跳到正文
cloudflare blog· Emilia Yoffie·· 2 天前精選AI 評分77

推出 Threat Signals:面向開源威脅情報的智慧體技能,免費提供給所有 Cloudflare 賬戶

Introducing Threat Signals: agentic skills for open-source threat intelligence, free for every Cloudflare account

AI 導讀

Cloudflare 推出 Threat Signals,利用 AI 技能自動化提取並標註開源威脅報告中的指標,保留上下文,直接生成可在 WAF 中使用的規則,並通過 API 與內部 TIP 整合。

推薦理由

Threat Signals 通過 AI 技能自動化提取並標註開源威脅報告中的指標,保留上下文,直接生成可在 WAF 中使用的規則,幫助企業快速提升防禦效率,並可通過 API 與內部 TIP 整合,實現全流程威脅情報閉環,降低人工分析成本。

正文 · AI 翻譯

Organizations can now scale threat intelligence expertise the way they scale infrastructure. Threat intelligence analysts and network defenders have long automated the ingestion of structured threat feeds to help enrich their SIEM or WAF. The harder work has always been unstructured reporting: turning a research post into indicators your tools can use, without losing the context that explains why they matter. AI skills make that work possible to automate. A skill is a set of rich, detailed instructions that captures how an experienced analyst handles one part of the job, and it runs the same way on every report. 

Threat Signals puts that process into practice at scale. It’s launching today, and we made it available to every Cloudflare account. 

Threat Signals turns open-source reporting that you choose into intelligence you can act on. Its agentic skills summarize reports, surface key context, extract and normalize indicators of compromise, and apply tags — all within a private, account-scoped dataset. The end result is a contextualized indicator stored in your account’s private Threat Intelligence dataset as a Threat Event that can instantly be applied in your WAF policy.

Starting today, we are also expanding access to Cloudforce One’s Threat Events Platform, our core threat intelligence offering, to all Cloudflare accounts for free. With this expansion, each account gets:

  • API and dashboard access to Threat Signals and the ability to select one RSS feed
  • A private dataset built from the RSS feed in Threat Signals, tailored to your reporting requirements and stored for up to 30 days
  • API and dashboard access to Threat Events Platform to investigate events, indicators, and tags related to your private dataset

Essentials, Advantage, and Elite enterprise customers can extend this offering to include an expanded number of RSS feeds, access to Cloudforce One’s proprietary threat intelligence datasets, the ability to generate custom agentic skills, higher storage options for Threat Signals’ derived open-source reporting, and the ability to create custom WAF rules on open-source and proprietary threat events.

Discovery is only the beginning

We started with open-source intelligence because it is the most obvious place to prove the power of agentic workflows. We also heard from customers that their existing platforms cannot scale beyond polling 100 RSS feeds. Recognizing the critical impact open-source reporting plays in understanding the threat landscape, we sought to build an infinitely scalable platform (more on that later).

Researchers regularly publish detailed findings on vulnerabilities, malicious infrastructure, phishing campaigns, malware families, and threat actors. While RSS feed readers make it easier to discover new reporting, discovery is only the beginning. Harnessing data into a usable workflow with consistent expertise is the key to building actionable defense.

Expertise has never been something organizations can replicate at scale. A report explains how a campaign works and identifies the infrastructure behind it, but before an analyst can use that information, they need to:

  • Read and summarize the report
  • Identify relevant indicators
  • Convert indicator values into a consistent format
  • Classify the report using an internal taxonomy for tagging
  • 將指標填入威脅情報平臺(TIP)
  • 保留指向原始來源的連結
  • 與安全團隊其餘成員共享情報

在數十個來源上重複此過程需要時間;此外,幾乎每一步都完全依賴人工判斷。因此,背景資訊會丟失。插入到 TIP 的指標與解釋其重要性並在修復週期後評估風險的上下文分離。幾週後,一個域名被推入黑名單,而沒有人知道原因,這並不令人驚訝。 

Threat Signals 的工作原理

Threat Signals 使用 RSS 監控對貴組織重要的開源報告。您可以新增 RSS 源,為其命名並歸類,並配置 Threat Signals 檢查新內容的頻率。支援三種源規範(RSS 2.0、Atom 和 RSS 1.0/RDF)。

每個您選擇的源都會進入一個 Workflow,該工作流會定期輪詢新文章。它使用 Browser Run 的 Markdown 快速操作來獲取並清理文章文本為可讀的 Markdown 格式,然後儲存在 R2。文本隨後被傳遞給指標洩露提取器和一組預設的 Cloudforce One 定義的技能,以總結內容、根據您的賬戶配置應用標籤,並在 IOC 級別新增指標上下文。

輸出是簡明的摘要和要點,幫助分析師快速瞭解發生了什麼、誰受影響以及報告為何重要。所有內容均可搜尋並已標記,您可以在整個平臺上查詢感興趣的文章。

最後,每個提取的指標都由賬戶自身私有 Threat Signals 資料集中的一次威脅事件支援。該事件、其指標和標籤以及原始報告保持關聯,分析師始終可以追溯情報來源及其存在的原因。這些指標隨後可用於 從威脅事件建立 WAF 規則,以保護您的應用程式和基礎設施。

我們的收穫

編寫一個指令碼從 RSS 源提取並使用正規表示式匹配 IP 地址並不難。Threat Signals 的第一個版本是一個為期一週的內部原型,由一名想從已閱讀報告中獲得更多價值的威脅分析師構建。將其轉變為每個賬戶都能依賴的東西更具挑戰性,且大多數拖慢我們的因素與解析無關。真正的難點在於讓輸出成為分析師信任並實際使用的內容。 

我們曾想讓系統自行生成任何看似有用的標籤。我們交談的團隊對此提出異議:用陌生詞彙標記情報更難使用,因為此時需要調和兩套詞彙。因此,我們將 AI 標記限制在每個賬戶現有的標籤目錄內。 

記錄標籤是自動應用還是由分析師手動應用聽起來像是一個小的後設資料,但實際上它至關重要。在我們的經驗中,分析師更願意信任自動標記,只要他們能清楚看到系統應用了哪些標籤。

摘要很有用,也是使用者首先注意到的內容。但在早期測試中,分析師反覆關注的是事件與其來源報告之間的關聯。隨著調查的深入,我們發現這一關聯始終幫助他們跟蹤指標,並理解每個指標為何重要。 

下一步

開源報告不侷限於 RSS 源。分析師需要能夠快速消費各種格式和管道的威脅情報。既然我們已經搭建了從資料來源攝取指標到平臺的基礎模組,下一步自然是新增更多消費者。請關注我們將支援的更多資料攝取管道,以便您將更多可操作情報帶入平臺,保護您的組織。

立即開啟 Cloudflare 儀表盤並設定您的訂閱源

最佳調查始於可信的背景資訊,Threat Signals 能在第一條線索之後持續保持這一背景。Threat Signals 現已通過 API 和儀表盤向每個 Cloudflare 賬戶普遍開放。開啟 Cloudflare 儀表盤,導航至 Application Security → Threat Intelligence → Threat Signals,並新增您的 RSS 源。文件在此。 

您還可以閱讀我們團隊的 威脅情報研究,並與您的賬戶團隊討論如何在企業環境中使用 Threat Events。

來源:cloudflare blog · blog.cloudflare.com