A network threat intelligence sharing method

By building a network threat intelligence sharing platform using blockchain smart contracts, the problems of difficulty in establishing trust, high risk of data leakage, and exposure of sensitive information are solved. It realizes automated and transparent information sharing and management, is highly adaptable, supports cross-industry needs, and provides efficient and secure threat intelligence sharing services.

CN120834965BActive Publication Date: 2025-11-21GUANGZHOU UNIVERSITY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511333989.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-18
Publication Date
2025-11-21
Estimated Expiration
2045-09-18

AI Technical Summary

Technical Problem

Existing network threat intelligence sharing suffers from difficulties in establishing trust, high risks of data leakage, and exposure of sensitive information. Furthermore, existing systems have limited adaptability and scalability, making it difficult to meet diverse needs across industries.

Method used

A network threat intelligence sharing platform is built using blockchain smart contracts, including user modules, threat intelligence modules, training model modules, relay modules, points modules, comment modules, incentive modules, and reputation modules. Threat intelligence information is stored in a unified format, and automated and transparent information sharing and management are achieved by utilizing the decentralization of blockchain and the distributed storage of IPFS.

Benefits of technology

It improves the efficiency of trust establishment in sharing cyber threat intelligence, reduces the risk of data leakage, enhances the transparency and adaptability of information, supports diverse needs across industries, and provides efficient and secure threat intelligence sharing and management services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120834965B_ABST
    Figure CN120834965B_ABST
Patent Text Reader

Abstract

The application provides a network threat intelligence sharing method, and relates to the technical field of network security.The method provided by the application comprises the following steps: building a blockchain smart contract, wherein the blockchain smart contract comprises a user module, a threat intelligence module, a training model module, a relay module, an integral module, a comment module, an incentive module, a reputation module and a statistical module; starting a Fabric network and an IPFS service and deploying the blockchain smart contract for subsequent use by users; and the purpose is to improve the problems of difficult trust establishment, high risk of data leakage and exposure of sensitive information in the prior art.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, and in particular to a network threat intelligence sharing method. BACKGROUND

[0002] With the rapid development of information technology, network security threat intelligence, as an important information data resource in the field of network security, plays an important role in helping enterprises understand the current security environment, identify potential threats and network security protection. With the increasingly serious situation of network security problems, the use of threat intelligence becomes particularly important. However, most of the open-source, easily accessible threat intelligence on the network has relatively low value, and the format organization is not standardized, which is not conducive to the use of enterprises in daily network security maintenance and defense activities.

[0003] Currently, network threat intelligence sharing mainly faces the following challenges: ① Difficulty in trust establishment: The quality and accuracy of information cannot be ignored. Shared intelligence may not be verified, or may contain incorrect information. If the receiving party has no ability to assess the reliability of the intelligence, these information cannot help improve the security situation, but may lead to waste of resources or incorrect defense strategies. Therefore, it is crucial to establish an effective intelligence evaluation mechanism to ensure the authenticity and effectiveness of the intelligence. ② High risk of data leakage: In traditional intelligence sharing methods, whether through email or centralized platform, there is a risk of eavesdropping or tampering of information. Especially on the centralized platform, since all data is centralized in one place, it is easy to become a target of hackers, and once a data leakage event occurs, the consequences will be very serious. ③ Exposure of sensitive information: Many organizations are reluctant to share detailed threat intelligence, fearing to leak internal details or business secrets. Existing technologies fail to provide adequate privacy protection measures, making organizations hesitant to share intelligence.

[0004] Although there have been many studies dedicated to network threat intelligence sharing, in the face of the increasing complexity of network environment and new challenges brought by technological progress, the existing solutions still have limitations: ① Traditional trust establishment processes such as identity verification, verification of information reliability, etc. Each participant needs to verify the identity of the other party and the authenticity of the intelligence, increasing the cost and security risk of communication. The lack of an automated mechanism to confirm the reliability of information sources leads to the complexity and opacity of the trust establishment process. ② Limited adaptability and scalability: Different organizations use different intelligence formats and standards, making it difficult for information to be interchanged. Existing systems are difficult to meet the diverse needs of cross-industry, limiting wider intelligence sharing and cooperation.

[0005] In summary, there is an urgent need for a network threat intelligence sharing method to improve the limitations of existing technologies. SUMMARY

[0006] The present application aims to provide a network threat intelligence sharing method, which can build a blockchain smart contract, and improve the problems of difficult trust establishment, high data leakage risk and sensitive information exposure in the prior art.

[0007] The present application provides a network threat intelligence sharing method, which comprises:

[0008] The blockchain smart contract comprises a user module, a threat intelligence module, a training model module, a relay module, an integral module, a comment module, an incentive module, a reputation module and a statistics module;

[0009] The Fabric network and the IPFS service are started, and the blockchain smart contract is deployed;

[0010] The user registers and initializes the platform management, and updates the corresponding mapping table;

[0011] Based on the threat intelligence module and the training model module, the user uploads and shares information and prices based on the incentive module; the shared information comprises unified format threat intelligence information and training model information;

[0012] The user selects to purchase the shared information priced based on the incentive module in the intelligence market;

[0013] The user comments on the shared information to obtain the comment credibility, and calculates the reputation value based on the comment credibility.

[0014] The network threat intelligence sharing method provided by the present application has the technical effects of automation, transparency, simplicity, adaptability and scalability.

[0015] Optionally, the user module is used to realize user registration, query user information and manage user list based on a transaction function; a public-private key pair encrypted based on an elliptic curve encryption algorithm is used for user registration and initialization of corresponding integral information and threat intelligence information of the user; the integral information comprises a user ID, an integral quantity and an integral source.

[0016] Optionally, the threat intelligence module is used to define and manage threat intelligence information, and build an intelligent contract platform in the field of network security; a decentralized data storage and sharing network is built based on a blockchain, and the threat intelligence information is stored in a chain in a unified STIX format; the unified format threat intelligence information is classified, and different types of attack intelligence are processed based on threat index labels.

[0017] Optionally, the training model module is used for model registration, model query, model update and model data analysis.

[0018] Register a model based on model information and a unified interface, and store model data on the IPFS, the model information including a model ID, an algorithm, and a data type; query a model based on multi-dimensional model information, the multi-dimensional model information including a model ID, a creator ID, and a model type; update a registered model, the update model operation including modifying a value of the model and modifying a demand quantity of the model; and analyze data of the model based on a paging query and a customized query strategy.

[0019] Optionally, the relay module is configured to relay a call, a transaction signature, and verification.

[0020] Optionally, the credit module is configured to register a credit, query a credit, update a credit, and analyze data of a credit.

[0021] Register a credit record based on credit information and a unified interface; query the credit information based on multi-dimensional user information, the multi-dimensional user information including a user ID, a credit source, and a credit state; update a registered credit record, the update credit operation including modifying a credit quantity, adjusting a credit validity period, and storing a credit record of a user transaction; and analyze data of the credit record based on a paging query and a customized query strategy.

[0022] Optionally, the comment module is configured to register a comment, review a comment, and query a comment.

[0023] A user submits a comment, a comment ID is generated based on a comment, a comment score, and a comment document, and is stored in a blockchain, the comment ID being composed of a universally unique identifier and a username of a comment user; a reviewer is determined based on a credit quantity of the user; and a comment is queried based on the comment ID.

[0024] Optionally, the incentive module is configured to register document incentive information, query document incentive information, and calculate an incentive.

[0025] Register document incentive information based on the shared information and a comment score, the document incentive information including an incentive condition, an incentive record, and a pricing change of the shared information; query document incentive information based on a document ID and the shared information; and calculate an incentive value of the document incentive information based on an incentive mechanism, the incentive mechanism including a credit incentive and a game mechanism.

[0026] Optionally, the reputation module is configured to register a reputation, query a reputation, update a reputation, and calculate a reputation value.

[0027] A user creates a corresponding reputation table when registering, the reputation table including a reputation value change record and a comment change on a reputation value; a table operation is performed on the reputation table, the table operation including adding data of the reputation table, modifying data of the reputation table and deleting data of the reputation table; the reputation value is calculated based on a comment credibility, a basic reputation value, a behavior compliance degree and a time decay factor, the comment credibility being constituted by a proportion of a number of favorable comments to a total number of comments; the reputation value calculation formula is as follows:

[0028] ,

[0029] Wherein, is the reputation value; is the basic reputation value; is the behavior compliance degree, the range being [0, 1]; is the comment credibility, the range being [0, 1]; is the time decay factor.

[0030] Optionally, the statistical module is used for data statistics, data query and data update; the data includes intelligence data, attack types, attack trace distribution, model data and system overview. BRIEF DESCRIPTION OF DRAWINGS

[0031] Figure 1 A flowchart of a network threat intelligence sharing method provided by the application;

[0032] Figure 2 A blockchain smart contract structure diagram of a network threat intelligence sharing method provided by the application;

[0033] Figure 3 A blockchain smart contract framework diagram of a network threat intelligence sharing method provided by the application. DETAILED DESCRIPTION

[0034] In order to make the objects, technical solutions and advantages of the embodiments of the application clearer, the technical solutions in the embodiments of the application will be described below clearly and completely. Obviously, the described embodiments are some but not all of the embodiments of the application. Based on the embodiments in the application, all other embodiments obtained by those skilled in the art without creative work fall within the scope of protection of the application. Unless otherwise defined, the technical terms or scientific terms used herein should be understood as the general meaning understood by those skilled in the art in the field of the application. The words such as "include" and similar words used herein mean that the elements or objects before the words cover the elements or objects listed after the words and their equivalents, and do not exclude other elements or objects.

[0035] ReferenceFigure 1 The application provides a network threat intelligence sharing method, comprising the following steps:

[0036] S1, a blockchain smart contract is built, and the blockchain smart contract comprises a user module, a threat intelligence module, a training model module, a relay module, an integral module, a comment module, an incentive module, a reputation module and a statistical module;

[0037] S2, a Fabric network and an IPFS service are started, and the blockchain smart contract is deployed;

[0038] S3, a user registers and initializes platform management, and updates a corresponding mapping table;

[0039] S4, based on the threat intelligence module and the training model module, a user uploads shared information and prices the shared information based on the incentive module; the shared information comprises unified format threat intelligence information and training model information;

[0040] S5, a user selects and purchases shared information priced based on the incentive module in an intelligence market;

[0041] S6, a user comments on the shared information to obtain comment credibility, and calculates a reputation value based on the comment credibility.

[0042] In some embodiments, in step S1, a blockchain smart contract design method of a network security threat intelligence sharing platform is designed (a smart contract is developed by using Go language), and the method comprises nine parts, namely a user module, a threat intelligence module, a training model module, a relay module, an integral module, a comment module, an incentive module, a reputation module and a statistical module.

[0043] Specifically, the user module: this module aims to manage and maintain user information and an integral system related to the user. The module realizes user registration, query of user information, management of a user list and other functions through a series of transaction functions, and cooperates with other contracts (such as an integral contract) to process user integral and level information. Among them, the transaction function is a function function in the chain code (smart contract) developed by Go language.

[0044] A user registers and initializes corresponding integral information and threat intelligence (CTI) shared information by using an elliptic curve encryption algorithm (ECC) encrypted public-private key pair; the user includes an intelligence provider and an ordinary user; the integral information includes a user ID, an integral quantity and an integral source.

[0045] Specifically, the threat intelligence module: this module provides an intelligent contract platform for the field of network security by defining and managing CTI information, and can handle different types of attack intelligence. Its core advantage is to provide decentralized data storage and access based on blockchain, and to ensure the credibility and transparency of intelligence by storing CTI intelligence in a unified STIX format on the chain.

[0046] The threat intelligence module provides CTI registration and management services for the blockchain network. The module can provide four major functions: ① Intelligence on-chain: by receiving and verifying intelligence data provided by users, a unique CTI ID is generated to ensure the source and legality of the intelligence. ② Intelligence storage: by serializing and storing intelligence data in the blockchain ledger, while the detailed content data of CTI is stored in IPFS. ③ Intelligence query: by providing multiple query methods (such as according to CTI ID, CTI Hash, creator ID, etc.), relevant intelligence data can be quickly retrieved. ④ Intelligence update and incentive: by dynamically updating intelligence data (such as adjusting value or demand), an incentive mechanism and continuous optimization of data are achieved.

[0047] Specifically, the training model module: this module is used to manage and register model information, and stores model information for training CTI intelligence on the chain.

[0048] The training model module provides model registration and management services for the blockchain network. The module has four core functions: ① Model registration: by receiving and processing model-related information (such as model ID, algorithm, data type, etc.), a unified interface is provided to register new models, ensuring reliable recording of model information. At the same time, the detailed content data of the model is stored in IPFS. ② Model query: supports accurate query according to model ID, creator ID, model type, etc., helping users efficiently retrieve model information and providing data support for subsequent analysis and decision-making. ③ Model update: supports updating the information of registered models, such as modifying the value and demand of the model, to ensure dynamic updating and accuracy of model data. ④ Model data analysis: supports data analysis of all models or specific model types through pagination query and customized query strategies.

[0049] Specifically, the relay module: this module is a relay module for calling other modules.

[0050] The relay module is mainly responsible for calling methods in other modules. The module has two core functions: ① Relay call: cross-contract calls are made by calling the methods of this contract. ② Transaction signature and verification: this function provides transaction signature verification and anti-replay attack mechanisms, and provides the function of cleaning expired Nonce records to avoid accumulation of invalid data.

[0051] Specifically, the integral module: this module is the core digital integral system of the entire network threat intelligence sharing, which integrates integral statistics, transaction record management and user behavior analysis.

[0052] The integral module provides integral management and transaction services for the network. The module has four core functions: ①Integral registration: by receiving and processing user's integral information (such as user ID, integral quantity, integral source, etc.), a unified interface (chain code developed in Go language and transaction function corresponding to chain code) is provided to register new integral record, to ensure accurate recording and management of integral information. ②Integral query: support accurate query according to user ID, integral source, integral state and other dimensions, help users efficiently retrieve personal integral information, and provide data support for subsequent operation and decision-making. ③Integral update: support updating the information of registered integral record, such as modifying integral quantity, adjusting integral validity period, storing user transaction integral record, etc. ④Integral data analysis: support data analysis of all integral records or specific user's integral situation through paging query and customized query strategy, wherein paging query and customized query strategy refer to query and keyword query of integral information, which is realized by chain code developed in Go language. In addition, users can obtain integral by providing intelligence and other users purchasing their intelligence.

[0053] Specifically, the comment module: this module is an intelligent module for managing comments, which is used for comment information management and comment review.

[0054] The comment module is mainly responsible for the management of comments on the blockchain. The module has three core functions: ①Comment information registration: the registration of comment information function allows users to submit comments, generates a unique comment ID based on comment content, comment score and related documents and stores it in the blockchain; among them, the related documents can be the documents storing the user's comment information; the comment ID is composed of the universally unique identifier (UUID) and the username of the comment user. ②Comment review: the review of comments function ensures that only users who meet the conditions can review comments, and administrators can approve or reject the comment status; the condition is that the user's integral quantity is greater than 1000. ③Comment query: the query of comments function queries specific comments through comment ID and returns detailed information of the comments.

[0055] Specifically, the incentive module: the module is a module for managing document incentive information on the blockchain, which supports calculating and managing the incentive value of documents according to different document types and incentive mechanisms.

[0056] The incentive module provides an incentive mechanism service for the network. The module has three core functions: ① document incentive information registration: the document incentive information registration function registers document incentive information according to the document type (such as CTI or model) and the comment score. The document incentive information includes the incentive situation, the incentive record and the pricing change of the shared information. ② document incentive information query: the document incentive information query function allows the incentive record to be queried through the document ID and the type. The incentive ID generation function creates a unique incentive ID. ③ incentive calculation: the incentive value calculation function calculates the corresponding incentive value according to different incentive mechanisms (such as point incentive and game mechanism).

[0057] Taking the use of point incentive to calculate the incentive value as an example, the formula used is as follows:

[0058] ,

[0059] wherein, is the incentive value; is the historical value, and ; is the comment score, and ; is the demand, and .

[0060] The final returned incentive value is rounded to two decimal places, and the result is as follows:

[0061] ,

[0062] Suppose, , , ; first, calculate the parameters of each part: , 20, , and finally substitute the incentive value formula to obtain , and because the finally returned incentive value is rounded to two decimal places, the final result is 18.00.

[0063] Specifically, the reputation module: this module is an intelligent module for managing user reputation.

[0064] The reputation module is responsible for managing reputation on the blockchain, and the module has four core functions: ① reputation registration: create a corresponding reputation table when each user registers. ② reputation query: this function is a comprehensive query of the information in the reputation table. ③ reputation update: update the data in the reputation table. ④ reputation value calculation: calculate the reputation value based on the comment credibility, the basic reputation value, the behavior compliance degree and the time decay factor. The comment credibility is composed of the proportion of the number of good comments to the total number of comments, and the calculation formula is as follows:

[0065] ,

[0066] in, Reputation value; The basic reputation score can be set based on factors such as the user's initial registration; for example, it can be 50 points for new users. The compliance score is in the range [0, 1]. A score close to 1 indicates a high level of compliance, while a score of 0.9 indicates a lower level of compliance. For example, a score of 0.9 indicates a user with no violations. The credibility of the review is measured in the range [0, 1], for example, the percentage of positive reviews in user interactions is 0.8. This is a time decay factor used to reflect the natural decay of reputation value over time. It can be set according to specific scenarios. For example, it is 1 for recent (e.g., within one month) and decays by 0.1 for every month exceeding one month. If the user's reputation-related behavior was 2 months ago, then this factor is 0.8.

[0067] Specifically, the statistics module: This module is used to manage and statistically analyze threat intelligence (CTI) data and related model information.

[0068] The statistics module is primarily responsible for data statistics on the blockchain. The module has three core functions: ① Data Statistics: This involves statistics on intelligence data, attack types, IOCs (Indicator of Compromise) distribution, model data, and system overview. ② Data Query: This function allows for comprehensive querying of the statistical information. ③ Data Update: This updates the statistical information when data is uploaded to the blockchain.

[0069] In some embodiments, in step S2, the Fabric network provides the underlying blockchain support, ensuring the transparency and immutability of transactions; the IPFS service is used to store and retrieve shared threat intelligence data, supporting distributed storage and efficient access to the data. This is the technological foundation for the entire system's operation. Smart contracts provide the logical execution for the entire system and must be deployed along with Fabric.

[0070] In some embodiments, in step S3, users (including intelligence providers and ordinary users) complete registration using a public-private key pair generated by an elliptic curve cryptography (ECC) algorithm. Simultaneously, the system initializes the user's points information and CTI sharing information, updating the user mapping table on the blockchain. This step achieves decentralized management of user identities and lays the foundation for subsequent points systems and reputation management.

[0071] In some embodiments, in step S4, the user uploads corresponding data information through the CTI contract and model contract, and backs it up on IPFS. The corresponding mapping table on the blockchain is updated. Upload records and other information are also stored.

[0072] In some embodiments, in step S5, users can access CTI intelligence and model information on the platform through the intelligence market, and purchase according to the pricing of the incentive mechanism. The points contract records transaction information. During the purchase process, the platform verifies the legality of the transaction through the contract, and updates the user's points and reputation information.

[0073] In some embodiments, in step S6, after purchasing information or models, users can evaluate the related content. The review information is stored through the review contract, and the platform updates the reputation value of the user according to the quality and contribution of the user's review. The review credibility will also affect the decision of the intelligence provider and other users. This process integrates multiple smart contracts, makes full use of the credibility of the blockchain and the distributed storage characteristics of IPFS, establishes a perfect threat intelligence sharing and management system, provides efficient and safe services for users, and at the same time strengthens the trust mechanism and incentive mechanism of the platform.

[0074] Reference Figure 2 The present application provides a blockchain smart contract structure diagram of a network threat intelligence sharing method, which specifically comprises:

[0075] The user (intelligence provider / ordinary user) initiates a request to interact with the system, such as registration and other operations;

[0076] The platform party audits the review contract and participates in system management;

[0077] The user contract performs user registration, purchases CTI models, and adds comments, and also initializes user reputation;

[0078] The model contract involves information storage, incentive calculation pricing, and is used for managing and registering model information operations;

[0079] The CTI contract stores information to IPFS and calculates incentive pricing;

[0080] The incentive contract receives incentive calculation pricing related information from the model contract and the CIT contract, and completes information chaining, information query, and information update operations;

[0081] The points contract will count the points according to the purchased CTI or model, and update the points information and store the transaction record;

[0082] The review contract will calculate the review credibility according to the user's added review, and store the information to the Fabric network;

[0083] The reputation contract is used to manage user reputation, receives the result of review credibility calculation, and stores the reputation information to the Fabric network;

[0084] The relay contract receives the request of a user (intelligence provider / ordinary user), participates in the registration process, and realizes cross-contract calling;

[0085] The statistics contract obtains statistical data from the Fabric network, and is used for managing and statistically analyzing threat intelligence (CTI) data and related model information;

[0086] The Fabric is used for storing reputation information, transaction records, credit information, comment information, and obtaining statistical data, so as to guarantee the decentralization and non-tamperability of data;

[0087] The IPFS is an interstellar file system, and is used for storing CTI information and model information, and realizing efficient distributed storage.

[0088] Reference Figure 3 The blockchain smart contract framework of the network threat intelligence sharing method provided by the application comprises:

[0089] The user module is used for user registration, key generation, and credit level;

[0090] The threat intelligence module is used for uploading, storing, backing up, and querying threat intelligence;

[0091] The training model module is used for uploading, storing, backing up, and querying a training model;

[0092] The relay module is used for cross-contract calling and signature verification;

[0093] The credit module is used for threat intelligence purchase, training model purchase, and transaction record query and storage;

[0094] The comment module is used for storing, querying, and auditing comment information;

[0095] The incentive module is used for storing, calculating, and querying incentive information;

[0096] The reputation module is used for user reputation calculation, comment credibility calculation, reputation information storage, and reputation information query;

[0097] The statistics module is used for threat intelligence statistics, training model statistics, on-chain data query, and statistical data update.

[0098] Although the embodiments of the application are described in detail above, it is obvious for those skilled in the art that various modifications and changes can be made to the embodiments. However, it should be understood that such modifications and changes all belong to the scope and spirit of the application described in the claims. Moreover, the application described herein can have other embodiments, and can be implemented or realized in various ways.

Claims

1. A method for sharing network threat intelligence, characterized in that, Includes the following steps: A blockchain smart contract is constructed, which includes: a user module, a threat intelligence module, a training model module, a relay module, an points module, a comment module, an incentive module, a reputation module, and a statistics module; Start the Fabric network and IPFS service and deploy the blockchain smart contract; User registration and platform management initialization are completed, and the corresponding mapping table is updated. Based on the threat intelligence module and the training model module, users upload shared information and are priced based on the incentive module; the shared information includes unified format threat intelligence information and training model information. Users can choose to purchase shared information in the intelligence market based on the pricing of the incentive module; Users comment on the shared information to obtain comment credibility, and a reputation value is calculated based on comment credibility, basic reputation value, behavioral compliance, and time decay factor.

2. The sharing method according to claim 1, characterized in that, The user module is used to implement user registration, query user information, and manage user lists based on transaction functions; based on the public-private key pair encrypted by the elliptic curve cryptography algorithm, users register and initialize the corresponding user's points information and threat intelligence information; the points information includes user ID, points quantity, and points source.

3. The sharing method according to claim 1, characterized in that, The threat intelligence module is used to build a smart contract platform in the field of cybersecurity by defining and managing threat intelligence information; to build a decentralized data storage and sharing network based on blockchain, and to store threat intelligence information on the chain in a unified STIX format; to classify the unified format threat intelligence information and process different types of attack intelligence based on threat indicator tags.

4. The sharing method according to claim 1, characterized in that, The training model module is used for model registration, model query, model update, and model data analysis. Models are registered based on model information and a unified interface, and the model data is stored on IPFS. The model information includes model ID, algorithm, and data type. Model query is performed based on multi-dimensional model information, which includes model ID, creator ID, and model type. The registered models are updated, including modifying the model's value and the required amount of data to be updated; data analysis is performed on the models based on paginated queries and customized query strategies.

5. The sharing method according to claim 1, characterized in that, The relay module is used for relay calls, transaction signing, and verification.

6. The sharing method according to claim 2, characterized in that, The points module is used for points registration, points query, points update, and points data analysis; Register points records based on points information and a unified interface; The points information is queried based on multi-dimensional user information, which includes user ID, points source, and points status. The system updates the points records of registered users, including modifying the number of points, adjusting the validity period of points, and storing the points records of user transactions. Data analysis is performed on the points records based on pagination query and customized query strategies.

7. The sharing method according to claim 2, characterized in that, The comment module is used for comment registration, comment review, and comment query. Users submit comments, and a comment ID is generated based on the comment, comment rating, and comment document and stored in the blockchain. The comment ID consists of a universally unique identifier and the commenter's username. The reviewer is determined based on the user's points. Comments are queried based on the comment ID.

8. The sharing method according to claim 1, characterized in that, The incentive module is used for document incentive information registration, document incentive information query, and incentive calculation. Register document incentive information based on the shared information and review ratings, the document incentive information including the incentive status, incentive records and pricing changes of the shared information; query document incentive information based on document ID and the shared information; The incentive value of the document incentive information is calculated based on an incentive mechanism, which includes an incentive mechanism for points and a game mechanism.

9. The sharing method according to claim 1, characterized in that, The reputation module is used for reputation registration, reputation query, reputation update and reputation value calculation; When a user registers, a corresponding reputation table is created. The reputation table includes records of reputation value changes and how comments affect the reputation value. The reputation table is updated by operations including adding data, modifying data, and deleting data. The reputation score is calculated based on review credibility, basic reputation value, behavioral compliance, and time decay factor. The review credibility is determined by the proportion of positive reviews to the total number of reviews. The formula for calculating the reputation score is as follows: , in, The reputation value; The basic reputation value; The compliance level of the behavior is defined in the range [0, 1]. The credibility of the comment is defined in the range [0, 1]. is the time decay factor.

10. The sharing method according to claim 1, characterized in that, The statistics module is used for data statistics, data query, and data update; the data includes intelligence data, attack types, attack trace distribution, model data, and system overview.

Citation Information

Patent Citations

  • Blockchain-based threat intelligence discrimination method, system and device, and medium

    CN113051306A

  • Information data verifiability security sharing method and system based on block chain and federal learning

    CN114338045A