Intelligence data synchronization method and device based on intelligence characteristics, program product

By calculating storage priorities based on intelligence features and synchronizing high-priority intelligence data, the problem of low resource utilization in traditional synchronization methods is solved, and efficient utilization and rapid response of intelligence data are achieved.

CN120429368BActive Publication Date: 2026-01-23ZHONGJINKE INFORMATION TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510888585.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-30
Publication Date
2026-01-23
Estimated Expiration
2045-06-30

AI Technical Summary

Technical Problem

Traditional methods of synchronizing intelligence data consume a lot of network resources and local storage space, and have low query efficiency, making it impossible to respond quickly to urgent network threats.

Method used

By determining the characteristics of intelligence data, calculating storage priorities, and selecting and synchronizing high-priority intelligence data from remote storage devices to local storage devices based on priorities and preset query conditions.

Benefits of technology

It improved the utilization rate of intelligence data, optimized the allocation of local storage resources, improved query efficiency and response speed, and avoided unnecessary storage pressure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120429368B_ABST
    Figure CN120429368B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a method and device for synchronizing intelligence data based on intelligence features, and a program product, wherein the method comprises: determining intelligence features of N first intelligence data; calculating storage priorities of M second intelligence data in a second storage device based on the intelligence features; determining K target intelligence data to be synchronized to a first storage device from the M second intelligence data according to the storage priorities of the M second intelligence data and a second preset query condition; and synchronizing the K target intelligence data to the first storage device. Through the present application, the problem of low resource rate of the related art intelligence data synchronization method is solved, and the utilization rate of intelligence data is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computers, and more specifically, to a method and apparatus, program product, and storage medium for synchronizing intelligence data based on intelligence features. Background Technology

[0002] In an increasingly complex cybersecurity environment, intelligence data is crucial for the timely identification and defense of cyberattacks. However, the massive storage and efficient retrieval of intelligence data have become a major challenge. Traditional methods for synchronizing intelligence data typically employ a static, full-scale synchronization strategy, which involves periodically downloading all intelligence data from the cloud or remote servers to local storage devices. This method not only consumes significant network resources and local storage space but also suffers from low local query efficiency due to the sheer volume of data, making it impossible to respond quickly to urgent cyber threats. Summary of the Invention

[0003] This application provides a method, apparatus, program product, and storage medium for synchronizing intelligence data based on intelligence features, in order to at least solve the problem of low resource efficiency in intelligence data synchronization methods in related technologies.

[0004] According to one embodiment of this application, a method for synchronizing intelligence data based on intelligence features is provided, comprising: determining intelligence features of N first intelligence data, wherein the N first intelligence data are intelligence data stored in a first storage device and satisfy a first preset query condition, and N is a natural number greater than or equal to 1; calculating the storage priority of M second intelligence data in a second storage device based on the intelligence features, wherein all M second intelligence data are intelligence data stored in the second storage device, and M is a natural number greater than or equal to 1; determining K target intelligence data to be synchronized to the first storage device from the M second intelligence data according to the storage priority of the M second intelligence data and the second preset query condition, wherein K is a natural number less than or equal to M; and synchronizing the K target intelligence data to the first storage device.

[0005] In one exemplary embodiment, determining the intelligence features of N first intelligence data includes: filtering intelligence data that satisfy the first preset query conditions from the first storage device to obtain N first intelligence data; performing data preprocessing operations on the N first intelligence data to obtain P third intelligence data, wherein the data preprocessing operations include data cleaning operations and data removal operations, and P is a natural number less than or equal to N; extracting P first information from the P third intelligence data, wherein the first information includes data information of the third intelligence data and data processing information acting on the third intelligence data; and determining the intelligence features of the P third intelligence data from the P first information to obtain the intelligence features of the N first intelligence data.

[0006] In one exemplary embodiment, calculating the storage priority of M second intelligence data in the second storage device based on the aforementioned intelligence features includes: for each of the aforementioned second intelligence data, calculating the storage priority in the second storage device through the following steps to obtain M storage priorities: extracting second information from the aforementioned second intelligence data, wherein the second information includes the data information of the aforementioned second intelligence data; and calculating the storage priority of the aforementioned second intelligence data in the second storage device based on the second information.

[0007] In one exemplary embodiment, calculating the storage priority of the second intelligence data in the second storage device based on the second information includes: parsing the geographical location of the intelligence source that generated the second intelligence data from the second information to obtain a first geographical location; calculating the distance between the first geographical location and the second geographical location to obtain a target distance, wherein the second geographical location is the geographical location of the intelligence source that generated the fourth intelligence data, and the fourth intelligence data has the same intelligence type as the second intelligence data; calculating the positional overlap between the first geographical location and the second geographical location according to the target distance and a preset distance threshold; and calculating the storage priority of the second intelligence data in the second storage device using a first preset weight and the positional overlap.

[0008] In one exemplary embodiment, calculating the storage priority of the second intelligence data in the second storage device based on the second information includes: parsing the target scenario to which the second intelligence data belongs from the second information to obtain target scenario information; using the target scenario information to determine the correlation between the second intelligence data and the target scenario; and using a second preset weight and the correlation to calculate the storage priority of the second intelligence data in the second storage device.

[0009] In one exemplary embodiment, calculating the storage priority of the second intelligence data in the second storage device based on the second information includes: parsing the intelligence type of the second intelligence data from the second information to obtain a target intelligence type; determining the weight of the target intelligence type among multiple preset intelligence types to obtain a target weight; and calculating the storage priority of the second intelligence data in the second storage device using a third preset weight and the target weight.

[0010] In one exemplary embodiment, determining K target intelligence data to be synchronized to the first storage device from the M second intelligence data according to the storage priority of the M second intelligence data and a second preset query condition includes one of the following: when the storage space of the first storage device meets the first preset storage condition, determining the fifth intelligence data and the intelligence data whose storage priority meets the first preset storage priority from the M second intelligence data as the K target intelligence data according to the storage priority of the M second intelligence data, wherein the fifth intelligence data is incremental intelligence data in the second storage device; when the storage space of the first storage device meets the second preset storage condition, determining the intelligence data whose storage priority meets the second preset storage priority from the M second intelligence data as the K target intelligence data.

[0011] In one exemplary embodiment, synchronizing K target intelligence data to the first storage device includes: when the storage space of the first storage device meets a third preset storage condition, comparing the storage priorities of N first intelligence data with the storage priorities of M second intelligence data; determining Q sixth intelligence data from the M second intelligence data based on the comparison result, wherein Q is a natural number less than or equal to M; and when the storage space of the first storage device meets a fourth preset storage condition, deleting R seventh intelligence data stored in the first storage device based on the storage priorities of the N first intelligence data, and storing the Q sixth intelligence data in the first storage device, wherein the R seventh intelligence data are intelligence data from the N first intelligence data, and R is less than or equal to N and greater than or equal to Q.

[0012] In an exemplary embodiment, before comparing the storage priorities of N pieces of first intelligence data with the storage priorities of M pieces of second intelligence data, when the storage space of the first storage device meets the third preset storage conditions, the method further includes: for each piece of first intelligence data, calculating the storage priority of the first intelligence data in the first storage device through the following steps to obtain the storage priorities of N pieces of first intelligence data: extracting third information from the first intelligence data, wherein the third information includes data usage information and data information of the first intelligence data; and calculating the storage priority of the first intelligence data in the first storage device based on the third information.

[0013] In one exemplary embodiment, calculating the storage priority of the first intelligence data in the first storage device based on the third information includes: parsing from the third information the number of queries on the first intelligence data within a target time period, the update time of the first intelligence data updated by the first storage device, and the calculation time of the storage priority of the first intelligence data; calculating the query frequency of the first intelligence data using the number of queries; calculating the data period of the first intelligence data using the update time and the calculation time; and calculating the storage priority of the first intelligence data in the first storage device using the query frequency and the data period.

[0014] According to another embodiment of this application, an intelligence data synchronization device based on intelligence features is provided, comprising: a first determining module, configured to determine intelligence features of N first intelligence data, wherein the N first intelligence data are intelligence data stored in a first storage device and satisfy a first preset query condition, and N is a natural number greater than or equal to 1; a calculation module, configured to calculate the storage priority of M second intelligence data in a second storage device based on the intelligence features, wherein the M second intelligence data are all intelligence data stored in the second storage device, and M is a natural number greater than or equal to 1; a second determining module, configured to determine K target intelligence data to be synchronized to the first storage device from the M second intelligence data according to the storage priority of the M second intelligence data and the second preset query condition, wherein K is a natural number less than or equal to M; and a synchronization module, configured to synchronize the K target intelligence data to the first storage device.

[0015] According to yet another embodiment of this application, a computer program product is also provided, including a computer program that, when executed by a processor, implements the steps in any of the above method embodiments.

[0016] According to yet another embodiment of this application, a computer-readable storage medium is also provided, wherein a computer program is stored therein, and the computer program is configured to perform the steps in any of the above method embodiments when it is run.

[0017] According to yet another embodiment of this application, an electronic device is also provided, including a memory and a processor, wherein the memory stores a computer program and the processor is configured to run the computer program to perform the steps in any of the above method embodiments.

[0018] This application analyzes N pieces of first intelligence data stored in a first storage device to extract intelligence features. Based on these features, the storage priority of M pieces of second intelligence data in a second storage device is calculated. Then, according to the intelligence data storage priority in the second storage device and a second preset query condition, K target intelligence data are selected from the M pieces of second intelligence data as intelligence data to be synchronized. The selected K target intelligence data are then synchronized from the second storage device to the first storage device. Therefore, this solves the problem of low resource utilization in intelligence data synchronization methods in related technologies, thereby improving the utilization rate of intelligence data. Attached Figure Description

[0019] Figure 1 This is a schematic diagram of the hardware environment for a method of synchronizing intelligence data based on intelligence features according to an embodiment of this application;

[0020] Figure 2 This is a flowchart of a method for synchronizing intelligence data based on intelligence features according to an embodiment of this application;

[0021] Figure 3 This is a flowchart of a method for synchronizing threat intelligence data according to an embodiment of this application;

[0022] Figure 4 This is a structural block diagram of an intelligence data synchronization device based on intelligence features, according to an embodiment of this application. Detailed Implementation

[0023] The embodiments of this application will be described in detail below with reference to the accompanying drawings and examples.

[0024] It should be noted that the terms "first," "second," etc., in the specification, claims, and drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.

[0025] The methods and embodiments provided in this application can be executed on a server device or a similar computing device. Taking running on a server device as an example, Figure 1This is a schematic diagram of the hardware environment for a method of synchronizing intelligence data based on intelligence features, according to an embodiment of this application. Figure 1 As shown, the server device may include one or more ( Figure 1 Only one is shown in the diagram. A processor 102 (which may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.) and a memory 104 for storing data are also shown. The server device may further include a transmission device 106 for communication functions and an input / output device 108. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the server equipment described above. For example, the server equipment may also include components that are more... Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown.

[0026] The memory 104 can be used to store computer programs, such as application software programs and modules, like the computer program corresponding to a method for synchronizing intelligence data based on intelligence features in this embodiment. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, thus implementing the aforementioned method. The memory 104 may include high-speed random access memory and non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to server devices via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0027] The transmission device 106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by a communication provider for the server device. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 may be a Radio Frequency (RF) module used for wireless communication with the Internet.

[0028] This embodiment provides a method for synchronizing intelligence data based on intelligence features. Figure 2 This is a flowchart of a method for synchronizing intelligence data based on intelligence features according to an embodiment of this application, such as... Figure 2 As shown, the process includes the following steps:

[0029] Step S202: Determine the intelligence features of N first intelligence data, wherein the N first intelligence data are intelligence data stored in the first storage device and satisfy the first preset query conditions, and N is a natural number greater than or equal to 1.

[0030] Optionally, the first intelligence data in this embodiment refers to the intelligence dataset stored in the first storage device, and this data is stored after being filtered. The first intelligence data includes, but is not limited to, various forms of threat intelligence data such as malicious Internet Protocol (IP) addresses, malicious domain names, known threat patterns, advanced persistent threat (APT) intelligence, and vulnerability information.

[0031] Optionally, the first preset query condition in this embodiment refers to the conditions or criteria used to filter intelligence data in the first storage device. It can be formulated according to the user's query preferences and needs. The first preset query condition includes, but is not limited to, specific industry, geographical location or type, and importance. For example, if the user is mainly concerned with intelligence in the financial industry, then the first preset query condition may be to only consider intelligence data related to the financial industry.

[0032] Optionally, the first storage device in this embodiment includes, but is not limited to, a local server or a local storage system, which is responsible for storing and maintaining locally available intelligence data. The main advantage of a local storage device is its fast data access speed, but its storage space is limited.

[0033] Optionally, the intelligence features in this embodiment include, but are not limited to, industry relevance, geographical location relevance, importance of intelligence type, and query frequency.

[0034] Step S204: Calculate the storage priority of M second intelligence data in the second storage device based on the above intelligence features, wherein the M second intelligence data are all intelligence data stored in the second storage device, and M is a natural number greater than or equal to 1.

[0035] Optionally, the second intelligence data in this embodiment refers to intelligence data stored in a second storage device, which may contain more comprehensive and up-to-date threat intelligence information.

[0036] Optionally, the second storage device in this embodiment includes, but is not limited to, a cloud server or a remote database, responsible for storing and updating large-scale intelligence data. The advantage of cloud storage is that the data coverage is extensive and the updates are timely, but the data access speed is slower than local storage, and there may be limitations in terms of network bandwidth and security.

[0037] Optionally, the first storage device and the second storage device in this embodiment can be various types of hardware and software systems, including but not limited to local servers, cloud storage services (such as Amazon Simple Storage Service (Amazon S3), Google Cloud Storage (GCS), Microsoft Azure Storage (Azure Storage)), database systems (such as relational databases MySQL and PostgreSQL, and non-relational databases MongoDB and Cassandra), distributed file systems (such as Hadoop Distributed File System (HDFS) and Google File System (GFS)), network-attached storage, storage area networks, solid-state drives, hybrid storage systems, secure storage devices, and in-memory databases.

[0038] Step S206: According to the storage priority of the M second intelligence data and the second preset query conditions, determine K target intelligence data to be synchronized to the first storage device from the M second intelligence data, wherein K is a natural number less than or equal to M.

[0039] Optionally, the storage priority in this embodiment is calculated based on intelligence features and is used to determine the synchronization order of intelligence data. Intelligence data with higher priority will be given priority to be synchronized to the local storage device in order to improve the coverage and query efficiency of local intelligence.

[0040] Optionally, the second preset query condition in this embodiment is used to further filter out intelligence data suitable for storage in the first storage device from the second intelligence data. Similar to the first preset query condition, it focuses more on the matching degree of the characteristics and needs of the second intelligence data, such as the timeliness of the intelligence and the matching degree with common local attack characteristics.

[0041] Step S208: Synchronize the K target intelligence data to the first storage device.

[0042] Optionally, the target intelligence data in this embodiment is the second intelligence data that meets the second preset query conditions.

[0043] Through the above steps, N pieces of first intelligence data stored in the first storage device are analyzed to extract intelligence features. Then, based on these features, the storage priority of M pieces of second intelligence data in the second storage device is calculated. Next, according to the intelligence data storage priority in the second storage device and a second preset query condition, K target intelligence data are selected from the M pieces of second intelligence data as the intelligence data to be synchronized. The selected K target intelligence data are then synchronized from the second storage device to the first storage device. This solves the problem of low resource utilization in intelligence data synchronization methods in related technologies, thereby improving the utilization rate of intelligence data.

[0044] In one exemplary embodiment, determining the intelligence features of N first intelligence data includes: filtering intelligence data that satisfy the first preset query conditions from the first storage device to obtain N first intelligence data; performing data preprocessing operations on the N first intelligence data to obtain P third intelligence data, wherein the data preprocessing operations include data cleaning operations and data removal operations, and P is a natural number less than or equal to N; extracting P first information from the P third intelligence data, wherein the first information includes data information of the third intelligence data and data processing information acting on the third intelligence data; and determining the intelligence features of the P third intelligence data from the P first information to obtain the intelligence features of the N first intelligence data.

[0045] Optionally, the data preprocessing operations in this embodiment include data cleaning and data removal operations, which are used to improve data quality and remove irrelevant or invalid data in order to optimize subsequent analysis and processing.

[0046] Optionally, the data cleaning operations in this embodiment include, but are not limited to, operations involving removing duplicates, correcting erroneous data, and filling in missing values.

[0047] Optionally, the data removal operation in this embodiment includes, but is not limited to, removing intelligence data that is no longer useful or of low quality based on factors such as the timeliness and relevance of the intelligence data.

[0048] Optionally, in this embodiment, the P third intelligence data refers to the first intelligence data after preprocessing, where P represents the number of valid intelligence data retained after the preprocessing operation.

[0049] Optionally, the first information in this embodiment includes a comprehensive record of the data information of the third intelligence data and the data processing information.

[0050] Optionally, the data information in this embodiment refers to the entity information contained in the intelligence data itself, including but not limited to Internet Protocol (IP) address, malware name, intelligence type, geographical location information of the intelligence source that generated the intelligence data, and the industry or scenario in which the intelligence data can be used.

[0051] Optionally, the data processing information in this embodiment represents the operations that the intelligence data undergoes during actual use, such as query frequency.

[0052] Through the above steps, N first intelligence data that meet the first preset query conditions are selected, and data preprocessing operations are performed on the first intelligence data to obtain P third intelligence data. Data preprocessing improves the accuracy and relevance of intelligence data, reduces the burden caused by invalid or outdated data, and improves the efficiency of subsequent processing.

[0053] In one exemplary embodiment, calculating the storage priority of M second intelligence data in the second storage device based on the aforementioned intelligence features includes: for each of the aforementioned second intelligence data, calculating the storage priority in the second storage device through the following steps to obtain M storage priorities: extracting second information from the aforementioned second intelligence data, wherein the second information includes the data information of the aforementioned second intelligence data; and calculating the storage priority of the aforementioned second intelligence data in the second storage device based on the second information.

[0054] Optionally, the second information in this embodiment includes, but is not limited to, the original data information containing the second intelligence data, such as IP address, domain name, malware name, intelligence type, geographical location information of the intelligence source that generated the intelligence data, and the industry or scenario in which the intelligence data can be used.

[0055] For example, in a cybersecurity company, assuming 800 threat intelligence data entries are downloaded from the cloud (corresponding to the second storage device mentioned above), the company first extracts the raw information of each data entry, such as malicious IP addresses and domain names. Then, based on the query preferences and actual needs of local users, combined with factors such as the timeliness of the intelligence, industry relevance, and geographical location, the company calculates the storage priority of each intelligence entry locally (corresponding to the first storage device mentioned above). Ultimately, 800 storage priorities are obtained. The company can use these priorities to decide which intelligence data needs to be stored locally immediately and which data can be temporarily stored in the cloud, thereby rationally allocating local storage resources, improving query efficiency and response speed, and avoiding unnecessary storage pressure.

[0056] Through the above steps, for M pieces of second intelligence data, second information is extracted from each piece of data, and the storage priority of the second intelligence data in the second storage device is calculated based on the second information. The precise calculation of the storage priority of cloud intelligence helps to optimize the resource allocation of the first storage device and ensure that important data can be synchronized or retained with priority.

[0057] In one exemplary embodiment, calculating the storage priority of the second intelligence data in the second storage device based on the second information includes: parsing the geographical location of the intelligence source that generated the second intelligence data from the second information to obtain a first geographical location; calculating the distance between the first geographical location and the second geographical location to obtain a target distance, wherein the second geographical location is the geographical location of the intelligence source that generated the fourth intelligence data, and the fourth intelligence data has the same intelligence type as the second intelligence data; calculating the positional overlap between the first geographical location and the second geographical location according to the target distance and a preset distance threshold; and calculating the storage priority of the second intelligence data in the second storage device using a first preset weight and the positional overlap.

[0058] Optionally, in this embodiment, the first geographical location refers to the specific geographical location of the intelligence source parsed from the second intelligence data. For example, if the geographical location of the malicious IP intelligence data source is Beijing, then Beijing is the first geographical location of the malicious IP intelligence data.

[0059] Optionally, in this embodiment, the first geographical location of intelligence data i can be represented as This indicates the coordinates of the source or destination of the intelligence data. These are used to represent the dimension and longitude of intelligence data i, respectively.

[0060] Optionally, the second geographical location in this embodiment includes, but is not limited to, the geographical location of another intelligence source with the same intelligence data type, or the commonly used location of an intelligence source with the same intelligence data type (such as the location of a target source storing intelligence data with higher priority). For example, the location intelligence within the urban area of ​​Beijing is more reliable than that in remote mountainous areas. In this case, the central coordinates of the urban area of ​​Beijing are used as a commonly used area, which is determined as the second geographical location.

[0061] Optionally, the target distance in this embodiment is used to represent the geographical distance between the first geographical location and the second geographical location, including but not limited to the distance calculated using the Haversine formula.

[0062] For example, the geographical location of intelligence data i Common locations of intelligence sources for intelligence data j of the same intelligence type The geographical distance between the two locations = In this context, the geographical location of intelligence data i corresponds to the first geographical location mentioned above, and the commonly used location of the intelligence source for intelligence data of the same intelligence type corresponds to the second geographical location mentioned above. , and , Let i and j represent the latitude and longitude of intelligence data i and j, respectively, and R represent the Earth's radius.

[0063] Optionally, the preset distance threshold in this embodiment is used to determine the proximity of two geographical locations. If the target distance is less than the preset distance threshold, the two geographical locations are considered to have a high degree of overlap.

[0064] Optionally, the location overlap degree in this embodiment is the degree of similarity or overlap between two geographical locations obtained by a specific calculation method (such as Gaussian distribution kernel function) based on the target distance and a preset distance threshold.

[0065] For example, the geographical distance between the geographical locations of intelligence data i and intelligence data j is represented as... In this case, the degree of positional overlap can be calculated using a Gaussian kernel. ,in, , , Used to represent geographical location With geographical location The similarity between them The standard deviation represents the Gaussian distribution and is used to control the width of the kernel function. This indicates the number of intelligence data items that share the same intelligence type as the second intelligence data mentioned above. These are used to represent the geographical locations of intelligence data i and intelligence data j, respectively.

[0066] Optionally, the first preset weight in this embodiment It is an importance coefficient assigned to geographic location similarity when calculating the storage priority of intelligence data, which is used to reflect the proportion of geographic location factors in intelligence value.

[0067] Through the above steps, the first geographical location information of the intelligence source is parsed from the second intelligence data. Then, intelligence data of the same type as the second intelligence data is found, and its second geographical location information is extracted. The target distance between the first and second geographical locations is calculated using a geographical distance calculation method, and the degree of overlap between the first and second geographical locations is determined. This determines the storage priority of the second intelligence data in the second storage device. Geographical location analysis helps to identify which intelligence data has a higher storage priority, thus prioritizing the storage of these intelligence data and avoiding resource waste and unreasonable occupation of storage space. This makes the subsequent storage strategy of intelligence data in the first storage device more intelligent and customized, and can more accurately reflect the actual needs and value of intelligence.

[0068] In one exemplary embodiment, calculating the storage priority of the second intelligence data in the second storage device based on the second information includes: parsing the target scenario to which the second intelligence data belongs from the second information to obtain target scenario information; using the target scenario information to determine the correlation between the second intelligence data and the target scenario; and using a second preset weight and the correlation to calculate the storage priority of the second intelligence data in the second storage device.

[0069] Optionally, the target scenario in this embodiment refers to the specific environment, industry, or usage scenario involved in the intelligence data. For example, the intelligence data is related to specific industries such as the financial industry and the medical industry, and may also involve specific environments such as mobile devices and industrial control systems.

[0070] Optionally, the correlation degree in this embodiment is used to measure the closeness between the second intelligence data and the target scenario. A high correlation degree means that the intelligence data is highly relevant and important to security decisions in that scenario.

[0071] Optionally, the second preset weight in this embodiment When calculating storage priority, scene relevance is considered. The importance coefficients assigned reflect the weight of the target scenario in the intelligence value assessment, where i represents intelligence data i. Generally, the second preset weight is greater than the first preset weight.

[0072] The following example illustrates this. Suppose a cybersecurity company maintains two intelligence databases, one on-premises and one in the cloud, aiming to optimize the storage and retrieval efficiency of the on-premises database. Recently, the company has frequently received security alerts regarding financial transaction systems; therefore, the "target scenario" is defined as a security threat related to financial transaction systems. From the cloud intelligence data, a piece of intelligence data about a phishing attack is extracted (corresponding to the second intelligence data mentioned above). This intelligence data contains the malicious link used to launch the attack and the industry targeted—the financial industry. Through analysis, the system identifies this intelligence data as a security threat related to financial transaction systems (corresponding to the target scenario information mentioned above), and its correlation with this scenario is extremely high. The system presets a weight for scenario correlation (corresponding to the second preset weight mentioned above), assuming this weight is 0.4. The correlation between this intelligence and the financial transaction system is calculated, yielding a high score (assumed to be 0.9). Then, using the second preset weight of 0.4 and the high correlation score of 0.9, the storage priority of this intelligence on the local storage device is calculated to be 0.36. The company can dynamically adjust the content of its local intelligence database based on the correlation between intelligence data and specific target scenarios, ensuring that the stored threat intelligence is more aligned with the company's business needs and security strategies. This improves the local intelligence database's response speed and protection capabilities when facing threats in specific scenarios, while also making reasonable use of local storage resources and avoiding waste of storage space.

[0073] Through the above steps, the target scenario to which the second intelligence data belongs is parsed from the second information. Then, based on the extracted target scenario information, the degree of correlation between the intelligence data and the target scenario is evaluated. By combining the second preset weight with the scenario correlation, the storage priority of the intelligence data in the second storage device is calculated. The storage priority of the intelligence data can be determined according to the scenario correlation, which facilitates the dynamic adjustment of the use of storage space in the future. This ensures that the storage resources of the first storage device are used efficiently and avoids irrelevant or low-relevance intelligence occupying valuable space.

[0074] In one exemplary embodiment, calculating the storage priority of the second intelligence data in the second storage device based on the second information includes: parsing the intelligence type of the second intelligence data from the second information to obtain a target intelligence type; determining the weight of the target intelligence type among multiple preset intelligence types to obtain a target weight; and calculating the storage priority of the second intelligence data in the second storage device using a third preset weight and the target weight.

[0075] Optionally, the multiple preset intelligence types in this embodiment are a predefined series of intelligence types and the weight of each type in the storage strategy. For example, a weight list is obtained by preset weights according to the threat level of intelligence data. For example, the weight of APT type intelligence data is 0.8, the weight of malware type intelligence data is 0.7, the weight of network vulnerability type intelligence data is 0.5, and the weight of other types of intelligence data is 0.4, etc.

[0076] Optionally, the third preset weight in this embodiment It is a system-preset weight used to evaluate intelligence types. In calculating the importance coefficient for storage priority, where i represents intelligence data i, the relationship between the third preset weight, the second preset weight, and the first preset weight is typically as follows. > .

[0077] The following example illustrates this. Suppose an internet company is facing increasingly complex cybersecurity threats. To optimize the storage and retrieval efficiency of its local threat intelligence database, it decides to implement the strategy described in the aforementioned claims. The company downloads a batch of new threat intelligence data from the cloud, including intelligence records about APT group activities (corresponding to the second intelligence data mentioned above). It parses this record and determines its intelligence type as APT activity (corresponding to the target intelligence type mentioned above). Then, it consults a preset intelligence type weight table, finds the weight value corresponding to APT activity, and sets it to 0.8 (corresponding to the target weight mentioned above). Considering the importance of intelligence type in storage decisions, a third preset weight is set to 0.4. Combining the target weight of 0.8 and the third preset weight of 0.4, the storage priority of this intelligence data is determined to be 0.32. Through this intelligence type-based priority calculation method, the company can ensure that local storage space is prioritized for storing the most threatening and urgent APT intelligence, rather than being occupied by low-value or outdated intelligence. This not only optimizes the use of local storage resources but also accelerates the response speed to advanced APT threat events and improves the overall security defense level.

[0078] Optionally, the target weight, the correlation between the second intelligence data and the target scene, and the location overlap between the first geographical location and the second geographical location in the above embodiments can be used individually or in combination, depending on the actual usage. When used in combination, the sum of the corresponding weight coefficients is 1, and the corresponding values ​​need to be normalized before weighted summation. For example, when calculating the storage priority of the second intelligence data in the second storage device, the storage priority is determined by comprehensively calculating the target weight, the correlation between the second intelligence data and the target scene, and the location overlap between the first geographical location and the second geographical location, based on the actual situation of the intelligence data. That is, the storage priority of intelligence data i in the second storage device. ,in, This represents the second preset weight mentioned above. This indicates the correlation between the second intelligence data and the target scenario. This represents the aforementioned first preset weight. This indicates the degree of overlap between the first and second geographical locations. This represents the aforementioned third preset weight. This indicates the weight of the target intelligence type corresponding to the intelligence data among multiple preset intelligence types. > and + .

[0079] Through the above steps, the type of intelligence is parsed from the second information. Then, the weight value of the target intelligence type is found in the system's preset intelligence type weight list. Combined with the third preset weight, the storage priority of the second intelligence data in the second storage device is calculated. By assigning different weights to different intelligence types, it is ensured that the intelligence types that are most valuable and influential to security protection can be saved first. Storage resources can be allocated reasonably, and invalid or low-value intelligence can be avoided from occupying valuable space, thus optimizing the efficiency of storage space utilization.

[0080] In one exemplary embodiment, determining K target intelligence data to be synchronized to the first storage device from the M second intelligence data according to the storage priority of the M second intelligence data and a second preset query condition includes one of the following: when the storage space of the first storage device meets the first preset storage condition, determining the fifth intelligence data and the intelligence data whose storage priority meets the first preset storage priority from the M second intelligence data as the K target intelligence data according to the storage priority of the M second intelligence data, wherein the fifth intelligence data is incremental intelligence data in the second storage device; when the storage space of the first storage device meets the second preset storage condition, determining the intelligence data whose storage priority meets the second preset storage priority from the M second intelligence data as the K target intelligence data.

[0081] Optionally, the first preset storage condition in this embodiment is used to determine whether a large amount of data can be synchronized. It is a strategy threshold when the first storage device meets specific conditions. The first preset storage condition includes, but is not limited to, high storage capacity, low utilization rate, etc. For example, the storage space utilization rate of the first storage device is 50%.

[0082] Optionally, the second preset storage condition in this embodiment is the opposite of the first preset storage condition, which means that under the condition that the storage space of the first storage device is tight or other limitations, it is necessary to select intelligence data for synchronization more carefully, including but not limited to the storage space utilization rate of the first storage device being higher than 80%.

[0083] Optionally, the fifth intelligence data in this embodiment refers to the newly added intelligence data in the second storage device, that is, the incremental intelligence data in the second storage device.

[0084] Optionally, the first preset storage priority in this embodiment is the lowest storage priority standard for intelligence data stored in the second storage device when the storage space of the first storage device meets the first preset storage conditions, and is used to filter the data to be synchronized.

[0085] Optionally, the second preset storage priority in this embodiment is a higher priority standard for intelligence data stored in the second storage device when the storage space of the first storage device meets the second preset storage conditions, and is used to filter more critical data when storage space is tight.

[0086] Optionally, the K target intelligence data in this embodiment are intelligence datasets selected from the second storage device to be synchronized to the first storage device based on the above strategy. The number is determined by the storage conditions and priority criteria. For example, when the first preset storage conditions are met, 1,000 high-priority intelligence data may be selected for synchronization; when the second preset storage conditions are met, only 100 highest-priority intelligence data may be selected for synchronization.

[0087] The following is a specific example to illustrate this:

[0088] Suppose a cybersecurity company has two threat intelligence databases: one on-premises and one in the cloud. The company monitors that the utilization rate of its on-premises storage device (corresponding to the first storage device mentioned above) is currently 25%, meeting the first preset storage condition (e.g., below 30% utilization). New threat intelligence data (corresponding to the fifth intelligence data mentioned above) is constantly being generated in the cloud system (corresponding to the second intelligence data mentioned above), while the cloud also stores a large amount of existing intelligence data (corresponding to the second intelligence data mentioned above). According to storage priority calculations, 1500 pieces of intelligence data in the cloud have a priority higher than 70%, falling within the first preset storage priority range. This intelligence data includes recent APT group activities, newly discovered malware, and vulnerability information. Since the on-premises storage space is sufficient, the company decides to allocate these 1500 high-priority intelligence data (corresponding to the K target intelligence data mentioned above) to the cloud. The data was synchronized to local storage devices to enhance local threat detection and response capabilities. After a period of time, the utilization rate of the local storage devices rose to 85%, no longer meeting the first preset storage condition but meeting the second preset storage condition (utilization rate above 80%). At this point, there was still a large amount of intelligence data in the cloud, but local storage space was already limited. Based on the second preset storage priority (e.g., priority above 90%), 300 pieces of intelligence data in the cloud met this standard. This intelligence data included recent APT attacks against the company's industry and critical zero-day vulnerability information. Faced with storage space limitations, the company decided to synchronize only these 300 highest priority pieces of intelligence data to local storage to ensure that high-value intelligence could be quickly accessed and utilized, while avoiding unnecessary data storage and maintaining the efficient operation of the local intelligence database. Through the adjustment of the above synchronization strategy, both the high query efficiency of the local intelligence database and the excessive consumption of storage resources were ensured, reflecting the core value of intelligent threat intelligence management.

[0089] Through the above steps, K target intelligence data are determined based on storage priority according to the first or second preset storage conditions. The synchronization strategy can be flexibly adjusted according to the space status of the first storage device to ensure that high-value intelligence data can be obtained even with limited resources.

[0090] In one exemplary embodiment, synchronizing K target intelligence data to the first storage device includes: when the storage space of the first storage device meets a third preset storage condition, comparing the storage priorities of N first intelligence data with the storage priorities of M second intelligence data; determining Q sixth intelligence data from the M second intelligence data based on the comparison result, wherein Q is a natural number less than or equal to M; and when the storage space of the first storage device meets a fourth preset storage condition, deleting R seventh intelligence data stored in the first storage device based on the storage priorities of the N first intelligence data, and storing the Q sixth intelligence data in the first storage device, wherein the R seventh intelligence data are intelligence data from the N first intelligence data, and R is less than or equal to N and greater than or equal to Q.

[0091] Optionally, the third preset storage condition in this embodiment refers to the condition when the storage space of the first storage device is in a moderately available state, allowing a certain degree of information data updates without worrying too much about storage space. In actual use, the third preset storage condition can be the same as the first preset storage condition.

[0092] Optionally, the sixth intelligence data in this embodiment is intelligence data selected from the second intelligence data, which has a storage priority higher than or equal to that of the corresponding type of intelligence in the first intelligence data, and is the intelligence data intended to be stored in the first storage device.

[0093] Optionally, the fourth preset storage condition in this embodiment refers to the condition when the storage space of the first storage device reaches a high utilization rate, requiring more careful management of the storage space of the first storage device to avoid overload.

[0094] Optionally, the R seventh intelligence data in this embodiment are intelligence data with lower priority stored in the first storage device that can be deleted to free up space, such as old intelligence data that is no longer active or has low timeliness in the first storage device, or expired malicious file hash values.

[0095] Optionally, when the intelligence data is synchronized to the first storage device in this embodiment, the synchronization can be performed within a preset time period, or if it is found that the intelligence data stored in the first storage device is not the latest version or the intelligence data cannot be found in the first storage device when querying the intelligence data, the corresponding intelligence data is obtained from the second storage device to update the intelligence data in the first storage device. For example, if the eighth intelligence data cannot be found from the first storage device or the eighth intelligence data found from the first storage device is not the latest version, the first storage device sends an intelligence data retrieval instruction to the second storage device to instruct the second storage device to send the eighth intelligence data to the first storage device.

[0096] By comparing the storage priorities of N first intelligence data and M second intelligence data through the above steps, deleting R seventh intelligence data stored in the first storage device with lower priority, and synchronizing Q sixth intelligence data to the first storage device, the storage of intelligence data in the first storage device can be dynamically adjusted to ensure that the stored data is the highest priority data in the current environment, while freeing up space for new data. This realizes intelligent updating of intelligence data and improves the real-time performance and integrity of the intelligence data stored in the first storage device.

[0097] In an exemplary embodiment, before comparing the storage priorities of N pieces of first intelligence data with the storage priorities of M pieces of second intelligence data, when the storage space of the first storage device meets the third preset storage conditions, the method further includes: for each piece of first intelligence data, calculating the storage priority of the first intelligence data in the first storage device through the following steps to obtain the storage priorities of N pieces of first intelligence data: extracting third information from the first intelligence data, wherein the third information includes data usage information and data information of the first intelligence data; and calculating the storage priority of the first intelligence data in the first storage device based on the third information.

[0098] Optionally, the third information in this embodiment is specific information extracted from the first intelligence data, used to judge and calculate the use value and information value of the intelligence data, that is, data use information and data information, including but not limited to the query frequency of intelligence data, update time (the latest update time of the intelligence data and the time for calculating the storage priority of the current intelligence data), the severity of related events, and the reliability of the source of the intelligence data.

[0099] Optionally, the data usage information in this embodiment is used to describe the frequency and manner in which the first intelligence data is queried, used, or cited, reflecting the activity and importance of the intelligence data, including but not limited to the number of queries in the past month, the average daily access volume, and the number of times the intelligence data is cited by the security team.

[0100] Optionally, the data information in this embodiment refers to the content information of the intelligence data itself, such as the type, timeliness, and specific description of the intelligence, which reflects the detailed information and value of the intelligence data.

[0101] Through the above steps, the data usage information and data information of the first intelligence data are extracted. Based on the above detailed calculation of the storage priority of the first intelligence data in the first storage device, the storage strategy of the first storage device can be optimized according to the usage frequency and the data information update cycle, thereby further improving the query efficiency and resource utilization of intelligence data.

[0102] In one exemplary embodiment, calculating the storage priority of the first intelligence data in the first storage device based on the third information includes: parsing from the third information the number of queries on the first intelligence data within a target time period, the update time of the first intelligence data updated by the first storage device, and the calculation time of the storage priority of the first intelligence data; calculating the query frequency of the first intelligence data using the number of queries; calculating the data period of the first intelligence data using the update time and the calculation time; and calculating the storage priority of the first intelligence data in the first storage device using the query frequency and the data period.

[0103] Optionally, the target time period in this embodiment is a specific time window used to count the number of intelligence data queries and evaluate the timeliness of intelligence, including but not limited to a day, a week, a month, a quarter, etc.

[0104] Optionally, the number of queries in this embodiment refers to the number of times the first intelligence data is queried within the target time period, reflecting the frequency and importance of the intelligence data. For example, a certain malicious IP intelligence was queried 50 times in the previous month.

[0105] Optionally, the query frequency in this embodiment is the query rate of intelligence data calculated based on the number of queries and the target time period, representing the activity level of the intelligence data.

[0106] Optionally, in this embodiment, the query frequency of intelligence data i It can be calculated in the following way: Where N represents the target time period mentioned above. Indicates the first Number of queries per day.

[0107] Optionally, the update time in this embodiment refers to the timestamp of the most recent update of the first intelligence data by the first storage device, which is used to evaluate the timeliness and freshness of the intelligence. For example, for intelligence of a certain APT organization, the update time is one week ago, that is, update time = one week ago.

[0108] Optionally, the calculation time in this embodiment is the time point at which the system currently calculates the priority of the first intelligence data storage, and is used to calculate the data cycle.

[0109] Optionally, the data period in this embodiment is the interval between the update time and the calculation time calculated according to a preset formula, which can also be referred to as the timeliness of intelligence data, i.e., the "freshness" of intelligence.

[0110] Optionally, the data period (i.e., timeliness) in this embodiment. It can be calculated in the following way: ,in, This indicates the calculation time mentioned above. This indicates the time when the intelligence data was last updated in the first storage device.

[0111] Optionally, in this embodiment, the storage priority of the first intelligence data in the first storage device, calculated using query frequency and data period, can be obtained by first performing a normalization operation and then calculating it using a weighted average method, for example: ,in, Indicates the data period (i.e., timeliness) of intelligence data i. This indicates the frequency of queries for intelligence data i. These represent the weight coefficients corresponding to query frequency and data period, respectively. .

[0112] The following is a concrete example. Suppose a large enterprise is running an internal security threat intelligence database. This database regularly receives and updates threat intelligence data from multiple sources. The database contains intelligence on the activities of a specific APT group (corresponding to the first intelligence data mentioned above). This intelligence was queried 50 times last month (corresponding to the number of queries mentioned above), and the most recent update occurred a week ago (corresponding to the update time mentioned above). Now it is September 1, 2023, and the database is updating its storage priority (corresponding to the calculation time mentioned above). Calculating the query frequency, since the 50 queries occurred within 30 days, the average number of queries per day = 50 / 30 ≈ The query frequency is 1.67 times per day. The interval between the calculation date (September 1, 2023) and the update date (one week prior) is the data period, approximately 7 days. Based on the query frequency (1.67 times / day) and the data period (7 days), a preset algorithm calculates the storage priority of this APT intelligence. Assuming a final calculation result of 0.85, this indicates high storage value. Assuming the enterprise intelligence database is currently 80% full, meeting the fourth preset storage condition, the system decides to discard intelligence data with a storage priority lower than 0.5 to free up space. For the aforementioned APT intelligence, due to its high storage priority (0.85), even under conditions of limited storage space, the enterprise will prioritize retaining this intelligence to ensure rapid local access to critical threat information. Intelligence data with low query frequency and long data periods will be considered for archiving or deletion to save local storage space and optimize the storage efficiency and response speed of the intelligence database. Through this dynamic calculation and adjustment of storage priorities, enterprises can intelligently manage their local threat intelligence database, ensuring high quality and reliability of intelligence data, thereby improving the overall level of network security protection.

[0113] Through the above steps, the number of queries, update time, and calculation time are analyzed, and the query frequency and data cycle are calculated accordingly. Then, the storage priority is calculated using the query frequency and data cycle. By considering the activity and timeliness of intelligence data, the storage priority of intelligence data is calculated more scientifically, which effectively guides the maintenance and updating of the intelligence database and improves the overall system's response speed and accuracy.

[0114] The following is a specific example to illustrate this method. Figure 3 This is a flowchart illustrating a method for synchronizing threat intelligence data according to an embodiment of this application. Assume a financial institution is running its own cybersecurity defense system, which includes a local server (corresponding to the first storage device mentioned above) for storing and quickly accessing threat intelligence data, and a cloud server (corresponding to the second storage device mentioned above) for obtaining broader and more up-to-date threat intelligence, such as... Figure 3 As shown, the steps to synchronize the aforementioned threat intelligence data are as follows:

[0115] Step S302: Determine the intelligence characteristics of the first intelligence data: Some threat intelligence data targeting the financial industry has been stored on the local server. The system analyzes the query frequency, industry relevance, geographical location relevance, and intelligence type importance of this data to understand which intelligence data is frequently queried and which intelligence data is most valuable to the local environment, thereby obtaining intelligence characteristics.

[0116] Step S304: Calculate the storage priority of the second intelligence data stored on the cloud server based on intelligence characteristics: The cloud server stores a large amount of threat intelligence data, including multiple industries such as finance and healthcare. Based on the above intelligence characteristics, the system calculates the storage priority of each intelligence data in the cloud server. For example, intelligence data related to the financial industry, located in a hot query area of ​​the local server (such as Beijing, China), and belonging to APT or vulnerability types will be given a higher priority.

[0117] Step S306: Determine the target intelligence data based on the storage priority of cloud intelligence data and the needs of the local environment: Based on the storage priority, storage space limitations, and security priorities of cloud intelligence data, the system selects a portion of cloud intelligence data (corresponding to the above K target intelligence data) as data to be synchronized. The selection of K needs to balance local storage capacity and the coverage of intelligence data.

[0118] Step S308: Synchronize target intelligence data to the local server: Within a preset time period, a portion of selected cloud intelligence data is synchronized from the cloud to the local server to enhance the data coverage of the local intelligence database and improve query speed and response efficiency. If the storage space on the local server is insufficient, intelligence data with lower priority will be deleted according to the storage priority of the intelligence data on the local server, and then a portion of selected cloud intelligence data will be synchronized from the cloud to the local server. If the storage space on the local server is sufficient, the selected portion of cloud intelligence data will be directly synchronized from the cloud to the local server.

[0119] Through the above steps, intelligent integration of cloud and local threat intelligence is achieved, which not only ensures the immediate availability of local intelligence, but also maximizes the breadth and depth of cloud intelligence, providing financial institutions with more accurate and efficient cybersecurity protection.

[0120] It should be noted that, through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of this application.

[0121] This embodiment also provides a device for synchronizing intelligence data based on intelligence features. This device is used to implement the above embodiments and preferred embodiments, and details already described will not be repeated. As used below, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.

[0122] Figure 4 This is a structural block diagram of an intelligence data synchronization device based on intelligence features, according to an embodiment of this application. Figure 4 As shown, the device includes:

[0123] The first determining module 42 is used to determine the intelligence features of N first intelligence data, wherein the N first intelligence data are stored in the first storage device and satisfy the first preset query conditions, and N is a natural number greater than or equal to 1.

[0124] The calculation module 44 is used to calculate the storage priority of M second intelligence data in the second storage device based on the above intelligence characteristics, wherein the M second intelligence data are all intelligence data stored in the above second storage device, and M is a natural number greater than or equal to 1.

[0125] The second determining module 46 is used to determine K target intelligence data to be synchronized to the first storage device from the M second intelligence data according to the storage priority of the M second intelligence data and the second preset query conditions, wherein the K is a natural number less than or equal to the M.

[0126] The synchronization module 48 is used to synchronize the K target intelligence data to the first storage device.

[0127] In an exemplary embodiment, the first determining module 42 includes: a first filtering unit, configured to filter out intelligence data that meets the first preset query conditions from the first storage device to obtain N pieces of first intelligence data; a first execution unit, configured to perform data preprocessing operations on the N pieces of first intelligence data to obtain P pieces of third intelligence data, wherein the data preprocessing operations include data cleaning operations and data removal operations, and P is a natural number less than or equal to N; a first extraction unit, configured to extract P pieces of first information from the P pieces of third intelligence data, wherein the first information includes data information of the third intelligence data and data processing information acting on the third intelligence data; and a first determining unit, configured to determine the intelligence features of the P pieces of third intelligence data from the P pieces of first information to obtain the intelligence features of the N pieces of first intelligence data.

[0128] In one exemplary embodiment, the calculation module 44 includes: for each of the second intelligence data, calculating the storage priority in the second storage device through the following steps to obtain M storage priorities; a second extraction unit, used to extract second information from the second intelligence data, wherein the second information includes data information of the second intelligence data; and a first calculation unit, used to calculate the storage priority of the second intelligence data in the second storage device based on the second information.

[0129] In an exemplary embodiment, the calculation module 44 includes: a first parsing unit, configured to parse the geographical location of the intelligence source that generated the second intelligence data from the second information to obtain a first geographical location; a second calculation unit, configured to calculate the distance between the first geographical location and the second geographical location to obtain a target distance, wherein the second geographical location is the geographical location of the intelligence source that generated the fourth intelligence data, and the fourth intelligence data has the same intelligence type as the second intelligence data; a third calculation unit, configured to calculate the positional overlap between the first geographical location and the second geographical location according to the target distance and a preset distance threshold; and a fourth calculation unit, configured to calculate the storage priority of the second intelligence data in the second storage device using a first preset weight and the positional overlap.

[0130] In one exemplary embodiment, the calculation module 44 includes: a second parsing unit, configured to parse the target scene to which the second intelligence data belongs from the second information to obtain target scene information; a second determining unit, configured to determine the correlation between the second intelligence data and the target scene using the target scene information; and a fifth calculation unit, configured to calculate the storage priority of the second intelligence data in the second storage device using a second preset weight and the correlation.

[0131] In an exemplary embodiment, the calculation module 44 includes: a third parsing unit, configured to parse the intelligence type of the second intelligence data from the second information to obtain a target intelligence type; a third determining unit, configured to determine the weight of the target intelligence type among multiple preset intelligence types to obtain a target weight; and a sixth calculation unit, configured to calculate the storage priority of the second intelligence data in the second storage device using the third preset weight and the target weight.

[0132] In one exemplary embodiment, the second determining module 46 includes one of the following: a fourth determining unit, configured to, when the storage space of the first storage device meets the first preset storage conditions, determine the fifth intelligence data and the intelligence data whose storage priority among the M second intelligence data meets the first preset storage priority as K target intelligence data according to the storage priority of the M second intelligence data, wherein the fifth intelligence data is incremental intelligence data in the second storage device; and a fifth determining unit, configured to, when the storage space of the first storage device meets the second preset storage conditions, determine the intelligence data whose storage priority among the M second intelligence data meets the second preset storage priority as K target intelligence data.

[0133] In one exemplary embodiment, the synchronization module 48 includes: a first comparison unit, configured to compare the storage priorities of N first intelligence data and M second intelligence data respectively, provided that the storage space of the first storage device meets a third preset storage condition; a sixth determination unit, configured to determine Q sixth intelligence data from the M second intelligence data based on the comparison result, wherein Q is a natural number less than or equal to M; and a first storage unit, configured to delete R seventh intelligence data stored in the first storage device based on the storage priorities of the N first intelligence data, and store the Q sixth intelligence data in the first storage device, provided that the storage space of the first storage device meets a fourth preset storage condition, wherein the R seventh intelligence data are intelligence data among the N first intelligence data, and R is less than or equal to N and greater than or equal to Q.

[0134] In an exemplary embodiment, the synchronization module 48 includes: for each of the first intelligence data, calculating the storage priority of the first intelligence data in the first storage device through the following steps to obtain N storage priorities of the first intelligence data; a third extraction unit, used to extract third information from the first intelligence data, wherein the third information includes data usage information and data information of the first intelligence data; and a seventh calculation unit, used to calculate the storage priority of the first intelligence data in the first storage device based on the third information.

[0135] In one exemplary embodiment, the synchronization module 48 includes: a fourth parsing unit, configured to parse from the third information the number of queries on the first intelligence data within a target time period, the update time of the first intelligence data updated by the first storage device, and the calculation time of the storage priority of the first intelligence data; an eighth calculation unit, configured to calculate the query frequency of the first intelligence data using the number of queries; a ninth calculation unit, configured to calculate the data period of the first intelligence data using the update time and the calculation time; and a tenth calculation unit, configured to calculate the storage priority of the first intelligence data in the first storage device using the query frequency and the data period.

[0136] It should be noted that the above modules can be implemented by software or hardware. For the latter, they can be implemented in the following ways, but are not limited to: all the above modules are located in the same processor; or, the above modules are located in different processors in any combination.

[0137] Embodiments of this application also provide a computer-readable storage medium storing a computer program, wherein the computer program is configured to execute the steps in any of the above method embodiments when run.

[0138] In one exemplary embodiment, the aforementioned computer-readable storage medium may include, but is not limited to, various media capable of storing computer programs, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard disk, magnetic disk, or optical disk.

[0139] Embodiments of this application also provide an electronic device, including a memory and a processor, wherein the memory stores a computer program and the processor is configured to run the computer program to perform the steps in any of the above method embodiments.

[0140] In one exemplary embodiment, the electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor and the input / output device is connected to the processor.

[0141] Embodiments of this application also provide a computer program product, which includes a computer program that, when executed by a processor, implements the steps in any of the above method embodiments.

[0142] Embodiments of this application also provide another computer program product, including a non-volatile computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps in any of the above method embodiments.

[0143] The embodiments described herein also provide a computer program that includes computer instructions stored in a computer-readable storage medium; a processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the steps in any of the above method embodiments.

[0144] Specific examples in this embodiment can be found in the examples described in the above embodiments and exemplary implementations, and will not be repeated here.

[0145] Obviously, those skilled in the art should understand that the modules or steps of this application described above can be implemented using general-purpose computing devices. They can be centralized on a single computing device or distributed across a network of multiple computing devices. They can be implemented using computer-executable program code, and thus can be stored in a storage device for execution by a computing device. In some cases, the steps shown or described can be performed in a different order than those presented here, or they can be fabricated as separate integrated circuit modules, or multiple modules or steps can be fabricated as a single integrated circuit module. Thus, this application is not limited to any particular combination of hardware and software.

[0146] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the principles of this application should be included within the protection scope of this application.

Claims

1. A method for synchronizing intelligence data based on intelligence features, characterized in that, include: Determine the intelligence features of N first intelligence data, wherein the N first intelligence data are intelligence data stored in a first storage device and satisfy a first preset query condition, and N is a natural number greater than or equal to 1; Based on the intelligence features, the storage priority of M second intelligence data in the second storage device is calculated respectively, wherein the M second intelligence data are all intelligence data stored in the second storage device, and M is a natural number greater than or equal to 1; According to the storage priority of M second intelligence data and the second preset query conditions, K target intelligence data to be synchronized to the first storage device are determined from the M second intelligence data, wherein K is a natural number less than or equal to M; Synchronize the K target intelligence data to the first storage device; The method of calculating the storage priority of M second intelligence data in the second storage device based on the intelligence features includes: for each second intelligence data, calculating the storage priority in the second storage device through the following steps to obtain M storage priorities: extracting second information from the second intelligence data, wherein the second information includes the data information of the second intelligence data; and calculating the storage priority of the second intelligence data in the second storage device based on the second information. Calculating the storage priority of the second intelligence data in the second storage device based on the second information includes: parsing the geographical location of the intelligence source that generated the second intelligence data from the second information to obtain a first geographical location; calculating the distance between the first geographical location and a second geographical location to obtain a target distance, wherein the second geographical location is the geographical location of the intelligence source that generated the fourth intelligence data, and the fourth intelligence data has the same intelligence type as the second intelligence data; calculating the location overlap between the first geographical location and the second geographical location according to the target distance and a preset distance threshold; and calculating the storage priority of the second intelligence data in the second storage device using a first preset weight and the location overlap. Calculating the storage priority of the second intelligence data in the second storage device based on the second information includes: parsing the target scenario to which the second intelligence data belongs from the second information to obtain target scenario information; using the target scenario information to determine the correlation between the second intelligence data and the target scenario; and using a second preset weight and the correlation to calculate the storage priority of the second intelligence data in the second storage device. Calculating the storage priority of the second intelligence data in the second storage device based on the second information includes: parsing the intelligence type of the second intelligence data from the second information to obtain the target intelligence type; determining the weight of the target intelligence type among multiple preset intelligence types to obtain the target weight; and calculating the storage priority of the second intelligence data in the second storage device using the third preset weight and the target weight.

2. The method according to claim 1, characterized in that, Identify the intelligence characteristics of N primary intelligence data, including: The intelligence data that meets the first preset query conditions is filtered out from the first storage device to obtain N first intelligence data; Perform data preprocessing operations on N first intelligence data to obtain P third intelligence data, wherein the data preprocessing operations include data cleaning operations and data removal operations, and P is a natural number less than or equal to N; P pieces of first information are extracted from P pieces of the third intelligence data, wherein the first information includes data information of the third intelligence data and data processing information acting on the third intelligence data; From P pieces of the first information, determine P intelligence features of the third intelligence data to obtain N intelligence features of the first intelligence data.

3. The method according to claim 1, characterized in that, Based on the storage priority of the M second intelligence data and the second preset query conditions, K target intelligence data to be synchronized to the first storage device are determined from the M second intelligence data, including one of the following: When the storage space of the first storage device meets the first preset storage conditions, according to the storage priority of M second intelligence data, the fifth intelligence data and the intelligence data whose storage priority meets the first preset storage priority among the M second intelligence data are determined as K target intelligence data, wherein the fifth intelligence data is incremental intelligence data in the second storage device; If the storage space of the first storage device meets the second preset storage conditions, the intelligence data whose storage priority meets the second preset storage priority among the M second intelligence data are determined as K target intelligence data.

4. The method according to claim 1, characterized in that, Synchronizing the K target intelligence data to the first storage device includes: If the storage space of the first storage device meets the third preset storage conditions, the storage priorities of N first intelligence data and M second intelligence data are compared respectively. Based on the comparison results, Q sixth intelligence data are determined from M second intelligence data, wherein Q is a natural number less than or equal to M; When the storage space of the first storage device meets the fourth preset storage conditions, R seventh intelligence data stored in the first storage device are deleted based on the storage priority of N first intelligence data, and Q sixth intelligence data are stored in the first storage device. R seventh intelligence data are intelligence data among N first intelligence data, and R is less than or equal to N and greater than or equal to Q.

5. The method according to claim 4, characterized in that, Before comparing the storage priorities of N pieces of the first intelligence data with the storage priorities of M pieces of the second intelligence data, provided that the storage space of the first storage device meets the third preset storage conditions, the method further includes: For each piece of the first intelligence data, the storage priority of the first intelligence data in the first storage device is calculated through the following steps to obtain the storage priorities of N pieces of the first intelligence data: Extract third information from the first intelligence data, wherein the third information includes data usage information and data information of the first intelligence data; The storage priority of the first intelligence data in the first storage device is calculated based on the third information.

6. The method according to claim 5, characterized in that, Calculating the storage priority of the first intelligence data in the first storage device based on the third information includes: The third information is used to parse the number of queries on the first intelligence data within the target time period, the update time of the first storage device updating the first intelligence data, and the calculation time of the storage priority of the first intelligence data. The query frequency of the first intelligence data is calculated using the number of queries. The data period of the first intelligence data is calculated using the update time and the calculation time; The storage priority of the first intelligence data in the first storage device is calculated using the query frequency and the data period.

7. A device for synchronizing intelligence data based on intelligence features, characterized in that, include: The first determining module is used to determine the intelligence features of N first intelligence data, wherein the N first intelligence data are intelligence data stored in the first storage device and satisfy the first preset query conditions, and N is a natural number greater than or equal to 1. The calculation module is used to calculate the storage priority of M second intelligence data in the second storage device based on the intelligence features, wherein the M second intelligence data are all intelligence data stored in the second storage device, and M is a natural number greater than or equal to 1. The second determining module is used to determine K target intelligence data to be synchronized to the first storage device from the M second intelligence data according to the storage priority of the M second intelligence data and the second preset query conditions, wherein K is a natural number less than or equal to M; The synchronization module is used to synchronize the K target intelligence data to the first storage device; The calculation module is used to calculate the storage priority in the second storage device for each piece of the second intelligence data through the following steps to obtain M storage priorities, including: a second extraction unit, used to extract second information from the second intelligence data, wherein the second information includes the data information of the second intelligence data; and a first calculation unit, used to calculate the storage priority of the second intelligence data in the second storage device based on the second information. The calculation module includes: a first parsing unit, configured to parse the geographical location of the intelligence source that generated the second intelligence data from the second information to obtain a first geographical location; a second calculation unit, configured to calculate the distance between the first geographical location and the second geographical location to obtain a target distance, wherein the second geographical location is the geographical location of the intelligence source that generated the fourth intelligence data, and the fourth intelligence data has the same intelligence type as the second intelligence data; a third calculation unit, configured to calculate the positional overlap between the first geographical location and the second geographical location according to the target distance and a preset distance threshold; and a fourth calculation unit, configured to calculate the storage priority of the second intelligence data in the second storage device using a first preset weight and the positional overlap. The calculation module includes: a second parsing unit, used to parse the target scene to which the second intelligence data belongs from the second information to obtain target scene information; a second determining unit, used to determine the correlation between the second intelligence data and the target scene using the target scene information; and a fifth calculation unit, used to calculate the storage priority of the second intelligence data in the second storage device using a second preset weight and the correlation. The calculation module includes: a third parsing unit, used to parse the intelligence type of the second intelligence data from the second information to obtain the target intelligence type; a third determining unit, used to determine the weight of the target intelligence type among multiple preset intelligence types to obtain the target weight; and a sixth calculation unit, used to calculate the storage priority of the second intelligence data in the second storage device using the third preset weight and the target weight.

8. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method described in any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, wherein the computer program, when executed by a processor, implements the steps of the method described in any one of claims 1 to 6.

10. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the method described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Dark web information mining method and device, equipment and medium

    CN115603925A

  • Master device, slave device, synchronization system, control method, and program

    JP2019148872A