Network security situation analysis method and device based on multi-agent cooperation
By building a multi-agent collaborative architecture, combining dynamic rank learning LoRA algorithm and natural language rule library, the problems of detection response lag and insufficient context correlation in the existing network security situation analysis methods are solved, and rapid response and accurate evaluation of unknown attacks are achieved.
Patent Information
- Application Number
- CN202510402794.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-01
- Publication Date
- 2025-07-04
AI Technical Summary
The existing network security situation analysis methods have lag in detection responses when facing new or unknown attacks, making it difficult to perceive unknown attacks in real time, and lack contextual correlation judgments for complex attack scenarios, resulting in low efficiency in security policy adjustment.
Using a network security situation analysis method based on multi-agent collaboration, through the construction of an agent architecture, combining dynamic rank learning LoRA algorithm and natural language rule database, the commander agent coordinates the staff agent and simulated Blue Army agent for reflection, questioning and debate, and generates multi-dimensional network security situation evaluation results and trend predictions.
It significantly improves the accuracy and prediction reliability of network security situation analysis, can quickly respond to unknown attacks, and provides comprehensive and timely security policy adjustments.
Smart Images

Figure CN120263466A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology. Specifically, it relates to a network security situation analysis method and device based on multi-agent collaboration. Background Art
[0002] Existing network security situation analysis methods mainly construct a rule base based on expert experience and historical attack data, and identify threats by matching known attack features. However, this method has the following technical defects: First, in the face of new or unknown attack behaviors, it is necessary to spend a lot of time collecting attack sample data and rely on experts to manually extract features to update the rule base, resulting in a lag in detection response and difficulty in discovering and blocking emerging attacks in a timely manner; Second, existing technologies mostly focus on the surface features of attack means (such as malicious code signatures, traffic anomalies, etc.), lacking in-depth correlation analysis of attackers and behavior chain logic, resulting in insufficient judgment of the context relevance of complex attack scenarios, and difficulty in accurately evaluating the potential harm level and evolution trend of attack behaviors, thereby affecting the dynamic adjustment efficiency of security policies.
[0003] Therefore, there is an urgent need for an intelligent analysis method that can real-time perceive unknown attacks and model in combination with attack intentions to improve the comprehensiveness and timeliness of network security situation analysis. Summary of the Invention
[0004] The purpose of this application is to provide a network security situation analysis method and device based on multi-agent collaboration to solve the problems of difficult to balance generality and domain adaptability and insufficient analysis of complex attack intentions in traditional methods through the combination of dynamic LoRA fine-tuning and multi-agent debate mechanism.
[0005] The purpose of this application is achieved through the following technical solutions:
[0006] In the first aspect, this application proposes a network security situation analysis method based on multi-agent collaboration, and the method includes:
[0007] Construct an intelligent agent architecture and routing for network security situation assessment and analysis based on an open-source large language model;
[0008] Based on the intelligent agent architecture and routing, define the roles of each intelligent agent in the intelligent agent architecture in combination with Prompt prompt words, and specify the communication format of the intelligent agents;
[0009] Fine-tune each intelligent agent in the intelligent agent architecture using the dynamic rank learning LoRA algorithm based on the open-source large model;
[0010] Based on the natural language rule base, the commander agent coordinates the staff agent and the simulated blue army agent, and conducts multi-dimensional analysis through reflection, questioning and debate mechanisms to generate network security situation assessment results and trend predictions.
[0011] In a possible implementation, the agent architecture includes a commander agent, a staff agent, a simulated blue army agent, and multiple data analysis agents;
[0012] The commander agent is used to conduct an overall assessment of the current network security situation based on the analysis results;
[0013] The staff agent is used to analyze the attack means, attack methods, attack organizations, and attack purposes of the attacker based on the raw data to obtain analysis results;
[0014] The simulated blue army agent is used to analyze the attack intention and the next attack target of the attacker from the perspective of the attacker based on the raw data to obtain analysis results;
[0015] The data analysis agent is used to extract and conduct preliminary analysis on the raw data based on the API interface, and send the raw data to the staff agent and the simulated blue army agent.
[0016] In a possible implementation, the data analysis agent is constructed based on the data type and analysis intention, and includes a traffic analysis agent, a network security alert analysis agent, a log analysis agent, and a threat intelligence analysis agent.
[0017] In a possible implementation, the communication format of the agent is a JSON structure, including a task name, an analysis target, a title, an information summary, a subject word, a keyword, and a context information ID, where the context information ID is used to associate historical interaction data.
[0018] In a possible implementation, the dynamic rank learning LoRA algorithm is as follows:
[0019] The input text after Token extraction is sent into a shallow neural network to obtain a rank weight vector;
[0020] The Token is input into multiple preset LoRA matrices to obtain a fusion matrix;
[0021] Based on the fusion matrix and the rank weight vector, dynamic weighted fusion is performed to obtain the total parameter update amount;
[0022] The total parameter update amount is superimposed on the original model weight to obtain the updated weight.
[0023] In a possible implementation, the output h of the open-source large model is composed of the superposition of the original weight and the dynamically weighted LoRA increment, satisfying: W is the original weight, x is the input, p i is the rank weight vector, B i A i is the LoRA matrix, and n is the total number of LoRA matrices.
[0024] In a possible implementation manner, based on the natural language rule base, using the commander agent to coordinate the staff agent and the simulated blue army agent, and performing multi-dimensional analysis through the reflection, questioning and debate mechanisms to generate the network security situation assessment result and trend prediction, the steps include:
[0025] Based on the natural language rule base, use the commander agent to extract matching analysis rules from the natural language rule base according to the analysis target;
[0026] Use the commander agent to send data request instructions to the staff agent and the simulated blue army agent based on the rules, requiring the provision of attack means analysis results, attack intention hypotheses and associated context data;
[0027] Verify the data validity through a multi-round interaction mechanism;
[0028] Through the commander agent, fuse multi-party data and debate conclusions, combine with the evaluation template in the natural language rules to generate a network security situation assessment report, and predict future threat trends based on historical attack pattern matching.
[0029] In a second aspect, the present application proposes a network security situation analysis device based on multi-agent collaboration, and the device includes:
[0030] A construction module for constructing an intelligent agent architecture and routing for network security situation assessment analysis based on an open-source large language model;
[0031] A role definition module for defining the roles of each intelligent agent in the intelligent agent architecture based on the intelligent agent architecture and routing, in combination with Prompt prompts, and specifying the communication format of the intelligent agents;
[0032] A fine-tuning module for fine-tuning each intelligent agent in the intelligent agent architecture using the dynamic rank learning LoRA algorithm based on the open-source large model;
[0033] A generation module for generating a network security situation assessment result and trend prediction through multi-dimensional analysis based on the natural language rule base, using the commander agent to coordinate the staff agent and the simulated blue army agent, through the reflection, questioning and debate mechanisms.
[0034] In a third aspect, the present application also proposes a computer device, which includes a processor and a memory. A computer program is stored in the memory, and the computer program is loaded and executed by the processor to implement the network security situation analysis method according to any one of the first aspects.
[0035] In a fourth aspect, the present application also proposes a computer-readable storage medium. A computer program is stored in the storage medium, and the computer program is loaded and executed by a processor to implement the network security situation analysis method according to any one of the first aspects.
[0036] The main solution of the present application and its various further alternative solutions can be freely combined to form multiple solutions, all of which are solutions that can be adopted and claimed by the present application; and in the present application, (each non-conflicting alternative) alternatives can be freely combined with each other and with other alternatives. Those skilled in the art can understand that there are various combinations according to the prior art and common general knowledge after understanding the solution of the present application, all of which are technical solutions to be protected by the present application, and will not be enumerated here.
[0037] The present application discloses a network security situation analysis method and device based on multi-agent collaboration. First, an intelligent agent architecture and routing for network security situation assessment and analysis are constructed based on an open-source large language model. The roles of each intelligent agent in the intelligent agent architecture are defined in combination with Prompt prompts, and the communication format of the intelligent agents is specified. The dynamic rank learning LoRA algorithm is used to fine-tune each intelligent agent in the intelligent agent architecture based on domain knowledge. Based on the natural language rule library, the commander intelligent agent coordinates the staff intelligent agent and the simulated blue army intelligent agent, and performs multi-dimensional analysis through reflection, questioning, and debate mechanisms to generate network security situation assessment results and trend predictions. By combining dynamic LoRA fine-tuning and the multi-agent debate mechanism, the problems of difficulty in balancing generality and domain adaptability and insufficient analysis of complex attack intentions in traditional methods are solved, and the accuracy and prediction reliability of network security situation assessment are significantly improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] To more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings required for the embodiments. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.
[0039] Figure 1 The flowchart shows a network security situation analysis method based on multi-agent collaboration proposed by an embodiment of the present application.
[0040] Figure 2Shows a schematic diagram of the agent architecture proposed in the embodiments of the present application.
[0041] Figure 3 Shows a schematic diagram of the agent routing proposed in the embodiments of the present application.
[0042] Figure 4 Shows the model architecture diagram proposed in the embodiments of the present application.
[0043] Figure 5 Shows a flowchart of a text processing and feature extraction proposed in the embodiments of the present application.
[0044] Figure 6 Shows a schematic flowchart of the multi-dimensional analysis method proposed in the embodiments of the present application. Detailed implementation manners
[0045] The following uses specific specific examples to illustrate the implementation manners of the present application. Those skilled in the art can easily understand other advantages and effects of the present application from the content disclosed in this specification. The present application can also be implemented or applied through other different specific implementation manners. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present application. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other.
[0046] Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without making creative efforts fall within the scope of protection of the present application.
[0047] In the prior art, existing network security situation analysis methods usually rely on expert knowledge and experience. When new or unknown attacks occur, it takes a certain amount of time to accumulate attack data. At the same time, it is also time-consuming for experts to summarize experience specifications and update the rule base, resulting in the inability to quickly monitor new / unknown attack behaviors. In addition, most existing analysis methods only start from the attack means and methods themselves without considering the attacker's intention, which may lead to incomplete analysis conclusions.
[0048] Therefore, to solve the above technical problems, the embodiments of the present application propose a network security situation analysis method and device based on multi-agent collaboration, which can make full use of the intelligent analysis capabilities provided by large language models and consider the constraints of computing power costs. Based on natural language rules, through reflection, questioning and debate, and combined with the analysis of the attacker's intention, an effective evaluation and analysis of the current network security situation can be carried out.
[0049] Please refer to Figure 1 , Figure 1 Shows a schematic flowchart of a network security situation analysis method based on multi-agent collaboration proposed in the embodiments of the present application. The method includes:
[0050] Step S1: Build an agent architecture and routing for network security situation assessment and analysis based on an open-source large language model.
[0051] Figure 2 FIG. shows a schematic diagram of the agent architecture proposed in an embodiment of the present application, including data analysis agents (traffic analysis, log analysis, security alert analysis, and threat intelligence analysis), staff agents (such as staff agents A, B, etc.), a commander agent, and a simulated blue army agent. These agents together constitute a complete network security assessment and analysis system, and achieve a comprehensive assessment and analysis of network security through collaborative work. Based on an open-source large language model, an agent architecture is built for network security situation assessment and analysis, including a commander agent, staff agents, a simulated blue army agent, and multiple data analysis agents. These agents work together through specific data streams and routing: the data analysis agents are responsible for extracting and initially analyzing raw data from different data sources, and passing the results to the staff agents and the simulated blue army agent; the staff agents deeply analyze the attack means, methods, organizations, and purposes, while the simulated blue army agent predicts the intentions and targets from the perspective of the attacker; finally, the commander agent integrates all the analysis results to generate a comprehensive network security situation assessment report. The entire process utilizes the powerful natural language processing ability of the open-source large language model, combined with domain-specific fine-tuning, to achieve efficient and accurate network security situation assessment and analysis.
[0052] The agent architecture includes a commander agent, staff agents, a simulated blue army agent, and multiple data analysis agents;
[0053] The commander agent is used to conduct an overall assessment of the current network security situation based on the analysis results;
[0054] The staff agent is used to analyze the attack means, attack methods, attack organizations, and attack purposes of the attacker based on the raw data to obtain analysis results;
[0055] The simulated blue army agent is used to analyze the attack intentions and next attack targets of the attacker from the perspective of the attacker based on the raw data to obtain analysis results;
[0056] The data analysis agent is used to extract and initially analyze the raw data based on the API interface, and send the raw data to the staff agent and the simulated blue army agent.
[0057] The commander agent receives and integrates the analysis results from the staff agent and the simulated blue army agent, completes the overall assessment of the current network security situation, inputs the analysis results from the staff agent and the simulated blue army agent, and outputs an overall network security situation assessment report.
[0058] Based on the raw data provided by the data analysis agent, the staff agent conducts in-depth analysis on the attack means, methods, organizations, and purposes of the attacker, and sends the analysis results to the commander agent. Its input is the raw data from the data analysis agent, and the output is the detailed analysis results regarding the attack means, methods, organizations, and purposes.
[0059] From the perspective of the attacker, the simulated blue army agent predicts and analyzes the attacker's intentions and next attack targets based on the raw data provided by the data analysis agent. The input is the raw data from the data analysis agent, and the output is the predicted attacker's intentions and possible next attack targets.
[0060] The data analysis agent extracts various types of raw data through the API interface, and conducts preliminary processing and analysis according to different data types and analysis intentions. Then it sends this raw data to the staff agent and the simulated blue army agent. The input is the raw data obtained through the API interface, and the output is the preliminarily processed raw data for further analysis.
[0061] The data analysis agent obtains raw data through the API interface and conducts preliminary processing and analysis. The data analysis agent sends the preliminarily processed raw data to the staff agent and the simulated blue army agent. The staff agent analyzes the attacker's means, methods, organizations, and purposes based on the received data, and the simulated blue army agent analyzes the attack intentions and next attack targets from the perspective of the attacker. The commander agent integrates the analysis results of the staff agent and the simulated blue army agent to generate an overall network security situation assessment report.
[0062] The data analysis agent is constructed based on data types and analysis intentions, including the traffic analysis agent, network security alert analysis agent, log analysis agent, and threat intelligence analysis agent.
[0063] The traffic analysis agent is responsible for analyzing network traffic data, detecting abnormal traffic patterns and potential security threats. The network security alert analysis agent analyzes the security alerts generated by the system to judge their severity and authenticity. The log analysis agent analyzes the log files of the system and applications to find abnormal activities and potential security incidents. The threat intelligence analysis agent collects, processes, and analyzes threat intelligence data to identify current and potential threats.
[0064] Secondly, plan the routing between agents. The routing between agents stipulates the data flow direction between agents. Figure 3The figure shows a schematic diagram of agent routing proposed in the embodiments of the present application. The data sources are traffic analysis agents, log analysis agents, security alert analysis agents, and threat intelligence analysis agents. Staff agent A retrieves data on demand through API calls, conducts reflection and questioning. Staff agent B also retrieves data on demand through API calls, conducts reflection and questioning. The simulated blue army agent B retrieves data on demand through API calls, conducts debates, attacks, and analyzes the intentions of the other party. The commander agent gives an analysis result based on the natural language processing rule library. Data is transmitted from each agent to staff agent A, staff agent B, and the simulated blue army agent B through API calls. After these staff agents and the simulated blue army agent conduct analysis, they transmit the results to the commander agent, and finally a comprehensive analysis result is given.
[0065] Step S2: Based on the agent architecture and routing, combined with Prompt prompts, define the roles of each agent in the agent architecture and stipulate the communication format of the agents.
[0066] The communication format of the agent is a JSON structure, including task name, analysis target, title, information summary, subject words, keywords, and context information ID, where the context information ID is used to associate historical interaction data.
[0067] Preset the functions and roles of the agents through system Prompt prompts, and standardize the definition of the communication format between the agents to avoid loss of key information. The Prompt prompt format is as follows:
[0068] {
[0069] SystemPrompt: Role, function definition, and communication format definition;
[0070] }
[0071] Taking the commander agent as an example, its prompt is as follows:
[0072] SystemPrompt: You are an excellent commander. Please analyze the current network security situation based on the analysis results provided by the staff and the data provided by the simulated blue army. At the same time, the output content should meet the format requirements.
[0073] The analysis rules are as follows:
[0074] Conduct evaluation and analysis by referring to the methods provided in the rule library;
[0075] Communicate with the staff when necessary and ask questions about the doubtful points;
[0076] Conduct multiple rounds of debates with the simulated blue army when necessary to analyze the actual attack intentions of the attacker.
[0077] The output content should meet the following JSON format definition:
[0078] {
[0079] Task Name: The task name is used to distinguish different tasks;
[0080] Analysis Target: The analysis target specified by the user, provided by the commander agent;
[0081] Title: The message title;
[0082] Message Summary: The content summary;
[0083] Subject: Subject Term 1, Subject Term 2;
[0084] Keywords: Keyword 1, Keyword 2;
[0085] Associated Words: Associated Word 1, Associated Word 2;
[0086] Context Information: Context Information 1, Context Information 2;
[0087] Context Information ID: messageId1,messageId2;
[0088] }
[0089] It should be noted that in this method, through the fine-grained characterization of information, it is possible to provide multi-dimensional effective data for the analysis of the agent, and it can provide direction guidance for the agent's thinking to avoid unnecessary hallucinations of the agent.
[0090] Step S3: Fine-tune each agent in the agent architecture using the dynamic rank learning LoRA algorithm based on the open-source large model.
[0091] When fine-tuning each agent in the agent architecture using the dynamic rank learning LoRA algorithm based on the open-source large model, more efficient personalized adjustment can be achieved through its multi-granularity parameter adaptation ability. This method pre-sets LoRA matrices with different ranks for each agent, and analyzes the input task type and complexity in real time through the dynamic weight vector to automatically activate the matching rank module.
[0092] The dynamic rank learning LoRA algorithm is as follows:
[0093] Send the Token-extracted input text into the shallow neural network to obtain the rank weight vector;
[0094] Send the Token into multiple pre-set LoRA matrices to obtain the fusion matrix;
[0095] Perform dynamic weighted fusion based on the fusion matrix and the rank weight vector to obtain the total parameter update amount;
[0096] The total parameter update amount is superimposed on the original model weights to obtain the updated weights.
[0097] Figure 4 The figure shows the model architecture diagram proposed in the embodiments of the present application. The input layer inputs data X, whose dimension is d-dimensional. The pre-trained weight W (d*d dimensional) represents a d x d matrix, which is frozen and does not participate in the subsequent training process. The shallow neural network has three layers, and the final output is composed of each branch network. Dynamic Rank Adaptation (LoRA) is an efficient fine-tuning method for large models. By dynamically adjusting the rank of the LoRA matrix, it realizes the adaptive processing of problems with different complexities. For simple problems, a small-rank matrix is used, and for complex problems, a large-rank matrix is used. The rank weight vector p is generated through the shallow neural network. i Fuse LoRA matrices with different ranks to balance model performance and computational efficiency.
[0098] Figure 5 The figure shows a flowchart of text processing and feature extraction proposed in the embodiments of the present application. First, the system receives the original text input and performs word segmentation on it to convert the text into a series of tokens. A shallow neural network is used to extract features from these tokens, and a rank weight classifier is used to calculate the importance of each feature. Among them, the Tokenized text sequence is input into a 3-layer fully connected shallow neural network (input dimension = Token dimension, output dimension = number of LoRA groups), and a rank weight vector is output (taking 3 groups as an example, p = [p1, p2, p3]). Then, multiple groups of LoRA matrices are predefined (taking 3 groups as an example, namely A1B1, A2B2, A3B3, with ranks r1, r2, r3 respectively, where r1 is smaller, r2 is medium, and r3 is larger. r1 has a smaller parameter space and is mainly applicable to simple problems; r3 has a larger parameter space and can be used to solve complex problems). The LoRA matrices with different ranks are fused according to the rank weight vector (p i ) to generate the parameter update amount delta W = p1A1B1 + p2A2B2 + p3A3B3, and the increment is superimposed on the original model weights: Wn = Wn-1 + delta_W. Finally, the model output is jointly determined by the original weights and the dynamic LoRA increment. The output h of the open-source large model is composed of the superposition of the original weights and the dynamically weighted LoRA increment, satisfying: W is the original weight, x is the input, p i is the rank weight vector, B i A i is the LoRA matrix, and n is the total number of LoRA matrices.
[0099] Compared with the conventional LoRA algorithm, the innovation of this algorithm lies in controlling the size of the parameter space to be adjusted by the rank. For simple problems, a smaller rank is adopted, and for complex problems, a larger rank is adopted. This method can not only effectively improve the domain knowledge of the intelligent agent, but also maintain the general analysis ability of the intelligent agent as much as possible.
[0100] Step S4: Based on the natural language rule base, use the commander intelligent agent to coordinate the staff intelligent agent and the simulated blue army intelligent agent, and conduct multi-dimensional analysis through the reflection, questioning and debate mechanisms to generate the network security situation assessment result and trend prediction.
[0101] In the network security situation assessment method based on the natural language rule base, the commander intelligent agent, as the core coordinator, first extracts the rules matching the current target from the rule base, and then issues data request instructions to the staff intelligent agent and the simulated blue army intelligent agent respectively, requiring them to provide reverse parsing of attack means, attack intention assumptions and associated context data; through multiple rounds of reflection-questioning-debate mechanisms, dynamically verify the data reliability and eliminate the analysis blind spots; finally, the commander intelligent agent fuses the data verified by multiple parties, combines the evaluation template in the rule base to generate an evaluation report including the current threat level, attack stage deduction and vulnerability distribution, and predicts the possible future attack paths and defense priorities based on the historical attack patterns, realizing the closed-loop analysis from multi-dimensional dynamic data to executable security policies.
[0102] Step S4 includes:
[0103] Based on the natural language rule base, use the commander intelligent agent to extract the matching analysis rules from the natural language rule base according to the analysis target;
[0104] Use the commander intelligent agent to send data request instructions to the staff intelligent agent and the simulated blue army intelligent agent based on the rules, requiring them to provide the analysis results of attack means, attack intention assumptions and associated context data;
[0105] Verify the data validity through multiple rounds of interaction mechanisms;
[0106] Through the commander intelligent agent, fuse the data and debate conclusions from multiple parties, combine the evaluation template in the natural language rules to generate a network security situation assessment report, and predict the future threat trends based on the historical attack pattern matching.
[0107] The commander intelligent agent screens the natural language rule base according to the current analysis target (such as attack traceability, risk assessment), and the key indicators extracted include abnormal traffic patterns, alarm correlation, threat intelligence confidence, etc., and adopts a logical template. The commander intelligent agent requests from the staff intelligent agent, including attack means analysis and context data.
[0108] Based on the analysis target and the applicable scope of natural language rules, the commander agent retrieves relevant analysis rules from the natural language rule library. Then, according to the key indicators, reference illustrations, and thinking processes defined in the analysis rules, it requests the staff agent and the simulated blue army agent to provide relevant analysis data. It deeply analyzes and thinks about the data provided by the staff agent and the simulated blue army agent, and conducts reflections (for example, the commander agent will reflect on whether the data provided by the staff agent is sufficient and request the staff agent to provide multiple different analysis results), follow-up questions (for example, asking the staff agent to supplement context-related data), and debates (for example, discussing with the simulated blue army agent about the attacker's intention and the possible impacts of the attack and trying to reach an agreement as much as possible) with the staff agent and the simulated blue army agent according to the thinking process prompted in the natural language rules. In addition, the commander agent comprehensively analyzes and evaluates the analysis results of each natural language analysis rule and outputs the analysis results. It can effectively evaluate the current overall network security situation and future development trends based on data such as network traffic, network security alerts, device logs, and threat intelligence.
[0109] Based on the above, Figure 6 The flowchart of the multi-dimensional analysis method proposed in the embodiment of the present application is shown. The evaluation analysis target represents the target or purpose of the evaluation. The commander agent is responsible for commanding and coordinating subsequent steps. The natural language rule library is a database containing natural language processing rules for processing and understanding natural language inputs. Each natural language rule includes: thinking process, key indicators, applicable scope, and reference examples. Requesting the staff agent and the simulated blue army agent to provide relevant analysis results involves multiple agents, and the analysis results are provided according to the above rules. The finally output analysis results are optimized through multiple rounds of iteration (including reflection, follow-up question, debate, and attacker intention analysis). Reflection, follow-up question, debate, and attacker intention analysis are feedback loops for optimizing the output results, and the analysis results are improved by continuously reflecting, asking follow-up questions, debating, and analyzing the attacker's intention.
[0110] Compared with the prior art, the embodiment of the present application has the following beneficial effects:
[0111] First, a complete multi-agent collaboration architecture is constructed, including a commander agent, a staff agent, a simulated blue army agent, and a data analysis agent, and a standardized communication object is realized by stipulating the routing between agents.
[0112] Second, comprehensive analysis is carried out from multiple angles such as attack methods, attack means, and the blue side's attack intention. The results are more accurate and comprehensive. The analysis process is described in fine granularity, effectively reducing the probability of agents generating hallucinations and improving the evaluation quality.
[0113] Third, an intelligent agent interaction protocol and format are defined, which require providing content such as information summaries, topics, keywords, and context, thereby reducing the loss of key information and ensuring efficient information exchange among multiple intelligent agents.
[0114] Fourth, it supports the rapid expansion of new data sources. Only by fine-tuning can new data analysis intelligent agents be integrated into the overall analysis system to meet the needs of diverse scenarios.
[0115] Fifth, a network security situation assessment method based on natural language rules and mechanisms of reflection, questioning, and debate is proposed. The LoRA (Low-Rank Adaptation) algorithm of dynamic rank learning is used to fine-tune the intelligent agents' domain knowledge. While ensuring general capabilities, it enhances domain analysis capabilities. The analysis method based on natural language rules has better generalization and adaptability than traditional indicator-dependent methods and can capture unknown attacks more effectively. The commander intelligent agent collaborates with the staff intelligent agent and the simulated blue army intelligent agent to deeply analyze problems from different perspectives and improve the reliability of conclusions.
[0116] The following presents a possible implementation of a network security situation analysis device based on multi-agent collaboration, which is used to execute each execution step and corresponding technical effects of the network security situation analysis method shown in the above embodiments and possible implementations. The device includes:
[0117] A construction module for constructing the intelligent agent architecture and routing for network security situation assessment analysis based on an open-source large language model.
[0118] A role definition module for defining the roles of each intelligent agent in the intelligent agent architecture based on the intelligent agent architecture and routing, in combination with Prompt prompts, and specifying the communication format of the intelligent agents.
[0119] A fine-tuning module for fine-tuning each intelligent agent in the intelligent agent architecture using the LoRA algorithm of dynamic rank learning based on an open-source large model.
[0120] A generation module for generating network security situation assessment results and trend predictions through multi-dimensional analysis using the commander intelligent agent to coordinate the staff intelligent agent and the simulated blue army intelligent agent based on a natural language rule base through mechanisms of reflection, questioning, and debate.
[0121] This preferred embodiment provides a computer device that can implement the steps in any of the embodiments of the network security situation analysis method provided in this application. Therefore, it can achieve the beneficial effects of the network security situation analysis method provided in this application. For details, refer to the previous embodiments and will not be elaborated here.
[0122] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructions or by controlling related hardware through instructions. These instructions can be stored in a computer-readable storage medium and loaded and executed by a processor. For this purpose, the embodiments of the present application provide a storage medium, which stores multiple instructions that can be loaded by a processor to execute the steps of any one of the network security situation analysis methods provided by the embodiments of the present application.
[0123] Among them, the storage medium may include: read-only memory (ROM, Read Only Memory), random access memory (RAM, Random Access Memory), magnetic disk or optical disk, etc.
[0124] Since the instructions stored in the storage medium can execute the steps of any one of the network security situation analysis method embodiments provided by the embodiments of the present application, the beneficial effects achievable by any one of the network security situation analysis methods provided by the embodiments of the present application can be realized. For details, see the previous embodiments and will not be elaborated here.
[0125] The above are only the preferred embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A network security situation analysis method based on multi-agent collaboration, characterized in that The method includes: Constructing an agent architecture and routing for network security situation assessment and analysis based on an open-source large language model; Based on the agent architecture and routing, defining the roles of each agent in the agent architecture by combining Prompt prompts and specifying the communication format of the agents; Fine-tuning each agent in the agent architecture using the dynamic rank learning LoRA algorithm based on an open-source large model; Based on the natural language rule base, using the commander agent to coordinate the staff agent and the simulated blue army agent, and performing multi-dimensional analysis through reflection, questioning, and debate mechanisms to generate network security situation assessment results and trend predictions.
2. The network security situation analysis method according to claim 1, wherein The agent architecture includes a commander agent, a staff agent, a simulated blue army agent, and multiple data analysis agents; The commander agent is used to conduct an overall assessment of the current network security situation based on the analysis results; The staff agent is used to analyze the attack means, attack methods, attack organizations, and attack purposes of the attacker based on the original data to obtain analysis results; The simulated blue army agent is used to analyze the attack intention and the next attack target of the attacker from the perspective of the attacker based on the original data to obtain analysis results; The data analysis agent is used to extract and perform preliminary analysis on the original data based on the API interface, and send the original data to the staff agent and the simulated blue army agent.
3. The network security situation analysis method according to claim 2, characterized in that, The data analysis agent is constructed based on the data type and analysis intention, and includes a traffic analysis agent, a network security alert analysis agent, a log analysis agent, and a threat intelligence analysis agent.
4. The network security situation analysis method according to claim 1, characterized in that, The communication format of the agent is a JSON structure, including a task name, an analysis target, a title, an information summary, subject words, keywords, and a context information ID, where the context information ID is used to associate historical interaction data.
5. The network security situation analysis method according to claim 1, wherein The dynamic rank learning LoRA algorithm is as follows: Sending the input text after Token extraction into a shallow neural network to obtain a rank weight vector; Inputting the Token into multiple pre-set LoRA matrices to obtain a fusion matrix; Performing dynamic weighted fusion based on the fusion matrix and the rank weight vector to obtain a total parameter update amount; Adding the total parameter update amount to the original model weight to obtain the updated weight.
6. The network security situation analysis method according to claim 1, characterized in that The output h of the open-source large model is composed of the superposition of the original weights and the LoRA increments after dynamic weighting, satisfying: W is the original weight, x is the input, p i is the rank weight vector, B i A i is the LoRA matrix, and n is the total number of LoRA matrices.
7. The network security situation analysis method according to claim 1, characterized in that, The steps of using the commander agent to coordinate the staff agent and the simulated blue army agent based on the natural language rule base, and performing multi-dimensional analysis through reflection, questioning, and debate mechanisms to generate network security situation assessment results and trend predictions include: Using the commander agent to extract matching analysis rules from the natural language rule base based on the analysis target; Using the commander agent to send data request instructions to the staff agent and the simulated blue army agent based on the rules, requesting the provision of attack means analysis results, attack intention hypotheses, and associated context data; Verifying the data validity through a multi-round interaction mechanism; Through the commander agent, fusing multi-party data and debate conclusions, combining with the evaluation template in the natural language rule to generate a network security situation assessment report, and predicting future threat trends based on historical attack pattern matching.
8. A network security situation analysis device based on multi-agent collaboration, characterized in that, The device includes: A building block for constructing an agent architecture and routing for network security situation assessment and analysis based on an open-source large language model; A role definition module for defining the roles of each agent in the agent architecture based on the agent architecture and routing, in combination with Prompt prompts, and specifying the communication format of the agents; A fine-tuning module for fine-tuning each agent in the agent architecture using the dynamic rank learning LoRA algorithm based on an open-source large model; A generation module for generating network security situation assessment results and trend predictions through multi-dimensional analysis using the commander agent to coordinate the staff agent and the simulated blue army agent based on a natural language rule base through reflection, questioning, and debate mechanisms.
9. A computer device, characterized in that, The computer device includes a processor and a memory, and a computer program is stored in the memory. The computer program is loaded and executed by the processor to implement the network security situation analysis method according to any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, A computer program is stored in the storage medium. The computer program is loaded and executed by a processor to implement the network security situation analysis method according to any one of claims 1-7.
Citation Information
Cited By
Industrial anomaly detection method based on multi-agent prompt learning
CN120852894A
Multi-agent driven safety alarm log simulation generation method
CN121098738A
Log auditing technology based on multi-agent cooperation and implementation framework thereof
CN121239492A
Network security automatic decision-making method and system based on multi-agent collaboration
CN121509033A
Enterprise side situation awareness method based on AI Agent distributed dynamic data processing
CN122339864A