This invention discloses a method, apparatus, device, and storage medium for producing
threat intelligence, applied in the field of
network security. The method includes: acquiring raw
threat information corresponding to IPs without
threat intelligence within a preset time period; aggregating the raw threat information based on the IPs to obtain aggregated raw threat information; extracting features from the aggregated raw threat information to obtain feature vectors; inputting the feature vectors into a trained neural
network model; if the IPs exhibit threatening behavior, determining the threat type of the IPs based on the trained neural
network model, and producing corresponding
threat intelligence based on the threat type. Compared to existing technologies that produce intelligence based on processed
data analysis, this method directly utilizes
machine learning technology to analyze raw threat information, ensuring the accuracy of
threat intelligence production. Furthermore, the
threat intelligence produced by this method can be directly applied to security devices, facilitating subsequent
security monitoring.