The invention relates to a
threat intelligence intelligent
analysis method based on a
large model and a
knowledge graph. The
threat intelligence intelligent
analysis method comprises the steps of performing automatic cleaning, structured extraction and consistent storage on multi-source heterogeneous data; performing multi-
modal information retrieval and association; dynamically prompting
engineering and reasoning enhancement;
threat research and judgment and output can be explained. According to the application, through a two-channel mixed framework in which atlas retrieval and vector retrieval are coordinated, an
assembly line of
keyword extraction, vector recall, atlas association, fusion duplicate removal and
assembly prompting is used, recall coverage and conclusion
interpretability are improved, a landing lightweight threat scoring and grading mechanism is provided, and CVSS, ATTamp, ATTamp, ATTamp, ATTamp, ATTamp, ATTamp, ATTamp, ATTamp, ATTamp, ATTamp, ATTamp and ATTamp are CK stage information is combined with retrieval evidences to obtain a unified total
score and four-level judgment, so that direct access to an automatic disposal process is facilitated, a structured prompt and an explainable output scheme for evidence alignment are provided, input is organized by using an evidence block, a map path abstract and an event timeline, all conclusions can be traced back to an original text and a link, and the result is more accurate. And
processing suggestions oriented to assets and businesses are generated in a linkage manner.