Data processing method and device, storage medium and computer device
By introducing a data confidence evaluation mechanism between objects into the threat intelligence sharing system, the problem of low object activity in threat intelligence data sharing is solved, the credibility assessment and reputation value update of intelligence data are realized, and the activity and data quality of the system are improved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-21
- Publication Date
- 2026-03-10
AI Technical Summary
In existing technologies, the contribution of producers and verifiers cannot be quantified during the threat intelligence data sharing process, resulting in low target activity, infrequent threat intelligence data updates, and difficulty in determining credibility.
By having objects evaluate each other's confidence in intelligence data during the reputation value update cycle, calculating the object's reputation change value based on the confidence evaluation score and historical reputation value, and determining the current reputation value by combining contribution and evaluation quantity, objects are encouraged to actively participate.
It improved the accuracy of intelligence data assessment, enhanced the reputation and activity of targets, and ensured the credibility and update frequency of intelligence data.
Smart Images

Figure CN120105038B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of artificial intelligence technology, and in particular to a data processing method, apparatus, storage medium and computer equipment. Background Technology
[0002] Threat intelligence data comprises information about cybersecurity threats and is a crucial data asset for assisting in attack detection and assessment. Threat intelligence describes existing or impending threats or dangers against assets and can be used to notify entities to take appropriate responses. Threat intelligence helps organizations and institutions discover and assess threats, enabling them to make informed decisions and implement defenses. Exchanging and sharing threat intelligence can reduce intelligence gathering costs, alleviate information silos, maximize the value of threat intelligence, and ultimately improve the threat detection and incident response capabilities of all participating parties.
[0003] In related technologies, threat intelligence data sharing schemes typically based on blockchain involve various roles such as threat intelligence centers, intelligence producers, consumers, and validators. Although the production and consumption of intelligence occur on a "trusted" blockchain, certain mechanisms are needed to ensure the reliability of the on-chain process, thereby ensuring the trustworthiness of the operations of all parties and the security of data transmission. However, during the data sharing process, the contributions of producers and validators cannot be quantified. This leads to situations where participants only expect to obtain threat intelligence data, rarely contributing to or evaluating it. Low participant activity results in infrequent updates to threat intelligence data, and the limited number of evaluations makes it difficult to determine the trustworthiness of the threat intelligence data. Therefore, there is an urgent need to propose a data processing method to address these technical problems. Summary of the Invention
[0004] The main objective of this application is to provide a data processing method, apparatus, storage medium, and computer equipment that can verify intelligence data by having contributing objects evaluate each other's intelligence data, improve the accuracy of intelligence data evaluation, update the reputation values of contributing and evaluating objects, and increase object activity.
[0005] In a first aspect, embodiments of this application provide a data processing method, including:
[0006] When a first object is detected to contribute intelligence data in the current reputation value update cycle, the intelligence data is sent to each second object so that each second object can evaluate the confidence level of the intelligence data. The second objects are other objects in the shared object set besides the first object.
[0007] When it is detected that a specified number of target objects in the second object are evaluating the data confidence of the intelligence data, the data confidence score of each target object, the evaluation confidence of the data confidence score, and the historical reputation value of each target object in the previous reputation value update cycle are obtained.
[0008] Based on the confidence score, confidence level, and corresponding historical reputation value of each target object, determine the reputation change value of each target object;
[0009] Record the contribution reputation change value of the first object in contributing the intelligence data, and the evaluation reputation change value of each target object;
[0010] When the current reputation value update period is detected to be over, the periodic active reputation change value of each object is determined based on the number of contributions and evaluations of each object in the shared object set during the current reputation value update period.
[0011] The historical reputation value, contribution reputation change value, evaluation reputation change value, and corresponding periodic active reputation change value of each object in the previous reputation value update cycle are summed to obtain the current reputation value of each object in the current reputation value update cycle.
[0012] Secondly, embodiments of this application provide a data processing apparatus, including:
[0013] The sending unit is configured to send the intelligence data to each second object when it is detected that the first object has contributed intelligence data in the current reputation value update cycle, so that each second object can evaluate the confidence of the intelligence data. The second object is other objects in the shared object set besides the first object.
[0014] The acquisition unit is used to acquire, when it is detected that a specified number of target objects in the second object are evaluating the data confidence of the intelligence data, the data confidence score of each target object, the evaluation confidence of the data confidence score, and the historical reputation value of each target object in the previous reputation value update cycle;
[0015] The first determining unit is used to determine the evaluation reputation change value of each target object based on the confidence evaluation score, evaluation confidence and corresponding historical reputation value of each target object;
[0016] A recording unit is used to record the contribution reputation change value of the first object in contributing the intelligence data, and the evaluation reputation change value of each target object;
[0017] The second determining unit is used to determine the periodic active reputation change value of each object based on the number of contributions and the number of evaluations of each object in the shared object set during the current reputation value update period when the current reputation value update period is detected to be over.
[0018] The calculation unit is used to sum the historical reputation value, contribution reputation change value, evaluation reputation change value and corresponding periodic active reputation change value of each object in the previous reputation value update cycle, so as to obtain the current reputation value of each object in the current reputation value update cycle.
[0019] Thirdly, embodiments of this application provide a storage medium that stores multiple instructions adapted for loading by a processor to execute any of the data processing methods described above.
[0020] Fourthly, embodiments of this application provide a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the data processing method as described above.
[0021] In this embodiment, when a first object contributes intelligence data during the current reputation update cycle, the intelligence data is sent to each second object so that each second object evaluates the confidence level of the intelligence data. The second objects are other objects in the shared object set besides the first object. When a specified number of target objects among the second objects are detected to evaluate the data confidence level of the intelligence data, the confidence level of each target object's data confidence evaluation score, the confidence level of the data confidence evaluation score, and the historical reputation value of each target object in the previous reputation update cycle are obtained. Based on the confidence evaluation score and the confidence level of each target object... The reliability and corresponding historical reputation value are used to determine the evaluation reputation change value of each target object; the contribution reputation change value of the first object contributing to the intelligence data and the evaluation reputation change value of each target object are recorded; when the current reputation value update cycle is detected to be over, the periodic active reputation change value of each object is determined according to the number of contributions and evaluations of each object in the shared object set in the current reputation value update cycle; the historical reputation value, contribution reputation change value, evaluation reputation change value and corresponding periodic active reputation change value of each object in the previous reputation value update cycle are summed to obtain the current reputation value of each object in the current reputation value update cycle. Compared with related technologies, which cannot quantify the contribution of producers and verifiers, resulting in objects only expecting to obtain threat intelligence data and rarely contributing to or evaluating threat intelligence data, the low object activity leads to infrequent updates of threat intelligence data, and the difficulty in determining the credibility of threat intelligence data due to the small number of evaluations, the intelligence data can be verified by objects evaluating each other, improving the accuracy of intelligence data evaluation, updating the reputation values of objects participating in contribution and evaluation, and improving object activity.
[0022] Other features and advantages of this disclosure will be set forth in the following description and will be apparent in part from the description or may be learned by practicing the disclosure. The objectives and other advantages of this disclosure may be realized and obtained by means of the structures particularly pointed out in the description, claims and drawings. Attached Figure Description
[0023] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0024] Figure 1This is a flowchart illustrating a blockchain-based threat intelligence sharing scheme provided in an embodiment of this application.
[0025] Figure 2 This is a schematic diagram of a data processing system provided in an embodiment of this application.
[0026] Figure 3 This is a flowchart illustrating the data processing method provided in an embodiment of this application.
[0027] Figure 4 This is a schematic diagram of the intelligence data sharing platform provided in an embodiment of this application.
[0028] Figure 5 This is a schematic diagram illustrating the use of points to query intelligence data, as provided in an embodiment of this application.
[0029] Figure 6 This is a schematic diagram of the structure of the data processing apparatus provided in the embodiments of this application.
[0030] Figure 7 A schematic diagram of the structure of a computer device provided in an embodiment of this application. Detailed Implementation
[0031] To enable those skilled in the art to better understand the solutions of this application, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0032] It should be noted that while some processes described in the specification, claims, and accompanying drawings contain multiple steps that appear in a specific order, it should be clearly understood that these steps may not be performed in the order they appear herein, or may be performed in parallel. The step numbers are merely used to distinguish different steps and do not represent any particular order of execution. Furthermore, descriptions such as "first," "second," or "objective" in this document are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.
[0033] Before providing a further detailed description of the embodiments of this disclosure, the terms and concepts used in these embodiments are explained, and they are subject to the following interpretations:
[0034] Blockchain-based threat intelligence sharing solutions: such as Figure 1 As shown, Figure 1This is a flowchart illustrating a blockchain-based threat intelligence sharing scheme provided in this application embodiment. It includes roles such as a threat intelligence center (central institution), intelligence data producers, consumers, and verifiers. Producers, verifiers, and consumers first register with the sharing platform through the central institution. Producers report a piece of threat intelligence data (hereinafter referred to as intelligence data), verifiers verify this intelligence data, and upon successful verification, it is uploaded to the blockchain. Consumers then retrieve this intelligence data from the blockchain, thereby achieving intelligence data sharing.
[0035] However, although intelligence production and consumption occur on a "trustworthy" blockchain, mechanisms are needed to ensure the reliability of the on-chain process, thereby guaranteeing the trustworthiness of all parties' operations and the security of data transmission. Furthermore, the establishment and operation of a central institution must reduce its high costs. Distributed sharing schemes based on blockchain and federated learning can ensure the security of data transmission, but they cannot guarantee the trustworthiness of the data "on-chain" operation, cannot solve the fairness issue, and cannot verify the quality of intelligence at a low cost. Currently, threat intelligence sharing still faces problems of imperfect mechanisms and trust asymmetry. Solving the fairness issue of threat intelligence requires incentivizing all parties to contribute their own intelligence, designing reasonable incentive mechanisms to reward contributions, while ensuring that the contributions of contributors are not unconditionally obtained by parties with smaller contributions. Solving the trust issue requires ensuring the trustworthiness of the contributed threat intelligence, establishing verification and evaluation mechanisms for the contributed intelligence data, and ensuring the quality of the contributed intelligence data.
[0036] To address the aforementioned problems, this application embodiment sends the intelligence data to each second object when a first object contributes intelligence data during the current reputation value update cycle, enabling each second object to evaluate the confidence level of the intelligence data. The second objects are other objects in the shared object set besides the first object. When a specified number of target objects among the second objects are detected to have evaluated the data confidence level of the intelligence data, the system acquires the data confidence level evaluation score, the confidence level of the data confidence level evaluation score, and the historical reputation value of each target object in the previous reputation value update cycle. Based on the confidence level evaluation score of each target object, The evaluation confidence level and corresponding historical reputation value are used to determine the evaluation reputation change value of each target object; the contribution reputation change value of the first object contributing the intelligence data and the evaluation reputation change value of each target object are recorded; when the current reputation value update cycle is detected to be over, the periodic active reputation change value of each object is determined based on the number of contributions and evaluations of each object in the shared object set during the current reputation value update cycle; the historical reputation value, contribution reputation change value, evaluation reputation change value, and corresponding periodic active reputation change value of each object in the previous reputation value update cycle are summed to obtain the current reputation value of each object in the current reputation value update cycle. Compared with related technologies, which cannot quantify the contribution of producers and verifiers, resulting in objects only expecting to obtain threat intelligence data and rarely contributing or evaluating threat intelligence data, the low object activity leads to infrequent updates of threat intelligence data, and the difficulty in determining the credibility of threat intelligence data due to the small number of evaluations, the verification of intelligence data can be achieved by having contributing objects evaluate each other's intelligence data, thereby improving the accuracy of intelligence data evaluation and updating the reputation values of the objects participating in the contribution and evaluation, thus increasing object activity. Please continue to refer to the following specific embodiments for details.
[0037] Please see Figure 2 , Figure 2 This is a schematic diagram of a data processing system provided in an embodiment of this application. It includes a terminal 140, an Internet 130, a gateway 120, a server 110, etc.
[0038] Terminal 140 includes, but is not limited to, pre-configured electronic devices with data reporting capabilities such as laptops, tablets, or desktop computers. Furthermore, it can be a single device or a collection of multiple devices. Terminal 140 can communicate with the Internet 130 via wired or wireless means to exchange intelligence data.
[0039] Terminal 140 refers to a computer system capable of submitting data to server 110. Compared to ordinary terminals, server 110 has higher requirements in terms of stability, security, and performance. Server 110 can be a single high-performance computer in a network platform, a cluster of multiple high-performance computers, a portion of a single high-performance computer (e.g., a virtual machine), or a combination of portions of multiple high-performance computers (e.g., virtual machines).
[0040] Gateway 120, also known as an internetwork connector or protocol converter, is a computer system or device that acts as a translator, enabling network interconnection at the transport layer. It bridges the gap between two systems using different communication protocols, data formats, languages, or even completely different architectures. Gateways can also provide filtering and security functions. Messages sent from terminal 140 to server 110 are forwarded to the corresponding server 110 via gateway 120. Similarly, intelligence data sent from server 110 to terminal 140 is also forwarded to the corresponding terminal 140 via gateway 120.
[0041] The data processing method of this disclosure embodiment can be implemented on server 110.
[0042] It should be noted that, Figure 2 The schematic diagram of the data processing system shown is merely an example. The data processing system and scenario described in the embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the evolution of image processing technology and the emergence of new business scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.
[0043] In this embodiment, the description will be from the perspective of a data processing device, which can be integrated into a computer device that has a storage unit and is equipped with a microprocessor and has computing capabilities.
[0044] Please see Figure 3 , Figure 3 A flowchart illustrating the data processing method provided in this application embodiment. The data processing method includes:
[0045] In step 201, when it is detected that the first object contributes intelligence data in the current reputation value update cycle, the intelligence data is sent to each second object so that each second object can evaluate the confidence of the intelligence data. The second object is any other object in the shared object set besides the first object.
[0046] The reputation value update cycle is a pre-defined period for updating the reputation value of each object, for example, once every 6 hours. The shared object set is a collection of objects that have registered their identities in the intelligence data sharing platform. The second object is any other object in the shared object set besides the first object. For example, if the objects that have registered their identities in the intelligence data sharing platform include object A, object B, and object C, and object A is the first object, then the second objects are object B and object C.
[0047] Specifically, if it is detected that a first object contributes intelligence data in the current reputation value update cycle, the intelligence data is sent to every second object in the shared object set except for the first object, so that each second object evaluates the confidence level of the intelligence data sent by the first object. Thus, the authenticity of the intelligence data is determined by evaluating the confidence level of multiple second objects.
[0048] In step 202, when it is detected that a specified number of target objects in the second object are evaluating the data confidence of the intelligence data, the data confidence score of each target object, the evaluation confidence of the data confidence score, and the historical reputation value of each target object in the previous reputation value update cycle are obtained.
[0049] The confidence level assessment involves the target object giving a confidence score based on its own experience regarding the intelligence data. It also requires providing the degree of confidence in that confidence score, also known as the level of certainty. The purpose of setting a specified number is to ensure that the intelligence data is effectively evaluated only if at least a specified number of target objects from the second group provide confidence assessments, thus avoiding the influence of subjective factors from a single object's assessment.
[0050] Specifically, in order to increase the activity of the target, the reputation values of the second target that evaluates the confidence of the intelligence data and the first target that contributes to the intelligence data will be recalculated. For the second target that evaluates the confidence, it is necessary to obtain its evaluation confidence score, the confidence of the given confidence score, and its historical reputation value in the previous reputation value update cycle.
[0051] The scenario is illustrated by object A contributing intelligence data, and objects B / C / D evaluating it: Object A contributes intelligence data X, and objects B / C / D give a confidence score of x / y / z for this intelligence, with their confidence level (degree of certainty) as m / n / k. Meanwhile, the historical reputation values of objects B / C / D are R respectively. B / R C / R Dx / y / z represent the evaluation scores given by objects B / C / D to the intelligence data X contributed by object A; m / n / k represent the degree of certainty (i.e., the confidence level) of each object (i.e., B / C / D) regarding the evaluation scores (i.e., x / y / z) of intelligence data X. The confidence level is derived from the judgment of objects B / C / D based on the information they possess.
[0052] The confidence level can be illustrated with the following example: Subject A likes to eat apples. Subject B rates this event with a confidence score of 80, which represents a 90% confidence level. This means that, based on the information available to him, Subject B is fairly certain (80 points) that Subject A likes to eat apples, and Subject B has a 90% degree of confidence in this judgment.
[0053] In step 203, the evaluation reputation change value of each target object is determined based on the confidence score, evaluation confidence, and corresponding historical reputation value of each target object.
[0054] Specifically, for each target object, the contribution of each target object to the confidence evaluation of the intelligence data is determined by the confidence evaluation score and the evaluation confidence of the confidence evaluation score; then, combined with the historical reputation value of each target object, the final evaluation reputation change value of each target object for the evaluation event of the confidence evaluation of the intelligence data is determined.
[0055] In some implementations, determining the rating reputation change value for each target object based on its confidence score, rating confidence level, and corresponding historical reputation value includes:
[0056] (1) Obtain the reputation score percentage of each target object;
[0057] (2) Determine the product of the confidence score of each target object and the corresponding confidence score to obtain the evaluation contribution value of each target object to the intelligence data;
[0058] (3) The evaluation contribution values of multiple target objects to the intelligence data are weighted and summed according to the reputation value ratio of each target object to obtain the actual evaluation contribution value of the intelligence data;
[0059] (4) Obtain the absolute value of the difference between the evaluation contribution value and the actual evaluation contribution value of each target object to obtain the evaluation contribution difference of each target object;
[0060] Based on the difference in evaluation contribution of each of the target objects, determine the percentage of the difference in evaluation contribution of each of the target objects;
[0061] (5) Determine the product of the evaluation contribution difference ratio of each target object and the total evaluation reputation value of the intelligence data to obtain the evaluation reputation change value of each target object.
[0062] The reputation score percentage for each target object is the ratio of its historical reputation score to the sum of the historical reputation scores of all target objects. The evaluation contribution value is the quantified result of each target object's contribution to the confidence assessment of the intelligence data; it is the product of each target object's confidence assessment score and its corresponding confidence level, yielding the evaluation contribution value for each target object regarding the intelligence data.
[0063] Specifically, if subject A contributes intelligence data X, and subjects B / C / D give a confidence score of x / y / z for this intelligence, their confidence level (i.e., degree of certainty) is m / n / k. Meanwhile, the historical reputation values of subjects B / C / D are R respectively. B / R C / R D Taking the scenario as an example, the actual evaluation contribution value It can be calculated using the following formula:
[0064] ;
[0065] in, This is the quantified evaluation contribution value of object B's contribution to the confidence assessment of intelligence data X. This is the quantified evaluation contribution value of object C's contribution to the confidence assessment of intelligence data X. This is the quantified evaluation contribution value of object D's contribution to the confidence evaluation of intelligence data X; The percentage of reputation value for object B, The percentage of reputation value for object C, The actual evaluation contribution value of intelligence data X is obtained by weighted summation of the evaluation contribution values of multiple target objects for intelligence data. .
[0066] Specifically, after issuing an evaluation task for each intelligence report, a total reward (i.e., the total evaluation reputation value E) is given for that intelligence evaluation task. After a specified time following the completion of the evaluation, the reward is distributed based on the quality of each object's evaluation, specifically the difference between each object's evaluation result and the final result. After calculating the actual evaluation contribution value, the evaluation contribution difference for each target object can be determined. The evaluation contribution difference is the absolute value of the difference between each target object's evaluation contribution value and its actual evaluation contribution value, which can be calculated using the following formula:
[0067] ;
[0068] ;
[0069] ;
[0070] in, , as well as These represent the differences in evaluation contributions of objects B, C, and D, respectively. It is understood that the total reward set for the intelligence evaluation task in this application is not limited to the total evaluation reputation value, but may also include other virtual rewards such as the total evaluation points, which are not limited here.
[0071] Based on the differences in evaluation contributions for each target object, the proportion of each target object in the total differences in evaluation contributions is determined, i.e., the percentage of evaluation contribution difference for each target object. Finally, the evaluation reputation change value for each target object is obtained by multiplying the percentage difference in evaluation contribution of each target object by the total evaluation reputation value of the intelligence data. .
[0072] Specifically, if subject A contributes intelligence data X, and subjects B / C / D give a confidence score of x / y / z for this intelligence, their confidence level (i.e., degree of certainty) is m / n / k. Meanwhile, the historical reputation values of subjects B / C / D are R respectively. B / R C / R D Taking this scenario as an example, the reputation change value for each target object can be calculated using the following formula:
[0073] ;
[0074] ;
[0075] ;
[0076] in, , as well as Let E represent the percentage difference in evaluation contributions for objects B, C, and D, respectively. For object B, calculate the total evaluation reputation score E and its corresponding percentage difference in contribution. The product of these factors yields the reputation change value for object B; for object C, the total reputation value E and its corresponding contribution difference percentage are calculated. The product of these factors yields the reputation change value for object C; for object D, the total reputation value E and its corresponding contribution difference percentage are calculated. The product of these factors yields the reputation change value for object D.
[0077] Specifically, in some implementations, after an object contributes intelligence data, a confidence evaluation task for the intelligence data is issued, and the number of members participating in the evaluation task for the intelligence to be evaluated is updated in real time, and the evaluation task is pushed to the object. Objects can selectively participate in the evaluation task to obtain reputation points or reward points. For newly contributed threat intelligence and unverified threat intelligence, objects are given priority to participate in the evaluation. For verified intelligence, objects that have not participated in the evaluation of that intelligence data can still evaluate it, but objects that have already participated in the verification cannot participate again, but can modify and update the evaluation results they have submitted. After a period of time after the evaluation of a piece of intelligence data is completed, the evaluation task for that intelligence data is closed, and reward distribution is executed. Objects can choose to appeal the modification of the confidence level of verified intelligence data whose evaluation has been closed, based on their practical experience, and provide supporting evidence for review by other objects. After the review is approved, the confidence level of the intelligence data is calculated and updated, and a reward is given to the object who filed the appeal.
[0078] Therefore, the evaluation reputation change value is determined by comprehensively considering the target object's confidence score, evaluation confidence level, and historical reputation value. The confidence score reflects the judgment on the credibility of the intelligence data, the evaluation confidence level reflects the degree of certainty in the judgment, and the historical reputation value represents past reputation. Combining multiple factors avoids the one-sidedness of single-factor evaluation, making the measurement of the target object's evaluation behavior more comprehensive and scientific, and more accurately reflecting its actual contribution and value to the intelligence data evaluation. By calculating the reputation value proportion, the evaluation contribution value of the target object is weighted and summed to obtain the actual evaluation contribution value. This gives a greater weight to the evaluation of objects with high reputation values in the overall evaluation, because their past performance is more reliable and consistent with common sense, making the evaluation results more consistent with reality and enhancing the objectivity of the evaluation system.
[0079] In some implementations, obtaining the reputation score percentage for each target object includes:
[0080] (1.1) Obtain the sum of the historical reputation values of each target object to obtain the total reputation value;
[0081] (1.2) Calculate the ratio of the historical reputation value of each target object to the total reputation value to obtain the reputation value percentage of each target object.
[0082] The calculation method for the reputation score percentage of each target object is as follows: obtain the sum of the historical reputation scores of each target object to get the total reputation score of all target objects; then calculate the ratio of the historical reputation score of each target object to the total reputation score to obtain the reputation score percentage of each target object.
[0083] Specifically, subject A contributes a piece of intelligence data X, and subjects B / C / D evaluate the confidence level of this intelligence data. The historical reputation values of subjects B / C / D are R respectively. B / R C / R D Taking the scenario as an example, the reputation score ratio of objects B / C / D can be determined using the following formula:
[0084] ;
[0085] ;
[0086] ;
[0087] in, This is the total reputation score, calculated for object B by determining its corresponding historical reputation score R. B With total reputation value The ratio of these ratios will give you the corresponding percentage of your reputation score. For object C, its corresponding historical reputation value R is calculated. C With total reputation value The ratio of these ratios will give you the corresponding percentage of your reputation score. For object D, its corresponding historical reputation value R is calculated. D With total reputation value The ratio of these ratios will give you the corresponding percentage of your reputation score. .
[0088] Therefore, by calculating the proportion of reputation value, the historical reputation value of the target object is incorporated into the current intelligence data evaluation system. Objects with higher historical reputation values will have a higher weight in the evaluation, meaning their evaluation opinions have a greater impact on the final actual evaluation contribution value. For example, in a scenario where object A contributes intelligence data X, and objects B, C, and D evaluate it, if object B has a higher historical reputation value, its reputation value will account for a higher proportion. If the value of object B is relatively large, then object B's contribution to the evaluation of intelligence data X will have a larger weight in the weighted summation. This allows for a more accurate synthesis of the evaluations from all objects, avoiding excessive interference from arbitrary evaluations by individual objects, making the evaluation results more consistent with reality, and enhancing the reliability of the evaluation results. When multiple target objects participate in the evaluation, the calculation of the reputation value proportion can comprehensively consider the historical reputation of all objects. Each object's historical reputation value participates in the calculation of the actual evaluation contribution value through a proportion, so that the evaluation result does not depend on the evaluation of a single object, but on a reasonable weighted synthesis of the evaluations of all objects. This method can effectively avoid the one-sidedness of a single object's evaluation, making the evaluation results more comprehensive and objective.
[0089] In some implementations, determining the percentage of evaluation contribution difference for each target object based on the evaluation contribution difference of each target object includes:
[0090] (1.1) Obtain the sum of the evaluation contribution differences for each of the target objects to obtain the total evaluation contribution difference;
[0091] (1.2) Calculate the ratio of the evaluation contribution difference of each target object to the total evaluation contribution difference to obtain the evaluation contribution difference percentage of each target object.
[0092] The calculation method for the percentage of evaluation contribution difference for each target object is as follows: obtain the sum of the evaluation contribution differences for each target object to get the total evaluation contribution difference for all target objects; then calculate the ratio of the evaluation contribution difference for each target object to the total evaluation contribution difference to obtain the percentage of evaluation contribution difference for each target object.
[0093] Specifically, subject A contributes a piece of intelligence data X, and subjects B / C / D evaluate the confidence level of this intelligence data. The differences in the evaluation contributions of subjects B / C / D are as follows: , as well as Taking the scenario as an example, the percentage difference in evaluation contributions between objects B, C, and D can be determined using the following formula:
[0094] ;
[0095] ;
[0096] ;
[0097] in, This is the total evaluation contribution difference. For object B, the corresponding evaluation contribution difference is calculated. Difference from overall evaluation contribution The ratio of these ratios can be used to obtain the corresponding percentage of difference in evaluation contribution. For object C, the difference in its corresponding evaluation contribution is calculated. Difference from overall evaluation contribution The ratio of these ratios can be used to obtain the corresponding percentage of difference in evaluation contribution. For object D, the difference in its corresponding evaluation contribution is calculated. Difference from overall evaluation contribution The ratio of these ratios can be used to obtain the corresponding percentage of difference in evaluation contribution. .
[0098] Therefore, by calculating the proportion of evaluation contribution differences, the evaluation contribution differences of each target object are considered within the overall differences of all objects, thus quantifying the relative differences between individual evaluation quality and overall evaluation. For example, in a scenario where object A contributes intelligence data X, and objects B, C, and D participate in the evaluation, the proportion of evaluation contribution differences for objects B, C, and D can be obtained respectively. , as well as This clearly shows the degree of deviation between each object's evaluation and the overall evaluation, thus more accurately measuring the quality of each object's evaluation. The percentage of difference in evaluation contribution directly reflects the relative quality of the target object's evaluation. A small percentage means that the object's evaluation is closer to the final actual evaluation contribution value, indicating higher evaluation quality; a large percentage indicates a greater degree of deviation, indicating relatively lower evaluation quality. This provides a clear and intuitive basis for subsequent reward allocation and reputation adjustments.
[0099] In step 204, the contribution reputation change value of the first object in contributing the intelligence data and the evaluation reputation change value of each target object are recorded.
[0100] Specifically, depending on the specific implementation scenario, a contribution reputation change value is set for contributing one piece of intelligence data. Based on this, after the first object contributes intelligence data, the corresponding contribution reputation change value is recorded, and the reputation change value of each target object that evaluates the confidence of this intelligence data is also recorded for subsequent reputation value calculation.
[0101] In step 205, when the current reputation value update period is detected to be over, the periodic active reputation change value of each object is determined based on the number of contributions and the number of evaluations of each object in the shared object set during the current reputation value update period.
[0102] If the current reputation value update period is detected to have ended, the periodic active reputation change value for each object will be calculated based on the number of contributions and evaluations made by each object in the current reputation value update period.
[0103] In some implementations, the periodic active reputation change value of each object is determined based on the number of contributions and evaluations made by each object in the shared object set during the current reputation value update period, including:
[0104] (1) Determine the contribution activity level based on the number of contributions made by each object in the shared object set during the current reputation value update cycle;
[0105] (2) Determine the rating activity based on the number of ratings for each object in the shared object set during the current reputation value update cycle;
[0106] (3) Obtain contribution index and evaluation index;
[0107] (4) Determine the weighted activity of each object in the shared object set based on the contribution activity, contribution index, evaluation activity and evaluation index of each object in the shared object set;
[0108] (5) Determine the periodic active reputation change value of each object based on the weighted activity of each object in the shared object set, the preset ratio coefficient and the adjustment parameters.
[0109] The periodic active reputation change value is determined based on the activity level of each object in the current reputation update cycle. Each object can be a contributor to intelligence data or an evaluator of the confidence level of intelligence data. Therefore, for an object, its activity level in the current reputation update cycle can be reflected in two dimensions: contribution activity and evaluation activity. Contribution activity is related to the number of contributions made by the object in the current reputation update cycle. Specifically, the number of contributions can be directly determined as contribution activity, or the product of the number of contributions and the corresponding contribution coefficient can be used as contribution activity; there is no limitation here. Evaluation activity is related to the number of evaluations made by the object in the current reputation update cycle. Specifically, the number of evaluations can be directly determined as evaluation activity, or the product of the number of evaluations and the corresponding evaluation coefficient can be used as evaluation activity; there is no limitation here.
[0110] Specifically, after obtaining the contribution activity and evaluation activity, the weighted activity of each object in the shared object set is determined by combining the pre-set contribution index and evaluation index. Finally, the periodic active reputation change value of each object is determined based on the weighted activity of each object in the shared object set, the preset ratio coefficient, and the adjustment parameters.
[0111] This approach measures an object's activity from two dimensions: contribution and evaluation, comprehensively covering the object's main behaviors within the intelligence-sharing system. It considers both the object's contribution as an intelligence data provider (contribution activity) and its role as an evaluator in controlling data quality (evaluation activity), avoiding the one-sidedness of assessing an object's contribution solely based on a single behavior. This allows the reputation change value to more comprehensively reflect the object's actual participation and value within the system. Determining the reputation change value based on weighted activity ensures that objects actively participating in both contribution and evaluation receive higher reputation enhancements. Active objects invest more time and effort in the system, and through this mechanism, they can receive corresponding rewards, such as higher reputation values potentially leading to greater resource access or system rewards. This incentivizes objects to remain active, further enriching and improving intelligence data resources and enhancing the overall value of the system.
[0112] In some implementations, determining the weighted activity of each object in the shared object set based on its contribution activity, contribution index, evaluation activity, and evaluation index includes:
[0113] (1.1) Using the contribution index as the index and the contribution activity of each object in the shared object set as the base, calculate the contribution sub-weighted activity of each object in the shared object set;
[0114] (1.2) Using the evaluation index as the index and the evaluation activity of each object in the shared object set as the base, calculate the evaluation sub-weighted activity of each object in the shared object set;
[0115] (1.3) Calculate the sum of the contribution sub-weighted activity and the corresponding evaluation sub-weighted activity of each object in the shared object set to obtain the weighted activity of each object in the shared object set.
[0116] Specifically, for each object in the shared object set, the contribution-weighted activity level is calculated using the contribution index as the index and the corresponding contribution activity level as the base. For example, the contribution activity level of object B is... The contribution index is Then the weighted activity of object B is... For each object in the shared object set, the sub-weighted activity of the evaluation dimension is calculated using the evaluation index as the index and the corresponding evaluation activity as the base. For example, the contribution activity of object B is... The evaluation index is Then the weighted activity of object B is... .
[0117] The weighted activity of each object in the shared object set is obtained by summing its contribution-weighted activity and its corresponding evaluation-weighted activity. For example, the contribution-weighted activity of object B is... The weighted activity level of the contributor is Then the weighted liveness of object B is .
[0118] Specifically, contribution index and evaluation index These are indices corresponding to contribution and evaluation, respectively, which determine the degree of "reward acceleration" or "penalty deceleration." For example, when... >1 or When the score is greater than 1, the object is considered to have high activity, which will cause the reputation score to increase at a faster rate; conversely, if... <1 or If the value is less than 1, it will create a "penalty slowdown" effect.
[0119] Therefore, by comprehensively considering the activity levels of both contribution and evaluation, a weighted activity level is determined, comprehensively and accurately measuring the object's contribution to the system. Different objects may have different strengths in contribution and evaluation, and this method can reflect all of these strengths. For example, some objects are good at intelligence gathering and have high contribution activity; others are experienced in evaluation and have high evaluation activity. By calculating and summing the contribution sub-weighted activity and the evaluation sub-weighted activity separately, the contributions of all types of objects are reasonably reflected in the weighted activity level, providing a reliable basis for subsequent accurate assessment of object reputation. This is achieved by adjusting the contribution index. and evaluation index The system can flexibly control the degree of incentive for different behaviors of objects. When When the value is greater than 1, the weighted activity level of objects with higher contribution activity will increase rapidly, and their reputation score will improve at a faster pace. This incentivizes objects to actively contribute more high-quality intelligence data; similarly, When the score is >1, users with high activity levels will receive more rewards, encouraging them to participate actively in the evaluation process. Conversely, <1 or When the score is less than 1, the reputation score of inactive objects decays more slowly, avoiding excessive punishment of temporarily inactive objects and maintaining their participation enthusiasm.
[0120] In some implementations, the periodic active reputation change value of each object is determined based on the weighted activity level of each object in the shared object set, a preset proportional coefficient, and adjustment parameters, including:
[0121] (1.1) Determine the product of the weighted activity of each object in the shared object set and the preset ratio coefficient to obtain the third calculation result of each object in the shared object set;
[0122] (1.2) Obtain the difference between the third calculation result of each object in the shared object set and the adjustment parameter to obtain the periodic active reputation change value of each object.
[0123] After obtaining the weighted activity level of each object in the shared object set, the third calculation result for each object is determined by multiplying the weighted activity level by a preset scaling factor k. The preset scaling factor k controls the overall growth or decay rate. The difference between the third calculation result for each object and the adjustment parameter l is used to obtain the periodic active reputation change value for each object. l is a constant that can be set to a positive or negative number as needed, used to adjust the baseline level or set the minimum growth / maximum decay limit.
[0124] Specifically, the periodic active reputation change value for each object can be calculated using the following formula:
[0125] =k( )−l;
[0126] in, This is the periodic active reputation change value, calculated by weighting the activity of each object in the shared object set. The product of this product and the preset proportionality coefficient k will yield the third calculation result k( The difference between the value and the adjustment parameter l is calculated to determine the periodic active reputation change value of each object in the shared object set.
[0127] Specifically, when implementing reputation score growth or decay based on activity level, the following points should be noted: If you want to reward high activity more, you can set it to a larger value. Conversely, if you want to mitigate the negative impact of low activity, you can choose a smaller value. Furthermore, the parameter k needs to be evaluated and adjusted regularly. , Alternatively, l can be used to ensure more flexible adjustment of the speed of rewards and punishments, thereby better adapting to different business needs.
[0128] Therefore, a flexible means of regulating reputation change values is provided by pre-setting a proportional coefficient k and adjusting the parameter l. k controls the overall growth or decay rate. Increasing k increases the magnitude of reputation score changes with weighted activity, resulting in more generous rewards for highly active users and effectively incentivizing active participation. Decreasing k reduces the magnitude of reputation score changes, making the reputation system more stable. The adjusting parameter l can set minimum growth or maximum decay limits. When used positively, it raises the baseline level of reputation score growth and reduces the degree of reputation score decay; when used negatively, it limits excessive reputation score growth, ensuring the rationality of the reputation system and adapting to the requirements of reputation change speed and range in different business scenarios. Calculating reputation change values based on weighted activity closely links users' actual contributions to the system with reputation changes. Weighted activity comprehensively considers the activity level of user contributions and evaluations, accurately reflecting the user's level of participation and contribution. The calculated reputation change value accurately reflects the impact of user contributions on reputation; users who actively contribute receive reputation improvements, incentivizing users to continuously provide value to the system and achieving a reasonable match between user contributions and reputation rewards.
[0129] In step 206, the historical reputation value, contribution reputation change value, evaluation reputation change value, and corresponding periodic active reputation change value of each object in the previous reputation value update cycle are summed to obtain the current reputation value of each object in the current reputation value update cycle.
[0130] Specifically, after obtaining the contribution reputation change value, evaluation reputation change value, and corresponding periodic active reputation change value of each object in the shared object set for each contribution or evaluation in the current reputation value update cycle, the historical reputation value of the previous reputation value update cycle is combined and summed to finally obtain the current reputation value of each object in the current reputation value update cycle.
[0131] Specifically, if object A contributed 3 pieces of intelligence data in the current reputation value update cycle, with contribution reputation change values of e, f, and g respectively, and evaluated 2 pieces of intelligence data, with evaluation reputation change values of m and n respectively, and the historical reputation value of the previous reputation value update cycle is h, and the corresponding periodic active reputation change value is j, then object A's current reputation value in the current reputation value update cycle is: e+f+g+m+n+h+j.
[0132] As described above, in this embodiment, when a first object contributes intelligence data in the current reputation value update cycle, the intelligence data is sent to each second object so that each second object evaluates the confidence level of the intelligence data. The second objects are other objects in the shared object set besides the first object. When a specified number of target objects among the second objects are detected to evaluate the data confidence level of the intelligence data, the confidence level of each target object's data confidence evaluation score, the confidence level of the data confidence evaluation score, and the historical reputation value of each target object in the previous reputation value update cycle are obtained. Based on the confidence evaluation score and evaluation of each target object... The confidence level and corresponding historical reputation value are used to determine the evaluation reputation change value of each target object; the contribution reputation change value of the first object contributing to the intelligence data and the evaluation reputation change value of each target object are recorded; when the current reputation value update cycle is detected to be over, the periodic active reputation change value of each object is determined according to the number of contributions and evaluations of each object in the shared object set in the current reputation value update cycle; the historical reputation value, contribution reputation change value, evaluation reputation change value and corresponding periodic active reputation change value of each object in the previous reputation value update cycle are summed to obtain the current reputation value of each object in the current reputation value update cycle. Compared with related technologies, which cannot quantify the contribution of producers and verifiers, resulting in objects only expecting to obtain threat intelligence data and rarely contributing to or evaluating threat intelligence data, the low object activity leads to infrequent updates of threat intelligence data, and the difficulty in determining the credibility of threat intelligence data due to the small number of evaluations, this technology can verify intelligence data by having objects evaluate each other's intelligence data, improve the accuracy of intelligence data evaluation, update the reputation values of objects participating in contribution and evaluation, and improve object activity.
[0133] For details, please refer to Figure 4 , Figure 4 This is a schematic diagram of an intelligence data sharing platform provided in an embodiment of this application. The main function of the intelligence sharing platform is to provide a platform for members to report intelligence; its basic principle is as follows: Figure 4As shown, each member (object) in the system contributes intelligence data to the public intelligence pool and receives a certain reputation score. When submitting intelligence data to the pool, an object must provide the intelligence data represented according to a fixed standard, along with its confidence level. Reported intelligence data is marked as "unverified" before being evaluated by other objects. Only when a certain number of members have evaluated the intelligence data is it considered "verified," thus reducing the subjectivity of threat intelligence evaluation. The reputation score a contributor receives for contributing intelligence data is related to the final confidence level of the intelligence after verification; members who contribute high-confidence intelligence will receive higher reputation scores, and vice versa.
[0134] Please see Figure 5 , Figure 5 This is a schematic diagram illustrating the use of points to query intelligence data in an embodiment of this application. All threat intelligence contributed by members is stored in a public intelligence pool, with the intelligence source and verification status marked, making it visible to all members within the threat intelligence alliance. When this module receives intelligence data reported by an object, the data is simply reported. It calls the intelligence deduplication module to check if the intelligence already exists in the public pool. If it does, the submission is rejected; otherwise, the submission is accepted and an evaluation process is initiated. In other words, the intelligence data at this point has been verified as valid and is considered contributed intelligence data. Objects can use this module to query and apply threat intelligence, but they must pay a certain amount of points as a cost. Successful queries deduct response points, while unsuccessful queries do not.
[0135] For details on the implementation of each of the above steps, please refer to the previous examples, which will not be repeated here.
[0136] To facilitate better implementation of the data processing method provided in the embodiments of this application, the embodiments of this application also provide an apparatus based on the above-described data processing method. The meanings of the terms used are the same as in the data processing method described above, and specific implementation details can be found in the descriptions within the method embodiments.
[0137] Please see Figure 6 , Figure 6 This is a schematic diagram of the structure of a data processing device provided in an embodiment of this application. The data processing device is applied to a computer device. The data processing device may include a sending unit 601, an acquiring unit 602, a first determining unit 603, a recording unit 604, a second determining unit 605, and a calculation unit 606, etc.
[0138] The sending unit 601 is used to send the intelligence data to each second object when it is detected that the first object has contributed intelligence data in the current reputation value update cycle, so that each second object can evaluate the confidence of the intelligence data. The second object is other objects in the shared object set besides the first object.
[0139] The acquisition unit 602 is used to acquire, when it is detected that a specified number of target objects in the second object are evaluating the data confidence of the intelligence data, the data confidence score of each target object, the evaluation confidence of the data confidence score, and the historical reputation value of each target object in the previous reputation value update cycle.
[0140] The first determining unit 603 is used to determine the evaluation reputation change value of each target object based on the confidence evaluation score, evaluation confidence and corresponding historical reputation value of each target object;
[0141] Recording unit 604 is used to record the contribution reputation change value of the first object in contributing the intelligence data, and the evaluation reputation change value of each target object;
[0142] The second determining unit 605 is used to determine the periodic active reputation change value of each object based on the number of contributions and the number of evaluations of each object in the shared object set during the current reputation value update cycle when the current reputation value update cycle is detected to be over.
[0143] The calculation unit 606 is used to sum the historical reputation value, contribution reputation change value, evaluation reputation change value and corresponding periodic active reputation change value of each object in the previous reputation value update cycle to obtain the current reputation value of each object in the current reputation value update cycle.
[0144] In some embodiments, the first determining unit 603 includes:
[0145] The first acquisition subunit is used to acquire the reputation value percentage of each of the target objects;
[0146] The first determining subunit is used to determine the product of the confidence evaluation score and the corresponding evaluation confidence score of each target object, so as to obtain the evaluation contribution value of each target object to the intelligence data;
[0147] The calculation subunit is used to perform a weighted summation of the evaluation contribution values of multiple target objects to the intelligence data according to the reputation value ratio of each target object, so as to obtain the actual evaluation contribution value of the intelligence data;
[0148] The second acquisition subunit is used to acquire the absolute value of the difference between the evaluation contribution value and the actual evaluation contribution value of each target object, so as to obtain the evaluation contribution difference of each target object;
[0149] The second determining subunit is used to determine the percentage of evaluation contribution difference for each of the target objects based on the evaluation contribution difference for each target object.
[0150] The third determining subunit is used to determine the product of the evaluation contribution difference ratio of each target object and the total evaluation reputation value of the intelligence data, so as to obtain the evaluation reputation change value of each target object.
[0151] In some embodiments, the first acquisition subunit is configured to:
[0152] The sum of the historical reputation values of each target object is obtained to get the total reputation value;
[0153] Calculate the ratio of the historical reputation value of each target object to the total reputation value to obtain the reputation value percentage of each target object.
[0154] In some embodiments, the second determining subunit is configured to:
[0155] The sum of the evaluation contribution differences for each of the target objects is obtained to get the total evaluation contribution difference;
[0156] Calculate the ratio of the evaluation contribution difference of each target object to the total evaluation contribution difference to obtain the percentage of evaluation contribution difference for each target object.
[0157] In some embodiments, the second determining unit 605 includes:
[0158] The fourth determining subunit is used to determine the contribution activity level based on the number of contributions made by each object in the shared object set during the current reputation value update cycle;
[0159] The fifth determining subunit is used to determine the evaluation activity based on the number of evaluations of each object in the shared object set during the current reputation value update cycle;
[0160] The third acquisition subunit is used to acquire the contribution index and the evaluation index;
[0161] The sixth determining subunit is used to determine the weighted activity of each object in the shared object set based on the contribution activity, contribution index, evaluation activity, and evaluation index of each object in the shared object set;
[0162] The seventh determining subunit is used to determine the periodic active reputation change value of each object based on the weighted activity of each object in the shared object set, the preset ratio coefficient, and the adjustment parameters.
[0163] In some embodiments, the sixth determining subunit is configured to:
[0164] Using the contribution index as the index and the contribution activity of each object in the shared object set as the base, calculate the contribution sub-weighted activity of each object in the shared object set.
[0165] Using the evaluation index as the index and the evaluation activity of each object in the shared object set as the base, calculate the evaluation sub-weighted activity of each object in the shared object set;
[0166] The weighted activity of each object in the shared object set is obtained by summing the contribution sub-weighted activity and the corresponding evaluation sub-weighted activity of each object.
[0167] In some embodiments, the seventh determining subunit is configured to:
[0168] The product of the weighted activity level of each object in the shared object set and the preset ratio coefficient is determined to obtain the third calculation result for each object in the shared object set;
[0169] The difference between the third calculation result of each object in the shared object set and the adjustment parameter is obtained to obtain the periodic active reputation change value of each object.
[0170] The specific implementation of each of the above units can be found in the previous embodiments, and will not be repeated here.
[0171] As described above, in this embodiment, when the sending unit 601 detects that a first object has contributed intelligence data in the current reputation value update cycle, it sends the intelligence data to each second object, so that each second object can evaluate the confidence level of the intelligence data. The second objects are other objects in the shared object set besides the first object. When the acquisition unit 602 detects that a specified number of target objects among the second objects have evaluated the data confidence level of the intelligence data, it acquires the data confidence level evaluation score, the evaluation confidence level of the data confidence level evaluation score, and the historical reputation value of each target object in the previous reputation value update cycle. The first determination unit 603 determines the data confidence level evaluation score and the historical reputation value of each target object based on the confidence level evaluation score and the historical reputation value of the target object in the previous reputation value update cycle. The system uses a combination of a confidence level and a corresponding historical reputation value to determine the evaluation reputation change value of each target object. A recording unit 604 records the contribution reputation change value of the first object contributing to the intelligence data, and the evaluation reputation change value of each target object. A second determining unit 605, upon detecting the end of the current reputation value update cycle, determines the periodic active reputation change value of each object based on the number of contributions and evaluations made by each object in the shared object set during the current reputation value update cycle. A calculation unit 606 sums the historical reputation value, contribution reputation change value, evaluation reputation change value, and corresponding periodic active reputation change value of each object in the previous reputation value update cycle to obtain the current reputation value of each object in the current reputation value update cycle. Compared to related technologies, where the contribution of producers and verifiers cannot be quantified, leading to objects only expecting to obtain threat intelligence data and rarely contributing or evaluating it, resulting in low object activity and infrequent updates to threat intelligence data, and making it difficult to determine the reliability of threat intelligence data due to the small number of evaluations, this system allows for the verification of intelligence data through mutual evaluation between contributing objects. This improves the accuracy of intelligence data evaluation and updates the reputation values of participating objects, thereby increasing object activity.
[0172] The specific implementation of each of the above units can be found in the previous embodiments, and will not be repeated here.
[0173] Reference Figure 7 , Figure 7This is a partial structural block diagram of a computer device 1000 implementing embodiments of the present disclosure. The computer device 1000 can vary significantly due to different configurations or performance characteristics, and may include one or more central processing units (CPUs) 622 (e.g., one or more processors) and a memory 632, and one or more storage media 630 (e.g., one or more mass storage devices) storing application programs 642 or data 644. The memory 632 and storage media 630 may be temporary or persistent storage. The program stored in the storage media 630 may include one or more modules (not shown in the diagram), each module including a series of instruction operations on the server 600. Furthermore, the CPU 622 may be configured to communicate with the storage media 630 and execute the series of instruction operations in the storage media 630 on the server 600.
[0174] Computer device 1000 may also include one or more power supplies 626, one or more wired or wireless network interfaces 650, one or more input / output interfaces 658, and / or one or more operating systems 641, such as Windows Server, Mac OS X, Unix, Linux, FreeBSD, etc.
[0175] The central processing unit 622 in the computer device 1000 can be used to execute the data processing methods of the embodiments of this disclosure, for example:
[0176] When a first object is detected to contribute intelligence data in the current reputation value update cycle, the intelligence data is sent to each second object so that each second object can evaluate the confidence level of the intelligence data. The second objects are other objects in the shared object set besides the first object.
[0177] When it is detected that a specified number of target objects in the second object are evaluating the data confidence of the intelligence data, the data confidence score of each target object, the evaluation confidence of the data confidence score, and the historical reputation value of each target object in the previous reputation value update cycle are obtained.
[0178] Based on the confidence score, confidence level, and corresponding historical reputation value of each target object, determine the reputation change value of each target object;
[0179] Record the contribution reputation change value of the first object in contributing the intelligence data, and the evaluation reputation change value of each target object;
[0180] When the current reputation value update period is detected to be over, the periodic active reputation change value of each object is determined based on the number of contributions and evaluations of each object in the shared object set during the current reputation value update period.
[0181] The historical reputation value, contribution reputation change value, evaluation reputation change value, and corresponding periodic active reputation change value of each object in the previous reputation value update cycle are summed to obtain the current reputation value of each object in the current reputation value update cycle.
[0182] This disclosure also provides a computer-readable storage medium for storing program code for executing the data processing methods of the foregoing embodiments.
[0183] This disclosure also provides a computer program product comprising a computer program. A processor of a computer device reads and executes the computer program, causing the computer device to perform the data processing method described above. For example:
[0184] When a first object is detected to contribute intelligence data in the current reputation value update cycle, the intelligence data is sent to each second object so that each second object can evaluate the confidence level of the intelligence data. The second objects are other objects in the shared object set besides the first object.
[0185] When it is detected that a specified number of target objects in the second object are evaluating the data confidence of the intelligence data, the data confidence score of each target object, the evaluation confidence of the data confidence score, and the historical reputation value of each target object in the previous reputation value update cycle are obtained.
[0186] Based on the confidence score, confidence level, and corresponding historical reputation value of each target object, determine the reputation change value of each target object;
[0187] Record the contribution reputation change value of the first object in contributing the intelligence data, and the evaluation reputation change value of each target object;
[0188] When the current reputation value update period is detected to be over, the periodic active reputation change value of each object is determined based on the number of contributions and evaluations of each object in the shared object set during the current reputation value update period.
[0189] The historical reputation value, contribution reputation change value, evaluation reputation change value, and corresponding periodic active reputation change value of each object in the previous reputation value update cycle are summed to obtain the current reputation value of each object in the current reputation value update cycle.
[0190] Furthermore, the terms “comprising” and “including”, and any variations thereof, are intended to cover non-exclusive inclusion, such that a process, method, system, product, or apparatus that includes a series of steps or units is not necessarily limited to those steps or units that are explicitly listed, but may include other steps or units that are not explicitly listed or that are inherent to such process, method, product, or apparatus.
[0191] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.
[0192] It should be understood that in the description of the embodiments of this application, "multiple" means two or more, "greater than", "less than", "exceeding" etc. are understood to exclude the number itself, and "above", "below", "within" etc. are understood to include the number itself.
[0193] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces, or indirect coupling or communication connection between apparatuses or units, and may be electrical, mechanical, or other forms.
[0194] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0195] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0196] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0197] It should also be understood that the various implementation methods provided in this application can be combined arbitrarily to achieve different technical effects.
[0198] In the embodiments of this application, the terms "module" or "unit" refer to a computer program or part of a computer program that has a predetermined function and works with other related parts to achieve a predetermined goal, and can be implemented wholly or partially using software, hardware (such as processing circuitry or memory), or a combination thereof. Similarly, a processor (or multiple processors or memory) can be used to implement one or more modules or units. Furthermore, each module or unit can be part of an overall module or unit that includes the functionality of that module or unit.
[0199] The above is a detailed description of the embodiments of this application. However, this application is not limited to the above embodiments. Those skilled in the art can make various equivalent modifications or substitutions without departing from the spirit of this application. All such equivalent modifications or substitutions are included within the scope defined by the claims of this application.
Claims
1. A data processing method, characterized by, The method comprises the following steps: When it is detected that a first object contributes an intelligence data about a network security threat in a current reputation value updating period, the intelligence data is sent to each second object, so that each second object performs a confidence evaluation on the intelligence data, and the second object is an object in a shared object set except the first object; When it is detected that a specified number of target objects in the second objects perform data confidence evaluation on the intelligence data, a data confidence evaluation score of each target object, an evaluation confidence of the data confidence evaluation score, and a historical reputation value of each target object in a last reputation value updating period are obtained, and when there are no less than the specified number of target objects in the second objects that perform confidence evaluation on the intelligence data, it is determined that the intelligence data is effectively evaluated, and the subjective factor of single object confidence evaluation is avoided; A sum value of the historical reputation values of each target object is obtained, and a total reputation value is obtained; A ratio of the historical reputation value of each target object to the total reputation value is calculated, and a reputation value proportion of each target object is obtained; A product of the confidence evaluation score of each target object and the corresponding evaluation confidence is determined, and an evaluation contribution value of each target object for the intelligence data is obtained; The evaluation contribution values of the plurality of target objects for the intelligence data are weighted and summed according to the reputation value proportions of the target objects, and an actual evaluation contribution value of the intelligence data is obtained; An absolute value of a difference between the evaluation contribution value of each target object and the actual evaluation contribution value is obtained, and an evaluation contribution difference of each target object is obtained; A sum value of the evaluation contribution differences of each target object is obtained, and a total evaluation contribution difference is obtained; A ratio of the evaluation contribution difference of each target object to the total evaluation contribution difference is calculated, and an evaluation contribution difference proportion of each target object is obtained; A product of the evaluation contribution difference proportion of each target object and the total evaluation reputation value of the intelligence data is determined, and an evaluation reputation change value of each target object is obtained; A contribution reputation change value of the first object for the intelligence data is recorded, and the evaluation reputation change value of each target object is recorded; When it is detected that the current reputation value updating period ends, a period active reputation change value of each object in the shared object set is determined according to the contribution quantity and the evaluation quantity of each object in the current reputation value updating period; The historical reputation value, the contribution reputation change value, the evaluation reputation change value and the corresponding period active reputation change value of each object in the last reputation value updating period are summed, and a current reputation value of each object in the current reputation value updating period is obtained.
2. The data processing method according to claim 1, characterized in that, The period active reputation change value of each object is determined according to the contribution quantity and the evaluation quantity of each object in the current reputation value updating period, and the method comprises the following steps: A contribution activity is determined according to the contribution quantity of each object in the shared object set in the current reputation value updating period. determine an evaluation activity according to a number of evaluations of each object in the shared object set in the current reputation value update period; obtain a contribution index and an evaluation index; determine a weighted activity of each object in the shared object set based on the contribution activity, the contribution index, the evaluation activity, and the evaluation index of each object in the shared object set; determine a period active reputation change value of each object according to the weighted activity, a preset proportion coefficient, and an adjustment parameter of each object in the shared object set.
3. The data processing method according to claim 2, characterized in that, The determining of the weighted activity of each object in the shared object set based on the contribution activity, the contribution index, the evaluation activity, and the evaluation index of each object in the shared object set comprises: taking the contribution index as an index and the contribution activity of each object in the shared object set as a base to calculate a contribution sub-weighted activity of each object in the shared object set; taking the evaluation index as an index and the evaluation activity of each object in the shared object set as a base to calculate an evaluation sub-weighted activity of each object in the shared object set; calculating a sum value of the contribution sub-weighted activity and the corresponding evaluation sub-weighted activity of each object in the shared object set to obtain the weighted activity of each object in the shared object set.
4. The data processing method according to claim 2, characterized in that, The determining of the period active reputation change value of each object according to the weighted activity, the preset proportion coefficient, and the adjustment parameter of each object in the shared object set comprises: determining a product of the weighted activity and the preset proportion coefficient of each object in the shared object set to obtain a third calculation result of each object in the shared object set; obtaining a difference value between the third calculation result and the adjustment parameter of each object in the shared object set to obtain the period active reputation change value of each object.
5. A data processing apparatus, characterized by, comprise: a sending unit configured to send, when it is detected that a first object contributes an intelligence data about a network security threat in a current reputation value update period, the intelligence data to each second object, so that each second object performs confidence evaluation on the intelligence data, the second object being an object other than the first object in a shared object set; an obtaining unit configured to, when it is detected that a specified number of target objects among the second objects perform data confidence evaluation on the intelligence data, obtain a data confidence evaluation score of each target object, an evaluation confidence on the data confidence evaluation score, and a historical reputation value of each target object in a last reputation value update period, and determine that the intelligence data is effectively evaluated when there are no less than the specified number of target objects among the second objects that perform confidence evaluation on the intelligence data, so as to avoid the influence of subjective factors of a single object on confidence evaluation; a first determining unit comprising: a first obtaining sub-unit configured to: obtain a sum value of the historical reputation values of each target object to obtain a total reputation value; calculate a ratio of the historical reputation value of each target object to the total reputation value to obtain a reputation value proportion of each target object; The first determining sub-unit is configured to determine a product of a confidence evaluation score of each target object and a corresponding evaluation confidence, to obtain an evaluation contribution value of each target object with respect to the intelligence data; The calculating sub-unit is configured to perform weighted summation on the evaluation contribution values of the target objects with respect to the intelligence data according to a credit value proportion of each target object, to obtain an actual evaluation contribution value of the intelligence data; The second obtaining sub-unit is configured to obtain an absolute value of a difference between the evaluation contribution value of each target object and the actual evaluation contribution value, to obtain an evaluation contribution difference of each target object; The second determining sub-unit is configured to: obtain a sum value of the evaluation contribution differences of the target objects, to obtain a total evaluation contribution difference; calculate a ratio of the evaluation contribution difference of each target object to the total evaluation contribution difference, to obtain an evaluation contribution difference proportion of each target object; The third determining sub-unit is configured to determine a product of the evaluation contribution difference proportion of each target object and a total evaluation credit value of the intelligence data, to obtain an evaluation credit change value of each target object; The recording unit is configured to record a contribution credit change value of the first object with respect to the intelligence data, and the evaluation credit change value of each target object; The second determining unit is configured to, when detecting that a current credit value update period ends, determine a period active credit change value of each object in the shared object set according to a contribution quantity and an evaluation quantity of each object in the shared object set in the current credit value update period; The calculating unit is configured to perform summation on a historical credit value, a contribution credit change value, an evaluation credit change value and a corresponding period active credit change value of each object in a previous credit value update period, to obtain a current credit value of each object in the current credit value update period.
6. A computer readable storage medium characterized by, The computer readable storage medium stores a plurality of instructions, which are adapted to be loaded by the processor to execute the data processing method in any one of claims 1 to 4.
7. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, The processor executes the computer program to implement the data processing method in any one of claims 1 to 4. The processor executes the computer program to implement the data processing method in any one of claims 1 to 4.
Citation Information
Patent Citations
Information management method and device
CN110135711A
Data processing method and device, storage medium and computer equipment
CN119646579A