A data processing method and device for intelligence data traceability analysis

By classifying and analyzing basic network intelligence data, combined with large models and multimodal information integration technology, the problem of processing diversified open source intelligence data has been solved, efficient intelligence data traceability analysis has been achieved, the depth of data mining and analysis accuracy have been improved, and the information push capability and user experience have been enhanced.

CN120123816BActive Publication Date: 2025-09-09NO 15 INST OF CHINA ELECTRONICS TECH GRP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510188274.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-20
Publication Date
2025-09-09
Estimated Expiration
2045-02-20

AI Technical Summary

Technical Problem

Existing technologies are unable to effectively process diversified open source intelligence data, resulting in low automation levels in intelligence analysis and data mining, insufficient analysis accuracy and efficiency, and poor user experience.

Method used

By acquiring basic network intelligence data, classifying and analyzing it, utilizing large models and multimodal information integration technology, combining multi-search engine fusion collection, DeepWeb deep mining and collaborative intelligence production, efficient traceability analysis of intelligence data can be achieved.

Benefits of technology

It has improved the depth of network security intelligence data mining, improved the accuracy and efficiency of data analysis, enhanced the data traceability analysis capabilities and the ability to accurately push information, and improved the user experience of obtaining network security data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120123816B_ABST
    Figure CN120123816B_ABST
Patent Text Reader

Abstract

The present invention discloses a data processing method and device for intelligence data tracing and analysis, the method comprising: acquiring basic network intelligence data information; the basic network intelligence data information comprising H first network intelligence data information; classifying and processing the basic network intelligence data information to obtain target classification intelligence information; the target classification intelligence information comprising M target network intelligence data information; each target network intelligence data information comprising N target category intelligence information; each target category intelligence information comprising L target intelligence data information; the target intelligence data information corresponds to the first network intelligence data information; L is an integer not less than 0; and analyzing and processing the target classification intelligence information to obtain target processing intelligence information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security processing technology, and in particular to a data processing method and device for intelligence data source tracing and analysis. Background Art

[0002] With the rapid development of technology and globalization, the rapid and widespread dissemination of information has ushered in a new era of fragmentation. The incompleteness, opacity, unreliability and asymmetry of information have gradually increased the complexity of intelligence analysis and collection. Open source intelligence has diversified information acquisition channels, including online multimedia content, social networks, etc. The collected data formats are different and difficult to process. There have long been problems such as disorganized intelligence materials, semantic gaps, and low automation levels in intelligence identification and extraction. Therefore, a data processing method and device for intelligence data tracing and analysis are provided to increase the depth of network security intelligence data mining, improve data analysis accuracy and efficiency, and thereby enhance data tracing and analysis capabilities and information accurate push capabilities, thereby improving users' experience in accurately obtaining network security data information. Summary of the Invention

[0003] The technical problem to be solved by the present invention is to provide a data processing method and device for intelligence data tracing and analysis, which is conducive to improving the depth of network security intelligence data mining, improving data analysis accuracy and analysis efficiency, and further improving data tracing and analysis capabilities and information accurate push capabilities, thereby improving users' experience in accurately obtaining network security data information.

[0004] In order to solve the above technical problems, the first aspect of the embodiment of the present invention discloses a data processing method for intelligence data source tracing analysis, the method comprising:

[0005] Obtaining basic network intelligence data information; the basic network intelligence data information includes H first network intelligence data information;

[0006] Classifying the basic network intelligence data information to obtain target classification intelligence information; the target classification intelligence information includes M target network intelligence data information; each target network intelligence data information includes N target category intelligence information; each target category intelligence information includes L target intelligence data information; the target intelligence data information corresponds to the first network intelligence data information; L is an integer not less than 0;

[0007] The target classification intelligence information is analyzed and processed to obtain target processing intelligence information.

[0008] A second aspect of an embodiment of the present invention discloses a data processing device for intelligence data source tracing and analysis, the device comprising:

[0009] An acquisition module, configured to acquire basic network intelligence data information; the basic network intelligence data information includes H first network intelligence data information;

[0010] a first processing module configured to classify the basic network intelligence data information to obtain target classification intelligence information; the target classification intelligence information includes M target network intelligence data information; each target network intelligence data information includes N target category intelligence information; each target category intelligence information includes L target intelligence data information; the target intelligence data information corresponds to the first network intelligence data information; and L is an integer not less than 0;

[0011] The second processing module is used to analyze and process the target classification intelligence information to obtain target processing intelligence information.

[0012] A third aspect of the present invention discloses another data processing device for intelligence data source tracing and analysis, the device comprising:

[0013] a memory storing executable program code;

[0014] a processor coupled to a memory;

[0015] The processor calls the executable program code stored in the memory to execute some or all of the steps in the data processing method for intelligence data tracing and analysis disclosed in the first aspect of the embodiment of the present invention.

[0016] The fourth aspect of the present invention discloses a computer-readable storage medium, which stores computer instructions. When the computer instructions are called, they are used to execute some or all of the steps in the data processing method for intelligence data tracing and analysis disclosed in the first aspect of an embodiment of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0018] Figure 1 This is a schematic diagram of a scenario of a data processing system for intelligence data traceability analysis provided by an embodiment of the present invention;

[0019] Figure 2 This is a flow chart of a data processing method for intelligence data source tracing and analysis disclosed in an embodiment of the present invention;

[0020] Figure 3This is a structural diagram of a data processing device for intelligence data source tracing and analysis disclosed in an embodiment of the present invention;

[0021] Figure 4 This is a schematic structural diagram of another data processing device for intelligence data source tracing and analysis disclosed in an embodiment of the present invention;

[0022] Figure 5 It is a structural diagram of an intelligence association analysis model disclosed in an embodiment of the present invention. DETAILED DESCRIPTION

[0023] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making any creative efforts shall fall within the scope of protection of the present invention.

[0024] The terms "first," "second," and so on, in the description and claims of the present invention and the accompanying drawings are used to distinguish between different objects, not to describe a specific order. Furthermore, the terms "including," "having," and any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, apparatus, product, or device comprising a series of steps or elements is not limited to the listed steps or elements but may optionally include steps or elements not listed, or may optionally include other steps or elements inherent to the process, method, product, or device.

[0025] References herein to "embodiments" mean that a particular feature, structure, or characteristic described in connection with the embodiments may be included in at least one embodiment of the present invention. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it constitute a separate or alternative embodiment that is mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described herein may be combined with other embodiments.

[0026] In this application, the word "exemplary" is used to mean "serving as an example, illustration, or illustration." Any embodiment described in this application as "exemplary" is not necessarily to be construed as preferred or advantageous over other embodiments. The following description is given to enable any person skilled in the art to implement and use the present application. In the following description, details are listed for the purpose of explanation. It should be understood that one of ordinary skill in the art can recognize that the present application can be implemented without using these specific details. In other instances, well-known structures and processes are not elaborated in detail to avoid obscuring the description of the present application with unnecessary details. Therefore, the present application is not intended to be limited to the embodiments shown, but is consistent with the widest scope consistent with the principles and features disclosed in this application.

[0027] It should be noted that since the method of the embodiment of the present application is executed in a computer device, the processing objects of each computer device exist in the form of data or information. For example, time is actually time information. It can be understood that if size, quantity, position, etc. are mentioned in subsequent embodiments, the corresponding data exist for the computer device to process. The details will not be repeated here.

[0028] It should be noted that the artificial intelligence related technologies that may be involved in this application are briefly described. Artificial Intelligence (AI) is the theory, method, technology and application system that uses digital computers or machines controlled by digital computers to simulate, extend and expand human intelligence, perceive the environment, acquire knowledge and use knowledge to obtain the best results. In other words, artificial intelligence is a comprehensive technology in computer science that attempts to understand the essence of intelligence and produce a new type of intelligent machine that can respond in a similar way to human intelligence. Artificial intelligence is to study the design principles and implementation methods of various intelligent machines, so that machines have the functions of perception, reasoning and decision-making.

[0029] Artificial intelligence (AI) technology is a comprehensive discipline encompassing a wide range of fields, encompassing both hardware and software technologies. Foundational AI technologies generally include sensors, specialized AI chips, cloud computing, distributed storage, big data processing, operating / interaction systems, and mechatronics. AI software technologies primarily encompass computer vision, speech processing, natural language processing, and machine learning / deep learning.

[0030] Computer vision (CV) is the science of making machines "see." Specifically, it refers to machine vision, where cameras and computers replace the human eye in identifying and measuring objects, performing further image processing to create images more suitable for human observation or transmission to instruments. As a scientific discipline, computer vision studies related theories and technologies, attempting to build artificial intelligence systems capable of extracting information from images or multidimensional data. Computer vision technologies typically include image processing, image recognition, image semantic understanding, image retrieval, optical character recognition (OCR), video processing, video semantic understanding, video content / behavior recognition, three-dimensional object reconstruction, 3D technology, virtual reality, augmented reality, simultaneous localization and mapping, and common biometric recognition technologies such as facial recognition and fingerprint recognition.

[0031] Unimodal information is data consisting of only one type, such as text, images, audio, video, or electromagnetic signals. Multimodal information is data that includes at least two types of unimodal information. Furthermore, multimodal information is suitable for complex tasks that require integrating multiple information sources, such as sentiment analysis, robot interaction, and autonomous driving. By integrating information from multiple modalities, higher performance and accuracy can often be achieved on the task.

[0032] A large model refers to an artificial neural network model with a very large number of parameters. In the field of artificial intelligence, a large model generally refers to a model with hundreds of millions to trillions of parameters. Models usually need to be trained on large-scale data sets and require a large amount of computing resources to be optimized and adjusted. Large models are generally used to solve complex tasks such as natural language processing, computer vision, and speech recognition. Generative AI is an AI that can create new content and ideas, including conversations, stories, images, videos, and music. In the embodiment of the present application, the large model can be ChatGPT, BERT, XLNet, Zhipu model, Claude, Moonshot AI model, ChatGLM model, Tongwen Qianyi model, MiniMax model, Spark model, Llama model, 360GPT model, Qwen model, Baichuan model, Skylark model, vivoLM model, Wenxin Yiyan and other large-scale language models, which are not limited in the embodiment of the present application.

[0033] The embodiments of the present application provide a data processing method, apparatus, computer equipment, and computer-readable storage medium for intelligence data provenance analysis, which are described in detail below.

[0034] See also Figure 1 , Figure 1This is a schematic diagram of a scenario of a data processing system for intelligence data traceability analysis provided in an embodiment of the present application. The data processing system for intelligence data traceability analysis may include a computer device 100, in which a data processing device for intelligence data traceability analysis is integrated, such as Figure 1 Computer equipment in.

[0035] In the embodiment of the present application, the computer device 100 is mainly used to obtain basic network intelligence data information; the basic network intelligence data information includes H first network intelligence data information;

[0036] Classify and process the basic network intelligence data information to obtain target classification intelligence information; the target classification intelligence information includes M target network intelligence data information; each target network intelligence data information includes N target category intelligence information; each target category intelligence information includes L target intelligence data information; the target intelligence data information corresponds to the first network intelligence data information; L is an integer not less than 0;

[0037] Analyze and process target classification intelligence information to obtain target processing intelligence information.

[0038] It can improve the depth of network security intelligence data mining, improve the accuracy and efficiency of data analysis, and thus improve data traceability analysis capabilities and information accurate push capabilities, thereby improving users' experience in accurately obtaining network security data information.

[0039] In the embodiments of the present application, the computer device 100 may be an independent server, or a server network or server cluster composed of servers. For example, the computer device 100 described in the embodiments of the present application includes, but is not limited to, a computer, a network host, a single network server, a set of multiple network servers, or a cloud server composed of multiple servers. A cloud server is composed of a large number of computers or network servers based on cloud computing.

[0040] It is understood that the computer device 100 used in the embodiments of the present application can be a device that includes both receiving and transmitting hardware, that is, a device that has receiving and transmitting hardware capable of performing two-way communication over a two-way communication link. Such a device may include: a cellular or other communication device that has a single-line display, a multi-line display, or a cellular or other communication device without a multi-line display. The specific computer device 100 can be a desktop terminal or a mobile terminal. The computer device 100 can also be a mobile phone, a tablet computer, a laptop computer, etc.

[0041] Those skilled in the art will understand that Figure 1The application environment shown in the figure is only one application scenario of the present application solution and does not constitute a limitation on the application scenario of the present application solution. Other application environments may also include Figure 1 More or fewer computer devices as shown in Figure 1 Only one computer device is shown. It can be understood that the data processing system for intelligence data tracing and analysis can also include one or more other services, which are not specifically limited here.

[0042] In addition, if Figure 1 As shown, the data processing system for intelligence data tracing and analysis may further include a memory 200 for storing data, such as image data, location information, and the like.

[0043] It should be noted that Figure 1 The scenario diagram of the data processing system for intelligence data tracing and analysis shown is merely an example. The data processing system and scenario for intelligence data tracing and analysis described in the embodiment of the present application are intended to more clearly illustrate the technical solution of the embodiment of the present application, and do not constitute a limitation on the technical solution provided in the embodiment of the present application. A person of ordinary skill in the art will appreciate that with the evolution of the data processing system for intelligence data tracing and analysis and the emergence of new business scenarios, the technical solution provided in the embodiment of the present application is equally applicable to similar technical problems.

[0044] The present invention discloses a data processing method and device for intelligence data traceability analysis, which are beneficial for increasing the depth of network security intelligence data mining, improving the accuracy and efficiency of data analysis, and thereby enhancing data traceability and analysis capabilities and the ability to accurately push information, thereby improving the user experience of accurately obtaining network security data information. These are described in detail below.

[0045] Example 1

[0046] See also Figure 2 , Figure 2 This is a flow chart of a data processing method for intelligence data traceability analysis disclosed in an embodiment of the present invention. Figure 2 The data processing method for intelligence data traceability analysis described above is applied to a management system, such as a local server or cloud server for management, and is not limited in the embodiments of the present invention. Figure 2 As shown, the data processing method for intelligence data traceability analysis may include the following operations:

[0047] 101. Obtain basic network intelligence data information.

[0048] In the embodiment of the present invention, the basic network intelligence data information includes H first network intelligence data information.

[0049] 102. Classify and process basic network intelligence data information to obtain target classification intelligence information.

[0050] In an embodiment of the present invention, the target classification intelligence information includes M target network intelligence data information; each target network intelligence data information includes N target category intelligence information; each target category intelligence information includes L target intelligence data information; the target intelligence data information corresponds to the first network intelligence data information; L is an integer not less than 0.

[0051] 103. Analyze and process the target classification intelligence information to obtain target processing intelligence information.

[0052] It should be noted that the above H is a positive integer greater than 1, M is a positive integer greater than or equal to 1, and N is a positive integer greater than or equal to 1, which is not limited in the embodiment of the present invention.

[0053] It should be noted that the above-mentioned first network intelligence data information is collected from intelligence material sources such as websites, social platforms, scientific research databases, vulnerability libraries, etc. through multi-source heterogeneous cross-language security intelligence data collection technology, in order to break through the core technical points such as intelligence collection based on self-learning of subject knowledge, deep intelligence material collection for DeepWeb, and multi-search engine fusion collection, combined with MSNB anti-crawl technology for intelligence sources, to achieve real-time collection of security information such as global cyberspace strategy, industry status, equipment system, research hotspots, threats, etc., to provide data support for breakthroughs and verification of deep mining, correlation analysis, and network security intelligence trend perception technology of network security, which is not limited in the embodiments of the present invention.

[0054] Furthermore, the first network intelligence data information can be based on the self-learning of subject knowledge to collect intelligence. Focusing on the goal of being able to quickly obtain network security intelligence materials with targeted and focused requirements, from the aspects of subject representation model and subject knowledge expansion, a breakthrough in the focused intelligence collection technology based on subject knowledge self-learning is achieved, supporting and realizing the comprehensive and high-quality collection of intelligence materials driven by the subject. The embodiment of the present invention does not limit it. Its implementation process is: (1) Constructing a subject representation model. Before data collection, the user needs to describe the subject he wants to collect, that is, the subject representation model. The described subject is the subject knowledge. In order to reduce the complexity of the search and collection subject representation model and improve the ease of use and maintenance for users, the present invention constructs a triple subject representation model. The subject knowledge is described by a triple <I, E, C>, where I is a set of keywords directly related to the subject, E is a set of keywords that are contrary to the subject, and C is a feature vector composed of keywords that are indirectly related to the subject. Among them, the feature value of each keyword in C represents the degree of relevance between the keyword and the subject. The I set in the model refers to the keyword set that can fully represent the characteristics of the domain. To limit the scope of crawling and collection; the E set is used to filter documents that are not related to the topic, that is, they must not contain any keywords in the E set; the C vector enables the algorithm to quantitatively calculate the degree of topic relevance of web pages, URLs and keywords in web pages, so that the topic knowledge can be expanded according to the quantitative calculation results during the crawling and collection process, and the output web pages and URLs are sorted according to the degree of topic relevance. During initialization, the user only needs to give a small number of representative keywords and weights to construct the C vector, and the topic knowledge expansion algorithm will continuously expand and improve the C vector. In the above topic representation model, the user only needs to set a few keywords at the beginning, which makes it easier to describe the topic. (2) Topic knowledge expansion. The text of the data source contains a large amount of knowledge related to the topic. Making full use of the topic-related keywords contained in the text of the intelligence source and continuously expanding the topic knowledge can better solve the problem of insufficient description of user topic knowledge. In the process of technological breakthrough, the synonyms of the natural language of the topic or its subcategories are fully considered for improvement. The present invention will construct a topic vocabulary relevance evaluation formula to describe the ability of keywords to represent topics, as shown below:

[0055]

[0056] Among them, the function γ k Indicates the topic relevance of keywords x is a noun, df(x) represents the DF value of x, D represents the currently collected web page set, |D| is the size of the D set, γ k The definition of (x,d) is as follows:

[0057]

[0058] Where d is a web page, φ(x,d) is the set of sentences in the text of d that contain both x and keywords from set I; S(d) is the set of sentences in the text of d; tf(x,u) and tf(x,d) represent the TF values ​​of x in the anchor text of u and the text of d; and U(d) is the set of all URLs in web page d. The complexity of this calculation is linear in the number of web pages, and in the set I and the number of URLs in the web page. The number of nouns and URLs per web page is generally not large and will not grow indefinitely over time.

[0059] Furthermore, the first network intelligence data information can be the intelligence collected by deep mining of DeepWeb. In the network environment, the pages that can be directly accessed through the links on the web pages and can be accessed by search engines are ordinary web pages. Their content is briefly summarized and the core information is missing. Most of the effective, core and comprehensive information can only be accessed through the interactive interface in the user filling in the page and sending a query request to the site server to access the page with detailed intelligence information stored in the database, that is, Deep Web. Focusing on the basic requirements of obtaining comprehensive and in-depth intelligence material content driven by security, the present invention adopts the core technical points such as DeepWeb interface detection and result link noise elimination based on DeepWeb data source research to support the acquisition of high-quality intelligence materials from intelligence sources with DeepWeb characteristics, thereby improving the quality of intelligence material collection. The embodiments of the present invention are not limited. Further, (1) DeepWeb interface detection. To obtain DeepWeb data information, it is necessary to first discover the DeepWeb data source on the web page, that is, to determine the DeepWeb site page. The query interface page is the only entrance to the DeepWeb background database. The determination of the DeepWeb data source can be transformed into the query interface page detection problem. The present invention uses the HTML structure information of the web page form to extract features, thereby determining the Deep Web query interface page and interaction mode, and performing interface accuracy verification on this basis. In addition, in order to improve the matching coverage of the Deep Web query interface of the core intelligence source, a patterned Deep Web query interface configuration library is constructed to adapt to a variety of different coding styles. (2) Noise removal. In the field of topic search and collection, a large amount of noise content such as advertisements and navigation bars will cause topic drift. In order to improve the quality of search and collection, the present invention removes noise through style tree comparison denoising, retains core effective information, and is used to improve the efficiency and quality of WeepWeb deep mining.

[0060] Furthermore, the first network intelligence data information can be collected based on the fusion of multiple search engines. For a certain network security intelligence topic, the search results of a single search engine may produce incomplete content to be collected. At the same time, the noise in the search results will cause the content collected to be offset. In response to the above-mentioned problem of collecting network security intelligence materials based on search engines, the present invention removes noise from the search engine search results of multiple search engines such as Baidu, Google, Zhongsou, Sogou, Qihoo, Bing, iAsk, Yahoo, NetEase, Tieyi, Soso, and Daqi based on the collection topic, generates effective search result information focused on the topic, and weakens the adverse effects of excessive topic deviation. On this basis, the results of multiple search engines that have been noise-removed one by one are collected to provide effective and targeted support for subsequent intelligence material fusion processing, and weaken the impact of incomplete single search result information on the generation of high-quality intelligence. Ultimately, the intelligence material collection is comprehensive and effective, and the embodiments of the present invention are not limited thereto.

[0061] It should be noted that after analyzing and processing the target classification intelligence information and obtaining the target processing intelligence information, the target processing intelligence information can also be collaboratively produced, that is, through the collaborative management and control of intelligence and the evaluation of the quality of intelligence collaborative production, the integration of intelligence on key focus objects, cutting-edge technology, industrial development trends, network equipment systems, etc. can be achieved. (1) Collaborative management and control. After the intelligence materials are collected, identified, and analyzed, they will exist in the database in different forms. In order to form a complete intelligence product, it is necessary to conduct collaborative management and control of different intelligence of the same subject. The approach taken is described as follows: After the intelligence information enters the primary processing site, by setting keywords, automatically aggregating a certain subject information, or setting other conditions, the preliminary information is further screened and subdivided into the database. For information containing valid information elements, it is marked and edited. Through the data fusion technology integrated with intelligence collection technology, the intelligence is automatically summarized, automatically viewed, automatically proofread, and associated. Finally, according to the form of the intelligence product set, such as special research reports, special professional databases, and portal website releases, the information is processed and the final destination of the intelligence is determined. According to the development characteristics of different intelligence, it is necessary to establish a data template for the development of the intelligence industry. By tracking the intelligence information for a long time, we can find the turning points and hot spots of the information, and use this to mine valuable intelligence and carry out intelligence situation awareness. (2) Evaluation of the quality of collaborative intelligence production. For the same subject, different intelligence data are evaluated according to the nature, scope of application, purpose, and real-time nature of the intelligence content. The quality of intelligence is evaluated according to the five-level indicators of low, relatively low, medium, relatively high, and high based on the indicators of timeliness, accuracy, availability, comprehensiveness, and pertinence. This provides appropriate intelligence for different users and ensures that the intelligence content is readable, easy to use, and of high quality.

[0062] It should be noted that the data processing method for intelligence data tracing analysis of the present application is aimed at the needs of intelligence source analysis and intelligence propagation path analysis in the intelligence analysis process, as well as the need to determine the release source. The security intelligence tracing analysis technology performs tracing analysis on two types of intelligence data: text and code. It uses text similarity comparison technology and code intelligence comparison technology based on homology judgment, and combines it with type-based intelligence association analysis to implement tracing analysis of the release source and author for text, and implement tracing analysis of the release source and attacker for code. The embodiments of the present invention do not limit this.

[0063] It can be seen that implementing the data processing method for intelligence data tracing and analysis described in the embodiment of the present invention is conducive to improving the depth of network security intelligence data mining, improving data analysis accuracy and analysis efficiency, and thus improving data tracing and analysis capabilities and information accurate push capabilities, thereby improving users' experience in accurately obtaining network security data information.

[0064] In an optional embodiment, target classification intelligence information is analyzed and processed to obtain target processing intelligence information, including:

[0065] Based on the target classification intelligence information, target intelligence tracing information is determined; the target intelligence tracing information includes a plurality of first target tracing information;

[0066] Based on the target intelligence tracing information, the target processing intelligence information is determined.

[0067] It should be noted that each of the above-mentioned first target tracing information corresponds to a target intelligence data information, which is not limited in the embodiment of the present invention.

[0068] In this optional embodiment, as an optional implementation manner, the above-mentioned determination of target processing intelligence information based on target intelligence tracing information includes:

[0069] Obtain user attention information; user attention information includes several browsing history information;

[0070] generating a first association vector based on the number of views in the browsing record information in the user's attention information;

[0071] Using the browsing association model to statistically analyze the target classification intelligence information and the browsing record information to obtain a second association vector;

[0072] Performing element-by-element multiplication on the first correlation vector and the second correlation vector to obtain a target correlation vector;

[0073] The target category intelligence information corresponding to the maximum value of the vector element in the target association vector is used as the target association intelligence information;

[0074] The first target tracing information corresponding to all target intelligence data information in the target association intelligence information is used as the target push intelligence information in the target processing intelligence information.

[0075] It should be noted that the above browsing record information represents the number of times the user browses the intelligence category (target network intelligence data information) and intelligence subcategory (corresponding to the target category intelligence information), which is not limited in the embodiment of the present invention.

[0076] It should be noted that the generation of the first association vector based on the number of views in the browsing history information within the user's attention information is performed by sequentially populating the vector with all intelligence subcategories (corresponding to the target category intelligence information) in the order in which they appear, thereby obtaining the first association vector. This is not a limitation of the present embodiment. For example, if the intelligence subcategories are XL1, XL2, XL3, XL4, and XL5 (corresponding to N=5), and the number of user views is 1, 0, 2, 3, and 1, respectively, then the first association vector is (1, 0, 2, 3, 1).

[0077] It should be noted that the above-mentioned use of the browsing association model to perform statistical analysis on the target classification intelligence information and browsing history information to obtain the second association vector is first quantified using the browsing association model to quantify the user's browsing target classification intelligence information, and then fill it into the vector to form a second association vector with the same dimension as the first association vector. This is not limited in the embodiment of the present invention. Further, the browsing association model is:

[0078]

[0079] It should be noted that the above-mentioned element-by-element multiplication calculation process of the first correlation vector and the second correlation vector is to perform multiplication calculation on the vector elements corresponding to each position in the two vectors, which is not limited in the embodiment of the present invention.

[0080] It should be noted that the above-mentioned use of the target category intelligence information corresponding to the maximum value of the vector element in the target association vector as the target association intelligence information is to select the intelligence category that the user is currently most concerned about, thereby determining the current intelligence tracing information, that is, the target push intelligence information, and the embodiments of the present invention do not limit this.

[0081] It should be noted that after determining the target push intelligence information, data distribution can also be performed based on the user's intelligence subscription situation, that is, the target push intelligence information is sent to the user through intelligence data subscription processing, intelligence data distribution strategy configuration and intelligence data distribution, which is not limited in the embodiment of the present invention. (1) By accepting, parsing and reviewing the user subscription request, the subsequent distribution process is started. (2) Then the distribution strategy is configured, and the distribution strategy based on user subscription is configured according to the intention preference of the distributed user and different intelligence categories, and the data permission control strategy is customized for the visibility and availability of intelligence data. Among them, the user intention preference setting is obtained through intelligence data push based on user behavior intention mining and topic recommendation, or configured according to the user's subscription request; the distributed intelligence security intelligence data can be filtered or limited according to information such as intelligence type, area described by security intelligence data, target direction, recipient unit, data confidentiality level, etc., mainly including distribution data rule definition, distribution object rule definition, and distribution mode rule definition. The data permission control strategy can authorize and manage data resources such as shared intelligence data directory to ensure controlled access to the security intelligence data resource directory. (3) Finally, data distribution is carried out. Through the mapping relationship between intelligence subscription data orders and data resources, the extraction of structured and unstructured data is realized. In response to periodic subscription needs, data distribution tasks are controlled and managed according to the mode, priority, and effective time of the intelligence distribution strategy. Data extraction is carried out according to the correspondence between data elements, data themes and intelligence data, and distribution data loading services are provided.

[0082] It can be seen that implementing the data processing method for intelligence data tracing and analysis described in the embodiment of the present invention is conducive to improving the depth of network security intelligence data mining, improving data analysis accuracy and analysis efficiency, and thus improving data tracing and analysis capabilities and information accurate push capabilities, thereby improving users' experience in accurately obtaining network security data information.

[0083] In another optional embodiment, determining target intelligence tracing information based on target classification intelligence information includes:

[0084] For any target intelligence data information, the target intelligence data information is parsed and processed to obtain the intelligence data source information corresponding to the target intelligence data information;

[0085] Based on the intelligence data source information and the target intelligence data information, first target tracing information corresponding to the target intelligence data information is determined.

[0086] It should be noted that the above-mentioned determination of target intelligence tracing information based on target classification intelligence information is aimed at the needs of intelligence source analysis and intelligence propagation path analysis in the intelligence analysis process, as well as the need to determine the release source. The security intelligence tracing analysis technology performs tracing analysis on two types of intelligence data: text and code. It uses text similarity comparison technology and code intelligence comparison technology based on homology judgment, and combines it with intelligence association analysis based on the empty model to realize tracing analysis of the release source and author for text, and realize tracing analysis of the release source and attacker for code, thereby realizing intelligence tracing analysis of network security information. The embodiment of the present invention does not limit this.

[0087] It can be seen that implementing the data processing method for intelligence data tracing and analysis described in the embodiment of the present invention is conducive to improving the depth of network security intelligence data mining, improving data analysis accuracy and analysis efficiency, and thus improving data tracing and analysis capabilities and information accurate push capabilities, thereby improving users' experience in accurately obtaining network security data information.

[0088] In yet another optional embodiment, parsing the target intelligence data information to obtain intelligence data source information corresponding to the target intelligence data information includes:

[0089] Extracting information from the target intelligence data to obtain intelligence feature information corresponding to the target intelligence data;

[0090] Determine whether the information type corresponding to the target intelligence data information is a text type, and obtain a type determination result;

[0091] When the judgment result is yes, performing text normalization processing on the intelligence feature information to obtain first intelligence text information corresponding to the target intelligence data information;

[0092] Performing vectorization processing on the first intelligence text information to obtain second intelligence text information corresponding to the target intelligence data information;

[0093] Using the association calculation model, the second intelligence text information and all basic traceability text information in the traceability candidate text information are calculated and processed to obtain first association value information corresponding to the target intelligence data information; the first association value information includes a plurality of first association values;

[0094] Among them, the association calculation model is:

[0095]

[0096] Among them, DYGLZ represents the first correlation value; SY1 and SY2 represent the second intelligence text information and the basic traceability text information respectively; xs1 and xs2 represent the first calculation coefficient and the second calculation coefficient respectively;

[0097] The basic tracing text information corresponding to the largest first correlation value in the first correlation value information is used as the target tracing text information corresponding to the target intelligence data information;

[0098] Determine the text source information corresponding to the target traceability text information as the intelligence data source information corresponding to the target intelligence data information;

[0099] When the judgment result is no, the intelligence feature information is detected, analyzed and processed to obtain the intelligence data source information corresponding to the target intelligence data information.

[0100] It should be noted that the above information types include text types and code types, which are not limited in the embodiment of the present invention.

[0101] It should be noted that the above-mentioned information extraction of the target intelligence data information and the acquisition of the intelligence feature information corresponding to the target intelligence data information can be achieved based on a convolutional neural network, which is not limited in the embodiment of the present invention. Furthermore, a convolutional neural network is used to perform traceability analysis on two types of intelligence data, text and code. For text, traceability analysis of the release source and author is achieved, and for code, traceability analysis of the release source and attacker is achieved. This technology first parses the intelligence data and extracts the time, region, author and content information of the intelligence. This is not limited in the embodiment of the present invention. Furthermore, before extracting information from the target intelligence data information, the data can also be audited, that is, the integrity and accuracy of the intelligence data can be audited to ensure the validity of the traceability data. This is not limited in the embodiment of the present invention. Furthermore, after extracting information from the target intelligence data information, erroneous, invalid, and redundant data can be eliminated to provide valid input data for traceability analysis. This is not limited in the embodiment of the present invention.

[0102] It should be noted that the first calculation coefficient and the second calculation coefficient are positive numbers between 0 and 1, and the sum of the two is 1, which is not limited in the embodiment of the present invention.

[0103] It should be noted that the above-mentioned text standardization processing of the intelligence feature information removes the messy characters that affect the word segmentation effect, and directly deletes them or replaces them with spaces. In addition, since the computer does not consider the full-width and half-width formats of the same characters to be the same characters, the text characters need to be converted into full-width and half-width formats, which is not limited in the embodiments of the present invention.

[0104] It should be noted that the above-mentioned vectorization processing of the first intelligence text information is a process of converting it into a form that can be recognized by a computer. Furthermore, this application uses an n-gram algorithm to vectorize the text, that is, the content in the text is subjected to a sliding window operation of size n according to bytes, forming a byte segment sequence of length n, which is not limited in the embodiment of the present invention.

[0105] It should be noted that the above-mentioned basic traceability text information includes the publishing source and author information of the text, which is not limited in the embodiment of the present invention.

[0106] It should be noted that the above basic tracing text information is collected network text information pre-stored in the system, including the writing style, keywords, organizational unit information, publishing source and author information of the text, etc., and the embodiment of the present invention does not limit this.

[0107] It should be noted that the above-mentioned calculation and processing of the second intelligence text information and all the basic tracing text information in the tracing candidate text information using the association calculation model is to calculate the association between the representation vector corresponding to the second intelligence text information and the representation vector corresponding to the basic tracing text information using the association calculation model, thereby obtaining the similarity between the two, so as to select the directly related basic tracing text information, and then determine the publication source and author information of the corresponding pair of texts. The embodiments of the present invention do not limit this.

[0108] It can be seen that implementing the data processing method for intelligence data tracing and analysis described in the embodiment of the present invention is conducive to improving the depth of network security intelligence data mining, improving data analysis accuracy and analysis efficiency, and thus improving data tracing and analysis capabilities and information accurate push capabilities, thereby improving users' experience in accurately obtaining network security data information.

[0109] In yet another optional embodiment, detecting, analyzing, and processing the intelligence feature information to obtain intelligence data source information corresponding to the target intelligence data information includes:

[0110] Performing image mapping processing on the intelligence feature information to obtain mapped intelligence data information corresponding to the target intelligence data information;

[0111] Performing image texture feature extraction on the mapped intelligence data information to obtain intelligence feature data information corresponding to the target intelligence data information;

[0112] Perform homology analysis on the intelligence feature data information to obtain the intelligence data source information corresponding to the target intelligence data information.

[0113] It should be noted that the above-mentioned detection, analysis, and processing of intelligence feature information to obtain the intelligence data source information corresponding to the target intelligence data information mainly solves the problem of classifying and determining the family and source of the code by classifying the security code, and mining the malicious code or attack organization associated with the code, thereby laying the foundation for the construction of a network security defense system. In this application, a code homology determination technology based on deep learning is used to map the code binary file into a grayscale image, and the code is analyzed and detected based on the texture features of the image. This is not limited in the embodiments of the present invention.

[0114] It should be noted that the above-mentioned image mapping processing of the intelligence feature information to obtain the mapped intelligence data information corresponding to the target intelligence data information is a code image mapping of the malicious code based on the B2M algorithm, which is not limited in the embodiment of the present invention. For the malicious code executable file corresponding to the intelligence feature information, that is, the binary file, 8 bits are read as an unsigned integer (range 0-255), and the fixed line width is a vector. The entire file finally generates a two-dimensional array, which is visualized as a grayscale image (mapped intelligence data information). The range of each element in the two-dimensional array is 0-255, which is exactly the value range of each pixel in the grayscale image, that is, each array element corresponds to a pixel in the image, which is not limited in the embodiment of the present invention.

[0115] Image texture feature extraction is performed on the mapped intelligence data information to obtain intelligence feature data information corresponding to the target intelligence data information. This is achieved based on the GLCM extraction method, that is, by utilizing the spatial correlation between the grayscale elements of the image, by calculating the grayscale correlation between two pixels with a certain relative position relationship in the image, a grayscale co-occurrence matrix of the image is established, and the required feature quantities are statistically analyzed from this matrix to perform image texture feature analysis to obtain intelligence feature data information, such as contrast, inverse difference, autocorrelation, difference, second-order moment and entropy. These statistics include the frequency and dependency of pixel grayscale changes in the image in direction and distance, and are not limited in the embodiments of the present invention.

[0116] It should be noted that the above-mentioned homology analysis of the intelligence feature data information to obtain the intelligence data source information corresponding to the target intelligence data information is based on the code homology analysis of the convolutional neural network, which is not limited in the embodiment of the present invention. Furthermore, the malicious code homology analysis first needs to establish a labeled code sample library associated with the attack organization. For the large number of code samples collected, the public file analysis platform VirusTotal can be used to analyze and label them, and the malicious code attack organization can be analyzed with the help of network security expert knowledge to establish a code sample library. Finally, the code sample library is input into the convolutional neural network model for training, and the trained model is used for location malicious code family determination and attack organization identification analysis, which is not limited in the embodiment of the present invention.

[0117] It can be seen that implementing the data processing method for intelligence data tracing and analysis described in the embodiment of the present invention is conducive to improving the depth of network security intelligence data mining, improving data analysis accuracy and analysis efficiency, and thus improving data tracing and analysis capabilities and information accurate push capabilities, thereby improving users' experience in accurately obtaining network security data information.

[0118] In an optional embodiment, determining first target tracing information corresponding to the target intelligence data information based on the intelligence data source information and the target intelligence data information includes:

[0119] Performing data analysis on the target intelligence data using an intelligence correlation analysis model to obtain intelligence correlation information corresponding to the target intelligence data;

[0120] The intelligence data source information and the intelligence association information are integrated to obtain the first target tracing information corresponding to the target intelligence data information.

[0121] It should be noted that the above-mentioned intelligence-related information represents time-related information (such as release time, production time, etc.) and space-related information (such as release country, release website, etc.), which is not limited in the embodiment of the present invention.

[0122] It should be noted that the above-mentioned fusion processing of intelligence data source information and intelligence correlation information is to splice the two data to form traceability information representing the network security intelligence ship path to provide orderly intelligence traceability analysis results, which is not limited in the embodiments of the present invention.

[0123] It should be noted that if Figure 5 As shown, the intelligence association analysis model includes a first encoding module, a second encoding module, a third encoding module, a first convolution module, a second convolution module, a third convolution module, a first normalization module, a second normalization module, a first attention module, a second attention module, a third attention module and a first fusion module; wherein,

[0124] The input end of the first encoding module and the input end of the second encoding module are configured to receive the model input of the intelligence association analysis module; the output end of the first encoding module is respectively connected to the input end of the first attention module and the input end of the first normalization module; the output end of the first attention module is connected to the input end of the first normalization module; the output end of the first normalization module is connected to the input end of the first convolution module; the output end of the first convolution module is connected to the input end of the first fusion module; the output end of the second encoding module is respectively connected to the input end of the second attention module and the input end of the second normalization module; the output end of the second normalization module is connected to the input end of the second convolution module; the output end of the second convolution module is connected to the input end of the first fusion module; the output end of the first fusion module is connected to the input end of the third encoding module; the output end of the third encoding module is connected to the input end of the third attention module; the output end of the third attention module is connected to the input end of the third convolution module; the output end of the third convolution module is configured to output the model output of the intelligence association analysis module.

[0125] It should be noted that the above-mentioned model input represents target intelligence data information, and the model output represents intelligence association information, which is not limited in the embodiment of the present invention.

[0126] It should be noted that the above-mentioned first encoding module, second encoding module, and third encoding module are constructed based on position encoding operations, which is not limited in the embodiment of the present invention.

[0127] It should be noted that the convolution kernel size of the above-mentioned first convolution module, second convolution module, and third convolution module is 1×1, and the number of channels is 1, which is not limited in the embodiment of the present invention.

[0128] It should be noted that the above-mentioned first normalization module and second normalization module are constructed based on the maximum pooling layer, which is not limited in the embodiment of the present invention.

[0129] It should be noted that the first, second, and third attention modules described above are constructed based on a multi-head attention mechanism or a scaled attention mechanism, which is not limited in the present embodiment. Furthermore, the modules constructed based on the scaled attention mechanism are modules that perform a weighted sum of input information by at least two linear layers, input the weighted sum to a scaled convolution unit, perform a scaled dot product operation, and then multiply the sum with the output of one of the linear layers to output a data representation, which is not limited in the present embodiment.

[0130] It should be noted that the above-mentioned first fusion module is constructed based on the splicing operation, which is not limited in the embodiment of the present invention.

[0131] It should be noted that the above-mentioned intelligence correlation analysis module extracts features from time correlation information and space correlation information respectively through two parallel data processing branches, and then merges them into one branch to form a feature extraction analysis of the correlation relationship between time and space correlation information, thereby realizing in-depth analysis of time and space intelligence correlation information and tracing analysis of the time and space relationship of intelligence. The embodiments of the present invention do not limit this.

[0132] It should be noted that the above-mentioned intelligence association analysis module can be trained based on the cross-entropy loss function, with the iterative cycle training number of not less than 300 times. The training samples can be formed by users collecting network security intelligence data, clustering it, and then labeling it (such as using the file analysis platform VirusTotal for analysis and labeling). The embodiments of the present invention do not limit this.

[0133] It can be seen that implementing the data processing method for intelligence data tracing and analysis described in the embodiment of the present invention is conducive to improving the depth of network security intelligence data mining, improving data analysis accuracy and analysis efficiency, and thus improving data tracing and analysis capabilities and information accurate push capabilities, thereby improving users' experience in accurately obtaining network security data information.

[0134] In another optional embodiment, the basic network intelligence data information is classified and processed to obtain target classification intelligence information, including:

[0135] Performing word segmentation processing on the basic network intelligence data information to obtain first processed intelligence information;

[0136] performing vectorization processing on the first processed intelligence information to obtain second processed intelligence information;

[0137] performing normalization processing on the second processed intelligence information to obtain third processed intelligence information;

[0138] Serializing the third processing intelligence information to obtain fourth processing intelligence information;

[0139] The fourth processed intelligence information is identified and processed to obtain target classification intelligence information.

[0140] It should be noted that the above-mentioned word segmentation processing of the intelligence text information corresponding to the basic network intelligence data information is word segmentation of the first network intelligence data information to divide the text into words and vocabulary units, which is not limited in the embodiment of the present invention.

[0141] It should be noted that the above-mentioned vectorization processing of the first processing intelligence information is to convert text data into vectors using TF-IDF (TermFrequency-Inverse Document Frequency), which is not limited in the embodiment of the present invention.

[0142] It should be noted that the above-mentioned normalization processing of the second processing intelligence information uses Min-Max normalization to scale the data to the interval [0, 1], which is not limited in the embodiment of the present invention.

[0143] It should be noted that the above-mentioned serialization processing of the third processing intelligence information is to serialize the third processing intelligence information into a one-hot code to map each word or tag to a unique integer, which is not limited in the embodiment of the present invention.

[0144] It should be noted that the aforementioned identification processing of the fourth processed intelligence information to obtain target classification intelligence information involves first detecting and identifying the intelligence data corresponding to the fourth processed intelligence information using an intelligence recognition model constructed based on a long short-term memory network to obtain intelligence classification information (including intelligence major categories and intelligence minor categories, such as destructive programs and Trojans). This intelligence classification information is then associated with the corresponding basic network intelligence data information to obtain the corresponding target intelligence data information. Furthermore, although this is not limited in this embodiment of the present invention, the major intelligence categories correspond to the target network intelligence data information, and the minor intelligence categories correspond to the target category intelligence information.

[0145] Furthermore, the model training of the above intelligence recognition model is implemented based on the following methods:

[0146] A1 Training sample screening: Based on the results of hierarchical clustering analysis (using the fully connected agglomerative hierarchical clustering algorithm for clustering analysis, the basic steps include:

[0147] Aa1 classifies each intelligence material into a category and calculates the distance between each two categories, that is, calculates the similarity between samples. This process uses the Euclidean distance formula for calculation;

[0148] Aa2 finds the two closest classes between each class and classifies them into one class;

[0149] Aa3 recalculates the similarity between the newly generated class and each other class, and the calculation between classes is calculated using the Average Linkage calculation method;

[0150] Aa4 repeats steps Aa2 and Aa3 until all sample points are classified into one class, thereby forming training samples for each intelligence class) as training samples, and vectorizes and normalizes the samples;

[0151] A2 Modeling: Establish a basic recognition model corresponding to the long short-term memory network and set network structure parameters and training parameters;

[0152] A3 training: using the samples obtained in step A1 to train the basic recognition model (the loss function may be a cross entropy loss function, and the number of iterations is not less than 300) to obtain an intelligence recognition model;

[0153] A4 Self-Learning: Automatically conducts incremental training and updates the model with the assistance of cluster analysis results. Through the self-learning process, a recognition and classification system with adaptive capabilities is built.

[0154] It should be noted that the above-mentioned hierarchical clustering algorithm can partition the data set into a tree-like clustering structure, helping us interpret the clustering results using a visual approach. By clustering intelligence data, different types of intelligence can be divided and similar intelligence can be aggregated. Multiple clustering can discover emerging intelligence types, facilitating the discovery of new research hotspots and new device systems. This is not limited in the present embodiment.

[0155] It can be seen that implementing the data processing method for intelligence data tracing and analysis described in the embodiment of the present invention is conducive to improving the depth of network security intelligence data mining, improving data analysis accuracy and analysis efficiency, and thus improving data tracing and analysis capabilities and information accurate push capabilities, thereby improving users' experience in accurately obtaining network security data information.

[0156] Example 2

[0157] See also Figure 3 , Figure 3This is a structural diagram of a data processing device for intelligence data traceability analysis disclosed in an embodiment of the present invention. Figure 3 The described device can be applied to a management system, such as a local server or a cloud server for management, etc., and the embodiment of the present invention does not limit this. Figure 3 As shown, the device may include:

[0158] Acquisition module 201, used to acquire basic network intelligence data information; the basic network intelligence data information includes H first network intelligence data information;

[0159] The first processing module 202 is configured to classify the basic network intelligence data information to obtain target classification intelligence information; the target classification intelligence information includes M target network intelligence data information; each target network intelligence data information includes N target category intelligence information; each target category intelligence information includes L target intelligence data information; the target intelligence data information corresponds to the first network intelligence data information; L is an integer not less than 0;

[0160] The second processing module 203 is used to analyze and process the target classification intelligence information to obtain target processing intelligence information.

[0161] It can be seen that implementation Figure 3 The described data processing device for intelligence data tracing and analysis is conducive to improving the depth of network security intelligence data mining, improving data analysis accuracy and analysis efficiency, and thus improving data tracing and analysis capabilities and information accurate push capabilities, thereby improving users' experience in accurately obtaining network security data information.

[0162] In another optional embodiment, as Figure 3 As shown, target classification intelligence information is analyzed and processed to obtain target processing intelligence information, including:

[0163] Based on the target classification intelligence information, target intelligence tracing information is determined; the target intelligence tracing information includes a plurality of first target tracing information;

[0164] Based on the target intelligence tracing information, the target processing intelligence information is determined.

[0165] It can be seen that implementation Figure 3 The described data processing device for intelligence data tracing and analysis is conducive to improving the depth of network security intelligence data mining, improving data analysis accuracy and analysis efficiency, and thus improving data tracing and analysis capabilities and information accurate push capabilities, thereby improving users' experience in accurately obtaining network security data information.

[0166] In another optional embodiment, Figure 3 As shown, based on the target classification intelligence information, the target intelligence tracing information is determined, including:

[0167] For any target intelligence data information, the target intelligence data information is parsed and processed to obtain the intelligence data source information corresponding to the target intelligence data information;

[0168] Based on the intelligence data source information and the target intelligence data information, first target tracing information corresponding to the target intelligence data information is determined.

[0169] It can be seen that implementation Figure 3 The described data processing device for intelligence data tracing and analysis is conducive to improving the depth of network security intelligence data mining, improving data analysis accuracy and analysis efficiency, and thus improving data tracing and analysis capabilities and information accurate push capabilities, thereby improving users' experience in accurately obtaining network security data information.

[0170] In another optional embodiment, Figure 3 As shown, the target intelligence data information is parsed and processed to obtain the intelligence data source information corresponding to the target intelligence data information, including:

[0171] Extracting information from the target intelligence data to obtain intelligence feature information corresponding to the target intelligence data;

[0172] Determine whether the information type corresponding to the target intelligence data information is a text type, and obtain a type determination result;

[0173] When the judgment result is yes, performing text normalization processing on the intelligence feature information to obtain first intelligence text information corresponding to the target intelligence data information;

[0174] Performing vectorization processing on the first intelligence text information to obtain second intelligence text information corresponding to the target intelligence data information;

[0175] Using the association calculation model, the second intelligence text information and all basic traceability text information in the traceability candidate text information are calculated and processed to obtain first association value information corresponding to the target intelligence data information; the first association value information includes a plurality of first association values;

[0176] Among them, the association calculation model is:

[0177]

[0178] Among them, DYGLZ represents the first correlation value; SY1 and SY2 represent the second intelligence text information and the basic traceability text information respectively; xs1 and xs2 represent the first calculation coefficient and the second calculation coefficient respectively;

[0179] The basic tracing text information corresponding to the largest first correlation value in the first correlation value information is used as the target tracing text information corresponding to the target intelligence data information;

[0180] Determine the text source information corresponding to the target traceability text information as the intelligence data source information corresponding to the target intelligence data information;

[0181] When the judgment result is no, the intelligence feature information is detected, analyzed and processed to obtain the intelligence data source information corresponding to the target intelligence data information.

[0182] It can be seen that implementation Figure 3 The described data processing device for intelligence data tracing and analysis is conducive to improving the depth of network security intelligence data mining, improving data analysis accuracy and analysis efficiency, and thus improving data tracing and analysis capabilities and information accurate push capabilities, thereby improving users' experience in accurately obtaining network security data information.

[0183] In another optional embodiment, Figure 3 As shown, the intelligence feature information is detected and analyzed to obtain the intelligence data source information corresponding to the target intelligence data information, including:

[0184] Performing image mapping processing on the intelligence feature information to obtain mapped intelligence data information corresponding to the target intelligence data information;

[0185] Performing image texture feature extraction on the mapped intelligence data information to obtain intelligence feature data information corresponding to the target intelligence data information;

[0186] Perform homology analysis on the intelligence feature data information to obtain the intelligence data source information corresponding to the target intelligence data information.

[0187] It can be seen that implementation Figure 3 The described data processing device for intelligence data tracing and analysis is conducive to improving the depth of network security intelligence data mining, improving data analysis accuracy and analysis efficiency, and thus improving data tracing and analysis capabilities and information accurate push capabilities, thereby improving users' experience in accurately obtaining network security data information.

[0188] In another optional embodiment, Figure 3 As shown, based on the intelligence data source information and the target intelligence data information, determining the first target tracing information corresponding to the target intelligence data information includes:

[0189] Performing data analysis on the target intelligence data using an intelligence correlation analysis model to obtain intelligence correlation information corresponding to the target intelligence data;

[0190] The intelligence data source information and the intelligence association information are integrated to obtain the first target tracing information corresponding to the target intelligence data information.

[0191] It can be seen that implementation Figure 3 The described data processing device for intelligence data tracing and analysis is conducive to improving the depth of network security intelligence data mining, improving data analysis accuracy and analysis efficiency, and thus improving data tracing and analysis capabilities and information accurate push capabilities, thereby improving users' experience in accurately obtaining network security data information.

[0192] In another optional embodiment, Figure 3 As shown, the basic network intelligence data information is classified and processed to obtain target classification intelligence information, including:

[0193] Performing word segmentation processing on the basic network intelligence data information to obtain first processed intelligence information;

[0194] performing vectorization processing on the first processed intelligence information to obtain second processed intelligence information;

[0195] performing normalization processing on the second processed intelligence information to obtain third processed intelligence information;

[0196] Serializing the third processing intelligence information to obtain fourth processing intelligence information;

[0197] The fourth processed intelligence information is identified and processed to obtain target classification intelligence information.

[0198] It can be seen that implementation Figure 3 The described data processing device for intelligence data tracing and analysis is conducive to improving the depth of network security intelligence data mining, improving data analysis accuracy and analysis efficiency, and thus improving data tracing and analysis capabilities and information accurate push capabilities, thereby improving users' experience in accurately obtaining network security data information.

[0199] Example 3

[0200] See also Figure 4 , Figure 4 This is a structural diagram of another data processing device for intelligence data traceability analysis disclosed in an embodiment of the present invention. Figure 4 The described device can be applied to a management system, such as a local server or a cloud server for management, etc., and the embodiment of the present invention does not limit this. Figure 4 As shown, the device may include:

[0201] A memory 301 storing executable program code;

[0202] a processor 302 coupled to the memory 301;

[0203] The processor 302 calls the executable program code stored in the memory 301 to execute the steps of the data processing method for intelligence data tracing and analysis described in the first embodiment.

[0204] Example 4

[0205] An embodiment of the present invention discloses a computer-readable storage medium that stores a computer program for electronic data exchange, wherein the computer program enables a computer to execute the steps of the data processing method for intelligence data tracing and analysis described in Example 1.

[0206] Example 5

[0207] An embodiment of the present invention discloses a computer program product, which includes a non-transitory computer-readable storage medium storing a computer program, and the computer program is operable to enable a computer to execute the steps of the data processing method for intelligence data tracing and analysis described in Example 1.

[0208] The device embodiments described above are merely illustrative. Modules described as separate components may or may not be physically separate, and components shown as modules may or may not be physical modules, i.e., they may be located in one place or distributed across multiple network modules. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.

[0209] Through the detailed description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus the necessary general hardware platform, or of course, by means of hardware. Based on this understanding, the above technical solution, in essence, or the portion that contributes to the prior art, can be embodied in the form of a software product, which can be stored in a computer-readable storage medium, including a read-only memory (ROM), a random access memory (RAM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), a one-time programmable read-only memory (OTPROM), an electronically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, magnetic disk storage, magnetic tape storage, or any other computer-readable medium capable of carrying or storing data.

[0210] Finally, it should be noted that the data processing method and device for intelligence data tracing and analysis disclosed in the embodiments of the present invention are only preferred embodiments of the present invention, and are only used to illustrate the technical solutions of the present invention, rather than to limit them. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features therein may be replaced by equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A data processing method for intelligence data traceability analysis, characterized in that: The method comprises: Obtaining basic network intelligence data information; the basic network intelligence data information includes H first network intelligence data information; Classifying the basic network intelligence data information to obtain target classification intelligence information; the target classification intelligence information includes M target network intelligence data information; each target network intelligence data information includes N target category intelligence information; each target category intelligence information includes L target intelligence data information; the target intelligence data information corresponds to the first network intelligence data information; L is an integer not less than 0; Analyzing and processing the target classification intelligence information to obtain target processing intelligence information; The analyzing and processing of the target classification intelligence information to obtain target processing intelligence information includes: Based on the target classification intelligence information, target intelligence tracing information is determined; the target intelligence tracing information includes a plurality of first target tracing information; Determining target processing intelligence information based on the target intelligence tracing information; The step of determining target intelligence tracing information based on the target classification intelligence information includes: For any of the target intelligence data information, the target intelligence data information is parsed and processed to obtain the intelligence data source information corresponding to the target intelligence data information; Based on the intelligence data source information and the target intelligence data information, determining first target tracing information corresponding to the target intelligence data information; The step of parsing the target intelligence data information to obtain intelligence data source information corresponding to the target intelligence data information includes: Extracting information from the target intelligence data to obtain intelligence feature information corresponding to the target intelligence data; Determine whether the information type corresponding to the target intelligence data information is a text type, and obtain a type determination result; When the judgment result is yes, performing text normalization processing on the intelligence feature information to obtain first intelligence text information corresponding to the target intelligence data information; Performing vectorization processing on the first intelligence text information to obtain second intelligence text information corresponding to the target intelligence data information; Using an association calculation model, calculation is performed on the second intelligence text information and all basic source tracing text information in the source tracing candidate text information to obtain first association value information corresponding to the target intelligence data information; the first association value information includes a plurality of first association values; Wherein, the association calculation model is: Wherein, DYGLZ represents the first correlation value; SY1 and SY2 represent the second intelligence text information and the basic traceability text information respectively; xs1 and xs2 represent the first calculation coefficient and the second calculation coefficient respectively; The basic tracing text information corresponding to the largest first correlation value in the first correlation value information is used as the target tracing text information corresponding to the target intelligence data information; Determine the text source information corresponding to the target traceability text information as the intelligence data source information corresponding to the target intelligence data information; When the judgment result is no, the intelligence feature information is detected, analyzed and processed to obtain intelligence data source information corresponding to the target intelligence data information.

2. The data processing method for intelligence data source tracing analysis according to claim 1, characterized in that: The detecting, analyzing, and processing the intelligence feature information to obtain intelligence data source information corresponding to the target intelligence data information includes: Performing image mapping processing on the intelligence feature information to obtain mapped intelligence data information corresponding to the target intelligence data information; Performing image texture feature extraction on the mapped intelligence data information to obtain intelligence feature data information corresponding to the target intelligence data information; Perform homology analysis on the intelligence feature data information to obtain intelligence data source information corresponding to the target intelligence data information.

3. The data processing method for intelligence data source tracing analysis according to claim 1, characterized in that: The determining, based on the intelligence data source information and the target intelligence data information, first target tracing information corresponding to the target intelligence data information includes: Performing data analysis on the target intelligence data using an intelligence correlation analysis model to obtain intelligence correlation information corresponding to the target intelligence data; The intelligence data source information and the intelligence association information are fused to obtain the first target tracing information corresponding to the target intelligence data information.

4. The data processing method for intelligence data source tracing analysis according to claim 1, characterized in that: The classifying and processing the basic network intelligence data information to obtain target classification intelligence information includes: Performing word segmentation processing on the basic network intelligence data information to obtain first processed intelligence information; performing vectorization processing on the first processing intelligence information to obtain second processing intelligence information; performing normalization processing on the second processing intelligence information to obtain third processing intelligence information; Serializing the third processing intelligence information to obtain fourth processing intelligence information; The fourth processed intelligence information is identified and processed to obtain target classification intelligence information.

5. A data processing device for intelligence data tracing and analysis, characterized in that: The device comprises: An acquisition module, configured to acquire basic network intelligence data information; the basic network intelligence data information includes H first network intelligence data information; a first processing module configured to classify the basic network intelligence data information to obtain target classification intelligence information; the target classification intelligence information includes M target network intelligence data information; each target network intelligence data information includes N target category intelligence information; each target category intelligence information includes L target intelligence data information; the target intelligence data information corresponds to the first network intelligence data information; and L is an integer not less than 0; A second processing module is used to analyze and process the target classification intelligence information to obtain target processing intelligence information; The analyzing and processing of the target classification intelligence information to obtain target processing intelligence information includes: Based on the target classification intelligence information, target intelligence tracing information is determined; the target intelligence tracing information includes a plurality of first target tracing information; Determining target processing intelligence information based on the target intelligence tracing information; The step of determining target intelligence tracing information based on the target classification intelligence information includes: For any of the target intelligence data information, the target intelligence data information is parsed and processed to obtain the intelligence data source information corresponding to the target intelligence data information; Based on the intelligence data source information and the target intelligence data information, determining first target tracing information corresponding to the target intelligence data information; The step of parsing the target intelligence data information to obtain intelligence data source information corresponding to the target intelligence data information includes: Extracting information from the target intelligence data to obtain intelligence feature information corresponding to the target intelligence data; Determine whether the information type corresponding to the target intelligence data information is a text type, and obtain a type determination result; When the judgment result is yes, performing text normalization processing on the intelligence feature information to obtain first intelligence text information corresponding to the target intelligence data information; Performing vectorization processing on the first intelligence text information to obtain second intelligence text information corresponding to the target intelligence data information; Using an association calculation model, calculation is performed on the second intelligence text information and all basic source tracing text information in the source tracing candidate text information to obtain first association value information corresponding to the target intelligence data information; the first association value information includes a plurality of first association values; Wherein, the association calculation model is: Wherein, DYGLZ represents the first correlation value; SY1 and SY2 represent the second intelligence text information and the basic traceability text information respectively; xs1 and xs2 represent the first calculation coefficient and the second calculation coefficient respectively; The basic tracing text information corresponding to the largest first correlation value in the first correlation value information is used as the target tracing text information corresponding to the target intelligence data information; Determine the text source information corresponding to the target traceability text information as the intelligence data source information corresponding to the target intelligence data information; When the judgment result is no, the intelligence feature information is detected, analyzed and processed to obtain intelligence data source information corresponding to the target intelligence data information.

6. A data processing device for intelligence data traceability analysis, characterized in that: The device comprises: a memory storing executable program code; a processor coupled to the memory; The processor calls the executable program code stored in the memory to execute the data processing method for intelligence data tracing and analysis as described in any one of claims 1 to 4.

7. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, which, when called, are used to execute the data processing method for intelligence data tracing and analysis as described in any one of claims 1 to 4.

Citation Information

Patent Citations

  • Network security intelligence collection method, device, equipment and storage medium

    CN110413864A

  • TTP information mining method and device based on threat intelligence, medium and electronic equipment

    CN118427636A