Threat intelligence detection method and device, electronic equipment and storage medium
By extracting the query fields in the log to be detected and matching them in the threat intelligence source, the intelligence log is generated and the threat intelligence detailed data is associated with the threat intelligence, and the problem of inefficient querying threat intelligence in the existing technology is solved, achieving fast and efficient threat intelligence query.
Patent Information
- Application Number
- CN202311746359.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-18
- Publication Date
- 2025-06-20
AI Technical Summary
In the prior art, the inquiry of threat intelligence is relatively inefficient, and it is difficult to quickly obtain the required threat intelligence.
By obtaining the log to be detected, extracting query fields related to the risk of the preset type, and matching them in the threat intelligence source, generating the intelligence log and the threat intelligence detailed data associated with the query field, to achieve rapid query.
It improves the efficiency of querying threat intelligence, reduces the need for manual query, and can quickly obtain relevant threat intelligence detailed data.
Smart Images

Figure CN120179871A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of computers, and more particularly, to a threat intelligence detection method, apparatus, electronic device, and storage medium. Background Art
[0002] Threat intelligence is usually stored in a threat intelligence database. Currently, usually when the system discovers an alarm, according to the alarm information, manually query the threat data related to the alarm information from the threat database. However, the query efficiency of this method is relatively low, and it is difficult to quickly obtain the required threat intelligence. Summary of the Invention
[0003] The present application provides a threat intelligence detection method, apparatus, electronic device, and storage medium to solve the problem in the prior art that the efficiency of querying threat intelligence is relatively low and it is difficult to quickly obtain the required threat intelligence.
[0004] In a first aspect, the present application provides a threat intelligence detection method, including: obtaining a log to be detected; extracting at least one query field related to a risk of a preset type from the log to be detected; matching each of the query fields in a threat intelligence source to obtain a matching result corresponding to each of the query fields; where the matching result indicates whether the log to be detected has a risk of this type, and various types of risks and corresponding detailed threat intelligence data are stored in the threat intelligence source; when the matching result indicates that the log to be detected has a risk of this type, obtaining the detailed threat intelligence data matching each of the query fields from the threat intelligence source; generating an intelligence log of the log to be detected, and associating the intelligence log with the detailed threat intelligence data of each of the query fields.
[0005] In an embodiment of the present application, since the intelligence log is associated with the detailed threat intelligence data, therefore, when it is necessary to query the threat intelligence of the log to be detected subsequently, the detailed threat intelligence data associated with the intelligence log can be directly found based on the intelligence log of the log to be detected. Thus, there is no need to manually query the threat data related to the alarm information from the threat database, improving the efficiency of querying threat intelligence.
[0006] Combined with the technical solution provided in the above first aspect, in some possible implementation manners, generating an intelligence log of the log to be detected, and associating the intelligence log with the detailed threat intelligence data of each of the query fields includes: determining whether the detailed threat intelligence data meets a preset risk determination condition; when the risk determination condition is met, generating an intelligence log of the log to be detected, and associating the intelligence log with the detailed threat intelligence data of each of the query fields.
[0007] In the embodiments of the present application, by further judging the detailed threat intelligence data, an intelligence log of the log to be detected is generated only when the detailed threat intelligence data meets the risk determination conditions, thereby improving the credibility of the intelligence log.
[0008] Combined with the technical solution provided in the first aspect above, in some possible implementation manners, extracting at least one query field related to a risk of a preset type from the log to be detected includes: judging whether the log to be detected meets a preset log matching rule corresponding to the risk of the preset type; when the log to be detected meets the log matching rule, extracting at least one query field related to the risk of the preset type from the log to be detected.
[0009] In the embodiments of the present application, by judging whether the log to be detected meets a preset log matching rule corresponding to a risk of a preset type, the log to be detected can be screened, so as to screen out the log to be detected that does not need to extract the query field related to the risk of the preset type, reducing the calculation amount of this solution.
[0010] Combined with the technical solution provided in the first aspect above, in some possible implementation manners, after extracting at least one query field related to the risk from the log to be detected, the method further includes: splicing the at least one query field into a query string; correspondingly, matching each of the query fields in the threat intelligence source to obtain a matching result of each of the query fields, including: matching the query string in the threat intelligence source to obtain a matching result corresponding to the query string.
[0011] In the embodiments of the present application, by splicing at least one query field into a query string and then using the query string to match in the threat intelligence source, the situation of query field loss during data transmission can be reduced, improving the security of this solution.
[0012] Combined with the technical solution provided in the first aspect above, in some possible implementation manners, the threat intelligence sources include a local intelligence source and a third-party intelligence source. The threat intelligence in the local intelligence source is less than that in the third-party intelligence source. Matching each of the query fields in the threat intelligence sources to obtain the matching results of each of the query fields includes: matching the query string in the local intelligence source; if there is a first matching result corresponding to the query string in the local intelligence source, using the first matching result as the final matching result of the query string; if there is no first matching result corresponding to the query string in the local intelligence source, matching the query string in the third-party intelligence source to obtain a second matching result of the query string, and using the second matching results of each of the query fields as the final matching result of the query string.
[0013] In the embodiments of the present application, by first matching the query string in the local intelligence source and, in the case of a matching failure, then matching the query string in the third-party intelligence source. Thus, the number of times of matching the query string from the third party can be reduced, and further the number of data interactions between the local device and the third-party device can be reduced, so that the matching time can be reduced and the matching efficiency can be improved.
[0014] Combined with the technical solution provided in the first aspect above, in some possible implementation manners, after matching the query field in the third-party intelligence source to obtain a second matching result, the method further includes: recording the second matching result and the detailed threat intelligence data corresponding to the second matching result in the local intelligence source.
[0015] In the embodiments of the present application, by recording the second matching result and the detailed threat intelligence data corresponding to the second matching result in the local intelligence source, the update of the local intelligence source is realized.
[0016] Combined with the technical solution provided in the first aspect above, in some possible implementation manners, matching each of the query fields in the threat intelligence sources to obtain the matching results corresponding to each of the query fields includes: putting the query string into a preset list of query fields to be queried; when the number of query strings included in the list of query fields to be queried meets a preset condition, respectively matching all the query strings in the list of query fields to be queried in the threat intelligence sources, and putting the query string being matched into a list of query fields in progress; in the case of obtaining a matching result of any one of the query strings, removing the query string from the list of query fields in progress.
[0017] In the embodiments of the present application, by setting a query field list, batch matching of multiple query strings can be achieved, improving the matching efficiency. At the same time, it is set that when the matching result is obtained, the query fields are removed from the query middle field list, so as to ensure that each query string can obtain a matching result.
[0018] In a second aspect, the present application provides a threat intelligence detection device, including: an intelligence detection engine and an intelligence update module. The intelligence detection engine is used to obtain logs to be detected; the intelligence detection engine is further used to extract at least one query field related to risks of a preset type from the logs to be detected; the intelligence update module is used to match each of the query fields in a threat intelligence source to obtain a matching result corresponding to each of the query fields; wherein, the matching result indicates whether the logs to be detected have risks of this type, and various types of risks and corresponding detailed threat intelligence data are stored in the threat intelligence source; the intelligence update module is further used to obtain detailed threat intelligence data matching each of the query fields from the threat intelligence source when the matching result indicates that the logs to be detected have risks of this type; the intelligence detection engine is further used to generate an intelligence log of the logs to be detected and associate the intelligence log with the detailed threat intelligence data of each of the query fields.
[0019] In a third aspect, the present application provides an electronic device, including: a memory and a processor, the memory is connected to the processor; the memory is used to store a program; the processor is used to call the program stored in the memory to execute the method described in the first aspect above and / or in any possible implementation manner in combination with the first aspect above.
[0020] In a fourth aspect, the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a computer, it executes the method described in the first aspect above and / or in any possible implementation manner in combination with the first aspect above. Description of the Drawings
[0021] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required to be used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as a limitation of the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.
[0022] Figure 1 It is a schematic flowchart of the first threat intelligence detection method shown in the embodiments of the present application;
[0023] Figure 2Schematic flowchart of the second threat intelligence detection method shown in the embodiments of the present application;
[0024] Figure 3 Block diagram of the structure of a threat intelligence detection device shown in the embodiments of the present application;
[0025] Figure 4 Data interaction diagram of the first threat intelligence detection device shown in the embodiments of the present application;
[0026] Figure 5 Data interaction diagram of the second threat intelligence detection device shown in the embodiments of the present application;
[0027] Figure 6 Data interaction diagram of the third threat intelligence detection device shown in the embodiments of the present application;
[0028] Figure 7 Block diagram of the structure of the first electronic device shown in the embodiments of the present application. Detailed implementation manners
[0029] Next, the technical solutions in the embodiments of the present application will be described in conjunction with the accompanying drawings in the embodiments of the present application.
[0030] It should be noted that: Similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present application, relational terms such as "first", "second", etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device.
[0031] Next, the technical solutions of the present application will be described in detail with reference to the accompanying drawings.
[0032] Please refer to Figure 1 , Figure 1 which is a threat intelligence detection method shown in the embodiments of the present application. Next, the specific steps included therein will be described in conjunction with Figure 1 thereof.
[0033] S100: Obtain the log to be detected.
[0034] Among them, the log to be detected can be a traffic log, a device log, etc., and the specific type of the log to be detected is not restricted here.
[0035] The log to be detected can be pre-obtained and stored in a storage medium, and can be directly called when needed; or, the log to be detected can also be obtained in real time.
[0036] S200: Extract at least one query field related to the risk of a preset type from the log to be detected.
[0037] The risk of the preset type can be set according to actual needs. Among them, different types of risks can be classified according to risk behaviors. Or, it can also be classified according to the field types required for detecting risks. For example, the risks that require two fields, namely domain name and port, for detection are classified into one category. The types of query fields corresponding to the same type of risk are the same.
[0038] Optionally, when there are multiple types of risks of the preset type, in each case of obtaining the log to be detected, for each type of risk of the preset type, extract at least one query field related to the risk of this type from the log to be detected. And for the query fields corresponding to each type of risk of the preset type, respectively execute the subsequent S300 - S500.
[0039] Optionally, when there are multiple types of risks of the preset type, inspection rules can be set for each type of risk of the preset type. Among them, the detection rule is used to indicate the type of query field that needs to be extracted from the log to be detected, and the detection rules corresponding to different types of risks can be different. Correspondingly, the specific method of extracting at least one query field related to the risk of the preset type from the log to be detected can be: based on the detection rule corresponding to the risk of the preset type, extract at least one query field related to the risk of this type from the log to be detected.
[0040] In one implementation, in order to reduce the occurrence of the situation where query fields are lost during data transmission, after extracting at least one query field related to the risk of the preset type from the log to be detected, at least one query field can also be concatenated into a query string.
[0041] Correspondingly, the specific method of matching each query field in the threat intelligence source to obtain the matching result of each query field is: match the query string in the threat intelligence source to obtain the matching result corresponding to the query string.
[0042] Among them, during the process of concatenating at least one query field into a query string, a delimiter can be added between different query fields.
[0043] The delimiter can be a character such as a colon, a slash, etc., and the specific type of the delimiter is not restricted here.
[0044] Optionally, in order to facilitate the threat intelligence source to accurately identify the type of each field in the query string, a marker representing the type of the query string can be added to the query string. After receiving the query string, the threat intelligence source looks up the data composition of the string in a preset comparison table composed of markers and string data according to the marker in the query string, and splits the query string according to the data composition.
[0045] For the sake of easy understanding, taking the first character of the query string as the marker and the colon as the delimiter as an example for illustration. If the query string is Field A: Field B: Field C: Field D. After the threat intelligence source receives the query string, it first looks up the string data composition corresponding to Field 1 in the preset comparison table composed of markers and string data. If the query result is that the first field of the query string represents a marker, the second field represents a domain name, the third field represents a website address, and the fourth field represents a port, then it can be determined that Field B is a domain name, Field C is a website address, and Field D is a port. The example here is only for easy understanding and should not be regarded as a limitation to this application.
[0046] In one implementation manner, the specific process of extracting at least one query field related to a risk of a preset type from the log to be detected can be: first, determine whether the log to be detected meets a preset log matching rule corresponding to the risk of the preset type; in the case where the log to be detected meets the log matching rule, extract at least one query field related to the risk of the preset type from the log to be detected.
[0047] By determining whether the log to be detected meets a preset log matching rule corresponding to the risk of the preset type, the log to be detected can be screened, so as to screen out the log to be detected that does not need to extract the query field related to the risk of the preset type, reducing the calculation amount of this solution.
[0048] Among them, the log matching rule can be to limit the log type. For example, if the log matching rule limits that it must be a traffic log, then in the case where the log to be detected is a device log, it is considered that the log to be detected does not meet the log matching rule. In the case where the log to be detected is a traffic log, it is considered that the log to be detected meets the log matching rule and the next step can be continued.
[0049] Alternatively, the log matching rule can also be to limit the data types that need to be included in the log. When the data types limited in the log matching rule are included in the log to be detected, it is considered that the log to be detected meets the log matching rule, and the next step can be continued. When the data types limited in the log matching rule are not included in the log to be detected, it is considered that the log to be detected does not meet the log matching rule.
[0050] Among them, the data types that need to be included in the log limited in the log matching rule can be the same as the types of query fields to be extracted.
[0051] Optionally, when there are multiple types of risks of a preset type and there is a detection rule corresponding to each type of risk, it is possible to first determine whether the log to be detected meets the log detection rule corresponding to the risk for each preset type of risk. When the log to be detected meets the log matching rule corresponding to the risk, a composite log is generated based on the log to be detected and the detection rule corresponding to the type of risk. Correspondingly, S200 is to extract at least one query field related to the risk corresponding to the detection rule from the composite log according to the detection rule.
[0052] Among them, the same log to be detected can meet the log matching rules of multiple preset types of risks. Therefore, the same log to be detected can correspond to multiple composite logs.
[0053] S300: Match each query field in the threat intelligence source to obtain the matching result corresponding to each query field.
[0054] Among them, the matching result indicates whether there is a risk of this type in the log to be detected, and various types of risks and corresponding detailed threat intelligence data are stored in the threat intelligence source.
[0055] The threat intelligence source records the matching conditions corresponding to the threat intelligence. Therefore, after the threat intelligence source receives each query field of the log to be detected, all query fields of the log to be detected are used as query conditions to search for threat intelligence that matches each query field of the log to be detected from the data stored in itself. If threat intelligence that matches each query field of the log to be detected is found, a matching result indicating the existence of this type of risk is returned. If there is no threat intelligence that matches each query field of the log to be detected, a matching result indicating the non-existence of this type of risk is returned.
[0056] Among them, the threat intelligence that matches each query field of the log to be detected specifically indicates that all matching conditions of the threat intelligence can be satisfied by the query fields of the log to be detected.
[0057] For example, if the query fields include domain name A, port B, and IP1, when the matching conditions of threat intelligence 1 are domain name A, port B, and IP1, it is considered that each query field of the log to be detected matches threat intelligence 1. The example here is only for easy understanding and should not be regarded as a limitation to this application.
[0058] In one implementation, the threat intelligence sources include a local intelligence source and a third-party intelligence source, and the threat intelligence in the local intelligence source is less than that in the third-party intelligence source. Correspondingly, the specific manner of matching each query field in the threat intelligence sources to obtain the matching results of each query field may be: first, match each query field in the local intelligence source. If there is a first matching result corresponding to each query field in the local intelligence source, then use the first matching result as the final matching result of the query field.
[0059] If there is no first matching result corresponding to the query field in the local intelligence source, then match the query field in the third-party intelligence source to obtain a second matching result of the query field, and use the second matching results of each query field as the final matching results of the query string.
[0060] Among them, the specific manner of matching each query field in the local intelligence source and the specific manner of matching the query field in the third-party intelligence source are the same as the specific manner of matching each query field in the threat intelligence sources described above. For the sake of brief description, it will not be elaborated here.
[0061] The local intelligence source can be any type of threat intelligence database, and the third-party intelligence source can be any type of threat intelligence database deployed in a third-party device.
[0062] Optionally, when matching the query field in the third-party intelligence source and after a preset duration, if no second matching result is obtained from the feedback of the third-party intelligence source, write each of these query fields into the list of query fields waiting for matching results. And after a certain period of time, match each of these query fields in the local intelligence source again. Among them, when the third-party intelligence source feedbacks the second matching result, store the second matching result and the corresponding query fields into the local intelligence source. Therefore, when matching each of these query fields in the local intelligence source again, if the third-party intelligence source has already feedback the second matching result, the second matching result can be obtained from the local intelligence source.
[0063] In one implementation, when at least one query field is concatenated into a query string, the specific method of matching each query field in the threat intelligence source to obtain the matching result of each query field may be: matching the query string in the local intelligence source; if there is a first matching result corresponding to the query string in the local intelligence source, then using the first matching result as the final matching result of the query string; if there is no first matching result corresponding to the query string in the local intelligence source, then matching the query string in the third-party intelligence source to obtain a second matching result of the query string, and using the second matching result of each query string as the final matching result of the query string.
[0064] Among them, the specific implementation method of the query string has been described clearly above. For the sake of brief description, it will not be elaborated here.
[0065] After receiving the query string, the local intelligence source or the third-party intelligence source splits the query string to obtain multiple query fields, and then uses the query fields to perform matching in the local intelligence source / third-party intelligence source. The specific method of using the query fields to perform matching in the local intelligence source / third-party intelligence source has been described clearly above. For the sake of brief description, it will not be elaborated here.
[0066] In one implementation, the local intelligence source may include multiple records, and each record includes the corresponding relationship between each historical query field and the historical matching result. In this case, the specific method of matching each query field in the local intelligence source is: checking in the local intelligence source whether there is a record in which the historical query field is exactly the same as each query field of the log to be detected. If there is, use the matching result included in the record as the matching result of the log to be detected.
[0067] For example, a record may record the matching result 1 corresponding to two query fields, namely domain name A and IP (Internet Protocol Address) 1. Then, when each query field of the log to be detected is domain name A and IP1, the matching result 1 can be used as the matching result corresponding to the log to be detected. The example here is only for easy understanding and should not be used as a limitation to this application.
[0068] Optionally, when at least one query field is concatenated into a query string, each record in the local intelligence source may record the corresponding relationship between the historical query string and the historical matching result. Correspondingly, the specific method of matching each query field in the local intelligence source is: checking in the local intelligence source whether there is a record in which the historical query string is exactly the same as the query string of the log to be detected. If there is, use the matching result included in the record as the matching result of the log to be detected.
[0069] In one implementation, when the second matching result is obtained, a new record is added to the local information source based on the second matching result. The added record includes each query field or query string corresponding to the second matching result. If the second matching result indicates that the log to be detected has this type of risk, the detailed threat intelligence data corresponding to the second matching result is stored.
[0070] To prevent the local data source from occupying too much memory, optionally, when the memory occupied by the local data source is greater than the preset memory threshold, some data recorded in the local data source is deleted. Among them, the deleted data can be the N records with the longest recording time; or, the deleted data can also be the N records with the longest time that are not hit by each query field or query string. Here, N is a positive integer.
[0071] Alternatively, only records with an update time less than a preset duration can be retained in the local data source. For example, only records updated within three days can be retained in the local data source. All records older than three days are deleted. The example here is only for easy understanding and should not be construed as a limitation of this application.
[0072] In one implementation, the specific process of matching each query field in the threat intelligence source to obtain the matching result corresponding to each query field can be as follows: First, the query string is placed in a preset list of query fields to be queried. When the number of query strings included in the list of query fields to be queried meets the preset condition, all the query strings in the list of query fields to be queried are respectively matched in the threat intelligence source, and the query string being matched is placed in the list of query fields in the query. Finally, when the matching result of any query string is obtained, the query string is removed from the list of query fields in the query.
[0073] Optionally, when the query string is placed in the preset list of query fields to be queried, it can be first detected whether there is a string identical to the query string in the list of query fields to be queried. If so, the query string is not written into the list of query fields to be queried.
[0074] Optionally, after the number of query strings included in the list of query fields in the query is greater than the preset threshold, receiving new logs to be detected can also be stopped. Until the number of query strings included in the list of query fields in the query is less than the preset normal value, new logs to be detected are continued to be received.
[0075] S400: When the matching result indicates that the log to be detected has this type of risk, obtain the detailed threat intelligence data matching each query field from the threat intelligence source.
[0076] S500: Generate an intelligence log for the log to be detected and associate the intelligence log with the detailed threat intelligence data of each query field.
[0077] Since the intelligence log is associated with the threat intelligence detailed data, when it is necessary to query the threat intelligence of the log to be detected subsequently, the detailed threat intelligence data associated with the intelligence log can be directly found based on the intelligence log of the log to be detected. Thus, there is no need to manually query the threat data related to the alarm information from the threat database, improving the efficiency of querying threat intelligence.
[0078] In one implementation, the specific method for generating the intelligence log of the log to be detected and associating the intelligence log with the detailed threat intelligence data of each query field may be: first, determine whether the detailed threat intelligence data meets the preset risk determination condition. When the risk determination condition is met, generate the intelligence log of the log to be detected and associate the intelligence log with the detailed threat intelligence data of each query field.
[0079] Among them, the risk determination condition is a condition for screening the detailed threat intelligence data. The risk determination condition may include that the confidence level of the detailed threat intelligence data is greater than the preset confidence level, the threat level of the detailed threat intelligence data is greater than the preset threat level, etc. The specific content of the risk determination condition can be set according to actual needs, and the specific content of the risk determination condition is not limited here.
[0080] Optionally, the risk determination conditions corresponding to different preset types of risks may be different.
[0081] In one implementation, the intelligence log may include a threat intelligence field and a log to be detected field. The threat intelligence field is used to represent the detailed threat intelligence data corresponding to the intelligence log, and the log to be detected field is used to represent the log to be detected corresponding to the intelligence log. Thus, the corresponding log to be detected can be found according to the log to be detected field of the intelligence log, and the corresponding detailed threat intelligence data can be found according to the threat intelligence field of the intelligence log.
[0082] Optionally, the intelligence log may further include a custom field, and the specific content of the custom field can be filled according to the actual needs of the user.
[0083] For the convenience of understanding the above threat intelligence detection method, please refer to Figure 2 , Figure 2 which is a schematic flowchart of a threat intelligence detection method shown in an embodiment of the present application.
[0084] As Figure 2 shown, determine whether the number of query strings included in the query string list in the field is greater than a preset threshold. If it is greater than the preset threshold, stop obtaining the log to be detected. If the number of query strings included in the query string list in the field is less than the preset normal value, obtain the log to be detected.
[0085] Then, obtain the detection rules corresponding to each preset type of risk, and for each detection rule, determine whether the log to be detected meets the log matching rule corresponding to the risk of the preset type corresponding to the detection rule. In the case where the log to be detected does not meet the log matching rule, no longer use the detection rule to detect the log to be detected.
[0086] In the case where the log to be detected meets the log matching rule corresponding to the risk of the preset type corresponding to the detection rule, generate a composite log based on the log to be detected and the detection rule. And extract at least one query field corresponding to the detection rule from the composite log. Combine the at least one query field into a query string.
[0087] Write the query string into the set list of query fields to be queried. When the number of query strings included in the list of query fields to be queried meets the preset condition, match the query string in the local intelligence source.
[0088] If there is a first matching result corresponding to the query string in the local intelligence source, use the first matching result as the final matching result of the query string.
[0089] If there is no first matching result corresponding to the query string in the local intelligence source, match the query string in the third-party intelligence source to obtain a second matching result of the query string, and use the second matching result of each query string as the final matching result of the query string.
[0090] If the final matching result of the query string indicates that the log to be detected has this type of risk, obtain the detailed threat intelligence data matching each query field from the threat intelligence source.
[0091] Determine whether the detailed threat intelligence data meets the preset risk determination conditions. In the case of meeting the risk determination conditions, generate an intelligence log of the log to be detected, and associate the intelligence log with the detailed threat intelligence data of each query field.
[0092] Figure 2 The specific implementation manners of the steps shown above have been clearly described in the foregoing, and for the sake of brief description, they will not be elaborated here.
[0093] Based on the same technical concept, the present application also provides a threat intelligence detection device, as Figure 3 shown, the threat intelligence detection device 100 includes an intelligence detection engine 110 and an intelligence update module 120.
[0094] The intelligence detection engine 110 is used to obtain the log to be detected.
[0095] The intelligence detection engine 110 is further configured to extract at least one query field related to a risk of a preset type from the log to be detected.
[0096] The intelligence update module 120 is configured to match each of the query fields in a threat intelligence source to obtain a matching result corresponding to each of the query fields; wherein, the matching result indicates whether there is a risk of this type in the log to be detected, and various types of risks and corresponding detailed threat intelligence data are stored in the threat intelligence source.
[0097] The intelligence update module 120 is further configured to, when the matching result indicates that there is a risk of this type in the log to be detected, obtain detailed threat intelligence data matching each of the query fields from the threat intelligence source.
[0098] The intelligence detection engine 110 is further configured to generate an intelligence log of the log to be detected and associate the intelligence log with the detailed threat intelligence data of each of the query fields.
[0099] The intelligence detection engine 110 is specifically configured to determine whether the detailed threat intelligence data meets a preset risk determination condition; when the risk determination condition is met, generate an intelligence log of the log to be detected and associate the intelligence log with the detailed threat intelligence data of each of the query fields.
[0100] The intelligence detection engine 110 is specifically configured to determine whether the log to be detected meets a preset log matching rule corresponding to the risk of the preset type; when the log to be detected meets the log matching rule, extract at least one query field related to the risk of the preset type from the log to be detected.
[0101] After extracting at least one query field related to the risk from the log to be detected, the intelligence detection engine 110 is further configured to splice the at least one query field into a query string.
[0102] Correspondingly, the intelligence update module 120 is specifically configured to match the query string in the threat intelligence source to obtain a matching result corresponding to the query string.
[0103] The threat intelligence sources include local intelligence sources and third-party intelligence sources. The threat intelligence in the local intelligence sources is less than that in the third-party intelligence sources. The intelligence update module 120 is specifically configured to match the query string in the local intelligence sources. If there is a first matching result corresponding to the query string in the local intelligence sources, the first matching result is used as the final matching result of the query string. If there is no first matching result corresponding to the query string in the local intelligence sources, the query string is matched in the third-party intelligence sources to obtain a second matching result of the query string, and the second matching results of the query strings are used as the final matching results of the query strings.
[0104] After matching the query field in the third-party intelligence sources to obtain a second matching result, the intelligence update module 120 is further configured to record the second matching result and the threat intelligence detailed data corresponding to the second matching result in the local intelligence sources.
[0105] The intelligence update module 120 is specifically configured to put the query string into a preset list of query fields to be queried. When the number of query strings included in the list of query fields to be queried meets a preset condition, all the query strings in the list of query fields to be queried are respectively matched in the threat intelligence sources, and the query string being matched is put into the list of query fields in progress. When a matching result of any query string is obtained, the query string is removed from the list of query fields in progress.
[0106] Optionally, the threat intelligence detection device may further include an intelligence rule management module. The intelligence rule management module is used to provide interfaces required for front-end interaction. Users can, through the interfaces of the threat intelligence detection device at the front end, implement querying, editing, importing, and exporting of detection rules; and maintain various configuration information for intelligence detection and update in the intelligence detection engine.
[0107] In one implementation, one implementation of the threat intelligence detection device is as Figure 4 shown. Figure 5 It is a schematic diagram of data interaction.
[0108] First, the intelligence rule management module can write data such as detection rules, log matching rules, risk determination conditions, and configuration information into the data layer (such as Redis (Remote Dictionary Server) cache). Among them, the detection rule is used to indicate the type of query fields that need to be extracted from the log to be detected, and each preset type of risk corresponds to a detection rule. Then, the intelligence detection engine can obtain data such as detection rules, log matching rules, risk determination conditions, and configuration information from the data layer. After that, the intelligence detection engine can obtain the log to be detected and extract at least one query field related to the type of risk from the log to be detected according to the detection rule corresponding to the preset type of risk.
[0109] After that, the intelligence detection engine writes at least one query field into the Kafka (a distributed messaging system) queue. The intelligence update module reads the at least one query field from the Kafka queue and matches each query field in the threat intelligence source (such as threat intelligence databases like TIP (Threaten Intelligence Platform) / TDE (Threat intelligence Detection Engine), etc.) to obtain the matching results corresponding to each query field. When the matching result indicates that the log to be detected has this type of risk, the detailed threat intelligence data matching each query field is obtained from the threat intelligence source. The intelligence update module writes the matching result and the detailed threat intelligence data (only when the matching result indicates that the log to be detected has this type of risk, there will be detailed threat intelligence data) into the Kafka queue.
[0110] The intelligence detection engine obtains the matching result and the detailed threat intelligence data from the Kafka queue, and generates an intelligence log for the log to be detected based on the matching result and the detailed threat intelligence data, and associates the intelligence log with the detailed threat intelligence data of each query field.
[0111] Among them, the intelligence detection engine can be implemented through Flink (a framework and distributed processing engine) and run on Yarn (Yet Another Resource Negotiator, a resource coordinator). The configuration information of the intelligence update module and the intelligence rule management module can be obtained from Nacos (Dynamic Naming and Configuration Service, a configuration management and service management platform). The intelligence rule management module is also used to read device information and monitor device changes.
[0112] Among them, Yarn can be, for example, Apache Hadoop Yarn (a new Hadoop resource manager, which is a general resource management system), etc., and its specific type is not restricted here.
[0113] In one implementation, a schematic diagram of data interaction of the threat intelligence detection device is as Figure 6 shown. Among them, Figure 6 the intelligence detection engine data synchronization task shown is part of the tasks in the intelligence detection engine. Figure 6 The data interaction and data processing performed by the intelligence detection engine and the intelligence detection engine data synchronization task in
[0114] are all executed by the intelligence detection engine 110 in this solution. Figure 6 As shown in
[0115]
[0116]
[0117]
[0118] shown, first, the intelligence rule management module writes the detection rules, log matching rules, risk determination conditions, and configuration information into the cache. The intelligence detection engine data synchronization task reads the detection rules, log matching rules, risk determination conditions, and configuration information from the cache and updates its own detection rules, log matching rules, risk determination conditions, and configuration information. At the same time, the intelligence detection engine data synchronization task can obtain the matching results and threat intelligence detailed data from the message queue to update the local intelligence source.
[0118] The threat intelligence detection device 100 provided in the embodiment of the present application has the same implementation principle and technical effects as those of the aforementioned threat intelligence detection method embodiment. For the sake of brief description, for matters not mentioned in the device embodiment, reference may be made to the corresponding contents in the aforementioned threat intelligence detection method embodiment.
[0119] See also Figure 7 , which is an electronic device 200 provided in an embodiment of the present application. The electronic device 200 includes: a processor 210 and a memory 220.
[0120] The memory 220 and the processor 210 are electrically connected to each other directly or indirectly to achieve data transmission or interaction. For example, these components can be electrically connected to each other via one or more communication buses or signal lines. The memory 220 is used to store computer programs, such as storing Figure 3 The software function module shown in is the threat intelligence detection device 100. Among them, the threat intelligence detection device 100 includes at least one software function module that can be stored in the memory 220 in the form of software or firmware or solidified in the operating system (OS) of the electronic device 200. The processor 210 is used to execute the executable module stored in the memory 220, such as the software function module or computer program included in the threat intelligence detection device 100. At this time, the processor 210 is used to obtain the log to be detected and extract at least one query field related to the preset type of risk from the log to be detected; match each of the query fields in the threat intelligence source to obtain the matching results corresponding to each of the query fields; wherein the matching result indicates whether the log to be detected has this type of risk, and the threat intelligence source stores various types of risks and corresponding threat intelligence detailed data; when the matching result indicates that the log to be detected has this type of risk, the threat intelligence detailed data matching each of the query fields is obtained from the threat intelligence source; an intelligence log of the log to be detected is generated, and the intelligence log is associated with the threat intelligence detailed data of each of the query fields.
[0121] Among them, the memory 220 may be, but is not limited to, RAM (Random Access Memory), ROM (Read Only Memory), PROM (Programmable Read-Only Memory), EPROM (Erasable Programmable Read-Only Memory), EEPROM (Electric Erasable Programmable Read-Only Memory), etc.
[0122] The processor 210 may be an integrated circuit chip with signal processing capabilities. The above-mentioned processor may be a general-purpose processor, including a CPU (Central Processing Unit), an NP (Network Processor), etc.; it may also be a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or the processor 210 may also be any conventional processor, etc.
[0123] Among them, the above-mentioned electronic device 200 includes, but is not limited to, a personal computer, a server, etc.
[0124] The embodiments of the present application also provide a computer-readable storage medium (hereinafter referred to as the storage medium). A computer program is stored on the storage medium. When the computer program is run by a computer such as the above-mentioned electronic device 200, it executes the threat intelligence detection method shown above. The computer-readable storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory, a random access memory, a magnetic disk, or an optical disc.
[0125] The above is only the preferred embodiment of the present application and is not used to limit the present application. For those skilled in the art, the present application may have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A threat intelligence detection method, characterized in that, Including: Obtain the log to be detected; Extract at least one query field related to risks of a preset type from the log to be detected; Match each of the query fields in a threat intelligence source to obtain a matching result corresponding to each query field; wherein, the matching result indicates whether the log to be detected has risks of this type, and various types of risks and corresponding detailed threat intelligence data are stored in the threat intelligence source; When the matching result indicates that the log to be detected has risks of this type, obtain the detailed threat intelligence data matching each query field from the threat intelligence source; Generate an intelligence log of the log to be detected and associate the intelligence log with the detailed threat intelligence data of each query field.
2. The method according to claim 1, characterized in that, Generating an intelligence log of the log to be detected and associating the intelligence log with the detailed threat intelligence data of each query field includes: Determine whether the detailed threat intelligence data meets a preset risk determination condition; When the risk determination condition is met, generate an intelligence log of the log to be detected and associate the intelligence log with the detailed threat intelligence data of each query field.
3. The method according to claim 1, characterized in that, Extracting at least one query field related to risks of a preset type from the log to be detected includes: Determine whether the log to be detected meets a preset log matching rule corresponding to the risks of the preset type; When the log to be detected meets the log matching rule, extract at least one query field related to the risks of the preset type from the log to be detected.
4. The method according to claim 1, characterized in that, After extracting at least one query field related to the risks from the log to be detected, the method further includes: Concatenate the at least one query field into a query string; Correspondingly, matching each of the query fields in a threat intelligence source to obtain a matching result corresponding to each query field includes: Match the query string in the threat intelligence source to obtain a matching result corresponding to the query string.
5. The method according to claim 4, characterized in that, The threat intelligence source includes a local intelligence source and a third-party intelligence source, and the threat intelligence in the local intelligence source is less than that in the third-party intelligence source. Matching each of the query fields in the threat intelligence source to obtain a matching result corresponding to each query field includes: Match the query string in the local intelligence source; If there is a first matching result corresponding to the query string in the local intelligence source, use the first matching result as the final matching result of the query string; If there is no first matching result corresponding to the query string in the local intelligence source, match the query string in the third-party intelligence source to obtain a second matching result of the query string, and use the second matching result of each query string as the final matching result of the query string.
6. The method according to claim 5, characterized in that, After matching the query field in the third-party intelligence source to obtain a second matching result, the method further includes: Record the second matching result and the detailed threat intelligence data corresponding to the second matching result into the local intelligence source.
7. The method according to claim 4, characterized in that, Match each of the query fields in the threat intelligence source to obtain the matching results corresponding to each of the query fields, including: Put the query string into a preset list of query fields to be queried; After the number of query strings included in the list of query fields to be queried meets a preset condition, match all the query strings in the list of query fields to be queried in the threat intelligence source respectively, and put the query string being matched into the list of query fields in progress; In the case of obtaining the matching result of any one of the query strings, remove the query string from the list of query fields in progress.
8. A threat intelligence detection device, characterized in that, Including: An intelligence detection engine for obtaining logs to be detected; The intelligence detection engine is further configured to extract at least one query field related to risks of a preset type from the logs to be detected; An intelligence update module for matching each of the query fields in the threat intelligence source to obtain the matching results corresponding to each of the query fields; wherein, the matching result indicates whether the logs to be detected have risks of this type, and various types of risks and corresponding detailed threat intelligence data are stored in the threat intelligence source; The intelligence update module is further configured to, in the case that the matching result indicates that the logs to be detected have risks of this type, obtain the detailed threat intelligence data matching each of the query fields from the threat intelligence source; The intelligence detection engine is further configured to generate an intelligence log of the logs to be detected and associate the intelligence log with the detailed threat intelligence data of each of the query fields.
9. An electronic device, characterized in that, Including: A memory and a processor, the memory is connected to the processor; The memory is used for storing programs; The processor is configured to call the program stored in the memory to execute the method according to any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, A computer program is stored thereon, and when the computer program is run by a computer, it executes the method according to any one of claims 1-7.