Threat intelligence acquisition method and related device

By analyzing encrypted instant messaging tool groups using pre-trained threat discrimination models and large language models, high-value groups are screened and threat intelligence is generated. This solves the problems of high cost and poor adaptability of manual intervention in existing technologies, and achieves efficient and stable threat intelligence acquisition.

CN121585633APending Publication Date: 2026-02-27BEIJING UNIV OF POSTS & TELECOMM
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511625855.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-07
Publication Date
2026-02-27

AI Technical Summary

Technical Problem

Existing technologies for processing threat intelligence in encrypted instant messaging groups suffer from high costs of manual intervention, poor adaptability, and difficulty in dealing with new types of threat intelligence.

Method used

A pre-trained threat discrimination model is used to screen high-value groups, a large language model is used to analyze communication content, generate dialogue targets and obtain threat intelligence, and a multi-level analysis and evaluation process is used to ensure the rationality and stability of the dialogue content.

Benefits of technology

It reduces human intervention, improves adaptability to different topic groups, generates more universal dialogue strategies, ensures the rationality and stability of dialogue content, and improves the efficiency of threat intelligence acquisition.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121585633A_ABST
    Figure CN121585633A_ABST
Patent Text Reader

Abstract

The invention provides a threat intelligence acquisition method and a related device, and the method comprises the steps: screening encrypted instant messaging tool groups based on a pre-trained threat discrimination model, and obtaining high-value groups with threats; analyzing the communication content of the high-value group to obtain a high-value dialogue target; dialogue generation is carried out based on the high-value dialogue target, and threat intelligence dialogue content is obtained; and performing intelligence acquisition on the high-value dialogue target based on the threat intelligence dialogue content to obtain high-value intelligence information. According to the invention, a more universal dialogue strategy can be generated, manual intervention is reduced, adaptability to different theme groups is improved, and rationality and stability of dialogue content are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of network security, and in particular, to a threat intelligence acquisition method and related device. BACKGROUND

[0002] This section is intended to provide background or context to the embodiments of the disclosure recited in the claims. The description herein does not constitute admission that the prior art is prior art nor does it constitute an admission of any description in this section as prior art to an application.

[0003] An encrypted instant messaging tool refers to an instant messaging software that uses technical means to encrypt communication content, always keeps the encrypted content in the transmission process, and only the designated recipient can decrypt it. Currently, some traditional methods for monitoring illegal activities using instant messaging software rely on parsing and restoring the clear text chat message data stream in network traffic to reconstruct historical chat records. However, these methods are no longer applicable to encrypted instant messaging tools that only have encrypted content during communication. In order to monitor illegal activities on such platforms, a robot account needs to be added to the encrypted instant messaging group to continuously monitor and extract and analyze using pre-defined rules and pre-trained natural language processing discriminant models.

[0004] However, in the related art, there are problems of high cost of manual intervention, poor adaptability and difficulty in dealing with new threat intelligence when dealing with potential threat intelligence in encrypted instant messaging groups. SUMMARY

[0005] Therefore, the purpose of the present disclosure is to provide a threat intelligence acquisition method and related device, which at least partially solves one of the technical problems in the related art.

[0006] To achieve the above purpose, in a first aspect, an embodiment of the present disclosure provides a threat intelligence acquisition method, which comprises: screening an encrypted instant messaging tool group based on a pre-trained threat discrimination model to obtain a high-value group with threats; analyzing the communication content of the high-value group to obtain a high-value dialogue target; generating a dialogue based on the high-value dialogue target to obtain threat intelligence dialogue content; acquiring intelligence based on the threat intelligence dialogue content to obtain high-value intelligence information.

[0007] Based on the same inventive concept, in a second aspect, an embodiment of the present disclosure provides a threat intelligence acquisition device, which comprises: a high-value group determination module configured to screen an encrypted instant messaging tool group based on a pre-trained threat discrimination model to obtain a high-value group with threats; The dialogue target determination module is configured to analyze the communication content of the high-value group to obtain a high-value dialogue target; The dialogue content determination module is configured to generate a dialogue based on the high-value dialogue target to obtain threat intelligence dialogue content; The intelligence information determination module is configured to obtain intelligence based on the threat intelligence dialogue content of the high-value dialogue target to obtain high-value intelligence information.

[0008] Based on the same inventive concept, a third aspect of the example embodiments of the present disclosure provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor executes the program to realize the method of the first aspect.

[0009] Based on the same inventive concept, a fourth aspect of the example embodiments of the present disclosure provides a non-transitory computer-readable storage medium, which stores computer instructions for causing a computer to execute the method of the first aspect.

[0010] Based on the same inventive concept, a fifth aspect of the example embodiments of the present disclosure provides a computer program product, including computer program instructions, which, when executed on a computer, cause the computer to execute the method of the first aspect.

[0011] As can be seen from the above, the threat intelligence obtaining method and related device provided by the embodiments of the present disclosure, the method includes: Based on the pre-trained threat discrimination model, the encrypted instant messaging tool group is screened to obtain a high-value group with threats; the communication content of the high-value group is analyzed to obtain a high-value dialogue target; a dialogue is generated based on the high-value dialogue target to obtain threat intelligence dialogue content; intelligence is obtained based on the threat intelligence dialogue content of the high-value dialogue target to obtain high-value intelligence information. The present disclosure can generate more general dialogue strategies, reduce manual intervention, improve adaptability to different theme groups, and ensure the rationality and stability of the dialogue content. BRIEF DESCRIPTION OF DRAWINGS

[0012] In order to more clearly illustrate the technical solutions in the present disclosure or the related art, the following will briefly introduce the drawings needed to be used in the embodiments or related art description. Obviously, the drawings in the following description are only examples of the present disclosure, and other drawings can be obtained by those skilled in the art without creative labor based on these drawings.

[0013] Figure 1An application scenario diagram of the threat intelligence acquisition method provided for the exemplary embodiments of the present disclosure is shown in FIG. 1. Figure 2 A flow diagram of the threat intelligence acquisition method provided for the exemplary embodiments of the present disclosure is shown in FIG. 2. Figure 3 A dialogue strategy diagram of the threat intelligence acquisition method provided for the exemplary embodiments of the present disclosure is shown in FIG. 3. Figure 4 A structure diagram of the threat intelligence acquisition apparatus provided for the exemplary embodiments of the present disclosure is shown in FIG. 4. Figure 5 An electronic device hardware structure diagram provided for the exemplary embodiments of the present disclosure is shown in FIG. 5. DETAILED DESCRIPTION

[0014] It can be understood that, before using the technical solutions disclosed in the embodiments of the present application, the type, use range, use scenario, etc. of the personal information involved in the present application should be informed to the user and the authorization of the user should be obtained in a proper manner according to relevant laws and regulations.

[0015] For example, in response to receiving the active request of the user, prompt information is sent to the user to explicitly prompt the user that the operation requested to be performed will require the acquisition and use of the personal information of the user. Thus, the user can voluntarily choose whether to provide the personal information to the electronic device, application program, server or storage medium, etc. software or hardware performing the operation of the technical solutions of the present application according to the prompt information.

[0016] As an optional but non-limiting implementation manner, in response to receiving the active request of the user, the manner of sending the prompt information to the user may, for example, be the manner of a pop-up window, in which the prompt information can be presented in the form of text. In addition, the pop-up window can also carry selection controls for the user to select "agree" or "disagree" to provide the personal information to the electronic device.

[0017] It can be understood that the above notification and user authorization process is only illustrative and does not limit the implementation manner of the present application, and other manners meeting the relevant laws and regulations can also be applied to the implementation manner of the present application.

[0018] It can be understood that the data (including but not limited to the data itself, the acquisition or use of the data) involved in the present technical solutions should comply with the requirements of the relevant laws and regulations and relevant provisions.

[0019] To make the objectives, technical solutions and advantages of the present disclosure clearer, the principles and spirits of the present disclosure will be described below with reference to several exemplary embodiments. It should be understood that the embodiments are only given to enable those skilled in the art to better understand and implement the present disclosure, and do not limit the scope of the present disclosure in any way. On the contrary, the embodiments are provided to make the present disclosure more thorough and complete, and to enable the scope of the present disclosure to be fully conveyed to those skilled in the art.

[0020] In this document, it should be understood that any quantity of elements in the accompanying drawings are used for illustration only, not limitation, and any naming is only for distinction, not any limiting meaning.

[0021] It should be noted that, unless otherwise defined, the technical terms or scientific terms used in the embodiments of the present disclosure should be understood as the common meanings understood by those skilled in the art to which the embodiments of the present disclosure belong. The terms "first", "second" and similar terms used in the embodiments of the present disclosure do not represent any order, number or importance, but are only used to distinguish different components. The terms "include" or "contain" and similar terms mean that the elements or objects before the terms encompass the elements or objects listed after the terms and their equivalents, without excluding other elements or objects. The terms "connect" or "connected" and similar terms are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. The terms "upper", "lower", "left", "right" and the like only represent relative positional relationships, and when the absolute positions of the described objects are changed, the relative positional relationships can also be changed accordingly. The article "a" or "an" before an element does not exclude the existence of multiple such elements.

[0022] The principles and spirits of the present disclosure will be described in detail below with reference to several representative embodiments of the present disclosure.

[0023] As described in the background, in the related art, there are problems of high cost of manual intervention, poor adaptability and difficulty in coping with new threat intelligence when processing potential threat intelligence in encrypted instant messaging groups. Specifically, an encrypted instant messaging tool refers to an instant messaging software that uses technical means to encrypt communication content, always in ciphertext during transmission, and only the designated recipient can decrypt it. These end-to-end encrypted instant messaging tools bring convenience to online communication while ensuring the security of communication based on cryptographic protocols, effectively protecting user privacy. However, due to its high security and anonymity, encrypted instant messaging tools have also been used by some criminals to provide cover for illegal activities. Research by network security company IntSights shows that some dark web black market vendors have shifted their business to social media platforms such as Telegram encrypted chat rooms, and end-to-end encrypted instant messaging software such as Telegram and WhatsApp has also been used to create underground forums on specific topics. Therefore, it is of great significance to the social security and stability to discover illegal activities from encrypted instant messaging platform groups and obtain information related to the activities.

[0024] Currently, some traditional methods of monitoring the use of instant messaging software by criminals rely on parsing and restoring plaintext chat message data streams in network traffic, and reconstructing historical chat records. However, these methods are no longer applicable to encrypted instant messaging tools that only have ciphertext during communication. In order to monitor illegal activities on such platforms, it is necessary to use an account of an encrypted communication tool platform to join a group that may have illegal activities and analyze the activities in the group to obtain threat intelligence. For groups that are found to have threats, the account can be used to engage in conversations in the group to obtain more relevant information from criminals.

[0025] The current method of actively obtaining threat intelligence information through conversation in groups that may have illegal activities mainly includes two types: One method is for security researchers to use pre-prepared analysis methods to analyze the content in encrypted instant messaging groups, filter out groups with threats through analysis results, and find relevant group members. Then, through manual intervention, a conversation is conducted according to the specific situation to obtain additional threat intelligence information. This method can be applied to groups of various topics, and the conversation content is written by security researchers to adapt to different needs.

[0026] Another method uses pre-designed analysis models and conversation templates to obtain threat intelligence. This method targets groups with specific topics, and communicates with group members who match pre-set identity roles to obtain threat intelligence content by filling in conversation templates to generate conversation responses. Into the deep web: Understanding E-commerce fraud from autonomous chat with cybercriminals proposes an automated chat robot named Aubrey, which uses 20 artificially generated conversation samples as seeds, combines group knowledge bases, builds finite state machines and retrieval models, and realizes conversations with criminals with different roles.

[0027] Due to the large number of groups in encrypted instant messaging software, although the use of automated analysis methods can filter out a large number of harmless groups, there will still be a large number of groups with potential threat activities that need further analysis. Because the members in these groups want to protect their information as much as possible from being leaked, they often do not actively disclose detailed threat information during group activities, so communication with them is needed to obtain more effective information. Researchers have difficulty tracking each group with threat activities and obtaining more threat-related information through conversations in these groups.

[0028] Using template-based automated conversation methods can reduce the need for human intervention to some extent. Current methods mainly use finite state automata and fill in conversation templates according to knowledge base content. This method first needs to set a specific topic, design a conversation strategy under this topic and form a finite state automaton, and manually build an initial knowledge base and answer content for the first conversation, and then extract new threat intelligence and improve the knowledge base during subsequent conversations. However, this method also needs to design conversation strategies and build knowledge bases for a large number of different group activity topics. Moreover, for new types of threat intelligence that appear outside the preset templates in group activities, this method is also difficult to identify and respond autonomously.

[0029] To solve the above problems, the present disclosure provides a threat intelligence obtaining method and related device scheme, the method comprising: The high-value group with threats is obtained by screening the encrypted instant messaging tool group based on a pre-trained threat discrimination model; the high-value conversation target is obtained by analyzing the communication content of the high-value group; the threat intelligence conversation content is obtained by conversation generation based on the high-value conversation target; and the high-value intelligence information is obtained by intelligence acquisition based on the threat intelligence conversation content. The present disclosure can effectively reduce the degree of manual intervention required for dialogue to obtain threat intelligence with members who may have threats in the encrypted instant messaging tool platform group. By combining the extensive world knowledge and reasoning ability of the large language model with the continuously constructed threat intelligence knowledge base, the method of the present disclosure can be applied to various topic encrypted communication group dialogue scenarios, and threat intelligence can be actively obtained from group members using a general dialogue strategy. Specifically, the present disclosure can reduce the degree of manual intervention and better adapt to groups of different topics. Since the large language model has extensive world knowledge and strong reasoning ability, a more general dialogue strategy can be designed, without the need to design different dialogue strategies for different topics of encrypted instant messaging groups. At the same time, since the dialogue generation ability of the large language model is superior to the existing template-based dialogue generation method, the generation quality of the dialogue content outside the preset template is also superior to the existing method.

[0030] The present disclosure also designs a multi-level analysis and evaluation process to continuously analyze whether to generate dialogue content, whether the generated content is reasonable, and whether the dialogue process needs to be terminated, effectively avoiding the instability of strategy and content generation that may exist when directly using a large language model for group dialogue based on a prompt engineering, reducing unreasonable group dialogue, and avoiding exposure of intelligence acquisition accounts in encrypted instant messaging groups.

[0031] After introducing the basic principles of the present disclosure, various non-limiting embodiments of the present disclosure will be specifically introduced below.

[0032] Reference Figure 1 which is a schematic diagram of an application scenario of the threat intelligence acquisition method provided by an exemplary embodiment of the present disclosure.

[0033] In this application scenario, a terminal device 101 and a server 102 are included. The terminal device 101 and the server 102 can be connected through a wired or wireless communication network to realize data interaction.

[0034] The terminal device 101 can be an electronic device close to a user side with data transmission, multimedia input / output functions, including but not limited to a desktop computer, a mobile phone, a mobile computer, a tablet computer, a media player, a smart wearable device, a personal digital assistant (PDA), or other electronic devices capable of realizing the above functions, etc. The electronic device can include a processor and a display screen with touch input function, the display screen being used to present a graphical user interface, the graphical user interface being capable of displaying an application interface, the processor being used to process application data, generate a graphical user interface, and control the display of the graphical user interface on the display screen.

[0035] The server 102 can be a stand-alone physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server providing cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN (Content Delivery Network), and basic cloud computing services such as big data and artificial intelligence platforms.

[0036] In some example embodiments, the threat intelligence acquisition method can run on the terminal device 101 or the server 102.

[0037] When the threat intelligence acquisition method runs on the server 102, the server 102 is used to provide a threat intelligence acquisition service to a user of the terminal device 101.

[0038] The server 102 screens the encrypted instant messaging tool groups based on a pre-trained threat discrimination model to obtain high-value groups with threats; The server 102 analyzes the communication content of the high-value groups to obtain high-value conversation targets; The server 102 generates a conversation based on the high-value conversation targets to obtain threat intelligence conversation content; The server 102 acquires intelligence based on the threat intelligence conversation content to obtain high-value intelligence information, and then transmits the high-value intelligence information to the terminal device 101.

[0039] It should be noted that the above application scenarios are only shown for the purpose of facilitating the understanding of the spirit and principles of the present disclosure, and the embodiments of the present disclosure are not limited in this respect. On the contrary, the embodiments of the present disclosure can be applied to any applicable scenario.

[0040] Reference Figure 2 A threat intelligence acquisition method, the method comprising the following steps: Step S210, screening the encrypted instant messaging tool group based on the pre-trained threat discrimination model to obtain a high-value group with threats.

[0041] In specific implementation, the way of screening the encrypted instant messaging tool group based on the pre-trained threat discrimination model to obtain a high-value group with threats is: Using a natural language processing model based on the DeBERTa architecture (i.e., the threat discrimination model), training on an intelligence threat judgment dataset, can comprehensively judge whether the encrypted instant messaging group may contain threat intelligence information according to the group name, group profile, group members, and chat content, etc. At the same time, using keyword filtering for large-scale groups, and using a large language model combined with analysis prompt words, continuously analyzing newly discovered groups, and constantly updating the group threat judgment dataset to adapt to the rapidly changing encrypted instant messaging groups (i.e., high-value groups with threats).

[0042] In some embodiments, the threat discrimination model is further trained by the following method: Determine the training group information of the encrypted instant messaging tool group, filter and screen the training group information to obtain a training threat intelligence dataset; Based on the training threat intelligence dataset, feature extraction is performed to obtain an intelligence threat feature set; Based on the intelligence threat feature set, the threat discrimination model is constructed.

[0043] In specific implementation, the way of determining the training group information of the encrypted instant messaging tool group, filtering and screening the training group information to obtain a training threat intelligence dataset is: The collected group name, profile, and chat content of the encrypted instant messaging software are filtered and screened by regular expressions, keywords, and manual discrimination to obtain a dataset for judging whether the group may have threats, and then a training threat intelligence dataset is obtained.

[0044] In specific implementation, the way of performing feature extraction based on the training threat intelligence dataset to obtain an intelligence threat feature set is: On the basis of the threat intelligence data set for training, the classifier is constructed, and then the group that may have threat activities can be quickly and efficiently screened out, and the chat robot is joined to obtain more information through the dialogue. After joining the group that may have threats, the group activity content is analyzed using multiple models to obtain key information such as the theme of the group activity, the entity in the group discussion content, the language features of the group users, and the like, and is provided to the intelligence knowledge maintenance part to construct the group related knowledge. On this basis, the overall portrait of the group members is constructed according to the user dialogue content using a large language model, and the intelligence threat feature set of the role features used for generating dialogue in the group is constructed accordingly.

[0045] In specific implementation, the manner of constructing the threat discrimination model based on the intelligence threat feature set is: Based on the intelligence threat feature set, a threat discrimination model is constructed using machine learning or deep learning algorithms. If the system detects a new threat intelligence data set, the threat discrimination model is used as a classifier, and a new group that may have threat activities is re-screened to generate a new intelligence threat feature set, and then the iteration of the threat discrimination model in the above steps is completed.

[0046] As a specific embodiment, after obtaining the high-value group with threats, the role features of the chat robot for dialogue with the dialogue target are determined by analyzing the high-value group with threats. Specifically, the role features are constructed by using multiple models (including a large language model) to complete tasks such as sentiment analysis, entity recognition, keyword extraction, and text summarization on the communication content metadata (such as the activity of the group, the introduction of the group, or the group notification) of the high-value group, and further analyzing the language style, user preference, and role characteristics extraction through the large language model to complete higher-level tasks such as role portrait construction for dialogue generation.

[0047] Step S220, analyzing the communication content of the high-value group to obtain a high-value dialogue target.

[0048] In some embodiments, analyzing the communication content of the high-value group to obtain a high-value dialogue target comprises: performing content screening on the communication content based on a large language model to obtain candidate dialogue content; analyzing the candidate dialogue content to obtain high-value content information; performing value assessment on the high-value group based on the high-value content information to obtain the high-value dialogue target.

[0049] In specific implementation, the manner of performing content screening on the communication content based on a large language model to obtain candidate dialogue content is: Since a considerable part of the group chat content in most encrypted communication groups is casual chatting or advertising, a special analysis process is needed to filter out irrelevant content and reject dialogue generation. The content that is not filtered out is used as candidate dialogue content.

[0050] In specific implementation, the candidate dialogue content is analyzed to obtain high-value content information, and the high-value group is evaluated based on the high-value content information to obtain the high-value dialogue target. The filtered content answer is analyzed using a large language model combined with a prompt engineering to extract existing threat intelligence information, and high-value group members are selected as dialogue targets.

[0051] In step S230, dialogue generation is performed based on the high-value dialogue target to obtain threat intelligence dialogue content.

[0052] In some embodiments, dialogue generation is performed based on the high-value dialogue target to obtain threat intelligence dialogue content, including: Determine the user portrait and speech content of the high-value dialogue target, and based on the user portrait and the speech content, obtain preliminary dialogue content; Based on the preliminary dialogue content, dialogue is performed with the high-value dialogue target to obtain reply content of the high-value dialogue target; The reply content is analyzed to obtain the threat intelligence dialogue content.

[0053] In specific implementation, the user portrait and speech content of the high-value dialogue target are determined, and based on the user portrait and the speech content, preliminary dialogue content is obtained. Based on the preliminary dialogue content, dialogue is performed with the high-value dialogue target to obtain reply content of the high-value dialogue target. Reference Figure 3 For high-value targets, a multi-round dialogue mechanism is used in combination with relevant intelligence knowledge to perform similarity-based search-enhanced generation. In this embodiment, the framework uses a smaller large language model to generate dialogue strategies based on the target group characteristics. The system will compile the user portrait and historical speech content to generate preliminary dialogue content for high-value information and reply content related to the question.

[0054] In some embodiments, the reply content is analyzed to obtain the threat intelligence dialogue content, including: The reply content is judged, and in response to the reply content containing threat intelligence, in response to the reply content having intelligence value, intelligence acquisition is performed on the reply content to obtain threat intelligence information. Based on the threat intelligence information, conversation generation is performed to obtain the threat intelligence conversation content.

[0055] In specific implementation, the reply content is judged, and in response to the reply content containing threat intelligence or having intelligence value, intelligence acquisition is performed on the reply content to obtain threat intelligence information; and based on the threat intelligence information, conversation generation is performed to obtain the threat intelligence conversation content. When receiving the reply of the target user, the system first judges whether it contains threat intelligence or has intelligence value by using a large language model. Figure 3 If it is determined to be valuable, the specific threat intelligence information is extracted immediately. Subsequently, the system generates threat intelligence conversation content for further interaction based on the newly obtained threat intelligence. In the generation process, the system uses a large language model to judge the content in terms of topic relevance, role authenticity and compliance: if it passes, it is sent to the group; if it fails, the model is asked to regenerate by the prompt word enhancement method and analyzed again by the judgment model; if the regenerated content still does not meet the requirements, an external larger large language model is called to regenerate in combination with the context and role. In order to maintain concealment, if the system still cannot generate suitable content, it will not send any content to avoid identity exposure.

[0056] In step S240, based on the threat intelligence conversation content, intelligence acquisition is performed on the high-value conversation target to obtain high-value intelligence information.

[0057] In this step, the system uses the LangChain framework to integrate large language models of different parameter sizes (such as the general-purpose Q2.5 series 3B / 7B / 72B, etc.) to build a hierarchical processing conversation content generation pipeline: smaller models are responsible for real-time content analysis and simple conversation generation to improve response speed, and larger models focus on role analysis and strategy construction and other complex tasks, thereby reducing deployment overhead and conversation delay while ensuring interaction quality.

[0058] In some embodiments, based on the threat intelligence conversation content, intelligence acquisition is performed on the high-value conversation target to obtain high-value intelligence information, including: Based on the conversation between the threat intelligence conversation content and the high-value conversation target, conversation content information is obtained, and the conversation content information is added to an analysis queue. Intelligence acquisition is performed on the conversation content information in the analysis queue to obtain the high-value intelligence information.

[0059] In specific implementation, the manner of obtaining the dialogue content information by dialoging the high-value dialogue target based on the threat intelligence dialogue content is: The system adds the real-time obtained dialogue content information to the analysis queue. When the large language model determines that the content has intelligence value, the system uses natural language processing technology to extract threat intelligence related to the current group chat theme from it and updates factual knowledge to the knowledge base, and drives the dialogue state automaton into the intelligence acquisition state. In this state, the dialogue generation model integrates the current dialogue context, target object information and group background to request the generation of follow-up questions from the larger large language model; if the target provides relevant answers to the follow-up questions, it is added to the analysis queue for further intelligence extraction, and the process is repeated until the questioning threshold is reached or the system determines that the dialogue should not continue; if the target does not reply in time or the reply content is not relevant and has no intelligence value, the state machine is reset to the initial state to find a high-value target again; if the target actively asks questions, the system will analyze the relevance of the questions and enter the search state or any dialogue state accordingly, ensuring that the dialogue process is natural and hidden and continuously obtaining valuable intelligence.

[0060] In specific implementation, the manner of obtaining the dialogue content information by dialoging the high-value dialogue target based on the threat intelligence dialogue content is: When extracting intelligence from the dialogue content information in the analysis queue, the system first uses natural language processing technology to extract key intelligence related to the current group chat theme, and dynamically updates factual knowledge to the knowledge base. When the large language model determines that the intelligence has value, it refers to Figure 3 The dialogue state automaton enters the intelligence acquisition state, and at this time the dialogue generation model integrates the context information, target object characteristics and group background to request the generation of follow-up questions from the larger large language model. If the target provides relevant answers, the system re-adds them to the analysis queue for further intelligence extraction, forming a closed-loop processing process; if the target does not reply or the reply content is not relevant, it is determined whether the retry condition is met through sentiment analysis, and according to the result, it is decided whether to re-enter the intelligence acquisition state or transfer to other dialogue states. The whole process continues to circulate until the questioning threshold is reached or the system determines that the dialogue should not continue, and finally outputs high-value intelligence information.

[0061] During the whole conversation, the similarity between multiple questions in the same group chat or for the same high-value user is judged using a small-scale large language model and prompt engineering methods to avoid generating repeated formats and content of reply responses, which are identified as robots. At the same time, for the generated conversation content, a small-scale large language model is also used to analyze its tone and content in combination with the group chat context to avoid inappropriate statements. For questions that successfully obtain answers, they are recorded and provided to the intelligence knowledge maintenance part to be added to the knowledge base and referenced when generating similar new questions. In addition, during the generation of questions on specific topics, human intervention can be used in the generation process of related questions, and by designing requirement prompts embedded in the question generation process, the large language model can generate conversation content that obtains intelligence information considered more critical by analysts in the conversation for specific topics.

[0062] During intelligence knowledge maintenance, a traditional method based on rule matching is combined with a large language model and prompt engineering method to extract entities and relationships from encrypted communication group chat content that may have intelligence value, and to build a knowledge base related to specific topics of encrypted communication groups. In this way, the large language model can understand some special chat content in the encrypted communication group during group conversation generation, such as slang, jargon, Leetspeak, and other special language usage used by group members, and understand the relevant background knowledge of the group conversation content, so as to generate conversation content that is more consistent with the characteristics of the group. In addition, this part also maintains the role characteristics of the manipulation accounts in each encrypted communication group, wherein the role characteristics are based on the above steps, using multiple models (including large language models) to complete tasks such as sentiment analysis, entity recognition, keyword extraction, text summarization, and further analyzing language style, user preference, and role characteristics extraction through a large language model to build a role portrait for conversation generation, to ensure that the style and characteristics of the chat robot's different statements in the same group are consistent.

[0063] It should be noted that the method of the embodiment of the present disclosure can be executed by a single device, such as a computer or a server. The method of the present embodiment can also be applied in a distributed scenario, and completed by multiple devices cooperating with each other. In this distributed scenario, one of the multiple devices can only execute one or more steps in the method of the present embodiment, and the multiple devices can interact with each other to complete the method.

[0064] It is to be noted that some embodiments of the present disclosure have been described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in a different order than those described above and still achieve desirable results. Additionally, the processes depicted in the figures do not necessarily require the particular order shown or sequential order to achieve desirable results. In certain implementations, multitasking and parallel processing can be advantageous or necessary.

[0065] Based on the same inventive concept, the present disclosure also provides a threat intelligence acquisition device corresponding to any of the above-mentioned embodiment methods.

[0066] Reference Figure 4 The threat intelligence acquisition device comprises: The high-value group determination module 410 is configured to filter the encrypted instant messaging tool group based on a pre-trained threat discrimination model to obtain a high-value group with threats; The conversation target determination module 420 is configured to analyze the communication content of the high-value group to obtain a high-value conversation target; The conversation content determination module 430 is configured to generate a conversation based on the high-value conversation target to obtain threat intelligence conversation content; The intelligence information determination module 440 is configured to acquire intelligence based on the threat intelligence conversation content of the high-value conversation target to obtain high-value intelligence information.

[0067] In the present exemplary embodiment, the high-value group determination module 410 is specifically configured to: Filter the encrypted instant messaging tool group based on a pre-trained threat discrimination model to obtain a high-value group with threats, wherein the threat discrimination model is trained by the following method: Determine training group information of the encrypted instant messaging tool group, filter the training group information, and obtain a training threat intelligence data set; Extract features based on the training threat intelligence data set to obtain an intelligence threat feature set; Construct based on the intelligence threat feature set to obtain the threat discrimination model.

[0068] In the present exemplary embodiment, the conversation target determination module 420 is specifically configured to: Filter the communication content based on a large language model to obtain candidate conversation content; analyze the candidate conversation content to obtain high-value content information; and evaluate the value of the high-value group based on the high-value content information to obtain the high-value conversation target.

[0069] In this example embodiment, the dialogue content determination module 430 is specifically configured to: determine a user portrait and a speech content of the high-value dialogue target, obtain preliminary dialogue content based on the user portrait and the speech content, perform dialogue with the high-value dialogue target based on the preliminary dialogue content to obtain reply content of the high-value dialogue target, judge the reply content, in response to the reply content containing threat intelligence, in response to the reply content having intelligence value, perform intelligence acquisition on the reply content to obtain threat intelligence information, and perform dialogue generation based on the threat intelligence information to obtain threat intelligence dialogue content.

[0070] In this example embodiment, the intelligence information determination module 440 is specifically configured to: perform dialogue with the high-value dialogue target based on the threat intelligence dialogue content to obtain dialogue content information, add the dialogue content information to an analysis queue, and perform intelligence acquisition on the dialogue content information in the analysis queue to obtain high-value intelligence information.

[0071] For the convenience of description, the above apparatus is described in various modules in terms of functions. Of course, the functions of the modules can be implemented in one or more software and / or hardware when implementing the present disclosure.

[0072] The apparatus of the above embodiments is used to implement the corresponding threat intelligence acquisition method in any of the above embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be described here.

[0073] Based on the same inventive concept, the present disclosure also provides an electronic device corresponding to any of the above method embodiments, which comprises a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the threat intelligence acquisition method of any of the above embodiments when executing the program.

[0074] Figure 5 A more specific hardware structure schematic diagram of an electronic device provided by the present embodiment is shown, which can include a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. The processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040 are connected to each other through the bus 1050 for communication within the device.

[0075] The processor 1010 can be implemented by a general-purpose CPU (Central Processing Unit), a microprocessor, an ASIC (Application Specific Integrated Circuit), or one or more integrated circuits, etc., for executing relevant programs to implement the technical solutions provided by the embodiments of the present specification.

[0076] The memory 1020 can be implemented in the form of a ROM (Read Only Memory), a RAM (Random Access Memory), a static storage device, a dynamic storage device, etc. The memory 1020 can store an operating system and other application programs, and when the technical solutions provided by the embodiments of the present specification are implemented by software or firmware, the relevant program codes are saved in the memory 1020 and called and executed by the processor 1010.

[0077] The input / output interface 1030 is configured to connect input / output modules to implement information input and output. The input / output modules can be configured as components in the device (not shown in the figure) or externally connected to the device to provide corresponding functions. The input devices can include a keyboard, a mouse, a touch screen, a microphone, various sensors, etc., and the output devices can include a display, a speaker, a vibrator, an indicator light, etc.

[0078] The communication interface 1040 is configured to connect a communication module (not shown in the figure) to implement the communication interaction between the device and other devices. The communication module can realize communication through a wired manner (such as USB, network cable, etc.) or through a wireless manner (such as mobile network, WIFI, Bluetooth, etc.).

[0079] The bus 1050 includes a channel for transmitting information between various components (such as the processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040) of the device.

[0080] It should be noted that although the above device only shows the processor 1010, the memory 1020, the input / output interface 1030, the communication interface 1040, and the bus 1050, in the specific implementation process, the device can also include other components necessary for normal operation. In addition, those skilled in the art can understand that the above device can also only include the components necessary to implement the solutions of the embodiments of the present specification, and does not have to include all the components shown in the figure.

[0081] The electronic device of the above-mentioned embodiments is used to implement the corresponding threat intelligence acquisition method in any of the preceding embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0082] Based on the same inventive concept, the disclosure also provides a non-transitory computer-readable storage medium storing computer instructions for causing the computer to perform the threat intelligence acquisition method according to any of the preceding embodiments.

[0083] The computer-readable medium of the present embodiments includes permanent and non-permanent, removable and non-removable media, which can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette, magnetic tape disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible by a computing device.

[0084] The above-mentioned non-transitory computer-readable storage medium can be any available medium or data storage device that can be accessed by a computer, including but not limited to magnetic storage (such as floppy disks, hard disks, magnetic tapes, magneto-optical disks (MO) and the like), optical storage (such as CDs, DVDs, BDs, HVDs and the like), and semiconductor memory (such as ROM, EPROM, EEPROM, non-volatile memory (NAND FLASH), solid state disk (SSD)) and the like.

[0085] The storage medium of the above-mentioned embodiments stores computer instructions for causing the computer to perform the threat intelligence acquisition method according to any of the above-mentioned exemplary method embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0086] Based on the same inventive concept, the disclosure also provides a computer program product comprising computer program instructions. In some embodiments, the computer program instructions can be executed by one or more processors of a computer to cause the computer and / or the processors to perform the threat intelligence acquisition method. Corresponding to the execution subject of each step in each embodiment of the threat intelligence acquisition method, the processor performing the corresponding step can belong to the corresponding execution subject.

[0087] The computer program product of the above embodiments is configured to cause the computer and / or the processor to perform the threat intelligence acquisition method according to any one of the above embodiments, and has the beneficial effects of the corresponding method embodiments, which are not repeated here.

[0088] Those skilled in the art know that the embodiments of the present disclosure can be implemented as a system, a method or a computer program product. Therefore, the present disclosure can be embodied in the form of entire hardware, entire software (including firmware, resident software, microcode, etc.), or a combination of hardware and software, which is generally referred to as "circuitry", "module" or "system" herein. In addition, in some embodiments, the present disclosure can also be embodied in the form of a computer program product in one or more computer readable media, which contains computer readable program codes.

[0089] Any combination of one or more computer readable medium can be employed. The computer readable medium can be a computer readable signal medium or a computer readable storage medium. A computer readable storage medium can be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or apparatus, or any suitable combination of the above. More specific examples (non-exhaustive list) of the computer readable storage medium include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this document, the computer readable storage medium can be any tangible medium that contains or stores a program that can be used by or in connection with an instruction execution system, apparatus or device.

[0090] The computer readable signal medium can include a data signal propagated in baseband or propagated as a carrier wave, in which computer readable program codes are contained. Such propagated data signal can take various forms, including but not limited to electromagnetic signal, optical signal or any suitable combination of the above. The computer readable signal medium can also be any computer readable medium other than the computer readable storage medium, which can send, propagate or transmit a program for use by or in connection with an instruction execution system, apparatus or device.

[0091] The program codes contained in the computer readable medium can be transmitted by any suitable medium, including but not limited to wireless, wire, optical cable, RF, etc., or any suitable combination of the above.

[0092] Computer program code for carrying out operations of the present disclosure can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).

[0093] It should be understood that each block of the flowchart and / or block diagram illustrations, and combinations of blocks in the flowchart and / or block diagram illustrations, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0094] These computer program instructions can also be stored in a computer readable medium that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer readable medium produce an article of manufacture including instructions which implement the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0095] The computer program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0096] Further, while operations of the present disclosure are described in a particular order in the figures, it is not necessary to perform the operations in the particular order shown or in all of the described operations are required to produce a desired result. Rather, the steps depicted in the flowcharts can be altered in order of execution. Additionally or alternatively, certain steps can be omitted, combined, performed in parallel, and / or performed in a different order.

[0097] The computer program product of the present application can be a computer program embodied on a non-transitory computer readable medium. The body of computer program instructions can be a source file, object file, executable file, or any other tangible form of computer program instructions. The computer program product can be supplied to users and customers of the present application by any apparatus which works to use a non-transitory computer readable medium to provide computer program instructions to a computer, such as the Internet, stores, a publisher, or other distribution mechanism.

[0098] It should be noted that although several modules or units for a device for action performance are mentioned in the foregoing detailed description, such a division is not mandatory. Indeed, according to an embodiment of the application, the features and functionalities of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functionalities of one module or unit described above can be further divided into embodied by a plurality of modules or units.

[0099] It should be understood by those of ordinary skill in the art that the above discussion of any embodiment is merely exemplary in nature and is not intended to imply limitations on the scope of the application, including the claims. Indeed, variations on the above embodiments can be made, and alterations of the steps of the embodiments or techniques described herein can be made in light of the above teachings. Also, the various embodiments or technical features from different embodiments can be combined to make a new embodiment, steps can be implemented in any order, and there are many other alternatives within the scope of the various embodiments of the application, which are all intended to be within the scope of the claims. Other embodiments are within the scope of the following claims.

[0100] In addition, to simplify the description and discussion, and so as not to make the embodiments of the present application difficult to understand, the known power / ground connections of integrated circuit (IC) chips and other components can or can not be shown in the provided drawings. In addition, the apparatus can be shown in the form of a block diagram in order to avoid making the embodiments of the present application difficult to understand, and this also takes into account the fact that the details of the implementation of these block diagram apparatus are highly dependent on the platform to be implemented to implement the embodiments of the present application (i.e. these details should be fully within the understanding of those skilled in the art). Where specific details (e.g. a circuit) are set forth in order to describe an exemplary embodiment of the present application, it should be apparent to those skilled in the art that the present application can be practiced without such specific details or with variations on the specific details. Therefore, the descriptions should be considered as illustrative and not restrictive.

[0101] While the present application has been described in connection with certain embodiments thereof, many modifications, substitutions, and alterations, thereof, will be apparent to those of ordinary skill in the art from the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) can use the embodiments discussed.

[0102] It is intended that the embodiments of the present application encompass all such substitutions, modifications and alterations that fall within the broadest possible scope of the appended claims. Accordingly, any and all such modifications, substitutions, alterations, omissions, and permutations are intended to be encompassed by the scope of the present application. Although specific embodiments of the application have been described in detail, those skilled in the art will appreciate that various modifications, substitutions, and alterations can be made to the embodiments without departing from the spirit and principles of the application. Accordingly, the various modifications, substitutions, and alterations are intended to be encompassed by the scope of the claims.

[0103] While the principles of the disclosure have been described above in connection with specific embodiments, it is to be understood that this disclosure is not limited to the disclosed embodiments, but is intended to encompass various modifications and equivalent arrangements. The use of the disjunctive is intended to cover the alternative of the conjunctive. Therefore, individual features of each aspect of the disclosure should be taken to be exemplary of that aspect only and not restrictive of other aspects. The scope of the disclosure should be determined by the broadest permissible interpretation of the following claims and their equivalents.

Claims

1. A threat intelligence acquisition method, characterized by comprising: The method comprises the following steps: screening a group of encrypted instant messaging tools based on a pre-trained threat discrimination model to obtain a high-value group with threats; analyzing the communication content of the high-value group to obtain a high-value conversation target; generating a conversation based on the high-value conversation target to obtain threat intelligence conversation content; obtaining intelligence based on the threat intelligence conversation content to obtain high-value intelligence information.

2. The method of claim 1, wherein, The method further comprises training a threat discrimination model by the following method: determining training group information of the group of encrypted instant messaging tools, filtering and screening the training group information to obtain a training threat intelligence data set; extracting features based on the training threat intelligence data set to obtain an intelligence threat feature set; constructing based on the intelligence threat feature set to obtain the threat discrimination model.

3. The method of claim 1, wherein, The method further comprises the following steps: screening the communication content based on a large language model to obtain candidate conversation content; analyzing the candidate conversation content to obtain high-value content information; evaluating the value of the high-value group based on the high-value content information to obtain the high-value conversation target.

4. The method of claim 1, wherein, The method further comprises the following steps: determining the user portrait and the speech content of the high-value conversation target, and obtaining preliminary conversation content based on the user portrait and the speech content; having a conversation with the high-value conversation target based on the preliminary conversation content to obtain reply content of the high-value conversation target; analyzing the reply content to obtain the threat intelligence conversation content.

5. The method of claim 4, wherein, The method further comprises the following steps: judging the reply content, and in response to the reply content containing threat intelligence, and in response to the reply content having intelligence value, obtaining intelligence from the reply content to obtain threat intelligence information; generating a conversation based on the threat intelligence information to obtain the threat intelligence conversation content.

6. The method of claim 1, wherein, The method further comprises the following steps: having a conversation with the high-value conversation target based on the threat intelligence conversation content to obtain conversation content information, and adding the conversation content information to an analysis queue; obtaining intelligence from the conversation content information in the analysis queue to obtain the high-value intelligence information. 7.A threat intelligence acquisition apparatus characterized by comprising: The method comprises the following steps: The high-value group determination module is configured to screen a group of encrypted instant messaging tools based on a pre-trained threat discrimination model to obtain a high-value group with threats; The conversation target determination module is configured to analyze the communication content of the high-value group to obtain a high-value conversation target; The conversation content determination module is configured to generate a conversation based on the high-value conversation target to obtain threat intelligence conversation content; An intelligence information determination module is configured to acquire intelligence information of the high-value dialogue target based on the threat intelligence dialogue content, to obtain high-value intelligence information.

8. An electronic device, comprising: A computer program product comprising a memory, a processor and a computer program stored on the memory and loadable on the processor, the processor implementing the method according to any one of claims 1 to 6 when executing the program.

9. A non-transitory computer-readable storage medium, comprising: The non-transitory computer readable storage medium stores computer instructions for causing a computer to execute the method according to any one of claims 1 to 6.

10. A computer program product, characterised in that, A computer program product comprising computer program instructions which, when executed on a computer, cause the computer to perform the method according to any one of claims 1 to 6.