The invention provides a minority language
threat intelligence clue expansion method,
system and device and a medium, and belongs to the technical field of
network security. The method comprises the steps of obtaining minority language
threat intelligence, performing data cleaning, format conversion and semantic index establishment on intelligence information, and constructing a vector
knowledge base by utilizing a vectorization model based on the processed intelligence information to serve as an initial
threat intelligence base; acquiring tactics, technologies and associated information related to the
attack from the initial
threat intelligence library by using a preset agent, and outputting semi-structured
attack process description information; and based on the
attack process description information, obtaining extension information and context promotion information, obtaining depth information related to an attack technology through analysis and retrieval, and generating a structured or reported
threat intelligence clue extension result. According to the method, the multi-agent with
domain knowledge and scene memory is utilized, and analysis and understanding of cross-language
threat intelligence, intelligence key point extraction and semi-structured representation output are achieved.