Vulnerability early warning system and method based on threat intelligence
By using a vulnerability early warning system based on threat intelligence, the problems of lagging and low analysis efficiency of traditional vulnerability early warning methods have been solved. This system enables accurate quantitative analysis and timely early warning of network devices, thereby improving network security management capabilities.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-25
- Publication Date
- 2026-04-17
AI Technical Summary
Traditional vulnerability alert methods cannot respond to emerging threats and unknown vulnerabilities in a timely manner, have low analysis efficiency, lack in-depth mining and quantitative analysis of threat intelligence data, and cannot adapt to complex and ever-changing network attack scenarios.
The vulnerability early warning system based on threat intelligence acquires multiple sets of threat intelligence data through a data acquisition module, analyzes and calculates vulnerability threat metrics through a threat determination module, performs multi-source splitting through a threat calculation module, and determines whether to issue an early warning based on the multi-source vulnerability threat coefficients, including data preprocessing to remove duplicate, erroneous, and invalid data.
It enables precise quantitative analysis of network devices, improves the accuracy and efficiency of vulnerability early warning analysis, ensures overall control of cyberspace security, and provides solid technical support for network security management.
Smart Images

Figure CN121887428A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of cybersecurity technology, and more specifically, to a vulnerability early warning system and method based on threat intelligence. Background Technology
[0002] In the current network environment, network devices face increasingly severe security threats, especially the potential risks of various unknown vulnerabilities.
[0003] Traditional vulnerability alerting methods primarily rely on regular security scans and matching against known vulnerability databases. This approach suffers from significant lag, failing to provide timely and effective responses to emerging threats and unknown vulnerabilities. This is mainly manifested in: diverse threat data sources and inconsistent formats, leading to low analysis efficiency; a lack of in-depth mining and quantitative analysis of threat intelligence data, making it difficult to accurately assess the actual threat level of vulnerabilities; and a simplistic alerting mechanism that cannot adapt to complex and ever-changing network attack scenarios. Summary of the Invention
[0004] This invention provides a vulnerability early warning system and method based on threat intelligence, which can effectively integrate multi-source threat intelligence, achieve accurate quantitative analysis of network devices, ensure the accuracy and efficiency of vulnerability early warning analysis, and thus control the overall cyberspace security, providing security technology support for network security management capabilities.
[0005] To achieve the above objectives, the present invention provides a vulnerability early warning system based on threat intelligence, comprising: The data acquisition module is used to pre-set multiple vulnerability detection time points, acquire multiple sets of threat intelligence data corresponding to network devices based on all vulnerability detection time points, and determine multiple threat intelligence data sequences based on all threat intelligence data. The threat determination module is used to analyze each threat intelligence data sequence and determine the vulnerability threat metric of the network device based on the analysis results. The threat calculation module is used to perform multi-source splitting of all vulnerability threat metrics and calculate the multi-source vulnerability threat coefficient of the network device. The vulnerability warning module is used to pre-set a preset multi-source vulnerability threat coefficient, and determine whether to issue a vulnerability warning to the network device based on the relationship between the multi-source vulnerability threat coefficient and the preset multi-source vulnerability threat coefficient.
[0006] Furthermore, it also includes: The data preprocessing module is used to traverse and preprocess all threat intelligence data, wherein the preprocessing includes deleting duplicate threat intelligence data, deleting erroneous threat intelligence data, and deleting invalid threat intelligence data.
[0007] Furthermore, the threat determination module is used for: The threat determination module is used to obtain the threat intelligence data range corresponding to the threat intelligence data sequence, wherein the threat intelligence data range includes a first preset threat intelligence data and a second preset threat intelligence data, and the first preset threat intelligence data is smaller than the second preset threat intelligence data. The threat determination module is used to partition the threat intelligence data sequence based on the first preset threat intelligence data being less than the second preset threat intelligence data. When the threat intelligence data in the threat intelligence data sequence is less than the first preset threat intelligence data, the corresponding threat intelligence data is assigned to the first threat intelligence data area. The threat determination module is used to classify the corresponding threat intelligence data into the second threat intelligence data area when the threat intelligence data in the threat intelligence data sequence is greater than or equal to the first preset threat intelligence data and less than the second preset threat intelligence data. The threat determination module is used to divide the corresponding threat intelligence data into the third threat intelligence data area when the threat intelligence data in the threat intelligence data sequence is greater than or equal to the second preset threat intelligence data. The threat determination module is used to determine the vulnerability threat metric of the network device based on the first threat intelligence data area, the threat intelligence data area and the third threat intelligence data area.
[0008] Furthermore, the threat determination module is used for: The threat determination module is used to merge the first threat intelligence data area and the third threat intelligence data area to obtain a comprehensive threat intelligence data area; The threat determination module is used to determine the vulnerability threat metric of the network device according to the following formula: ; Where q is the vulnerability threat metric of the network device, a is the number of threat intelligence data in the comprehensive threat intelligence data area, s1 is the first preset threat intelligence data, s2 is the second preset threat intelligence data, and d w To synthesize the w-th threat intelligence data in the threat intelligence data area, c1 represents the number of threat intelligence data in the first threat intelligence data area, c2 represents the number of threat intelligence data in the second threat intelligence data area, and c3 represents the number of threat intelligence data in the third threat intelligence data area.
[0009] Furthermore, the threat calculation module is used for: The threat calculation module is used to extract the same vulnerability threat metric value from all vulnerability threat metrics and calculate the smooth threat coefficient of the network device; The threat calculation module is used to extract the different vulnerability threat metrics from all vulnerability threat metrics and calculate the fluctuation threat coefficient of the network device; The threat calculation module is used to perform a weighted summation of the smooth threat coefficient and the fluctuating threat coefficient to obtain the multi-source vulnerability threat coefficient of the network device.
[0010] Furthermore, the threat calculation module is used for: The threat calculation module is used to obtain multiple sets of vulnerability threat metric values based on the same vulnerability threat metric value; The threat calculation module is used to count the number of the first vulnerability threat metric set in the vulnerability threat metric set; The threat calculation module is used to extract a vulnerability threat metric from each of the sets of vulnerability threat metrics, and to calculate the first vulnerability threat metric and the value. The threat calculation module is used to calculate the average vulnerability threat metric value of all the same vulnerability threat metric values, remove all vulnerability threat metric value sets that are less than the average vulnerability threat metric value, and count the number of second vulnerability threat metric value sets of the remaining vulnerability threat metric value sets. The threat calculation module is used to extract one vulnerability threat metric value from the remaining vulnerability threat metric value set, and to calculate the second vulnerability threat metric value set and value; The threat calculation module is used to calculate the smooth threat coefficient of the network device based on the number of the first vulnerability threat metric set, the number of the second vulnerability threat metric set, the sum of the first vulnerability threat metric value and the sum of the second vulnerability threat metric value.
[0011] Furthermore, the threat calculation module is used for: The threat calculation module is used to construct a vulnerability threat metric curve based on all the different vulnerability threat metric values; The threat calculation module is used to determine the maximum slope corresponding to the vulnerability threat metric curve and to determine the standard deviation of the vulnerability threat metric for all different vulnerability threat metric values. The threat calculation module is used to take the product of the maximum slope and the standard deviation of the vulnerability threat metric as the fluctuation threat coefficient of the network device.
[0012] Furthermore, the vulnerability warning module is used for: The vulnerability warning module is used to determine that no vulnerability warning will be issued to the network device when the multi-source vulnerability threat coefficient is less than the preset multi-source vulnerability threat coefficient. The vulnerability warning module is used to determine and issue a vulnerability warning to the network device when the multi-source vulnerability threat coefficient is greater than or equal to the preset multi-source vulnerability threat coefficient.
[0013] To achieve the above objectives, the present invention also provides a vulnerability early warning method based on threat intelligence, comprising: Multiple vulnerability detection time points are pre-set, and multiple sets of threat intelligence data corresponding to network devices are obtained based on all vulnerability detection time points. Multiple threat intelligence data sequences are determined based on all threat intelligence data. Each threat intelligence data sequence is analyzed, and a vulnerability threat metric for the network device is determined based on the analysis results. All vulnerability threat metrics are split into multiple sources, and the multi-source vulnerability threat coefficient of the network device is calculated. A preset multi-source vulnerability threat coefficient is set in advance. Based on the relationship between the multi-source vulnerability threat coefficient and the preset multi-source vulnerability threat coefficient, it is determined whether to issue a vulnerability warning to the network device.
[0014] Furthermore, before determining multiple threat intelligence data sequences based on all threat intelligence data, the process also includes: All threat intelligence data is traversed and preprocessed, wherein the preprocessing includes deleting duplicate threat intelligence data, deleting erroneous threat intelligence data, and deleting invalid threat intelligence data.
[0015] Compared with the prior art, the beneficial effects of the present invention are as follows: This invention discloses a vulnerability early warning system and method based on threat intelligence. The system includes: a data acquisition module that acquires multiple sets of threat intelligence data corresponding to network devices based on all vulnerability detection time points, and determines multiple threat intelligence data sequences based on all the threat intelligence data; a threat determination module that analyzes each threat intelligence data sequence to determine the vulnerability threat metric of the network device; a threat calculation module that performs multi-source splitting on all vulnerability threat metrics and calculates the multi-source vulnerability threat coefficient of the network device; and a vulnerability early warning module that determines whether to issue a vulnerability early warning to the network device based on the relationship between the multi-source vulnerability threat coefficient and a preset multi-source vulnerability threat coefficient. This system can effectively integrate multi-source threat intelligence, achieve accurate quantitative analysis of network devices, ensure the accuracy and efficiency of vulnerability early warning analysis, and thus control the overall cyberspace security, providing security technology support for network security management capabilities. Attached Figure Description
[0016] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the invention. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings: Figure 1A schematic diagram of the vulnerability early warning system based on threat intelligence in an embodiment of the present invention is shown; Figure 2 A flowchart illustrating a vulnerability warning method based on threat intelligence in an embodiment of the present invention is shown. Detailed Implementation
[0017] The specific embodiments of the present invention will be described in further detail below with reference to the accompanying drawings and examples. The following examples are for illustrative purposes only and are not intended to limit the scope of the invention.
[0018] In the description of this application, it should be understood that the terms "center", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are only for the convenience of describing this application and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on this application.
[0019] The terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this application, unless otherwise stated, "a plurality of" means two or more.
[0020] In the description of this application, it should be noted that, unless otherwise expressly specified and limited, the terms "installation," "connection," and "linking" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection between two components. Those skilled in the art can understand the specific meaning of the above terms in this application based on the specific circumstances.
[0021] The following is a description of preferred embodiments of the present invention in conjunction with the accompanying drawings.
[0022] like Figure 1 As shown, embodiments of the present invention disclose a vulnerability early warning system based on threat intelligence, including: a data acquisition module, a threat determination module, a threat calculation module, and a vulnerability early warning module.
[0023] In some embodiments of this application, the data acquisition module is used to pre-set multiple vulnerability detection time points, acquire multiple sets of threat intelligence data corresponding to network devices based on all vulnerability detection time points, and determine multiple threat intelligence data sequences based on all threat intelligence data. In this embodiment, the vulnerability detection time points are preset and refer to specific times. The number of vulnerability detection time points is preferably 20, including the 2nd second, the 4th second, the 6th second, the 8th second, the 10th second, the 12th second, the 14th second, the 16th second, the 18th second, the 20th second, the 22nd second, the 24th second, the 26th second, the 28th second, the 30th second, the 32nd second, the 34th second, the 36th second, the 38th second, and the 40th second.
[0024] In this embodiment, each vulnerability detection time point includes a set of threat intelligence data, including abnormal traffic rate, connection failure frequency, abnormal CPU usage rate, login failure rate, etc., which are not shown one by one here.
[0025] In this embodiment, when determining multiple threat intelligence data sequences based on all threat intelligence data, the process includes: extracting the same type of threat intelligence data from each group of threat intelligence data to construct a threat intelligence data sequence. For example, extracting the traffic anomaly rate from each group of threat intelligence data to construct a threat intelligence data sequence that only includes the traffic anomaly rate. Threat intelligence data sequences related to connection failure frequency can also be obtained. The remaining ones will not be shown one by one.
[0026] In some embodiments of this application, it also includes: The data preprocessing module is used to traverse and preprocess all threat intelligence data, wherein the preprocessing includes deleting duplicate threat intelligence data, deleting erroneous threat intelligence data, and deleting invalid threat intelligence data.
[0027] The beneficial effects of the above technical solution are: by traversing and preprocessing threat intelligence data, duplicate, erroneous and invalid data can be effectively eliminated, ensuring that the threat intelligence data used in subsequent analysis is accurate and reliable, and avoiding analytical bias caused by data quality issues.
[0028] In some embodiments of this application, a threat determination module is used to analyze each threat intelligence data sequence and determine the vulnerability threat metric of the network device based on the analysis results; In some embodiments of this application, the threat determination module is used for: The threat determination module is used to obtain the threat intelligence data range corresponding to the threat intelligence data sequence, wherein the threat intelligence data range includes a first preset threat intelligence data and a second preset threat intelligence data, and the first preset threat intelligence data is smaller than the second preset threat intelligence data. The threat determination module is used to partition the threat intelligence data sequence based on the first preset threat intelligence data being less than the second preset threat intelligence data. When the threat intelligence data in the threat intelligence data sequence is less than the first preset threat intelligence data, the corresponding threat intelligence data is assigned to the first threat intelligence data area. The threat determination module is used to classify the corresponding threat intelligence data into the second threat intelligence data area when the threat intelligence data in the threat intelligence data sequence is greater than or equal to the first preset threat intelligence data and less than the second preset threat intelligence data. The threat determination module is used to divide the corresponding threat intelligence data into the third threat intelligence data area when the threat intelligence data in the threat intelligence data sequence is greater than or equal to the second preset threat intelligence data. The threat determination module is used to determine the vulnerability threat metric of the network device based on the first threat intelligence data area, the threat intelligence data area and the third threat intelligence data area.
[0029] In this embodiment, the threat intelligence data range corresponding to each threat intelligence data sequence is different, specifically determined according to the type of threat intelligence data sequence, that is, based on traffic anomaly rate, connection failure frequency, abnormal CPU utilization rate, and login failure rate. The threat intelligence data range refers to the allowable fluctuation range of network devices.
[0030] The beneficial effects of the above technical solution are as follows: By dividing the threat intelligence data sequence into three data areas according to different threat levels, and then determining the vulnerability threat metric of network devices based on the first threat intelligence data area, the third threat intelligence data area, and the third threat intelligence data area, the present invention can more accurately quantify the vulnerability threats faced by network devices, provide a reliable data foundation for subsequent threat calculation, and thus improve the accuracy of vulnerability warning.
[0031] In some embodiments of this application, the threat determination module is used for: The threat determination module is used to merge the first threat intelligence data area and the third threat intelligence data area to obtain a comprehensive threat intelligence data area; The threat determination module is used to determine the vulnerability threat metric of the network device according to the following formula: ; Where q is the vulnerability threat metric of the network device, a is the number of threat intelligence data in the comprehensive threat intelligence data area, s1 is the first preset threat intelligence data, s2 is the second preset threat intelligence data, and d wTo synthesize the w-th threat intelligence data in the threat intelligence data area, c1 represents the number of threat intelligence data in the first threat intelligence data area, c2 represents the number of threat intelligence data in the second threat intelligence data area, and c3 represents the number of threat intelligence data in the third threat intelligence data area.
[0032] In this embodiment, the threat intelligence data corresponding to the first threat intelligence data area and the third threat intelligence data area are relatively extreme. By merging these two areas, the extreme threat situation faced by network devices can be reflected more comprehensively.
[0033] In some embodiments of this application, the threat calculation module is used to perform multi-source splitting of all vulnerability threat metrics and calculate the multi-source vulnerability threat coefficient of the network device; In some embodiments of this application, the threat calculation module is used for: The threat calculation module is used to extract the same vulnerability threat metric value from all vulnerability threat metrics and calculate the smooth threat coefficient of the network device; The threat calculation module is used to extract the different vulnerability threat metrics from all vulnerability threat metrics and calculate the fluctuation threat coefficient of the network device; The threat calculation module is used to perform a weighted summation of the smooth threat coefficient and the fluctuating threat coefficient to obtain the multi-source vulnerability threat coefficient of the network device.
[0034] In this embodiment, multi-source splitting means splitting all vulnerability threat metrics into identical vulnerability threat metrics and different vulnerability threat metrics.
[0035] In this embodiment, if the vulnerability threat metric values include 2.2, 2.5, 2.5, 2.5, 2.6, 2.6, 2.7, 2.8, 2.8, 2.8, and 2.9, then the same vulnerability threat metric values are {2.5, 2.5, 2.5}, {2.6, 2.6}, and {2.8, 2.8, 2.8}, while different vulnerability threat metric values are 2.2, 2.7, and 2.9. This is provided as an example for ease of understanding, and adjustments should be made based on the actual calculation situation.
[0036] In this embodiment, the smooth threat coefficient and the volatile threat coefficient are weighted based on subjective weighting and objective weighting methods. Here, the weight of the smooth threat coefficient is preferably 0.4, and the weight of the volatile threat coefficient is preferably 0.6. The specific weights can be adjusted according to actual needs.
[0037] The beneficial effects of the above technical solution are as follows: by extracting the same and different metrics from all vulnerability threat metrics, calculating the smooth threat coefficient and the fluctuating threat coefficient separately, and then weighting and summing the two based on the weighting method, it can comprehensively and accurately reflect the multi-source vulnerability threat situation faced by network devices. This comprehensive consideration of different types of threat coefficients helps to more accurately assess the security status of network devices, providing solid and reliable data support for subsequent vulnerability early warning, and further improving the accuracy and effectiveness of vulnerability early warning.
[0038] In some embodiments of this application, the threat calculation module is used for: The threat calculation module is used to obtain multiple sets of vulnerability threat metric values based on the same vulnerability threat metric value; The threat calculation module is used to count the number of the first vulnerability threat metric set in the vulnerability threat metric set; The threat calculation module is used to extract a vulnerability threat metric from each of the sets of vulnerability threat metrics, and to calculate the first vulnerability threat metric and the value. The threat calculation module is used to calculate the average vulnerability threat metric value of all the same vulnerability threat metric values, remove all vulnerability threat metric value sets that are less than the average vulnerability threat metric value, and count the number of second vulnerability threat metric value sets of the remaining vulnerability threat metric value sets. The threat calculation module is used to extract one vulnerability threat metric value from the remaining vulnerability threat metric value set, and to calculate the second vulnerability threat metric value set and value; The threat calculation module is used to calculate the smooth threat coefficient of the network device based on the number of the first vulnerability threat metric set, the number of the second vulnerability threat metric set, the sum of the first vulnerability threat metric value and the sum of the second vulnerability threat metric value.
[0039] In this embodiment, the vulnerability threat metrics in each vulnerability threat metric set are the same, but the vulnerability threat metrics between each vulnerability threat metric set are different.
[0040] In this embodiment, the smooth threat coefficient of the network device is calculated according to the following formula: ; Where g is the smooth threat coefficient of the network device, k1 is the number of the first vulnerability threat metric set, k2 is the number of the second vulnerability threat metric set, j1 is the sum of the first vulnerability threat metric and j2 is the sum of the second vulnerability threat metric.
[0041] The beneficial effects of the above technical solution are as follows: The present invention calculates the smooth threat coefficient of network devices based on the number of the first vulnerability threat measurement value set, the number of the second vulnerability threat measurement value set, the sum of the first vulnerability threat measurement value and the sum of the second vulnerability threat measurement value. This can more accurately measure the stability and consistency of network devices under the same threat conditions. The smooth threat coefficient reflects the overall performance of network devices when facing similar threats, providing an important reference indicator for subsequent security assessment and early warning. It helps to discover potential security problems in network devices in a timely manner, and then take effective measures to prevent and deal with them.
[0042] In some embodiments of this application, the threat calculation module is used for: The threat calculation module is used to construct a vulnerability threat metric curve based on all the different vulnerability threat metric values; The threat calculation module is used to determine the maximum slope corresponding to the vulnerability threat metric curve and to determine the standard deviation of the vulnerability threat metric for all different vulnerability threat metric values. The threat calculation module is used to take the product of the maximum slope and the standard deviation of the vulnerability threat metric as the fluctuation threat coefficient of the network device.
[0043] The beneficial effects of the above technical solution are as follows: using the product of the maximum slope and the standard deviation of the vulnerability threat metric as the fluctuation threat coefficient of the network device can accurately capture the fluctuation characteristics of the network device under different threat conditions. The maximum slope reflects the drastic change in the vulnerability threat metric, while the standard deviation of the vulnerability threat metric reflects the dispersion of the data. The fluctuation threat coefficient obtained by multiplying the two can comprehensively and accurately quantify the fluctuation of the network device when facing threats. This is crucial for evaluating the security performance of network devices in complex and ever-changing network environments, providing security personnel with important information on the changing trends of the network device's security status, helping to identify potential security risks in advance, and taking timely countermeasures, thereby effectively improving the security protection capabilities of network devices.
[0044] In some embodiments of this application, the vulnerability warning module is used to pre-set a preset multi-source vulnerability threat coefficient, and determine whether to issue a vulnerability warning to the network device based on the relationship between the multi-source vulnerability threat coefficient and the preset multi-source vulnerability threat coefficient.
[0045] In some embodiments of this application, the vulnerability warning module is used for: The vulnerability warning module is used to determine that no vulnerability warning will be issued to the network device when the multi-source vulnerability threat coefficient is less than the preset multi-source vulnerability threat coefficient. The vulnerability warning module is used to determine and issue a vulnerability warning to the network device when the multi-source vulnerability threat coefficient is greater than or equal to the preset multi-source vulnerability threat coefficient.
[0046] In this embodiment, the preset multi-source vulnerability threat coefficient is preferably 1.5, but it can be adjusted adaptively according to actual needs.
[0047] The beneficial effects of the above technical solution are as follows: This invention determines whether to issue a vulnerability warning to a network device based on the relationship between the multi-source vulnerability threat coefficient and a preset multi-source vulnerability threat coefficient. It has clear judgment criteria and operability, enabling timely and accurate warnings of vulnerability threats faced by network devices. When the multi-source vulnerability threat coefficient is less than the preset value, it indicates that the current security status of the network device is relatively stable, and no warning is needed. However, when the multi-source vulnerability threat coefficient is greater than or equal to the preset value, it indicates that the network device faces a relatively serious vulnerability threat. Issuing a timely warning in this case helps security personnel to quickly take countermeasures, prevent further deterioration of the security incident, and thus effectively ensure the secure operation of the network device.
[0048] To further illustrate the technical concept of this invention, the technical solution of this invention will now be described in conjunction with specific application scenarios.
[0049] Correspondingly, such as Figure 2 As shown, this application also provides a vulnerability early warning method based on threat intelligence, including: S110: Pre-set multiple vulnerability detection time points, acquire multiple sets of threat intelligence data corresponding to network devices based on all vulnerability detection time points, and determine multiple threat intelligence data sequences based on all threat intelligence data; S120: Analyze each threat intelligence data sequence and determine the vulnerability threat metric of the network device based on the analysis results; S130: Perform multi-source splitting on all vulnerability threat metrics and calculate the multi-source vulnerability threat coefficient of the network device; S140: Pre-set a preset multi-source vulnerability threat coefficient, and determine whether to issue a vulnerability warning to the network device based on the relationship between the multi-source vulnerability threat coefficient and the preset multi-source vulnerability threat coefficient.
[0050] In some embodiments of this application, before determining multiple threat intelligence data sequences based on all threat intelligence data, the method further includes: All threat intelligence data is traversed and preprocessed, wherein the preprocessing includes deleting duplicate threat intelligence data, deleting erroneous threat intelligence data, and deleting invalid threat intelligence data.
[0051] In the description of the above embodiments, specific features, structures, materials, or characteristics may be combined in any suitable manner in one or more embodiments or examples.
[0052] Although the invention has been described above with reference to embodiments, various modifications can be made and components can be replaced with equivalents without departing from the scope of the invention. In particular, as long as there is no structural conflict, the features in the embodiments disclosed in this invention can be combined with each other in any way. The fact that not all of these combinations are described in this specification is merely for the sake of brevity and resource conservation.
[0053] It will be understood by those skilled in the art that the above are merely preferred embodiments of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A vulnerability alerting system based on threat intelligence, characterized in that, include: The data acquisition module is used to pre-set multiple vulnerability detection time points, acquire multiple sets of threat intelligence data corresponding to network devices based on all vulnerability detection time points, and determine multiple threat intelligence data sequences based on all threat intelligence data. The threat determination module is used to analyze each threat intelligence data sequence and determine the vulnerability threat metric of the network device based on the analysis results. The threat calculation module is used to perform multi-source splitting of all vulnerability threat metrics and calculate the multi-source vulnerability threat coefficient of the network device. The vulnerability warning module is used to pre-set a preset multi-source vulnerability threat coefficient, and determine whether to issue a vulnerability warning to the network device based on the relationship between the multi-source vulnerability threat coefficient and the preset multi-source vulnerability threat coefficient.
2. The threat intelligence based vulnerability alerting system as claimed in claim 1, wherein, Also includes: The data preprocessing module is used to traverse and preprocess all threat intelligence data, wherein the preprocessing includes deleting duplicate threat intelligence data, deleting erroneous threat intelligence data, and deleting invalid threat intelligence data.
3. The threat intelligence based vulnerability alerting system as claimed in claim 1, wherein, The threat determination module is used for: The threat determination module is used to obtain the threat intelligence data range corresponding to the threat intelligence data sequence, wherein the threat intelligence data range includes a first preset threat intelligence data and a second preset threat intelligence data, and the first preset threat intelligence data is smaller than the second preset threat intelligence data. The threat determination module is used to partition the threat intelligence data sequence based on the first preset threat intelligence data being less than the second preset threat intelligence data. When the threat intelligence data in the threat intelligence data sequence is less than the first preset threat intelligence data, the corresponding threat intelligence data is assigned to the first threat intelligence data area. The threat determination module is used to classify the corresponding threat intelligence data into the second threat intelligence data area when the threat intelligence data in the threat intelligence data sequence is greater than or equal to the first preset threat intelligence data and less than the second preset threat intelligence data. The threat determination module is used to divide the corresponding threat intelligence data into the third threat intelligence data area when the threat intelligence data in the threat intelligence data sequence is greater than or equal to the second preset threat intelligence data. The threat determination module is used to determine the vulnerability threat metric of the network device based on the first threat intelligence data area, the threat intelligence data area and the third threat intelligence data area.
4. The threat intelligence based vulnerability alerting system as claimed in claim 3, wherein, The threat determination module is used for: The threat determination module is used to merge the first threat intelligence data area and the third threat intelligence data area to obtain a comprehensive threat intelligence data area; The threat determination module is used to determine the vulnerability threat metric of the network device according to the following formula: ; Wherein, q is the vulnerability threat metric value of the network device, a is the number of threat intelligence data in the comprehensive threat intelligence data area, s1 is the first preset threat intelligence data, s2 is the second preset threat intelligence data, d w For the wth threat intelligence data in the comprehensive threat intelligence data area, c1 is the number of threat intelligence data in the first threat intelligence data area, c2 is the number of threat intelligence data in the second threat intelligence data area, and c3 is the number of threat intelligence data in the third threat intelligence data area.
5. The threat intelligence based vulnerability alerting system as claimed in claim 1, wherein, The threat calculation module is used for: The threat calculation module is used to extract the same vulnerability threat metric value from all vulnerability threat metrics and calculate the smooth threat coefficient of the network device; The threat calculation module is used to extract the different vulnerability threat metrics from all vulnerability threat metrics and calculate the fluctuation threat coefficient of the network device; The threat calculation module is used to perform a weighted summation of the smooth threat coefficient and the fluctuating threat coefficient to obtain the multi-source vulnerability threat coefficient of the network device.
6. The threat intelligence based vulnerability alerting system as claimed in claim 5 wherein, The threat calculation module is used for: The threat calculation module is used to obtain multiple sets of vulnerability threat metric values based on the same vulnerability threat metric value; The threat calculation module is used to count the number of the first vulnerability threat metric set in the vulnerability threat metric set; The threat calculation module is used to extract a vulnerability threat metric from each of the sets of vulnerability threat metrics, and to calculate the first vulnerability threat metric and the value. The threat calculation module is used to calculate the average vulnerability threat metric value of all the same vulnerability threat metric values, remove all vulnerability threat metric value sets that are less than the average vulnerability threat metric value, and count the number of second vulnerability threat metric value sets of the remaining vulnerability threat metric value sets. The threat calculation module is used to extract one vulnerability threat metric value from the remaining vulnerability threat metric value set, and to calculate the second vulnerability threat metric value set and value; The threat calculation module is used to calculate the smooth threat coefficient of the network device based on the number of the first vulnerability threat metric set, the number of the second vulnerability threat metric set, the sum of the first vulnerability threat metric value and the sum of the second vulnerability threat metric value.
7. The vulnerability early warning system based on threat intelligence according to claim 5, characterized in that, The threat calculation module is used for: The threat calculation module is used to construct a vulnerability threat metric curve based on all the different vulnerability threat metric values; The threat calculation module is used to determine the maximum slope corresponding to the vulnerability threat metric curve and to determine the standard deviation of the vulnerability threat metric for all different vulnerability threat metric values. The threat calculation module is used to take the product of the maximum slope and the standard deviation of the vulnerability threat metric as the fluctuation threat coefficient of the network device.
8. The vulnerability early warning system based on threat intelligence according to claim 1, characterized in that, The vulnerability warning module is used for: The vulnerability warning module is used to determine that no vulnerability warning will be issued to the network device when the multi-source vulnerability threat coefficient is less than the preset multi-source vulnerability threat coefficient. The vulnerability warning module is used to determine and issue a vulnerability warning to the network device when the multi-source vulnerability threat coefficient is greater than or equal to the preset multi-source vulnerability threat coefficient.
9. A vulnerability early warning method based on threat intelligence, applied to the vulnerability early warning system based on threat intelligence as described in any one of claims 1-8, characterized in that, include: Multiple vulnerability detection time points are pre-set, and multiple sets of threat intelligence data corresponding to network devices are obtained based on all vulnerability detection time points. Multiple threat intelligence data sequences are determined based on all threat intelligence data. Each threat intelligence data sequence is analyzed, and a vulnerability threat metric for the network device is determined based on the analysis results. All vulnerability threat metrics are split into multiple sources, and the multi-source vulnerability threat coefficient of the network device is calculated. A preset multi-source vulnerability threat coefficient is set in advance. Based on the relationship between the multi-source vulnerability threat coefficient and the preset multi-source vulnerability threat coefficient, it is determined whether to issue a vulnerability warning to the network device.
10. The vulnerability early warning method based on threat intelligence according to claim 9, characterized in that, Before determining multiple threat intelligence data sequences based on all threat intelligence data, the process also includes: All threat intelligence data is traversed and preprocessed, wherein the preprocessing includes deleting duplicate threat intelligence data, deleting erroneous threat intelligence data, and deleting invalid threat intelligence data.