Threat intelligence detection method and device, equipment and storage medium

By using preset threat intelligence database and memory space in threat intelligence detection, combined with Hyperscan high-performance regular expressions, the problem of low threat intelligence detection in the existing technology is solved, and more efficient and accurate threat intelligence detection is achieved.

CN120050065APending Publication Date: 2025-05-27XIAN SECLOVER INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510042854.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-10
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

Existing threat intelligence detection methods are inefficient, require writing a large number of rules and frequently updated, making it difficult to detect and respond to complex cybersecurity threats in real time.

Method used

By presetting the threat intelligence database and memory space, using Hyperscan high-performance regular expressions to process and match multiple types of threat intelligence data, supporting multi-pattern matching, reducing matching time, and improving detection efficiency by constantly updating the database and memory space.

Benefits of technology

It improves the efficiency and accuracy of threat intelligence detection, reduces matching time, supports multi-pattern matching, facilitates maintenance and updates, and enhances the detection capabilities of complex threat intelligence data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050065A_ABST
    Figure CN120050065A_ABST
Patent Text Reader

Abstract

The invention discloses a threat intelligence detection method, device and equipment and a storage medium, according to the scheme, multiple types of current threat intelligence data are processed based on a Hyperscan high-performance regular expression to generate a preset threat intelligence database, multi-mode matching is supported, multiple regular expressions can be compiled at a time, and the threat intelligence detection efficiency is improved. The matching result can be obtained only through one-time matching during matching, the usability and the matching performance are greatly improved, the matching time is shortened, and then the efficiency of threat intelligence detection is improved; in addition, all types of current threat intelligence data are uniformly expressed and processed through a Hyperscan high-performance regular expression, and later maintenance and updating are facilitated; moreover, by continuously updating the threat intelligence database and the memory space, the accuracy of detecting new threat intelligence data can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to threat intelligence detection methods, devices, equipment and storage media. Background Art

[0002] In today's digital age, cybersecurity threats are becoming increasingly complex and frequent, and hacker attack methods are constantly evolving, from traditional viruses and Trojans to advanced persistent threats, zero-day vulnerability attacks, etc., and the diversity and complexity of threats are increasing. Traditional security protection measures are no longer able to cope with these advanced threats, and enterprises and organizations also need to be able to detect and respond to security incidents in real time to minimize potential losses. Threat intelligence detection can monitor and analyze network traffic, logs, and events in real time, and can quickly discover abnormal behaviors and potential threats, becoming an important part of the cybersecurity field.

[0003] Currently, when conducting threat intelligence detection, threat intelligence data is usually first converted into corresponding matching rules, and then matched in the rule matching engine, so as to determine whether there are abnormal behaviors and potential threats based on the matching results.

[0004] However, the above threat intelligence detection method requires writing a large number of rules and frequently updating them, which results in low efficiency of threat intelligence detection. Summary of the invention

[0005] The present application aims to at least solve the technical problems existing in the prior art. To this end, the first aspect of the present application proposes a threat intelligence detection method, which includes:

[0006] Obtain threat intelligence data to be detected;

[0007] The threat intelligence data to be detected is matched and processed through the preset threat intelligence database and the preset memory space. If the matching result is matched, the threat intelligence detection result is generated according to the matching result; wherein, the preset threat intelligence database is generated after processing various types of current threat intelligence data based on Hyperscan high-performance regular expressions;

[0008] Based on the threat intelligence data to be detected, the preset threat intelligence database and the preset memory space are updated to generate a new threat intelligence database and a new memory space;

[0009] Based on the new threat intelligence database and the new memory space, the new threat intelligence data to be detected is matched and processed, and the threat intelligence detection results are generated based on the matching results.

[0010] In a possible implementation, the method further includes:

[0011] Obtain various types of current threat intelligence data and target regular expressions corresponding to each current threat intelligence data;

[0012] For each type, save each target regular expression into a file corresponding to the type to obtain multiple current threat intelligence files;

[0013] Read each target regular expression in the current threat intelligence file, obtain a regular expression array, and generate a compilation flag array and an ID array corresponding to the regular expression array;

[0014] Compile each target regular expression in the regular expression array according to the Hyperscan standard to obtain the preset threat intelligence database.

[0015] In a possible implementation, the method further includes:

[0016] Obtaining preset threat intelligence rules corresponding to each current threat intelligence file; wherein the preset threat intelligence rules are used to specify the current threat intelligence file and target matching fields loaded into the preset data set;

[0017] The preset network threat detection engine rules are loaded one by one. If the preset network threat detection engine rule is a preset threat intelligence rule, the target regular expression corresponding to the preset threat intelligence rule is read from the current threat intelligence file to the preset data set.

[0018] In a possible implementation, the method further includes:

[0019] Get at least one current matching thread;

[0020] For at least one current matching thread, a preset memory space corresponding to the current matching thread is obtained.

[0021] In a possible implementation, the method further includes:

[0022] Pre-save the preset threat intelligence database and preset memory space into the preset data set;

[0023] The threat intelligence data to be detected is matched and processed through the preset threat intelligence database and preset memory space, including:

[0024] Obtain a preset threat intelligence database and preset memory space from a preset data set.

[0025] In a possible implementation manner, before matching the threat intelligence data to be detected through a preset threat intelligence database and a preset memory space, the method includes:

[0026] Get the current matching field corresponding to the threat intelligence data to be detected;

[0027] If the current matching field meets the conditions corresponding to the preset threat intelligence rules in the preset data set, the matching process is started.

[0028] In a possible implementation, updating a preset threat intelligence database and a preset memory space based on the threat intelligence data to be detected to generate a new threat intelligence database and a new memory space includes:

[0029] According to the type of the threat intelligence data to be detected, the current regular expression corresponding to the threat intelligence data to be detected is updated to the corresponding current threat intelligence file to obtain a new current threat intelligence file;

[0030] Clear the preset threat intelligence database and preset memory space through the preset extended command;

[0031] Process the new current threat intelligence file to generate a new threat intelligence database and new memory space.

[0032] The second aspect of the present application provides a threat intelligence detection device, which includes:

[0033] An acquisition module is used to obtain threat intelligence data to be detected;

[0034] The first generation module is used to match the threat intelligence data to be detected through a preset threat intelligence database and a preset memory space, and if the matching result is matched, a threat intelligence detection result is generated according to the matching result; wherein the preset threat intelligence database is generated after processing multiple types of current threat intelligence data based on Hyperscan high-performance regular expressions;

[0035] An update module is used to update a preset threat intelligence database and a preset memory space based on the threat intelligence data to be detected, and generate a new threat intelligence database and a new memory space;

[0036] The second generating module is used to match the new threat intelligence data to be detected based on the new threat intelligence database and the new memory space, and generate the threat intelligence detection result based on the matching result.

[0037] In a possible implementation manner, the above-mentioned threat intelligence detection device is further used for:

[0038] Obtain various types of current threat intelligence data and target regular expressions corresponding to each current threat intelligence data;

[0039] For each type, save each target regular expression into a file corresponding to the type to obtain multiple current threat intelligence files;

[0040] Read each target regular expression in the current threat intelligence file, obtain a regular expression array, and generate a compilation flag array and an ID array corresponding to the regular expression array;

[0041] Compile each target regular expression in the regular expression array according to the Hyperscan standard to obtain the preset threat intelligence database.

[0042] In a possible implementation manner, the above-mentioned threat intelligence detection device is further used for:

[0043] Obtaining preset threat intelligence rules corresponding to each current threat intelligence file; wherein the preset threat intelligence rules are used to specify the current threat intelligence file and target matching fields loaded into the preset data set;

[0044] The preset network threat detection engine rules are loaded one by one. If the preset network threat detection engine rule is a preset threat intelligence rule, the target regular expression corresponding to the preset threat intelligence rule is read from the current threat intelligence file to the preset data set.

[0045] In a possible implementation manner, the above-mentioned threat intelligence detection device is further used for:

[0046] Get at least one current matching thread;

[0047] For at least one current matching thread, a preset memory space corresponding to the current matching thread is obtained.

[0048] In a possible implementation manner, the above-mentioned threat intelligence detection device is further used for:

[0049] Pre-save the preset threat intelligence database and preset memory space into the preset data set;

[0050] The threat intelligence data to be detected is matched and processed through the preset threat intelligence database and preset memory space, including:

[0051] Obtain a preset threat intelligence database and preset memory space from a preset data set.

[0052] In a possible implementation manner, the above-mentioned threat intelligence detection device is further used for:

[0053] Get the current matching field corresponding to the threat intelligence data to be detected;

[0054] If the current matching field meets the conditions corresponding to the preset threat intelligence rules in the preset data set, the matching process is started.

[0055] In a possible implementation manner, the update module is specifically used to:

[0056] According to the type of the threat intelligence data to be detected, the current regular expression corresponding to the threat intelligence data to be detected is updated to the corresponding current threat intelligence file to obtain a new current threat intelligence file;

[0057] Clear the preset threat intelligence database and preset memory space through the preset extended command;

[0058] Process the new current threat intelligence file to generate a new threat intelligence database and new memory space.

[0059] The third aspect of the present application proposes an electronic device, which includes a processor and a memory, wherein the memory stores at least one instruction, at least one program, a code set or an instruction set, and the at least one instruction, the at least one program, the code set or the instruction set is loaded and executed by the processor to implement the threat intelligence detection method as described in the first aspect.

[0060] In a fourth aspect, the present application proposes a computer-readable storage medium, in which at least one instruction, at least one program, a code set or an instruction set is stored. The at least one instruction, the at least one program, the code set or the instruction set is loaded and executed by a processor to implement the threat intelligence detection method as described in the first aspect.

[0061] The embodiments of the present application have the following beneficial effects:

[0062] The threat intelligence detection method provided by the embodiment of the present application includes: obtaining threat intelligence data to be detected, matching and processing the threat intelligence data to be detected through a preset threat intelligence database and a preset memory space, if the matching result is matched, generating a threat intelligence detection result according to the matching result, updating the preset threat intelligence database and the preset memory space based on the threat intelligence data to be detected, generating a new threat intelligence database and a new memory space, matching and processing the new threat intelligence data to be detected based on the new threat intelligence database and the new memory space, and generating a threat intelligence detection result based on the matching result. This scheme generates a preset threat intelligence database after processing multiple types of current threat intelligence data based on Hyperscan high-performance regular expressions, supports multi-mode matching, can compile multiple regular expressions at one time, and only needs one match to obtain the matching result during matching, which greatly improves the ease of use and matching performance, reduces the matching time, and thus improves the efficiency of threat intelligence detection; in addition, by uniformly representing and processing all types of current threat intelligence data through Hyperscan high-performance regular expressions, it is convenient for later maintenance and updating; and by continuously updating the threat intelligence database and memory space, the accuracy of detecting new threat intelligence data can be improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0063] Figure 1 A block diagram of a computer device provided in an embodiment of the present application;

[0064] Figure 2 A flowchart of a threat intelligence detection method provided in an embodiment of the present application;

[0065] Figure 3 A flowchart of the steps for generating a preset threat intelligence database provided in an embodiment of the present application;

[0066] Figure 4 A flowchart of the steps for obtaining a preset memory space provided in an embodiment of the present application;

[0067] Figure 5 A flowchart of the steps for generating a new threat intelligence database and a new memory space provided in an embodiment of the present application;

[0068] Figure 6 A structural block diagram of a threat intelligence detection device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0069] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0070] At present, when conducting threat intelligence detection, it is usually necessary to first convert the threat intelligence data into corresponding matching rules, and then match them in the rule matching engine, so as to determine whether there are abnormal behaviors and potential threats based on the matching results. The existing Suricata is an open source network threat detection engine that can monitor network traffic in real time and detect various types of attacks and malicious activities, and has a very good detection effect on known attack patterns. Suircata supports two methods for detecting threat intelligence: one is to detect threat intelligence and attack behaviors based on signatures (i.e. rules); the other is to load threat intelligence data based on the Dataset mechanism to uniformly process the matching of threat intelligence. Dataset can be regarded as a memory structure for storing threat intelligence data sets and their necessary parameters. Dataset is an independent data set that does not rely on the database. Among them, the threat intelligence detection method based on signatures needs to convert threat intelligence data into corresponding matching rules, and then match them in the rule matching engine; the threat intelligence detection method based on Dataset needs to load threat intelligence into memory by type and construct a hash table for matching. Although both methods can support the detection of multiple threat intelligence and enhance protection capabilities, they also have the following shortcomings:

[0071] 1. Since the amount of threat intelligence data is generally large, if a signature-based detection method is used, a large number of rules need to be written, which dramatically increases the number of rules, resulting in a long time to load the rules each time.

[0072] 2. Threat intelligence data is updated very frequently. If a signature-based detection method is used, the rules need to be frequently reloaded after each update to take effect. Frequent reloading of rules will affect the consistency of detection.

[0073] 3. Using Dataset to load threat intelligence data has high performance and is convenient for frequent updates. However, the current Dataset only supports threat intelligence of IP, string, MD5, and SHA256 types. These types can only be matched accurately, that is, it can support threat intelligence data that requires accurate matching, such as malicious IP intelligence, JA3, JA4, and emails, but cannot support matching of substrings, regular expressions, etc. Therefore, it cannot well support scenarios such as malicious domain names, malicious URLs, malicious CAs, etc. that require matching partial strings.

[0074] 4. After using Dataset to load threat intelligence, Suricata also supports using pcrexform to apply regular expressions to the target before the Dataset is accurately matched, but this regular expression is unified and there is no way to apply different regular expressions to each threat intelligence data.

[0075] 5. Dataset data loading is performed in the process of rule loading, so the Dataset cannot be updated alone. To update the Dataset, the rule reloading process must be executed. Even if the rules remain unchanged, all rules must be loaded again.

[0076] Based on this, the present application provides a threat intelligence detection method, which includes: obtaining threat intelligence data to be detected, matching and processing the threat intelligence data to be detected through a preset threat intelligence database and a preset memory space, if the matching result is matched, generating a threat intelligence detection result according to the matching result, updating the preset threat intelligence database and the preset memory space based on the threat intelligence data to be detected, generating a new threat intelligence database and a new memory space, matching and processing the new threat intelligence data to be detected based on the new threat intelligence database and the new memory space, and generating a threat intelligence detection result based on the matching result. This solution generates a preset threat intelligence database after processing multiple types of current threat intelligence data based on Hyperscan high-performance regular expressions, supports multi-mode matching, can compile multiple regular expressions at one time, and only needs one match to obtain the matching result during matching, which greatly improves the ease of use and matching performance, reduces the matching time, and thus improves the efficiency of threat intelligence detection; in addition, by uniformly representing and processing all types of current threat intelligence data through Hyperscan high-performance regular expressions, it is convenient for later maintenance and updating; and by continuously updating the threat intelligence database and memory space, the accuracy of detecting new threat intelligence data can be improved.

[0077] In the following, the terms "first" and "second" are used for descriptive purposes only and are not to be understood as indicating or implying relative importance or implicitly indicating the number of technical features indicated. Thus, features defined as "first" and "second" may explicitly or implicitly include one or more of the features. In the description of the embodiments of the present disclosure, unless otherwise specified, "multiple" means two or more. In addition, the use of "based on" or "according to" means openness and inclusiveness, because the process, steps, calculations or other actions "based on" or "according to" one or more of the conditions or values ​​may be based on additional conditions or values ​​beyond the described values ​​in practice.

[0078] The threat intelligence detection method provided in the present application can be applied to a computer device (electronic device), which can be a server or a terminal, wherein the server can be a single server or a server cluster composed of multiple servers. The embodiments of the present application do not specifically limit this. The terminal can be, but is not limited to, various personal computers, laptops, smart phones, tablet computers, and portable wearable devices.

[0079] Take the computer device as a server as an example. Figure 1 A block diagram of a server is shown, such as Figure 1 As shown, the server may include a processor and a memory connected via a system bus. The processor of the server is used to provide computing and control capabilities. The memory of the server includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. When the computer program is executed by the processor, a threat intelligence detection method is implemented.

[0080] Those skilled in the art will understand that Figure 1 The structure shown in the figure is only a block diagram of a partial structure related to the solution of the present application, and does not constitute a limitation on the server to which the solution of the present application is applied. Optionally, the server may include more or fewer components than shown in the figure, or combine certain components, or have a different arrangement of components.

[0081] It should be noted that the execution subject of the embodiments of the present application may be a computer device or a threat intelligence detection device. The following method embodiments are described using a computer device as the execution subject.

[0082] Figure 2 A flowchart of a threat intelligence detection method provided in an embodiment of the present application. Figure 2 As shown, the method comprises the following steps:

[0083] Step 202: Obtain threat intelligence data to be detected.

[0084] Among them, the threat intelligence data to be detected may include but is not limited to malicious IP intelligence, malicious domain name intelligence, malicious Uniform Resource Locator (URL) intelligence, malicious certification authority (CA) intelligence, malicious email intelligence and other types.

[0085] In addition, when obtaining threat intelligence data to be detected, for example, it can be obtained through data released by security researchers, hacker groups or security organizations, or through alarm information and evaluation reports of security equipment and systems within the organization, or through commercial threat intelligence providers. This application does not specifically limit the method of obtaining threat intelligence data to be detected.

[0086] Step 204: match the threat intelligence data to be detected using a preset threat intelligence database and a preset memory space. If the matching result is a match, a threat intelligence detection result is generated according to the matching result.

[0087] Among them, the preset threat intelligence database is generated after processing various types of current threat intelligence data based on Hyperscan high-performance regular expressions. It should be noted that the various types of current threat intelligence data here are the latest threat intelligence data sets. Hyperscan is an open source library specially designed for high-performance regular expression matching, aiming to provide a fast and efficient regular expression matching solution for massive data. Hyperscan fully utilizes the advantages of multi-core processors and parallel computing, and adopts a variety of optimization technologies, including pipeline matching, fast pattern matching and other technologies to achieve high-performance regular expression matching. In addition, Hyperscan supports multi-mode matching and can match multiple regular expressions at the same time without the need to perform independent matching operations on each expression, thereby improving matching performance. In general, Hyperscan is a powerful and high-performance regular expression matching library, which is particularly suitable for scenarios where regular expression matching of large amounts of data is required.

[0088] In some optional embodiments, Figure 3 As shown, Figure 3 A flowchart of the steps for generating a preset threat intelligence database provided in an embodiment of the present application includes:

[0089] Step 302: Obtain multiple types of current threat intelligence data and target regular expressions corresponding to each type of current threat intelligence data.

[0090] Step 304: For each type, each target regular expression is saved into a file corresponding to the type to obtain multiple current threat intelligence files.

[0091] Step 306: read each target regular expression in the current threat intelligence file, obtain a regular expression array, and generate a compilation flag array and an ID array corresponding to the regular expression array.

[0092] Step 308: Compile each target regular expression in the regular expression array according to the Hyperscan standard to obtain a preset threat intelligence database.

[0093] Among them, for each type of current threat intelligence data, the corresponding target regular expression can be saved in a file corresponding to the type, and multiple current threat intelligence files can be obtained. For example, for the current malicious domain name threat intelligence data, the corresponding regular expression can be saved in the file domain.list; for the current malicious URL threat intelligence data, the corresponding regular expression can be saved in the file url.list; for the current malicious CA threat intelligence data, the corresponding regular expression can be saved in the file ca.list; for the current malicious email threat intelligence data, the corresponding regular expression can be saved in the file mail.list.

[0094] In addition, preset threat intelligence rules can also be written in advance. The preset threat intelligence rules are used to specify the current threat intelligence file and target matching field loaded into the preset data set, and the type of the preset data set can be set to the regex type, that is, the regular expression type. For example, for the current malicious domain name threat intelligence data, the preset threat intelligence rule is written as: alert dns any any->any any(msg:"Malicious domain detected";dns.query;Dataset:isset,domain_iocs,type regex,load domain.list,memcap 10mb,hashsize 1024;classtype:trojan-activity;sid:12;rev:1;). Among them, the current threat intelligence file contained in the preset threat intelligence rule is domain.list, and the target matching field contained is dns.query.

[0095] After obtaining the preset threat intelligence rules corresponding to each current threat intelligence file, Suricata is started to load the preset network threat detection engine rules one by one. If the preset network threat detection engine rules are preset threat intelligence rules, the target regular expression corresponding to the preset threat intelligence rules is read from the current threat intelligence file to the preset data set Dataset. Among them, different initialization loading processes need to be taken according to the different types of current threat intelligence data. If it is a regex type, it enters the loading process in the preset data set Dataset extended by this application.

[0096] In addition, the target regular expression is saved in the current threat intelligence file line by line, so that after reading all the lines in the current threat intelligence file, a regular expression array can be obtained, which can be recorded as pats[]. In addition, a compilation flag array and an ID array corresponding to the regular expression array can also be generated. Among them, the compilation flag array can be recorded as flags[], and the ID array can be recorded as ids[].

[0097] Finally, we can use the compilation interface of Hyperscan to compile each target regular expression in the regular expression array according to the standard of Hyperscan. After successful compilation, it returns to the preset data set Dataset corresponding to the current threat intelligence data of this type, thereby obtaining the preset threat intelligence database.

[0098] In some optional embodiments, Figure 4 As shown, Figure 4 A flowchart of the steps of obtaining a preset memory space provided in an embodiment of the present application includes:

[0099] Step 402: Obtain at least one current matching thread.

[0100] Step 404: For at least one current matching thread, obtain a preset memory space corresponding to the current matching thread.

[0101] Among them, the memory space required for matching can be prepared for the current matching thread first. If it is a multi-threaded environment, a memory space needs to be applied for each thread. That is, at least one current matching thread needs to be obtained first, and then the corresponding preset memory space is allocated to the obtained current matching thread. The preset memory space can be recorded as scratch.

[0102] Then, the preset threat intelligence database and preset memory space can be saved in the preset data set for use in the subsequent matching process. In addition, the memory that is no longer used can be cleaned up, that is, the memory is cleaned up after the initialization of the current threat intelligence data of the current type is completed, and then other rules and subsequent processes are initialized.

[0103] After Suricata receives the threat intelligence data to be detected, it passes through the decoding module and the application protocol parsing module in sequence, and then enters the detection module for matching processing. In some optional embodiments, before matching the threat intelligence data to be detected through the preset threat intelligence database and the preset memory space, the current matching field corresponding to the threat intelligence data to be detected can also be obtained first. If the current matching field meets the conditions corresponding to the preset threat intelligence rules in the preset data set, the matching process is started.

[0104] Among them, the current matching field can be http.uri, dns.query and other fields. When the current matching field successfully matches the target matching field defined in the pre-written preset threat intelligence rule, that is, it is determined that the previous matching field meets the conditions corresponding to the preset threat intelligence rule in the preset data set, the matching process can be started to match the threat intelligence data to be detected.

[0105] When matching, the preset threat intelligence database and preset memory space can be obtained from the preset data set, and then the threat intelligence data to be detected can be matched and processed by the preset threat intelligence database and preset memory space. Specifically, the Hyperscan matching interface can be called to determine whether the current matching field corresponding to the threat intelligence data to be detected can match the preset threat intelligence database.

[0106] Optionally, for any of the substring matching, beginning matching, and end matching scenarios, among which malicious URL intelligence may require substring matching and beginning matching, and malicious domain name intelligence and malicious CA intelligence may require end matching, regular expressions can be conveniently used to represent the threat intelligence data to be detected. Specifically, end matching only requires adding a $ symbol at the end of the regular expression, and beginning matching only requires adding a ^ symbol at the beginning of the regular expression.

[0107] If the match result is matched, a threat intelligence detection result is generated based on the match result. If the current matching field can be found in the preset threat intelligence database, it is considered to be matched, thereby obtaining a threat intelligence detection result, which is used to determine the existence of network threats. In addition, a threat alarm log can also be generated to report malicious attack behaviors to users or administrators for further processing by users or administrators.

[0108] Step 206: Update the preset threat intelligence database and the preset memory space based on the threat intelligence data to be detected to generate a new threat intelligence database and a new memory space.

[0109] If the matching result is no match, the preset threat intelligence database and the preset memory space need to be updated to generate a new threat intelligence database and a new memory space. Figure 5 As shown, Figure 5 A flowchart of the steps of generating a new threat intelligence database and a new memory space provided in an embodiment of the present application includes:

[0110] Step 502: According to the type of threat intelligence data to be detected, the current regular expression corresponding to the threat intelligence data to be detected is updated to the corresponding current threat intelligence file to obtain a new current threat intelligence file.

[0111] Step 504: Clear the preset threat intelligence database and preset memory space through a preset extension command.

[0112] Step 506: Process the new current threat intelligence file to generate a new threat intelligence database and new memory space.

[0113] Among them, the current regular expression corresponding to the threat intelligence data to be detected can be updated to the corresponding current threat intelligence file, thereby obtaining a new current threat intelligence file. Then use the preset extended command to clear the preset threat intelligence database and preset memory space. Specifically, the extended Unix Socket command can be used to execute the reload-iocs command to reload the specified type of threat intelligence data separately. For example, if the threat intelligence data to be detected is malicious domain name intelligence data, the malicious domain name intelligence data can be reloaded separately to improve loading efficiency.

[0114] After the Suricata main program receives the reload-iocs command, it can clear the preset threat intelligence database and preset memory space while ensuring the safety of the matching thread, and then re-read and load the specified type of threat intelligence data from the new current threat intelligence file, thereby generating a new threat intelligence database and new memory space. The specific implementation process can refer to the above embodiments, which will not be repeated here.

[0115] After generating a new threat intelligence database and a new memory space, the new threat intelligence database and the new memory space may be saved again in a preset data set for subsequent matching.

[0116] Step 208: Perform matching processing on the new threat intelligence data to be detected based on the new threat intelligence database and the new memory space, and generate a threat intelligence detection result based on the matching result.

[0117] After acquiring new threat intelligence data to be detected, the new threat intelligence data to be detected can be matched based on the new threat intelligence database and the new memory space, and a threat intelligence detection result is generated based on the matching result. The specific matching process can refer to the above embodiments, which will not be repeated here.

[0118] The present application provides a threat intelligence detection method, which includes: obtaining threat intelligence data to be detected, matching and processing the threat intelligence data to be detected through a preset threat intelligence database and a preset memory space, if the matching result is matched, generating a threat intelligence detection result according to the matching result, updating the preset threat intelligence database and the preset memory space based on the threat intelligence data to be detected, generating a new threat intelligence database and a new memory space, matching and processing the new threat intelligence data to be detected based on the new threat intelligence database and the new memory space, and generating a threat intelligence detection result based on the matching result. This solution generates a preset threat intelligence database by processing multiple types of current threat intelligence data based on Hyperscan high-performance regular expressions, supports multi-mode matching, and can compile multiple regular expressions at one time. Only one match is needed to obtain the matching result during matching, which greatly improves the ease of use and matching performance, reduces the matching time, and thus improves the efficiency of threat intelligence detection; in addition, by uniformly representing and processing all types of current threat intelligence data through Hyperscan high-performance regular expressions, it is convenient for later maintenance and updating; and by continuously updating the threat intelligence database and memory space, the accuracy of detecting new threat intelligence data can be improved.

[0119] It should be understood that, although the various steps in the flowcharts involved in the above-mentioned embodiments are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence according to the order indicated by the arrows. Unless there is a clear explanation in this article, the execution of these steps does not have a strict order restriction, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-mentioned embodiments can include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a part of the steps or stages in other steps.

[0120] Figure 6 A structural block diagram of a threat intelligence detection device provided in an embodiment of the present application.

[0121] like Figure 6 As shown, the threat intelligence detection device 600 includes:

[0122] The acquisition module 602 is used to acquire threat intelligence data to be detected.

[0123] The first generating module 604 is used to match and process the threat intelligence data to be detected through a preset threat intelligence database and a preset memory space. If the matching result is matched, a threat intelligence detection result is generated according to the matching result; wherein, the preset threat intelligence database is generated after processing various types of current threat intelligence data based on Hyperscan high-performance regular expressions.

[0124] The updating module 606 is used to update the preset threat intelligence database and the preset memory space based on the threat intelligence data to be detected, and generate a new threat intelligence database and a new memory space.

[0125] The second generating module 608 is used to perform matching processing on the new threat intelligence data to be detected based on the new threat intelligence database and the new memory space, and generate a threat intelligence detection result based on the matching result.

[0126] Regarding the device in the above embodiment, the specific manner in which each module performs operations has been described in detail in the embodiment of the method, and will not be elaborated here. Each module in the above threat intelligence detection device can be implemented in whole or in part by software, hardware, and a combination thereof. The above modules can be embedded in or independent of the processor in the computer device in the form of hardware, or can be stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations of the above modules.

[0127] In one embodiment of the present application, a computer device is provided, the computer device comprising a memory and a processor, the memory storing a computer program, and the processor implementing the following steps when executing the computer program:

[0128] Obtain threat intelligence data to be detected;

[0129] The threat intelligence data to be detected is matched and processed through the preset threat intelligence database and the preset memory space. If the matching result is matched, the threat intelligence detection result is generated according to the matching result; wherein, the preset threat intelligence database is generated after processing various types of current threat intelligence data based on Hyperscan high-performance regular expressions;

[0130] Based on the threat intelligence data to be detected, the preset threat intelligence database and the preset memory space are updated to generate a new threat intelligence database and a new memory space;

[0131] Based on the new threat intelligence database and the new memory space, the new threat intelligence data to be detected is matched and processed, and the threat intelligence detection results are generated based on the matching results.

[0132] In one embodiment of the present application, when the processor executes the computer program, the processor further implements the following steps:

[0133] Obtain various types of current threat intelligence data and target regular expressions corresponding to each current threat intelligence data;

[0134] For each type, save each target regular expression into a file corresponding to the type to obtain multiple current threat intelligence files;

[0135] Read each target regular expression in the current threat intelligence file, obtain a regular expression array, and generate a compilation flag array and an ID array corresponding to the regular expression array;

[0136] Compile each target regular expression in the regular expression array according to the Hyperscan standard to obtain the preset threat intelligence database.

[0137] In one embodiment of the present application, when the processor executes the computer program, the processor further implements the following steps:

[0138] Obtaining preset threat intelligence rules corresponding to each current threat intelligence file; wherein the preset threat intelligence rules are used to specify the current threat intelligence file and target matching fields loaded into the preset data set;

[0139] The preset network threat detection engine rules are loaded one by one. If the preset network threat detection engine rule is a preset threat intelligence rule, the target regular expression corresponding to the preset threat intelligence rule is read from the current threat intelligence file to the preset data set.

[0140] In one embodiment of the present application, when the processor executes the computer program, the processor further implements the following steps:

[0141] Get at least one current matching thread;

[0142] For at least one current matching thread, a preset memory space corresponding to the current matching thread is obtained.

[0143] In one embodiment of the present application, when the processor executes the computer program, the processor further implements the following steps:

[0144] Pre-save the preset threat intelligence database and preset memory space into the preset data set;

[0145] The threat intelligence data to be detected is matched and processed through the preset threat intelligence database and preset memory space, including:

[0146] Obtain a preset threat intelligence database and preset memory space from a preset data set.

[0147] In one embodiment of the present application, when the processor executes the computer program, the processor further implements the following steps:

[0148] Get the current matching field corresponding to the threat intelligence data to be detected;

[0149] If the current matching field meets the conditions corresponding to the preset threat intelligence rules in the preset data set, the matching process is started.

[0150] In one embodiment of the present application, when the processor executes the computer program, the processor further implements the following steps:

[0151] According to the type of the threat intelligence data to be detected, the current regular expression corresponding to the threat intelligence data to be detected is updated to the corresponding current threat intelligence file to obtain a new current threat intelligence file;

[0152] Clear the preset threat intelligence database and preset memory space through the preset extended command;

[0153] Process the new current threat intelligence file to generate a new threat intelligence database and new memory space.

[0154] The computer device provided in the embodiment of the present application has similar implementation principles and technical effects to those of the above-mentioned method embodiment, and will not be described in detail here.

[0155] In one embodiment of the present application, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0156] Obtain threat intelligence data to be detected;

[0157] The threat intelligence data to be detected is matched and processed through the preset threat intelligence database and the preset memory space. If the matching result is matched, the threat intelligence detection result is generated according to the matching result; wherein, the preset threat intelligence database is generated after processing various types of current threat intelligence data based on Hyperscan high-performance regular expressions;

[0158] Based on the threat intelligence data to be detected, the preset threat intelligence database and the preset memory space are updated to generate a new threat intelligence database and a new memory space;

[0159] Based on the new threat intelligence database and the new memory space, the new threat intelligence data to be detected is matched and processed, and the threat intelligence detection results are generated based on the matching results.

[0160] In one embodiment of the present application, when the computer program is executed by a processor, the following steps are further implemented:

[0161] Obtain various types of current threat intelligence data and target regular expressions corresponding to each current threat intelligence data;

[0162] For each type, save each target regular expression into a file corresponding to the type to obtain multiple current threat intelligence files;

[0163] Read each target regular expression in the current threat intelligence file, obtain a regular expression array, and generate a compilation flag array and an ID array corresponding to the regular expression array;

[0164] Compile each target regular expression in the regular expression array according to the Hyperscan standard to obtain the preset threat intelligence database.

[0165] In one embodiment of the present application, when the computer program is executed by a processor, the following steps are further implemented:

[0166] Obtaining preset threat intelligence rules corresponding to each current threat intelligence file; wherein the preset threat intelligence rules are used to specify the current threat intelligence file and target matching fields loaded into the preset data set;

[0167] The preset network threat detection engine rules are loaded one by one. If the preset network threat detection engine rule is a preset threat intelligence rule, the target regular expression corresponding to the preset threat intelligence rule is read from the current threat intelligence file to the preset data set.

[0168] In one embodiment of the present application, when the computer program is executed by a processor, the following steps are further implemented:

[0169] Get at least one current matching thread;

[0170] For at least one current matching thread, a preset memory space corresponding to the current matching thread is obtained.

[0171] In one embodiment of the present application, when the computer program is executed by a processor, the following steps are further implemented:

[0172] Pre-save the preset threat intelligence database and preset memory space into the preset data set;

[0173] The threat intelligence data to be detected is matched and processed through the preset threat intelligence database and preset memory space, including:

[0174] Obtain a preset threat intelligence database and preset memory space from a preset data set.

[0175] In one embodiment of the present application, when the computer program is executed by a processor, the following steps are further implemented:

[0176] Get the current matching field corresponding to the threat intelligence data to be detected;

[0177] If the current matching field meets the conditions corresponding to the preset threat intelligence rules in the preset data set, the matching process is started.

[0178] In one embodiment of the present application, when the computer program is executed by a processor, the following steps are further implemented:

[0179] According to the type of the threat intelligence data to be detected, the current regular expression corresponding to the threat intelligence data to be detected is updated to the corresponding current threat intelligence file to obtain a new current threat intelligence file;

[0180] Clear the preset threat intelligence database and preset memory space through the preset extended command;

[0181] Process the new current threat intelligence file to generate a new threat intelligence database and new memory space.

[0182] The computer-readable storage medium provided in this embodiment has similar implementation principles and technical effects to those of the above method embodiments, and will not be described in detail here.

[0183] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. As an illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).

[0184] Those skilled in the art will readily appreciate other embodiments of the present disclosure after considering the specification and practicing the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include common knowledge or customary techniques in the art that are not disclosed in the present disclosure. The specification and examples are intended to be exemplary only, and the true scope and spirit of the present disclosure are indicated by the following claims.

[0185] It should be understood that the present disclosure is not limited to the exact structures that have been described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present disclosure is limited only by the appended claims.

Claims

1. A threat intelligence detection method, characterized in that: The method comprises: Obtain threat intelligence data to be detected; The threat intelligence data to be detected is matched and processed through a preset threat intelligence database and a preset memory space. If the matching result is matched, a threat intelligence detection result is generated according to the matching result; wherein the preset threat intelligence database is generated after processing various types of current threat intelligence data based on Hyperscan high-performance regular expressions; Based on the threat intelligence data to be detected, the preset threat intelligence database and the preset memory space are updated to generate a new threat intelligence database and a new memory space; Based on the new threat intelligence database and the new memory space, matching processing is performed on the new threat intelligence data to be detected, and a threat intelligence detection result is generated based on the matching result.

2. The method according to claim 1, characterized in that: The method further comprises: Obtain multiple types of current threat intelligence data and target regular expressions corresponding to each of the current threat intelligence data; For each type, each target regular expression is saved into a file corresponding to the type to obtain multiple current threat intelligence files; Read each of the target regular expressions in the current threat intelligence file to obtain a regular expression array, and generate a compilation flag array and an ID array corresponding to the regular expression array; Each of the target regular expressions in the regular expression array is compiled according to the standard of Hyperscan to obtain the preset threat intelligence database.

3. The method according to claim 2, characterized in that The method further comprises: Obtaining preset threat intelligence rules corresponding to each of the current threat intelligence files; wherein the preset threat intelligence rules are used to specify the current threat intelligence files and target matching fields loaded into the preset data set; The preset network threat detection engine rules are loaded one by one. If the preset network threat detection engine rule is the preset threat intelligence rule, the target regular expression corresponding to the preset threat intelligence rule is read from the current threat intelligence file to the preset data set.

4. The method according to any one of claims 1 to 3, characterized in that: The method further comprises: Get at least one current matching thread; For the at least one current matching thread, a preset memory space corresponding to the current matching thread is obtained.

5. The method according to claim 3, characterized in that: The method further comprises: Pre-save the preset threat intelligence database and the preset memory space into the preset data set; The matching process of the threat intelligence data to be detected by using a preset threat intelligence database and a preset memory space includes: The preset threat intelligence database and the preset memory space are obtained from the preset data set.

6. The method according to claim 3, characterized in that Before matching the threat intelligence data to be detected through a preset threat intelligence database and a preset memory space, the method includes: Obtaining a current matching field corresponding to the threat intelligence data to be detected; If the current matching field meets the condition corresponding to the preset threat intelligence rule in the preset data set, the matching process is started.

7. The method according to claim 3, characterized in that The updating of the preset threat intelligence database and the preset memory space based on the threat intelligence data to be detected to generate a new threat intelligence database and a new memory space includes: According to the type of the threat intelligence data to be detected, the current regular expression corresponding to the threat intelligence data to be detected is updated to the corresponding current threat intelligence file to obtain a new current threat intelligence file; Clearing the preset threat intelligence database and the preset memory space through a preset extended command; The new current threat intelligence file is processed to generate a new threat intelligence database and a new memory space.

8. A threat intelligence detection device, characterized in that: The device comprises: An acquisition module is used to obtain threat intelligence data to be detected; The first generation module is used to match the threat intelligence data to be detected through a preset threat intelligence database and a preset memory space, and if the matching result is matched, a threat intelligence detection result is generated according to the matching result; wherein the preset threat intelligence database is generated after processing multiple types of current threat intelligence data based on Hyperscan high-performance regular expressions; An updating module, used to update the preset threat intelligence database and the preset memory space based on the threat intelligence data to be detected, and generate a new threat intelligence database and a new memory space; The second generating module is used to perform matching processing on the new threat intelligence data to be detected based on the new threat intelligence database and the new memory space, and generate a threat intelligence detection result based on the matching result.

9. An electronic device, characterized in that: The electronic device includes a processor and a memory, wherein the memory stores at least one instruction, at least one program, a code set or an instruction set, and the at least one instruction, the at least one program, the code set or the instruction set is loaded and executed by the processor to implement the threat intelligence detection method as described in any one of claims 1-7.

10. A computer-readable storage medium, characterized in that: The storage medium stores at least one instruction, at least one program, a code set or an instruction set, and the at least one instruction, the at least one program, the code set or the instruction set is loaded and executed by the processor to implement the threat intelligence detection method as described in any one of claims 1-7.