Threat intelligence characteristic index construction method based on time dimension fusion

By constructing a time-dimensional hierarchical modeling framework and an improved dynamic time warping algorithm, dynamic threat feature indicators are generated, solving the problems of insufficient timeliness and lack of correlation of traditional threat indicators, and realizing the improvement of the timeliness and comprehensiveness of network threat detection.

CN120979708APending Publication Date: 2025-11-18GUANGXI POWER GRID CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511076344.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-01
Publication Date
2025-11-18

AI Technical Summary

Technical Problem

Traditional threat indicators based on static attributes are not timely enough, cannot capture the dynamic behavior of attackers, and lack time-dimensional correlation analysis, resulting in insufficient timeliness and comprehensiveness of network threat detection.

Method used

A time-dimensional hierarchical modeling framework is constructed, which combines a time-dimensional fusion engine and a dynamic threat indicator generation module. An improved dynamic time warping algorithm and a multi-dimensional feature fusion method are used to generate dynamic threat feature indicators. Through a time decay weight model and multi-granularity feature extraction, a dynamic and comprehensive quantitative assessment of network threats is achieved.

Benefits of technology

It improves the timeliness and comprehensiveness of network threat detection, enabling timely discovery of potential threats and rapid location of attack paths, providing more accurate threat assessment data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120979708A_ABST
    Figure CN120979708A_ABST
Patent Text Reader

Abstract

The invention discloses a threat intelligence characteristic index construction method based on time dimension fusion, and belongs to the field of network security. In order to solve the problems that traditional threat indexes are insufficient in timeliness and lack of relevance, a time dimension layered modeling framework is constructed, and dynamic threat feature indexes (TI oTV) are generated through a time decay weight model, an improved DTW-T algorithm and a multi-dimensional feature fusion formula. According to the method, threat behavior time sequence mode modeling, multi-source intelligence time alignment and feature enhancement and attack chain stage interpretability mapping are realized. Through power grid scene verification, the time sequence anomaly detection rate reaches 95%, the attack chain integrity reaches 89%, the average response time is 3 minutes, and the network threat detection accuracy and timeliness are effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to a method for constructing threat intelligence feature indicators based on time-dimensional fusion, which is used to dynamically capture the temporal characteristics of network threats, fuse multi-source intelligence and map attack chain stages, thereby improving the accuracy, timeliness and comprehensiveness of network threat detection. Background Technology

[0002] In today's digital age, the cyber threat landscape is severe and dynamically evolving. Traditional threat indicators (IoC) based on static attributes (such as IP addresses, domain names, and hash values) have significant shortcomings:

[0003] Insufficient timeliness: Attackers evade static signature detection by using Domain Name Generation Algorithms (DGAs) to generate short-lived, valid domain names and frequently rotating IP addresses. For example, botnet attacks can change thousands of IP addresses daily, rendering detection based on fixed IP addresses ineffective.

[0004] Lack of correlation: Cyberattacks are processes with a temporal sequence and logical correlation (such as initial probing, vulnerability exploitation, data theft, etc.), but traditional methods analyze individual behaviors in isolation, ignoring the correlation information in the time dimension, making it impossible to understand the attack process as a whole and difficult to prevent it in advance.

[0005] To address the aforementioned issues, it is urgent to introduce a time-dimensional fusion mechanism to construct dynamic threat characteristic indicators in order to overcome the limitations of traditional methods.

[0006] Full names of terms and abbreviations

[0007] ●IoC: Indicator of Compromise

[0008] ●DGA: Domain Generation Algorithm

[0009] ●TIoTV: Threat Intelligence over Time

[0010] Variant)

[0011] ●DTW: Dynamic Time Warping

[0012] • DTW-T: An improved dynamic time warping algorithm

[0013] -Variant)

[0014] ●NTP: Network Time Protocol

[0015] ●PTP: Precision Time Protocol

[0016] ●SCADA: Supervisory Control and Data Acquisition System

[0017] Acquisition

[0018] ●RTU: Remote Terminal Unit Summary of the Invention

[0019] This invention constructs a time-dimensional hierarchical modeling framework, integrating threat event streams, a time-dimensional fusion engine, and a dynamic threat indicator generation module. The time-dimensional fusion engine performs time slice division, multi-granularity feature extraction, and spatiotemporal correlation analysis. Combined with a time decay weight model, an improved dynamic time warping algorithm (DTW-T), and a multi-dimensional feature fusion method, it generates a dynamic threat feature indicator (TIoTV). Through data preprocessing, time slicing, feature extraction, correlation analysis, and indicator generation, it achieves dynamic and comprehensive quantitative assessment of network threats, thereby solving the problems of insufficient timeliness and lack of correlation in traditional threat indicators.

[0020] Technical solution

[0021] This invention aims to address the shortcomings of traditional static threat indicators, such as insufficient timeliness and lack of correlation. It constructs a dynamic threat signature indicator (TIoTV) by introducing a time-dimensional fusion mechanism to accurately capture the temporal patterns of threat behavior, integrate multi-source intelligence, and mine temporal correlations. This fully maps the attack chain stages, providing more accurate and interpretable threat assessment data for network security protection, improving the timeliness and comprehensiveness of threat detection, and helping to discover potential threats early and quickly locate attack paths. The specific implementation process is as follows:

[0022] 1. Time-dimension hierarchical modeling framework

[0023] In this technical solution, the time-dimensional hierarchical modeling framework is the core architecture for constructing the Dynamic Threat Signature (TIoTV) indicator. Its design aims to efficiently process and analyze network threat events, accurately extract threat features, and generate reliable dynamic threat indicators. This framework mainly consists of a threat event stream, a time-dimensional fusion engine, and a dynamic threat indicator generation module. These modules work collaboratively to form a complete processing flow.

[0024] 1.1 Threat Event Flow

[0025] The threat event stream, serving as the initial input to the entire framework, is a collection of network security-related events gathered from various network data sources. These data sources are broad in scope, including but not limited to firewall logs, intrusion detection system (IDS) alerts, system operation logs, and network traffic monitoring data. This raw threat event data continuously flows into the framework in the form of an event stream. It contains a wealth of potential threat information, but initially it is unprocessed and disorganized. For example, each network access attempt recorded in a firewall log may include information such as source IP, destination IP, port number, and access time; an intrusion detection system alert will provide detailed information such as the type of attack detected and the time of occurrence. The continuous input of the threat event stream provides a sufficient data foundation for subsequent analysis and processing.

[0026] 1.2 Time Dimension Fusion Engine

[0027] The time-dimensional fusion engine is a key processing component of the entire framework. It undertakes the important task of in-depth processing and analysis of threat event streams, and mainly includes three core functions: time slice segmentation, multi-granularity feature extraction, and spatiotemporal correlation analysis.

[0028] Time Slicing (Δt = 1 min ~ 24 h): To more effectively analyze the characteristics of threat events over time, the continuous flow of threat events needs to be divided into discrete time slices according to certain time intervals. The time slice range is set from 1 minute to 24 hours, which is determined by comprehensively considering the diversity and speed of change of network threats. For some rapidly erupting and short-duration network attacks, such as DDoS (Distributed Denial of Service) attacks, dividing the time slices into minutes can capture detailed changes in attack behavior in a timely manner; while for some long-term latent and periodically occurring threats, such as some advanced persistent threats (APT) attacks, dividing the time slices into hours or even days can help to discover their long-term activity patterns. In practical applications, the appropriate time slice granularity can be flexibly selected according to the specific network environment and threat type. For example, during e-commerce promotions with large fluctuations in network traffic, the time slice granularity for monitoring network attacks can be set to finer, such as 1-5 minutes, in order to promptly detect and respond to sudden attack events; while in a relatively stable enterprise internal network environment, the time slice granularity for monitoring regular threats can be set to the hour level.

[0029] Multi-granularity feature extraction: After dividing the time slices, features are extracted from threat event data within each time slice at multiple different granular levels. These features can be divided into micro and macro levels. Micro-level features include event frequency, which is the number of times a specific type of threat event occurs within a time slice; calculating event frequency can quickly determine the activity level of a threat. Entropy change rate measures the uncertainty and disorder of threat events within a time slice; the higher the entropy change rate, the more complex and unpredictable the changes in threat events. Macro-level features include periodic patterns; by analyzing the occurrence patterns of threat events across multiple time slices, periodic characteristics are identified, such as the activity of certain malware exhibiting a periodic pattern of occurring at fixed times each day. Trend slope describes the changing trend of threat events over a period of time—whether it is rising, falling, or remaining stable; calculating the trend slope can predict the direction of threat development in advance. For example, when analyzing network traffic data, multi-granularity feature extraction revealed that between 9:00 AM and 10:00 AM every Monday, the frequency of abnormal connection requests initiated by a specific IP address increased significantly, and the trend slope gradually increased. Combined with the high entropy change rate, it can be preliminarily determined that the IP address poses a potential threat risk.

[0030] Spatiotemporal correlation analysis: In addition to considering the temporal characteristics of threat events, it is also necessary to analyze their spatial dimensions and the correlation between spatiotemporal dimensions. The spatial dimension mainly involves the network location information of the threat event, such as the source IP address, destination IP address, and network region. Spatiotemporal correlation analysis, through the construction of complex models and algorithms, uncovers the inherent connections between threat events in different time slices and different network spatial locations. For example, if it is found that an IP address frequently communicates with multiple known malicious IP addresses in different time slices, and the communication pattern shows a certain regularity, it can be inferred that this IP address is likely also a threat. At the same time, by combining the results of time slice division and multi-granularity feature extraction, the changing trends of these spatiotemporally correlated events in the time series can be further analyzed to judge the development trend of the threat. For example, through spatiotemporal correlation analysis, it was found that the infection time of a certain malware in different regions has a certain sequence, and the infection range gradually expands over time, which provides an important basis for formulating targeted prevention measures.

[0031] 1.3 Generation of Dynamic Threat Indicators

[0032] After processing by the time-dimensional fusion engine, the time factor (T), spatial factor (S), and context factor (C) are taken as inputs and a dynamic threat indicator (TIoTV) is generated through a specific functional relationship f. The time factor (T) includes time-related information obtained from time-slice division and multi-granularity feature extraction, such as the time of event occurrence and the trend of feature changes within the time slice. The spatial factor (S) covers information related to the cyberspace location of the threat event. The context factor (C) integrates other background information related to the threat event, such as network service type and system environment configuration. The TIoTV generated through this multi-factor fusion method can comprehensively and accurately reflect the actual situation of network threats. The function f in the formula TIoTV = f(T,S,C) is a carefully designed and optimized complex calculation model. It weights and fuses the various factors according to their importance and interrelationships, ultimately outputting a quantified dynamic threat indicator value. This indicator value can intuitively reflect the degree of threat faced by the current network environment, providing a basis for decision-making for network security personnel. For example, when the TIoTV value exceeds a certain preset threshold, it indicates that the network has a high risk of threat and that corresponding security measures need to be taken in a timely manner to prevent and respond to it.

[0033] 2. Core Algorithm and Formula

[0034] 2.1 Time Decay Weight Model

[0035] In the analysis and assessment of cyber threat events, to accurately measure the importance of events occurring at different times to the current threat assessment, this invention constructs a time decay weight model, which uses an improved exponential decay function to allocate event weights, as shown in the following formula:

[0036] w(t) = e (-λ·Δτ) ×(1+log(1+N(Δτ)))

[0037] The meanings and functions of each parameter in the formula are as follows:

[0038] λ (Attenuation coefficient): This parameter controls the rate at which event weights decay over time, with a default value of 0.25. This value is not arbitrarily determined but derived from extensive experiments and in-depth analysis of real-world cases. In actual network environments, the value of the attenuation coefficient significantly impacts event weights. If the value is too small, event weights decay slowly over time, causing older events to have an excessive impact on current threat assessments, failing to accurately reflect the current threat situation. If the value is too large, event weights decay too quickly, and recent critical events may not receive due attention. Through simulation analysis of massive amounts of data under various network attack scenarios, it was found that setting the attenuation coefficient to 0.25 balances the influence of historical events with highlighting the importance of recent events in current threat assessments, achieving a relatively ideal assessment effect. For example, when analyzing malware propagation behavior, setting the attenuation coefficient to 0.25 allows the weight of early infection events to decrease reasonably over time, while the weight of recently erupted infection events is relatively higher, thus more accurately presenting the current propagation trend of malware. The optimization and analysis of the time decay weight model parameters are as follows:

[0039] (1) Parameter tuning experiment design: The grid search method was used to determine the optimal value of λ. In the experiment, the range of λ was set to [0.1, 0.4], with a step size of 0.05, i.e., experiments were conducted for λ = 0.1, 0.15, 0.2, 0.25, 0.3, 0.35, and 0.4 respectively. For each λ value, a large amount of known network threat event data was used for training and testing. During the training process, the time decay weight model was used to calculate the event weights, and the threat index value was calculated in combination with the comprehensive threat assessment formula; during the testing phase, network threat events were classified and detected based on the calculated threat index values, and the detection accuracy was used as the evaluation index. By comparing the detection accuracy under different λ values, the optimal λ value was determined. Parameter sensitivity analysis: When the λ value is small, such as λ = 0.1, the detection rate is low. This is because the event weight decays slowly over time, and past events have too much influence on the current threat assessment, causing the model to fail to reflect the current threat situation in a timely and accurate manner. As the λ value gradually increases, the detection rate gradually improves, reaching a relatively high level when λ = 0.25. However, when the λ value continues to increase to 0.35 and above, the detection rate begins to decline again. This is because the event weight decays too quickly, and recent key events do not receive due attention. Taking all factors into consideration, setting λ to 0.25 can highlight the importance of recent events in the current threat assessment while taking into account the influence of historical events, thus achieving a more ideal assessment effect.

[0040] Δτ (Time Difference Between Current Time and Event Occurrence): This parameter precisely measures the time interval from the moment the event occurred to the current assessment time. Calculating this time difference is crucial in network security monitoring because network threats are highly time-sensitive. The impact of a threat event typically changes over time. For example, during a DDoS attack, the abnormal surge in traffic in the initial short period is significant for assessing the severity and urgency of the attack; a smaller time difference in this situation assigns a higher weight to events during that period. As the attack continues or ends, the time difference gradually increases, and the weight of the corresponding event decays according to the model. By accurately calculating Δτ and applying it to the formula, the model can dynamically reflect the timeliness of the event.

[0041] N(Δτ) (count of similar events within the time window Δτ): Represents the number of times a similar threat event occurs within a time window with the current time as the endpoint and a time difference Δτ as the length. The count of similar events reflects the degree of clustering and activity of threat events. When a certain type of threat event occurs frequently within a specific time window, it indicates a strong trend of threat activity, and its importance to the current threat assessment should be increased accordingly. For example, if an IP address frequently sends abnormal connection requests to many different target IPs over a period of time, the threat level of this IP address may be underestimated if the count of similar events is not considered when calculating the weight. By introducing N(Δτ) and combining it with the logarithmic function, the weight of frequently occurring events can be effectively increased, giving them a more important position in threat assessment. The use of the logarithmic function can also avoid the excessive increase in weight due to an excessively large event count, ensuring the stability and rationality of the weight calculation.

[0042] Compared to traditional weighting methods, this time decay weighting model comprehensively considers the proximity of the event occurrence time and the frequency of similar events within a certain time range, which can more accurately reflect the actual importance of threat events and provide more reliable support for subsequent threat assessment and decision-making.

[0043] 2.2 Calculation of Time Series Correlation

[0044] In the field of network threat intelligence analysis, accurately calculating the correlation between time series is crucial for discovering potential threat patterns and predicting the development trend of attack behaviors. This invention proposes an improved algorithm based on the Dynamic Time Warping (DTW) algorithm for more accurate calculation of time series correlation, as shown in the following formula:

[0045]

[0046] The parameters in the formula are of great significance:

[0047] This section is based on the core idea of ​​the classic Dynamic Time Warping (DTW) algorithm. In network threat analysis scenarios, the time-series data we face (such as changes in network traffic over time, attack event time series, etc.) often vary in length and exhibit temporal scaling and skew. The DTW algorithm calculates the similarity between two time series by finding the optimal matching path between them. It is a local distance function used to measure the distance between corresponding points x in two time series. i and y j The distance between them. For example, when analyzing network traffic time series, It can be a distance metric based on the difference in flow rate, such as Euclidean distance, which can intuitively reflect the degree of difference in flow rate values ​​at two points in time. This is achieved by accumulating the local distances of all possible matching points and taking the minimum value. This represents the "best matching distance" between two time series when scaling and offset on the time axis are ignored. The smaller this value is, the more similar the shapes of the two time series are.

[0048] T Sim (T X ,T Y (): This is the time series similarity factor, used to further consider the similarity of time series in the time dimension. Its calculation formula is... In practical network security scenarios, simply considering the shape similarity of time series is insufficient; the correspondence between time points is equally crucial. Specifically, t... x and t y These are the times when the corresponding events occur in time series X and Y, respectively, and T. max This represents the maximum time span within the entire analysis period. For example, when analyzing the time series of a series of attack events, if two attack event sequences have similar occurrence patterns, but one sequence occurred much later than the other, their actual correlation may be low. This time series similarity factor is used to determine the maximum time span within the entire analysis period. x -t y The smaller | is, the closer the times of corresponding events in the two time series are, the better T Sim (T X ,T Y The closer the value of ) is to 1, the higher their similarity in the time dimension; conversely, when |t x -t y The larger |T Sim (T X ,T Y The closer the value of ) is to 0, the lower the similarity in the time dimension.

[0049] The significance of the overall formula: It determines the optimal matching distance based on DTW. With time series similarity factor T Sim (T X ,T Y Multiplying the two time series yields DTW-T(X,Y), which more comprehensively reflects the correlation between them. This calculation method considers both the shape similarity of the time series data and the correspondence between the times of event occurrence. Compared to the traditional DTW algorithm, it can more accurately identify the inherent connections between time series related to network threats. For example, when detecting the spread of new malware, calculating the correlation between infection time series in different regions using this improved algorithm can effectively reveal the temporal patterns and regional correlations of malware spread, providing a strong basis for timely prevention and control measures.

[0050] In the field of network threat intelligence analysis, this invention proposes the DTW-T algorithm based on the Dynamic Time Warping (DTW) algorithm to calculate the correlation degree of time series. However, this algorithm has high computational complexity, which may affect real-time performance. Therefore, the following algorithm optimization strategy is introduced:

[0051] DTW-T Approximation Based on Sliding Window: Traditional DTW-T algorithms require computation across the entire time series, resulting in significant computational overhead. The sliding window approximation method, however, selects only data within a sliding window of the time series for calculation when determining correlation. The window size is dynamically adjusted based on actual conditions. For example, when network threat events occur infrequently and data changes are relatively stable, the window size can be set larger, such as 50 time points; when frequent network threat events are detected or abnormal data fluctuations occur, the window size is reduced to 10 time points. This reduces computational overhead and improves efficiency. Furthermore, incremental computation is used during the sliding window movement. That is, when the window moves to a new time point, the calculation results from the previous window are used to update only the newly added and moved data points, avoiding redundant calculations of the entire window and further reducing computational complexity.

[0052] Distributed parallel processing: This method utilizes a distributed computing framework (such as Apache Spark) to distribute the computational tasks of the DTW-T algorithm across multiple computing nodes for parallel processing. The time-series data is divided into multiple subsets according to certain rules (such as time slices), and these subsets are sent to different computing nodes. Each computing node independently calculates the DTW-T correlation between the subsets, and finally, the results from all nodes are aggregated. This distributed parallel processing approach significantly reduces computation time and improves the real-time performance of the algorithm.

[0053] Computational Time Comparison: In a simulated network threat analysis scenario containing 1000 time series, each with 1000 time points, the computational time of the DTW-T algorithm before and after optimization was tested. The test environment was a server equipped with an 8-core CPU and 16GB of memory. The results show that the unoptimized DTW-T algorithm took an average of 300 seconds to calculate the correlation of all time series; after optimization using a sliding window-based approximation, the average time was reduced to 100 seconds; further, by combining distributed parallel processing (using 4 computing nodes), the average time was only 20 seconds. These optimization strategies and computational time comparison data demonstrate that the optimized DTW-T algorithm significantly improves computational efficiency while maintaining computational accuracy, meeting the real-time requirements of network threat intelligence analysis.

[0054] In the power grid scenario, considering the characteristics of power system data, the local distance function... Weighted Euclidean distance is used to highlight changes in key parameters such as voltage and frequency. The specific calculation method is as follows:

[0055]

[0056] in:

[0057] x i1 ,x i2 ,…,x in and y j1 ,y j2 ,…,y jn These represent the n feature values ​​of time series X and Y at corresponding times i and j, respectively. In the power grid scenario, these feature values ​​may include voltage, frequency, power, etc.

[0058] w1, w2, ..., w n These are the weighting coefficients corresponding to each feature. In the power grid scenario, voltage and frequency are key parameters affecting the stable operation of the power system, therefore they are given higher weights. For example, through the analysis of a large amount of power grid fault data and normal operation data, it was found that voltage fluctuations have a relatively greater impact on power grid security; therefore, the weight w corresponding to voltage can be... 电压 Set to 0.6, the weight w corresponding to the frequency 频率 The weight of the first parameter is set to 0.3, and the total weight of other secondary parameters (such as power factor) is set to 0.1. The logic of weight allocation is based on the degree of influence of each parameter on the safe and stable operation of the power grid; the greater the influence of a parameter, the higher its weight. This weighting method can better highlight the changes in key parameters when calculating the correlation between time series, thus more accurately reflecting the similarity and correlation between different time series.

[0059] 2.3 Comprehensive Threat Assessment

[0060] In network threat situational awareness, accurately assessing the overall threat level is crucial for timely detection of potential threats and the development of effective protection strategies. Therefore, this invention employs a multi-dimensional feature fusion formula to calculate the Dynamic Threat Feature Index (TIoTV), achieving a comprehensive quantitative assessment of network threats. The specific formula is as follows:

[0061]

[0062] Meanwhile, to ensure a reasonable weighting of features across all dimensions in the comprehensive evaluation, a coefficient constraint is set: α + γ + γ = 1, with default values ​​of α = 0.4, β = 0.3, and β = 0.3. The following is a detailed explanation of each term in the formula:

[0063] (1) This section reflects the threat contribution based on the time decay weighting model. w(t) i ) is the weight of the i-th event in the time decay weight model. This represents the cumulative weighting of time decay across a series of related threat events, reflecting the combined impact of threat events occurring at different times within a given period on the current threat assessment. The time decay weighting model considers the proximity of events and the frequency of similar events within a certain timeframe, highlighting the importance of recent and frequently occurring events. α, as a weighting coefficient, adjusts the relative importance of this dimension in the overall threat assessment. The default setting α = 0.4 means that the impact of events based on time decay weights accounts for a larger proportion of the overall threat assessment. This is because in real-world network environments, recent threat events typically better reflect the actual risks faced by the network, and assigning them higher weights makes the assessment results closer to the actual threat situation. For example, when facing a persistent network scanning attack, recent frequent scanning activities have a higher weight, and calculating this dimension can more accurately capture the urgency and severity of the attack.

[0064] (2) β·(DTW-T(X,Y)): This part is based on the time series correlation calculation results, reflecting the contribution of the similarity and correlation between different time series to the threat level. DTW-T(X,Y) is the correlation between two time series calculated based on an improved algorithm of Dynamic Time Warping (DTW). In network threat analysis, many threat behaviors exhibit certain time series patterns. By calculating the correlation between different time series (such as network traffic change sequences, attack event occurrence time series, etc.), potential threat patterns and rules can be discovered. β, as a weighting coefficient, is used to adjust the role of time series correlation in comprehensive threat assessment. The default β = 0.3, indicating that time series correlation accounts for a certain proportion in comprehensive threat assessment. For example, when a new abnormal network traffic pattern is found to have a high correlation with historically known attack traffic patterns in the time series, the calculation result of this dimension will increase accordingly, thereby improving the comprehensive threat assessment value and indicating the possible existence of similar attack threats.

[0065] (3) γ·Entropy(P): This section introduces information entropy (P) to measure the impact of the uncertainty and disorder of threat events on the overall threat level. Information entropy is an important concept in information theory. In network threat assessment, it reflects the diversity and complexity of network behavior. For example, in network traffic data, if there is a high degree of uncertainty and diversity in the source, destination, and protocol type of traffic, i.e., a high information entropy, it may mean that there are more unknown risks and potential threats in the network environment. γ, as a weighting coefficient, is used to control the importance of information entropy in the overall threat assessment. The default γ = 0.3, indicating that information entropy also plays an indispensable role in the overall threat level assessment. By considering the dimension of information entropy, we can avoid focusing only on known threat patterns and also pay attention to behaviors in the network that exhibit abnormal complexity and uncertainty, thereby providing a more comprehensive assessment of network threats.

[0066] (4) Significance of Coefficient Constraints: The constraint α+β+γ=1 ensures that the sum of the weights of each dimension's features in the comprehensive threat assessment is 1, avoiding unreasonable weight allocation. By reasonably setting the default coefficient values ​​α=0.4, β=0.3, and γ=0.3, in general network security scenarios, the contributions of the three important dimensions—time decay weight, time series correlation, and information entropy—to the comprehensive threat assessment can be balanced. Of course, in practical applications, these coefficients can be flexibly adjusted according to different network environment characteristics, threat types, and security requirements to achieve a more accurate threat assessment effect. For example, in network environments with high real-time requirements, the value of α can be appropriately increased to highlight the impact of recent events; while in scenarios with high sensitivity to abnormal behavior, the value of γ can be increased to strengthen the consideration of information entropy.

[0067] In summary, the TIoTV calculated using the multi-dimensional feature fusion formula can comprehensively consider multiple important aspects of network threats, providing more accurate and comprehensive threat assessment results for network security protection, and helping to promptly detect and respond to potential network threats.

[0068] 3. Implementation Steps

[0069] 3.1 Data Preprocessing: Timestamp alignment of the raw logs (error < 1ms)

[0070] In network threat intelligence analysis, raw log data comes from various network devices and security tools, such as firewalls, intrusion detection systems, and server logs. The timestamps recorded by these data sources may contain varying degrees of error due to factors such as hardware clock differences, system time synchronization issues, and data transmission delays. If these timestamps are not accurately aligned, subsequent time-series-based analysis will be biased, severely impacting the accuracy of the analysis results.

[0071] In the implementation steps of this invention, timestamp alignment of the original log is a crucial foundational step. By employing a high-precision time synchronization algorithm and time calibration technology, the timestamp alignment error is ensured to be controlled within 1ms. This error standard is set to guarantee the accuracy of the time difference (Δτ) calculation in the subsequent time decay weight model. In the time decay weight model w(t)=e (-λ·Δτ) In ×(1+log(1+N(Δτ))), Δτ is the difference between the current time and the time of the event. Precise timestamp alignment can minimize the calculation error of Δτ, thereby ensuring the accuracy of the event weight w(t) calculation and providing a reliable basis for subsequent threat assessment.

[0072] In its implementation, the Network Time Protocol (NTP) is used as the basic time synchronization framework, combined with hardware clock calibration technology for timestamp alignment. NTP can synchronize time with a time server over the network to obtain a high-precision standard time. Simultaneously, tailored calibration algorithms are used to fine-tune the local clock based on the characteristics of different devices' hardware clocks, eliminating drift and errors inherent in the hardware clock itself. For example, for network devices with lower clock accuracy, the deviation between their clock and the NTP server time is measured periodically, and the timestamps are corrected using linear interpolation or filtering algorithms based on the deviation value, ensuring high-precision alignment of the final timestamps.

[0073] In the implementation steps of this invention, timestamp alignment of the original logs is a crucial and fundamental step. By employing high-precision time synchronization algorithms and time calibration techniques, the timestamp alignment error is ensured to be controlled within 1ms. In real-world complex network environments, especially when heterogeneous devices (such as older industrial control equipment) are involved, the following specific implementation details are adopted to achieve sub-millisecond time synchronization:

[0074] The IEEE 1588 Precision Time Protocol (PTP) combined with hardware crystal oscillator calibration is employed: Using IEEE 1588PTP as the basic time synchronization framework, this protocol enables high-precision time synchronization with a time server over a network. For older industrial control equipment, its hardware crystal oscillators may exhibit significant clock drift and accuracy issues. To address this, a clock compensation algorithm based on the least squares method is used. First, the deviation between the older equipment's clock and the PTP server's time is measured periodically (e.g., every 10 minutes), and the deviation values ​​at multiple time points are recorded. Then, the least squares method is used to fit these deviation values, obtaining a curve model of the clock deviation changing over time. Based on this model, the clock deviation at the next moment is predicted, and the equipment's timestamp is adjusted accordingly. For example, if measurement and fitting reveal that an older industrial control equipment's clock is 5ms slow per hour, and the model predicts it will be 2.5ms slow in the next half hour, then during data acquisition, a 2.5ms compensation value is added to the equipment's timestamp in advance, thereby achieving more accurate time synchronization.

[0075] Network Time Protocol (NTP) assisted synchronization: In addition to IEEE 1588PTP, NTP is also used as an auxiliary time synchronization method. NTP can synchronize time with multiple time servers over the network to obtain high-precision standard time. For some older devices that do not support IEEE 1588PTP, NTP can serve as the primary time synchronization method. Furthermore, deploying multiple NTP servers in the network creates redundancy and improves the reliability of time synchronization. When an NTP server fails or experiences synchronization anomalies, the device can automatically switch to another available NTP server for time synchronization.

[0076] 3.2 Time Slicing: Adaptive Sliding Window

[0077] Time slicing divides continuous time-series data into multiple segments of fixed or variable length for subsequent feature extraction and analysis. This invention employs an adaptive sliding window technique for time slicing. This technique dynamically adjusts the size and position of the window based on the characteristics and changes of the data, offering greater flexibility and adaptability compared to fixed-window methods. In complex network environments, the frequency and duration of network threat events exhibit significant uncertainty. The formula for dynamically adjusting the size of the adaptive sliding window is:

[0078]

[0079] Wherein: W0 is the initial window size, set to 10 minutes in the power grid scenario (compliant with the power grid dispatch cycle), serving as the starting baseline for window adjustment. W0 can be adjusted according to different network environments or business scenarios. For example, in scenarios requiring higher network attack monitoring frequency, W0 can be appropriately reduced to more promptly capture attack behavior; while in scenarios focusing more on long-term trend analysis, W0 can be increased. λ is the attenuation coefficient, optimized to 0.3 in the power grid scenario. This parameter controls the attenuation rate of the window size as the number of abnormal events changes. A larger λ value results in a faster window size reduction as the number of abnormal events increases; conversely, a smaller λ value results in a slower window size change. Its value needs to comprehensively consider factors such as the frequency and stability of threat events in the network environment, and be determined through extensive experiments and verification with actual data. N(t) is the number of abnormal events within the current window, providing a basis for adjusting the window size by real-time statistics of the number of abnormal events occurring within the window. The definition of an abnormal event can be determined according to specific network security monitoring rules. For example, in a power grid scenario, unauthorized SCADA access and abnormal traffic in industrial control protocols can be considered abnormal events. thr As a threshold, N in the power grid scenario thr =5. When N(t) exceeds N thr When N(t) is less than N, it indicates that the current threat activity is relatively active, and the window begins to shrink according to the formula; thr The window size can be appropriately increased or kept stable according to the formula. The threshold setting needs to be combined with historical data and actual security requirements, ensuring timely detection of threat activities while avoiding excessively frequent window adjustments. Adaptive sliding window technology can automatically adjust the window size based on real-time data changes. For example, when abnormal fluctuations in network traffic are detected, statistical indicators such as the rate of change and standard deviation of traffic are calculated to determine the severity of the current data change. If the change is severe, it indicates a possible sudden threat event; in this case, the sliding window size is reduced to observe the local features of the data more closely. Conversely, if the data change is relatively stable, the window size is appropriately increased to obtain more comprehensive long-term trend information. Simultaneously, the sliding window moves along the time axis with a certain step size, which is dynamically adjusted according to data changes. During periods of rapid data change, a smaller step size is used to ensure that important information is not missed; during periods of relatively stable data, a larger step size is used to improve processing efficiency.

[0080] In the adaptive sliding window technique used for time slicing, the initial window value W0 = 10 minutes is not arbitrary, but rather incorporates knowledge from areas such as power grid dispatch cycles. In power grid systems, dispatch operations are typically performed within a certain time cycle. A 10-minute initial window value matches the power grid dispatch cycle, effectively capturing network threat events within that cycle. For example, some critical operations in the power grid, such as power adjustment and equipment switching, are often completed within a single dispatch cycle. A 10-minute window can cover potential anomalies during these operations, such as abnormal traffic in industrial control protocols or unauthorized access. If the initial window value is set too small, it may not be able to capture all relevant events in a single dispatch operation, leading to incomplete threat analysis; conversely, if the initial window value is set too large, it may include too much irrelevant information, increasing computational burden and reducing response speed to sudden threat events. Therefore, considering both the business characteristics of power grid dispatch and the needs of network threat monitoring, setting the initial window value W0 to 10 minutes is reasonable. Furthermore, this is combined with the dynamic adjustment formula of the adaptive sliding window... During power grid operation, when an abnormality in a key indicator (such as frequency deviation > 0.2 Hz) is detected, the window can be automatically reduced to 1 minute, enhancing the ability to capture attack chains and further improving the flexibility and effectiveness of window settings.

[0081] 3.3 Feature Extraction

[0082] 3.3.1 Short-term characteristics: event frequency, rate of change of entropy

[0083] (1) Event Frequency: Event frequency refers to the number of times a certain type of network threat event occurs within a specific time slice. It is an important indicator for measuring the frequency of network threat activities and directly corresponds to the count of similar events N(Δτ) in the time decay weight model. After the time slice is determined, various threat events within the time slice are classified and statistically analyzed to calculate the frequency of each type of event. For example, in the analysis of network intrusion events, the number of occurrences of different types of intrusion events (such as port scanning, brute-force attacks, etc.) within a time slice is counted. A higher event frequency usually means that the type of threat is more active in the current time and poses a greater potential risk to network security. By continuously monitoring the changing trend of event frequency, abnormal increases or decreases in threat activities can be detected in a timely manner, providing an important basis for network security early warning. At the same time, as an important component of the time decay weight model, the value of event frequency N(Δτ) directly affects the calculation result of event weight w(t), and thus affects the accuracy of comprehensive threat assessment.

[0084] (2) Entropy Change Rate: In information theory, entropy measures the degree of uncertainty or disorder in information. In network threat analysis, the entropy change rate reflects the dynamic changes in network behavior within a time slice. To calculate the entropy change rate, a probability distribution model is first constructed based on different characteristics of the network data (such as IP addresses, port numbers, protocol types, etc.), and then the information entropy formula is used. Calculate the entropy value of network behavior within each time slice. The rate of change of entropy is the ratio of the difference in entropy values ​​between adjacent time slices to the entropy value of the previous time slice. This value is used in the comprehensive threat assessment formula. The γ·Entropy(P) term quantifies the degree of disruption in the threat. A large rate of change in entropy indicates a significant change in network behavior within a short period, potentially suggesting new threat activities or anomalous behavior. For example, when a previously stable network traffic pattern suddenly introduces multiple unknown protocol types and a large number of different source IP addresses, the entropy value increases rapidly, and the rate of change in entropy also increases accordingly. This indicates an anomaly in the network environment, requiring further in-depth analysis.

[0085] 3.3.2 Long-term characteristics: cyclical patterns, trend slope

[0086] (1) Periodic Patterns: Many cyber threat behaviors exhibit certain periodic patterns. For example, some malware may conduct data theft or propagation activities at specific times of the day, or launch attacks on fixed workdays of the week. These periodic patterns can be discovered through long-term analysis of data from multiple time slices. A time series analysis method is employed, using the improved DTW-T algorithm to calculate the similarity of event sequences within different time windows, combined with a time series similarity factor. Identify recurring attack patterns. Once these patterns are identified, not only can the timing of potential threat events be predicted in advance, but network security protection strategies can also be optimized and adjusted based on these patterns. For example, if it is predicted that malware may be conducting data theft activities between 2 AM and 3 AM each day, access control and monitoring of critical data can be strengthened during that time period.

[0087] (2) Trend Slope: The trend slope describes the changing trend of network threat-related indicators over a period of time and is an important long-term characteristic for measuring the development of threats. Linear regression is performed on the time series data to calculate the rate of change of threat indicators per unit time, which is used to adjust the local distance function in DTW-T. Enhance sensitivity to trend changes. When calculating the trend slope, select a relatively long time window and perform linear regression analysis on the changes of a certain threat indicator (such as the number of attack events, the number of affected hosts, etc.) over time within the window. The slope of the resulting regression line is the trend slope. If the trend slope is positive and the value is large, it indicates that the threat indicator is on the rise, suggesting that the network threat is intensifying; conversely, if the trend slope is negative, it indicates that the threat situation has eased. For example, by calculating the trend slope of the number of hosts infected by malware over a period of time, if the slope is found to be continuously rising, this alerts network administrators to take timely measures, such as strengthening system vulnerability patching and deploying stricter access control policies, to curb the spread of malware.

[0088] 3.4 Association Analysis: Constructing a Time Dependency Graph (TDG)

[0089] Association analysis aims to uncover the inherent connections between different cyber threat events, which is achieved by constructing a Time Dependency Graph (TDG). A Time Dependency Graph is a directed graph where nodes represent cyber threat events and edges represent the temporal dependencies between events.

[0090] When constructing a Time Dependency Graph (TDG), each threat event is first added as a node to the graph based on data obtained from the time slicing and feature extraction stages. Detailed event information is labeled for each node, including event type, occurrence time, and related source and destination IP addresses. Then, the edges between nodes are determined by analyzing the temporal sequence and logical relationships between events. If event A occurs before event B, and event A may cause or influence the occurrence of event B, then a directed edge is drawn from the node of event A to the node of event B. The edge weights of the Time Dependency Graph (TDG) can be calculated based on the DTW-T(X,Y) formula to determine the correlation strength between events, combined with the local distance function in the formula.

[0091] For example, during a network attack, the attacker first performs a port scan (Event A) to obtain information about the open ports of the target host, and then uses this information to launch a vulnerability attack (Event B). In this case, a directed edge will be established in TDG from the port scan event node to the vulnerability attack event node. The weight of the edge can be calculated using the DTW-T(X,Y) algorithm to reflect the degree of correlation between the two events.

[0092] By constructing a TDG (Topology-Driven Generation), the temporal dependencies and propagation paths between network threat events can be visually displayed. Using relevant algorithms in graph theory, such as shortest path algorithms and topology sorting algorithms, TDGs can be analyzed to discover potential threat propagation chains and critical nodes. For example, the shortest path algorithm can find the shortest propagation path from the initial attack event to the event causing the greatest harm, helping security analysts quickly locate key propagation links in a threat; topology sorting can determine the chronological order of threat events, providing a basis for developing targeted defense strategies.

[0093] 3.5 Metric Generation: Output TIoTV vectors with timestamps

[0094] After completing steps such as data preprocessing, time slicing, feature extraction, and correlation analysis, the multi-dimensional feature fusion formula is applied. Calculate the Dynamic Threat Signature (TIoTV) indicator and add a precise timestamp to it to form a timestamped TIoTV vector output.

[0095] The TIoTV vector is a comprehensive quantitative representation of the current network threat status, integrating features from multiple dimensions such as time decay weight, time series correlation, and information entropy. By fusing these features with specific weights, a numerical value that comprehensively reflects the degree of network threat is obtained. The coefficient constraint α+β+γ=1 (default α=0.4, β=0.3, γ=0.3) ensures that the sum of the weights of each feature dimension in the comprehensive threat assessment is 1, avoiding unreasonable weight allocation. In typical network security scenarios, the default coefficient values ​​can balance the contributions of the three important dimensions—time decay weight, time series correlation, and information entropy—to the comprehensive threat level.

[0096] Simultaneously, a timestamp is added to TIoTV to record the calculation time of this indicator, enabling security analysts to clearly understand the changes in network threats at different points in time. The output timestamped TIoTV vector can be directly applied to network security monitoring systems and decision support systems. In network security monitoring systems, the real-time calculated TIoTV vector is compared with a preset security threshold. If the TIoTV value exceeds the threshold, the system immediately issues an alarm, indicating a high threat risk to the network. In decision support systems, by analyzing historical TIoTV vectors, the development trends and patterns of network threats can be summarized, providing data support for the formulation and adjustment of network security strategies. For example, based on the changing trend of TIoTV vectors over a period of time, the effectiveness of network security protection measures can be judged, thereby deciding whether to add new security equipment or adjust existing security strategies. Attached Figure Description

[0097] Figure 1 The flowchart of the method described in this invention illustrates the implementation process of the threat intelligence feature index construction method based on time dimension fusion. First, the data is preprocessed and timestamp aligned. Then, time slicing is performed through an adaptive sliding window. Next, short-term and long-term features are extracted. Then, a time dependency graph is constructed for correlation analysis. Finally, a TIoTV vector with timestamps is generated to achieve threat assessment and response. Detailed Implementation

[0098] The present invention will be further described below with reference to specific embodiments:

[0099] 1. Example 1

[0100] 1.1 Scene Setting

[0101] The core dispatch network of Guangxi Power Grid Company was attacked by a suspected advanced persistent threat (APT). The security team used the threat intelligence feature index construction method of this invention for real-time monitoring and analysis.

[0102] 1.2 Step 1: Data Preprocessing

[0103] (1) Data source:

[0104] Collect 8,000 cross-system event records from power grid SCADA system operation logs, substation RTU telemetry data, network traffic mirroring, and industrial control firewall alarms.

[0105] (2) Timestamp alignment:

[0106] By employing the IEEE 1588 Precision Time Protocol (PTP) combined with hardware crystal oscillator calibration, sub-millisecond synchronization is achieved with an error controlled within 0.5ms.

[0107] Example:

[0108] The SCADA system recorded the abnormal operation time of the circuit breaker as `2025-05-14 08:45:12.002`;

[0109] The voltage fluctuation time reported by the RTU device was `2025-05-1408:45:12.004`;

[0110] After calibration, the time difference is less than 0.5ms, ensuring the accuracy of timing analysis.

[0111] 1.3 Step 2: Time Slicing

[0112] (1) Adaptive sliding window:

[0113] The initial window size is set to 10 minutes (in accordance with the power grid dispatch cycle), with a step size of 2 minutes.

[0114] When a key indicator is detected to be abnormal (such as a frequency deviation > 0.2 Hz), the window automatically shrinks to 1 minute.

[0115] (2) Mathematical Connections:

[0116] Formula for dynamically adjusting window size:

[0117]

[0118] in:

[0119] W0 = 10 minutes (initial window);

[0120] λ = 0.3 (optimization coefficient for power grid scenario);

[0121] N(t) is the number of abnormal events in the current window;

[0122] N thr =5 (threshold).

[0123] Example: During the period from 08:40 to 08:50, 6 unauthorized SCADA accesses were detected. The window automatically shrunk to 1 minute to enhance the capture of the attack chain.

[0124] Step 3 of 1.4: Feature Extraction

[0125] (1) Short-term characteristics

[0126] ●Event frequency:

[0127] Calculate the frequency of abnormal traffic in the industrial control protocol every 10 minutes:

[0128] Modbus / TCP abnormal frames: 120 times / 10 minutes (threshold: <20 times);

[0129] DNP3 unauthenticated access: 80 times / 10 minutes (threshold: <10 times);

[0130] This frequency value is used as N(\Delta\tau) in the time decay weighting model.

[0131] ● Rate of change of entropy:

[0132] Calculate information entropy based on RTU device ID and data point address:

[0133]

[0134] During the attack period (08:45-08:50), the entropy value jumped from 1.8 to 3.2, with a change rate of 77.8%, triggering the alarm threshold (>50%).

[0135] (2) Long-term characteristics

[0136] • Cyclical pattern:

[0137] Using the DTW-T algorithm to analyze the load curve over a week, similar abnormal flow patterns were found during the peak electricity consumption period from 18:00 to 20:00 each day. The time series similarity factor T Sim =0.89 (threshold: 0.8).

[0138] Formula application:

[0139]

[0140] Local distance function Weighted Euclidean distance is used to highlight changes in key parameters such as voltage and frequency.

[0141] • Trend slope:

[0142] A linear regression of the RTU heartbeat response time over a continuous 72 hours yielded a slope of +0.3 ms / hour, indicating an upward trend in communication latency, which may foreshadow a network layer attack.

[0143] Step 4 of 1.5: Association Analysis

[0144] Building TDG:

[0145] Extracted events (such as protocol anomalies, data tampering, and privilege escalation) are used as nodes, and edge weights are calculated using DTW-T.

[0146] Example:

[0147] The correlation between node A (the Modbus aberration frame at 08:30) and node B (the RTU data aberration at 08:45) is DTW-T(A,B) = 0.85.

[0148] The correlation degree between node B and node C (circuit breaker malfunction at 09:00) is DTW-T(B,C) = 0.92;

[0149] By filtering with an edge weight greater than 0.8, the attack path is constructed as follows: protocol probing → data tampering → control command injection.

[0150] Step 5 of 1.6: Indicator Generation

[0151] Computing TIoTV:

[0152] Substituting into the comprehensive threat assessment formula (with power grid scenario parameters optimized to α = 0.5, β = 0.3, γ = 0.2):

[0153]

[0154] Time decay weight term: ∑w(t) i= 0.91 (Recent control events have high weight);

[0155] Relevance factor: DTW-T(X,Y) = 0.88 (high attack chain integrity);

[0156] Entropy value: Entropy(P) = 3.2 (high degree of device behavior disorder);

[0157] The final TIoTV = 0.5 × 0.91 + 0.3 × 0.88 + 0.2 × 3.2 = 1.649 (threshold: 1.2), triggering a special alarm.

[0158] 1.7 Implementation Results

[0159] Detection capability: Successfully identified covert attacks against the power grid dispatching system, providing early warnings 6 hours earlier than traditional IDS, thus avoiding potential regional power outages.

[0160] False alarm rate: Based on the power system characteristic optimization model, the false alarm rate is reduced from 12% to 1.5% compared to the traditional method.

[0161] Efficiency of response: By clearly demonstrating the attack path through TDG, the security team can quickly isolate the affected RTU devices (such as substation ID: 1035) and block the spread of the attack.

[0162] 1.8 Comparison with existing technologies

[0163]

[0164]

[0165] The embodiments of the present invention are not limited to the above description. The error threshold for timestamp alignment in data preprocessing (e.g., 1ms), the initial value W0 of the adaptive sliding window in the time slice, and the threshold N can be adjusted according to the actual network security scenario. thr The values ​​of the parameters, the statistical granularity of short-term features and the analysis period of long-term features in feature extraction, the edge weight calculation parameters of the time-dependent graph (TDG) in association analysis, and the values ​​of the decay coefficient λ of the time decay weight model and the coefficients α, β, and γ of the multi-dimensional feature fusion formula in dynamic threat index generation, all fall within the protection scope of this invention.

Claims

1. A method for constructing threat intelligence feature indicators based on time-dimensional fusion, characterized in that, include: A time-dimensional hierarchical modeling framework is constructed, which includes a threat event stream, a time-dimensional fusion engine, and a dynamic threat indicator generation module; The threat event stream is used to collect cybersecurity-related events and form an event stream input; The time-dimensional fusion engine performs time-slice division, multi-granularity feature extraction, and spatiotemporal correlation analysis on the event stream; The dynamic threat indicator generation module integrates time factors, spatial factors, and context factors to generate a dynamic threat characteristic indicator (TIoTV).

2. The method according to claim 1, characterized in that, The time interval for dividing the time slices ranges from 1 minute to 24 hours and can be flexibly adjusted according to the network environment and threat type. When network traffic fluctuates greatly, a granularity of 1-5 minutes is used, while an hourly granularity is used in a stable environment.

3. The method according to claim 1, characterized in that, The multi-granularity feature extraction includes micro-features and macro-features. Micro-features include event frequency and entropy change rate, while macro-features include periodic patterns and trend slope.

4. The method according to claim 1, characterized in that, The spatiotemporal correlation analysis is used to uncover the connections between threat events at different time slices and cyberspace locations. The spatial dimension involves location information such as source IP address, destination IP address, and network region.

5. The method according to claim 1, characterized in that, The event weights are calculated using a time decay weighting model, with the formula: w(t) = e (-λ·Δτ) ×(1+log(1+N(Δτ))), where λ is the decay coefficient, Δτ is the time difference, and N(Δτ) is the count of similar events within the time window.

6. The method according to claim 1, characterized in that, The improved Dynamic Time Warping-T algorithm (DTW-T) is used to calculate the correlation degree of time series, and the formula is as follows: The algorithm efficiency is optimized through sliding window and distributed parallel processing.

7. The method according to claim 1, characterized in that, The Dynamic Threat Signature Index (TIoTV) is calculated using a multi-dimensional feature fusion formula: Among them, α+β+γ=1, default α=0.4, β=0.3, γ=0.

3.

8. The method according to claim 1, characterized in that, It also includes the following implementation steps: Data preprocessing: Timestamp alignment of the raw logs, with the error controlled within 1ms; Time slicing: An adaptive sliding window is used to dynamically adjust the window size based on the number of abnormal events; Feature extraction: Extracting short-term features (event frequency, entropy change rate) and long-term features (periodic patterns, trend slope); Association analysis: Construct a Time Dependency Graph (TDG) to display the temporal dependencies between events; Metric generation: Outputs a TIoTV vector with timestamps.

9. A computer-readable storage medium, characterized in that, The medium stores a computer program configured to perform the steps of the threat intelligence signature construction method based on time-dimensional fusion as described in any one of claims 1-8.

10. A computer program product, characterized in that, The product includes computer-executable instructions for implementing the function of the threat intelligence feature indicator construction method based on time-dimensional fusion as described in any one of claims 1-8.