A method, device, electronic device, and storage medium for threat intelligence production

By analyzing and analyzing the log data on the enterprise side, vector-level threat intelligence is generated, which solves the problem that log data cannot be effectively utilized in the existing technology, and improves the production efficiency and security defense capabilities of threat intelligence.

CN117544367BActive Publication Date: 2025-06-10BEIJING THREATBOOK TECHNOLOGY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202311532827.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-11-16
Publication Date
2025-06-10
Estimated Expiration
2043-11-16

AI Technical Summary

Technical Problem

The existing technology relies on the manufacturer's side to issue initial vector-level threat intelligence, resulting in the log data on the enterprise side being unable to be effectively utilized, and the threat intelligence is relatively limited and it is impossible to broaden the enterprise's local intelligence database.

Method used

By obtaining the user's log data, parsing the log data to obtain the threat intelligence primary key, obtaining the aggregated list and aggregated data based on the primary key, and conducting confidence analysis to generate vector-level threat intelligence.

Benefits of technology

Mass production of vector-level threat intelligence has been achieved, the production efficiency of threat intelligence has been improved, and users have helped build a more complete security defense system, reducing the occurrence of network security problems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117544367B_ABST
    Figure CN117544367B_ABST
Patent Text Reader

Abstract

An embodiment of the present application provides a method, apparatus, electronic device, and storage medium for producing threat intelligence. Among them, the method includes: obtaining log data of a user; parsing the log data to obtain a threat intelligence primary key; obtaining an aggregation list according to the threat intelligence primary key; obtaining aggregation data corresponding to the threat intelligence primary key in the aggregation list; performing credibility analysis on the aggregation data to obtain threat intelligence. Implementing the embodiments of the present application can batch-produce vector-level threat intelligence, improve the production efficiency of threat intelligence, provide assistance for the maintenance of network security, reduce the occurrence of network security problems, avoid risks, and help users build a more perfect security defense system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology. Specifically, it relates to a method, device, electronic device and storage medium for generating threat intelligence. Background Art

[0002] With the development of the Internet, network security issues have become more prominent. Protecting customer privacy and the security of company assets is crucial. Threat intelligence is an important tool for avoiding risks and protecting network security. It can provide enterprises with information about threats and hazards related to security issues and help them make security operation decisions.

[0003] In the prior art, through the access of various security log data, the manufacturer side issues initial vector-level threat intelligence and deploys corresponding defense strategies to the analysis cluster on the enterprise side to generate vector-level threat intelligence, and finally forms a complete network security defense system for the enterprise environment.

[0004] However, since the prior art needs to rely on the manufacturer side to issue initial vector-level threat intelligence, the following problems will occur: The log data associated with the threat intelligence on the enterprise side will not be utilized, wasting a large amount of log data; such threat intelligence is relatively limited and cannot expand the enterprise's local intelligence database. Summary of the Invention

[0005] The purpose of the embodiments of this application is to provide a method, device, electronic device and storage medium for generating threat intelligence, which can batch generate vector-level threat intelligence, improve the production efficiency of threat intelligence, provide help for the maintenance of network security, reduce the occurrence of network security problems, avoid risks, and help users build a more perfect security defense system.

[0006] In a first aspect, the embodiments of this application provide a method for generating threat intelligence, the method includes:

[0007] Obtain the log data of the user;

[0008] Parse the log data to obtain the threat intelligence primary key;

[0009] Obtain an aggregation list according to the threat intelligence primary key;

[0010] Obtain the aggregation data corresponding to the threat intelligence primary key in the aggregation list;

[0011] Perform credibility analysis on the aggregation data to obtain threat intelligence.

[0012] In the above implementation process, parsing the log data to obtain the threat intelligence primary key, and then performing credibility analysis on the aggregated data corresponding to the threat intelligence primary key can achieve batch production of vector-level threat intelligence, improve the production efficiency of threat intelligence, help maintain network security, reduce the occurrence of network security problems, avoid risks, and help users build a more perfect security defense system.

[0013] Further, the step of obtaining the aggregation list according to the threat intelligence primary key includes:

[0014] Caching the threat intelligence primary key to obtain a cache list;

[0015] Performing data collision between the threat intelligence primary key and the threat intelligence in the threat intelligence list to obtain a collision list;

[0016] Performing data aggregation on the cache list or the collision list to obtain the aggregation list.

[0017] In the above implementation process, colliding the threat intelligence primary key with the threat intelligence list can achieve the expansion of threat intelligence, so that the collision list contains more threat intelligence primary keys, expanding the scope of the produced threat intelligence and providing more guarantees for network security.

[0018] Further, the step of performing data collision between the threat intelligence primary key and the threat intelligence in the threat intelligence list to obtain a collision list includes:

[0019] Matching the threat intelligence primary key with the threat intelligence in the threat intelligence list;

[0020] If the threat intelligence primary key matches the threat intelligence in the threat intelligence list, extracting the first threat intelligence information that is matched;

[0021] Generating the collision list according to the first threat intelligence information.

[0022] In the above implementation process, matching the threat intelligence primary key with the threat intelligence list and adding the matched threat intelligence in the threat intelligence list to the collision list can expand the production scope of threat intelligence and improve the production efficiency.

[0023] Further, the step of performing data aggregation on the cache list or the collision list to obtain the aggregation list includes:

[0024] Obtaining the second threat intelligence information;

[0025] Judging the number of times the second threat intelligence information appears in the cache list or the collision list;

[0026] If the number of occurrences of the second threat intelligence information in the cache list or the collision list is greater than or equal to a preset number, aggregate the second threat intelligence information to obtain the aggregated second threat intelligence information;

[0027] Generate the aggregation list according to the aggregated second threat intelligence information.

[0028] In the above implementation process, aggregating the data in the cache list or the collision list can reduce the occupied space of the data in the aggregation list, prevent data redundancy, and improve the utilization rate of the aggregation list.

[0029] Further, the step of performing credibility analysis on the aggregated data to obtain threat intelligence includes:

[0030] Obtain multiple production condition groups;

[0031] Perform credibility analysis on the aggregated data and the multiple production condition groups to obtain the credibility of the aggregated data;

[0032] Determine whether the credibility of the aggregated data meets a certain production condition group;

[0033] If so, use the threat intelligence information corresponding to the aggregated data as the threat intelligence;

[0034] If not, add the threat intelligence information corresponding to the aggregated data to the list of threat intelligence to be produced.

[0035] In the above implementation process, dividing the production conditions into multiple production condition groups and then performing credibility analysis on the aggregated data and multiple production condition groups respectively can refine the credibility analysis, thereby improving the reliability of the credibility analysis.

[0036] Further, the step of obtaining multiple production condition groups includes:

[0037] Configure the production conditions required for producing threat intelligence, where the production conditions include active time attack days, historical attack count, active time attack count, historical attack organization count, historical attack system count, active time attack organization count, active time attack system count, active time attack target count, geographical location, threat level, and historical attack days;

[0038] Divide the production conditions according to credibility to obtain multiple production condition groups with different credibility levels.

[0039] In the above implementation process, dividing the production conditions can combine production condition groups with different credibility levels, facilitating obtaining the analysis result after credibility analysis and reducing the error in the credibility analysis process.

[0040] Further, the step of performing credibility analysis on the aggregated data and the multiple production condition groups to obtain the credibility of the aggregated data includes:

[0041] Performing credibility analysis on the aggregated data and the multiple production condition groups respectively to obtain multiple credibility analysis results;

[0042] Determining the credibility with a compliant analysis result among the multiple credibility analysis results as the credibility of the aggregated data.

[0043] In the above implementation process, determining the credibility of the aggregated data based on multiple credibility analysis results can improve the accuracy of the credibility, make the aggregated data more precise, and improve the usability and practicality of the aggregated data.

[0044] Further, the step of performing credibility analysis on the aggregated data and each of the multiple production condition groups respectively to obtain multiple credibility analysis results includes:

[0045] Performing credibility analysis on the aggregated data and each production condition in each production condition group respectively to obtain a production condition analysis result corresponding to each production condition;

[0046] Obtaining a credibility analysis result of each production condition group corresponding to each production condition based on the production condition analysis result corresponding to each production condition;

[0047] Determining the credibility analysis results of the multiple production condition groups as the multiple credibility analysis results.

[0048] In the above implementation process, performing credibility analysis on the aggregated data and each production condition respectively ensures that each production condition is matched with the aggregated data, avoids omission of the aggregated data, and improves the effectiveness of the credibility analysis result.

[0049] Further, the step of determining the credibility with a compliant analysis result among the multiple credibility analysis results as the credibility of the aggregated data includes:

[0050] Sorting the credibilities with compliant analysis results among the multiple credibility analysis results according to grades;

[0051] Determining the credibility with the highest grade among the sorted credibilities as the credibility of the aggregated data.

[0052] In the above implementation process, sorting the credibilities according to grades can quickly select the credibility with the highest grade, effectively ensure the usability of the aggregated data, and improve the efficiency of threat intelligence production.

[0053] Second aspect, an embodiment of the present application further provides a threat intelligence production device, the device includes:

[0054] An acquisition module, configured to acquire log data of a user;

[0055] An analysis module, configured to analyze the log data to obtain a threat intelligence primary key;

[0056] An aggregation module, configured to obtain an aggregation list according to the threat intelligence primary key;

[0057] A data acquisition module, configured to acquire aggregation data corresponding to the threat intelligence primary key in the aggregation list;

[0058] A credibility analysis module, configured to perform credibility analysis on the aggregation data to obtain threat intelligence.

[0059] In the above implementation process, by analyzing the log data to obtain the threat intelligence primary key and then performing credibility analysis on the aggregation data corresponding to the threat intelligence primary key, it is possible to realize batch production of vector-level threat intelligence, improve the production efficiency of threat intelligence, provide help for the maintenance of network security, reduce the occurrence of network security problems, avoid risks, and help users build a more perfect security defense system.

[0060] Third aspect, an electronic device provided by an embodiment of the present application includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, and when the processor executes the computer program, the steps of the method described in any item of the first aspect are implemented.

[0061] Fourth aspect, a computer-readable storage medium provided by an embodiment of the present application, instructions are stored on the storage medium, and when the instructions run on a computer, the computer is caused to execute the method described in any item of the first aspect.

[0062] Fifth aspect, a computer program product provided by an embodiment of the present application, when the computer program product runs on a computer, the computer is caused to execute the method described in any item of the first aspect.

[0063] Other features and advantages of the present disclosure will be described in the subsequent description, or, some features and advantages can be inferred from the description or determined without doubt, or can be known by implementing the above technologies of the present disclosure.

[0064] And can be implemented according to the content of the description. The following will be described in detail with reference to the preferred embodiments of the present application and the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0065] To more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the accompanying drawings required for the embodiments of the present application. It should be understood that the following drawings only show some embodiments of the present application and should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.

[0066] Figure 1 It is a schematic flowchart of the method for producing threat intelligence provided by the embodiment of the present application;

[0067] Figure 2 It is a schematic diagram of the structural composition of the threat intelligence production device provided by the embodiment of the present application;

[0068] Figure 3 It is a schematic diagram of the structural composition of the electronic device provided by the embodiment of the present application. Specific Embodiments

[0069] The following will describe the technical solutions in the embodiments of the present application in conjunction with the accompanying drawings in the embodiments of the present application.

[0070] It should be noted that similar reference numerals and letters represent similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present application, terms such as "first" and "second" are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.

[0071] The following will further describe the specific embodiments of the present application in detail in conjunction with the drawings and embodiments. The following embodiments are used to illustrate the present application but do not limit the scope of the present application.

[0072] Embodiment 1

[0073] Figure 1 It is a schematic flowchart of the method for producing threat intelligence provided by the embodiment of the present application. As Figure 1 shown, the method includes:

[0074] S1. Obtain the log data of the user;

[0075] S2. Parse the log data to obtain the threat intelligence primary key;

[0076] S3. Obtain the aggregation list according to the threat intelligence primary key;

[0077] S4. Obtain the aggregation data corresponding to the threat intelligence primary key in the aggregation list;

[0078] S5. Perform credibility analysis on the aggregation data to obtain the threat intelligence.

[0079] In the above implementation process, the threat intelligence primary key is obtained by parsing the log data, and then the credibility analysis is performed on the aggregated data corresponding to the threat intelligence primary key, so as to realize the batch production of vector-level threat intelligence, improve the production efficiency of threat intelligence, provide help for the maintenance of network security, reduce the occurrence of network security problems, avoid risks, and help users build a more perfect security defense system.

[0080] The embodiment of the present application proposes a method for threat intelligence production, which can enrich and produce intelligence that has no association with the manufacturer side, broaden the threat intelligence library within the enterprise, make full use of the enterprise's massive log data, and does not rely on the manufacturer side intelligence. Only by configuring relevant intelligence production conditions and accessing the logs of security products, threat intelligence that meets the enterprise's requirements can be produced, thereby enriching the local threat intelligence library and helping enterprise security practitioners make better security operation decisions.

[0081] In S2, after the log data is accessed, the system parses and processes the log data to obtain the threat intelligence primary key.

[0082] Further, S3 includes:

[0083] Cache the threat intelligence primary key to obtain a cache list;

[0084] Perform data collision between the threat intelligence primary key and the threat intelligence in the threat intelligence list to obtain a collision list;

[0085] Perform data aggregation on the cache list or the collision list to obtain an aggregation list.

[0086] In the above implementation process, colliding the threat intelligence primary key with the threat intelligence list can realize the expansion of threat intelligence, so that the collision list contains more threat intelligence primary keys, expanding the scope of the produced threat intelligence and providing more guarantees for network security.

[0087] The threat intelligence list contains manufacturer-side intelligence and is stored in a storage medium. Query the manufacturer-side intelligence that has been cached in the system memory according to the threat intelligence primary key. If intelligence is collided during the query process, aggregate after supplementing the intelligence. Otherwise, aggregate after supplementing the geographical location according to the manufacturer-side data. At the same time, cache the threat intelligence primary key in the cache list for subsequent production use.

[0088] Further, the step of performing data collision between the threat intelligence primary key and the threat intelligence in the threat intelligence list to obtain a collision list includes:

[0089] Match the threat intelligence primary key with the threat intelligence in the threat intelligence list;

[0090] If the threat intelligence primary key matches the threat intelligence in the threat intelligence list, extract the first threat intelligence information that is matched;

[0091] Generate a collision list based on the first threat intelligence information.

[0092] In the above implementation process, by matching the threat intelligence primary key with the threat intelligence list and adding the threat intelligence matched in the threat intelligence list to the collision list, the production scope of threat intelligence can be expanded and the production efficiency can be improved.

[0093] If the manufacturer-side intelligence data is queried in the threat intelligence list, supplement the latest manufacturer-side intelligence data (the first threat intelligence information) to the threat intelligence primary key, such as geographical location, threat level, hacker organization, and virus family, for later production use.

[0094] Further, the steps of performing data aggregation on the cache list or the collision list to obtain an aggregation list include:

[0095] Obtain the second threat intelligence information;

[0096] Judge the number of times the second threat intelligence information appears in the cache list or the collision list;

[0097] If the number of times the second threat intelligence information appears in the cache list or the collision list is greater than or equal to the preset number of times, perform data aggregation on the second threat intelligence information to obtain the aggregated second threat intelligence information;

[0098] Generate an aggregation list based on the aggregated second threat intelligence information.

[0099] In the above implementation process, performing data aggregation on the data in the cache list or the collision list can reduce the occupied space of the data in the aggregation list, prevent data redundancy, and improve the utilization rate of the aggregation list.

[0100] The aggregation of log data is performed with the threat intelligence primary key as the unique key. The specific aggregation method is to aggregate the same log data corresponding to the threat intelligence primary key (the second threat intelligence information can be a certain threat intelligence primary key) for each day into one piece of data. Among them, the first attack time is taken as the time when the latest piece of log data is generated on the same day, and the last attack time is taken as the time when the last piece of log data is generated on the same day. At the same time, for each piece of aggregated data, the attack count is incremented by 1, representing the total number of attacks on the same day. The number of attack targets, attack systems, and attack organizations are also obtained from the log data, and the counts are respectively statistically based on the name as the unique key. For example, "System 1 - 5 times" and "System 2 - 3 times" indicate that System 1 was attacked 5 times and System 2 was attacked 3 times on the same day.

[0101] The specific fields involved in aggregation are: the first attack time, the most recent attack time, the number of attacks, the number of attack targets, the number of attacking organizations, the number of attacked systems, the attack type, the geographical location, the threat level, the hacker organization, and the virus family.

[0102] In S4, first, obtain the threat intelligence primary key, and try to obtain the integrated data corresponding to this primary key from the cache list. If it cannot be queried, query all the data aggregated by day according to the threat intelligence primary key. After obtaining the aggregated data of this primary key, according to the active time in the production conditions, organize and merge the aggregated data into one piece of data. According to the active time configuration, organize the number of attacks, the number of attack days, the number of attacking organizations, the number of attack targets, and the number of attacked systems of this threat intelligence within the active cycle, and then add it to the cache. This piece of data will be used for the judgment of subsequent production conditions.

[0103] Further, S5 includes:

[0104] Obtain multiple production condition groups;

[0105] Conduct credibility analysis on the aggregated data and multiple production condition groups to obtain the credibility of the aggregated data;

[0106] Judge whether the credibility of the aggregated data meets a certain production condition group;

[0107] If so, regard the threat intelligence information corresponding to the aggregated data as threat intelligence;

[0108] If not, add the threat intelligence information corresponding to the aggregated data to the list of threat intelligence to be produced.

[0109] In the above implementation process, by dividing the production conditions into multiple production condition groups and then conducting credibility analysis on the aggregated data and multiple production condition groups respectively, the credibility analysis can be refined, thereby improving the reliability of the credibility analysis.

[0110] When the threat intelligence to be produced meets any one of the production condition groups, the credibility of the intelligence will be set to the credibility corresponding to this production condition group, indicating that the intelligence meets this production condition group.

[0111] Further, the step of obtaining multiple production condition groups includes:

[0112] Configure the production conditions required for producing threat intelligence. The production conditions include active time, attack days, historical attack count, active time attack count, historical attacking organization count, historical attacked system count, active time attacking organization count, active time attacked system count, active time attack target count, geographical location, threat level, and historical attack days;

[0113] Divide the production conditions according to the credibility to obtain multiple production condition groups with different credibility levels.

[0114] In the above implementation process, dividing the production conditions can group production conditions with different credibilities together, facilitating the obtaining of analysis results after credibility analysis and reducing errors in the credibility analysis process.

[0115] According to the configuration of the production conditions, determine whether this piece of threat intelligence meets the production requirements. The specific fields for judgment include: active time attack days, historical attack count, active time attack count, historical attack organization count, historical attack system count, active time attack organization count, active time attack system count, active time attack target count, geographical location, threat level, historical attack days.

[0116] Each piece of intelligence needs to set a credibility level, which is divided into three levels: high, medium, and low, corresponding to different production condition groups.

[0117] Furthermore, the steps of performing credibility analysis on the aggregated data and multiple production condition groups to obtain the credibility of the aggregated data include:

[0118] Perform credibility analysis on the aggregated data and multiple production condition groups respectively to obtain multiple credibility analysis results;

[0119] Determine the credibility of the aggregated data as the credibility of the analysis results that are in line among the multiple credibility analysis results.

[0120] In the above implementation process, determining the credibility of the aggregated data based on multiple credibility analysis results can improve the accuracy of the credibility, make the aggregated data more precise, and improve the availability and practicality of the aggregated data.

[0121] Each production condition group contains multiple production conditions. Only when the multiple credibility analysis results corresponding to the multiple production conditions are all in line can the credibility of the production condition group be determined as the corresponding high, medium, or low level.

[0122] Furthermore, the steps of performing credibility analysis on the aggregated data and multiple production condition groups respectively to obtain multiple credibility analysis results include:

[0123] Perform credibility analysis on the aggregated data and each production condition in each production condition group respectively to obtain the production condition analysis results corresponding to each production condition;

[0124] Obtain the credibility analysis results of the production condition groups corresponding to each production condition based on the production condition analysis results corresponding to each production condition;

[0125] Determine the credibility analysis results of multiple production condition groups as multiple credibility analysis results.

[0126] In the above implementation process, perform credibility analysis on the aggregated data with each production condition respectively to ensure that each production condition is matched with the aggregated data, avoid omission of the aggregated data, and improve the effectiveness of the credibility analysis results.

[0127] Further, the step of determining the credibility of the analysis result as compliant among multiple credibility analysis results as the credibility of the aggregated data includes:

[0128] Sort the credibility of the analysis result as compliant among multiple credibility analysis results according to the level;

[0129] Determine the credibility with the highest level among the sorted credibility as the credibility of the aggregated data.

[0130] In the above implementation process, sorting the credibility according to the level can quickly select the credibility with the highest level, effectively ensure the availability of the aggregated data, and improve the efficiency of threat intelligence production.

[0131] Since the aggregated data may conform to the credibility of multiple production condition groups, therefore, after obtaining the credibility of the compliant production condition groups, it is necessary to sort the credibility according to the level and use the credibility with the highest level as the credibility of the aggregated data.

[0132] Finally, determine whether the threat intelligence corresponding to the aggregated data is qualified. Specifically, it is necessary to determine whether it contains threat level, credibility field, and whether the threat intelligence primary key is a correct IP address. If all are compliant, the threat intelligence corresponding to the aggregated data is qualified, and the qualified threat intelligence will be produced subsequently.

[0133] Optionally, if the threat intelligence to be produced conforms to the production conditions and the manufacturer-side intelligence contains this threat intelligence, then supplement the manufacturer-side intelligence to the produced threat intelligence to provide multi-angle threat intelligence information for the enterprise.

[0134] Embodiment 2

[0135] To execute the method corresponding to the above Embodiment 1 to achieve the corresponding functions and technical effects, the following provides a threat intelligence production device, as Figure 2 shown. The device includes:

[0136] Acquisition module 1, used to acquire the log data of the user;

[0137] Parsing module 2, used to parse the log data to obtain the threat intelligence primary key;

[0138] An aggregation module 3, configured to obtain an aggregation list according to a threat intelligence primary key;

[0139] A data acquisition module 4, configured to obtain aggregated data corresponding to the threat intelligence primary key in the aggregation list;

[0140] A credibility analysis module 5, configured to perform a credibility analysis on the aggregated data to obtain threat intelligence.

[0141] In the above implementation process, by parsing the log data to obtain the threat intelligence primary key and then performing a credibility analysis on the aggregated data corresponding to the threat intelligence primary key, it is possible to achieve batch production of vector-level threat intelligence, improve the production efficiency of threat intelligence, provide assistance for the maintenance of network security, reduce the occurrence of network security problems, avoid risks, and help users build a more perfect security defense system.

[0142] Furthermore, the aggregation module 3 is further configured to:

[0143] Cache the threat intelligence primary key to obtain a cache list;

[0144] Perform data collision between the threat intelligence primary key and the threat intelligence in the threat intelligence list to obtain a collision list;

[0145] Perform data aggregation on the cache list or the collision list to obtain an aggregation list.

[0146] In the above implementation process, by performing a collision between the threat intelligence primary key and the threat intelligence list, it is possible to expand the threat intelligence, so that the collision list contains more threat intelligence primary keys, expanding the scope of the produced threat intelligence and providing more guarantees for network security.

[0147] Furthermore, the aggregation module 3 is further configured to:

[0148] Match the threat intelligence primary key with the threat intelligence in the threat intelligence list;

[0149] If the threat intelligence primary key matches the threat intelligence in the threat intelligence list, extract the first threat intelligence information that is matched;

[0150] Generate a collision list according to the first threat intelligence information.

[0151] In the above implementation process, by matching the threat intelligence primary key with the threat intelligence list and adding the matched threat intelligence in the threat intelligence list to the collision list, it is possible to expand the production scope of threat intelligence and improve the production efficiency.

[0152] Furthermore, the aggregation module 3 is further configured to:

[0153] Obtain second threat intelligence information;

[0154] Determine the number of times the second threat intelligence information appears in the cache list or the collision list;

[0155] If the number of times the second threat intelligence information appears in the cache list or the collision list is greater than or equal to the preset number of times, aggregate the second threat intelligence information to obtain the aggregated second threat intelligence information;

[0156] Generate an aggregation list based on the aggregated second threat intelligence information.

[0157] In the above implementation process, aggregating the data in the cache list or the collision list can reduce the occupied space of the data in the aggregation list, prevent data redundancy, and improve the utilization rate of the aggregation list.

[0158] Furthermore, the credibility analysis module 5 is also used for:

[0159] Obtain multiple production condition groups;

[0160] Perform credibility analysis on the aggregated data and multiple production condition groups to obtain the credibility of the aggregated data;

[0161] Determine whether the credibility of the aggregated data meets a certain production condition group;

[0162] If so, regard the threat intelligence information corresponding to the aggregated data as threat intelligence;

[0163] If not, add the threat intelligence information corresponding to the aggregated data to the list of threat intelligence to be produced.

[0164] In the above implementation process, dividing the production conditions into multiple production condition groups and then performing credibility analysis on the aggregated data and multiple production condition groups respectively can refine the credibility analysis, thereby improving the reliability of the credibility analysis.

[0165] Furthermore, the credibility analysis module 5 is also used for:

[0166] Configure the production conditions required for producing threat intelligence. The production conditions include active time attack days, historical attack count, active time attack count, historical attack organization count, historical attack system count, active time attack organization count, active time attack system count, active time attack target count, geographical location, threat level, and historical attack days;

[0167] Divide the production conditions according to credibility to obtain multiple production condition groups with different credibility levels.

[0168] In the above implementation process, dividing the production conditions can combine production condition groups with different credibilities together, facilitating obtaining the analysis result after credibility analysis and reducing the error in the credibility analysis process.

[0169] Furthermore, the credibility analysis module 5 is also used for:

[0170] Performing credibility analysis on the aggregated data respectively with multiple production condition groups to obtain multiple credibility analysis results;

[0171] Determining the credibility of the aggregated data as the credibility that meets the criteria among the multiple credibility analysis results.

[0172] In the above implementation process, determining the credibility of the aggregated data according to multiple credibility analysis results can improve the accuracy of the credibility, make the aggregated data more precise, and improve the usability and practicality of the aggregated data.

[0173] Furthermore, the credibility analysis module 5 is also used for:

[0174] Performing credibility analysis on the aggregated data respectively with each production condition in each production condition group to obtain production condition analysis results corresponding to each production condition;

[0175] Obtaining credibility analysis results of the production condition groups corresponding to each production condition according to the production condition analysis results corresponding to each production condition;

[0176] Determining the credibility analysis results of multiple production condition groups as multiple credibility analysis results.

[0177] In the above implementation process, performing credibility analysis on the aggregated data respectively with each production condition ensures that each production condition is matched with the aggregated data, avoids omission of the aggregated data, and improves the effectiveness of the credibility analysis results.

[0178] Furthermore, the credibility analysis module 5 is also used for:

[0179] Sorting the credibility that meets the criteria among the multiple credibility analysis results according to levels;

[0180] Determining the credibility with the highest level among the sorted credibility as the credibility of the aggregated data.

[0181] In the above implementation process, sorting the credibility according to levels can quickly select the credibility with the highest level, effectively guarantee the usability of the aggregated data, and improve the efficiency of threat intelligence production.

[0182] The above-mentioned threat intelligence production device can implement the method of the first embodiment. The optional items in the first embodiment are also applicable to this embodiment and will not be elaborated here.

[0183] The remaining content of the embodiments of the present application can refer to the content of the first embodiment, and will not be repeated in this embodiment.

[0184] Embodiment 3

[0185] An embodiment of the present application provides an electronic device, including a memory and a processor. The memory is used to store a computer program, and the processor runs the computer program to enable the electronic device to execute the threat intelligence production method of Embodiment 1.

[0186] Optionally, the above electronic device may be a server.

[0187] Please refer to Figure 3 , Figure 3 , which is a schematic structural composition diagram of the electronic device provided by the embodiment of the present application. The electronic device may include a processor 31, a communication interface 32, a memory 33, and at least one communication bus 34. Among them, the communication bus 34 is used to realize the direct connection communication between these components. Among them, the communication interface 32 of the device in the embodiment of the present application is used to communicate with other node devices for signaling or data. The processor 31 may be an integrated circuit chip with signal processing capabilities.

[0188] The above-mentioned processor 31 may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or the processor 31 may also be any conventional processor, etc.

[0189] The memory 33 may be, but is not limited to, a random access memory (RAM), a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), etc. The memory 33 stores computer-readable instructions. When the computer-readable instructions are executed by the processor 31, the device can execute the above Figure 1 steps involved in the method embodiment.

[0190] Optionally, the electronic device may further include a storage controller and an input / output unit. Each component of the memory 33, the storage controller, the processor 31, the peripheral interface, and the input / output unit is electrically connected directly or indirectly to each other to achieve data transmission or interaction. For example, these components may be electrically connected to each other through one or more communication buses 34. The processor 31 is configured to execute an executable module stored in the memory 33, such as a software function module or a computer program included in the device.

[0191] The input / output unit is used to provide a user with the ability to create tasks and create an optional start period or a preset execution time for the task to achieve interaction between the user and the server. The input / output unit may be, but is not limited to, a mouse, a keyboard, etc.

[0192] It can be understood that Figure 3 the structure shown is only illustrative, and the electronic device may further include more or fewer components than those shown in Figure 3 or have a different configuration from that shown in Figure 3 . Figure 3 Each component shown in may be implemented using hardware, software, or a combination thereof.

[0193] In addition, an embodiment of the present application further provides a computer-readable storage medium storing a computer program, which when executed by a processor implements the method for generating threat intelligence in Embodiment 1.

[0194] An embodiment of the present application further provides a computer program product, which when running on a computer causes the computer to execute the method described in the method embodiment.

[0195] In several embodiments provided by the present application, it should be understood that the disclosed apparatus and method may also be implemented in other ways. The apparatus embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the drawings show the possible architectures, functions, and operations of apparatuses, methods, and computer program products according to multiple embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the module, program segment, or part of code includes one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based device for performing the specified functions or actions, or may be implemented by a combination of dedicated hardware and computer instructions.

[0196] In addition, each functional module in the various embodiments of the present application may be integrated together to form an independent part, or each module may exist alone, or two or more modules may be integrated to form an independent part.

[0197] If the above-mentioned function is implemented in the form of a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, ROM, RAM, magnetic disks, or optical discs that can store program codes.

[0198] The above are only the embodiments of the present application and are not used to limit the protection scope of the present application. For those skilled in the art, the present application may have various changes and modifications. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application. It should be noted that similar reference numerals and letters represent similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.

[0199] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by the present application, and all should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

[0200] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising said element.

Claims

1. A method for producing threat intelligence, characterized in that, the method includes: Obtain the log data of the user; Parse the log data to obtain a threat intelligence primary key; Obtain an aggregation list according to the threat intelligence primary key; Obtain the aggregation data corresponding to the threat intelligence primary key in the aggregation list; Perform credibility analysis on the aggregation data to obtain threat intelligence; The step of obtaining the aggregation list according to the threat intelligence primary key includes: Cache the threat intelligence primary key to obtain a cache list; Perform data collision between the threat intelligence primary key and the threat intelligence in the threat intelligence list to obtain a collision list; Perform data aggregation on the cache list or the collision list to obtain the aggregation list; The step of performing data collision between the threat intelligence primary key and the threat intelligence in the threat intelligence list to obtain a collision list includes: Match the threat intelligence primary key with the threat intelligence in the threat intelligence list; If the threat intelligence primary key matches the threat intelligence in the threat intelligence list, extract the first threat intelligence information that is matched; Generate the collision list according to the first threat intelligence information; The step of performing data aggregation on the cache list or the collision list to obtain the aggregation list includes: Obtain second threat intelligence information; Judge the number of times the second threat intelligence information appears in the cache list or the collision list; If the number of times the second threat intelligence information appears in the cache list or the collision list is greater than or equal to a preset number of times, perform data aggregation on the second threat intelligence information to obtain aggregated second threat intelligence information; Generate the aggregation list according to the aggregated second threat intelligence information; The second threat intelligence information is one of the threat intelligence primary keys, and the threat intelligence primary key includes geographical location, threat level, hacker organization, and virus family.

2. The method for producing threat intelligence according to claim 1, characterized in that, The step of performing credibility analysis on the aggregation data to obtain threat intelligence includes: Obtain a plurality of production condition groups; Perform credibility analysis on the aggregation data and the plurality of production condition groups to obtain the credibility of the aggregation data; Judge whether the credibility of the aggregation data conforms to a certain production condition group; If so, use the threat intelligence information corresponding to the aggregation data as the threat intelligence; If not, add the threat intelligence information corresponding to the aggregation data to the list of threat intelligence to be produced.

3. The method for producing threat intelligence according to claim 2, characterized in that, The step of obtaining a plurality of production condition groups includes: Configure the production conditions required for producing threat intelligence, and the production conditions include active time attack days, historical attack count, active time attack count, historical attack organization count, historical attack system count, active time attack organization count, active time attack system count, active time attack target count, geographical location, threat level, and historical attack days; Divide the production conditions according to credibility to obtain a plurality of production condition groups with different credibility levels.

4. The production method of threat intelligence according to claim 3, wherein, the step of performing credibility analysis on the aggregated data and the multiple production condition groups to obtain the credibility of the aggregated data includes: performing credibility analysis on the aggregated data and the multiple production condition groups respectively to obtain multiple credibility analysis results; determining the credibility with an analysis result of compliance among the multiple credibility analysis results as the credibility of the aggregated data.

5. The production method of threat intelligence according to claim 4, wherein, the step of performing credibility analysis on the aggregated data and the multiple production condition groups respectively to obtain multiple credibility analysis results includes: performing credibility analysis on the aggregated data and each production condition in each production condition group respectively to obtain a production condition analysis result corresponding to each production condition; obtaining a credibility analysis result of the production condition group corresponding to each production condition according to the production condition analysis result corresponding to each production condition; determining the credibility analysis results of the multiple production condition groups as the multiple credibility analysis results.

6. The production method of threat intelligence according to claim 4, wherein, the step of determining the credibility with an analysis result of compliance among the multiple credibility analysis results as the credibility of the aggregated data includes: sorting the credibility with an analysis result of compliance among the multiple credibility analysis results by level; determining the credibility with the highest level among the sorted credibility as the credibility of the aggregated data.

7. A production device for threat intelligence, wherein, the device includes: an acquisition module for acquiring log data of a user; a parsing module for parsing the log data to obtain a threat intelligence primary key; an aggregation module for obtaining an aggregation list according to the threat intelligence primary key; a data acquisition module for acquiring aggregated data corresponding to the threat intelligence primary key in the aggregation list; a credibility analysis module for performing credibility analysis on the aggregated data to obtain threat intelligence; the aggregation module is further configured to: cache the threat intelligence primary key to obtain a cache list; perform data collision on the threat intelligence primary key and the threat intelligence in the threat intelligence list to obtain a collision list; perform data aggregation on the cache list or the collision list to obtain the aggregation list; match the threat intelligence primary key with the threat intelligence in the threat intelligence list; if the threat intelligence primary key matches the threat intelligence in the threat intelligence list, extracting the first threat intelligence information that is matched; generating the collision list according to the first threat intelligence information; acquiring second threat intelligence information; judging the number of times the second threat intelligence information appears in the cache list or the collision list; if the number of times the second threat intelligence information appears in the cache list or the collision list is greater than or equal to a preset number of times, performing data aggregation on the second threat intelligence information to obtain aggregated second threat intelligence information; generating the aggregation list according to the aggregated second threat intelligence information; The second threat intelligence information is one of the threat intelligence primary keys, and the threat intelligence primary keys include geographical location, threat level, hacker organization, and virus family.

8. An electronic device, characterized in that it includes a memory and a processor, the memory is used to store a computer program, and the processor runs the computer program to enable the electronic device to execute the threat intelligence production method according to any one of claims 1 to 6.

9. A storage medium, characterized in that it stores a computer program, and when the computer program is executed by a processor, it implements the threat intelligence production method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Threat intelligence fused network traffic intrusion detection method and system

    CN112202818A