Threat assessment method and device, equipment, storage medium and computer program product
By generating black and white IP databases and calculating threat scores, the threat level of autonomous system numbers is assessed, solving the problem of low efficiency in investigating massive IP threats and achieving rapid and accurate threat assessment and handling.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-02-04
- Publication Date
- 2026-04-14
AI Technical Summary
Existing technologies struggle to quickly and accurately identify threats from massive numbers of IP addresses, resulting in low threat investigation efficiency.
A black IP database is generated based on the IP addresses of command and control servers used by attackers, and a white IP database is generated based on terminal access information. Threat scores are calculated, the threat level of autonomous system numbers is assessed, and warnings are issued.
It enables automatic threat assessment of all IPs within the Autonomous System ID, quickly identifies high-threat IPs for handling, and improves network security and the speed and accuracy of threat assessment.
Smart Images

Figure CN121864465A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cybersecurity technology, and in particular to threat assessment methods, apparatus, devices, storage media, and computer program products. Background Technology
[0002] An Autonomous System (AS) is a combination of IP networks and routers under the jurisdiction of one or more entities on the Internet, which enforce common routing policies. You can think of each AS as a post office, with numerous IP addresses under each AS. The ASes of each hosting provider are relatively fixed; IPs from a particular provider belong to one or a few ASs. Attackers also tend to use relatively fixed VPSs; new C2s from the same organization are highly likely to belong to the same hosting provider as their historical C2s. However, because each AS contains a massive number of IPs, while it's possible to locate an attacker's C2, it's not possible to perform a more accurate and rapid threat assessment based on this vast number of IPs.
[0003] The above content is only used to help understand the technical solution of this application and does not represent an admission that the above content is prior art. Summary of the Invention
[0004] The main purpose of this application is to provide a threat assessment method, apparatus, device, storage medium, and computer program product, which aims to solve the technical problem of low efficiency in threat investigation of massive IP addresses.
[0005] To achieve the above objectives, this application proposes a threat assessment method, the method comprising: A black IP database is obtained by cleaning up IPs based on the IP addresses of command and control servers used by attackers, and a white IP database is generated based on terminal access information. Threat scores are calculated for each autonomous system ID to be evaluated based on the black IP database and the white IP database. The threat level of each Autonomous System ID to be evaluated is assessed based on the threat score, and a warning is issued based on the target Autonomous System ID, which is an Autonomous System ID to be evaluated whose threat level is higher than a preset level.
[0006] Optionally, the steps of obtaining a black IP database by performing IP cleaning based on the IP address of the command and control server used by the attacker, and generating a white IP database based on terminal access information, include: By querying historical attack records to identify attackers, and by controlling server IP addresses according to the attackers' commands to perform data cleansing and generate a black IP database; IPs are merged based on the terminal IP access volume corresponding to the terminal access information to obtain a white IP database.
[0007] Optionally, the steps of querying historical attack records to identify attackers and controlling server IP addresses to perform data cleaning based on the attackers' commands to generate a black IP database include: By querying historical attack records, the attacker can be identified, and the command and control server used by the attacker can be obtained. Obtain the command and control server IP address; Data is cleaned based on the command control server IP address to generate a black IP database.
[0008] Optionally, the step of performing data cleaning based on the command control server IP address to generate a black IP database includes: Collect the content delivery network IP, parking IP, and sinking IP from the IP address of the command and control server; The black IP database is obtained by excluding the content distribution network IP, the parking IP, and the sinking IP from the command and control server IP address.
[0009] Optionally, the step of merging IPs based on the terminal IP access volume corresponding to the terminal access information to obtain a white IP database includes: The terminal IP access volume is determined based on the terminal access information. The ranking of access volume is determined based on the access volume of the terminal IP address. Select terminal access IPs within the target ranking range based on the access volume ranking; Obtain the terminal access domains within the target ranking range; A white IP database is generated based on the terminal access IP and the terminal access domain name.
[0010] Optionally, the step of generating a white IP database based on the terminal access IP and the terminal access domain name includes: Based on the terminal access domain name, multiple domain names are determined to point to IP addresses; The terminal access IP and the domain name pointing to the IP are merged to obtain merged IP information; By excluding content delivery network IPs, parking IPs, and sinking IPs from the merged IP information, a white IP database is obtained.
[0011] Optionally, before the step of calculating a threat score for each autonomous system ID to be evaluated based on the black IP database and the white IP database, the method further includes: Search for the target data center in the IP hosting database; Based on the Autonomous System Number (ASN) database and the target data center, multiple ASNs to be evaluated are identified.
[0012] Optionally, the step of calculating a threat score for each autonomous system ID to be evaluated based on the black IP database and the white IP database includes: Based on the black IP database and the white IP database, query each autonomous system number to be evaluated, and generate the white score and black score corresponding to each autonomous system number to be evaluated; The threat score corresponding to each autonomous system number to be evaluated is determined based on the white score and the black score.
[0013] Optionally, the step of querying each autonomous system number to be evaluated based on the black IP database and the white IP database, and generating the white score and black score corresponding to each autonomous system number to be evaluated, includes: Determine the number of black IPs in each autonomous system number to be evaluated that overlap with the black IP database; Determine the number of white IPs that overlap with the white IP database in each autonomous system number to be evaluated; The black score corresponding to each autonomous system number to be evaluated is calculated based on the number of overlapping black IPs, and the white score corresponding to each autonomous system number to be evaluated is calculated based on the number of overlapping white IPs.
[0014] Optionally, the step of assessing the threat level of each autonomous system number to be assessed based on the threat score and issuing a warning based on the target autonomous system number includes: The score range for each autonomous system number to be evaluated is determined based on the threat score; The threat level of each autonomous system number to be evaluated is determined based on the aforementioned score range; The target autonomous system number is determined based on the threat level, and a warning is issued based on the target autonomous system number.
[0015] Furthermore, to achieve the above objectives, this application also proposes a threat assessment device, which includes: The library generation module is used to clean up IPs based on the IP addresses of command and control servers used by attackers to obtain a black IP library, and to generate a white IP library based on terminal access information. The score calculation module is used to calculate the threat score for each autonomous system ID to be evaluated based on the black IP database and the white IP database. The threat alert module is used to assess the threat level of each Autonomous System Number to be assessed based on the threat score, and to issue a warning alert based on the target Autonomous System Number, which is an Autonomous System Number to be assessed whose threat level is higher than a preset level.
[0016] Optionally, the database generation module is also used to query historical attack records to identify attackers, and to perform data cleaning based on the attacker's command to control the server IP address to generate a black IP database; and to merge IPs based on the terminal IP access volume corresponding to the terminal access information to obtain a white IP database.
[0017] Optionally, the database generation module is further configured to query historical attack records to identify attackers and obtain the command and control server used by the attackers; obtain the command and control server IP address of the command and control server; and perform data cleaning based on the command and control server IP address to generate a black IP database.
[0018] Optionally, the library generation module is further configured to collect the content delivery network IP, parking IP, and sinking IP from the command and control server IP address; exclude the content delivery network IP, parking IP, and sinking IP from the command and control server IP address to obtain a black IP library.
[0019] Optionally, the library generation module is further configured to: determine the terminal IP access volume based on the terminal access information; determine the access volume ranking based on the terminal IP access volume; select terminal access IPs within a target ranking range based on the access volume ranking; obtain terminal access domain names within the target ranking range; and generate a white IP library based on the terminal access IPs and the terminal access domain names.
[0020] Optionally, the library generation module is further configured to determine multiple domain name pointing IPs based on the terminal access domain name; merge the terminal access IP and the domain name pointing IP to obtain merged IP information; exclude the content delivery network IP, parking IP and sinking IP in the merged IP information to obtain a white IP library.
[0021] Optionally, the score calculation module is also used to query the target data center in the IP hosting database; and to determine multiple autonomous system numbers to be evaluated based on the autonomous system number database and the target data center.
[0022] In addition, to achieve the above objectives, this application also proposes a threat assessment device, the device comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the threat assessment method as described above.
[0023] In addition, to achieve the above objectives, this application also proposes a storage medium, which is a computer-readable storage medium, on which a computer program is stored, which, when executed by a processor, implements the steps of the threat assessment method described above.
[0024] In addition, to achieve the above objectives, this application also provides a computer program product, which includes a computer program that, when executed by a processor, implements the steps of the threat assessment method described above.
[0025] One or more technical solutions proposed in this application have at least the following technical effects: This application generates a black IP database by performing IP cleaning based on the IP address of the command and control server used by the attacker, and a white IP database based on terminal access information. Threat scores are calculated for each Autonomous System Number (ASN) to be evaluated based on the black and white IP databases. The threat level of each ASN is assessed based on these threat scores, and a warning is issued based on the target ASN, which is an ASN with a threat level higher than a preset level. In this way, automatic threat assessment is achieved for all IPs within an ASN after the IP address of the command and control server used by the attacker is determined. This allows for the rapid selection of higher-threat IPs for further action, improving network security and the speed and accuracy of IP threat assessment. Attached Figure Description
[0026] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0027] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0028] Figure 1 This is a flowchart illustrating an embodiment of the threat assessment method of this application. Figure 2 This is a schematic diagram of the AS structure in one embodiment of the threat assessment method of this application; Figure 3 This is a simplified flowchart of one embodiment of the threat assessment method of this application; Figure 4 This is a flowchart illustrating Embodiment 2 of the threat assessment method of this application; Figure 5 This is a schematic diagram of the module structure of the threat assessment device according to an embodiment of this application; Figure 6 This is a schematic diagram of the device structure of the hardware operating environment involved in the threat assessment method in the embodiments of this application.
[0029] The purpose, features, and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0030] It should be understood that the specific embodiments described herein are merely illustrative of the technical solutions of this application and are not intended to limit this application.
[0031] To better understand the technical solution of this application, a detailed description will be provided below in conjunction with the accompanying drawings and specific implementation methods.
[0032] The main solution of this application embodiment is as follows: a black IP database is obtained by performing IP cleaning based on the IP address of the command and control server used by the attacker, and a white IP database is generated based on terminal access information; a threat score is calculated for each autonomous system number to be evaluated based on the black IP database and the white IP database; the threat level of each autonomous system number to be evaluated is evaluated based on the threat score, and a warning is issued based on the target autonomous system number, wherein the target autonomous system number is the autonomous system number to be evaluated whose threat level is higher than a preset level.
[0033] In this embodiment, for ease of description, the following description will use the identification computer as the execution subject.
[0034] Because existing technology uses Autonomous Systems (AS), which are combinations of IP networks and routers under the jurisdiction of one or more entities on the Internet, they enforce common routing policies on the Internet. Each AS can be understood as a post office, with many IP addresses under each AS. The ASes of each hosting provider are relatively fixed; that is, IPs from a particular provider belong to one or several ASs. Attackers' commonly used VPSs are also relatively fixed; new C2s within the same organization are highly likely to belong to the same hosting provider as historical C2s. However, because each AS contains a massive number of IPs, while it's possible to find the attacker's C2, it's not possible to perform a more accurate and rapid threat assessment based on the sheer number of IPs.
[0035] This application provides a solution that enables automatic threat assessment of all IPs within an Autonomous System ID after determining the command and control server IP used by the attacker. This allows for the rapid screening of higher-threat IPs for further action, improving network security and enhancing the speed and accuracy of IP threat assessment.
[0036] It should be noted that the executing entity in this embodiment can be a computing service device with data processing, network communication, and program execution functions, such as a tablet computer, personal computer, or mobile phone, or an electronic device or server capable of performing the above functions. The following description uses a computer as an example to illustrate this embodiment and the subsequent embodiments.
[0037] Based on this, embodiments of this application provide a threat assessment method, referring to... Figure 1 , Figure 1 This is a flowchart illustrating the first embodiment of the threat assessment method of this application.
[0038] In this embodiment, the threat assessment method includes steps S10 to S30: Step S10: Based on the IP address of the command and control server used by the attacker, perform IP cleaning to obtain a black IP database, and generate a white IP database based on terminal access information; It should be noted that an Autonomous System (AS) refers to a combination of IP networks and routers under the jurisdiction of one or more entities on the Internet, which enforce a common routing policy on the Internet. For example... Figure 2 As shown, each Autonomous System (AS) under a data center can be understood as a mail server, with many IP addresses under each AS. The ASs of each hosting provider are relatively fixed; that is, IPs from a particular provider belong to one or several ASs. Attackers' commonly used VPSs are also relatively fixed; new C2s within the same organization are highly likely to belong to the same hosting provider as historical C2s. Based on this assumption, an algorithm for assessing AS threat levels was implemented. The total number of IPv4 addresses on the internet is over 4 billion, of which over 700 million are owned by hosting providers. APT attackers typically rent VPSs within these IP ranges. The ASNs used by normal network services and those used by attackers usually do not overlap. This invention proposes an algorithm for assessing IP threat scores, as follows: Figure 3 As shown, this method can be used for initial screening when investigating a large number of IPs. Classifying IPs into five types based on threat level significantly reduces the workload of manual analysis.
[0039] It should be understood that the technical solution of this invention can calculate the threat level of unknown IPs. When investigating a large number of suspicious IPs, it can quickly classify IPs into 5 threat types, significantly reducing the workload of analysis and effectively improving the efficiency of network security analysts. It can be used as a preliminary investigation method. This method has the following advantages: Flexible algorithm: It can calculate in two modes: 1: DataCenter, divided by host vendor; 2: divided by ASN, which is more flexible. Adjustable blacklist range: Due to the smaller number of APT IPs, it is less likely to cause data noise like ordinary threat IPs. If only a few organizations are being focused on, the IPs of these organizations can be processed separately, resulting in higher model sensitivity and a lower false positive rate. Comprehensive data coverage: The whitelist dataset covers domestic (terminal data) and international (top 1 million domain name data), with a low false negative rate. High speed: The algorithm is simple and the query speed is fast, which can process massive amounts of IPs in a short time.
[0040] In practice, the attacker is first identified, and then the attacker's C2 IP, which is the IP address of the command and control server, can be determined. This allows the generation of corresponding black IP and white IP databases, which facilitates subsequent threat level analysis.
[0041] Step S20: Calculate the threat score for each autonomous system ID to be evaluated based on the black IP database and the white IP database; It should be noted that after obtaining the black IP database and the white IP database, the corresponding Autonomous System Number (ASN) is used to query and determine the number of overlapping IPs. Here, the Autonomous System to be evaluated is referred to as AS, and the ASN number is referred to as ASN.
[0042] In one feasible implementation, in order to determine multiple autonomous system numbers to be evaluated before performing threat score calculation, step S20 further includes: querying the target data center in the IP hosting database; and determining multiple autonomous system numbers to be evaluated based on the autonomous system number database and the target data center.
[0043] It should be understood that querying DataCenter in the IP Hosting database can yield the target data center. Then, querying ASN in the target data center and ASN database yields multiple Autonomous System Numbers to be evaluated. These can be ASNs within a selected range, all ASNs, or a specified number of ASNs randomly selected. This embodiment does not limit this.
[0044] In one feasible implementation, in order to accurately calculate the threat score, step S20 includes: querying each autonomous system number to be evaluated based on the black IP database and the white IP database, generating a white score and a black score corresponding to each autonomous system number to be evaluated; and determining the threat score corresponding to each autonomous system number to be evaluated based on the white score and the black score.
[0045] In practice, the number of black IPs and white IPs under each ASN and DataCenter is counted to generate white score and black score. In other words, the number of IPs in the black IP database and white IP database corresponding to all IPs under each ASN is determined, and then the white score and black score are determined.
[0046] It should be noted that after determining the white score and the black score, the white score is subtracted from the black score to obtain the final score, which ranges from -10 to 10. The lower the score, the higher the threat level.
[0047] In one feasible implementation, in order to accurately determine the white score and black score, the step of querying each autonomous system number to be evaluated based on the black IP database and the white IP database to generate the white score and black score corresponding to each autonomous system number to be evaluated includes: determining the number of black IPs that overlap with the black IP database in each autonomous system number to be evaluated; determining the number of white IPs that overlap with the white IP database in each autonomous system number to be evaluated; calculating the black score corresponding to each autonomous system number to be evaluated based on the number of black IPs that overlap; and calculating the white score corresponding to each autonomous system number to be evaluated based on the number of white IPs that overlap.
[0048] It should be understood that the process begins by fitting the black IP database to the autonomous system IDs to be evaluated, determining the number of overlapping black IPs for each ID, and similarly determining the number of overlapping white IPs. Scoring is then based on these numbers, resulting in black IP scores and white IP scores. The specific scoring method can be calculated as the percentage of overlapping IPs out of the total number of IPs.
[0049] Step S30: Assess the threat level of each Autonomous System ID to be assessed based on the threat score, and issue a warning based on the target Autonomous System ID, which is an Autonomous System ID to be assessed whose threat level is higher than a preset level.
[0050] In practice, after determining the threat score, the threat level of different Autonomous System Numbers to be evaluated is assessed based on the threat score. Then, based on the threat level, ASNs that need to be warned are selected as target Autonomous System Numbers. The preset level can be any specified level. For example, if there are 5 levels in total and the preset level is set to 4, then ASNs above level 4 are selected as target Autonomous System Numbers.
[0051] In one feasible implementation, in order to accurately issue warnings, step S30 includes: determining the score range of each autonomous system number to be evaluated based on the threat score; determining the threat level of each autonomous system number to be evaluated based on the score range; determining the target autonomous system number based on the threat level; and issuing a warning based on the target autonomous system number.
[0052] It should be noted that, firstly, the score range for each Autonomous System ID to be evaluated is determined based on the threat score, and then the threat level can be determined. Specifically, based on the score and the number of black and white IPs, the threat levels are divided into five categories (high risk, medium risk, ambiguous, low risk, and safe): a) High risk: A large number of black IPs have been detected, with no or only a few white IPs. This is highly likely a C2 attack and requires close monitoring.
[0053] b) Medium risk: Black IPs have appeared, but in small numbers; there are also a small number of white IPs, which can be partially assessed.
[0054] c) Ambiguous: There are no white IPs and black IPs, or the difference in the number of white and black IPs is not significant, so partial judgment is possible.
[0055] d) Low risk: mainly white IPs, in moderate numbers, with a small number of black IPs, but the probability of them being black IPs is relatively low.
[0056] Security: It's almost certainly a legitimate IP address; it's impossible for it to be a malicious IP address.
[0057] It should be understood that after determining the threat level, a warning is issued to the target Autonomous System Number (ASN), or if a certain ASN or Data Center is determined to be whitelisted, it can be added directly and set to whitelist. Based on the threat type, safe and low-risk threats are ignored, high-risk threats are given priority for assessment, and medium-risk and ambiguous threats are subject to partial random checks.
[0058] This embodiment provides a threat assessment method. It obtains a black IP database by performing IP cleaning based on the command and control server IP addresses used by attackers, and a white IP database by generating terminal access information. Threat scores are calculated for each Autonomous System Number (ASN) to be assessed based on the black and white IP databases. The threat level of each ASN is then assessed based on these threat scores, and a warning is issued for a target ASN, which is an ASN with a threat level higher than a preset level. This method enables automatic threat assessment of all IPs within an ASN after determining the command and control server IP used by the attacker. This allows for the rapid selection of higher-threat IPs for further action, improving network security and increasing the speed and accuracy of IP threat assessment.
[0059] Based on the first embodiment of this application, in the second embodiment of this application, the content that is the same as or similar to that in the first embodiment described above can be referred to the above description, and will not be repeated hereafter. Based on this, please refer to... Figure 4 Step S10 includes steps S101 to S102: Step S101: Query historical attack records to identify the attacker, and control the server IP address according to the attacker's commands to perform data cleaning and generate a black IP database. It should be noted that the first step is to query historical attack records to identify the attacker being targeted. Then, the attacker's corresponding C2 IP can be located, and data cleaning can be performed based on the C2 IP to obtain a black IP database.
[0060] In one feasible implementation, in order to accurately construct the black IP database, step S101 includes: querying historical attack records to identify the attacker and obtaining the command and control server used by the attacker; obtaining the command and control server IP address of the command and control server; and performing data cleaning based on the command and control server IP address to generate the black IP database.
[0061] It should be understood that the first step is to identify the command and control server used by the attacker, and then to clean up the C2 IPs (IP addresses of the command and control server) used by the attacker, thereby obtaining a black IP database. The cleaning process involves excluding some unwanted IPs.
[0062] In one feasible implementation, in order to obtain a black IP database, the steps of data cleaning based on the command and control server IP address to generate the black IP database include: collecting the content delivery network IP, parking IP, and sinking IP from the command and control server IP address; excluding the content delivery network IP, the parking IP, and the sinking IP from the command and control server IP address to obtain the black IP database.
[0063] In practice, CDN IPs (CDN is an abbreviation for Content Delivery Network) and Parking / Sinkhole IPs are excluded to generate a black IP database.
[0064] Step S102: Perform IP merging based on the terminal IP access volume corresponding to the terminal access information to obtain a white IP database.
[0065] In one feasible implementation, in order to obtain a white IP database, it is first necessary to determine the terminal access information and the number of IPs and domains accessed by the top users. Step S102 includes: determining the terminal IP access volume based on the terminal access information; determining the access volume ranking based on the terminal IP access volume; selecting terminal access IPs within a target ranking range based on the access volume ranking; obtaining terminal access domains within the target ranking range; and generating a white IP database based on the terminal access IPs and the terminal access domains.
[0066] It should be noted that, firstly, terminal access information is obtained from network data to determine the statistics of terminal access volume, and then the IPs within the target ranking range are selected as terminal access IPs, such as the IPs of the top 1 million and top 5 million.
[0067] It should be understood that the next step is to obtain the terminal access domain names corresponding to the target ranking range, that is, to select the corresponding number of domain names within the ranking range. For example, if the top 1 million IPs are selected, then the top 1 million domain names are filtered out.
[0068] In one feasible implementation, in order to accurately determine the white IP database based on the terminal access IP and the terminal access domain name, the step of generating the white IP database based on the terminal access IP and the terminal access domain name includes: determining multiple domain name pointing IPs according to the terminal access domain name; merging the terminal access IP and the domain name pointing IP to obtain merged IP information; excluding the content delivery network IP, parking IP and sinking IP in the merged IP information to obtain the white IP database.
[0069] In practice, the IPs pointing to the top 1 million terminal access IPs and the top 1 million domain names are merged, and then CDN IPs and Parking / Sinkhole IPs are excluded to generate a white IP database.
[0070] This embodiment identifies attackers by querying historical attack records and performs data cleansing based on the attacker's commands to control server IP addresses, generating a black IP database. IPs are then merged based on the terminal access volume corresponding to the terminal access information to obtain a white IP database. This method removes CDN IPs and Parking / Sinkhole IPs, preventing the generation of noisy data. Furthermore, by determining the threat level of an ASN based on threat scores and the number of black and white IPs, IPs can be quickly categorized into multiple levels, minimizing the number of IPs requiring analysis and significantly reducing manual operational costs.
[0071] It should be noted that the above examples are only for understanding this application and do not constitute a limitation on the threat assessment method of this application. Any simple modifications based on this technical concept are within the protection scope of this application.
[0072] This application also provides a threat assessment device, please refer to... Figure 5 The threat assessment device includes: The library generation module 10 is used to clean up IPs based on the IP address of the command and control server used by the attacker to obtain a black IP library, and to generate a white IP library based on terminal access information.
[0073] The score calculation module 20 is used to calculate the threat score for each autonomous system number to be evaluated based on the black IP database and the white IP database.
[0074] The threat alert module 30 is used to assess the threat level of each autonomous system number to be assessed based on the threat score, and to issue a warning alert based on the target autonomous system number, wherein the target autonomous system number is the autonomous system number to be assessed whose threat level is higher than a preset level.
[0075] This embodiment obtains a black IP database by performing IP cleaning based on the command and control server IP address used by the attacker, and a white IP database by generating a white IP database based on terminal access information. Threat scores are calculated for each Autonomous System Number (ASN) to be evaluated based on the black and white IP databases. The threat level of each ASN is assessed based on these threat scores, and a warning is issued for a target ASN, which is an ASN with a threat level higher than a preset level. In this way, automatic threat assessment is achieved for all IPs within an ASN after the command and control server IP used by the attacker is determined. This allows for the rapid selection of higher-threat IPs for further action, improving network security and the speed and accuracy of IP threat assessment.
[0076] In one embodiment, the library generation module 10 is further configured to query historical attack records to identify attackers, and perform data cleaning based on the attacker's command to control the server IP address to generate a black IP library; and merge IPs based on the terminal IP access volume corresponding to the terminal access information to obtain a white IP library.
[0077] In one embodiment, the library generation module 10 is further configured to query historical attack records to identify attackers and obtain the command and control server used by the attackers; obtain the command and control server IP address of the command and control server; and perform data cleaning based on the command and control server IP address to generate a black IP library.
[0078] In one embodiment, the library generation module 10 is further configured to collect the content delivery network IP, parking IP, and sinking IP from the command and control server IP address; exclude the content delivery network IP, parking IP, and sinking IP from the command and control server IP address to obtain a black IP library.
[0079] In one embodiment, the library generation module 10 is further configured to: determine the terminal IP access volume based on the terminal access information; determine the access volume ranking based on the terminal IP access volume; select terminal access IPs within a target ranking range based on the access volume ranking; obtain terminal access domain names within the target ranking range; and generate a white IP library based on the terminal access IPs and the terminal access domain names.
[0080] In one embodiment, the library generation module 10 is further configured to determine multiple domain name pointing IPs based on the terminal access domain name; merge the terminal access IP and the domain name pointing IP to obtain merged IP information; and exclude the content delivery network IP, parking IP and sinking IP in the merged IP information to obtain a white IP library.
[0081] In one embodiment, the score calculation module 20 is further configured to query the target data center in the IP hosting database; and determine multiple autonomous system numbers to be evaluated based on the autonomous system number database and the target data center.
[0082] In one embodiment, the score calculation module 20 is further configured to query each autonomous system number to be evaluated based on the black IP database and the white IP database, generate white scores and black scores corresponding to each autonomous system number to be evaluated, and determine the threat score corresponding to each autonomous system number to be evaluated based on the white scores and black scores.
[0083] In one embodiment, the score calculation module 20 is further configured to determine the number of black IPs that overlap with the black IP database in each autonomous system number to be evaluated; determine the number of white IPs that overlap with the white IP database in each autonomous system number to be evaluated; calculate the black score corresponding to each autonomous system number to be evaluated based on the number of black IP overlaps; and calculate the white score corresponding to each autonomous system number to be evaluated based on the number of white IP overlaps.
[0084] In one embodiment, the threat alert module 30 is further configured to determine the score range of each autonomous system number to be evaluated based on the threat score; determine the threat level of each autonomous system number to be evaluated based on the score range; determine the target autonomous system number based on the threat level; and issue a warning alert based on the target autonomous system number.
[0085] The threat assessment device provided in this application, employing the threat assessment method described in the above embodiments, can solve the technical problem of low efficiency in threat investigation of massive IP addresses. Compared with the prior art, the beneficial effects of the threat assessment device provided in this application are the same as those of the threat assessment method provided in the above embodiments, and other technical features in the threat assessment device are the same as those disclosed in the methods of the above embodiments, and will not be repeated here.
[0086] This application provides a threat assessment device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, which are executed by the at least one processor to enable the at least one processor to perform the threat assessment method in Embodiment 1 above.
[0087] The following is for reference. Figure 6 The diagram illustrates a structural schematic suitable for implementing the threat assessment device in the embodiments of this application. The threat assessment device in the embodiments of this application may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Description), PMPs (Portable Media Players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 6 The threat assessment device shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.
[0088] like Figure 6 As shown, the threat assessment device may include a processing unit 1001 (e.g., a central processing unit, a graphics processing unit, etc.) that can perform various appropriate actions and processes according to a program stored in ROM (Read Only Memory) 1002 or a program loaded from storage device 1003 into RAM (Random Access Memory) 1004. RAM 1004 also stores various programs and data required for the operation of the threat assessment device. The processing unit 1001, ROM 1002, and RAM 1004 are interconnected via bus 1005. Input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems can be connected to I / O interface 1006: input devices 1007 including, for example, touchscreens, touchpads, keyboards, mice, image sensors, microphones, accelerometers, gyroscopes, etc.; output devices 1008 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 1003 including, for example, magnetic tapes, hard disks, etc.; and communication devices 1009. Communication device 1009 allows the threat assessment device to communicate wirelessly or wiredly with other devices to exchange data. While the figure shows a threat assessment device with various systems, it should be understood that implementation or possession of all the systems shown is not required. More or fewer systems may be implemented alternatively.
[0089] Specifically, according to the embodiments disclosed in this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device, or installed from storage device 1003, or installed from ROM 1002. When the computer program is executed by processing device 1001, it performs the functions defined in the methods of the embodiments disclosed in this application.
[0090] The threat assessment device provided in this application, employing the threat assessment method described in the above embodiments, can solve the technical problem of low efficiency in threat investigation of massive IP addresses. Compared with the prior art, the beneficial effects of the threat assessment device provided in this application are the same as those of the threat assessment method provided in the above embodiments, and other technical features of this threat assessment device are the same as those disclosed in the previous embodiment method, and will not be repeated here.
[0091] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any suitable manner in one or more embodiments or examples.
[0092] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
[0093] This application provides a computer-readable storage medium having computer-readable program instructions (i.e., a computer program) stored thereon, the computer-readable program instructions being used to perform the threat assessment method in the above embodiments.
[0094] The computer-readable storage medium provided in this application may be, for example, a USB flash drive, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, system, or device. The program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.
[0095] The aforementioned computer-readable storage medium may be included in the threat assessment device; or it may exist independently and not be assembled into the threat assessment device.
[0096] The aforementioned computer-readable storage medium carries one or more programs. When these programs are executed by a threat assessment device, the threat assessment device performs the following actions: performs IP cleaning based on the IP address of the command and control server used by the attacker to obtain a black IP database, and generates a white IP database based on terminal access information; calculates a threat score for each Autonomous System Number (ASN) to be assessed based on the black IP database and the white IP database; assesses the threat level of each ASN to be assessed based on the threat score, and issues a warning based on a target ASN, where the target ASN is an ASN to be assessed with a threat level higher than a preset level.
[0097] Computer program code for performing the operations of this application can be written in one or more programming languages or a combination thereof. These programming languages include object-oriented programming languages—such as Python, Java, Smalltalk, and C++—and conventional procedural programming languages—such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a Local Area Network (LAN) or a Wide Area Network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0098] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0099] The modules described in the embodiments of this application can be implemented in software or hardware. The names of the modules do not necessarily limit the functionality of the unit itself.
[0100] The readable storage medium provided in this application is a computer-readable storage medium that stores computer-readable program instructions (i.e., computer programs) for executing the above-described threat assessment method, thereby solving the technical problem of low efficiency in threat investigation of massive IP addresses. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided in this application are the same as those of the threat assessment method provided in the above embodiments, and will not be repeated here.
[0101] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the threat assessment method described above.
[0102] The computer program product provided in this application can solve the technical problem of low efficiency in threat investigation of massive IP addresses. Compared with the prior art, the beneficial effects of the computer program product provided in this application are the same as those of the threat assessment method provided in the above embodiments, and will not be repeated here.
[0103] The above description is only a part of the embodiments of this application and does not limit the patent scope of this application. All equivalent structural transformations made under the technical concept of this application and using the contents of the specification and drawings of this application, or direct / indirect applications in other related technical fields, are included in the patent protection scope of this application.
[0104] This invention discloses A1. A threat assessment method, the method comprising: A black IP database is obtained by cleaning up IPs based on the IP addresses of command and control servers used by attackers, and a white IP database is generated based on terminal access information. Threat scores are calculated for each autonomous system ID to be evaluated based on the black IP database and the white IP database. The threat level of each Autonomous System ID to be evaluated is assessed based on the threat score, and a warning is issued based on the target Autonomous System ID, which is an Autonomous System ID to be evaluated whose threat level is higher than a preset level.
[0105] A2. As described in A1, the steps of obtaining a black IP database by IP cleaning based on the IP address of the command and control server used by the attacker, and generating a white IP database based on terminal access information, include: By querying historical attack records to identify attackers, and by controlling server IP addresses according to the attackers' commands to perform data cleansing and generate a black IP database; IPs are merged based on the terminal IP access volume corresponding to the terminal access information to obtain a white IP database.
[0106] A3. As described in A2, the steps of querying historical attack records to identify the attacker, and controlling the server IP address according to the attacker's commands to perform data cleaning and generate a black IP database include: By querying historical attack records, the attacker can be identified, and the command and control server used by the attacker can be obtained. Obtain the command and control server IP address; Data is cleaned based on the command control server IP address to generate a black IP database.
[0107] A4. As described in A3, the step of performing data cleaning based on the command control server IP address to generate a black IP database includes: Collect the content delivery network IP, parking IP, and sinking IP from the IP address of the command and control server; The black IP database is obtained by excluding the content distribution network IP, the parking IP, and the sinking IP from the command and control server IP address.
[0108] A5. As described in A2, the step of merging IPs based on the terminal IP access volume corresponding to the terminal access information to obtain a white IP database includes: The terminal IP access volume is determined based on the terminal access information. The ranking of access volume is determined based on the access volume of the terminal IP address. Select terminal access IPs within the target ranking range based on the access volume ranking; Obtain the terminal access domains within the target ranking range; A white IP database is generated based on the terminal access IP and the terminal access domain name.
[0109] A6. As described in A5, the step of generating a white IP database based on the terminal access IP and the terminal access domain name includes: Based on the terminal access domain name, multiple domain names are determined to point to IP addresses; The terminal access IP and the domain name pointing to the IP are merged to obtain merged IP information; By excluding content delivery network IPs, parking IPs, and sinking IPs from the merged IP information, a white IP database is obtained.
[0110] A7. As described in A1, the step of calculating the threat score for each autonomous system ID to be evaluated based on the black IP database and the white IP database further includes the following before the step of: Search for the target data center in the IP hosting database; Based on the Autonomous System Number (ASN) database and the target data center, multiple ASNs to be evaluated are identified.
[0111] A8. As described in A1, the step of calculating a threat score for each autonomous system ID to be evaluated based on the black IP database and the white IP database includes: Based on the black IP database and the white IP database, query each autonomous system number to be evaluated, and generate the white score and black score corresponding to each autonomous system number to be evaluated; The threat score corresponding to each autonomous system number to be evaluated is determined based on the white score and the black score.
[0112] A9. As described in A8, the step of querying each Autonomous System ID to be evaluated based on the black IP database and the white IP database, and generating the white score and black score corresponding to each Autonomous System ID to be evaluated, includes: Determine the number of black IPs in each autonomous system number to be evaluated that overlap with the black IP database; Determine the number of white IPs that overlap with the white IP database in each autonomous system number to be evaluated; The black score corresponding to each autonomous system number to be evaluated is calculated based on the number of overlapping black IPs, and the white score corresponding to each autonomous system number to be evaluated is calculated based on the number of overlapping white IPs.
[0113] A10. The method as described in any one of A1-A9, wherein the step of assessing the threat level of each Autonomous System ID to be assessed based on the threat score and issuing a warning based on the target Autonomous System ID includes: The score range for each autonomous system number to be evaluated is determined based on the threat score; The threat level of each autonomous system number to be evaluated is determined based on the aforementioned score range; The target autonomous system number is determined based on the threat level, and a warning is issued based on the target autonomous system number.
[0114] The present invention also discloses B11. A threat assessment device, the device comprising: The library generation module is used to clean up IPs based on the IP addresses of command and control servers used by attackers to obtain a black IP library, and to generate a white IP library based on terminal access information. The score calculation module is used to calculate the threat score for each autonomous system ID to be evaluated based on the black IP database and the white IP database. The threat alert module is used to assess the threat level of each Autonomous System Number to be assessed based on the threat score, and to issue a warning alert based on the target Autonomous System Number, which is an Autonomous System Number to be assessed whose threat level is higher than a preset level.
[0115] B12. In the threat assessment device described in B11, the database generation module is further configured to query historical attack records to identify attackers, and to perform data cleaning based on the attacker's command to control the server IP address to generate a black IP database; and to merge IPs based on the terminal IP access volume corresponding to the terminal access information to obtain a white IP database.
[0116] B13. In the threat assessment device described in B12, the database generation module is further configured to query historical attack records to identify attackers, obtain the command and control server used by the attackers; obtain the command and control server IP address of the command and control server; and perform data cleaning based on the command and control server IP address to generate a black IP database.
[0117] B14. The threat assessment device as described in B13, wherein the library generation module is further configured to collect the content delivery network IP, parking IP, and sinking IP from the command and control server IP address; exclude the content delivery network IP, parking IP, and sinking IP from the command and control server IP address to obtain a black IP library.
[0118] B15. The threat assessment device as described in B12, wherein the library generation module is further configured to: determine the terminal IP access volume based on the terminal access information; determine the access volume ranking based on the terminal IP access volume; select terminal access IPs within a target ranking range based on the access volume ranking; obtain terminal access domain names within the target ranking range; and generate a white IP library based on the terminal access IPs and the terminal access domain names.
[0119] B16. The threat assessment device as described in B15, wherein the library generation module is further configured to determine multiple domain name pointing IPs based on the terminal access domain name; merge the terminal access IP and the domain name pointing IP to obtain merged IP information; exclude content delivery network IPs, parking IPs and sinking IPs from the merged IP information to obtain a white IP library.
[0120] B17. The threat assessment apparatus as described in B11, wherein the score calculation module is further configured to query the target data center in the IP hosting database; and to determine multiple autonomous system numbers to be assessed based on the autonomous system number database and the target data center.
[0121] The present invention also discloses C18. A threat assessment device, the device comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the threat assessment method as described above.
[0122] The present invention also discloses D19. A storage medium, which is a computer-readable storage medium, wherein a computer program is stored on the storage medium, and the computer program, when executed by a processor, implements the steps of the threat assessment method as described above.
[0123] The present invention also discloses E20. A computer program product comprising a computer program that, when executed by a processor, implements the steps of the threat assessment method as described above.
Claims
1. A threat assessment method, characterized in that, The method includes: A black IP database is obtained by cleaning up IPs based on the IP addresses of command and control servers used by attackers, and a white IP database is generated based on terminal access information. Threat scores are calculated for each autonomous system ID to be evaluated based on the black IP database and the white IP database. The threat level of each Autonomous System ID to be evaluated is assessed based on the threat score, and a warning is issued based on the target Autonomous System ID, which is an Autonomous System ID to be evaluated whose threat level is higher than a preset level.
2. The method as described in claim 1, characterized in that, The steps of obtaining a black IP database by performing IP cleaning based on the IP address of the command and control server used by the attacker, and generating a white IP database based on terminal access information, include: By querying historical attack records to identify attackers, and by controlling server IP addresses according to the attackers' commands to perform data cleansing and generate a black IP database; IPs are merged based on the terminal IP access volume corresponding to the terminal access information to obtain a white IP database.
3. The method as described in claim 2, characterized in that, The steps of querying historical attack records to identify attackers and controlling server IP addresses to perform data cleaning based on the attackers' commands to generate a black IP database include: By querying historical attack records, the attacker can be identified, and the command and control server used by the attacker can be obtained. Obtain the command and control server IP address; Data is cleaned based on the command control server IP address to generate a black IP database.
4. The method as described in claim 3, characterized in that, The step of cleaning data based on the command control server IP address to generate a black IP database includes: Collect the content delivery network IP, parking IP, and sinking IP from the IP address of the command and control server; The black IP database is obtained by excluding the content distribution network IP, the parking IP, and the sinking IP from the command and control server IP address.
5. The method as described in claim 2, characterized in that, The step of merging IPs based on the terminal IP access volume corresponding to the terminal access information to obtain a white IP database includes: The terminal IP access volume is determined based on the terminal access information. The ranking of access volume is determined based on the access volume of the terminal IP address. Select terminal access IPs within the target ranking range based on the access volume ranking; Obtain the terminal access domains within the target ranking range; A white IP database is generated based on the terminal access IP and the terminal access domain name.
6. The method as described in claim 5, characterized in that, The step of generating a white IP database based on the terminal access IP and the terminal access domain name includes: Based on the terminal access domain name, multiple domain names are determined to point to IP addresses; The terminal access IP and the domain name pointing to the IP are merged to obtain merged IP information; By excluding content delivery network IPs, parking IPs, and sinking IPs from the merged IP information, a white IP database is obtained.
7. A threat assessment device, characterized in that, The device includes: The library generation module is used to clean up IPs based on the IP addresses of command and control servers used by attackers to obtain a black IP library, and to generate a white IP library based on terminal access information. The score calculation module is used to calculate the threat score for each autonomous system ID to be evaluated based on the black IP database and the white IP database. The threat alert module is used to assess the threat level of each Autonomous System Number to be assessed based on the threat score, and to issue a warning alert based on the target Autonomous System Number, which is an Autonomous System Number to be assessed whose threat level is higher than a preset level.
8. A threat assessment device, characterized in that, The device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the threat assessment method as described in any one of claims 1 to 6.
9. A storage medium, characterized in that, The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, it implements the steps of the threat assessment method as described in any one of claims 1 to 6.
10. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the steps of the threat assessment method as described in any one of claims 1 to 6.