The invention relates to the technical field of
network security, in particular to an automatic malicious
software feature conversion and unified management method,
system and device based on an MAEC standard and a storage medium. The method comprises the following steps: acquiring a malicious
software analysis report and analyzing static feature and
dynamic feature data, establishing a field
semantic mapping relationship based on a preset rule base, and automatically associating features to a behavior tag, a capability tag and a feature tag of an MAEC standard;
feature extraction, mapping and standard object generation are achieved through a Python script, malicious
software instance objects and behavior objects in the MAEC
data model are instantiated, the incidence relation between the objects is created, and a structured description file meeting the MAEC-5. 0 standard is generated; performing semantic classification on the generated malicious
software behavior objects, classifying the behavior objects related to
semantics into behavior entities, and establishing a hierarchical relationship; a MongoDB and MySQL dual-
database architecture is established to store an
original report and structured data, and automatic operation is realized through a Linux timed task.