A security early warning method, device and equipment fusing threat information and assets

By deeply integrating threat and asset information and utilizing multi-dimensional matching rules and confidence calculations, accurate early warning notifications are generated, solving the problem of the separation between threat information and asset management systems in existing technologies, and achieving efficient security early warning and response.

CN122226470APending Publication Date: 2026-06-16HEFEI TANOVO INFORMATION SECURITY TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HEFEI TANOVO INFORMATION SECURITY TECH CO LTD
Filing Date
2026-04-20
Publication Date
2026-06-16

AI Technical Summary

Technical Problem

In existing technologies, threat information is separated from asset management systems, leading to problems such as false alarms, missed alarms, delayed warnings, high costs of manual intervention, and low accuracy of alerts.

Method used

By acquiring raw threat information and target asset information, cleaning and standardizing the data, matching using a multi-dimensional matching rule base, calculating confidence levels, generating early warning notifications, and recording the handling status, a deep integration of threat information and assets is achieved.

Benefits of technology

It improves the accuracy and efficiency of early warning, realizes a closed loop of the entire process from threat intelligence acquisition to early warning response, and identifies potential threat assets in advance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122226470A_ABST
    Figure CN122226470A_ABST
Patent Text Reader

Abstract

The application provides a security early warning method and device fusing threat information and assets, and equipment. The method comprises the following steps: obtaining original threat information data and target asset information; performing cleaning, deduplication and standardization processing on the original threat information data to obtain a standardized threat feature data set; performing structural integration and dynamic verification and update on the target asset information to obtain a standardized asset information data set; performing matching processing on the standardized threat feature data set and the standardized asset information data set to obtain an initial matching result set; obtaining a hierarchical matching result set with a confidence label according to the initial matching result set; performing shunting processing on the hierarchical matching result set to obtain an effective threat early warning data set; and performing matching processing on the effective threat early warning data set and preset asset target correlation information to obtain early warning whole-process disposal data. The scheme of the application realizes threat information and asset fusion active early warning, and improves early warning accuracy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information processing technology, and in particular to a method, apparatus, and equipment for security early warning that integrates threat information and assets. Background Technology

[0002] With the continuous iteration of cyberattack techniques and the ever-expanding scale of enterprise IT assets, threat information utilization and asset management have become two core technical directions for proactive risk prevention in cybersecurity protection systems. Currently, most mainstream technical solutions in the industry adopt a discrete architecture. Enterprises typically deploy or subscribe to multi-source threat information platforms independently, acquiring threat data such as malicious Internet Protocol addresses (IPs), domain names, vulnerability numbers, and malicious file hashes through commercial application programming interfaces (APIs) or open-source data sources. Simultaneously, they build independent asset management systems through proactive asset scanning, endpoint proxy collection, and configuration management databases to manage information ledgers for IT assets such as servers, network devices, and endpoints. Regarding the linkage between threat information and assets, conventional solutions rely on security operations personnel to manually compare and analyze intelligence and assets, assess risks, and issue notifications. Some security information and event management systems can achieve basic automated threat identification by matching traffic log IPs with threat information lists through preset rules. However, the aforementioned existing technologies still have many core shortcomings that fail to meet the proactive security early warning needs of enterprises.

[0003] First, the data of the threat information platform and the asset management system are deeply disconnected, and can only achieve simple matching based on a single dimension such as IP. It cannot make a comprehensive judgment by combining information such as asset software version, vulnerability remediation status, and business importance, which easily leads to false alarms and false negatives.

[0004] Secondly, existing solutions are mostly post-attack tracing and early warning systems, and threat information updates are mostly timed synchronizations, making it impossible to obtain the latest intelligence in real time. This results in significant delays in early warning and makes it easy to miss the best defense opportunity.

[0005] Finally, the timing and methods of manual intervention are unreasonable. Either the entire process relies on manual screening and comparison, which is costly and inefficient, or it relies entirely on automatic alarms without a review process, which makes it impossible to guarantee the accuracy of alarms. At the same time, the early warning notifications are mostly broadcast-style pushes, which cannot accurately reach the corresponding asset responsible persons, resulting in a delay in threat handling response and an inability to form an effective closed-loop risk prevention and control system. Summary of the Invention

[0006] This invention provides a security early warning method, apparatus, and equipment that integrates threat information and assets, solving the problems of low accuracy and poor timeliness in asset security early warning.

[0007] To solve the above-mentioned technical problems, the technical solution of the present invention is as follows: This invention provides a security early warning method that integrates threat information and assets, comprising: Acquire raw threat information data and target asset information; The original threat information data is cleaned, deduplicated, and standardized to obtain a standardized threat feature dataset; The target asset information is structured, integrated, and dynamically verified and updated to obtain a standardized asset information dataset; According to the preset multi-dimensional matching rule library, the standardized threat feature dataset and the standardized asset information dataset are matched to obtain an initial matching result set; Based on the initial matching result set, the confidence level of each matching result is calculated to obtain a hierarchical matching result set with confidence level labels; According to the preset confidence level range, the hierarchical matching result set is split into multiple streams to obtain an effective threat warning dataset; The effective threat warning dataset and the preset asset target association information are matched to obtain warning notification data, and the response status of the warning notification data is recorded to obtain warning full-process handling data.

[0008] Optionally, the acquisition of raw threat information data and target asset information includes: According to the preset priority classification rules, multi-source data is obtained from multiple threat information sources. Specifically, data is obtained from threat information sources with the first preset priority using a real-time polling method, and data is obtained from threat information sources with the second preset priority using a timed synchronization method. The legality of the multi-source data is verified to obtain the original threat information data; The raw asset data is acquired through multiple preset acquisition channels, including at least one of network scanning channel, terminal agent reporting channel and manual input channel; The integrity of the original asset data is verified to obtain the target asset information.

[0009] Optionally, the original threat information data is cleaned, deduplicated, and standardized to obtain a standardized threat feature dataset, including: The original threat information data is cleaned to obtain cleaned threat information data; The cleaned threat information data is format-converted and feature fields are extracted to obtain a standardized threat feature dataset.

[0010] Optionally, the target asset information is structured, integrated, and dynamically verified and updated to obtain a standardized asset information dataset, including: The target asset information is subjected to structured classification processing to obtain an initial asset information dataset; The initial asset information dataset is monitored and verified in real time to obtain a standardized asset information dataset.

[0011] Optionally, the standardized threat feature dataset and the standardized asset information dataset are matched according to a preset multi-dimensional matching rule base to obtain an initial matching result set, including: Obtain a preset multi-dimensional matching rule library, which includes a first matching rule and a second matching rule; Based on the standardized threat feature dataset and the standardized asset information dataset, the feature matching verification is performed by traversing the multi-dimensional matching rule base to obtain multiple initial matching results. Among them, the first matching rule is used for direct matching of threat features and asset basic information, and the second matching rule is used for multi-condition association matching. The initial matching results are summarized to obtain an initial matching result set.

[0012] Optionally, based on the initial matching result set, the confidence level of each matching result is calculated to obtain a hierarchical matching result set with confidence level labels, including: Obtain the sum of effective rule weights, the quantified value of threat information credibility, and the quantified value of asset information integrity for each matching result in the initial matching result set; Based on the sum of effective rule weights, the quantified value of threat information credibility, and the quantified value of asset information integrity corresponding to each matching result in the initial matching result set, the confidence value of each matching result is determined. Add a corresponding confidence score label to each match result, and sort the match results according to the confidence score to obtain a hierarchical match result set with confidence score labels.

[0013] Optionally, the hierarchical matching result set is split according to a preset confidence interval to obtain an effective threat warning dataset, including: A first confidence threshold and a second confidence threshold are preset, wherein the first confidence threshold is less than the second confidence threshold; Matching results with a confidence level greater than or equal to the second confidence threshold are marked as first warning information; Matching results with a confidence level greater than or equal to the first confidence threshold and less than the second confidence threshold are marked as second warning information; Matching results with a confidence level less than the first confidence threshold are marked as third warning information and stored in the system log; The first, second, and third warning messages are aggregated to obtain an effective threat warning dataset.

[0014] Optionally, the effective threat warning dataset and preset asset target association information are matched to obtain warning notification data, and the response status of the warning notification data is recorded to obtain warning full-process handling data, including: Based on the asset information in the effective threat warning dataset, the corresponding primary target address information and backup target address information are extracted from the preset asset target association information; Based on the main target address information and the preset notification channel configuration rules, generate and send the first early warning notification data; Obtain the sending time, delivery status, target viewing time, and response time of the first warning notification data; When the response time is less than or equal to a preset time threshold, the sending time, delivery status, target viewing time, and response time of the first warning notification data are integrated to obtain the warning full-process handling data. When the response time exceeds a preset response time threshold, a second early warning notification is generated and sent according to the backup target address information and preset notification channel configuration rules. The sending time, delivery status, viewing time, and response time of the backup target are obtained for the second early warning notification data; The sending time, delivery status, viewing time of backup targets, and response time of the second early warning notification data are integrated to obtain the early warning full-process handling data.

[0015] This invention also provides a security early warning device that integrates threat information and assets, comprising: The acquisition module is used to acquire raw threat information data and target asset information; The processing module is used to clean, deduplicate, and standardize the original threat information data to obtain a standardized threat feature dataset; to perform structured integration and dynamic verification and updating of the target asset information to obtain a standardized asset information dataset; to match the standardized threat feature dataset and the standardized asset information dataset according to a preset multi-dimensional matching rule library to obtain an initial matching result set; to calculate the confidence level of each matching result based on the initial matching result set to obtain a hierarchical matching result set with confidence level labels; to perform splitting processing on the hierarchical matching result set according to a preset confidence level interval to obtain an effective threat warning dataset; to match the effective threat warning dataset with preset asset target association information to obtain push warning notification data, and to record the response status of the push warning notification data to obtain warning full-process handling data.

[0016] This invention also provides a computing device, including: a processor and a memory storing a computer program, wherein the computer program, when run by the processor, executes the above-described method.

[0017] The technical solution of the present invention has at least the following effects: The above-described solution of the present invention acquires original threat information data and target asset information; cleans, deduplicates, and standardizes the original threat information data to obtain a standardized threat feature dataset; performs structured integration and dynamic verification and updating of the target asset information to obtain a standardized asset information dataset; matches the standardized threat feature dataset and the standardized asset information dataset according to a preset multi-dimensional matching rule library to obtain an initial matching result set; calculates the confidence level of each matching result based on the initial matching result set to obtain a hierarchical matching result set with confidence level labels; performs diversion processing on the hierarchical matching result set according to a preset confidence level interval to obtain an effective threat warning dataset; matches the effective threat warning dataset with preset asset target association information to obtain warning notification data, and records the response status of the warning notification data to obtain warning full-process handling data, thereby realizing proactive warning by integrating threat information and assets, improving the accuracy of warnings and the efficiency of handling. Attached Figure Description

[0018] Figure 1 This is the main flowchart of the security early warning method for integrating threat information and assets provided in this embodiment of the invention; Figure 2 This is a schematic diagram of the data processing process of the security early warning method for fusing threat information and assets provided in an embodiment of the present invention; Figure 3 This is a structural diagram of the security early warning device that integrates threat information and assets provided in an embodiment of the present invention; Figure 4 This is a schematic diagram of the structure of the computing device provided in an embodiment of the present invention. Detailed Implementation

[0019] Exemplary embodiments of the invention will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the invention are shown in the drawings, it should be understood that the invention may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this invention will be thorough and complete, and will fully convey the scope of the invention to those skilled in the art.

[0020] like Figure 1 As shown, embodiments of the present invention propose a security early warning method that integrates threat information and assets, which may include: Step 11: Obtain raw threat information data and target asset information; Step 12: Clean, deduplicate, and standardize the original threat information data to obtain a standardized threat feature dataset; Step 13: Perform structured integration and dynamic verification and updating of the target asset information to obtain a standardized asset information dataset; Step 14: According to the preset multi-dimensional matching rule library, the standardized threat feature dataset and the standardized asset information dataset are matched to obtain an initial matching result set; Step 15: Based on the initial matching result set, calculate the confidence level of each matching result to obtain a hierarchical matching result set with confidence level labels; Step 16: According to the preset confidence level interval, the hierarchical matching result set is split into multiple streams to obtain an effective threat warning dataset; Step 17: Match the effective threat warning dataset with the preset asset target association information to obtain warning notification data, and record the response status of the warning notification data to obtain warning full-process handling data.

[0021] In step 11 of this embodiment, raw threat information data is obtained through a preset multi-source intelligence access path, and target asset information is obtained through a preset multi-channel asset acquisition method. The raw threat information data comes from multiple compliant threat intelligence providers and publicly disclosed vulnerability release platforms. The target asset information covers all IT asset-related information within the scope to be protected.

[0022] In step 12, invalid data removal and duplicate data removal operations are performed on the original threat information data. After data cleaning, the data is converted to a unified format, and the core threat feature fields are extracted to form a standardized threat feature dataset.

[0023] In step 13, the target asset information is structured and classified according to data type and stored. At the same time, changes in asset information are monitored in real time and periodically verified to complete the dynamic update of asset information and form a standardized asset information dataset.

[0024] In step 14, the preset multi-dimensional matching rule library is invoked to perform full feature matching verification between the standardized threat feature dataset and the standardized asset information dataset, record all successful matching results, and summarize them to form an initial matching result set.

[0025] In step 15, the rule weight information, threat intelligence credibility information, and asset information integrity information corresponding to each matching result in the initial matching result set are extracted. The confidence value of each matching result is obtained through the preset confidence calculation formula. A confidence label is added to each matching result and sorting is completed to obtain a hierarchical matching result set with confidence labels.

[0026] In step 16, all matching results in the hierarchical matching result set are classified according to the three preset confidence intervals, and different types of early warning information are labeled respectively, and the results are summarized to form an effective threat early warning dataset.

[0027] In step 17, the effective threat warning dataset is matched with the preset asset target association information to obtain the target contact information of the corresponding assets. Warning notification data is generated and sent according to the preset hierarchical notification strategy. At the same time, the entire process of response and handling of warning notifications is tracked and recorded, and the entire process of warning handling data is summarized.

[0028] The technical solution described in this embodiment achieves deep integration of threat intelligence and asset information, completing a closed loop from threat intelligence acquisition to early warning and handling. It can identify potential threatened assets in advance and improve the accuracy of security early warning and the efficiency of handling.

[0029] In an optional embodiment of the present invention, step 11, obtaining the original threat information data and target asset information, may include: In step 111, multi-source data is obtained from multiple threat information sources according to the preset priority classification rules. Specifically, data is obtained from threat information sources with the first preset priority using a real-time polling method, and data is obtained from threat information sources with the second preset priority using a timed synchronization method. In step 112, the legality of the multi-source data is verified to obtain the original threat information data; In step 113, raw asset data is acquired through multiple preset acquisition channels, including at least one of network scanning channel, terminal agent reporting channel, and manual input channel; In step 114, the integrity of the original asset data is verified to obtain the target asset information.

[0030] In step 111 of this embodiment, multi-source data is obtained from multiple threat information sources according to preset priority classification rules. Specifically, the system pre-configures priorities for various threat intelligence sources, setting emergency vulnerability reporting sources and commercial high-precision threat intelligence APIs as the first preset priority, and using a real-time polling method to obtain data. The polling interval can be configured to 1 minute to ensure that high-risk threat information is captured within a very short time after its generation. The national vulnerability database and open-source intelligence platforms are set as the second preset priority, and data is obtained using a timed synchronization method, with the synchronization period set as needed to 30 minutes. Through differentiated acquisition strategies, the system can reasonably control system resource consumption while ensuring the real-time nature of key intelligence.

[0031] In step 112, the legality of the multi-source data is verified to obtain the original threat information data. The system has a built-in intelligence data cleaning and standardization engine. First, it performs format verification and integrity checks on the acquired unstructured text, semi-structured JSON, and other formatted data, removing incomplete, duplicate, and invalid data. Then, based on a preset data conversion standard, it converts the verified data into a unified format and extracts key feature fields such as threat type, threat identifier, scope of impact, and occurrence time. Through legality verification and standardization, it ensures that the threat intelligence data entering the matching process has a complete, consistent, and computable structured form.

[0032] In step 113, raw asset data is acquired through multiple pre-defined acquisition channels. These channels include a network scanning channel, which proactively probes asset viability, open ports, and service versions based on the Nmap scanning engine according to configuration cycles; a terminal agent reporting channel, which monitors and reports dynamic information such as software installation and configuration changes in real time through a lightweight agent program deployed on the terminal; and a manual data entry channel, allowing administrators to supplement information such as asset ownership and business attributes that cannot be obtained automatically through a web interface. These three channels work together to achieve comprehensive coverage and dynamic updates of asset data.

[0033] In step 114, the original asset data is subjected to integrity verification to obtain target asset information. The system performs field integrity checks on the collected original data based on a preset asset information model, verifying whether key fields such as asset name, IP address, responsible person (target), and department are missing or formatted incorrectly. For incomplete data, a completion mechanism is triggered, such as through historical records or prompting for manual supplementation. The asset information that passes verification is written to a distributed asset database. Structured data is stored in MySQL, while unstructured software manifests, configuration files, etc., are stored in MongoDB, forming complete target asset information that can be directly accessed by the intelligent matching module.

[0034] In an optional embodiment of the present invention, step 12, which involves cleaning, deduplicating, and standardizing the original threat information data to obtain a standardized threat feature dataset, may include: Step 121: Perform data cleaning on the original threat information data to obtain cleaned threat information data; Step 122: Perform format conversion processing on the cleaned threat information data and extract feature fields to obtain a standardized threat feature dataset.

[0035] In step 121 of this embodiment, the original threat information data is cleaned to obtain cleaned threat information data. Specifically, the system's built-in intelligence data cleaning and standardization engine first performs format standardization verification on the original threat information data obtained from multiple sources, identifying and removing incomplete data caused by transmission errors or interface anomalies. Subsequently, the system uses a comparison algorithm based on content hash values ​​to deduplicate the same threat information from different threat intelligence sources. For example, multiple records corresponding to the same malicious IP address or the same CVE vulnerability number reported by multiple intelligence sources are merged into a single unique record. For duplicate data, the system retains the record with the highest information completeness and the most recent update time, and discards the rest. In addition, the system also filters invalid fields in the intelligence data, such as removing redundant text unrelated to threat characteristics in the threat description and correcting data formats that obviously do not conform to the standards, ensuring that the cleaned threat information data has the basic attributes of completeness, uniqueness, and validity.

[0036] In step 122, the cleaned threat information data undergoes format conversion and feature fields are extracted to obtain a standardized threat feature dataset. The system uniformly converts the cleaned data into a data format conforming to a preset structured threat information expression standard. This format uses a JSON architecture and can completely describe the type, identifier, attributes, and relationships of threat objects. During the format conversion process, the system extracts predefined key threat feature fields from the original data, specifically including: a threat type field, used to identify whether the threat is a malicious IP address, malicious domain name, vulnerability information, or malicious file hash; a threat identifier field, such as an IP address value, CVE number string, or SHA256 hash value, which can be used as a unique identifier for direct matching with asset information; a threat severity level field, which is normalized based on the CVSS score or the threat intelligence platform's own rating; a threat impact scope field, recording the software name, version range, or system type that the threat may affect; and a threat occurrence time and source field, used for subsequent confidence calculation and priority ranking. After format conversion and feature extraction, the system forms a standardized threat feature dataset with a unified structure, complete fields, and can be directly used for multi-dimensional intelligent matching with asset information.

[0037] In an optional embodiment of the present invention, step 13, which involves structurally integrating and dynamically verifying and updating the target asset information to obtain a standardized asset information dataset, may include: Step 131: Perform structured classification processing on the target asset information to obtain an initial asset information dataset; Step 132: Perform real-time change monitoring and verification on the initial asset information dataset to obtain a standardized asset information dataset.

[0038] In step 131 of this embodiment, the target asset information is processed through structured classification to obtain an initial asset information dataset. Specifically, the system classifies the multi-source raw asset data acquired through the acquisition channels according to a preset asset information model. The classification process divides the data into two categories based on data attributes: structured data and unstructured data. Structured data includes fields such as asset name, asset identifiers (e.g., IP address and MAC address), target (responsible person) unique identifier, department, and asset status. This type of data has clear field types and length constraints. The system maps it to a predefined table in the relational database MySQL, establishing the association between assets and targets, and assets and business systems through primary keys and foreign keys. Unstructured data includes software installation lists, vulnerability repair records, asset configuration files, etc. This type of data has a variable structure and complex content. The system stores it in the form of documents in a MongoDB database. Each document records the unstructured information of one asset and associates it with the structured data through the asset's unique identifier. Through structured classification processing, the system transforms the originally scattered and heterogeneous raw asset data into an initial asset information dataset that is clearly classified, rationally stored, and easy to quickly retrieve and match for subsequent calculations.

[0039] In step 132, the initial asset information dataset undergoes real-time change monitoring and verification to obtain a standardized asset information dataset. The system achieves dynamic updates and integrity assurance of asset information through multi-mechanism collaboration. Regarding change monitoring, a lightweight agent program deployed on terminal assets monitors events such as software installation, uninstallation, and configuration changes in real time. Once a change is detected, it proactively reports the change information to the system, triggering incremental updates to the corresponding asset records. Simultaneously, the network scanning engine performs a full network asset scan at configurable intervals, using tools such as Nmap to detect asset liveness status, open ports, and service version changes. The scan results are compared with existing records, and asset information is automatically updated when discrepancies are found. Regarding integrity verification, the system performs key field verification on each updated asset record, checking for missing or incorrectly formatted core fields such as asset name, IP address, and target information. For records that fail verification, the system automatically completes the data based on historical records or generates a list of fields to be completed, prompting the administrator for manual completion. The standardized asset information dataset formed after real-time change monitoring and integrity verification has a unified data structure, complete and accurate fields, and high timeliness, providing reliable data support for subsequent intelligent matching of threat assets.

[0040] In an optional embodiment of the present invention, step 14, matching the standardized threat feature dataset and the standardized asset information dataset according to a preset multi-dimensional matching rule base to obtain an initial matching result set, may include: Step 141: Obtain a preset multi-dimensional matching rule library, which includes a first matching rule and a second matching rule; Step 142: Based on the standardized threat feature dataset and the standardized asset information dataset, traverse the multi-dimensional matching rule base to perform feature matching verification and obtain multiple initial matching results. Among them, the first matching rule is used for direct matching of threat features and asset basic information, and the second matching rule is used for multi-condition association matching. Step 143: Summarize the multiple initial matching results to obtain an initial matching result set.

[0041] In step 141 of this embodiment, the system retrieves a pre-configured multi-dimensional matching rule base from the local rule base storage module. This rule base is the core basis for determining the matching between threat features and asset information, and contains two types of independent and superimposed matching rules, namely the first matching rule and the second matching rule. The first matching rule is a basic direct matching rule, preset as a precise equivalence matching logic for single-dimensional features, used to achieve a one-to-one direct comparison between threat features and basic asset information. The preset matching dimensions of the rule include, but are not limited to, feature fields that can be directly verified by equivalence, such as malicious IP addresses, CVE vulnerability numbers, and malicious file hash values. Each rule... The first matching rule has a fixed base weight value. The second matching rule is a multi-condition association matching rule, which is preset with multi-dimensional feature logic and combination matching logic. It is used to realize the joint judgment of multiple threat features and multi-dimensional asset information. The preset association conditions of the rule can cover multiple dimensions such as threat severity level, range of affected software versions, asset vulnerability repair status, and importance level of the business to which the asset belongs. Each second matching rule can customize the number of association conditions, the judgment logic of each sub-condition, and the combination weight. The two types of rules together constitute a complete multi-dimensional matching rule library, which supports administrators to add, modify, delete and configure weights of rules through the web management interface.

[0042] In step 142, the system loads the standardized threat feature dataset and the standardized asset information dataset respectively, traverses all rules in the multi-dimensional matching rule base, and performs feature matching verification on each threat record and each asset record in turn to obtain multiple initial matching results. The specific matching process is as follows: (1) The matching process and matching results based on the first matching rule; The first matching rule is a single-dimensional exact equality matching, and its matching determination formula is as follows: ; In the formula, This is the identifier for the matching result of the first matching rule. A value of 1 indicates a successful match, and a value of 0 indicates a failed match. This is an indicator function; the function takes the value 1 when the condition within the parentheses is true, and takes the value 0 when the condition is false. To standardize the threat signature dataset A single basic feature field in the data. , ; For the standardization of asset information data centralization and Corresponding basic feature fields of the same dimension The matching process is as follows: the system iterates through each threat record in the standardized threat feature dataset and extracts its preset basic feature fields. Simultaneously, it iterates through each asset record in the standardized asset information dataset and extracts the feature fields of the corresponding dimensions. Substitute the values ​​into the above formula to complete the equivalence determination; for example, a threat record in the standardized threat feature dataset... This is the malicious IP address field, with a value of 192.168.3.20, representing a specific asset record in the standardized asset information dataset. The asset IP address field has a value of 192.168.3.20. The conditions for judgment are met. The value is 1. Match successful; the system generates the corresponding initial matching result, recording the threat ID, asset ID, matching rule type (first matching rule), matching dimension (IP address), matching time, and rule base weight value corresponding to the matching result; if and If the values ​​are inconsistent, then Matching failed, and no matching result was generated.

[0043] (2) The matching process and matching results based on the second matching rule; The second matching rule is a multi-condition association combination matching, and its matching determination formula is as follows: ; In the formula, This is the identifier for the matching result of the second matching rule. A value of 1 indicates a successful match, and a value of 0 indicates a failed match. The total number of pre-defined associated conditions for this second matching rule; For the first Feature fields in the standardized threat feature dataset corresponding to each association condition. For the first Feature fields in the standardized asset information dataset corresponding to each association condition; For chain multiplication, only if all corresponding When all values ​​are 1, The final value is 1, indicating a successful match. The matching process is as follows: the system iterates through each threat record in the standardized threat feature dataset and extracts the threat feature fields corresponding to all associated conditions of the second matching rule. , ... Simultaneously, it iterates through each asset record in the standardized asset information dataset and extracts the corresponding asset feature fields. , ... The substituting of each sub-condition into the formula sequentially completes the judgment of each sub-condition, and then the final matching result is obtained through multiplication; for example, a certain second matching rule presets 3 related conditions ( ): Condition 1 ( ): This is the CVE vulnerability number representing the threat characteristic, with a value of CVE-2024-12345. For the CVE number in the asset vulnerability remediation record, it must meet the following requirements. ; Condition 2 ( ): The affected software version range for the threat signature is defined as Apache Tomcat 9.0.0 to 9.0.70. The installed software version for the asset must meet the following requirements. ; Condition 3 ( ): As a prerequisite for exploiting vulnerabilities based on threat characteristics, the value is that the vulnerability has not been patched. For the remediation status of the vulnerability corresponding to the asset, the following must be met: When the system performs a matching verification between a threat record and an asset record, it extracts the asset's... , , If all three sub-conditions are true, the corresponding All values ​​are 1, and after multiplication... Match successful; the system generates the corresponding initial matching result, recording the threat ID, asset ID, matching rule type (second matching rule), multiple conditions for matching, matching time, and the weight value of the rule combination; if any sub-condition is not met, the corresponding... The value is 0, and after multiplication... If a match fails, no matching result is generated. After the system completes the traversal and verification of all threat records, asset records, and all matching rules, it summarizes all successfully matched initial matching results to form an initial matching result set.

[0044] In step 143, the multiple initial matching results are summarized to obtain an initial matching result set. The system aggregates all basic and advanced matching results generated during the matching process, and initially merges them according to the combination of threat identifier and asset identifier. For multiple matches between the same threat and the same asset under multiple rules, the system retains the rule with the highest weight as the representative to avoid duplicate recording. The summarized initial matching result set contains a detailed description of the matching relationship between each threat and asset, the source of the matching rule, and the basis for the matching, providing a complete data foundation for subsequent confidence calculation, priority ranking, and manual review.

[0045] In an optional embodiment of the present invention, step 15, calculating the confidence level of each matching result based on the initial matching result set to obtain a hierarchical matching result set with confidence level labels, may include: Step 151: Obtain the sum of effective rule weights, the quantified value of threat information credibility, and the quantified value of asset information integrity for each matching result in the initial matching result set; Step 152: Determine the confidence level of each matching result based on the sum of effective rule weights, the quantified value of threat information credibility, and the quantified value of asset information integrity corresponding to each matching result in the initial matching result set. Step 153: Add a corresponding confidence score label to each matching result, and sort the matching results according to the confidence score to obtain a hierarchical matching result set with confidence score labels.

[0046] In step 151 of this embodiment, the system obtains the sum of effective rule weights, threat information credibility quantification, and asset information integrity quantification for each matching result in the initial matching result set. Specifically, the system backtracks all effective matching rules triggered by each matching result. Each rule has a preset weight value based on its importance set by the administrator during creation; for example, the weight of a basic matching rule is set to 30, and the weight of an advanced matching rule involving a combination of vulnerabilities and software versions is set to 70. The threat information credibility quantification is determined based on the reliability level of the threat intelligence source. The credibility of sources from commercial threat intelligence API interfaces is set to the range of 90 to 100, and the credibility of publicly available open-source intelligence sources is set to the range of 60 to 80. The asset information integrity quantification is calculated based on the asset information collection method and field completeness. The asset information integrity reported in real-time through a terminal agent is set to the range of 90 to 100, the asset information integrity obtained through network scanning is set to the range of 70 to 85, and the asset information entered manually is dynamically evaluated based on the field fill rate.

[0047] In step 152, the confidence score for each match is calculated. The system uses the following formula: , in, This represents the confidence score of a single match result. For the first i The preset weight values ​​for each valid matching rule; For the first i The matching completion degree of each valid matching rule is 1 when the matching condition is fully met, and between 0 and 1 when the matching condition is a fuzzy match or partially met, depending on the matching precision. This serves as a reliable metric for the corresponding threat information. This is a quantified value for the information completeness of the corresponding asset. The upper limit of the quantifiable value for threat information credibility is fixed at 100; The upper limit of the asset information integrity quantification value is fixed at 100. The total number of valid matching rules triggered by this matching result; To match the scenario correction coefficient, the system dynamically determines the coefficient based on the combination of threat type and asset type. For core business assets matched with high-risk vulnerabilities, a correction coefficient of 1.2 is used to increase confidence; for ordinary test assets matched with low-risk alerts, a correction coefficient of 0.8 is used to reduce false positive risk. The formula normalizes the confidence score to a percentage range by multiplying the weighted sum of rule weights and matching completion rates in the numerator by the confidence, completeness, and scenario correction coefficients, and then dividing by the maximum possible score under ideal conditions. This ensures comparability of matching results for different threat types and asset types.

[0048] In step 153, a corresponding confidence level label is added to each matching result, and the matching results are sorted according to the confidence level to obtain a tiered matching result set with confidence level labels. The system writes the calculated confidence level value as a percentage into the metadata of each matching result to form a confidence level label, and then sorts the matching results in descending order according to the confidence level value. Matching results with a confidence level value of not less than 90% are marked as high confidence level, those between 60% and 90% are marked as pending review level, and those not higher than 60% are marked as low confidence level. The generation of the tiered matching result set enables subsequent processing modules to adopt differentiated processing strategies based on the confidence level. High confidence level results are directly pushed to the alert, pending review results are transferred to the manual review module, and low confidence level results are archived for future reference, thereby achieving accurate diversion and efficiency optimization of the alert process.

[0049] In an optional embodiment of the present invention, step 16, which involves splitting the hierarchical matching result set according to a preset confidence interval to obtain an effective threat warning dataset, may include: Step 161: Preset a first confidence threshold and a second confidence threshold, wherein the first confidence threshold is less than the second confidence threshold; Step 162: Mark the matching results with a confidence level greater than or equal to the second confidence level threshold as first warning information; mark the matching results with a confidence level greater than or equal to the first confidence level threshold and less than the second confidence level threshold as second warning information; mark the matching results with a confidence level less than the first confidence level threshold as third warning information and store them in the system log; Step 163: Summarize the first warning information, the second warning information, and the third warning information to obtain an effective threat warning dataset.

[0050] In step 161 of this embodiment, a first confidence threshold and a second confidence threshold are preset, wherein the first confidence threshold is less than the second confidence threshold. Specifically, during the initial configuration phase, the administrator sets two key thresholds through the management interface. The first confidence threshold is used to distinguish between low-confidence matching results and matching results requiring review, and is set to 60% by default; the second confidence threshold is used to distinguish between matching results requiring review and high-confidence matching results, and is set to 90% by default. The two thresholds divide the confidence value range into three continuous intervals: 0 to the first confidence threshold is the low-confidence interval, the first confidence threshold to the second confidence threshold is the interval requiring review, and the second confidence threshold to 100% is the high-confidence interval. The administrator can dynamically adjust the specific values ​​of the two thresholds according to actual security operation needs. For example, in scenarios where high accuracy is pursued, the second confidence threshold can be increased to 95%, and in scenarios where high coverage is pursued, the first confidence threshold can be decreased to 50%, thereby achieving flexible configuration of warning sensitivity.

[0051] In step 162, matching results with a confidence level greater than or equal to the second confidence threshold are marked as first warning information; matching results with a confidence level greater than or equal to the first confidence threshold but less than the second confidence threshold are marked as second warning information; and matching results with a confidence level less than the first confidence threshold are marked as third warning information and stored in the system log. The system performs a triage judgment on each record in the tiered matching result set based on its confidence level. For matching results with a confidence level not lower than the second confidence threshold, the system marks them as first warning information. This type of information represents a highly credible matching relationship between the threat and the asset, and can directly enter the warning notification process without manual intervention. Simultaneously, the system internally prioritizes this type of information based on the threat severity level and asset importance, ensuring that records of ultra-critical threats matching core assets are pushed first. For matching results with a confidence level between the first and second confidence thresholds, the system marks them as second warning information. This type of information represents a certain degree of uncertainty in the matching relationship, requiring manual intervention to verify the authenticity of the threat. The system pushes this type of information to the manual review interaction module and sends a review reminder to the administrator. For matching results with a confidence level lower than the first confidence level threshold, the system marks them as third warning information. This type of information indicates that the credibility of the matching relationship is low, which may be due to data noise or excessive rule matching. The system does not trigger a warning or enter the review process, but instead stores it in the system log for reference in subsequent operation analysis or rule optimization.

[0052] In step 163, the first, second, and third warning messages are aggregated to obtain an effective threat warning dataset. The system aggregates and integrates the three types of warning messages generated in step 162 according to a unified metadata structure. Each record contains complete fields such as threat details, asset details, matching criteria, confidence level, classification label, and timestamp. The aggregated effective threat warning dataset provides a unified input interface for the subsequent warning notification and manual review modules. Furthermore, it serves as the data foundation for system operation reports, supporting administrators in regularly analyzing key indicators such as the distribution of matching results across different confidence level intervals, manual review conversion rates, and warning accuracy, facilitating continuous optimization of matching rules and threshold configurations.

[0053] In an optional embodiment of the present invention, step 17 involves matching the effective threat warning dataset with preset asset target association information to obtain warning notification data, and recording the response status of the warning notification data to obtain full-process warning handling data. This may include: Step 171: Based on the asset information in the effective threat warning dataset, extract the corresponding primary target address information and backup target address information from the preset asset target association information; Step 172: Generate and send first early warning notification data based on the main target address information and the preset notification channel configuration rules; Step 173: Obtain the sending time, delivery status, target viewing time, and response time of the first warning notification data; Step 174: When the response time is less than or equal to a preset time threshold, the sending time, delivery status, target viewing time, and response time of the first warning notification data are integrated to obtain warning full-process handling data; when the response time exceeds the preset response time threshold, second warning notification data is generated and sent according to the backup target address information and preset notification channel configuration rules, and the sending time, delivery status, backup target viewing time, and response time of the second warning notification data are obtained; the sending time, delivery status, backup target viewing time, and response time of the second warning notification data are integrated to obtain warning full-process handling data.

[0054] In step 171 of this embodiment, based on the asset information in the effective threat warning dataset, the corresponding primary responsible person's address information and backup responsible person's address information are extracted from the preset asset responsible person (target) association information. Specifically, the system pre-establishes an asset-responsible person association mapping table in the asset information storage and update module. Each asset record is associated with a primary responsible person identifier and a backup responsible person identifier configured by department or business line. When the asset corresponding to a warning record in the effective threat warning dataset is determined, the system queries the mapping table through the asset's unique identifier to extract the primary responsible person's name, mobile phone number, email address, and other address information, while simultaneously extracting similar address information for the backup responsible person. The backup responsible person mechanism ensures that when the primary responsible person is unable to respond in a timely manner due to being off duty, on vacation, or busy with work, the warning information can still be handled by other personnel in the same department or business line, avoiding gaps in warning handling.

[0055] In step 172, based on the address information of the responsible party and the preset notification channel configuration rules, the system generates and sends first warning notification data. The system determines the notification method based on the threat severity level and the preset notification channel configuration rules. Threat severity levels are divided into four levels: extremely high, high, medium, and low, based on the CVSS vulnerability scoring system or threat intelligence platform rating. Users can customize the notification channel combination for each level in the management interface. For example, for extremely high-risk threats, the system simultaneously triggers SMS notifications, email notifications, and system pop-up notifications, generating first warning notification data containing fields such as threat type, threat identifier, affected asset name, threat severity level, and suggested handling measures. This data is then sent via the SMS gateway, email server, and system message push interface. For medium-risk threats, the system only triggers email notifications to reduce the frequency of disturbance to the responsible party.

[0056] In step 173, the sending time, delivery status, and the viewing and response times of the responsible person for the first early warning notification data are obtained. The system records a sending timestamp when sending the notification and obtains the delivery status through the SMS gateway's receipt interface, the mail server's delivery receipt, and the system pop-up's read receipt mechanism. When the responsible person logs into the system via the notification link to view the early warning details, the system records the viewing timestamp. When the responsible person submits a handling plan in the system interface, such as confirming and fixing the threat, marking it as a false alarm, or requesting a delayed processing, the system records the response timestamp and the handling content. The above time and status data are stored in a structured form in the asset information storage and update module, forming a complete notification tracking log.

[0057] In step 174, after the system completes the sending of the early warning notification, it performs a two-branch closed-loop processing on the response status of the primary responsible person: When the primary responsible person's response time is less than or equal to a preset time threshold, the system integrates the sending time, delivery status, primary responsible person's viewing time and response time, and corresponding threat handling information of the first early warning notification data into a complete early warning process handling data; when the primary responsible person's response time exceeds the preset response time threshold, the system automatically triggers a notification escalation mechanism, generates and sends second early warning notification data based on the backup target address information and preset notification channel configuration rules, and simultaneously collects the sending time, delivery status, backup responsible person's viewing time and response time of the second early warning notification data, integrating the full-link notification and response data of the primary and backup responsible persons into a complete early warning process handling data. The early warning process handling data generated in this step will be synchronously fed back to the threat-asset intelligent matching module and the threat intelligence automatic acquisition module through the internal data bus, serving as the core basis for adjusting the threat intelligence source acquisition frequency. Combined with the technical solution recorded in the technical documents, the threat intelligence source acquisition frequency is specifically adjusted through a three-tier mechanism: The first is a real-time dynamic adjustment mechanism. Based on the threat level and response status of the warning, the system adjusts the acquisition frequency of the corresponding threat intelligence source in real time. If the warning is a super-risk or high-risk threat, the system will temporarily increase the priority of the corresponding threat intelligence source, switching it from the normal priority timed synchronization mode to the high priority real-time polling mode, regardless of whether the person in charge responds within the threshold. The polling interval can be configured to a minimum of 1 minute. If the person in charge fails to respond within the time limit, it indicates that the urgency of the threat response has increased. The system will further shorten the polling interval of the intelligence source and increase the intelligence acquisition frequency to ensure that the latest dynamics of the threat are captured in real time. Secondly, there is a cross-module linkage control and adjustment mechanism. According to the control logic connection rules recorded in the technical solution, the acquisition frequency control signal of the threat intelligence automatic acquisition module is dynamically issued by the threat-asset intelligent matching module. The early warning full-process handling data generated in this step will serve as the core input of the threat-asset intelligent matching module to adjust the frequency control signal. When a critical threat occurs or the early warning is not responded to within the time limit, the threat-asset intelligent matching module will automatically issue a frequency increase instruction to the threat intelligence automatic acquisition module to realize the linkage control between the early warning handling status and the intelligence acquisition frequency. Thirdly, there is a periodic optimization and adjustment mechanism. The early warning data generated in this step will be included in the operation reports generated by the system periodically. During the optimization and iteration phase, the system will re-prioritize the threat intelligence sources based on data such as the early warning response time, threat handling efficiency, and intelligence matching accuracy throughout the entire cycle, and adjust their fixed acquisition frequency accordingly. For intelligence sources that trigger high-risk early warnings frequently and have high handling response pressure, their acquisition cycle will be changed from timed synchronization mode to real-time polling mode to shorten the acquisition cycle. For intelligence sources with low risk, low trigger rate, and high false alarm rate, their timed synchronization cycle can be extended to reduce system resource consumption while ensuring the early warning effect.

[0058] like Figure 2 As shown, a specific embodiment of the security early warning method that integrates threat information and assets provided by this invention is as follows: Step 1: System parameter configuration during the initialization phase; The administrator completes the configuration of basic system parameters to provide rule support for real-time operation, specifically including: Configure threat intelligence sources: Fill in the API key of the threat intelligence platform to be connected, the configuration of the public intelligence source crawler, set the priority classification rules of the intelligence sources, and preset that high-priority intelligence sources use a real-time polling method with a minimum interval of 1 minute to obtain data, while ordinary priority intelligence sources use a timed synchronization method with a period of 30 minutes to obtain data. (1) Configure asset collection: Select three types of asset collection channels: network scanning, terminal agent reporting, and manual entry; configure the network scanning range, agent reporting parameters, and manual entry field specifications. (2) Configure matching rules: Enable the default multi-dimensional matching rule library, support the addition, modification and deletion of rules, set the rule triggering conditions and preset weights, and preset 60% as the first confidence threshold and 90% as the second confidence threshold; (3) Configure notification strategy: Preset the combination of notification channels and response time thresholds corresponding to different threat levels, configure asset-responsible person association mapping rules, and set up notification upgrade mechanisms for primary and backup responsible persons.

[0059] (4) After configuration, the system starts the corresponding engine and enters the real-time operation stage.

[0060] Step 2, Threat intelligence acquisition and standardization during the real-time operation phase; Following the preset configuration in step 1, the system automatically acquires multi-source threat intelligence data and obtains the original threat information data after legality verification. The original threat information data undergoes cleaning, deduplication, and standardization: incomplete data is removed through format verification; multi-source threat information is deduplicated and merged based on a content hash value comparison algorithm, retaining the record with the highest information completeness and the most recent update time; the cleaned data is uniformly converted to STIX2.1 format, and key feature fields such as threat type, threat identifier, severity level, and impact scope are extracted to form a standardized threat feature dataset; for vulnerability-related threat information, the vulnerability exploitation difficulty coefficient and potential impact coefficient are calculated based on CVSS scoring and stored as additional feature fields in the dataset.

[0061] Step 3: Asset information collection, updating, and structured integration processing; Following the pre-configured steps in step 1, the system acquires raw asset data through three acquisition channels and obtains target asset information after integrity verification. The system then performs structured integration and dynamic updates of the target asset information: asset information is stored in structured and unstructured categories; structured data (asset name, IP address, responsible person information, etc.) is stored in a MySQL relational database, while unstructured data (software installation lists, vulnerability repair records, etc.) is stored in a MongoDB document database. Asset change events are reported in real-time through a lightweight terminal agent, and a network scanning engine performs periodic full-network scans and updates asset records, forming a standardized asset information dataset after integrity verification. Simultaneously, an asset association graph is constructed upon asset entry, and asset grouping is completed based on the mapping relationship between assets and business systems. The comprehensive importance score for each group of business systems is calculated for subsequent priority ranking of matching results.

[0062] Step 4, Threat-Asset Intelligent Matching Processing; The system performs matching processing on the standardized threat feature dataset from step 2 and the standardized asset information dataset from step 3 according to the multi-dimensional matching rule base preset in step 1. The multi-dimensional matching rule base includes a first matching rule and a second matching rule. The first matching rule is used for direct matching of threat features and basic asset information, and the second matching rule is used for multi-condition association matching. The system traverses the rule base to complete the matching verification of all threat records and asset records, and synchronously records the dynamic hit rate of the rules (the ratio of the number of successful historical matchings of the rule within the current time window to the total number of matchings), which serves as an auxiliary parameter for subsequent confidence calculation. All matching results are summarized to form an initial matching result set.

[0063] Step 5: Calculate the confidence score of the matching results; The system calculates the confidence score of a single match based on the initial matching result set. The calculation formula is as follows: , in, This represents the confidence score of a single match result. For the first i The preset weight values ​​for each valid matching rule; For the first i The matching completion degree of each valid matching rule is 1 when the matching condition is fully met, and between 0 and 1 when the matching condition is a fuzzy match or partially met, depending on the matching precision. This serves as a reliable metric for the corresponding threat information. This is a quantified value for the information completeness of the corresponding asset. The upper limit of the quantifiable value for threat information credibility is fixed at 100; The upper limit of the asset information integrity quantification value is fixed at 100. The total number of valid matching rules triggered by this matching result; To adjust the matching coefficients for different scenarios, the system adds a confidence level label to each matching result and sorts them from highest to lowest value, resulting in a hierarchical matching result set with confidence level labels.

[0064] Step 6: Streaming and processing of matching results based on confidence intervals; The system performs three types of traffic splitting on the hierarchical matching result set according to the confidence threshold preset in step 1: (1) Matching results with a confidence level ≤ 60% are marked as third warning information and recorded in the system log for future reference; (2) Matching results with a confidence level in the range of 60%-90% are marked as the second warning information, generating a "threat warning to be reviewed" and pushed to the manual review stage; (3) Matching results with a confidence level of ≥90% are marked as the first warning information, generating a "highly credible threat warning". The comprehensive priority index is calculated and sorted based on the threat level and asset importance, forming a processing queue and pushing it to the warning notification stage.

[0065] The three types of early warning information are aggregated to form an effective threat early warning dataset.

[0066] Step 7: Manual review and processing of threat warnings pending review; The system pushes the "Threat Warning to be Reviewed" generated in step 6 to the manual review interaction module. Administrators can view threat details, asset details, matching criteria, and confidence calculation process breakdown data through the visual review interface. Based on supplementary evidence, they can submit three types of review results, and the system will perform corresponding processing: (1) Select “Confirm Threat”: Mark the result as “Confirmed Threat Warning” and push it to the warning notification stage; (2) Select “Exclude false alarms”: Mark the result as a false alarm warning and record it in the system log, and synchronously feed it back to the threat-asset intelligent matching module to optimize the rule weight and confidence calculation model; (3) Select “Temporarily postpone processing”: mark the warning as “to be followed up” and trigger a review reminder again after a preset time.

[0067] The threat data that has been manually reviewed and confirmed is compiled into confirmed threat warning data.

[0068] Step 8: Sending and responding to early warning notifications; The system receives the "High-Confidence Threat Warning" generated in step 6 and the "Confirmed Threat Warning" generated in step 7. It extracts the primary and backup responsible person information for the corresponding assets from the responsible person association mapping table in the asset database. Following the notification strategy preset in step 1, it generates and sends a warning notification by matching the notification channel corresponding to the threat level. The system records the notification sending time, delivery status, responsible person viewing time, and response time in real time, and determines the response status accordingly. (1) If the person in charge reviews and provides feedback on the handling plan within the preset response threshold of 1 hour, the system records complete handling information and the warning process ends; (2) If the person in charge fails to respond beyond the preset threshold, the system will automatically send a reminder notification, trigger the escalation mechanism to send a warning to the backup person in charge, and simultaneously report the overdue non-response situation to the superior administrator until the warning is handled.

[0069] Integrate data from the entire value chain to form early warning and full-process handling data.

[0070] Step 9: Optimize the matching rules and intelligence sources during the iteration phase; The system calculates the frequency of matching rule triggers, manual review confirmation rate, and exclusion rate weekly. Rules with confirmation rates below a preset threshold are automatically weighted lower, and rules with persistently high exclusion rates are marked as pending review and prompted to the administrator for correction. Based on confirmed threats and excluded false alarms from manual review feedback, the system updates the scenario correction coefficients of the confidence calculation model through incremental learning. Simultaneously, based on the effectiveness of threat warning and handling, the system adjusts the priority and acquisition strategy of threat intelligence sources to optimize intelligence source configuration.

[0071] Step 10: Optimize the operational statistics and notification configuration during the iteration phase; The system compiles key operational metrics monthly, including threat identification time, early warning accuracy, average response time of responsible personnel, and workload of manual review, generating a visual operational report. When the ratio of the number of high-confidence matching results to the number of manually confirmed results exceeds the preset fluctuation range over multiple consecutive statistical periods, the system automatically pushes threshold adjustment suggestions to the administrator. After the administrator confirms, the system updates the triage threshold configuration. Simultaneously, based on early warning notification response data, the system optimizes the notification strategy configuration, such as the combination of notification channels and response time thresholds corresponding to different threat levels, completing the full-process optimization and iteration of the system.

[0072] This invention proposes a security early warning method that integrates threat information and assets. By constructing a multi-source threat intelligence differentiation acquisition mechanism and an asset association map, it introduces vulnerability exploitation difficulty coefficients and potential impact coefficients in the feature extraction stage, adopts a confidence calculation formula in the matching stage, and establishes a comprehensive priority processing queue based on confidence-based traffic diversion. This enables multi-dimensional deep fusion and matching of threat information and asset information, solving the false positive and false negative problems caused by single-dimensional matching in existing technologies. By displaying the confidence decomposition process through a visual manual review interface and establishing a closed loop for review result feedback, it optimizes the timing and method of manual intervention, significantly reducing the workload of manual review while ensuring the accuracy of early warnings. Through the primary and backup responsible person upgrade notification mechanism and full-process response tracking, it ensures that early warning information is accurately delivered and forms a closed loop for handling. By dynamically optimizing matching rules based on operational data and adaptively adjusting thresholds, it continuously improves the accuracy and adaptability of system early warnings, realizing a shift from passive response to proactive early warning, significantly shortening threat identification time and responsible person response time, and improving overall security protection efficiency.

[0073] like Figure 3 As shown, this embodiment of the invention also provides a security early warning device 30 that integrates threat information and assets, comprising: Acquisition module 31 is used to acquire raw threat information data and target asset information; Processing module 32 is used to clean, deduplicate, and standardize the original threat information data to obtain a standardized threat feature dataset; to perform structured integration and dynamic verification and updating of the target asset information to obtain a standardized asset information dataset; to perform matching processing on the standardized threat feature dataset and the standardized asset information dataset according to a preset multi-dimensional matching rule library to obtain an initial matching result set; to calculate the confidence level of each matching result based on the initial matching result set to obtain a hierarchical matching result set with confidence level labels; to perform splitting processing on the hierarchical matching result set according to a preset confidence level interval to obtain an effective threat warning dataset; to perform matching processing on the effective threat warning dataset and preset asset target association information to obtain push warning notification data, and to record the response status of the push warning notification data to obtain warning full-process handling data.

[0074] Optionally, module 31 is specifically used for: According to the preset priority classification rules, multi-source data is obtained from multiple threat information sources. Specifically, data is obtained from threat information sources with the first preset priority using a real-time polling method, and data is obtained from threat information sources with the second preset priority using a timed synchronization method. The legality of the multi-source data is verified to obtain the original threat information data; The raw asset data is acquired through multiple preset acquisition channels, including at least one of network scanning channel, terminal agent reporting channel and manual input channel; The integrity of the original asset data is verified to obtain the target asset information.

[0075] Optionally, processing module 32 is specifically used for: The original threat information data is cleaned to obtain cleaned threat information data; The cleaned threat information data is format-converted and feature fields are extracted to obtain a standardized threat feature dataset.

[0076] Optionally, the processing module 32 is also specifically used for: The target asset information is subjected to structured classification processing to obtain an initial asset information dataset; The initial asset information dataset is monitored and verified in real time to obtain a standardized asset information dataset.

[0077] Optionally, the processing module 32 is also specifically used for: Obtain a preset multi-dimensional matching rule library, which includes a first matching rule and a second matching rule; Based on the standardized threat feature dataset and the standardized asset information dataset, the feature matching verification is performed by traversing the multi-dimensional matching rule base to obtain multiple initial matching results. Among them, the first matching rule is used for direct matching of threat features and asset basic information, and the second matching rule is used for multi-condition association matching. The initial matching results are summarized to obtain an initial matching result set.

[0078] Optionally, the processing module 32 is also specifically used for: Obtain the sum of effective rule weights, the quantified value of threat information credibility, and the quantified value of asset information integrity for each matching result in the initial matching result set; Based on the sum of effective rule weights, the quantified value of threat information credibility, and the quantified value of asset information integrity corresponding to each matching result in the initial matching result set, the confidence value of each matching result is determined. Add a corresponding confidence score label to each match result, and sort the match results according to the confidence score to obtain a hierarchical match result set with confidence score labels.

[0079] Optionally, the processing module 32 is also specifically used for: A first confidence threshold and a second confidence threshold are preset, wherein the first confidence threshold is less than the second confidence threshold; Matching results with a confidence level greater than or equal to the second confidence threshold are marked as first warning information; Matching results with a confidence level greater than or equal to the first confidence threshold and less than the second confidence threshold are marked as second warning information; Matching results with a confidence level less than the first confidence threshold are marked as third warning information and stored in the system log; The first, second, and third warning messages are aggregated to obtain an effective threat warning dataset.

[0080] Optionally, the processing module 32 is also specifically used for: Based on the asset information in the effective threat warning dataset, the corresponding primary target address information and backup target address information are extracted from the preset asset target association information; Based on the main target address information and the preset notification channel configuration rules, generate and send the first early warning notification data; Obtain the sending time, delivery status, target viewing time, and response time of the first warning notification data; When the response time is less than or equal to a preset time threshold, the sending time, delivery status, target viewing time, and response time of the first warning notification data are integrated to obtain the warning full-process handling data. When the response time exceeds a preset response time threshold, a second early warning notification is generated and sent according to the backup target address information and preset notification channel configuration rules. The sending time, delivery status, viewing time, and response time of the backup target are obtained for the second early warning notification data; The sending time, delivery status, viewing time of backup targets, and response time of the second early warning notification data are integrated to obtain the early warning full-process handling data.

[0081] It should be noted that this device is a device corresponding to the above method. All implementation methods in the above method embodiments are applicable to this embodiment and can achieve the same technical effect.

[0082] like Figure 4 As shown, this embodiment of the invention also provides a computing device 40, including a processor 41, a memory 42, and a program or instructions stored in the memory 42 and executable on the processor 41. When the program or instructions are executed by the processor 41, they implement the various processes of the above-described security early warning method embodiment for fusing threat information and assets, and achieve the same technical effects. To avoid repetition, they will not be described again here. It should be noted that the computing device in this embodiment of the invention includes the aforementioned mobile electronic devices and non-mobile electronic devices.

[0083] The above are preferred embodiments of the present invention. It should be noted that, for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. A security early warning method that integrates threat information and asset information, characterized in that, include: Acquire raw threat information data and target asset information; The original threat information data is cleaned, deduplicated, and standardized to obtain a standardized threat feature dataset; The target asset information is structured, integrated, and dynamically verified and updated to obtain a standardized asset information dataset; According to the preset multi-dimensional matching rule library, the standardized threat feature dataset and the standardized asset information dataset are matched to obtain an initial matching result set; Based on the initial matching result set, the confidence level of each matching result is calculated to obtain a hierarchical matching result set with confidence level labels; According to the preset confidence level range, the hierarchical matching result set is split into multiple streams to obtain an effective threat warning dataset; The effective threat warning dataset and the preset asset target association information are matched to obtain warning notification data, and the response status of the warning notification data is recorded to obtain warning full-process handling data.

2. The security early warning method for integrating threat information and assets according to claim 1, characterized in that, The acquisition of raw threat information data and target asset information includes: According to the preset priority classification rules, multi-source data is obtained from multiple threat information sources. Specifically, data is obtained from threat information sources with the first preset priority using a real-time polling method, and data is obtained from threat information sources with the second preset priority using a timed synchronization method. The legality of the multi-source data is verified to obtain the original threat information data; The raw asset data is acquired through multiple preset acquisition channels, including at least one of network scanning channel, terminal agent reporting channel and manual input channel; The integrity of the original asset data is verified to obtain the target asset information.

3. The security early warning method for integrating threat information and assets according to claim 1, characterized in that, The original threat information data is cleaned, deduplicated, and standardized to obtain a standardized threat feature dataset, including: The original threat information data is cleaned to obtain cleaned threat information data; The cleaned threat information data is format-converted and feature fields are extracted to obtain a standardized threat feature dataset.

4. The security early warning method for integrating threat information and assets according to claim 1, characterized in that, The target asset information is structured, integrated, and dynamically verified and updated to obtain a standardized asset information dataset, including: The target asset information is subjected to structured classification processing to obtain an initial asset information dataset; The initial asset information dataset is monitored and verified in real time to obtain a standardized asset information dataset.

5. The security early warning method for integrating threat information and assets according to claim 1, characterized in that, According to a preset multi-dimensional matching rule base, the standardized threat feature dataset and the standardized asset information dataset are matched to obtain an initial matching result set, including: Obtain a preset multi-dimensional matching rule library, which includes a first matching rule and a second matching rule; Based on the standardized threat feature dataset and the standardized asset information dataset, the feature matching verification is performed by traversing the multi-dimensional matching rule base to obtain multiple initial matching results. Among them, the first matching rule is used for direct matching of threat features and asset basic information, and the second matching rule is used for multi-condition association matching. The initial matching results are summarized to obtain an initial matching result set.

6. The security early warning method for integrating threat information and assets according to claim 1, characterized in that, Based on the initial matching result set, the confidence level of each matching result is calculated to obtain a hierarchical matching result set with confidence level labels, including: Obtain the sum of effective rule weights, the quantified value of threat information credibility, and the quantified value of asset information integrity for each matching result in the initial matching result set; Based on the sum of effective rule weights, the quantified value of threat information credibility, and the quantified value of asset information integrity corresponding to each matching result in the initial matching result set, the confidence value of each matching result is determined. Add a corresponding confidence score label to each match result, and sort the match results according to the confidence score to obtain a hierarchical match result set with confidence score labels.

7. The security early warning method for integrating threat information and assets according to claim 1, characterized in that, The hierarchical matching result set is split according to a preset confidence interval to obtain an effective threat warning dataset, including: A first confidence threshold and a second confidence threshold are preset, wherein the first confidence threshold is less than the second confidence threshold; Matching results with a confidence level greater than or equal to the second confidence threshold are marked as first warning information; Matching results with a confidence level greater than or equal to the first confidence threshold and less than the second confidence threshold are marked as second warning information; Matching results with a confidence level less than the first confidence threshold are marked as third warning information and stored in the system log; The first, second, and third warning messages are aggregated to obtain an effective threat warning dataset.

8. The security early warning method for integrating threat information and assets according to claim 1, characterized in that, The effective threat warning dataset and preset asset target association information are matched to obtain warning notification data, and the response status of the warning notification data is recorded to obtain warning full-process handling data, including: Based on the asset information in the effective threat warning dataset, the corresponding primary target address information and backup target address information are extracted from the preset asset target association information; Based on the main target address information and the preset notification channel configuration rules, generate and send the first early warning notification data; Obtain the sending time, delivery status, target viewing time, and response time of the first warning notification data; When the response time is less than or equal to a preset time threshold, the sending time, delivery status, target viewing time, and response time of the first warning notification data are integrated to obtain the warning full-process handling data. When the response time exceeds a preset response time threshold, a second early warning notification is generated and sent according to the backup target address information and preset notification channel configuration rules. The sending time, delivery status, viewing time, and response time of the backup target are obtained for the second early warning notification data; The sending time, delivery status, viewing time of backup targets, and response time of the second early warning notification data are integrated to obtain the early warning full-process handling data.

9. A security early warning device that integrates threat information and asset information, characterized in that, include: The acquisition module is used to acquire raw threat information data and target asset information; The processing module is used to clean, deduplicate, and standardize the original threat information data to obtain a standardized threat feature dataset. The target asset information is structured, integrated, and dynamically verified and updated to obtain a standardized asset information dataset; the standardized threat feature dataset and the standardized asset information dataset are matched according to a preset multi-dimensional matching rule library to obtain an initial matching result set; Based on the initial matching result set, the confidence level of each matching result is calculated to obtain a hierarchical matching result set with confidence level labels; According to the preset confidence level range, the hierarchical matching result set is split into multiple streams to obtain an effective threat warning dataset; The effective threat warning dataset and the preset asset target association information are matched to obtain push warning notification data, and the response status of the push warning notification data is recorded to obtain warning full-process handling data.

10. A computing device, characterized in that, include: A processor, a memory storing a computer program, wherein the computer program, when executed by the processor, performs the method as described in any one of claims 1 to 8.