Privacy-Preserving Network Threat Analysis Methods and Systems
By constructing specialized channels and learning evolutionary game models, we have achieved the protection of privacy of sensitive information in network threat intelligence sharing, improved network defense capabilities and intelligence sharing efficiency, and solved the problem of sensitive information leakage in threat intelligence sharing.
Patent Information
- Application Number
- CN202411714425.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-27
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2044-11-27
AI Technical Summary
How to protect the privacy of sensitive information in network threat intelligence sharing, prevent leakage or misuse, and improve network defense efficiency.
We establish specialized channels for disseminating intelligence, requiring authorization before joining, to cater to users with specific and sensitive information. We employ learning evolutionary game theory for quantitative analysis to obtain reasonable incentive strategies, manage user permissions through digital certificates and tags, and establish a shared model to protect privacy.
It has improved cybersecurity defense capabilities, promoted the sharing and utilization of threat intelligence, reduced the risk of sensitive information leakage, and enabled physical users to better deploy cybersecurity defense measures.
Smart Images

Figure CN119520136B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cybersecurity technology, and in particular to a privacy-preserving method and system for analyzing cyber threats. Background Technology
[0002] Sharing cyber threat intelligence can improve the efficiency of cyber defense. However, threat intelligence often contains sensitive information. If this sensitive information is leaked or misused, it may lead to serious consequences and huge losses. Therefore, controlling access to threat intelligence and protecting its privacy has become one of the key aspects of threat intelligence exchange and sharing.
[0003] Therefore, there is an urgent need for a targeted, privacy-preserving method and system for analyzing cyber threats. Summary of the Invention
[0004] The purpose of this invention is to provide a network threat analysis method and system based on privacy protection. By constructing a professional channel to distribute intelligence, and requiring authorization before joining, it satisfies users with specific and sensitive information. At the same time, it models and analyzes the expected benefits shared by different users, and uses learning evolutionary game theory for quantitative analysis to obtain a reasonable incentive strategy, thereby protecting the privacy of users' sensitive information and improving network security defense capabilities.
[0005] Firstly, this application provides a privacy-preserving network threat analysis method, the method comprising:
[0006] An entity user submits a registration request to an authentication server, which returns a digital certificate to the entity user. Based on the digital certificate, the entity user can communicate encrypted with other entities and create shared models and share threat intelligence with other entities.
[0007] Based on the digital certificate, the entity user joins the open community and applies to join the professional channel as needed; joining the open community is automatically reviewed by a smart contract, which is stored on the blockchain and provided to the user for use; the professional channel is independent of the open community, and the professional channel is reviewed by the authentication server. After the review is passed, the authentication server issues a tag signed by the digital certificate to the entity user, which carries the scope of permissions and validity period information;
[0008] The entity users share the threat intelligence they have obtained with the open community. The threat intelligence comes from one or more of the following: their own network monitoring, intrusion detection system, intrusion prevention system, security information, event management system, network traffic, and log data. They also return incentives from the open community. If privacy needs to be protected, the entity users carry their own corresponding tags in the threat intelligence.
[0009] In the process of returning incentives, the open community first has each entity user jointly create a shared model based on learning evolutionary game theory. Each entity user carries their own digital certificate C and / or tag L in the shared threat intelligence. Assuming that each entity user participates with bounded rationality, in the initial stage of the game, each entity user chooses to share threat intelligence with a certain probability P. Participating in sharing threat intelligence can obtain a certain payoff U. The higher the quality of the threat intelligence, the larger the coefficient w associated with it. The aforementioned digital certificate C and / or tag L, probability P, and coefficient w are used as the input terms of the shared model, and the payoff U is used as the output term of the shared model. The shared model is trained with the goal of maximizing the payoff U. Each entity user with bounded rationality uses the shared model to participate in repeated games. The open community calculates the expected payoff of sharing based on the output payoff U and returns it as an incentive to each entity user.
[0010] The open community conducts a quality assessment of the threat intelligence shared by various entity users and shares the quality assessment results in the open community. The quality assessment results are positively correlated with the coefficient w.
[0011] Each entity user initiates a query request. After identity verification, the open community returns threat intelligence that meets the query conditions to the entity user. If the threat intelligence obtained carries a tag, it indicates that it contains sensitive information. The authentication server will be notified to verify whether the entity user who initiated the query request has the tag signed by the digital certificate, and whether the scope of permissions and validity period information meet the requirements. If the requirements are met, the threat intelligence containing sensitive information will be sent to the entity user through a professional channel.
[0012] Physical users analyze the threat intelligence obtained from the query and deploy their own network defense measures based on the analysis results.
[0013] Secondly, this application provides a privacy-protected network threat analysis system, which includes: entity users, authentication servers, open communities, professional channels, and blockchain;
[0014] An entity user submits a registration request to an authentication server, which returns a digital certificate to the entity user. Based on the digital certificate, the entity user can communicate encrypted with other entities and create shared models and share threat intelligence with other entities.
[0015] Based on the digital certificate, the entity user joins the open community and applies to join the professional channel as needed; joining the open community is automatically reviewed by a smart contract, which is stored on the blockchain and provided to the user for use; the professional channel is independent of the open community, and the professional channel is reviewed by the authentication server. After the review is passed, the authentication server issues a tag signed by the digital certificate to the entity user, which carries the scope of permissions and validity period information;
[0016] The entity users share the threat intelligence they have obtained with the open community. The threat intelligence comes from one or more of the following: their own network monitoring, intrusion detection system, intrusion prevention system, security information, event management system, network traffic, and log data. They also return incentives from the open community. If privacy needs to be protected, the entity users carry their own corresponding tags in the threat intelligence.
[0017] In the process of returning incentives, the open community first has each entity user jointly create a shared model based on learning evolutionary game theory. Each entity user carries their own digital certificate C and / or tag L in the shared threat intelligence. Assuming that each entity user participates with bounded rationality, in the initial stage of the game, each entity user chooses to share threat intelligence with a certain probability P. Participating in sharing threat intelligence can obtain a certain payoff U. The higher the quality of the threat intelligence, the larger the coefficient w associated with it. The aforementioned digital certificate C and / or tag L, probability P, and coefficient w are used as the input terms of the shared model, and the payoff U is used as the output term of the shared model. The shared model is trained with the goal of maximizing the payoff U. Each entity user with bounded rationality uses the shared model to participate in repeated games. The open community calculates the expected payoff of sharing based on the output payoff U and returns it as an incentive to each entity user.
[0018] The open community conducts a quality assessment of the threat intelligence shared by various entity users and shares the quality assessment results in the open community. The quality assessment results are positively correlated with the coefficient w.
[0019] Each entity user initiates a query request. After identity verification, the open community returns threat intelligence that meets the query conditions to the entity user. If the threat intelligence obtained carries a tag, it indicates that it contains sensitive information. The authentication server will be notified to verify whether the entity user who initiated the query request has the tag signed by the digital certificate, and whether the scope of permissions and validity period information meet the requirements. If the requirements are met, the threat intelligence containing sensitive information will be sent to the entity user through a professional channel.
[0020] Physical users analyze the threat intelligence obtained from the query and deploy their own network defense measures based on the analysis results.
[0021] Thirdly, this application provides a privacy-preserving network threat analysis system, the system comprising: entity users, authentication servers, intermediate devices, professional channels, and blockchain, wherein the intermediate devices comprise: a processor and a memory.
[0022] The memory is used to store program code and transmit the program code to the processor;
[0023] The processor is configured to execute any one of the possible methods of the first aspect according to the instructions in the program code.
[0024] Fourthly, this application provides a computer-readable storage medium for storing program code, which is executed by a processor to implement the method described in any one of the various possibilities of the first aspect.
[0025] Beneficial effects
[0026] This invention provides a privacy-preserving network threat analysis method and system. It distributes intelligence through specialized channels, requiring authorization before access is granted to users with specific and sensitive information. Simultaneously, it models and analyzes the expected benefits shared by different users, employing learning evolutionary game theory for quantitative analysis to obtain reasonable incentive strategies. This protects the privacy of users' sensitive information. Each user entity queries the open community to obtain the necessary threat intelligence, analyzes this intelligence, and deploys its own network defense measures. This improves network security defense capabilities and overcomes the problem of existing technologies leaking or misusing sensitive information during threat intelligence sharing, which could lead to serious consequences and huge losses.
[0027] The present invention has the following advantages and effects:
[0028] With appropriate incentives, the efficiency of sharing and utilizing cyber threat intelligence can be improved.
[0029] Establish a professional channel to distribute intelligence, and only authorized users can join, to meet the needs of users with specific and sensitive information;
[0030] By obtaining the most detailed threat intelligence possible from the open community, each entity user can better deploy its own network defense measures, improving defense capabilities while reducing the resources required to obtain intelligence;
[0031] Improve the efficiency of intelligence sharing. Attached Figure Description
[0032] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. Obviously, those skilled in the art can obtain other drawings based on these drawings without creative effort.
[0033] Figure 1 This is a flowchart of the privacy-preserving network threat analysis method of the present invention;
[0034] Figure 2 This is an architecture diagram of the privacy-protected network threat analysis system of the present invention. Detailed Implementation
[0035] The preferred embodiments of the present invention will now be described in detail with reference to the accompanying drawings, so that the advantages and features of the present invention can be more easily understood by those skilled in the art, thereby providing a clearer and more explicit definition of the scope of protection of the present invention.
[0036] Figure 1 A general flowchart of the privacy-preserving network threat analysis method provided in this application, the method comprising:
[0037] An entity user submits a registration request to an authentication server, which returns a digital certificate to the entity user. Based on the digital certificate, the entity user can communicate encrypted with other entities and create shared models and share threat intelligence with other entities.
[0038] Based on the digital certificate, the entity user joins the open community and applies to join the professional channel as needed; joining the open community is automatically reviewed by a smart contract, which is stored on the blockchain and provided to the user for use; the professional channel is independent of the open community, and the professional channel is reviewed by the authentication server. After the review is passed, the authentication server issues a tag signed by the digital certificate to the entity user, which carries the scope of permissions and validity period information;
[0039] The entity users share the threat intelligence they have obtained with the open community. The threat intelligence comes from one or more of the following: their own network monitoring, intrusion detection system, intrusion prevention system, security information, event management system, network traffic, and log data. They also return incentives from the open community. If privacy needs to be protected, the entity users carry their own corresponding tags in the threat intelligence.
[0040] In the process of returning incentives, the open community first has each entity user jointly create a shared model based on learning evolutionary game theory. Each entity user carries their own digital certificate C and / or tag L in the shared threat intelligence. Assuming that each entity user participates with bounded rationality, in the initial stage of the game, each entity user chooses to share threat intelligence with a certain probability P. Participating in sharing threat intelligence can obtain a certain payoff U. The higher the quality of the threat intelligence, the larger the coefficient w associated with it. The aforementioned digital certificate C and / or tag L, probability P, and coefficient w are used as the input terms of the shared model, and the payoff U is used as the output term of the shared model. The shared model is trained with the goal of maximizing the payoff U. Each entity user with bounded rationality uses the shared model to participate in repeated games. The open community calculates the expected payoff of sharing based on the output payoff U and returns it as an incentive to each entity user.
[0041] The open community conducts a quality assessment of the threat intelligence shared by various entity users and shares the quality assessment results in the open community. The quality assessment results are positively correlated with the coefficient w.
[0042] Each entity user initiates a query request. After identity verification, the open community returns threat intelligence that meets the query conditions to the entity user. If the threat intelligence obtained carries a tag, it indicates that it contains sensitive information. The authentication server will be notified to verify whether the entity user who initiated the query request has the tag signed by the digital certificate, and whether the scope of permissions and validity period information meet the requirements. If the requirements are met, the threat intelligence containing sensitive information will be sent to the entity user through a professional channel.
[0043] Physical users analyze the threat intelligence obtained from the query and deploy their own network defense measures based on the analysis results.
[0044] In some preferred embodiments, the network defense measures include: data encryption, firewall settings, intrusion blocking, and redirection.
[0045] In some preferred embodiments, the specialized channel is an encrypted communication channel.
[0046] The threat intelligence also includes daily data and event behavior, which are mapped to each other. Based on the mapping relationship, the data feature vectors of the same event can be associated to improve the quality of threat intelligence.
[0047] Each entity user can also query the open community for threat intelligence quality assessment results to determine if the returned threat intelligence meets their needs. If so, the threat intelligence is analyzed, and appropriate defensive measures are deployed. If not, the entity user reports that the threat intelligence bias is too large. The open community then adjusts the coefficient w, restarts the evolutionary game, calculates new shared expected payoffs, and returns new incentives to each entity user. These incentives also include penalties; entity users providing threat intelligence with excessive bias will be penalized accordingly to improve the overall intelligence reliability of the system.
[0048] Figure 2 The architecture diagram of the privacy-preserving network threat analysis system provided in this application includes: entity users, authentication server, open community, professional channel and blockchain;
[0049] An entity user submits a registration request to an authentication server, which returns a digital certificate to the entity user. Based on the digital certificate, the entity user can communicate encrypted with other entities and create shared models and share threat intelligence with other entities.
[0050] Based on the digital certificate, the entity user joins the open community and applies to join the professional channel as needed; joining the open community is automatically reviewed by a smart contract, which is stored on the blockchain and provided to the user for use; the professional channel is independent of the open community, and the professional channel is reviewed by the authentication server. After the review is passed, the authentication server issues a tag signed by the digital certificate to the entity user, which carries the scope of permissions and validity period information;
[0051] The entity users share the threat intelligence they have obtained with the open community. The threat intelligence comes from one or more of the following: their own network monitoring, intrusion detection system, intrusion prevention system, security information, event management system, network traffic, and log data. They also return incentives from the open community. If privacy needs to be protected, the entity users carry their own corresponding tags in the threat intelligence.
[0052] In the process of returning incentives, the open community first has each entity user jointly create a shared model based on learning evolutionary game theory. Each entity user carries their own digital certificate C and / or tag L in the shared threat intelligence. Assuming that each entity user participates with bounded rationality, in the initial stage of the game, each entity user chooses to share threat intelligence with a certain probability P. Participating in sharing threat intelligence can obtain a certain payoff U. The higher the quality of the threat intelligence, the larger the coefficient w associated with it. The aforementioned digital certificate C and / or tag L, probability P, and coefficient w are used as the input terms of the shared model, and the payoff U is used as the output term of the shared model. The shared model is trained with the goal of maximizing the payoff U. Each entity user with bounded rationality uses the shared model to participate in repeated games. The open community calculates the expected payoff of sharing based on the output payoff U and returns it as an incentive to each entity user.
[0053] The open community conducts a quality assessment of the threat intelligence shared by various entity users and shares the quality assessment results in the open community. The quality assessment results are positively correlated with the coefficient w.
[0054] Each entity user initiates a query request. After identity verification, the open community returns threat intelligence that meets the query conditions to the entity user. If the threat intelligence obtained carries a tag, it indicates that it contains sensitive information. The authentication server will be notified to verify whether the entity user who initiated the query request has the tag signed by the digital certificate, and whether the scope of permissions and validity period information meet the requirements. If the requirements are met, the threat intelligence containing sensitive information will be sent to the entity user through a professional channel.
[0055] Physical users analyze the threat intelligence obtained from the query and deploy their own network defense measures based on the analysis results.
[0056] This application provides a privacy-preserving network threat analysis system, the system comprising: entity users, authentication servers, intermediate devices, professional channels, and a blockchain, wherein the intermediate devices include: a processor and a memory.
[0057] The memory is used to store program code and transmit the program code to the processor;
[0058] The processor is configured to execute the method described in any one of the embodiments of the first aspect according to the instructions in the program code.
[0059] This application provides a computer-readable storage medium for storing program code, which is executed by a processor to implement the method described in any one of the embodiments of the first aspect.
[0060] In a specific implementation, the present invention also provides a computer storage medium, wherein the computer storage medium may store a program, and the program, when executed, may include some or all of the steps in the various embodiments of the present invention. The storage medium may be a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM), etc.
[0061] Those skilled in the art will clearly understand that the techniques in the embodiments of the present invention can be implemented using software plus necessary general-purpose hardware platforms. Based on this understanding, the technical solutions in the embodiments of the present invention, or the parts that contribute to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in various embodiments or certain parts of the embodiments of the present invention.
[0062] The same or similar parts between the various embodiments in this specification can be referred to mutually. In particular, the embodiments are basically similar to the method embodiments, so the description is relatively simple, and the relevant parts can be referred to the description in the method embodiments.
[0063] The embodiments of the present invention described above do not constitute a limitation on the scope of protection of the present invention.
Claims
1. A privacy-preserving network threat analysis method, characterized in that, The method includes: An entity user submits a registration request to an authentication server, which returns a digital certificate to the entity user. Based on the digital certificate, the entity user can communicate encrypted with other entities and create shared models and share threat intelligence with other entities. Based on the digital certificate, the entity user joins the open community and applies to join the professional channel as needed; joining the open community is automatically reviewed by a smart contract, which is stored on the blockchain and provided to the user for use; the professional channel is independent of the open community, and the professional channel is reviewed by the authentication server. After the review is passed, the authentication server issues a tag signed by the digital certificate to the entity user, which carries the scope of permissions and validity period information; The entity users share the threat intelligence they have obtained with the open community. The threat intelligence comes from one or more of the following: their own network monitoring, intrusion detection system, intrusion prevention system, security information, event management system, network traffic, and log data. They also return incentives from the open community. If privacy needs to be protected, the entity users carry their own corresponding tags in the threat intelligence. In the process of returning incentives, the open community first has each entity user jointly create a shared model based on learning evolutionary game theory. Each entity user carries their own digital certificate C and / or tag L in the shared threat intelligence. Assuming that each entity user participates with bounded rationality, in the initial stage of the game, each entity user chooses to share threat intelligence with a certain probability P. Participating in sharing threat intelligence can obtain a certain payoff U. The higher the quality of the threat intelligence, the larger the coefficient w associated with it. The aforementioned digital certificate C and / or tag L, probability P, and coefficient w are used as the input terms of the shared model, and the payoff U is used as the output term of the shared model. The shared model is trained with the goal of maximizing the payoff U. Each entity user with bounded rationality uses the shared model to participate in repeated games. The open community calculates the expected payoff of sharing based on the output payoff U and returns it as an incentive to each entity user. The open community conducts a quality assessment of the threat intelligence shared by various entity users and shares the quality assessment results in the open community. The quality assessment results are positively correlated with the coefficient w. Each entity user initiates a query request. After identity verification, the open community returns threat intelligence that meets the query conditions to the entity user. If the threat intelligence obtained carries a tag, it indicates that it contains sensitive information. The authentication server will be notified to verify whether the entity user who initiated the query request has the tag signed by the digital certificate, and whether the scope of permissions and validity period information meet the requirements. If the requirements are met, the threat intelligence containing sensitive information will be sent to the entity user through a professional channel. Physical users analyze the threat intelligence obtained from the query and deploy their own network defense measures based on the analysis results.
2. The method according to claim 1, characterized in that: The network defense measures include: data encryption, firewall settings, intrusion blocking, and redirection.
3. The method according to claim 1, characterized in that: The specialized channel is an encrypted communication channel.
4. A privacy-preserving network threat analysis system, characterized in that, The system includes: physical users, authentication servers, an open community, professional channels, and a blockchain; An entity user submits a registration request to an authentication server, which returns a digital certificate to the entity user. Based on the digital certificate, the entity user can communicate encrypted with other entities and create shared models and share threat intelligence with other entities. Based on the digital certificate, the entity user joins the open community and applies to join the professional channel as needed; joining the open community is automatically reviewed by a smart contract, which is stored on the blockchain and provided to the user for use; the professional channel is independent of the open community, and the professional channel is reviewed by the authentication server. After the review is passed, the authentication server issues a tag signed by the digital certificate to the entity user, which carries the scope of permissions and validity period information; The entity users share the threat intelligence they have obtained with the open community. The threat intelligence comes from one or more of the following: their own network monitoring, intrusion detection system, intrusion prevention system, security information, event management system, network traffic, and log data. They also return incentives from the open community. If privacy needs to be protected, the entity users carry their own corresponding tags in the threat intelligence. In the process of returning incentives, the open community first has each entity user jointly create a shared model based on learning evolutionary game theory. Each entity user carries their own digital certificate C and / or tag L in the shared threat intelligence. Assuming that each entity user participates with bounded rationality, in the initial stage of the game, each entity user chooses to share threat intelligence with a certain probability P. Participating in sharing threat intelligence can obtain a certain payoff U. The higher the quality of the threat intelligence, the larger the coefficient w associated with it. The aforementioned digital certificate C and / or tag L, probability P, and coefficient w are used as the input terms of the shared model, and the payoff U is used as the output term of the shared model. The shared model is trained with the goal of maximizing the payoff U. Each entity user with bounded rationality uses the shared model to participate in repeated games. The open community calculates the expected payoff of sharing based on the output payoff U and returns it as an incentive to each entity user. The open community conducts a quality assessment of the threat intelligence shared by various entity users and shares the quality assessment results in the open community. The quality assessment results are positively correlated with the coefficient w. Each entity user initiates a query request. After identity verification, the open community returns threat intelligence that meets the query conditions to the entity user. If the threat intelligence obtained carries a tag, it indicates that it contains sensitive information. The authentication server will be notified to verify whether the entity user who initiated the query request has the tag signed by the digital certificate, and whether the scope of permissions and validity period information meet the requirements. If the requirements are met, the threat intelligence containing sensitive information will be sent to the entity user through a professional channel. Physical users analyze the threat intelligence obtained from the query and deploy their own network defense measures based on the analysis results.
5. A privacy-preserving network threat analysis system implementing the method of any one of claims 1-3, characterized in that, The system includes: physical users, authentication servers, intermediate devices, professional channels, and a blockchain. The intermediate devices include: a processor and a memory. The memory is used to store program code and transmit the program code to the processor; The processor is used to execute instructions in the program code to implement the open community function in the method of any one of claims 1-3.
6. A computer-readable storage medium, characterized in that, The computer-readable storage medium is used to store program code, which is executed by a processor to implement the method of any one of claims 1-3.
Citation Information
Patent Citations
Threat information exchange sharing method based on block chain
CN109981564A
System and methods for detecting authentication object forgery or manipulation attacks
US20240244068A1