Information providing object evaluation method, device and equipment based on threat information
By integrating and processing network security intelligence data, building multiple intelligence databases and performing weighted evaluations, the problems of inconsistent intelligence data quality and lack of a unified evaluation system in the existing technology are solved, and effective assessment of the objects provided by intelligence and accurate identification of network security threats are achieved.
Patent Information
- Application Number
- CN202510209431.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-25
- Publication Date
- 2025-06-13
AI Technical Summary
When integrating and utilizing network security intelligence data, the existing technology has problems such as incomplete data quality and lack of unified data standards and evaluation systems, making it difficult to accurately identify and early warning of network security threats.
By obtaining external and internal threat intelligence data, deduplication and classification processing, multiple intelligence databases are built, and evaluation indicator parameters are determined based on the number of threat intelligence in the intelligence database, and weighted operations are performed to obtain the evaluation results of the intelligence-provided object.
It realizes an objective and impartial assessment of the intelligence contribution to the objects provided by the intelligence, and improves the accuracy of intelligence analysis and the application effect of the network security situation awareness platform.
Smart Images

Figure CN120144555A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of big data, and particularly to a method, device, and equipment for evaluating intelligence providing objects based on threat intelligence. Background Art
[0002] With the rapid development of the financial industry, security threats in the cyber space are increasing day by day. In particular, cyber attacks against financial data show the characteristics of high frequency and diversification. As the lifeblood of the economic system, the network security of the financial industry is not only related to the stable development of the industry, but also directly related to the fund security and privacy protection of the majority of users.
[0003] To cope with cyber security threats, the financial industry has generally established a cyber security situation awareness platform. This platform realizes real-time monitoring and early warning of security threats such as cyber attacks and vulnerabilities by aggregating data from various cyber security intelligence vendors. These intelligence data cover multiple dimensions such as the types, sources, targets, and impact scopes of cyber attacks, providing rich security intelligence support for the financial industry.
[0004] However, there are still some problems in integrating and utilizing these intelligence data in the existing technology. The data quality of each intelligence vendor is uneven, and some data have problems such as false, redundant, and incomplete, which affect the accurate identification and early warning of security threats by the platform. At the same time, due to the lack of unified data standards and evaluation systems, the platform cannot effectively evaluate and compare the data of each intelligence vendor, and it is difficult to select high-quality intelligence data sources. Summary of the Invention
[0005] This application provides a method, device, and equipment for evaluating intelligence providing objects based on threat intelligence to solve the problem of the lack of unified evaluation and comparison of intelligence providing objects in the existing technology.
[0006] In a first aspect, this application provides a method for evaluating an intelligence providing object based on threat intelligence, including:
[0007] Obtain external threat intelligence data and internal threat intelligence data. The external threat intelligence data is provided by multiple intelligence providing objects, and the internal threat intelligence data is provided by an internal organization that has suffered an attack;
[0008] Perform deduplication and classification processing on the external threat intelligence data and the internal threat intelligence data to obtain multiple intelligence libraries. Among them, each intelligence providing object corresponds to multiple intelligence libraries;
[0009] For any one of the multiple intelligence providing objects, based on the number of threat intelligence in the multiple intelligence libraries corresponding to the intelligence providing object, determine multiple evaluation index parameters corresponding to the intelligence providing object;
[0010] Perform a weighted operation on the multiple evaluation index parameters to obtain an evaluation result of the intelligence provider object, where the evaluation result is used to indicate the intelligence contribution degree of the intelligence provider object.
[0011] In a second aspect, the present application provides an evaluation device for an intelligence provider object based on threat intelligence, including:
[0012] An acquisition module, configured to acquire external threat intelligence data and internal threat intelligence data, where the external threat intelligence data is provided by multiple intelligence provider objects, and the internal threat intelligence data is provided by an internal organization that has been attacked;
[0013] A processing module, configured to perform deduplication and classification processing on the external threat intelligence data and the internal threat intelligence data to obtain multiple intelligence databases, where each intelligence provider object corresponds to multiple intelligence databases;
[0014] A determination module, configured to, for any one intelligence provider object among the multiple intelligence provider objects, determine multiple evaluation index parameters corresponding to the intelligence provider object based on the number of threat intelligence in the multiple intelligence databases corresponding to the intelligence provider object;
[0015] A processing module, configured to perform a weighted operation on the multiple evaluation index parameters to obtain an evaluation result of the intelligence provider object, where the evaluation result is used to indicate the intelligence contribution degree of the intelligence provider object.
[0016] In a third aspect, the present application provides an electronic device, including: a processor and a memory communicatively connected to the processor;
[0017] The memory stores computer-executable instructions;
[0018] The processor executes the computer-executable instructions stored in the memory to implement the method for evaluating an intelligence provider object based on threat intelligence as described in the first aspect and various possible implementation manners of the first aspect.
[0019] In a fourth aspect, the present application provides a computer-readable storage medium, on which computer-executable instructions are stored, and when the computer-executable instructions are executed by a processor, they are used to implement the method for evaluating an intelligence provider object based on threat intelligence as described in the first aspect and various possible implementation manners of the first aspect.
[0020] In a fifth aspect, the present application provides a program product, including a computer program, and when the computer program is executed by a processor, it implements the method for evaluating an intelligence provider object based on threat intelligence as described above.
[0021] The threat intelligence-based information provider evaluation method, device, and equipment provided by this application integrate external and internal threat intelligence data. By removing duplicate information and conducting detailed classification, multiple intelligence databases are constructed. For any information provider, a series of evaluation index parameters are set based on the number of threat intelligence in multiple associated intelligence databases. Subsequently, weighted calculations are performed on these parameters to obtain the comprehensive evaluation result of this information provider, which directly reflects its intelligence contribution degree. This method not only deeply explores the internal relationship between intelligence data, enhances the accuracy of intelligence analysis, but also ensures an objective and fair assessment of the capabilities and service quality of each intelligence provider through the construction of a multi-dimensional evaluation system and the comprehensive application of algorithms. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] The accompanying drawings herein are incorporated into the specification and form a part of this specification, showing embodiments consistent with this application, and are used together with the specification to explain the principles of this application.
[0023] Figure 1 Schematic flowchart of a threat intelligence-based information provider evaluation method provided by this application Figure 1 ;
[0024] Figure 2 Schematic flowchart of a threat intelligence-based information provider evaluation method provided by this application Figure 2 ;
[0025] Figure 3 Schematic flowchart of a threat intelligence-based information provider evaluation method provided by this application Figure 3 ;
[0026] Figure 4 Schematic flowchart of a threat intelligence-based information provider evaluation method provided by this application Figure 4 ;
[0027] Figure 5 Schematic flowchart of a threat intelligence-based information provider evaluation method provided by this application Figure 5 ;
[0028] Figure 6 Schematic structural diagram of a threat intelligence-based information provider evaluation device provided by this application;
[0029] Figure 7 Schematic structural diagram of a threat intelligence-based information provider evaluation equipment provided by this application.
[0030] Through the above-mentioned drawings, specific embodiments of the present application have been shown, and will be described in more detail hereinafter. These drawings and the written description are not intended to limit the scope of the concept of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by reference to specific embodiments. Detailed Description of the Embodiments
[0031] Here, exemplary embodiments will be described in detail, and examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.
[0032] It should be noted that the method, apparatus, and device for evaluating an intelligence providing object based on threat intelligence provided by the present application can be used in the field of big data and can also be used in any field other than big data. The application fields of the method, apparatus, and device for evaluating an intelligence providing object based on threat intelligence in the present application are not limited.
[0033] With the rapid development of the financial industry, security threats in the cyberspace are increasing day by day, especially network attacks against financial data showing the characteristics of high frequency and diversification. As the lifeblood of the economic system, the network security of the financial industry not only concerns the stable development of the industry, but also directly relates to the fund security and privacy protection of the vast number of users. Therefore, the financial industry's demand for network security intelligence is becoming increasingly urgent, and it is necessary to rely on high-quality intelligence data to timely discover and respond to potential security threats.
[0034] However, the current financial industry faces many challenges in network security intelligence. On the one hand, due to the complex and sensitive business involved in the financial industry and the continuous innovation of network attack means, the collection and analysis of network security intelligence have become extremely difficult; on the other hand, there are many network security intelligence vendors in the market, and the formats, contents, qualities, etc. of the intelligence data provided by each are uneven, lacking a unified standard and evaluation system, resulting in great difficulties for the financial industry in integrating and utilizing these intelligence data.
[0035] To cope with network security threats, the financial industry has generally established a network security situation awareness platform, which realizes real-time monitoring and early warning of security threats such as network attacks and vulnerabilities by aggregating data from various network security intelligence vendors. These intelligence data cover multiple dimensions such as the type, source, target, and impact range of network attacks, providing rich security intelligence support for the financial industry.
[0036] However, there are still some problems in the integration and utilization of these intelligence data in the existing technology. First, due to the differences in data formats and contents among various intelligence providers, the platform needs to spend a lot of time and effort on format conversion and content integration when receiving and processing these data. Second, the data quality of each intelligence provider varies, and some data have problems such as false, redundant, and incomplete, which affect the accurate identification and early warning of security threats by the platform. Finally, due to the lack of a unified data standard and evaluation system, the platform cannot effectively evaluate and compare the data of each intelligence provider, making it difficult to select high-quality intelligence data sources and restricting the application effect of the network security situation awareness platform in the financial industry.
[0037] To address the above problems, the intelligence provider object evaluation method based on threat intelligence provided in this application constructs a unified intelligence standard system for cyber attack intelligence, aiming to integrate threat intelligence data from multiple intelligence provider objects. By applying big data and artificial intelligence technologies, a comprehensive evaluation standard system is established from multiple dimensions such as data scale, data timeliness, and data accuracy, and various evaluation indicators are calculated accordingly. On this basis, according to the weights assigned to each indicator, multiple algorithms are used for comprehensive calculation, and finally specific scores and rankings are obtained, thus constructing a complete evaluation system to comprehensively evaluate intelligence service provider objects.
[0038] The specific application of this application in network security protection can objectively and fairly evaluate the strength and service level of each intelligence provider through the establishment of multi-dimensional evaluation criteria and the comprehensive application of algorithms, providing more scientific and reliable intelligence support for decision-makers.
[0039] The following uses specific embodiments to elaborate in detail on the technical solutions of this application and how the technical solutions of this application solve the above technical problems. These several specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of this application will be described below with reference to the accompanying drawings.
[0040] Figure 1 Flow schematic of an intelligence provider object evaluation method based on threat intelligence provided for an embodiment of this application Figure 1 As Figure 1 shown, the intelligence provider object evaluation method based on threat intelligence provided in this embodiment includes:
[0041] S101: Obtain external threat intelligence data and internal threat intelligence data.
[0042] Among them, the external threat intelligence data is provided by multiple intelligence provider objects, and the internal threat intelligence data is provided by the internal organization that has been attacked.
[0043] It is understandable that to ensure the timeliness and effectiveness of data, threat intelligence data for the most recent month is usually obtained to evaluate the intelligence providers. External threat intelligence data mainly comes from multiple intelligence providers, which may be professional research institutions or other organizations with security monitoring and data analysis capabilities. They collect and organize information on potential threats, vulnerabilities, attack methods, etc. through various channels such as the Internet and the dark web. Internal threat intelligence data is provided by internal organizations that have suffered attacks or discovered security incidents, and can be compared with external threat intelligence data to judge the accuracy of the data provided by the intelligence providers.
[0044] S102: Dedup and classify the external threat intelligence data and internal threat intelligence data to obtain multiple intelligence repositories.
[0045] Among them, each intelligence provider corresponds to multiple intelligence repositories.
[0046] It is understandable that due to the wide range of external and internal intelligence sources, the data may be duplicated and cross-referenced. Therefore, it is necessary to deduplicate the collected intelligence data to ensure the uniqueness of each piece of intelligence. At the same time, to make more effective use of this intelligence, it is also necessary to classify the intelligence, such as dividing it according to dimensions such as threat level and network address. Each intelligence provider will correspond to multiple different types of intelligence repositories according to the types and quantities of the intelligence it provides, which is convenient for subsequent analysis and evaluation.
[0047] S103: For any one of the multiple intelligence providers, based on the quantity of threat intelligence in the multiple intelligence repositories corresponding to the intelligence provider, determine multiple evaluation index parameters corresponding to the intelligence provider.
[0048] It is understandable that for each intelligence provider, we need to evaluate the quality and contribution of its intelligence. This can be achieved by analyzing the quantity of threat intelligence in the multiple intelligence repositories it provides. The evaluation index parameters include: high-risk identification rate, high-risk confirmation rate, and high-risk contribution rate, etc. These parameters can comprehensively reflect the intelligence production capacity, professionalism, and reliability of the intelligence provider. For the specific determination method of the evaluation index parameters, please refer to the following text and will not be elaborated here.
[0049] S104: Perform weighted arithmetic processing on the multiple evaluation index parameters to obtain the evaluation result of the intelligence provider.
[0050] Among them, the evaluation result is used to indicate the intelligence contribution of the intelligence provider.
[0051] It is understandable that since different evaluation index parameters have different importance for evaluating the contribution degree of the intelligence provider object, it is necessary to perform weighted operation processing on these parameters. The weights of the weighted operation can be set according to actual needs and experience. Usually, the weights are a fixed set of values within a period of time to ensure the fairness and accuracy of the evaluation results. The finally obtained evaluation results will be used to indicate the intelligence contribution degree of the intelligence provider object, providing an important reference for subsequent intelligence collection, analysis, and utilization. At the same time, this evaluation process also helps to motivate the intelligence provider object to improve the quality and timeliness of intelligence, jointly promoting the improvement of the network security protection level.
[0052] An evaluation method for an intelligence provider object based on threat intelligence provided in this embodiment. This method obtains external threat intelligence data and internal threat intelligence data, and performs deduplication and classification processing on the external threat intelligence data and the internal threat intelligence data to obtain multiple intelligence databases. For any one of the multiple intelligence provider objects, based on the number of threat intelligence in the multiple intelligence databases corresponding to the intelligence provider object, multiple evaluation index parameters corresponding to the intelligence provider object are determined. Perform weighted operation processing on the multiple evaluation index parameters to obtain the evaluation result of the intelligence provider object, and the evaluation result is used to indicate the intelligence contribution degree of the intelligence provider object. This method deeply mines the correlation information in the intelligence data, improves the accuracy of intelligence analysis, and through the establishment of multi-dimensional evaluation criteria and the comprehensive application of algorithms, can objectively and fairly evaluate the strength and service level of each intelligence provider.
[0053] Figure 2 It is a flow diagram of an evaluation method for an intelligence provider object based on threat intelligence provided in an embodiment of the present application Figure 2 As Figure 2 shown, on the basis of the Figure 1 embodiment, a possible implementation manner of generating multiple intelligence databases is described in detail, including:
[0054] S201: Perform deduplication processing on the internal threat intelligence data to generate an internal intelligence database.
[0055] It is understandable that the internal threat intelligence data is usually provided by the enterprise's internal security team or the affected business departments. These data may contain duplicate information, such as the same security incident reported multiple times or similar attack patterns. In order to improve the efficiency and accuracy of subsequent analysis, it is first necessary to perform deduplication processing on these internal threat intelligence data. The deduplication process can include processing according to the network protocol address (Internet Protocol Address, abbreviated as IP address) of each threat intelligence, processing according to the affected systems, etc. After deduplication, all the remaining data is saved to generate an internal intelligence database. During the evaluation process, there is only one internal intelligence database.
[0056] S202: Parse, extract, and process the internal threat intelligence data in the internal intelligence database according to the preset ban identifier to generate an internal disposal intelligence database.
[0057] It can be understood that in order to effectively respond to security threats and other information that has emerged, internal agencies usually ban these threats and mark the banned or blocked intelligence according to the preset ban identifier. After obtaining the internal threat intelligence, it is possible to determine which threat intelligence has been processed and banned according to the preset ban identifier. Extract and save this processed and banned intelligence to generate an internal disposal intelligence database. During the evaluation process, there is only one internal disposal intelligence.
[0058] S203: For any one of the multiple intelligence providing objects, deduplicate the external threat intelligence data to generate an intelligence summary deduplication database.
[0059] It can be understood that the intelligence providing objects may provide intelligence on the same or similar threats. To avoid duplicate processing of the same intelligence in subsequent analysis, it is necessary to deduplicate the external threat intelligence data. This process may involve comparing different fields of the intelligence, such as threat type, target system, attack method, etc., to ensure that each retained intelligence is independent and represents a different threat. After deduplicating the external threat intelligence data of all intelligence providing objects, a summary deduplication database will be generated, that is, an intelligence summary deduplication database. During the evaluation process, the number of intelligence summary deduplication databases corresponds to the number of intelligence providing objects.
[0060] S204: Parse, extract, and process the external threat intelligence data in the intelligence summary deduplication database according to the high-risk identifier to generate a high-risk intelligence database.
[0061] It can be understood that the external threat intelligence data in the intelligence summary deduplication database may cover various threat types and severity levels. To prioritize the threats that pose the greatest risk to the enterprise, it is necessary to parse and extract the intelligence according to the preset high-risk identifier. The high-risk identifier may be set based on factors such as the severity of the threat, the scope of influence, and the exploitable nature. By matching these high-risk identifiers, the intelligence that requires special attention can be extracted from the intelligence summary deduplication database. These parsed and extracted high-risk intelligence will form a high-risk intelligence database, providing an important basis for the enterprise's security defense and emergency response. During the evaluation process, the number of high-risk intelligence databases corresponds to the number of intelligence providing objects.
[0062] A method for evaluating intelligence providers based on threat intelligence provided in this embodiment generates an internal intelligence library by deduplicating internal threat intelligence data. Parsing and extracting the internal threat intelligence data in the internal intelligence library according to a preset ban identifier generates an internal disposal intelligence library. For any one of multiple intelligence providers, deduplicate the external threat intelligence data to generate an intelligence summary deduplication library. Parsing and extracting the external threat intelligence data in the intelligence summary deduplication library according to a high-risk identifier generates a high-risk intelligence library. This method divides threat intelligence into multiple intelligence libraries, which can clarify the quantity of threat intelligence provided by each intelligence provider in each category, making intelligence analysis more efficient.
[0063] Figure 3 The flowchart of a method for evaluating intelligence providers based on threat intelligence provided by an embodiment of the present application Figure 3 As Figure 3 shown, on the basis of the Figure 1 embodiment, a possible implementation manner for generating a high-risk intelligence trust library is described in detail, including:
[0064] S301: Integrate the high-risk intelligence libraries of all intelligence providers to obtain a high-risk intelligence set.
[0065] It can be understood that intelligence providers may be different security organizations and research institutions, all of which are constantly collecting and analyzing intelligence on network threats. Each intelligence provider has its own high-risk intelligence library, which stores threat intelligence that they consider important and urgent. To make more effective use of this intelligence, these intelligence are merged into a unified data set, that is, a high-risk intelligence set.
[0066] S302: Classify the high-risk intelligence set according to the network addresses of the external threat intelligence to obtain multiple first high-risk intelligences.
[0067] It can be understood that the integrated high-risk intelligence set is classified according to the network addresses of the external threat intelligence. The network address is the key information for identifying the threat source. Therefore, we will divide the intelligence into multiple groups according to this information, and the intelligence within each group points to the same network address. In this way, multiple first high-risk intelligences are obtained, each representing a specific network threat source.
[0068] S303: Determine whether the quantity of the first high-risk intelligence is greater than a preset value.
[0069] It is understandable that in order to determine which network addresses are the real threat foci, we need to judge whether the number of the first high-risk intelligence corresponding to each network address is greater than a preset value. This preset value is set according to the enterprise security policy, and it represents the minimum number that we consider a network address is concerned by the intelligence providers.
[0070] S304: When the number of the first high-risk intelligence is greater than the preset value, extract the first high-risk intelligence and determine it as the second high-risk intelligence.
[0071] It is understandable that if the number of the first high-risk intelligence of a certain network address exceeds the preset value, then we can consider that this network address is an important threat source. In this case, we will extract these first high-risk intelligence and determine them as the second high-risk intelligence. For example, the preset value can be 3. If the number of the first high-risk intelligence of a certain network address exceeds 3, that is, this network address is marked as high-risk intelligence by 4 or more intelligence providers, the threat intelligence of this network address needs to be paid attention to.
[0072] S305: Integrate and process the second high-risk intelligence to obtain a high-risk intelligence trusted library.
[0073] It is understandable that finally, we will integrate and process the intelligence determined as the second high-risk intelligence again to form a high-risk intelligence trusted library. The intelligence in this library has all been strictly screened and confirmed, and has high credibility and importance. During the evaluation process, there is only one high-risk intelligence trusted library.
[0074] An intelligence provider evaluation method based on threat intelligence provided in this embodiment, this method integrates and processes the high-risk intelligence libraries of all intelligence providers to obtain a high-risk intelligence set. Classify and process the high-risk intelligence set according to the network addresses of external threat intelligence to obtain multiple first high-risk intelligence; the network addresses of each first high-risk intelligence are the same. When the number of the first high-risk intelligence is greater than the preset value, extract the first high-risk intelligence and determine it as the second high-risk intelligence. Integrate and process the second high-risk intelligence to obtain a high-risk intelligence trusted library. This method integrates multiple high-risk intelligence libraries, classifies, extracts and integrates key intelligence to form a high-risk intelligence trusted library, effectively improving the comprehensiveness, accuracy and processing efficiency of intelligence.
[0075] Figure 4 It is a flow diagram of an intelligence provider evaluation method based on threat intelligence provided in an embodiment of the present application Figure 4 As Figure 4 shown, on the basis of Figure 1 the embodiment, a possible implementation manner of generating a high-risk intelligence first report library is described in detail, including:
[0076] S401: Classify the high-risk intelligence database according to the network addresses in the external threat intelligence to obtain multiple third high-risk intelligence items.
[0077] Among them, the network addresses of each third high-risk intelligence item are the same and come from the same intelligence provider.
[0078] It can be understood that for the high-risk intelligence database of an intelligence provider, the threat intelligence therein is classified according to the network addresses, and the intelligence with the same network address is grouped into a set of third high-risk intelligence items. After classification according to the network addresses, multiple third high-risk intelligence items can be obtained.
[0079] S402: Determine the first moment when the third high-risk intelligence item first appears.
[0080] It can be understood that the third high-risk intelligence item is a combination of intelligence with the same network address in an intelligence provider. According to the data of each piece of intelligence, the appearance moment of each piece of intelligence is obtained, and the earliest moment among all the appearance moments is selected as the first moment corresponding to this third high-risk intelligence item.
[0081] S403: Determine the second moment when the first high-risk intelligence item first appears.
[0082] It can be understood that the first high-risk intelligence item is a combination of intelligence with the same network address among all intelligence providers. Similarly, the earliest appearance moment among the intelligence with the same network address is selected as the second moment of the first high-risk intelligence item.
[0083] S404: According to the network addresses of the third high-risk intelligence item and the first high-risk intelligence item, determine whether the first moment of the same network address is equal to the second moment.
[0084] It can be understood that for each intelligence provider, according to the network address of its first high-risk intelligence item, the intelligence with the same network address is queried in the third high-risk intelligence item, and then the first moment and the second moment corresponding to the two pieces of intelligence are compared. Determine whether the first moment is equal to the second moment.
[0085] S405: When the first moment is equal to the second moment, extract the high-risk intelligence corresponding to the network address and generate a high-risk intelligence first report database.
[0086] It can be understood that if it can be understood, then the first high-risk intelligence item is extracted to generate a high-risk intelligence first report database. The equality of the first moment and the second moment also indicates that for the threat intelligence of this network address, the corresponding intelligence provider was the first to discover and report it, and the intelligence provided by this intelligence provider has relatively high timeliness. During the evaluation process, the number of high-risk intelligence first report databases corresponds to the number of intelligence providers.
[0087] A method for evaluating an information providing object based on threat intelligence provided in this embodiment classifies a high-risk information database according to the network addresses of external threat intelligence to obtain multiple third high-risk informations; the network addresses of each third high-risk information are the same and come from the same information providing object. Determine the first moment when the third high-risk information first appears. Determine the second moment when the first high-risk information first appears. According to the network addresses of the third high-risk information and the first high-risk information, determine whether the first moment of the same network address is equal to the second moment. If the first moment is equal to the second moment, extract the high-risk information corresponding to the network address and generate a high-risk information first report database. By comparing the first appearance times of informations under the same network address, this method accurately extracts and generates a high-risk information first report database, effectively improving the timeliness and accuracy of information processing.
[0088] Figure 5 Schematic flow of a method for evaluating an information providing object based on threat intelligence provided in an embodiment of the present application Figure 5 As Figure 5 shown, based on the Figure 1 embodiment, a possible implementation manner for determining evaluation index parameters is described in detail, including:
[0089] S501: Determine a high-risk recognition rate according to the number of threat intelligence in the high-risk information database and the high-risk information trusted database.
[0090] It can be understood that the high-risk recognition rate is used to evaluate the coverage of high-risk IP information provided by an information providing object (information provider), that is, the proportion of high-risk information provided by the information providing object among all high-risk information. The high-risk recognition rate is equal to the number of threat intelligence in the high-risk information database / the number of threat intelligence in the high-risk information trusted database.
[0091] S502: Determine a high-risk first report rate according to the number of threat intelligence in the high-risk information first report database and the information summary and duplicate removal database.
[0092] It can be understood that the high-risk first report rate is used to evaluate the timeliness of high-risk information provided by an information providing object. The high-risk first report rate is equal to the number of threat intelligence in the high-risk information first report database / the number of threat intelligence in the information summary and duplicate removal database. The high-risk first report rate is not only a quantitative indicator, but also an indicator reflecting the comprehensive ability of the information providing object in information collection, analysis and reporting. A high high-risk first report rate usually means that the object has high sensitivity and professionalism in intelligence work and can timely discover and report intelligence information that poses a major threat to social stability or enterprise operation, etc.
[0093] S503: Perform a matching process on the high-risk information database and the internal information database to obtain a first matching information.
[0094] Among them, the first matching information is threat intelligence with the same network address and located in the high-risk intelligence database and the internal intelligence database respectively.
[0095] It can be understood that the high-risk intelligence database is a collection of high-risk intelligence provided by external agencies, and the internal intelligence database is a collection of intelligence generated by internal agencies suffering attacks. Matching the high-risk intelligence database and the internal intelligence database aims to screen out from the collection of high-risk intelligence provided by external agencies the threat intelligence that matches the intelligence generated by internal agencies suffering attacks, that is, to find the first matching information with the same network address, which helps to evaluate the accuracy of intelligence collection and analysis by external agencies, and thus judge the reliability of their intelligence services.
[0096] S504: Determine the high-risk confirmation rate according to the number of the first matching information and the number of threat intelligence in the high-risk intelligence database.
[0097] It can be understood that the high-risk confirmation rate is used to evaluate the situation of the high-risk intelligence provided by the intelligence provider being feedback by the financial institution. The high-risk confirmation rate is equal to the number of the first matching information / the number of threat intelligence in the high-risk intelligence database, that is, the proportion of the number of the first matching information (that is, the intelligence that exists in both the high-risk intelligence database and the internal intelligence database and has the same network address) in the total number of threat intelligence in the high-risk intelligence database, and is used to measure the efficiency and effect of the cooperation between the intelligence provider and the financial institution.
[0098] S505: Perform matching processing on the high-risk intelligence first report database and the internal intelligence database to obtain the second matching information.
[0099] It can be understood that the second matching information is threat intelligence with the same network address and located in the high-risk intelligence first report database and the internal intelligence database respectively. The high-risk intelligence first report database is a collection of intelligence first proposed by the intelligence provider compared with other providers. The matching of such intelligence not only reveals potential network security threats, but also reflects the timeliness and accuracy of the intelligence.
[0100] S506: Determine the first report high-risk confirmation rate according to the number of the second matching information and the number of threat intelligence in the high-risk intelligence database.
[0101] It is understandable that the first report high-risk confirmation rate is used to evaluate the situation where the first report high-risk intelligence provided by the intelligence provider is feedback by the financial institution. The first report high-risk confirmation rate is equal to the number of the second matching intelligence / the number of threat intelligence in the high-risk intelligence database. This indicator directly reflects the accuracy and practicality of the first report high-risk intelligence submitted by the intelligence provider. When the first report high-risk confirmation rate is relatively high, it means that a relatively large proportion of the first report high-risk intelligence submitted by the intelligence provider has been confirmed and feedback by the financial institution, which reflects the professional quality of the intelligence provider and the sensitivity of intelligence collection. On the contrary, if the first report high-risk confirmation rate is relatively low, it may indicate that there are many false reports or missed reports in the first report high-risk intelligence submitted by the intelligence provider, or the intelligence collection and analysis capabilities need to be improved.
[0102] Optionally, the evaluation indicators also include: high-risk contribution rate and high-risk accuracy rate. The specific determination method is as follows:
[0103] Perform matching processing on the high-risk intelligence database and the internal disposal intelligence database to obtain the third matching intelligence. The third matching intelligence is the threat intelligence with the same network address and located in the high-risk intelligence database and the internal disposal intelligence database respectively.
[0104] It is understandable that the third matching intelligence reflects the high-risk intelligence provided by the intelligence provider that has been internally identified and blocked. The number of the third matching intelligence can verify the effectiveness of the intelligence in the high-risk intelligence database and improve the reliability of the intelligence provider.
[0105] Determine the high-risk contribution rate according to the number of the third matching intelligence and the number of threat intelligence in the internal disposal intelligence database.
[0106] It is understandable that the high-risk contribution rate is used to evaluate the contribution of the high-risk intelligence provided by the intelligence provider to the blocking or interruption work of the financial institution. The high-risk contribution rate is equal to the number of the third matching intelligence / the number of threat intelligence in the internal disposal intelligence database. When the high-risk contribution rate is relatively high, it indicates that the high-risk intelligence provided by the intelligence provider plays an important role in the network security protection of the financial institution and effectively reduces the network security risk. On the contrary, when the high-risk contribution rate is relatively low, it may mean that the quality of the high-risk intelligence provided by the intelligence provider is not high or the practicality is not strong.
[0107] Determine the high-risk accuracy rate according to the number of the third matching intelligence and the number of threat intelligence in the high-risk intelligence database.
[0108] It is understandable that the high-risk accuracy rate is used to evaluate the precision of the effective high-risk intelligence provided by the intelligence provider. It reflects the professional ability and accuracy of the intelligence provider in intelligence collection and analysis. The high-risk accuracy rate is equal to the number of the third-matched intelligence / the number of threat intelligence in the high-risk intelligence database. A high high-risk accuracy rate means that the high-risk intelligence provided by the intelligence provider has a high credibility and practicality, and can accurately reflect the actual situation of network security threats.
[0109] Optionally, the evaluation indicators also include: the first-report high-risk contribution rate and the first-report high-risk accuracy rate. The specific determination method is as follows:
[0110] Perform matching processing on the first-report high-risk intelligence database and the internal disposal intelligence database to obtain the fourth-matched intelligence. The fourth-matched intelligence is the threat intelligence with the same network address and located in the first-report high-risk intelligence database and the internal disposal intelligence database respectively.
[0111] It is understandable that the determination of the fourth-matched intelligence first verifies the timeliness and accuracy of the high-risk intelligence provided by the intelligence provider. When the intelligence in the first-report high-risk intelligence database matches the intelligence in the internal disposal intelligence database, it indicates that the intelligence provider has discovered and reported the threat in the first time, and the threat indeed exists and has been identified and processed by the internal security team. This proves that the intelligence provider has a keen threat perception ability and accurate intelligence analysis ability.
[0112] Determine the first-report high-risk contribution rate according to the number of the fourth-matched intelligence and the number of threat intelligence in the internal disposal intelligence database.
[0113] It is understandable that the first-report high-risk contribution rate is used to evaluate the contribution of the first-report high-risk intelligence provided by the intelligence provider to the blocking or interception work of financial institutions. The first-report high-risk contribution rate is equal to the number of the fourth-matched intelligence / the number of threat intelligence in the internal disposal intelligence database. A high first-report high-risk contribution rate indicates that the first-report high-risk intelligence provided by the intelligence provider is timely and accurate, enabling the internal organization to discover and block and intercept the high-risk threat intelligence in time.
[0114] Determine the first-report high-risk accuracy rate according to the number of the fourth-matched intelligence and the number of threat intelligence in the high-risk intelligence database.
[0115] It is understandable that the first-report high-risk accuracy rate is used to evaluate the precision of the first-report high-risk intelligence provided by the intelligence provider. The first-report high-risk accuracy rate is equal to the number of the fourth-matched intelligence / the number of threat intelligence in the high-risk intelligence database. A high first-report high-risk accuracy rate will enhance the trust of financial institutions in the intelligence provider, believing that it can provide timely, accurate and reliable threat intelligence.
[0116] Optionally, the evaluation indicators also include: the traceability support rate. The specific determination method is as follows:
[0117] Determine the number of threat intelligence that meets the preset geographical judgment conditions in the intelligence summary deduplication library.
[0118] It can be understood that the preset geographical judgment condition is a geographical determination condition preset in advance, which is used to judge whether the threat intelligence address provided by the intelligence provider meets the requirements. For example, the preset geographical judgment condition can be that the address information of the threat intelligence must be accurate to a specific province and city. Aggregate all the threat intelligence in the intelligence summary deduplication library that meets the preset geographical judgment conditions and determine the number of threat intelligence, so as to analyze the accuracy of the threat intelligence subsequently.
[0119] Determine the traceability support rate according to the number of threat intelligence and the number of intelligence in the intelligence summary deduplication library.
[0120] It can be understood that the traceability support rate is used to evaluate whether the threat intelligence provided by the intelligence provider has traceability information. The traceability support rate is equal to the number of threat intelligence / the number of intelligence in the intelligence summary deduplication library. The traceability information can reveal the true source and usage of the IP address, which helps to verify the authenticity and reliability of the intelligence.
[0121] An intelligence provider evaluation method based on threat intelligence provided in this embodiment, this method calculates key indicators such as high-risk recognition rate, high-risk first report rate, high-risk confirmation rate, first report high-risk confirmation rate, high-risk contribution rate, and first report high-risk accuracy rate by comparing data such as the high-risk intelligence library, the high-risk intelligence trusted library, the intelligence summary deduplication library, and the internal intelligence library. At the same time, this method also judges the proportion of threat intelligence that meets the preset geographical conditions in the intelligence summary deduplication library to determine the traceability support rate. This series of operations effectively improves the accuracy and efficiency of intelligence analysis, realizes the rapid identification, confirmation and disposal of high-risk intelligence, and enhances the timeliness and practicality of intelligence. In addition, by calculating various indicators, this method also provides strong data support for subsequent intelligence analysis and decision-making, further improving the overall effectiveness of intelligence work.
[0122] Figure 6 It is a structural schematic diagram of an intelligence provider evaluation device based on threat intelligence provided by this application. As Figure 6 shown, this application provides an intelligence provider evaluation device based on threat intelligence. The intelligence provider evaluation device 600 based on threat intelligence includes:
[0123] An acquisition module 601, configured to acquire external threat intelligence data and internal threat intelligence data. The external threat intelligence data is provided by multiple intelligence providers, and the internal threat intelligence data is provided by an internal organization that has been attacked;
[0124] A processing module 602 is configured to perform deduplication and classification processing on the external threat intelligence data and the internal threat intelligence data to obtain multiple intelligence databases, where multiple intelligence databases correspond to each intelligence provider;
[0125] A determination module 603 is configured to, for any one of the multiple intelligence providers, determine multiple evaluation index parameters corresponding to the intelligence provider based on the number of threat intelligence in the multiple intelligence databases corresponding to the intelligence provider;
[0126] The processing module 602 is configured to perform weighted operation processing on the multiple evaluation index parameters to obtain an evaluation result of the intelligence provider, where the evaluation result is used to indicate the intelligence contribution degree of the intelligence provider.
[0127] Optionally, the processing module 602 is further configured to perform deduplication processing on the internal threat intelligence data to generate an internal intelligence database;
[0128] The processing module 602 is further configured to perform parsing and extraction processing on the internal threat intelligence data in the internal intelligence database according to a preset ban identifier to generate an internal disposal intelligence database;
[0129] The processing module 602 is further configured to, for any one of the multiple intelligence providers, perform deduplication processing on the external threat intelligence data to generate an intelligence summary deduplication database;
[0130] The processing module 602 is further configured to perform parsing and extraction processing on the external threat intelligence data in the intelligence summary deduplication database according to a high-risk identifier to generate a high-risk intelligence database.
[0131] Optionally, the apparatus further includes: a judgment module 604;
[0132] The processing module 602 is further configured to perform integration processing on the high-risk intelligence databases of all the intelligence providers to obtain a high-risk intelligence set;
[0133] The processing module 602 is further configured to perform classification processing on the high-risk intelligence set according to the network address of the external threat intelligence, to obtain multiple first high-risk intelligences; the network addresses of each of the first high-risk intelligences are the same;
[0134] The judgment module 604 is configured to judge whether the number of the first high-risk intelligences is greater than a preset value;
[0135] The determination module 603 is further configured to, when the number of the first high-risk intelligences is greater than the preset value, extract the first high-risk intelligence and determine it as a second high-risk intelligence;
[0136] The processing module 602 is further configured to integrate and process the second high-risk intelligence to obtain a high-risk intelligence trust library.
[0137] Optionally, the device further includes a generation module 605;
[0138] The processing module 602 is further configured to classify the high-risk intelligence library according to the network addresses of the external threat intelligence to obtain a plurality of third high-risk intelligence; the network addresses of each third high-risk intelligence are the same and come from the same intelligence provider;
[0139] The determination module 603 is further configured to determine a first moment when the third high-risk intelligence first appears;
[0140] The determination module 603 is further configured to determine a second moment when the first high-risk intelligence first appears;
[0141] The judgment module 604 is further configured to judge whether the first moment of the same network address is equal to the second moment according to the network addresses of the third high-risk intelligence and the first high-risk intelligence;
[0142] The generation module 605 is configured to extract the high-risk intelligence corresponding to the network address and generate a high-risk intelligence first report library when the first moment is equal to the second moment.
[0143] Optionally, the determination module 603 is further configured to determine a high-risk recognition rate according to the number of threat intelligence in the high-risk intelligence library and the high-risk intelligence trust library;
[0144] The determination module 603 is further configured to determine a high-risk first report rate according to the number of threat intelligence in the high-risk intelligence first report library and the intelligence summary and deduplication library.
[0145] Optionally, the processing module 602 is further configured to perform matching processing on the high-risk intelligence library and the internal intelligence library to obtain first matching intelligence, where the first matching intelligence is threat intelligence with the same network address and located in the high-risk intelligence library and the internal intelligence library respectively;
[0146] The determination module 603 is further configured to determine a high-risk confirmation rate according to the number of the first matching intelligence and the number of threat intelligence in the high-risk intelligence library;
[0147] The processing module 602 is further configured to perform matching processing on the high-risk intelligence first report library and the internal intelligence library to obtain second matching intelligence, where the second matching intelligence is threat intelligence with the same network address and located in the high-risk intelligence first report library and the internal intelligence library respectively;
[0148] The determining module 603 is further configured to determine a first report high-risk confirmation rate according to the quantity of the second matching intelligence and the quantity of threat intelligence in the high-risk intelligence database.
[0149] Optionally, the processing module 602 is further configured to perform matching processing on the high-risk intelligence database and the internal disposal intelligence database to obtain third matching intelligence, where the third matching intelligence is threat intelligence with the same network address and located in the high-risk intelligence database and the internal disposal intelligence database respectively;
[0150] The determining module 603 is further configured to determine a high-risk contribution rate according to the quantity of the third matching intelligence and the quantity of threat intelligence in the internal disposal intelligence database;
[0151] The determining module 603 is further configured to determine a high-risk accuracy rate according to the quantity of the third matching intelligence and the quantity of threat intelligence in the high-risk intelligence database.
[0152] Optionally, the processing module 602 is further configured to perform matching processing on the high-risk intelligence first report database and the internal disposal intelligence database to obtain fourth matching intelligence, where the fourth matching intelligence is threat intelligence with the same network address and located in the high-risk intelligence first report database and the internal disposal intelligence database respectively;
[0153] The determining module 603 is further configured to determine a first report high-risk contribution rate according to the quantity of the fourth matching intelligence and the quantity of threat intelligence in the internal disposal intelligence database;
[0154] The determining module 603 is further configured to determine a first report high-risk accuracy rate according to the quantity of the fourth matching intelligence and the quantity of threat intelligence in the high-risk intelligence database.
[0155] Optionally, the determining module 603 is further configured to determine the quantity of threat intelligence in the intelligence summary deduplication database that meets the preset geographical judgment condition;
[0156] The determining module 603 is further configured to determine a traceability support rate according to the quantity of the threat intelligence and the quantity of intelligence in the intelligence summary deduplication database.
[0157] The intelligence providing object evaluation device based on threat intelligence provided by the embodiments of the present application has a similar implementation principle and technical effect to the implementation manners of each part in the foregoing intelligence providing object evaluation method based on threat intelligence, and will not be elaborated herein.
[0158] Figure 7 It is a structural schematic diagram of an intelligence providing object evaluation device based on threat intelligence provided by the present application. As Figure 7As shown in the figure, the present application provides an intelligence providing object evaluation device based on threat intelligence. The intelligence providing object evaluation device 700 based on threat intelligence includes: a receiver 701, a transmitter 702, a processor 703, and a memory 704.
[0159] The receiver 701 is configured to receive instructions and data;
[0160] The transmitter 702 is configured to transmit instructions and data;
[0161] The memory 704 is configured to store computer-executable instructions;
[0162] The processor 703 is configured to execute the computer-executable instructions stored in the memory 704 to implement each step executed by the method in the above-mentioned embodiments. For details, reference may be made to the relevant descriptions in the foregoing method embodiments.
[0163] Optionally, the above-mentioned memory 704 can be either independent or integrated with the processor 703.
[0164] When the memory 704 is independently provided, the electronic device further includes a bus for connecting the memory 704 and the processor 703.
[0165] For the implementation principle and technical effects of the electronic device provided in this embodiment, reference may be made to the foregoing embodiments, which will not be elaborated herein.
[0166] The present application embodiment also provides a computer-readable storage medium, in which computer-executable instructions are stored. When the processor executes the computer-executable instructions, the method described in any of the foregoing embodiments is implemented.
[0167] The present application embodiment also provides a computer program product, including a computer program, which implements the method described in any of the foregoing embodiments when executed by the processor.
[0168] It should be noted that, for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present application is not limited by the described action sequence, because according to the present application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to the present application.
[0169] It should be understood that the above-described device embodiments are merely illustrative, and the devices of the present application can also be implemented in other ways. For example, the division of units / modules in the above embodiments is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units, modules, or components can be combined, or can be integrated into another system, or some features can be ignored or not executed.
[0170] In the above embodiments, the descriptions of the respective embodiments have their own focuses. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments. The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered that the scope described in this specification is covered.
[0171] Those skilled in the art will readily conceive of other embodiments of the present application after considering the specification and practicing the invention disclosed herein. The present application is intended to cover any variations, uses, or adaptations of the present application, which follow the general principles of the present application and include the common general knowledge or conventional technical means in the technical field not disclosed in the present application. The specification and the embodiments are only regarded as exemplary, and the true scope and spirit of the present application are pointed out by the following claims.
[0172] It should be understood that the present application is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present application is only limited by the appended claims.
Claims
1. A method for evaluating an intelligence provider based on threat intelligence, characterized in that: include: Acquire external threat intelligence data and internal threat intelligence data, wherein the external threat intelligence data is provided by multiple intelligence providers, and the internal threat intelligence data is provided by an internal organization that has been attacked; Deduplication and classification are performed on the external threat intelligence data and the internal threat intelligence data to obtain multiple intelligence libraries, wherein each intelligence provider corresponds to multiple intelligence libraries; For any one of the multiple intelligence providing objects, based on the amount of threat intelligence in multiple intelligence repositories corresponding to the intelligence providing object, determine multiple evaluation index parameters corresponding to the intelligence providing object; A weighted operation is performed on the plurality of evaluation index parameters to obtain an evaluation result of the information providing object, wherein the evaluation result is used to indicate the information contribution of the information providing object.
2. The method according to claim 1, characterized in that The intelligence library includes: an internal intelligence library, an internal disposal intelligence library, an intelligence summary deduplication library, and a high-risk intelligence library. The external threat intelligence and the internal threat intelligence are deduplicated and classified to obtain multiple intelligence libraries, including: Deduplication processing is performed on the internal threat intelligence data to generate an internal intelligence database; Parsing and extracting the internal threat intelligence data in the internal intelligence database according to the preset blocking mark to generate an internal disposal intelligence database; For any one of the multiple intelligence providing objects, deduplication processing is performed on the external threat intelligence data to generate an intelligence summary deduplication library; According to the high-risk identification, the external threat intelligence data in the intelligence summary and deduplication database is parsed and extracted to generate a high-risk intelligence database.
3. The method according to claim 2, characterized in that The intelligence database further includes: a high-risk intelligence trustworthy database, and the method further includes: Integrate the high-risk intelligence databases of all the intelligence providing objects to obtain a high-risk intelligence collection; According to the network address of the external threat intelligence, the high-risk intelligence set is classified and processed to obtain a plurality of first high-risk intelligences; the network address of each of the first high-risk intelligences is the same; Determining whether the amount of the first high-risk intelligence is greater than a preset value; When the amount of the first high-risk intelligence is greater than a preset value, extracting the first high-risk intelligence and determining it as the second high-risk intelligence; The second high-risk intelligence is integrated and processed to obtain a high-risk intelligence credible database.
4. The method according to claim 3, characterized in that The intelligence database further includes: a high-risk intelligence initial report database, and the method further includes: According to the network address of the external threat intelligence, the high-risk intelligence library is classified and processed to obtain a plurality of third high-risk intelligences; the network address of each of the third high-risk intelligences is the same and comes from the same intelligence provider; Determine the first moment when the third high-risk intelligence first appears; Determine a second moment when the first high-risk intelligence first appears; According to the network addresses of the third high-risk intelligence and the first high-risk intelligence, determining whether the first time at the same network address is equal to the second time; When the first moment is equal to the second moment, high-risk intelligence corresponding to the network address is extracted, and a high-risk intelligence first report library is generated.
5. The method according to claim 4, characterized in that The evaluation indicators include: high-risk identification rate and high-risk first report rate. The number of threat intelligence in multiple intelligence repositories corresponding to the intelligence provider is determined based on the number of threat intelligence in multiple intelligence repositories corresponding to the intelligence provider, and multiple evaluation indicator parameters corresponding to the intelligence provider are determined, including: Determining a high-risk identification rate according to the amount of threat intelligence in the high-risk intelligence library and the high-risk intelligence trusted library; The high-risk first report rate is determined according to the number of threat intelligence in the high-risk intelligence first report database and the intelligence summary and deduplication database.
6. The method according to claim 5, characterized in that The evaluation index also includes: high-risk confirmation rate and first-report high-risk confirmation rate, and the method also includes: Matching the high-risk intelligence database with the internal intelligence database to obtain first matching intelligence, where the first matching intelligence is threat intelligence with the same network address and located in the high-risk intelligence database and the internal intelligence database respectively; Determining a high-risk confirmation rate according to the amount of the first matching intelligence and the amount of threat intelligence in the high-risk intelligence library; Matching the high-risk intelligence first report library and the internal intelligence library to obtain second matching intelligence, where the second matching intelligence is threat intelligence with the same network address and located in the high-risk intelligence first report library and the internal intelligence library respectively; The first reported high-risk confirmation rate is determined according to the number of the second matching intelligence and the number of threat intelligence in the high-risk intelligence library.
7. The method according to claim 5, characterized in that The evaluation index also includes: high-risk contribution rate and high-risk accuracy rate. The method also includes: Matching the high-risk intelligence library and the internal disposal intelligence library to obtain third matching intelligence, where the third matching intelligence is threat intelligence with the same network address and located in the high-risk intelligence library and the internal disposal intelligence library respectively; Determining a high-risk contribution rate according to the amount of the third matching intelligence and the amount of threat intelligence in the internal disposal intelligence library; The high-risk accuracy rate is determined according to the quantity of the third matching intelligence and the quantity of threat intelligence in the high-risk intelligence library.
8. The method according to claim 5, characterized in that The evaluation index also includes: the first report high risk contribution rate and the first report high risk accuracy rate, and the method also includes: Matching the high-risk intelligence first report library and the internal disposal intelligence library to obtain fourth matching intelligence, where the fourth matching intelligence is threat intelligence with the same network address and located in the high-risk intelligence first report library and the internal disposal intelligence library respectively; Determine the first reported high-risk contribution rate according to the quantity of the fourth matching intelligence and the quantity of threat intelligence in the internal disposal intelligence library; The accuracy rate of first high-risk reporting is determined according to the number of the fourth matching intelligence and the number of threat intelligence in the high-risk intelligence library.
9. The method according to claim 5, characterized in that The preset evaluation index also includes: traceability support rate, and the method also includes: Determine the number of threat intelligence in the intelligence summary deduplication database that meets the preset regional judgment conditions; The tracing support rate is determined based on the amount of threat intelligence and the amount of intelligence in the intelligence summary deduplication database.
10. A threat intelligence-based intelligence provider evaluation device, characterized in that: include: An acquisition module, used to acquire external threat intelligence data and internal threat intelligence data, wherein the external threat intelligence data is provided by multiple intelligence providers, and the internal threat intelligence data is provided by an internal organization that has been attacked; A processing module, used to perform deduplication and classification processing on the external threat intelligence data and the internal threat intelligence data to obtain multiple intelligence libraries, wherein each intelligence provider corresponds to multiple intelligence libraries; A determination module, configured to determine, for any one of the multiple intelligence providing objects, multiple evaluation index parameters corresponding to the intelligence providing object based on the amount of threat intelligence in multiple intelligence repositories corresponding to the intelligence providing object; The processing module is used to perform weighted calculation processing on the multiple evaluation index parameters to obtain the evaluation result of the intelligence providing object, and the evaluation result is used to indicate the intelligence contribution of the intelligence providing object.
11. An electronic device, characterized in that: include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory to implement the method according to any one of claims 1 to 9.
12. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 9 when executed by a processor.
13. A computer program product, characterized in that The invention comprises a computer program, which implements the method according to any one of claims 1 to 9 when being executed by a processor.