2022.10.12
Overview
A labeling method for information security protection detection rules and an information security threat tactic, technique and procedure (TTP) labeling device. The labeling method includes: obtaining a plurality of reference documents related to definitions of TTP and classify them to generate corpuses; building a keyword thesaurus; obtaining a plurality of to-be-labeled detection rules, and extracting key information fields from them and comparing the key information fields with keywords, so as to label the to-be-labeled detection rules; for those not labeled of the to-be-labeled detection rules, performing a text similarity calculation on the key information fields and the corpuses, and labeling those not labeled of the to-be-labeled detection rules with the corpus having the highest similarity; training with the labeled detection rules and the corpuses as a training data set to generate a TTP labeling model; and inputting a current to-be-labeled detection rule to generate a TTP labeling result.Category
發明
Patented
111138541
發明第I822388號
Filing Date
2022.10.12Expired Date
2042.10.11Notification
2025.04.25