Web 0Day vulnerability detection and mining method and platform based on security intelligence
By constructing a Web 0Day vulnerability detection and mining method based on security intelligence, and utilizing a large security model and multi-module combination, the problems of low efficiency and poor adaptability of Web 0Day vulnerability detection are solved, and efficient and accurate vulnerability detection and mining are achieved.
Patent Information
- Application Number
- CN202411933699.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-26
- Publication Date
- 2025-09-26
- Estimated Expiration
- 2044-12-26
AI Technical Summary
Existing technologies are difficult to effectively detect and exploit Web 0Day vulnerabilities, especially in terms of sample data scarcity, complexity and diversity, real-time and adaptability. Traditional methods are inefficient and unable to respond to emerging attacks in a timely manner.
Construct a Web 0Day vulnerability detection and mining method based on security intelligence. By training a large security model in the vertical network security field, combining the memory module, planning module and tool module, and utilizing the intelligent agent characteristics of the large model, combined with cross-language integration and front-end visualization technology, deep dynamic analysis and multi-dimensional feature mining of Web applications can be achieved.
It improves the ability to mine and detect Web 0Day vulnerabilities, can respond to and adapt to dynamically changing vulnerability exploitation methods in real time, generate effective test cases, and improve the accuracy and efficiency of vulnerability detection.
Smart Images

Figure CN119892422B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of network security and relates to the construction of a security intelligent body, specifically a Web 0Day vulnerability detection and mining method and platform based on a security intelligent body. Background Art
[0002] With the rapid development of internet technology, web applications have become an essential component of both enterprise and personal information. However, the rapid iteration and complexity of web applications also present potential security risks, particularly zero-day vulnerabilities. These vulnerabilities are security flaws that have not yet been publicly disclosed or patched. Once maliciously exploited, they can lead to serious consequences such as data leaks and system intrusions, posing a significant threat to network security.
[0003] Traditional web vulnerability detection methods are primarily categorized into manual analysis and automated tool detection. Manual analysis relies on the experience and skills of security experts, resulting in low detection efficiency and high costs. While automated tools can cover some known vulnerabilities, their ability to detect unknown vulnerabilities (such as zero-day vulnerabilities) is limited, and they often lack a deep understanding of complex vulnerability characteristics. Furthermore, existing methods often fail to adapt promptly to emerging attack techniques, resulting in delayed vulnerability detection.
[0004] In recent years, breakthroughs in artificial intelligence (AI) technology have brought new opportunities to the security field. Security big models have emerged. They combine advanced artificial intelligence algorithms with training on massive amounts of security data, and can accurately identify various security threats, vulnerabilities, and risks, providing strong support for network security. Furthermore, the development of security big models has led to the birth of security agents, which combine the powerful analytical capabilities and autonomous decision-making capabilities of security big models to intelligently formulate and execute corresponding security policies based on real-time security trends. The emergence of security agents marks the transition of network security protection from passive defense to active intelligent defense, providing strong guarantees for building a more secure and reliable network environment. However, the direct application of security agent technology to vulnerability mining still faces the following challenges:
[0005] 1. The scarcity of sample data for Web 0Day vulnerabilities makes it difficult for traditional AI models to effectively learn vulnerability characteristics.
[0006] 2. Complexity and diversity: The structure and development technologies of web applications are complex and diverse, involving multiple programming languages, frameworks, and protocols. This requires the model to have cross-language and cross-domain understanding capabilities.
[0007] 3. Real-time and adaptability: 0-day vulnerability mining requires real-time response capabilities to cope with dynamic changes in vulnerability exploitation methods. Summary of the Invention
[0008] To address the above challenges, the present invention proposes a Web 0Day vulnerability detection and mining method and platform based on security intelligence. By training a large security model and building a security intelligence agent, it achieves in-depth dynamic analysis and multi-dimensional feature mining of Web applications, thereby improving the mining capability and detection efficiency of Web 0Day vulnerabilities.
[0009] In order to achieve the above object, the technical solutions specifically adopted by the present invention are as follows:
[0010] A Web 0Day vulnerability detection and mining method based on a security agent includes the following steps:
[0011] S1. Collection and preprocessing of massive network security related data;
[0012] S2. Train a large security model in a vertical network security field;
[0013] S3. With the aforementioned security big model as the core, combined with a customized memory module, tool module, and planning module, a security agent is constructed using the agent characteristics of the big model. This security agent is used for Web 0Day vulnerability detection and mining tasks, including analyzing possible vulnerability injection points on Web pages and generating test cases for vulnerability mining verification.
[0014] S4. Based on cross-language integration and front-end visualization technology, a web visualization platform is built in combination with security intelligence.
[0015] S5. Based on the Web visualization platform, the vulnerability analysis of Web page content, the generation and verification of vulnerability test cases, and the visual display of security professional knowledge Q&A functions are realized.
[0016] Furthermore, the massive network security related data collected in the step S1 mainly includes vulnerability information and exploit scripts in vulnerability libraries (such as CVE, NVD), attack samples (such as SQL injection, cross-site scripting attacks) and traffic logs, security research papers and technical reports, as well as project information of web frameworks and open source code libraries. By integrating these diverse data sources, solid and comprehensive data support is provided for the training of large security models and the construction of security intelligence agents. The collection of massive network security related data includes two parts: one is to use the Scrapy framework to crawl network security related data from search engines, open source libraries and other channels; the other is to obtain information such as e-books and collections of papers in the field of network security through manual collection.
[0017] Furthermore, in step S1, the preprocessing of massive network security-related data includes formatting the crawled data into a structured format, removing irrelevant noise information, and cleaning up duplicate, useless or redundant data according to the data type; extracting text from manually collected PDF documents using OCR technology, improving accuracy through image preprocessing and recognition correction, and finally structuring the text and saving it in a standard format.
[0018] Furthermore, in the step S2, based on the LLama-Factory framework, Qwen 7B is used as the base model, 400,000 Web vulnerability security data are used for 10 rounds of incremental pre-training, and 4,000 self-constructed question-answer pairs are used for supervised instruction fine-tuning to obtain a large security model in the vertical network security field; the training process includes an incremental pre-training stage and a supervised instruction fine-tuning stage; in the incremental pre-training stage, the base model is trained with a large amount of data in the security field, thereby learning rich vertical field knowledge and expanding its knowledge boundaries; in the supervised instruction fine-tuning stage, the model is trained with self-constructed instruction question-answer pairs, so that the model's answers are more vertical to the security field and aligned with the human answer logic, and finally a large security model in the vertical network security field is obtained. The model shows significant advantages in network security-related tasks, especially in tasks such as vulnerability analysis and test case generation, its professionalism and accuracy have been significantly improved, providing model support for the subsequent construction of security intelligent agents.
[0019] Furthermore, in step S3, the construction of the security agent is based on the Dify framework, and the security agent includes:
[0020] The underlying big model uses the security big model to provide professional security decision support. It provides more in-depth professional security knowledge and can more accurately support the detection and mining of Web0Day vulnerabilities compared to general models.
[0021] The memory module consists of long-term memory and short-term memory. Long-term memory is used to assist in executing RAG retrieval enhancement generation tasks, liberating the time dependency in the model training process and enabling it to answer cutting-edge knowledge about the security field. Short-term memory temporarily stores information related to the current conversation, thereby improving the agent's short-term memory ability and enhancing the coherence and accuracy of the conversation.
[0022] The planning module is responsible for converting user security questions into classification tasks. By understanding the semantics and context of user input questions, combined with designed prompt word engineering, it guides the model to make accurate judgments, ensuring the optimal path for each problem handling, thereby achieving efficient and accurate task execution.
[0023] The tool module includes page analysis tools, test case generation tools, and RAG retrieval enhancement generation tools, which are used to assist in analyzing security vulnerabilities of web pages, generate vulnerability test cases, and extract the latest security information from external literature and databases, enhance the knowledge base of large models, and improve the accuracy and comprehensiveness of vulnerability detection and mining.
[0024] Furthermore, in step S4, cross-language integration technology is used to call a Python-based security agent on a Java-developed Web platform, and GRPC technology is used to build a high-performance, distributed, cross-language service architecture between the security agent and the Web system; the front-end visualization technology uses VUE and Element-UI to build a Web visualization framework, combines HTML5 and CSS to design the web page structure and style, and uses JavaScript to achieve dynamic interaction, supporting vulnerability analysis, test case generation and verification, and visual display of security knowledge Q&A and other functions.
[0025] The present invention also provides a security agent-based Web 0Day vulnerability detection and mining platform, which uses the above-mentioned security agent-based Web 0Day vulnerability detection and mining method to implement Web 0Day vulnerability detection and mining.
[0026] The present invention has the following characteristics and beneficial effects:
[0027] This paper trains a large-scale security model specifically for the cybersecurity field. Unlike existing commercially available security models such as SecGPT, HackMentor, and AutoAudit, this model leverages more comprehensive and forward-looking data sources to enhance its capabilities. In addition to common open-source datasets and public data obtained through crawlers, it further integrates high-quality purchased e-books and the latest academic papers in the cybersecurity field. As a result, the large-scale model trained by this invention performs better in security knowledge question answering, test case generation, and other aspects.
[0028] This paper builds a security agent based on a self-trained security model. Compared to existing mainstream large language models such as GPT-4 and GLM-4, which cannot directly perform vulnerability analysis on user-provided URLs, the security agent of this invention can perform vulnerability analysis on web pages using only user-provided URLs, generate effective test cases, and efficiently discover web zero-day vulnerabilities.
[0029] This invention builds a Web visualization platform that supports the visualization of multiple functions such as vulnerability analysis, test case generation and verification, and security knowledge Q&A. Through interactive dialogue, users can easily perform Web vulnerability detection and analysis, generate test cases, and verify them. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] Figure 1 This is the overall framework diagram of the Web 0Day vulnerability detection and mining method based on security intelligence;
[0031] Figure 2 This is the result diagram of the security agent's Web 0Day vulnerability detection and mining verification effect;
[0032] Figure 3 Provide users with a flowchart for Web 0Day vulnerability mining and verification based on a Web visualization platform. DETAILED DESCRIPTION
[0033] The present invention is described in detail below in conjunction with specific embodiments. The following examples will help those skilled in the art to further understand the present invention, but are not intended to limit the present invention in any form. It should be noted that, in the absence of conflict, the embodiments of the present invention and the features in the embodiments can be combined with each other.
[0034] The overall framework of the Web 0Day vulnerability detection and mining method based on security intelligence of the present invention is shown in the figure below: Figure 1 As shown, it includes 5 steps: data collection and preprocessing, large security model training, security intelligent agent construction, Web visualization platform construction, and Web visualization platform application.
[0035] 1. Data Collection and Preprocessing
[0036] In data acquisition of the present invention and pre-processing process, a part adopts Scrapy framework to carry out efficient data crawling, collects a large amount of knowledge relevant to network security by multiple channels such as search engine, blog forum, open source knowledge base.Specifically, the main data source crawled comprises the vulnerability information in vulnerability library (such as CVE, NVD) and utilizes script, attack sample (such as SQL injection, cross-site scripting) and flow log, security research paper and technical report, and the project data of Web framework and open source code base.First, use the Spider crawler of Scrapy framework to automatically crawl target data from these websites, such as vulnerability description, attack method, utilize script, flow log, technical documentation etc., and extract corresponding information (such as, the numbering of vulnerability, the system affected, vulnerability type, the code of attack sample, the offensive behavior in flow log, the safety suggestion in technical report etc.) according to the structure of data.In order to adapt to the crawling of dynamic web content, use in conjunction with the Middleware and Selenium tools such as Scrapy, process the page that JavaScript renders, guarantee to obtain complete web page data.
[0037] Next, when cleaning the initially extracted security knowledge, the crawled data must first be formatted and converted into a structured format suitable for subsequent analysis and storage. For text data, first remove the noise information, including advertisements, page navigation, comments, and other parts that are not related to security knowledge. Then, apply targeted cleaning strategies for different types of data. For example, for vulnerability information, remove duplicate vulnerability descriptions and resolved vulnerability records, unify the naming conventions of vulnerability types, clean up irrelevant fields, and ensure that the description of each vulnerability item is concise and clear. For attack samples, such as SQL injection or cross-site scripting code snippets, it is necessary to remove useless comments and formatting information, and standardize the code format for subsequent analysis. For traffic logs, remove irrelevant request and response content, extract key attack behavior features, such as IP, port, request path, attack parameters and other information, and unify the format to avoid unnecessary redundant data.
[0038] Another portion of the data is collected manually. For manually collected PDF e-books and thesis collections, OCR technology is needed to extract text information. First, PDF pages are converted into images using PDF2Image, and then text recognition is performed using the Tesseract OCR engine. To improve recognition accuracy, the image can be preprocessed, including steps such as denoising, binarization, and rotation correction. The extracted text may contain recognition errors, so post-processing is required to correct common errors, clean up redundant characters, and structure content such as paragraphs and titles. Finally, the cleaned text is saved in a standard format for subsequent storage and analysis.
[0039] 2. Security large model training
[0040] The security model training process of this invention consists of two main phases: incremental pre-training and supervised instruction fine-tuning. In the incremental pre-training phase, the base model is trained with a large amount of security domain data, thereby learning rich vertical domain knowledge and expanding its knowledge boundaries. In the supervised instruction fine-tuning phase, the model is trained using self-constructed instruction question-answer pairs, making the model's answers more vertical to the security domain and logically aligned with human responses.
[0041] After comparing the Qwen 7B model with other large open-source models (such as Llama3 and ChatGLM3), we found that, given similar parameter counts, the Qwen 7B model demonstrated superior performance. Therefore, we chose the Qwen 7B model as the base model for subsequent training. The entire training process was based on the LLama-Factory framework, using an A10 graphics card with 32GB of video memory.
[0042] During the incremental pre-training phase, model training takes a long time, with each training session requiring approximately 25 hours. With over 400,000 pieces of training data, the model undergoes approximately 10 rounds of incremental pre-training to ensure that the base model has sufficient knowledge in the security domain. After completing incremental pre-training, the supervised instruction fine-tuning phase, which involves training on 4,000 self-constructed question-answer pairs, takes approximately 13 hours. This data not only includes security-related instruction question-answer pairs but also intentionally incorporates 20% general knowledge. This design effectively prevents catastrophic forgetting and maintains the model's general knowledge beyond security domain knowledge.
[0043] The Lora training method is used for training large, secure models. This method significantly reduces the number of trainable parameters, lowers memory requirements, and improves both training and computational efficiency. The Lora training method also offers flexibility, enabling the storage of multiple small adapters for different tasks. This reduces the risk of overfitting and improves the model's generalization across multiple tasks.
[0044] 3. Construction of a secure intelligent entity
[0045] The core of this approach is the construction of a secure agent. Leveraging the agent-like nature of the large language model, the Dify AI integrated development platform, and custom tool components, this agent is constructed. The secure agent consists of four components: an underlying large model, a memory module, a planning module, and a tool module.
[0046] The underlying big model uses the security big model trained above. Compared to general-purpose big models, our model possesses deeper and richer security domain knowledge. It focuses on vertical applications in the security field and can provide more accurate and professional security-related services. Specifically, the model integration process involves first merging and formatting the trained big security model using the convert_hf_to_gguf.py script in the llama.cpp tool. Multiple safetytensors files are merged and converted into a single convert.bin file. Next, the convert.bin file is quantized using the llama-quantize quantization tool compiled from llama.cpp to produce quantized.bin. The Modelfile file is then compiled and integrated into Ollama using the create command in Ollama. Finally, Ollama is integrated into Dify.
[0047] In the tool module of the intelligent agent, three tool components are written by ourselves, namely RAG search enhancement generation tool, page analysis tool, and test case generation tool:
[0048] (1) RAG Retrieval Enhancement Generation Tool: This tool is mainly used to retrieve matching auxiliary information from the knowledge base based on user questions. It enhances the knowledge boundary of the large model without retraining the model or modifying the model parameters, so that the page analysis tool model can answer the cutting-edge knowledge of network security and the latest knowledge in the field. Specifically, the text data is segmented and vectorized and stored in the vector database. The semantic similarity is compared in the knowledge base based on the user question. The highly relevant content is recalled and re-ranked. Finally, the large model uses this part of the content as known auxiliary information and combines it with the user's own question to provide an answer.
[0049] (2) Page Analysis Tool: This tool is used to crawl the content of web pages and perform cleaning and filtering. Specifically, it first uses the requests library to crawl static page content, which is suitable for pages that do not rely on JavaScript rendering. If the target page needs to load content dynamically, the tool will switch to Selenium, which can simulate user operations and load dynamic content generated by JavaScript to ensure that the complete information of the page is captured. After the page content is crawled, the tool will use the lxml library to parse and clean the page, which provides faster parsing speed and more powerful XPath support. During the parsing process, the tool will clean up redundant advertisements, navigation bars, footers and other irrelevant content, retaining only key page information related to security.
[0050] (3) Test case generation tool: When a vulnerability that requires further verification is discovered, the agent will request the large model to generate the corresponding test case code. The agent will then call the test case generation tool to combine the URL provided by the user with the generated test case code. The splicing method mainly uses regular expressions to dynamically identify and locate potential injection points in the URL. By matching regular expressions, different types of injection points can be automatically identified, including query parameters, path parts, and even request headers. Then, the malicious payload will be inserted into the corresponding position based on the results of the regular expression matching, ultimately forming a complete and executable test case set to help security testers verify whether the vulnerability actually exists.
[0051] In the agent's planning module, a routing or question classifier is constructed. Its purpose is to treat user questions as classification tasks. By combining the large model's prompt word engineering with the agent's own characteristics, it dynamically plans an appropriate execution path and calls the corresponding tools to complete the task. In the design of this invention, the underlying implementation of the routing module relies on the large model's powerful reasoning capabilities. Through semantic understanding and contextual analysis of user input questions, combined with the designed prompt word engineering, the model is guided to make accurate judgments, ensuring that the optimal path is obtained for each question processing, thereby achieving efficient and accurate task execution.
[0052] The core model prompt words written by the present invention are as follows:
[0053]
[0054]
[0055] The agent's memory module is divided into long-term memory and short-term memory. Long-term memory is achieved by vectorizing and encoding text information and storing it in a vector database; short-term memory is achieved through memory storage, caching, and other methods. In this invention, long-term memory is used to assist in the execution of RAG retrieval and enhanced generation tasks, freeing up the time dependency of the model training process and enabling it to answer cutting-edge knowledge in the security field. Short-term memory improves the agent's short-term memory ability by temporarily storing information related to the current conversation, thereby enhancing the coherence and accuracy of the conversation.
[0056] The pseudo code of the model algorithm for this example is as follows:
[0057]
[0058]
[0059] The pseudocode is explained as follows:
[0060] The security agent determines the type of input question by selecting a route and employing different strategies to generate the appropriate answer. The core of its operation lies in accurately classifying questions and selecting the most appropriate processing flow based on their characteristics.
[0061] First, when the input question is classified as a common-sense question (including basic knowledge of network security), the intelligent body will directly reason and answer by calling the self-trained security big model. It is pre-trained on a large amount of security data and has the ability to handle common security issues while retaining the ability to answer general knowledge. Therefore, relying on the big model's own question-answering capabilities, it can quickly and accurately generate answers.
[0062] For cutting-edge cybersecurity questions, the agent employs a more complex process. In this case, it first uses the RAG retrieval-augmented generation tool to match and recall content with the highest similarity to the question from an external knowledge base as supplementary information. Finally, the larger model combines this supplementary information with reasoning about the original question to generate a more accurate answer, especially when faced with emerging security threats and complex technical contexts.
[0063] In the scenario of web zero-day vulnerability mining, the intelligent agent first extracts the URL from the query, crawls the corresponding page content through a page analysis tool, and performs content filtering. Finally, the cleaned page content is passed to the security model to analyze the page for potential security vulnerabilities and generate a corresponding vulnerability report. If a vulnerability is detected that requires further verification, the intelligent agent requests the model to generate test case code. It then calls the test case generation tool to combine the user-provided URL with the test case code to produce a complete and usable test case set. This process not only identifies potential security vulnerabilities on the page but also generates test cases for vulnerability verification, improving the efficiency and accuracy of security analysis.
[0064] Finally, for questions that cannot be classified, the agent returns a default message of "Cannot handle this question." This design ensures that the agent can provide clear feedback even when the input cannot be classified, avoiding situations where the agent does not respond or responds with incorrect answers due to hallucinations.
[0065] After testing, existing mainstream large language models, such as GPT-4 and GLM-4, are unable to directly perform vulnerability analysis on URLs provided by users. Figure 2 As shown, the security agent constructed based on the self-trained security big model of the present invention can effectively analyze vulnerabilities of Web pages and generate effective test cases, thereby efficiently mining Web 0Day vulnerabilities.
[0066] 4. Construction of Web Visualization Platform
[0067] This paper uses GRPC technology to build a high-performance, distributed, cross-language service architecture between security agents and web systems. First, the service and message formats are defined using Protocol Buffers (protobuf), the corresponding Python server and Java client code are generated, and the RPC API is exposed. Then, the defined RPC service is implemented on the Python side, and the GRPC server is started. On the Java side, client code is generated, a GRPC channel is created, and a connection is made to the server. Ultimately, through GRPC technology, the Java web front-end system can effectively call the security agent written in Python and interact with the user.
[0068] Then, VUE and Element-UI technologies are used to build a Web visualization framework, HTML5 and CSS are combined to complete the web page structure and style design, and JavaScript is used to realize dynamic interaction of Web services.
[0069] 5. Application of Web Visualization Platform
[0070] Based on the Web visualization platform, users can easily interact with security agents to detect and mine Web 0Day vulnerabilities. The page is analyzed based on the URL provided by the user, potential vulnerabilities are identified, and corresponding test cases are generated on demand based on the analysis results. In addition, the Web platform also provides a test case verification function, which can batch verify the effectiveness of test cases and present the detection results in a visual way, that is, the rendering status of the page after sending the test case. The overall process is as follows: Figure 3 shown.
[0071] The above shows and describes the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The above embodiments and descriptions are merely preferred examples of the present invention and are not intended to limit the present invention. Various changes and improvements may be made to the present invention without departing from the spirit and scope of the present invention. Such changes and improvements fall within the scope of the present invention. The scope of protection claimed in the present invention is defined by the appended claims and their equivalents.
Claims
1. A Web 0Day vulnerability detection and mining method based on security intelligence, characterized in that: The following steps are involved: S1. Collection and preprocessing of massive network security related data; S2. Train a large security model in a vertical network security field; S3. With the aforementioned security big model as the core, combined with the customized memory module, tool module, and planning module, a security agent is constructed using the agent characteristics of the big model itself; In step S3, the construction of the security agent is based on the Dify framework, and the security agent includes: The underlying big model uses the aforementioned security big model to provide professional security decision support; The memory module consists of long-term memory and short-term memory. The long-term memory is used to assist in executing the RAG retrieval enhancement generation task, freeing the model from time dependencies during training and enabling it to answer cutting-edge knowledge in the security field. The short-term memory is used to temporarily store information related to the current conversation. The planning module is responsible for converting user security questions into classification tasks. By understanding the semantics and context of user input questions, combined with designed prompt word engineering, it guides the model to make accurate judgments, ensuring the optimal path for each problem handling. The tool module includes a page analysis tool, a test case generation tool, and a RAG search enhancement generation tool. These tools are used to assist in analyzing security vulnerabilities in web pages, generate vulnerability test cases, and extract the latest security information from external literature and databases. This enhances the knowledge base of large models and improves the accuracy and comprehensiveness of vulnerability detection and mining. S4. Based on cross-language integration and front-end visualization technology, a web visualization platform is built in combination with security intelligence. S5. Based on the Web visualization platform, implement vulnerability analysis of Web page content, generation and effect verification of vulnerability test cases, and visual display of security professional knowledge questions and answers.
2. The method for detecting and mining Web 0Day vulnerabilities based on security agents according to claim 1, characterized in that: In step S1, the collection of massive network security related data includes two parts: first, using the Scrapy framework to crawl network security related data from search engines and open source libraries; The second is to obtain e-books and paper collections in the field of network security through manual collection.
3. The method for detecting and mining Web 0Day vulnerabilities based on security agents according to claim 1, characterized in that: In step S1, the preprocessing includes formatting the crawled data into a structured format, removing irrelevant noise information, and cleaning up duplicate, useless or redundant data according to the data type; extracting text from manually collected PDF documents using OCR technology, improving accuracy through image preprocessing and recognition correction, and finally structuring the text and saving it in a standard format.
4. The method for detecting and mining Web 0Day vulnerabilities based on security agents according to claim 1, characterized in that: In step S2, based on the LLama-Factory framework and taking Qwen 7B as the base model, 10 rounds of incremental pre-training are performed using 400,000 pieces of web vulnerability security data, and supervised instruction fine-tuning is performed using 4,000 self-built question-answer pairs to obtain a large security model in the vertical network security field.
5. The method for detecting and mining Web 0Day vulnerabilities based on security agents according to claim 4, characterized in that: The training process of step S2 includes an incremental pre-training stage and a supervised instruction fine-tuning stage; in the incremental pre-training stage, the base model is trained with a large amount of data from the security field, thereby learning rich vertical field knowledge and expanding its knowledge boundaries; in the supervised instruction fine-tuning stage, the model is trained with self-constructed instruction question-answer pairs, so that the model's answers are more vertical to the security field and aligned with the human answer logic, and finally a large security model in the vertical network security field is obtained.
6. The method for detecting and mining Web 0Day vulnerabilities based on security agents according to claim 1, characterized in that: In step S4, cross-language integration technology is used to call a Python-based security agent on a Java-based Web platform, and GRPC technology is used to build a high-performance, distributed, cross-language service architecture between the security agent and the Web system; the front-end visualization technology uses VUE and Element-UI to build a Web visualization framework, combines HTML5 and CSS to design the web page structure and style, and uses JavaScript to achieve dynamic interaction, supporting vulnerability analysis, test case generation and verification, and visual display of security knowledge questions and answers.
7. A Web 0Day vulnerability detection and mining platform based on security intelligence, characterized by: Web 0Day vulnerability detection and mining is achieved by using the security agent-based Web 0Day vulnerability detection and mining method according to any one of claims 1 to 6.