Threat intelligence analysis method and device, equipment, storage medium and product
Through large language models, the directed acyclic graph framework is constructed, and threat indicator generation, evaluation and intelligence summary are integrated, which solves the problems of insufficient linear reasoning limitations and dynamic adaptability in existing threat intelligence analysis, and achieves efficient and accurate threat intelligence analysis.
Patent Information
- Application Number
- CN202510598866.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-09
- Publication Date
- 2025-07-18
AI Technical Summary
The existing threat intelligence analysis methods have linear reasoning limitations, cannot capture multi-path logical relationships, insufficient role separation and dynamicity, static models are difficult to adapt to the rapid evolution of attack methods, and are inefficient in unstructured intelligence processing, resulting in poor analysis accuracy and efficiency.
The directed acyclic graph (DAG) framework is built using a large language model. Through the role transformation of threat indicator generator, threat evaluator and intelligence aggregator, multiple iterative reasoning and topological sorting are realized, coherent threat intelligence reports are generated, and threat metrics generation, evaluation and intelligence summary are integrated to dynamically adapt to complex threats.
It improves the accuracy and efficiency of threat intelligence analysis, can dynamically adapt to complex threats, reduce misjudgments, realizes automated processing of unstructured data, and improves defense coordination efficiency.
Smart Images

Figure CN120342737A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular, to a threat intelligence analysis method, device, equipment, storage medium and product. Background Art
[0002] Threat intelligence analysis refers to the process of collecting, analyzing and utilizing security threat information to identify, detect and defend potential attacks. The technical background of network threat intelligence analysis covers multiple fields, including big data analysis, machine learning, behavior analysis, intrusion detection and situation awareness, etc. With the continuous evolution of network attack means, the traditional detection methods based on feature matching and rules have become difficult to effectively cope with new threats. Therefore, modern threat intelligence analysis relies on more advanced technologies, such as artificial intelligence and deep learning, to discover hidden attacks and zero-day vulnerabilities.
[0003] In the prior art, a large model can be applied to implement threat intelligence analysis. The threat intelligence analysis method based on the large model uses deep learning and natural language processing technologies to extract, correlate and predict potential threats from massive security logs, network traffic, social media, security reports and dark web data.
[0004] However, the existing threat intelligence analysis methods have at least the following defects: Firstly, the limitation of linear reasoning. Traditional methods (such as chain of thought) model the reasoning process as a linear chain and cannot capture multi-path logical relationships (such as multi-stage penetration of APT attacks). Secondly, the lack of role separation and dynamics. The existing solutions split threat analysis into independent modules (such as detection, response), resulting in information fragmentation; static models are difficult to adapt to the rapid evolution of attack means (such as the real-time mutation of adversarial samples). Thirdly, the inefficient processing of unstructured intelligence. Traditional methods rely on manual parsing of text reports and cannot automatically extract key information. Therefore, the accuracy and efficiency of the existing threat intelligence analysis are poor. Summary of the Invention
[0005] The present invention provides a threat intelligence analysis method, device, equipment, storage medium and product to solve the defects of poor accuracy and efficiency in threat intelligence analysis in the prior art and achieve accurate and efficient threat intelligence analysis.
[0006] The present invention provides a threat intelligence analysis method, including: Obtaining data to be analyzed, where the data to be analyzed includes network traffic data, log data, open source intelligence data, and security device data; Based on the data to be analyzed, constructing an initial mind map; each node in the mind map represents a threat proposition, and the connection edge between two nodes in the mind map represents the logical relationship between the two nodes; Implement the role conversion among the threat indicator generator, threat assessor, and intelligence aggregator through a single large language model to obtain a threat intelligence analysis model; Input the initial mind map into the threat intelligence analysis model, and through multiple iterative inferences, obtain the intelligence aggregation result output by the threat intelligence analysis model and the mind map after iterative inference; the intelligence aggregation result includes: records of the inference process, evidence chains, threat assessment results, and recommended measures; Based on the intelligence aggregation result, perform a topological sort on the mind map after iterative inference to generate a coherent thought chain, and output a threat intelligence report, where the threat intelligence report includes: the coherent thought chain and the intelligence aggregation result.
[0007] According to a threat intelligence analysis method provided by the present invention, the constructing an initial mind map based on the data to be analyzed includes: Define the nodes of the initial mind map; Define the logical relationships between the nodes in the initial mind map; Organize all the nodes and all the logical relationships into a structured framework to obtain the initial mind map.
[0008] According to a threat intelligence analysis method provided by the present invention, the implementing the role conversion among the threat indicator generator, threat assessor, and intelligence aggregator through a single large language model to obtain a threat intelligence analysis model includes: Implement the threat indicator generator within the single large language model, where the threat indicator generator is used to generate threat propositions; Implement a threat assessor within the single large language model, where the threat assessor is used to evaluate the threat propositions to obtain the evaluation results corresponding to the threat propositions; Implement an intelligence aggregator within the single large language model, where the intelligence aggregator is used to aggregate the evaluation results corresponding to the threat propositions; Through a pre-set role setting, guide the single large language model to implement the role conversion among the threat indicator generator, the threat assessor, and the intelligence aggregator to obtain the threat intelligence analysis model.
[0009] According to a threat intelligence analysis method provided by the present invention, the inputting the initial mind map into the threat intelligence analysis model and through multiple iterative inferences to obtain the intelligence aggregation result output by the threat intelligence analysis model and the mind map after iterative inference includes: Based on the initial mind map, generate initial threat propositions through the threat indicator generator; Add a new node corresponding to the initial threat proposition to the current mind map, and define the logical relationships between the new node and other nodes to obtain an updated mind map; Evaluate the initial threat proposition through the threat evaluator to obtain an evaluation result corresponding to the initial threat proposition; the evaluation result corresponding to the initial threat proposition includes: evaluation passed, evaluation not passed, and further evaluation required; If the evaluation result corresponding to the initial threat proposition is evaluation passed or evaluation not passed, then summarize the evaluation result corresponding to the initial proposition and the evaluation process of the initial proposition through the intelligence summarizer to obtain the intelligence summary result; If the evaluation result corresponding to the initial threat proposition is further evaluation required, then perform iterative reasoning processing to obtain the intelligence summary result output by the threat intelligence analysis model and the mind map after iterative reasoning; Among them, the iterative reasoning processing includes: Generate a new threat proposition through the threat indicator generator; Add a new node corresponding to the new threat proposition to the current mind map, and define the logical relationships between the new node and other nodes to obtain an updated mind map; Evaluate the new threat proposition through the threat evaluator to obtain an evaluation result corresponding to the new threat proposition; the evaluation result corresponding to the new threat proposition includes: evaluation passed, evaluation not passed, and further evaluation required; If the evaluation result corresponding to the new threat proposition is further evaluation required, then return to execute the step of generating a new threat proposition through the threat indicator generator, otherwise, summarize the evaluation results corresponding to all propositions and the evaluation processes of all propositions through the intelligence summarizer to obtain the intelligence summary result.
[0010] According to a threat intelligence analysis method provided by the present invention, based on the intelligence summary result, perform topological sorting on the mind map after iterative reasoning to generate a coherent thinking chain, specifically including: Based on the intelligence summary result, apply the Kahn algorithm to perform topological sorting on the mind map after iterative reasoning to generate a coherent thinking chain.
[0011] According to a threat intelligence analysis method provided by the present invention, after obtaining the data to be analyzed, the method further includes: Perform noise reduction processing on the data to be analyzed to obtain the data to be analyzed after noise reduction processing, and the noise reduction processing includes at least one of the following: removing duplicate data, filtering out irrelevant information, and correcting incorrect data.
[0012] The present invention also provides a threat intelligence analysis device, including the following modules: An acquisition module, configured to acquire data to be analyzed, where the data to be analyzed includes network traffic data, log data, open source intelligence data, and security device data; A construction module, configured to construct an initial mind map based on the data to be analyzed; each node in the mind map represents a threat proposition, and the connection edge between two nodes in the mind map represents the logical relationship between the two nodes; A processing module, configured to implement role conversion among a threat metric generator, a threat evaluator, and an intelligence aggregator through a single large language model to obtain a threat intelligence analysis model; An input module, configured to input the initial mind map into the threat intelligence analysis model, and after multiple iterative inferences, obtain the intelligence aggregation result output by the threat intelligence analysis model and the mind map after iterative inferences; the intelligence aggregation result includes: records of the inference process, evidence chains, threat assessment results, and recommended measures; A sorting module, configured to perform topological sorting on the mind map after iterative inferences based on the intelligence aggregation result, generate a coherent thought chain, and output a threat intelligence report, where the threat intelligence report includes: the coherent thought chain and the intelligence aggregation result.
[0013] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored on the memory and running on the processor, where when the processor executes the computer program, it implements the threat intelligence analysis method as described in any one of the above.
[0014] The present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the threat intelligence analysis method as described in any one of the above.
[0015] The present invention also provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the threat intelligence analysis method as described in any one of the above.
[0016] The threat intelligence analysis method, apparatus, device, storage medium and product provided by the present invention introduce a mind map framework, model threat intelligence analysis as a directed acyclic graph, decompose the threat intelligence analysis process into nodes at multiple levels, and promote the hierarchical understanding of complex threat patterns by the large model based on the inference framework of the directed acyclic graph. Moreover, by integrating roles such as threat indicator generation, threat assessment, and intelligence aggregation, non-linear and multi-path reasoning is achieved. Further, through iterative reasoning and topological sorting, complex threats can be dynamically adapted to reduce misjudgments caused by insufficient model generalization. Further, by utilizing the semantic understanding ability of the large model, structured threat features are extracted from the data to be analyzed, realizing automatic processing of unstructured data. Further, a closed-loop of detection, analysis, and response is implemented in a single model, reducing manual intervention and improving the efficiency of defense collaboration. Therefore, the solution of the present invention improves the accuracy and efficiency of threat intelligence analysis. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0018] Figure 1 is one of the flow diagrams of the threat intelligence analysis method provided by the present invention.
[0019] Figure 2 is the second flow diagram of the threat intelligence analysis method provided by the present invention.
[0020] Figure 3 is the structural diagram of the threat intelligence analysis apparatus provided by the present invention.
[0021] Figure 4 is the structural diagram of the electronic device provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0022] To make the objectives, technical solutions, and advantages of the present invention clearer, the following will clearly and completely describe the technical solutions in the present invention in conjunction with the drawings in the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.
[0023] It should be noted that the brief description of terms in this application is only for facilitating the understanding of the following described embodiments, rather than intending to limit the embodiments of this application. Unless otherwise specified, these terms should be understood in their ordinary and common meanings.
[0024] In this application, terms such as "first", "second", etc. in the specification, claims and the above-mentioned drawings are used to distinguish similar or like objects or entities, and do not necessarily mean to limit a specific order or sequence, unless otherwise indicated. It should be understood that such terms can be interchanged under appropriate circumstances, for example, it can be implemented in an order other than those given in the illustration or description of the embodiments of this application.
[0025] In addition, the terms "comprising" and "having" and any variations thereof are intended to cover but not be exclusive of inclusion. For example, a product or device comprising a series of components does not necessarily have to be limited to those components clearly listed, but may include other components not clearly listed or inherent to these products or devices. The term "module" used in this application refers to any known or later developed hardware, software, firmware, artificial intelligence, fuzzy logic or a combination of hardware or / and software code that can perform functions related to that element.
[0026] The term "large model" used in the embodiments of this application refers to an artificial intelligence model with ultra-large-scale parameters and data training, which relies on massive data and is pre-trained and instructionally fine-tuned through a complex network structure, so as to perform well in tasks such as understanding, generation, and prediction.
[0027] The term "threat intelligence analysis" used in the embodiments of this application refers to the process of collecting, analyzing and utilizing security threat information to identify, detect and defend against potential attacks.
[0028] In practical applications, the technical background of network threat intelligence analysis covers multiple fields, including big data analysis, machine learning, behavior analysis, intrusion detection, and situation awareness, etc. With the continuous evolution of network attack means, traditional detection methods based on signature matching and rules have become difficult to effectively cope with new threats. Therefore, modern threat intelligence analysis relies on more advanced technologies, such as artificial intelligence and deep learning, to discover hidden attacks and zero-day vulnerabilities.
[0029] In the prior art, large models can be applied to achieve threat intelligence analysis. The threat intelligence analysis method based on large models utilizes deep learning and natural language processing technologies to extract, correlate, and predict potential threats from massive amounts of security logs, network traffic, social media, security reports, and dark web data. Large models can understand and generate complex security intelligence texts, enabling automated threat classification, event correlation analysis, and attack prediction. In addition, large models have a powerful context understanding ability, enabling them to extract valuable information from unstructured data and improve the accuracy of malicious behavior detection.
[0030] The inference methods of large models improve the understanding and decision-making abilities by simulating the human thinking process. Common strategies include step-by-step reasoning, multi-path exploration, and contextual thinking. Step-by-step reasoning breaks down complex problems into intermediate steps, making the model more accurate in tasks such as logical reasoning and mathematical calculations. Multi-path exploration allows the model to consider different reasoning routes simultaneously and select the optimal solution to handle open-ended or complex decision-making problems. Contextual thinking enables the model to think in a context-compliant manner according to a specific background or role setting, improving professionalism and adaptability. The combination of these methods makes large models more coherent and reliable in inference tasks and capable of handling a wider range of application scenarios.
[0031] In some exemplary technologies, a method for automatically extracting actionable cyber threat intelligence (CTI) using large models and knowledge graphs (KGs). Specifically, meaningful triples are extracted from CTI texts, and the extracted data is used to construct a KG, providing a structured and queryable representation of threat intelligence. This method has proven effective in small-scale tests but is not suitable for large-scale data where large language models are applied to KG construction and link prediction.
[0032] In some exemplary technologies, a method for creating a multi-task teaching corpus, which specifically uses a large language model to select appropriate tasks from a corpus, generate queries corresponding to the tasks, and corresponding responses. However, this method still requires a certain degree of manual participation and cannot achieve full automation.
[0033] In some exemplary technologies, a security event log template mining method based on an unsupervised large language model (Large Language Model - TD algorithm) is specifically used for unsupervised data extraction from security event logs. This method detects structures similar to regular expressions in log messages and converts them into standard regular expressions to improve the automation of data parsing. Additionally, in an exemplary technology, a threat intelligence analysis method based on large-scale model collaboration uses natural language processing technology based on deep learning to extract threat intelligence content information from dark web web pages, and respectively performs global content information semantic feature extraction and keyword information semantic feature extraction on the threat intelligence content information. Furthermore, based on the keyword information of the threat intelligence, fine-grained context semantic association enhancement is performed on its global content information to achieve in-depth understanding and structured representation of the threat intelligence content. However, this method is still limited by a linear reasoning method when dealing with complex attack chains and is difficult to effectively model the dependencies of multi-stage attacks.
[0034] In another exemplary technology, an AI-enhanced network security threat intelligence analysis method, by real-time acquiring threat intelligence data and network traffic data in the network environment and combining a semantic recognition model and a threat analysis model, realizes the correlation analysis and in-depth mining of multi-dimensional data features, solves the problem that traditional network security analysis methods are difficult to accurately capture the essential features of unknown attack behaviors, and has the effects of improving threat detection accuracy, enhancing threat response speed, and improving network security defense capabilities. Although this method can achieve in-depth mining of network threats, due to its dependence on a specific threat analysis model, it is difficult to dynamically adjust the reasoning path, and there is still room for improvement in the automated processing ability of unstructured intelligence.
[0035] For example, in an exemplary technology, a threat intelligence analysis method based on large-scale model collaboration uses natural language processing technology based on deep learning to extract threat intelligence content information from dark web web pages, and respectively performs global content information semantic feature extraction and keyword information semantic feature extraction on the threat intelligence content information. Furthermore, based on the keyword information of the threat intelligence, fine-grained context semantic association enhancement is performed on its global content information to achieve in-depth understanding and structured representation of the threat intelligence content. However, this method is still limited by a linear reasoning method when dealing with complex attack chains and is difficult to effectively model the dependencies of multi-stage attacks.
[0036] For another example, in another exemplary technology, an AI-enhanced network security threat intelligence analysis method obtains threat intelligence data and network traffic data in the network environment in real time, and combines a semantic recognition model and a threat analysis model to achieve the correlation analysis and in-depth mining of multi-dimensional data features, solving the problem that traditional network security analysis methods are difficult to accurately capture the essential features of unknown attack behaviors, and having the effects of improving the accuracy of threat detection, enhancing the threat response speed, and improving the network security defense ability. Although this method can achieve in-depth mining of network threats, due to its dependence on a specific threat analysis model, it is difficult to dynamically adjust the inference path, and there is still room for improvement in the automated processing ability of unstructured intelligence.
[0037] However, the existing threat intelligence analysis methods have at least the following defects: First, the limitation of linear reasoning. Traditional methods (such as the chain of thought) model the reasoning process as a linear chain and cannot capture multi-path logical relationships (such as the multi-stage penetration of APT attacks). Second, the lack of role separation and dynamics. The existing solutions split threat analysis into independent modules (such as detection, response), resulting in information fragmentation; static models are difficult to adapt to the rapid evolution of attack means (such as the real-time mutation of adversarial samples). Third, the inefficient processing of unstructured intelligence. Traditional methods rely on manual parsing of text reports and cannot automatically extract key information. Therefore, the accuracy and efficiency of the existing threat intelligence analysis are poor.
[0038] The technical solution of the present application and how the technical solution of the present application solves the above technical problems will be described in detail below with specific embodiments. The following several specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The following combines Figure 1 - Figure 2 Describe the threat intelligence analysis method of the present invention.
[0039] Figure 1 is one of the flow diagrams of the threat intelligence analysis method provided by the present invention. As Figure 1 shown, the method includes steps 101 to 105.
[0040] Step 101, obtain data to be analyzed. The data to be analyzed includes network traffic data, log data, open source intelligence data, and security device data.
[0041] Step 102, construct an initial mind map based on the data to be analyzed.
[0042] Wherein, each node in the mind map represents a threat proposition, and the connection edge between two nodes in the mind map represents the logical relationship between the two nodes.
[0043] Step 103: Implement the role conversion among the threat metric generator, threat assessor, and intelligence aggregator through a single large language model to obtain a threat intelligence analysis model.
[0044] Step 104: Input the initial mind map into the threat intelligence analysis model. After multiple iterative inferences, obtain the intelligence aggregation result output by the threat intelligence analysis model and the mind map after iterative inference.
[0045] Among them, the intelligence aggregation result includes: records of the inference process, evidence chains, threat assessment results, and recommended measures.
[0046] Step 105: Based on the intelligence aggregation result, perform a topological sort on the mind map after iterative inference to generate a coherent thought chain and output a threat intelligence report.
[0047] Among them, the threat intelligence report includes: a coherent thought chain and the intelligence aggregation result.
[0048] In practical applications, the execution entity of this threat intelligence analysis method can be a threat intelligence analysis device. There are various implementation methods for the threat intelligence analysis device. For example, it can be implemented through a computer program, such as application software, etc.; or, for example, a chip, etc. It can also be implemented as a medium storing relevant computer programs, such as a USB flash drive, cloud disk, etc.; or, furthermore, it can be implemented through an entity device integrated or installed with relevant computer programs, such as a server, intelligent device, etc.
[0049] The threat intelligence analysis method will be illustrated below with a threat intelligence analysis device as the execution entity.
[0050] Specifically, step 101 includes: obtaining the data to be analyzed.
[0051] In practical applications, the data to be analyzed is multi-source data, that is, the data to be analyzed is obtained from multiple data sources. Exemplarily, the threat intelligence analysis device obtains the data to be analyzed from multiple data sources. The multiple data sources include but are not limited to: network traffic data, log data, open source intelligence data, and security device data.
[0052] Among them, network traffic data refers to the information of data packets transmitted in the network, including but not limited to the source address, destination address, transmission protocol, data packet size, transmission time, etc. of the data packets. Exemplarily, the threat intelligence analysis device can obtain network traffic data from network devices and network monitoring tools.
[0053] Among them, log data refers to the record files generated by systems, application programs, network devices, etc., used to record various events and operations. Exemplarily, the threat intelligence analysis device can obtain log data from server logs, system logs, and application program logs.
[0054] Among them, open-source intelligence data refers to information obtained from public channels, which can be free or publicly released. For example, a threat intelligence analysis device can obtain open-source intelligence data from social media, news websites, and technology forums.
[0055] Among them, security device data refers to alarms, logs, and reports generated by various security devices. For example, a threat intelligence analysis device can obtain security device data from firewalls, intrusion detection systems (IDS), or intrusion prevention systems (IPS), and security software.
[0056] It can be understood that the threat intelligence analysis method provided in this application obtains the data to be analyzed provided by multiple data sources, and performs threat intelligence analysis on the data to be analyzed provided by multiple data sources, achieving comprehensive and reliable threat intelligence analysis, being able to adapt to threat intelligence analysis in complex scenarios, and improving the comprehensiveness and reliability of threat intelligence analysis.
[0057] Further, step 102 includes: constructing an initial mind map based on the data to be analyzed.
[0058] Among them, each node in the mind map represents a threat proposition, and the connection edge between two nodes in the mind map represents the logical relationship between the two nodes.
[0059] In this embodiment, a mind map refers to a framework based on a directed acyclic graph (DAG), which is used to model the iterative reasoning process in a large language model. Through natural language feedback, the model can iteratively generate high-quality answers during the reasoning process. Among them, a directed acyclic graph is a special graph structure, where the edges in the graph have directions and there are no loops in the graph.
[0060] In this embodiment, by introducing a directed acyclic graph (DAG) into threat analysis, this solution can capture the multi-path logic of attacks. For example, when detecting supply chain attacks, the DAG can simultaneously model multiple attack paths such as "tampering with dependent libraries" and "pushing malicious updates", and associate their dependencies through edges. This method is significantly better than traditional tree-like reasoning, which misses complex attack patterns due to its inability to express cyclic dependencies.
[0061] Optionally, in a possible implementation manner, the above step 102 includes: defining the nodes of the initial mind map; defining the logical relationships between the nodes in the initial mind map; organizing all the nodes and all the logical relationships into a structured framework to obtain the initial mind map.
[0062] Among them, each node in the mind map represents a threat proposition, and these propositions are the key information extracted from the data to be analyzed. For example, one node can be "Detecting suspicious IP behavior", and another node can be "Checking whether the IP is an internal asset".
[0063] Among them, the logical relationship refers to the dependency relationship between nodes, indicating that the establishment of one proposition depends on the result of another proposition. In practical applications, the logical relationship can be determined by predefined rules, such as based on known threat patterns or security policies; it can also be determined by data-driven analysis methods, such as using machine learning models or statistical analysis to identify patterns and associations in the data.
[0064] In an example, if it is known that an attacker usually tries to move laterally after obtaining initial access rights, then a rule can be predefined to establish a logical relationship between the two propositions of "Obtaining initial access rights" and "Trying to move laterally".
[0065] In another example, by analyzing historical data through a machine learning model, it is found that certain specific network traffic patterns are usually associated with malicious behavior, thus establishing a logical relationship between "Detecting a specific network traffic pattern" and "Judging as malicious behavior".
[0066] It can be understood that after defining the nodes of the initial mind map and the logical relationships between the nodes in the initial mind map, all nodes and all logical relationships are organized into a structured framework to obtain the initial mind map.
[0067] Specifically, organizing all reasoning nodes and logical relationships into a structured framework usually takes the form of a directed acyclic graph (DAG). A DAG can clearly represent the sequence and dependency relationships in the reasoning process, ensuring the logic and coherence of the reasoning.
[0068] For example, in a DAG, the node of "Checking whether the IP is an internal asset" can be used as a pre - node of the node of "Detecting suspicious IP behavior", indicating that before evaluating the suspicious IP behavior, it is necessary to first determine whether the IP belongs to an internal asset.
[0069] The following combines a specific example to illustrate the specific process of constructing the initial mind map. Suppose it is necessary to analyze the behavior of a suspicious IP address.
[0070] First, define the nodes of the initial mind map. The nodes correspond one - to - one with the threat propositions. Threat proposition 1 is "Detecting suspicious IP behavior", and threat proposition 2 is "Checking whether the IP is an internal asset". Therefore, 2 nodes are defined, one node corresponding to "Detecting suspicious IP behavior" and the other node corresponding to "Checking whether the IP is an internal asset".
[0071] Furthermore, define the logical relationships between the nodes in the initial mind map. For example, based on predefined rules, if an IP address does not belong to internal assets, it is more likely to be an external attack source. Therefore, establish a logical relationship between "check if the IP is an internal asset" and "detect suspicious IP behavior". Another example is that based on data-driven analysis methods, by analyzing historical data through a machine learning model, it is found that IP addresses related to high-frequency access behavior usually have a higher attack risk. Therefore, establish a logical relationship between "detect suspicious IP behavior" and "evaluate IP risk".
[0072] Furthermore, organize all nodes and all logical relationships into a structured framework to obtain the initial mind map. It can be understood that through the above steps, a structured initial mind map can be obtained, laying a foundation for subsequent iterative reasoning and threat intelligence analysis.
[0073] Furthermore, step 103 includes: achieving role conversion between the threat indicator generator, threat evaluator, and intelligence aggregator through a single large language model to obtain a threat intelligence analysis model.
[0074] Among them, the threat indicator generator (Indicator Generator) is a key role in the mind map framework. It is responsible for generating initial propositions and driving subsequent reasoning steps during the threat intelligence analysis process. It promotes the entire analysis process by introducing new threat indicators (Indicators of Compromise, IoC) or reasoning nodes.
[0075] Among them, the threat evaluator (Threat Evaluator) plays the role of a "referee" during the threat intelligence analysis process. Its main task is to evaluate the credibility and relevance of the threat indicators or threat propositions generated by the threat indicator generator and provide feedback to guide subsequent reasoning steps.
[0076] Among them, the intelligence aggregator (Intelligence Aggregator) plays the role of a "summarizer" during the threat intelligence analysis process. Its main task is to integrate scattered reasoning propositions and evaluation results into a coherent and structured threat intelligence report, providing clear analysis results and decision-making basis.
[0077] In practical applications, the threat indicator generator proposes reasoning steps, the threat evaluator conducts threat evaluations or intelligence aggregations, and the intelligence aggregator summarizes the results.
[0078] Specifically, in the threat indicator generation stage, the threat indicator generator introduces a proposition and adds a node to the DAG. For example, in threat intelligence analysis, the threat indicator generator proposes "detect suspicious IP behavior".
[0079] In the threat assessment phase, the threat assessor evaluates the propositions introduced by the threat indicator generator, either confirming it or providing criticism. If criticism is provided, new nodes are added and edges are established between the proposition and the criticism. For example, the threat assessor points out "Check if the IP is an internal asset".
[0080] In the iterative reasoning phase, according to the comments of the threat assessor, a refined proposition is generated, represented as a new node in the DAG. For example, the threat indicator generator proposes "Combine the analysis of failed SSH logins".
[0081] In the intelligence aggregation phase, the processes of threat indicator generation, threat assessment, and iterative reasoning are repeated until the proposition is aggregated with intelligence. For example, after multiple rounds of iteration, the final intelligence aggregation is "Evaluate the communication behavior between devices".
[0082] In the summary phase, the intelligence aggregator performs comprehensive reasoning, executes a topological sort on the DAG, and generates a coherent chain of thoughts.
[0083] In the present invention, by combining the semantic understanding ability of the large language model (such as parsing unstructured vulnerability reports) with the structured knowledge graph (such as the STIX standard), the full life cycle management of threat intelligence is realized. By introducing the mind map framework, the large language model is used to deeply analyze text intelligence, extract key threat information (such as IoC, tactics, techniques, procedures TTPs), so as to generate a structured intelligence report that meets the standards, improve the queryability and operability of intelligence, and enhance the intelligence sharing and collaborative analysis capabilities between different platforms.
[0084] Optionally, in a possible implementation manner, step 103 includes: Implement a threat indicator generator within a single large language model, where the threat indicator generator is used to generate threat propositions; Implement a threat assessor within a single large language model, where the threat assessor is used to evaluate threat propositions and obtain the evaluation results corresponding to the threat propositions; Implement an intelligence aggregator within a single large language model, where the intelligence aggregator is used to aggregate the evaluation results corresponding to threat propositions; Through a pre-set role setting, guide the single large language model to realize the role conversion between the threat indicator generator, the threat assessor, and the intelligence aggregator, and obtain a threat intelligence analysis model.
[0085] Furthermore, step 104 includes: inputting the initial mind map into the threat intelligence analysis model, and after multiple rounds of iterative reasoning, obtaining the intelligence aggregation result output by the threat intelligence analysis model and the mind map after iterative reasoning; the intelligence aggregation result includes: records of the reasoning process, the evidence chain, the threat assessment result, and recommended measures.
[0086] In this embodiment, the entire reasoning process is modeled as a directed acyclic graph (DAG), where each node represents a proposition and the edges represent logical or dependency relationships, ensuring an orderly reasoning process without circular dependencies.
[0087] Optionally, in a possible implementation manner, step 104 above includes: Based on the initial mind map, generate initial threat propositions through a threat indicator generator; Add new nodes corresponding to the initial threat propositions to the current mind map, and define the logical relationships between the new nodes and other nodes to obtain an updated mind map; Evaluate the initial threat propositions through a threat evaluator to obtain the evaluation results corresponding to the initial threat propositions; the evaluation results corresponding to the initial threat propositions include: evaluation passed, evaluation not passed, and further evaluation required; If the evaluation result corresponding to the initial threat proposition is evaluation passed or evaluation not passed, then summarize the evaluation result corresponding to the initial proposition and the evaluation process of the initial proposition through an intelligence aggregator to obtain an intelligence aggregation result; If the evaluation result corresponding to the initial threat proposition is further evaluation required, then perform iterative reasoning processing to obtain the intelligence aggregation result output by the threat intelligence analysis model and the mind map after iterative reasoning; Among them, the iterative reasoning processing includes: Generate new threat propositions through a threat indicator generator; Add new nodes corresponding to the new threat propositions to the current mind map, and define the logical relationships between the new nodes and other nodes to obtain an updated mind map; Evaluate the new threat propositions through a threat evaluator to obtain the evaluation results corresponding to the new threat propositions; the evaluation results corresponding to the new threat propositions include: evaluation passed, evaluation not passed, and further evaluation required; If the evaluation result corresponding to the new threat proposition is further evaluation required, then return to execute the step of generating new threat propositions through a threat indicator generator, otherwise, summarize the evaluation results corresponding to all propositions and the evaluation processes of all propositions through an intelligence aggregator to obtain an intelligence aggregation result.
[0088] Specifically, the threat indicator generator (Indicator Generator) generates initial threat propositions based on the initial mind map. The initial threat propositions can be key information extracted from the data to be analyzed. Add new nodes to the current mind map, each node representing a threat proposition, and define the logical relationships between these new nodes and other nodes. This step ensures the dynamic update and expansion of the reasoning graph.
[0089] Furthermore, the Threat Evaluator evaluates the initial threat proposition to judge its credibility and relevance. The evaluation results may include: evaluation passed, evaluation failed, and further evaluation required. Evaluation passed indicates that the threat proposition holds and can be used as valid information. Evaluation failed indicates that the threat proposition does not hold and needs to be excluded. Further evaluation required indicates that the evidence to support the proposition is insufficient and further verification is needed.
[0090] Furthermore, if the evaluation result of the initial threat proposition is evaluation passed or evaluation failed, the Intelligence Aggregator aggregates the evaluation result and the evaluation process to generate an intelligence aggregation result.
[0091] In contrast, if the evaluation result of the initial threat proposition is further evaluation required, it enters the iterative reasoning processing stage. First, the Threat Indicator Generator generates a new threat proposition. Then, a new node is added to the current mind map, and the logical relationships between the new node and other nodes are defined. Then, the Threat Evaluator evaluates the new threat proposition to judge its credibility and relevance. Then, if the evaluation result of the new threat proposition is further evaluation required, it returns to the step of the Threat Indicator Generator generating a new threat proposition to continue generating new threat propositions. If the evaluation result of the new threat proposition is evaluation passed or evaluation failed, the Intelligence Aggregator aggregates the evaluation results and the evaluation processes of all propositions to generate a final intelligence aggregation result.
[0092] The following uses a specific example to illustrate the reasoning iteration process. Figure 2 is the second schematic diagram of the process of the threat intelligence analysis method provided by the present invention. As Figure 2 shown, for the threat intelligence analysis process of a suspicious IP access, it is as follows: The Threat Indicator Generator 1 discovers a suspicious access behavior. First, the detection system discovers that there is a suspicious access behavior (such as high-frequency access) for a certain IP address. This node serves as the initial reasoning starting point and generates the first proposition.
[0093] The Threat Evaluator 1 checks whether the IP is an internal asset. This Threat Evaluator node aggregates the intelligence of the suspicious IP and checks whether it belongs to internal assets to exclude false alarms. If the IP belongs to internal assets, it may be a normal access; otherwise, it enters the next step of analysis.
[0094] The Threat Indicator Generator 2 analyzes in combination with SSH failed logins. Combining the SSH login failure situation of the suspicious IP, it judges whether there is a brute-force cracking or unauthorized access attempt. This node adds a new proposition to further deeply analyze the attack intention.
[0095] The threat assessor 2 checks for abnormal logins to the account. It examines whether there are abnormal account login behaviors, such as high-frequency failed attempts, unconventional login times, etc. This node serves as a review to prevent misjudgment.
[0096] The threat indicator generator 3 analyzes the traffic of associated devices. If the account is indeed abnormal, it conducts an extended analysis to check the network traffic situation of the affected devices. This node introduces new data sources to comprehensively evaluate the threat.
[0097] The threat indicator generator 4 discovers suspicious traffic behaviors. First, the detection system detects that a certain IP address has suspicious traffic behaviors (abnormal traffic). This node serves as the initial reasoning starting point and generates the second proposition.
[0098] The threat assessor 3 evaluates the communication behaviors between devices. It further checks whether there is abnormal traffic between related devices, such as C2 communication, abnormal data exchange, etc. This node provides a threat assessment analysis of the traffic behavior to determine whether it belongs to an attack.
[0099] The intelligence aggregator generates a threat report. Finally, the intelligence aggregator combines all the reasoning steps with aggregated intelligence and summarizes the entire event.
[0100] Specifically, step 105 includes: based on the result of intelligence aggregation, performing a topological sort on the mind map after iterative reasoning to generate a coherent thought chain, and outputting a threat intelligence report; the threat intelligence report includes: the coherent thought chain and the result of intelligence aggregation.
[0101] Among them, topological sorting is a linear sorting of a directed acyclic graph. It can be understood that topological sorting can ensure the coherence of the reasoning logic, optimize the threat situation awareness, and improve the accuracy and reliability of threat intelligence analysis.
[0102] Optionally, in one example, the above step 105 specifically includes: based on the result of intelligence aggregation, applying Kahn's algorithm to perform a topological sort on the mind map after iterative reasoning to generate a coherent thought chain.
[0103] Among them, Kahn's Algorithm is a greedy algorithm for topological sorting, applicable to directed acyclic graphs (DAGs), mainly used to solve problems such as task scheduling, dependency resolution, logical reasoning, etc. Topological sorting means arranging all the nodes in a DAG into a linear sequence such that for each directed edge , node appears before node . Kahn's algorithm realizes topological sorting through breadth-first search (BFS), especially suitable for processing graphs with hierarchical structures.
[0104] Specifically, Kahn's algorithm maintains a queue of nodes with an in-degree of 0 (i.e., tasks with no dependencies at present). Nodes are taken out of the queue in sequence, added to the topological sequence, and the in-degree of their adjacent nodes is decreased by 1. If the in-degree of an adjacent node becomes 0, it is added to the queue. Until the queue is empty, if all nodes have been added to the topological sequence, the sorting is successful; otherwise, it indicates that there is a cycle in the graph.
[0105] The mathematical formula for topological sorting is as follows: Given a directed acyclic graph , where: is the set of vertices (nodes), is the set of edges (directed connections, representing dependency relationships).
[0106] Topological sorting is a permutation T (sequence): such that for each directed edge , in the permutation T , must appear before , that is: where, represents the position of vertex v in the sorting.
[0107] In-degree is defined as the number of edges pointing to vertex v: Initially, find all nodes with an in-degree of 0: Recursively delete nodes: Select a node S in , add it to the sorting result, and update the in-degree of all adjacent nodes: If the in-degree of a certain node drops to 0, add it to S .
[0108] Termination condition: When all nodes are added to the sorting, the final topological sequence is obtained: In addition, in a possible implementation, after the above step 101, the above method further includes: Perform noise reduction processing on the data to be analyzed to obtain the data to be analyzed after noise reduction processing. The noise reduction processing includes at least one of the following: removing duplicate data, filtering out irrelevant information, and correcting incorrect data.
[0109] In this embodiment, after obtaining the data to be analyzed, noise reduction processing is performed, which can improve the accuracy and reliability of threat intelligence analysis.
[0110] It can be understood that, compared with the prior art, the present invention has significantly improved in terms of reasoning method, dynamic adaptability, and unstructured data processing ability.
[0111] Specifically, based on the mind map framework of a directed acyclic graph (DAG), the present invention disassembles the inference process of the large model into logical nodes such as threat indicator generation, threat assessment, and intelligence aggregation, enabling the inference to be carried out in parallel along multiple paths and ensuring logical consistency through topological sorting. Compared with the semantic analysis method based on deep learning, the DAG structure of the present invention can better depict complex attack chains and adapt to attack analysis scenarios with multiple stages, multiple causations, and multiple sources.
[0112] Furthermore, the present invention integrates roles such as Indicator Generator (threat indicator generator), Threat Evaluator (threat evaluator), and Intelligence Aggregator (intelligence aggregator) within a single large model, enabling the model to dynamically adjust the analysis strategy during the inference process. For example, after detecting suspicious traffic, the system can iteratively refine the attack judgment through the threat assessment node to avoid misjudgment based on static rules. This ability is superior to traditional threat analysis methods based on fixed models, making detection and response more flexible.
[0113] Furthermore, the present invention combines the natural language processing ability of the large model to automatically extract threat indicators (IoC) and attack tactics (such as the MITRE ATT&CK framework) from unstructured intelligence (such as vulnerability reports, social media discussions), and maps them to a structured knowledge base to achieve automated, real-time, and efficient threat analysis. Compared with the prior art, this method not only improves the in-depth understanding ability of threat intelligence but also can dynamically adapt to the rapid evolution of attack means, providing stronger intelligent and automated support for network security defense.
[0114] The threat intelligence analysis method provided in this embodiment constructs an initial mind map based on the acquired data to be analyzed; each node in the mind map represents a threat proposition, and the connecting edge between two nodes in the mind map represents the logical relationship between the two nodes; the role conversion between the threat indicator generator, the threat evaluator, and the intelligence aggregator is achieved through a single large language model to obtain a threat intelligence analysis model; the initial mind map is input into the threat intelligence analysis model, and after multiple iterative inferences, the intelligence aggregation result output by the threat intelligence analysis model and the mind map after iterative inference are obtained; based on the intelligence aggregation result, a topological sort is performed on the mind map after iterative inference to generate a coherent thought chain, and a threat intelligence report is output, where the threat intelligence report includes: the coherent thought chain and the intelligence aggregation result. The solution of this embodiment, by introducing the mind map framework, models threat intelligence analysis as a directed acyclic graph, decomposes the threat intelligence analysis process into nodes at multiple levels, and based on the inference framework of the directed acyclic graph, promotes the hierarchical understanding of complex threat patterns by the large model. Moreover, it integrates roles such as threat indicator generation, threat assessment, and intelligence aggregation to achieve non-linear and multi-path reasoning. Further, through iterative inference and topological sorting, it can dynamically adapt to complex threats and reduce misjudgments caused by insufficient model generalization. Further, by utilizing the semantic understanding ability of the large model, structured threat features are extracted from the data to be analyzed to achieve automated processing of unstructured data. Further, a closed-loop of detection, analysis, and response is implemented in a single model, reducing manual intervention and improving the efficiency of defense collaboration. Therefore, the solution of the present invention improves the accuracy and efficiency of threat intelligence analysis.
[0115] The threat intelligence analysis device provided by the present invention will be described below. The threat intelligence analysis device described below can be mutually referred to with the threat intelligence analysis method described above.
[0116] Figure 3 is a schematic structural diagram of the threat intelligence analysis device provided by the present invention, as Figure 3 shown, the threat intelligence analysis device includes: an acquisition module 31, a construction module 32, a processing module 33, an input module 34, and a sorting module 35.
[0117] The acquisition module 31 is used to acquire data to be analyzed, and the data to be analyzed includes network traffic data, log data, open source intelligence data, and security device data.
[0118] The construction module 32 is used to construct an initial mind map based on the data to be analyzed; each node in the mind map represents a threat proposition, and the connecting edge between two nodes in the mind map represents the logical relationship between the two nodes.
[0119] The processing module 33 is used to implement the role conversion among the threat metric generator, the threat assessor, and the intelligence aggregator through a single large language model, and obtain a threat intelligence analysis model.
[0120] The input module 34 is used to input the initial mind map into the threat intelligence analysis model. After multiple iterative inferences, the intelligence aggregation result output by the threat intelligence analysis model and the mind map after iterative inference are obtained; the intelligence aggregation result includes: the record of the inference process, the evidence chain, the threat assessment result, and the recommended measures.
[0121] The sorting module 35 is used to perform topological sorting on the mind map after iterative inference based on the intelligence aggregation result, generate a coherent thought chain, and output a threat intelligence report; the threat intelligence report includes: the coherent thought chain and the intelligence aggregation result.
[0122] Optionally, in a possible implementation manner, the above-mentioned construction module 32 is specifically used for: Define the nodes of the initial mind map; Define the logical relationships between the nodes in the initial mind map; Organize all nodes and all logical relationships into a structured framework to obtain the initial mind map.
[0123] Optionally, in a possible implementation manner, the above-mentioned processing module 33 is specifically used for: Implement a threat metric generator within a single large language model, and the threat metric generator is used to generate threat propositions; Implement a threat assessor within a single large language model, and the threat assessor is used to evaluate threat propositions to obtain the evaluation results corresponding to the threat propositions; Implement an intelligence aggregator within a single large language model, and the intelligence aggregator is used to aggregate the evaluation results corresponding to the threat propositions; Through a pre-set role setting, guide the single large language model to implement the role conversion among the threat metric generator, the threat assessor, and the intelligence aggregator, and obtain a threat intelligence analysis model.
[0124] Optionally, in a possible implementation manner, the above-mentioned input module 34 is specifically used for: Based on the initial mind map, generate an initial threat proposition through the threat metric generator; Add a new node corresponding to the initial threat proposition to the current mind map, and define the logical relationship between the new node and other nodes to obtain an updated mind map; Evaluate the initial threat proposition through the threat assessor to obtain the evaluation result corresponding to the initial threat proposition; the evaluation result corresponding to the initial threat proposition includes: evaluation passed, evaluation not passed, and further evaluation required; If the evaluation result corresponding to the initial threat proposition is "evaluation passed" or "evaluation failed", the intelligence aggregator aggregates the evaluation result corresponding to the initial proposition and the evaluation process of the initial proposition to obtain the intelligence aggregation result; If the evaluation result corresponding to the initial threat proposition is "further evaluation required", iterative reasoning processing is performed to obtain the intelligence aggregation result output by the threat intelligence analysis model and the mind map after iterative reasoning; Among them, the iterative reasoning processing includes: Generating a new threat proposition through a threat indicator generator; Adding a new node corresponding to the new threat proposition to the current mind map and defining the logical relationship between the new node and other nodes to obtain an updated mind map; Evaluating the new threat proposition through a threat evaluator to obtain the evaluation result corresponding to the new threat proposition; the evaluation result corresponding to the new threat proposition includes: evaluation passed, evaluation failed, further evaluation required; If the evaluation result corresponding to the new threat proposition is "further evaluation required", return to execute the step of generating a new threat proposition through the threat indicator generator, otherwise, the intelligence aggregator aggregates the evaluation results corresponding to all propositions and the evaluation processes of all propositions to obtain the intelligence aggregation result.
[0125] Optionally, in a possible implementation manner, the above sorting module 35 is specifically used for: Based on the intelligence aggregation result, applying the Kahn algorithm to perform topological sorting on the mind map after iterative reasoning to generate a coherent thinking chain.
[0126] Optionally, in a possible implementation manner, the above threat intelligence analysis device further includes: A preprocessing module for performing noise reduction processing on the data to be analyzed to obtain the data to be analyzed after noise reduction processing, and the noise reduction processing includes at least one of the following: removing duplicate data, filtering out irrelevant information, and correcting error data.
[0127] The threat intelligence analysis device provided in this embodiment, the construction module constructs an initial mind map based on the data to be analyzed obtained by the acquisition module; each node in the mind map represents a threat proposition, and the connection edge between two nodes in the mind map represents the logical relationship between the two nodes; the processing module realizes the role conversion between the threat indicator generator, the threat evaluator and the intelligence aggregator through a single large language model to obtain a threat intelligence analysis model; the input module inputs the initial mind map into the threat intelligence analysis model, and after multiple iterative inferences, obtains the intelligence aggregation result output by the threat intelligence analysis model and the mind map after iterative inferences; the sorting module performs a topological sort on the mind map after iterative inferences based on the intelligence aggregation result to generate a coherent thought chain and outputs a threat intelligence report, and the threat intelligence report includes: the coherent thought chain and the intelligence aggregation result. The solution of this embodiment, by introducing the mind map framework, models threat intelligence analysis as a directed acyclic graph, decomposes the threat intelligence analysis process into nodes at multiple levels, and based on the inference framework of the directed acyclic graph, promotes the hierarchical understanding of complex threat patterns by the large model. Moreover, it integrates roles such as threat indicator generation, threat assessment and intelligence aggregation to achieve non-linear and multi-path reasoning. Further, through iterative inference and topological sorting, it can dynamically adapt to complex threats and reduce misjudgments caused by insufficient model generalization. Further, by using the semantic understanding ability of the large model, it extracts structured threat features from the data to be analyzed and realizes the automated processing of unstructured data. Further, a closed loop of detection, analysis and response is realized in a single model, reducing manual intervention and improving the efficiency of defense collaboration. Therefore, the solution of the present invention improves the accuracy and efficiency of threat intelligence analysis.
[0128] Figure 4 is a schematic structural diagram of the electronic device provided by the present invention, as Figure 4As shown in the figure, the electronic device may include: a processor 410, a communications interface 420, a memory 430, and a communication bus 440. Among them, the processor 410, the communications interface 420, and the memory 430 complete mutual communication through the communication bus 440. The processor 410 may call logical instructions in the memory 430 to execute a threat intelligence analysis method, which includes: obtaining data to be analyzed, where the data to be analyzed includes network traffic data, log data, open source intelligence data, and security device data; based on the data to be analyzed, constructing an initial mind map, where each node in the mind map represents a threat proposition, and the connection edge between two nodes in the mind map represents the logical relationship between the two nodes; implementing role conversion between a threat metric generator, a threat assessor, and an intelligence aggregator through a single large language model to obtain a threat intelligence analysis model; inputting the initial mind map into the threat intelligence analysis model, and after multiple iterative inferences, obtaining the intelligence aggregation result output by the threat intelligence analysis model and the mind map after iterative inference. The intelligence aggregation result includes: a record of the inference process, an evidence chain, a threat assessment result, and recommended measures; based on the intelligence aggregation result, performing a topological sort on the mind map after iterative inference to generate a coherent thought chain, and outputting a threat intelligence report, where the threat intelligence report includes: the coherent thought chain and the intelligence aggregation result.
[0129] In addition, when the logical instructions in the above-mentioned memory 430 can be implemented in the form of software functional units and sold or used as an independent product, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical disks, etc., which can store program codes.
[0130] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the threat intelligence analysis method provided by the above-mentioned various methods. The method includes: obtaining data to be analyzed, where the data to be analyzed includes network traffic data, log data, open source intelligence data, and security device data; based on the data to be analyzed, constructing an initial mind map, where each node in the mind map represents a threat proposition, and the connection edge between two nodes in the mind map represents the logical relationship between the two nodes; realizing the role conversion between a threat indicator generator, a threat assessor, and an intelligence aggregator through a single large language model to obtain a threat intelligence analysis model; inputting the initial mind map into the threat intelligence analysis model, and through multiple iterative inferences, obtaining the intelligence aggregation result output by the threat intelligence analysis model and the mind map after iterative inferences. The intelligence aggregation result includes: a record of the reasoning process, an evidence chain, a threat assessment result, and recommended measures; based on the intelligence aggregation result, performing a topological sort on the mind map after iterative inferences to generate a coherent thought chain, and outputting a threat intelligence report, where the threat intelligence report includes: the coherent thought chain and the intelligence aggregation result.
[0131] On another aspect, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it realizes the execution of the threat intelligence analysis method provided by the above-mentioned various methods. The method includes: obtaining data to be analyzed, where the data to be analyzed includes network traffic data, log data, open source intelligence data, and security device data; based on the data to be analyzed, constructing an initial mind map, where each node in the mind map represents a threat proposition, and the connection edge between two nodes in the mind map represents the logical relationship between the two nodes; realizing the role conversion between a threat indicator generator, a threat assessor, and an intelligence aggregator through a single large language model to obtain a threat intelligence analysis model; inputting the initial mind map into the threat intelligence analysis model, and through multiple iterative inferences, obtaining the intelligence aggregation result output by the threat intelligence analysis model and the mind map after iterative inferences. The intelligence aggregation result includes: a record of the reasoning process, an evidence chain, a threat assessment result, and recommended measures; based on the intelligence aggregation result, performing a topological sort on the mind map after iterative inferences to generate a coherent thought chain, and outputting a threat intelligence report, where the threat intelligence report includes: the coherent thought chain and the intelligence aggregation result.
[0132] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative efforts.
[0133] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to enable a computer device (which can be a personal computer, server, or network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0134] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments or equivalently replace some of the technical features. These modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of each embodiment of the present invention.
Claims
1. A threat intelligence analysis method, characterized in that, Including: Obtain the data to be analyzed, where the data to be analyzed includes network traffic data, log data, open source intelligence data, and security device data; Based on the data to be analyzed, construct an initial mind map; each node in the mind map represents a threat proposition, and the connection edge between two nodes in the mind map represents the logical relationship between the two nodes; Implement the role conversion between the threat indicator generator, threat evaluator, and intelligence aggregator through a single large language model to obtain a threat intelligence analysis model; Input the initial mind map into the threat intelligence analysis model, and through multiple iterative inferences, obtain the intelligence aggregation result output by the threat intelligence analysis model and the mind map after iterative inference; The intelligence aggregation result includes: records of the reasoning process, evidence chain, threat assessment result, and recommended measures; Based on the intelligence aggregation result, perform a topological sort on the mind map after iterative inference to generate a coherent thought chain, and output a threat intelligence report, where the threat intelligence report includes: the coherent thought chain and the intelligence aggregation result.
2. The threat intelligence analysis method according to claim 1, wherein The constructing an initial mind map based on the data to be analyzed includes: Define the nodes of the initial mind map; Define the logical relationships between the nodes in the initial mind map; Organize all nodes and all logical relationships into a structured framework to obtain the initial mind map.
3. The threat intelligence analysis method according to claim 1, wherein The implementing the role conversion between the threat indicator generator, threat evaluator, and intelligence aggregator through a single large language model to obtain a threat intelligence analysis model includes: Implement the threat indicator generator within the single large language model, where the threat indicator generator is used to generate threat propositions; Implement a threat evaluator within the single large language model, where the threat evaluator is used to evaluate the threat propositions to obtain the evaluation results corresponding to the threat propositions; Implement an intelligence aggregator within the single large language model, where the intelligence aggregator is used to aggregate the evaluation results corresponding to the threat propositions; Through a pre-set role setting, guide the single large language model to implement the role conversion between the threat indicator generator, the threat evaluator, and the intelligence aggregator to obtain the threat intelligence analysis model.
4. The threat intelligence analysis method according to claim 1, wherein The inputting the initial mind map into the threat intelligence analysis model and through multiple iterative inferences to obtain the intelligence aggregation result output by the threat intelligence analysis model and the mind map after iterative inference includes: Based on the initial mind map, generate an initial threat proposition through the threat indicator generator; Add a new node corresponding to the initial threat proposition to the current mind map, and define the logical relationship between the new node and other nodes to obtain an updated mind map; Evaluate the initial threat proposition through the threat evaluator to obtain the evaluation result corresponding to the initial threat proposition; the evaluation result corresponding to the initial threat proposition includes: evaluation passed, evaluation failed, and further evaluation required; If the evaluation result corresponding to the initial threat proposition is evaluation passed or evaluation failed, the intelligence aggregator aggregates the evaluation result corresponding to the initial proposition and the evaluation process of the initial proposition to obtain the intelligence aggregation result; If the evaluation result corresponding to the initial threat proposition is that further evaluation is required, iterative reasoning processing is performed to obtain the intelligence aggregation result output by the threat intelligence analysis model and the mind map after iterative reasoning; Among them, the iterative reasoning processing includes: Generating a new threat proposition through the threat index generator; Adding a new node corresponding to the new threat proposition to the current mind map and defining the logical relationship between the new node and other nodes to obtain an updated mind map; Evaluating the new threat proposition through the threat evaluator to obtain the evaluation result corresponding to the new threat proposition; the evaluation result corresponding to the new threat proposition includes: evaluation passed, evaluation failed, and further evaluation required; If the evaluation result corresponding to the new threat proposition is that further evaluation is required, return to execute the step of generating a new threat proposition through the threat index generator, otherwise, the intelligence aggregator aggregates the evaluation results corresponding to all propositions and the evaluation processes of all propositions to obtain the intelligence aggregation result.
5. The threat intelligence analysis method according to claim 1, wherein Based on the intelligence aggregation result, performing a topological sort on the mind map after iterative reasoning to generate a coherent thought chain, specifically including: Based on the intelligence aggregation result, applying the Kahn algorithm to perform a topological sort on the mind map after iterative reasoning to generate a coherent thought chain.
6. The threat intelligence analysis method according to any one of claims 1-5, characterized in that After obtaining the data to be analyzed, the method further includes: Performing noise reduction processing on the data to be analyzed to obtain the data to be analyzed after noise reduction processing, and the noise reduction processing includes at least one of the following: removing duplicate data, filtering out irrelevant information, and correcting incorrect data.
7. A threat intelligence analysis device, characterized in that, Including: An acquisition module, configured to acquire data to be analyzed, where the data to be analyzed includes network traffic data, log data, open source intelligence data, and security device data; A construction module, configured to construct an initial mind map based on the data to be analyzed; each node in the mind map represents a threat proposition, and the connection edge between two nodes in the mind map represents the logical relationship between the two nodes; A processing module, configured to implement role conversion between the threat index generator, the threat evaluator, and the intelligence aggregator through a single large language model to obtain a threat intelligence analysis model; An input module, configured to input the initial mind map into the threat intelligence analysis model, and after multiple iterative reasoning, obtain the intelligence aggregation result output by the threat intelligence analysis model and the mind map after iterative reasoning; The intelligence aggregation result includes: a record of the reasoning process, an evidence chain, a threat assessment result, and recommended measures; A sorting module, configured to perform a topological sort on the mind map after iterative reasoning based on the intelligence aggregation result to generate a coherent thought chain, and output a threat intelligence report, where the threat intelligence report includes: a coherent thought chain and the intelligence aggregation result.
8. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the threat intelligence analysis method according to any one of claims 1 to 6.
9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the threat intelligence analysis method according to any one of claims 1 to 6.
10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the threat intelligence analysis method according to any one of claims 1 to 6.