A threat intelligence processing method, device, equipment and medium
By calculating indicators such as the accuracy, available processing time and credibility of threat intelligence, the processing priority of threat intelligence is determined, which solves the problem of time-consuming threat intelligence analysis in existing technologies and improves the network security processing efficiency of the power system.
Patent Information
- Application Number
- CN202411403328.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-09
- Publication Date
- 2025-10-24
- Estimated Expiration
- 2044-10-09
AI Technical Summary
In existing technologies, it takes a long time to analyze threat intelligence results obtained from multiple intelligence sources, resulting in the inability to handle network security incidents in a timely manner.
By obtaining the first threat parameter, reception time, intelligence source identification information, power system log and other data of the threat intelligence to be processed, the intelligence accuracy, available processing time, credibility and target relevance rate are calculated to comprehensively determine whether to process it.
It improves the efficiency of threat intelligence processing, filters out less effective threat intelligence, reduces the amount of processing, and improves overall processing efficiency.
Smart Images

Figure CN119254503B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of threat intelligence processing, and in particular to a threat intelligence processing method, device, equipment and medium. BACKGROUND
[0002] At present, the power grid power field is facing increasingly severe network security challenges, especially with the accelerated construction of the new energy system, the access of numerous new energy power stations and third-party market subjects, which greatly increases the complexity and risk exposure of the network environment, leading to frequent network security incidents in the power grid power system, and new vulnerabilities emerging continuously, directly impacting the network security and business continuity of the power grid.
[0003] However, in the prior art, a large amount of threat intelligence needs to be obtained from multiple intelligence sources, and each threat intelligence needs to be analyzed, resulting in a long waiting time for the analysis results of a large amount of threat intelligence, and thus the technical personnel cannot timely process the threat events to be occurred. SUMMARY
[0004] The present application provides a threat intelligence processing method, device, equipment and medium to filter threat intelligence, thereby improving the processing efficiency of threat intelligence.
[0005] In a first aspect, the present application provides a threat intelligence processing method, comprising:
[0006] obtaining a first threat parameter in the threat intelligence to be processed, a receiving time of the threat intelligence to be processed, an occurrence time of a threat event corresponding to the threat intelligence to be processed, first identification information of an intelligence source to which the threat intelligence to be processed belongs, second identification information of an intelligence source to which a historical threat intelligence belongs, third identification information of an intelligence source to which a historical accurate intelligence belongs, a second threat parameter of a known threat in a threat database, a threat attack parameter of the known threat, and a third threat parameter recorded in a power system operation log;
[0007] determining an intelligence accuracy rate of the intelligence source to which the threat intelligence to be processed belongs according to the first identification information, the second identification information and the third identification information;
[0008] determining a usable processing duration of the threat intelligence to be processed according to the receiving time and the occurrence time;
[0009] determining a credibility rate of the threat intelligence to be processed according to the first threat parameter and the third threat parameter;
[0010] determining a target correlation rate between the threat intelligence to be processed and the known threat according to the second threat parameter of the known threat in the threat database, the threat attack parameter of the known threat and the first threat parameter;
[0011] According to the intelligence accuracy rate, the available processing time length, the credibility rate and the target correlation rate, it is judged whether to process the to-be-processed threat intelligence.
[0012] In a second aspect, the present application further provides a threat intelligence processing device, comprising:
[0013] The parameter acquisition module is configured to acquire the first threat parameter in the to-be-processed threat intelligence, the receiving time of the to-be-processed threat intelligence, the occurrence time of the threat event corresponding to the to-be-processed threat intelligence, the first identification information of the intelligence source to which the to-be-processed threat intelligence belongs, the second identification information of the intelligence source of the historical threat intelligence, the third identification information of the intelligence source of the historical accurate intelligence, the second threat parameter of the known threat in the threat database, the threat attack parameter of the known threat and the third threat parameter recorded in the power system operation log.
[0014] The accuracy rate determination module is configured to determine the intelligence accuracy rate of the intelligence source to which the to-be-processed threat intelligence belongs according to the first identification information, the second identification information and the third identification information.
[0015] The time length determination module is configured to determine the available processing time length of the to-be-processed threat intelligence according to the receiving time and the occurrence time.
[0016] The credibility rate determination module is configured to determine the credibility rate of the to-be-processed threat intelligence according to the first threat parameter and the third threat parameter.
[0017] The correlation rate determination module is configured to determine the target correlation rate between the to-be-processed threat intelligence and the known threat according to the second threat parameter of the known threat in the threat database, the threat attack parameter of the known threat and the first threat parameter.
[0018] The processing determination module is configured to determine whether to process the to-be-processed threat intelligence according to the intelligence accuracy rate, the available processing time length, the credibility rate and the target correlation rate.
[0019] In a third aspect, the present application further provides an electronic device, comprising:
[0020] at least one processor; and
[0021] a memory in communication with the at least one processor; wherein
[0022] The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the threat intelligence processing method provided by any of the embodiments of the present application.
[0023] In a fourth aspect, the embodiments of the present application further provide a computer readable storage medium, which stores computer instructions for causing a processor to implement the threat intelligence processing method of any of the embodiments of the present application.
[0024] The embodiments of the present application can respectively determine the intelligence accuracy, available processing time length, credibility and target correlation of the threat intelligence to be processed, and then comprehensively determine whether to process the threat intelligence to be processed according to the intelligence accuracy, available processing time length, credibility and target correlation of the threat intelligence to be processed, so as to filter out the threat intelligence to be processed with low effectiveness, reduce the number of threat intelligence to be processed, and improve the processing efficiency of processing a large amount of threat intelligence to be processed.
[0025] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present application, nor is it used to limit the scope of the present application. Other features of the present application will become apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS
[0026] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments description. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can also be obtained by those skilled in the art without creative labor.
[0027] Figure 1 is a flow chart of a threat intelligence processing method provided by the first embodiment of the present application;
[0028] Figure 2 is a flow chart of a threat intelligence processing method provided by the second embodiment of the present application;
[0029] Figure 3 is a structural schematic diagram of a threat intelligence processing device provided by the third embodiment of the present application;
[0030] Figure 4 is a structural schematic diagram of an electronic device for implementing the threat intelligence processing method of the embodiments of the present application. DETAILED DESCRIPTION
[0031] In order to make the technical personnel in the art better understand the present application scheme, the following will combine the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor should belong to the scope of protection of the present application.
[0032] It should be noted that the terms "first", "second", "third", and "fourth" and the like in the description and in the claims of the present application and above-mentioned accompanying drawings are used to distinguish similar objects, and do not necessarily have to be used to describe a particular order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the application described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0033] In the technical solutions of the embodiments of the present application, the acquisition, storage and application of the first threat parameter in the to-be-processed threat intelligence and the receiving time of the to-be-processed threat intelligence and the like conform to the relevant legal regulations and do not violate public order and good customs.
[0034] Embodiment one
[0035] Figure 1 A flowchart of a threat intelligence processing method provided by the first embodiment of the present application, the present embodiment can be applicable to the case of judging whether to process threat intelligence, and the method can be executed by a threat intelligence processing device. The threat intelligence processing device can be realized in the form of hardware and / or software and be specifically configured in an electronic device, such as a server.
[0036] Referring to Figure 1 The threat intelligence processing method shown in the figure comprises:
[0037] S101, acquiring a first threat parameter in to-be-processed threat intelligence, a receiving time of the to-be-processed threat intelligence, an occurrence time of a threat event corresponding to the to-be-processed threat intelligence, first identification information of an intelligence source to which the to-be-processed threat intelligence belongs, second identification information of an intelligence source to which historical threat intelligence belongs, third identification information of an intelligence source to which historical accurate intelligence belongs, a second threat parameter of a known threat in a threat database, a threat attack parameter of the known threat, and a third threat parameter recorded in a power system operation log.
[0038] In this embodiment, the threat intelligence to be processed can be threat intelligence that needs to be determined whether it needs to be processed. The threat intelligence can include, but is not limited to, information about potential attack threats that the power system can face, that is, information about threat events. The data format of the threat intelligence to be processed can be JSON (JavaScript Object Notation), CSV (Comma-Separated Values), STIX (Structured Threat Information Expression), TAXII (Trusted Automated Exchange of Indicator Information), and the like.
[0039] The first threat parameter is a threat parameter in the threat intelligence to be processed. The threat parameter can include, but is not limited to, a malicious IP (internet protocol) address, a malicious domain name, a malicious file hash value, a registry key, a malicious script or macro, and the like. The specific type of the first threat parameter is not limited by the present application. The historical threat intelligence can be threat intelligence received before the receiving time of the threat intelligence to be processed. The historical accurate intelligence can be historical threat intelligence that has occurred corresponding threat events; correspondingly, the historical threat intelligence can also include historical false intelligence, which can be historical threat intelligence that has not occurred corresponding threat events. The intelligence source can be a data source that sends the threat intelligence. The first identification information can be used to identify the intelligence source to which the threat intelligence to be processed belongs; the second identification information can be used to identify the intelligence source to which the historical threat intelligence belongs; and the third identification information can be used to identify the intelligence source to which the historical accurate intelligence belongs.
[0040] The threat database can be a database for storing known threats and threat attack parameters. The known threat can be a threat that has specific information. The second threat parameter is a threat parameter of the known threat. The third threat parameter can be a threat parameter recorded in the power system operation log.
[0041] The receiving moment can be a moment when the electronic device deployed with the threat intelligence processing method provided by the embodiment receives the threat intelligence to be processed. The occurrence moment can be a moment when the threat event corresponding to the threat intelligence to be processed occurs. In an optional embodiment, the occurrence time of the threat event corresponding to the threat intelligence to be processed can be predicted according to the first threat parameter of the threat intelligence to be processed through a threat occurrence time prediction model, to obtain the occurrence time of the threat event corresponding to the threat intelligence to be processed. In a specific implementation, the threat occurrence time prediction model can be trained through the occurrence time of the historical threat intelligence and the threat parameter of the historical threat intelligence; the threat occurrence time prediction model is a time series analysis model, for example, can be an ARIMA model (Autoregressive Integrated Moving Average Model).
[0042] S102, determining the intelligence accuracy rate of the intelligence source to which the threat intelligence to be processed belongs according to the first identification information, the second identification information and the third identification information.
[0043] In the embodiment, the intelligence accuracy rate can be used to represent the accuracy rate of the threat intelligence provided by the intelligence source to which the threat intelligence to be processed belongs; the higher the intelligence accuracy rate is, the greater the possibility of the occurrence of the threat event corresponding to the threat intelligence provided by the intelligence source is; the higher the intelligence accuracy rate is, the smaller the possibility of the occurrence of the threat event corresponding to the threat intelligence provided by the intelligence source is.
[0044] Specifically, according to the first identification information, the second identification information and the third identification information, the intelligence accuracy rate of the intelligence source to which the threat intelligence to be processed belongs is determined by using a certain algorithm.
[0045] Optionally, the intelligence accuracy rate of the intelligence source to which the threat intelligence to be processed belongs is determined according to the identification information of the intelligence source to which the threat intelligence to be processed belongs, the identification information of the intelligence source of the historical threat intelligence and the identification information of the intelligence source of the historical accurate intelligence, including: according to the identification information of the intelligence source to which the threat intelligence to be processed belongs, the first number of the historical threat intelligence of the same intelligence source as the intelligence source to which the threat intelligence to be processed belongs is counted in the identification information of the intelligence source of the historical threat intelligence; according to the identification information of the intelligence source to which the threat intelligence to be processed belongs, the second number of the historical accurate intelligence of the same intelligence source as the intelligence source to which the threat intelligence to be processed belongs is counted in the identification information of the intelligence source of the historical accurate intelligence; and according to the first number and the second number, the intelligence accuracy rate of the intelligence source to which the threat intelligence to be processed belongs is determined.
[0046] Specifically, the historical threat intelligence with the same identification information as the identification information of the threat intelligence source to which the to-be-processed threat intelligence belongs is searched, and the number of the searched historical threat intelligence is counted; the counted number is determined as a first number; the historical accurate intelligence with the same identification information as the identification information of the threat intelligence source to which the to-be-processed threat intelligence belongs is searched, and the number of the searched historical accurate intelligence is counted; the counted number is determined as a second number; a ratio between the second number and the first number is calculated, and the calculated ratio is determined as the intelligence accuracy rate.
[0047] It can be understood that, by using the technical solution, the first number of the historical threat intelligence with the same threat intelligence source as the threat intelligence source to which the to-be-processed threat intelligence belongs is counted, and the second number of the historical accurate intelligence with the same threat intelligence source as the threat intelligence source to which the to-be-processed threat intelligence belongs is counted; according to the first number and the second number, the intelligence accuracy rate of the threat intelligence source to which the to-be-processed threat intelligence belongs is determined, and the intelligence accuracy rate with a higher correctness rate can be obtained.
[0048] S103, determining the available processing time length of the to-be-processed threat intelligence according to the receiving time and the occurrence time.
[0049] In this embodiment, the available processing time length can be a time length available for processing the to-be-processed threat intelligence before the threat event corresponding to the to-be-processed threat intelligence occurs after the to-be-processed threat intelligence is received. Specifically, according to the receiving time and the occurrence time, the available processing time length of the to-be-processed threat intelligence is determined by using a certain algorithm.
[0050] Optionally, determining the available processing time length of the to-be-processed threat intelligence according to the receiving time and the occurrence time includes: calculating the time length between the receiving time and the occurrence time, and determining the calculated time length as the available processing time length of the to-be-processed threat intelligence.
[0051] It can be understood that, by using the technical solution, the time length between the receiving time and the occurrence time is calculated, and the calculated time length is determined as the available processing time length of the to-be-processed threat intelligence, thereby improving the accuracy rate of the available processing time length.
[0052] S104, determining the credibility rate of the to-be-processed threat intelligence according to the first threat parameter and the third threat parameter.
[0053] In this embodiment, the credibility rate can be used to represent the authenticity of the to-be-processed threat intelligence; the higher the credibility rate is, the greater the probability of the occurrence of the threat event corresponding to the to-be-processed threat intelligence is; the lower the credibility rate is, the smaller the probability of the occurrence of the threat event corresponding to the to-be-processed threat intelligence is. Specifically, according to the first threat parameter and the third threat parameter, the credibility rate of the to-be-processed threat intelligence is determined by using a certain algorithm.
[0054] Optionally, the number of the first threat parameters is at least one, and the number of the third threat parameters is at least one; and the determining of the credibility of the to-be-processed threat intelligence according to the first threat parameters and the third threat parameters comprises: for each first threat parameter, searching for a third threat parameter same as the first threat parameter in the third threat parameters, and determining the searched third threat parameter as threat evidence corresponding to the first threat parameter; counting the number of the threat evidence corresponding to each first threat parameter; and determining the credibility of the to-be-processed threat intelligence according to the number of the threat evidence corresponding to each first threat parameter.
[0055] In the formula, the threat evidence can be a third threat parameter same as the first threat parameter of the to-be-processed threat intelligence recorded in the power system operation log. Specifically, for each first threat parameter, a third threat parameter same as the first threat parameter is searched, and the searched third threat parameter is determined as threat evidence corresponding to the first threat parameter; the number of the threat evidence corresponding to each first threat parameter is counted; the total number between the threat evidence corresponding to each first threat parameter is calculated; and the calculated total number and the credibility coefficient are multiplied to obtain the credibility of the to-be-processed threat intelligence. For example, the first threat parameter of the to-be-processed threat intelligence includes a malicious IP address A, a malicious domain name B and a malicious file hash value C; the number of the malicious IP address A is searched in each malicious IP address recorded in the power system operation log; the number of the malicious domain name B is searched in each malicious domain name recorded in the power system operation log; the number of the malicious file hash value C is searched in each malicious file hash value recorded in the power system operation log; and the credibility of the to-be-processed threat intelligence is determined according to the number of the malicious IP address A, the number of the malicious domain name B and the number of the malicious file hash value C searched in the power system operation log.
[0056] It can be understood that by using the above technical solution, for each first threat parameter, a third threat parameter same as the first threat parameter is searched in the third threat parameters, and the searched third threat parameter is determined as threat evidence corresponding to the first threat parameter; the number of the threat evidence corresponding to each first threat parameter is counted; and the credibility of the to-be-processed threat intelligence is determined according to the number of the threat evidence corresponding to each first threat parameter, thereby improving the accuracy of the determined credibility.
[0057] S105, determining a target relevance rate between the to-be-processed threat intelligence and the known threat according to the second threat parameter of the known threat in the threat database, the threat attack parameter of the known threat and the first threat parameter.
[0058] In this embodiment, the target correlation rate can represent the correlation degree between the threat event corresponding to the threat intelligence to be processed and the threat event of the known threat; specifically, according to the second threat parameter of the known threat, the threat attack parameter of the known threat and the first threat parameter, a certain algorithm is used to determine the target correlation rate between the threat intelligence to be processed and the known threat.
[0059] In S106, it is determined whether to process the threat intelligence to be processed according to the intelligence accuracy rate, the available processing time length, the credibility rate and the target correlation rate.
[0060] Specifically, according to the second threat parameter of the known threat, the threat attack parameter of the known threat and the first threat parameter, a certain algorithm is used to determine the target correlation rate between the threat intelligence to be processed and the known threat.
[0061] The embodiment of the application can determine the intelligence accuracy rate, the available processing time length, the credibility rate and the target correlation rate of the threat intelligence to be processed respectively; and then, through the intelligence accuracy rate, the available processing time length, the credibility rate and the target correlation rate of the threat intelligence to be processed, it is comprehensively determined whether to process the threat intelligence to be processed, so as to filter out the threat intelligence to be processed with low effectiveness, reduce the number of threat intelligence to be processed, and improve the processing efficiency of processing a large amount of threat intelligence to be processed.
[0062] Embodiment two
[0063] Figure 2 The flowchart of the threat intelligence processing method provided by the embodiment two of the application, the embodiment of the application optimizes and improves the determination operation of the correlation rate on the basis of the technical solutions of the above-mentioned embodiments.
[0064] Further, the operation of determining the correlation rate between the threat intelligence to be processed and the known threat according to the second threat parameter of the known threat, the threat attack parameter of the known threat and the first threat parameter is refined as: identifying the target attack parameter of the threat intelligence to be processed according to the first threat parameter through the attack parameter identification model; finding the known threat matching the threat intelligence to be processed according to the second threat parameter of each known threat and the first threat parameter; and determining the target correlation rate between the threat intelligence to be processed and the matching known threat according to the threat attack parameter of the matching known threat and the target attack parameter, so as to improve the determination operation of the target conflict detection result.
[0065] It should be noted that the parts not described in detail in the embodiment of the application can be referred to the description of the foregoing embodiments.
[0066] Referring to Figure 2 The threat intelligence processing method shown in FIG. 1 comprises the following steps.
[0067] S201, acquire a first threat parameter in the to-be-processed threat information, a receiving time of the to-be-processed threat information, an occurrence time of a threat event corresponding to the to-be-processed threat information, first identification information of an information source to which the to-be-processed threat information belongs, second identification information of an information source of historical threat information, third identification information of an information source of historical accurate information, second threat parameters of known threats in a threat database, threat attack parameters of the known threats, and third threat parameters recorded in a power system operation log.
[0068] S202, determine an information accuracy rate of the information source to which the to-be-processed threat information belongs according to the first identification information, the second identification information, and the third identification information.
[0069] S203, determine a usable processing duration of the to-be-processed threat information according to the receiving time and the occurrence time.
[0070] S204, determine a credibility rate of the to-be-processed threat information according to the first threat parameter and the third threat parameter.
[0071] S205, identify a target attack parameter of the to-be-processed threat information according to the first threat parameter through an attack parameter identification model.
[0072] In this embodiment, the target attack parameter can be an attack parameter of a threat event corresponding to the to-be-processed threat information to the power system. The attack parameter can include but is not limited to attack technology, attack tool, and attack method. The attack technology can be a technology used by a threat party to attack the power system; the attack tool can be a tool used by the threat party to attack the power system. The attack parameter identification model can be a deep learning model used to identify the target attack parameter of the threat information. In an optional embodiment, the attack parameter identification model can be obtained by training the threat parameters of the historical threat information and the attack parameters of the threat events corresponding to the historical threat information.
[0073] S206, find a known threat matching the to-be-processed threat information according to the second threat parameters of the known threats and the first threat parameter.
[0074] Specifically, among the known threats, find a known threat with the same second threat parameter and first threat parameter as the to-be-processed threat information, and determine the found threat as the known threat matching the to-be-processed threat information.
[0075] S207, determine a target correlation rate between the to-be-processed threat information and the matched known threat according to the threat attack parameter of the matched known threat and the target attack parameter.
[0076] Specifically, a certain algorithm is adopted to determine the target correlation rate between the threat intelligence to be processed and the matched known threat according to the matched threat attack parameter and target attack parameter of the known threat.
[0077] Optionally, the threat attack parameter is an attack parameter of the known threat; the target attack parameter is an attack parameter of the threat intelligence to be processed; the attack parameter comprises an attack technique, an attack method and an attack tool; the target correlation rate between the threat intelligence to be processed and the matched known threat is determined according to the matched threat attack parameter and target attack parameter of the known threat, comprising: calculating a first correlation rate between the attack technique of the matched known threat and the attack technique of the threat intelligence to be processed; calculating a second correlation rate between the attack method of the matched known threat and the attack method of the threat intelligence to be processed; calculating a third correlation rate between the attack tool of the matched known threat and the attack tool of the threat intelligence to be processed; and determining the target correlation rate between the threat intelligence to be processed and the matched known threat according to the first correlation rate, the second correlation rate and the third correlation rate.
[0078] Specifically, a set data conversion algorithm can be adopted to convert the attack technique, the attack method and the attack tool in the threat attack parameter and the attack technique, the attack method and the attack tool in the target attack parameter into corresponding numerical values respectively; the Pearson correlation coefficient method is adopted to calculate the correlation rate between the attack technique numerical value of the matched known threat and the attack technique numerical value of the threat intelligence to be processed, and the calculated correlation rate is determined as the first correlation rate.
[0079] The Pearson correlation coefficient method is adopted to calculate the correlation rate between the attack technique numerical value of the matched known threat and the attack technique numerical value of the threat intelligence to be processed, and the calculated correlation rate is determined as the first correlation rate; the Pearson correlation coefficient method is adopted to calculate the correlation rate between the attack tool numerical value of the matched known threat and the attack tool numerical value of the threat intelligence to be processed, and the calculated correlation rate is determined as the second correlation rate; the Pearson correlation coefficient method is adopted to calculate the correlation rate between the attack method numerical value of the matched known threat and the attack method numerical value of the threat intelligence to be processed, and the calculated correlation rate is determined as the third correlation rate; and the mean value between the first correlation rate, the second correlation rate and the third correlation rate is determined as the target correlation rate between the threat intelligence to be processed and the matched known threat.
[0080] It can be understood that, by using the above technical solution, the first correlation rate between the matched attack technology of the known threat and the attack technology of the threat intelligence to be processed is calculated, the second correlation rate between the matched attack method of the known threat and the attack method of the threat intelligence to be processed is calculated, the third correlation rate between the matched attack tool of the known threat and the attack tool of the threat intelligence to be processed is calculated, and the target correlation rate between the threat intelligence to be processed and the matched known threat is determined according to the first correlation rate, the second correlation rate and the third correlation rate, thereby improving the accuracy of the target correlation rate between the threat intelligence to be processed and the matched known threat.
[0081] In S208, it is determined whether to process the threat intelligence to be processed according to the intelligence accuracy rate, the available processing time length, the credibility rate and the target correlation rate.
[0082] Optionally, it is determined whether to process the threat intelligence to be processed according to the intelligence accuracy rate, the available processing time length, the credibility rate and the correlation rate, including: the intelligence accuracy rate, the available processing time length, the credibility rate and the target correlation rate are weighted and summed to obtain an effective value of the threat intelligence to be processed; and it is determined whether to process the threat intelligence to be processed according to the effective value of the threat intelligence to be processed.
[0083] Specifically, the intelligence accuracy rate, the available processing time length, the credibility rate and the target correlation rate can be weighted and summed by using a set intelligence accuracy rate weight, a set available processing time length weight, a set credibility rate and a set target correlation rate to obtain the effective value of the threat intelligence to be processed; and the effective value of the threat intelligence to be processed can be expressed by the following formula, for example:
[0084] Y=ax1+bx2+cx3+d(1-x4);
[0085] wherein Y represents the effective value, a represents the intelligence accuracy rate weight, x1 represents the intelligence accuracy rate, b represents the credibility rate weight, x2 represents the credibility rate, c represents the target correlation rate weight, x3 represents the target correlation rate, d represents the available processing time length weight, and x4 represents the available processing time length.
[0086] If the effective value of the threat intelligence to be processed is greater than or equal to a set threshold value, it is determined that the threat intelligence to be processed needs to be processed; and if the effective value of the threat intelligence to be processed is less than the set threshold value, it is determined that the threat intelligence to be processed does not need to be processed.
[0087] It can be understood that, by using the above technical solution, the intelligence accuracy rate, the available processing time length, the credibility rate and the target correlation rate can be weighted and summed to obtain the effective value of the threat intelligence to be processed; and it is determined whether to process the threat intelligence to be processed according to the effective value of the threat intelligence to be processed, thereby improving the accuracy of the determination of whether the threat intelligence to be processed needs to be processed.
[0088] In an optional embodiment, the finally determined threat intelligence to be processed that needs to be processed can be determined as target threat intelligence; a visualization tool can be used to visualize each target threat intelligence and integrate into a unified view to facilitate analysis and processing of each target threat intelligence; the visualization tool can include but is not limited to chart tools, graphic tools and dashboard tools, etc.
[0089] In an optional embodiment, a time view of the threat event corresponding to the threat intelligence to be processed can also be generated according to the receiving time and the occurrence time, so as to facilitate the technical personnel to understand the evolution process of the threat.
[0090] In an optional embodiment, the geographical location information of the attacked power equipment of the threat event corresponding to the target threat intelligence can also be analyzed to visualize the affected geographical area and other information on the map.
[0091] In an optional embodiment, the threat database can periodically notify the technical personnel to update the data in the threat database; the user can update the data in the threat database by manual input, manual upload or using removable media; the threat database can export or share the threat parameters to the technical personnel of the power grid system in other regions.
[0092] In an optional embodiment, the number of threat intelligence to be processed can be at least one. Before determining the intelligence accuracy of the intelligence source to which the threat intelligence to be processed belongs according to the first identification information, the second identification information and the third identification information, the information recorded in each threat intelligence to be processed can be data cleaned, and the threat intelligence to be processed can be updated according to the cleaning result.
[0093] In an optional embodiment, the IP domain name intelligence in the threat intelligence to be processed can be matched according to the blacklist database; wherein the blacklist database stores at least one known malicious IP domain name, and whether there is a malicious IP domain name matching the IP domain name of the threat intelligence to be processed in the blacklist database is searched; if there is, the IP domain name of the threat intelligence to be processed is determined as malicious IP domain name intelligence, the network traffic transmitted by the malicious IP domain name intelligence is identified, and the network traffic associated with the malicious IP domain name is alarmed to prevent the power system from communicating with the malicious IP domain name.
[0094] In an optional embodiment, the asset corresponding to each to-be-processed threat intelligence and the asset portrait can be compared to determine the to-be-processed threat intelligence of the important-level asset. The asset portrait contains the asset level corresponding to the asset and can determine the important-level asset, thereby determining the threat intelligence information of the important-level asset and determining the threat intelligence information as the high-risk asset threat intelligence. The asset portrait contains the asset and the asset level, and the asset level contains low, medium and high.
[0095] In an optional embodiment, the malicious file information and the malware information in the to-be-processed threat intelligence can be analyzed, including the sample, the analysis report and the detailed information of the behavior of the malicious file. The power grid system determines whether the file in the network transmission is a malicious file according to the to-be-processed threat intelligence, and executes an alarm if it is determined to be a malicious file.
[0096] Further, the malicious file information and the malware information in the to-be-processed threat intelligence can be analyzed in a database matching manner, the matched file types include file strings, codes, digital signatures, etc. The attempt of the malware to communicate with the outside world is recorded as an analysis report, including DNS (Domain Name System) requests, HTTP (HyperText Transfer Protocol) / HTTPS (HyperText Transfer Protocol Secure) traffic and C&C (Command and Control) server interaction. The system log, the security log and the application log are viewed to view the behavior of the malicious file, such as registry modification, process creation and destruction and network connection.
[0097] The technical scheme of the embodiment of the present application can identify the target attack parameter of the to-be-processed threat intelligence according to the first threat parameter through the attack parameter identification model, find the known threat matched with the to-be-processed threat intelligence according to the second threat parameter and the first threat parameter of each known threat, and determine the target correlation rate between the to-be-processed threat intelligence and the matched known threat according to the threat attack parameter of the matched known threat and the target attack parameter, thereby improving the accuracy of the determined target correlation rate.
[0098] Embodiment three
[0099] Figure 3 A structural schematic diagram of a threat intelligence processing device provided by the embodiment three of the present application. The embodiment can be applicable to judging whether to process the threat intelligence. The device can execute the threat intelligence processing method. The threat intelligence processing device can be realized in the form of hardware and / or software. The device can be configured in an electronic device, such as a server.
[0100] Referring to Figure 3 The threat information processing device shown in the embodiment comprises a parameter acquisition module 301, an accuracy rate determination module 302, a time length determination module 303, a credibility rate determination module 304, a correlation rate determination module and a processing judgment module 305, wherein,
[0101] The parameter acquisition module 301 is configured to acquire a first threat parameter in the threat information to be processed, a receiving time of the threat information to be processed, an occurrence time of a threat event corresponding to the threat information to be processed, first identification information of an intelligence source to which the threat information to be processed belongs, second identification information of an intelligence source of historical threat information, third identification information of an intelligence source of historical accurate information, a second threat parameter of a known threat in a threat database, a threat attack parameter of the known threat and a third threat parameter recorded in a power system operation log.
[0102] The accuracy rate determination module 302 is configured to determine an intelligence accuracy rate of the intelligence source to which the threat information to be processed belongs according to the first identification information, the second identification information and the third identification information.
[0103] The time length determination module 303 is configured to determine an available processing time length of the threat information to be processed according to the receiving time and the occurrence time.
[0104] The credibility rate determination module 304 is configured to determine a credibility rate of the threat information to be processed according to the first threat parameter and the third threat parameter.
[0105] The correlation rate determination module 305 is configured to determine a target correlation rate between the threat information to be processed and the known threat according to the second threat parameter of the known threat in the threat database, the threat attack parameter of the known threat and the first threat parameter.
[0106] The processing judgment module 306 is configured to determine whether to process the threat information to be processed according to the intelligence accuracy rate, the available processing time length, the credibility rate and the target correlation rate.
[0107] The embodiment of the present application can determine the intelligence accuracy rate, the available processing time length, the credibility rate and the target correlation rate of the threat information to be processed respectively, and then comprehensively determine whether to process the threat information to be processed according to the intelligence accuracy rate, the available processing time length, the credibility rate and the target correlation rate of the threat information to be processed, so as to filter out the threat information to be processed with low effectiveness, reduce the number of threat information to be processed and improve the processing efficiency of processing a large number of threat information to be processed.
[0108] Optionally, the accuracy rate determination module 302 comprises:
[0109] The first quantity determining unit is configured to, according to the identification information of the information source to which the threat information to be processed belongs, count, in the identification information of the information source to which the historical threat information belongs, a first quantity of historical threat information of which the information source is the same as the information source to which the threat information to be processed belongs.
[0110] The second quantity determining unit is configured to, according to the identification information of the information source to which the threat information to be processed belongs, count, in the identification information of the information source to which the historical accurate information belongs, a second quantity of historical accurate information of which the information source is the same as the information source to which the threat information to be processed belongs.
[0111] The accuracy rate determining unit is configured to determine, according to the first quantity and the second quantity, the information accuracy rate of the information source to which the threat information to be processed belongs.
[0112] Optionally, the time length determining module 303 comprises:
[0113] The time length determining unit is configured to calculate the time length between the receiving time and the occurrence time, and determine the calculated time length as the available processing time length of the threat information to be processed.
[0114] Optionally, the number of the first threat parameters is at least one, and the number of the third threat parameters is at least one.
[0115] The credibility rate determining module 304 comprises:
[0116] The correct searching unit is configured to, for each first threat parameter, search, in the third threat parameters, a third threat parameter that is the same as the first threat parameter, and determine the searched third threat parameter as the threat evidence corresponding to the first threat parameter.
[0117] The quantity counting unit is configured to count the number of the threat evidence corresponding to each first threat parameter.
[0118] The credibility rate determining unit is configured to determine, according to the number of the threat evidence corresponding to each first threat parameter, the credibility rate of the threat information to be processed.
[0119] Optionally, the correlation rate determining module 305 comprises:
[0120] The target parameter determining unit is configured to, according to the first threat parameter, identify, by using an attack parameter identification model, a target attack parameter of the threat information to be processed.
[0121] The known threat searching unit is configured to search, according to the second threat parameter of each known threat and the first threat parameter, a known threat that matches the threat information to be processed.
[0122] The correlation rate determining unit is configured to determine, according to the threat attack parameter of the matched known threat and the target attack parameter, a target correlation rate between the threat information to be processed and the matched known threat.
[0123] Optionally, the threat attack parameter is an attack parameter of a known threat; the target attack parameter is an attack parameter of the threat intelligence to be processed; and the attack parameter comprises an attack technology, an attack method and an attack tool.
[0124] The correlation rate determination unit is specifically configured to:
[0125] calculate a first correlation rate between the attack technology of the matched known threat and the attack technology of the threat intelligence to be processed;
[0126] calculate a second correlation rate between the attack method of the matched known threat and the attack method of the threat intelligence to be processed;
[0127] calculate a third correlation rate between the attack tool of the matched known threat and the attack tool of the threat intelligence to be processed;
[0128] determine a target correlation rate between the threat intelligence to be processed and the matched known threat according to the first correlation rate, the second correlation rate and the third correlation rate.
[0129] Optionally, the processing judgment module comprises:
[0130] The effective value determination unit is configured to perform weighted summation on the intelligence accuracy rate, the available processing time length, the credibility rate and the target correlation rate to obtain an effective value of the threat intelligence to be processed.
[0131] The judgment unit is configured to judge whether to process the threat intelligence to be processed according to the effective value of the threat intelligence to be processed.
[0132] The threat intelligence processing device provided by the embodiment of the present application can execute the threat intelligence processing method provided by any embodiment of the present application, and has the corresponding function modules and beneficial effects of executing the threat intelligence processing method.
[0133] Embodiment four
[0134] Figure 4 A structural schematic diagram of an electronic device 400 that can be used to implement embodiments of the present application is shown. The electronic device is intended to represent various forms of digital computers, such as laptops, desktops, tablets, personal digital assistants, servers, blade servers, mainframes, and other appropriate computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular telephones, smartphones, wearable devices (e.g., headsets, glasses, watches, etc.), and other similar computing devices. The components shown here, their connections and relationships, and their functions, are meant to be examples only, and are not intended to limit the implementations of the present application described and / or claimed in this document.
[0135] As Figure 4As shown, the electronic device 400 includes at least one processor 401, and a memory, such as a read-only memory (ROM) 402, a random access memory (RAM) 403, and the like, connected to the at least one processor 401 in communication. The memory stores a computer program executable by the at least one processor, and the processor 401 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 402 or loaded from the storage unit 408 into the random access memory (RAM) 403. In the RAM 403, various programs and data required for the operation of the electronic device 400 can also be stored. The processor 401, the ROM 402, and the RAM 403 are connected to each other through a bus 404. An input / output (I / O) interface 405 is also connected to the bus 404.
[0136] A plurality of components in the electronic device 400 are connected to the I / O interface 405, including an input unit 406, such as a keyboard, a mouse, and the like, an output unit 407, such as various types of displays, a speaker, and the like, a storage unit 408, such as a magnetic disk, an optical disk, and the like, and a communication unit 409, such as a network card, a modem, a wireless communication transceiver, and the like. The communication unit 409 allows the electronic device 400 to exchange information / data with other devices through a computer network, such as the Internet, and / or various telecommunication networks.
[0137] The processor 401 can be various general-purpose and / or special-purpose processing components having processing and computing capabilities. Some examples of the processor 401 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, and the like. The processor 401 performs various methods and processes described above, such as the processing method of threat intelligence.
[0138] In some embodiments, the processing method of threat intelligence can be implemented as a computer program tangibly embodied in a computer readable storage medium, such as the storage unit 408. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 400 via the ROM 402 and / or the communication unit 409. When the computer program is loaded into the RAM 403 and executed by the processor 401, one or more steps of the processing method of threat intelligence described above can be performed. Alternatively, in other embodiments, the processor 401 can be configured to perform the processing method of threat intelligence by any other appropriate means, such as by means of firmware.
[0139] The various embodiments of the systems and techniques described above can be implemented in digital electronic circuitry, integrated circuitry, a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on a chip (SOC), a complex programmable logic device (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.
[0140] Computer programs used to implement the methods of the application can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable processing device to produce a machine, such that the computer program, when executed, implements the functions / acts specified in the flowcharts and / or block diagrams. The computer program can be executed entirely on a machine, partially on a machine, partially on a machine and partially on a remote machine or entirely on a remote machine or server.
[0141] In the context of the present application, a computer-readable storage medium can be a tangible medium that can contain or store computer programs for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium will include one or more lines of a program of instructions in a transitory signal, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0142] To provide for interaction with a user, the systems and techniques described here can be implemented on an electronic device having a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form, including acoustic, speech, or tactile input.
[0143] The systems and techniques described here can be implemented in a computing system that includes a back end component (e.g., as a data server), or that includes a middleware component (e.g., an application server), or that includes a front end component (e.g., a user computer having a graphical user interface or a Web browser through which a user can interact with an implementation of the systems and techniques described here), or any combination of such back end, middleware, or front end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), blockchain network, and the Internet.
[0144] The computing system can include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other. A server can be a cloud server, also known as cloud computing server or cloud host, which is a host product in the cloud computing service system, to solve the defects of large management difficulty and weak business scalability in traditional physical host and VPS (Virtual Private Server).
[0145] It should be understood that the various forms of flow shown above can be re-ordered, added to, or deleted from without departing from the scope of the present disclosure. For example, the steps recited in the present disclosure can be executed in parallel, executed in sequence, or executed in different orders, as long as the desired results of the present disclosure are achieved, and the present disclosure is not limited herein.
[0146] The above detailed description does not limit the scope of the application. Various modifications, combinations, sub-combinations and alternatives can be made to the detailed description. Any modification, equivalent replacement and improvement made within the spirit and principle of the application shall fall within the scope of the application.
Claims
1. A method of processing threat intelligence, characterized by, The method comprises: acquiring a first threat parameter in the to-be-processed threat information, a receiving time of the to-be-processed threat information, an occurrence time of a threat event corresponding to the to-be-processed threat information, first identification information of an information source to which the to-be-processed threat information belongs, second identification information of an information source to which historical threat information belongs, third identification information of an information source to which historical accurate information belongs, second threat parameters of known threats in a threat database, threat attack parameters of the known threats, and third threat parameters recorded in a power system operation log; determining an information accuracy rate of the information source to which the to-be-processed threat information belongs according to the first identification information, the second identification information, and the third identification information; determining an available processing duration of the to-be-processed threat information according to the receiving time and the occurrence time; determining a credibility rate of the to-be-processed threat information according to the first threat parameters and the third threat parameters; determining a target correlation rate between the to-be-processed threat information and the known threats according to the second threat parameters of the known threats in the threat database, the threat attack parameters of the known threats, and the first threat parameters; judging whether to process the to-be-processed threat information according to the information accuracy rate, the available processing duration, the credibility rate, and the target correlation rate.
2. The method of claim 1, wherein, The determining of the information accuracy rate of the information source to which the to-be-processed threat information belongs according to the identification information of the information source to which the to-be-processed threat information belongs, the identification information of the information source to which the historical threat information belongs, and the identification information of the information source to which the historical accurate information belongs comprises: counting, according to the identification information of the information source to which the to-be-processed threat information belongs, a first quantity of historical threat information in the identification information of the information source to which the historical threat information belongs and having the same information source as the information source to which the to-be-processed threat information belongs; counting, according to the identification information of the information source to which the to-be-processed threat information belongs, a second quantity of historical accurate information in the identification information of the information source to which the historical accurate information belongs and having the same information source as the information source to which the to-be-processed threat information belongs; determining the information accuracy rate of the information source to which the to-be-processed threat information belongs according to the first quantity and the second quantity.
3. The method of claim 1, wherein, The determining of the available processing duration of the to-be-processed threat information according to the receiving time and the occurrence time comprises: calculating a duration between the receiving time and the occurrence time, and determining the calculated duration as the available processing duration of the to-be-processed threat information.
4. The method of claim 1, wherein, The quantity of the first threat parameters is at least one, and the quantity of the third threat parameters is at least one. The determining of the credibility rate of the to-be-processed threat information according to the first threat parameters and the third threat parameters comprises: for each first threat parameter, searching, in the third threat parameters, a third threat parameter same as the first threat parameter, and determining the searched third threat parameter as threat evidence corresponding to the first threat parameter; counting the quantity of the threat evidence corresponding to each first threat parameter; determining the credibility rate of the to-be-processed threat information according to the quantity of the threat evidence corresponding to each first threat parameter.
5. The method of claim 1, wherein, The target correlation rate between the to-be-processed threat intelligence and the known threat is determined according to the second threat parameter of the known threat in the threat database, the threat attack parameter of the known threat and the first threat parameter, and the target correlation rate between the to-be-processed threat intelligence and the known threat is determined according to the second threat parameter of the known threat and the first threat parameter. The target attack parameter of the to-be-processed threat intelligence is identified according to the first threat parameter through an attack parameter identification model. The known threat matching the to-be-processed threat intelligence is found according to the second threat parameter of each known threat and the first threat parameter. The target correlation rate between the to-be-processed threat intelligence and the matching known threat is determined according to the threat attack parameter of the matching known threat and the target attack parameter.
6. The method of claim 5, wherein, The threat attack parameter is an attack parameter of the known threat; the target attack parameter is an attack parameter of the to-be-processed threat intelligence; and the attack parameter includes an attack technology, an attack method and an attack tool. The target correlation rate between the to-be-processed threat intelligence and the matching known threat is determined according to the threat attack parameter of the matching known threat and the target attack parameter, and the target correlation rate between the to-be-processed threat intelligence and the matching known threat is determined according to the first correlation rate, the second correlation rate and the third correlation rate. The first correlation rate between the attack technology of the matching known threat and the attack technology of the to-be-processed threat intelligence is calculated. The second correlation rate between the attack method of the matching known threat and the attack method of the to-be-processed threat intelligence is calculated. The third correlation rate between the attack tool of the matching known threat and the attack tool of the to-be-processed threat intelligence is calculated. The target correlation rate between the to-be-processed threat intelligence and the matching known threat is determined according to the first correlation rate, the second correlation rate and the third correlation rate.
7. The method of claim 1, wherein, The effective value of the to-be-processed threat intelligence is obtained by weighted summation of the intelligence accuracy rate, the available processing time length, the credibility rate and the target correlation rate. Whether to process the to-be-processed threat intelligence is determined according to the effective value of the to-be-processed threat intelligence. The device comprises:
8. A threat intelligence processing apparatus, characterized by comprising: The parameter acquisition module is configured to acquire a first threat parameter in to-be-processed threat intelligence, a receiving time of the to-be-processed threat intelligence, an occurrence time of a threat event corresponding to the to-be-processed threat intelligence, first identification information of an intelligence source to which the to-be-processed threat intelligence belongs, second identification information of an intelligence source of historical threat intelligence, third identification information of an intelligence source of historical accurate intelligence, a second threat parameter of a known threat in a threat database, a threat attack parameter of the known threat and a third threat parameter recorded in a power system operation log. The accuracy rate determination module is configured to determine an intelligence accuracy rate of the intelligence source to which the to-be-processed threat intelligence belongs according to the first identification information, the second identification information and the third identification information. The time length determination module is configured to determine an available processing time length of the to-be-processed threat intelligence according to the receiving time and the occurrence time. The credibility determining module is configured to determine a credibility of the threat intelligence to be processed according to the first threat parameter and the third threat parameter. The correlation determining module is configured to determine a target correlation between the threat intelligence to be processed and a known threat in the threat database according to a second threat parameter of the known threat, a threat attack parameter of the known threat, and the first threat parameter. The processing determining module is configured to determine whether to process the threat intelligence to be processed according to the intelligence accuracy, the available processing time length, the credibility, and the target correlation.
9. An electronic device, comprising: The electronic device comprises: at least one processor; and a memory connected with the at least one processor in communication; wherein the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to execute the threat intelligence processing method in any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer instructions, and the computer instructions are used to enable the processor to implement the threat intelligence processing method in any one of claims 1-7 when executed.
Citation Information
Patent Citations
Threat intelligence-based credibility updating method and apparatus, and electronic device
CN116170202A
Estimation apparatus, estimation method and program
US20230008765A1