Threat intelligence life cycle determination method and device, equipment and medium

By using Netflow data analysis and cycle activity mapping relationships in threat intelligence systems, the life cycle of threat intelligence is dynamically adjusted, and the problem of insufficient flexibility of fixed cycle mode in the existing technology is solved, and the accuracy and timeliness of intelligence are improved.

CN120238345APending Publication Date: 2025-07-01CHINA TELECOM NETWORK SECURITY TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510372405.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-27
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

The method of determining threat intelligence life cycles using fixed cycles in the prior art lacks flexibility and cannot dynamically adjust according to the actual situation of threat intelligence, resulting in the validity period of the intelligence that does not match the actual situation, affecting the accuracy and timeliness of the intelligence.

Method used

By obtaining Netflow data in network traffic, finding the same source IP as the attack IP, determining the periodic activity of the source IP, and dynamically adjusting the life cycle of threat intelligence based on the periodic activity and pre-configured mapping relationship.

Benefits of technology

It realizes dynamic adjustment of the life cycle according to the actual situation of threat intelligence, and improves the accuracy and timeliness of threat intelligence.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238345A_ABST
    Figure CN120238345A_ABST
Patent Text Reader

Abstract

The invention discloses a threat intelligence life cycle determination method and device, equipment and a medium, and belongs to the technical field of network security, the method comprises the following steps: acquiring Netflow data in network traffic collected in a preset cycle, the Netflow data comprising a source IP and a destination IP; based on an attack IP of the threat intelligence collected in advance, searching a source IP which is the same as the attack IP from the Netflow data; based on the searched source IP and the target IP corresponding to the source IP, the periodic activeness of the source IP is determined, and the periodic activeness is used for representing the number of different target IPs interacting with the source IP in a preset period; and determining the life cycle of the threat intelligence corresponding to the attack IP which is the same as the source IP based on the periodic activeness and a pre-configured mapping relationship between the periodic activeness and the life cycle. And the accuracy and timeliness of threat intelligence are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and in particular, to a method, apparatus, device, and medium for determining the threat intelligence life cycle. Background Art

[0002] With the continuous evolution and complexity of network attack means, threat intelligence has become an important part of network security defense. Threat intelligence provides detailed information about potential threats, including malicious IP addresses, domain names, attack methods, attack families, etc., helping security teams identify and respond to threats in a timely manner.

[0003] Currently, the mainstream method for determining the threat intelligence life cycle mainly adopts a fixed-cycle mode. Taking domain name intelligence as an example, after some domain names are entered into the threat intelligence database, a validity period of 1 year is given according to established rules. However, in the real scenario, which is complex and changeable, factors such as the business characteristics corresponding to the domain name and the frequency of being attacked vary greatly. In fact, it takes 2 to 3 years for the threat effectiveness to disappear. Similarly, for IP intelligence, a validity period of 3 months is usually given, and it may actually lose its threat effectiveness in only 1 month due to factors such as the transfer of the attack source and the termination of malicious behavior, and should be expired in advance. Therefore, the fixed-cycle mode cannot dynamically adjust the life cycle according to the actual situation of threat intelligence. For example, for highly popular intelligence, that is, intelligence in areas with frequent network attacks, wide spread, and continuous attention, its life cycle should be appropriately extended to ensure continuous monitoring and protection; while for low-active intelligence, such as IPs or domain names that are no longer active, its life cycle should be appropriately shortened to reduce resource waste and false alarms.

[0004] Therefore, the method for determining the threat intelligence life cycle using a fixed cycle in the prior art lacks flexibility and cannot be dynamically adjusted according to the actual situation of threat intelligence, resulting in the inconsistency between the validity period of the intelligence and the actual situation, and affecting the accuracy and timeliness of the intelligence. Summary of the Invention

[0005] Embodiments of this application provide a method, apparatus, device, and medium for determining the threat intelligence life cycle, which can dynamically adjust the life cycle according to the actual situation of threat intelligence, and improve the accuracy and timeliness of threat intelligence.

[0006] In a first aspect, embodiments of this application provide a method for determining the threat intelligence life cycle, the method including:

[0007] Obtain Netflow data in network traffic collected within a preset period, where the Netflow data includes a source IP and a destination IP;

[0008] Based on the attack IPs of pre-collected threat intelligence, find source IPs in the Netflow data that are the same as the attack IPs;

[0009] Based on the found source IP and the destination IP corresponding to the source IP, determine the periodic activity of the source IP, where the periodic activity is used to characterize the number of different destination IPs that interact with the source IP within the preset period;

[0010] Based on the periodic activity and the pre-configured mapping relationship between the periodic activity and the lifecycle, determine the lifecycle of the threat intelligence corresponding to the attack IP that is the same as the source IP.

[0011] In some embodiments, each piece of Netflow data further includes a source port, a destination port, and a communication protocol. Before searching for the source IP that is the same as the attack IP from the Netflow data based on the attack IP of the pre-collected threat intelligence, it further includes:

[0012] For each piece of Netflow data, perform some or all of the following exclusion operations:

[0013] Exclude the Netflow data whose source IP is a preset source IP and / or whose destination IP is a preset destination IP;

[0014] Exclude the Netflow data whose source port or destination port does not belong to the preset port range;

[0015] Exclude the Netflow data whose communication protocol is not the preset communication protocol.

[0016] In some embodiments, searching for the source IP that is the same as the attack IP from the Netflow data based on the attack IP of the pre-collected threat intelligence includes:

[0017] For any source IP in the Netflow data, determine the Netflow data set corresponding to the any source IP, where the Netflow data set includes each piece of Netflow data in the Netflow data that interacts with the source IP for the same destination IP, and the source IPs and destination IPs of each piece of Netflow data in the same Netflow data set are the same;

[0018] For any attack IP, match the attack IP with the source IPs in each Netflow data set to determine the source IP that matches the any attack IP.

[0019] In some embodiments, before determining the lifecycle of the threat intelligence corresponding to the attack IP that is the same as the source IP based on the periodic activity and the pre-configured mapping relationship between the periodic activity and the lifecycle, the following steps are further included:

[0020] Determine whether the threat intelligence is configured with an original lifecycle. If so, determine the remaining lifecycle of the threat intelligence.

[0021] The step of determining the lifecycle of the threat intelligence corresponding to the attack IP that is the same as the source IP based on the periodic activity and the pre-configured mapping relationship between the periodic activity and the lifecycle includes:

[0022] Based on the remaining lifecycle, the periodic activity, and the pre-configured mapping relationship between the periodic activity and the lifecycle, determine the lifecycle of the threat intelligence corresponding to the attack IP that is the same as the source IP.

[0023] In some embodiments, the step of determining the lifecycle of the threat intelligence corresponding to the attack IP that is the same as the source IP based on the remaining lifecycle, the periodic activity, and the pre-configured mapping relationship between the periodic activity and the lifecycle includes:

[0024] Based on the periodic activity and the pre-configured mapping relationship between the periodic activity and the lifecycle, determine the current lifecycle of the threat intelligence.

[0025] Based on the current lifecycle and the remaining lifecycle, determine the lifecycle of the threat intelligence.

[0026] In some embodiments, the step of determining the current lifecycle of the threat intelligence based on the periodic activity and the pre-configured mapping relationship between the periodic activity and the lifecycle includes:

[0027] If the periodic activity is zero, determine zero as the current lifecycle of the threat intelligence.

[0028] If the periodic activity is not zero, determine the preset value corresponding to the periodic activity in the pre-configured mapping relationship between the periodic activity and the lifecycle as the current lifecycle of the threat intelligence.

[0029] In a second aspect, an embodiment of the present application provides a device for determining the lifecycle of threat intelligence. The device includes:

[0030] An acquisition module, configured to acquire Netflow data in network traffic collected within a preset period, where the Netflow data includes a source IP and a destination IP.

[0031] A search module, configured to search for a source IP identical to the attack IP from the Netflow data based on the attack IPs of pre-collected threat intelligence.

[0032] A first determination module, configured to determine the periodic activity of the source IP based on the found source IP and the destination IP corresponding to the source IP, where the periodic activity is used to characterize the number of different destination IPs that interact with the source IP within the preset period.

[0033] A second determination module, configured to determine the lifecycle of the threat intelligence corresponding to the attack IP identical to the source IP based on the periodic activity and the pre-configured mapping relationship between the periodic activity and the lifecycle.

[0034] In some embodiments, each piece of Netflow data further includes a source port, a destination port, and a communication protocol, and further includes:

[0035] A rejection module, configured to, before the search module searches for a source IP identical to the attack IP from the Netflow data based on the attack IPs of pre-collected threat intelligence, perform some or all of the following rejection operations for each piece of Netflow data:

[0036] Reject the Netflow data whose source IP is a preset source IP and / or whose destination IP is a preset destination IP;

[0037] Reject the Netflow data whose source port or destination port does not belong to the preset port range;

[0038] Reject the Netflow data whose communication protocol is not the preset communication protocol.

[0039] In some embodiments, the search module is specifically configured to:

[0040] For any source IP in the Netflow data, determine a set of Netflow data corresponding to the source IP, where the set of Netflow data includes each piece of Netflow data in the Netflow data that interacts with the same destination IP as the source IP, and the source IPs and destination IPs of each piece of Netflow data in the same set of Netflow data are the same;

[0041] For any attack IP, match the attack IP with the source IPs in each set of Netflow data to determine the source IP that matches the attack IP.

[0042] In some embodiments, it further includes:

[0043] A judgment module, configured to judge whether the threat intelligence is configured with an original lifecycle before the second determination module determines the lifecycle of the threat intelligence corresponding to the attack IP identical to the source IP based on the periodic activity and the pre-configured mapping relationship between the periodic activity and the lifecycle. If so, determine the remaining lifecycle of the threat intelligence;

[0044] The second determination module is specifically configured to:

[0045] Based on the remaining lifecycle, the periodic activity, and the pre-configured mapping relationship between the periodic activity and the lifecycle, determine the lifecycle of the threat intelligence corresponding to the attack IP identical to the source IP.

[0046] In some embodiments, the second determination module is specifically configured to:

[0047] Based on the periodic activity and the pre-configured mapping relationship between the periodic activity and the lifecycle, determine the current lifecycle of the threat intelligence;

[0048] Based on the current lifecycle and the remaining lifecycle, determine the lifecycle of the threat intelligence.

[0049] In some embodiments, the second determination module is specifically configured to:

[0050] If the periodic activity is zero, determine zero as the current lifecycle of the threat intelligence;

[0051] If the periodic activity is not zero, determine the preset value corresponding to the periodic activity in the pre-configured mapping relationship between the periodic activity and the lifecycle as the current lifecycle of the threat intelligence.

[0052] In a third aspect, an embodiment of the present application provides an electronic device, including: at least one processor, and a memory communicatively connected to the at least one processor, where:

[0053] The memory stores a computer program executable by the at least one processor. When the computer program is executed by the at least one processor, the at least one processor can execute the method for determining the lifecycle of the threat intelligence described above.

[0054] In a fourth aspect, an embodiment of the present application provides a storage medium. When the computer program in the storage medium is executed by a processor of an electronic device, the electronic device can execute the method for determining the lifecycle of the threat intelligence described above.

[0055] Fifth aspect, an embodiment of the present application provides a computer program product. When the computer program product is called and executed by an electronic device, it enables the electronic device to execute the method for determining the threat intelligence life cycle described above.

[0056] In an embodiment of the present application, Netflow data in network traffic collected within a preset period is obtained. The Netflow data includes a source IP and a destination IP. Based on the attack IPs of pre-collected threat intelligence, the source IPs identical to the attack IPs are searched for in the Netflow data. Based on the found source IPs and the destination IPs corresponding to the source IPs, the periodic activity of the source IP is determined. The periodic activity is used to characterize the number of different destination IPs that interact with the source IP within the preset period. Based on the periodic activity and the pre-configured mapping relationship between the periodic activity and the life cycle, the life cycle of the threat intelligence corresponding to the attack IP identical to the source IP is determined. In this way, dynamically adjusting the life cycle according to the periodic activity of the threat intelligence is beneficial to improving the accuracy and timeliness of the threat intelligence.

[0057] Other features and advantages of the present application will be described in the subsequent specification. And, partly, they will become obvious from the specification, or be understood by implementing the present application. The objectives and other advantages of the present application can be realized and obtained by the structures specifically pointed out in the written specification, claims, and drawings. Description of the Drawings

[0058] The drawings described herein are used to provide a further understanding of the present application and form a part of the present application. The schematic embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation to the present application. In the drawings:

[0059] Figure 1 It is a flowchart of a method for determining the threat intelligence life cycle provided by an embodiment of the present application;

[0060] Figure 2 It is a framework flowchart of a method for determining the threat intelligence life cycle provided by an embodiment of the present application;

[0061] Figure 3 It is a schematic structural diagram of a device for determining the threat intelligence life cycle provided by an embodiment of the present application;

[0062] Figure 4 It is a schematic hardware structure diagram of an electronic device for implementing the method for determining the threat intelligence life cycle provided by an embodiment of the present application. Detailed Embodiments

[0063] To make the objectives, technical solutions, and advantages of this application clearer and more understandable, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all of them. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts belong to the scope of protection of this application. Without conflict, the embodiments in this application and the features in the embodiments can be arbitrarily combined with each other. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0064] In the description and claims of this application and the above accompanying drawings, the terms "first" and "second" are used to distinguish different objects, rather than to describe a specific order. In addition, the term "including" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but optionally further includes steps or units not listed, or optionally further includes other steps or units inherent to these processes, methods, products, or devices. "Multiple" in this application can represent at least two, for example, it can be two, three, or more, and there is no limitation in the embodiments of this application.

[0065] The following provides an explanation of the exemplary embodiments of this application in conjunction with the accompanying drawings, including various details of the embodiments of this application to facilitate understanding. It should be considered that they are only exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described here without departing from the scope of disclosure of this application. Similarly, for the sake of clarity and conciseness, the description of well-known functions and structures is omitted below. It should be noted that in the embodiments of this application, some industry-existing solutions such as certain software, components, models, etc. may be mentioned. They should be considered exemplary, and their purpose is only to illustrate the feasibility in the implementation of the technical solutions of this application, but it does not mean that the applicant has already or necessarily used this solution.

[0066] In the technical solutions of this application, the acquisition, transmission, storage, use, etc. of data all comply with the requirements of relevant national laws and regulations.

[0067] Before introducing the method for determining the threat intelligence lifecycle provided by the embodiments of this application, for the convenience of understanding, the technical background of the embodiments of this application will be introduced in detail below.

[0068] With the continuous evolution and complexity of cyber - attack means, threat intelligence has become an important part of cyber - security defense. Threat intelligence provides detailed information about potential threats, including malicious IP addresses, domain names, attack methods, attack families, etc., helping security teams identify and respond to threats in a timely manner.

[0069] Currently, the mainstream way to determine the threat intelligence life - cycle mainly adopts a fixed - cycle mode. Taking domain - name - type intelligence as an example, after some domain names are entered into the threat intelligence database, they are given a validity period of 1 year according to established rules. However, the real - world scenarios are complex and changeable. The business characteristics corresponding to this domain name, the frequency of being attacked and other factors vary greatly. In fact, it takes 2 to 3 years for the threat effect to disappear. Similarly, for IP - type intelligence, a validity period of 3 months is usually given, but it may also lose its threat effect in only 1 month due to factors such as the transfer of the attack source and the termination of malicious behavior, and should be expired in advance. Therefore, the fixed - cycle mode cannot dynamically adjust the life - cycle according to the actual situation of threat intelligence. For example, in the face of highly - prevalent intelligence, that is, intelligence in areas with frequent cyber - attacks, wide spread, and continuous attention, its life - cycle should be appropriately extended to ensure continuous monitoring and protection; while for low - activity intelligence, such as IPs or domain names that are no longer active, its life - cycle should be appropriately shortened to reduce resource waste and false alarms.

[0070] In view of this, in order to solve the problem that the existing method of determining the threat intelligence life - cycle using a fixed cycle lacks flexibility and cannot be dynamically adjusted according to the actual situation of threat intelligence, resulting in the inconsistency between the validity period of intelligence and the actual situation, and affecting the accuracy and timeliness of intelligence, the embodiments of this application provide a method, device, equipment, and medium for determining the threat intelligence life - cycle. The following describes some preferred embodiments of this application with reference to the accompanying drawings of the specification.

[0071] To facilitate the understanding of this application, in the technical terms involved in this application:

[0072] Threat intelligence: Also known as security intelligence or security threat intelligence, generally refers to information related to cyber - space threats refined from security data, including threat sources, attack intentions, attack techniques, attack target information, and knowledge that can be used to solve threats or respond to hazards.

[0073] Netflow: A network protocol used to collect IP traffic information and monitor network traffic. Netflow technology can effectively monitor and count network traffic. Its biggest feature is traffic statistics based on IP flows, and IP flows contain information such as source IP address, destination IP address, source port number, destination port number, and protocol type required for network traffic monitoring and analysis. According to the traffic information provided by Netflow, real - time network monitoring can be carried out to detect abnormal network traffic, and at the same time, long - term network traffic statistics can also be carried out, so as to provide a basis for network optimization, service billing, etc.

[0074] The following uses specific embodiments to illustrate the method for determining the threat intelligence lifecycle proposed in this application.

[0075] Figure 1 It is a flowchart of a method for determining the threat intelligence lifecycle provided in an embodiment of this application. This method is applied to an electronic device capable of executing the method for determining the threat intelligence lifecycle. The electronic device can be a personal computer (PC), a server, etc., and this method includes the following steps.

[0076] In step 101, obtain Netflow data in the network traffic collected within a preset period. Among them, the Netflow data includes the source IP and the destination IP.

[0077] Specifically, each Netflow data further includes information such as the source port, the destination port, the communication protocol, and the communication time. The preset period can be one hour, one day, one week, and this application does not limit this.

[0078] In step 102, based on the attack IPs of the pre-collected threat intelligence, find the source IPs in the Netflow data that are the same as the attack IPs.

[0079] Among them, the pre-collected threat intelligence can be obtained from common threat intelligence open source communities, log files of internal systems and network devices, public databases, threat intelligence platforms, etc., and this application does not limit this.

[0080] Specifically, after obtaining each threat intelligence, it is also possible to count information such as the attack IPs (IP addresses related to known malicious activities), attack methods, attack families, attack times, and attack targets of each threat intelligence. After noise cleaning, the molecule side is saved in the database.

[0081] Specifically, in order to improve the accuracy and efficiency of analysis, before finding the source IPs in the Netflow data that are the same as the attack IPs based on the attack IPs of the pre-collected threat intelligence, it is also possible to perform some or all of the following exclusion operations for each Netflow data: exclude Netflow data with the source IP being the preset source IP and / or the destination IP being the preset destination IP; exclude Netflow data with the source port or the destination port not belonging to the preset port range; exclude Netflow data with the communication protocol not being the preset communication protocol.

[0082] In specific implementation, the preset destination IP or the preset source IP can be a non-WAN IP, that is, an IP address used in a private network or an internal network, such as a private IP, a link-local address, a loopback address, and other reserved IPs for specific purposes or testing. Since these preset destination IPs or preset source IPs are usually trustworthy, or their traffic has been covered by other security measures, and most network attacks mainly come from external networks, especially IP addresses from the public Internet. Therefore, after obtaining the Netflow data, the source IP and the destination IP can be verified to ensure that they do not belong to the preset destination IP or the preset source IP. If it is found that the source IP is the preset source IP and / or the destination IP is the preset destination IP, these Netflow data will be excluded. In this way, by filtering out a large amount of known internal traffic, the amount of NetFlow data that needs to be processed can be significantly reduced, thereby improving the performance and response speed of the analysis tool. Moreover, normal traffic in the internal network may trigger some rule-based security alerts, resulting in false alarms. By filtering out this traffic, the number of false alarms can be reduced, and the accuracy and reliability of the alerts can be improved.

[0083] In specific implementation, the preset port range can be (1 - 65535). In actual network traffic, the port number should always be within the range of 1 - 65535. If a port number outside this range appears, it may be that the data packet is damaged or tampered with, resulting in the port number exceeding the normal range. It may also be that some malware or attackers may deliberately send data packets containing illegal port numbers to confuse the detection system or bypass security policies. It is also possible that configuration errors in network devices or systems may result in the recording of invalid port numbers. Therefore, after obtaining the Netflow data, the source port and the destination port can be verified to ensure that they are within the range of 1 - 65535. If it is found that the port number is not within the range of 1 - 65535, these Netflow data will be excluded. In this way, by filtering out traffic outside the preset port range, the amount of NetFlow data that needs to be processed can be significantly reduced, thereby improving the performance and response speed of the analysis tool.

[0084] In specific implementation, the preset communication protocol can be the Transmission Control Protocol (TCP) and the connectionless transport layer protocol (User Datagram Protocol, UDP). Because non-preset communication protocols, such as the Internet Control Message Protocol (ICMP) or the Internet Group Management Protocol (IGMP), may contain a large amount of normal communication or other insignificant services, and these traffic may interfere with the analysis of the preset communication protocol. Therefore, after obtaining the Netflow data, the communication protocol can be verified to ensure that they are preset communication protocols. If it is found that the communication protocol is not a preset communication protocol, these Netflow data will be excluded. In this way, by filtering out the traffic that is not a preset communication protocol, the amount of NetFlow data that needs to be processed can be significantly reduced, thereby improving the performance and response speed of the analysis tool.

[0085] In specific implementation, based on the attack IPs of the pre-collected threat intelligence, the source IPs identical to the attack IPs can be found from the Netflow data. For any source IP in the Netflow data, a Netflow data set corresponding to the source IP can be determined. Among them, the Netflow data set includes each Netflow data with the same destination IP that interacts with the source IP in the Netflow data. The source IPs of the Netflow data in the same Netflow data set are the same and the destination IPs are the same. For any attack IP, the attack IP is matched with the source IPs in each Netflow data set to determine the source IP that matches any attack IP.

[0086] Suppose that after performing the above exclusion operation on each Netflow data, the excluded Netflow data is shown in Table 1.

[0087] Table 1

[0088]

[0089]

[0090] For any source IP in the Netflow data of Table 1 above, determine the Netflow data set corresponding to any source IP. Taking IP A as an example, among the above 10 Netflow data, the destination IPs that interact with IP A are IP J and IP Y. Therefore, the Netflow data set corresponding to IP A has two, namely Set 1 corresponding to (IP A, IP J): {Data 1, Data 2} and Set 2 corresponding to (IP A, IP Y): {Data 10}. Correspondingly, the destination for interacting with IP B is IP K. Therefore, the Netflow data set corresponding to IP B is Set 3 corresponding to (IP B, IP K): {Data 3}, and so on. The Netflow data in Table 1 above can obtain the respective Netflow data sets shown in Table 2.

[0091] Table 2

[0092]

[0093]

[0094] According to the above method, the above 10 Netflow data can be divided into 8 sets as shown in Table 2. And as can be seen from Table 2 above, the same Netflow data set corresponds to a group of source IP and destination IP. The source IPs of the Netflow data in the same Netflow data set are the same and the destination IPs are the same. For example, Set 1 and Set 6. Different Netflow data sets may include the same source IP or the same destination IP. For example, the source IPs of Set 1 and Set 2 are the same but the destination IPs are different, and the source IPs of Set 6 and Set 8 are different but the destination IPs are the same.

[0095] Suppose the attack IP of Threat Intelligence 1 is IP A. Then, it is only necessary to match the attack IP (IP A) with the source IPs in the 8 Netflow data sets in Table 2, rather than with the source IPs of the 10 Netflow data in Table 1. When the data volume is large, the amount of NetFlow data that needs to be processed can be reduced, which is beneficial to further improving the processing efficiency. It can be determined that the source IPs matching the attack IP (IP A) are Set 1 and Set 2 in the Netflow data sets in Table 2.

[0096] Suppose the attack IP of Threat Intelligence 2 is IP E. Then, the attack IP (IP E) can be matched with the source IPs in the 8 Netflow data sets in Table 2. It can be determined that the source IPs matching the attack IP (IP E) are Set 6 in the Netflow data sets in Table 2.

[0097] Again, assume that the attack IP of threat intelligence 3 is IP X. Then, the attack IP (IP X) can be matched with the source IPs in the 8 Netflow data sets in Table 2, and it can be determined that there is no source IP in the 8 Netflow data sets in Table 2 that matches the attack IP (IP X).

[0098] In step 103, based on the found source IP and the destination IP corresponding to the source IP, the periodic activity of the source IP is determined. The periodic activity is used to characterize the number of different destination IPs that interact with the source IP within a preset period.

[0099] Specifically, taking the source IPs matched by the above threat intelligence 1 (attack IP is IP A) as an example, which are set 1 and set 2 in the Netflow data sets in Table 2. The source IP and destination IP of set 1 are (IP A, IP J), and the source IP and destination IP of set 2 are (IP A, IP Y). That is, within the preset period, the number of destination IPs that interact with the source IP (IP A) is 2, namely IPJ and IP Y. So, it is determined that the periodic activity of the source IP (IP A) is 2, which means the periodic activity of threat intelligence 1 is 2. Taking the above threat intelligence 3 (attack IP is IP X) as an example, since there is no source IP in the 8 Netflow data sets in Table 2 that matches the attack IP (IP X), that is, within the preset period, there is no Netflow data with IP X as the source IP. Therefore, it can be determined that the periodic activity of the attack IP (IP X) is 0. Among them, the greater the periodic activity, the more active the attack IP is within the preset period. On the contrary, the smaller the periodic activity, the less active the attack IP is within the preset period.

[0100] In step 104, based on the periodic activity and the pre-configured mapping relationship between the periodic activity and the lifecycle, the lifecycle of the threat intelligence corresponding to the attack IP that is the same as the source IP is determined.

[0101] Specifically, the mapping relationship between the periodic activity and the lifecycle can be pre-configured according to the rule that the greater the periodic activity, the greater the corresponding lifecycle, and the smaller the periodic activity, the smaller the corresponding lifecycle. For example, when the periodic activity is 0, the corresponding lifecycle is 3 days, and when the periodic activity is 110, the corresponding lifecycle is 15 days. Assume that the pre-configured mapping relationship between the periodic activity and the lifecycle is shown in Table 3.

[0102] Table 3

[0103] Periodic activity Lifecycle value 0 3 days 1-100 7 days 101-1000 15 days 1001-2000 30 days 2001-3000 60 days 3001 and above 120 days

[0104] In specific implementation, taking one day as an example of the preset cycle, since the cycle activity is determined based on the current day, before this day, the threat intelligence may have already determined its life cycle. Therefore, before performing the above steps, it is also possible to determine whether the threat intelligence has configured an original life cycle. If so, determine the remaining life cycle of the threat intelligence. For example, it is possible to determine whether the threat intelligence has configured an original life cycle based on the original life cycle identifier. When it is determined that the threat intelligence has configured an original life cycle, the remaining life cycle of the threat intelligence can be determined according to the value corresponding to the original life cycle identifier.

[0105] In specific implementation, if the threat intelligence has not configured an original life cycle, then the life cycle of the threat intelligence corresponding to the attack IP with the same source IP can be directly determined based on the cycle activity and the pre-configured mapping relationship between the cycle activity and the life cycle.

[0106] Taking the mapping relationship between the cycle activity and the life cycle shown in Table 3 above as an example, if the cycle activity on the current day is 120, according to Table 3, the life cycle of Threat Intelligence 1 is 15 days; if the cycle activity on the current day is 80, according to Table 3, the life cycle of Threat Intelligence 1 is 7 days; if the cycle activity on the current day is 0, according to Table 3, the life cycle of Threat Intelligence 1 is 3 days.

[0107] In specific implementation, if the threat intelligence has configured an original life cycle, then the life cycle of the threat intelligence corresponding to the attack IP with the same source IP can be determined based on the remaining life cycle, the cycle activity, and the pre-configured mapping relationship between the cycle activity and the life cycle.

[0108] In specific implementation, the current life cycle of the threat intelligence can be determined based on the cycle activity and the pre-configured mapping relationship between the cycle activity and the life cycle, that is, determine the corresponding life cycle within this preset cycle. Then, based on the current life cycle and the remaining life cycle, determine the life cycle of the threat intelligence.

[0109] In specific implementation, if the cycle activity is zero, then determine zero as the current life cycle of the threat intelligence; if the cycle activity is not zero, then determine the preset value corresponding to the cycle activity in the pre-configured mapping relationship between the cycle activity and the life cycle as the current life cycle of the threat intelligence.

[0110] Taking the mapping relationship between the periodic activity and the life cycle shown in Table 3 above as an example, assume that the remaining life cycle of threat intelligence 1 is 7 days. If the periodic activity on the current day is 120, according to Table 3, the current life cycle of threat intelligence 1 is 15 days. Then, the life cycle of threat intelligence 1 is 7 days plus 15 days, which is 22 days. If the periodic activity on the current day is 80, according to Table 3, the current life cycle of threat intelligence 1 is 7 days. Then, the life cycle of threat intelligence 1 is 7 days plus 7 days, which is 14 days. If the periodic activity on the current day is 0, then the current life cycle of threat intelligence 1 is 0 days. Then, the life cycle of threat intelligence 1 is 7 days plus 0 days, which is 7 days.

[0111] In specific implementation, every day, the value of the life cycle of all threat situations with a set life cycle is decreased by 1. When the value of the life cycle of the threat intelligence decreases to less than 0, the threat intelligence is set to the expired state, so that the inactive threat intelligence can be gradually converted into expired intelligence.

[0112] In this way, the life cycle of the threat intelligence can be dynamically adjusted according to the periodic activity, and the adjustment range of its life cycle can be controlled according to the magnitude of the periodic activity of the threat intelligence. For the threat intelligence with the original life cycle configured, if the periodic activity on the current day is 0, it means that the threat intelligence is not active on the current day. Therefore, the life cycle does not need to be increased.

[0113] Compared with the method for determining the life cycle of threat intelligence with a fixed cycle in the prior art, the method for determining the life cycle provided by the embodiment of the present application is more flexible in determining the life cycle, and can be dynamically adjusted according to the actual situation of the threat intelligence, which is beneficial to improving the accuracy and timeliness of the threat intelligence.

[0114] Next, a method for determining the life cycle of threat intelligence provided by the embodiment of the present application will be introduced with specific embodiments.

[0115] Figure 2 FIG. is a framework flowchart of a method for determining the life cycle of threat intelligence provided by the embodiment of the present application, including five modules: a network traffic data collection module, a network traffic data filtering module, a threat intelligence information collection module, a threat intelligence and network traffic collision module, and a threat intelligence dynamic life cycle management module.

[0116] Among them, the network traffic data collection module is used to obtain the Netflow data in the daily collected network traffic, and record the five-tuple information and communication time of each Netflow data. The five-tuple information includes the source IP, source port, destination IP, destination port, and communication protocol, and sends the obtained Netflow data to the network traffic data filtering module.

[0117] A network traffic data filtering module is used to perform a preset elimination operation according to the received Netflow data. For each Netflow data, the following elimination operations are respectively performed to eliminate the Netflow data with the source IP being the preset source IP and / or the destination IP being the preset destination IP in the Netflow data; eliminate the Netflow data with the source port or the destination port not belonging to the preset port range in the Netflow data; eliminate the Netflow data with the communication protocol not being the preset communication protocol, and send the eliminated Netflow data to the threat intelligence and network traffic collision module.

[0118] A threat intelligence information collection module is used to select a large number of open-source threat intelligence communities and multiple threat intelligence feed services, record information such as the attack IP address, attack method, attack family, attack time, and attack target of each threat intelligence. After basic noise cleaning, it is saved in the local database by field, and the threat intelligence is sent to the threat intelligence and network traffic collision module.

[0119] A threat intelligence and network traffic collision module is used to determine a Netflow data set corresponding to any source IP in the Netflow data. For the attack IP of any threat intelligence, the attack IP is associated and collided with the source IPs in each Netflow data set to determine the source IP that matches any attack IP, and the association and collision result is sent to the threat intelligence dynamic life cycle management module.

[0120] A threat intelligence dynamic life cycle management module is used to calculate the periodic activity of the attack IP corresponding to the source IP based on the found source IP and the destination IP corresponding to the source IP, and determine the life cycle of the threat intelligence corresponding to the attack IP that is the same as the source IP based on the periodic activity and the pre-configured mapping relationship between the periodic activity and the life cycle.

[0121] The threat intelligence dynamic life cycle management module is also used to determine whether the threat intelligence is configured with an original life cycle. If so, determine the remaining life cycle of the threat intelligence, and determine the current life cycle of the threat intelligence based on the periodic activity and the pre-configured mapping relationship between the periodic activity and the life cycle; determine the life cycle of the threat intelligence based on the current life cycle and the remaining life cycle.

[0122] The threat intelligence dynamic life cycle management module is also used to perform daily scheduling. Every day, subtract 1 from the value of the life cycle of all threat situations with the life cycle set. When the value of the life cycle of the threat intelligence is reduced to less than 0, set the threat intelligence to the expired state, so that the inactive threat intelligence can be gradually converted into expired intelligence.

[0123] Based on the same technical concept, an embodiment of the present application further provides a device for determining the threat intelligence life cycle. The principle of the device for determining the threat intelligence life cycle to solve problems is similar to the above method for determining the threat intelligence life cycle. Therefore, for the implementation of the device for determining the threat intelligence life cycle, reference can be made to the implementation of the method for determining the threat intelligence life cycle, and the repeated parts will not be elaborated.

[0124] Figure 3 FIG. 4 is a schematic structural diagram of a device for determining the threat intelligence life cycle provided by an embodiment of the present application, including an acquisition module 301, a search module 302, a first determination module 303, and a second determination module 304.

[0125] The acquisition module 301 is configured to acquire Netflow data in the network traffic collected within a preset period, where the Netflow data includes a source IP and a destination IP.

[0126] The search module 302 is configured to search for a source IP identical to the attack IP from the Netflow data based on the attack IP of the threat intelligence collected in advance.

[0127] The first determination module 303 is configured to determine the periodic activity of the source IP based on the found source IP and the destination IP corresponding to the source IP, where the periodic activity is used to represent the number of different destination IPs that interact with the source IP within the preset period.

[0128] The second determination module 304 is configured to determine the life cycle of the threat intelligence corresponding to the attack IP identical to the source IP based on the periodic activity and the mapping relationship between the periodic activity and the life cycle configured in advance.

[0129] In some embodiments, each piece of Netflow data further includes a source port, a destination port, and a communication protocol, and further includes:

[0130] The elimination module 305 is configured to, before the search module 302 searches for a source IP identical to the attack IP from the Netflow data based on the attack IP of the threat intelligence collected in advance, perform some or all of the following elimination operations on each piece of Netflow data:

[0131] Eliminate the Netflow data in which the source IP is a preset source IP and / or the destination IP is a preset destination IP;

[0132] Eliminate the Netflow data in which the source port or the destination port does not belong to the preset port range;

[0133] Filter out the Netflow data in which the communication protocol is not the preset communication protocol from the Netflow data.

[0134] In some embodiments, the searching module 302 is specifically configured to:

[0135] For any source IP in the Netflow data, determine the Netflow data set corresponding to the any source IP, where the Netflow data set includes each Netflow data of the same destination IP that interacts with the source IP in the Netflow data, and the source IPs of the Netflow data in the same Netflow data set are the same and the destination IPs are the same;

[0136] For any attack IP, match the attack IP with the source IPs in each of the Netflow data sets to determine the source IP that matches the any attack IP.

[0137] In some embodiments, it further includes:

[0138] A judging module 306, configured to judge whether the threat intelligence is configured with an original life cycle before the second determining module 304 determines the life cycle of the threat intelligence corresponding to the attack IP with the same source IP based on the periodic activity and the pre-configured mapping relationship between the periodic activity and the life cycle. If so, determine the remaining life cycle of the threat intelligence;

[0139] The second determining module 304 is specifically configured to:

[0140] Based on the remaining life cycle, the periodic activity, and the pre-configured mapping relationship between the periodic activity and the life cycle, determine the life cycle of the threat intelligence corresponding to the attack IP with the same source IP.

[0141] In some embodiments, the second determining module 304 is specifically configured to:

[0142] Based on the periodic activity and the pre-configured mapping relationship between the periodic activity and the life cycle, determine the current life cycle of the threat intelligence;

[0143] Based on the current life cycle and the remaining life cycle, determine the life cycle of the threat intelligence.

[0144] In some embodiments, the second determining module 304 is specifically configured to:

[0145] If the periodic activity is zero, determine zero as the current life cycle of the threat intelligence;

[0146] If the periodic activity is not zero, then in the mapping relationship between the pre-configured periodic activity and the life cycle, the preset value corresponding to the periodic activity is determined as the current life cycle of the threat intelligence.

[0147] The division of modules in the embodiments of the present application is illustrative. It is only a logical function division. In actual implementation, there may be other division methods. In addition, each functional module in the embodiments of the present application can be integrated in one processor, can also exist physically alone, or two or more modules can be integrated in one module. The coupling between each module can be realized through some interfaces, and these interfaces are usually electrical communication interfaces, but it does not exclude the possibility of being mechanical interfaces or other forms of interfaces. Therefore, the modules described as separate components may or may not be physically separated, and can be located in one place or distributed to different positions of the same or different devices. The above integrated modules can be implemented in the form of hardware or in the form of software function modules.

[0148] Based on the same inventive concept, the embodiments of the present application provide an electronic device, and this device can implement the function of determining the life cycle of the threat intelligence discussed above.

[0149] Below, refer to Figure 4 to describe the electronic device 130 implemented according to this embodiment of the present application. Figure 4 The shown electronic device 130 is only an example, and should not bring any restrictions to the functions and usage scope of the embodiments of the present application.

[0150] As Figure 4 shown, the electronic device 130 is presented in the form of a general electronic device. The components of the electronic device 130 may include but are not limited to: the above at least one processor 131, the above at least one memory 132, and a bus 133 connecting different system components (including the memory 132 and the processor 131).

[0151] The bus 133 represents one or more of several types of bus structures, including a memory bus or a memory controller, a peripheral bus, a processor, or a local bus using any bus structure in a variety of bus structures.

[0152] The memory 132 may include a readable medium in the form of volatile memory, such as a random access memory (RAM) 1321 and / or a cache memory 1322, and may further include a read-only memory (ROM) 1323.

[0153] The memory 132 may also include a program / utilities 1325 having a set (at least one) of program modules 1324. Such program modules 1324 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment.

[0154] The electronic device 130 may also communicate with one or more external devices 134 (such as a keyboard, a pointing device, etc.), may also communicate with one or more devices that enable a user to interact with the electronic device 130, and / or may communicate with any device (such as a router, a modem, etc.) that enables the electronic device 130 to communicate with one or more other electronic devices. Such communication may be carried out through an input / output (I / O) interface 135. Also, the electronic device 130 may communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through a network adapter 136. As shown in the figure, the network adapter 136 communicates with other modules for the electronic device 130 through a bus 133. It should be understood that although not shown in the figure, other hardware and / or software modules may be used in conjunction with the electronic device 130, including but not limited to: microcode, device drivers, redundant processors, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.

[0155] Based on the same inventive concept, an embodiment of the present application provides a computer-readable storage medium. The computer program product includes: computer program code, which when running on a computer, causes the computer to execute the method for determining the threat intelligence life cycle as described in any of the foregoing. Since the principle of solving problems by the above computer-readable storage medium is similar to the method for determining the threat intelligence life cycle, the implementation of the above computer-readable storage medium can refer to the implementation of the method, and the repeated parts will not be described again.

[0156] Based on the same inventive concept, an embodiment of the present application further provides a computer program product. The computer program product includes: computer program code, which when running on a computer, causes the computer to execute the method for determining the threat intelligence life cycle as described in any of the foregoing. Since the principle of solving problems by the above computer program product is similar to the method for determining the threat intelligence life cycle, the implementation of the above computer program product can refer to the implementation of the method, and the repeated parts will not be described again.

[0157] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) that contain computer-usable program code.

[0158] The present application is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate a means for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0159] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction means that implements the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0160] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of user operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0161] Obviously, those skilled in the art can make various modifications and variations to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these modifications and variations.

Claims

1. A method for determining a threat intelligence life cycle, characterized in that: The method comprises: Obtain Netflow data from network traffic collected within a preset period, wherein the Netflow data includes a source IP and a destination IP; Based on the attack IP of the threat intelligence collected in advance, searching the source IP same as the attack IP from the Netflow data; Based on the found source IP and the destination IP corresponding to the source IP, determine the periodic activity of the source IP, where the periodic activity is used to characterize the number of different destination IPs that interact with the source IP within the preset period; Based on the periodic activity and a pre-configured mapping relationship between the periodic activity and the life cycle, the life cycle of the threat intelligence corresponding to the attack IP that is the same as the source IP is determined.

2. The method according to claim 1, characterized in that Each of the Netflow data further includes a source port, a destination port and a communication protocol. Before searching the Netflow data for a source IP identical to the attack IP based on the pre-collected threat intelligence, the attack IP further includes: For each Netflow data, perform some or all of the following elimination operations: Eliminate the Netflow data whose source IP is a preset source IP and / or whose destination IP is a preset destination IP; Eliminate the Netflow data whose source port or destination port does not belong to the preset port range; The Netflow data whose communication protocol is not the preset communication protocol is eliminated.

3. The method according to claim 1, characterized in that The attack IP based on the pre-collected threat intelligence, searching the Netflow data for a source IP that is the same as the attack IP, includes: For any source IP in the Netflow data, determine a Netflow data set corresponding to the any source IP, wherein the Netflow data set includes each Netflow data of the same destination IP interacting with the source IP in the Netflow data, and each Netflow data in the same Netflow data set has the same source IP and the same destination IP; For any attacking IP, the attacking IP is matched with the source IP in each of the Netflow data sets to determine the source IP that matches the any attacking IP.

4. The method according to claim 1, characterized in that Before determining the life cycle of the threat intelligence corresponding to the attack IP that is the same as the source IP based on the periodic activity and the pre-configured mapping relationship between the periodic activity and the life cycle, the method further includes: Determine whether the threat intelligence is configured with an original life cycle, and if so, determine the remaining life cycle of the threat intelligence; The determining, based on the periodic activity and a preconfigured mapping relationship between the periodic activity and the life cycle, the life cycle of the threat intelligence corresponding to the attack IP that is the same as the source IP includes: Based on the remaining life cycle, the cycle activity, and the mapping relationship between the pre-configured cycle activity and the life cycle, the life cycle of the threat intelligence corresponding to the attack IP that is the same as the source IP is determined.

5. The method according to claim 4, characterized in that The determining, based on the remaining life cycle, the cycle activity, and the pre-configured mapping relationship between the cycle activity and the life cycle, the life cycle of the threat intelligence corresponding to the attack IP that is the same as the source IP includes: Determine the current life cycle of the threat intelligence based on the periodic activity and the pre-configured mapping relationship between the periodic activity and the life cycle; Based on the current life cycle and the remaining life cycle, a life cycle of the threat intelligence is determined.

6. The method according to claim 5, characterized in that The determining the current life cycle of the threat intelligence based on the periodic activity and the pre-configured mapping relationship between the periodic activity and the life cycle includes: If the period activity is zero, zero is determined as the current life cycle of the threat intelligence; If the periodic activity is not zero, then in the mapping relationship between the pre-configured periodic activity and the life cycle, the preset value corresponding to the periodic activity is determined as the current life cycle of the threat intelligence.

7. A device for determining a threat intelligence life cycle, characterized in that: The device comprises: An acquisition module is used to acquire Netflow data in network traffic collected within a preset period, wherein the Netflow data includes a source IP and a destination IP; A search module, used for searching the source IP same as the attack IP from the Netflow data based on the attack IP of the threat intelligence collected in advance; A first determination module is used to determine the periodic activity of the source IP based on the found source IP and the destination IP corresponding to the source IP, wherein the periodic activity is used to characterize the number of different destination IPs interacting with the source IP within the preset period; The second determination module is used to determine the life cycle of the threat intelligence corresponding to the attack IP that is the same as the source IP based on the periodic activity and a pre-configured mapping relationship between the periodic activity and the life cycle.

8. The device according to claim 7, characterized in that Each Netflow data also includes a source port, a destination port and a communication protocol, and also includes: The elimination module is used to perform some or all of the following elimination operations for each Netflow data before the search module searches for the source IP that is the same as the attack IP based on the attack IP of the threat intelligence collected in advance from the Netflow data: Eliminate the Netflow data whose source IP is a preset source IP and / or whose destination IP is a preset destination IP; Eliminate the Netflow data whose source port or destination port does not belong to the preset port range; The Netflow data whose communication protocol is not the preset communication protocol is eliminated.

9. An electronic device, characterized in that: include: at least one processor, and a memory communicatively connected to the at least one processor, wherein: The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can perform the method according to any one of claims 1 to 6.

10. A storage medium, characterized in that: When the computer program in the storage medium is executed by a processor of an electronic device, the electronic device can execute the method according to any one of claims 1 to 6.