous step as a correction factor to perform mathematical operations on the "historical score". For example, a weighted average or product method can be used to incorporate the current matching performance into the historical data. If the current matching degree is high, it indicates that the intelligence source provided an accurate warning in this event, and its score will increase accordingly; conversely, if there are false alarms or omissions, the score will decrease. The "dynamic score" generated by this process is no longer static historical data, but a timely evaluation value that incorporates the latest practical verification results.

[0125] In step 603 of some embodiments, the processing system performs a weighted calculation of the dynamic score and the authority level to obtain the updated credibility weight corresponding to each external intelligence source. This step comprehensively considers two dimensions: "real-world performance" and "identity endorsement," generating the final weight coefficient. The processing system combines the "dynamic score" reflecting real-time accuracy obtained in step 602 and the "authority level" reflecting source reliability obtained in step 601 according to a preset ratio (i.e., weight coefficient). The weighted summation or normalization process is performed. The calculated "updated credibility weight" W is a comprehensive trust index that neither blindly follows authority (if the authoritative source performs poorly in the local environment, the weight will also decrease) nor completely depends on short-term fluctuations, thus achieving an objective quantification of the value of external intelligence sources, as shown in the following formula.

[0126]

[0127] Where M is the matching degree, which is the proportion of the current intelligence to match the internal data; H is the historical score, which is the evaluation matching degree of the intelligence source over a period of time (e.g., 30 days); S is the authority, which is the credibility level of the intelligence source (government agencies = 1.0, commercial platforms = 0.6, open source forums = 0.2); α is the authority weight coefficient (default 0.3, adjustable); T is the total score of all intelligence sources.

[0128] In one example, refer to Figure 7 This is an example diagram of multi-dimensional evaluation data from an external intelligence source provided in an embodiment of this application. Figure 7As shown in the figure, the table visually displays the key indicator parameters for credibility assessment of three different types of external intelligence sources (source A, a government agency; source B, a commercial platform; and source C, an open-source forum). Specifically, it includes the original confidence level provided by each intelligence source, the real-time matching degree obtained after internal enhanced intelligence verification (e.g., source A is 0.88, source C is only 0.33), the historical scores, and the authority level preset based on the source type (e.g., government agencies are 1, open-source forums are 0.2). These quantitative data serve as the input basis for the dynamic weight allocation algorithm of this application, used to calculate the updated credibility weight of each intelligence source, thereby reflecting the quality differences of different intelligence sources in a real combat environment.

[0129] Based on this, the update credibility weight allocation for each intelligence source according to the above formula is calculated as shown in the following formula.

[0130]

[0131]

[0132]

[0133] Through steps 601 to 603 above, a closed-loop evaluation model of "historical benchmark + real-time verification + authoritative correction" is constructed, realizing an evidence-driven dynamic management mechanism for intelligence sources. This mechanism can dynamically adjust the credibility weight of external intelligence sources in real time based on their actual performance in the local business environment, effectively solving the problem of low accuracy caused by blind trust in external intelligence sources or static scoring in traditional solutions. This enables the system to automatically select the high-quality intelligence sources most suitable for the current network environment, ensuring that the threat intelligence subsequently generated has extremely high confidence and business adaptability.

[0134] Step 104: Based on the updated credibility weights, perform weighted fusion of external multi-source intelligence data to generate an external comprehensive threat score.

[0135] Step 104 is described in detail below.

[0136] In step 104 of some embodiments, external multi-source intelligence data is weighted and fused based on updated credibility weights to generate an external comprehensive threat score. After completing the "physical examination" and weight allocation of each intelligence source, this step performs mathematical fusion of multi-source data. Specifically, for the same threat entity (such as a malicious IP), the system obtains the original threat scores or confidence levels given by all external intelligence sources, multiplies these original scores by the "updated credibility weight" corresponding to the intelligence source calculated in step 103, and then sums or normalizes the weighted results. The "external comprehensive threat score" generated by this calculation method is no longer a simple average or blindly accepting one source's opinion, but a comprehensive judgment result after calibration with localized evidence, which can more accurately reflect the true external credibility of the threat in the current network environment.

[0137] Reference Figure 8 The external multi-source intelligence data is weighted and fused based on the updated credibility weights to generate an external comprehensive threat score, including the following steps 801 to 802.

[0138] Step 801: Multiply the threat confidence score corresponding to each external intelligence source by the corresponding update confidence weight to obtain a weighted score.

[0139] Step 802: Sum the weighted scores of all external intelligence sources to obtain the comprehensive external threat score.

[0140] Steps 801 to 802 are described in detail below.

[0141] In step 801 of some embodiments, the processing system multiplies the threat confidence score corresponding to each external intelligence source with its corresponding updated credibility weight to obtain a weighted score. This step is a data fusion calculation step, designed to adjust the value of the data provided by the intelligence source based on its reliability. The processing system first obtains the "threat confidence score" given by each "external intelligence source" for a specific threat entity (such as a malicious IP). This score is usually provided by the intelligence vendor and represents the vendor's confidence in its judgment (e.g., a value between 0 and 1). Subsequently, the processing system introduces the "updated credibility weight" verified based on internal practical data in the previous step and multiplies the original threat confidence score. Through this "multiplication" operation, the threat scores provided by intelligence sources that perform well in internal verification and have high weights are retained or amplified; while the threat scores provided by intelligence sources that frequently give false positives and have low weights are diluted or reduced. The calculated "weighted score" is no longer simply an external opinion, but a corrected value adjusted by local trust quantification.

[0142] In step 802 of some embodiments, the weighted scores of all external intelligence sources are summed to obtain an external comprehensive threat score. This step performs the final aggregation logic, unifying the scattered multi-source data into a single metric. The system sums the weighted scores calculated by all external intelligence sources for the same threat entity (normalization may also be included in some embodiments). This process is similar to a weighted voting mechanism, and the final output "external comprehensive threat score" comprehensively reflects the degree of consensus among all external intelligence sources on the threat, and this consensus is based on the principle of accuracy. This score provides a global, high-confidence indicator of external threats, providing standardized input data for subsequent integration with internal intelligence.

[0143] In one example, based on such Figure 7 The updated credibility weights corresponding to the three intelligence sources shown are used to integrate multi-source external intelligence based on the weight allocation results using the intelligence calibration fusion sub-function, and the comprehensive threat score of the attacking IP is calculated. The calculation example is shown in the formula below.

[0144]

[0145] Through steps 801 and 802 above, a multi-source intelligence fusion algorithm based on trust metrics is implemented using a mathematical model of "weighted product" and "summation." This effectively solves the decision-making problem when multiple sources of intelligence conflict (e.g., one source claims it is malicious, while another claims it is safe), and avoids the shortcomings of simple average-value algorithms, which are easily influenced by low-quality intelligence sources. The external comprehensive threat score generated in this way can absorb the judgment value of high-quality intelligence sources to the greatest extent and eliminate noise from low-reputation sources, thereby ensuring that the final external threat intelligence is optimal in terms of accuracy and reliability.

[0146] Step 105: Obtain target threat intelligence data based on enhanced intelligence data and external comprehensive threat scoring.

[0147] Step 105 is described in detail below.

[0148] In step 105 of some embodiments, the processing system obtains target threat intelligence data based on enhanced intelligence data and external comprehensive threat scores. This is the final assembly step in intelligence generation. The processing system correlates and merges the "enhanced intelligence data" (focusing on an internal perspective, including attacker capabilities and victim risk) generated in step 102, which contains rich business context, with the calibrated "external comprehensive threat score" (focusing on an external perspective, including global threat reputation) generated in step 104. The final generated "target threat intelligence data" is a high-value structured dataset that possesses both the breadth of external intelligence and the depth of internal business. This data is typically output in standard formats such as JSON, directly supporting the subsequent deployment of automated defense strategies, such as hardening high-risk assets or blocking high-reputation threat sources.

[0149] In one example, it is correlated and fused with internal contextual intelligence (that is, combined with enhanced intelligence data and external comprehensive threat scores) to generate the final calibrated target threat intelligence data, and the specific example code is shown below.

[0150] { "attacker": { "techniques": ["T1059.001", "T1021.002"], / / List of attack techniques "capability_score": 0.47, / / Attack capability score "tactics": ["Execution", "Persistence"], / / List of attack tactics "threat_type": "malicious", / / Threat type "confidence": 0.86, / / Overall threat score "sources": ["SourceA", " SourceB", " SourceC"], "behavior": { "first_seen_time": "2025-06-15 T14:22:03Z", / / First attack time "last_seen_time": "2025-07-24T09:45:37Z", / / Last active time "attack_count": 12, / / Total number of attacks "compromised_asset_count": 5, / / Total number of compromised assets "compromised_assets": [ "asset-1","asset-2","asset-3","asset-4"] / / List of attacked assets "internal_attack": ["SSH brute-force","Network Scanning"], } }, "victim": { "asset_id":"asset_1", / / Victim's asset ID "risk_breakdown": {"base": 6, "exposure": 0.8, "impact": 1.0}, / / Risk ratings for various types of affected assets "composite_risk": 3.44, / / Comprehensive risk score "compromise_count": 5, / / Number of times attacked "attacker_ips": ["45.33.12.78", "185.143.223.91"] / / List of attacking IPs }, } Understandably, the code above demonstrates the structured intelligence data generated by the context-enhanced analysis module in this application embodiment. Its core lies in achieving deep integration of threat intelligence and internal business scenarios through a dual-perspective profile of "attacker" and "victim." In the attacker profile, the processing system not only records attack techniques, tactical lists, and behavioral temporal characteristics, but also quantifies the attack capability score using a specific formula. In the victim profile, by linking internal asset information data, it displays detailed victim asset IDs, risk breakdown scores (including basic, exposure, and impact risks), and comprehensive risk scores, thus providing a precise quantitative reference for assessing the impact of threats on actual business operations.

[0151] This structured intelligence serves as the foundation for subsequent intelligence fusion and calibration, providing core support for cross-dimensional data verification. By associating and fusing this enhanced intelligence, which contains rich business context, with external multi-source intelligence, the system can output final calibrated intelligence including a comprehensive threat score and source labeling, such as the 0.86 confidence score and source list reflected in the code. This intelligence output with dual-perspective profiling breaks through the limitations of traditional intelligence that only focuses on attack indicators. By clearly defining the risk composition of victim assets and the technical characteristics of attackers, it provides standardized data guidance for collaborative defense modules to issue precise blocking and hardening strategies.

[0152] Furthermore, the solution in this application also includes a collaborative defense module, which is an internal network protection system based on the fused intelligence output by this application. It mainly comprises three sub-functions: risk asset identification, protection policy generation, and multi-subnet push execution. The risk asset identification sub-function identifies asset groups with similar risk characteristics by comparing asset features (system configuration, open ports, vulnerability lists, etc.). The protection policy generation sub-function automatically extracts malicious IPs from the intelligence daily to generate a blocking list and generates protection plans based on the risk asset characteristics. The multi-subnet push execution sub-function issues protection commands to security devices (firewalls, EDRs, etc.) in each subnet through a standardized API interface, achieving cross-subnet collaborative protection.

[0153] Based on this, refer to Figure 9 The method for generating threat intelligence data provided in this application also includes steps 901 to 904.

[0154] Step 901: Analyze the target threat intelligence data and extract target-side features and attack source features.

[0155] Step 902: Identify similar risk asset groups with configurations similar to those of the target side within the internal network.

[0156] Step 903: Generate blocking strategies targeting attack source characteristics, and generate preventative protection strategies targeting similar risky asset groups.

[0157] Step 904: Send the blocking and preventative protection policies to the cybersecurity devices associated with similar risk asset groups.

[0158] Steps 901 to 904 are described in detail below.

[0159] In step 901 of some embodiments, the processing system parses the target threat intelligence data, extracting target-side features and attack source features. This step is the decision input stage for collaborative defense, aiming to separate key elements of "attack" and "defense" from the generated structured intelligence. The processing system parses the fields of the final product generated in the preceding steps—the "target threat intelligence data" (usually in standardized JSON or XML format). The extracted "attack source features" refer to indicators used to identify the attacker's identity and behavioral patterns, such as malicious IP addresses, attack payload hashes, or malicious domain names used; the extracted "target-side features" refer to the vulnerability attributes exhibited by the victim's assets when attacked, such as open risky ports (e.g., port 445), specific versions of running service software (e.g., Apache Log4j 2.14.1), or operating system patch versions. These two types of features provide precise parameter basis for subsequent development of targeted defense strategies.

[0160] In step 902 of some embodiments, the processing system identifies a group of similar risky assets within the internal network that have configurations similar to the target's characteristics. This step embodies the proactive defense concept of "learning from one example to understand others." The processing system uses the extracted "target-side characteristics" as a fingerprint template to perform a horizontal search in the enterprise's asset management database or network-wide asset mapping data. The aim is to find assets that, although no alerts have been issued, have the same vulnerability configuration as the victim target. For example, if the victim target is compromised due to an unpatched vulnerability, the system will identify all hosts across the network that also have the same unpatched vulnerability. These identified asset sets are called "similar risky asset groups," and they are potential high-risk targets and key protection targets for collaborative defense.

[0161] In step 903 of some embodiments, the processing system generates a blocking policy based on attack source characteristics and a preventative protection policy for similar risk asset groups. This step develops differentiated solutions for different targets. For external attackers, the processing system generates a blocking policy based on "attack source characteristics," such as creating inbound drop rules for malicious IPs on the perimeter firewall. For potential internal victims, the processing system generates a preventative protection policy based on the specific risks they face. This policy is not a simple block, but a targeted hardening measure, such as issuing virtual patch policies to block exploit traffic targeting specific vulnerabilities, or increasing the monitoring level of EDR agents on the asset group to detect suspicious behavior in real time. Through this combined approach, the system achieves both containment of attack sources and enhanced immunity to potential victims.

[0162] In step 904 of some embodiments, the processing system sends blocking and preventative protection policies to the network security devices associated with the similar risk asset group. This step is the execution and implementation phase of the defense action. The processing system establishes communication with the underlying physical devices through standardized API interfaces or Security Orchestration and Automated Response (SOAR) channels. The processing system automatically identifies the network location of the "similar risk asset group" and finds the "network security devices" responsible for protecting these assets, including but not limited to next-generation firewalls (NGFW), host-side endpoint detection and response systems (EDR), or micro-segmentation gateways. Subsequently, the processing system accurately distributes the generated blocking instructions and hardening policies to these devices and makes them effective, thereby completing the defense deployment before the attack spreads laterally.

[0163] Reference Figure 10 This is a detailed flowchart illustrating the operation of a collaborative defense implementation module provided in an embodiment of this application. Figure 10 As shown, this collaborative defense implementation module uses the final generated internal threat intelligence and internal asset information table as core inputs. First, through the risk asset identification sub-function, it compares the vulnerability characteristics recorded in the intelligence with the system configuration, vulnerability list, and other attributes of all network assets to accurately locate similar risk asset groups affected by threats. Subsequently, the protection strategy generation sub-function implements differentiated handling for the identified threats, including automatically extracting malicious IP addresses from the intelligence to generate a blocking list, and customizing preventative protection plans based on the actual risk characteristics of the affected assets, thereby transforming abstract intelligence into executable security commands.

[0164] During the policy execution phase, this module achieves cross-regional defense synchronization through multi-subnet push execution sub-functions, effectively solving the problem of defense fragmentation. The processing system utilizes standardized API interfaces to distribute generated blocking policies and hardening instructions in real time to security protection devices distributed across different subnet environments (such as subnet environments 1, 2, and 3), including firewalls and Endpoint Detection and Response (EDR) systems. This collaborative model of discovery at a single point and response across the entire network ensures that defense policies reach potential victim assets before the lateral spread of attacks, thereby constructing a dynamic and multi-dimensional security barrier within the multi-subnet architecture and significantly improving the overall resilience of the entire network environment against complex internal threats.

[0165] Through steps 901 to 904 above, a closed-loop process from intelligence analysis to similar risk identification, strategy generation, and execution is constructed, establishing an intelligence-driven intranet collaborative defense mechanism. This mechanism overcomes the passive limitations of traditional "single-point alerting and single-point handling," enabling rapid identification and protection of all vulnerable assets with similar risk characteristics across the entire network based on attack and defense intelligence from a single victim point. It achieves a "one-point discovery, network-wide immunity" joint defense and control effect, significantly improving the enterprise network's response speed and overall defensive resilience against the spread of known threats.

[0166] Through steps 101 to 105 above, the technical solution extracts attack capabilities and target risks from alarm data, achieving a deep integration of threat intelligence with internal business scenarios. This addresses the pain point of existing technologies where intelligence is detached from actual business operations. Simultaneously, it innovatively utilizes internally generated enhanced intelligence as evidence to dynamically verify the matching degree and update the weights of external intelligence sources, constructing an "internal verification of external" intelligence calibration mechanism that effectively eliminates noise and false alarms from external intelligence. This localized evidence-driven intelligence generation and fusion method significantly improves the accuracy, timeliness, and guiding value of the final target threat intelligence data for actual business defense.

[0167] Reference Figure 11 This is a schematic diagram of the overall architecture of a threat intelligence generation and sharing method provided in an embodiment of this application. Figure 11 As shown, this architecture, through the collaborative work of multiple core modules, constructs a closed-loop system from initial security alarm access to cross-subnet collaborative defense. The process begins with the multi-source alarm data access stage on the left. The processing system receives alarm data in real time from IDS, IPS, EDR, security gateways, and other security devices in various subnet environments. This heterogeneous initial alarm data is uniformly input into the alarm processing module. Inside the alarm processing module, the system transforms massive discrete alarms into composite security events through feature extraction and similarity aggregation, and simultaneously correlates them with internal asset information data. By assessing the severity of the attack and the criticality of the assets, alarms with high analytical value are extracted, thus laying the data foundation for subsequent intelligence enhancement.

[0168] Subsequently, the refined high-value alerts enter the context-enhanced analysis module. This module combines the vulnerability status, network location, and business attributes of internal assets, generating enhanced intelligence data with business context awareness from the perspectives of attacker tactical profiling and victim risk. This effectively solves the problem of insufficient adaptability caused by the lack of business background in traditional intelligence. Next, this enhanced intelligence data is input into the intelligence fusion calibration module. This module uses real-world attack behavior as verification criteria to perform real-time retrieval and comparison of the incoming commercial threat intelligence data. By calculating the matching degree between internal facts and external intelligence, the processing system can dynamically output a commercial threat intelligence credibility score, thereby assigning updated credibility weights to each intelligence source and generating the final target threat intelligence data through weighted fusion.

[0169] At the end of the process, the generated final target threat intelligence data is pushed to the collaborative defense implementation module. This module not only analyzes the threat characteristics in the intelligence but also identifies asset groups with similar vulnerability configurations to the current victim within the internal network. For these identified risk entities, the module automatically generates blocking strategies for the attack source and preventative protection strategies for similar assets, and synchronously distributes these strategies to network security devices in subnet environment 1, subnet environment 2, and subnet environment 3 via standardized interfaces. This cross-subnet collaborative mechanism ensures that defense actions cover all potential vulnerable points across the entire network, thus achieving a highly efficient security protection effect of "one-point detection, network-wide immunity" in a multi-subnet architecture.

[0170] This application also provides a threat intelligence data generation apparatus, which can implement the above-described threat intelligence data generation method, referring to... Figure 12 The device 1200 includes: The acquisition module 1210 is used to acquire multi-source heterogeneous alarm data and external multi-source intelligence data; The feature analysis module 1220 is used to perform feature analysis based on multi-source heterogeneous alarm data to obtain the attack capability score of the attacking end and the comprehensive risk score of the target side, and to obtain enhanced intelligence data based on the attack capability score and the comprehensive risk score. The matching credibility calculation module 1230 is used to perform matching retrieval on external multi-source intelligence data based on enhanced intelligence data, obtain the matching degree, and obtain the updated credibility weight of each external intelligence source in the external multi-source intelligence data based on the matching degree. The external scoring module 1240 is used to perform weighted fusion of external multi-source intelligence data based on updated credibility weights to generate an external comprehensive threat score. The target data generation module 1250 is used to obtain target threat intelligence data based on enhanced intelligence data and external comprehensive threat scoring.

[0171] In some embodiments, the feature analysis module 1220 is further configured to: Based on a pre-defined adversarial tactical technology framework, attack behavior data in multi-source heterogeneous alarm data is analyzed to obtain attack tactical stages and attack tools. Determine the number of attack tools and the number of stages in the attack tactics; Based on the number of tools and the number of stages, the attack capability score of the attacking end is calculated; The system acquires internal asset information data and, based on the victim target identifier and internal asset information data from multi-source heterogeneous alarm data, obtains a comprehensive risk score for the target side.

[0172] In some embodiments, the feature analysis module 1220 is further configured to: Based on the victim's identifier, queries are performed in the internal asset information data to obtain the vulnerability status information, network topology location information, and business attribute information of the target side. A basic risk score is calculated based on the vulnerability status information; Calculate exposure risk scores based on network topology location information; Determine the criticality level and data sensitivity level of the target system contained in the business attribute information, and calculate the impact risk score based on the criticality level and sensitivity level. The comprehensive risk score on the target side is obtained by weighting and summing the basic risk score, exposure risk score, and impact risk score.

[0173] In some embodiments, the matching confidence calculation module 1230 is further configured to: Identify the source IP address and type of attack behavior from enhanced intelligence data; Based on the attack source IP address, the corresponding external judgment record is obtained by searching through external multi-source intelligence data. The matching degree is obtained by performing consistency matching based on the attack type and attack behavior type corresponding to the external judgment record.

[0174] In some embodiments, the matching confidence calculation module 1230 is further configured to: Obtain the historical ratings and preset authority levels of each external intelligence source; The historical scores are corrected based on the matching degree to obtain a dynamic score; The dynamic score and authority level are weighted to obtain the update credibility weight for each external intelligence source.

[0175] In some embodiments, the external scoring module 1240 is further configured to: The threat confidence score for each external intelligence source is multiplied by the corresponding update credibility weight to obtain a weighted score. The weighted scores of all external intelligence sources are summed to obtain the overall external threat score.

[0176] In some embodiments, the acquisition module 1210 is further configured to: Acquire initial multi-source heterogeneous alarm data and extract feature information from the initial multi-source heterogeneous alarm data; Based on feature information, similarity aggregation is performed to obtain multiple composite security events; Based on the victim target identifier in each complex security incident, a query is performed in the internal asset information data to obtain the asset criticality score corresponding to each complex security incident; A comprehensive evaluation is conducted based on the attack severity level, asset criticality score, and attack frequency of the complex security incidents to obtain a comprehensive evaluation score for each complex security incident. Composite security events with a comprehensive evaluation score exceeding a preset evaluation score are selected from multiple composite security events and used as multi-source heterogeneous alarm data.

[0177] In some embodiments, the target data generation module 1250 is further configured to: Analyze target threat intelligence data to extract target-side features and attack source features; Identify groups of similar risky assets within the internal network that have configurations similar to those of the target side; Generate blocking strategies targeting attack source characteristics, and generate preventative protection strategies targeting similar risky asset groups; Send blocking and preventative protection policies to cybersecurity devices associated with similar risk asset groups.

[0178] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, the specific implementation of the threat intelligence data generation device is basically the same as the specific implementation of the threat intelligence data generation method described above, and will not be repeated here.

[0179] This application also provides an electronic device, including: At least one memory; At least one processor; At least one program; The program is stored in a memory, and the processor executes the at least one program to implement the threat intelligence data generation method described above. The electronic device can be any smart terminal, including mobile phones, tablets, personal digital assistants (PDAs), and in-vehicle computers.

[0180] Please see Figure 13 , Figure 13 The hardware structure of an electronic device according to another embodiment is illustrated. The electronic device includes: The processor 1301 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this application. The memory 1302 can be implemented in the form of ROM (Read-Only Memory), static storage device, dynamic storage device, or RAM (Random Access Memory). The memory 1302 can store the operating system and other applications. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 1302, and the processor 1301 calls and executes the threat intelligence data generation method of the embodiments of this application. The input / output interface 1303 is used to implement information input and output; The communication interface 1304 is used to enable communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.). Bus 1305 transmits information between various components of the device (e.g., processor 1301, memory 1302, input / output interface 1303, and communication interface 1304); The processor 1301, memory 1302, input / output interface 1303 and communication interface 1304 are connected to each other within the device via bus 1305.

[0181] This application embodiment also provides a storage medium, which is a computer-readable storage medium, storing a computer program that, when executed by a processor, implements the above-described method for generating threat intelligence data.

[0182] Memory, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs and non-transitory computer-executable programs. Furthermore, memory may include high-speed random access memory, and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, memory may optionally include memory remotely located relative to the processor, and these remote memories can be connected to the processor via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.

[0183] The embodiments described in this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided by the embodiments of this application. As those skilled in the art will know, with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of this application are also applicable to similar technical problems.

[0184] Those skilled in the art will understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of this application, and may include more or fewer steps than shown, or combine certain steps, or different steps.

[0185] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.

[0186] Those skilled in the art will understand that all or some of the steps in the methods disclosed above, as well as the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, or suitable combinations thereof.

[0187] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0188] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.

[0189] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of the units described above is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. The coupling or direct coupling or communication connection between the shown or discussed units may be through some interfaces, or indirect coupling or communication connection between the apparatus or units, and may be electrical, mechanical, or other forms.

[0190] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0191] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0192] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes multiple instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing programs, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0193] The preferred embodiments of the present application have been described above with reference to the accompanying drawings, but this does not limit the scope of the claims of the present application. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and substance of the embodiments of the present application shall be within the scope of the claims of the present application.

Claims

1. A method for generating threat intelligence data, characterized in that, The method includes: Acquire multi-source heterogeneous alarm data and external multi-source intelligence data; Based on the multi-source heterogeneous alarm data, feature analysis is performed to obtain the attack capability score of the attacking end and the comprehensive risk score of the target side, and enhanced intelligence data is obtained based on the attack capability score and the comprehensive risk score. Based on the enhanced intelligence data, the external multi-source intelligence data is matched and retrieved to obtain the matching degree, and the update credibility weight of each external intelligence source in the external multi-source intelligence data is obtained based on the matching degree. Based on the updated credibility weights, the external multi-source intelligence data is weighted and fused to generate an external comprehensive threat score. Based on the enhanced intelligence data and the external comprehensive threat score, target threat intelligence data is obtained.

2. The method for generating threat intelligence data according to claim 1, characterized in that, The feature analysis based on the multi-source heterogeneous alarm data yields an attack capability score for the attacking end and a comprehensive risk score for the target side, including: Based on a pre-defined adversarial tactical framework, the attack behavior data in the multi-source heterogeneous alarm data is analyzed to obtain the attack tactical stages and attack tools. Determine the number of tools in the attack tool and the number of stages in the attack tactical phase; Based on the number of tools and the number of stages, the attack capability score of the attacking terminal is calculated; The system acquires internal asset information data and, based on the victim target identifier in the multi-source heterogeneous alarm data and the internal asset information data, obtains the comprehensive risk score for the target side.

3. The method for generating threat intelligence data according to claim 2, characterized in that, The comprehensive risk score obtained from the victim target identifier in the multi-source heterogeneous alarm data and the internal asset information data includes: Based on the victim target identifier, a query is performed in the internal asset information data to obtain the vulnerability status information, network topology location information, and business attribute information of the target side; A basic risk score is calculated based on the vulnerability status information. Calculate the exposure risk score based on the network topology location information; The criticality level and data sensitivity level of the business system corresponding to the target side contained in the business attribute information are determined, and the impact risk score is calculated based on the criticality level and the sensitivity level. The comprehensive risk score of the target side is obtained by weighted summation of the basic risk score, the exposure risk score, and the impact risk score.

4. The method for generating threat intelligence data according to claim 1, characterized in that, The process of matching and retrieving the external multi-source intelligence data based on the enhanced intelligence data to obtain the matching degree includes: The attack source IP address and attack type are determined from the enhanced intelligence data; Based on the IP address of the attack source, a search is performed in the external multi-source intelligence data to obtain the corresponding external judgment record; The matching degree is obtained by performing consistency matching between the attack type corresponding to the external judgment record and the attack behavior type.

5. The method for generating threat intelligence data according to claim 1, characterized in that, The step of obtaining the updated credibility weight of each external intelligence source in the external multi-source intelligence data based on the matching degree includes: Obtain the historical rating and preset authority level of each of the aforementioned external intelligence sources; The historical scores are corrected based on the matching degree to obtain a dynamic score; The dynamic score and the authority level are weighted and calculated to obtain the update credibility weight corresponding to each external intelligence source.

6. The method for generating threat intelligence data according to claim 1, characterized in that, The step of weighting and fusing the external multi-source intelligence data based on the updated credibility weights to generate an external comprehensive threat score includes: The threat confidence score corresponding to each of the external intelligence sources is multiplied by the corresponding update confidence weight to obtain a weighted score; The weighted scores of all external intelligence sources are summed to obtain the comprehensive external threat score.

7. The method for generating threat intelligence data according to claim 1, characterized in that, The acquisition of multi-source heterogeneous alarm data includes: Acquire initial multi-source heterogeneous alarm data, and extract feature information from the initial multi-source heterogeneous alarm data; Based on the aforementioned feature information, similarity aggregation is performed to obtain multiple composite security events; Based on the victim target identifier in each of the composite security events, a query is performed in the internal asset information data to obtain the asset criticality score corresponding to each of the composite security events; A comprehensive evaluation is conducted based on the attack severity level corresponding to the attack characteristics of the composite security incident, the asset criticality score, and the attack frequency of the composite security incident to obtain a comprehensive evaluation score for each composite security incident. The composite security events whose comprehensive evaluation score exceeds the preset evaluation score are selected from the multiple composite security events and used as the multi-source heterogeneous alarm data.

8. The method for generating threat intelligence data according to claim 1, characterized in that, The method further includes: Analyze the target threat intelligence data to extract target-side features and attack source features; Identify groups of similar risky assets within the internal network that have configurations similar to the target side characteristics; Generate blocking strategies targeting the attack source characteristics, and generate preventative protection strategies targeting the similar risk asset groups; The blocking strategy and the preventative protection strategy are sent to the network security devices associated with the similar risk asset group.

9. A threat intelligence data generation device, characterized in that, The device includes: The acquisition module is used to acquire multi-source heterogeneous alarm data and external multi-source intelligence data; The feature analysis module is used to perform feature analysis based on the multi-source heterogeneous alarm data to obtain the attack capability score of the attacking end and the comprehensive risk score of the target side, and to obtain enhanced intelligence data based on the attack capability score and the comprehensive risk score. The matching credibility calculation module is used to perform matching retrieval on the external multi-source intelligence data based on the enhanced intelligence data, obtain the matching degree, and obtain the updated credibility weight of each external intelligence source in the external multi-source intelligence data based on the matching degree. An external scoring module is used to perform weighted fusion of the external multi-source intelligence data based on the updated credibility weights to generate an external comprehensive threat score. The target data generation module is used to obtain target threat intelligence data based on the enhanced intelligence data and the external comprehensive threat score.

10. An electronic device, characterized in that, The device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the method for generating threat intelligence data according to any one of claims 1 to 8.

11. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method for generating threat intelligence data according to any one of claims 1 to 8.