Threat intelligence based trustworthiness updating method and device and electronic device
By assessing the credibility of threat intelligence from multiple dimensions and dynamically updating its aging time, the problem of not being able to determine changes in the credibility of threat intelligence in existing technologies is solved, thereby improving the responsiveness of security vendors and the accuracy of threat intelligence.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- HILLSTONE NETWORKS CO LTD
- Filing Date
- 2023-02-17
- Publication Date
- 2026-04-28
AI Technical Summary
Existing technologies cannot effectively determine how the credibility of threat intelligence changes under the influence of multiple dimensions, making it difficult for security vendors to update and age threat intelligence in a timely manner.
By acquiring the intelligence types and information of target threat intelligence, the credibility intelligence weight value of each preset dimension is determined, the initial credibility score is calculated, and aging processing is carried out when the credibility score is lower than the threshold. This includes considering the influence of multiple dimensions such as compromise indicators, geographical location, tag type, intelligence source and threat information.
It enables dynamic updates to the credibility of threat intelligence based on multiple dimensions, timely aging processing, and improves the accuracy of threat intelligence and the responsiveness of security vendors.
Smart Images

Figure CN116170202B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of cybersecurity, and more specifically, to a trust update method, apparatus, and electronic device based on threat intelligence. Background Technology
[0002] With the rapid development of attack tools and the decreasing cost of attacks, cybersecurity incidents are occurring frequently, requiring security vendors to respond promptly and accurately. This places high demands on both the quantity and quality of security vendor intelligence. Threat intelligence is evidence-based knowledge, including context, mechanisms, indicators, meanings, and actionable recommendations. This knowledge relates to existing or emerging threats or harms facing assets and can provide information support for the asset-related parties' decision-making regarding response to or handling of threats or harms. The main content of threat intelligence, as described by security vendors, consists of Indicators of Compromise (IOCs) used to identify and detect threats, such as file hashes, IP addresses, domains, URLs (Uniform Resource Locator), and related attribution tags.
[0003] Currently, threat intelligence from security vendors can be categorized into three main types based on their source: in-house generated intelligence, commercial intelligence, and third-party open-source intelligence. In-house generated intelligence primarily originates from vendors' sandbox testing, rule filtering, and security personnel analysis. Due to its clear evidentiary information, this type of intelligence has the highest credibility compared to the other two. Commercial intelligence mainly comes from threat intelligence vendors, and due to the authority of these vendors, its intelligence also possesses high credibility. Third-party open-source intelligence primarily comes from various open-source projects, and comparatively, it has the lowest credibility.
[0004] Typically, Indicators of Compromise (IOCs) age rapidly shortly after an attack, their trustworthiness decreasing quickly. However, due to information lag, security vendors find it difficult to age IOCs synchronously, often retaining the threat as malicious for a period. This aging time is usually a fixed threshold; only after reaching this threshold is the IOC's maliciousness level set to unknown.
[0005] Among related technologies, a dynamic evaluation method and system for the comprehensive quality of network threat intelligence is proposed, including the following steps: Step 1, defining network threat intelligence in a structured manner; Step 2, intelligence source quality evaluation: using an iterative algorithm for intelligence source quality evaluation to evaluate the content authority and link authority of the intelligence source; Step 3, intelligence content quality evaluation: for two pieces of intelligence with the same IP value or the same domain name, calculating their similarity based on four features: intelligence source, timestamp, threat category, and description tag; Step 4, comprehensive dynamic evaluation of intelligence quality.
[0006] However, the above-mentioned technical solutions, which calculate the similarity of structured threat intelligence, are mainly aimed at third-party open-source intelligence, and cannot determine how the credibility of threat intelligence changes over time under the influence of multiple dimensions.
[0007] There is currently no effective solution to the above problems. Summary of the Invention
[0008] This invention provides a method, apparatus, and electronic device for updating credibility based on threat intelligence, to at least solve the technical problem in related technologies that cannot determine the changes in the credibility of threat intelligence under the influence of multiple dimensions.
[0009] According to one aspect of the present invention, a trustworthiness update method based on threat intelligence is provided, comprising: acquiring the intelligence type and intelligence information of target threat intelligence, wherein the target threat intelligence refers to threat intelligence whose intelligence status has been determined to be malicious; determining an intelligence weight value for the trustworthiness of the target threat intelligence for each preset dimension based on the intelligence information; determining an initial trustworthiness score of the target threat intelligence based on the intelligence type and all the intelligence weight values; updating the target trustworthiness score of the target threat intelligence based on the initial trustworthiness score; and aging the target threat intelligence if the target trustworthiness score is less than a preset trustworthiness threshold, wherein the aging process is used to clear the intelligence status of the target threat intelligence.
[0010] Optionally, the step of determining the intelligence weight value of each preset dimension for the credibility of the target threat intelligence based on the intelligence information includes: when the preset dimension is a first dimension, determining the protocol information about the compromise indicator carried by the intelligence information, wherein the compromise indicator is text used by the target threat intelligence to record malicious attacks, and the protocol information includes at least: the deadline of the compromise indicator and the geographical location of the compromise indicator; determining the deadline weight value based on a first influence parameter, the deadline, and the current time, wherein the deadline weight value is the intelligence weight value related to the deadline under the first dimension; and determining the geographical location weight value based on a second influence parameter and the geographical location, wherein the geographical location weight value is the intelligence weight value related to the geographical location under the first dimension.
[0011] Optionally, the step of determining the intelligence weight value of each preset dimension for the credibility of the target threat intelligence based on the intelligence information further includes: when the preset dimension is a second dimension, determining the tag information carried by the intelligence information, wherein the tag information includes: the tag type of the target threat intelligence and the danger level of the tag corresponding to the tag type, the tag type including: malicious tag, public service tag; determining the tag sub-weight value corresponding to all tags in the target threat intelligence based on the tag information, wherein the tag sub-weight value is determined according to the tag type corresponding to the tag and the danger level; determining the tag weight value based on all the tag sub-weight values and a third influence parameter, wherein the tag weight value is the intelligence weight value related to the second dimension.
[0012] Optionally, the step of determining the intelligence weight value of each preset dimension for the credibility of the target threat intelligence based on the intelligence information further includes: when the preset dimension is a third dimension, determining the intelligence source information carried by the intelligence information, wherein the intelligence source information includes: intelligence source type; determining the intelligence source sub-weight value corresponding to all intelligence sources in the target threat intelligence based on the intelligence source information, wherein the intelligence source sub-weight value is determined according to the intelligence source type corresponding to the intelligence source; determining the intelligence source weight value based on all the intelligence source sub-weight values and a fourth influence parameter, wherein the intelligence source weight value is the intelligence weight value related to the third dimension.
[0013] Optionally, the step of determining the intelligence weight value of each preset dimension for the credibility of the target threat intelligence based on the intelligence information further includes: when the preset dimension is the fourth dimension, determining the amount of threat information carried by the intelligence information, wherein the threat information is the threat record captured by the target threat intelligence; and determining the threat information weight value based on the amount of information and a fifth influence parameter, wherein the threat information weight value is the intelligence weight value related to the fourth dimension.
[0014] Optionally, the step of determining the initial credibility score of the target threat intelligence based on the intelligence type and all the intelligence weight values includes: determining the influence weight value corresponding to each preset dimension; determining the initial value of the target threat intelligence based on the intelligence type; and determining the initial credibility score of the target threat intelligence based on the initial value, the intelligence weight values of all the preset dimensions, and the influence weight values corresponding to the preset dimensions.
[0015] Optionally, the step of updating the target credibility score of the target threat intelligence based on the initial credibility score includes: determining the entry time of the target threat intelligence into the database based on the intelligence information; determining a first credibility score of the target threat intelligence at the current time based on the initial credibility score, the entry time, and a preset decay parameter when the target threat intelligence is not queried; determining a second credibility score of the target threat intelligence at the current time based on the first credibility score, the entry time, and supplementary parameters when the target threat intelligence is queried and the first credibility score is less than or equal to the preset credibility threshold; determining the time when the first credibility score reaches the preset credibility threshold and the query time when the target threat intelligence is queried, and determining a third credibility score of the target threat intelligence at the current time based on the first credibility score, the entry time, the supplementary parameters, the arrival time, and the query time.
[0016] Optionally, when the target threat intelligence updates the intelligence information, the intelligence weight value of the target threat intelligence on each of the preset dimensions is updated based on the updated intelligence information; and the target credibility score of the target threat intelligence is updated based on the updated intelligence weight value.
[0017] According to another aspect of the present invention, a trustworthiness update apparatus based on threat intelligence is also provided, comprising: an acquisition unit, configured to acquire the intelligence type and intelligence information of target threat intelligence, wherein the target threat intelligence refers to threat intelligence whose intelligence status has been determined to be malicious; a first determination unit, configured to determine an intelligence weight value for the trustworthiness of the target threat intelligence for each preset dimension based on the intelligence information; a second determination unit, configured to determine an initial trustworthiness score of the target threat intelligence based on the intelligence type and all the intelligence weight values; and an update unit, configured to update the target trustworthiness score of the target threat intelligence based on the initial trustworthiness score, and to perform aging processing on the target threat intelligence when the target trustworthiness score is less than a preset trustworthiness threshold, wherein the aging processing is used to clear the intelligence status of the target threat intelligence.
[0018] Optionally, the first determining unit includes: a first determining module, configured to determine, when the preset dimension is the first dimension, protocol information regarding the compromise indicator carried by the intelligence information, wherein the compromise indicator is text used by the target threat intelligence to record malicious attacks, and the protocol information includes at least: the deadline of the compromise indicator and the geographical location of the compromise indicator; a second determining module, configured to determine a deadline weight value based on a first influence parameter, the deadline, and the current time, wherein the deadline weight value is the intelligence weight value related to the deadline under the first dimension; and a third determining module, configured to determine a geographical location weight value based on a second influence parameter and the geographical location, wherein the geographical location weight value is the intelligence weight value related to the geographical location under the first dimension.
[0019] Optionally, the first determining unit further includes: a fourth determining module, configured to determine the tag information carried by the intelligence information when the preset dimension is the second dimension, wherein the tag information includes: the tag type of the target threat intelligence and the danger level of the tag corresponding to the tag type, the tag type including: malicious tag, public service tag; a fifth determining module, configured to determine the tag sub-weight value corresponding to all tags in the target threat intelligence based on the tag information, wherein the tag sub-weight value is determined according to the tag type corresponding to the tag and the danger level; a sixth determining module, configured to determine the tag weight value based on all the tag sub-weight values and a third influence parameter, wherein the tag weight value is the intelligence weight value related to the second dimension.
[0020] Optionally, the first determining unit further includes: a seventh determining module, configured to determine the intelligence source information carried by the intelligence information when the preset dimension is the third dimension, wherein the intelligence source information includes: intelligence source type; an eighth determining module, configured to determine the intelligence source sub-weight value corresponding to all intelligence sources in the target threat intelligence based on the intelligence source information, wherein the intelligence source sub-weight value is determined according to the intelligence source type corresponding to the intelligence source; and a ninth determining module, configured to determine the intelligence source weight value based on all the intelligence source sub-weight values and the fourth influence parameter, wherein the intelligence source weight value is the intelligence weight value related to the third dimension.
[0021] Optionally, the first determining unit further includes: a tenth determining module, configured to determine the number of threat information carried by the intelligence information when the preset dimension is the fourth dimension, wherein the threat information is a threat record captured by the target threat intelligence; and an eleventh determining module, configured to determine a threat information weight value based on the number of information and a fifth influence parameter, wherein the threat information weight value is the intelligence weight value related to the fourth dimension.
[0022] Optionally, the second determining unit includes: a twelfth determining module, used to determine the influence weight value corresponding to each of the preset dimensions; a thirteenth determining module, used to determine the initial value of the target threat intelligence based on the intelligence type; and a fourteenth determining module, used to determine the initial credibility score of the target threat intelligence based on the initial value, the intelligence weight values of all the preset dimensions, and the influence weight values corresponding to the preset dimensions.
[0023] Optionally, the updating unit includes: a fifteenth determining module, configured to determine the entry time of the target threat intelligence based on the intelligence information; a sixteenth determining module, configured to determine a first credibility score of the target threat intelligence at the current time based on the initial credibility score, the entry time, and a preset decay parameter when the target threat intelligence is not queried; a seventeenth determining module, configured to determine a second credibility score of the target threat intelligence at the current time based on the first credibility score, the entry time, and supplementary parameters when the target threat intelligence is queried and the first credibility score is greater than the preset credibility threshold; and an eighteenth determining module, configured to determine the arrival time when the first credibility score reaches the preset credibility threshold and the query time when the target threat intelligence is queried, and to determine a third credibility score of the target threat intelligence at the current time based on the first credibility score, the entry time, the supplementary parameters, the arrival time, and the query time when the target threat intelligence is queried.
[0024] Optionally, the credibility update device further includes: a first update module, configured to update the intelligence weight value of the target threat intelligence on each of the preset dimensions based on the updated intelligence information when the target threat intelligence updates the intelligence information; and a second update module, configured to update the target credibility score of the target threat intelligence based on the updated intelligence weight value.
[0025] According to another aspect of the present invention, an electronic device is also provided, including one or more processors and a memory, the memory being used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors cause the one or more processors to implement the above-described threat intelligence-based trust update method.
[0026] This disclosure involves acquiring the intelligence type and information of a target threat intelligence, determining the intelligence weight value of each preset dimension on the credibility of the target threat intelligence based on the intelligence information, determining the initial credibility score of the target threat intelligence based on the intelligence type and all intelligence weight values, updating the target credibility score of the target threat intelligence based on the initial credibility score, and aging the target threat intelligence if the target credibility score is less than a preset credibility threshold. In this disclosure, the intelligence weight value affecting the credibility of the target threat intelligence for each preset dimension can be determined first. Then, based on the intelligence type and all intelligence weight values of the target threat intelligence, the initial credibility score of the target threat intelligence is determined. The target credibility score of the target threat intelligence is then updated based on the initial credibility score. If the target credibility score is less than the preset credibility threshold, the intelligence status of the target threat intelligence needs to be cleared, and the target threat intelligence is aged in a timely manner. This allows for dynamic updating of the credibility of threat intelligence based on the different weights of multiple dimensions on credibility, achieving the function of timely updating the aging time of threat intelligence, thereby solving the technical problem in related technologies where it is impossible to determine the changes in the credibility of threat intelligence under the influence of multiple dimensions. Attached Figure Description
[0027] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this application, illustrate exemplary embodiments of the invention and, together with their description, serve to explain the invention and do not constitute an undue limitation thereof. In the drawings:
[0028] Figure 1 This is a flowchart of an optional trust update method based on threat intelligence according to an embodiment of the present invention;
[0029] Figure 2 This is a schematic diagram of an optional dynamic assessment process for threat intelligence credibility according to an embodiment of the present invention;
[0030] Figure 3 This is a schematic diagram of an optional trust update device based on threat intelligence according to an embodiment of the present invention;
[0031] Figure 4 This is a hardware structure block diagram of an electronic device (or mobile device) for a trust update method based on threat intelligence according to an embodiment of the present invention. Detailed Implementation
[0032] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0033] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0034] To facilitate understanding of the present invention by those skilled in the art, some terms or nouns involved in the various embodiments of the present invention are explained below:
[0035] Whois is a transmission protocol used to query information such as the IP address and owner of a domain name. It is also a database used to query whether a domain name has been registered and to obtain detailed information about the registered domain name (such as the domain owner and domain registrar).
[0036] It should be noted that the relevant information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this disclosure are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of the relevant data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation portals are provided for users to choose to authorize or refuse.
[0037] This invention addresses the Indicators of Compromise (IOCs) in threat intelligence databases of security vendors. It fully considers relevant information of IOCs and constructs a dynamic aging mechanism for IOC credibility. It proposes a method for dynamically evaluating the credibility of threat intelligence. After a threat intelligence is determined to be malicious, it comprehensively considers dimensions such as threat intelligence type, tags, and Whois information, models the time series, and dynamically calculates the change in the credibility of the threat intelligence's IOC over time. This addresses the issue of credibility changes of different IOCs over time under multiple factors, and can determine how the credibility of IOCs changes over time under the influence of multiple dimensions, thus helping security vendors to more rationally set the aging time for threat intelligence.
[0038] The present invention will now be described in detail with reference to various embodiments.
[0039] Example 1
[0040] According to an embodiment of the present invention, an embodiment of a trust update method based on threat intelligence is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0041] Figure 1 This is a flowchart of an optional trust update method based on threat intelligence according to an embodiment of the present invention, such as... Figure 1 As shown, the method includes the following steps:
[0042] Step S101: Obtain the intelligence type and intelligence information of the target threat intelligence, wherein the target threat intelligence refers to the threat intelligence whose intelligence status has been determined to be malicious.
[0043] Step S102: Based on the intelligence information, determine the intelligence weight value of each preset dimension for the credibility of the target threat intelligence.
[0044] Step S103: Determine the initial credibility score of the target threat intelligence based on the intelligence type and all intelligence weight values.
[0045] Step S104: Based on the initial credibility score, update the target credibility score of the target threat intelligence, and if the target credibility score is less than the preset credibility threshold, perform aging processing on the target threat intelligence, wherein the aging processing is used to clear the intelligence status of the target threat intelligence.
[0046] Through the above steps, the intelligence type and information of the target threat intelligence can be obtained. Based on the intelligence information, the intelligence weight value of each preset dimension on the credibility of the target threat intelligence is determined. Based on the intelligence type and all intelligence weight values, the initial credibility score of the target threat intelligence is determined. Based on the initial credibility score, the target credibility score of the target threat intelligence is updated. If the target credibility score is less than the preset credibility threshold, the target threat intelligence is aged out. In this embodiment of the invention, the intelligence weight value of each preset dimension affecting the credibility of the target threat intelligence can be determined first. Then, based on the intelligence type and all intelligence weight values of the target threat intelligence, the initial credibility score of the target threat intelligence is determined. Then, the target credibility score of the target threat intelligence is updated based on the initial credibility score. If the target credibility score is less than the preset credibility threshold, the intelligence status of the target threat intelligence needs to be cleared, and the target threat intelligence is aged out in a timely manner. This allows for dynamic updates to the credibility of threat intelligence based on the different weights of multiple dimensions on credibility, thereby achieving the function of timely updating the aging time of threat intelligence. This solves the technical problem in related technologies where it is impossible to determine the changes in the credibility of threat intelligence under the influence of multiple dimensions.
[0047] The embodiments of the present invention will now be described in detail with reference to the steps described above.
[0048] Step S101: Obtain the intelligence type and intelligence information of the target threat intelligence, wherein the target threat intelligence refers to the threat intelligence whose intelligence status has been determined to be malicious.
[0049] In this embodiment of the invention, the intelligence type and information of the target threat intelligence can be obtained first. Target threat intelligence refers to threat intelligence whose intelligence status has been determined to be malicious (i.e., threat intelligence that has been determined to be malicious), and can be self-produced intelligence, commercial intelligence, or third-party open-source intelligence. The intelligence type can be determined based on the type of compromised indicators in the target threat intelligence, such as file HASH type, IP type, DOMAIN type, URL type, etc. The intelligence information can include: Whois information (i.e., protocol information) about the compromised indicators, tag information, intelligence source information, threat information, etc.
[0050] Step S102: Based on the intelligence information, determine the intelligence weight value of each preset dimension for the credibility of the target threat intelligence.
[0051] In this embodiment of the invention, intelligence weight values (i.e., determining the degree of influence of each preset dimension on the credibility of the target threat intelligence) can be calculated based on intelligence information, such as basic information dimensions (which can be divided into deadline dimension, geographical location dimension, tag dimension, intelligence source dimension, threat information dimension, etc.).
[0052] Optionally, the step of determining the intelligence weight value of each preset dimension for the credibility of the target threat intelligence based on intelligence information includes: when the preset dimension is the first dimension, determining the protocol information about the compromise indicator carried by the intelligence information, wherein the compromise indicator is the text used by the target threat intelligence to record malicious attacks, and the protocol information includes at least: the deadline of the compromise indicator and the geographical location of the compromise indicator; determining the deadline weight value based on the first influence parameter, the deadline, and the current time, wherein the deadline weight value is an intelligence weight value related to the deadline under the first dimension; and determining the geographical location weight value based on the second influence parameter and the geographical location, wherein the geographical location weight value is an intelligence weight value related to the geographical location under the first dimension.
[0053] In this embodiment of the invention, if the preset dimension is the first dimension (i.e., the basic information dimension, which mainly focuses on the geographical location and expiration time of the IOC's Whois information (mainly targeting IP and DOMAIN)), then the protocol information regarding the compromise indicator carried by the intelligence information can be determined first. In this embodiment, the compromise indicator is the text used by the target threat intelligence to record malicious attacks (i.e., the compromise indicator is the main content used by the target threat intelligence to identify and detect threats), and the protocol information includes at least: the expiration time (expire_tine) of the compromise indicator and the geographical location of the compromise indicator. Then, according to the first influence parameter α... et (i.e., the deadline impact factor), the deadline (expire_tine), and the current time (current_time) are used to determine the deadline weight value S. et The deadline weight value is an intelligence weight value related to the deadline in the first dimension. Furthermore, it can be determined based on the second influence parameter α. geo (i.e., geographical location influence factor) and geographical location (e.g., divided into domestic and international), determine the geographical location weight value S. geo The geographic location weight value is an intelligence weight value related to geographic location in the first dimension. The specific calculation process is as follows:
[0054] `expire_time` is the expiration time of the IOC. If the current time is less than the expiration time, it means that the Whois information of the IOC has not expired and is still in a state where relevant information can be obtained through Whois, making it easy to trace. Therefore, the reliability weight of such IOCs can be reduced; conversely, its weight should be increased. Therefore, the reliability weight of `expire_time` information (i.e., expiration time information) is (i.e., the expiration time weight value S). et The formula for calculating ) is:
[0055]
[0056] Where, α et The cutoff time impact factor, and 0 < α et <1.
[0057] Similar to expire_time information, geolocation information is mainly divided into domestic and international categories. Domestically, due to strict regulations and real-name registration, it generally doesn't contain IOCs specifically designed for attack purposes; it's more likely used for malicious testing and experimentation. Therefore, its aging rate is relatively faster compared to international information. Thus, the credibility weight of geolocation information (i.e., the geolocation weight value S) is relatively high. geo The formula for calculating ) is:
[0058]
[0059] Where, α geo The geographical location is the influencing factor, and 0 < α. geo <1.
[0060] Optionally, the step of determining the intelligence weight value of each preset dimension for the credibility of the target threat intelligence based on intelligence information further includes: when the preset dimension is the second dimension, determining the tag information carried by the intelligence information, wherein the tag information includes: the tag type of the target threat intelligence and the danger level of the tag corresponding to the tag type, and the tag type includes: malicious tag and public service tag; based on the tag information, determining the tag sub-weight value corresponding to all tags in the target threat intelligence, wherein the tag sub-weight value is determined according to the tag type and danger level corresponding to the tag; and based on all tag sub-weight values and a third influence parameter, determining the tag weight value, wherein the tag weight value is an intelligence weight value related to the second dimension.
[0061] In this embodiment of the invention, if the preset dimension is the second dimension (i.e., the tag dimension), the tag information carried by the intelligence information can be determined first. In this embodiment, the tag information includes: the tag type of the target threat intelligence and the danger level of the tag corresponding to the tag type. The tag type includes: malicious tags and public service tags. That is, the tags in this embodiment can be divided into two main categories, namely malicious tags and public service tags. For threat intelligence, the tag danger level can be divided into four levels: low, medium, high, and severe. Malicious tags include CnC (Command and Control), Sinkhole, APT (Advanced Persistent Threat) attacks, etc., and the danger level can be medium, high, or severe. For public service tags such as DNS, CDN, etc., the danger level can be low. Then, based on the tag information, the tag sub-weight value ω corresponding to all tags in the target threat intelligence can be determined. iThe sub-weight value of this label is determined based on the label type and hazard level corresponding to the label, and then based on all label sub-weight values and the third influence parameter α. tag (i.e., label influence factor), determine the label weight value S tag The label weight value is an intelligence weight value related to the second dimension, and the specific calculation process is as follows:
[0062] When calculating the impact of tags on trustworthiness, it's necessary to consider whether the IOC's tags are malicious or public. The more malicious tags a IOC has, the higher its trustworthiness. Public service IPs / Domains, if exploited, generally have a shorter effective period; therefore, the more public service tags a IOC has, the lower its trustworthiness, and the impact of public service tags is greater than that of malicious tags. Therefore, a separate malicious weight ω can be set for malicious tags of different risk levels. m A value greater than 0 indicates a higher risk level, resulting in a greater weight and a greater impact on the credibility of the Indicator of Consciousness (IOC). For public service tags, a weight ω is set. c <0, and |ω c |>ω m .
[0063] In this embodiment, the label weight value S tag The calculation formula is:
[0064]
[0065] Where, ω i α is the sub-weight value of the label corresponding to the label. tag The label impact factor is α, and 0 < α. tag <1, where n is the number of tags and i is the tag identifier index.
[0066] Optionally, the step of determining the intelligence weight value of each preset dimension for the credibility of the target threat intelligence based on the intelligence information further includes: when the preset dimension is the third dimension, determining the intelligence source information carried by the intelligence information, wherein the intelligence source information includes: intelligence source type; determining the intelligence source sub-weight value corresponding to all intelligence sources in the target threat intelligence based on the intelligence source information, wherein the intelligence source sub-weight value is determined according to the intelligence source type corresponding to the intelligence source; determining the intelligence source weight value based on all intelligence source sub-weight values and the fourth influence parameter, wherein the intelligence source weight value is the intelligence weight value related to the third dimension.
[0067] In this embodiment of the invention, if the preset dimension is the third dimension (i.e., the intelligence source dimension), the intelligence source information carried by the intelligence information can be determined first (the intelligence source information includes: intelligence source type, such as self-produced source, commercial source, third-party source, etc.). Then, based on the intelligence source information, the intelligence source sub-weight value ω corresponding to all intelligence sources in the target threat intelligence is determined. i The sub-weight value of the intelligence source is determined based on the intelligence source type corresponding to the intelligence source, and then based on the sub-weight values of all intelligence sources and the fourth influence parameter α. source (i.e., intelligence source influence factor), determine the intelligence source weight value S source The intelligence source weight value is an intelligence weight value related to the third dimension, and the specific calculation process is as follows:
[0068] In this embodiment, the credibility of threat intelligence sources, from highest to lowest, is categorized as self-generated, commercial, and third-party sources. Among these, different threat intelligence vendors within the commercial source have varying levels of authority, resulting in different levels of credibility. This embodiment can assume that the credibility of each commercial source has been determined, and different weights are assigned based on their credibility. The formula for calculating the source weight is as follows:
[0069]
[0070] Where, ω i α is the sub-weight value for each intelligence source, set separately for each intelligence source. source The intelligence source influence factor, and 0 < α source <1, where n is the number of intelligence sources and i is the identifier subscript of the intelligence source.
[0071] Optionally, the step of determining the intelligence weight value of each preset dimension for the credibility of the target threat intelligence based on the intelligence information further includes: when the preset dimension is the fourth dimension, determining the amount of threat information carried by the intelligence information, wherein the threat information is the threat record captured by the target threat intelligence; and determining the threat information weight value based on the amount of information and the fifth influence parameter, wherein the threat information weight value is the intelligence weight value related to the fourth dimension.
[0072] In this embodiment of the invention, if the preset dimension is the fourth dimension (i.e., the threat information dimension), the amount of threat information carried by the intelligence information can be determined first. This threat information is the threat record captured by the target threat intelligence. That is, security vendors may record fields such as captured port information and related traffic. The appearance of this field indicates that a clear malicious behavior has been captured, and the amount of captured threat information is proportional to its credibility. Therefore, the amount of information m and the fifth influence parameter α can be used as the basis for determining the quantity of information m. imfo (i.e., threat information impact factor), determine the threat information weight value S infoThe threat information weight value is an intelligence weight value related to the fourth dimension, and the threat information weight value S info The calculation formula is:
[0073] S info =1+α info *n;
[0074] Where n is the number of threat messages, α info The threat information impact factor, and 0 < α info <1.
[0075] Step S103: Determine the initial credibility score of the target threat intelligence based on the intelligence type and all intelligence weight values.
[0076] Optionally, the step of determining the initial credibility score of the target threat intelligence based on the intelligence type and all intelligence weight values includes: determining the influence weight value corresponding to each preset dimension; determining the initial value of the target threat intelligence based on the intelligence type; and determining the initial credibility score of the target threat intelligence based on the initial value, the intelligence weight values of all preset dimensions, and the influence weight values corresponding to the preset dimensions.
[0077] In this embodiment of the invention, the initial credibility score S of the target threat intelligence can be determined based on the intelligence type and all intelligence weight values. init Specifically, the influence weight value ω for each preset dimension can be obtained by using a weighting method. i (Assign influence weights to different preset dimensions based on actual conditions) (i.e., determine the influence weight value corresponding to each preset dimension), and then determine the initial value S of the target threat intelligence based on the intelligence type. type Then, the obtained threat intelligence credibility is combined with intelligence weight values S from multiple preset dimensions. i Calculate the initial credibility score (i.e., determine the initial credibility score of the target threat intelligence based on the initial value, the intelligence weight values of all preset dimensions, and the influence weight values corresponding to the preset dimensions), the initial credibility score S init The calculation formula is:
[0078]
[0079] Among them, S i The influence weight value ω for each preset dimension i S type The initial value corresponds to the intelligence type, n is the number of preset dimensions, and i is the identifier index of the preset dimension.
[0080] Step S104: Based on the initial credibility score, update the target credibility score of the target threat intelligence, and if the target credibility score is less than the preset credibility threshold, perform aging processing on the target threat intelligence, wherein the aging processing is used to clear the intelligence status of the target threat intelligence.
[0081] Optionally, the step of updating the target credibility score of the target threat intelligence based on the initial credibility score includes: determining the entry time of the target threat intelligence into the database based on the intelligence information; if the target threat intelligence has not been queried, determining a first credibility score of the target threat intelligence at the current time based on the initial credibility score, the entry time, and a preset decay parameter; if the target threat intelligence has been queried and the first credibility score is greater than a preset credibility threshold, determining a second credibility score of the target threat intelligence at the current time based on the first credibility score, the entry time, and supplementary parameters; if the target threat intelligence has been queried and the first credibility score is less than or equal to the preset credibility threshold, determining the time when the first credibility score reaches the preset credibility threshold and the query time when the target threat intelligence is queried, and determining a third credibility score of the target threat intelligence at the current time based on the first credibility score, the entry time, the supplementary parameters, the arrival time, and the query time.
[0082] In this embodiment of the invention, based on the law governing the gradual cooling of an object whose temperature is higher than its surroundings as it transfers heat to the surrounding medium (i.e., Newton's law of cooling), the formula can be transformed as follows:
[0083]
[0084] Where H is the ambient temperature. Let T be the initial temperature. t Let t0 be the current temperature of the object, k be the decay coefficient, t0 be the initial time, and t be the current time.
[0085] In this embodiment, H = 0, and by analogy, the formula for threat intelligence credibility decay can be obtained:
[0086]
[0087]
[0088] Where α is the attenuation coefficient, and different values can be set for different types of threat intelligence; S normal This is the decay model when no queries are performed normally; t is the current time; ε is the credibility threshold; β is a supplementary coefficient used to increase credibility after querying the stored information, with a default value of 0; t mean The average timestamp of the time when threat intelligence sources are entered into the database; t ε For S normalThe time it takes to reach the credibility threshold; t lastseen This is the time of the most recent query.
[0089] In this embodiment, the target credibility score of the target threat intelligence can be updated based on the initial credibility score. Specifically, the entry time t of the target threat intelligence into the database can be determined based on the intelligence information. mean (If multiple intelligence sources have different entry times, the average entry time is taken.) If the target threat intelligence is not queried, the first confidence score of the target threat intelligence at the current time t can be determined based on the initial confidence score, entry time, and preset decay parameter α (i.e., if the target threat intelligence is not queried, its first confidence score S can be calculated). normal If the target threat intelligence is queried and the first confidence score is greater than the preset confidence threshold (i.e., S), then... normal If the first confidence score is greater than ε), then the second confidence score S of the target threat intelligence at the current time t can be determined based on the first confidence score, the entry time, and the supplementary parameter β. score If the target threat intelligence is queried and the first confidence score is less than or equal to the preset confidence threshold (i.e., S...), normal If ≤ε), then the time t required for the first confidence score to reach the preset confidence threshold can be determined. ε And the query time t when the target threat intelligence is queried. lastseen (i.e., the time of the most recent query), and based on the first confidence score, the entry time, the supplementary parameters, the arrival time, and the query time, determine the third confidence score S of the target threat intelligence at the current time. score .
[0090] In this embodiment, the credibility of threat intelligence can be calculated and updated periodically. If there is a manual query on that day, it indicates that the IOC of the threat intelligence has a relevant analysis requirement. The next calculation sets a supplementary coefficient β (β>0) based on the intelligence type to increase its credibility score. If information from other intelligence sources is added to the database or updated on that day, the intelligence weight values and initial credibility scores of each dimension need to be recalculated to update the target credibility score of the threat intelligence. After updating the target credibility score of the target threat intelligence, if the target credibility score is less than a preset credibility threshold, it indicates that the target threat intelligence is no longer trustworthy and needs to be aged out. The intelligence status of the target threat intelligence is set to unknown, and its credibility needs to be reassessed (i.e., when the target credibility score is less than the preset credibility threshold, the target threat intelligence is aged out, and this aging out process is used to clear the intelligence status of the target threat intelligence).
[0091] Optionally, when the target threat intelligence is updated, the intelligence weight values of the target threat intelligence in each preset dimension are updated based on the updated intelligence information; and the target credibility score of the target threat intelligence is updated based on the updated intelligence weight values.
[0092] In this embodiment of the invention, if the target threat intelligence updates its intelligence information (for example, by adding information from other intelligence sources to the database or updating the information), it is necessary to update the intelligence weight value of the target threat intelligence in each preset dimension according to the updated intelligence information, and then update the target credibility score of the target threat intelligence according to the updated intelligence weight value.
[0093] Figure 2 This is a schematic diagram of an optional dynamic threat intelligence credibility assessment process according to an embodiment of the present invention, such as... Figure 2 As shown, the initial credibility of threat intelligence can be calculated based on its multi-dimensional information (including intelligence type, tags, Whois information, entry time, source information, and threat information). Then, the credibility is updated according to the credibility change model (for example, after the information is updated, the initial credibility can be recalculated based on the updated multi-dimensional information, or after a third-party query, the credibility can be directly updated according to the credibility change model). Then, it is determined whether the credibility is less than the threshold. If the credibility is less than the threshold, the threat intelligence is invalid; otherwise, it is valid.
[0094] In this embodiment of the invention, by fully considering the relevant information of threat intelligence in the security vendor's intelligence database, the impact of each dimension on the credibility of IOC is calculated separately to construct a dynamic IOC aging model, which can effectively solve the problem of inaccurate static aging evaluation indicators for IOC by security vendors.
[0095] The following is a detailed description with reference to another embodiment.
[0096] Example 2
[0097] The trustworthiness update device based on threat intelligence provided in this embodiment includes multiple implementation units, each of which corresponds to a specific implementation step in Embodiment 1 above.
[0098] Figure 3 This is a schematic diagram of an optional trust update device based on threat intelligence according to an embodiment of the present invention, such as... Figure 3 As shown, the credibility update device may include: an acquisition unit 30, a first determination unit 31, a second determination unit 32, and an update unit 33, wherein...
[0099] The acquisition unit 30 is used to acquire the intelligence type and intelligence information of the target threat intelligence, wherein the target threat intelligence refers to the threat intelligence whose intelligence status has been determined to be malicious.
[0100] The first determining unit 31 is used to determine the intelligence weight value of the credibility of the target threat intelligence for each preset dimension based on intelligence information.
[0101] The second determining unit 32 is used to determine the initial credibility score of the target threat intelligence based on the intelligence type and all intelligence weight values.
[0102] The update unit 33 is used to update the target credibility score of the target threat intelligence based on the initial credibility score, and to age the target threat intelligence if the target credibility score is less than the preset credibility threshold. The aging process is used to clear the intelligence status of the target threat intelligence.
[0103] The aforementioned credibility update device can acquire the intelligence type and intelligence information of the target threat intelligence through the acquisition unit 30, determine the intelligence weight value of each preset dimension to the credibility of the target threat intelligence based on the intelligence information through the first determination unit 31, determine the initial credibility score of the target threat intelligence based on the intelligence type and all intelligence weight values through the second determination unit 32, update the target credibility score of the target threat intelligence based on the initial credibility score through the update unit 33, and perform aging processing on the target threat intelligence if the target credibility score is less than the preset credibility threshold. In this embodiment of the invention, the intelligence weight value that affects the credibility of the target threat intelligence for each preset dimension can be determined first. Then, based on the intelligence type of the target threat intelligence and all intelligence weight values, the initial credibility score of the target threat intelligence is determined. The target credibility score of the target threat intelligence is then updated based on the initial credibility score. If the target credibility score is less than the preset credibility threshold, the intelligence status of the target threat intelligence needs to be cleared, and the target threat intelligence needs to be aged in a timely manner. This allows for dynamic updating of the credibility of threat intelligence based on the different weights of multiple dimensions affecting credibility, thereby achieving the function of timely updating the aging time of threat intelligence. This solves the technical problem in related technologies where it is impossible to determine the changes in the credibility of threat intelligence under the influence of multiple dimensions.
[0104] Optionally, the first determining unit includes: a first determining module, configured to determine the protocol information regarding the compromise indicator carried by the intelligence information when the preset dimension is the first dimension, wherein the compromise indicator is text used by the target threat intelligence to record malicious attacks, and the protocol information includes at least: the deadline of the compromise indicator and the geographical location of the compromise indicator; a second determining module, configured to determine the deadline weight value based on the first influence parameter, the deadline, and the current time, wherein the deadline weight value is an intelligence weight value related to the deadline under the first dimension; and a third determining module, configured to determine the geographical location weight value based on the second influence parameter and the geographical location, wherein the geographical location weight value is an intelligence weight value related to the geographical location under the first dimension.
[0105] Optionally, the first determining unit further includes: a fourth determining module, used to determine the tag information carried by the intelligence information when the preset dimension is the second dimension, wherein the tag information includes: the tag type of the target threat intelligence and the danger level of the tag corresponding to the tag type, and the tag type includes: malicious tag and public service tag; a fifth determining module, used to determine the tag sub-weight value corresponding to all tags in the target threat intelligence based on the tag information, wherein the tag sub-weight value is determined according to the tag type and danger level corresponding to the tag; and a sixth determining module, used to determine the tag weight value based on all tag sub-weight values and the third influence parameter, wherein the tag weight value is the intelligence weight value related to the second dimension.
[0106] Optionally, the first determining unit further includes: a seventh determining module, used to determine the intelligence source information carried by the intelligence information when the preset dimension is the third dimension, wherein the intelligence source information includes: intelligence source type; an eighth determining module, used to determine the intelligence source sub-weight values corresponding to all intelligence sources in the target threat intelligence based on the intelligence source information, wherein the intelligence source sub-weight values are determined according to the intelligence source type corresponding to the intelligence source; and a ninth determining module, used to determine the intelligence source weight value based on all intelligence source sub-weight values and the fourth influence parameter, wherein the intelligence source weight value is an intelligence weight value related to the third dimension.
[0107] Optionally, the first determining unit further includes: a tenth determining module, used to determine the amount of threat information carried by the intelligence information when the preset dimension is the fourth dimension, wherein the threat information is the threat record captured by the target threat intelligence; and an eleventh determining module, used to determine the threat information weight value based on the amount of information and the fifth influence parameter, wherein the threat information weight value is the intelligence weight value related to the fourth dimension.
[0108] Optionally, the second determining unit includes: a twelfth determining module, used to determine the influence weight value corresponding to each preset dimension; a thirteenth determining module, used to determine the initial value of the target threat intelligence based on the intelligence type; and a fourteenth determining module, used to determine the initial credibility score of the target threat intelligence based on the initial value, the intelligence weight values of all preset dimensions, and the influence weight values corresponding to the preset dimensions.
[0109] Optionally, the updating unit includes: a fifteenth determining module, used to determine the entry time of the target threat intelligence based on intelligence information; a sixteenth determining module, used to determine the first credibility score of the target threat intelligence at the current time based on the initial credibility score, the entry time, and a preset decay parameter when the target threat intelligence has not been queried; a seventeenth determining module, used to determine the second credibility score of the target threat intelligence at the current time based on the first credibility score, the entry time, and supplementary parameters when the target threat intelligence has been queried and the first credibility score is greater than a preset credibility threshold; and an eighteenth determining module, used to determine the time when the first credibility score reaches the preset credibility threshold and the query time when the target threat intelligence is queried, and to determine the third credibility score of the target threat intelligence at the current time based on the first credibility score, the entry time, supplementary parameters, the arrival time, and the query time when the target threat intelligence has been queried.
[0110] Optionally, the credibility update device further includes: a first update module, used to update the intelligence weight value of the target threat intelligence in each preset dimension based on the updated intelligence information when the target threat intelligence updates the intelligence information; and a second update module, used to update the target credibility score of the target threat intelligence based on the updated intelligence weight value.
[0111] The aforementioned credibility update device may also include a processor and a memory. The aforementioned acquisition unit 30, first determination unit 31, second determination unit 32, update unit 33, etc., are all stored in the memory as program units, and the processor executes the aforementioned program units stored in the memory to realize the corresponding functions.
[0112] The aforementioned processor contains a kernel, which retrieves the corresponding program units from memory. One or more kernels can be configured. By adjusting kernel parameters, the target threat intelligence's target credibility score is updated based on the initial credibility score. If the target credibility score is lower than a preset credibility threshold, the target threat intelligence undergoes an aging process.
[0113] The aforementioned memory may include non-permanent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.
[0114] This application also provides a computer program product, which, when executed on a data processing device, is suitable for executing an initialization program having the following method steps: acquiring the intelligence type and intelligence information of the target threat intelligence; determining the intelligence weight value of each preset dimension for the credibility of the target threat intelligence based on the intelligence information; determining the initial credibility score of the target threat intelligence based on the intelligence type and all intelligence weight values; updating the target credibility score of the target threat intelligence based on the initial credibility score; and aging the target threat intelligence if the target credibility score is less than a preset credibility threshold.
[0115] According to another aspect of the present invention, an electronic device is also provided, including one or more processors and a memory, the memory being used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors cause the one or more processors to implement the above-described threat intelligence-based trust update method.
[0116] Figure 4 This is a hardware structure block diagram of an electronic device (or mobile device) for a trustworthiness update method based on threat intelligence, according to an embodiment of the present invention. Figure 4 As shown, an electronic device may include one or more ( Figure 4 The processor 402 (which may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.) and the memory 404 for storing data may also be included. In addition, it may include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the I / O interface), a network interface, a keyboard, a power supply, and / or a camera. Those skilled in the art will understand that... Figure 4 The structure shown is for illustrative purposes only and does not limit the structure of the electronic device described above. For example, the electronic device may also include components that are more... Figure 4 The more or fewer components shown, or having the same Figure 4 The different configurations shown.
[0117] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0118] In the above embodiments of the present invention, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0119] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.
[0120] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0121] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0122] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.
[0123] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A credibility update method based on threat intelligence, characterized in that, include: The types of intelligence and information of target threat intelligence are obtained, wherein the target threat intelligence refers to threat intelligence whose intelligence status has been determined to be malicious. Based on the intelligence information, an intelligence weight value is determined for the credibility of the target threat intelligence for each preset dimension, wherein each preset dimension includes at least: basic information dimension, tag dimension, intelligence source dimension, and threat information dimension; Based on the intelligence type and all the intelligence weight values, an initial credibility score for the target threat intelligence is determined; Based on the initial credibility score, the target credibility score of the target threat intelligence is updated, and if the target credibility score is less than a preset credibility threshold, the target threat intelligence is aged out, wherein the aging out process is used to clear the intelligence status of the target threat intelligence; The step of determining the initial credibility score of the target threat intelligence based on the intelligence type and all the intelligence weight values includes: Determine the influence weight value corresponding to each of the preset dimensions; Based on the intelligence type, determine the initial value of the target threat intelligence; Based on the initial value, the intelligence weight values of all the preset dimensions, and the influence weight values corresponding to the preset dimensions, the initial credibility score of the target threat intelligence is determined; The step of updating the target credibility score of the target threat intelligence based on the initial credibility score includes: Based on the intelligence information, determine the time for storing the target threat intelligence; If the target threat intelligence is not queried, a first confidence score of the target threat intelligence at the current time is determined based on the initial confidence score, the entry time, and the preset decay parameter. When the target threat intelligence is queried and the first confidence score is greater than the preset confidence threshold, the second confidence score of the target threat intelligence at the current time is determined based on the first confidence score, the entry time, and supplementary parameters. When the target threat intelligence is queried and the first credibility score is less than or equal to the preset credibility threshold, the time when the first credibility score reaches the preset credibility threshold and the query time when the target threat intelligence is queried are determined. Based on the first credibility score, the entry time, the supplementary parameters, the arrival time, and the query time, the third credibility score of the target threat intelligence at the current time is determined.
2. The credibility update method according to claim 1, characterized in that, The step of determining the intelligence weight value of each preset dimension to the credibility of the target threat intelligence based on the intelligence information includes: When the preset dimension is the first dimension, the protocol information about the compromise indicator carried by the intelligence information is determined, wherein the compromise indicator is the text used by the target threat intelligence to record malicious attacks, and the protocol information includes at least: the expiration time of the compromise indicator and the geographical location of the compromise indicator. Based on the first influence parameter, the deadline, and the current time, a deadline weight value is determined, wherein the deadline weight value is the intelligence weight value related to the deadline under the first dimension; Based on the second influence parameter and the geographic location, a geographic location weight value is determined, wherein the geographic location weight value is the intelligence weight value related to the geographic location under the first dimension.
3. The credibility update method according to claim 1, characterized in that, The step of determining the intelligence weight value of each preset dimension for the credibility of the target threat intelligence based on the intelligence information further includes: When the preset dimension is the second dimension, the tag information carried by the intelligence information is determined, wherein the tag information includes: the tag type of the target threat intelligence and the danger level of the tag corresponding to the tag type, and the tag type includes: malicious tag and public service tag; Based on the tag information, determine the tag sub-weight values corresponding to all tags in the target threat intelligence, wherein the tag sub-weight values are determined according to the tag type corresponding to the tag and the danger level; Based on all the aforementioned tag sub-weight values and the third influence parameter, a tag weight value is determined, wherein the tag weight value is the intelligence weight value related to the second dimension.
4. The credibility update method according to claim 1, characterized in that, The step of determining the intelligence weight value of each preset dimension for the credibility of the target threat intelligence based on the intelligence information further includes: When the preset dimension is the third dimension, the intelligence source information carried by the intelligence information is determined, wherein the intelligence source information includes: intelligence source type; Based on the intelligence source information, determine the intelligence source sub-weight values corresponding to all intelligence sources in the target threat intelligence, wherein the intelligence source sub-weight values are determined according to the intelligence source type corresponding to the intelligence source; Based on all the aforementioned intelligence source sub-weight values and the fourth influence parameter, an intelligence source weight value is determined, wherein the intelligence source weight value is the intelligence weight value related to the third dimension.
5. The credibility update method according to claim 1, characterized in that, The step of determining the intelligence weight value of each preset dimension for the credibility of the target threat intelligence based on the intelligence information further includes: When the preset dimension is the fourth dimension, the amount of threat information carried by the intelligence information is determined, wherein the threat information is the threat record captured by the target threat intelligence; Based on the amount of information and the fifth influence parameter, a threat information weight value is determined, wherein the threat information weight value is the intelligence weight value related to the fourth dimension.
6. The credibility update method according to claim 1, characterized in that, Also includes: When the target threat intelligence updates the intelligence information, the intelligence weight value of the target threat intelligence in each of the preset dimensions is updated based on the updated intelligence information; Based on the updated intelligence weight value, the target credibility score of the target threat intelligence is updated.
7. A trustworthiness update device based on threat intelligence, characterized in that, include: The acquisition unit is used to acquire the intelligence type and intelligence information of the target threat intelligence, wherein the target threat intelligence refers to threat intelligence whose intelligence status has been determined to be malicious. The first determining unit is used to determine the intelligence weight value of each preset dimension to the credibility of the target threat intelligence based on the intelligence information, wherein each preset dimension includes at least: basic information dimension, tag dimension, intelligence source dimension, and threat information dimension; The second determining unit is used to determine the initial credibility score of the target threat intelligence based on the intelligence type and all the intelligence weight values; An update unit is configured to update the target credibility score of the target threat intelligence based on the initial credibility score, and to perform aging processing on the target threat intelligence if the target credibility score is less than a preset credibility threshold, wherein the aging processing is used to clear the intelligence status of the target threat intelligence; The second determining unit includes: a twelfth determining module, used to determine the influence weight value corresponding to each preset dimension; a thirteenth determining module, used to determine the initial value of the target threat intelligence based on the intelligence type; and a fourteenth determining module, used to determine the initial credibility score of the target threat intelligence based on the initial value, the intelligence weight values of all preset dimensions, and the influence weight values corresponding to the preset dimensions. The updating unit includes: a fifteenth determining module, used to determine the entry time of the target threat intelligence based on intelligence information; a sixteenth determining module, used to determine the first credibility score of the target threat intelligence at the current time based on the initial credibility score, the entry time, and a preset decay parameter when the target threat intelligence has not been queried; a seventeenth determining module, used to determine the second credibility score of the target threat intelligence at the current time based on the first credibility score, the entry time, and supplementary parameters when the target threat intelligence has been queried and the first credibility score is greater than a preset credibility threshold; and an eighteenth determining module, used to determine the time when the first credibility score reaches the preset credibility threshold and the query time when the target threat intelligence is queried, and to determine the third credibility score of the target threat intelligence at the current time based on the first credibility score, the entry time, supplementary parameters, the arrival time, and the query time when the target threat intelligence has been queried.
8. An electronic device, characterized in that, It includes one or more processors and a memory, the memory being used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors cause the one or more processors to implement the threat intelligence-based trust update method as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Method and device for discriminating threat information credibility based on multi-dimensional trusted feature
CN108600212A
Dynamic evaluation method and system for comprehensive quality of network threat intelligence
CN115237977A