Threat intelligence determination method and apparatus, storage medium
By classifying target data according to preset threat detection conditions, target threat intelligence is generated, which solves the problem of low accuracy of threat intelligence in existing technologies and achieves higher accuracy.
Patent Information
- Application Number
- CN202411080579.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-07
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2044-08-07
AI Technical Summary
Existing technologies that perform source analysis on newly added domain name and IP information in target data have a low accuracy rate in identifying threat intelligence.
By setting up threat detection conditions, the potential threat information in the target data is determined to be known threat information, unknown threat information, or false alarm threat information, and target threat intelligence is generated according to the category, including processing methods such as static analysis and dynamic sandbox operation.
It improves the accuracy of threat intelligence identification and avoids the inaccuracies caused by source analysis in traditional methods.
Smart Images

Figure CN119011235B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data processing, network security and other related technical fields, in particular, relates to a threat intelligence determination method and device, and a storage medium. BACKGROUND
[0002] Threat hunting and security intelligence production are important components in the field of network security. Threat hunting is a proactive defense process that actively seeks potential or unknown threats by analyzing network and system traffic data. Security intelligence production is a process of collecting, analyzing and distributing information about threats. By sharing and utilizing this information, organizations can prepare in advance and more effectively defend against upcoming threats. The combination of these two fields provides strong support for modern network security strategies. Traditional methods match the newly added domain name information and IP information in the target data to calculate the homologous analysis result corresponding to the target data, and finally determine the threat intelligence of the target data in the historical threat intelligence according to the homologous analysis result, but this method does not include the process of threat hunting and intelligence production.
[0003] In view of the problem that in the related art, by performing homologous analysis on the newly added domain name information and IP information of the target data, the threat intelligence matching the target data is determined in the historical threat intelligence according to the analysis result, resulting in a relatively low accuracy of determining the threat intelligence, no effective solution has been proposed so far. SUMMARY
[0004] The main purpose of the present application is to provide a threat intelligence determination method and device, and a storage medium, to solve the problem that in the related art, by performing homologous analysis on the newly added domain name information and IP information of the target data, the threat intelligence matching the target data is determined in the historical threat intelligence according to the analysis result, resulting in a relatively low accuracy of determining the threat intelligence.
[0005] In order to achieve the above object, according to one aspect of the present application, a threat intelligence determination method is provided. The method comprises: determining potential threat information in target data, wherein the target data is security event data, traffic data or log data with a probability of existence of a threat greater than a preset probability; determining a target category corresponding to the potential threat information according to a preset threat detection condition, wherein the target category is one of a first threat category, a second threat category and a third threat category, the first threat category represents that the potential threat information is included in historical threat information, the second threat category represents that the potential threat information is not included in the historical threat information, and the third threat category represents that the potential threat information is false positive threat information; and determining target threat intelligence corresponding to the target data according to a processing method corresponding to the target category in a case where the target category is the first threat category or the second threat category.
[0006] Further, in a case where the target category is the second threat category, generating target threat intelligence corresponding to the target data according to the processing method corresponding to the target category comprises: obtaining intrusion indicator information corresponding to the potential threat information; compiling and packaging the intrusion indicator information to obtain a target configuration file; issuing the target configuration file to a target terminal having a file upload permission; obtaining a target execution file returned by a security device deployed on the target terminal after matching terminal log files related to the target data and the intrusion indicator information in the target configuration file, wherein the terminal log files are log files related to the target data; and generating target threat intelligence corresponding to the target data according to the target execution file.
[0007] Further, generating target threat intelligence corresponding to the target data according to the target execution file comprises: performing static analysis on the target execution file to obtain a first analysis result corresponding to the target execution file; running the target execution file through a target sandbox to obtain a second analysis result corresponding to the target execution file; and generating target threat intelligence corresponding to the target data according to the first analysis result and the second analysis result.
[0008] Further, the method further comprises: in a case where the target execution file is received, adding intrusion indicator information corresponding to the potential threat information to a list of intrusion indicator information.
[0009] Further, if the target category is the first threat category, the target threat intelligence corresponding to the target data is determined according to a processing method corresponding to the target category, including: determining at least one first threat intelligence that matches the potential threat information successfully and whose number of times is higher than a threshold according to historical query records; and determining the target threat intelligence corresponding to the target data according to the at least one first threat intelligence.
[0010] Further, the target category corresponding to the potential threat information is determined according to a preset threat detection condition, including: judging whether the potential threat information satisfies the preset threat detection condition to obtain a judgment result; and determining the target category corresponding to the potential threat information according to the judgment result.
[0011] Further, the target category corresponding to the potential threat information is determined according to the judgment result, including: if the judgment result indicates that the potential threat information satisfies the preset threat detection condition, determining that the target category corresponding to the potential threat information is the first threat category; if the judgment result indicates that the potential threat information does not satisfy the preset threat detection condition, obtaining category input information input by a target object; and determining that the target category corresponding to the potential threat information is the second threat category or the third threat category according to the category input information.
[0012] To achieve the above object, according to another aspect of the present application, a threat intelligence determination device is provided. The device comprises: a first determination unit configured to determine potential threat information in target data, wherein the target data is security event data, traffic data or log data whose threat probability is greater than a preset probability; a second determination unit configured to determine a target category corresponding to the potential threat information according to a preset threat detection condition, wherein the target category is one of a first threat category, a second threat category and a third threat category, the first threat category indicates that the potential threat information is included in historical threat information, the second threat category indicates that the potential threat information is not included in the historical threat information, and the third threat category indicates that the potential threat information is a false alarm threat information; and a third determination unit configured to determine target threat intelligence corresponding to the target data according to a processing method corresponding to the target category if the target category is the first threat category or the second threat category.
[0013] Further, the third determining unit comprises: a first obtaining module, configured to, if the target category is the second threat category, obtain intrusion indicator information corresponding to the potential threat information; a processing module, configured to compile and package the intrusion indicator information to obtain a target configuration file; a delivering module, configured to deliver the target configuration file to a target terminal having a file uploading permission; a second obtaining module, configured to obtain a target execution file returned by a security device deployed on the target terminal after the security device matches terminal log files and the intrusion indicator information in the target configuration file successfully, wherein the terminal log files are log files related to the target data; and a generating module, configured to generate target threat intelligence corresponding to the target data according to the target execution file.
[0014] Further, the generating module comprises: an analyzing submodule, configured to perform static analysis on the target execution file to obtain a first analysis result corresponding to the target execution file; a running submodule, configured to run the target execution file through a target sandbox to obtain a second analysis result corresponding to the target execution file; and a generating submodule, configured to generate target threat intelligence corresponding to the target data according to the first analysis result and the second analysis result.
[0015] Further, the apparatus further comprises an adding unit, configured to, if the target execution file is received, add intrusion indicator information corresponding to the potential threat information to an intrusion indicator information list.
[0016] Further, the third determining unit comprises: a first determining module, configured to, if the target category is the first threat category, determine at least one first threat intelligence that matches the potential threat information successfully according to historical query records, wherein the number of times of matching is higher than a threshold value; and a second determining module, configured to determine target threat intelligence corresponding to the target data according to the at least one first threat intelligence.
[0017] Further, the second determining unit comprises: a judging module, configured to judge whether the potential threat information satisfies the preset threat detection condition to obtain a judgment result; and a third determining module, configured to determine a target category corresponding to the potential threat information according to the judgment result.
[0018] Further, the third determining module comprises: a first determining submodule, configured to determine that the target category corresponding to the potential threat information is the first threat category if the judgment result indicates that the potential threat information satisfies the preset threat detection condition; an acquiring submodule, configured to acquire category input information input by a target object if the judgment result indicates that the potential threat information does not satisfy the preset threat detection condition; and a second determining submodule, configured to determine that the target category corresponding to the potential threat information is the second threat category or the third threat category according to the category input information.
[0019] In order to achieve the above object, according to an aspect of the present application, a computer readable storage medium is provided, the storage medium stores a program, wherein the program controls the device where the storage medium is located to execute the threat intelligence determining method according to any one of the above embodiments when the program is running.
[0020] In order to achieve the above object, according to another aspect of the present application, an electronic device is also provided, the electronic device comprises one or more processors and a memory, the memory is configured to store the threat intelligence determining method according to any one of the above embodiments implemented by the one or more processors.
[0021] In the technical solution provided by the present application, the preset threat detection condition is used to determine whether the potential threat information in the target data is known threat information (i.e. the first threat category), unknown threat information (i.e. the second threat category) or false threat information (i.e. the third threat category). In the case that the potential threat information is known threat information or unknown threat information, the target threat intelligence of the target data is generated according to the corresponding processing method to determine the processing strategy of the potential threat information. In this way, the potential threat information can be quickly classified by the preset threat detection condition, and it can be accurately determined whether the potential threat information is known threat information or unknown threat information or false threat information, and then the corresponding processing method is determined according to the category of the potential threat information to obtain the target threat intelligence. The problem of inaccurate threat intelligence caused by the traditional method of matching and calculating the newly added domain name information and IP information in the target data to determine the homologous analysis result corresponding to the target data, and finally determining the threat intelligence of the target data in the historical threat intelligence according to the homologous analysis result is avoided, and the determination accuracy of the threat intelligence is improved. BRIEF DESCRIPTION OF DRAWINGS
[0022] The accompanying drawings, which form a part of the present application, are intended to provide further understanding of the present application, and the illustrative embodiments of the present application and their description serve the purpose of explaining the present application. The accompanying drawings should not be construed as an inappropriate limitation on the present application. In the drawings:
[0023] Figure 1 is a flowchart of the threat intelligence determining method according to an embodiment of the present application;
[0024] Figure 2 FIG. 1 is a schematic diagram of a threat hunting seed discovery framework according to an embodiment of the present application;
[0025] Figure 3 FIG. 2 is a schematic diagram of a threat wanted and capture framework according to an embodiment of the present application;
[0026] Figure 4 FIG. 3 is a schematic diagram of an intelligence production framework according to an embodiment of the present application;
[0027] Figure 5 FIG. 4 is a schematic diagram of a security intelligence operation framework according to an embodiment of the present application;
[0028] Figure 6 FIG. 5 is a schematic diagram of a threat hunting seed verification framework according to an embodiment of the present application;
[0029] Figure 7 FIG. 6 is a schematic diagram of a method for determining threat intelligence according to an embodiment of the present application;
[0030] Figure 8 FIG. 7 is a schematic diagram of a device for determining threat intelligence according to an embodiment of the present application;
[0031] Figure 9 FIG. 8 is a schematic diagram of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0032] It should be noted that the embodiments and features of the present application can be combined with each other without conflict. The present application will be described in detail below with reference to the accompanying drawings and in conjunction with the embodiments.
[0033] In order to enable persons skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by persons skilled in the art without creative labor should fall within the scope of protection of the present application.
[0034] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and in the above drawings are used to distinguish similar objects, and do not necessarily have to describe a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device including a series of steps or units does not have to be limited to only those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0035] It should be noted that the relevant information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for display, analyzed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties. For example, an interface is provided between the system and the relevant user or institution. Before obtaining the relevant information, the interface needs to send a request to the aforementioned user or institution, and after receiving the consent information feedback from the aforementioned user or institution, the relevant information is obtained.
[0036] The present application will be described below in conjunction with the preferred implementation steps, Figure 1 is a flowchart of a threat intelligence determination method provided according to an embodiment of the present application. The method can be executed by a server, which can be implemented by an independent server or a server cluster composed of multiple servers, as shown in Figure 1 , the method includes the following steps:
[0037] Step S101, determining potential threat information in target data, wherein the target data is security event data, traffic data or log data with a probability of threat greater than a preset probability.
[0038] Optionally, the potential threat information in the target data is determined through a threat hunting seed discovery framework. Figure 2 is a schematic diagram of a threat hunting seed (i.e. potential threat information) discovery framework according to an embodiment of the present application. As shown in Figure 2 , the threat hunting seed discovery framework can determine the potential threat information in the target data in at least one of the following ways:
[0039] Method one, analysis through high-confidence security threat intelligence IOC (Indicator of Compromise), i.e. matching through verified IOC intelligence to find threat hunting seeds (i.e. the above-mentioned potential threat information), for example, specific intelligence content includes but is not limited to: domain name, IP, Hash, etc.
[0040] The second way is to perform cross-product correlation analysis through security events, that is, to perform cross analysis on security logs of different products through network behavior, time sequence behavior, and other cross correlation methods to find threat hunting seeds;
[0041] The third way is network traffic analysis based on DNS and other protocols, that is, to construct a domain name connection graph according to domain name access behavior and domain name registration information of a user, to find abnormal domain names as threat hunting seeds based on community discovery, composition analysis, and other graph analysis methods according to connectivity of the graph;
[0042] The fourth way is complex event processing and analysis based on terminal behavior, that is, to use complex event processing, IOA (Indicator of Attack) behavior analysis, SOAR (Security Orchestration, Automation and Response) playbook, and other complex event processing and analysis methods as a judgment basis, and to output terminal behavior information as threat hunting seeds, where the terminal behavior information includes but is not limited to domain name, IP, Hash, and the like.
[0043] It should be noted that a common form of the threat hunting seed is IOC information, for example, potential threat information can include one or more of domain name, IP, Hash, and the like, and can also include terminal device ID, device MAC address, and other effective information that can be used to locate an attacker or a victim.
[0044] It should be noted that the target data can be obtained in one or more security protection products, different security protection products have different product forms and deployment locations, for example, firewall, intrusion detection and protection system (IDPS), data loss prevention (DLP), network detection and response (NDR), web application firewall (WAF), endpoint detection and response (EDR), and the like.
[0045] In step S102, a target category corresponding to the potential threat information is determined according to a preset threat detection condition, wherein the target category is one of a first threat category, a second threat category and a third threat category, the first threat category represents that the potential threat information is included in the historical threat information, the second threat category represents that the potential threat information is not included in the historical threat information, and the third threat category represents that the potential threat information is a false positive threat information.
[0046] Optionally, the threat hunting seed is verified through the preset threat detection condition to determine whether the threat hunting seed is a real threat event, and if so, it is determined whether the current threat hunting seed belongs to known threat information (i.e., the first threat category, N day), unknown threat information (i.e., the second threat category, 0 day) or false positive threat information (i.e., the third threat category).
[0047] It should be noted that the known threat information means that the security threat has been discovered and verified by a security vendor and other security agencies, and the security protection methods such as threat intelligence and detection rules corresponding to the threat have already existed.
[0048] In step S103, in a case where the target category is the first threat category or the second threat category, target threat intelligence corresponding to the target data is determined according to a processing method corresponding to the target category.
[0049] Here, the target threat intelligence corresponding to the target data is used to determine a processing strategy for the potential threat information.
[0050] Optionally, if the potential threat information belongs to the known threat information (i.e., the first threat category), the threat analysis enters a security intelligence operation framework process, i.e., the target threat intelligence corresponding to the target data is determined through the historical threat intelligence; if the potential threat information belongs to the unknown threat information (i.e., the second threat category), the threat analysis enters a threat pursuit and capture framework, i.e., the target threat intelligence corresponding to the target data is determined through the IOC information and other contents of the potential threat information; and if the potential threat information belongs to the false positive threat information (i.e., the third threat category), no processing is performed.
[0051] In summary, by determining the potential threat information in the target data as known threat information (i.e., the first threat category) or unknown threat information (i.e., the second threat category) or false positive threat information (i.e., the third threat category) according to the preset threat detection condition. In the case that the potential threat information is known threat information or unknown threat information, the target threat intelligence of the target data is generated according to the corresponding processing method to determine the processing strategy of the potential threat information. By presetting the threat detection condition, the potential threat information can be quickly classified, and it can be accurately determined that the potential threat information is known threat information or unknown threat information or false positive threat information, and then the corresponding processing method is determined according to the category of the potential threat information to obtain the target threat intelligence. The problem of inaccurate threat intelligence caused by the traditional method of determining the homologous analysis result corresponding to the target data by matching and calculating the newly added domain name information and IP information in the target data, and finally determining the threat intelligence of the target data in the historical threat intelligence according to the homologous analysis result is avoided, and the determination accuracy of the threat intelligence is improved.
[0052] Optionally, in the method for determining threat intelligence provided in the embodiments of the present application, if the target category is the second threat category, generating the target threat intelligence corresponding to the target data according to the processing method corresponding to the target category comprises: obtaining the intrusion indicator information corresponding to the potential threat information; compiling and packaging the intrusion indicator information to obtain a target configuration file; issuing the target configuration file to a target terminal having a file upload permission; obtaining a target execution file returned by a security device deployed on the target terminal after successfully matching the intrusion indicator information in the target configuration file and a terminal log file, wherein the terminal log file is a log file related to the target data; and generating the target threat intelligence corresponding to the target data according to the target execution file.
[0053] Here, the target execution file uploaded by the target terminal to the server is a malicious executable file on the target terminal.
[0054] In an optional embodiment, in the case that the potential threat information belongs to unknown threat information (0day), the active discovery and intelligence production of the threat information are realized by the threat wanted and capture framework. Figure 3 is a schematic diagram of the threat wanted and capture framework according to the embodiments of the present application. As shown in Figure 3As shown, in the case that the potential threat information belongs to unknown threat information, IOC information (i.e., intrusion indicator information, or "threat indicator information") corresponding to the potential threat information is acquired, and the IOC information corresponding to the potential threat information is published as a wanted poster to a server. The wanted poster server (which can correspond to the server in the foregoing embodiments) compiles and packages the wanted poster to obtain a package configuration (Package, PKG) file (i.e., a target configuration file), and distributes the target configuration file to a target terminal having a file upload permission, and acquires a malicious executable file (i.e., a target executable file) corresponding to the potential threat information returned by a security device deployed on the target terminal after the security device matches terminal log files and the IOC information in the target configuration file. By analyzing the execution process and process behavior of the malicious executable file, target threat intelligence corresponding to the target data can be generated.
[0055] It should be noted that after the target configuration file is distributed to the target terminal having the file upload permission, it can be determined by the target terminal whether there is a target terminal log file matching the IOC information in the target configuration file in the terminal log file. If there is, the target terminal log file is analyzed to determine a target executable file corresponding to the potential threat information, and the target executable file and the IOC information matching the target terminal log file are uploaded to the server. If there is not, it indicates that there is no target executable file corresponding to the potential threat information in the plurality of terminal devices.
[0056] In some examples, the server can iteratively update the IOC information list, for example, delete the IOC having a corresponding target executable file and the IOC not matching the terminal log file within a preset time period from the IOC information list.
[0057] Through the threat wanted poster and capture framework, threats can be actively discovered, and EDR (Endpoint Detection and Response) type terminal security devices can analyze behavior events generated based on terminal products, and thus quickly and accurately obtain a malicious executable file corresponding to potential threat information.
[0058] Optionally, in the method for determining threat intelligence provided in the embodiments of the present application, generating target threat intelligence corresponding to the target data according to the target executable file includes: performing static analysis on the target executable file to obtain a first analysis result corresponding to the target executable file; running the target executable file through a target sandbox to obtain a second analysis result corresponding to the target executable file; and generating target threat intelligence corresponding to the target data according to the first analysis result and the second analysis result.
[0059] According to the first analysis result and the second analysis result, the target threat intelligence corresponding to the target data can be generated, which can include:
[0060] The intelligence information in the first analysis result and the second analysis result is determined, the intelligence information is analyzed in association with the existing threat intelligence, and the target threat intelligence corresponding to the target data is obtained according to the association between the target executable file and the existing intelligence.
[0061] In an optional embodiment, the intelligence production process of the potential threat information is implemented through an intelligence production framework. Figure 4 is a schematic diagram of the intelligence production framework provided by the embodiments of the present application. As shown in Figure 4 , first, the malicious executable file is matched with the known IOC intelligence, if no IOC intelligence of the current malicious executable file is found, the intelligence production process is performed. Here, the malicious executable file can be handed over to the security analyst for static analysis, and the intelligence and rules including Yara are output (i.e. the first analysis result). At the same time, the malicious executable file is run in the sandbox and its network behavior is recorded to generate the IOC intelligence. At the same time, the behavior information generated during its running process is analyzed, and the CEP and other intelligence and rule contents are summarized and generated (i.e. the second analysis result). Finally, the intelligence and rule contents of the static analysis process and the dynamic analysis process are output, the intelligence information is analyzed in association with the existing IOC intelligence, the association between the current malicious executable file and the existing intelligence is determined, and the target threat intelligence corresponding to the target data is obtained.
[0062] The network connection behavior of the malicious executable file with the C2 server and the Downloader server and the like addresses is obtained through the sandbox and the reverse analysis and the like malicious executable file analysis methods. And the type of the malicious executable file is determined according to the execution process of the malicious executable file and the process startup and the process behavior. Based on the above information, the target threat intelligence corresponding to the target data can be quickly and accurately generated.
[0063] Optionally, in the method for determining the threat intelligence provided by the embodiments of the present application, the method further includes: in the case of receiving the target executable file, adding the intrusion indicator information corresponding to the potential threat information to the intrusion indicator information list.
[0064] In an optional embodiment, in the process of active discovery and threat hunting, if the executable file corresponding to the domain name in the process access wanted list has a security threat, the server maintains an IOC list, the IOCs in the list are threat hunting seeds verified by the threat hunting seed verification framework as unknown threat information, and the list has an adding and deleting mechanism. When the aging condition is met, the relevant IOCs in the IOC list that meet the aging condition are deleted; when a new IOC is added to the list, the list will increase the IOC information. If the number of IOC information in the list reaches the threshold, the deletion mechanism of the list will be started.
[0065] In this embodiment, by adding the intrusion indicator information corresponding to the potential threat information to the intrusion indicator information list, it is helpful to quickly determine the threat intelligence and improve the security of the system.
[0066] Optionally, in the method for determining threat intelligence provided in the embodiments of the present application, if the target category is a first threat category, the target threat intelligence corresponding to the target data is determined according to the processing method corresponding to the target category, including: determining at least one first threat intelligence with a number of successful matches with the potential threat information higher than a threshold according to historical query records; and determining the target threat intelligence corresponding to the target data according to the at least one first threat intelligence.
[0067] In an optional embodiment, in the case that the potential threat information belongs to known threat information, the target threat intelligence is determined through a security intelligence operation framework. Figure 5 is a schematic diagram of the security intelligence operation framework provided in the embodiments of the present application. As shown in Figure 5 The security intelligence operation framework includes five key components: intelligence collection, intelligence analysis, intelligence sharing, intelligence application, and feedback loop.
[0068] In some examples, the first threat intelligence with a number of successful matches with the potential threat information higher than a threshold can be determined from historical threat intelligence in a historical time period with a preset time length and ending at the current time according to historical query records.
[0069] In some examples, when the target category corresponding to the potential threat information is a first threat category, if there is no at least one first threat intelligence with a number of successful matches with the potential threat information higher than a threshold, the target threat intelligence corresponding to the target data can be determined through the threat intelligence with the highest ranking of successful matches with the potential threat information among all known threat intelligences.
[0070] It should be noted that when the target category corresponding to the potential threat information is the first threat category, if there is at least one first threat intelligence that matches the potential threat information successfully and the number of times of matching is higher than the threshold, the second threat intelligence that has a correlation relationship with the first threat intelligence can also be obtained, and the target threat intelligence is generated according to the first threat intelligence and the second threat intelligence. For example, intelligence information can be obtained from the second threat intelligence, and the target threat intelligence is generated according to the obtained intelligence information and the first threat intelligence, wherein the intelligence information includes but is not limited to: the threat type, the threat mode and the processing strategy of the threat information matched successfully by the second threat intelligence.
[0071] It should be noted that the threat type includes but is not limited to: virus, Trojan, worm, malicious software, phishing, ransomware, etc.; the threat mode includes but is not limited to: self-replication and propagation, disguising as legitimate software, tampering or stealing computer systems or data, fake e-mails, websites, etc. to lure users to provide sensitive information, encrypt user data and require payment of ransom to unlock data, etc.; the processing strategy includes but is not limited to: installing security software, regularly updating the threat information library, regularly updating the security patches of the operating system and the application program, using the firewall, regularly backing up the data, etc.
[0072] It should be noted that the recent active intelligence and the intelligence that has a correlation relationship with the recent active intelligence belong to the feedback cycle in the security intelligence operation framework, and the optimization of the intelligence query and the rule conversion mechanism and the generation of the active intelligence and the intelligence rule belong to the intelligence application in the security intelligence operation framework.
[0073] By matching the historical threat intelligence and the correlation intelligence thereof with the potential threat information, the target threat intelligence is generated, which can further improve the determination accuracy of the threat intelligence.
[0074] Optionally, in the method for determining the threat intelligence provided in the embodiments of the present application, the target category corresponding to the potential threat information is determined according to the preset threat detection condition, which includes: judging whether the potential threat information meets the preset threat detection condition to obtain a judgment result; and determining the target category corresponding to the potential threat information according to the judgment result.
[0075] In an optional embodiment, it is judged whether the potential threat information meets the preset threat detection condition to obtain a judgment result, and the target category corresponding to the potential threat information is determined through the judgment result.
[0076] It should be noted that the preset threat detection condition includes but is not limited to: historical threat intelligence, a preset security rule and other threat detection strategies.
[0077] By the preset threat detection condition, the potential threat information can be accurately classified and processed, the target category to which the potential threat information belongs can be quickly determined, and then a corresponding processing method is determined according to the target category, so that target threat intelligence is obtained, and the efficiency and accuracy of threat detection are improved.
[0078] Optionally, in the method for determining threat intelligence provided in the embodiments of the present application, the target category corresponding to the potential threat information is determined according to the judgment result, including: if the judgment result represents that the potential threat information meets the preset threat detection condition, the target category corresponding to the potential threat information is determined as the first threat category; if the judgment result represents that the potential threat information does not meet the preset threat detection condition, category input information input by the target object is obtained; and according to the category input information, the target category corresponding to the potential threat information is determined as the second threat category or the third threat category.
[0079] In an optional embodiment, the verification and classification process of the input threat hunting seed (i.e., potential threat information) is implemented through a threat hunting seed verification framework. Figure 6 is a schematic diagram of the threat hunting seed verification framework provided in the embodiments of the present application. As shown in Figure 6 , the threat hunting seed verification framework mainly includes two modules connected in series, which are a threat intelligence and rule matching module and a security expert analysis module.
[0080] Firstly, whether the potential threat information exists in the historical threat intelligence is queried through the threat intelligence and rule matching module: if it exists, the potential threat information is determined as known threat information (i.e., the first threat category); if it does not exist, whether the potential threat information meets the security rules is continued to be judged: if it meets, the potential threat information is determined as known threat information; if it does not meet, whether the potential threat information meets other threat detection strategies is continued to be judged: if it meets, the potential threat information is determined as known threat information; if it does not meet, it means that the potential threat information belongs to a difficult case, enters the security expert analysis module, and is verified through an expert system based on security information search and the like, and according to the verification result (i.e., the category input information input by the target object) of the expert system, it is determined whether the potential threat information belongs to a brand-new unknown threat information (i.e., the second threat category) not included in the security check or a false alarm event (i.e., the third threat category) which is not a threat.
[0081] It should be noted that if the potential threat information belongs to known threat information, it subsequently enters the security intelligence operation framework process; if the potential threat information belongs to unknown threat information, it subsequently enters the threat wanted and capture framework.
[0082] The potential threat information is preliminarily classified through historical threat information, preset security rules and other threat detection strategies, and further verified by an expert system for the potential threat information that cannot be determined through the above detection, so as to accurately classify the potential threat information and improve the production efficiency of threat information.
[0083] It should be noted that, Figure 7 is a schematic diagram of a threat information determination method provided by an embodiment of the present application, as Figure 7 indicated, the threat information determination method mainly includes six process frameworks, which are: threat hunting seed discovery framework, threat hunting seed verification framework, threat wanted and capture framework, security information operation framework, information production framework and information fusion framework.
[0084] The threat information determination method provided by the embodiment of the present application determines the potential threat information in the target data, wherein the target data is traffic with a threat probability greater than a preset probability; according to a preset threat detection condition, a target category corresponding to the potential threat information is determined, wherein the target category is one of the following: a first threat category, a second threat category and a third threat category, the first threat category represents that the historical threat information includes the potential threat information, the second threat category represents that the historical threat information does not include the potential threat information, and the third threat category represents that the potential threat information is a false positive threat information; in the case that the target category is the first threat category or the second threat category, a target threat information corresponding to the target data is determined according to a processing method corresponding to the target category, wherein the target threat information is used to determine a processing strategy for the potential threat information, which solves the problem in the related art that the determination accuracy of threat information is relatively low due to the same source analysis on the domain name information and IP information newly added in the target data, and the determination of threat information matching the target data in the historical threat information according to the analysis result.
[0085] In summary, by the preset threat detection condition, the potential threat information in the target data is determined as known threat information (i.e., the first threat category) or unknown threat information (i.e., the second threat category) or false threat information (i.e., the third threat category). In the case that the potential threat information is known threat information or unknown threat information, the target threat intelligence of the target data is generated according to the corresponding processing method to determine the processing strategy for the potential threat information. By the preset threat detection condition, the potential threat information can be quickly classified, and it can be accurately determined that the potential threat information is known threat information or unknown threat information or false threat information, and then the corresponding processing method is determined according to the category of the potential threat information to obtain the target threat intelligence. The problem of inaccurate threat intelligence caused by the traditional method of determining the homologous analysis result corresponding to the target data by matching and calculating the domain name information and IP information newly added in the target data, and finally determining the threat intelligence of the target data in the historical threat intelligence according to the homologous analysis result is avoided, and the determination accuracy of the threat intelligence is improved.
[0086] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described herein can be executed in an order different from that shown herein.
[0087] The embodiments or examples of the present application are not exhaustive, but only illustrate some embodiments or examples, and do not specifically limit the protection scope of the present application. In the case of no contradiction, each step in a certain embodiment or example can be implemented as an independent example, and the steps can be combined arbitrarily, for example, the scheme after removing some steps in a certain embodiment or example can also be implemented as an independent example, and the order of the steps in a certain embodiment or example can be exchanged arbitrarily, in addition, the optional mode or optional example in a certain embodiment or example can be combined arbitrarily; in addition, the embodiments or examples can be combined arbitrarily, for example, the steps of different embodiments or examples can be combined arbitrarily, a certain embodiment or example can be combined with the optional mode or optional example of other embodiments or examples.
[0088] The embodiment of the present application also provides a threat intelligence determination device. It should be noted that the threat intelligence determination device of the embodiment of the present application can be used to execute the threat intelligence determination method provided by the embodiment of the present application. The threat intelligence determination device provided by the embodiment of the present application is introduced as follows.
[0089] Figure 8 is a schematic diagram of the threat intelligence determination device according to the embodiment of the present application. As Figure 8As shown, the apparatus comprises: a first determination unit 801, a second determination unit 802, and a third determination unit 803.
[0090] The first determination unit 801 is configured to determine potential threat information in target data, wherein the target data is security event data, traffic data, or log data, and a probability of existence of a threat in the target data is greater than a preset probability.
[0091] The second determination unit 802 is configured to determine a target category corresponding to the potential threat information according to a preset threat detection condition, wherein the target category is one of: a first threat category, a second threat category, and a third threat category, the first threat category indicates that the potential threat information is included in historical threat information, the second threat category indicates that the potential threat information is not included in the historical threat information, and the third threat category indicates that the potential threat information is false positive threat information.
[0092] The third determination unit 803 is configured to, in a case where the target category is the first threat category or the second threat category, determine target threat intelligence corresponding to the target data according to a processing method corresponding to the target category.
[0093] The threat intelligence determination apparatus provided in the embodiments of the present application comprises a first determination unit 801 configured to determine potential threat information in target data, wherein the target data is security event data, traffic data or log data with a probability of existence of a threat greater than a preset probability; a second determination unit 802 configured to determine a target category corresponding to the potential threat information according to a preset threat detection condition, wherein the target category is one of a first threat category, a second threat category and a third threat category, the first threat category represents that the potential threat information is included in historical threat information, the second threat category represents that the potential threat information is not included in the historical threat information, and the third threat category represents that the potential threat information is a false alarm threat information; and a third determination unit 803 configured to, in a case where the target category is the first threat category or the second threat category, determine target threat intelligence corresponding to the target data according to a processing method corresponding to the target category, thereby solving the problem in the related art that the determination accuracy of threat intelligence is relatively low due to the same-source analysis of domain name information and IP information newly added in the target data, and the determination of threat intelligence matching the target data in historical threat intelligence according to an analysis result. In the present solution, the potential threat information in the target data is determined to be known threat information (i.e., the first threat category), unknown threat information (i.e., the second threat category) or false alarm threat information (i.e., the third threat category) according to the preset threat detection condition. In a case where the potential threat information is known threat information or unknown threat information, target threat intelligence of the target data is generated according to the corresponding processing method, so as to determine a processing strategy for the potential threat information. Through the preset threat detection condition, the potential threat information can be quickly classified, and it can be accurately determined whether the potential threat information is known threat information, unknown threat information or false alarm threat information, and then the corresponding processing method is determined according to the category of the potential threat information, so as to obtain the target threat intelligence. The problem of inaccurate threat intelligence caused by the matching calculation of the domain name information and the IP information newly added in the target data, the determination of the same-source analysis result corresponding to the target data, and the determination of the threat intelligence of the target data in the historical threat intelligence according to the same-source analysis result in the traditional method is avoided, and thus the determination accuracy of the threat intelligence is improved.
[0094] Optionally, in the threat intelligence determination apparatus provided by the embodiment of the present application, the third determination unit comprises: a first acquisition module, configured to acquire the intrusion indicator information corresponding to the potential threat information if the target category is the second threat category; a processing module, configured to compile and package the intrusion indicator information to obtain a target configuration file; a delivery module, configured to deliver the target configuration file to a target terminal having a file uploading permission; a second acquisition module, configured to acquire a target execution file returned by a security device deployed on the target terminal after the security device matches the intrusion indicator information in the terminal log file and the target configuration file successfully, wherein the terminal log file is a log file related to the target data; and a generation module, configured to generate the target threat intelligence corresponding to the target data according to the target execution file.
[0095] Optionally, in the threat intelligence determination apparatus provided by the embodiment of the present application, the generation module comprises: an analysis submodule, configured to perform static analysis on the target execution file to obtain a first analysis result corresponding to the target execution file; a running submodule, configured to run the target execution file through a target sandbox to obtain a second analysis result corresponding to the target execution file; and a generation submodule, configured to generate the target threat intelligence corresponding to the target data according to the first analysis result and the second analysis result.
[0096] Optionally, in the threat intelligence determination apparatus provided by the embodiment of the present application, the apparatus further comprises an adding unit, configured to add the intrusion indicator information corresponding to the potential threat information to the intrusion indicator information list if the target execution file is received.
[0097] Optionally, in the threat intelligence determination apparatus provided by the embodiment of the present application, the third determination unit comprises: a first determination module, configured to determine at least one first threat intelligence, which matches the potential threat information successfully and has a number of times of matching higher than a threshold, according to historical query records if the target category is the first threat category; and a second determination module, configured to determine the target threat intelligence corresponding to the target data according to the at least one first threat intelligence.
[0098] Optionally, in the threat intelligence determination apparatus provided by the embodiment of the present application, the second determination unit comprises: a judgment module, configured to judge whether the potential threat information satisfies a preset threat detection condition to obtain a judgment result; and a third determination module, configured to determine the target category corresponding to the potential threat information according to the judgment result.
[0099] Optionally, in the threat intelligence determination apparatus provided by the embodiment of the present application, the third determination module comprises: a first determination sub-module, configured to determine that the target category corresponding to the potential threat information is a first threat category if the judgment result indicates that the potential threat information satisfies the preset threat detection condition; an acquisition sub-module, configured to acquire category input information input by the target object if the judgment result indicates that the potential threat information does not satisfy the preset threat detection condition; and a second determination sub-module, configured to determine that the target category corresponding to the potential threat information is a second threat category or a third threat category according to the category input information.
[0100] The threat intelligence determination apparatus comprises a processor and a memory, the first determination unit 801, the second determination unit 802 and the third determination unit 803 are all stored in the memory as program units, and the processor is configured to execute the program units stored in the memory to realize accurate determination of threat intelligence.
[0101] The processor comprises a core, and the core is configured to call corresponding program units from the memory. One or more than one core can be arranged, and the core parameters are adjusted to realize accurate determination of threat intelligence.
[0102] The memory can comprise a non-permanent memory in a computer readable medium, random access memory (RAM) and / or non-volatile memory such as read-only memory (ROM) or flash memory (flash RAM), and the memory comprises at least one memory chip.
[0103] The embodiment of the present application provides a computer readable storage medium, which stores a program, and the program is executed by a processor to realize the threat intelligence determination method.
[0104] The embodiment of the present application provides a processor, which is used to run a program, and the program is executed to realize the threat intelligence determination method.
[0105] As Figure 9As shown, the embodiment of the present application provides an electronic device, the device comprising a processor, a memory and a program stored on the memory and executable on the processor, and the processor implements the following steps when executing the program: determining potential threat information in target data, wherein the target data is security event data, traffic data or log data with a probability of existence of a threat greater than a preset probability; determining a target category corresponding to the potential threat information according to a preset threat detection condition, wherein the target category is one of the following: a first threat category, a second threat category and a third threat category, the first threat category representing that the potential threat information is included in historical threat information, the second threat category representing that the potential threat information is not included in the historical threat information, and the third threat category representing that the potential threat information is a false alarm threat information; and in the case that the target category is the first threat category or the second threat category, determining target threat intelligence corresponding to the target data according to a processing method corresponding to the target category.
[0106] Optionally, if the target category is the second threat category, generating the target threat intelligence corresponding to the target data according to the processing method corresponding to the target category comprises: obtaining intrusion indicator information corresponding to the potential threat information; compiling and packaging the intrusion indicator information to obtain a target configuration file; issuing the target configuration file to a target terminal having a file upload permission; obtaining a target execution file returned by a security device deployed on the target terminal after successfully matching terminal log files and the intrusion indicator information in the target configuration file, wherein the terminal log files are log files related to the target data; and generating the target threat intelligence corresponding to the target data according to the target execution file.
[0107] Optionally, generating the target threat intelligence corresponding to the target data according to the target execution file comprises: performing static analysis on the target execution file to obtain a first analysis result corresponding to the target execution file; running the target execution file through a target sandbox to obtain a second analysis result corresponding to the target execution file; and generating the target threat intelligence corresponding to the target data according to the first analysis result and the second analysis result.
[0108] Optionally, the method further comprises: in the case that the target execution file is received, adding the intrusion indicator information corresponding to the potential threat information to an intrusion indicator information list.
[0109] Optionally, if the target category is the first threat category, determining the target threat intelligence corresponding to the target data according to the processing method corresponding to the target category comprises: determining at least one first threat intelligence with a number of successful matches with the potential threat information higher than a threshold value according to historical query records; and determining the target threat intelligence corresponding to the target data according to the at least one first threat intelligence.
[0110] Optionally, the determining, according to the preset threat detection condition, of the target category corresponding to the potential threat information comprises: determining whether the potential threat information satisfies the preset threat detection condition to obtain a determination result; and determining the target category corresponding to the potential threat information according to the determination result.
[0111] Optionally, the determining, according to the determination result, of the target category corresponding to the potential threat information comprises: if the determination result indicates that the potential threat information satisfies the preset threat detection condition, determining that the target category corresponding to the potential threat information is a first threat category; if the determination result indicates that the potential threat information does not satisfy the preset threat detection condition, obtaining category input information input by the target object; and determining, according to the category input information, that the target category corresponding to the potential threat information is a second threat category or a third threat category.
[0112] The device herein can be a server, a PC, a PAD, a mobile phone, etc.
[0113] The application further provides a computer program product adapted to execute the following method steps when executed on a data processing device: determining potential threat information in target data, wherein the target data is security event data, traffic data or log data with a threat probability greater than a preset probability; determining, according to a preset threat detection condition, a target category corresponding to the potential threat information, wherein the target category is one of a first threat category, a second threat category and a third threat category, the first threat category indicating that the potential threat information is included in historical threat information, the second threat category indicating that the potential threat information is not included in the historical threat information, and the third threat category indicating that the potential threat information is a false alarm threat information; and determining, in a case where the target category is the first threat category or the second threat category, target threat intelligence corresponding to the target data according to a processing method corresponding to the target category.
[0114] Optionally, if the target category is the second threat category, the generating, according to the processing method corresponding to the target category, of the target threat intelligence corresponding to the target data comprises: obtaining intrusion index information corresponding to the potential threat information; compiling and packaging the intrusion index information to obtain a target configuration file; issuing the target configuration file to a target terminal having a file uploading permission; obtaining a target execution file returned by a security device deployed on the target terminal after successfully matching terminal log files and the intrusion index information in the target configuration file, wherein the terminal log files are log files related to the target data; and generating the target threat intelligence corresponding to the target data according to the target execution file.
[0115] Optionally, the generating the target threat intelligence corresponding to the target data according to the target executable file comprises: performing static analysis on the target executable file to obtain a first analysis result corresponding to the target executable file; running the target executable file through a target sandbox to obtain a second analysis result corresponding to the target executable file; and generating the target threat intelligence corresponding to the target data according to the first analysis result and the second analysis result.
[0116] Optionally, the method further comprises: in a case where the target executable file is received, adding the intrusion indicator information corresponding to the potential threat information to the intrusion indicator information list.
[0117] Optionally, if the target category is the first threat category, the determining the target threat intelligence corresponding to the target data according to the processing method corresponding to the target category comprises: determining at least one first threat intelligence with a number of successful matches with the potential threat information higher than a threshold according to historical query records; and determining the target threat intelligence corresponding to the target data according to the at least one first threat intelligence.
[0118] Optionally, the determining the target category corresponding to the potential threat information according to the preset threat detection condition comprises: judging whether the potential threat information satisfies the preset threat detection condition to obtain a judgment result; and determining the target category corresponding to the potential threat information according to the judgment result.
[0119] Optionally, the determining the target category corresponding to the potential threat information according to the judgment result comprises: if the judgment result indicates that the potential threat information satisfies the preset threat detection condition, determining that the target category corresponding to the potential threat information is the first threat category; if the judgment result indicates that the potential threat information does not satisfy the preset threat detection condition, obtaining category input information input by a target object; and determining that the target category corresponding to the potential threat information is a second threat category or a third threat category according to the category input information.
[0120] Those skilled in the art should understand that embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage media, etc.) containing computer-usable program code.
[0121] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 one or more flow or blocks Figure 1 means for functionally implementing the steps listed in the flowchart block or blocks.
[0122] These computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture including instructions which implement the function specified in the flowchart block or blocks. Figure 1 one or more flow or blocks Figure 1 means for functionally implementing the steps listed in the flowchart block or blocks.
[0123] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 one or more flow or blocks Figure 1 means for functionally implementing the steps listed in the flowchart block or blocks.
[0124] In one typical configuration, the computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.
[0125] The memory can include non-persistent memory and / or volatile memory, such as random access memory (RAM) and / or cache memory, for storing instructions and data used and / or generated by the computing device. The memory can also include non-volatile memory, such as read-only memory (ROM), electrically programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), flash memory, or other non-volatile memory.
[0126] Computer-readable media includes permanent and non-permanent, movable and non-movable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette, magnetic tape disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible to a computing device. According to the definition herein, computer-readable media does not include transitory media such as modulated data signals and carriers.
[0127] It should also be noted that the terms "comprising", "containing", or any other variant thereof are intended to cover non-exclusive inclusions, such that a process, method, article or apparatus that comprises a list of elements does not only include those elements, but also other elements not explicitly listed or inherent to such process, method, article or apparatus. Without more limitations, the element defined by the phrase "comprising a" does not exclude the presence of additional identical elements in the process, method, article or apparatus that includes the element.
[0128] Those skilled in the art will appreciate that embodiments of the present application can be provided as a method, system or computer program product. Accordingly, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Furthermore, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage devices, etc.) containing computer usable program code.
[0129] The above merely provides embodiments of the present application and is not intended to limit the present application. Various modifications and changes can be made to the present application by those skilled in the art. Any modification, equivalent replacement, improvement, etc. made within the spirit and principles of the present application shall be included in the scope of the claims of the present application.
Claims
1. A method for determining threat intelligence, characterized in that, The method comprises: determining potential threat information in target data, wherein the target data is security event data, traffic data or log data with a probability of threat greater than a preset probability; determining a target category corresponding to the potential threat information according to a preset threat detection condition, wherein the target category is one of a first threat category, a second threat category and a third threat category, the first threat category represents that the potential threat information is included in historical threat information, the second threat category represents that the potential threat information is not included in the historical threat information, and the third threat category represents that the potential threat information is false alarm threat information; in a case where the target category is the first threat category or the second threat category, determining target threat intelligence corresponding to the target data according to a processing method corresponding to the target category. If the target category is the second threat category, generating the target threat intelligence corresponding to the target data according to the processing method corresponding to the target category comprises: obtaining intrusion indicator information corresponding to the potential threat information; compiling and packaging the intrusion indicator information to obtain a target configuration file; downloading the target configuration file to a target terminal having a file upload permission; obtaining a target execution file returned by a security device deployed on the target terminal after matching terminal log files and the intrusion indicator information in the target configuration file, wherein the terminal log files are log files related to the target data; generating the target threat intelligence corresponding to the target data according to the target execution file.
2. The method of claim 1, wherein, Generating the target threat intelligence corresponding to the target data according to the target execution file comprises: performing static analysis on the target execution file to obtain a first analysis result corresponding to the target execution file; running the target execution file through a target sandbox to obtain a second analysis result corresponding to the target execution file; generating the target threat intelligence corresponding to the target data according to the first analysis result and the second analysis result.
3. The method of claim 1, wherein, The method further comprises: in a case where the target execution file is received, adding intrusion indicator information corresponding to the potential threat information to an intrusion indicator information list.
4. The method of claim 1, wherein, If the target category is the first threat category, determining the target threat intelligence corresponding to the target data according to the processing method corresponding to the target category comprises: determining at least one first threat intelligence with a number of successful matches with the potential threat information higher than a threshold value according to historical query records; determining the target threat intelligence corresponding to the target data according to the at least one first threat intelligence.
5. The method according to any one of claims 1 to 4, characterized in that, Determining the target category corresponding to the potential threat information according to the preset threat detection condition comprises: determining whether the potential threat information satisfies the preset threat detection condition to obtain a determination result; determining the target category corresponding to the potential threat information according to the determination result.
6. The method of claim 5, wherein, Determining the target category corresponding to the potential threat information according to the determination result comprises: If the judgment result represents that the potential threat information satisfies the preset threat detection condition, it is determined that a target category corresponding to the potential threat information is the first threat category; If the judgment result represents that the potential threat information does not satisfy the preset threat detection condition, category input information input by a target object is acquired; According to the category input information, it is determined that the target category corresponding to the potential threat information is the second threat category or the third threat category.
7. A threat intelligence determination apparatus characterized by comprising: Comprise: The first determination unit is configured to determine potential threat information in target data, wherein the target data is security event data, traffic data or log data in which a probability of terminal threat is greater than a preset probability; The second determination unit is configured to determine a target category corresponding to the potential threat information according to a preset threat detection condition, wherein the target category is one of a first threat category, a second threat category and a third threat category, the first threat category represents that historical threat information includes the potential threat information, the second threat category represents that the historical threat information does not include the potential threat information, and the third threat category represents that the potential threat information is a false alarm threat information; The third determination unit is configured to, in a case where the target category is the first threat category or the second threat category, determine target threat intelligence corresponding to the target data according to a processing method corresponding to the target category. The third determination unit comprises: a first acquisition module configured to, if the target category is the second threat category, acquire intrusion index information corresponding to the potential threat information; a processing module configured to compile and package the intrusion index information to obtain a target configuration file; a delivery module configured to deliver the target configuration file to a target terminal having a file upload permission; a second acquisition module configured to acquire a target execution file returned by a security device deployed on the target terminal after matching terminal log files and the intrusion index information in the target configuration file, wherein the terminal log files are log files related to the target data; and a generation module configured to generate target threat intelligence corresponding to the target data according to the target execution file.
8. An electronic device, comprising: The computer readable storage medium comprises a stored program, wherein when the program runs, the device where the storage medium is located is controlled to perform the threat intelligence determination method in any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that, The computer readable storage medium comprises a stored program, wherein when the program runs, the device where the storage medium is located is controlled to perform the threat intelligence determination method in any one of claims 1 to 6.
Citation Information
Patent Citations
Threat intelligence feature library generation method and device, storage medium and processor
CN113794727A
Network threat detection method and device
CN114697066A