Multi-dimensional threat intelligence credibility assessment method based on content similarity value

Through the multi-dimensional threat intelligence credibility assessment method, the threat intelligence is evaluated by using similarity values and preset characteristics, solving the problem of single threat intelligence credibility assessment in the existing technology, and improving the accuracy and timeliness of intelligence products.

WO2025152458A1PCT designated stage expired Publication Date: 2025-07-24GUANGXI POWER GRID LLC

Patent Information

Application Number
PCT/CN2024/116592
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-16
Filing Date
2024-09-03
Publication Date
2025-07-24

AI Technical Summary

Technical Problem

The credibility assessment method for threat intelligence in the prior art is single and cannot be conducted in multi-dimensional assessment, resulting in the timeliness and accuracy of intelligence products that cannot be guaranteed.

Method used

A multi-dimensional threat intelligence credibility assessment method based on content similarity values is adopted. By calculating the similarity values and preset characteristics of threat intelligence and trusted intelligence, threat intelligence is evaluated in two layers to generate the most accurate threat intelligence sequence.

Benefits of technology

It improves the accuracy and timeliness of threat intelligence and ensures the accuracy and reliability of the credibility evaluation results of intelligence products.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024116592_24072025_PF_FP_ABST
    Figure CN2024116592_24072025_PF_FP_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of network security, and disclosed is a multi-dimensional threat intelligence credibility assessment method based on a content similarity value, comprising: acquiring threat intelligence content from multiple dimensions that needs credibility assessment; on the basis of the category of threat intelligence, acquiring credible threat intelligence content corresponding to the category of the threat intelligence; comparing the threat intelligence content with the credible threat intelligence content, and calculating a similarity value between the threat intelligence content needing credibility assessment and the credible threat intelligence content; comparing the similarity value with a threshold, and determining the threat intelligence of which the similarity value is greater than the threshold and which needs to be credible as preliminarily credible threat intelligence; and performing credibility assessment on the preliminarily credible threat intelligence again by means of preset features of the threat intelligence, and generating a credible threat intelligence sequence on the basis of an assessment result. In the present invention, by means of two-level comprehensive assessment, the most accurate and most credible threat intelligence sequence is obtained, thereby improving the accuracy of threat intelligence judgment.
Need to check novelty before this filing date? Find Prior Art

Description

A multi-dimensional threat intelligence credibility assessment method based on content similarity value Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a multi-dimensional threat intelligence credibility assessment method based on content similarity values. Background Art

[0002] Threat intelligence is evidence-based information that describes threats. It includes contextual information about the threat, the methods and mechanisms used, threat indicators, impact of the attack, and recommended countermeasures. The purpose of threat intelligence is to provide clues for reconstructing past attacks and predicting future ones, gaining as much insight as possible into attackers' motivations, tactics, tools, resources, and behavioral processes, and establishing effective security defenses. Due to the large volume, high repetition rate, and diverse sources of threat intelligence, in practice, the acquisition, organization, and use of threat intelligence can contain misleading or confusing false information.

[0003] However, the known threat intelligence credibility assessment methods are relatively simple and cannot conduct multi-dimensional credibility assessment of threat intelligence, nor can they judge the timeliness of intelligence products, and the credibility of threat intelligence cannot be guaranteed.

[0004] Summary of the Invention

[0005] In response to the problems existing in the prior art, the present invention provides a multi-dimensional threat intelligence credibility assessment method based on content similarity values, which can evaluate the credibility of threat intelligence from multiple levels, ensure the improvement of the accuracy of the threat intelligence to be evaluated, and judge the timeliness of the intelligence product.

[0006] The specific technical solutions are as follows:

[0007] A multi-dimensional threat intelligence credibility assessment method based on content similarity values ​​includes:

[0008] Obtain threat intelligence content from multiple dimensions that requires credibility assessment;

[0009] Obtain credible threat intelligence content corresponding to the threat intelligence category;

[0010] Compare the threat intelligence content with the credible threat intelligence content and calculate the similarity value between the threat intelligence content that needs to be evaluated for credibility and the credible threat intelligence content;

[0011] Comparing the similarity value with a threshold value, and determining the threat intelligence requiring credibility if the similarity value is greater than the threshold value as preliminary credible threat intelligence;

[0012] The credibility of the preliminary credible threat intelligence is re-evaluated based on the preset features of the threat intelligence, and a credible threat intelligence sequence is generated based on the evaluation results.

[0013] Preferably, the threat information includes the intelligence source, intelligence release time and intelligence threat description information.

[0014] Preferably, the threat intelligence content is compared with the credible threat intelligence content to calculate the similarity value between the threat intelligence content that needs to be evaluated for credibility and the credible threat intelligence content, using the following formula for calculation: S = θ1 * S time +θ2*S soure +(1-θ1-θ2)*S desc

[0015] Among them, S is the similarity value between the threat intelligence that needs to be evaluated for credibility and the credible threat intelligence, S time is the similarity value of the intelligence release time between the threat intelligence that needs to be evaluated for credibility and the credible threat intelligence, S source is the similarity value between the threat intelligence that needs to be evaluated for credibility and the credible threat intelligence, S desc is the similarity value of the intelligence threat description information between the threat intelligence that needs to be evaluated for credibility and the credible threat intelligence, and θ1 and θ2 are weights set according to the category of the threat intelligence that needs to be evaluated for credibility.

[0016] Preferably, the similarity value S of the intelligence release time between the threat intelligence that needs to be evaluated for credibility and the credible threat intelligence is time The calculation formula is as follows:

[0017] Where t(vt) is the release time of threat intelligence that needs to be evaluated for credibility, and t(vi) is the release time of credible threat intelligence.

[0018] Preferably, the similarity value S between the threat intelligence that needs to be evaluated for credibility and the credible threat intelligence is source The calculation formula is as follows: source =|Au(vt)-Au(vi)|

[0019] Among them, Au(vt) represents the authority of the source of threat intelligence that needs to be evaluated for credibility, and Au(vi) represents the authority of the intelligence source of credible threat intelligence.

[0020] Preferably, the similarity value S of the threat description information between the threat intelligence that needs to be evaluated for credibility and the credible threat intelligence is desc The calculation formula is as follows:

[0021] Wherein, Xt represents the threat description information of the threat intelligence that needs to be evaluated for credibility, and is described in the form of a vector; Xi represents the threat description information of the credible threat intelligence, and is described in the form of a vector.

[0022] Preferably, the preset threshold is set according to the category of threat intelligence to be detected.

[0023] Preferably, the preset features of the threat intelligence include source ratio information, hit ratio information, richness information, difference information and / or timeliness information.

[0024] Compared with the prior art, the present invention has the following beneficial effects:

[0025] In this method, the threat intelligence to be evaluated for credibility is first compared with the system's existing credibility threat intelligence to obtain a similarity value. Similarity values ​​exceeding a set threshold are then compared, completing the first-level evaluation of credible threat intelligence. The credible threat intelligence generated from the first-level evaluation is then subjected to a second-level evaluation using pre-set features, generating a sequence of credible threat intelligence. Through these two levels of evaluation, the most accurate and credible threat intelligence sequence is comprehensively evaluated, improving the accuracy of threat intelligence assessment. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following briefly describes the drawings required for the specific embodiments or the description of the prior art. Similar elements or parts are generally identified by similar reference numerals throughout the drawings. Elements or parts in the drawings are not necessarily drawn to scale.

[0027] FIG1 is a flow chart of the method of the present invention;

[0028] FIG2 is a flow chart of a credibility assessment method based on preset features. DETAILED DESCRIPTION

[0029] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0030] It will be understood that when used in this specification and the appended claims, the terms “comprises” and “comprising” indicate the presence of described features, integers, steps, operations, elements and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof.

[0031] It should also be understood that the terms used in the present specification are only for the purpose of describing particular embodiments and are not intended to limit the present invention. As used in the present specification and the appended claims, the singular forms "a", "an", and "the" are intended to include the plural forms unless the context clearly indicates otherwise.

[0032] It should be further understood that the term "and / or" used in the present description and the appended claims refers to and includes any and all possible combinations of one or more of the associated listed items.

[0033] Referring to Figures 1 and 2 , the present invention discloses a multi-dimensional threat intelligence credibility assessment method based on content similarity values, including:

[0034] S1. Obtain threat intelligence content from multiple dimensions that requires credibility assessment. In actual applications, the server can utilize the information characteristics of threat intelligence to obtain threat intelligence to be detected from multiple intelligence sources.

[0035] S2. According to the category of threat intelligence, obtain the corresponding credible threat intelligence content; wherein the credible threat intelligence content is a standard value that has been set in the system.

[0036] S3. Compare the threat intelligence content with the credible threat intelligence content, and calculate the similarity value between the threat intelligence content that needs to be evaluated for credibility and the credible threat intelligence content; each threat intelligence that needs to be evaluated for credibility has a corresponding credible threat intelligence set. After obtaining the threat intelligence that needs to be evaluated for credibility, the credible threat intelligence set used to verify the threat intelligence that needs to be evaluated for credibility can be obtained from a sample library of the same category based on the category of the threat intelligence that needs to be evaluated for credibility.

[0037] S4. Compare the similarity value with a threshold, and determine the credible threat intelligence that needs to be verified if the similarity value is greater than the threshold as preliminary credible threat intelligence; wherein the preset threshold can be set according to the category of the threat intelligence to be detected.

[0038] S5. Conduct a credibility reassessment on the preliminary credible threat intelligence based on the preset features of the threat intelligence, and generate a credibility threat intelligence sequence based on the assessment results.

[0039] Specifically, the threat intelligence includes the intelligence source, intelligence release time, and intelligence threat description information. The intelligence source refers to the source of the threat intelligence to be detected, that is, the origin or dissemination channel of the threat intelligence to be detected. The intelligence release time refers to the time when the threat intelligence to be detected was released. The intelligence threat description information refers to the threat description of the threat intelligence to be detected.

[0040] Specifically, the threat intelligence content is compared with the credible threat intelligence content, and the similarity value between the threat intelligence content that needs to be evaluated for credibility and the credible threat intelligence content is calculated using the following formula: S = θ1 * S time +θ2*S soure +(1-θ1-θ2)*S desc

[0041] Among them, S is the similarity value between the threat intelligence that needs to be evaluated for credibility and the credible threat intelligence, S time is the similarity value of the intelligence release time between the threat intelligence that needs to be evaluated for credibility and the credible threat intelligence, S source is the similarity value between the threat intelligence that needs to be evaluated for credibility and the credible threat intelligence, S desc is the similarity value of the intelligence threat description information between the threat intelligence that needs to be evaluated for credibility and the credible threat intelligence, and θ1 and θ2 are weights set according to the category of the threat intelligence that needs to be evaluated for credibility.

[0042] Specifically, the similarity value S of the intelligence release time between the threat intelligence that needs to be evaluated for credibility and the credible threat intelligence is time The calculation formula is as follows:

[0043] Where t(vt) is the release time of threat intelligence that needs to be evaluated for credibility, and t(vi) is the release time of credible threat intelligence.

[0044] Specifically, the similarity value S between the threat intelligence that needs to be evaluated for credibility and the credible threat intelligence is source The calculation formula is as follows: source =|Au(vt)-Au(vi)|

[0045] Among them, Au(vt) represents the authority of the source of threat intelligence that needs to be evaluated for credibility, and Au(vi) represents the authority of the intelligence source of credible threat intelligence. The authority of the intelligence source has the following six values: (1) When the intelligence source is unknown, the authority is 0; (2) When the intelligence source belongs to an independent source site, the authority is 0.2, and the independent source site can be a blog, forum, or personal website; (3) When the intelligence source belongs to a website and 0≤r≤106, the authority is 0.4, and r represents the Alexa ranking of the intelligence source. Alexa ranking refers to the world ranking of the website, and the website visits are its main evaluation indicator; (4) When the intelligence source belongs to a website and 106≤r≤104, the authority is 0.6; (5) When the intelligence source belongs to a website and r>104, the authority is 0.8; (6) When the intelligence source belongs to a well-known organization or institution, the authority is 1, and the well-known organization or institution can be Weibu Online or Google. The embodiment of the present invention can store the authority values ​​in a table form in the server side, which makes it easy to query the authority values ​​during the calculation process.

[0046] Specifically, the similarity value S between the threat intelligence that needs to be evaluated for credibility and the credible threat intelligence is desc The calculation formula is as follows:

[0047] Wherein, Xt represents the threat description information of the threat intelligence that needs to be evaluated for credibility, and is described in the form of a vector; Xi represents the threat description information of the credible threat intelligence, and is described in the form of a vector.

[0048] Specifically, the preset features of the threat intelligence include source ratio information, hit ratio information, richness information, difference information and / or timeliness information.

[0049] Among them, the source ratio information is used to evaluate the proportion of threat intelligence pushed by each intelligence source in the total number of threat intelligence. This indicator measures the number of intelligence sources delivered. This indicator can be used to assess the scarcity of intelligence delivered by certain intelligence sources and their low cost-effectiveness. The hit ratio information is used to evaluate the proportion of intelligence hit by user queries distributed among various intelligence sources. This indicator measures the applicability of the intelligence source. This indicator can be used to assess the situation where some intelligence sources simply pursue quantity advantages but have a large amount of invalid intelligence. Timeliness information includes the proportion of first-time intelligence released by each intelligence source. This indicator measures the output efficiency of the intelligence source. This indicator can be used to assess the timeliness of intelligence delivery by the intelligence source. Richness information is used to evaluate the proportion of threat intelligence with rich auxiliary information in each intelligence source. This indicator measures the richness of the intelligence source. Among them, auxiliary information can be WHOIS information, international public opinion verification information, relevant sample information, RDN / PDN / port / service / host name / SSL digital certificate / executable file digital signature and other technical information, professional analysis reports, and other current information and continuous historical information support. This information can serve as an important basis for subsequent tracing, review, analysis and tracking. This indicator can be used to assess the comprehensive strength of the production organization of the intelligence source.

[0050] Diversity information is used to assess the overlap between intelligence sources. This metric measures the independence of the source's production capabilities. In practical applications, multi-source threat intelligence should exhibit reasonable diversity to facilitate cross-checking and supplementation. Highly overlapping intelligence sources lack credibility and are generally of lower quality. This metric can be used to assess the overlap between intelligence sources, as well as the technical characteristics and regional distribution of the source's production organizations, effectively assessing plagiarism and imitation.

[0051] Those skilled in the art will appreciate that the units of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition of each example has been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.

[0052] In the embodiments provided by the present invention, it should be understood that the division of units is merely a logical function division, and there may be other division methods in actual implementation, for example, multiple units can be combined into one unit, one unit can be split into multiple units, or some features can be ignored, etc.

[0053] In addition, the functional units in the various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0054] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-0nly Memory), random access memory (RAM, Random Access Memory), mobile hard disk, magnetic disk or optical disk, etc., various media that can store program code.

[0055] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or make equivalent replacements for some or all of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the scope of the technical solutions of the embodiments of the present invention, and they should all be included in the scope of the claims and description of the present invention.

Claims

1. A multi-dimensional threat intelligence credibility assessment method based on content similarity values, characterized in that, Including: Obtain threat intelligence content from multiple dimensions that needs to be evaluated for credibility; According to the category of the threat intelligence, obtain the corresponding credible threat intelligence content; Compare the threat intelligence content with the credible threat intelligence content, and calculate the similarity value between the threat intelligence content that needs to be evaluated for credibility and the credible threat intelligence content; Compare the size of the similarity value with the threshold, and determine the threat intelligence that needs to be evaluated for credibility with the similarity value greater than the threshold as the preliminary credible threat intelligence; Through the preset features of the threat intelligence, conduct a re-credibility assessment of the preliminary credible threat intelligence, and generate a sequence of credible threat intelligence according to the assessment results.

2. The multi-dimensional threat intelligence credibility evaluation method based on content similarity values according to claim 1, wherein The threat intelligence content includes the intelligence source, the intelligence release time, and the intelligence threat description information.

3. The multi-dimensional threat intelligence credibility evaluation method based on content similarity values according to claim 2, characterized in that Compare the threat intelligence content with the trusted threat intelligence content, calculate the similarity value between the threat intelligence content that needs to be evaluated for credibility and the trusted threat intelligence content, and calculate it using the following formula: S = θ1 * S time + θ2 * S soure +(1 - θ1 - θ2) * S desc Among them, S is the similarity value between the threat intelligence to be evaluated for credibility and the credible threat intelligence, S time is the similarity value of the intelligence release time between the threat intelligence to be evaluated for credibility and the credible threat intelligence, S source is the similarity value of the intelligence source between the threat intelligence to be evaluated for credibility and the credible threat intelligence, S desc is the similarity value of the intelligence threat description information between the threat intelligence to be evaluated for credibility and the credible threat intelligence, and θ1, θ2 are the weights set according to the category of the threat intelligence to be evaluated for credibility.

4. The multi-dimensional threat intelligence credibility evaluation method based on content similarity values according to claim 3, characterized in that The similarity value S of the intelligence release time between the threat intelligence to be evaluated for credibility and the credible threat intelligence time The calculation formula is as follows: Where t(vt) is the intelligence release time of the threat intelligence that needs to be evaluated for credibility, and t(vi) is the intelligence release time of the credible threat intelligence.

5. The multi-dimensional threat intelligence credibility evaluation method based on content similarity values according to claim 3, characterized in that The similarity value S between the threat intelligence to be evaluated for credibility and the intelligence sources of the trusted threat intelligence source The calculation formula is as follows: S source = |Au(vt) - Au(vi)| Among them, Au(vt) represents the authority of the source of the threat intelligence that needs to be evaluated for credibility, and Au(vi) represents the authority of the intelligence source of the credible threat intelligence.

6. The multi-dimensional threat intelligence credibility assessment method based on content similarity values according to claim 3, wherein The similarity value S of the threat intelligence description information between the threat intelligence to be evaluated for credibility and the credible threat intelligence desc The calculation formula is as follows: Among them, Xt represents the threat description information of the threat intelligence that needs to be evaluated for credibility, and is described in vector form; Xi represents the threat description information of the credible threat intelligence, and is described in vector form.

7. The multi-dimensional threat intelligence credibility evaluation method based on content similarity values according to claim 3, wherein The preset threshold is set according to the category of the threat intelligence to be detected.

8. The multi-dimensional threat intelligence credibility evaluation method based on content similarity values according to claim 1, wherein The preset features of the threat intelligence include source ratio information, hit ratio information, richness information, difference information, and / or timeliness information.

Citation Information

Patent Citations

  • Method and device for discriminating threat information credibility based on multi-dimensional trusted feature

    CN108600212A

  • A method for discriminating phishing websites based on threat intelligence

    CN109522504A

  • Threat intelligence-based credibility updating method and apparatus, and electronic device

    CN116170202A

  • Multi-dimensional threat intelligence credibility evaluation method based on content similarity value

    CN117914580A

  • Dynamic Threat Intelligence Detection and Control System

    US20200358829A1

Cited By

  • Scientific and technological information collection method and system based on multi-modal data acquisition

    CN119917709A