Threat intelligence-based security analysis methods, devices, electronic equipment, and media

By performing secondary collision and clustering of multiple real-time logs and threat intelligence, the problem of difficulty in detecting advanced long-term threat attacks in existing technologies has been solved, achieving higher accuracy and efficiency in security analysis.

CN118631557BActive Publication Date: 2026-01-06QI AN XIN TECHNOLOGY GROUP INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410841796.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-26
Publication Date
2026-01-06
Estimated Expiration
2044-06-26

AI Technical Summary

Technical Problem

Existing technologies struggle to detect covert attack behaviors by combining single logs with threat intelligence when facing advanced persistent threat (APT) attacks, leading to reduced accuracy in security analysis.

Method used

The system acquires a log chain to be analyzed, which consists of multiple real-time logs that have already been collided with threat intelligence. It then performs a secondary collision with the threat intelligence to generate secondary alert data. Finally, it clusters and aggregates threat intelligence from different security vendors to generate detailed alert data.

Benefits of technology

It improved the accuracy of security analysis, uncovered issues that could not be detected by a single log, enhanced the ability to detect covert attacks, and improved the efficiency and accuracy of security analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118631557B_ABST
    Figure CN118631557B_ABST
Patent Text Reader

Abstract

The application provides a threat intelligence-based security analysis method and device, electronic equipment and medium. The threat intelligence-based security analysis method comprises: acquiring a log chain to be analyzed, the log chain to be analyzed being composed of a plurality of real-time logs that have collided with threat intelligence; performing secondary collision between the log chain to be analyzed and the threat intelligence; and generating secondary alarm data based on corresponding content in the log chain to be analyzed and the threat intelligence that have successfully collided. After the plurality of real-time logs collide with the threat intelligence, the collided real-time logs are again collided with the threat intelligence. In this way, problems that cannot be found in the collision between a single log and the threat intelligence can be found, and alarm data that has not been found before can be output, thereby improving the accuracy of security analysis of logs based on threat intelligence.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cybersecurity technology, and in particular to a security analysis method, apparatus, electronic device, and medium based on threat intelligence. Background Technology

[0002] With the continuous development of computer technology, malicious actors use various network technologies to attack targets in order to steal their data and endanger their information security. Therefore, conducting security analysis on targets and protecting their information security has become particularly important.

[0003] Currently, security analysis of target objects primarily relies on analyzing their logs using threat intelligence. Specifically, network traffic probes are used to acquire the target object's logs, which are then compared with pre-acquired threat intelligence. If the comparison is successful—meaning the log content matches the information described in the threat intelligence—an alert is generated based on the match and sent to a security analyst for further analysis. If the comparison fails—meaning the log content does not match the threat intelligence—the log is considered to have no security issues, and no further security operations are performed. The process then continues with the next acquired log file, comparing it with threat intelligence.

[0004] However, for some long-term attacks, such as Advanced Persistent Threats (APTs), their attack behavior is relatively covert, making them difficult to detect through a single log-and-threat intelligence analysis. This results in the attack not being successfully analyzed, reducing the number of alerts and lowering the accuracy of security analysis. Summary of the Invention

[0005] The purpose of this application is to provide a security analysis method, apparatus, electronic device, and medium based on threat intelligence to improve the accuracy of security analysis.

[0006] To address the aforementioned technical problems, this application provides the following technical solutions:

[0007] The first aspect of this application provides a security analysis method based on threat intelligence. The method includes: acquiring a log chain to be analyzed, the log chain to be analyzed consisting of multiple real-time logs that have been collided with threat intelligence; performing a secondary collision between the log chain to be analyzed and the threat intelligence; and generating secondary alarm data based on the successfully collided log chain to be analyzed and the corresponding content in the threat intelligence.

[0008] Compared to existing technologies, the security analysis method based on threat intelligence provided in the first aspect of this application, after colliding multiple real-time logs with threat intelligence, then colliding these collated real-time logs together again with threat intelligence, can discover problems that cannot be found by colliding a single log with threat intelligence. That is, by the correlation between multiple real-time logs, security issues can be discovered, and previously undiscovered alarm data can be output, thereby improving the accuracy of security analysis of logs based on threat intelligence.

[0009] In some modified embodiments of the first aspect of this application, the step of obtaining the log chain to be analyzed includes: starting from the current moment, obtaining real-time logs that collided with the threat intelligence within a preset time period, and arranging the obtained logs in chronological order to obtain the log chain to be analyzed, wherein the preset time period is longer than the time interval between collisions between each real-time log and the threat intelligence.

[0010] By acquiring only real-time logs from a previous period for secondary collision detection, new alarms can be discovered through the correlation between multiple real-time logs, while the number of log collisions can be reduced, collision efficiency can be improved, and thus the efficiency of security analysis can be improved.

[0011] In some modified embodiments of the first aspect of this application, the threat intelligence is stored in an intelligence database; the step of retrieving real-time logs that collide with the threat intelligence within a preset time period starting from the current moment includes: when the threat intelligence in the intelligence database is updated, retrieving real-time logs that collide with the threat intelligence within a preset time period starting from the current moment.

[0012] When threat intelligence is updated, the log chain to be analyzed is retrieved for a second collision. Since the updated intelligence carries more attacker information, the probability of discovering security issues in the second collision can be increased, and the number of invalid second collisions can be reduced. This ensures the accuracy of security analysis while improving the efficiency of security analysis.

[0013] In some modified embodiments of the first aspect of this application, after generating secondary alarm data, the method further includes: deleting alarm data that is duplicated with primary alarm data from the secondary alarm data, obtaining and outputting new alarm data, wherein the primary alarm data is generated when each real-time log successfully collides with the threat intelligence.

[0014] Since the log chain to be analyzed consists of multiple real-time logs, the alarm data generated after the log chain to be analyzed and the threat intelligence collide twice will contain alarm data generated from the first collision of each real-time log with the threat intelligence. The duplicate alarm data in the second alarm data is deleted, and only the newly added alarm data is output, so that the user sees the newly added alarm data every time. This improves the accuracy of the alarm output and enhances the user's alarm experience.

[0015] In some modified embodiments of the first aspect of this application, the multiple real-time logs are provided by different first security vendors, the number of threat intelligences is multiple, and the multiple threat intelligences are provided by different second security vendors, wherein the first security vendor and the second security vendor are not completely the same or completely different; the method further includes: acquiring alarm data provided by the first security vendor and / or the second security vendor, wherein the provided alarm data is generated by the corresponding security vendor based on its provided logs and / or threat intelligence, and its own collected threat intelligence and / or logs; and fusing, deduplicating, and normalizing the acquired alarm data with the secondary alarm data to obtain and output an alarm dataset.

[0016] While performing secondary collision analysis on the log chain, alarm data from different security vendors is also acquired. All acquired alarm data is merged, and large amounts of data are processed into smaller amounts. This smaller data, along with the alarm data obtained from the secondary or primary collision analysis, is then sent to the virtual operations center. This allows security analysts at the center to analyze the alarm data, improving the accuracy of the analysis while reducing the amount of alarm data that personnel need to analyze, thus increasing the efficiency of security analysts' analysis.

[0017] In some modified embodiments of the first aspect of this application, the number of threat intelligences is multiple, and the multiple threat intelligences are provided by different security vendors; the method further includes: acquiring multiple threat intelligences; clustering the intelligences belonging to the same attack event among the multiple threat intelligences according to multiple preset dimensions to obtain an intelligence set; acquiring relevant information of all assets, the relevant information including content related to the threat intelligences; colliding the relevant information of all assets with the intelligence set; if the collision is successful, generating and outputting asset alarm data based on the relevant information of all assets that have successfully collided with the corresponding content in the intelligence set.

[0018] Clustering threat intelligence from different security vendors according to preset dimensions can yield more complete attack behavior characteristics of attackers. This information can then be compared with all current assets. Compared with comparing with single pieces of intelligence, the implicit relationships between these intelligences can uncover more security issues, thereby improving the accuracy of security analysis.

[0019] In some modified embodiments of the first aspect of this application, the method further includes: if the collision fails, storing the relevant information in a clue database; when it is determined that at least one of all assets is subject to a security threat, checking the relevant information in the clue database to determine whether the security threat exists in other parts of all assets.

[0020] The failure to match intelligence data with asset information does not necessarily mean that there are no security issues with the assets. It may simply mean that the current intelligence is not accurate enough. Therefore, the asset information is stored as clues. When a security threat is discovered in the assets, the stored clues are retrieved, and investigations are conducted based on the discovered threat. This allows for the discovery of other similar threats that were not previously detected, improving the accuracy of security analysis.

[0021] In some modified embodiments of the first aspect of this application, the number of threat intelligences is multiple, and the multiple threat intelligences are provided by different security vendors; the method further includes: obtaining relevant information of key assets, the relevant information including content related to threat intelligences; colliding the relevant information of the key assets with multiple threat intelligences; if the collision is successful, generating intermediate alarm data based on the relevant information of the key assets that was successfully collided with the corresponding content in the multiple threat intelligences; clustering the alarm data belonging to the same attack event in the intermediate alarm data according to multiple preset dimensions, generating and outputting clustered alarm data.

[0022] First, the key asset information is compared with multiple threat intelligences. Then, alarm data is generated based on the comparison results. The alarm data is then aggregated and output according to preset dimensions. The output alarm data can provide a more detailed and comprehensive description of the attack. While having the function of key asset security analysis, it can also improve the comprehensiveness of the analysis results, so that security analysts can make judgments and improve the accuracy of the judgments.

[0023] In some modified embodiments of the first aspect of this application, after collating the relevant information of the key asset with multiple threat intelligences, the method further includes: if the collision is successful, obtaining the relevant logs of the key asset, wherein the recording period of the relevant logs is longer than a preset period; and determining and outputting attack-related information based on the key fields in the relevant logs.

[0024] After identifying security issues in key assets through collision detection, relevant fields in long-term stored logs are used to determine the current stage of the attack, associated devices, the presence of security protections, and whether the intrusion was carried out through a jump server. This enables precise and comprehensive tracing, thereby ensuring that security issues in key assets can be thoroughly resolved and improving the security of key assets.

[0025] A second aspect of this application provides a security analysis method based on threat intelligence. The method includes: acquiring multiple threat intelligences provided by different security vendors; clustering the intelligences belonging to the same attack event among the multiple threat intelligences according to multiple preset dimensions to obtain an intelligence set; acquiring relevant information of all assets, the relevant information including content related to the threat intelligence; collating the relevant information of all assets with the intelligence set; if the collision is successful, generating and outputting asset alarm data based on the relevant information of all assets that have successfully collided with the corresponding content in the intelligence set.

[0026] A third aspect of this application provides a security analysis method based on threat intelligence. The method includes: acquiring relevant information about key assets, the relevant information including content related to threat intelligence; collating the relevant information about the key assets with multiple threat intelligences provided by different security vendors; if the collision is successful, generating intermediate alarm data based on the relevant information about the key assets that was successfully collided with the corresponding content in the multiple threat intelligences; clustering the alarm data belonging to the same attack event in the intermediate alarm data according to multiple preset dimensions, generating and outputting clustered alarm data.

[0027] A fourth aspect of this application provides a security analysis device based on threat intelligence. The device includes: a first acquisition module for acquiring a log chain to be analyzed, the log chain to be analyzed consisting of multiple real-time logs that have collided with threat intelligence; a first collision module for performing a secondary collision between the log chain to be analyzed and the threat intelligence; and a first generation module for generating secondary alarm data based on the successfully collided log chain to be analyzed and the corresponding content in the threat intelligence.

[0028] This application provides a security analysis device based on threat intelligence, the device comprising: a second acquisition module for acquiring multiple threat intelligences provided by different security vendors; a clustering module for clustering the multiple threat intelligences belonging to the same attack event according to multiple preset dimensions to obtain an intelligence set; a third acquisition module for acquiring relevant information of all assets, the relevant information including content related to threat intelligence; a second collision module for collating the relevant information of all assets with the intelligence set; if the collision is successful, proceeding to a second output module; the second output module for generating and outputting asset alarm data based on the relevant information of all assets that have successfully collided with the corresponding content in the intelligence set.

[0029] The sixth aspect of this application provides a security analysis device based on threat intelligence. The device includes: a fourth acquisition module for acquiring relevant information of key assets, the relevant information including content related to threat intelligence; a third collision module for collating the relevant information of the key assets with multiple threat intelligences provided by different security vendors; if the collision is successful, proceeding to a second generation module; the second generation module for generating intermediate alarm data based on the relevant information of the key assets that has been successfully collided and the corresponding content in the multiple threat intelligences; and a third output module for clustering alarm data belonging to the same attack event in the intermediate alarm data according to multiple preset dimensions, generating and outputting clustered alarm data.

[0030] A seventh aspect of this application provides an electronic device, the electronic device comprising: a processor, a memory, and a bus; wherein the processor and the memory communicate with each other via the bus; the processor is configured to invoke program instructions in the memory to execute the methods of the first aspect, the second aspect, or the third aspect.

[0031] The eighth aspect of this application provides a computer-readable storage medium comprising: a stored program; wherein, when the program is executed, it controls the device on which the storage medium is located to perform the methods of the first aspect, the second aspect, or the third aspect.

[0032] The security analysis method based on threat intelligence provided in the second and third aspects of this application, the security analysis device based on threat intelligence provided in the fourth, fifth and sixth aspects, the electronic device provided in the seventh aspect, and the computer-readable storage medium provided in the eighth aspect have the same or similar beneficial effects as the security analysis method based on threat intelligence provided in the first aspect. Attached Figure Description

[0033] The above and other objects, features, and advantages of exemplary embodiments of this application will become readily understood by reading the following detailed description with reference to the accompanying drawings. In the drawings, several embodiments of this application are illustrated by way of example and not limitation, with the same or corresponding reference numerals denoteing the same or corresponding parts, wherein:

[0034] Figure 1 This is a schematic diagram of the overall architecture of the security analysis based on threat intelligence in the embodiments of this application. Figure 1 ;

[0035] Figure 2 This is a flowchart illustrating the security analysis method based on threat intelligence in the embodiments of this application. Figure 1 ;

[0036] Figure 3 This is a schematic diagram of the overall architecture of the security analysis based on threat intelligence in the embodiments of this application. Figure 2 ;

[0037] Figure 4 This is a schematic diagram of the overall architecture of the security analysis based on threat intelligence in the embodiments of this application. Figure 3 ;

[0038] Figure 5 This is a schematic diagram illustrating the process of performing log and intelligence collisions on a broad scale in an embodiment of this application;

[0039] Figure 6 This is a flowchart illustrating the broad-based security analysis in an embodiment of this application;

[0040] Figure 7 This is a flowchart illustrating the security analysis method based on threat intelligence in the embodiments of this application. Figure 2 ;

[0041] Figure 8 This is a flowchart illustrating the process of performing global security analysis at a depth level in an embodiment of this application;

[0042] Figure 9 This is a flowchart illustrating the in-depth security analysis process in this application embodiment;

[0043] Figure 10 This is a flowchart illustrating the security analysis method based on threat intelligence in the embodiments of this application. Figure 3 ;

[0044] Figure 11 This is a flowchart illustrating the security analysis method based on threat intelligence in the embodiments of this application. Figure 4 ;

[0045] Figure 12 This is a flowchart illustrating the security analysis method based on threat intelligence in the embodiments of this application. Figure 5 ;

[0046] Figure 13 This is a flowchart illustrating the security analysis method based on threat intelligence in the embodiments of this application. Figure 6 ;

[0047] Figure 14 This is a schematic diagram of the structure of the threat intelligence-based security analysis device in the embodiments of this application. Figure 1 ;

[0048] Figure 15 This is a schematic diagram of the structure of the threat intelligence-based security analysis device in the embodiments of this application. Figure 2 ;

[0049] Figure 16 This is a schematic diagram of the structure of the threat intelligence-based security analysis device in the embodiments of this application. Figure 3 ;

[0050] Figure 17 This is a schematic diagram of the structure of the threat intelligence-based security analysis device in the embodiments of this application. Figure 4 ;

[0051] Figure 18 This is a schematic diagram of the structure of the threat intelligence-based security analysis device in the embodiments of this application. Figure 5 ;

[0052] Figure 19 This is a schematic diagram of the structure of the threat intelligence-based security analysis device in the embodiments of this application. Figure 6 ;

[0053] Figure 20 This is a schematic diagram of the structure of the electronic device in the embodiments of this application. Detailed Implementation

[0054] Exemplary embodiments of this application will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of this application are shown in the drawings, it should be understood that this application may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided to enable a more thorough understanding of this application and to fully convey the scope of this application to those skilled in the art.

[0055] It should be noted that, unless otherwise stated, the technical or scientific terms used in this application shall have the ordinary meaning as understood by one of ordinary skill in the art to which this application pertains.

[0056] Currently, security analysis based on the collision of logs and threat intelligence is difficult to detect when the attack is relatively covert. It is hard to find the attack from a single log, and thus the accuracy of the security analysis is reduced.

[0057] The inventors discovered that the low accuracy of current security analysis stems from its use of streaming analysis. This involves acquiring a log entry, comparing it with threat intelligence, and so on. However, covert attacks often employ methods dispersed over a long period, with each period containing only undetectable actions. These actions, when executed consecutively, can cause significant harm. Therefore, by storing collected logs long-term and performing secondary cross-matching with threat intelligence, more covert attacks can be discovered without disrupting normal attack detection processes, thus improving the accuracy of security analysis.

[0058] In view of this, embodiments of this application provide a security analysis method, apparatus, electronic device, and medium based on threat intelligence. After multiple real-time logs are collided with threat intelligence, the multiple real-time logs are stored for a long time. Under certain conditions, the stored multiple real-time logs form a log chain to be analyzed, and are collided a second time with the threat intelligence to generate alarm data. Then, the data that has previously triggered alarms is deleted from the alarm data, resulting in new alarm data. Generally speaking, if there are some covert and long-lasting attacks in the target object, there will be some hidden correlations between multiple real-time logs. By colliding with threat intelligence, these correlations can be discovered and alarm data can be formed. In this way, compared with the collision of a single log with threat intelligence, more covert attacks can be discovered, thereby improving the accuracy of security analysis.

[0059] First, the overall architecture of the security analysis method based on threat intelligence provided in the embodiments of this application will be described.

[0060] Figure 1 This is a schematic diagram of the overall architecture of the security analysis based on threat intelligence in the embodiments of this application. Figure 1 See Figure 1 As shown, the architecture may include: security vendor A, security vendor B, security vendor C, security vendor D, a threat intelligence center, and a virtual operations center.

[0061] Security vendors A and B provide the threat intelligence center with logs of the target assets they have detected. Security vendors C and D provide the threat intelligence center with threat intelligence.

[0062] It should be noted that security vendor A and security vendor B are different vendors. Security vendor C and security vendor D are also different vendors. Security vendors A and B can be completely identical to, not completely identical to, or even completely different from, security vendors C and D. The specific security vendor chosen can be determined by the entity owning the target asset based on the actual circumstances.

[0063] The Threat Intelligence Center receives probe data and intelligence data from the Big Data Center. Through long-term data merging and collision with new intelligence information, it generates new intelligence and clues. Through joint analysis engines, rule models, behavioral models, correlation models, statistical models, etc., it forms specific specialized analyses, such as global network threat attack analysis and analysis of important early warning trends. It generates different types of alerts and sends high-value intelligence and alerts to the Virtual Operations Center for further analysis and processing.

[0064] The virtual operations center collects various alarm data, merges and further analyzes different types of alarms through alarm display, risk factor management, and operations management, forms specific security incidents, generates various handling suggestions, and hands them over to the coordination and command platform for specific management actions such as early warning, notification, and emergency response, and feeds back the alarm status to the threat intelligence center.

[0065] During the security analysis process, the threat intelligence center acquires and stores threat intelligence provided by security vendors C and D. Next, the threat intelligence center obtains a log from either security vendor A or B and compares it with the various threat intelligence pieces stored in its database. If the comparison is successful, the center outputs corresponding alert data to the virtual operations center. Upon receiving the alert data, the security analysts within the virtual operations center further analyze it to determine its validity. If the alert is confirmed to be valid, appropriate security measures are implemented.

[0066] Every log received by the Threat Intelligence Center from security vendor A or B is stored for a relatively long period. For example, the Threat Intelligence Center stores logs received over the past six months. In this case, the Threat Intelligence Center provides a large storage space to store the large volume of logs. Subsequently, the Threat Intelligence Center combines multiple stored logs and performs a collision analysis with the threat intelligence. This collision may generate new alerts that have never been generated before. The Threat Intelligence Center then sends this new alert data to the virtual operations center, providing security analysts with more alert data to help uncover more threats.

[0067] Next, the security analysis method based on threat intelligence provided in the embodiments of this application will be described in detail.

[0068] Figure 2 This is a flowchart illustrating the security analysis method based on threat intelligence in the embodiments of this application. Figure 1 See Figure 2 As shown, the method may include:

[0069] S21: Obtain the log chain to be analyzed. The log chain to be analyzed consists of multiple real-time logs that have already been processed by threat intelligence.

[0070] The log, also known as the traffic log, is mainly from Netflow. It includes timestamps, source Internet Protocol (IP) addresses, destination IP addresses, source ports, destination ports, inbound and outbound traffic, and Quality of Service (QoS). It is a record output after a stream (with the same source IP address, destination IP address, source port, and destination port) is integrated.

[0071] Real-time logs are the logs output by probes from various security vendors. In this embodiment, logs of the target asset can be obtained by purchasing probe services from different security vendors. In practical applications, probe services from multiple security vendors can be purchased simultaneously to obtain multiple logs for the same target asset. This can compensate for the problem of insufficient detection by a single security vendor, thus improving the accuracy of target asset log acquisition.

[0072] Once the real-time logs are obtained, they can be compared with threat intelligence in a short period of time.

[0073] Threat intelligence is evidence-based knowledge, including context, mechanisms, indicators, meanings, and actionable recommendations. This knowledge relates to existing or emerging threats or harms facing assets and can be used to support the decision-making of asset-related entities in responding to or handling threats or harms. In this embodiment, it specifically refers to providing input for human operations regarding high-value security events involving known objects.

[0074] The process of comparing real-time logs with threat intelligence involves determining whether the traffic-related information in the logs matches the description in the threat intelligence. If they match, the comparison is successful, and the matching points are the points where the comparison was successful. If they do not match, it means that the content in the real-time logs does not match the description in the threat intelligence, and the comparison fails.

[0075] After multiple real-time logs are collided with threat intelligence, that is, after a period of time, the collided real-time logs need to be combined again and collided with threat intelligence. At this point, it is necessary to obtain the log chain to be analyzed. The log chain to be analyzed needs to consist of multiple consecutive real-time logs. Here, "consecutive" can mean that all real-time logs in the log chain to be analyzed are consecutive, or it can mean that some real-time logs in the log chain to be analyzed are consecutive.

[0076] In this embodiment, each time a real-time log is received from a security vendor's probe, the real-time log is stored. Generally, real-time logs need to be stored for a long period, such as 6 months or 12 months. When it is necessary to obtain the log chain to be analyzed, the required real-time logs can be extracted from the stored real-time logs and then assembled into the log chain to be analyzed.

[0077] For example, suppose we can provide log storage for the past 6 months. If we receive and store a real-time log every 10 seconds, we would have 10 × 6 × 6 × 24 × 30 × 6 = 1,555,200 logs stored over the past 6 months. If a secondary collision occurs every month, then the log chain to be analyzed would consist of logs stored within the past month, specifically the most recently stored 10 × 6 × 6 × 24 × 30 = 259,200 logs.

[0078] S22: Perform a secondary collision between the log chain to be analyzed and the threat intelligence.

[0079] Since logs record traffic information, while threat intelligence describes attack characteristics, matching the traffic information with the attack characteristics (i.e., collision detection) can determine whether there is any attack behavior in the logs.

[0080] The log chain to be analyzed contains long-term behavioral information of the target asset. By comparing it with threat intelligence, we can discover anomalies in the target asset that can only be detected through long-term behavior.

[0081] In a specific collision detection process, a periodic task is initiated to retrieve the IP address, domain name, URL, and file MD5 hash of the target IP address from logs (device logs, traffic logs, and threat intelligence logs), and then performs deduplication and caching. Next, the target IP address, domain name, URL, and file MD5 hash are matched against threat intelligence (by calling the corresponding detection API). If the detection is successful, the log is treated as a threat log, tagged with the vendor providing the corresponding threat intelligence, and IOC-related information is added. Finally, the newly generated threat logs are written to the corresponding threat log database according to their type, so that they can be provided as alert data to security analysts for further analysis.

[0082] Threat intelligence collisions can be provided by multiple vendors. For threat intelligence from different vendors, logs need to be collated with them. That is, the IP address, domain name, URL, and file MD5 hash of the target IP address in the logs are sequentially collated with vendor A, vendor B, vendor C, and so on. Collaborating with multiple threat intelligence data sources can increase the number of alerts obtained by collisions with a single vendor by more than 20%, improve alert accuracy by more than 15%, and increase the intelligence information IOC supplementation by more than 30% compared to collisions with a single vendor.

[0083] S23: Generate secondary alert data based on the log chain to be analyzed after a successful collision and the corresponding content in the threat intelligence.

[0084] The log chain to be analyzed includes multiple real-time logs. If multiple real-time logs generate alert data when they first collide with threat intelligence, then these alert data will also be generated in the subsequent collisions between the log chain to be analyzed and the threat intelligence. If there is a long-term attack on the target asset, then some additional alert data will be generated in the collisions between the log chain to be analyzed and the threat intelligence. These two types of alert data will be generated together after the collision, i.e., secondary alert data.

[0085] For example, consider the analysis of an APT-Q-29 (Winnti) attack. Winnti attacks an organization, compromising several of its C2 servers and controlling a large number of IPs. However, the current threat intelligence is either not updated or lacks the capability to detect Winnti APTs. After achieving its attack objectives, Winnti cleans up its attack traces. Once the organization updates its threat intelligence with a certain security vendor, it gains the ability to detect Winnti and trace its logs over the past six months, revealing that Winnti APTs have previously attacked the organization.

[0086] Although attack traces are cleaned up, behavioral information remains in the logs. Therefore, by combining updated threat intelligence with long-term stored logs, it is possible to analyze APT attacks that have a long duration and cause great harm.

[0087] As can be seen from the above, the security analysis method based on threat intelligence provided in this application collisions multiple real-time logs with threat intelligence, and then collisions these collisions together with the threat intelligence again. In this way, problems that cannot be found by colliding a single log with threat intelligence can be discovered. That is, by the correlation between multiple real-time logs, security problems can be discovered, and previously undiscovered alarm data can be output, thereby improving the accuracy of security analysis of logs based on threat intelligence.

[0088] Furthermore, as a response to Figure 2 In a refinement and extension of the method shown, this application also provides a security analysis method based on threat intelligence.

[0089] In this application embodiment, to improve the accuracy of security analysis, two main aspects are addressed. One is breadth, which involves extending the log storage period (e.g., from 1 month to 6 months, or even 12 months), utilizing threat intelligence from multiple vendors, and conducting secondary collision analysis based on this. The other is depth, which involves conducting various specialized analyses (e.g., comprehensive analysis and focused analysis) on the target assets.

[0090] Figure 3 This is a schematic diagram of the overall architecture of the security analysis based on threat intelligence in the embodiments of this application. Figure 2 See Figure 3 As shown, the architecture can include a data layer, a service layer, and an application layer.

[0091] The threat intelligence center has a three-layer architecture consisting of a data layer, a service layer, and an application layer.

[0092] The data layer is used for intelligence data access and preprocessing. Specifically, it can access traffic logs, security logs, traffic alerts, security alerts, asset information, third-party threat intelligence, multi-vendor probe data, and threat intelligence. Preprocessing methods include extraction, correlation, cleaning, comparison, and labeling. In this embodiment, based on the initial data collection, probe data from multiple vendors and intelligence radar data and threat intelligence (Indicators of Compromise, IOC) data from certain designated vendors are added. Through the influx of various alert data, the alerts are deduplicated, enriched, and merged before being sent to the service layer for further rule matching.

[0093] The service layer is used to support various security analysis scenarios at the upper layer through rule-based modeling and analysis. The intelligence joint analysis engine can include operational rules, statistical rules, correlation rules, sequence rules, behavioral rules, rule management, etc.

[0094] The application layer, representing upper-level applications, is mainly divided into two parts: enhancing basic security analysis capabilities and improving specialized security analysis. Basic security analysis expands the scope, including analysis of existing alerts and newly added alerts. Advanced security analysis expands the depth, including global network threat and attack analysis and analysis of key early warning trends.

[0095] Figure 4 This is a schematic diagram of the overall architecture of the security analysis based on threat intelligence in the embodiments of this application. Figure 3 See Figure 4 As shown, the architecture may include a threat intelligence center and a virtual operations center.

[0096] In the threat intelligence center, threat intelligence from different vendors (Vendor A, Vendor B, and Vendor C) is accessed, and the vendor attribution is identified. This intelligence is then compared with traffic logs to generate new intelligence, and the vendor attribution of the new intelligence and the referencing logs is identified. Next, intelligence deduplication is performed, identifying the vendor attribution for the same intelligence. Then, existing intelligence is compared with new intelligence, and compromise analysis is conducted. During intelligence comparison, it's necessary to determine whether existing and new intelligence belong to the same category, which can be determined by the victim's IP address. If so, it's used as supplementary information to existing intelligence in the virtual operations center for intelligence access and classification. If not, it's treated as new intelligence and compared with assets, with asset attribution marked during the comparison. Finally, it's used for intelligence access and clue classification in the virtual operations center.

[0097] By tagging intelligence, deduplicating intelligence, and comparing existing and new intelligence, intelligence with IP addresses, and intelligence with assets (categorized as ordinary and key assets), a hierarchical classification and clue aggregation of intelligence (security incidents) is ultimately formed. This maximizes the value of newly added intelligence while minimizing the number of collisions, greatly improving the efficiency and effectiveness of the operation.

[0098] Figure 5 This is a schematic diagram illustrating the process of performing log and intelligence collisions on a broad scale in an embodiment of this application. See [link / reference]. Figure 5 As shown, traffic logs, alarm logs, cloud threat intelligence, and asset data are integrated as datasets, and threat intelligence from different vendors A, B, and C is also integrated. In the collision process, data and intelligence are compared. This is mainly divided into two parts: one is real-time, performing compromise detection (IP, domain, URL, etc.) to enrich the relevant information in the alarms (IOC, malware families) and improve the accuracy of the analysis. The other part is timed (e.g., at 00:00 every day), performing detection on attack IP intelligence, file reputation, domain reputation, etc., to generate a risk database for internal blacklist use and subsequent specialized analysis. This includes three scenarios: Scenario 1: Viewing corresponding alarms for centralized analysis; Scenario 2: Source tracing analysis; Scenario 3: Discovering unknown threats.

[0099] Figure 6 This is a flowchart illustrating the breadth of security analysis in an embodiment of this application. See [link / reference] Figure 6 As shown, alarms, logs, and intelligence are accessed from the big data platform. For basic security analysis, alarms are fused, deduplicated, and normalized to obtain existing alarms. For collisions between logs and intelligence, intelligence updates are performed, and alarm deduplication is carried out in alarm management to obtain new alarms. Both existing and new alarms require intelligence upgrade management. Existing and new alarms are then synchronized as intelligence to the operations workbench of the virtual operations center.

[0100] For in-depth security analysis, namely specialized security analysis, intelligence or clues are used through alarm management in basic security analysis.

[0101] Figure 7 This is a flowchart illustrating the security analysis method based on threat intelligence in the embodiments of this application. Figure 2 See Figure 7 As shown, the method may include:

[0102] S71: Obtain alarm data provided by the first security vendor and / or the second security vendor. The alarm data provided is generated by the corresponding security vendor based on the logs and / or threat intelligence they provide, and the threat intelligence and / or logs they collect themselves.

[0103] There can be multiple primary security vendors, each capable of providing the same or different real-time logs for the target asset. Multiple real-time logs can be obtained through these primary security vendors.

[0104] There can be multiple secondary security vendors, each capable of providing the same or different threat intelligence. By using these secondary security vendors, one can obtain multiple threat intelligence reports.

[0105] The first and second security vendors can be the vendors determined separately in the process of acquiring logs and threat intelligence. They can be completely identical, partially identical, or completely different. For example, vendors A and B can be used to acquire logs, and vendors A and B can be used to acquire threat intelligence. Another example: vendors A and C can be used to acquire logs, and vendors A and D can be used to acquire threat intelligence. Yet another example: vendors A and B can be used to acquire logs, and vendors C and D can be used to acquire threat intelligence.

[0106] For a particular vendor, using its own probes allows it to collect logs from target assets and also provides its own threat intelligence. By comparing the collected logs with the threat intelligence it possesses, and if the comparison is successful, corresponding alert data is generated and then output to the threat intelligence center.

[0107] Vendors use their own probe logs and threat intelligence for security analysis. Because they use logs and intelligence aligned with their areas of expertise, the resulting alerts are more accurate, improving the precision of subsequent security analyses. Since different vendors have varying areas of expertise in security analysis, obtaining alert data from each vendor maximizes the accuracy and comprehensiveness of the alerts, further enhancing the precision of subsequent security analyses.

[0108] For acquiring alert data, you can connect to vendors that provide logs, vendors that provide threat intelligence, or vendors that provide both logs and threat intelligence. The choice depends on the current situation of the threat intelligence center and the quality of the data provided by the vendors.

[0109] Alert data generated by individual vendors can also be provided to the virtual operations center, enabling security analysts to discover more security issues and conduct more comprehensive security analyses. In addition to providing alert data to the virtual operations center, new intelligence obtained from broader data collection can also be provided to the virtual operations center, allowing its security analysts to utilize more information for security analysis. This new intelligence involves a secondary cross-referencing of logs from a longer period with threat intelligence.

[0110] S72: Starting from the current moment, retrieve the real-time logs that collided with threat intelligence within a preset time period, and arrange the retrieved logs in chronological order to obtain the log chain to be analyzed. The preset time period is longer than the time interval between collisions between each real-time log and the threat intelligence.

[0111] For real-time logs, this embodiment will receive real-time logs based on vendor probes whenever there is interaction with the target asset. Furthermore, the real-time logs acquired within a short time interval will be collided with threat intelligence. For example, real-time logs are received every second, and every 10 minutes, the real-time logs received in the most recent 10 minutes will be collided with threat intelligence. This is the first collision.

[0112] After a relatively long preset period, the real-time logs that have been collided during this period will be aggregated and collided with the threat intelligence again. For example, every month, the real-time logs that have been collided within the past month will be used as a log chain to be analyzed and then collided with the threat intelligence a second time.

[0113] In practical applications, as time goes on, vendors generate new threat intelligence, meaning the threat intelligence provided by each vendor and stored in the threat intelligence center's database are also updated. In this case, the timing for a secondary collision in the log chain to be analyzed can be an intelligence update. Combining new intelligence with the correlations between logs can uncover more issues and generate more alerts in a single collision, improving the efficiency of security analysis while ensuring its accuracy.

[0114] Specifically, step S72 above may include:

[0115] Step A1: When the threat intelligence in the intelligence database is updated, retrieve the real-time logs that collide with the threat intelligence within the preset time period starting from the current moment.

[0116] In other words, the condition for triggering a secondary collision between long-term stored logs and threat intelligence is that the threat intelligence used for the collision has been updated. For example, when it is determined that the threat intelligence has been updated, real-time logs that have been collided within the past month will be used as the log chain to be analyzed, and then a secondary collision will be performed with the updated threat intelligence.

[0117] S73: Perform a secondary collision between the log chain to be analyzed and the threat intelligence.

[0118] S74: Generate secondary alert data based on the log chain to be analyzed after a successful collision and the corresponding content in the threat intelligence.

[0119] Steps S73 and S74 are implemented in the same way as steps S22 and S23 mentioned above, and will not be described again here.

[0120] S75: Delete alarm data that is duplicated with primary alarm data from secondary alarm data, obtain and output new alarm data. Primary alarm data is generated when each real-time log and threat intelligence are successfully matched.

[0121] In the secondary collision analysis between the log chain to be analyzed and threat intelligence, not only are each real-time log in the log chain individually collided with the threat intelligence, but the implicit connections between the real-time logs can also be collided with the threat intelligence. That is, the resulting secondary alert data will include alert data generated when each real-time log successfully collides with the threat intelligence. Since the primary alert data has already been output to the user, the previously output alert data in the secondary alert data can be deleted, and only the newly added alert data can be output. This ensures that the user receives alerts for previously undetected long-term attacks, improving the user's alert data reception experience. Security analysts in the virtual operations center can also obtain more alert data for judging long-term attacks, thereby better discovering long-term attacks in target assets.

[0122] S76: The acquired alarm data and secondary alarm data are merged, deduplicated, and normalized to obtain and output the alarm dataset.

[0123] In addition to providing logs and threat intelligence, different vendors also offer alert data due to their security analysis capabilities. While different vendors specialize in different security analyses, some vendors may produce the same alert data for a particular analysis, and this data may overlap with secondary alert data generated in the current system. Therefore, it is necessary to merge, deduplicate, and normalize this acquired alert data with the secondary alert data. This allows for the output of an alert dataset after the initial output of new alert data. Transforming alert data from large datasets to smaller datasets and outputting it to the virtual operations center facilitates security analysts' analysis of long-term, covert attacks and enables precise and rapid analysis of multiple alerts.

[0124] Thus, the process of broadening the scope—namely, increasing the log storage period, acquiring threat intelligence from multiple vendors, performing secondary collision analysis between long-period logs and updated threat intelligence, conducting security analysis, and generating and outputting alert data—has been completed.

[0125] Next, we will continue to explain the security analysis from a deeper perspective, namely: various types of security analysis (including global network threat attack analysis and key network threat attack analysis).

[0126] S77: Perform global asset analysis based on threat intelligence.

[0127] Multiple vendors provide threat intelligence. Some of this intelligence is different, while some is the same. Therefore, when conducting a global analysis, it is necessary to first cluster these intelligences. Each vendor's threat intelligence has its own advantages. By combining the strengths and compensating for the weaknesses, a comprehensive analysis can be conducted to fully obtain the behavioral patterns of currently discovered attackers. Furthermore, by comparing these patterns with assets, it can be determined whether there are more threats within the assets.

[0128] Specifically, step S77 above may include:

[0129] Step B1: Obtain multiple threat intelligences.

[0130] Among multiple threat intelligence reports, some are provided by a single vendor, while others are provided by multiple vendors. For threat intelligence provided by multiple vendors, the vendors can be identified within the threat intelligence reports themselves. This allows for later assessment of the vendors' intelligence-providing capabilities based on the accuracy of the intelligence, enabling the selection of the optimal vendor for acquiring threat intelligence. For example: Vendor A provides intelligence 1 and intelligence 2, Vendor B provides intelligence 1 and intelligence 3, Vendor C provides intelligence 4, and so on. For intelligence 1, vendors A and B can be identified.

[0131] Step B2: Cluster the intelligence belonging to the same attack event from multiple threat intelligences according to multiple preset dimensions to obtain an intelligence set.

[0132] Among multiple threat intelligence reports, some describe a single attacker or a type of attack, while others describe different attackers or different types of attacks. Therefore, it's necessary to aggregate threat intelligence reports belonging to the same attacker or type of attack. This aggregated intelligence, combined with asset information, can then be used to discover more attacks by the same attacker or type of attack. For example, a unit includes departments a, b, and c. Threat intelligence 1 indicates that attacker A attacked a terminal in department a; threat intelligence 2 indicates that attacker A attacked a terminal in department b; and threat intelligence 3 indicates that attacker B attacked terminals in other departments. Clustering threat intelligences 1 and 2 reveals that attacker A attacked terminals in two departments of the unit. This suggests that the attacker may have attacked terminals in other departments as well, allowing for security checks on those terminals to uncover more attacks and improve the accuracy of security analysis.

[0133] During clustering, multiple preset dimensions can provide a logical and complete description of the attacker's behavior or attack events. Therefore, multiple threat intelligences can be clustered according to these preset dimensions. In practical applications, these preset dimensions may include, but are not limited to: geographical distribution, criminal groups, time span, malicious type, and remote control domains. The specific clustering method is the same as conventional information clustering methods and will not be elaborated here.

[0134] Step B3: Obtain relevant information for all assets, including information related to threat intelligence.

[0135] The term "all assets" here refers to all assets of the target object that requires security testing. All assets include, but are not limited to: equipment, software, websites, services, etc.

[0136] Information related to all assets refers to information that can uniquely identify an asset and the operations performed on that asset. Examples include IP address, port, and logs.

[0137] In the acquisition of information, it can be provided proactively by the target object, obtained through probe detection, or a combination of the two methods mentioned above, to ensure comprehensive information acquisition.

[0138] Step B4: Collide the relevant information of all assets with the intelligence set. If the collision is successful, proceed to step B5; if the collision fails, proceed to step B6.

[0139] An intelligence set can summarize an attacker or a type of attack behavior. Since all assets to be monitored have been identified, by combining intelligence with asset information and summarizing the intelligence, more attacks by the same attacker or of the same type can be discovered in the assets, thus improving the comprehensiveness of security analysis.

[0140] Step B5: Based on the relevant information of all assets that successfully collided and the corresponding content in the intelligence set, generate and output asset alarm data.

[0141] Assets that successfully collide with intelligence reports are those with security vulnerabilities. Therefore, this asset information is combined with relevant intelligence to generate alert data, which is then output to security analysts. Security analysts can then combine more alert data to make a more accurate assessment of the same attacker or similar attack events.

[0142] Step B6: Store the relevant information in the clue database.

[0143] A collision failure indicates that the information described in the intelligence does not exist among the currently known assets. The assets may be safe, but there may also be unknown security issues. Therefore, the asset information can be stored as clues in the clue database.

[0144] Step B7: When it is determined that at least one of the assets is under security threat, the relevant information in the clue database is used to investigate the security threat to determine whether there are other security threats in the other assets.

[0145] For clues that failed to be successfully matched previously, if security analysts discover threats in the asset during subsequent analyses, they need to re-examine these previously unmatched asset information in the clue database based on the discovered threats. This may uncover similar threats. This approach avoids missing threats due to unknown intelligence, improving the comprehensiveness of security analysis.

[0146] Figure 8 This is a flowchart illustrating the process of performing global security analysis at a depth level in this application embodiment. See also... Figure 8 As shown, the threat radar in the big data platform identifies network attacks and generates threat intelligence, which is then connected to the threat intelligence center. Under the global network threat attack analysis of the threat intelligence center, the threat intelligence is clustered, including analysis of geographical distribution, group / family structure, time span, malicious type, remote control domain, and response recommendations. Then, each clustered intelligence is compared with assets. If the comparison is successful, the asset and intelligence are sent as known intelligence to the operations workbench of the virtual operations center for further analysis by security analysts. If the comparison fails, the asset and intelligence are sent as unknown clues to the virtual operations center for clue aggregation, enabling subsequent threat discovery in other security analyses. Based on the discovered threats, clues can be further screened to uncover previously undetected security issues.

[0147] For example, suppose in a certain project, a large amount of cloud threat intelligence was collected by region, but few matched with platform asset information. A large amount of intelligence data was put into the clue database. When security analysts were assessing a certain threat, they discovered a remote code execution vulnerability in log4j2 [CVE-2021-44228]. Security service personnel checked the clue database and found a large number of log4j2 vulnerabilities at the same time. They immediately initiated the emergency response process and carried out emergency coordination with the responsible units within the scope of supervision.

[0148] S78: Focus on analyzing assets based on threat intelligence.

[0149] Sometimes, it is not necessary to perform security analysis on all assets of a target. It may be sufficient to analyze key assets. Therefore, key assets are identified from all assets, and these key assets are compared with threat intelligence to achieve focused and specialized asset analysis.

[0150] Specifically, step S78 above may include:

[0151] Step C1: Obtain relevant information about key assets, including content related to threat intelligence.

[0152] Key assets can refer to those assets that are important to the target and that would suffer significant losses if attacked.

[0153] The identification of key assets can be initiated by the target entity or by selecting pre-defined types of assets from all assets held by the target entity. These types of assets are generally considered important to most target entities. Examples include servers storing important projects and terminal equipment used by the finance department.

[0154] Information related to key assets can be obtained proactively from the target entity, detected through probes, or a combination of both methods to ensure comprehensive information acquisition.

[0155] Step C2: Cross-reference the relevant information of key assets with multiple threat intelligence reports. If the cross-reference is successful, proceed to step C3; otherwise, proceed to step C4.

[0156] The Threat Intelligence Center receives threat intelligence from various vendors. There is more than one threat intelligence. The relevant information of key assets is compared with each threat intelligence separately, and a result is obtained for each comparison.

[0157] Step C3: Generate intermediate alert data based on relevant information of key assets that have successfully collided with the corresponding content from multiple threat intelligence sources.

[0158] If a critical asset successfully collides with a specific threat intelligence, it indicates that the critical asset has been attacked as described by that threat intelligence. Based on the critical asset and the threat intelligence, alert data is then generated for security analysts to conduct further analysis.

[0159] Step C4: Store the relevant information in the clue database.

[0160] A failed collision indicates that the information described in the intelligence does not exist in the current key assets. The assets may be safe, but there may also be unknown security issues. Therefore, information about important assets can be stored as clues in the clue database. When security issues are discovered later, there is no need to search through massive logs. The clue database stores information that was questionable at the time but lacked concrete evidence, which can help achieve rapid investigation.

[0161] Step C5: Cluster the alarm data belonging to the same attack event in the intermediate alarm data according to multiple preset dimensions, and generate and output the clustered alarm data.

[0162] After generating intermediate alert data in step C3, since multiple threat intelligences may be related, some threat intelligences may describe the same attacker, and some threat intelligences may describe the same type of attack event. Therefore, clustering the intermediate alert data, that is, aggregating the alert data of the same attacker or the same type of attack event, not only reduces the workload of security analysts in the later stage, but also enables comprehensive analysis of attacks and improves the comprehensiveness of security analysis.

[0163] Step C6: Obtain relevant logs for key assets. The recording period for these logs should be longer than the preset period.

[0164] After the key assets and intelligence are successfully matched and alarm data is generated, due to the significant losses caused by the attack on the key assets, it is necessary to trace the source in order to thoroughly understand the problems caused by the attack.

[0165] The specific method for tracing the source involves obtaining relevant logs from key assets. Generally, it's necessary to review logs over a longer period, such as the last six months. Compared to short-term logs, long-term logs can characterize the entire attack process, enabling precise attribution.

[0166] The acquisition of logs related to key assets is the same as that of regular asset logs, and will not be elaborated here.

[0167] Step C7: Based on the key fields in the relevant logs, determine and output attack-related information.

[0168] Because the log records every operation on the asset, the specific details of the operation can be understood by looking at the relevant fields in the log.

[0169] For example, by using request_body, request_header, URL, and response_body, one can determine the attacker's current attack stage (e.g., scanning, intrusion, compromise), as well as the machines associated with the threat device, and check for signs of C2 or intrusion via jump servers. Of course, other attack information can be determined using the above fields or other fields, which will not be listed here.

[0170] Figure 9 This is a flowchart illustrating the in-depth security analysis process in this application embodiment. See [link / reference]. Figure 9As shown, the threat radar in the big data platform identifies network attacks and generates threat intelligence, which is then connected to the threat intelligence center. Under the key network threat attack analysis of the threat intelligence center, critical assets are compared with the threat intelligence. The threat intelligence obtained from this comparison can come not only from the threat radar but also from probes within the big data platform. If the comparison is successful, alert data is generated and clustered according to geographic distribution, group / familiarity analysis, time span analysis, malicious type analysis, remote control domain analysis, and remediation recommendations. Finally, this intelligence is sent to the operations workbench of the virtual operations center for further analysis and attribution by security analysts.

[0171] For example, suppose in 2023hvv, a user uses threat intelligence to detect a suspected APT-Q-12 (pseudo-hunter) attack. Security analysts analyze the alert and, through analysis of long-term stored traffic logs, discover that the user accessed a phishing email, triggering an XSS zero-day vulnerability and executing JavaScript code. The host is at high risk, so an emergency response process is initiated, using professional detection and removal tools to handle the situation, and machines in the same network area are also detected.

[0172] It should be noted that steps S77 and S78 can be executed selectively, or both can be executed, and they can be executed synchronously or asynchronously. Furthermore, steps S71-S72, S73-S76, and S77-S78 can be executed selectively, or all of them can be executed, and they can be executed synchronously or asynchronously.

[0173] As described above, the security analysis method based on threat intelligence provided in this application offers a security analysis approach from both breadth and depth. It considers the access of probe logs and threat intelligence data from multiple vendors and extends the log storage period from the common one month to six months, providing possibilities for secondary data analysis in terms of breadth. It standardizes probe logs of different formats to prevent different vendors' probes from only alerting for their own specialized security scenarios, forming a capability pool, leveraging strengths and mitigating weaknesses, and maximizing the intelligence advantages of each vendor to create synergistic intelligence value, providing a foundation for subsequent intelligence performance evaluation. Based on log and IOC intelligence collisions, combined with threat intelligence updates, secondary analysis is performed on the log chains and traffic to be analyzed, and this is integrated with intelligence generated from specialized analyses to uncover new alerts. For alert fusion, deduplication, and normalization from various vendors, large alert volumes are transformed into smaller data sets. It incorporates global network threat attack analysis and key network threat attack analysis scenarios, providing possibilities for future introduction of business scenarios such as provincial attack source analysis, provincial compromised host analysis, and important predicted trend analysis. Aggregating security capabilities (probe collection capabilities, threat intelligence capabilities) from multiple vendors within a single project greatly promotes the unification of technical standards in the security industry and breaks down technical barriers between security vendors. Global network threat attack analysis uncovers unknown clues through large-scale network threat clustering analysis. Focused network threat attack analysis provides targeted attack analysis by focusing on known assets.

[0174] This concludes the description of the security analysis method based on threat intelligence provided in the embodiments of this application.

[0175] Furthermore, this application also provides a security analysis method based on threat intelligence.

[0176] Figure 10 This is a flowchart illustrating the security analysis method based on threat intelligence in the embodiments of this application. Figure 3 See Figure 10 As shown, the method may include:

[0177] S101: Obtain multiple threat intelligences from different security vendors.

[0178] S102: Cluster the intelligence belonging to the same attack event from multiple threat intelligences according to multiple preset dimensions to obtain an intelligence set.

[0179] S103: Obtain relevant information for all assets, including information related to threat intelligence.

[0180] S104: Collide all asset-related information with the intelligence set. If the collision is successful, proceed to S105.

[0181] S105: Based on the relevant information of all assets that have successfully collided and the corresponding content in the intelligence set, generate and output asset alarm data.

[0182] Furthermore, as a response to Figure 10 In a further refinement and extension of the method shown, this application also provides a security analysis method based on threat intelligence.

[0183] Figure 11 This is a flowchart illustrating the security analysis method based on threat intelligence in the embodiments of this application. Figure 4 See Figure 11 As shown, the method may include:

[0184] S111: Obtain multiple threat intelligences from different security vendors.

[0185] S112: Cluster the intelligence belonging to the same attack event from multiple threat intelligences according to multiple preset dimensions to obtain an intelligence set.

[0186] S113: Obtain information on all assets, including information related to threat intelligence.

[0187] S114: Collide all asset information with the intelligence set. If the collision is successful, proceed to S115. If the collision fails, proceed to S116.

[0188] S115: Based on the relevant information of all assets that have successfully collided and the corresponding content in the intelligence set, generate and output asset alarm data.

[0189] S116: Store the relevant information in the clue database.

[0190] S117: When it is determined that at least one of all assets is under security threat, the relevant information in the clue database is used to investigate the security threat in order to determine whether there are other security threats in the other assets.

[0191] It should be noted that the descriptions of the above method embodiments are similar to those of the foregoing method embodiments, and have similar beneficial effects. For technical details not disclosed in the method embodiments of this application, please refer to the descriptions of the foregoing method embodiments of this application for understanding.

[0192] Furthermore, this application also provides a security analysis method based on threat intelligence.

[0193] Figure 12 This is a flowchart illustrating the security analysis method based on threat intelligence in the embodiments of this application. Figure 5 See Figure 12 As shown, the method may include:

[0194] S121: Obtain relevant information about key assets, including information related to threat intelligence.

[0195] S122: Cross-reference key asset information with multiple threat intelligence reports from different security vendors. If the cross-reference is successful, proceed to S123.

[0196] S123: Generate intermediate alert data based on relevant information of key assets that have successfully collided with the corresponding content in multiple threat intelligences.

[0197] S124: Cluster alarm data belonging to the same attack event in the intermediate alarm data according to multiple preset dimensions, generate and output clustered alarm data.

[0198] Furthermore, as a response to Figure 12 In a further refinement and extension of the method shown, this application also provides a security analysis method based on threat intelligence.

[0199] Figure 13 This is a flowchart illustrating the security analysis method based on threat intelligence in the embodiments of this application. Figure 6 See Figure 13 As shown, the method may include:

[0200] S131: Obtain information about key assets, including information related to threat intelligence.

[0201] S132: Cross-reference key asset information with multiple threat intelligence reports from different security vendors. If the cross-reference is successful, proceed to S133.

[0202] S133: Generate intermediate alert data based on relevant information of key assets that have successfully collided with the corresponding content in multiple threat intelligences.

[0203] S134: Cluster alarm data belonging to the same attack event in the intermediate alarm data according to multiple preset dimensions, and generate and output clustered alarm data.

[0204] S135: Obtain relevant logs for key assets, with the recording period of these logs exceeding the preset period.

[0205] S136: Based on key fields in relevant logs, determine and output attack-related information.

[0206] It should be noted that the descriptions of the above method embodiments are similar to those of the foregoing method embodiments, and have similar beneficial effects. For technical details not disclosed in the method embodiments of this application, please refer to the descriptions of the foregoing method embodiments of this application for understanding.

[0207] Based on the same inventive concept, as an implementation of the above method, this application also provides a security analysis device based on threat intelligence.

[0208] Figure 14 This is a schematic diagram of the structure of the threat intelligence-based security analysis device in the embodiments of this application. Figure 1 See Figure 14 As shown, the device may include a first acquisition module 141, a first collision module 142, and a first generation module 143. The first acquisition module 141, the first collision module 142, and the first generation module 143 are connected sequentially.

[0209] The first acquisition module 141 is used to acquire the log chain to be analyzed, which consists of multiple real-time logs that have been collided with threat intelligence.

[0210] The first collision module 142 is used to perform a secondary collision between the log chain to be analyzed and the threat intelligence.

[0211] The first generation module 143 is used to generate secondary alarm data based on the log chain to be analyzed that has successfully collided and the corresponding content in the threat intelligence.

[0212] Furthermore, as a response to Figure 14 In addition to the refinement and expansion of the illustrated device, this application also provides a security analysis device based on threat intelligence.

[0213] Figure 15 This is a schematic diagram of the structure of the threat intelligence-based security analysis device in the embodiments of this application. Figure 2 See Figure 15 As shown, the device may include: a first acquisition module 151, a first collision module 152, a first generation module 153, a first output module 154, an alarm module 155, a global module 156, and a key module 157. The first acquisition module 151, the first collision module 152, the first generation module 153, and the first output module 154 are connected sequentially, and are independently configured with respect to the alarm module 155, the global module 156, and the key module 157.

[0214] The first acquisition module 151 is used to acquire the log chain to be analyzed, which includes multiple real-time logs that have been matched with threat intelligence.

[0215] The first acquisition module 151 is specifically used to acquire real-time logs that collide with the threat intelligence within a preset time period starting from the current moment, and arrange the acquired logs in chronological order to obtain the log chain to be analyzed, wherein the preset time period is longer than the time interval between collisions between each real-time log and the threat intelligence.

[0216] When the threat intelligence is stored in the intelligence database, the first acquisition module 151 is specifically used to acquire real-time logs that collide with the threat intelligence within a preset time period, starting from the current moment, when the threat intelligence in the intelligence database is updated.

[0217] The first collision module 152 is used to perform a secondary collision between the log chain to be analyzed and the threat intelligence.

[0218] The first generation module 153 is used to generate secondary alarm data based on the log chain to be analyzed after a successful collision and the corresponding content in the threat intelligence.

[0219] The first output module 154 is used to delete alarm data that is duplicated with the primary alarm data in the secondary alarm data, and obtain and output the newly added alarm data, wherein the primary alarm data is generated when each real-time log successfully collides with the threat intelligence.

[0220] When the multiple real-time logs are provided by different first security vendors, and the number of threat intelligences is multiple, with multiple threat intelligences provided by different second security vendors, and the first security vendor and the second security vendor are not completely the same or completely different, the alarm module 155 is used to obtain alarm data provided by the first security vendor and / or the second security vendor. The provided alarm data is generated by the corresponding security vendor based on its provided logs and / or threat intelligence, and its own collected threat intelligence and / or logs. The obtained alarm data is then fused with the secondary alarm data, deduplicated, and normalized to obtain and output an alarm dataset.

[0221] When there are multiple threat intelligences provided by different security vendors, the global module 156 is used to acquire multiple threat intelligences; cluster the intelligences belonging to the same attack event among the multiple threat intelligences according to multiple preset dimensions to obtain an intelligence set; acquire relevant information of all assets, the relevant information including content related to the threat intelligences; collide the relevant information of all assets with the intelligence set; if the collision is successful, generate and output asset alarm data based on the relevant information of all assets that have successfully collided with the corresponding content in the intelligence set.

[0222] The global module 156 is also used to store the relevant information in the clue database if the collision fails; when it is determined that at least one of the assets has a security threat, the security threat is investigated in the clue database based on the relevant information to determine whether the security threat exists in other parts of the assets.

[0223] When there are multiple threat intelligences provided by different security vendors, the key module 157 is used to obtain relevant information about key assets, which includes content related to threat intelligences; to collide the relevant information of the key assets with multiple threat intelligences; if the collision is successful, intermediate alarm data is generated based on the relevant information of the key assets that were successfully collided and the corresponding content in the multiple threat intelligences; and the alarm data belonging to the same attack event in the intermediate alarm data are clustered according to multiple preset dimensions to generate and output clustered alarm data.

[0224] The key module 157 is also used to obtain the relevant logs of the key asset if the collision is successful, and the recording period of the relevant logs is longer than a preset period; based on the key fields in the relevant logs, to determine and output attack-related information.

[0225] Based on the same inventive concept, as an implementation of the above method, this application also provides a security analysis device based on threat intelligence.

[0226] Figure 16 This is a schematic diagram of the structure of the threat intelligence-based security analysis device in the embodiments of this application. Figure 3 See Figure 16 As shown, the device may include: a second acquisition module 161, a clustering module 162, a third acquisition module 163, a second collision module 164, and a second output module 165. The second acquisition module 161, the clustering module 162, the third acquisition module 163, the second collision module 164, and the second output module 165 are connected sequentially.

[0227] The second acquisition module 161 is used to acquire multiple threat intelligences provided by different security vendors.

[0228] Clustering module 162 is used to cluster the intelligence belonging to the same attack event from the multiple threat intelligences according to multiple preset dimensions to obtain an intelligence set.

[0229] The third acquisition module 163 is used to acquire relevant information about all assets, including content related to threat intelligence.

[0230] The second collision module 164 is used to collide the relevant information of all assets with the intelligence set. If the collision is successful, the process proceeds to the second output module 165.

[0231] The second output module 165 is used to generate and output asset alarm data based on the relevant information of all the assets that have successfully collided and the corresponding content in the intelligence set.

[0232] Furthermore, as a response to Figure 16In addition to the refinement and expansion of the illustrated device, this application also provides a security analysis device based on threat intelligence.

[0233] Figure 17 This is a schematic diagram of the structure of the threat intelligence-based security analysis device in the embodiments of this application. Figure 4 See Figure 17 As shown, the device may include: a second acquisition module 171, a clustering module 172, a third acquisition module 173, a second collision module 174, a second output module 175, and a clue investigation module 176. The clustering module 172, the third acquisition module 173, the second collision module 174, and the second output module 175 are connected in sequence, and the clue investigation module 176 is connected to the second collision module 174.

[0234] The second acquisition module 171 is used to acquire multiple threat intelligences provided by different security vendors.

[0235] Clustering module 172 is used to cluster the intelligence belonging to the same attack event from the multiple threat intelligences according to multiple preset dimensions to obtain an intelligence set.

[0236] The third acquisition module 173 is used to acquire relevant information about all assets, including content related to threat intelligence.

[0237] The second collision module 174 is used to collide the relevant information of all assets with the intelligence set. If the collision is successful, the process proceeds to the second output module 175. If the collision fails, the process proceeds to the clue investigation module 176.

[0238] The second output module 175 is used to generate and output asset alarm data based on the relevant information of all the assets that have successfully collided and the corresponding content in the intelligence set.

[0239] The clue investigation module 176 is used to store the relevant information in the clue database; when it is determined that at least one of the assets has a security threat, the security threat is investigated in the clue database based on the relevant information to determine whether the security threat exists in other parts of the assets.

[0240] Based on the same inventive concept, as an implementation of the above method, this application also provides a security analysis device based on threat intelligence.

[0241] Figure 18 This is a schematic diagram of the structure of the threat intelligence-based security analysis device in the embodiments of this application. Figure 5 See Figure 18As shown, the device may include: a fourth acquisition module 181, a third collision module 182, a second generation module 183, and a third output module 184. The fourth acquisition module 181, the third collision module 182, the second generation module 183, and the third output module 184 are connected sequentially.

[0242] The fourth acquisition module 181 is used to acquire relevant information about key assets, including content related to threat intelligence.

[0243] The third collision module 182 is used to collide the relevant information of the key assets with multiple threat intelligences provided by different security vendors. If the collision is successful, the process proceeds to the second generation module 183.

[0244] The second generation module 183 is used to generate intermediate alarm data based on the relevant information of the key assets that have successfully collided and the corresponding content in the multiple threat intelligences.

[0245] The third output module 184 is used to cluster alarm data belonging to the same attack event in the intermediate alarm data according to multiple preset dimensions, and generate and output clustered alarm data.

[0246] Furthermore, as a response to Figure 18 In addition to the refinement and expansion of the illustrated device, this application also provides a security analysis device based on threat intelligence.

[0247] Figure 19 This is a schematic diagram of the structure of the threat intelligence-based security analysis device in the embodiments of this application. Figure 6 See Figure 19 As shown, the device may include: a fourth acquisition module 191, a third collision module 192, a second generation module 193, a third output module 194, and a tracing module 195. The fourth acquisition module 191, the third collision module 192, the second generation module 193, and the third output module 194 are connected sequentially, and the tracing module 195 is connected to the third collision module 192.

[0248] The fourth acquisition module 191 is used to acquire relevant information about key assets, including content related to threat intelligence.

[0249] The third collision module 192 is used to collide the relevant information of the key assets with multiple threat intelligences provided by different security vendors. If the collision is successful, the process proceeds to the second generation module 193 and the source tracing module 195.

[0250] The second generation module 193 is used to generate intermediate alarm data based on the relevant information of the key assets that have successfully collided and the corresponding content in the multiple threat intelligences.

[0251] The third output module 194 is used to cluster alarm data belonging to the same attack event in the intermediate alarm data according to multiple preset dimensions, and generate and output clustered alarm data.

[0252] The tracing module 195 is used to obtain relevant logs of the key assets, the recording period of the relevant logs being longer than a preset period; based on the key fields in the relevant logs, attack-related information is determined and output.

[0253] It should be noted that the description of the above device embodiments is similar to the description of the above method embodiments, and has similar beneficial effects. For technical details not disclosed in the device embodiments of this application, please refer to the description of the method embodiments of this application for understanding.

[0254] Based on the same inventive concept, embodiments of this application also provide an electronic device.

[0255] Figure 20 This is a schematic diagram of the electronic device in an embodiment of this application. See also... Figure 20 As shown, the electronic device may include: a processor 201, a memory 202, and a bus 203; wherein the processor 201 and the memory 202 communicate with each other through the bus 203; the processor 201 is used to call program instructions in the memory 202 to execute the methods in one or more of the above embodiments.

[0256] It should be noted that the descriptions of the above electronic device embodiments are similar to those of the above method embodiments, and have similar beneficial effects. For technical details not disclosed in the electronic device embodiments of this application, please refer to the descriptions of the method embodiments of this application for understanding.

[0257] Based on the same inventive concept, embodiments of this application also provide a computer-readable storage medium, which may include: a stored program; wherein, when the program is running, it controls the device where the storage medium is located to execute the methods in one or more of the above embodiments.

[0258] It should be noted that the descriptions of the storage medium embodiments above are similar to those of the method embodiments above, and have similar beneficial effects. For technical details not disclosed in the storage medium embodiments of this application, please refer to the descriptions of the method embodiments of this application for understanding.

[0259] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A security analysis method based on threat intelligence, characterized in that, The method comprises: obtaining a log chain to be analyzed, the log chain to be analyzed being composed of a plurality of real-time logs that have collided with threat intelligence; secondarily colliding the log chain to be analyzed with the threat intelligence; generating secondary alarm data based on the corresponding content of the log chain to be analyzed and the threat intelligence that collide successfully; wherein the number of threat intelligence is a plurality, and the plurality of threat intelligence is provided by different security vendors; the method further comprises: obtaining a plurality of threat intelligence; clustering the intelligence in the plurality of threat intelligence that belongs to the same attack event according to a plurality of preset dimensions to obtain an intelligence set; obtaining relevant information of all assets, the relevant information containing content related to threat intelligence; colliding the relevant information of all assets with the intelligence set; if the collision is successful, generating and outputting asset alarm data based on the corresponding content of the relevant information of all assets and the intelligence set that collide successfully; wherein the number of threat intelligence is a plurality, and the plurality of threat intelligence is provided by different security vendors; the method further comprises: obtaining relevant information of key assets, the relevant information containing content related to threat intelligence; colliding the relevant information of key assets with a plurality of threat intelligence; if the collision is successful, generating intermediate alarm data based on the corresponding content of the relevant information of key assets and the plurality of threat intelligence that collide successfully; clustering the alarm data in the intermediate alarm data that belongs to the same attack event according to a plurality of preset dimensions to generate and output clustered alarm data.

2. The method of claim 1, wherein, The method further comprises: obtaining a log chain to be analyzed, the log chain to be analyzed being composed of a plurality of real-time logs that have collided with threat intelligence; 3. The method of claim 2, wherein, secondarily colliding the log chain to be analyzed with the threat intelligence; generating secondary alarm data based on the corresponding content of the log chain to be analyzed and the threat intelligence that collide successfully; 4. The method of claim 1, wherein, wherein the number of threat intelligence is a plurality, and the plurality of threat intelligence is provided by different security vendors; the method further comprises: obtaining a plurality of threat intelligence; 5. The method of claim 1, wherein, clustering the intelligence in the plurality of threat intelligence that belongs to the same attack event according to a plurality of preset dimensions to obtain an intelligence set; obtaining relevant information of all assets, the relevant information containing content related to threat intelligence; colliding the relevant information of all assets with the intelligence set; if the collision is successful, generating and outputting asset alarm data based on the corresponding content of the relevant information of all assets and the intelligence set that collide successfully; wherein the number of threat intelligence is a plurality, and the plurality of threat intelligence is provided by different security vendors; the method further comprises: obtaining relevant information of key assets, the relevant information containing content related to threat intelligence; colliding the relevant information of key assets with a plurality of threat intelligence; if the collision is successful, generating intermediate alarm data based on the corresponding content of the relevant information of key assets and the plurality of threat intelligence that collide successfully; clustering the alarm data in the intermediate alarm data that belongs to the same attack event according to a plurality of preset dimensions to generate and output clustered alarm data. The method further comprises: obtaining a log chain to be analyzed, the log chain to be analyzed being composed of a plurality of real-time logs that have collided with threat intelligence; secondarily colliding the log chain to be analyzed with the threat intelligence; generating secondary alarm data based on the corresponding content of the log chain to be analyzed and the threat intelligence that collide successfully; wherein the number of threat intelligence is a plurality, and the plurality of threat intelligence is provided by different security vendors; the method further comprises: obtaining a plurality of threat intelligence; clustering the intelligence in the plurality of threat intelligence that belongs to the same attack event according to a plurality of preset dimensions to obtain an intelligence set; obtaining relevant information of all assets, the relevant information containing content related to threat intelligence; colliding the relevant information of all assets with the intelligence set; if the collision is successful, generating and outputting asset alarm data based on the corresponding content of the relevant information of all assets and the intelligence set that collide successfully; wherein the number of threat intelligence is a plurality, and the plurality of threat intelligence is provided by different security vendors; the method further comprises: obtaining relevant information of key assets, the relevant information containing content related to threat intelligence; colliding the relevant information of key assets with a plurality of threat intelligence; if the collision is successful, generating intermediate alarm data based on the corresponding content of the relevant information of key assets and the plurality of threat intelligence that collide successfully; clustering the alarm data in the intermediate alarm data that belongs to the same attack event according to a plurality of preset dimensions to generate and output clustered alarm data. The obtained alarm data is fused with the secondary alarm data, de-duplicated, and normalized to obtain and output an alarm data set.

6. The method according to any one of claims 1 to 5, characterized in that, The method further includes: If the collision fails, the related information is stored in a clue library; When it is determined that there is a security threat in at least one of the assets, the related information is searched for the security threat in the clue library to determine whether the security threat exists in other assets.

7. The method according to any one of claims 1 to 5, characterized in that, After the related information of the key asset is collided with multiple threat intelligence, the method further includes: If the collision succeeds, the related log of the key asset is obtained, and a recording period of the related log is greater than a preset period; Based on the key field in the related log, attack-related information is determined and output.

8. A security analysis apparatus based on threat intelligence, characterized by, The device includes: A first obtaining module is configured to obtain a log chain to be analyzed, the log chain to be analyzed being composed of multiple real-time logs that have been collided with threat intelligence; A first collision module is configured to perform secondary collision of the log chain to be analyzed and the threat intelligence; A first generating module is configured to generate secondary alarm data based on corresponding content in the log chain to be analyzed and the threat intelligence that succeeds in the collision; When the number of threat intelligence is multiple, and the multiple threat intelligence is provided by different security manufacturers, a global module is configured to obtain multiple threat intelligence, cluster intelligence in the multiple threat intelligence that belongs to a same attack event according to multiple preset dimensions to obtain an intelligence set, obtain related information of all assets, the related information including content related to threat intelligence, perform collision of the related information of all assets and the intelligence set, and if the collision succeeds, generate and output asset alarm data based on corresponding content in the related information of all assets and the intelligence set that succeeds in the collision; When the number of threat intelligence is multiple, and the multiple threat intelligence is provided by different security manufacturers, a key module is configured to obtain related information of a key asset, the related information including content related to threat intelligence, perform collision of the related information of the key asset and multiple threat intelligence, if the collision succeeds, generate intermediate alarm data based on corresponding content in the related information of the key asset and the multiple threat intelligence that succeeds in the collision, and cluster alarm data in the intermediate alarm data that belongs to a same attack event according to multiple preset dimensions to generate and output clustered alarm data.

9. An electronic device, comprising: The electronic device includes a processor, a memory, and a bus; wherein the processor, the memory, and the bus complete communication with each other; the processor is configured to invoke program instructions in the memory to execute the method in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, The storage medium includes a stored program; wherein when the program runs, the device where the storage medium is located executes the method in any one of claims 1 to 7.

Citation Information

Patent Citations

  • AI-combined cloud computing service threat analysis method and server

    CN114896401A

  • Network security early warning system and method based on threat intelligence and log collision

    CN117857082A