Multi-source Intelligence Fusion Processing Method, Device, Equipment and Medium

By performing quality evaluation and weighted fusion of multiple intelligence sources, the problems of insufficient data and uneven quality of a single intelligence source are solved, and the automatic identification of malicious addresses is realized, which improves accuracy and efficiency.

CN120165986BActive Publication Date: 2025-08-05PENG CHENG LAB
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510639119.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-19
Publication Date
2025-08-05
Estimated Expiration
2045-05-19

AI Technical Summary

Technical Problem

In the prior art, due to the narrow data sources and application scenarios covered by a single intelligence source, the network threat intelligence data is not comprehensive enough, and the quality of different intelligence sources is uneven, the manual analysis methods are inefficient, and the accuracy of malicious address recognition is low.

Method used

By obtaining the first network threat intelligence data of the target address information and the second network threat intelligence data of multiple external intelligence sources, the evaluation is carried out under the quality evaluation dimensions of multiple intelligence sources, and the quality comprehensive score is obtained, and the malicious address judgment result is weighted and fusion is carried out based on the judgment result and the comprehensive score is determined.

Benefits of technology

It realizes automated comprehensive judgment of malicious addresses, improves identification accuracy and efficiency, makes full use of information from internal and external intelligence sources, and reduces manual intervention.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120165986B_ABST
    Figure CN120165986B_ABST
Patent Text Reader

Abstract

The embodiments of the present disclosure provide a multi-source intelligence fusion processing method, apparatus, equipment and medium. After obtaining the first network threat intelligence data and the second network threat intelligence data, the method can perform a quality assessment on each external intelligence source under multiple different intelligence source quality assessment dimensions to obtain multiple quality assessment scores, and weight them to obtain a comprehensive quality score corresponding to each external intelligence source; when the first network threat intelligence data determines that the target address information is unknown address information, the determination results of each second network threat intelligence data on the target address information are determined, and based on this, different count values are assigned to each external intelligence source; based on the comprehensive quality score, the weighting coefficient of the corresponding external intelligence source is determined, and the multi-source intelligence fusion value is obtained by weighted fusion based on the weighting coefficient and the corresponding count values under each external intelligence source, and the malicious address determination result of the target address information is determined based on this, which can improve the accuracy of malicious address identification.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of network security technology, and in particular to a multi-source intelligence fusion processing method, apparatus, device, and medium. Background Art

[0002] With the rapid development of internet technology, network information security issues are becoming increasingly prominent. Cyber Threat Intelligence (CTI) data is crucial for identifying, assessing, and responding to cybersecurity threats. It provides information about potential and ongoing threats to network security and infrastructure. Cyber threat intelligence can be used to determine whether a corresponding Internet Protocol (IP) address is malicious. Therefore, high-quality cyber threat intelligence is crucial for identifying malicious addresses.

[0003] In related technologies, since the data sources and application scenarios covered by a single intelligence source are relatively narrow, the data is not comprehensive enough. Combining network threat intelligence data from multiple intelligence sources to identify malicious addresses has become a trend. However, due to the uneven quality of network threat intelligence data from different intelligence sources, malicious addresses can currently only be identified through manual analysis combined with network threat intelligence data from multiple intelligence sources. The manual analysis method is not only inefficient, but also heavily dependent on human experience, resulting in low accuracy in identifying malicious addresses. Summary of the Invention

[0004] The main purpose of the embodiments of the present disclosure is to propose a multi-source intelligence fusion processing method, device, equipment and medium, which can improve the accuracy of malicious address identification.

[0005] To achieve the above objectives, a first aspect of the embodiments of the present disclosure provides a multi-source intelligence fusion processing method, comprising:

[0006] Obtain target address information to be detected, and obtain first network threat intelligence data corresponding to the target address information from an internal intelligence source, and obtain second network threat intelligence data corresponding to the target address information from multiple external intelligence sources respectively;

[0007] Performing a quality assessment on each of the external intelligence sources under a plurality of different intelligence source quality assessment dimensions to obtain a plurality of quality assessment scores, and weighting the plurality of quality assessment scores to obtain a comprehensive quality score corresponding to each of the external intelligence sources;

[0008] When the first network threat intelligence data determines that the target address information is unknown address information, determining a determination result of each second network threat intelligence data on the target address information, and assigning a different count value to each external intelligence source based on the different determination results;

[0009] Determine the weighting coefficient of the corresponding external intelligence source based on the comprehensive quality score, and perform weighted fusion according to the weighting coefficient and the corresponding count value under each external intelligence source to obtain a multi-source intelligence fusion value;

[0010] The malicious address determination result of the target address information is determined based on the size of the multi-source intelligence fusion value.

[0011] In some embodiments, assigning different count values to each of the external intelligence sources based on different determination results includes:

[0012] Determining a first quantity of the target address information as malicious address information from the determination results corresponding to each of the external intelligence sources;

[0013] Determining a second number of the external intelligence sources, and determining a proportion of the plurality of external intelligence sources that determine that the target address information is the malicious address information based on the first number and the second number;

[0014] When the determination ratio reaches a preset ratio, and the quality comprehensive score corresponding to the external intelligence source that determines that the target address information is the malicious address information reaches a preset score, the target address information is determined to be the malicious address information;

[0015] When the judgment ratio is lower than the preset ratio, or the comprehensive quality score corresponding to the external intelligence source that judges the target address information as malicious address information is lower than the preset score, different counting values are assigned to each external intelligence source based on different judgment results.

[0016] In some embodiments, the multi-source intelligence fusion processing method further includes:

[0017] Determining an internal confidence level of the internal intelligence source from the first network threat intelligence data, wherein the internal confidence level has a value between 0 and 1;

[0018] Obtain a preset voting ratio adjustment coefficient and a basic voting threshold, determine the difference between 1 and the internal confidence, multiply the difference by the voting ratio adjustment coefficient to obtain a product, and obtain the preset ratio based on the sum of the product and the basic voting threshold.

[0019] In some embodiments, determining the weighting coefficient of the corresponding external intelligence source based on the comprehensive quality score includes:

[0020] Accumulate the comprehensive quality scores of multiple external intelligence sources to obtain a total quality score;

[0021] The ratio of the comprehensive quality score of each external intelligence source to the total quality score is used as the weighting coefficient of the corresponding external intelligence source.

[0022] In some embodiments, the multi-source intelligence fusion processing method further includes:

[0023] When the first network threat intelligence data determines that the target address information is malicious address information, and the internal confidence of the internal intelligence source is greater than a preset confidence threshold, determining the determination results of each second network threat intelligence data on the target address information;

[0024] When the determination result under any one of the external intelligence sources also determines that the target address information is the malicious address information, it is determined that the target address information is the malicious address information.

[0025] In some embodiments, performing quality assessment on each of the external intelligence sources under multiple different intelligence source quality assessment dimensions to obtain multiple quality assessment scores, and weighting the multiple quality assessment scores to obtain a comprehensive quality score corresponding to each of the external intelligence sources, includes:

[0026] Performing a quality assessment on each of the external intelligence sources based on intelligence update time, intelligence source confidence, intelligence source comprehensiveness, intelligence source authority, and intelligence source stability, thereby obtaining an intelligence update time score, an intelligence source confidence score, an intelligence source comprehensiveness score, an intelligence source authority score, and an intelligence source stability score for each of the external intelligence sources;

[0027] Multiple of the intelligence update time score, the intelligence source confidence score, the intelligence source comprehensiveness score, the intelligence source authority score and the intelligence source stability score are weighted to obtain a comprehensive quality score corresponding to each external intelligence source.

[0028] In some embodiments, the quality assessment of each external intelligence source is performed based on intelligence update time, intelligence source confidence, intelligence source comprehensiveness, intelligence source authority, and intelligence source stability to obtain an intelligence update time score, intelligence source confidence score, intelligence source comprehensiveness score, intelligence source authority score, and intelligence source stability score for each external intelligence source, including:

[0029] Based on the difference between the current time and the update time of each second network threat intelligence data, rounding down according to the preset step time interval to determine the corresponding first deduction step value, and deducting the corresponding first deduction step value in sequence based on the preset initial time score to obtain the intelligence update time score of each external intelligence source that changes in a step-by-step manner;

[0030] Obtaining the external confidence of each of the external intelligence sources, and mapping the external confidence to a confidence value corresponding to the confidence level, to obtain an intelligence source confidence score for each of the external intelligence sources;

[0031] Ranking the plurality of external intelligence sources under the plurality of intelligence source comprehensiveness dimensions to obtain comprehensiveness rankings, determining a second deduction step value corresponding to each external intelligence source according to the comprehensiveness rankings, and sequentially deducting the corresponding second deduction step values based on a preset initial comprehensiveness score to obtain a step-wise intelligence source comprehensiveness score for each external intelligence source;

[0032] Ranking the plurality of external intelligence sources under the plurality of intelligence source authority dimensions to obtain an authority ranking, and determining a third deduction step value corresponding to each external intelligence source according to the authority ranking, and deducting the corresponding third deduction step value in sequence based on a preset initial authority score to obtain an intelligence source authority score for each external intelligence source that changes in a step-by-step manner;

[0033] Determine the intelligence update frequency, error volatility score and historical stability score of each of the external intelligence sources, and weight the intelligence update frequency, error volatility score and historical stability score to obtain the intelligence source stability score for each of the external intelligence sources.

[0034] In some embodiments, the obtaining of first network threat intelligence data corresponding to the target address information from an internal intelligence source, and the obtaining of second network threat intelligence data corresponding to the target address information from multiple external intelligence sources, respectively, include:

[0035] Acquire multiple different types of preset fields from an internal intelligence source and multiple external intelligence sources, respectively, wherein the preset fields include an information source field, a maliciousness level field, an intelligence threat type field, an intelligence threat level field, and a confidence level field;

[0036] Performing data cleaning and formatting processing on the preset fields of the same type to obtain a plurality of target fields after the data cleaning and formatting processing;

[0037] First network threat intelligence data is obtained based on the multiple target fields corresponding to the internal intelligence source, and corresponding second network threat intelligence data is obtained based on the multiple target fields corresponding to each of the external intelligence sources.

[0038] In some embodiments, after determining the malicious address determination result of the target address information based on the magnitude of the multi-source intelligence fusion value, the multi-source intelligence fusion processing method further includes:

[0039] Receive intelligence sharing requests from target terminals;

[0040] parsing the intelligence sharing request, determining the sharing authority of the target terminal, and selecting shared information from the first network threat intelligence data, the second network threat intelligence data, and the malicious address determination result based on the sharing authority;

[0041] The shared information is sent to the target terminal.

[0042] To achieve the above-mentioned purpose, a second aspect of the embodiments of the present disclosure provides a multi-source intelligence fusion processing device, comprising:

[0043] a data acquisition module, configured to acquire target address information to be detected, and to acquire first network threat intelligence data corresponding to the target address information from an internal intelligence source, and to acquire second network threat intelligence data corresponding to the target address information from multiple external intelligence sources;

[0044] a quality assessment module, configured to perform a quality assessment on each of the external intelligence sources under a plurality of different intelligence source quality assessment dimensions to obtain a plurality of quality assessment scores, and to weight the plurality of quality assessment scores to obtain a comprehensive quality score corresponding to each of the external intelligence sources;

[0045] a preliminary determination module, configured to, when the first network threat intelligence data determines that the target address information is unknown address information, determine a determination result of each of the second network threat intelligence data on the target address information, and assign a different count value to each of the external intelligence sources based on the different determination results;

[0046] A multi-source fusion module is used to determine the weighting coefficient of the corresponding external intelligence source based on the comprehensive quality score, and perform weighted fusion according to the weighting coefficient and the corresponding count value of each external intelligence source to obtain a multi-source intelligence fusion value;

[0047] The malicious determination module is used to determine the malicious address determination result of the target address information based on the size of the multi-source intelligence fusion value.

[0048] To achieve the above-mentioned purpose, the third aspect of the embodiment of the present disclosure proposes an electronic device, which includes a memory and a processor, and the memory stores a computer program. When the processor executes the computer program, it implements the multi-source intelligence fusion processing method described in the embodiment of the first aspect.

[0049] To achieve the above-mentioned purpose, the fourth aspect of the embodiment of the present disclosure proposes a storage medium, which is a computer-readable storage medium and stores a computer program. When the computer program is executed by the processor, it implements the multi-source intelligence fusion processing method described in the embodiment of the first aspect above.

[0050] The embodiment of the present disclosure can obtain the target address information to be detected by executing a multi-source intelligence fusion processing method, and obtain the first network threat intelligence data corresponding to the target address information from an internal intelligence source, and obtain the second network threat intelligence data corresponding to the target address information from multiple external intelligence sources respectively; perform quality assessment on each external intelligence source under multiple different intelligence source quality assessment dimensions to obtain multiple quality assessment scores, and weight the multiple quality assessment scores to obtain a comprehensive quality score corresponding to each external intelligence source; when the first network threat intelligence data determines that the target address information is unknown address information, determine the judgment results of each second network threat intelligence data on the target address information, and assign different count values to each external intelligence source based on different judgment results; determine the weighting coefficient of the corresponding external intelligence source based on the comprehensive quality score, and perform weighted fusion based on the weighting coefficient and the corresponding count values under each external intelligence source to obtain a multi-source intelligence fusion value; determine the malicious address judgment result of the target address information based on the size of the multi-source intelligence fusion value.

[0051] In this way, the embodiment of the present disclosure obtains network threat intelligence data from internal intelligence sources and external intelligence sources respectively, and then performs quality assessment on external intelligence sources under different intelligence source quality assessment dimensions, so as to accurately assess the intelligence quality of each external intelligence source and obtain the corresponding comprehensive quality score of each external intelligence source; then, judgment is made based on the data of the internal intelligence source first. When the first network threat intelligence data determines that the target address information is unknown address information, it indicates that it is difficult for the internal intelligence source to accurately determine the malicious situation of the target address information, so it is necessary to introduce the data of the external intelligence source for comprehensive judgment. Specifically, the judgment results of the target address information of each second network threat intelligence data are first determined, and based on Different counting values are assigned to each external intelligence source based on different judgment results, so as to quantify the judgment of each external intelligence source on the target address information. Then, the weighting coefficient of the corresponding external intelligence source is determined based on the comprehensive quality score, so that the external intelligence source with better quality has more decision-making weight in the fusion process, and also provides a fusion basis for the fusion between different external intelligence sources. Finally, weighted fusion is performed according to the weighting coefficient and the corresponding counting value of each external intelligence source. The obtained multi-source intelligence fusion value can comprehensively represent the judgment of multiple external intelligence sources on the target address information. Therefore, based on the size of the multi-source intelligence fusion value, the malicious address judgment result of the target address information can be accurately obtained.

[0052] Compared with the solutions in the related art that can only be analyzed manually, the embodiments of the present disclosure can not only fuse data from multiple intelligence sources to realize automatic comprehensive judgment of target address information without manual intervention, thereby improving the efficiency of malicious address judgment, but also cleverly consider the judgment of internal intelligence sources and external intelligence sources, and realize multi-source judgment of malicious addresses driven by internal intelligence sources, thereby fully considering the information of different intelligence sources, and ultimately improving the accuracy of malicious address identification. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] Figure 1 It is a schematic diagram of an application environment of the multi-source intelligence fusion processing method provided by an embodiment of the present disclosure;

[0054] Figure 2 It is a flowchart of the multi-source intelligence fusion processing method provided by the embodiment of the present disclosure;

[0055] Figure 3 yes Figure 2 A schematic diagram of a process flow further included in step 203;

[0056] Figure 4 is a flowchart of a process for determining a preset ratio provided by an embodiment of the present disclosure;

[0057] Figure 5 yes Figure 2 A schematic diagram of a process flow further included in step 204;

[0058] Figure 6 This is a flowchart further included in the multi-source intelligence fusion processing method provided by the embodiment of the present disclosure;

[0059] Figure 7 yes Figure 2 A schematic diagram of a process flow further included in step 202;

[0060] Figure 8 yes Figure 7 A schematic diagram of a process flow further included in step 701;

[0061] Figure 9 yes Figure 2 A schematic diagram of a process flow further included in step 201;

[0062] Figure 10 yes Figure 2 A schematic diagram of a process flow further included after step 205;

[0063] Figure 11 is a schematic diagram of a multi-source intelligence fusion processing system provided by an embodiment of the present disclosure;

[0064] Figure 12It is a complete schematic diagram of the determination process provided by the embodiment of the present disclosure;

[0065] Figure 13 This is a schematic diagram of the functional modules of the multi-source intelligence fusion processing device provided by an embodiment of the present disclosure;

[0066] Figure 14 Schematic diagram of the hardware structure of the electronic device provided by the embodiment of the present disclosure. DETAILED DESCRIPTION

[0067] In order to enable those skilled in the art to better understand the solutions of the present disclosure, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments of the present disclosure, all other embodiments obtained by those skilled in the art without making any creative efforts shall fall within the scope of protection of the present disclosure.

[0068] It is understandable that in the specific implementation of the present disclosure, when it comes to retrieving initial time series data, initial sample time series data and related data, when the above embodiments of the present disclosure are applied to specific products or technologies, it is necessary to obtain the object's permission or consent, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards.

[0069] In addition, when the embodiments of the present disclosure need to retrieve initial time series data, initial sample time series data and related data, separate permission or separate consent for the initial time series data, initial sample time series data and related data will be obtained through pop-up windows or jumping to a confirmation page. After clearly obtaining separate permission or separate consent for the initial time series data, initial sample time series data and related data, the necessary initial time series data, initial sample time series data and related data for the normal operation of the embodiments of the present disclosure will be obtained.

[0070] In the embodiments of the present disclosure, the term "module" or "unit" refers to a computer program or portion of a computer program that has a predetermined function and works together with other related components to achieve a predetermined goal. The ... that can be implemented in whole or in part using software, hardware (such as processing circuitry or memory), or a combination thereof. Similarly, a processor (or multiple processors or memories) can be used to implement one or more modules or units. Furthermore, each module or unit can be part of an overall module or unit that includes the functionality of that module or unit.

[0071] Before further explaining the embodiments of the present disclosure in detail, the nouns and terms involved in the embodiments of the present disclosure are explained. The nouns and terms involved in the embodiments of the present disclosure are subject to the following interpretations:

[0072] Artificial intelligence (AI) is a new technical discipline that studies and develops theories, methods, technologies, and application systems for simulating, extending, and expanding human intelligence. A branch of computer science, AI seeks to understand the essence of intelligence and create new intelligent machines that can respond in a manner similar to human intelligence. Research in this field includes robotics, speech recognition, image recognition, natural language processing, and expert systems. AI can simulate the information processes of human consciousness and thinking. It also encompasses theories, methods, technologies, and application systems that use digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, to perceive the environment, acquire knowledge, and use that knowledge to achieve optimal results.

[0073] Fundamental AI technologies generally include sensors, dedicated AI chips, cloud computing, distributed storage, big data processing, operating / interaction systems, and mechatronics. AI software technologies primarily encompass computer vision, robotics, biometrics, speech processing, natural language processing, and machine learning / deep learning.

[0074] Cyber Threat Intelligence (CTI) data is key data used to identify, assess, and respond to cybersecurity threats. It is information about potential and ongoing threats related to network security and infrastructure.

[0075] An Internet Protocol (IP) address is a unified address format provided by the IP protocol. It assigns a logical address to every network and host on the internet, masking differences in physical addresses. Network threat intelligence can be used to determine whether a corresponding IP address is malicious, making high-quality network threat intelligence crucial for identifying malicious addresses.

[0076] In related technologies, since the data sources and application scenarios covered by a single intelligence source are relatively narrow, the data is not comprehensive enough. Combining network threat intelligence data from multiple intelligence sources to identify malicious addresses has become a trend. However, due to the uneven quality of network threat intelligence data from different intelligence sources, malicious addresses can currently only be identified through manual analysis combined with network threat intelligence data from multiple intelligence sources. The manual analysis method is not only inefficient, but also heavily dependent on human experience, resulting in low accuracy in identifying malicious addresses.

[0077] In order to solve the above problems, the embodiments of the present disclosure propose a multi-source intelligence fusion processing method, device, equipment and medium, which can improve the accuracy of malicious address identification.

[0078] See also Figure 1 , Figure 1 A schematic diagram of a scenario of an implementation environment of a multi-source intelligence fusion processing method provided in an embodiment of the present disclosure includes: a terminal 101 and a server 102.

[0079] Exemplarily, the server 102 can obtain the target address information to be detected from the terminal 101, and obtain the first network threat intelligence data corresponding to the target address information from the internal intelligence source, and obtain the second network threat intelligence data corresponding to the target address information from multiple external intelligence sources; perform quality assessment on each external intelligence source under multiple different intelligence source quality assessment dimensions to obtain multiple quality assessment scores, and weight the multiple quality assessment scores to obtain a comprehensive quality score corresponding to each external intelligence source; when the first network threat intelligence data determines that the target address information is unknown address information, determine the judgment results of each second network threat intelligence data on the target address information, and assign different count values to each external intelligence source based on different judgment results; determine the weighting coefficient of the corresponding external intelligence source based on the comprehensive quality score, and perform weighted fusion based on the weighting coefficient and the corresponding count values under each external intelligence source to obtain a multi-source intelligence fusion value; determine the malicious address judgment result of the target address information based on the size of the multi-source intelligence fusion value.

[0080] Terminal 101 can be a mobile phone, computer, intelligent voice interaction device, smart wearable device, smart home appliance, vehicle-mounted terminal, etc., but is not limited thereto. Terminal 101 can also independently execute the multi-source intelligence fusion processing method. Terminal 101 and server 102 can be directly or indirectly connected via wired or wireless communication, which is not limited in the present embodiment.

[0081] Server 102 can be a standalone physical server, a server cluster or distributed system consisting of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. Furthermore, server 102 can be a node server in a blockchain network.

[0082] It should be noted that Figure 1The scenario diagram of the implementation environment of the multi-source intelligence fusion processing method shown is only an example. The scenario described in the embodiment of the present disclosure is to more clearly illustrate the technical solution of the embodiment of the present disclosure, and does not constitute a limitation on the technical solution provided by the embodiment of the present disclosure. Ordinary technicians in this field can know that with the evolution of technology and the emergence of new business scenarios, the technical solution provided by the embodiment of the present disclosure is also applicable to similar technical problems.

[0083] See also Figure 2 , Figure 2 201 to 205:

[0084] Step 201: Obtain target address information to be detected, obtain first network threat intelligence data corresponding to the target address information from an internal intelligence source, and obtain second network threat intelligence data corresponding to the target address information from multiple external intelligence sources.

[0085] Step 202: Perform a quality assessment on each external intelligence source under multiple different intelligence source quality assessment dimensions to obtain multiple quality assessment scores, and weight the multiple quality assessment scores to obtain a comprehensive quality score corresponding to each external intelligence source;

[0086] Step 203: When the first network threat intelligence data determines that the target address information is unknown address information, determining the determination results of each second network threat intelligence data on the target address information, and assigning different count values to each external intelligence source based on the different determination results;

[0087] Step 204: Determine the weighting coefficient of the corresponding external intelligence source based on the comprehensive quality score, and perform weighted fusion based on the weighting coefficient and the corresponding count value of each external intelligence source to obtain a multi-source intelligence fusion value;

[0088] Step 205: Determine the malicious address determination result of the target address information based on the multi-source intelligence fusion value.

[0089] With respect to the above-mentioned step 201, the target address information is information containing the target address, which refers to a specific network address in a network environment that needs to be subjected to security detection. Furthermore, the target address may be a network identifier such as an IP address, a domain name, or a URL. In the embodiment of the present disclosure, only the target address is an IP address as an example for illustration. It should be noted that the target address information, as an entry point for network attacks, may carry risks such as malware propagation and data leakage. By locating the target address, threat detection can be focused from generalized network traffic analysis to specific attack vectors. The target address information may be input by the user end, and the user end may send the target address information that needs to be detected to the server based on actual detection needs. Alternatively, the target address information may be automatically obtained by the server from the system in which it is located or the system being detected. The embodiment of the present disclosure does not impose specific restrictions on this.

[0090] First, cyber threat intelligence data related to target addresses, obtained from internal intelligence sources, accurately reflects the target address's actual behavior and impact within its own network environment and serves as a crucial basis for determining whether the target address poses a threat. Internal intelligence sources can come from an enterprise's own security equipment, systems, and security operations teams, such as internal firewall logs and detection systems. This data reflects the target address's activities within the enterprise's internal network environment, its interactions with internal systems, and potential security incidents.

[0091] Second, cyber threat intelligence data related to target address information is obtained from multiple external intelligence sources. While internal intelligence sources provide critical information, a single internal source has limitations. External intelligence sources can compensate for the lack of breadth and diversity of internal intelligence sources. External intelligence sources include open source intelligence platforms, third-party security service providers, and industry-shared intelligence repositories, also known as commercial intelligence sources. These data sources can provide a wider range of cyber threat information, covering the external cyber threat landscape, other similar attacks encountered, and threat trends.

[0092] Regarding step 202 above, the quality assessment score is a single score obtained by evaluating the external intelligence source based on different intelligence source quality assessment dimensions. For example, the external intelligence source is evaluated based on multiple factors such as intelligence update time, intelligence source confidence, intelligence source comprehensiveness, intelligence source authority, and intelligence source stability. Each dimension is assigned a corresponding score based on the degree of satisfaction. This score is the quality assessment score.

[0093] The overall quality score is a numerical value derived from the weighted calculation of multiple quality assessment scores, reflecting the overall quality of an external intelligence source. It comprehensively considers the performance of an external intelligence source across various assessment dimensions, providing a more comprehensive and accurate measure of the source's quality. For example, by assigning different weights to the quality assessment scores for dimensions such as intelligence update time, source confidence, source comprehensiveness, source authority, and source stability, and then multiplying the quality assessment scores for each dimension by their corresponding weights and adding them together, the overall quality score is obtained.

[0094] It should be noted that a single evaluation dimension cannot fully reflect the quality of an intelligence source. Different external intelligence sources may have different strengths and weaknesses in different aspects, while other intelligence sources may provide information with high accuracy but may lack completeness. Therefore, the disclosed embodiments, through multi-dimensional evaluation, can examine intelligence sources from multiple perspectives, gaining a more comprehensive and objective understanding of their quality status to adapt to complex and ever-changing network threats. Different evaluation dimensions have different degrees of importance in judging the quality of intelligence sources. By assigning different weights to different dimensions, the relative importance of each dimension in the overall evaluation can be reflected, allowing the overall quality score to more accurately reflect the actual value of the intelligence source.

[0095] Regarding step 203, the determination result refers to the determination of whether the target address information is a malicious address by the second network threat intelligence data of each external intelligence source. For example, the determination results may include "malicious," "non-malicious," "suspicious," "unknown," and so on.

[0096] When the first cyber threat intelligence data determines the target address information as "unknown," it indicates that the first cyber threat intelligence data determines the target address information to be unknown, indicating that the internal intelligence source is unable to clearly determine the malicious nature of the target address information. In this case, external intelligence sources are needed to supplement the information and more comprehensively determine the nature of the target address. Determining the results of each second cyber threat intelligence data set on the target address information is to gather information from more perspectives and understand the views of different external intelligence sources on the target address. For example, an internal intelligence source may be unable to make an accurate judgment on a specific target address due to limited data coverage or limitations of its analysis algorithm. However, an external intelligence source may have richer data or more advanced analysis methods and can provide valuable judgment results.

[0097] The count value is a quantified value based on the judgment results of the external intelligence source. It is a quantitative representation of the judgment results of each external intelligence source and is used for subsequent weighted fusion calculations. The setting of the count value is usually related to the nature of the judgment result. For example, when the judgment result is "malicious", the count value can be set to 1; when the judgment result is "non-malicious", the count value is -1; when the judgment result is "suspicious", the count value is 0.5; when the judgment result is "unknown", the count value is 0. In this way, the larger the value in the counting process, the more likely the target address information is malicious address information. It should be noted that the specific value of the count value can be adjusted based on actual conditions and experience.

[0098] It should be noted that assigning different count values to each external intelligence source based on different judgment results is intended to quantify the judgments of each external intelligence source. This has two advantages. First, it facilitates subsequent calculations and comparisons. By converting judgment results into count values, mathematical methods can be used to integrate and analyze information from multiple external intelligence sources, such as performing weighted summations, to obtain a comprehensive assessment result. Second, it can reflect the differences and importance of different judgment results. Different judgment results have different influences on the final determination of whether the target address is malicious. By assigning different count values, different judgment results can be given corresponding weights in the calculation, making the final decision more scientific and accurate.

[0099] For the above step 204, the weighting coefficient is a value determined based on the comprehensive quality score of the external intelligence source. It reflects the importance or influence of the external intelligence source in the multi-source intelligence fusion process. It should be noted that the higher the comprehensive quality score, the better the intelligence quality of the external intelligence source, and the larger the corresponding weighting coefficient.

[0100] It should be noted that different external intelligence sources differ in terms of data accuracy, completeness, timeliness, etc., that is, the quality is uneven. Determining the weighting coefficient of the corresponding external intelligence source based on the comprehensive quality score can allow external intelligence sources with better quality to have more decision-making weight in the fusion process. This can fully utilize the advantages of high-quality intelligence sources, reduce the interference of low-quality intelligence sources on the final results, and make the fusion results more reliable and accurate.

[0101] The multi-source intelligence fusion value is a composite value calculated by weightedly fusing the count values of each external intelligence source with the corresponding weighting coefficients. It comprehensively considers the judgments of multiple external intelligence sources and the quality of each source, and can fully reflect the overall judgment of multiple external intelligence sources on the target address information. The multi-source intelligence fusion value is a quantitative indicator used to ultimately determine whether the target address information is malicious. For example, the larger the multi-source intelligence fusion value obtained through weighted fusion calculation, the higher the probability that multiple external intelligence sources have comprehensively judged the target address information to be malicious; conversely, the smaller the fusion value, the lower the probability that the target address information is malicious.

[0102] By combining weighted coefficients with the corresponding count values from each external intelligence source, we can effectively integrate the judgment information from multiple external intelligence sources. The count value of each external intelligence source represents its judgment of the target address information. Through weighted fusion, these judgments are comprehensively processed according to the quality and importance of each intelligence source, resulting in a result that comprehensively reflects the overall judgment of multiple external intelligence sources, namely the multi-source intelligence fusion value.

[0103] With respect to the above step 205, the malicious address determination result refers to the final judgment conclusion on whether the target address information is a malicious address based on the multi-source intelligence fusion processing method. The malicious address determination result can be "malicious" or "non-malicious", or there may be some intermediate states, such as "suspicious", depending on the determination criteria and thresholds adopted.

[0104] It should be noted that the multi-source intelligence fusion value is obtained by comprehensively processing the information of multiple external intelligence sources. It takes into account the comprehensive quality scores of different external intelligence sources and their judgment results on the target address information. Different intelligence sources may judge the target address from different angles, based on different data and algorithms. The multi-source intelligence fusion value can integrate these scattered and even contradictory information, and comprehensively reflect the overall judgment of multiple external intelligence sources on the target address, rather than simply judging based on the majority principle or a single intelligence source.

[0105] Furthermore, because the multi-source intelligence fusion value provides a quantitative metric, it provides a clear numerical basis for identifying malicious addresses. Compared to subjective judgments based on manual analysis, this quantitative approach is more objective and accurate. Reasonable thresholds can be set based on historical data, actual business needs, and other factors. When the fusion value is greater than the threshold, it indicates that multiple external intelligence sources, combined, have a high degree of confidence in concluding that the target address is malicious. Conversely, when the fusion value is less than the threshold, it indicates that the target address is unlikely to be malicious. Therefore, multi-source intelligence fusion can fully leverage the strengths of each intelligence source and offset the shortcomings of a single intelligence source. Different intelligence sources may vary in data coverage, detection technology, and update frequency. Some sources may be more sensitive to certain types of malicious behavior, while others may excel in other areas. By integrating information from these sources, we can more comprehensively capture the characteristics of the target address, thereby improving the accuracy of malicious address identification.

[0106] In summary, the embodiment of the present disclosure obtains network threat intelligence data from internal intelligence sources and external intelligence sources respectively by executing the multi-source intelligence fusion processing method in steps 201 to 205, and then performs quality assessment on the external intelligence source under different intelligence source quality assessment dimensions, so as to accurately assess the intelligence quality of each external intelligence source and obtain the quality comprehensive score corresponding to each external intelligence source; then, a judgment is made based on the data of the internal intelligence source first. When the first network threat intelligence data determines that the target address information is unknown address information, it indicates that it is difficult for the internal intelligence source to accurately determine the malicious situation of the target address information, so it is necessary to introduce the data of the external intelligence source for comprehensive judgment, specifically first determining the quality of each second network threat intelligence data. The target address information is determined, and different count values are assigned to each external intelligence source based on different determination results, thereby quantifying the determination of the target address information by each external intelligence source. Then, the weight coefficient of the corresponding external intelligence source is determined based on the comprehensive quality score, so that the external intelligence source with better quality has more decision weight in the fusion process, and also provides a fusion basis for the fusion between different external intelligence sources. Finally, weighted fusion is performed according to the weight coefficient and the corresponding count value under each external intelligence source. The obtained multi-source intelligence fusion value can comprehensively represent the determination of the target address information by multiple external intelligence sources. Therefore, based on the size of the multi-source intelligence fusion value, the malicious address determination result of the target address information can be accurately obtained. Compared with the solution in the related art that can only be analyzed manually, the embodiment of the present disclosure can not only fuse the data of multiple intelligence sources to realize automatic comprehensive determination of the target address information without manual intervention, thereby improving the efficiency of malicious address determination, but also cleverly consider the determination of internal intelligence sources and external intelligence sources, realize multi-source determination of malicious addresses driven by internal intelligence sources, thereby fully considering the information of different intelligence sources, and ultimately improving the accuracy of malicious address identification.

[0107] Next, the contents further included in step 201 to step 205 in the embodiment of the present disclosure are described in detail.

[0108] See also Figure 3 , Figure 3 yes Figure 2 In some embodiments, the process of assigning different count values to each external intelligence source based on different determination results may include steps 301 to 304:

[0109] Step 301: determining a first quantity of target address information determined to be malicious address information from the determination results corresponding to each external intelligence source;

[0110] Step 302: Determine a second number of external intelligence sources, and determine a proportion of the plurality of external intelligence sources that determine that the target address information is malicious address information based on the first number and the second number.

[0111] Step 303: When the determination ratio reaches a preset ratio and the quality comprehensive score corresponding to the external intelligence source that determines that the target address information is malicious address information reaches a preset score, the target address information is determined to be malicious address information;

[0112] Step 304: When the judgment ratio is lower than the preset ratio, or the quality comprehensive score corresponding to the external intelligence source that judges the target address information as malicious address information is lower than the preset score, different counting values are assigned to each external intelligence source based on different judgment results.

[0113] In the above steps, after obtaining the second network threat intelligence data corresponding to the target address information from multiple external intelligence sources, the judgment results of these data are counted. The judgment results here include whether the target address information is malicious address information or not. The number of external intelligence sources that determine the target address information to be malicious address information is counted, and this number is defined as the first number. The second number is the total number of all external intelligence sources. The ratio obtained by dividing the first number by the second number is the judgment ratio of the target address information to be malicious address information. For example, suppose there are 5 external intelligence sources, namely intelligence source A, intelligence source B, intelligence source C, intelligence source D, intelligence source E and intelligence source F. Among them, intelligence source A, intelligence source C and intelligence source D determine that the target address information is malicious address information. Then the first number is 3, the second number is 6, and the judgment ratio is 50%.

[0114] The preset ratio is a threshold value set in advance in the embodiment of the present disclosure for judging the determination results of multiple external intelligence sources on the target address information. The preset ratio can be determined based on actual needs and experience, and is used to measure whether the proportion of external intelligence sources that determine that the target address information is malicious address information in all external intelligence sources has reached a level sufficient to determine that the target address is malicious. The preset score has a similar function to the preset ratio. It is also a threshold value set in advance in the embodiment of the present disclosure for measuring the comprehensive score of the quality of the external intelligence source. It is a value determined based on the expectations for the quality of the intelligence source and the actual application needs, and is used to judge whether the quality of the external intelligence source that determines that the target address information is malicious address information has reached a certain standard.

[0115] In the disclosed embodiment, two conditions must be met simultaneously to determine that target address information is malicious: first, the determination ratio must reach a predetermined ratio, and second, the comprehensive quality score of the external intelligence sources that determine the target address information as malicious must also reach a predetermined score. When both conditions are met, the target address information can be directly determined to be malicious.

[0116] It should be noted that, in the embodiment of the present disclosure, when the internal intelligence source cannot accurately confirm the maliciousness of the target address information, the voting decision of the external intelligence source is relied upon. The preset ratio set can be understood as the voting ratio. When the judgment result corresponding to the external intelligence source can determine that the target address information is malicious address information, it indicates that the external intelligence source casts a vote to support the target address information as malicious address information. In this way, by voting with enough external intelligence sources and the quality of these external intelligence sources is high enough, it is possible to quickly and accurately determine that the target address information is malicious address information, thereby improving the judgment efficiency.

[0117] On the contrary, when the above two conditions cannot be met at the same time, that is, the judgment ratio is lower than the preset ratio or the comprehensive quality score corresponding to the external intelligence source that judges the target address information as malicious address information is lower than the preset score, it is necessary to assign different counting values to them according to the different judgment results of each external intelligence source, so as to subsequently perform weighted fusion operations on the external intelligence source data, thereby further realizing accurate judgment of the maliciousness of the target address information based on the data of the external intelligence source.

[0118] See also Figure 4 , Figure 4 401 to 402:

[0119] Step 401: determining the internal confidence level of the internal intelligence source from the first network threat intelligence data;

[0120] Among them, the size of the internal confidence is between 0 and 1;

[0121] Step 402: Obtain a preset voting ratio adjustment coefficient and a basic voting threshold, determine the difference between 1 and the internal confidence, multiply the difference by the voting ratio adjustment coefficient to obtain a product, and obtain the preset ratio based on the sum of the product and the basic voting threshold.

[0122] In the above steps, the internal intelligence source is a numerical value that measures the reliability of the internal intelligence source's determination of the target address information, and its value range is between 0 and 1, where 0 indicates that the internal intelligence source's determination of the target address information is completely unreliable, and 1 indicates that the internal intelligence source's determination of the target address information is completely reliable. It should be noted that the disclosed embodiment can determine this internal confidence level from the first network threat intelligence data obtained from the internal intelligence source through a certain algorithm or evaluation method. For example, the internal confidence level can be obtained by comprehensively evaluating factors such as the accuracy of the internal intelligence source's historical data and the reliability of the data source. The disclosed embodiment does not impose specific limitations on this.

[0123] The voting ratio adjustment coefficient is a pre-set coefficient used to adjust the amplitude of the preset ratio calculated based on the internal confidence level. It is a fixed value, and its value affects the size of the preset ratio. The basic voting threshold is also a pre-set value and serves as a basis for calculating the preset ratio.

[0124] In order to better measure the impact of the internal confidence of the internal intelligence source on the votes of the external intelligence source in the embodiment of the present disclosure, a voting threshold ratio threshold formula is designed: Tvote=(1-Cinternal)×α+β. Where Tvote is the preset ratio, representing the minimum voting ratio required for the external intelligence source to determine that the target address information is malicious, Cinternal is the internal confidence, ranging from [0,1], α represents the voting ratio adjustment coefficient, which can be used to control the degree of influence of the internal confidence on the preset ratio, and β represents the basic voting threshold, ensuring that a certain external consensus threshold is retained even when the internal confidence is high.

[0125] It should be noted that this calculation method is used to determine the preset ratio in order to dynamically adjust the proportion of external intelligence sources required to determine that the target address information is malicious, based on the reliability of the internal intelligence source. When the internal confidence level is high, the difference between 1 and the internal confidence level is small, and the calculated preset ratio is relatively low. This means that the required proportion of external intelligence sources that believe the target address information is malicious is relatively low, because the internal intelligence source itself is relatively reliable. When the internal confidence level is low, the difference is large, and the preset ratio is relatively high. This means that more external intelligence sources must believe that the target address information is malicious before the target address information is determined to be malicious. This allows for more cautious judgments when internal intelligence sources are unreliable, improving the accuracy and reliability of judgments.

[0126] For example, setting α = 0.5 adjusts the influence of internal confidence on the preset ratio, and β = 0.3 sets the minimum voting ratio, ensuring that even if internal intelligence is extremely high, at least 30% of external intelligence sources must support it. When the internal intelligence source has high confidence (e.g., Cinternal = 0.9), Tvote = (1-0.9) × 0.5 + 0.3 = 0.35, meaning that only 35% of external intelligence sources need to vote that the target address information is malicious to confirm the target address information as malicious, thus achieving a rapid response. When the internal intelligence source has low confidence (e.g., Cinternal = 0.2), Tvote = (1-0.2) × 0.5 + 0.3 = 0.7, requiring 70% of external intelligence sources to vote maliciously to confirm the target address information as malicious, thus achieving cautious decision-making and reducing the chance of false positives.

[0127] Furthermore, in the embodiment of the present disclosure, during the execution of step 203, a judgment may also be made based on the internal confidence of the internal intelligence source. Specifically, the embodiment of the present disclosure may first obtain the internal confidence of the internal intelligence source, and only when the internal confidence meets a threshold requirement (such as a threshold of T) further judge the determination result of the first network threat intelligence data. That is, only when the internal confidence meets the threshold requirement and when the first network threat intelligence data determines that the target address information is unknown address information, further determine the determination result of each second network threat intelligence data on the target address information, and assign different count values to each external intelligence source based on the different determination results. Subsequent steps will not be repeated here.

[0128] See also Figure 5 , Figure 5 yes Figure 2 In some embodiments, the process of determining the weighting coefficient of the corresponding external intelligence source based on the comprehensive quality score may include steps 501 to 502:

[0129] Step 501: accumulating the comprehensive quality scores of multiple external intelligence sources to obtain a total quality score;

[0130] Step 502: The ratio of the comprehensive quality score of each external intelligence source to the total quality score is used as the weighting coefficient of the corresponding external intelligence source.

[0131] In the above steps, the total quality score refers to the sum of the comprehensive quality scores of multiple external intelligence sources. In the disclosed embodiment, the comprehensive quality score of each external intelligence source is divided by the total quality score. The ratio obtained is the weighting coefficient of the external intelligence source. This coefficient reflects the proportion of the quality of the external intelligence source in the total quality of all external intelligence sources. The larger the proportion, the higher the quality of the external intelligence source, and the greater the weight should be given in the fusion process.

[0132] This method of determining weighting coefficients is based on the principle that higher-quality external intelligence sources should have greater decision-making weight in multi-source intelligence fusion. By calculating the ratio of the comprehensive quality score to the total quality score, we can objectively reflect the relative quality of each external intelligence source, thereby rationally allocating its weight in the fusion process. This allows the multi-source intelligence fusion value to more accurately reflect the contribution of each external intelligence source, improving the accuracy of malicious address determination results in target address information. Therefore, high-quality external intelligence sources play a greater role in fusion, preventing the unreasonable influence of external intelligence sources of varying quality on the fusion results, ultimately achieving more reliable malicious address identification.

[0133] Furthermore, in the weighted fusion process, the embodiment of the present disclosure only selects some external intelligence sources with high rankings (such as the top N / 2, that is, the top half after sorting the N external intelligence sources according to the size of the quality comprehensive score) based on the comprehensive quality scores of each external intelligence source for subsequent weighted fusion judgment.

[0134] For example, if Si represents the i-th external intelligence source, where i represents the code of the external intelligence sources ranked in the top N / 2 in terms of scores, the weighting coefficient of the i-th external intelligence source is Wi. If the comprehensive quality score of the i-th external intelligence source is scorei, then Wi=scorei / sum(scorei) can be obtained. This formula means the proportion of the comprehensive quality score of the external intelligence source in the top N / 2 external intelligence sources, and Wi ranges from 0 to 1.

[0135] When different count values are assigned to each external information source based on different determination results, the "malicious" is recorded as 1 point, the "non-malicious" is -1 point, the "suspicious" is 0.5 point, and the "unknown" is 0 point. Then, weighted fusion is performed according to the weighting coefficient and the corresponding count value under each external information source, and the multi-source intelligence fusion value Ai is multiplied by Wi to obtain the weighted judgment score Sum(Wi*Ai). Specifically, sum up the weighted judgment scores Sum(Wi*Ai) of N / 2 Si, and then compare Sum(Wi*Ai) with the preset determination thresholds T (including the first determination threshold T1 and the second determination threshold T2, T1>T2). If Sum(Wi*Ai)>=T1, the final malicious address determination result indicates that the target address information is malicious address information, that is, the result is "malicious"; if Sum(Wi*Ai)<T2, the final malicious address determination result indicates that the target address information is non-malicious address information, that is, the result is "non-malicious"; if Sum(Wi*Ai)>=T2 and Sum(Wi*Ai)<T1, the final malicious address determination result indicates that the target address information is suspicious address information, that is, the result is "suspicious".

[0136] It should be noted that the first determination threshold T1 and the second determination threshold T2 are selected by comprehensively considering the distribution trend of the weighted judgment score Sum(Wi*Ai) and the historically accumulated data. For example, take the three historical samples of "malicious", "non-malicious", and "suspicious" in the historical data sample, calculate Sum(Wi*Ai) respectively, take the minimum value of the weight sum of the "malicious" sample as the first determination threshold T1, and take the maximum value of the weight sum of the "non-malicious" sample as the second determination threshold T2. These two thresholds can continuously learn historical data dynamically and optimize and adjust in real time.

[0137] Please refer to Figure 6 , Figure 6 is a schematic flowchart further included in the multi-source intelligence fusion processing method provided by the embodiments of the present disclosure. In some embodiments, the multi-source intelligence fusion processing method may further include steps 601 to step 602:

[0138] Step 601, when the first network threat intelligence data determines that the target address information is malicious address information and the internal confidence of the internal information source is greater than the preset confidence threshold, determine the determination results of each second network threat intelligence data on the target address information;

[0139] Step 602, when the determination result under any external information source also determines that the target address information is malicious address information, determine that the target address information is malicious address information.

[0140] In the above steps, the internal confidence level has been mentioned in the previous step. It is determined from the first network threat intelligence data and is used to measure the reliability of the internal intelligence source's judgment of the target address information. It will not be further explained here. The preset confidence threshold is a pre-set value used as a standard for judging the reliability of the internal intelligence source. When the internal confidence level exceeds this threshold, the internal intelligence source's judgment of the target address information is considered relatively reliable.

[0141] When the first network threat intelligence data determines that the target address information is malicious address information, and the internal confidence of the internal intelligence source is greater than a preset confidence threshold, the embodiment of the present disclosure can further determine the judgment results of each second network threat intelligence data on the target address information, and when the judgment result under any external intelligence source also determines that the target address information is malicious address information, it is determined that the target address information is malicious address information. Therefore, on the basis of the internal intelligence source's highly reliable judgment (that it is malicious address information), as long as there is an external intelligence source that also supports this judgment, the confidence in the judgment can be further enhanced.

[0142] It should be noted that because multiple intelligence sources all point to the same result (the target address information is malicious address information), this judgment is more likely to be accurate. This helps to quickly and accurately determine that the target address information is malicious address information with the joint support of internal intelligence sources and at least one external intelligence source, thereby improving the efficiency and accuracy of malicious address identification and avoiding the risks that may arise from over-reliance on a single intelligence source.

[0143] In addition, when the internal confidence of the internal intelligence source is less than the preset confidence threshold, the judgment result is also determined to be "unknown" to avoid the low internal confidence affecting the accurate judgment of the maliciousness of the target address information. Therefore, in this case, the judgment results of each second network threat intelligence data on the target address information can be determined, and subsequent steps 204 and 205 can be executed; or, when the first network threat intelligence data determines that the target address information is suspicious address information, and the internal confidence of the internal intelligence source is greater than the preset confidence threshold, the target address information is suspicious address information, so that when the internal confidence of the internal intelligence source is high, the malicious situation of the target address information can be quickly determined by the internal intelligence source itself; or, when the first network threat intelligence data determines that the target address information is malicious address information, and the internal confidence of the internal intelligence source is greater than the preset confidence threshold, and multiple external intelligence sources determine that the target address information is non-malicious address information, then the target address information is finally determined to be suspicious address information, so that the data of the internal intelligence source and the external intelligence source can be re-obtained for re-judgment.

[0144] See also Figure 7 , Figure 7 yes Figure 2 Schematic diagram of the process further included in step 202. In some embodiments, the process of performing quality assessment on each external intelligence source under multiple different intelligence source quality assessment dimensions to obtain multiple quality assessment scores, and weighting the multiple quality assessment scores to obtain a comprehensive quality score corresponding to each external intelligence source may include steps 701 to 702:

[0145] Step 701: Perform a quality assessment on each external intelligence source based on intelligence update time, intelligence source confidence, intelligence source comprehensiveness, intelligence source authority, and intelligence source stability, obtaining an intelligence update time score, intelligence source confidence score, intelligence source comprehensiveness score, intelligence source authority score, and intelligence source stability score for each external intelligence source.

[0146] Step 702, weighting multiple of the intelligence update time score, intelligence source confidence score, intelligence source comprehensiveness score, intelligence source authority score and intelligence source stability score to obtain a comprehensive quality score corresponding to each external intelligence source.

[0147] In the above steps, the embodiment of the present disclosure can conduct a quality assessment on each external intelligence source from five different dimensions, namely, intelligence update time, intelligence source confidence, intelligence source comprehensiveness, intelligence source authority, and intelligence source stability. Corresponding assessment standards and methods are formulated for each dimension to obtain the scores of each external intelligence source under these five dimensions. Different dimensions reflect the quality of the external intelligence source from different aspects. It is impossible to fully understand the pros and cons of the intelligence source by evaluating from only a single dimension. Through evaluation from multiple dimensions, the quality of each external intelligence source can be measured more comprehensively and accurately, providing a more detailed and reliable data basis for subsequent weighted calculations.

[0148] Intelligence update time refers to the time at which an external intelligence source updates its secondary cyber threat intelligence data. Timely updates reflect the latest cyber threat landscape and are crucial for identifying malicious addresses. Source confidence measures the credibility of the intelligence provided by the external intelligence source and is related to the accuracy and reliability of the intelligence. Source comprehensiveness indicates the scope of data covered and the breadth of application scenarios involved. Comprehensive intelligence sources provide richer information for identifying malicious addresses. Source authority reflects the source's professional status and influence in the cybersecurity field. Authoritative intelligence sources offer more valuable references. Source stability reflects the source's ability to provide stable and reliable intelligence over a period of time. Stable intelligence sources contribute to the consistent and accurate identification of malicious addresses. The intelligence update time score, source confidence score, source comprehensiveness score, source authority score, and source stability score are quantitative scores derived from a quality assessment of each external intelligence source across the five dimensions listed above, which are used to calculate the overall quality score.

[0149] The embodiment of the present disclosure can weight multiple scores among the intelligence update time score, intelligence source confidence score, intelligence source comprehensiveness score, intelligence source authority score and intelligence source stability score to obtain a comprehensive quality score corresponding to each external intelligence source. By weighted calculation of the comprehensive quality score, it is possible to reasonably comprehensively consider each dimension according to its importance. For example, any multiple scores can be selected from the intelligence update time score, intelligence source confidence score, intelligence source comprehensiveness score, intelligence source authority score and intelligence source stability score for weighted calculation, such as selecting the intelligence update time score and the intelligence source confidence score, or selecting the intelligence source comprehensiveness score, intelligence source authority score and intelligence source stability score, or selecting all scores for weighting. It can be set according to actual needs, and the embodiment of the present disclosure does not impose specific restrictions on this.

[0150] See also Figure 8 , Figure 8 yes Figure 7 Schematic diagram of the process further included in step 701. In some embodiments, the process of performing quality assessment on each external intelligence source based on intelligence update time, intelligence source confidence, intelligence source comprehensiveness, intelligence source authority, and intelligence source stability to obtain the intelligence update time score, intelligence source confidence score, intelligence source comprehensiveness score, intelligence source authority score, and intelligence source stability score for each external intelligence source may include steps 801 to 805:

[0151] Step 801: Based on the difference between the current time and the update time of each second network threat intelligence data, round down the difference according to the preset step time interval to determine the corresponding first deduction step value, and deduct the corresponding first deduction step value from the preset initial time score in sequence to obtain the intelligence update time score of each external intelligence source in a step-by-step manner;

[0152] Step 802: Obtain the external confidence level of each external intelligence source, and map the external confidence level to a confidence value corresponding to the confidence level to obtain an intelligence source confidence score for each external intelligence source.

[0153] Step 803: Rank multiple external intelligence sources based on the comprehensiveness dimension to obtain a comprehensiveness ranking, determine a second deduction step value corresponding to each external intelligence source based on the comprehensiveness ranking, and deduct the corresponding second deduction step value from the preset initial comprehensiveness score in sequence to obtain a step-by-step intelligence source comprehensiveness score for each external intelligence source.

[0154] Step 804: Rank multiple external intelligence sources based on multiple intelligence source authority dimensions to obtain authority rankings, determine a corresponding third deduction step value for each external intelligence source based on the authority rankings, and deduct the corresponding third deduction step values from the preset initial authority scores in sequence to obtain a step-by-step intelligence source authority score for each external intelligence source.

[0155] Step 805: Determine the intelligence update frequency, error volatility score, and historical stability score of each external intelligence source, and weight the intelligence update frequency, error volatility score, and historical stability score to obtain the intelligence source stability score for each external intelligence source.

[0156] In the above steps, the preset step time interval is a time interval set in advance, which is used to divide different time stages so as to perform a step-by-step calculation of the intelligence update time score; the first deduction step value is the deduction value corresponding to each step determined based on the difference between the current time and the intelligence update time, rounded down according to the preset step time interval; the preset initial time score is a set starting score, which serves as the basis for calculating the intelligence update time score, and the corresponding deduction step value is subsequently deducted according to the time difference. Specifically, the embodiment of the present disclosure can calculate the difference between the current time and the update time of each second network threat intelligence data, and then round this difference down according to the preset step time interval to obtain the corresponding first deduction step value. Finally, the first deduction step value is deducted from the preset initial time score in sequence, thereby obtaining the intelligence update time score that changes in a step-by-step manner under each external intelligence source.

[0157] For example, the intelligence update time score is a ranking of the timeliness of the data extracted from different external intelligence sources for the same target address information. The higher the ranking, the higher the score. In order to better simulate the impact of intelligence timeliness on the score and avoid the smooth transition of linear attenuation, so that the score remains stable within a specific time period and then suddenly drops, showing a step-like change, the embodiment of the present disclosure designs a formula that uses intelligence update time as a variable factor. The generated score shows a step-like change, and the obtained intelligence update time score is , where t represents the difference between the current time and the update time of each second network threat intelligence data (in days); Smax represents the preset initial time score (for example, 100 points); Smin represents the preset score threshold, that is, the minimum score threshold to prevent the score from falling to a negative value (for example, 0); k represents the score of each step down, for example, 20 points are deducted for each time interval; Tstep represents the time interval between steps, for example, one step down every 7 days; the symbol Indicates rounding down to get the first deduction step value to ensure that the score is constant within a specific time period. The time step and score change range can be adjusted according to actual needs. When the time difference t=12 days, (Round down), the first deduction level value is points, then the intelligence update time score point.

[0158] It's important to note that this step-by-step approach to calculating intelligence update time scores more accurately simulates the impact of intelligence timeliness on scores. It avoids the smooth transition issues that can occur with linear decay, allowing scores to remain stable over a specific period of time before suddenly dropping. This better reflects the changing value of intelligence over time in real-world scenarios and allows for more effective assessment of the quality of external intelligence sources in terms of their update time.

[0159] External confidence refers to the degree of trustworthiness of the intelligence provided by each external intelligence source, and may be measured on a scale of "high, medium, or low." The confidence value is the specific score to which the external confidence is mapped and is used to calculate the intelligence source confidence score. Specifically, embodiments of the present disclosure can obtain the external confidence of each external intelligence source and map the external confidence to a confidence value corresponding to the confidence level, thereby obtaining an intelligence source confidence score for each external intelligence source.

[0160] For example, the intelligence source confidence score is calculated based on the external confidence values of relevant data from different external intelligence sources for the same target address information. When external confidence is measured on a scale of "high, medium, or low," it can be initially mapped to specific scores such as "90, 60, or 10" for calculation. The specific values can be dynamically adjusted based on the results. For example, suppose there is external intelligence source B with an external confidence assessed as "medium." According to the initial mapping, it is mapped to 60 points. Therefore, the source confidence score of this external intelligence source is 60 points. If the actual results later indicate that this mapped score is unreasonable, it can be adjusted, for example, to 50 points.

[0161] It should be noted that mapping external confidence levels to specific numerical values for calculations can quantify the credibility of intelligence sources, facilitate comprehensive consideration in multi-dimensional quality assessments, and more intuitively compare the differences in confidence levels among different external intelligence sources, thereby more comprehensively evaluating their quality.

[0162] The comprehensiveness dimensions of multiple intelligence sources are used to measure multiple aspects of the comprehensiveness of intelligence sources, such as attack type coverage, geographical coverage, data dimension richness and other factors; the comprehensiveness ranking is the ranking result obtained after evaluating multiple external intelligence sources under the comprehensiveness dimensions of multiple intelligence sources, and the higher the ranking, the more comprehensive the intelligence source; the second deduction step value is the deduction value corresponding to each ranking step determined based on the comprehensiveness ranking; the preset initial comprehensiveness score is a set starting score, which serves as the basis for calculating the comprehensiveness score of the intelligence source, and the corresponding deduction step value is subsequently deducted according to the ranking. Specifically, the embodiment of the present disclosure can rank multiple external intelligence sources under the comprehensiveness dimensions of multiple intelligence sources to obtain a comprehensiveness ranking, and determine the second deduction step value corresponding to each external intelligence source according to the comprehensiveness ranking, and deduct the corresponding second deduction step value based on the preset initial comprehensiveness score in turn to obtain a step-by-step intelligence source comprehensiveness score for each external intelligence source.

[0163] For example, the comprehensiveness of intelligence sources needs to comprehensively consider factors such as attack type coverage, geographical coverage, and data dimension richness. The scoring is based on the accumulated historical list of major cybersecurity activities, and the above-mentioned measurement indicators of their intelligence are counted in turn to rank the intelligence sources. In order to better simulate the impact of the intelligence comprehensiveness ranking on the score, a formula is designed. This formula uses the intelligence comprehensiveness ranking as a variable factor, and the generated score shows a step-by-step change. The resulting intelligence source comprehensiveness score is , where R represents the comprehensiveness ranking of the intelligence source (the smaller the more comprehensive), Smax represents the preset initial comprehensiveness score, that is, the preset maximum score (such as 100 points), Smin represents the preset minimum score, such as 0, k represents the score of each ranking step down, such as 10 points for each step down, Nstep represents the step width, such as one step for every 2 people, and the symbol Represents rounding down to ensure that the score is fixed within each ranking interval to obtain the second deduction step value. For example, the score is quantified according to the ranking formula as {external intelligence source 1: 100 points, external intelligence source 2: 95 points, external intelligence source 3: 90 points, external intelligence source 4: 85 points}, then Nstep=1, k=5, and taking the third-ranked external intelligence source 3 as an example, , the second deduction level value is 5*2=10 points, the intelligence source comprehensiveness score = 100-10=90 points, and so on.

[0164] It should be noted that this step-by-step calculation method based on comprehensiveness ranking can more accurately reflect the impact of differences in the comprehensiveness of intelligence sources on the score, avoiding the irrationality that may be caused by simple linear ranking calculations, making the score relatively stable within each ranking interval, and more in line with the differences in the comprehensiveness of different intelligence sources in actual situations, thereby more effectively evaluating the quality of external intelligence sources in terms of comprehensiveness.

[0165] Multiple intelligence source authority dimensions are used to measure multiple aspects of the authority of intelligence sources, such as traffic and ranking, reputation and security, industry certification and citation, community trust, etc.; the authority ranking is the ranking result obtained after evaluating multiple external intelligence sources under multiple intelligence source authority dimensions, and the higher the ranking, the more authoritative the intelligence source; the third deduction step value is the deduction value corresponding to each ranking step determined according to the authority ranking; the preset initial authority score is a set starting score, which serves as the basis for calculating the authority score of the intelligence source, and the corresponding deduction step value is subsequently deducted according to the ranking. Specifically, the embodiment of the present disclosure can rank multiple external intelligence sources under multiple intelligence source authority dimensions to obtain an authority ranking, and determine the third deduction step value corresponding to each external intelligence source according to the authority ranking, and deduct the corresponding third deduction step value based on the preset initial authority score to obtain a step-by-step authority score for each external intelligence source.

[0166] For example, the authority ranking of intelligence sources can be comprehensively evaluated by taking into account the rankings of multiple authority-measuring websites. This can be done through multiple dimensions, such as traffic and ranking, reputation and security, industry certification and citations, and community trust. For example, online platforms that provide website and application rankings and competitive data analysis can check domain name registration history and age, identify newly registered suspicious domain names, and whether they are listed as reliable site security alliance whitelists by the official or security community. After considering these items separately, the final comprehensive ranking result can be obtained. In order to better simulate the impact of the authority ranking of intelligence sources on the score, the formula design used in the above process of determining the intelligence source comprehensiveness score and the intelligence update time score can be used. The difference is that the authority ranking of intelligence sources is used as a variable factor, and the generated scores show a step-by-step change, which will not be repeated here. In the process of determining the full-dimensional score of the intelligence source, R represents the authority ranking of the intelligence source (the smaller the more authoritative), Smax represents the preset initial authority score, that is, the highest score, such as 100 points, Smin represents the lowest score, such as 0, k represents the score of each ranking step, such as deducting 10 points for each step down, and Nstep represents the step width, such as a step for every 10 people, to ensure that the score is fixed in each ranking interval to obtain the value of the third deduction step.

[0167] It should be noted that the use of this step-by-step calculation method based on authority ranking can more accurately reflect the impact of differences in the authority of intelligence sources on the score, avoid the shortcomings of simple linear ranking calculations, and make the score more reasonably reflect the authority quality of the intelligence source, providing a more reliable evaluation basis for multi-source intelligence fusion processing.

[0168] The intelligence update frequency refers to the frequency with which an external intelligence source updates its network threat intelligence data; the error volatility score is a score that reflects the error fluctuation of the intelligence source, quantified by the standard deviation of the changes in the false alarm rate and the missed alarm rate. Intelligence sources with small fluctuations have high scores; the historical stability score is a score that reflects the historical stability of the intelligence source, obtained by evaluating the fluctuation amplitude and consistency of historical data. Intelligence sources with small fluctuations have high scores. Specifically, the disclosed embodiment can determine the intelligence update frequency, error volatility score, and historical stability score of each external intelligence source, and weight the intelligence update frequency, error volatility score, and historical stability score to obtain the intelligence source stability score for each external intelligence source.

[0169] For example, the intelligence source stability score is a comprehensive measure of the continuity and consistency of the intelligence source over a period of time, including the consistency of update frequency, historical stability, error volatility, etc. The update frequency consistency is quantified by calculating the standard deviation. Intelligence sources with smaller fluctuations in update frequency receive high scores. Error volatility is quantified by the standard deviation of changes in false alarm rate and missed alarm rate. Intelligence sources with smaller fluctuations receive high scores. Historical stability is quantified by evaluating the fluctuation amplitude and consistency of historical data. Intelligence sources with smaller fluctuations receive high scores. The scores of these sub-items are weighted, summed, and normalized to obtain the intelligence source stability score.

[0170] It should be noted that calculating the intelligence source stability score by comprehensively considering the frequency of intelligence updates, error volatility, and historical stability can more comprehensively measure the continuity and consistency of external intelligence sources over a period of time. By combining these factors through weighting and normalization, a score that more accurately reflects the stability of the intelligence source can be obtained, thereby providing a more reliable quality assessment basis for multi-source intelligence fusion processing.

[0171] See also Figure 9 , Figure 9 yes Figure 2 In some embodiments, the process of obtaining the first network threat intelligence data corresponding to the target address information from the internal intelligence source and obtaining the second network threat intelligence data corresponding to the target address information from multiple external intelligence sources may include steps 901 to 903:

[0172] Step 901: Acquire multiple different types of preset fields from an internal intelligence source and multiple external intelligence sources respectively;

[0173] Among them, the preset fields include information source field, maliciousness field, intelligence threat type field, intelligence threat degree field, and confidence field;

[0174] Step 902: Perform data cleaning and formatting on preset fields of the same type to obtain multiple target fields after data cleaning and formatting.

[0175] Step 903: obtain first network threat intelligence data based on the corresponding multiple target fields under the internal intelligence source, and obtain corresponding second network threat intelligence data based on the corresponding multiple target fields under each external intelligence source.

[0176] In the above steps, the embodiment of the present disclosure can obtain multiple different types of preset fields from intelligence sources such as internal intelligence sources and multiple external intelligence sources, such as information source (source) field, maliciousness (malicious) field, threat type (threat_type) field, threat level (threat_level) field, confidence (confidence_level) field, etc., and then perform data cleaning and formatting processing on the preset fields of the same type to obtain multiple target fields after data cleaning and formatting processing. The goal is to format these key fields into a unified data structure, including standardized field names and standardized field values, to ensure that the threat intelligence information obtained from different data sources is processed consistently so that it has the same data structure.

[0177] For example, different intelligence sources will eventually map the maliciousness-related fields to the malicious field, and its field values will be standardized and mapped to (malicious, suspicious, unknown, non-malicious). This consistent data structure provides a consistent data foundation for subsequent analysis and judgment.

[0178] Finally, the embodiment of the present disclosure obtains first network threat intelligence data based on multiple target fields corresponding to the internal intelligence source, and obtains corresponding second network threat intelligence data based on multiple target fields corresponding to each external intelligence source, so as to subsequently process and analyze the network threat intelligence data based on different intelligence sources.

[0179] See also Figure 10 , Figure 10 yes Figure 2 In some embodiments, after determining the malicious address determination result of the target address information based on the size of the multi-source intelligence fusion value, the multi-source intelligence fusion processing method may further include steps 1001 to 1003:

[0180] Step 1001: receiving an intelligence sharing request from a target terminal;

[0181] Step 1002: parsing the intelligence sharing request, determining the sharing authority of the target terminal, and selecting shared information from the first network threat intelligence data, the second network threat intelligence data, and the malicious address determination result based on the sharing authority;

[0182] Step 1003: Send the shared information to the target terminal.

[0183] In the above steps, the target terminal is the device terminal that initiates the intelligence sharing request, which may be a personal computer, server, mobile device, etc. It hopes to obtain network threat intelligence data related to the target address information and malicious address determination results and other information; the intelligence sharing request is a request instruction sent by the target terminal to the current system to express its desire to obtain relevant network threat intelligence and malicious address determination results and other information.

[0184] Sharing permissions are permissions that limit the scope and level of intelligence information that a target terminal can obtain. Different target terminals may have different sharing permissions. For example, some terminals may only be able to obtain secondary network threat intelligence data from a portion of an external intelligence source, while other terminals may be able to obtain complete malicious address determination results. Specifically, the disclosed embodiments can parse the received intelligence sharing request, extract information related to the target terminal, and then determine the sharing permissions of the target terminal based on preset permission rules and information such as the identity of the target terminal.

[0185] Finally, the disclosed embodiment can, based on sharing permissions, filter out the shared information that the target terminal has the permission to obtain from the first network threat intelligence data, the second network threat intelligence data, and the malicious address determination results owned by the system, and send the shared information to the target terminal, providing the third-party target terminal with integrated multi-source intelligence so that it can perform multi-dimensional statistical analysis of the threat intelligence data, thereby ensuring the security and reasonable use of intelligence information. Since different terminals may have different usage requirements and security levels, by setting sharing permissions, the leakage of sensitive information can be avoided, while allowing each terminal to obtain useful intelligence information that matches its permissions, thereby realizing effective sharing and management of intelligence.

[0186] Furthermore, the disclosed embodiments can also provide a channel for feedback correction of the accuracy of intelligence data for the shared target terminal. In the process of multi-source intelligence fusion processing, since multiple intelligence sources are involved, the data quality of different intelligence sources varies, and the situation of network threats is constantly changing, so the intelligence data may be inaccurate. Therefore, there is a need for a feedback mechanism to allow users or related systems that use these intelligence data to feed back inaccurate information found to the system. The subject of feedback can be the target terminal that receives the intelligence sharing information, and the feedback method can be varied. For example, through the special feedback interface provided by the system, the feedback information can be filled in, including the target address information, the description of the problem found, the actual situation, etc.; feedback can also be provided through email, message push, etc.

[0187] After the system receives feedback, it needs to analyze and process the content. First, the authenticity and reliability of the feedback must be verified. For example, further querying data from other intelligence sources, analyzing historical data, and other methods can be used to confirm whether the reported issue actually exists. If accuracy issues with the intelligence data are confirmed, the relevant intelligence data must be corrected. For the first network threat intelligence data (internal intelligence source), the internal intelligence database can be updated and corrected based on the feedback information. For the second network threat intelligence data (external intelligence source), the feedback information can be fed back to the corresponding external intelligence source to prompt them to make data corrections. The system itself can also mark or adjust the data from the external intelligence source as appropriate. By continuously receiving feedback and making corrections, the system can gradually reduce errors and deviations in the intelligence data, making subsequent malicious address determinations more accurate and reliable.

[0188] Further, see Figure 11 , Figure 11 : is a schematic diagram of the multi-source intelligence fusion processing system provided by the embodiment of the present disclosure. The embodiment of the present disclosure also provides a multi-source intelligence fusion processing system (hereinafter referred to as the system), which can execute the multi-source intelligence fusion processing method in the above embodiment. The system is composed of a multi-source heterogeneous intelligence data acquisition module, a multi-source heterogeneous intelligence data fusion module, and a fusion intelligence sharing module. Among them, the multi-source heterogeneous intelligence data acquisition module is composed of an internal intelligence source generation submodule and an external intelligence source collection submodule; the multi-source heterogeneous intelligence data fusion module is composed of a multi-source IP threat intelligence information processing submodule, an intelligence source quality assessment quantification submodule, and an IP threat intelligence fusion judgment submodule, aiming to obtain higher quality and more comprehensive threat intelligence, thereby improving the accuracy of malicious address identification.

[0189] The following is a detailed description of the multi-source intelligence fusion processing method and its application in the multi-source intelligence fusion processing system:

[0190] (1) The multi-source heterogeneous intelligence acquisition module consists of an internal intelligence source generation submodule and an external intelligence source collection submodule. This module uses an automated method to acquire business intelligence information and generate internal intelligence information in real time in parallel, ensuring rapid acquisition of comprehensive threat intelligence information.

[0191] The internal intelligence source generation submodule first collects raw honey-spotting logs from the four types of honey devices (e.g., honey spots, honey courts, honey arrays, and honey holes) involved in large-scale network security activities. It then retains key information from the logs, including timestamps, honey-spotting IP addresses, honey-spotting types, honey-spotting behaviors, attack behaviors, ports, and honey-spotting times, while removing other noise and redundant data. Finally, it converts the logs into unified internal intelligence and stores it in a database to facilitate subsequent multi-source heterogeneous intelligence data fusion processing. The external intelligence source collection submodule typically provides intelligence sources in the form of application programming interfaces (APIs). This submodule first establishes a continuously updateable list of multi-source intelligence interfaces. This list contains all the required field information for each intelligence source, including the interface address, request token, request content format, and request parameters. This list supports on-demand updates to accommodate newly added API-based intelligence sources. Secondly, when an IP-based intelligence query is required, the system automatically triggers the collection module to execute, which automatically calls all intelligence source APIs to complete threat intelligence acquisition.

[0192] (2) The multi-source heterogeneous intelligence data fusion module is used to process the data obtained by the multi-source heterogeneous intelligence acquisition module, perform intelligence source quality assessment and quantification, fusion judgment, and normalized storage to generate multi-source fusion intelligence. It includes a multi-source IP threat intelligence information processing sub-module, an intelligence source quality assessment and quantification sub-module, and an IP threat intelligence fusion judgment sub-module.

[0193] The multi-source IP threat intelligence information processing submodule mainly extracts key fields from N external intelligence sources and internal intelligence sources, including information source (source), maliciousness (malicious), threat type (threat_type), threat level (threat_level), confidence (confidence_level), etc. Its goal is to format these key fields into a unified data structure (standardized field names and standardized field values) to ensure that threat intelligence information obtained from different data sources is processed consistently and has the same data structure.

[0194] The intelligence source quality assessment quantification submodule comprehensively considers multiple factors, including intelligence update time, intelligence source confidence, intelligence source comprehensiveness, intelligence source authority, and intelligence source stability, and quantifies them using scores. The methods for obtaining the intelligence update time score, intelligence source confidence score, intelligence source comprehensiveness score, intelligence source authority score, and intelligence source stability score corresponding to these factors have been described in the above embodiments and will not be repeated here.

[0195] The IP threat intelligence fusion and determination sub-module takes the internal intelligence source as the benchmark, collaborates with other mainstream external intelligence sources, namely N mainstream external intelligence sources, to make comprehensive threat determinations. The specific number of external intelligence sources can be adjusted according to the actual situation. Please refer to Figure 12 , Figure 12 which is a complete schematic diagram of the determination process provided by the embodiments of the present disclosure. The determination process is as follows:

[0196] (2.1) Quick malicious determination based on internal confidence;

[0197] For the IP to be detected, when the internal intelligence source marks the IP as malicious, the system makes a dynamic decision by combining the internal confidence and the determination results of the external intelligence sources. Subsequently, the internal confidence is calculated first. When the internal confidence >= the preset determination threshold T, if any external intelligence source also determines it as malicious, then the IP is determined as malicious through fusion and the blocking is immediately triggered; if none of the external intelligence sources determine it as malicious, that is, all are "non-malicious", then the IP is determined as suspicious through fusion and enters continuous monitoring and behavior baseline analysis; if the internal confidence < T, it is tentatively marked as "unknown" first and enters the process of 2.2.

[0198] Among them, the calculation of the internal confidence comprehensively considers various indicators (number of honeycombing times, attack types, attack behaviors, timeliness, consistency between internal and external intelligence, etc.), quantifies them with weights, and the weights can be dynamically adjusted through machine learning algorithm training based on historical data. Finally, a comprehensive score is obtained and normalized to ensure that the internal confidence is within the range of [0,1]. The threshold T can continuously learn historical data dynamically and optimize the adjustment in real time.

[0199] (2.2) External intelligence source voting mechanism;

[0200] If the internal intelligence determines the IP as "unknown" for maliciousness, then it depends on the external intelligence source voting decision: count the proportion of malicious votes from external manufacturers. If the proportion of malicious votes exceeds Tvote (the voting threshold proportion threshold, such as N / 2) and the intelligence source quality score is relatively high, then it is determined as malicious. If the proportion of malicious votes is less than Tvote, then it enters step 2.3 to further make a comprehensive determination by combining high-quality intelligence sources.

[0201] In the embodiments of the present disclosure, in order to better measure the influence of the internal confidence of the internal intelligence source on the external intelligence source voting, a voting threshold proportion threshold formula is designed: Tvote = (1 - Cinternal) × α + β. Where Tvote is the preset proportion, representing the minimum voting proportion required for the external intelligence source to determine the target address information as malicious, Cinternal is the internal confidence, with a range of [0,1], α represents the voting proportion adjustment coefficient, which can be used to control the influence degree of the internal confidence on the preset proportion, and β represents the basic voting threshold, ensuring that even when the internal confidence is at a high confidence level, a certain external consensus threshold is still retained.

[0202] (2.3) High-quality information source weighted fusion determination;

[0203] When the voting result ratio is insufficient, select the top N / 2, that is, the top 50% of commercial intelligence manufacturers with the highest scores quantified by the information source quality assessment quantization sub-module, and take its weighted fusion determination result at this time. Further, in the weighted fusion process of the embodiments of the present disclosure, only some external information sources ranked at the top (such as the top N / 2, that is, after sorting N external information sources according to the size of the comprehensive quality score, in the first half position) are selected based on the comprehensive quality scores of each external information source for subsequent weighted fusion determination.

[0204] For example, if Si represents the i-th external information source, where i represents the code of the external information source ranked in the top N / 2, and the weighting coefficient of the i-th external information source is Wi, and assuming the comprehensive quality score of the i-th external information source is scorei, then Wi = scorei / sum(scorei) can be obtained. The meaning of this formula is the proportion of the comprehensive quality score of this external information source among the top N / 2 external information sources, and the range of Wi is between 0 and 1.

[0205] When different count values are assigned to each external information source based on different determination results, mark "malicious" as 1 point, "non-malicious" as -1 point, "suspicious" as 0.5 points, and "unknown" as 0 points. Then, weighted fusion is performed according to the weighting coefficient and the corresponding count value of each external information source. Multiply the multi-source information fusion value Ai and Wi to obtain the weighted judgment score Sum(Wi * Ai). Specifically, summarize the weighted judgment scores Sum(Wi * Ai) of N / 2 Si, and then compare Sum(Wi * Ai) with the preset determination thresholds T (including the first determination threshold T1 and the second determination threshold T2, T1 > T2). If Sum(Wi * Ai) >= T1, the final malicious address determination result indicates that the target address information is malicious address information, that is, the result is "malicious"; if Sum(Wi * Ai) < T2, the final malicious address determination result indicates that the target address information is non-malicious address information, that is, the result is "non-malicious"; if Sum(Wi * Ai) >= T2 and Sum(Wi * Ai) < T1, the final malicious address determination result indicates that the target address information is suspicious address information, that is, the result is "suspicious".

[0206] It should be noted that the first judgment threshold T1 and the second judgment threshold T2 are selected based on a comprehensive consideration of the distribution trend of the weighted judgment score Sum(Wi*Ai) and historical accumulated data. For example, three types of historical data samples, "malicious", "non-malicious" and "suspicious", are taken, and Sum(Wi*Ai) is calculated respectively. The weight and minimum value of the "malicious" sample are taken as the first judgment threshold T1, and the weight and maximum value of the "non-malicious" sample are taken as the second judgment threshold T2. These two thresholds can dynamically learn historical data and be optimized and adjusted in real time.

[0207] (3) The fusion intelligence sharing module opens up and shares the capabilities and data of the threat intelligence platform, providing integrated multi-source intelligence to third parties (target terminals), conducting multi-dimensional statistical analysis of threat intelligence data, and providing a channel for feedback and correction of intelligence data accuracy. In addition, different access rights and flow control strategies are provided for callers with different trust levels.

[0208] Finally, the multi-source intelligence fusion processing system in the disclosed embodiment, by executing the multi-source intelligence fusion method, takes the internal intelligence source as the benchmark, and coordinates with other external intelligence sources to make a comprehensive threat judgment, and the internal intelligence is generated in combination with the most actual threats to the defense unit. Finally, combined with the perspective of external intelligence, a comprehensive threat judgment is formed to form an effective IP ban. It solves the problem of relying on external intelligence sources or open source intelligence sources and neglecting internal intelligence sources when judging multi-source intelligence IP threats, and overcomes the disadvantage of requiring manual analysis due to differences in intelligence sources. In addition, it provides an innovative reference method for generating high-quality comprehensive threat intelligence, and also proposes a quality assessment and quantification method for threat intelligence data sources, namely a weighted scoring model. This method comprehensively considers multi-dimensional factors such as intelligence update time, intelligence source confidence, intelligence source comprehensiveness, intelligence source authority, and intelligence source stability, and scientifically quantifies them with specific scores.

[0209] See also Figure 13 The embodiment of the present disclosure further provides a multi-source intelligence fusion processing device, which can implement the above-mentioned multi-source intelligence fusion processing method. The multi-source intelligence fusion processing device includes:

[0210] The data acquisition module 1301 is configured to acquire target address information to be detected, acquire first network threat intelligence data corresponding to the target address information from an internal intelligence source, and acquire second network threat intelligence data corresponding to the target address information from multiple external intelligence sources.

[0211] A quality assessment module 1302 is configured to perform a quality assessment on each external intelligence source based on multiple different intelligence source quality assessment dimensions to obtain multiple quality assessment scores, and to weight the multiple quality assessment scores to obtain a comprehensive quality score corresponding to each external intelligence source;

[0212] The preliminary determination module 1303 is configured to determine, when the first network threat intelligence data determines that the target address information is unknown address information, the determination results of each second network threat intelligence data on the target address information, and assign different count values to each external intelligence source based on the different determination results;

[0213] The multi-source fusion module 1304 is used to determine the weight coefficient of the corresponding external intelligence source based on the comprehensive quality score, and perform weighted fusion based on the weight coefficient and the corresponding count value of each external intelligence source to obtain a multi-source intelligence fusion value;

[0214] The malicious determination module 1305 is used to determine the malicious address determination result of the target address information based on the size of the multi-source intelligence fusion value.

[0215] In summary, the multi-source intelligence fusion processing device executes the multi-source intelligence fusion processing method in the above embodiment, obtains network threat intelligence data from internal intelligence sources and external intelligence sources respectively, and then performs quality assessment on external intelligence sources under different intelligence source quality assessment dimensions, so as to accurately assess the intelligence quality of each external intelligence source and obtain the corresponding comprehensive quality score of each external intelligence source; then, the judgment is made based on the data of the internal intelligence source first. When the first network threat intelligence data determines that the target address information is unknown address information, it indicates that it is difficult for the internal intelligence source to accurately determine the malicious situation of the target address information, so it is necessary to introduce the data of the external intelligence source for comprehensive judgment, specifically first determine the quality of each second network threat intelligence data for the target The target address information is determined, and different count values are assigned to each external intelligence source based on different determination results, thereby quantifying the determination of the target address information by each external intelligence source. Then, the weight coefficient of the corresponding external intelligence source is determined based on the comprehensive quality score, so that the external intelligence source with better quality has more decision weight in the fusion process, and also provides a fusion basis for the fusion between different external intelligence sources. Finally, weighted fusion is performed according to the weight coefficient and the corresponding count value under each external intelligence source. The obtained multi-source intelligence fusion value can comprehensively represent the determination of the target address information by multiple external intelligence sources. Therefore, based on the size of the multi-source intelligence fusion value, the malicious address determination result of the target address information can be accurately obtained. Compared with the solution in the related art that can only be analyzed manually, the embodiment of the present disclosure can not only fuse the data of multiple intelligence sources to realize automatic comprehensive determination of the target address information without manual intervention, thereby improving the efficiency of malicious address determination, but also cleverly consider the determination of internal intelligence sources and external intelligence sources, realize multi-source determination of malicious addresses driven by internal intelligence sources, thereby fully considering the information of different intelligence sources, and ultimately improving the accuracy of malicious address identification.

[0216] The specific implementation of the multi-source intelligence fusion processing device is basically the same as the specific embodiment of the multi-source intelligence fusion processing method described above, and will not be repeated here. Under the premise of meeting the requirements of the embodiment of the present disclosure, the multi-source intelligence fusion processing device can also be provided with other functional modules to implement the multi-source intelligence fusion processing method in the above embodiment.

[0217] The present disclosure also provides an electronic device comprising a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the multi-source intelligence fusion processing method. The electronic device can be any smart terminal, such as a tablet computer or an in-vehicle computer.

[0218] See also Figure 14 , Figure 14 The hardware structure of an electronic device according to another embodiment is shown. The electronic device includes:

[0219] The processor 1401 may be implemented as a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is configured to execute relevant programs to implement the technical solutions provided by the embodiments of the present disclosure.

[0220] The memory 1402 can be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 1402 can store operating devices and other applications. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 1402 and is called by the processor 1401 to execute the multi-source intelligence fusion processing method of the embodiments of this disclosure.

[0221] Input / output interface 1403, used to implement information input and output;

[0222] Communication interface 1404, used to implement communication interaction between this device and other devices, which can be achieved through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WiFi, Bluetooth, etc.);

[0223] Bus 1405 , which transmits information between various components of the device (e.g., processor 1401 , memory 1402 , input / output interface 1403 , and communication interface 1404 );

[0224] The processor 1401 , the memory 1402 , the input / output interface 1403 and the communication interface 1404 are connected to each other in communication within the device via a bus 1405 .

[0225] The embodiment of the present disclosure also provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it implements the above-mentioned multi-source intelligence fusion processing method.

[0226] The memory, as a non-transient computer-readable storage medium, can be used to store non-transient software programs and non-transient computer executable programs. In addition, the memory may include a high-speed random access memory and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some embodiments, the memory may optionally include a memory remotely arranged relative to the processor, and these remote memories may be connected to the processor via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0227] The embodiments described in the embodiments of the present disclosure are intended to more clearly illustrate the technical solutions of the embodiments of the present disclosure and do not constitute a limitation on the technical solutions provided by the embodiments of the present disclosure. Those skilled in the art will appreciate that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of the present disclosure are also applicable to similar technical problems.

[0228] Those skilled in the art will understand that the technical solutions shown in the drawings do not constitute a limitation on the embodiments of the present disclosure, and may include more or fewer steps than shown in the drawings, or a combination of certain steps, or different steps.

[0229] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, i.e., they may be located in one place or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of this embodiment.

[0230] Those skilled in the art will appreciate that all or some of the steps, devices, and functional modules / units in the methods disclosed above may be implemented as software, firmware, hardware, or appropriate combinations thereof.

[0231] The terms "first," "second," "third," "fourth," and the like (if any) in the specification of the present disclosure and the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a particular order or sequential sequence. It should be understood that the terms used in this manner are interchangeable where appropriate so that the embodiments of the present disclosure described herein can be implemented in orders other than those illustrated or described herein. In addition, the terms "including" and "having," and any variations thereof, are intended to cover non-exclusive inclusions, e.g., a process, method, apparatus, product, or apparatus comprising a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0232] It should be understood that in the present disclosure, "at least one (item)" refers to one or more, and "plurality" refers to two or more. "And / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.

[0233] In the several embodiments provided in the present disclosure, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the above-mentioned units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0234] The units described above as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0235] In addition, the functional units in the various embodiments of the present disclosure may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0236] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present disclosure is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including multiple instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method of each embodiment of the present disclosure. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk, and other media that can store programs.

[0237] The preferred embodiments of the present disclosure are described above with reference to the accompanying drawings, but are not intended to limit the scope of the present disclosure. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and essence of the present disclosure should be within the scope of the present disclosure.

Claims

1. A multi-source intelligence fusion processing method, characterized in that: include: Obtain target address information to be detected, and obtain first network threat intelligence data corresponding to the target address information from an internal intelligence source, and obtain second network threat intelligence data corresponding to the target address information from multiple external intelligence sources respectively; Performing a quality assessment on each of the external intelligence sources under a plurality of different intelligence source quality assessment dimensions to obtain a plurality of quality assessment scores, and weighting the plurality of quality assessment scores to obtain a comprehensive quality score corresponding to each of the external intelligence sources; When the first network threat intelligence data determines that the target address information is unknown address information, determining a determination result of each second network threat intelligence data on the target address information; Determining a first quantity of the target address information as malicious address information from the determination results corresponding to each of the external intelligence sources; Determining a second number of the external intelligence sources, and determining a proportion of the plurality of external intelligence sources that determine that the target address information is the malicious address information based on the first number and the second number; When the determination ratio reaches a preset ratio, and the quality comprehensive score corresponding to the external intelligence source that determines that the target address information is the malicious address information reaches a preset score, the target address information is determined to be the malicious address information; When the determination ratio is lower than the preset ratio, or the comprehensive quality score corresponding to the external intelligence source that determines that the target address information is malicious address information is lower than the preset score, different count values are assigned to each external intelligence source based on different determination results; Determine the weighting coefficient of the corresponding external intelligence source based on the comprehensive quality score, and perform weighted fusion according to the weighting coefficient and the corresponding count value under each external intelligence source to obtain a multi-source intelligence fusion value; The malicious address determination result of the target address information is determined based on the size of the multi-source intelligence fusion value.

2. The multi-source intelligence fusion processing method according to claim 1, characterized in that: The multi-source intelligence fusion processing method further includes: Determining an internal confidence level of the internal intelligence source from the first network threat intelligence data, wherein the internal confidence level has a value between 0 and 1; Obtain a preset voting ratio adjustment coefficient and a basic voting threshold, determine the difference between 1 and the internal confidence, multiply the difference by the voting ratio adjustment coefficient to obtain a product, and obtain the preset ratio based on the sum of the product and the basic voting threshold.

3. The multi-source intelligence fusion processing method according to claim 1, characterized in that: Determining the corresponding weighting coefficient of the external intelligence source based on the comprehensive quality score includes: Accumulate the comprehensive quality scores of multiple external intelligence sources to obtain a total quality score; The ratio of the comprehensive quality score of each external intelligence source to the total quality score is used as the weighting coefficient of the corresponding external intelligence source.

4. The multi-source intelligence fusion processing method according to claim 1, characterized in that: The multi-source intelligence fusion processing method further includes: When the first network threat intelligence data determines that the target address information is malicious address information, and the internal confidence of the internal intelligence source is greater than a preset confidence threshold, determining the determination results of each second network threat intelligence data on the target address information; When the determination result under any one of the external intelligence sources also determines that the target address information is the malicious address information, it is determined that the target address information is the malicious address information.

5. The multi-source intelligence fusion processing method according to claim 1, characterized in that: The step of performing a quality assessment on each of the external intelligence sources under a plurality of different intelligence source quality assessment dimensions to obtain a plurality of quality assessment scores, and weighting the plurality of quality assessment scores to obtain a comprehensive quality score corresponding to each of the external intelligence sources, includes: Performing a quality assessment on each of the external intelligence sources based on intelligence update time, intelligence source confidence, intelligence source comprehensiveness, intelligence source authority, and intelligence source stability, thereby obtaining an intelligence update time score, an intelligence source confidence score, an intelligence source comprehensiveness score, an intelligence source authority score, and an intelligence source stability score for each of the external intelligence sources; Multiple of the intelligence update time score, the intelligence source confidence score, the intelligence source comprehensiveness score, the intelligence source authority score and the intelligence source stability score are weighted to obtain a comprehensive quality score corresponding to each external intelligence source.

6. The multi-source intelligence fusion processing method according to claim 5, characterized in that: The quality assessment of each external intelligence source is performed based on intelligence update time, intelligence source confidence, intelligence source comprehensiveness, intelligence source authority, and intelligence source stability, to obtain an intelligence update time score, intelligence source confidence score, intelligence source comprehensiveness score, intelligence source authority score, and intelligence source stability score for each external intelligence source, including: Based on the difference between the current time and the update time of each second network threat intelligence data, rounding down according to the preset step time interval to determine the corresponding first deduction step value, and deducting the corresponding first deduction step value in sequence based on the preset initial time score to obtain the intelligence update time score of each external intelligence source that changes in a step-by-step manner; Obtaining the external confidence of each of the external intelligence sources, and mapping the external confidence to a confidence value corresponding to the confidence level, to obtain an intelligence source confidence score for each of the external intelligence sources; Ranking the plurality of external intelligence sources under the plurality of intelligence source comprehensiveness dimensions to obtain comprehensiveness rankings, determining a second deduction step value corresponding to each external intelligence source according to the comprehensiveness rankings, and sequentially deducting the corresponding second deduction step values based on a preset initial comprehensiveness score to obtain a step-wise intelligence source comprehensiveness score for each external intelligence source; Ranking the plurality of external intelligence sources under the plurality of intelligence source authority dimensions to obtain an authority ranking, and determining a third deduction step value corresponding to each external intelligence source according to the authority ranking, and deducting the corresponding third deduction step value in sequence based on a preset initial authority score to obtain an intelligence source authority score for each external intelligence source that changes in a step-by-step manner; Determine the intelligence update frequency, error volatility score and historical stability score of each of the external intelligence sources, and weight the intelligence update frequency, error volatility score and historical stability score to obtain the intelligence source stability score for each of the external intelligence sources.

7. The multi-source intelligence fusion processing method according to claim 1, characterized in that: The obtaining of first network threat intelligence data corresponding to the target address information from an internal intelligence source, and obtaining second network threat intelligence data corresponding to the target address information from multiple external intelligence sources, respectively, include: Acquire multiple different types of preset fields from an internal intelligence source and multiple external intelligence sources, respectively, wherein the preset fields include an information source field, a maliciousness level field, an intelligence threat type field, an intelligence threat level field, and a confidence level field; Performing data cleaning and formatting processing on the preset fields of the same type to obtain a plurality of target fields after the data cleaning and formatting processing; First network threat intelligence data is obtained based on the multiple target fields corresponding to the internal intelligence source, and corresponding second network threat intelligence data is obtained based on the multiple target fields corresponding to each of the external intelligence sources.

8. The multi-source intelligence fusion processing method according to claim 1, characterized in that: After determining the malicious address determination result of the target address information based on the magnitude of the multi-source intelligence fusion value, the multi-source intelligence fusion processing method further includes: Receive intelligence sharing requests from target terminals; parsing the intelligence sharing request, determining the sharing authority of the target terminal, and selecting shared information from the first network threat intelligence data, the second network threat intelligence data, and the malicious address determination result based on the sharing authority; The shared information is sent to the target terminal.

9. A multi-source intelligence fusion processing device, characterized in that: include: a data acquisition module, configured to acquire target address information to be detected, and to acquire first network threat intelligence data corresponding to the target address information from an internal intelligence source, and to acquire second network threat intelligence data corresponding to the target address information from multiple external intelligence sources; a quality assessment module, configured to perform a quality assessment on each of the external intelligence sources under a plurality of different intelligence source quality assessment dimensions to obtain a plurality of quality assessment scores, and to weight the plurality of quality assessment scores to obtain a comprehensive quality score corresponding to each of the external intelligence sources; a preliminary determination module, configured to, when the first network threat intelligence data determines that the target address information is unknown address information, determine a determination result of each of the second network threat intelligence data on the target address information, and determine a first number of the target address information determined to be malicious address information from the determination results corresponding to each of the external intelligence sources; Determining a second number of the external intelligence sources, and determining a proportion of the plurality of external intelligence sources that determine that the target address information is the malicious address information based on the first number and the second number; When the determination ratio reaches a preset ratio, and the comprehensive quality score corresponding to the external intelligence source that determines that the target address information is the malicious address information reaches a preset score, the target address information is determined to be the malicious address information; when the determination ratio is lower than the preset ratio, or the comprehensive quality score corresponding to the external intelligence source that determines that the target address information is the malicious address information is lower than the preset score, different counting values are assigned to each of the external intelligence sources based on different determination results; A multi-source fusion module is used to determine the weighting coefficient of the corresponding external intelligence source based on the comprehensive quality score, and perform weighted fusion according to the weighting coefficient and the corresponding count value of each external intelligence source to obtain a multi-source intelligence fusion value; The malicious determination module is used to determine the malicious address determination result of the target address information based on the size of the multi-source intelligence fusion value.

10. An electronic device, characterized in that: The electronic device includes a memory and a processor, the memory stores a computer program, and the processor implements the multi-source intelligence fusion processing method according to any one of claims 1 to 8 when executing the computer program.

11. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the multi-source intelligence fusion processing method according to any one of claims 1 to 8 is implemented.

Citation Information

Patent Citations

  • Multi-source threat intelligence processing method and device

    CN113992374A

  • Internet protocol address identification method and device, computer equipment and storage medium

    CN118250095A