Internet threat intelligence monitoring method and device and computer readable storage medium

By receiving and analyzing suspicious internet behavior data, and optimizing the internet threat intelligence database using cellular automata and feedback information, the problem of existing technologies being unable to adapt to the upgrading and mutation of internet threats has been solved, enabling timely and accurate threat monitoring.

CN116743478BActive Publication Date: 2026-04-24CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA UNITED NETWORK COMM GRP CO LTD
Filing Date
2023-07-07
Publication Date
2026-04-24

AI Technical Summary

Technical Problem

Existing internet threat intelligence monitoring methods are unable to adapt to the upgrading and mutation of internet threats, resulting in poor monitoring effectiveness.

Method used

By receiving suspicious internet behavior data, extracting multiple behavioral feature data, and using cellular automata to obtain the feature data with the highest probability of association with internet threat behavior data, calculating similarity to determine whether there is threat behavior, and updating the threat intelligence database through feedback information to optimize monitoring effectiveness.

Benefits of technology

It enables timely and accurate monitoring of suspicious online activities, thus preventing losses caused by threatening behavior.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116743478B_ABST
    Figure CN116743478B_ABST
Patent Text Reader

Abstract

The application provides an internet threat intelligence monitoring method and device and a computer readable storage medium, relates to the technical field of network security, and is used for solving the problem that the prior art cannot adapt to the monitoring requirements after the upgrading and variation of internet threats, and the method comprises the following steps: receiving internet threat intelligence monitoring application information from an applicant, wherein the internet threat intelligence monitoring application information comprises internet suspicious behavior data to be analyzed; obtaining a plurality of first behavior feature data of the internet suspicious behavior data to be analyzed, and respectively obtaining a plurality of second behavior feature data with the maximum association probability with the plurality of first behavior feature data in the internet threat behavior data; and obtaining a monitoring result of whether the internet suspicious behavior data to be analyzed corresponds to an existing internet threat behavior according to a first similarity between the plurality of first behavior feature data and the plurality of second behavior feature data. The application can improve the effect of internet threat intelligence monitoring.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to an internet threat intelligence monitoring method, apparatus, and computer-readable storage medium. Background Technology

[0002] With the rapid development of artificial intelligence, current methods for monitoring internet threat intelligence are gradually becoming inadequate to meet the monitoring needs of evolving and mutated internet threats. Therefore, there is an urgent need to improve existing internet threat intelligence monitoring technologies to avoid potential losses from internet threats. Summary of the Invention

[0003] The technical problem to be solved by the present invention is to address the above-mentioned shortcomings of the prior art by providing an Internet threat intelligence monitoring method, device and computer-readable storage medium, so as to solve the problem that the existing Internet threat intelligence monitoring methods are gradually unable to meet the monitoring needs after the Internet threats have upgraded and mutated.

[0004] In a first aspect, the present invention provides an internet threat intelligence monitoring method, the method comprising:

[0005] Receive Internet threat intelligence monitoring requests from applicants, which include suspicious Internet behavior data to be analyzed;

[0006] Obtain multiple first behavioral feature data from the suspicious internet behavior data to be analyzed, and then obtain multiple second behavioral feature data from the internet threat behavior data that have the highest probability of association with the multiple first behavioral feature data.

[0007] Based on the first similarity between multiple first behavioral feature data and multiple second behavioral feature data, the monitoring results are obtained to determine whether the suspected Internet behavior data to be analyzed corresponds to the existence of Internet threat behavior.

[0008] Optionally, multiple first behavioral feature data of the suspicious internet behavior data to be analyzed are obtained, and multiple second behavioral feature data of the internet threat behavior data with the highest probability of association with the multiple first behavioral feature data are obtained respectively, specifically including:

[0009] Obtain first online time characteristic data from the suspicious internet behavior data to be analyzed. And the first use of bandwidth characteristic data ;

[0010] Obtain internet threat behavior data from internet threat intelligence databases;

[0011] Using cellular automata to obtain data on internet threat behaviors The second online time feature data with the highest correlation probability , and with The second most probable association is achieved using bandwidth feature data. .

[0012] Optionally, based on the first similarity between multiple first behavioral feature data and multiple second behavioral feature data, a monitoring result is obtained to determine whether the suspected internet behavior data to be analyzed corresponds to an internet threat behavior, specifically including:

[0013] The first similarity between multiple first-behavioral feature data and multiple second-behavioral feature data is calculated according to formula (1). :

[0014]

[0015] in, for transpose, for transpose, The first adjustment coefficient is i, j, and t, which are three dimensions of storing suspicious internet behavior data and internet threat behavior data in a sparse matrix. m, n, and p are the upper limits of the values ​​of i, j, and t.

[0016] if If the value is less than the first preset threshold, a monitoring result is obtained indicating that the suspected internet behavior data to be analyzed corresponds to a suspected internet threat behavior; otherwise, a monitoring result is obtained indicating that the suspected internet behavior data to be analyzed does not correspond to a suspected internet threat behavior.

[0017] Optionally, after obtaining monitoring results indicating whether the suspicious internet behavior data to be analyzed corresponds to internet threat behavior, the method further includes:

[0018] Send the monitoring results to the applicant and receive feedback from the applicant regarding the accuracy of the monitoring results;

[0019] The internet threat behavior data is updated based on multiple suspicious internet behaviors and corresponding feedback information within a preset historical time period.

[0020] Optionally, the internet threat behavior data can be updated based on multiple suspicious internet behavior data and corresponding feedback information within a preset historical time period, specifically including:

[0021] Based on the corresponding feedback information, determine whether the false alarm rate of the monitoring results of multiple suspicious Internet behavior data within a preset historical time period reaches the second preset threshold.

[0022] If the false alarm rate reaches the second preset threshold, internet threat behavior data is filtered from operator signaling data, and multiple suspicious internet behavior data within a preset historical time period and corresponding feedback information are used to verify the accuracy and coverage of the filtered internet threat behavior data.

[0023] Add the latest internet threat behavior data that meets the preset accuracy and coverage conditions to the internet threat intelligence database.

[0024] Optionally, internet threat behavior data is filtered from operator signaling data, and the accuracy and coverage of the filtered internet threat behavior data are verified using multiple suspicious internet behavior data within a preset historical time period and corresponding feedback information. Specifically, this includes:

[0025] Set the maximum number of iterations and the initial iteration parameters, and execute the following iterative operation starting from the initial number of iterations:

[0026] The internet threat behavior data for this round of iterative calculations is filtered from operator signaling data using a preset model;

[0027] Calculate the second similarity between each suspicious internet behavior data within a preset historical time period and the internet threat behavior data in this round of iteration, and evaluate whether the accuracy and coverage of the internet threat behavior data in this round of iteration meet the preset conditions based on the second similarity and the corresponding feedback information;

[0028] If the accuracy and coverage of the current iteration do not meet the preset conditions, the preset model is adjusted through supervised learning, and the next iteration is executed.

[0029] If the accuracy and coverage of this round of iterations meet the preset conditions, the internet threat behavior data obtained in this round of iterations will be the latest internet threat behavior data and the iteration will end, or the iteration will end when the maximum number of iterations is reached.

[0030] Optionally, the second similarity between each piece of suspicious internet behavior data within a preset historical time period and the internet threat behavior data calculated in this round of iteration includes:

[0031] Get the first within the preset historical time period The third online time characteristic data of suspicious internet behavior data and third-party bandwidth characteristic data ;

[0032] Using cellular automata to obtain the internet threat behavior data in this round of iterative computation and The fourth online time feature data with the highest correlation probability , and with The fourth method with the highest correlation probability uses bandwidth feature data. ;

[0033] Calculate the first using formula (2). The second similarity between the suspicious internet behavior data and the internet threat behavior data in this round of iteration calculations. :

[0034]

[0035] in, , To determine the amount of suspicious internet behavior data within a preset historical timeframe, for transpose, for transpose, is the first adjustment coefficient, i, j, and t are the three dimensions of storing suspicious internet behavior data and internet threat behavior data in a sparse matrix, and m, n, and p are the upper limits of the values ​​of i, j, and t.

[0036] Optionally, the accuracy and coverage of the internet threat behavior data obtained in this round of iterative computation are evaluated based on the second similarity and the corresponding feedback information to determine whether they meet preset conditions, specifically including:

[0037] according to The accuracy of the internet threat behavior data obtained from this round of iterative calculations is obtained from the corresponding feedback information. and coverage ,in, This represents the number of iterations in this round of iterations.

[0038] Evaluate whether the accuracy and coverage of the Internet threat behavior data in this round of iterative calculations satisfy equation (3). If so, the accuracy and coverage of this round of iterative calculations have reached the preset conditions:

[0039]

[0040] in, The mathematical symbol represents the probability meaning, indicating that the result of the expression within the parentheses is a probability value.

[0041] Optionally, if the accuracy and coverage of the current iteration do not meet the preset conditions, the next iteration is executed after adjusting the preset model through supervised learning, specifically including:

[0042] If the accuracy and coverage of the Internet threat behavior data in this round of iteration do not meet equation (3), the preset model is adjusted according to the conditions of equations (4)-(6):

[0043]

[0044]

[0045]

[0046] in, This is the second adjustment factor. , For the first The recursive supervised learning factor in the next iteration. , They are respectively the front The highest coverage and accuracy in the next iteration;

[0047] set up Then, execute the next round of iteration calculations.

[0048] Secondly, the present invention provides an Internet threat intelligence monitoring device, the device comprising:

[0049] The receiving module is used to receive Internet threat intelligence monitoring application information from the applicant, which includes suspicious Internet behavior data to be analyzed.

[0050] The acquisition module, connected to the receiving module, is used to acquire multiple first behavioral feature data of the suspicious Internet behavior data to be analyzed, and to acquire multiple second behavioral feature data of the Internet threat behavior data that have the highest probability of being associated with the multiple first behavioral feature data.

[0051] The monitoring module, connected to the acquisition module, is used to obtain monitoring results on whether the suspected Internet behavior data to be analyzed corresponds to Internet threat behavior based on the first similarity between multiple first behavioral feature data and multiple second behavioral feature data.

[0052] Thirdly, the present invention provides a computer-readable storage medium having a computer program stored thereon, which, when run by a processor, implements the Internet threat intelligence monitoring method as described above.

[0053] This invention provides an internet threat intelligence monitoring method, apparatus, and computer-readable storage medium. It acquires multiple first behavioral feature data from suspicious internet behavior data and then acquires multiple second behavioral feature data from internet threat behavior data that have the highest probability of association with the multiple first behavioral feature data. Based on the first similarity between the multiple first behavioral feature data and the multiple second behavioral feature data, it obtains a monitoring result indicating whether the suspicious internet behavior data corresponds to an internet threat behavior. By extracting feature data and performing data association, the effectiveness of internet threat intelligence monitoring is improved. It can promptly and accurately determine whether the suspicious internet behavior provided by the applicant is an internet threat behavior, thereby providing the applicant with timely and accurate monitoring results and preventing the applicant from suffering losses due to internet threat behaviors. Attached Figure Description

[0054] Figure 1 This is a flowchart of an Internet threat intelligence monitoring method according to an embodiment of the present invention;

[0055] Figure 2 This is a schematic diagram of a scenario for an internet threat intelligence monitoring method according to an embodiment of the present invention;

[0056] Figure 3 This is a schematic diagram of a sparse matrix data storage structure according to an embodiment of the present invention;

[0057] Figure 4 This is a schematic diagram of the structure of an Internet threat intelligence monitoring device according to an embodiment of the present invention. Detailed Implementation

[0058] To enable those skilled in the art to better understand the technical solution of the present invention, the embodiments of the present invention will be further described in detail below with reference to the accompanying drawings.

[0059] It is understood that the specific embodiments and accompanying drawings described herein are merely for explaining the invention and are not intended to limit the invention.

[0060] It is understood that, without conflict, the various embodiments and features in the embodiments of the present invention can be combined with each other.

[0061] It is understood that, for ease of description, only the parts related to the present invention are shown in the accompanying drawings, while the parts unrelated to the present invention are not shown in the drawings.

[0062] It is understood that each unit or module involved in the embodiments of the present invention may correspond to only one entity structure, or may be composed of multiple entity structures, or multiple units or modules may be integrated into one entity structure.

[0063] It is understood that, without conflict, the functions and steps marked in the flowcharts and block diagrams of this invention may occur in a different order than that marked in the accompanying drawings.

[0064] It is understood that the flowcharts and block diagrams of this invention illustrate the possible architecture, functions, and operations of systems, apparatuses, devices, and methods according to various embodiments of the invention. Each block in the flowchart or block diagram may represent a unit, module, program segment, or code, containing executable instructions for implementing the specified function. Furthermore, each block or combination of blocks in the block diagram and flowchart can be implemented using a hardware-based system to achieve the specified function, or using a combination of hardware and computer instructions.

[0065] It is understood that the units and modules involved in the embodiments of the present invention can be implemented by software or by hardware. For example, the units and modules can be located in a processor.

[0066] Example 1:

[0067] like Figure 1 As shown, the present invention provides an Internet threat intelligence monitoring method, the method comprising:

[0068] S01. Receive Internet threat intelligence monitoring application information from the applicant, which includes suspicious Internet behavior data to be analyzed;

[0069] S02. Obtain multiple first behavioral feature data of the suspicious Internet behavior data to be analyzed, and respectively obtain multiple second behavioral feature data of the Internet threat behavior data that have the highest probability of association with the multiple first behavioral feature data.

[0070] S03. Based on the first similarity between multiple first behavioral feature data and multiple second behavioral feature data, obtain the monitoring results of whether the suspected Internet behavior data to be analyzed corresponds to Internet threat behavior.

[0071] Specifically, in this embodiment, one application scenario of the method is as follows: Figure 2As shown, the process includes: Step ① Receiving Internet Threat Intelligence Monitoring Application Information through the Internet Threat Intelligence Monitoring Device. This application information includes suspicious Internet behavior data to be analyzed, submitted by the applicant. For example, a user can submit this application after receiving information about suspicious Internet behavior. The user terminal provides suspicious terminal information related to the suspicious Internet behavior. The operator queries the recent network behavior characteristic data of the corresponding terminal based on the suspicious terminal information as the Internet suspicious behavior data to be analyzed, and submits the Internet Threat Intelligence Monitoring Application Information to the Internet Threat Intelligence Monitoring Device. After receiving the application, the Internet Threat Intelligence Monitoring Device selects multiple first behavioral characteristic data for the Internet suspicious behavior data to be analyzed. Based on the multiple second behavioral characteristic data with the highest probability of association with the multiple first behavioral characteristic data from the collected Internet threat behavior data, the monitoring results of the Internet suspicious behavior data to be analyzed are obtained. For example, if the Internet suspicious behavior uses the same or similar IP address, similar traffic information, online / offline time difference, or bandwidth usage associated with the IP address, it can be determined that the Internet suspicious behavior is likely also an Internet threat behavior. Therefore, the monitoring result corresponding to the Internet suspicious behavior data to be analyzed is given. By extracting feature data from suspicious internet behavior data to be analyzed, and correlating the feature data with corresponding features in internet threat behavior data, the feature analysis of internet threat behavior data can be combined to improve the effectiveness of internet threat intelligence monitoring. This allows for timely and accurate determination of whether the suspicious internet behavior provided by the applicant is an internet threat behavior, thereby providing the applicant with timely and accurate monitoring results and preventing the applicant from suffering losses caused by internet threat behavior.

[0072] Optionally, multiple first behavioral feature data of the suspicious internet behavior data to be analyzed are obtained, and multiple second behavioral feature data of the internet threat behavior data with the highest probability of association with the multiple first behavioral feature data are obtained respectively, specifically including:

[0073] Obtain first online time characteristic data from the suspicious internet behavior data to be analyzed. And the first use of bandwidth characteristic data ;

[0074] Obtain data on internet threat behavior from internet threat intelligence databases;

[0075] Using cellular automata to obtain data on internet threat behaviors The second online time feature data with the highest correlation probability , and with The second most probable association is achieved using bandwidth feature data. .

[0076] Specifically, in this embodiment, the internet threat behavior data is obtained from an internet threat intelligence database. Therefore, after step ①, steps ② and ③ are also included: the internet threat intelligence monitoring device obtains internet threat behavior data from the internet threat intelligence database, and the internet threat intelligence database returns internet threat behavior data to the internet threat intelligence monitoring device. Then, pre-selected features of the two types of data are associated. Specifically, in this embodiment, the pre-selected features include online time features (which can be the time difference between online and offline) and bandwidth usage features (which can be bandwidth usage associated with IP addresses). Data with these two features are extracted from both the suspicious internet behavior data and the internet threat behavior data. The cellular automaton auto-emergence method is used to obtain the feature data with the highest correlation probability from the internet threat behavior data. It is understood that the method for obtaining the feature data with the highest correlation probability from the internet threat behavior data can also employ other technical means, and is not limited to cellular automata.

[0077] Optionally, based on the first similarity between multiple first behavioral feature data and multiple second behavioral feature data, a monitoring result is obtained to determine whether the suspected internet behavior data to be analyzed corresponds to internet threat behavior, specifically including:

[0078] The first similarity between multiple first-behavioral feature data and multiple second-behavioral feature data is calculated according to formula (1). :

[0079]

[0080] in, for transpose, for transpose, The first adjustment coefficient is i, j, and t, which are three dimensions of storing suspicious internet behavior data and internet threat behavior data in a sparse matrix. m, n, and p are the upper limits of the values ​​of i, j, and t.

[0081] if If the value is less than the first preset threshold, then the monitoring result corresponding to the suspected internet behavior data to be analyzed is obtained, indicating that there is an internet threat behavior; otherwise, the monitoring result corresponding to the suspected internet behavior data to be analyzed is obtained, indicating that there is no internet threat behavior.

[0082] Specifically, in this embodiment, the similarity between the corresponding feature data in the suspected internet behavior data and the internet threat behavior data to be analyzed is calculated according to formula (1). The similarity between the two is quantified according to the similarity value. The higher the similarity, the more likely the suspected behavior is an internet threat behavior. Therefore, a threshold can be preset. If the value is less than the threshold, the suspected internet behavior is determined to be an internet threat behavior; otherwise, it is determined to be normal internet behavior. The suspected internet behavior data and the internet threat behavior data are respectively calculated using the following formula: Figure 3 The sparse matrix shown has three dimensions: i, j, and t. m, n, and p are the upper limits of the values ​​of i, j, and t, respectively. Sparse matrices have the advantages of small storage space and fast search speed.

[0083] Optionally, after obtaining monitoring results indicating whether the suspicious internet behavior data to be analyzed corresponds to internet threat behavior, the method further includes:

[0084] Send the monitoring results to the applicant and receive feedback from the applicant regarding the accuracy of the monitoring results;

[0085] The internet threat behavior data is updated based on multiple suspicious internet behaviors and corresponding feedback information within a preset historical time period.

[0086] Specifically, in this embodiment, to further improve the accuracy of monitoring and analyzing suspicious internet behavior data, a step of continuously updating internet threat behavior data is proposed. That is, after obtaining the monitoring results of the requested suspicious internet behavior data, the following steps are performed: Figure 2 Step ④ shows the return of the monitoring results to the applicant, which can be a user or an operator. The applicant can be a user or an operator who collects data from the network. Step ⑤ sends feedback on whether the monitoring results are correct to the Internet threat intelligence monitoring device. The Internet threat intelligence monitoring device summarizes multiple suspicious Internet behavior data and corresponding feedback information received over a period of time (preset historical time length) and uses this as the basis for updating Internet threat behavior data.

[0087] Optionally, the internet threat behavior data can be updated based on multiple suspicious internet behavior data and corresponding feedback information within a preset historical time period, specifically including:

[0088] Based on the corresponding feedback information, determine whether the false alarm rate of the monitoring results of multiple suspicious Internet behavior data within a preset historical time period reaches the second preset threshold.

[0089] If the false alarm rate reaches the second preset threshold, internet threat behavior data is filtered from operator signaling data, and multiple suspicious internet behavior data within a preset historical time period and corresponding feedback information are used to verify the accuracy and coverage of the filtered internet threat behavior data.

[0090] Add the latest internet threat behavior data that meets the preset accuracy and coverage conditions to the internet threat intelligence database.

[0091] Specifically, in this embodiment, the update of internet threat behavior data is initiated when a certain number of false alarms for suspicious internet behavior data are detected within a preset time period. Because a high false alarm rate indicates that the collected internet threat behavior data does not cover the latest internet threat behavior characteristics, it is necessary to increase the coverage of the internet threat behavior data. Specifically, for suspicious internet behavior data within this period of excessive false alarm rate, the following steps can be taken: Figure 2 Step I, as shown, filters new internet threat behavior data from operator signaling data and adds it to the internet threat intelligence database. The newly filtered internet threat behavior data should be able to accurately analyze suspicious internet behavior data during this period. Therefore, the internet threat intelligence monitoring device first executes step ⑥ to check the accuracy and coverage of the filtered data, and then executes step ⑦ to add the latest internet threat behavior data that meets the preset conditions of accuracy and coverage to the internet threat intelligence database. In subsequent monitoring, updated internet threat behavior data can be obtained from the internet threat intelligence database.

[0092] Optionally, internet threat behavior data is filtered from operator signaling data, and the accuracy and coverage of the filtered internet threat behavior data are verified using multiple suspicious internet behavior data within a preset historical time period and corresponding feedback information. Specifically, this includes:

[0093] Set the maximum number of iterations and the initial iteration parameters, and execute the following iterative operation starting from the initial number of iterations:

[0094] The internet threat behavior data for this round of iterative calculations is filtered from operator signaling data using a preset model;

[0095] Calculate the second similarity between each suspicious internet behavior data within a preset historical time period and the internet threat behavior data in this round of iteration, and evaluate whether the accuracy and coverage of the internet threat behavior data in this round of iteration meet the preset conditions based on the second similarity and the corresponding feedback information;

[0096] If the accuracy and coverage of the current iteration do not meet the preset conditions, the preset model is adjusted through supervised learning, and the next iteration is executed.

[0097] If the accuracy and coverage of this round of iterations meet the preset conditions, the internet threat behavior data obtained in this round of iterations will be the latest internet threat behavior data and the iteration will end, or the iteration will end when the maximum number of iterations is reached.

[0098] Specifically, in this embodiment, internet threat behavior data is filtered through iterative calculations. In each round of iterative calculations, the accuracy and coverage of the filtered internet threat behavior data are checked to see if they meet the preset conditions. If they meet the preset conditions, internet threat behavior data with satisfactory accuracy and coverage are filtered out. Otherwise, a supervised learning factor is set to monitor the effect of the next round of iterative calculations in filtering data, and the accuracy and coverage of the filtered data are gradually improved until they meet the preset conditions.

[0099] Optionally, the second similarity between each piece of suspicious internet behavior data within a preset historical time period and the internet threat behavior data calculated in this round of iteration includes:

[0100] Get the first within the preset historical time period The third online time characteristic data of suspicious internet behavior data and third-party bandwidth characteristic data ;

[0101] Using cellular automata to obtain the internet threat behavior data in this round of iterative computation and The fourth online time feature data with the highest correlation probability , and with The fourth method with the highest correlation probability uses bandwidth feature data. ;

[0102] Calculate the first using formula (2). The second similarity between the suspicious internet behavior data and the internet threat behavior data in this round of iteration calculations. :

[0103]

[0104] in, , To determine the amount of suspicious internet behavior data within a preset historical timeframe, for transpose, for transpose, is the first adjustment coefficient, i, j, and t are the three dimensions of storing suspicious internet behavior data and internet threat behavior data in a sparse matrix, and m, n, and p are the upper limits of the values ​​of i, j, and t.

[0105] Optionally, the accuracy and coverage of the internet threat behavior data obtained in this round of iterative computation are evaluated based on the second similarity and the corresponding feedback information to determine whether they meet preset conditions, specifically including:

[0106] according to The accuracy of the internet threat behavior data obtained from this round of iterative calculations is obtained from the corresponding feedback information. and coverage ,in, This represents the number of iterations in this round of iterations.

[0107] Evaluate whether the accuracy and coverage of the Internet threat behavior data in this round of iterative calculations satisfy equation (3). If so, the accuracy and coverage of this round of iterative calculations have reached the preset conditions:

[0108]

[0109] in, The mathematical symbol represents the probability meaning, indicating that the result of the expression within the parentheses is a probability value.

[0110] Optionally, if the accuracy and coverage of the current iteration do not meet the preset conditions, the next iteration is executed after adjusting the preset model through supervised learning, specifically including:

[0111] If the accuracy and coverage of the Internet threat behavior data in this round of iteration do not meet equation (3), the preset model is adjusted according to the conditions of equations (4)-(6):

[0112]

[0113]

[0114]

[0115] in, This is the second adjustment factor. , For the first The recursive supervised learning factor in the next iteration. , They are respectively the front The highest coverage and accuracy in the next iteration;

[0116] set up Then, execute the next round of iteration calculations.

[0117] Specifically, in this embodiment, the calculation formula for the iterative operation includes formulas (2)-(6) as described above. Formula (2) is similar to formula (1), except that the purpose of using formula (2) here is to obtain the accuracy and coverage of the filtered data. An example of the specific calculation process of the iterative operation is as follows: First, set the initial number of iterations to 1. The maximum number of iterations is The existing model is selected to filter Internet threat behavior data from operator signaling data for this round of iteration. Equation (2) is used to perform approximate analysis on the Internet suspicious behavior data and the Internet threat behavior data selected in this round of iteration to obtain the approximation degree between the two. The approximation analysis process is similar to the monitoring analysis process using formula (1). After obtaining the approximation degree, the accuracy and coverage of the model-selected data are further obtained based on the approximation degree. The accuracy can be the proportion of the number of correctly predicted data by the model to the total number of data. The coverage can be the evaluation of the completeness of the test during the test coverage. For example, by judging Whether the value is less than a first preset threshold, the result of identifying suspicious behavior data from the internet threat behavior data filtered by this round of iteration is obtained. Based on this result and the corresponding feedback information, the accuracy of the identification is determined, thereby obtaining the accuracy rate of the internet threat behavior data in this round of iteration. It can be calculated The proximity of suspicious internet behavior data is used to obtain the coverage of internet threat behavior data in this round of iterative calculations. Accuracy and coverage can also be defined and calculated using other methods, as long as they can express the computational effect of each iteration. The accuracy of the current iteration is then obtained. and coverage Then, determine whether the accuracy and coverage of this iteration meet the preset conditions of equation (3). If so, use the data obtained from this iteration as the basis for subsequent Internet threat intelligence monitoring and end the iteration. Otherwise, execute the next iteration. The next iteration monitors and controls the operation effect through equations (4)-(6) to gradually improve the accuracy of each iteration. and coverage Until accuracy and coverage If the requirement is met, and the maximum number of iterations is reached. If the requirements are still not met, the iterative calculation must be terminated. This embodiment obtains highly accurate and comprehensive Internet threat behavior data through deep supervised learning and cellular automata, which helps to improve the timeliness and accuracy of subsequent Internet threat intelligence monitoring.

[0118] Example 2:

[0119] like Figure 4 As shown, Embodiment 2 of the present invention provides an Internet threat intelligence monitoring device, the device comprising:

[0120] The receiving module 01 is used to receive Internet threat intelligence monitoring application information from the applicant, which includes suspicious Internet behavior data to be analyzed.

[0121] The acquisition module 02, connected to the receiving module 01, is used to acquire multiple first behavioral feature data of the suspicious Internet behavior data to be analyzed, and to acquire multiple second behavioral feature data of the Internet threat behavior data that have the highest probability of being associated with the multiple first behavioral feature data.

[0122] The monitoring module 03, connected to the acquisition module 02, is used to obtain the monitoring result of whether the suspected Internet behavior data to be analyzed corresponds to the existence of Internet threat behavior based on the first similarity between multiple first behavioral feature data and multiple second behavioral feature data.

[0123] Optionally, module 02 is acquired, specifically including:

[0124] The first acquisition unit is used to acquire first online time characteristic data from the suspicious internet behavior data to be analyzed. And the first use of bandwidth characteristic data ;

[0125] The second acquisition unit is used to acquire internet threat behavior data from the internet threat intelligence database;

[0126] The third acquisition unit, connected to the first and second acquisition units, is used to acquire data related to internet threat behavior using cellular automata. The second online time feature data with the highest correlation probability , and with The second most probable association is achieved using bandwidth feature data. .

[0127] Optionally, monitoring module 03 specifically includes:

[0128] The similarity calculation unit is used to calculate the first similarity between multiple first-behavioral feature data and multiple second-behavioral feature data according to equation (1). :

[0129]

[0130] in, for transpose, for transpose, The first adjustment coefficient is i, j, and t, which are three dimensions of storing suspicious internet behavior data and internet threat behavior data in a sparse matrix. m, n, and p are the upper limits of the values ​​of i, j, and t.

[0131] The decision unit, connected to the similarity calculation unit, is used to determine if... If the value is less than the first preset threshold, then the monitoring result corresponding to the suspected internet behavior data to be analyzed is obtained, indicating that there is an internet threat behavior; otherwise, the monitoring result corresponding to the suspected internet behavior data to be analyzed is obtained, indicating that there is no internet threat behavior.

[0132] Optionally, the device further includes:

[0133] The feedback module is used to send the monitoring results to the applicant and receive feedback from the applicant regarding the correctness of the monitoring results.

[0134] The update module is used to update internet threat behavior data based on multiple suspicious internet behavior data and corresponding feedback information within a preset historical time period.

[0135] Optionally, the module is updated, specifically including:

[0136] The update trigger unit is used to determine whether the false alarm rate of the monitoring results of multiple suspicious Internet behavior data within a preset historical time period reaches the second preset threshold based on the corresponding feedback information.

[0137] An update calculation unit, connected to the update triggering unit, is used to filter Internet threat behavior data from operator signaling data if the false alarm rate reaches a second preset threshold, and to verify the accuracy and coverage of the filtered Internet threat behavior data using multiple Internet suspicious behavior data within a preset historical time period and corresponding feedback information.

[0138] The data update unit, connected to the update operation unit, is used to add the latest Internet threat behavior data that meets preset accuracy and coverage conditions to the Internet threat intelligence database.

[0139] Optionally, updating the arithmetic unit specifically includes:

[0140] The iteration start unit is used to set the maximum number of iterations and the initial iteration parameters. Starting from the initial number of iterations, the following iteration operations are performed:

[0141] The iterative filtering unit, connected to the iteration start unit, is used to filter Internet threat behavior data from operator signaling data for this round of iterative calculation using a preset model;

[0142] The iterative verification unit, connected to the iterative filtering unit, is used to calculate the second similarity between each suspicious internet behavior data within a preset historical time period and the internet threat behavior data of the current iteration, and to evaluate whether the accuracy and coverage of the internet threat behavior data of the current iteration meet the preset conditions based on the second similarity and the corresponding feedback information.

[0143] The iterative loop unit, connected to the iterative verification unit, is used to adjust the preset model through supervised learning and execute the next round of iterative calculation if the accuracy and coverage of the current iteration do not meet the preset conditions.

[0144] The iteration termination unit, connected to the iteration verification unit, is used to terminate the iteration operation if the accuracy and coverage of the current iteration operation meet the preset conditions, obtain the latest Internet threat behavior data from the current iteration operation, or terminate the iteration operation when the maximum number of iterations is reached.

[0145] Optionally, the iterative verification unit calls the first acquisition unit, the third acquisition unit, and the similarity calculation unit to:

[0146] The first acquisition unit is also used to acquire the first historical time within a preset historical time period. The third online time characteristic data of suspicious internet behavior data and third-party bandwidth characteristic data ;

[0147] The third acquisition unit is also used to acquire, using cellular automata, the internet threat behavior data from the current iteration calculation that is related to... The fourth online time feature data with the highest correlation probability , and with The fourth method with the highest correlation probability uses bandwidth feature data. ;

[0148] The similarity calculation unit is also used to calculate the similarity using equation (2). The second similarity between the suspicious internet behavior data and the internet threat behavior data in this round of iteration calculations. :

[0149]

[0150] in, , To determine the amount of suspicious internet behavior data within a preset historical timeframe, for transpose, for transpose, is the first adjustment coefficient, i, j, and t are the three dimensions of storing suspicious internet behavior data and internet threat behavior data in a sparse matrix, and m, n, and p are the upper limits of the values ​​of i, j, and t.

[0151] Optionally, the iterative verification unit may further include:

[0152] Obtain sub-units, connect them to the similarity calculation unit, and use them to calculate the similarity based on the sub-units. The accuracy of the internet threat behavior data obtained from this round of iterative calculations is obtained from the corresponding feedback information. and coverage ,in, This represents the number of iterations in this round of iterations.

[0153] The evaluation sub-unit, connected to the acquisition sub-unit, is used to evaluate whether the accuracy and coverage of the Internet threat behavior data in this round of iterations satisfy equation (3). If so, the accuracy and coverage of this round of iterations meet the preset conditions.

[0154]

[0155] in, The mathematical symbol represents the probability meaning, indicating that the result of the expression within the parentheses is a probability value.

[0156] Optionally, the iterative loop unit specifically includes:

[0157] The adjustment sub-unit is used to adjust the preset model according to the conditions of equations (4)-(6) if the accuracy and coverage of the Internet threat behavior data in this round of iteration does not meet equation (3):

[0158]

[0159]

[0160]

[0161] in, This is the second adjustment factor. , For the first The recursive supervised learning factor in the next iteration. , They are respectively the front The highest coverage and accuracy in the next iteration;

[0162] The loop subunit, connected to the adjustment subunit, is used for setting... Then, execute the next round of iteration calculations.

[0163] Embodiment 2 of the present invention provides an Internet threat intelligence monitoring device, which corresponds to the Internet threat intelligence monitoring method of Embodiment 1. It can detect Internet threat behaviors in a timely and accurate manner and avoid losses caused by Internet threat behaviors.

[0164] Example 3:

[0165] Embodiment 3 of the present invention provides a computer-readable storage medium storing a computer program thereon. When the computer program is run by a processor, it implements the Internet threat intelligence monitoring method as described in Embodiment 1.

[0166] The computer-readable storage medium includes volatile or non-volatile, removable or non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, computer program modules, or other data). Computer-readable storage media include, but are not limited to, RAM (Random Access Memory), ROM (Read-Only Memory), EEPROM (Electrically Erasable Programmable Read-Only Memory), flash memory or other memory technologies, CD-ROM (Compact Disc Read-Only Memory), DVD or other optical disc storage, cartridges, magnetic tapes, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and is accessible to a computer.

[0167] In addition, the present invention may also provide a computer device, the device including a memory and a processor, wherein the memory stores a computer program, and when the processor runs the computer program stored in the memory, the processor executes the Internet threat intelligence monitoring method as described in Embodiment 1.

[0168] The memory is connected to the processor. The memory can be flash memory, read-only memory or other types of memory. The processor can be a central processing unit or a microcontroller.

[0169] Embodiments 1-3 of this invention provide an internet threat intelligence monitoring method, device, and computer-readable storage medium. By acquiring multiple first behavioral feature data from suspicious internet behavior data, and separately acquiring multiple second behavioral feature data from internet threat behavior data that have the highest probability of association with the multiple first behavioral feature data, a monitoring result is obtained based on the first similarity between the multiple first behavioral feature data and the multiple second behavioral feature data to determine whether the suspicious internet behavior data corresponds to an internet threat behavior. By extracting feature data and performing data association, the effectiveness of internet threat intelligence monitoring is improved. This allows for timely and accurate determination of whether the suspicious internet behavior provided by the applicant constitutes an internet threat behavior, thereby providing the applicant with timely and accurate monitoring results and preventing the applicant from suffering losses due to internet threat behaviors.

[0170] It is understood that the above embodiments are merely exemplary embodiments used to illustrate the principles of the present invention, and the present invention is not limited thereto. For those skilled in the art, various modifications and improvements can be made without departing from the spirit and essence of the present invention, and these modifications and improvements are also considered to be within the scope of protection of the present invention.

Claims

1. A method for monitoring internet threat intelligence, characterized in that, The method includes: The system receives Internet threat intelligence monitoring application information from applicants. The Internet threat intelligence monitoring application information includes suspicious Internet behavior data to be analyzed. After receiving suspicious Internet behavior, the user terminal provides suspicious terminal information of the suspicious Internet behavior. The operator queries the network behavior feature data of the corresponding terminal based on the suspicious terminal information as Internet suspicious behavior data to be analyzed. The system acquires multiple first behavioral feature data from the suspected internet behavior data to be analyzed, and then acquires multiple second behavioral feature data from the known internet threat behavior data that have the highest probability of association with the multiple first behavioral feature data. The known internet threat behavior data is obtained from the internet threat intelligence database. Based on the first similarity between multiple first behavioral feature data and multiple second behavioral feature data, the monitoring results of whether the suspected Internet behavior data to be analyzed corresponds to the existence of Internet threat behavior are obtained. Send the monitoring results to the applicant and receive feedback from the applicant regarding the accuracy of the monitoring results; Based on the corresponding feedback information, determine whether the false alarm rate of the monitoring results of multiple suspicious Internet behavior data within a preset historical time period reaches the second preset threshold. If the false alarm rate reaches the second preset threshold, new internet threat behavior data is filtered from the operator signaling data. The accuracy and coverage of the filtered internet threat behavior data are then verified using multiple suspicious internet behavior data points within a preset historical time period and corresponding feedback information. Specifically, this includes: Set the maximum number of iterations and the initial iteration parameters, and execute the following iterative operation starting from the initial number of iterations: The internet threat behavior data for this round of iterative calculations is filtered from operator signaling data using a preset model; Calculate the second similarity between each suspicious internet behavior data point within a preset historical time period and the internet threat behavior data from this round of iterations. Based on the second similarity and corresponding feedback information, evaluate whether the accuracy and coverage of the internet threat behavior data from this round of iterations meet preset conditions. Specifically, this includes: The accuracy of the internet threat behavior data in this round of iterative calculation is obtained based on the second similarity score and the corresponding feedback information. and coverage ,in, This represents the number of iterations in this round of iterations. Evaluate whether the accuracy and coverage of the Internet threat behavior data in this round of iterative calculations satisfy equation (3). If so, the accuracy and coverage of this round of iterative calculations have reached the preset conditions: , in, The mathematical symbols represent probabilistic meanings, indicating that the result of the formula in the parentheses is a probability value. i, j, and t are the three dimensions of storing suspicious internet behavior data and internet threat behavior data in a sparse matrix. m, n, and p are the upper limits of the values ​​of i, j, and t. If the accuracy and coverage of this round of iterations do not meet the preset conditions, the preset model is adjusted through supervised learning, and the next round of iterations is executed, specifically including: If the accuracy and coverage of the Internet threat behavior data in this round of iteration do not meet equation (3), the preset model is adjusted according to the conditions of equations (4)-(6): , , , in, This is the second adjustment factor. , For the first The recursive supervised learning factor in the next iteration. , They are respectively the front The highest coverage and accuracy in the next iteration; set up Then execute the next round of iterations. If the accuracy and coverage of this round of iteration reach the preset conditions, the Internet threat behavior data obtained in this round of iteration is the latest Internet threat behavior data and the iteration ends, or the iteration ends when the maximum number of iterations is reached; Add the latest internet threat behavior data that meets the preset accuracy and coverage conditions to the internet threat intelligence database.

2. The method according to claim 1, characterized in that, Obtain multiple first behavioral feature data from the suspicious internet behavior data to be analyzed, and then obtain multiple second behavioral feature data from the internet threat behavior data that have the highest probability of association with the multiple first behavioral feature data, specifically including: Obtain first online time characteristic data from the suspicious internet behavior data to be analyzed. And the first use of bandwidth characteristic data ; Obtain internet threat behavior data from internet threat intelligence databases; Using cellular automata to obtain data on internet threat behaviors The second online time feature data with the highest correlation probability , and with The second most probable association is achieved using bandwidth feature data. .

3. The method according to claim 2, characterized in that, Based on the first similarity between multiple first behavioral feature data and multiple second behavioral feature data, the monitoring results are obtained to determine whether the suspected internet behavior data to be analyzed corresponds to internet threat behavior. Specifically, this includes: The first similarity between multiple first-behavioral feature data and multiple second-behavioral feature data is calculated according to formula (1). : , in, for transpose, for transpose, This is the first adjustment factor; if If the value is less than the first preset threshold, then the monitoring result corresponding to the suspected internet behavior data to be analyzed is obtained, indicating that there is an internet threat behavior; otherwise, the monitoring result corresponding to the suspected internet behavior data to be analyzed is obtained, indicating that there is no internet threat behavior.

4. The method according to any one of claims 1-3, characterized in that, Calculate the second similarity between each suspicious internet behavior data point within a preset historical time period and the internet threat behavior data calculated in this round of iterations, specifically including: Get the first within the preset historical time period The third online time characteristic data of suspicious internet behavior data and third-party bandwidth characteristic data ; Using cellular automata to obtain the internet threat behavior data in this round of iterative computation and The fourth online time feature data with the highest correlation probability , and with The fourth most probable association uses bandwidth feature data. ; Calculate the first using formula (2). The second similarity between the suspicious internet behavior data and the internet threat behavior data in this round of iteration calculations. : , in, , To determine the amount of suspicious internet behavior data within a preset historical timeframe, for transpose, for transpose, This is the first adjustment factor.

5. An internet threat intelligence monitoring device, characterized in that, The device includes: The receiving module is used to receive Internet threat intelligence monitoring application information from the applicant. The Internet threat intelligence monitoring application information includes Internet suspicious behavior data to be analyzed. After receiving Internet suspicious behavior, the user terminal provides suspicious terminal information of Internet suspicious behavior. The operator queries the network behavior feature data of the corresponding terminal based on the suspicious terminal information as Internet suspicious behavior data to be analyzed. The acquisition module, connected to the receiving module, is used to acquire multiple first behavioral feature data of the suspicious Internet behavior data to be analyzed, and to acquire multiple second behavioral feature data of the known Internet threat behavior data that have the highest probability of association with the multiple first behavioral feature data. The known Internet threat behavior data is acquired from the Internet threat intelligence database. The monitoring module, connected to the acquisition module, is used to obtain the monitoring result of whether the suspected Internet behavior data to be analyzed corresponds to Internet threat behavior based on the first similarity between multiple first behavioral feature data and multiple second behavioral feature data. The feedback module is used to send the monitoring results to the applicant and receive feedback from the applicant regarding the correctness of the monitoring results. The update module is used for: Based on the corresponding feedback information, determine whether the false alarm rate of the monitoring results of multiple suspicious Internet behavior data within a preset historical time period reaches the second preset threshold. If the false alarm rate reaches the second preset threshold, new internet threat behavior data is filtered from the operator signaling data. The accuracy and coverage of the filtered internet threat behavior data are then verified using multiple suspicious internet behavior data points within a preset historical time period and corresponding feedback information. Specifically, this includes: Set the maximum number of iterations and the initial iteration parameters, and execute the following iterative operation starting from the initial number of iterations: The internet threat behavior data for this round of iterative calculations is filtered from operator signaling data using a preset model; Calculate the second similarity between each suspicious internet behavior data point within a preset historical time period and the internet threat behavior data from this round of iterations. Based on the second similarity and corresponding feedback information, evaluate whether the accuracy and coverage of the internet threat behavior data from this round of iterations meet preset conditions. Specifically, this includes: The accuracy of the internet threat behavior data in this round of iterative calculation is obtained based on the second similarity and the corresponding feedback information. and coverage ,in, This represents the number of iterations in this round of iterations. Evaluate whether the accuracy and coverage of the Internet threat behavior data in this round of iterative calculations satisfy equation (3). If so, the accuracy and coverage of this round of iterative calculations have reached the preset conditions: , in, The mathematical symbols represent probabilistic meanings, indicating that the result of the formula in parentheses is a probability value. i, j, and t are the three dimensions of storing suspicious internet behavior data and internet threat behavior data in a sparse matrix. m, n, and p are the upper limits of the values ​​of i, j, and t. If the accuracy and coverage of this round of iterations do not meet the preset conditions, the preset model is adjusted through supervised learning, and the next round of iterations is executed, specifically including: If the accuracy and coverage of the Internet threat behavior data in this round of iteration do not meet equation (3), the preset model is adjusted according to the conditions of equations (4)-(6): , , , in, This is the second adjustment factor. , For the first The recursive supervised learning factor in the next iteration. , They are respectively the front The highest coverage and accuracy in the next iteration; set up Then execute the next round of iterations. If the accuracy and coverage of this round of iteration reach the preset conditions, the Internet threat behavior data obtained in this round of iteration is the latest Internet threat behavior data and the iteration ends, or the iteration ends when the maximum number of iterations is reached; Add the latest internet threat behavior data that meets the preset accuracy and coverage conditions to the internet threat intelligence database.

6. A computer-readable storage medium, characterized in that, It stores a computer program that, when executed by a processor, implements the Internet threat intelligence monitoring method as described in any one of claims 1-4.

Citation Information

Patent Citations

  • Method and device for discriminating threat information credibility based on multi-dimensional trusted feature

    CN108600212A