在大数据、云计算、物联网等新型信息技术飞速发展的背景下,网络空间威胁也朝泛化和复杂化的趋势在发展,各类网络攻击也更加具有持续性和隐蔽性。基于威胁情报进行网络安全防御能够及时分析已发生的入侵,对未来威胁态势进行预判,并据此评估潜在的安全风险以指导用户制定有效的安全决策,系统化增强网络空间防御能力。威胁情报的范畴十分广泛,因此,介绍了威胁情报感知、共享和分析等方面的研究和发展。
With a rapid development of information technologies including big data, cloud computing, Internet of things, etc., the threats in cyber space also become more ubiquitous and complex. Moreover, more and more persis- tence and hidden features present in all kinds of network attacks. Threat intelligence based network defense can analyze the undergoing attacks and predict the threat situation in the future. Furthermore, based on the potential risk, users can define efficient security policy, thus the defense capabilities of the cyber space could be enhanced system- atically. Threat intelligence is a very wide research area. The research works and developments of the sensing, shar- ing and analysis for threat intelligence were studied and reviewed deeply.