Network security analysis method and device and storage medium

By deeply integrating threat intelligence from multiple external channels with intelligent correlation analysis of local situations, the problem of firewalls' single integration dimension and weak correlation analysis capabilities in threat intelligence utilization is solved, achieving high-precision threat detection and adaptive defense, and providing a more insightful security situation view.

CN120675744APending Publication Date: 2025-09-19GYPSY INFORMATION CONSULTING (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510688718.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-26
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

Existing firewalls have problems in integrating and utilizing threat intelligence, such as a single integration dimension, weak correlation analysis capabilities, lack of local context awareness, and low intelligence level, resulting in a high false alarm rate and an inability to accurately assess real risks.

Method used

By acquiring and pre-processing threat intelligence data from multiple external threat intelligence platforms and combining it with real-time local data for multiple correlation analysis techniques, threat events are generated, including IoC matching, TTP behavior pattern recognition, and risk assessment, enabling intelligent correlation analysis.

Benefits of technology

It significantly improves the depth and breadth of threat intelligence utilization, improves the accuracy of threat detection, reduces false alarm rates, enhances the ability to discover unknown and advanced threats, implements risk-driven adaptive defense, and provides a more insightful view of the security situation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120675744A_ABST
    Figure CN120675744A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a network security analysis method and device and a medium. The method comprises the following steps: acquiring threat intelligence source data from a plurality of external threat intelligence platforms, and preprocessing the threat intelligence source data to obtain standard intelligence data; acquiring and formatting real-time local data; processing the standard intelligence data and the formatted real-time local data by using various correlation analysis technologies to generate a threat event; according to a risk assessment result, automatically or semi-automatically executing a corresponding defense action on the firewall; and displaying the related details of the threat event to an administrator. The method has the following advantages: 1, the threatening intelligence utilization depth and breadth are obviously improved; 2, the accuracy of threat detection is greatly improved, and false alarms are reduced; 3, the discovery capability of unknown and advanced threats is enhanced; 4, risk-driven adaptive defense is realized; and 5, a more insight security situation view is provided.
Need to check novelty before this filing date? Find Prior Art