A threat intelligence lifecycle management method and device

CN122802192APending Publication Date: 2026-09-22NEW H3C NETWORK INFORMATION SECURITY SOFTWARE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610822179.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-08
Publication Date
2026-09-22

AI Technical Summary

Technical Problem

[0010]本申请提供一种威胁情报生命周期管理方法及装置,用以克服传统方案由于依赖静态特征的、固定有效期导致的存活期计算结果不可靠、不准确的问题

Benefits of technology

本申请通过记录威胁情报在真实网络环境中的多次出现时刻,动态计算其首次出现至今的总时长、相邻两次出现的时间间隔,并结合历史存活期与间隔的差值确定剩余存活期,进而依据总时长所属的数值区间匹配对应的存活级别与存活系数,最终利用目标公式自适应地更新当前存活期。该机制使得威胁情报的生命周期不再依赖固定时长或静态源属性,而是完全由其实际活跃行为驱动。由此,系统能够自动识别出于活跃期的情报并延长期有效窗口,同时加速失效情报的淘汰,显著提升了情报库的整体时效性与准确性,降低人工复核成本,并克服了传统方案中模型不可解释、参数调整困难等缺陷,增强了网络安全产品的威胁检测与响应能力。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122802192A_ABST
    Figure CN122802192A_ABST
Patent Text Reader

Abstract

The application provides a threat intelligence lifecycle management method and device. The method comprises: determining, for threat intelligence that has been recorded in a threat intelligence library and is recorded again, a time when the threat intelligence is recorded for the first time, a time when the threat intelligence is recorded last time, and a time when the threat intelligence is recorded currently; calculating a first difference value between the time when the threat intelligence is recorded currently and the time when the threat intelligence is recorded for the first time, and a second difference value between the time when the threat intelligence is recorded currently and the time when the threat intelligence is recorded last time; obtaining a historical survival period of the threat intelligence, calculating a difference value between the historical survival period and the second difference value, and obtaining a remaining survival period of the threat intelligence; matching the first difference value with a preset numerical interval to determine a survival level of the threat intelligence, determining a survival coefficient according to the survival level, and calculating a current survival period of the threat intelligence according to a target formula. The method can dynamically and automatically evaluate the survival state of the threat intelligence, quantify the intelligence value, and has good interpretability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cybersecurity technology, and in particular to a method and apparatus for threat intelligence lifecycle management. Background Technology

[0002] Threat intelligence (TI) refers to structured information used to identify and respond to cyberattacks. It is typically deployed in security information management platforms, threat detection and response products, and other similar products to assist security systems in proactively detecting attack behaviors and improving defense initiative and response efficiency. Threat intelligence lifecycle management refers to closed-loop control of the entire process of intelligence collection, analysis, distribution, and failure feedback. Its value lies in ensuring the timeliness and accuracy of intelligence, reducing manual operation costs, and supporting efficient security operations.

[0003] There are currently two lifecycle management solutions for threat intelligence: The first approach is a lifecycle management solution based on a fixed duration. This solution pre-determines a fixed validity period (such as 90 days or 180 days) for all threat intelligence. The timer starts from the moment the intelligence is generated or stored in the database. After the expiration date, the system will automatically mark it as invalid, or trigger a manual review process where security personnel decide whether to extend the validity period.

[0004] The second approach is a lifecycle management scheme based on intelligence source attribute assessment. This scheme uses machine learning models to analyze static characteristics of intelligence sources, such as credibility, field completeness, threat type, and malice level, and automatically calculates and assigns an initial effective duration for each piece of intelligence based on these characteristics.

[0005] Both of the above solutions have significant drawbacks, specifically in the following aspects: First, the fixed validity period mechanism lacks dynamic adaptability. In real-world networks, many malicious IPs, domains, and other attack infrastructures are often abandoned by attackers within a short period. The first approach, using a fixed validity period, retains expired intelligence for weeks or even months, causing defense strategies to lag significantly behind actual threats. Furthermore, the validity period parameter usually relies on manual experience for setting; an excessively high value will trigger false alarms, while an excessively low value will result in missed detections.

[0006] Second, the decision-making logic of machine learning models is opaque. The validity period determination given by the model in the second approach lacks interpretability. When a piece of intelligence is determined to be invalid by the model, security personnel cannot trace the specific basis for the model's determination. This problem is particularly prominent in scenarios where high-value threat intelligence requires intensive manual review, potentially leading to serious operational risks.

[0007] Third, the inconsistent quality of intelligence sources leads to assessment failure. The second approach relies excessively on the static attributes of intelligence sources to determine their validity. However, in real-world environments, intelligence sources commonly suffer from complex issues such as missing fields, cross-data source referencing, and conflicting information aggregation, making data quality difficult to guarantee. Directly assessing intelligence validity based on such unreliable source attributes lacks scientific basis and cannot guarantee accuracy.

[0008] Fourth, maintaining the accuracy of threat intelligence is costly. Both the first and second approaches heavily rely on manual verification for intelligence effectiveness. Faced with massive amounts of intelligence, this manual management method is not only inefficient and costly, but also fails to meet real-time response requirements.

[0009] In summary, traditional threat intelligence lifecycle management solutions have significant shortcomings, making it difficult to effectively guarantee the timeliness and accuracy of threat intelligence, and resulting in the inability to effectively identify new attack methods such as advanced persistent threats. Therefore, there is an urgent need for a dynamic, efficient, and interpretable threat intelligence lifecycle management solution. Summary of the Invention

[0010] This application provides a threat intelligence lifecycle management method and apparatus to overcome the problems of unreliable and inaccurate lifecycle calculation results caused by the reliance on static features and fixed validity periods in traditional solutions.

[0011] Specifically, this application provides the following technical solution: Firstly, this application provides a method for threat intelligence lifecycle management, the method comprising: For target threat intelligence that is already in the threat intelligence database and is recorded again, determine the time when the target threat intelligence was first recorded, the time when it was last recorded, and the time when it is currently recorded; Calculate a first difference between the currently recorded time and the first recorded time, and a second difference between the currently recorded time and the last recorded time; Obtain the historical survival time calculated when the target threat intelligence was last recorded, calculate the difference between the historical survival time and the second difference, and obtain the remaining survival time of the target threat intelligence; The first difference is matched with a preset numerical range to determine the survival level of the target threat intelligence, and the survival coefficient of the target threat intelligence is determined based on the survival level of the target threat intelligence. The current lifespan of the target threat intelligence is calculated according to the target formula, which is:

[0012] in, For the current lifespan, For the remaining lifespan, This is the interval threshold for the numerical interval in the first difference matching. The first difference, This represents the survival coefficient.

[0013] Secondly, this application provides a threat intelligence lifecycle management device, the device comprising: The first module is used to determine the time when the target threat intelligence was first recorded, the time when it was last recorded, and the time when it is currently recorded for a target threat intelligence that is already in the threat intelligence database and is being recorded again. The second module is used to calculate a first difference between the currently recorded time and the first recorded time, and a second difference between the currently recorded time and the last recorded time; The third module is used to obtain the historical survival period calculated when the target threat intelligence was last recorded, calculate the difference between the historical survival period and the second difference, and obtain the remaining survival period of the target threat intelligence. The fourth module is used to match the first difference with a preset numerical range to determine the survival level of the target threat intelligence, and to determine the survival coefficient of the target threat intelligence based on the survival level of the target threat intelligence. The fifth module is used to calculate the current lifespan of the target threat intelligence according to the target formula, which is:

[0014] in, For the current lifespan, For the remaining lifespan, This is the interval threshold for the numerical interval in the first difference matching. The first difference, This represents the survival coefficient.

[0015] Thirdly, this application provides an electronic device, comprising: A memory, one or more processors; the memory is coupled to the processors; wherein the memory stores computer program code, the computer program code including computer instructions, and when the computer instructions are executed by the processor, the electronic device performs the method described above.

[0016] Fourthly, this application provides a computer-readable storage medium including computer instructions that, when executed on an electronic device, cause the electronic device to perform the method described above.

[0017] Fifthly, this application provides a computer program product that, when run on a computer, causes the computer to perform the method described above.

[0018] The technical solution provided in this application has the following beneficial effects: This application records the multiple occurrences of threat intelligence in a real network environment, dynamically calculates the total duration from its first appearance to the present, the time interval between two consecutive appearances, and determines the remaining lifespan by combining the difference between historical lifespan and interval. Then, it matches the corresponding lifespan level and lifespan coefficient based on the numerical range to which the total duration belongs, and finally adaptively updates the current lifespan using a target formula. This mechanism makes the lifespan of threat intelligence no longer dependent on a fixed duration or static source attributes, but entirely driven by its actual active behavior. Therefore, the system can automatically identify intelligence in its active period and extend its effective window, while accelerating the elimination of expired intelligence, significantly improving the overall timeliness and accuracy of the intelligence database, reducing manual review costs, and overcoming the shortcomings of traditional solutions such as uninterpretable models and difficulties in parameter adjustment, thus enhancing the threat detection and response capabilities of network security products.

[0019] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application. Attached Figure Description

[0020] The accompanying drawings, which are incorporated in and form part of this application, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0021] Figure 1 A flowchart illustrating the threat intelligence lifecycle management method provided in this application embodiment; Figure 2 A schematic diagram of the framework of the threat intelligence lifecycle management device provided in the embodiments of this application; Figure 3 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0022] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application.

[0023] The terminology used in this application is for the purpose of describing particular embodiments only and is not intended to be limiting of the application. The singular forms “a,” “the,” and “the” used herein are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any and all possible combinations of one or more of the corresponding listed items.

[0024] It should be understood that although the terms first, second, third, etc., may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, without departing from the scope of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to determination."

[0025] This application provides a method and apparatus for threat intelligence lifecycle management, which aims to dynamically and automatically update the lifespan of threat intelligence, improve the timeliness and accuracy of intelligence management, and thereby enhance network security defense capabilities.

[0026] In this application, the lifespan refers to the time period from when threat intelligence is generated or confirmed to be valid until it is determined to be invalid. This application performs corresponding lifecycle management operations based on the lifespan of threat intelligence, such as maintaining the intelligence's validity, marking it as invalid, or triggering a review, in order to improve the overall quality and response efficiency of the intelligence database.

[0027] Specifically, when a threat intelligence is recorded by a security device or intelligence platform, it means that the attack behavior indicated by that intelligence has been observed or triggered in the current environment. For the first collected threat intelligence, the system will store it in the database (storing the intelligence and its basic attributes in the threat intelligence database and assigning it an initial lifespan). The intelligence stored in the database can be used for subsequent threat detection or blocking.

[0028] If a threat intelligence already in the database is recorded again, it indicates that the threat behavior corresponding to that intelligence is still active or has reappeared. At this point, the system automatically triggers a threat intelligence lifespan calculation process to determine the updated lifespan. Based on this calculation result, the system will perform lifecycle management operations such as extending the lifespan, shortening the lifespan, keeping it unchanged, or immediately deactivating it. This achieves automated and dynamic adjustment of the lifespan, effectively avoiding false alarms or missed alarms caused by fixed-duration mechanisms.

[0029] The aforementioned intelligence repository specifically refers to a threat intelligence repository, whose purpose is to store, maintain, and query threat intelligence and its metadata, such as its lifespan. This repository is typically deployed on security information and incident management platforms, threat detection and response systems, next-generation firewalls, or security orchestration automation and response products. These products perform real-time matching and detection of network traffic, system logs, or file behavior based on the lifespan status of the intelligence in the repository: for intelligence within its lifespan, alerts or blocking are triggered; for expired intelligence, automatic filtering or demotion is performed, thereby reducing false positive rates, improving detection accuracy, and minimizing manual intervention.

[0030] The core of this application lies in its approach: eliminating the need for manually preset fixed expiration dates and avoiding reliance on static attributes of unreliable intelligence sources. Instead, it automatically updates the lifespan of each intelligence piece based on dynamic observation records in the real-world environment. Furthermore, interpretable computational logic ensures the accuracy and reliability of the lifespan. This significantly improves the efficiency of threat intelligence utilization in actual security operations, ultimately enhancing overall cybersecurity protection capabilities.

[0031] The technical solution and its beneficial effects of this application will be described in detail below through specific embodiments.

[0032] This application provides a method for threat intelligence lifecycle management, such as... Figure 1 As shown, the method may include the following steps: Step 110: For target threat intelligence that is already in the threat intelligence database and is recorded again, determine the time when the target threat intelligence was first recorded, the time when it was last recorded, and the time when it is currently recorded; The method described in this application is applicable to various cybersecurity products that require dynamic maintenance of the effectiveness of threat intelligence, including but not limited to security information and incident management platforms, threat detection and response systems, next-generation firewalls, security orchestration automation and response platforms, and independent threat intelligence database management systems.

[0033] Specifically, for threat intelligence recorded for the first time, it is added to the database, and its lifespan is set to an initial value (initial lifespan value). This lifespan will decay naturally over time. For threat intelligence that is already in the database and is recorded again, its lifespan is calculated and updated through steps 110 to 150.

[0034] The initial value of the lifespan is defined as follows: Initial value of lifespan, in this embodiment .

[0035] In this application, the threat intelligence database stores historical information for each piece of intelligence, including the timestamp of each time the intelligence was observed or triggered. When a threat intelligence that has already been entered into the database is recorded again by a security device, the system treats it as a target threat intelligence and extracts three key time points from it: the time of first recording, the time of the last recording, and the time of the current recording.

[0036] The three time definitions above are as follows: The time when this intelligence was first recorded; The last time this information was recorded; The current time when this information was recorded.

[0037] These timestamps are used for subsequent dynamic calculations of lifespan. In this embodiment, the times mentioned above are in days. In practical applications, they can also be expressed in hours or other time units.

[0038] Step 120: Calculate the first difference between the currently recorded time and the first recorded time, and the second difference between the currently recorded time and the last recorded time; Specifically, the second difference can be calculated as follows: calculate the difference between the last recorded time and the first recorded time (called difference A), and the difference between the current recorded time and the first recorded time (i.e., the first difference); calculate the difference between the first difference and difference A to obtain the difference between the current recorded time and the last recorded time (i.e., the second difference).

[0039] The differences A, the first difference, and the second difference are defined as follows: Difference A: The time elapsed since the last recorded instance of this information.

[0040] The first difference indicates the time elapsed since the information was first recorded.

[0041] The second difference represents the natural decay time of the information, that is, the time elapsed since the last time the information was last recorded.

[0042] In this embodiment, the differences mentioned above are expressed in days. In practical applications, they can also be expressed in hours or other time units.

[0043] Step 130: Obtain the historical survival time calculated when the target threat intelligence was last recorded, calculate the difference between the historical survival time and the second difference, and obtain the remaining survival time of the target threat intelligence; Specifically, the system reads the target threat intelligence from the threat intelligence database and calculates its lifespan (i.e., historical lifespan) when it was last recorded. Since the second difference of time has passed from the last record to the current record, the lifespan of the intelligence is reduced accordingly. That is, remaining lifespan = historical lifespan - second difference.

[0044] Historical lifespan and remaining lifespan are defined as follows: Historical lifespan; : Remaining lifetime, representing the remaining lifetime value after natural decay since the last recorded and calculated lifetime.

[0045] It should be noted that if the remaining lifespan calculated in the above manner is greater than 0, it indicates that the intelligence is still valid; if it is less than 0, it indicates that the intelligence has expired. For intelligence that has expired and is recorded again, this application introduces a degradation prevention mechanism to reset the current lifespan of the intelligence to its initial value, as shown below:

[0046] This mechanism is specifically designed for "dormant-resurrection" type intelligence. When intelligence is detected to have been dormant for a long time and then become active again, a new round of lifespan calculation is initiated, which effectively ensures the stability and dynamic adaptability of the system in intermittent intelligence scenarios.

[0047] Step 140: Match the first difference with a preset numerical range to determine the survival level of the target threat intelligence, and determine the survival coefficient of the target threat intelligence based on the survival level of the target threat intelligence; Specifically, the system presets multiple consecutive numerical intervals, each corresponding to a survival level. Each survival level is pre-associated with a survival coefficient. The system matches the first difference calculated in step 120 with these numerical intervals to determine the survival level of the target threat intelligence, and then obtains the corresponding survival coefficient. This coefficient is used to adjust the dynamic update range of the survival period: the higher the activity level of the intelligence in a shorter period of time, the greater its value and the greater the survival reward.

[0048] Step 150: Calculate the current lifespan of the target threat intelligence according to the target formula, whereby the target formula is:

[0049] The parameters in the above formula are defined as follows: The current lifespan of the intelligence, that is, the length of time after this update the intelligence should remain valid from the current moment; The remaining lifespan of intelligence is the remaining value after natural decay, calculated from the historical lifespan when the intelligence was last recorded before this update. The threshold value for the numerical range in the first difference matching; First difference; Survival rate of intelligence; This indicates the remaining lifespan of the intelligence at the current survival level. The larger this value, the higher the intelligence's activity level.

[0050] This application achieves dynamic adaptive adjustment of the lifespan based on the actual active history of intelligence through the aforementioned method. On the one hand, it eliminates the need to manually set a fixed validity period or rely on static attributes of unreliable intelligence sources. On the other hand, through closed-loop feedback calculation based on actual recording intervals and remaining lifespan, the lifespan can truly reflect the continuous activity level of threat behavior, significantly improving the timeliness and accuracy of intelligence in the intelligence database, reducing false positives and false negatives, and enhancing network security protection effectiveness.

[0051] Optionally, the method specifically determines the survival coefficient of the target threat intelligence in the following ways: if the historical survival period is less than or equal to the initial survival period value, then the survival coefficient of the target threat intelligence is determined as the initial survival coefficient value corresponding to the survival level; if the historical survival period is greater than the initial survival period value, then the survival coefficient of the target threat intelligence is determined as the ratio of the historical survival period to the initial survival period value. As shown below:

[0052]

[0053]

[0054]

[0055]

[0056] In the above formula, the parameters are defined as follows: Survivability coefficient of threat intelligence: : The initial survival coefficient corresponding to the survival level of the threat intelligence.

[0057] For example, this application pre-classifies threat intelligence into seven survival levels (S, A, B, C, D, E, O) based on its activity level in historical records. A higher survival level indicates that the threat intelligence survives longer and receives a greater survival bonus when recorded again. Each level corresponds to a threshold range and an initial survival coefficient. The threshold range is generally the maximum value within the corresponding range (not exceeding the initial survival coefficient). Specifically, the threshold range for the lowest level, O, is the initial survival coefficient. See the table below:

[0058] Table 1 By comparing the initial difference in threat intelligence with a numerical range, the range in which the initial difference falls is determined, thus obtaining the survival level of the threat intelligence. Different survival levels have their own initial survival coefficient values. These initial survival coefficient values ​​are calculated using the hybrid value density assessment model shown below:

[0059]

[0060]

[0061] In the above formula, the parameters are defined as follows: Initial values ​​of the survival coefficient corresponding to each survival level; The power-law term represents the probability density function of intelligence being reused per unit of time, used to measure the value density of different levels of intelligence in the short term. Generally, the higher the level of intelligence, the more frequently it is reused by multiple families in the short term, indicating a higher value density. For short-term value weighting coefficients, The value decay index is used; the baseline constant 1 ensures the intelligence value density benchmark and model stability of the model; in this embodiment... , ; Logarithmic terms are used to ensure a smooth and continuous gradient distribution of intelligence value at different levels, preventing excessive amplification of the value density of high-level intelligence. This is the long-term value gradient coefficient. The upper limit of the valuation is usually the maximum value of the range threshold; in this example... , .

[0062] The hybrid value density assessment model of this application, as the pre-calculation unit of the aforementioned target formula, calculates the initial value of the survival coefficient of each survival level by integrating the power law decay and logarithmic gradient mechanism. It can not only quickly amplify the value of highly active intelligence and amplify the value density difference between intelligence of different levels, but also ensure that the gradient is smooth and controllable. It can flexibly adapt to the value assessment needs of different security environments, making the calculation results of the target formula more consistent with real scenarios.

[0063] The aforementioned hybrid design enables the model to both accurately identify high-value, high-density intelligence in the short term and maintain the consistency and rationality of the entire intelligence value system. This is achieved through parameters... , , Its coordinated adjustment can flexibly adapt to the needs of intelligence value density assessment in different security environments.

[0064] In summary, this application has at least the following significant beneficial effects: First, achieve automated management of the threat intelligence lifecycle. This application introduces a threat intelligence survival model based on a hierarchical strategy (i.e., the calculation process from steps 110 to 150), transforming the lifecycle management mode of threat intelligence from a passive mode relying on static characteristics and fixed validity periods in traditional schemes to a dynamic and adaptive mode based on actual threat activities. It can simulate the natural depletion of intelligence's lifespan while also capturing the characteristic of intelligence being reused, and dynamically providing non-linear survival rewards. The system can automatically monitor the activity status of intelligence, predict its expiration time, and ultimately achieve automated lifecycle management of the intelligence repository, significantly reducing the need for manual intervention.

[0065] Second, improve the accuracy and interpretability of threat intelligence value assessment. This application proposes a hybrid value density assessment model that scientifically quantifies the differences in value density of threat intelligence at different survival levels. By classifying threat intelligence through quantified survival values, it can effectively distinguish between high-frequency active intelligence and botnet intelligence, and is particularly suitable for quantifying the potential threat level and severity of short-term bursts of intelligence. The model combines the sensitivity of the power-law term (providing significant rewards to highly active intelligence) with the smoothness of the logarithmic term (avoiding excessive suppression of low-activity intelligence), allowing highly active intelligence to receive non-linear and reasonable survival rewards. Its decision-making process is logically transparent, and the physical meaning of each parameter is clear, overcoming the problem of uninterpretable decisions caused by the black-box nature of traditional machine learning. As a result, the workload of security analysts manually verifying intelligence is significantly reduced, and the accuracy and efficiency of analysis are effectively improved.

[0066] Based on the same inventive concept, this application provides a threat intelligence lifecycle management device, the structural schematic diagram of which is shown below. Figure 2As shown, it specifically includes: The first module 210 is used to determine the time when the target threat intelligence was first recorded, the time when it was last recorded, and the time when it is currently recorded for a target threat intelligence that is already in the threat intelligence database and is being recorded again. The second module 220 is used to calculate a first difference between the currently recorded time and the first recorded time, and a second difference between the currently recorded time and the last recorded time; The third module 230 is used to obtain the historical survival period calculated when the target threat intelligence was last recorded, calculate the difference between the historical survival period and the second difference, and obtain the remaining survival period of the target threat intelligence. The fourth module 240 is used to match the first difference with a preset numerical range to determine the survival level of the target threat intelligence, and to determine the survival coefficient of the target threat intelligence based on the survival level of the target threat intelligence. Module 250 is used to calculate the current lifespan of the target threat intelligence according to the target formula, which is:

[0067] in, For the current lifespan, For the remaining lifespan, This is the interval threshold for the numerical interval in the first difference matching. The first difference, This represents the survival coefficient.

[0068] Optionally, the device further includes: The sixth module is used to add the threat intelligence to the threat intelligence database for the first recorded threat intelligence, and set the lifespan of the threat intelligence to an initial lifespan value.

[0069] Optionally, the fourth module 240 determines the survival coefficient of the target threat intelligence in the following ways: If the historical survival period is less than or equal to the initial survival period value, then the survival coefficient of the target threat intelligence is determined as the initial survival coefficient value corresponding to the survival level; If the historical survival period is greater than the initial survival period value, then the survival coefficient of the target threat intelligence is determined as the ratio of the historical survival period to the initial survival period value.

[0070] Optionally, the device further includes: The seventh module is used to calculate the initial survival coefficient values ​​corresponding to each survival level using a hybrid value density assessment model, which is as follows:

[0071]

[0072]

[0073] in, For power-law terms, For short-term value weighting coefficients, Value depreciation index; For logarithmic terms, This is the long-term value gradient coefficient. This represents the maximum value of the interval threshold.

[0074] Optionally, the threshold value of the numerical range corresponding to the non-lowest survival level is the maximum value of the corresponding numerical range, and the threshold value of the data range corresponding to the lowest survival level is the initial value of the survival period.

[0075] Optionally, the device further includes: The eighth module is used to determine the current survival time of the target threat intelligence as the initial survival time value when the remaining survival time is less than 0.

[0076] The apparatus provided in this application is used to perform the corresponding method described above. Therefore, the beneficial effects it can achieve can be referred to the beneficial effects of the corresponding method described above, and will not be repeated here.

[0077] This application provides an electronic device that may include a memory and one or more processors. The memory stores computer program code, including computer instructions. When the processor executes the computer instructions, the electronic device can perform various functions or steps of the above-described method embodiments.

[0078] The structure of this electronic device can be referenced. Figure 3 The structure of the electronic device 100 shown.

[0079] For example, the processor mentioned above can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.

[0080] This application provides a computer-readable storage medium including computer instructions that, when executed on an electronic device, cause the electronic device to perform the various functions or steps of the above-described method embodiments.

[0081] The aforementioned computer-readable storage media include, but are not limited to, any of the following: USB flash drive, portable hard drive, read-only memory (ROM), random access memory (RAM), magnetic disk or optical disk, and other media capable of storing program code.

[0082] This application provides a computer program product that, when run on a computer, causes the computer to perform various functions or steps of the above-described method embodiments.

[0083] The electronic devices, computer-readable storage media, and computer program products provided in the above embodiments are all used to execute the corresponding methods provided above. Therefore, the beneficial effects they can achieve can be referred to the beneficial effects in the corresponding methods provided above, and will not be repeated here.

[0084] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0085] The specific implementation process of the functions and roles of each unit / module in the above device can be found in the implementation process of the corresponding steps in the above method, and will not be repeated here.

[0086] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to in the description of the method embodiments. The device embodiments described above are merely illustrative. The units / modules described as separate components may or may not be physically separate. The components shown as units / modules may or may not be physical units / modules, that is, they may be located in one place or distributed across multiple network units / modules. Some or all of the units / modules can be selected to achieve the purpose of this application according to actual needs. Those skilled in the art can understand and implement this without creative effort.

[0087] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.

Claims

1. A method for threat intelligence lifecycle management, characterized in that, The method includes: For target threat intelligence that is already in the threat intelligence database and is recorded again, determine the time when the target threat intelligence was first recorded, the time when it was last recorded, and the time when it is currently recorded; Calculate a first difference between the currently recorded time and the first recorded time, and a second difference between the currently recorded time and the last recorded time; Obtain the historical survival time calculated when the target threat intelligence was last recorded, calculate the difference between the historical survival time and the second difference, and obtain the remaining survival time of the target threat intelligence; The first difference is matched with a preset numerical range to determine the survival level of the target threat intelligence, and the survival coefficient of the target threat intelligence is determined based on the survival level of the target threat intelligence. The current lifespan of the target threat intelligence is calculated according to the target formula, which is: ; in, For the current lifespan, For the remaining lifespan, This is the interval threshold for the numerical interval in the first difference matching. The first difference, This represents the survival coefficient.

2. The method according to claim 1, characterized in that, The method further includes: For threat intelligence recorded for the first time, the threat intelligence is added to the threat intelligence database, and the lifespan of the threat intelligence is set to the initial lifespan value.

3. The method according to claim 2, characterized in that, The method specifically determines the survival coefficient of the target threat intelligence in the following ways: If the historical survival period is less than or equal to the initial survival period value, then the survival coefficient of the target threat intelligence is determined as the initial survival coefficient value corresponding to the survival level; If the historical survival period is greater than the initial survival period value, then the survival coefficient of the target threat intelligence is determined as the ratio of the historical survival period to the initial survival period value.

4. The method according to claim 3, characterized in that, The method further includes: The initial survival coefficient values ​​corresponding to each survival level were calculated using a hybrid value density assessment model, which is as follows: ; ; ; in, For power-law terms, For short-term value weighting coefficients, Value depreciation index; For logarithmic terms, This is the long-term value gradient coefficient. This represents the maximum value of the interval threshold.

5. The method according to claim 2, characterized in that, The threshold value of the numerical range corresponding to the non-lowest survival level is the maximum value of the corresponding numerical range, and the threshold value of the data range corresponding to the lowest survival level is the initial value of the survival period.

6. The method according to claim 2, characterized in that, The method further includes: When the remaining lifespan is less than 0, the current lifespan of the target threat intelligence is determined as the initial lifespan value.

7. A threat intelligence lifecycle management device, characterized in that, The device includes: The first module is used to determine the time when the target threat intelligence was first recorded, the time when it was last recorded, and the time when it is currently recorded for a target threat intelligence that is already in the threat intelligence database and is being recorded again. The second module is used to calculate a first difference between the currently recorded time and the first recorded time, and a second difference between the currently recorded time and the last recorded time; The third module is used to obtain the historical survival period calculated when the target threat intelligence was last recorded, calculate the difference between the historical survival period and the second difference, and obtain the remaining survival period of the target threat intelligence. The fourth module is used to match the first difference with a preset numerical range to determine the survival level of the target threat intelligence, and to determine the survival coefficient of the target threat intelligence based on the survival level of the target threat intelligence. The fifth module is used to calculate the current lifespan of the target threat intelligence according to the target formula, which is: ; in, For the current lifespan, For the remaining lifespan, This is the interval threshold for the numerical interval in the first difference matching. The first difference, This represents the survival coefficient.

8. The apparatus according to claim 7, characterized in that, The device further includes: The sixth module is used to add the threat intelligence to the threat intelligence database for the first recorded threat intelligence, and set the lifespan of the threat intelligence to an initial lifespan value.

9. The apparatus according to claim 8, characterized in that, The fourth module specifically determines the survival coefficient of the target threat intelligence in the following ways: If the historical survival period is less than or equal to the initial survival period value, then the survival coefficient of the target threat intelligence is determined as the initial survival coefficient value corresponding to the survival level; If the historical survival period is greater than the initial survival period value, then the survival coefficient of the target threat intelligence is determined as the ratio of the historical survival period to the initial survival period value.

10. An electronic device, characterized in that, include: A memory, one or more processors; the memory is coupled to the processors; wherein the memory stores computer program code, the computer program code including computer instructions, and when the computer instructions are executed by the processor, the electronic device performs the method as described in any one of claims 1-6.

11. A computer-readable storage medium comprising computer instructions, characterized in that, When the computer instructions are executed on the electronic device, the electronic device causes the electronic device to perform the method as described in any one of claims 1-6.

12. A computer program product, characterized in that, When the computer program product is run on a computer, it causes the computer to perform the method as described in any one of claims 1-6.