An information data distribution method, device, equipment, medium and product
By acquiring device resource information through an intelligence management platform and building a personalized threat intelligence database, device compatibility issues were resolved, and the accuracy and efficiency of threat detection were improved.
Patent Information
- Application Number
- CN202410220271.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-02-28
- Publication Date
- 2025-12-09
- Estimated Expiration
- 2044-02-28
AI Technical Summary
Existing threat intelligence signature databases cannot meet the compatibility requirements of different types and configurations of local security devices, resulting in insufficient accuracy and efficiency in threat detection and security analysis.
By acquiring multi-dimensional resource information of security devices through an intelligence management platform, evaluating the information based on device-related information and intelligence-related information, building a personalized threat intelligence database, and distributing it to security devices, the type and capacity of the intelligence database are ensured to meet the device's needs.
It improved the accuracy and efficiency of threat detection for security equipment, thereby enhancing security operation efficiency.
Smart Images

Figure CN118802275B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of security, in particular, to an intelligence data distribution method, device, equipment, medium and product. BACKGROUND
[0002] With the increasing complexity of network attacks and attack means, traditional security protection devices have been unable to meet the complex and variable network threats. At present, threat intelligence has become an important means of threat detection and security analysis. At present, in addition to using traditional protection means, local security devices also begin to use threat intelligence feature library technology to enhance the perception ability of threats and risks. The local intelligence feature library is output by a cloud threat intelligence platform, and the local security device loads the threat intelligence feature library, without querying the cloud, and directly completes the query and matching in the local. There are many types of local security devices, and the operating systems of the devices are different, and the memory and storage of the devices are different. At present, the compatibility of the intelligence feature library for security devices is poor, and therefore the current threat intelligence feature library cannot meet the actual needs of the current security devices. SUMMARY
[0003] The present disclosure provides an intelligence data distribution method, device, equipment, medium and product.
[0004] According to a first aspect of the present disclosure, an intelligence data distribution method is provided, applied to an intelligence management platform, and the method comprises:
[0005] Obtaining multi-dimensional resource information reported by a security device; wherein the resource information comprises device-related information and intelligence-related information;
[0006] Performing resource evaluation based on the device-related information and the intelligence-related information in the resource information to obtain an evaluation result; wherein the evaluation result is used to indicate the type and intelligence capacity of a threat intelligence library of the security device, and the required intelligence quantity of each intelligence attribute preference of the threat intelligence library of the type;
[0007] Constructing a threat intelligence library of the security device based on the evaluation result, and distributing the threat intelligence library to the security device.
[0008] Further, the device-related information includes but is not limited to device type, device operating system and version information, device memory, device storage space, and device supported intelligence library format; the intelligence-related information includes but is not limited to at least one intelligence attribute preference, intelligence type proportion of each intelligence attribute preference, and priority of each intelligence attribute preference.
[0009] Further, the resource evaluation based on the device-related information and the intelligence-related information in the resource information obtains an evaluation result, comprising:
[0010] Based on the device type of the security device, determine the basic threat intelligence library matched with the security device in the basic threat intelligence library;
[0011] Based on the format and storage space of the intelligence library supported by the security device, determine the intelligence capacity of the matched basic threat intelligence library; wherein the intelligence capacity is used to indicate the maximum number of intelligence data allowed to be stored in the matched basic threat intelligence library;
[0012] Based on the intelligence-related information of the security device, determine the intelligence quantity of the intelligence corresponding to each intelligence attribute preference in the matched basic threat intelligence library;
[0013] Determine the evaluation result based on the matched basic threat intelligence library, the intelligence capacity and the intelligence quantity.
[0014] Further, the determination of the intelligence capacity of the matched basic threat intelligence library based on the format and storage space of the intelligence library supported by the security device comprises:
[0015] Determine the space size occupied by each intelligence based on the format of the intelligence library supported by the device;
[0016] Based on the storage space and the space size occupied by each intelligence, calculate the maximum number of intelligence data, and determine the maximum number of intelligence data as the intelligence capacity.
[0017] Further, the determination of the intelligence quantity of the intelligence corresponding to each intelligence attribute preference in the matched basic threat intelligence library based on the intelligence-related information of the security device comprises:
[0018] Obtain the intelligence type proportion of each intelligence attribute preference;
[0019] Based on the intelligence type proportion and the intelligence capacity, calculate the intelligence quantity of each intelligence attribute preference.
[0020] Further, the construction of the threat intelligence library of the security device based on the evaluation result comprises:
[0021] Sort the intelligence data to which each intelligence attribute preference belongs based on the priority to obtain a first sorting result;
[0022] Sort the intelligence data to which each intelligence attribute preference belongs based on the intelligence discovery time of the intelligence data to obtain a second sorting result;
[0023] screening, in the second sorting result, intelligence data matching the intelligence quantity preferred by each of the intelligence attributes, to obtain a threat intelligence base of the security device after screening.
[0024] Further, the method further comprises:
[0025] In response to a reporting request initiated by the security device, verifying the legality of a security authentication identifier in the reporting request;
[0026] In a case where the security authentication identifier is verified to be legal, receiving resource information carried in the reporting request.
[0027] Further, before acquiring the multi-dimensional device resource information reported by the security device, the method further comprises:
[0028] receiving device registration information sent by the security device, and performing device registration on the security device;
[0029] After the security device is successfully registered, feeding back an account activation link to a user to which the security device belongs.
[0030] In response to an activation operation of the account activation link by the user to which the security device belongs, generating the security authentication identifier, and feeding back the security authentication identifier to the security device.
[0031] Further, before distributing the threat intelligence base to the security device, the method further comprises:
[0032] determining an intelligence query rule of the security device for the threat intelligence base, and distributing the threat intelligence base and the intelligence query rule to the security device.
[0033] Further, the method further comprises:
[0034] In a case where an update request triggered by the security device is detected, updating the threat intelligence base of the security device.
[0035] According to a second aspect of the present disclosure, an intelligence data distribution method is provided, applied to a security device, and the method comprises:
[0036] reporting, to an intelligence management platform, multi-dimensional resource information; wherein the resource information comprises device-related information and intelligence-related information;
[0037] obtain a threat intelligence base fed back by the intelligence management platform; wherein the threat intelligence base is constructed based on an evaluation result obtained by the intelligence management platform from resource evaluation based on the device-related information and the intelligence-related information in the resource information, the evaluation result being used to indicate a type and intelligence capacity of the threat intelligence base of the security device, and a threat intelligence base of the type favoring intelligence quantity of required intelligence for each intelligence attribute.
[0038] According to a third aspect of the present disclosure, there is provided an intelligence data distribution apparatus arranged in an intelligence management platform, the apparatus comprising:
[0039] a resource obtaining module configured to obtain multi-dimensional resource information reported by a security device; wherein the resource information comprises device-related information and intelligence-related information;
[0040] a resource evaluation module configured to perform resource evaluation based on the device-related information and the intelligence-related information in the resource information, to obtain an evaluation result; wherein the evaluation result is used to indicate a type and intelligence capacity of a threat intelligence base of the security device, and a threat intelligence base of the type favoring intelligence quantity of required intelligence for each intelligence attribute;
[0041] an intelligence base constructing module configured to construct a threat intelligence base of the security device based on the evaluation result, and distribute the threat intelligence base to the security device.
[0042] According to a fourth aspect of the present disclosure, there is provided an intelligence data distribution apparatus arranged in a security device, the apparatus comprising:
[0043] a resource reporting module configured to report multi-dimensional resource information to an intelligence management platform; wherein the resource information comprises device-related information and intelligence-related information;
[0044] an intelligence base obtaining module configured to obtain a threat intelligence base fed back by the intelligence management platform; wherein the threat intelligence base is constructed based on an evaluation result obtained by the intelligence management platform from resource evaluation based on the device-related information and the intelligence-related information in the resource information, the evaluation result being used to indicate a type and intelligence capacity of the threat intelligence base of the security device, and a threat intelligence base of the type favoring intelligence quantity of required intelligence for each intelligence attribute.
[0045] According to a fifth aspect of the present disclosure, there is provided an electronic device. The electronic device comprises a memory and a processor, the memory having a computer program stored thereon, and the processor implementing the method as described above when executing the program.
[0046] According to a sixth aspect of the present disclosure, a computer readable storage medium is provided, having stored thereon a computer program which, when executed by a processor, implements the above method of the present disclosure.
[0047] According to a seventh aspect of the present disclosure, a computer program product is provided, comprising a computer program which, when executed by a processor, implements the above method of the present disclosure.
[0048] The present disclosure provides an intelligence data distribution method, device, equipment, medium and product. In the embodiments of the present disclosure, first, multi-dimensional resource information reported by a security device can be acquired; wherein the resource information comprises device-related information and intelligence-related information; then, resource evaluation is performed based on the device-related information and the intelligence-related information in the resource information to obtain an evaluation result; wherein the evaluation result is used to indicate the type and intelligence capacity of a threat intelligence library of the security device, and the intelligence quantity of intelligence required by the threat intelligence library of the type for each intelligence attribute preference; finally, the threat intelligence library of the security device is constructed based on the evaluation result, and the threat intelligence library is distributed to the security device.
[0049] In the above embodiments, the intelligence management platform can customize the threat intelligence library for the security device in a personalized manner through the evaluation result of the device-related information and the intelligence-related information, which can not only improve the accuracy of threat detection of the security device, but also improve the detection efficiency and the efficiency of security operation.
[0050] In order to make the above objectives, features and advantages of the present disclosure more apparent, the following will describe preferred embodiments in detail, and the accompanying drawings will be described as follows. BRIEF DESCRIPTION OF DRAWINGS
[0051] In order to more clearly illustrate the technical solutions of the embodiments of the present disclosure, the following will briefly introduce the drawings needed to be used in the embodiments. The drawings herein are incorporated into the specification and form a part of the specification, which illustrate the embodiments consistent with the present disclosure, and are used to explain the technical solutions of the present disclosure together with the specification. It should be understood that the following drawings only show some embodiments of the present disclosure, and therefore should not be considered as a limitation to the scope, and for those skilled in the art, other related drawings can also be obtained without creative labor.
[0052] Figure 1 A flowchart of an intelligence data distribution method provided by an exemplary embodiment of the present disclosure;
[0053] Figure 2 A corresponding relationship diagram of an intelligence management platform and a security device provided by an exemplary embodiment of the present disclosure;
[0054] Figure 3 Flow chart of an intelligence data distribution method according to another example embodiment of the present disclosure;
[0055] Figure 4 Schematic diagram of resource evaluation by an intelligence management platform according to an example embodiment of the present disclosure;
[0056] Figure 5 Flow chart of an intelligence data distribution method according to another example embodiment of the present disclosure;
[0057] Figure 6 Schematic diagram of a security device registration process according to an example embodiment of the present disclosure;
[0058] Figure 7 Flow chart of an intelligence data distribution method according to another example embodiment of the present disclosure;
[0059] Figure 8 Schematic diagram of security device resource reporting according to an example embodiment of the present disclosure;
[0060] Figure 9 Schematic diagram of an intelligence query rule according to an example embodiment of the present disclosure;
[0061] Figure 10 Flow chart of an intelligence data distribution method according to another example embodiment of the present disclosure;
[0062] Figure 11 Schematic block diagram of functional modules of an intelligence data distribution apparatus according to an example embodiment of the present disclosure;
[0063] Figure 12 Schematic block diagram of functional modules of an intelligence data distribution apparatus according to another example embodiment of the present disclosure;
[0064] Figure 13 Structural block diagram of an electronic device according to an example embodiment of the present disclosure;
[0065] Figure 14 Structural block diagram of a computer system according to an example embodiment of the present disclosure. DETAILED DESCRIPTION
[0066] To make the objects, technical solutions and advantages of the embodiments of the present disclosure clearer, the following will be combined with the accompanying drawings of the embodiments of the present disclosure to make a clear and complete description of the technical solutions in the embodiments of the present disclosure. Obviously, the described embodiments are only part of the embodiments of the present disclosure and are not all the embodiments. The components of the embodiments of the present disclosure generally described and shown in the accompanying drawings can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present disclosure provided in the accompanying drawings is not intended to limit the scope of the claimed present disclosure, but only represents selected embodiments of the present disclosure. Based on the embodiments of the present disclosure, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present disclosure.
[0067] It should be noted that similar reference numerals and letters refer to similar items throughout the accompanying drawings, and therefore, once an item is defined in one drawing, it need not be further defined and explained in subsequent drawings.
[0068] The term "and / or" herein only describes an associated relationship, which means that there can be three relationships, for example, A and / or B can mean that A exists alone, A and B exist together, and B exists alone. In addition, the term "at least one" herein means any one of a plurality or any combination of at least two of a plurality, for example, including at least one of A, B, and C can mean including any one or more elements selected from the set consisting of A, B, and C.
[0069] It is found through research that as the complexity of network attacks and attack means continue to improve, traditional security protection devices have been unable to meet the complex and variable network threats. At present, threat intelligence has become an important means of threat detection and security analysis. At the present stage, in addition to using traditional protection means, local security devices begin to gradually use threat intelligence feature library technology to enhance the perception ability of threats and risks. The local intelligence feature library is output by a cloud threat intelligence platform, and after the local security device loads the threat intelligence feature library, it does not need to query the cloud, and can directly complete the query and matching in the local. There are many types of local security devices, and the operating systems of the devices are different, and the memory and storage of the devices are different. At present, the compatibility of the intelligence feature library for security devices is poor, and therefore the current threat intelligence feature library cannot meet the actual needs of the current security devices.
[0070] Based on the above research, the present disclosure provides an intelligence data distribution method, device, equipment, medium and product. In the embodiments of the present application, first, multi-dimensional resource information reported by a security device can be acquired; wherein the resource information includes device-related information and intelligence-related information, then, resource evaluation is performed based on the device-related information and the intelligence-related information in the resource information to obtain an evaluation result; wherein the evaluation result is used to indicate the type and intelligence capacity of the threat intelligence library of the security device, and the intelligence quantity of the threat intelligence library of the type required for each intelligence attribute preference, finally, the threat intelligence library of the security device is constructed based on the evaluation result, and the threat intelligence library is distributed to the security device.
[0071] In the above embodiments, the intelligence management platform customizes the threat intelligence library for the security device based on the evaluation result of the device-related information and the intelligence-related information, which not only improves the accuracy of threat detection of the security device, but also improves the detection efficiency and the efficiency of security operation.
[0072] In order to facilitate the understanding of the present embodiment, first, a data query method disclosed by the present embodiment is introduced in detail, and the execution subject of the data query method provided by the present embodiment is generally an electronic device with certain computing capability. In some possible implementation manners, the data query method can be realized by calling the computer readable instructions stored in the memory by the processor.
[0073] Referring to Figure 1 Fig. 1 is a flowchart of a first intelligence data distribution method provided by the present embodiment, and the data query method can be applied to an intelligence management platform, and the method comprises steps S101-S103, wherein:
[0074] Step S101: acquiring multi-dimensional resource information reported by a security device.
[0075] Here, the intelligence management platform acquires multi-dimensional resource information reported by a security device, wherein the resource information includes device-related information and intelligence-related information.
[0076] In a possible embodiment, as Figure 2 shown, Figure 2 an exemplary correspondence relationship diagram between the intelligence management platform and the security device is shown, the intelligence management platform can be in communication connection with n security devices, and can acquire multi-dimensional resource information reported by each security device.
[0077] Here, the multi-dimensional resource information includes: device-related information and intelligence-related information, wherein the device-related information includes but is not limited to: device type Type, device operating system and version information Operating_System, device memory, device storage space S, and device supported intelligence library format Data_Format; the intelligence-related information includes but is not limited to: at least one intelligence attribute preference Data_P, intelligence type proportion of each intelligence attribute preference Data_N, and priority of each intelligence attribute preference Data_L.
[0078] It should be noted that the storage space S of the device can be understood as the size of the space for storing intelligence data, and the size of the storage space S is set by the security device according to its own business needs, and the present disclosure does not make specific limitations on this.
[0079] The format Data_Format of the intelligence library supported by the device is reported by the security device according to its own business needs. For example, the format Data_Format of the intelligence library supported by the device can be txt, sql, xml, etc., and the format Data_Format of the intelligence library supported by the device is not limited here.
[0080] The contents of the intelligence attribute preference Data_P, the intelligence type proportion Data_N, and the priority of each intelligence attribute preference Data_L are not specifically limited here, and the security device can customize them according to its own business needs.
[0081] For example, when the intelligence attribute preference Data_P is "phishing type", the intelligence type proportion Data_N can be "50%", and the priority of this intelligence attribute preference Data_L is "1"; when the intelligence attribute preference Data_P is "APT intelligence", the intelligence type proportion Data_N is "40%", and the priority of this intelligence attribute preference Data_L is "2"; when the intelligence attribute preference Data_P is "mining virus", the intelligence type proportion Data_N is "10%", and the priority of this intelligence attribute preference Data_L is "3", wherein priority 1 represents the highest priority, and the larger the number, the lower the priority.
[0082] Step S102: performing resource evaluation based on the device-related information and the intelligence-related information in the resource information to obtain an evaluation result.
[0083] After the intelligence management platform obtains the multi-dimensional resource information reported by the security device, the intelligence management platform can perform resource evaluation based on the device-related information and the intelligence-related information in the resource information to obtain an evaluation result.
[0084] Here, the information management platform obtains the evaluation result by performing resource evaluation on the device-related information and the information-related information reported by the security device, wherein the evaluation result is used to indicate the type and information capacity of the threat information base of the security device, and the threat information base of the type prefers the information quantity of the required information for each information attribute.
[0085] Step S103: constructing the threat information base of the security device based on the evaluation result, and distributing the threat information base to the security device.
[0086] After the information management platform obtains the evaluation result by performing resource evaluation on the device-related information and the information-related information in the resource information, the information management platform can construct the threat information base of the security device based on the evaluation result, and distribute the threat information base to the security device.
[0087] In one possible embodiment, after the information management platform obtains the evaluation result, the information management platform constructs the threat information base of the security device based on the evaluation result, and distributes the threat information base to the security device. It should be noted that, before the information management platform constructs the threat information base of the security device, the information management platform has constructed different basic threat information bases according to the device type Type of the security device, and on this basis, the information management platform performs more fine-grained construction on the basic threat information base according to the evaluation result, and finally constructs the threat information base of the different security devices.
[0088] In the above embodiments, the information management platform customizes the threat information base for the security device based on the evaluation result of the device-related information and the information-related information, which not only improves the accuracy of threat detection of the security device, but also improves the detection efficiency and the security operation efficiency.
[0089] In one embodiment, as shown in Figure 3 the above steps include the following steps:
[0090] Step S301: determining the basic threat information base matched with the security device in the basic threat information base based on the device type of the security device.
[0091] Here, after obtaining the multi-dimensional resource information reported by the security device, the information management platform can perform resource evaluation based on the device-related information and the information-related information in the resource information. In specific implementation, the information management platform can determine the basic threat information base matched with the security device in the basic threat information base based on the device type of the security device.
[0092] It should be noted that the intelligence management platform pre-constructs different intelligence sub-libraries according to different device types, that is, the intelligence management platform constructs various different basic threat intelligence libraries according to different device types. Here, the basic threat intelligence library matched with the security type can be determined in the already constructed basic threat intelligence library according to the device type of the security device; subsequent more fine-grained construction can be performed according to various intelligence library construction elements (such as intelligence capacity and intelligence quantity) reported by the security device.
[0093] In a possible embodiment, Figure 4 An exemplary schematic diagram of the intelligence management platform performing resource assessment is shown.
[0094] As Figure 4 shown, after the intelligence management platform obtains the resource information including device-related information and intelligence-related information reported by the security device, the intelligence management platform determines the basic threat intelligence library matched with the security device based on the device type Type in the device-related information. For example, when the device type Type is a mobile terminal, the basic threat intelligence library matched with the mobile terminal is determined to be a mobile terminal type intelligence library; when the device type Type is an Internet of Things device, the basic threat intelligence library matched with the Internet of Things device is determined to be an Internet of Things type intelligence library.
[0095] In step S302, the intelligence capacity of the matched basic threat intelligence library is determined based on the format and storage space of the intelligence library supported by the device of the security device.
[0096] After the intelligence management platform determines the basic threat intelligence library matched with the security device based on the device type of the security device, the intelligence capacity of the matched basic threat intelligence library can be determined based on the format and storage space of the intelligence library supported by the device of the security device, wherein the intelligence capacity is used to indicate the maximum number of intelligence data allowed to be stored in the matched basic threat intelligence library.
[0097] In a possible embodiment, the intelligence management platform determines the intelligence capacity of the matched basic threat intelligence library based on the format and storage space of the intelligence library supported by the device of the security device, and specifically includes the following steps:
[0098] First, the size of the space occupied by each intelligence is determined based on the format of the intelligence library supported by the device;
[0099] Second, the maximum number of intelligence data is calculated based on the storage space and the size of the space occupied by each intelligence, and the maximum number of intelligence data is determined as the intelligence capacity.
[0100] Here, the format of the intelligence library supported by the device can be understood as the format type of the intelligence data in the intelligence library. Specifically, asFigure 4 As shown, the intelligence management platform determines the basic threat intelligence database that matches the security device based on the device type. Then, based on the Data_Format (e.g., txt, sql, xml, etc.) of the intelligence database supported by the security device, the intelligence management platform determines the space size m of each piece of intelligence data under the format type of the intelligence data. Then, based on the storage space S reported by the security device and the space size occupied by each piece of intelligence data, the platform calculates the maximum number of intelligence data Num_max, with the formula Num_max = S / m, and determines the maximum number of intelligence data data as the intelligence capacity.
[0101] Step S303: Based on the intelligence-related information of the security device, determine the number of intelligences corresponding to each intelligence attribute preference in the matching basic threat intelligence database.
[0102] After determining the intelligence capacity of the matching basic threat intelligence database based on the format and storage space of the intelligence database supported by the security device, the intelligence management platform can determine the intelligence quantity corresponding to each intelligence attribute preference in the matching basic threat intelligence database based on at least one intelligence attribute preference of the security device, the proportion of intelligence types of each intelligence attribute preference, and the priority of each intelligence attribute preference.
[0103] In one possible embodiment, the intelligence management platform determines the number of intelligence items corresponding to each intelligence attribute preference in the matching basic threat intelligence database based on the intelligence-related information of the security device. Specifically, this includes the following steps:
[0104] First, obtain the percentage of intelligence types for each intelligence attribute preference;
[0105] Secondly, based on the proportion of intelligence types and intelligence capacity, the amount of intelligence for each intelligence attribute preference is calculated.
[0106] Specifically, such as Figure 4 As shown, after determining the intelligence capacity of the matching basic threat intelligence database based on the format and storage space of the intelligence database supported by the security device, the intelligence management platform can obtain the proportion of intelligence types for each intelligence attribute preference, Data_N. Then, based on the proportion of intelligence types for each intelligence attribute preference, Data_N, and the determined intelligence capacity, the intelligence quantity for each intelligence attribute preference, Data_P, is calculated.
[0107] Here, the quantity of intelligence for each intelligence attribute preference can be determined by calculating the proportion of intelligence types and the intelligence capacity. This processing method ensures that the total quantity of intelligence for each intelligence attribute preference satisfies the following relationship with the intelligence capacity:
[0108] Num_max=∑Data_Pi*Data_Nj(i,j=0,1,2,3....n).
[0109] Step S304 involves matching the basic threat intelligence database, intelligence capacity, and intelligence quantity to determine the assessment results.
[0110] After determining the number of intelligences corresponding to each intelligence attribute preference in the matching basic threat intelligence database based on intelligence-related information from security devices, the intelligence management platform can determine the matching basic threat intelligence database, intelligence capacity, and intelligence quantity as the assessment results described above.
[0111] In one possible embodiment, the intelligence management platform will determine the evaluation result by matching the basic threat intelligence database, intelligence capacity, and intelligence quantity, specifically including the following steps:
[0112] First, the intelligence data belonging to each intelligence attribute preference are sorted according to priority to obtain the first sorting result;
[0113] Secondly, based on the intelligence discovery time of the intelligence data, the intelligence data belonging to each intelligence attribute preference are sorted to obtain a second sorting result;
[0114] Next, in the second sorting results, intelligence data that matches the amount of intelligence for each intelligence attribute preference is filtered out, resulting in a threat intelligence database for security devices.
[0115] Specifically, such as Figure 4 As shown, after determining the number of intelligence items corresponding to each intelligence attribute preference in the matching basic threat intelligence database based on intelligence-related information from security devices, the intelligence management platform can sort the intelligence data belonging to each intelligence attribute preference (Data_P) based on priority (Data_L) to obtain the first sorting result. For example, the intelligence data belonging to the highest priority intelligence attribute preference can be placed at the front.
[0116] Then, the intelligence management platform sorts the intelligence data according to the intelligence discovery time of the intelligence data, and obtains a second sorting result.
[0117] For example, intelligence data with priority Data_L = 1 becomes first priority intelligence based on the intelligence discovery time, intelligence data with priority Data_L = 2 becomes second priority intelligence based on the intelligence discovery time, and so on, intelligence data with priority Data_L = n becomes nth priority intelligence based on the intelligence discovery time.
[0118] Finally, the intelligence data that matches the number of intelligences for each intelligence attribute preference is filtered from the second sorting results. After filtering, the threat intelligence database of the security devices is obtained, which is then distributed to each security device by the intelligence management platform.
[0119] In this embodiment, firstly, the intelligence management platform identifies a basic threat intelligence database that matches the security device within the basic threat intelligence database. Then, based on the format and storage space of the intelligence database supported by the security device, the intelligence management platform determines the intelligence capacity of the matching basic threat intelligence database. Next, based on the intelligence-related information of the security device, the intelligence management platform determines the quantity of intelligence corresponding to each intelligence attribute preference in the matching basic threat intelligence database. Finally, the intelligence management platform uses the matching basic threat intelligence database, intelligence capacity, and intelligence quantity to determine the evaluation result. This final evaluation result is used by the intelligence management platform to construct the threat intelligence database for the security device. The constructed threat intelligence database has high accuracy, further improving the reliability of the intelligence data distribution method.
[0120] In one embodiment, such as Figure 5 As shown, before obtaining the multi-dimensional device resource information reported by the security device, the method further includes the following steps:
[0121] Step S501: Receive device registration information sent by the security device and register the security device.
[0122] Before acquiring multi-dimensional device resource information reported by security devices, the intelligence management platform can receive device registration information sent by security devices and register the security devices.
[0123] In one possible embodiment, such as Figure 6 As shown, Figure 6 An exemplary schematic diagram of the security device registration process is shown. Before the intelligence management platform obtains the multi-dimensional device resource information reported by the security device, the owner of the security device needs to register on the intelligence management platform. The intelligence management platform receives the device registration information sent by the security device. For example, the registration information can be the device name, device manufacturer, device unique hardware serial number, registrant's email address, and login password. It should be noted that the content of the device registration information is not limited here.
[0124] Step S502: After the security device is successfully registered, an account activation link is sent to the user who owns the security device.
[0125] The intelligence management platform receives device registration information sent by security devices and registers the security devices. After successful registration, it sends an account activation link to the user to whom the security device belongs.
[0126] In a possible embodiment, as shown in Figure 6 After the security device is successfully registered, the intelligence management platform feeds back an account activation link to the user to whom the security device belongs, and the activation link is used to generate a security authentication identifier.
[0127] In response to the activation operation of the user to whom the security device belongs on the account activation link, the security authentication identifier is generated, and the security authentication identifier is fed back to the security device.
[0128] After the intelligence management platform feeds back the account activation link to the user to whom the security device belongs, in response to the activation operation of the user to whom the security device belongs on the account activation link, the intelligence management platform generates a security authentication identifier, and feeds back the security authentication identifier to the security device.
[0129] In a possible embodiment, as shown in Figure 6 After the user to whom the security device belongs clicks the activation, in response to the activation operation of the user to whom the security device belongs on the account activation link, the intelligence management platform generates a security authentication identifier token, and the generation manner of the security authentication identifier token is not limited herein.
[0130] Exemplarily, the security authentication identifier token can be generated according to the password, the unique hardware serial number of the device and other elements set during the registration, and the generated security authentication identifier token is used to verify the legality of the security authentication identifier in the security device reporting request. It should be noted that the security authentication identifier token is only one implementation manner of the security authentication, and other security authentication manners can also be adopted to implement, which are not limited herein.
[0131] In the embodiment, first, the intelligence management platform receives the device registration information sent by the security device, and performs device registration on the security device; then, after the security device is successfully registered, the intelligence management platform feeds back an account activation link to the user to whom the security device belongs; finally, in response to the activation operation of the user to whom the security device belongs on the account activation link, the intelligence management platform generates a security authentication identifier, and feeds back the security authentication identifier to the security device, and the generated security authentication identifier token is used to verify the legality of the security authentication identifier in the security device reporting request, which improves the security and reliability of the intelligence data distribution method.
[0132] In one embodiment, as shown in Figure 7 The above step of obtaining the multidimensional resource information reported by the security device specifically includes the following steps:
[0133] In response to the reporting request initiated by the security device, the legality of the security authentication identifier in the reporting request is verified.
[0134] Before the intelligence management platform acquires the multi-dimensional resource information reported by the security device, the intelligence management platform verifies the legality of the security authentication identifier in the reporting request initiated by the security device in response to the reporting request.
[0135] In a possible embodiment, as shown in Figure 8 , Figure 8 An exemplary security device resource reporting schematic diagram is shown, and in the process of acquiring the multi-dimensional resource information reported by the security device by the intelligence management platform, the intelligence management platform verifies the legality of the security authentication identifier token in the reporting request initiated by the security device in response to the reporting request. If the security authentication identifier token is legal, the resource information reported thereby is received, otherwise the resource information reported thereby is rejected.
[0136] Step S702, in the case where the security authentication identifier is verified to be legal, the resource information carried in the reporting request is received.
[0137] In a possible embodiment, as shown in Figure 8 , the intelligence management platform verifies the legality of the security authentication identifier in the reporting request initiated by the security device in response to the reporting request, and in the case where the security authentication identifier is verified to be legal, the intelligence management platform receives the resource information carried in the reporting request.
[0138] In this embodiment, the intelligence management platform verifies the legality of the security authentication identifier in the reporting request initiated by the security device in response to the reporting request, and in the case where the security authentication identifier is verified to be legal, the intelligence management platform receives the resource information carried in the reporting request, otherwise rejects the resource information carried in the reporting request, further improving the security of the intelligence data distribution method.
[0139] In one embodiment, before distributing the threat intelligence library to the security device, the method further includes the following steps:
[0140] Determining the intelligence query rule of the security device for the threat intelligence library, and distributing the threat intelligence library and the intelligence query rule to the security device.
[0141] In a possible embodiment, before distributing the threat intelligence library to the security device, the intelligence management platform determines the intelligence query rule of the security device for the threat intelligence library, and distributes the threat intelligence library and the intelligence query rule to the security device.
[0142] Here, the intelligence management platform can customize the intelligence library query scheme based on the device memory reported by the security device and in combination with the specific business needs of the security device.
[0143] Exemplarily, as shown in Figure 9 , Figure 9An intelligence query rule schematic diagram is exemplarily shown. For a business with high security response, the query condition can be customized according to the priority Data_L. For example, first, the first priority intelligence is queried. If there is no matching, no high risk is returned first. Then, the second priority intelligence is matched. If there is no matching, no medium risk is returned. In this way, until the lowest priority intelligence is matched, the process is ended.
[0144] Here, it should be noted that the intelligence query rule can be customized and adjusted according to business needs, which is not limited here.
[0145] In the embodiment, the intelligence management platform determines the intelligence query rule of the security device for the threat intelligence library, and distributes the threat intelligence library and the intelligence query rule to the security device. The intelligence query rule can be customized and adjusted according to business needs, which improves the expansibility and flexibility of the intelligence data distribution method.
[0146] In the embodiment of the present disclosure, an update process of the threat intelligence library of the security device can also be set. Wherein, the update process of the threat intelligence library triggered by the security device can be set, and the update process of the threat intelligence library triggered by the intelligence management platform can also be set.
[0147] In an optional implementation, the update process of the threat intelligence library specifically includes the following steps:
[0148] In the case of detecting the update request triggered by the security device, updating the threat intelligence library of the security device.
[0149] Here, the security device can detect whether the business needs and the device information of the security device have changed, and trigger the update of the threat intelligence library of the security device in the case of detecting that the change has occurred. At this time, the security device can send an update request to the intelligence management platform to request the intelligence management platform to update the threat intelligence library of the security device. Here, the multi-dimensional resource information reported by the security device can be obtained.
[0150] In the case of detecting that the business needs of the security device and the device information of the security device have changed, the intelligence management platform re-obtains the multi-dimensional resource information reported by the security device, and then executes the above steps S102 and S103 on the re-reported resource information, thereby realizing the update of the threat intelligence library of the security device. In specific implementation, resource evaluation can be performed based on the device-related information and intelligence-related information in the resource information to obtain an evaluation result. Finally, the intelligence management platform reconstructs the threat intelligence library of the security device based on the evaluation result, and distributes the updated threat intelligence library to the security device.
[0151] In another optional implementation, the update process of the threat intelligence library specifically includes the following steps:
[0152] The information management platform can detect whether the corresponding basic threat information database has changed, for example, can detect whether the data volume and data content of the information data in the corresponding basic threat information database have changed, and trigger updating of the threat information database of the security device in the case of detecting that the corresponding basic threat information database has changed. At this time, the information management platform reacquires the multidimensional resource information reported by the security device, and then performs the above steps S102 and S103 on the re-reported resource information, thereby realizing updating of the threat information database of the security device. In specific implementation, resource evaluation can be performed based on the device-related information and information-related information in the resource information to obtain an evaluation result, and finally the information management platform reconstructs the threat information database of the security device based on the evaluation result, and distributes the updated threat information database to the security device.
[0153] In the embodiment, the information management platform reconstructs the threat information database of the security device and distributes the updated threat information database to the security device in the case of detecting that the business requirement of the security device and the device information of the security device have changed, and the updated threat information database meets the business requirement of the security device, thereby further improving the flexibility and reliability of the information data distribution method.
[0154] In one embodiment, as shown in Figure 10 An information data distribution method is provided, applied to a security device, including the following steps:
[0155] Step S1001, reporting multidimensional resource information to an information management platform.
[0156] In a possible embodiment, the security device can report multidimensional resource information to the information management platform, wherein the resource information includes device-related information and information-related information.
[0157] The device-related information includes but is not limited to device type, operating system and version information of the device, memory of the device, storage space of the device, and format of the threat information database supported by the device; and the information-related information includes but is not limited to at least one information attribute preference, information type proportion of each information attribute preference, and priority of each information attribute preference.
[0158] Step S1002, obtaining a threat information database fed back by the information management platform.
[0159] In a possible embodiment, after the security device reports the multi-dimensional resource information to the intelligence management platform, the security device obtains the threat intelligence library fed back by the intelligence management platform, wherein the threat intelligence library is constructed based on the evaluation result obtained by the intelligence management platform based on the device-related information and the intelligence-related information in the resource information, the evaluation result is used to indicate the type and intelligence capacity of the threat intelligence library of the security device, and the threat intelligence library of the type needs intelligence of the intelligence quantity preferred for each intelligence attribute.
[0160] In the embodiment, the security device reports the multi-dimensional resource information to the intelligence management platform, the resource information is processed by the intelligence management platform to generate the threat intelligence library, the security device obtains the threat intelligence library fed back by the intelligence management platform, and each security device corresponds to different threat intelligence libraries, thereby improving the accuracy of the intelligence data distribution method.
[0161] In the case of dividing the functional modules according to the respective functions, the disclosure further provides an intelligence data distribution apparatus, which is arranged in the intelligence management platform and can be a server or a chip applied to the server. Figure 11 An example of the intelligence data distribution apparatus provided by the disclosure is shown in a functional block diagram. As shown in the figure, the intelligence data distribution apparatus includes: Figure 11
[0162] The resource obtaining module 1101 is configured to obtain the multi-dimensional resource information reported by the security device, wherein the resource information includes device-related information and intelligence-related information.
[0163] The resource evaluation module 1102 is configured to perform resource evaluation based on the device-related information and the intelligence-related information in the resource information to obtain an evaluation result, wherein the evaluation result is used to indicate the type and intelligence capacity of the threat intelligence library of the security device, and the threat intelligence library of the type needs intelligence of the intelligence quantity preferred for each intelligence attribute.
[0164] The intelligence library construction module 1103 is configured to construct the threat intelligence library of the security device based on the evaluation result and distribute the threat intelligence library to the security device.
[0165] In one embodiment, the device-related information includes but is not limited to the device type, the operating system and version information of the device, the memory of the device, the storage space of the device, and the format of the intelligence library supported by the device; and the intelligence-related information includes but is not limited to at least one intelligence attribute preference, the proportion of the intelligence type of each intelligence attribute preference, and the priority of each intelligence attribute preference.
[0166] In one embodiment, the resource evaluation module 1102 includes:
[0167] The first determining unit is configured to determine, based on the device type of the security device, a basic threat intelligence library matched with the security device from a plurality of basic threat intelligence libraries;
[0168] The second determining unit is configured to determine, based on the format and storage space of the device-supported intelligence library of the security device, an intelligence capacity of the matched basic threat intelligence library, wherein the intelligence capacity is used to indicate a maximum number of intelligence data allowed to be stored in the matched basic threat intelligence library.
[0169] The third determining unit is configured to determine, based on the intelligence-related information of the security device, an intelligence quantity of intelligence corresponding to each intelligence attribute preference in the matched basic threat intelligence library.
[0170] The fourth determining unit is configured to determine the evaluation result based on the matched basic threat intelligence library, the intelligence capacity and the intelligence quantity.
[0171] In one embodiment, the resource evaluation module 1102 comprises:
[0172] The fifth determining unit is configured to determine, based on the format of the device-supported intelligence library, a space size occupied by each piece of intelligence.
[0173] The sixth determining unit is configured to calculate the maximum number of intelligence data based on the storage space and the space size occupied by each piece of intelligence, and determine the maximum number of intelligence data as the intelligence capacity.
[0174] In one embodiment, the resource evaluation module 1102 comprises:
[0175] The first obtaining unit is configured to obtain a proportion of intelligence types of each intelligence attribute preference.
[0176] The calculating unit is configured to calculate, based on the proportion of intelligence types and the intelligence capacity, an intelligence quantity of each intelligence attribute preference.
[0177] In one embodiment, the resource evaluation module 1102 comprises:
[0178] The second obtaining unit is configured to sort, based on the priority, intelligence data belonging to each intelligence attribute preference to obtain a first sorting result.
[0179] The third obtaining unit is configured to sort, based on an intelligence discovery time of the intelligence data, the intelligence data belonging to each intelligence attribute preference to obtain a second sorting result.
[0180] A fourth obtaining unit is configured to filter, from the second sorting result, intelligence data matching the quantity of intelligence of each intelligence attribute preference, and obtain a threat intelligence library of the security device after the filtering.
[0181] In one embodiment, the resource obtaining module 1101 comprises:
[0182] A verification unit is configured to verify the legality of a security authentication identifier in the reporting request in response to the reporting request initiated by the security device.
[0183] A receiving unit is configured to receive resource information carried in the reporting request in a case where the security authentication identifier is verified to be legal.
[0184] In one embodiment, the apparatus further comprises:
[0185] A device registration module is configured to receive device registration information sent by the security device, and perform device registration on the security device.
[0186] A first feedback module is configured to feed back an account activation link to a user to whom the security device belongs after the security device is successfully registered.
[0187] A second feedback module is configured to generate the security authentication identifier and feed back the security authentication identifier to the security device in response to an activation operation of the account activation link by the user to whom the security device belongs.
[0188] In one embodiment, the apparatus further comprises:
[0189] An intelligence query rule sending module is configured to determine an intelligence query rule of the intelligence query service of the security device with respect to the threat intelligence library, and distribute the threat intelligence library and the intelligence query rule to the security device.
[0190] In one embodiment, the apparatus further comprises:
[0191] An intelligence library upgrading module is configured to update the threat intelligence library of the security device in a case where an update request triggered by the security device is detected.
[0192] In a case where each functional module is divided according to each function, the embodiments of the present disclosure further provide an intelligence data distribution apparatus arranged in a security device, which can be a server or a chip applied to a server. Figure 12 A functional module schematic block diagram of the intelligence data distribution apparatus provided by an exemplary embodiment of the present disclosure is shown in FIG. 2. Figure 12 As shown in FIG. 2, the intelligence data distribution apparatus comprises:
[0193] The resource reporting module 1201 is configured to report multi-dimensional resource information to an intelligence management platform; wherein the resource information comprises device-related information and intelligence-related information.
[0194] The intelligence library obtaining module 1202 is configured to obtain a threat intelligence library fed back by the intelligence management platform; wherein the threat intelligence library is constructed based on an evaluation result of resource evaluation of the intelligence management platform based on the device-related information and the intelligence-related information in the resource information, the evaluation result is used to indicate a type and intelligence capacity of a threat intelligence library of the security device, and a threat intelligence library of the type needs intelligence quantity of intelligence for each intelligence attribute preference.
[0195] Figure 13 A structural schematic diagram of an electronic device provided for an example embodiment of the present disclosure is shown in FIG. 13. Figure 13 As shown in the figure, the electronic device 1300 comprises at least one processor 1301 and a memory 1302 coupled to the processor 1301, and the processor 1301 can execute corresponding steps in the above-mentioned method disclosed by the embodiments of the present disclosure.
[0196] The above-mentioned processor 1301 can also be referred to as a central processing unit (CPU), which can be an integrated circuit chip with signal processing capability. Each step in the above-mentioned method disclosed by the embodiments of the present disclosure can be completed by integrated logic circuits of hardware or instructions in the form of software in the processor 1301. The above-mentioned processor 1301 can be a general-purpose processor, a digital signal processor (DSP), an ASIC, a field-programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor. The steps of the method disclosed in conjunction with the embodiments of the present disclosure can be directly embodied as hardware coding executed by the processor, or executed by a combination of hardware and software modules in the coding processor. The software module can be located in the memory 1302, such as random access memory, flash memory, read-only memory, programmable read-only memory or electrically erasable programmable memory, register or other mature storage medium in the art. The processor 1301 reads information in the memory 1302 and combines hardware to complete the steps of the above-mentioned method.
[0197] In addition, various operations / processes according to the present disclosure are implemented by software and / or firmware, which can be loaded from a storage medium or a network to a computer system with a special hardware structure, such as a server or a personal computer, to implement the embodiments of the present disclosure. Figure 14The computer system 1400 shown is equipped with the programs that constitute the software. When various programs are installed, the computer system is able to perform various functions, including functions such as those described above. Figure 14 A block diagram of a computer system provided for an exemplary embodiment of this disclosure.
[0198] Computer system 1400 is intended to represent various forms of digital electronic computer devices, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. Electronic devices may also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0199] like Figure 14 As shown, the computer system 1400 includes a computing unit 1401, which can perform various appropriate actions and processes based on a computer program stored in a read-only memory (ROM) 1402 or a computer program loaded from a storage unit 1408 into a random access memory (RAM) 1403. The RAM 1403 may also store various programs and data required for the operation of the computer system 1400. The computing unit 1401, ROM 1402, and RAM 1403 are interconnected via a bus 1404. An input / output (I / O) interface 1405 is also connected to the bus 1404.
[0200] Multiple components in computer system 1400 are connected to I / O interface 1405, including: input unit 1406, output unit 1407, storage unit 1408, and communication unit 1409. Input unit 1406 can be any type of device capable of inputting information into computer system 1400. Input unit 1406 can receive input numerical or character information and generate key signal inputs related to user settings and / or function control of the electronic device. Output unit 1407 can be any type of device capable of presenting information and may include, but is not limited to, a monitor, speaker, video / audio output terminal, vibrator, and / or printer. Storage unit 1408 may include, but is not limited to, hard disks and optical disks. Communication unit 1409 allows computer system 1400 to exchange information / data with other devices via a network such as the Internet, and may include, but is not limited to, modems, network cards, infrared communication devices, wireless communication transceivers, and / or chipsets, such as Bluetooth™ devices, WiFi devices, WiMax devices, cellular communication devices, and / or the like.
[0201] The computing unit 1401 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 1401 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, or the like. The computing unit 1401 performs various methods and processes described above. For example, in some embodiments, the above-described methods disclosed by the embodiments of the present disclosure can be implemented as a computer software program tangibly embodied in a machine-readable medium, such as the storage unit 1408. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 1300 via the ROM 1402 and / or the communication unit 1409. In some embodiments, the computing unit 1401 can be configured to perform the above-described methods disclosed by the embodiments of the present disclosure by any other suitable means, for example, by means of firmware.
[0202] The embodiments of the present disclosure also provide a computer-readable storage medium, wherein when instructions in the computer-readable storage medium are executed by a processor of an electronic device, the electronic device is enabled to perform the above-described methods disclosed by the embodiments of the present disclosure.
[0203] The computer-readable storage medium in the embodiments of the present disclosure can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. The above-described computer-readable storage medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the above. More specifically, the above-described computer-readable storage medium can include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or a flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
[0204] The above-described computer-readable medium can be contained in the above-described electronic device; or can exist separately without being assembled into the electronic device.
[0205] The embodiments of the present disclosure also provide a computer program product, comprising a computer program, wherein the computer program is executed by a processor to implement the above-described methods disclosed by the embodiments of the present disclosure.
[0206] Computer program code for carrying out operations of the present disclosure can be written in any one or more of a variety of programming languages or combinations of languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).
[0207] The flow diagrams and the block diagrams in the drawings are meant as possible implementations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flow diagrams and the block diagrams can represent a module, a segment, or a portion of code, which comprises one or more executable instructions for implementing the specified logical function(s). It should also be noted that in some alternative implementations, the functions noted in the blocks can occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently or the blocks can sometimes be executed in the reverse order, depending upon the functionality involved. It will also be noted that each block of the block diagrams and / or flow diagrams, and combinations thereof, can be implemented by special purpose hardware-based systems that perform the specified functions or operations, or combinations of special purpose hardware and computer instructions.
[0208] The modules, components or units described in the embodiments of the present disclosure can be implemented by software or by hardware. In some cases, the name of the module, component or unit does not constitute a limitation on the module, component or unit itself.
[0209] The functions described above in the detailed description of embodiments of the present disclosure can be implemented in one or more hardware logic components or by computer instructions that are executed in a hardware logic component. For example, and without limitation, illustrative hardware logic components that can be used include Field-programmable Gate Arrays (FPGAs), Application-specific Integrated Circuits (ASICs), Application-specific Standard Products (ASSPs), System-on-a-chip systems (SOCs), Complex Programmable Logic Devices (CPLDs), etc.
[0210] The above description is merely exemplary of some embodiments of the present disclosure and of the principles thereof. It is to be understood that the disclosure is not limited in scope to the particular embodiments described herein, which are intended as examples only, and that the scope of the disclosure is, instead, defined by the appended claims, along with the full range of equivalents to which such claims are entitled. For example, the features of the various embodiments described above can be combined with each other, unless expressly prohibited by the above description.
[0211] While some specific embodiments of the present disclosure have been described in detail, those skilled in the art should understand that the above examples are merely exemplary and are not intended to limit the scope of the present disclosure. Those skilled in the art should understand that the above embodiments can be modified without departing from the scope and spirit of the present disclosure. The scope of the present disclosure is defined by the appended claims.
Claims
1. An information data distribution method characterized by comprising: The application is applied to an information management platform, and comprises: obtaining multi-dimensional resource information reported by a security device; wherein the resource information comprises device-related information and information-related information; performing resource evaluation based on the device-related information and the information-related information in the resource information to obtain an evaluation result; wherein the evaluation result is used to indicate the type and information capacity of a threat information base of the security device, and the threat information base of the type needs information quantity of information preferred by each information attribute; constructing the threat information base of the security device based on the evaluation result, and distributing the threat information base to the security device.
2. The method of claim 1, wherein, The device-related information comprises but is not limited to device type, operating system and version information of the device, memory of the device, storage space of the device, and format of information base supported by the device; and the information-related information comprises but is not limited to at least one information attribute preference, information type proportion of each information attribute preference, and priority of each information attribute preference.
3. The method according to claim 1 or 2, characterized in that, The resource evaluation based on the device-related information and the information-related information in the resource information to obtain an evaluation result comprises: determining a matched basic threat information base in a basic threat information base based on the device type of the security device; determining information capacity of the matched basic threat information base based on the format and storage space of the information base supported by the device of the security device; wherein the information capacity is used to indicate maximum number of information data allowed to be stored in the matched basic threat information base; determining information quantity of information corresponding to each information attribute preference in the matched basic threat information base based on the information-related information of the security device; determining the evaluation result based on the matched basic threat information base, the information capacity and the information quantity.
4. The method of claim 3, wherein, The determination of the information capacity of the matched basic threat information base based on the format and storage space of the information base supported by the device of the security device comprises: determining space size occupied by each information based on the format of the information base supported by the device; calculating the maximum number of information data based on the storage space and the space size occupied by each information, and determining the maximum number of information data as the information capacity.
5. The method of claim 3, wherein, The determination of the information quantity of information corresponding to each information attribute preference in the matched basic threat information base based on the information-related information of the security device comprises: obtaining information type proportion of each information attribute preference; calculating information quantity of each information attribute preference based on the information type proportion and the information capacity.
6. The method of claim 3, wherein, The construction of the threat information base of the security device based on the evaluation result comprises: sorting information data belonging to each information attribute preference based on priority to obtain a first sorting result; sorting information data belonging to each information attribute preference based on information discovery time of the information data to obtain a second sorting result; screening information data matched with the information quantity of each information attribute preference in the second sorting result to obtain the threat information base of the security device after screening.
7. The method of claim 1, wherein, The method further comprises: In response to a report request initiated by the security device, verifying the legality of a security authentication identifier in the report request; In a case where the security authentication identifier is verified to be legal, receiving resource information carried in the report request.
8. The method of claim 7, wherein, Before acquiring the multi-dimensional device resource information reported by the security device, the method further comprises: Receiving device registration information sent by the security device, and performing device registration on the security device; After the device registration on the security device is successful, feeding back an account activation link to a user to whom the security device belongs; In response to an activation operation of the account activation link by the user to whom the security device belongs, generating the security authentication identifier, and feeding back the security authentication identifier to the security device.
9. The method of claim 1, wherein, Before distributing the threat intelligence library to the security device, the method further comprises: Determining an intelligence query rule of the security device for the threat intelligence library, and distributing the threat intelligence library and the intelligence query rule to the security device.
10. The method of claim 1, wherein, The method further comprises: In a case where an update request triggered by the security device is detected, updating the threat intelligence library of the security device.
11. An information data distribution method characterized by comprising: Applied to a security device, comprising: Reporting multi-dimensional resource information to an intelligence management platform; wherein the resource information comprises device-related information and intelligence-related information; Acquiring a threat intelligence library fed back by the intelligence management platform; wherein the threat intelligence library is constructed based on an evaluation result obtained by the intelligence management platform based on the device-related information and the intelligence-related information in the resource information, and the evaluation result is used to indicate the type and intelligence capacity of the threat intelligence library of the security device, and the threat intelligence library of the type prefers the intelligence quantity of the required intelligence for each intelligence attribute.
12. An information data distribution apparatus characterized by comprising: Set in an intelligence management platform, the device comprises: A resource acquisition module configured to acquire multi-dimensional resource information reported by a security device; wherein the resource information comprises device-related information and intelligence-related information; A resource evaluation module configured to perform resource evaluation based on the device-related information and the intelligence-related information in the resource information, and obtain an evaluation result; wherein the evaluation result is used to indicate the type and intelligence capacity of the threat intelligence library of the security device, and the threat intelligence library of the type prefers the intelligence quantity of the required intelligence for each intelligence attribute; An intelligence library construction module configured to construct a threat intelligence library of the security device based on the evaluation result, and distribute the threat intelligence library to the security device.
13. An information data distribution apparatus characterized by comprising: Set in a security device, the device comprises: A resource reporting module configured to report multi-dimensional resource information to an intelligence management platform; wherein the resource information comprises device-related information and intelligence-related information; An intelligence database acquisition module is configured to acquire a threat intelligence database fed back by the intelligence management platform. The threat intelligence database is constructed based on an evaluation result of resource evaluation of the intelligence management platform based on the device-related information and the intelligence-related information in the resource information. The evaluation result is used to indicate a type and intelligence capacity of the threat intelligence database of the security device, and a preferred intelligence quantity of the threat intelligence database of the type for each intelligence attribute.
14. An electronic device, comprising: Comprises: at least one processor; a memory for storing instructions executable by the at least one processor; wherein the at least one processor is configured to execute the instructions to implement the method of any one of claims 1-11.
15. A computer-readable storage medium, characterized in that, When the instructions in the computer readable storage medium are executed by the processor of the electronic device, the electronic device is enabled to perform the method of any one of claims 1-11.
16. A computer program product comprising a computer program, characterized in that, The computer program, when executed by the processor, implements the steps of the method of any one of claims 1-11.
Citation Information
Patent Citations
Threat intelligence-based network security detection method and system
CN107819783A
Intelligence data distribution method and device
CN111835788A