Threat intelligence triple extraction method and system based on double-pointer architecture
By adopting a triple extraction method based on a dual-pointer architecture in threat intelligence analysis, the problem of insufficient processing of complex semantics and context dependencies in the prior art is solved, and higher accuracy and efficiency of threat intelligence analysis are achieved.
Patent Information
- Application Number
- CN202510417210.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-03
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-04-03
AI Technical Summary
Existing threat intelligence extraction methods are difficult to effectively identify and process complex semantics, attack chains and context dependencies, resulting in inaccuracy and inefficiency of threat intelligence analysis.
A threat intelligence triple extraction method based on a dual-pointer architecture is adopted to generate context-aware vectors of head entities, tail entities and relationships through the BERT model, and a candidate entity pair is identified in combination with the dual-pointer architecture, and filter and classify the score module and Softmax layer to generate threat intelligence triple.
It improves the accuracy and stability of threat entity identification, enhances the model's understanding of context and complex relationships, and can more accurately reveal different links and relationships in the attack chain, providing security experts with more comprehensive and in-depth threat intelligence analysis.
Smart Images

Figure CN119938930A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of network security technology, and in particular relates to a threat intelligence triplet extraction method and system based on a dual-pointer architecture. Background Art
[0002] The statements in this section merely provide background information related to the present invention and do not necessarily constitute prior art.
[0003] With the rapid development of cyber attack technology, traditional security defense measures are facing unprecedented challenges. In particular, in the face of complex attack methods, such as advanced persistent threats (APT) and 0-day attacks, traditional defense systems are often unable to effectively identify and respond to these highly hidden and persistent attacks. Therefore, threat intelligence (CTI) has become an indispensable and important part of the network security field, providing detailed intelligence about network attacks and helping security teams prevent potential threats in real time.
[0004] Threat intelligence not only includes basic intrusion indicators (IOCs) such as malicious IP addresses, domain names, and file hashes, but also involves more comprehensive information such as attacker activity patterns, attack tools, attack sources, and attack targets. Unlike traditional security vulnerability databases (such as CVE), CTI provides more dynamic and timely reports that can describe the entire process of the attack, the attack chain, and its impact in detail, providing organizations with early warnings and helping to respond to new and complex network threats. CTI reports are usually generated by security experts through analysis of attack activities and published in the form of technical documents, reports, or news articles.
[0005] However, as cybersecurity threats continue to escalate, the number and complexity of CTI have also shown explosive growth, which has brought tremendous pressure to manual analysis and processing. Existing CTI extraction methods often rely on rule matching or regular expressions to extract key indicators. Although these methods are effective in some cases, they are prone to overlooking certain potential threat information due to the lack of understanding of context and semantics. In addition, existing methods do not adequately handle the professional terms and complex contexts in threat intelligence, resulting in low accuracy in extracting and classifying information.
[0006] In recent years, deep learning technology has been widely used in the automated analysis of threat intelligence, especially through natural language processing (NLP) methods to process unstructured text data. These methods can automatically extract potential threat information from CTI reports, including attack sources, targets, and attack patterns. However, the existing deep learning framework still has shortcomings, mainly reflected in the insufficient understanding of the complex semantics, attack chains, and contextual dependencies in threat intelligence. Therefore, it is difficult for existing technologies to effectively respond to specific challenges in the field of network security, and it is impossible to provide security experts with comprehensive and accurate threat intelligence analysis, and it is also impossible to help security teams respond more quickly and accurately when dealing with complex attacks. Summary of the invention
[0007] In order to overcome the shortcomings of the above-mentioned prior art, the present invention provides a threat intelligence triplet extraction method and system based on a dual-pointer architecture, which can effectively avoid mutual interference between entities, thereby ensuring that the generated threat entity triplet is more accurate, accurately revealing the different links in the attack chain and the relationship between them, and providing security experts with a more comprehensive and in-depth threat intelligence analysis.
[0008] To achieve the above objectives, one or more embodiments of the present invention provide the following technical solutions: A first aspect of the present invention provides a threat intelligence triple extraction method based on a dual-pointer architecture.
[0009] A threat intelligence triplet extraction method based on a dual-pointer architecture includes: Get the text of threat intelligence; The obtained text is analyzed using the BERT model as an encoder, that is, three independent weight matrices are used to generate context-aware vectors for the head entity, tail entity, and relation respectively; Based on the dual pointer architecture, the context-aware vectors of the head entity and the tail entity are respectively identified, and candidate entity pairs are generated; the candidate entity pairs and the context-aware vector of the relationship are concatenated to generate a relationship entity vector; The scoring module is used to filter the relationship entity vectors; the filtered relationship entity vectors are input into the Softmax layer for relationship classification to generate the identification results of threat intelligence triples.
[0010] Furthermore, the dual-pointer architecture includes a head entity recognition module and a tail entity recognition module, and the head entity recognition module and the tail entity recognition module have the same network architecture.
[0011] Furthermore, the head entity recognition module is used to identify the context-aware vector of the head entity, decode it after capturing the context information of the head entity, and finally output the head entity set; the tail entity recognition module is used to identify the context-aware vector of the tail entity, decode it after capturing the context information of the tail entity, and finally output the tail entity set.
[0012] Furthermore, each entity in the head entity set and the tail entity set is concatenated two by two to generate a candidate entity pair.
[0013] Furthermore, the relationship entity vectors are screened using a scoring module, which is implemented based on a double-layer multi-layer perceptron. Specifically, the concatenated multiple relationship entity vectors are input into a double-layer multi-layer perceptron, and the double-layer multi-layer perceptron scores each entity pair in the multiple relationship entity vectors, and screens the relationship entity vectors according to the scoring results.
[0014] Furthermore, a scoring threshold is set, and the scores given by the double-layer multi-layer perceptron to each relationship entity vector are compared with the set scoring threshold, and entity pairs with lower scores are discarded, and only entity pairs with scores higher than the set scoring threshold are retained.
[0015] Furthermore, the Softmax layer selects the optimal relationship in the filtered relationship entity vector according to the calculated output probability value, and finally generates a threat intelligence triplet including a head entity, a tail entity and a relationship.
[0016] A second aspect of the present invention provides a threat intelligence triplet extraction system based on a dual-pointer architecture.
[0017] A threat intelligence triplet extraction system based on a dual-pointer architecture, comprising: The BERT model encoding module is configured to: obtain the text of threat intelligence; analyze the obtained text using the BERT model as an encoder, that is, using three independent weight matrices to generate context-aware vectors for the head entity, the tail entity, and the relationship respectively; The dual-pointer architecture module is configured to: identify the context-aware vectors of the head entity and the tail entity respectively based on the dual-pointer architecture, and generate a candidate entity pair; concatenate the candidate entity pair and the context-aware vector of the relationship to generate a relationship entity vector; The scoring module is configured to: filter the relation entity vectors using the scoring module; The relationship classification module is configured to: input the filtered relationship entity vector into the Softmax layer for relationship classification to generate the recognition result of the threat intelligence triplet. A third aspect of the present invention provides a computer-readable storage medium having a program stored thereon, which, when executed by a processor, implements the steps in a threat intelligence triple extraction method based on a dual-pointer architecture as described in the first aspect of the present invention.
[0018] The fourth aspect of the present invention provides an electronic device, including a memory, a processor, and a program stored in the memory and executable on the processor. When the processor executes the program, the steps in the threat intelligence triple extraction method based on a dual-pointer architecture as described in the first aspect of the present invention are implemented.
[0019] One or more of the above technical solutions have the following beneficial effects: The present invention identifies the context-aware vectors of the head entity and the tail entity respectively based on the dual-pointer architecture, and generates candidate entity pairs; the candidate entity pairs and the context-aware vectors of the relationship are spliced to generate a relationship entity vector. The present invention uses an innovative dual-pointer architecture to independently identify the head entity and the tail entity, effectively avoiding the influence of mutual interference between entities and improving the accuracy and stability of entity recognition; in addition, the model generates a relationship entity vector, splices the vectors of the head and tail entity pairs and the relationship representation, and accurately captures the complex relationship between entities. This process not only enhances the model's ability to understand the context, but also can better model the multi-level relationships in the attack chain, effectively improving the deep learning framework in the prior art in the threat intelligence analysis. There are significant deficiencies, especially in the understanding of complex semantics, attack chains and context dependencies; at the same time, it also avoids the problem that traditional models are difficult to accurately capture the multi-level and multi-dimensional entity relationships in the threat intelligence in the field of network security, resulting in the inability to provide accurate analysis results for security experts.
[0020] The present invention uses a scoring module to screen the relationship entity vector; the screened relationship entity vector is input into the Softmax layer for relationship classification to generate the recognition result of the threat intelligence triple. By adopting a scoring mechanism and a preset threshold, the present invention can accurately screen out high-quality candidate entity pairs and discard low-quality invalid entity pairs, thereby reducing the computational burden and improving efficiency. Through this screening method, the model can focus on processing high-quality entity pairs and avoid the interference of invalid data on the final result; at the same time, this method also ensures that the generated threat entity triple is more accurate, can accurately reveal the different links in the attack chain and the relationship between them, and provide security experts with a more comprehensive and in-depth threat intelligence analysis.
[0021] Advantages of additional aspects of the present invention will be given in part in the following description, and in part will become obvious from the following description, or will be learned through practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] The accompanying drawings in the specification, which constitute a part of the present invention, are used to provide a further understanding of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute improper limitations on the present invention.
[0023] Figure 1 This is a flowchart of a threat intelligence triplet extraction method based on a dual-pointer architecture in Example 1 of the present invention.
[0024] Figure 2 This is a structural diagram of a threat intelligence triplet extraction system based on a dual-pointer architecture in Example 2 of the present invention. DETAILED DESCRIPTION
[0025] It should be noted that the following detailed descriptions are exemplary and are intended to provide further explanation of the present invention. Unless otherwise specified, all technical and scientific terms used herein have the same meanings as those commonly understood by those skilled in the art to which the present invention belongs.
[0026] It should be noted that the terms used herein are for describing specific embodiments only and are not intended to be limiting of exemplary embodiments according to the present invention.
[0027] In the absence of conflict, the embodiments of the present invention and the features of the embodiments may be combined with each other. The overall idea proposed by the present invention is as follows: The present invention provides a threat intelligence triple extraction method based on a dual-pointer architecture. The method uses a BERT model as an encoder. First, three context-aware vectors are generated through three independent weight matrices, which respectively represent the semantic information of the head entity, the tail entity, and the relationship. Subsequently, the semantic information of the head entity, the tail entity, and the relationship is placed in an entity recognition unit. The unit adopts a dual-pointer network architecture and includes two identical entity recognition modules, which are used to recognize the head entity and the tail entity, respectively; wherein the head entity recognition module decodes the semantic information of the head entity and processes it through the Multi-Head Self Attention layer, the Multi-Head Cross-Attention layer, and the Feed Forward Network layer. These layers help the model capture the context information of the head entity and finally output a set of candidate head entities. The processing process of the tail entity recognition module is the same as that of the head entity module (parameters are independent). The semantic information of the tail entity is decoded, and after the same three-layer structure processing, a set of candidate tail entities is generated. Next, the model concatenates each entity in the head entity set and the tail entity set in pairs to generate multiple entity pairs. For each pair of entities, the model concatenates the vector of the head and tail entity pairs with the relationship representation to form a relationship entity vector containing the head entity, tail entity, and relationship information. Subsequently, the concatenated vector is input into a two-layer multi-layer perceptron (MLP) for scoring. The MLP scores each entity pair and discards entity pairs with lower scores based on the scoring results, retaining only entity pairs with scores higher than the set threshold. After scoring and screening, the retained entity pairs are sent to the Softmax layer for relationship identification. The Softmax layer selects the optimal relationship based on the output probability value and generates the final triple (head entity, relationship, tail entity).
[0028] Embodiment 1 This embodiment discloses a threat intelligence triplet extraction method based on a dual-pointer architecture.
[0029] like Figure 1 As shown, a threat intelligence triplet extraction method based on a dual-pointer architecture includes: Step S1, obtaining the text of threat intelligence; using the BERT model as an encoder to analyze the obtained text, that is, using three independent weight matrices to generate context-aware vectors of the head entity, the tail entity, and the relationship respectively; Step S2: identifying the context-aware vectors of the head entity and the tail entity respectively based on the dual-pointer architecture, and generating candidate entity pairs; concatenating the candidate entity pairs and the context-aware vector of the relationship to generate a relationship entity vector; Step S3: Using the scoring module to screen the relationship entity vectors; Step S4: Input the filtered relationship entity vector into the Softmax layer for relationship classification to generate the recognition result of the threat intelligence triplet.
[0030] Based on the above process, the present invention can effectively avoid mutual interference between entities, thereby ensuring that the generated threat entity triples are more accurate, accurately revealing the different links in the attack chain and the relationship between them, and providing security experts with a more comprehensive and in-depth threat intelligence analysis. To facilitate the understanding of the technical solution of the present invention, the specific implementation steps in the technical solution of the present invention are further explained and illustrated below.
[0031] Step S1, obtaining the text of threat intelligence; using the BERT model as an encoder to analyze the obtained text, that is, using three independent weight matrices to generate context-aware vectors of the head entity, the tail entity, and the relationship respectively.
[0032] Use the BERT model as the encoder and generate the head entity through an independent weight matrix , tail entity and relationship The context-aware vector can accurately capture the semantic information of different entities and relations to improve the accuracy of entity and relation extraction. This method enhances the model's context understanding ability by optimizing the representation of each element separately and can better model the complex interactive relationships between entities. This process involves the following key steps and formulas: First, define the input text of threat intelligence for ;in, For text Middle words, is the length of the sentence. Enter the text It is sent to the BERT model for embedding processing, and three context-aware vectors are generated through three independent weight matrices, namely: ; ; ; in, , and is the weight matrix of different vectors, which is used to map the context-aware vectors of head entity, tail entity and relation respectively; , and is the vector representation of the corresponding vector, , , For words The vector embedding of , , ; , and They are the embedding dimension representations of the head entity, tail entity, and relation vector respectively; Indicates a dimensional vector space, Indicates a dimensional matrix, Represents the embedding dimension representation of a vector.
[0033] Step S2: Based on the dual-pointer architecture, the context-aware vectors of the head entity and the tail entity are respectively identified, and candidate entity pairs are generated; the candidate entity pairs and the context-aware vectors of the relationship are concatenated to generate a relationship entity vector.
[0034] By using a dual-pointer architecture to independently identify the head entity and the tail entity, and concatenating the relationship representation with the head and tail entity pair vectors, the complex relationships and interactions between entities can be accurately modeled through fusion. This method improves the accuracy of entity and relationship extraction by independently optimizing the representation of the head and tail entities and effectively fusing the relationship information, enhancing the model's understanding of context and its ability to capture complex dependencies between entities.
[0035] The dual-pointer architecture includes two modules, namely the head entity recognition module and the tail entity recognition module, and the head entity recognition module and the tail entity recognition module have the same network architecture. The head entity recognition module is used to identify the context-aware vector of the head entity, decode it after capturing the context information of the head entity, and finally output the head entity set; the tail entity recognition module is used to identify the context-aware vector of the tail entity, decode it after capturing the context information of the tail entity, and finally output the tail entity set. The processing flow of each module of the dual-pointer architecture contains three main layers: Multi-Head Self-Attentionce layer, Multi-Head Cross-Attention layer, and Feed Forward Network layer.
[0036] Take the context-aware vector of head entity recognition as an example: First, the context representation of the input is processed through the Multi-Head Self-Attention layer , to capture the self-attention relationship between words in the sentence, that is: ; ; ; in, represents the contextual representation of the input head entity, weight matrices representing the query, key, and value of the head entity, respectively; The query vector representing the head entity, a key vector representing the head entity, The value vector representing the head entity. Then, the calculated attention score is normalized by the Softmax function to obtain the weighted representation of each word, namely: ; in, is the output of the head entity self-attention layer, is the dimension of the key vector, Representation vector Next, the Multi-Head Cross-Attention layer is used to interactively model the representation of the head entity and the context of the tail entity to capture the dependency between them. The specific formula is as follows: ; ; ; in, is the context representation matrix of the tail entity, are the weight matrices for query, key, and value across the attention layer, respectively; represents the query vector of the head entity across the attention layers, represents the key vector of the tail entity across the attention layer, Represents the value vector of the tail entity in the cross-attention layer. Through this cross-attention mechanism, the model can capture the interaction between the head entity and the tail entity. After the cross-attention layer, the model performs a nonlinear transformation through the Feed Forward Network (FFN) layer to obtain the final head entity representation, namely: ; in, is the weight matrix of FFN, Used to transform input features to hidden layer features, Used for transformation from hidden layer features to output features; is the bias term, is the activation function, is the head entity representation after FFN processing. The final output is the set representation of the head entity , Indicates the first A head entity.
[0037] The recognition process of the tail entity is similar to that of the head entity, and is also processed through the Multi-Head Self-Attention layer, Multi-Head Cross-Attention layer, and Feed Forward Network layer (but it is based on the tail entity recognition module).
[0038] First, the contextual representation of the input tail entity is processed through the Multi-Head Self-Attention layer , to capture the self-attention relationship between words in the sentence, that is: ; ; ; in, represents the contextual representation of the input tail entity, The weight matrices representing the query, key, and value of the tail entity respectively; The query vector representing the tail entity, represents the key vector of the tail entity, Represents the value vector of the tail entity. The calculated attention score is normalized by the Softmax function to obtain the weighted representation of each word, namely: ; in, is the output of the tail entity self-attention layer, is the dimension of the key vector, is a vector Next, the Multi-Head Cross-Attention layer is used to interactively model the representation of the tail entity and the context of the head entity to capture the dependency between them. The specific formula is as follows: ; ; ; in, is the context representation matrix of the tail entity, are the weight matrices for query, key, and value across the attention layer, respectively; represents the query vector of the tail entity across the attention layers, represents the key vector of the head entity across the attention layers, Represents the value vector of the head entity in the cross-attention layer. Through this cross-attention mechanism, the model can capture the interaction between the tail entity and the head entity. After the cross-attention layer, the model performs a nonlinear transformation through the Feed Forward Network (FFN) layer to obtain the final tail entity representation, namely: ; in, is the weight matrix of FFN, Used to transform input features to hidden layer features, Used for transformation from hidden layer features to output features; is the bias term, is the activation function, is the tail entity representation after FFN processing. The final output is the set representation of the tail entity , Represents the first A tail entity.
[0039] Furthermore, each entity in the head entity set and the tail entity set is concatenated two by two to generate candidate entity pairs. Specifically, in the head entity set and tail entity collection In the model, all possible entity pairs Combine them in pairs to generate multiple candidate entity pairs, where each pair of entities can be regarded as a potential relationship instance, namely: ; in, Represents the set of all possible candidate entity pairs. For each pair of entities , the model represents them and the relationship Concatenate and generate a relation entity vector containing entity and relation information, namely: ; in, represents the concatenated relation entity vector, Is the head entity and tail entity Entity pairs; It is a relational representation, which contains the semantic relationship between the head entity and the tail entity.
[0040] Step S3: Use the scoring module to screen the relationship entity vectors.
[0041] The scoring module is used to screen the relational entity vectors. The scoring module is implemented based on a two-layer multi-layer perceptron and can screen the relational entity vectors containing entity and relation information. Scoring is performed to screen out high-quality relational entity vectors, that is, the concatenated multiple relational entity vectors are input into a double-layer multi-layer perceptron, which scores each entity pair in the multiple relational entity vectors and screens the relational entity vectors based on the scoring results. Specifically, the relational entity vectors are input After the first layer of full connection (linear transformation) and activation function, an intermediate representation is obtained ,Right now: ; in, is a weight matrix responsible for projecting the input relation entity vector into the hidden layer space, and ; is the dimension of the input relation entity vector, is the dimension of the hidden layer, is the bias term, is the activation function.
[0042] The second layer converts the output of the hidden layer Further transformed into a score value , that is, the score of each candidate entity pair, namely: ; in, is the weight matrix of the second layer, is the dimension of the hidden layer, 1 means the output is a scalar (score value), is the bias term. Indicates the quality or validity of a candidate entity pair.
[0043] The candidate relationship entity vectors are screened according to the preset threshold: a scoring threshold is set, and the scores given by the double-layer multi-layer perceptron to each relationship entity vector are compared with the set scoring threshold, and entity pairs with lower scores are discarded, and only entity pairs with scores higher than the set scoring threshold are retained to generate the final set of relationship entity vectors, that is: ; in, Represents the final filtered relationship entity vector set. Is the head entity and tail entity The relationship entity vector. is the preset scoring threshold, and the relation entity vectors below this score will be discarded.
[0044] Step S4: Input the filtered relationship entity vector into the Softmax layer for relationship classification to generate the recognition result of the threat intelligence triplet.
[0045] The Softmax layer selects the optimal relationship (i.e., the most likely relationship) in the filtered relationship entity vector according to the calculated output probability value, and finally generates a threat intelligence triple containing the head entity, the tail entity, and the relationship. Specifically, the purpose of relationship classification is to classify the relationship entity vector of each candidate entity pair according to the relationship entity vector of each candidate entity pair. , predict the type of relationship between them. The Softmax layer outputs the probability distribution of each entity pair belonging to different relationship categories. Given each relationship entity vector , the Softmax layer will calculate the corresponding relationship category probability, that is: ; in, is the input filtered relation entity vector, which contains entity pairs Information, is the weight matrix of the Softmax layer, where is the number of relation categories, is the bias term of the Softmax layer, is the output probability after Softmax activation, indicating the candidate entity pair The probability of belonging to each relation category.
[0046] According to the probability distribution of the Softmax layer output , each entity can be The corresponding predicted relationship category Combined, the threat entity triple is finally generated Specifically, the triple generation formula is as follows: ; in, Represents entity pair The predicted relationship category between is the relationship type corresponding to the maximum value in the output probability of the Softmax layer.
[0047] Embodiment 2 This embodiment discloses a threat intelligence triplet extraction system based on a dual-pointer architecture.
[0048] like Figure 2 As shown, a threat intelligence triplet extraction system based on a dual-pointer architecture includes: The BERT model encoding module is configured to: obtain the text of threat intelligence; analyze the obtained text using the BERT model as an encoder, that is, use three independent weight matrices to generate context-aware vectors of the head entity, tail entity, and relationship respectively; wherein the three independent weight matrices are implemented through three independent transformation layers, namely Figure 2The head entity linear transformation layer, the tail entity linear transformation layer and the relationship linear transformation layer are shown in .
[0049] The dual-pointer architecture module is configured to: identify the context-aware vectors of the head entity and the tail entity respectively based on the dual-pointer architecture, and generate a candidate entity pair; concatenate the candidate entity pair and the context-aware vector of the relationship to generate a relationship entity vector; The scoring module is configured to: filter the relation entity vectors using the scoring module; The relationship classification module is configured to: input the filtered relationship entity vector into the Softmax layer for relationship classification to generate the recognition result of the threat intelligence triplet. Embodiment 3 The purpose of this embodiment is to provide a computer-readable storage medium.
[0050] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps in a threat intelligence triple extraction method based on a dual-pointer architecture as described in the first embodiment of the present disclosure.
[0051] Embodiment 4 The purpose of this embodiment is to provide an electronic device.
[0052] An electronic device includes a memory, a processor, and a program stored in the memory and executable on the processor. When the processor executes the program, the steps in a threat intelligence triple extraction method based on a dual-pointer architecture as described in Embodiment 1 of the present disclosure are implemented.
[0053] The steps involved in the apparatuses of the above embodiments 2, 3 and 4 correspond to the method embodiment 1, and the specific implementation methods can refer to the relevant description part of embodiment 1. The term "computer-readable storage medium" should be understood as a single medium or multiple media including one or more instruction sets; it should also be understood to include any medium that can store, encode or carry an instruction set for execution by a processor and enable the processor to execute any method in the present invention.
[0054] Those skilled in the art should understand that the modules or steps of the present invention described above can be implemented by a general-purpose computer device, or alternatively, they can be implemented by a program code executable by a computing device, so that they can be stored in a storage device and executed by the computing device, or they can be made into individual integrated circuit modules, or multiple modules or steps therein can be made into a single integrated circuit module for implementation. The present invention is not limited to any specific combination of hardware and software.
[0055] Although the above describes the specific implementation mode of the present invention in conjunction with the accompanying drawings, it is not intended to limit the scope of protection of the present invention. Those skilled in the art should understand that various modifications or variations that can be made by those skilled in the art on the basis of the technical solution of the present invention without creative work are still within the scope of protection of the present invention.
Claims
1. A threat intelligence triplet extraction method based on a dual pointer architecture, characterized in that: include: Get the text of threat intelligence; The resulting text is analyzed using the BERT model as an encoder, i.e., three independent weight matrices are used to generate context-aware vectors for the head entity, tail entity, and relation, respectively. Based on the dual pointer architecture, the context-aware vectors of the head entity and the tail entity are respectively identified, and candidate entity pairs are generated; the candidate entity pairs and the context-aware vector of the relationship are concatenated to generate a relationship entity vector; Use the scoring module to filter the relationship entity vectors; The filtered relationship entity vectors are input into the Softmax layer for relationship classification to generate the recognition results of threat intelligence triples.
2. A threat intelligence triplet extraction method based on a dual pointer architecture as claimed in claim 1, characterized in that: The dual-pointer architecture includes a head entity recognition module and a tail entity recognition module, and the head entity recognition module and the tail entity recognition module have the same network architecture.
3. A threat intelligence triplet extraction method based on a dual pointer architecture as described in any one of claims 1-2, characterized in that: The head entity recognition module is used to identify the context-aware vector of the head entity, decode it after capturing the context information of the head entity, and finally output the head entity set; the tail entity recognition module is used to identify the context-aware vector of the tail entity, decode it after capturing the context information of the tail entity, and finally output the tail entity set.
4. A threat intelligence triplet extraction method based on a dual pointer architecture as described in claim 3, characterized in that: Each entity in the head entity set and the tail entity set is concatenated two by two to generate candidate entity pairs.
5. A threat intelligence triplet extraction method based on a dual pointer architecture as claimed in claim 1, characterized in that: The relational entity vectors are screened using a scoring module, which is implemented based on a double-layer multi-layer perceptron. Specifically, the concatenated multiple relational entity vectors are input into a double-layer multi-layer perceptron, which scores each entity pair in the multiple relational entity vectors, and screens the relational entity vectors according to the scoring results.
6. A threat intelligence triplet extraction method based on a dual pointer architecture as claimed in claim 5, characterized in that: A scoring threshold is set, and the scores given by the double-layer multi-layer perceptron to each relationship entity vector are compared with the set scoring threshold. Entity pairs with lower scores are discarded, and only entity pairs with scores higher than the set scoring threshold are retained.
7. A threat intelligence triplet extraction method based on a dual pointer architecture as claimed in claim 1, characterized in that: The Softmax layer selects the optimal relationship in the filtered relationship entity vector according to the calculated output probability value, and finally generates a threat intelligence triple containing a head entity, a tail entity and a relationship.
8. A threat intelligence triplet extraction system based on a dual pointer architecture, characterized in that: include: The BERT model encoding module is configured to: obtain the text of threat intelligence; The obtained text is analyzed using the BERT model as an encoder, that is, three independent weight matrices are used to generate context-aware vectors for the head entity, tail entity, and relation respectively; The dual-pointer architecture module is configured to: identify the context-aware vectors of the head entity and the tail entity respectively based on the dual-pointer architecture, and generate a candidate entity pair; concatenate the candidate entity pair and the context-aware vector of the relationship to generate a relationship entity vector; The scoring module is configured to: filter the relation entity vectors using the scoring module; The relationship classification module is configured to: input the filtered relationship entity vector into the Softmax layer for relationship classification to generate the recognition result of the threat intelligence triplet.
9. A computer-readable storage medium having a program stored thereon, characterized in that: When the program is executed by a processor, the steps in a threat intelligence triple extraction method based on a dual-pointer architecture as described in any one of claims 1 to 7 are implemented.
10. An electronic device comprising a memory, a processor, and a program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, it implements the steps in the threat intelligence triple extraction method based on a dual-pointer architecture as described in any one of claims 1-7.
Citation Information
Patent Citations
Criminal case entity relation joint extraction method based on pointer network
CN114691895A
Multi-triple extraction method, device, equipment, medium and product
CN115168599A
Threat intelligence information processing method and device, electronic equipment and storage medium
CN116886420A
Method for jointly extracting entities and relationships from network security threat intelligence
CN117332785A
Threat intelligence data processing method and computer readable storage medium
CN117668244A