网络威胁情报质量评估:网络防御系统的关键因素
收稿日期: 2025-04-15
网络出版日期: 2026-06-17
基金资助
澳门重点研发专项计划(0007/2024/AKP);深圳市科技计划-科技重大专项(KJZD20240903103811016)
版权
Quality assessment of cyber threat intelligence: a key factor for network defense systems
Received date: 2025-04-15
Online published: 2026-06-17
Copyright
随着关键信息基础设施中网络信息系统的规模与复杂度持续提升,网络防御系统面临告警海量、噪声偏高、关联度弱等问题,导致真实攻击的识别与处置效率受到限制。网络威胁情报(cyber threat intelligence,CTI)可通过提供威胁指标与上下文信息,辅助缩短平均检测时间与平均响应时间,但其来源异构、质量参差不齐、交付流程不透明等问题,导致情报在实战应用中的可信性与可用性难以保障。因此,本文系统梳理近年来威胁情报质量评估的代表性研究成果与工业实践经验,围绕“情报源评估”和“情报内容评估”两条主线,对各类评估指标与方法范式进行归纳与对比,并将评估目标概括为“对不对、快不快、好不好”三类核心维度。在此基础上,本文总结现有评估方法对工业级情报选型、融合与运营的启示,分析当前评估工作在可验证性、适用性与可操作性方面的不足,并提出面向实战需求的后续研究方向。本文可为构建科学、可落地的威胁情报质量评估体系提供参考,支撑网络防御系统提升告警处置与风险响应能力。
向夏雨 , 周琥晨 , 周可 , 顾钊铨 . 网络威胁情报质量评估:网络防御系统的关键因素[J]. 网络空间安全科学学报, 2026 . DOI: 10.20172/j.issn.2097-3136.260535
As networked information systems are increasingly deployed in critical infrastructures, network defense systems face pervasive challenges of massive alerts, high noise, and weak correlation, which undermines the timely identification and response to real attacks. Cyber threat intelligence (CTI) can assist in reducing the mean time to detect (MTTD) and the mean time to respond (MTTR) by providing threat indicators and contextual information, thereby supporting alert triage and decision-making. However, in practice, CTI is heterogeneous in origin and uneven in quality, and its opaque production and delivery processes make its trustworthiness and usability difficult to guarantee. This paper systematically combs representative academic research results and industry practices on CTI quality evaluation in recent years. We organize existing work along two primary dimensions—source evaluation and content evaluation—and summarize the evaluation objectives into three core facets: correctness, timeliness, and utility. Based on this synthesis, we summarize the implications of existing evaluation methods for industrial-level intelligence selection, integration, and operation, identify the limitations of current evaluation work in verifiability, applicability, and operability, and outline future research directions oriented to real-world defense needs. Our review provides a structured reference for constructing scientific and practical CTI quality assessment systems, so as to support network defense systems in improving their alert handling and risk response capabilities.
表 1 威胁情报评估研究分类及其对工业界的启示Table 1 Classification of threat intelligence evaluation studies and their implications for industry |
| 研究内容 | 研究类型 | 代表工作 | 工业痛点 | 工业启示 |
| 威胁情报 源评估 | 指标体系建模 | [23-25] | 情报缺乏统一标准,供应商能力难比较 | 建立多维评价基线,支撑情报选型评估 |
| 源信任建模 | [17,26-29] | 情报源质量波动, 长期可信度难维护 | 引入动态信任机制,持续维护高可信情报源 | |
| 数据驱动评估 | [30-32] | 多源情报规模大, 人工筛选成本高 | 采用自动评分与排序,提升筛选效率 | |
| 威胁情报 内容评估 | 指标体系建模 | [33-34] | 内容质量缺乏统一口径,结果难对齐 | 构建标准化指标体系,增强评估一致性 |
| 源信任建模 | [35-37] | 社区贡献质量不均,优质情报易被稀释 | 识别高价值节点,优化共享与治理机制 | |
| 数据驱动评估 | [38-39] | 情报更新快,人工难以及时判断有效性 | 建立生命周期预测与动态更新机制 | |
| 情报源与内容 综合评估 | 联合评估模型 | [40-41] | 单独评估来源或内容难反映整体价值 | 构建源—内容联合评估框架,支撑融合与运营决策 |
表 2 代表性威胁情报质量评估研究的关键差异对比Table 2 Key differences of representative CTI quality assessment studies |
| 代表工作 | 评估对象 | 评估依据 | 主要优势 | 局限 |
| FeedRank[26] | 情报源 | 完整性/准确性/速度;源间时间–空间关联图(原创性/复用性) | 强调源间关系建模;支持动态源管理与异常源识别 | 依赖源间关联可观测;低交集/覆盖偏置生态下区分度与稳定性受限 |
| TIAM[35] | 情报内容 | 内容特征提取与自动分类;将 IoC 与 ATT&CK 技术关联以补足上下文 | 面向稀疏/碎片化情报的结构化与上下文增强;支持自动化评估 | 依赖特征/规则或模型设定;跨场景迁移与“真值”构建受数据条件约束 |
| ETIP[37] | 情报内容 | 多源聚合;启发式加权(相关性/准确性/多样性等)形成威胁评分 | 可解释、易落地;贴近 SOC 的“事件/IoC 优先级排序”需求 | 权重/阈值敏感;依赖平台数据与关联能力;跨研究可比性不足 |
| Plaza[38] | CTI报告 | 多层级结构化质量指标:属性层/对象层/报告层(时效性、表示一致性、声誉、数据量充足性等) | 指标体系清晰;强调标准格式与评估透明性;便于工具化实现 | 更偏格式/数据质量度量;与真实攻击命中/防御收益的直接验证相对弱 |
| CTIC[44] | 源 + 内容 | 源相关图迭代评分(源可信);内容可用性评估(可验证性/丰富性/时效性等,含 ML) | 体现“源可信→内容融合”的协同思路;形成联合评估框架雏形 | 联合评估代表性工作较少;动态反馈与冲突消解缺乏统一可复现评测口径 |
| Yang等[47] | 源 + 内容 | 源间交互相关图(源可信);内容可用性自动评估(时效性、完整性等)输出综合评分 | 将源可信与内容可用性统一到单一评分;便于工程集成与选型 | 对数据/验证口径依赖较强;跨组织迁移与横向对比复现仍受限 |
| 1 |
方滨兴. 定义网络空间安全[J]. 网络与信息安全学报, 2018, 4 (1): 1- 5.
Fang B X. Define cyberspace security[J]. Chinese Journal of Network and Information Security, 2018, 4 (1): 1- 5.
|
| 2 |
贾焰, 方滨兴, 李爱平, 等. 基于人工智能的网络空间安全防御战略研究[J]. 中国工程科学, 2021, 23 (3): 98- 105.
Jia Y, Fang B X, Li A P, et al. Artificial intelligence enabled cyberspace security defense[J]. Strategic Study of CAE, 2021, 23 (3): 98- 105.
|
| 3 |
Alahmadi B A, Axon L, Martinovic I. 99% false positives: a qualitative study of {SOC} analysts' perspectives on security alarms[C]//31st USENIX Security Symposium (USENIX Security 22). 2022: 2783-2800.
|
| 4 |
Kokulu F B, Soneji A, Bao T, et al. Matched and mismatched SOCs: a qualitative study on security operations center issues[C]//Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security. New York: ACM, 2019: 1955-1970.
|
| 5 |
Yang L, Chen Z, Wang C, et al. True attacks, attack attempts, or benign triggers? an empirical measurement of network alerts in a security operations center[C]//33rd USENIX Security Symposium (USENIX Security 24). 2024: 1525-1542.
|
| 6 |
Fu C P, Li Q, Xu K, et al. Point cloud analysis for ML-based malicious traffic detection: reducing majorities of false positive alarms[C]//Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security. New York: ACM, 2023: 1005-1019.
|
| 7 |
向夏雨, 顾钊铨, 曾丽仪. 网络威胁情报共享与融合技术综述[J]. 网络空间安全科学学报, 2024, 2 (2): 2- 17.
Xiang X Y, Gu Z Q, Zeng L Y. A survey of cyber threat intelligence sharing and fusion technologies[J]. Journal of Cybersecurity, 2024, 2 (2): 2- 17.
|
| 8 |
Xiang X Y, Liu H, Zeng L Y, et al. IPAttributor: cyber attacker attribution with threat intelligence-enriched intrusion data[J]. Mathematics, 2024, 12(9): 1364.
|
| 9 |
Fortune Business Insights. Threat intelligence market [EB/OL]. (2025-03-17) [2025-11-12]. https://www.fortunebusinessinsights.com/zh/threat-intelligence-market-102984.
|
| 10 |
Recorded Future. 2024 state of threat intelligence [EB/OL]. (2025-02-11) [2025-11-12]. https://go.recordedfuture.com/hubfs/2024%20State%20of%20Threat%20Intelligence/Recorded%20Future%202024%20State%20of%20Threat%20Intelligence%20Report.pdf?hsLang=en.
|
| 11 |
Sinha S, Bailey M, Jahanian F. Shades of grey: on the effectiveness of reputation-based “blacklists” [C]//2008 3rd International Conference on Malicious and Unwanted Software (MALWARE). IEEE, 2008: 57-64.
|
| 12 |
Sheng S, Wardman B, Warner G, et al. An empirical analysis of phishing blacklists[C]//In Sixth Conference on Email and Anti-Spam (CEAS). IEEE, 2009: 23-31.
|
| 13 |
Kührer M, Rossow C, Holz T. Paint it black: evaluating the effectiveness of malware blacklists[M]//Research in Attacks, Intrusions and Defenses. Cham: Springer International Publishing, 2014: 1-21.
|
| 14 |
Oest A, Safaei Y, Doupe A, et al. PhishFarm: a scalable framework for measuring the effectiveness of evasion techniques against browser phishing blacklists[C]//Proceedings of the 2019 IEEE Symposium on Security and Privacy (SP). Piscataway: IEEE Press, 2019: 1344-1361.
|
| 15 |
Ramachandran A, Feamster N, Vempala S. Filtering spam with behavioral blacklisting[C]//Proceedings of the 14th ACM Conference on Computer and Communications Security. New York: ACM, 2007: 342-351.
|
| 16 |
Tounsi W, Rais H. A survey on technical threat intelligence in the age of sophisticated cyber attacks[J]. Computers & Security, 2018, 72, 212- 233.
|
| 17 |
Bouwman X, Griffioen H, Egbers J, et al. A different cup of {TI}? the added value of commercial threat intelligence[C]//29th USENIX security symposium (USENIX security 20). 2020: 433-450.
|
| 18 |
Wang Z J, Li X B. Intrusion prevention system design[M]//Proceedings of the International Conference on Information Engineering and Applications (IEA) 2012. London Springer, 2013: 375-382.
|
| 19 |
Clincy V, Shahriar H. Web application firewall: network security models and configuration[C]//Proceedings of the 2018 IEEE 42nd Annual Computer Software and Applications Conference (COMPSAC). Piscataway: IEEE Press, 2018: 835-836.
|
| 20 |
Neupane K, Haddad R, Chen L. Next generation firewall for network security: a survey[C]//Proceedings of the SoutheastCon 2018. Piscataway: IEEE Press, 2018: 1-6
|
| 21 |
Yang W Z, Lam K Y. Automated cyber threat intelligence reports classification for early warning of cyber attacks in next generation SOC[C]//Information and Communications Security. Cham: Springer, 2020: 145-164.
|
| 22 |
MITRE, MITRE ATT&CK [DB/OL]. [2025-11-12]. https://attack.mitre.org/.
|
| 23 |
Li Q, Jiang Z W, Yang Z M, et al. A quality evaluation method of cyber threat intelligence in user perspective[C]//Proceedings of the 2018 17th IEEE International Conference on Trust, Security and Privacy in Computing and Communications/ 12th IEEE International Conference on Big Data Science and Engineering (TrustCom/BigDataSE). Piscataway: IEEE Press, 2018: 269-276.
|
| 24 |
Schaberreiter T, Kupfersberger V, Rantos K, et al. A quantitative evaluation of trust in the quality of cyber threat intelligence sources[C]//Proceedings of the 14th International Conference on Availability, Reliability and Security. New York: ACM, 2019: 1-10.
|
| 25 |
Chen S S, Hwang R H, Ali A, et al. Improving quality of indicators of compromise using STIX graphs[J]. Computers & Security, 2024, 144, 103972.
|
| 26 |
Meier R, Scherrer C, Gugelmann D, et al. FeedRank: a tamper- resistant method for the ranking of cyber threat intelligence feeds[C]//Proceedings of the 2018 10th International Conference on Cyber Conflict (CyCon). Piscataway: IEEE Press, 2018: 321-344.
|
| 27 |
Li V G, Dunn M, Pearce P, et al. Reading the tea leaves: a comparative analysis of threat intelligence[C]//28th USENIX security symposium (USENIX Security 19). 2019: 851-867.
|
| 28 |
Griffioen H, Booij T, Doerr C. Quality evaluation of cyber threat intelligence feeds[M]//Applied Cryptography and Network Security. Cham: Springer International Publishing, 2020: 277-296.
|
| 29 |
Satvat K, Gjomemo R, Venkatakrishnan V N. TIPCE: a longitudinal threat intelligence platform comprehensiveness analysis[C]//Proceedings of the Fourteenth ACM Conference on Data and Application Security and Privacy. New York: ACM, 2024: 349-360.
|
| 30 |
Tundis A, Ruppert S, Mühlhäuser M. A feature-driven method for automating the assessment of OSINT cyber threat sources[J]. Computers & Security, 2022, 113, 102576.
|
| 31 |
Zhang S Q, Chen P, Bai G Y, et al. An automatic assessment method of cyber threat intelligence combined with ATT&CK matrix[J]. Wireless Communications and Mobile Computing, 2022, 7875910.
|
| 32 |
Plaza A, Hayajneh T. Defining metrics for comparing threat intelligence solutions through the lens of the analyst[C]//Proceedings of the 2023 IEEE 14th Annual Ubiquitous Computing, Electronics & Mobile Communication Conference (UEMCON). Piscataway: IEEE Press, 2023: 192-199.
|
| 33 |
González G G, Faiella M, Medeiros I, et al. ETIP: an enriched threat intelligence platform for improving OSINT correlation, analysis, visualization and sharing capabilities[J]. Journal of Information Security and Applications, 2021, 58, 102715.
|
| 34 |
Schlette D, Böhm F, Caselli M, et al. Measuring and visualizing cyber threat intelligence quality[J]. International Journal of Information Security, 2021, 20 (1): 21- 38.
|
| 35 |
Chandel S, Yan M D, Chen S J, et al. Threat intelligence sharing community: a countermeasure against advanced persistent threat[C]//Proceedings of the 2019 IEEE Conference on Multimedia Information Processing and Retrieval (MIPR). Piscataway: IEEE Press, 2019: 353-359
|
| 36 |
Choo E, Nabeel M, Kim D, et al. A large scale study and classification of VirusTotal reports on phishing and malware URLs[J]. Proceedings of the ACM on Measurement and Analysis of Computing Systems, 2023, 7 (3): 1- 26.
|
| 37 |
Lin P C, Hsu W H, Lin Y D, et al. Correlation of cyber threat intelligence with sightings for intelligence assessment and augmentation[J]. Computer Networks, 2023, 228, 109736.
|
| 38 |
Kodituwakku A, Xu C, Rogers D, et al. Temporal aspects of cyber threat intelligence[C]//Proceedings of the 2023 IEEE International Conference on Big Data. Piscataway: IEEE Press, 2023: 6207-6211.
|
| 39 |
Sakellariou G, Fouliras P, Mavridis I. A methodology for developing & assessing CTI quality metrics[J]. IEEE Access, 2024, 12, 6225- 6238.
|
| 40 |
Wang M H, Yang L B, Lou W. A comprehensive dynamic quality assessment method for cyber threat intelligence[C]//Proceedings of the 2022 52nd Annual IEEE/IFIP International Conference on Dependable Systems and Networks Workshops (DSN-W). Piscataway: IEEE Press, 2022: 178-181.
|
| 41 |
Venčkauskas A, Jusas V, Barisas D. Quality dimensions for automatic assessment of structured cyber threat intelligence data[J]. Applied Sciences, 2025, 15 (8): 4327.
|
| 42 |
VirusTotal [DB/OL]. [2025-11-12]. https://www.virustotal.com/gui/home/.
|
| 43 |
IBM X-Force exchange[DB/OL]. [2025-11-12]. https://exchange.xforce.ibmcloud.com/.
|
| 44 |
Hybrid analysis[DB/OL]. [2025-11-12]. https://www.hybrid-analysis.com/.
|
| 45 |
AlientVault OTX[DB/OL]. [2025-11-12]. https://otx.alienvault.com/.
|
| 46 |
Chatziamanetoglou D, Rantos K. Weighted quality criteria for cyber threat intelligence: assessment and prioritisation in the MISP data model[J]. International Journal of Information Security, 2025, 24 (4): 160.
|
| 47 |
Yang L B, Wang M H, Lou W. An automated dynamic quality assessment method for cyber threat intelligence[J]. Computers & Security, 2025, 148: 104079.
|
| 48 |
Mohaisen A, Al-Ibrahim O, Kamhoua C, et al. Assessing quality of contribution in information sharing for threat intelligence[C]//Proceedings of the 2017 IEEE Symposium on Privacy-Aware Computing (PAC). Piscataway: IEEE Press, 2017: 182-183.
|
| 49 |
Park J, Alasmary H, Al-Ibrahim O, et al. QOI: assessing participation in threat information sharing[C]//Proceedings of the 2018 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP). Piscataway: IEEE Press, 2018: 6951-6955.
|
| 50 |
Rashid Z, Noor U, Altmann J. Network externalities in cybersecurity information sharing ecosystems[M]//Economics of Grids, Clouds, Systems, and Services. Cham: Springer International Publishing, 2019: 116-125.
|
| 51 |
Azevedo R, Medeiros I, Bessani A. PURE: generating quality threat intelligence by clustering and correlating OSINT[C]//2019 18th IEEE International Conference on Trust, Security and privacy in computing and Communications/13th IEEE International Conference on Big Data Science and Engineering (TrustCom/BigDataSE). IEEE, 2019: 483-490.
|
| 52 |
Wagner T D, Mahbub K, Palomar E, et al. Cyber threat intelligence sharing: survey and research directions[J]. Computers & Security, 2019, 87, 101589.
|
| 53 |
Sillaber C, Sauerwein C, Mussmann A, et al. Data quality challenges and future research directions in threat intelligence sharing practice[C]//Proceedings of the 2016 ACM on Workshop on Information Sharing and Collaborative Security. New York: ACM, 2016: 65-70.
|
| 54 |
Li L, Li X Y, Gao Y L. MTIV: a trustworthiness determination approach for threat intelligence[M]//Security, Privacy, and Anonymity in Computation, Communication, and Storage. Cham: Springer International Publishing, 2017: 5-14.
|
| 55 |
Wagner T D, Palomar E, Mahbub K, et al. Relevance filtering for shared cyber threat intelligence[M]//Information Security Practice and Experience. Cham: Springer International Publishing, 2017: 576-586.
|
| 56 |
Montesdioca G P Z, Maçada A C G. Quality dimensions of the DeLone-McLean model to measure user satisfaction: an empirical test on the information security context[C]//Proceedings of the 2015 48th Hawaii International Conference on System Sciences. Piscataway: IEEE Press, 2015: 5010-5019.
|
| 57 |
Talha M, Abou E K, Elmarzouqi N. Big data: trade-off between data quality and data security[J]. Procedia Computer Science, 2019, 151, 916- 922.
|
| 58 |
Shamala P, Ahmad R, Zolait A, et al. Integrating information quality dimensions into information security risk management (ISRM)[J]. Journal of Information Security and Applications, 2017, 36, 1- 10.
|
| 59 |
Sicari S, Rizzardi A, Miorandi D, et al. Security policy enforcement for networked smart objects[J]. Computer Networks, 2016, 108, 133- 147.
|
| 60 |
Sillaber C, Mussmann A, Breu R. Experience: data and information quality challenges in governance, risk, and compliance management[J]. Journal of Data and Information Quality, 2019, 11 (2): 1- 14.
|
| 61 |
Sillaber C, Breu R. Using stakeholder knowledge for data quality assessment in IS security risk management processes[C]//Proceedings of the 2015 ACM SIGMIS Conference on Computers and People Research. New York: ACM, 2015: 153-159.
|
| 62 |
Bertino E, Abu Jabal A, Calo S, et al. The challenge of access control policies quality[J]. Journal of Data and Information Quality, 2018, 10 (2): 1- 6.
|
| 63 |
Grispos G, Glisson W B, Storer T. How good is your data? investigating the quality of data generated during security incident response investigations[PP/OL]. V1. arXiv (2019-01-11) [2025-11-12]. https://doi.org/10.48550/arXiv.1901.03723
|
| 64 |
Reda O, Benabdellah N C, Zellou A. A systematic literature review on data quality assessment[J]. Bulletin of Electrical Engineering and Informatics, 2023, 12(6).
|
| 65 |
Kohlrausch J, Brin E A. ARIMA supplemented security metrics for quality assurance and situational awareness[J]. Digital Threats: Research and Practice, 2020, 1 (1): 1- 21.
|
| 66 |
Haug A. Understanding the differences across data quality classifications: a literature review and guidelines for future research[J]. Industrial Management & Data Systems, 2021, 121 (12): 2651- 2671.
|
| 67 |
Ehrlinger L, Wöß W. A survey of data quality measurement and monitoring tools[J]. Frontiers in Big Data, 2022, 5, 850611.
|
| 68 |
Sarhan M, Layeghy S, Moustafa N, et al. Cyber threat intelligence sharing scheme based on federated learning for network intrusion detection[J]. Journal of Network and Systems Management, 2023, 31, 3.
|
| 69 |
Li Z Y, Zeng J, Chen Y, et al. AttacKG: constructing technique knowledge graph from cyber threat intelligence reports[C]//Computer Security – ESORICS 2022. Cham: Springer, 2022: 589-609
|
| 70 |
白敏, 汪列军. 利用威胁情报构建主动安全关联分析及运营框架[J]. 网络空间安全科学学报, 2025, 3 (5): 84- 101.
Bai M, Wang L J. Leveraging threat intelligence to construct a proactive security correlation analysis and operation framework[J]. Journal of Cybersecurity, 2025, 3 (5): 84- 101.
|
| 71 |
Krašovec A, Steri G, Karopoulos G, et al. Large language models for cyber threat intelligence: extracting MITRE with LLMs[M]//Availability, Reliability and Security. ChamSpringer Nature Switzerland2025: 80-89.
|
| 72 |
Büchel M, Albrecht M R, Payer M, et al. SoK: automated TTP extraction from CTI reports – are we there yet[C]//USENIX Security Symposium, 2025
|
/
| 〈 |
|
〉 |