Threat intelligence information processing method and apparatus, and storage medium
By integrating vulnerability and incident intelligence information and using model recognition, the accuracy problem of threat intelligence information identification in existing technologies has been solved, achieving more efficient network security protection and cost optimization.
Patent Information
- Application Number
- CN202311083132.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-08-25
- Publication Date
- 2026-01-27
- Estimated Expiration
- 2043-08-25
AI Technical Summary
Existing threat intelligence identification technologies suffer from underreporting and false alarms, leading to increased cybersecurity risks and operational costs. Keyword matching technologies are also lagging behind in updates and can result in multiple meanings of a single word.
By fusing vulnerability intelligence and event intelligence information, using a named entity recognition model to extract attribute information, and combining it with asset information to determine threat and vulnerability information, and using a trained event prediction model to process event intelligence information, vulnerability intelligence fusion information and event intelligence fusion information are generated for security processing.
It improved the accuracy of threat intelligence information identification, reduced false negatives and missed reports, shortened the response time for security operations personnel, enhanced network security protection capabilities, and reduced operating costs.
Smart Images

Figure CN117134962B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to a method, apparatus, and storage medium for processing threat intelligence information. Background Technology
[0002] With the rapid development of computer and network technologies, various cybersecurity incidents occur frequently, network attacks are becoming increasingly common, and the quantity and types of threat intelligence information are growing daily, posing a serious threat to network security and increasing the risk of data leakage for telecommunications operators and other enterprises, as well as users. Currently, telecommunications operators and other enterprises typically use keyword matching technology to identify threat intelligence information, determining whether the intelligence description contains keywords related to them, in order to obtain threat intelligence information of interest. However, due to the continuous emergence of new vulnerabilities and attacks, keyword updates are lagging, and keyword matching technology may miss important threat intelligence information. In addition, some keywords have multiple meanings, and keyword matching technology may obtain irrelevant threat intelligence. Therefore, using existing threat intelligence information identification technologies results in a significant number of missed threat intelligence reports and false positives, affecting the accuracy of threat intelligence information identification, posing network security risks, and increasing operational costs. Summary of the Invention
[0003] In view of this, one technical problem to be solved by the present invention is to provide a method, apparatus and storage medium for processing threat intelligence information.
[0004] According to a first aspect of this disclosure, a method for processing threat intelligence information is provided, comprising: fusing vulnerability intelligence information and event intelligence information respectively to generate fused vulnerability intelligence information and fused event intelligence information; extracting attribute information from the fused vulnerability intelligence information, and determining whether the vulnerability intelligence information corresponding to the fused vulnerability intelligence information is a threat vulnerability information based on the attribute information and asset information; processing the fused event intelligence information using a trained event prediction model to determine whether the event intelligence information corresponding to the fused event intelligence information is an industry threat event information; and performing security processing on the threat vulnerability information and the industry threat event information.
[0005] Optionally, extracting attribute information from the vulnerability intelligence fusion information includes: processing the vulnerability intelligence fusion information using a trained named entity recognition model to obtain attribute information of the vulnerability intelligence fusion information; wherein, the attribute information includes: attributes and corresponding attribute values.
[0006] Optionally, the named entity recognition model includes a Bi-LSTM neural network model; the attributes include: vulnerability type, vulnerability number, affected components, affected versions, and solutions.
[0007] Optionally, the asset information includes: component concern information and enterprise asset information; determining whether the vulnerability intelligence information corresponding to the vulnerability intelligence fusion information is a threat vulnerability information based on the attribute information and asset information includes: comparing the attribute information with the component concern information, and determining whether the vulnerability intelligence information corresponding to the vulnerability intelligence fusion information is the threat vulnerability information based on the comparison result; if it is determined that the vulnerability intelligence information corresponding to the vulnerability intelligence fusion information is not the threat vulnerability information, comparing the attribute information with the enterprise asset information, and determining whether the vulnerability intelligence information corresponding to the vulnerability intelligence fusion information is the threat vulnerability information based on the comparison result.
[0008] Optionally, before processing the event intelligence fusion information using the trained event prediction model, the method further includes: labeling the historical event intelligence fusion information in the historical event information set based on labeling rules to determine the tags of the historical event intelligence fusion information; performing word segmentation on the historical event intelligence fusion information to generate keywords; generating word vectors for the keywords, and generating word vectors for the historical event intelligence fusion information based on the word vectors of all the keywords; generating event samples based on the word vectors and tags of the historical event intelligence fusion information; and using the event samples to train the event prediction model.
[0009] Optionally, the step of training the event prediction model using the event samples includes: dividing all the event samples into a training set, a validation set, and a test set; training the event prediction model using the event samples in the training set; and validating and testing the trained event prediction model using the event samples in the validation set and the event samples in the test set, respectively.
[0010] Optionally, the event prediction model includes: a convolutional layer, a pooling layer, and a fully connected layer; the process of training the event prediction model using the event samples includes: inputting the word vectors of the event samples into the convolutional layer for convolution to obtain a feature set; inputting the feature set into the pooling layer to obtain a pooled feature vector; inputting the feature vector into the fully connected layer and generating industry threat event category information through a softmax activation function; and adjusting the event prediction model based on the industry threat event category information and the labels of the event samples.
[0011] Optionally, labels are set for the industry threat event information; new event samples are generated based on the word vectors and labels of the industry threat event information, and the event prediction model is trained again.
[0012] Optionally, the security processing of the threat vulnerability information and the industry threat event information includes: notifying the target personnel of the threat vulnerability information and the industry threat event information so that the target personnel can determine whether the threat vulnerability information and the industry threat event information need to be alerted; wherein, the notification to the target personnel includes: sending an email, or displaying the threat vulnerability information and the industry threat event information in an information platform.
[0013] Optionally, the step of fusing vulnerability intelligence information and event intelligence information separately includes: using a text deduplication algorithm to fuse vulnerability intelligence information and event intelligence information separately.
[0014] Optionally, web crawler technology can be used to crawl and process the information published on the target website to obtain the vulnerability intelligence information and the event intelligence information.
[0015] According to a second aspect of this disclosure, a threat intelligence information processing apparatus is provided, comprising: a fusion processing module, configured to fuse vulnerability intelligence information and event intelligence information respectively to generate fused vulnerability intelligence information and fused event intelligence information; a vulnerability analysis module, configured to extract attribute information from the fused vulnerability intelligence information and determine, based on the attribute information and asset information, whether the vulnerability intelligence information corresponding to the fused vulnerability intelligence information is a threat vulnerability information; an event analysis module, configured to process the fused event intelligence information using a trained event prediction model to determine whether the event intelligence information corresponding to the fused event intelligence information is an industry threat event information; and a security processing module, configured to perform security processing on the threat vulnerability information and the industry threat event information.
[0016] According to a third aspect of this disclosure, a threat intelligence information processing method is provided, comprising: a memory; and a processor coupled to the memory, the processor being configured to perform the method described above based on instructions stored in the memory.
[0017] According to a fourth aspect of this disclosure, a computer-readable storage medium is provided that stores computer instructions which are executed by a processor using the method described above.
[0018] The threat intelligence information processing method, apparatus, and storage medium disclosed herein generate vulnerability intelligence fusion information and event intelligence fusion information. Based on the attribute information and asset information in the vulnerability intelligence fusion information, it determines whether the information is a threat vulnerability. It then uses an event prediction model to process the event intelligence fusion information to determine whether it is an industry threat event information, and then performs security processing. This can improve the accuracy of threat intelligence information identification, reduce the occurrence of missed threat intelligence and false positives of invalid threat intelligence, reduce the response time of security operations personnel, improve network security protection capabilities, and reduce operating costs. Attached Figure Description
[0019] The above and other objects, features, and advantages of this disclosure will become more apparent from the more detailed description of the embodiments thereof in conjunction with the accompanying drawings. The accompanying drawings are provided to further illustrate the embodiments of this disclosure and form part of the specification. They are used together with the embodiments of this disclosure to explain the disclosure and do not constitute a limitation thereof. The above and other objects and advantages of this disclosure will be further described below with reference to specific embodiments and the accompanying drawings. In the drawings, the same or corresponding technical features or components will be represented by the same or corresponding reference numerals.
[0020] Figure 1 This is a schematic flowchart of an embodiment of the threat intelligence information processing method according to the present disclosure;
[0021] Figure 2 This is a schematic diagram of the process for determining threat vulnerability information in one embodiment of the threat intelligence information processing method according to the present disclosure;
[0022] Figure 3 This is a flowchart illustrating the training of an event prediction model in one embodiment of the threat intelligence information processing method according to the present disclosure.
[0023] Figure 4 This is a flowchart illustrating the process of training an event prediction model using industry threat event information in one embodiment of the threat intelligence information processing method according to this disclosure.
[0024] Figure 5 This is a schematic diagram of a module of an embodiment of a threat intelligence information processing apparatus according to the present disclosure;
[0025] Figure 6 This is a schematic diagram of a module according to another embodiment of the threat intelligence information processing apparatus according to the present disclosure;
[0026] Figure 7 This is a schematic diagram of a module according to yet another embodiment of the threat intelligence information processing apparatus according to the present disclosure. Detailed Implementation
[0027] Exemplary embodiments of the present disclosure will be described below with reference to the accompanying drawings. For clarity and brevity, not all features of the embodiments are described in the specification. However, it should be understood that many implementation-specific settings must be made in carrying out the embodiments to achieve the developer's specific goals, such as complying with constraints related to the device and business, and these constraints may vary depending on the implementation. Furthermore, it should be understood that while development work can be very complex and time-consuming, such development work is merely a routine task for those skilled in the art who benefit from the present disclosure.
[0028] It should be noted that, unless otherwise specifically stated, the relative arrangement, numerical expressions, and values of the components and steps set forth in these embodiments do not limit the scope of this disclosure.
[0029] Those skilled in the art will understand that the terms "first," "second," etc., in the embodiments of this disclosure are only used to distinguish different steps, devices, or modules, and do not represent any specific technical meaning, nor do they indicate a necessary logical order between them.
[0030] It should also be understood that in the embodiments disclosed herein, "a plurality of" may refer to two or more, and "at least one" may refer to one, two or more.
[0031] It should also be understood that any component, data or structure mentioned in the embodiments of this disclosure can generally be understood as one or more unless expressly defined or given to the contrary in the context.
[0032] Furthermore, the term "and / or" in this disclosure is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this disclosure generally indicates that the preceding and following related objects have an "or" relationship.
[0033] It should also be understood that the description of the various embodiments in this disclosure emphasizes the differences between the various embodiments, and the similarities or similarities can be referred to each other. For the sake of brevity, they will not be described in detail.
[0034] At the same time, it should be understood that, for ease of description, the dimensions of the various parts shown in the accompanying drawings are not drawn according to actual scale.
[0035] The following description of at least one exemplary embodiment is merely illustrative and is in no way intended to limit this disclosure or its application or use.
[0036] Techniques, methods, and equipment known to those skilled in the art may not be discussed in detail, but where appropriate, such techniques, methods, and equipment should be considered part of the specification.
[0037] It should be noted that similar labels and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be discussed further in subsequent figures.
[0038] Furthermore, to avoid obscuring this disclosure with unnecessary detail, only processing steps and / or apparatus structures closely related to at least the solutions according to this disclosure are shown in the accompanying drawings, while other details not closely related to this disclosure are omitted. It should also be noted that similar reference numerals and letters in the drawings indicate similar items, and therefore once an item is defined in one drawing, it need not be discussed again in subsequent drawings.
[0039] Among the related technologies known to the inventor, telecommunications operators and other enterprises possess a large number of Internet attack surfaces. An Internet attack surface is a collection of publicly accessible information, services, resources, and functions of an organization, enterprise, individual, or system on the Internet, constituting potential entry points and targets that attackers may exploit. For example, an Internet attack surface includes: domain names and subdomains, IP addresses, open ports, network services, applications and APIs, cloud resources, third-party services, configuration information, and publicly available information (employee information, contact information, organizational structure, etc.).
[0040] The risk of data breaches for telecommunications operators and other businesses, as well as users, is constantly increasing. The potential security threats can be broadly categorized into two types. The first type is threats targeting critical infrastructure, such as vulnerabilities in general components. The critical infrastructure of telecommunications operators and other businesses includes a range of network and technical facilities used to provide communication services, data transmission, and internet access; for example, it includes: wireless base stations and mobile communication networks, fiber optic and transmission networks, data centers, switches and routers, internet access facilities, and core networks. The second type of security threat is threats targeting business systems, such as defects in business systems and privilege escalation vulnerabilities. Current threat intelligence identification technologies suffer from numerous instances of missed threat intelligence reports and false positives.
[0041] Figure 1 This is a flowchart illustrating an embodiment of the threat intelligence information processing method according to the present disclosure, as follows: Figure 1 As shown:
[0042] Step 101: The vulnerability intelligence information and event intelligence information are fused separately to generate vulnerability intelligence fusion information and event intelligence fusion information.
[0043] In one embodiment, threat intelligence information includes vulnerability intelligence information and event intelligence information, such as component vulnerability intelligence information and event intelligence information.
[0044] Step 102: Extract attribute information from the vulnerability intelligence fusion information, and determine whether the vulnerability intelligence information corresponding to the vulnerability intelligence fusion information is a threat vulnerability information based on the attribute information and asset information.
[0045] Step 103: Use the trained event prediction model to process the event intelligence fusion information and determine whether the event intelligence information corresponding to the event intelligence fusion information is an industry threat event information.
[0046] Step 104: Perform security processing on threat vulnerability information and industry threat incident information.
[0047] In one embodiment, web crawling technology is used to crawl and process information published on a target website to obtain threat intelligence information such as vulnerability intelligence and event intelligence. The target website can be a professional security website, such as Alibaba Cloud security bulletins, the National Information Security Vulnerability Sharing Platform, or NSFOCUS security vulnerabilities. For example, distributed web crawling technology can be used to obtain information published on the target website; this information consists of raw intelligence information released by professional security organizations both domestically and internationally, including vulnerability intelligence and event intelligence.
[0048] There are various methods for fusing vulnerability intelligence and event intelligence separately. For example, text deduplication algorithms can be used to fuse vulnerability intelligence and event intelligence separately. These algorithms include existing ones such as Simhash and Jaccard (the Jaccard similarity coefficient algorithm). Simhash and Jaccard algorithms can be used to fuse vulnerability intelligence and event intelligence separately, generating fused vulnerability intelligence and fused event intelligence information.
[0049] In one embodiment, distributed web crawling technology is used to obtain threat information (vulnerability intelligence) such as vulnerabilities and patches released by professional security organizations such as the National Information Security Vulnerability Sharing Platform and Alibaba Cloud, while simultaneously crawling security incident intelligence information (event intelligence) released by domestic and foreign professional security companies. After obtaining the raw vulnerability intelligence and event intelligence information, based on the detailed descriptions and titles of the vulnerability intelligence and event intelligence information, and combined with algorithms such as Simhash and Jaccard (text deduplication techniques), the vulnerability intelligence information and event intelligence information are fused to generate fused vulnerability intelligence information and fused event intelligence information, which can reduce data redundancy.
[0050] There are multiple methods for extracting attribute information from vulnerability intelligence fusion information. Figure 2 This is a schematic diagram of the process for determining threat vulnerability information in one embodiment of the threat intelligence information processing method according to this disclosure, such as... Figure 2 As shown:
[0051] Step 201: Use the trained named entity recognition model to process the vulnerability intelligence fusion information to obtain the attribute information of the vulnerability intelligence fusion information.
[0052] In one embodiment, the named entity recognition model includes existing models such as BERT (Bidirectional Encoder Representations from Transformers) and Bi-LSTM (Bidirectional Long Short-Term Memory) neural network models. Attribute information includes attributes and their corresponding values; attributes include vulnerability type, vulnerability number, affected components, affected versions, and solutions.
[0053] By using named entity recognition technology in natural language processing and models such as the Bi-LSTM neural network model, attributes such as vulnerability type, vulnerability number, affected components, affected versions, and solutions are extracted from the vulnerability intelligence fusion information to form vulnerability intelligence information with a unified format and machine readability.
[0054] For example, the vulnerability intelligence fusion information states: "On March 31, 2022, Spring officially released a security bulletin disclosing CVE-2022-22965, a remote code execution vulnerability in the Spring Framework. Due to a flaw in the Spring framework's processing flow, attackers can remotely write backdoor files and modify configurations on the target host, thereby gaining access to the target host through these backdoor files. Users of Spring Framework 5.3.x < 5.3.18, Spring Framework 5.2.x < 5.2.20, and JDK version 9 or higher are vulnerable to this vulnerability. Alibaba Cloud Emergency Response Center recommends that affected customers upgrade their Spring Framework to version 5.3.18, 5.2.20, or higher."
[0055] The attribute information extracted from the above vulnerability intelligence fusion information using the Bi-LSTM neural network model is as follows: "Vulnerability type: Remote code execution; Vulnerability number: CVE-2022-22965; Affected component: Spring Framework; Affected version: Spring Framework 5.3.x < 5.3.18; Spring Framework 5.2.x < 5.2.20; Solution: It is recommended that affected customers upgrade their Spring Framework to version 5.3.18, 5.2.20 or above."
[0056] Step 202: Compare the attribute information with the component concern information, and determine whether the vulnerability intelligence information corresponding to the vulnerability intelligence fusion information is a threat vulnerability information based on the comparison processing result.
[0057] In one embodiment, asset information includes component concern information and enterprise asset information. If the result of comparing the attribute information with the component concern information is a match or identical, then the vulnerability intelligence information corresponding to the vulnerability intelligence fusion information is determined to be threat vulnerability information; if the result of comparing the attribute information with the component concern information is a mismatch or different, then the vulnerability intelligence information corresponding to the vulnerability intelligence fusion information is determined not to be threat vulnerability information.
[0058] Step 203: If it is determined that the vulnerability intelligence information corresponding to the vulnerability intelligence fusion information is not a threat vulnerability information, the attribute information is compared with the enterprise asset information, and the vulnerability intelligence information corresponding to the vulnerability intelligence fusion information is determined based on the comparison result.
[0059] In one embodiment, if the result of comparing the attribute information with the enterprise asset information is a match or the same, then the vulnerability intelligence information corresponding to the vulnerability intelligence fusion information is determined to be threat vulnerability information; if the result of comparing the attribute information with the enterprise asset information is a mismatch or different, then the vulnerability intelligence information corresponding to the vulnerability intelligence fusion information is determined not to be threat vulnerability information.
[0060] Component focus information can be information about components relevant to industries such as telecommunications, while enterprise asset information can be enterprise asset information for companies such as telecommunications operators. For example, component focus information may include: "Database components: Elasticsearch, Redis, MongoDB, MySQL, etc.; Middleware: Tomcat, Kafka, Flume, etc." Component focus information is maintained by the company's staff.
[0061] The attribute information is compared with the component concern information. That is, the attribute values of the affected components in the attribute information are compared (collision) with the component concern information (such as the component information in the key concern component table of enterprises such as telecom operators). If the comparison result is successful (match or same), the vulnerability intelligence information corresponding to the vulnerability intelligence fusion information is determined to be threat vulnerability information and security processing is carried out.
[0062] If the comparison result is unsuccessful (mismatch or different), it is determined that the vulnerability intelligence information corresponding to the vulnerability intelligence fusion information is not a threat vulnerability information. The attribute information is then compared with the enterprise asset information, that is, the attribute values of the affected components, affected versions, etc. in the attribute information are compared with the information of the components of interest and versions in the enterprise asset information (which can be the enterprise asset library).
[0063] An enterprise asset inventory is a collection used to record, manage, and track various assets within an organization. Assets can include hardware devices, software, network resources, data, components, services, and more. Information in the enterprise asset inventory includes device and component names, device and component version information, etc.
[0064] If the comparison is successful (match or identical), the vulnerability intelligence information corresponding to the fused vulnerability intelligence information is identified as a threat vulnerability and is subject to security processing. If the comparison is unsuccessful (mismatch or different), the vulnerability intelligence information corresponding to the fused vulnerability intelligence information is identified as not a threat vulnerability.
[0065] Based on custom interaction rules and by providing an API interface, the system can compare (collide) attribute values such as affected components and affected versions in the attribute information with the information of interested components and versions in the enterprise asset database. Since the enterprise asset database information is highly confidential, providing the comparison function through an API comparison interface can enhance the system's security.
[0066] In one embodiment, the event prediction model needs to be trained before it can be used to process event intelligence fusion information. Figure 3 This is a flowchart illustrating the training of an event prediction model in one embodiment of the threat intelligence information processing method according to this disclosure, as shown below. Figure 3 As shown:
[0067] Step 301: Based on the annotation rules, the historical event intelligence fusion information in the historical event information set is annotated to determine the labels of the historical event intelligence fusion information.
[0068] In one embodiment, the historical event intelligence fusion information is pre-acquired event intelligence fusion information. The event prediction model is a text classification model used to determine whether the event intelligence information corresponding to the event intelligence fusion information is industry threat event information. The industry can be the telecommunications industry, etc. That is, the output of the event prediction model can be telecommunications industry threat event information (positive prediction result) or not telecommunications industry threat event information (negative prediction result).
[0069] The labeling rules can be of various types. For example, the labeling rules include: when information such as historical event intelligence fusion information and industry threat event information involves attacks on relevant domestic and foreign telecommunications companies, vulnerabilities of commonly used components in the asset database, ransomware with a wide range of harm, new attack organizations with a wide range of harm, malicious programs with a wide range of harm, and large-scale attack events with high domestic and foreign attention, the label is determined to be a positive label; otherwise, the label is determined to be a negative label.
[0070] Step 302: Perform word segmentation on the historical event intelligence fusion information to generate keywords.
[0071] In one embodiment, tools such as jieba can be used to segment historical event intelligence fusion information. Based on existing stop word lists, Chinese stop words and other words can be removed to generate keywords, thereby eliminating semantic noise.
[0072] Step 303: Generate word vectors for keywords, and generate word vectors for historical event intelligence fusion information based on the word vectors of all keywords.
[0073] In one embodiment, a pre-trained word vector table, organized by character, can be used to map keywords to word vectors of fixed length. For keywords not appearing in the pre-trained word vector table, word vectors are randomly generated using existing PyTorch tools. The word vectors of all keywords can be concatenated to generate word vectors for historical event intelligence fusion information.
[0074] Step 304: Generate event samples based on word vectors and tags from historical event intelligence fusion information, and use the event samples to train the event prediction model.
[0075] In one embodiment, various existing methods can be used to generate event samples by combining word vectors and tags from historical event intelligence fusion information. All event samples are divided into training, validation, and test sets. The event prediction model is trained using event samples from the training set; the trained event prediction model is validated and tested using event samples from the validation and test sets, respectively.
[0076] Event prediction models can be text classification models such as Convolutional Neural Networks (CNN), and include convolutional layers, pooling layers, and fully connected layers. The process involves inputting the word vectors of event samples into a convolutional layer for convolution to obtain a feature set; then inputting the feature set into a pooling layer to obtain a pooled feature vector; finally, inputting the feature vector into a fully connected layer and using a softmax activation function to generate industry threat event category information; and finally, adjusting the event prediction model based on the industry threat event category information and the labels of the event samples.
[0077] For example, the event prediction model is the textCNN text classification model. All event samples are divided into training, validation, and test sets in a 7:1:2 ratio. Various model training methods can be used to train the textCNN model.
[0078] Input the word vectors of the event samples (which can be the intelligence keyword matrix) into the convolutional layer of the Text-CNN network, and perform convolution operations sequentially using multi-channel convolution kernels (e.g., kernels with dimensions of 3*300, 4*300, and 5*300). The expression is as follows:
[0079] c i =f(w·x) i:i+h-1 +b)(1-1);
[0080] Where, x i:i+h-1 This represents a window of size h×k between the i-th word vector and the (i+h-1)-th word vector of an event sample, consisting of multiple word vectors (x... i ,x i+1 ,....,x i+h-1The window consists of h, which represents the number of words contained in the window, w, which is an h×k dimensional weight matrix, b, which is a bias parameter, and f, which is a non-linear function ReLU.
[0081] After performing a convolution operation on the event samples, a feature set C = {c1, c2, ..., c3} is obtained. n-h+1}
[0082] The feature set is input into the pooling layer to select the largest feature C' = max{C} from the feature vectors generated by each sliding window. These features are then concatenated to form a vector representation, i.e., to generate a feature vector.
[0083] The feature vectors are input into a fully connected layer, and the softmax activation function is used to generate industry threat event category information. The industry threat event category information includes the probability that the event sample is a positive or negative industry threat event. A positive industry threat event represents an industry threat event, and a negative industry threat event represents a non-industry threat event.
[0084] The system compares industry threat event category information with event sample labels, uses existing training methods, and adjusts the parameters of the event prediction model based on the comparison results to ensure that the prediction accuracy of the event prediction model reaches a preset accuracy threshold.
[0085] Figure 4 This is a flowchart illustrating the process of training an event prediction model using industry threat event information in one embodiment of the threat intelligence information processing method according to this disclosure, as shown below. Figure 4 As shown:
[0086] Step 401: Set labels for industry threat event information.
[0087] Step 402: Generate new event samples based on word vectors and labels of industry threat event information, and use them to retrain the event prediction model.
[0088] In one embodiment, after using a trained event prediction model to determine that the event intelligence information corresponding to the event intelligence fusion information is industry threat event information, based on the confirmation of the prediction results by the operators, a label is set for the industry threat event information. The label can be a positive label or a negative label, which can correct the prediction results of the event prediction model.
[0089] New event samples are generated based on word vectors and tags from industry threat event information.
[0090] The event prediction model can be retrained using new event samples alone, or using both new and existing event samples. Using corrected industry threat event information can enrich the training set, and retraining the model can improve prediction performance.
[0091] In one embodiment, multiple methods can be used for security processing. For example, threat vulnerability information and industry threat event information can be notified to target personnel so that they can determine whether early warning processing is required. Early warning processing includes analyzing threat intelligence and issuing work orders for processing threat intelligence. The methods for notifying target personnel of threat vulnerability information and industry threat event information include sending emails and displaying the threat vulnerability information and industry threat event information in an information platform.
[0092] Target personnel can include operations staff, security experts, etc. Threat vulnerability information and industry threat event information can be added to a watchlist and communicated to operations staff and security experts via email, platform display, etc. Operations staff and security experts then determine whether to issue alerts for the threat vulnerability information and industry threat event information, conduct further analysis and refinement of the intelligence, and decide whether to distribute it to various business units, achieving closed-loop intelligence processing and providing a closed-loop solution. Operations staff and security experts then issue relevant work orders, and each subsystem reports the remediation results on a designated platform after completing the vulnerability patching.
[0093] The threat intelligence information processing method disclosed herein generates vulnerability intelligence fusion information and event intelligence fusion information. Based on the attribute information and asset information in the vulnerability intelligence fusion information, it determines whether the information is a threat vulnerability. It then uses an event prediction model to process the event intelligence fusion information to determine whether it is an industry threat event information, and then performs security processing. This method can improve the accuracy of threat intelligence information identification, reduce the occurrence of missed threat intelligence and false positives of invalid threat intelligence, reduce the response time of security operations personnel, improve network security protection capabilities, and reduce operating costs.
[0094] In one embodiment, such as Figure 5 As shown, this disclosure provides a threat intelligence information processing device 50, including a fusion processing module 51, a vulnerability analysis module 52, an event analysis module 53, and a security processing module 54. The fusion processing module 51 performs fusion processing on vulnerability intelligence information and event intelligence information respectively, generating fused vulnerability intelligence information and fused event intelligence information. For example, the fusion processing module 51 uses a text deduplication algorithm to perform fusion processing on the vulnerability intelligence information and event intelligence information respectively.
[0095] The vulnerability analysis module 52 extracts attribute information from the fused vulnerability intelligence information and determines whether the vulnerability intelligence information corresponding to the fused vulnerability intelligence information is a threat vulnerability based on the attribute information and asset information. The event analysis module 53 processes the fused event intelligence information using a trained event prediction model to determine whether the event intelligence information corresponding to the fused event intelligence information is an industry threat event.
[0096] The security processing module 54 performs security processing on threat vulnerability information and industry threat event information. For example, the security processing module 54 notifies target personnel of threat vulnerability information and industry threat event information so that they can determine whether early warning processing of threat vulnerability information and industry threat event information is required.
[0097] In one embodiment, the vulnerability analysis module 52 processes the fused vulnerability intelligence information using a trained named entity recognition model to obtain the attribute information of the fused vulnerability intelligence information. The vulnerability analysis module 52 compares the attribute information with the component interest information, and determines whether the vulnerability intelligence information corresponding to the fused vulnerability intelligence information is a threat vulnerability based on the comparison result.
[0098] For example, if the vulnerability analysis module 52 determines that the vulnerability intelligence information corresponding to the vulnerability intelligence fusion information is not a threatening vulnerability information, it will compare the attribute information with the enterprise asset information. Based on the comparison result, the vulnerability analysis module 52 will determine whether the vulnerability intelligence information corresponding to the vulnerability intelligence fusion information is a threatening vulnerability information.
[0099] In one embodiment, such as Figure 6 As shown, the threat intelligence information processing device 50 also includes a model training module 55 and an information crawling module 56. The information crawling module 56 uses web crawling technology to crawl and process information published on target websites to obtain vulnerability intelligence information and event intelligence information.
[0100] The model training module 55 annotates the historical event intelligence fusion information in the historical event information set based on annotation rules to determine the tags of the historical event intelligence fusion information; it then performs word segmentation on the historical event intelligence fusion information to generate keywords. The model training module 55 generates word vectors for the keywords, and based on the word vectors of all keywords, it generates word vectors for the historical event intelligence fusion information; finally, the model training module 55 generates event samples based on the word vectors and tags of the historical event intelligence fusion information, and uses these event samples to train the event prediction model.
[0101] In one embodiment, the model training module 55 divides all event samples into a training set, a validation set, and a test set. It uses the event samples in the training set to train the event prediction model, and uses the event samples in the validation set and the test set to validate and test the trained event prediction model, respectively.
[0102] The event prediction model includes convolutional layers, pooling layers, and fully connected layers. The model training module 55 inputs the word vectors of the event samples into the convolutional layer for convolutional operations to obtain a feature set. The model training module 55 inputs the feature set into the pooling layer to obtain the feature vectors after pooling. The model training module 55 inputs the feature vectors into the fully connected layer and generates industry threat event category information through the softmax activation function. Based on the industry threat event category information and the labels of the event samples, the model training module 55 adjusts the event prediction model.
[0103] The model training module 55 sets labels for industry threat event information, generates new event samples based on word vectors and labels of industry threat event information, and uses them to retrain the event prediction model.
[0104] In one embodiment, such as Figure 7 As shown, threat intelligence information processing may include a memory 701, a processor 702, a communication interface 703, and a bus 704. The memory 701 is used to store instructions, and the processor 702 is coupled to the memory 701. The processor 702 is configured to execute the aforementioned threat intelligence information processing method based on the instructions stored in the memory 701.
[0105] The memory 701 can be high-speed RAM, non-volatile memory, or a memory array. The memory 701 may also be divided into blocks, and these blocks can be combined into virtual volumes according to certain rules. The processor 702 can be a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the threat intelligence information processing method disclosed herein.
[0106] In one embodiment, this disclosure provides a computer-readable storage medium storing computer instructions that, when executed by a processor, implement the method as described in any of the above embodiments.
[0107] Computer-readable storage media may take the form of any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may, for example, include, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatuses, or devices, or any combination thereof. More specific examples (not an exhaustive list) of readable storage media may include: electrical connections having one or more wires, portable disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0108] Embodiments of this disclosure may also be computer program products comprising computer program instructions that, when executed by a processor, cause the processor to perform the steps of the methods according to various embodiments of this disclosure as described in the "Exemplary Methods" section above.
[0109] The threat intelligence information processing method, apparatus, and storage medium in the above embodiments generate vulnerability intelligence fusion information and event intelligence fusion information. Based on the attribute information and asset information in the vulnerability intelligence fusion information, they determine whether it is threat vulnerability information. They then use an event prediction model to process the event intelligence fusion information to determine whether it is industry threat event information, and then perform security processing. This can improve the accuracy of threat intelligence information identification, reduce the occurrence of missed threat intelligence and false positives of invalid threat intelligence, reduce the response time of security operations personnel, improve network security protection capabilities, reduce operating costs, and improve the user experience.
[0110] The basic principles of this disclosure have been described above with reference to specific embodiments. However, it should be noted that the advantages, benefits, and effects mentioned in this disclosure are merely examples and not limitations, and should not be considered as essential features of each embodiment of this disclosure. Furthermore, the specific details disclosed above are for illustrative and facilitative purposes only, and are not limitations. These details do not limit the scope of this disclosure to the necessity of employing the aforementioned specific details for implementation.
[0111] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For system embodiments, since they largely correspond to method embodiments, the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.
[0112] The block diagrams of devices, apparatuses, devices, and systems disclosed herein are merely illustrative examples and are not intended to require or imply that they must be connected, arranged, or configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, devices, and systems can be connected, arranged, and configured in any manner. Words such as “comprising,” “including,” “having,” etc., are open-ended terms meaning “including but not limited to,” and are used interchangeably with them. The terms “or” and “and” as used herein refer to the terms “and / or,” and are used interchangeably with them unless the context clearly indicates otherwise. The term “such as” as used herein refers to the phrase “such as but not limited to,” and is used interchangeably with it.
[0113] It should also be noted that in the apparatus, devices, and methods of this disclosure, the components or steps can be disassembled and / or recombined. These disassemblies and / or recombinations should be considered as equivalent solutions to this disclosure.
[0114] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use this disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects without departing from the scope of this disclosure. Therefore, this disclosure is not intended to be limited to the aspects shown herein, but rather to be carried out within the widest scope consistent with the principles and novel features disclosed herein.
[0115] The above description has been given for illustrative and descriptive purposes. Furthermore, this description is not intended to limit the embodiments of this disclosure to the forms disclosed herein. Although several exemplary aspects and embodiments have been discussed above, those skilled in the art will understand that the above embodiments are illustrative only and do not limit the scope of this disclosure. Those skilled in the art will understand that the above embodiments can be combined, modified, or replaced without departing from the scope and spirit of this disclosure.
Claims
1. A method for processing threat intelligence information, comprising: Vulnerability intelligence information and event intelligence information are fused separately to generate fused vulnerability intelligence information and fused event intelligence information. Extract attribute information from the vulnerability intelligence fusion information, and determine whether the vulnerability intelligence information corresponding to the vulnerability intelligence fusion information is a threat vulnerability information based on the attribute information and asset information; The asset information includes component concern information and enterprise asset information. Determining whether the vulnerability intelligence information corresponding to the vulnerability intelligence fusion information is threat vulnerability information includes: The attribute information is compared with the component attention information, and based on the comparison result, it is determined whether the vulnerability intelligence information corresponding to the vulnerability intelligence fusion information is the threat vulnerability information; if it is determined that the vulnerability intelligence information corresponding to the vulnerability intelligence fusion information is not the threat vulnerability information, the attribute information is compared with the enterprise asset information, and based on the comparison result, it is determined whether the vulnerability intelligence information corresponding to the vulnerability intelligence fusion information is the threat vulnerability information. The trained event prediction model is used to process the event intelligence fusion information to determine whether the event intelligence information corresponding to the event intelligence fusion information is an industry threat event information; The aforementioned threat vulnerability information and industry threat event information are subject to security processing; The method further includes the following steps before processing the fused event intelligence information using a trained event prediction model: The historical event intelligence fusion information in the historical event information set is labeled according to the labeling rules to determine the tags of the historical event intelligence fusion information; the historical event intelligence fusion information is segmented into words to generate keywords; word vectors of the keywords are generated, and word vectors of the historical event intelligence fusion information are generated based on the word vectors of all the keywords; event samples are generated based on the word vectors of the historical event intelligence fusion information and the tags; and the event samples are used to train the event prediction model.
2. The method as described in claim 1, wherein extracting attribute information from the vulnerability intelligence fusion information includes: The vulnerability intelligence fusion information is processed using a trained named entity recognition model to obtain the attribute information of the vulnerability intelligence fusion information; The attribute information includes: attributes and corresponding attribute values.
3. The method as described in claim 2, wherein, The named entity recognition model includes: a Bi-LSTM neural network model; The attributes include: vulnerability type, vulnerability number, affected components, affected versions, and solutions.
4. The method as described in claim 1, wherein training the event prediction model using the event samples comprises: All the event samples were divided into a training set, a validation set, and a test set; The event prediction model is trained using event samples from the training set; The trained event prediction model is validated and tested using event samples from the validation set and the test set, respectively.
5. The method of claim 1, wherein, The event prediction model includes: convolutional layers, pooling layers, and fully connected layers; the training process of the event prediction model using the event samples includes: The word vectors of the event samples are input into the convolutional layer for convolution operation to obtain the feature set; The feature set is input into the pooling layer to obtain the feature vector after pooling. The feature vector is input into the fully connected layer, and industry threat event category information is generated through the activation function. The event prediction model is adjusted based on industry threat event category information and the labels of the event samples.
6. The method of claim 2, further comprising: Set tags for the industry threat event information; New event samples are generated based on the word vectors and tags of the industry threat event information, which are then used to retrain the event prediction model.
7. The method of claim 1, wherein, The security processing of the threat vulnerability information and the industry threat event information includes: The threat vulnerability information and the industry threat event information are notified to the target personnel so that the target personnel can determine whether the threat vulnerability information and the industry threat event information need to be given an early warning. The methods for notifying the target personnel include: sending emails, and displaying the threat vulnerability information and the industry threat event information in an information platform.
8. The method of claim 1, wherein, The process of fusing vulnerability intelligence information and event intelligence information includes: The vulnerability intelligence information and event intelligence information are fused together using a text deduplication algorithm.
9. The method according to any one of claims 1 to 8, further comprising: Web crawling technology is used to crawl and process the information published on the target website to obtain the vulnerability intelligence information and the event intelligence information.
10. A threat intelligence information processing device, comprising: The fusion processing module is used to fuse vulnerability intelligence information and event intelligence information separately to generate fused vulnerability intelligence information and fused event intelligence information. The vulnerability analysis module is used to extract attribute information from the vulnerability intelligence fusion information, and determine whether the vulnerability intelligence information corresponding to the vulnerability intelligence fusion information is a threat vulnerability information based on the attribute information and asset information. The asset information includes component concern information and enterprise asset information. The vulnerability analysis module is specifically used to compare the attribute information with the component concern information, and based on the comparison result, determine whether the vulnerability intelligence information corresponding to the vulnerability intelligence fusion information is the threat vulnerability information. If it is determined that the vulnerability intelligence information corresponding to the vulnerability intelligence fusion information is not the threat vulnerability information, the module compares the attribute information with the enterprise asset information, and based on the comparison result, determines whether the vulnerability intelligence information corresponding to the vulnerability intelligence fusion information is the threat vulnerability information. The event analysis module is used to process the event intelligence fusion information using a trained event prediction model to determine whether the event intelligence information corresponding to the event intelligence fusion information is an industry threat event information. The security processing module is used to perform security processing on the threat vulnerability information and the industry threat event information; The model training method is used to annotate historical event intelligence fusion information in a historical event information set based on annotation rules before processing the event intelligence fusion information using a trained event prediction model, thereby determining the tags of the historical event intelligence fusion information; performing word segmentation on the historical event intelligence fusion information to generate keywords; generating word vectors for the keywords; generating word vectors for the historical event intelligence fusion information based on the word vectors of all the keywords; generating event samples based on the word vectors and tags of the historical event intelligence fusion information; and using the event samples to train the event prediction model.
11. A threat intelligence information processing device, comprising: Memory; And a processor coupled to the memory, the processor being configured to perform the method as described in any one of claims 1 to 9 based on instructions stored in the memory.
12. A computer-readable storage medium storing computer instructions that are executed by a processor according to any one of claims 1 to 9.
Citation Information
Patent Citations
Power grid intranet security management and vulnerability automatic verification method and system
CN111143834A
Data deduplication method and device, storage medium and electronic equipment
CN115344563A
Monitoring alarm event identification method based on convolutional neural network model
CN115358369A
Network security named entity identification method based on threat intelligence
CN116611436A