Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

36 results about "Cyber threat intelligence" patented technology

Network threat knowledge automatic extraction method, electronic equipment and storage medium

PendingCN120930756AWeb data indexingSemantic analysisCyber threat intelligenceLinguistic model
The invention discloses a network threat knowledge automatic extraction method, electronic equipment and a storage medium, and the method comprises the following steps executed by a computer hardware system: collecting threat intelligence data related to an APT organization from a multi-source network security text, and processing the threat intelligence data to generate a standardized corpus; using the pre-training sentence vector model to generate semantic embedding for a corpus input text and a manual annotation example library text, and retrieving similar examples to construct an ICL prompt template; inputting a large language model subjected to LoRA fine tuning, and extracting structured triples of multiple types of entities and semantic relationships; generating standardized entity nodes and updated relation information by adopting semantic aggregation; and constructing an APT organization network threat intelligence knowledge graph and outputting a structured file. The method provides key technical support for APT attack tracing, threat situation awareness and automatic security policy generation.
Owner:GUIZHOU UNIV

Systems and methods for improving cybersecurity using detection and response models and data valuation frameworks

PendingUS20250358121A1User identity/authority verificationCyber threat intelligenceEngineering
A method can include determining, by one or more processing circuits, a cybersecurity resilience posture of an entity. The method can include identifying or generating, by the one or more processing circuits, at least one token comprising a proof or a posture state corresponding with the cybersecurity resilience posture of the entity. The method can include determining, by the one or more processing circuits using a cyber threat intelligence (CTI) model, at least one of a quantitative value or a qualitative value corresponding to the at least one token. The method can include updating, by the one or more processing circuits, a cybersecurity profile of the entity corresponding to at least one protection product.
Owner:AS0001 INC

Electric power information network multi-source threat intelligence analysis method, system, device and medium

ActiveCN120979831ASemantic analysisKnowledge representationCyber threat intelligenceAttack
The invention relates to the technical field of power information network threat intelligence analysis, and provides a power information network multi-source threat intelligence analysis method, system and device and a medium, and the method comprises the steps: obtaining to-be-analyzed multi-source threat intelligence data of a power information network; performing attack entity relationship extraction analysis on the text intelligence data according to a preset attack entity data model and a preset entity association mode table to generate an attack reconstruction main graph; carrying out attack entity relationship extraction analysis on the attack vulnerability codes based on a preset code large model and an attack entity retrieval database to generate a plurality of attack reconstruction sub-graphs; and combining the attack reconstruction main graph and the attack reconstruction sub-graphs to generate a target attack reconstruction graph. According to the method, an attack entity relationship extraction mechanism based on a unified attack entity data model is combined with a multi-source attack graph reconstruction mechanism, so that the accuracy and comprehensiveness of attack entity recognition are improved, the reliability of threat detection and attack tracing is ensured, and the security defense capability of the electric power information network is improved.
Owner:STATE GRID ZHEJIANG ELECTRIC POWER CO LTD HANGZHOU POWER SUPPLY CO

Network threat intelligence structured processing method and system based on artificial intelligence

PendingCN121303290AInference methodsSecuring communicationCyber threat intelligenceLinguistic model
The invention relates to the technical field of crossing of artificial intelligence and network security, in particular to a network threat intelligence structured processing method and system based on artificial intelligence. The method comprises the following steps: acquiring unstructured original threat intelligence and performing credibility evaluation on an intelligence source; based on a large language model and knowledge graph enhanced retrieval, a step-by-step analysis plan for original threat intelligence is generated; dynamically calling a tool to execute an information extraction subtask corresponding to each step in the analysis plan to obtain a preliminary extraction result; performing multi-dimensional confidence evaluation on the preliminary extraction result; and taking the preliminary extraction result with the confidence higher than or equal to a threshold as a final result, and outputting the final result in a formatting manner and updating the final result to the knowledge graph. According to the method, the problem that unstructured multi-mode threat intelligence is difficult to convert into structured data which is readable by a machine, self-consistent in logic and capable of being put into actual combat in the prior art is solved, and the improvement of attack chain understanding depth and integrity is realized.
Owner:DATA SPACE RES INST

Systems and methods for cyber threat detection based on new and / or updated cyber threat intelligence

Systems, methods, and apparatuses are described for detection and / or analysis of cyber threats based on updated cyber threat intelligence associated with cyber threats. Packet filtering output data such as logs of packet communications and / or copies of packets may be generated based on first cyber threat intelligence associated with a cyber threat. Updated criteria based on subsequent updated cyber threat intelligence may then be applied to the packet filtering output data.
Owner:CENTRIPETAL NETWORKS INC

Network threat analysis method and system based on learning evolutionary game

PendingCN121485949AUser identity/authority verificationCyber threat intelligenceEngineering
According to the network threat analysis method and system based on the learning evolutionary game provided by the invention, the expected benefit of sharing is analyzed through modeling, quantitative analysis is carried out by adopting the learning evolutionary game, and a reasonable incentive strategy is obtained, so that the sharing and utilization efficiency of network threat intelligence is promoted; each entity enterprise inquires from the open community to obtain the required threat intelligence, analyzes the threat intelligence and deploys own network defense measures, so that the network security defense capability is improved, and the problems that in the prior art, the capability of providing a large number of resources is difficult, the data sharing and exchanging capability is weak, and a large number of continuous network attacks are difficult to defend are solved.
Owner:北京国瑞数智技术有限公司

Efficient Threat Context-Aware Packet Filtering for Network Protection

PendingUS20250358295A1Securing communicationCyber threat intelligenceAttack
A threat intelligence gateway (TIG) may protect TCP / IP networks from network (e.g., Internet) threats by enforcing certain policies on in-transit packets that are crossing network boundaries. The policies may be composed of packet filtering rules with packet-matching criteria derived from cyber threat intelligence (CTI) associated with Internet threats. These CTI-derived packet-filtering rules may be created offline by policy creation and management servers, which may distribute the policies to subscribing TIGs that subsequently enforce the policies on in-transit packets. Each packet filtering rule may specify a disposition that may be applied to a matching in-transit packet, such as deny / block / drop the in-transit packet or pass / allow / forward the in-transit packet, and also may specify directives that may be applied to a matching in-transit packet, such as log, capture, spoof-tcp-rst, etc. Often, however, the selection of a rule's disposition and directives that best protect the associated network may not be optimally determined before a matching in-transit packet is observed by the associated TIG. In such cases, threat context information that may only be available (e.g., computable) at in-transit packet observation and / or filtering time, such as current time-of-day, current TIG / network location, current TIG / network administrator, the in-transit packet being determined to be part of an active attack on the network, etc., may be helpful to determine the disposition and directives that may best protect the network from the threat associated with the in-transit packet. The present disclosure describes examples of methods, systems, and apparatuses that may be used for efficiently determining (e.g., accessing and / or computing), in response to the in-transit packet, threat context information associated with an in-transit packet. The threat context information may be used to efficiently determine the disposition and / or one or more directives to apply to the in-transit packet. This may result in dispositions and / or directives being applied to in-transit packets that better protect the network as compared with solely using dispositions and directives that were predetermined prior to receiving the in-transit packet.
Owner:CENTRIPETAL NETWORKS INC

Network threat analysis method and system based on improved evolutionary game

PendingCN121418119ABiological modelsSecuring communicationCyber threat intelligenceData mining
According to the network threat analysis method and system based on the improved evolutionary game, shared expected benefits are analyzed through modeling, quantitative analysis is carried out through the learning evolutionary game, a reasonable incentive strategy is obtained, meanwhile, a user selects a game strategy through autonomous learning, returned incentive is corrected, and the network threat analysis efficiency is improved. Optimal screening of threat intelligence is realized, sharing and utilization efficiency of network threat intelligence is better promoted, network security defense capability is improved, and the defects that the prior art is lack of reinforcement learning capability, needs to depend on a large number of intelligence resources, can only passively receive incentives and intelligence returned by communities, and is poor in security defense capability are overcome. And protection and defense cannot be fully carried out according to the self condition maximization.
Owner:北京国瑞数智技术有限公司

Cyber threat detection based on threat context, threat changes and / or impact status

ActiveUS12580893B2Machine learningSecuring communicationCyber threat intelligenceInternet traffic
Aspects described herein may relate to cyber threat detection based on threat context and / or threat changes. Cyber threat intelligence (CTI) data may be received from a CTI provider. Endpoint data that indicates evidence that endpoints are cyber threats may be determined based on the CTI data. The endpoint data may be analyzed and / or compared to stored data associated with the endpoint. The analysis and / or comparison may be performed to determine whether evidence that the endpoint is a cyber threat has changed. Based on any changes, dispositions for the endpoint may be determined and sent. The dispositions may change how devices filter network traffic associated with the endpoint. Alternatives to default dispositions may be determined based on a impact of blocking potentially legitimate network traffic to and / or from the endpoints. Machine-learning models may assist in processing and analyzing CTI data, performing threat monitoring, and / or determining feeds that include the dispositions.
Owner:CENTRIPETAL NETWORKS INC

Methods and systems for efficient adaptive logging of cyber threat incidents

ActiveUS12603862B2Securing communicationData packCyber threat intelligence
A packet-filtering network appliance such as a threat intelligence gateway (TIG) protects TCP / IP networks from Internet threats by enforcing certain policies on in-transit packets that are crossing network boundaries. The policies are composed of packet filtering rules derived from cyber threat intelligence (CTI). Logs of rule-matching packets and their associated flows are sent to cyberanalysis applications located at security operations centers (SOCs) and operated by cyberanalysts. Some cyber threats / attacks, or incidents, are composed of many different flows occurring at a very high rate, which generates a flood of logs that may overwhelm computer, storage, network, and cyberanalysis resources, thereby compromising cyber defenses. The present disclosure describes incident logging, in which a single incident log efficiently incorporates the logs of the many flows that comprise the incident, thereby potentially reducing resource consumption while improving the informational / cyberanalytical value of the incident log for cyberanalysis when compared to the component flow logs. Incident logging vs. flow logging can be automatically and adaptively switched on or off depending on the combination of resource consumption and informational / cyberanalytical value.
Owner:CENTRIPETAL NETWORKS INC

Adaptive encrypted system for analyzing cyber threat data using two-stage causal inference and homomorphic anomaly embeddings

ActiveDE202025107724U1Digital data protectionPlatform integrity maintainanceData packCyber threat intelligence
An adaptive, encrypted data analysis system for cyber threats, consisting of: a secure data interface unit configured to receive cyber threat telemetry data originating from a variety of distributed computing resources, including network infrastructure devices, endpoint systems, cloud workloads, and application servers, wherein the received cyber threat telemetry data includes network interaction records, authentication activity data, process execution data, behavioral traces, and temporal event information, and wherein the cyber threat telemetry data is received in an encrypted state; a cryptographic coding unit that is operationally coupled with the secure data interface unit and is configured to transform the received encrypted cyber threat telemetry data into a variety of encrypted anomaly embedding representations by performing feature normalization, temporal alignment, and semantic coding operations prior to encryption, and is further configured to apply homomorphic encryption to generate ciphertext-based anomaly embeddings that preserve mathematical operability; a homomorphic anomaly inference processor that is operationally coupled with the cryptographic coding unit and is configured to perform encrypted analytical operations directly on the ciphertext-based anomaly embeddings, wherein the homomorphic anomaly inference processor is configured to compute encrypted deviation indicators that represent behavioral deviations from encrypted baseline profiles without performing any decryption at any stage of the computation; a first causal inference unit that is operationally coupled with the homomorphic anomaly inference processor and is configured to create encrypted local causal dependency representations by evaluating conditional relationships between encrypted anomaly embeddings corresponding to individual system components, user interactions, and execution contexts, thereby deriving causally attributable sources of detected anomalies; a second causal inference unit that is operationally coupled with the first causal inference unit and configured to aggregate encrypted local causal dependency representations across a variety of computing resources to derive encrypted global causal propagation representations that indicate coordinated or multi-stage cyber threat behavior spanning multiple system domains; an adaptive learning control unit operationally coupled with the cryptographic coding unit, the homomorphic anomaly detection processor, and the first and second causal inference units, wherein the adaptive learning control unit is configured to update encrypted baseline behavior profiles and encrypted causal dependency parameters based on validated threat findings while maintaining all learning operations within an encrypted computation domain; and a secure output control unit that is operationally coupled with the second causal inference unit and configured to generate cyber threat intelligence signals that include encrypted risk indicators, threat classification outputs, and response prioritization information, with the generated outputs excluding the disclosure of underlying plaintext cyber threat telemetry.
Owner:MUTHU SHANMUGAM SALEM +1

Large-scale exchange of cyber threat intelligence via routing protocols

PendingUS20260129069A1Securing communicationCyber threat intelligenceExchange network
The techniques described herein provide a transport mechanism for large-scale exchange of cyber threat intelligence between entities and / or within an entity. Cyber threats evolve rapidly, and entities face challenges in efficiently sharing threat intelligence at “network speed” and applying mitigations across their networks. Existing techniques lack scalability, real-time updates, and coordination among organizations. Moreover, there is no existing technique for large-scale exchange of cyber threat intelligence. Additionally identifying threat data is often performed manually and is subjective. The techniques described herein provide mechanisms that leverage BGP or other routing protocols to facilitate large-scale threat intelligence exchange and mitigation across entities in real-time. The techniques described herein enable entities, including cloud providers, internet service providers, and others, to collaboratively mitigate cyber threats by disseminating real-time confirmed and actionable threat intelligence across their networks.
Owner:CISCO TECHNOLOGY INC

Network threat intelligence sharing method and related device

PendingCN121000463ASecuring communicationCyber threat intelligenceCiphertext
The invention belongs to the technical field of network space security, and discloses a network threat intelligence sharing method and related device.The method comprises the steps that network threat intelligence is obtained and encrypted to obtain an intelligence ciphertext, the intelligence ciphertext is stored in a local server, and a hash value of the intelligence ciphertext is obtained and stored in a private chain; and obtaining a keyword of the network threat intelligence, generating an intelligence keyword index by using a searchable encryption method according to the keyword of the network threat intelligence, and storing the intelligence keyword index to the alliance chain. The local security and privacy of the network threat intelligence are realized based on encrypted storage and the block chain, and the network threat intelligence is prevented from being tampered locally. Meanwhile, the information keyword index is stored in the alliance chain to achieve keyword sharing, specific content of the network threat information is not disclosed, and the retrievability, the safety, the privacy and the non-tampering performance of the network threat information in sharing are achieved.
Owner:CHINA ELECTRIC POWER RESEARCH INSTITUTE CO LTD +3

Small sample named entity recognition method and system based on prompt learning

The invention provides a small sample named entity recognition method and system based on prompt learning, and belongs to the field of named entity recognition, and the method comprises the steps: S1, collecting a network threat intelligence report, and carrying out the preprocessing to obtain a corpus; constructing a vocabulary for pre-training a mask language model based on a corpus to obtain a pre-training model CTIBERT; s2, constructing a CTINER data set based on a corpus; s3, task prompts composed of identity prompts, background information and position prompts are constructed; s4, based on SBERT and Jaccard similarity, selecting a sentence with the closest similarity to the sequence X to be recognized from the CTINER data set for demonstration; and S5, inputting the task prompt, the SBERT, the Jaccard sentence demonstration and the to-be-identified sequence X into the named entity identification network together, and outputting a predicted entity tag. According to the method, the performance of the small sample named entity recognition model is improved.
Owner:CAPITAL NORMAL UNIVERSITY

Methods, systems, equipment and media for multi-source threat intelligence analysis of power information networks

ActiveCN120979831BSemantic analysisKnowledge representationCyber threat intelligenceAttack
This invention relates to the field of threat intelligence analysis technology for power information networks, and provides a method, system, device, and medium for multi-source threat intelligence analysis of power information networks. The method includes acquiring multi-source threat intelligence data to be analyzed from the power information network; extracting and analyzing attack entity relationships from the text intelligence data based on a preset attack entity data model and a preset entity association pattern table to generate an attack reconstruction master graph; extracting and analyzing attack entity relationships from the vulnerability code based on a preset code model and an attack entity retrieval database to generate several attack reconstruction sub-graphs; and merging the attack reconstruction master graph and the various attack reconstruction sub-graphs to generate a target attack reconstruction graph. This invention improves the accuracy and comprehensiveness of attack entity identification by combining an attack entity relationship extraction mechanism based on a unified attack entity data model with a multi-source attack graph reconstruction mechanism, ensuring the reliability of threat detection and attack tracing, and enhancing the security defense capabilities of power information networks.
Owner:STATE GRID ZHEJIANG ELECTRIC POWER CO LTD HANGZHOU POWER SUPPLY CO

Method and system for analyzing cybersecurity threats and improving defensive intelligence

PendingUS20250365294A1Mathematical modelsPlatform integrity maintainanceCyber-attackCyber threat intelligence
Disclosed is a cyber threat intelligence platform configured to: a) designate a virtual machine as an attacker machine; b) designate a virtual machine as a victim machine; c) receive cyberattack data representative of a cyberattack executed by the attacker machine against the victim machine; e) receive defense action data representative of a defense action executed by the victim machine against the cyberattack; f) mark a first point in time when the cyberattack is executed, and mark a second point in time when the defense action is initiated; g) compare the first point in time with the second point in time to ascertain an attack-defense time lapse as a performance measure for computer system threat management of cyberattacks or defense actions, and h) view or analyze cyberattack and defense actions for effectiveness, including perspectives derived from the relative timing of the actions as indicated on the time lapse.
Owner:THREATOLOGY INC

Network threat intelligence analysis system based on Agent RAG and knowledge graph

The invention relates to the technical field of network security, and provides a network threat intelligence analysis system based on Agent RAG and a knowledge graph, and the system comprises a security scene recognition module which is used for outputting a judgment result whether the judgment result can be executed or not; the intention recognition module is used for screening associated fields from the threat knowledge field list; the retrieval enhancement module is used for fusing and generating a structured retrieval result set; the task planning module is used for planning and generating a task execution chain comprising at least one subtask; the task execution module is used for calling a large language model to perform reasoning and information integration and outputting an initial analysis result; and the security back-off module is used for triggering a corresponding security back-off strategy and generating a final analysis result. According to the method, an intelligent analysis framework fusing an Agent dynamic RAG closed loop, a multi-layer semantic knowledge network and a full-process security bottom-taking mechanism is constructed, so that deep semantic understanding of network threat intelligence is realized.
Owner:GUANGZHOU UNIVERSITY

Method for detecting and predicting cyber threats in industrial environments

PCT designated stageWO2026008896A1Securing communicationCyber threat intelligenceAttack
The invention relates to a method for detecting and predicting cyber threats in industrial environments using cyber threat intelligence (CTI), comprising: I) identifying threats (200) and classifying same through the analysis of TTP measures and IOC / IOA indicators, including a basic and advanced CTI process for unidentified known / similar threats and zero-day vulnerabilities; ii) identifying trends and campaigns (300), detecting patterns and repeated events, analysing attack behaviours and characteristics in order to predict trends and campaigns directed towards specific devices, industrial sectors or clients; iii) generating dictionaries updated with remote access attempts in order to analyse data used in attacks; and iv) generating use cases in order to manage incidents, anticipating changes to known threats. The method is based on multilevel modelling (L1, L2,..., Ln): the input (11) from a threat capture system feeds to a basic CTI (12) at the first level, resulting in initial information (21), relating to both attackers and threats (22), which is input into the advanced CTI (23) at the next level and so on until the last one, in order to obtain the final information (30) relating to cyber attacks and attackers.
Owner:TELEFONICA CYBERSECURITY & CLOUD TECH S L U

Distributed cyber threat intelligence platform

ActiveUS12719888B2Computer networkCyber threat intelligence
Techniques are described herein for providing a distributed cyber threat intelligence platform. An example system includes a set of cyber threat intelligence content stored on a distributed ledger accessible by one or more nodes. The example system further includes an artificial intelligence (AI) engine configured to: receive a node input from a new device indicating a node type to be established for the new device, generate one or more responses to the node input, and establish a new node for the new device on the distributed ledger that corresponds to the node type. The example system further includes a smart contracts engine configured to: receive, from the new node, a second input associated with cyber threat intelligence, store the second input in the distributed ledger as part of the set of cyber threat intelligence content, and transmit the second input to the one or more nodes.
Owner:TEACHERS INSURANCE & ANNUITY ASSOC OF AMERICA

APT attack organization attribution method and system based on topic-enhanced heterogeneous hypergraph

PendingCN122348838ACyber threat intelligenceAttack
The application relates to the technical field of network space security, and discloses an APT attack organization attribution method and system based on a topic-enhanced heterogeneous hypergraph. First, multi-source network threat intelligence texts are obtained, attack behavior elements are extracted from the network threat intelligence texts, and initial semantic feature representations of the attack behavior elements are generated; the attack behavior elements are taken as behavior element nodes, event-intra hyperedges and topic-level cross-event hyperedges are constructed, unified modeling is carried out, a topic-enhanced heterogeneous hypergraph structure containing multiple types of nodes and multiple types of hyperedges is formed, feature aggregation processing is carried out, and a hypergraph structure feature reflecting attack behavior collaborative relationships is obtained; organization-level feature representations used for representing overall behavior patterns of attack organizations are generated; attribution determination is carried out on APT attack organizations to which attack behaviors belong; and attack organization attribution results are output. The application solves the problems of the unified APT attribution method, such as insufficient description of multi-entity collaborative relationships, weak cross-event semantic correlation and the like.
Owner:HAINAN NORMAL UNIV

Semantic enhancement-based network threat intelligence causal relationship automatic extraction method and system

PendingCN121723466ASemantic analysisBiological modelsCyber threat intelligenceText entry
The invention discloses a semantic enhancement-based network threat intelligence causal relationship automatic extraction method and system, and belongs to the technical field of network security. The method can solve the problems of shallow understanding of unstructured threat intelligence semantics and lack of causal relationship mining ability in the prior art. The method comprises the following steps: firstly, collecting a CTI report and constructing mapping from an attack technology to a CWE weak point and a CoA alarm; secondly, preprocessing and standardizing the CTI text; then, performing field tagging and calculating semantic enhancement features; thirdly, the text is input into a sentence-level BERT and BiLSTM combined model, semantic enhancement features and an interlayer semantic feedback mechanism are fused in the model, and time sequence and causal relationship modeling is carried out; and finally, through joint prediction and training, outputting CWE and CoA labels, and generating a ''weakness-technology-alarm'' ternary causal graph. According to the method, end-to-end causal relationship modeling is realized through deep semantic understanding and knowledge fusion, and the output result has high interpretability and high operability.
Owner:CHINA ACADEMY OF INFORMATION & COMM

Network topology annotation methods, devices and equipment for addressing cybersecurity threats

ActiveCN119299199BSecuring communicationCyber threat intelligenceEngineering
This application relates to a method, apparatus, and device for annotating network topology structures to address network security threats. The method includes: acquiring a set of network threat intelligence; determining the severity characterization value of each network threat intelligence in the set; determining the weight of each network node in the network topology to be annotated; for each network node in the network topology, identifying at least one associated network threat intelligence related to the network node from the set of network threat intelligence, and determining the threat level of the network node based on the weight of the network node and the severity characterization value of the at least one associated network threat intelligence; and annotating the threat level and weight of the network node in the network topology. This method can improve the effectiveness of network security protection.
Owner:ELECTRIC POWER RES INST CHINA SOUTHERN POWER GRID CO LTD +1

Cyber threat detection based on threat context, threat changes, and / or impact status

PendingUS20260122038A1Machine learningSecuring communicationCyber threat intelligenceInternet traffic
Aspects described herein may relate to cyber threat detection based on threat context and / or threat changes. Cyber threat intelligence (CTI) data may be received from a CTI provider. Endpoint data that indicates evidence that endpoints are cyber threats may be determined based on the CTI data. The endpoint data may be analyzed and / or compared to stored data associated with the endpoint. The analysis and / or comparison may be performed to determine whether evidence that the endpoint is a cyber threat has changed. Based on any changes, dispositions for the endpoint may be determined and sent. The dispositions may change how devices filter network traffic associated with the endpoint. Alternatives to default dispositions may be determined based on a impact of blocking potentially legitimate network traffic to and / or from the endpoints. Machine-learning models may assist in processing and analyzing CTI data, performing threat monitoring, and / or determining feeds that include the dispositions.
Owner:CENTRIPETAL NETWORKS INC

Third-party linkage threat intelligence blocking policy issuing method and device and processing equipment

PendingCN122160115ASecuring communicationThird partyCyber threat intelligence
The application provides a third-party linkage threat intelligence blocking strategy issuing method and device and processing equipment, which can comprehensively and timely acquire various threat intelligence by constructing a multi-source threat intelligence collection channel, and can quickly and accurately identify potential threats by using machine learning and artificial intelligence algorithms for intelligent analysis, and can realize real-time blocking of threats by automatically generating a blocking strategy and executing the blocking strategy in linkage with network security equipment, so that a more perfect network threat intelligence application system is provided for enterprise network security work, and network security is better guaranteed.
Owner:WUHAN SIPU TECH CO LTD

Threat intelligence structured analysis method and device based on large language model

The embodiment of the invention provides a threat intelligence structured analysis method and device based on a large language model, and belongs to the field of artificial intelligence. The method comprises the following steps: acquiring a network threat intelligence text; analyzing and cleaning the network threat intelligence text to obtain a to-be-analyzed text; performing intrusion index identification and extraction on the to-be-analyzed text based on a pre-constructed first large language model to obtain an intrusion index corresponding to the to-be-analyzed text; based on a pre-constructed second large language model, generating a structured attack technique and tactics for the to-be-analyzed text to obtain the structured attack technique and tactics corresponding to the to-be-analyzed text; and integrating the intrusion index and the structured attack technique and tactics to generate a structured threat intelligence analysis result. The method does not depend on a large amount of training data.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

A Method for Generating Attack Scenario Graphs (ASGs) for Network Threat Intelligence Analysis Based on Deep Learning and Natural Language Processing

ActiveCN119966695BSpeech recognitionSecuring communicationCyber threat intelligenceSemantic context
This invention discloses a method for generating Attack Scenario Graphs (ASGs) for network threat intelligence analysis based on deep learning and natural language processing. This method combines deep learning models with natural language processing techniques to improve the efficiency and accuracy of attack scenario graph generation. The steps include: collecting network threat intelligence and performing entity recognition using an improved BERT-BiLSTM-CRF model, combined with regular expressions to identify threat attack entities; using the CR-M-SpanBERT model for core referential parsing to capture semantic contextual dependencies between entities; using dependency parsing techniques to extract bidirectional contextual semantic dependencies of the text, and combining this with RoBERTa-BiGRU to generate embedding representations; finally, extracting triple information based on the BERT-RE model to generate the attack scenario graph. This invention improves the processing capability of complex network threat intelligence data, has strong robustness and adaptability, and is particularly suitable for multimodal threat intelligence.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Accurate attack graph construction method based on command line

PendingCN121792143ABiological modelsSecuring communicationCyber threat intelligenceAlgorithm
The invention discloses an accurate attack graph construction method based on a command line. The method comprises the following steps: 1, constructing a framework for providing a basis for an initial attack graph from a network threat intelligence CTI report; 2, aiming at command line data, extracting key entities and relationships by utilizing a rule and learning combined mode, and constructing a command line attack subgraph; and 3, based on a technical and tactical label matching and semantic alignment strategy, fusing the command line attack sub-graph to the initial attack graph to form an enhanced attack graph, and forming an enhanced attack graph containing complete attack details. According to the method, a small amount of high-value command line information in the CTI report can be complemented into the attack graph, so that the integrity of an attack chain is remarkably improved; according to the method, a rule-model mechanism is fused, the robustness of command line relation extraction is improved, and the identification risk caused by only model inference is avoided; according to the method, cross-modal accurate fusion can be realized, and the analysis capability of the attack graph in threat investigation and attack chain restoration scenes is effectively improved.
Owner:TAIZHOU RES INST ZHEJIANG UNIV OF TECH

Improved cyber threat detection

PCT designated stageWO2025257555A1Platform integrity maintainanceSecuring communicationCyber threat intelligenceData set
The invention resides in a computer-implemented method of processing source data for determining a cyber threat, using an ANN, and generating a machine readable output dataset for producing in a natural language and / or graphical representation of the determined cyber threat The method can be automated to transform unstructured CTI reports into a STIX format machine readable report for enabling more efficient and accurate cyber threat intelligence management. The ANN used from training can use BERT transformers. In one example, there resides a computer-implemented method of processing source data for determining a cyber threat, the method comprising: using an input dataset, said input dataset comprising the source data to be analysed for determining a cyber threat; processing the input dataset for (i) extracting entities and / or (ii) determining relationships between entities; and generating a machine readable output dataset for producing in a natural language and / or graphical representation of the determined cyber threat.
Owner:ELEMENDAR LTD

Network threat intelligence automatic extraction method based on multi-source fusion

PendingCN121809666ABiological modelsNatural language data processingCyber threat intelligenceLinguistic model
The invention provides an efficient and accurate network threat intelligence automatic extraction method, and aims to solve the problems of incomplete entity recognition, inaccurate relation reasoning, easy model illusion and the like when an existing intelligence extraction technology faces CTI texts with multi-source isomerism, complex safety terms and implicit relation expression. According to the method, the advantages of a deep learning model and a large language model are fused, and the structured understanding ability of complex threat intelligence is comprehensively improved. According to the specific technical scheme, firstly, multi-source data from security reports, technical blogs and the like are processed in a unified mode through a text standardization and entity preliminary screening module, and the basic quality of information extraction is improved; secondly, an entity-driven attention model is introduced, threat entity semantics are recovered through external knowledge enhancement and an entity-to-attention mechanism, a preliminary relation is recognized, and the extraction accuracy is improved; thirdly, capturing potential attack chain logic and implicit association by adopting an example retrieval mechanism based on relational logic driving and combining the analogy reasoning capability of a large language model; and finally, through a decision fusion and arbitration mechanism, consistency comparison, conflict verification and deletion completion are carried out on results of the deep model and the large model, so that the accuracy, integrity and robustness of network threat intelligence extraction are remarkably improved.
Owner:GUIZHOU UNIV

Network threat intelligence issuing method and related device

PendingCN122339775AComputer networkCyber threat intelligence
This application provides a method and related equipment for distributing network threat intelligence. The technical solution of this application combines multi-source internet data to assess the activity level of threat intelligence, dynamically sorts and filters intelligence that meets the needs of target security devices, thereby achieving more efficient and accurate distribution of network threat intelligence. This embodiment can dynamically sort intelligence based on its real-time activity level, effectively improving the timeliness and accuracy of security protection responses, optimizing device resource utilization, and reducing the impact of invalid intelligence.
Owner:BEIJING QIHOOD TECHNOLOGY CO LTD