taptap下载安装安卓学报 ›› 2024, Vol. 42 ›› Issue (4): 29-36.

• 民机安全性与适航 • 上一篇    下一篇

基于多源异构数据的网络威胁情报质量评估方法

周景贤  ,李其蔚  ,程志棚   

  1. (1a.taptap下载安装安卓信息安全测评中心,天津300300;1b.taptap下载安装安卓计算机科学与技术学院,天津300300;2.中国民用航空华北地区空中交通管理局通信网络中心,北京100621)
  • 收稿日期:2023-08-21 修回日期:2024-01-17 出版日期:2024-12-19 发布日期:2024-12-21
  • 作者简介:周景贤(1981—),男,河南信阳人,副研究员,博士,研究方向为协议安全、风险评估、民航信息系统安全等.
  • 基金资助:
    民航安全能力建设资金项目(PESA2019074,PESA2021009)

Quality evaluation method of cyber threat intelligence based on multi-source heterogeneous data

ZHOU Jingxian   LI Qiwei  CHENG Zhipeng#br#   

  1. (1a. Information Security Evaluation Center; 1b. College of Computer Science and Technology, CAUC, Tianjin 300300, China;
    2. Communication Network Center of North China Air Traffic Management Bureau, CAAC, Beijing 100621, China)
  • Received:2023-08-21 Revised:2024-01-17 Online:2024-12-19 Published:2024-12-21

摘要: 随着网络攻击形式的多样化和攻击手段的复杂化,网络威胁情报(CTI,cyber threat intelligence)已成为应对
未知网络威胁的重要手段。 为有效解决网络威胁情报因来源广和重复性高而导致其质量难以评估的问题,
本文提出一种基于多源异构数据的网络威胁情报质量评估方法 ISU-Measure(intelligence-source-user
measure)。首先,设计及时性、活跃性、关联性、完整性作为量化指标来表征微观威胁情报的质量;其次,提出
将规模性、周期性、独创性作为量化指标来评估威胁情报源整体质量;然后,针对用户需求差异性设计了用
户指标偏好并与 Critic 权重法结合生成复合权重,同时对 7 个量化指标赋权构建量化评估模型。 通过对 12
个主流威胁情报源的质量评估结果显示,ISU-Measure 方法设计的复合权重法优于 Critic 权重法和均值
法,相比其他研究方法在指标覆盖范围、获取难度、区分性上具有明显优势。

关键词: 网络安全, 威胁情报, 多源情报, 量化评估, Critic 权重法

Abstract: With the diversification of cyber attacks forms and the complexity of attack methods, cyber threat intelligence (CTI)
has become an important means of dealing with unknown cyber threats. To effectively solve the problem of difficulty
to evaluate CTI quality due to the wide source and high repeatability, this paper proposes ISU-Measure (intelligent-source-user measure), a quality evaluation method of CTI based on multi-source heterogeneous data. Firstly,
timeliness, activity, relevance and completeness are designed as quantitative indicators to characterize the quality
of micro threat intelligence. Secondly, it is proposed to use scale, periodicity and originality as quantitative indicators to evaluate the overall quality of threat intelligence sources. Then, based on the differences in user needs, user
indicator preferences are designed and combing with the Critic weighting method, composite weight is generated.
At the same time, seven quantitative indicators are weighted to construct a quantitative evaluation model. The quality evaluation results of 12 mainstream threat intelligence sources show that the composite weighting method designed by the ISU-Measure method is superior to the Critic weighting method and the mean method, and has significant advantages in indicator coverage, acquisition difficulty and discrimination, compared with other research
methods.

Key words: cyber security, threat intelligence, multi-source intelligence, quantitative evaluation, Critic weighting method

中图分类号: 

Baidu
map