Broadcasting and television network security operation method and system based on large model

Through the large-model-based radio and television network security operation method, multi-source heterogeneous data is collected in real time and noise is filtered. Combined with the RAG knowledge base and multi-model MOE architecture, the problems of insufficient data processing capabilities and lagging detection methods in the radio and television network are solved, and efficient threat analysis and global threat perception are achieved, thereby improving the efficiency and accuracy of security operations.

CN120750602APending Publication Date: 2025-10-03NINGBO RADIO & TELEVISION GRP
View PDF 0 Cites 4 Cited by

Patent Information

Application Number
CN202511006256.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-22
Publication Date
2025-10-03

AI Technical Summary

Technical Problem

The existing radio and television network security operation technology has problems such as insufficient data processing capabilities, lagging detection methods and poor system coordination. The existing radio and television network security operation technology has problems such as insufficient data processing capabilities, lagging detection methods and poor system coordination.

Method used

Through the large-scale model-based radio and television network security operation method, multi-source heterogeneous data is collected in real time, noise filtering is performed using the XLM-RoBERTa model and multiple classification models, and threat analysis is performed in combination with the RAG knowledge base module and multi-model MOE architecture, achieving a transition from passive defense to active prediction.

Benefits of technology

It improves data quality, reduces false alarms and missed alarms, and achieves efficient noise reduction processing of massive log, traffic and terminal behavior data in radio and television networks, enhances global threat perception and linkage handling capabilities, and improves security operation efficiency and accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120750602A_ABST
    Figure CN120750602A_ABST
Patent Text Reader

Abstract

The invention discloses a broadcast television network security operation method and system based on a large model, and the method comprises the steps: collecting log, network flow and terminal behavior data in real time, storing the data in a Kafka message queue, receiving the data through an AI intelligent noise reduction module, extracting alarm text semantic features through an XLM-ROBERTa model, and carrying out the noise filtering through combining with a multi-classification model, thereby obtaining high-value data; inputting the high-value data and security document knowledge corresponding to the network threat intelligence into an RAG knowledge base module, generating enhanced context information data through knowledge extraction, vectorization storage and similarity retrieval, inputting the enhanced context information data into a cue word of a reply model, and outputting a first threat analysis reply; inputting the high-value data and the first threat analysis reply into a multi-model MOE architecture, distributing tasks through a gating network, integrating expert network output results, and generating a second threat analysis reply and a corresponding attack thermodynamic diagram; and executing feedback optimization operation of the corresponding module based on the second threat analysis reply, thereby improving the safety operation efficiency of the broadcast television network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a radio and television network security operation method and system based on a large model. Background Art

[0002] In recent years, with the rapid development of information technology, broadcasting and television networks have undergone profound changes, with their business scope continuously expanding from traditional radio and television program transmission to diverse areas such as converged media, cloud services, and 5G communications. During this transformation, the application of big model technology in broadcasting and television network security operations has become particularly necessary. With its powerful data analysis and processing capabilities, big models can efficiently handle massive amounts of multi-source heterogeneous data and accurately identify potential security threats. Their semantic understanding and reasoning capabilities help improve the accuracy and depth of security incident analysis, providing strong support for the development of effective protection strategies. They have become a key technical means of ensuring the security and stable operation of broadcasting and television networks, and play a significant role in promoting the digital transformation of the broadcasting and television industry and enhancing its core competitiveness.

[0003] However, existing broadcast and television network security operations technologies struggle to cope with real-time analysis of massive amounts of log, traffic, and terminal behavior data. Rule-based approaches are unable to effectively identify emerging threats such as APT attacks and zero-day vulnerabilities, resulting in high rates of false positives and false negatives. Furthermore, individual security devices operate in isolation, lacking global threat awareness and coordinated response capabilities. This severely restricts the effectiveness of broadcast and television network security operations, impacting the safe broadcasting of programs and the protection of user data. Summary of the Invention

[0004] The technical problem solved by the present invention is that the existing radio and television network security operation technology has problems such as insufficient data processing capabilities, lagging detection methods and poor system coordination. By enhancing semantic understanding, multimodal analysis and intelligent decision-making capabilities, an intelligent security operation system is constructed to achieve the transition from passive defense to active prediction, providing solid security guarantees for the digital transformation of the radio and television industry.

[0005] To solve the above technical problems, the present invention provides the following technical solution: a radio and television network security operation method based on a large model, the specific steps of which include:

[0006] Step S100: Real-time collection of multi-source heterogeneous data, including log data, network traffic data, and terminal behavior data. The multi-source heterogeneous data is stored in a Kafka message queue. An AI intelligent noise reduction module receives the multi-source heterogeneous data from the Kafka message queue and performs noise reduction processing. The AI ​​intelligent noise reduction module uses the XLM-RoBERTa model to extract semantic features of the alarm text, and combines a fully connected neural network, XGBoost, a convolutional neural network, and a bidirectional long short-term memory network classification model to perform noise filtering to obtain high-value data after noise reduction.

[0007] Step S200: Inputting the security document knowledge corresponding to the high-value data and network threat intelligence into the RAG knowledge base module, generating enhanced context information data through knowledge extraction, vectorized storage, and similarity retrieval, inputting the context information data into the prompt word of the response model, and the response model outputting a first threat analysis response based on the prompt word;

[0008] Step S300: Input the high-value data and the first threat analysis response into a multi-model MOE architecture, which includes an expert network and a gated network. The gated network allocates tasks and integrates the output results of each expert network to generate a second threat analysis response and a corresponding attack heat map.

[0009] Step S400: performing feedback optimization operations based on the second threat analysis response, wherein the feedback optimization operations include dynamic adjustment of noise reduction parameters, incremental update of the knowledge base, multi-model MOE architecture weight optimization, and model iteration.

[0010] As a preferred solution of the large-scale model-based broadcasting and television network security operation method of the present invention, step S100 specifically includes:

[0011] Step S101: collect the log data in real time through a distributed probe collection system; use a bypass-deployed traffic probe to mirror protocol traffic data to obtain the network traffic data; monitor terminal behavior events through an EDR agent to obtain the terminal behavior data, where the terminal behavior events include process creation, file operations, and abnormal registry access; and perform data cleaning and sample balancing on the collected multi-source heterogeneous data;

[0012] Step S102: Denoise the multi-source heterogeneous data using an AI intelligent denoising module, wherein the AI ​​intelligent denoising module includes an XLM-ROBERTa model and a classification model.

[0013] Use the XLM-ROBERTa model to perform multi-language semantic embedding on multi-source heterogeneous data, generate a 768-dimensional vector representation, and obtain the XLM-R vector;

[0014] The classification model includes a fully connected neural network, XGBoost, a convolutional neural network, and a bidirectional long short-term memory network; the XLM-R vector is input into the fully connected neural network, and a binary classification result is output through three hidden layers, wherein the three hidden layers include 512, 256, and 128 nodes respectively;

[0015] Using the XLM-R vector as a feature, the learning depth of the XGBoost is set to 6, and the learning rate is set to 0.1; the convolutional neural network uses a 1D convolution kernel to capture local semantic expressions, with a corresponding convolution kernel width of 3 and a number of channels of 6. The corresponding classification probability is output through a global maximum pooling layer and a fully connected layer. The bidirectional long short-term memory network has 128 hidden units, models the temporal dependency of multi-source heterogeneous data, and outputs the corresponding binary classification results through a fully connected layer. The binary classification results include safety event alerts and dangerous event alerts.

[0016] Step S103: The outputs of each model are integrated through weighted voting, and the weights of the fully connected neural network, XGBoost, convolutional neural network, and bidirectional long short-term memory network are set to 0.3, 0.3, 0.2, and 0.2 respectively; a five-fold cross-validation is performed using the expert-labeled sample set, and training is stopped when the accuracy is greater than 0.92;

[0017] The trained denoising model is deployed as a microservice, which receives the multi-source heterogeneous data and outputs the denoised high-value data.

[0018] As a preferred solution of the large-scale model-based broadcasting and television network security operation method of the present invention, step S200 specifically includes:

[0019] Step S201, the knowledge extraction and vectorized storage specifically includes: obtaining security document knowledge, the security document knowledge including network security knowledge, a vulnerability library, and user private data; performing text segmentation on the security document knowledge to obtain corresponding paragraph sets, the paragraph sets including a network security paragraph set, a vulnerability library paragraph set, and a user private data paragraph set; and performing multilingual semantic embedding on the paragraph sets using the XLM-ROBERTa model to obtain a vector database;

[0020] Step S201, similarity retrieval specifically includes: obtaining user question data and performing semantic enrichment, performing multilingual semantic embedding on the semantically enriched user question data using the XLM-ROBERTa model to obtain a question data vector, performing similarity retrieval on the question data vector and a vector database, returning a set of paragraphs with the greatest similarity, injecting the set of paragraphs with the user question data and the user question data into the prompt word of the large model, and the large model outputting a first threat analysis response based on the prompt word.

[0021] As a preferred solution of the large-scale model-based broadcasting and television network security operation method of the present invention, step S300 specifically includes:

[0022] Step S301: Input the high-value data and the first threat analysis response into a multi-model MOE architecture, which includes a gated network, an expert network, and an integration mechanism. The high-value data and the first threat analysis response are received, and task types are parsed through the gated network to obtain corresponding task types, including structured tasks, unstructured tasks, and real-time tasks, and the task types are assigned to corresponding expert network models.

[0023] Step S302: The expert network model includes multiple expert models with different parameters, including a security knowledge model, a multimodal model, and a conversation model. The expert network model performs specialized analysis based on corresponding task types.

[0024] Step S303 : performing weighted voting on the outputs of the expert models with different parameters, dynamically adjusting the output weights corresponding to the outputs of the expert models with different parameters according to the historical accuracy, and outputting the second threat analysis response.

[0025] As a preferred solution of the large-scale model-based broadcasting and television network security operation method of the present invention, step S400 specifically includes:

[0026] Step S401: extract false positive samples and missed negative samples from the security event alarms of the Kafka message queue, calculate the false positive rate and missed negative rate based on the output of the noise reduction model, and perform parameter optimization based on the false positive rate and missed negative rate. The parameter optimization specifically includes:

[0027] Adaptively adjust the semantic similarity threshold of the XLM-ROBERTa model based on false positives and false negatives, dynamically adjust the voting weights of the fully connected neural network and XGBoost models through reinforcement learning, and update the microservice configuration of the denoising model based on the adjusted weights;

[0028] Step S402: Extract the newly added IOC data and vulnerability exploitation techniques from the second threat analysis response and perform NER entity extraction. After marking, the data is stored in the vector database. Based on the timeliness, the original data is automatically downgraded or archived.

[0029] Step S403: Count the task processing accuracy of each expert model, dynamically adjust the task allocation weight, and add a new expert model branch;

[0030] In step S404, based on the false alarm rate, missed alarm rate and the corresponding vector database after being marked, the corresponding incremental training set in the newly added knowledge of the RAG knowledge base is obtained, and the XLM-RoBERTa and classification models of the denoising model are retrained based on the adjusted parameters in combination with the business scenario annotation to ensure that the cross-validation accuracy is greater than 92%; additional training data is added for the weak scenarios of the MOE expert model to update the corresponding model parameters.

[0031] As a preferred solution of the large-model-based radio and television network security operation method of the present invention, wherein: the adaptive adjustment of the semantic similarity threshold corresponding to the XLM-ROBERTa model specifically includes: for the false positive sample, lowering the similarity threshold of the XLM-ROBERTa semantic similarity;

[0032] For the missed samples, the similarity threshold of the XLM-ROBERTa semantic similarity is increased.

[0033] As a preferred solution of the large-scale model-based radio and television network security operation method described in the present invention, the first threat analysis response includes first pre-processing suggestion data corresponding to the alarm text and corresponding attacker activity records, and the second threat analysis response includes second pre-processing suggestion data corresponding to the alarm text and attack link restoration, and the second pre-processing suggestion data is supplemented and verified by the first pre-processing suggestion data.

[0034] As a preferred solution of the large-scale model-based broadcasting and television network security operation method of the present invention, the parsing logic of the gated network for performing task type parsing specifically includes: receiving the high-value data after the first threat response analysis and noise reduction, and analyzing the corresponding matching requirements;

[0035] If the matching requirement is an exact matching rule or a knowledge base query, the corresponding task type is a structured task and is assigned to the security knowledge model;

[0036] If the matching requirement is multimodal understanding or semantic understanding, the corresponding task type is an unstructured task and a multimodal model is assigned;

[0037] If the matching requirement is a low-latency response, the corresponding task type is a real-time task and is assigned to the conversation model with 7B parameters.

[0038] As a preferred solution of the large-model-based broadcasting and television network security operation method described in the present invention, constructing an attack heat map specifically includes: obtaining high-value alarm data after noise reduction and attack link restoration results in the second threat analysis response, using a predefined rule engine to map alarm types to MITRE ATT&CK tactics and techniques, and automatically supplementing alarm labels that are not clearly mapped through a security knowledge model;

[0039] Obtain threat frequency and threat level; count the number of alarms per unit time for each tactic or technique to obtain the threat frequency; calculate the comprehensive threat score of the tactic or technique based on the preset risk value of the alarm to obtain the threat level; the risk value includes high risk, medium risk, and low risk;

[0040] With ATT&CK tactics as the horizontal axis and technology as the vertical axis, the ECharts library is used to generate a matrix heat map. The color gradient is represented as follows: red represents high frequency or high risk, yellow represents medium frequency or medium risk, and green represents low frequency or low risk.

[0041] Broadcasting and television network security operation system based on large models, including data collection module, threat detection module and feedback optimization module

[0042] The data acquisition module is used to collect multi-source heterogeneous data in real time, perform data cleaning and sample balancing, and output standardized data to the Kafka message queue;

[0043] The threat detection module is used to perform AI intelligent noise reduction, RAG knowledge base enhancement and multi-model MOE architecture multi-model collaborative analysis to output high-value threat analysis results;

[0044] The feedback optimization module is used to dynamically adjust system parameter configuration based on the threat detection results displayed by the heat map and manual annotation feedback;

[0045] The beneficial effects of the present invention are as follows: by collecting multi-source heterogeneous data in real time and combining it with an AI intelligent noise reduction module, the XLM-RoBERTa model and multiple classification models are used for noise filtering, thereby achieving efficient noise reduction processing of massive logs, traffic and terminal behavior data in radio and television networks, which can improve data quality, reduce false positives and missed reports, and thus provide a high-value data foundation for subsequent threat analysis. By dynamically adjusting noise reduction parameters and model weights, the system's adaptive capabilities are further optimized, ensuring that high accuracy can be maintained in different business scenarios.

[0046] Through the collaborative work of the RAG knowledge base module and the multi-model MOE architecture, in-depth mining and intelligent analysis of threat intelligence are achieved. The RAG knowledge base module uses semantic retrieval and context enhancement technology to generate accurate first threat analysis responses; the multi-model MOE architecture dynamically allocates tasks to different expert models through a gated network, and combines a weighted voting mechanism to output second threat analysis responses and attack heat maps. It can fully restore the attack chain, provide multi-dimensional disposal suggestions, and use heat maps to intuitively display threat distribution, thereby improving the security operation efficiency and global threat perception capabilities of radio and television networks. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] Figure 1 A schematic diagram of the basic process of a large-scale model-based radio and television network security operation method provided by one embodiment of the present invention. DETAILED DESCRIPTION

[0048] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are described in detail below in conjunction with the drawings. It is obvious that the described embodiments are only part of the embodiments of the present invention, but not all of the embodiments.

[0049] Example, see Figure 1 , which is an embodiment of the present invention, provides a radio and television network security operation method based on a large model, and the specific steps include:

[0050] Step S100: Real-time collection of multi-source heterogeneous data, including log data, network traffic data, and terminal behavior data. The multi-source heterogeneous data is stored in a Kafka message queue. An AI intelligent noise reduction module receives the multi-source heterogeneous data from the Kafka message queue and performs noise reduction processing. The AI ​​intelligent noise reduction module uses the XLM-RoBERTa model to extract semantic features of the alarm text, and combines a fully connected neural network, XGBoost, a convolutional neural network, and a bidirectional long short-term memory network classification model to perform noise filtering to obtain high-value data after noise reduction.

[0051] Step S200: Inputting the security document knowledge corresponding to the high-value data and network threat intelligence into the RAG knowledge base module, generating enhanced context information data through knowledge extraction, vectorized storage, and similarity retrieval, inputting the context information data into the prompt word of the response model, and the response model outputting a first threat analysis response based on the prompt word;

[0052] Step S300: Input the high-value data and the first threat analysis response into a multi-model MOE architecture, which includes an expert network and a gated network. The gated network allocates tasks and integrates the output results of each expert network to generate a second threat analysis response and a corresponding attack heat map.

[0053] Step S400: performing feedback optimization operations based on the second threat analysis response, wherein the feedback optimization operations include dynamic adjustment of noise reduction parameters, incremental update of the knowledge base, multi-model MOE architecture weight optimization, and model iteration.

[0054] Step S100 specifically includes:

[0055] Step S101: collect the log data in real time through a distributed probe collection system; use a bypass-deployed traffic probe to mirror protocol traffic data to obtain the network traffic data; monitor terminal behavior events through an EDR agent to obtain the terminal behavior data, where the terminal behavior events include process creation, file operations, and abnormal registry access; and perform data cleaning and sample balancing on the collected multi-source heterogeneous data;

[0056] Step S102: Denoise the multi-source heterogeneous data using an AI intelligent denoising module, wherein the AI ​​intelligent denoising module includes an XLM-ROBERTa model and a classification model.

[0057] Use the XLM-ROBERTa model to perform multi-language semantic embedding on multi-source heterogeneous data, generate a 768-dimensional vector representation, and obtain the XLM-R vector;

[0058] The classification model includes a fully connected neural network, XGBoost, a convolutional neural network, and a bidirectional long short-term memory network; the XLM-R vector is input into the fully connected neural network, and a binary classification result is output through three hidden layers, wherein the three hidden layers include 512, 256, and 128 nodes respectively;

[0059] Using the XLM-R vector as a feature, the learning depth of the XGBoost is set to 6, and the learning rate is set to 0.1; the convolutional neural network uses a 1D convolution kernel to capture local semantic expressions, with a corresponding convolution kernel width of 3 and a number of channels of 6. The corresponding classification probability is output through a global maximum pooling layer and a fully connected layer. The bidirectional long short-term memory network has 128 hidden units, models the temporal dependency of multi-source heterogeneous data, and outputs the corresponding binary classification results through a fully connected layer. The binary classification results include safety event alerts and dangerous event alerts.

[0060] Step S103: The outputs of each model are integrated through weighted voting, and the weights of the fully connected neural network, XGBoost, convolutional neural network, and bidirectional long short-term memory network are set to 0.3, 0.3, 0.2, and 0.2 respectively; a five-fold cross-validation is performed using the expert-labeled sample set, and training is stopped when the accuracy is greater than 0.92;

[0061] The trained denoising model is deployed as a microservice, which receives the multi-source heterogeneous data and outputs the denoised high-value data.

[0062] In this embodiment, distributed probes are used to collect log data, bypass traffic probes are used to obtain network traffic, and EDR agents are used to monitor terminal behavior events. After data cleaning and sample balancing, the XLM-RoBERTa model is used to generate a 768-dimensional semantic vector for multi-source heterogeneous alarm texts, and four classification models are input: fully connected neural network, XGBoost, CNN and BiLSTM, which respectively model semantic features and temporal dependencies and output binary classification results (safe or dangerous alarms). The expert annotation data is historical alarm text (log or traffic or terminal behavior records), and the annotation results are binary labels (safe event alarm = 0, dangerous event alarm = 1). There are four possibilities for type prediction: correctly identifying dangerous events (TP), misjudging security events as dangerous (FP), correctly identifying security events (TN), and missing dangerous events (FN). By combining the output of the weighted voting fusion model with a 50% cross-validation expert-labeled sample set, we ensure an accuracy rate of >92%, achieve efficient noise filtering, reduce false positives and suppress FP, such as normal operations mistakenly triggering alarms, reduce missed negatives, avoid FN, such as APT attacks being ignored, enhance data value, and accurately separate high-threat events (TP) from low-risk noise (TN). Finally, it is deployed as a microservice to output high-value data after noise reduction in real time, laying a high-quality foundation for subsequent threat analysis.

[0063] Step S200 specifically includes:

[0064] Step S201, the knowledge extraction and vectorized storage specifically includes: obtaining security document knowledge, the security document knowledge including network security knowledge, a vulnerability library, and user private data; performing text segmentation on the security document knowledge to obtain corresponding paragraph sets, the paragraph sets including a network security paragraph set, a vulnerability library paragraph set, and a user private data paragraph set; and performing multilingual semantic embedding on the paragraph sets using the XLM-ROBERTa model to obtain a vector database;

[0065] Step S201, similarity retrieval specifically includes: obtaining user question data and performing semantic enrichment, performing multilingual semantic embedding on the semantically enriched user question data using the XLM-ROBERTa model to obtain a question data vector, performing similarity retrieval on the question data vector and a vector database, returning a set of paragraphs with the greatest similarity, injecting the set of paragraphs with the user question data and the user question data into the prompt word of the large model, and the large model outputting a first threat analysis response based on the prompt word.

[0066] In this embodiment, the semantic retrieval and context enhancement technology of the RAG knowledge base module is used to achieve accurate analysis and efficient response to threats to radio and television network security. The XLM-RoBERTa model is used to perform multi-language semantic embedding and vectorized storage of multi-source security document knowledge (including network security knowledge, vulnerability libraries, and user private data), and a high-coverage vector database is constructed; at the same time, semantic enrichment technology is used to deeply process user question data to generate semantically rich question vectors, and similarity retrieval is used to quickly match the most relevant knowledge paragraphs. The retrieval results and user questions are injected into the prompt words of the large model together to generate a context-aware first threat analysis response. It achieves the rapid extraction of key information from massive heterogeneous data, significantly improving the accuracy and efficiency of threat analysis. At the same time, by dynamically updating the vector database, the timeliness and comprehensiveness of the knowledge base are ensured, providing intelligent decision-making support for radio and television network security operations.

[0067] Step S300 specifically includes:

[0068] Step S301: Input the high-value data and the first threat analysis response into a multi-model MOE architecture, which includes a gated network, an expert network, and an integration mechanism. The high-value data and the first threat analysis response are received, and task types are parsed through the gated network to obtain corresponding task types, including structured tasks, unstructured tasks, and real-time tasks, and the task types are assigned to corresponding expert network models.

[0069] Step S302: The expert network model includes multiple expert models with different parameters, including a security knowledge model, a multimodal model, and a conversation model. The expert network model performs specialized analysis based on corresponding task types.

[0070] Step S303 : performing weighted voting on the outputs of the expert models with different parameters, dynamically adjusting the output weights corresponding to the outputs of the expert models with different parameters according to the historical accuracy, and outputting the second threat analysis response.

[0071] In this embodiment, the dynamic task allocation and multi-model collaborative analysis of the multi-model MOE architecture enable refined processing and intelligent decision-making of network security threats. The gated network intelligently analyzes the task type (such as structured tasks, unstructured tasks, or real-time tasks) based on the input high-value data and the first threat analysis response, and accurately assigns it to the corresponding expert model. Each expert model conducts specialized analysis for a specific task type, fully leveraging its strengths. For example, the security knowledge model excels at rule matching and knowledge base querying, the multimodal model excels at semantic understanding and complex scenario analysis, and the conversation model ensures low-latency response. By dynamically adjusting the output weights of each expert model through a weighted voting mechanism, the optimal analysis results can be integrated to generate a more accurate and comprehensive second threat analysis response. This technology achieves efficient analysis of complex threat scenarios, improving the accuracy and adaptability of threat detection. At the same time, through dynamic weight optimization, it ensures that the system can maintain high performance in different business scenarios, providing strong technical support for radio and television network security operations.

[0072] Step S400 specifically includes:

[0073] Step S401: extract false positive samples and missed negative samples from the security event alarms of the Kafka message queue, calculate the false positive rate and missed negative rate based on the output of the noise reduction model, and perform parameter optimization based on the false positive rate and missed negative rate. The parameter optimization specifically includes:

[0074] Adaptively adjust the semantic similarity threshold of the XLM-ROBERTa model based on false positives and false negatives, dynamically adjust the voting weights of the fully connected neural network and XGBoost models through reinforcement learning, and update the microservice configuration of the denoising model based on the adjusted weights;

[0075] Step S402: Extract the newly added IOC data and vulnerability exploitation techniques from the second threat analysis response and perform NER entity extraction. After marking, the data is stored in the vector database. Based on the timeliness, the original data is automatically downgraded or archived.

[0076] Step S403: Count the task processing accuracy of each expert model, dynamically adjust the task allocation weight, and add a new expert model branch;

[0077] In step S404, based on the false alarm rate, missed alarm rate and the corresponding vector database after being marked, the corresponding incremental training set in the newly added knowledge of the RAG knowledge base is obtained, and the XLM-RoBERTa and classification models of the denoising model are retrained based on the adjusted parameters in combination with the business scenario annotation to ensure that the cross-validation accuracy is greater than 92%; additional training data is added for the weak scenarios of the MOE expert model to update the corresponding model parameters.

[0078] In this embodiment, by extracting false positive and false negative samples from the Kafka message queue, combining them with the output of the noise reduction model to calculate the false positive and false negative rates and optimize parameters, including adaptively adjusting the XLM-ROBERTa semantic similarity threshold and dynamically adjusting the voting weights of the fully connected neural network and XGBoost; extracting new IOC data and vulnerability exploitation techniques from the second threat analysis response and updating the vector database, automatically downgrading or archiving old data; calculating the accuracy of the expert model to adjust task allocation weights and add new branches; obtaining incremental training sets based on relevant data, retraining the noise reduction model and the MOE expert model, and ensuring a cross-validation accuracy rate exceeding 92%, enabling dynamic self-optimization and continuous iteration of the system. This improves the accuracy of the noise reduction model, reduces the risk of false positives and false negatives, ensures the timeliness of the knowledge base and the adaptability of the expert model, enables the system to continuously evolve with changes in threats, maintains a high level of threat analysis capabilities over the long term, and provides continuous and reliable technical support for radio and television network security operations.

[0079] The adaptive adjustment of the semantic similarity threshold corresponding to the XLM-ROBERTa model specifically includes: for the false positive sample, lowering the similarity threshold of the XLM-ROBERTa semantic similarity;

[0080] For the missed samples, the similarity threshold of the XLM-ROBERTa semantic similarity is increased.

[0081] In this embodiment, by lowering the semantic similarity threshold of the XLM-ROBERTa model for false positive samples, it is possible to reduce the misjudgment of security incidents as dangerous incidents, effectively filter out unnecessary alarm noise, and avoid resource waste and analysis interference caused by oversensitivity; by raising the semantic similarity threshold for missed samples, the model's ability to capture potential dangerous incidents can be enhanced, the omission of real threats can be reduced, and high-risk incidents can be ensured to receive timely attention. The adaptive adjustment mechanism realizes the dynamic optimization of the semantic similarity threshold, so that the XLM-ROBERTa model can accurately identify dangerous incidents and effectively suppress false positives in different scenarios, thereby improving the overall accuracy and adaptability of the noise reduction processing, providing more reliable high-value data for subsequent threat analysis, and further ensuring the accuracy and efficiency of threat detection in radio and television network security operations, helping the system maintain a stable and efficient operation state in a complex and changing network environment.

[0082] The first threat analysis reply includes first pre-processing suggestion data corresponding to the alarm text and corresponding attacker activity records, and the second threat analysis reply includes second pre-processing suggestion data corresponding to the alarm text and attack link restoration, and the second pre-processing suggestion data is supplemented and verified by the first pre-processing suggestion data.

[0083] In this embodiment, the first pre-processing recommendation data provides preliminary processing measures (such as isolating suspicious IPs, blocking abnormal traffic, etc.) based on the retrieved threat intelligence and context information, and the attacker activity record describes the characteristics of the attack behavior, including the attack source, target, time, exploited vulnerabilities or technologies. The multi-model collaborative analysis generated through the multi-model MOE architecture deepens and verifies the first threat analysis response. The second pre-treatment recommendation data is based on the initial recommendations and combines the specialized analysis of expert models (such as multimodal understanding and real-time conversational reasoning) to provide more accurate treatment solutions (such as vulnerability remediation priorities and coordinated defense device strategies). The attack chain is restored by using security knowledge models and multimodal models to restore the complete attack path (such as the initial intrusion point, lateral movement steps, and data leakage path) and map it to the MITRE ATT&CK framework. The attack heat map visualizes the distribution of attacks based on threat frequency and level (such as high-frequency / high-risk attacks concentrated in certain types of techniques or tactics) to assist in global threat perception. The first threat analysis response focuses on rapid response and basic intelligence integration, relying on knowledge base retrieval. The second threat analysis response achieves in-depth analysis and dynamic optimization through multi-model collaboration, supplementing and verifying the accuracy of the first threat analysis response and providing visual decision support. This forms a closed loop from "initial warning" to "precise treatment", improving the security operation efficiency of radio and television networks.

[0084] The parsing logic of the gating network for task type parsing specifically includes: receiving the high-value data after the first threat response analysis and noise reduction, and analyzing the corresponding matching requirements;

[0085] If the matching requirement is an exact matching rule or a knowledge base query, the corresponding task type is a structured task and is assigned to the security knowledge model;

[0086] If the matching requirement is multimodal understanding or semantic understanding, the corresponding task type is an unstructured task and a multimodal model is assigned;

[0087] If the matching requirement is a low-latency response, the corresponding task type is a real-time task, and a conversation model is assigned.

[0088] In this embodiment, the high-value data after the first threat response analysis and noise reduction is received through the gated network, the matching requirements are analyzed and the task types are parsed into structured tasks, unstructured tasks and real-time tasks, which are respectively assigned to the security knowledge model, multimodal model and conversation model, so as to achieve precise adaptation of tasks and models. For structured tasks that require precise matching rules or knowledge base queries, the accuracy of the results can be guaranteed by handing them over to the security knowledge model; for unstructured tasks that require multimodal understanding or semantic understanding, complex information can be deeply analyzed through the multimodal model; for real-time tasks that require low-latency response, the results can be quickly fed back with the help of the conversation model. The dynamic allocation mechanism gives full play to the advantages of each expert model, improves the efficiency and quality of task processing, avoids the performance bottleneck of a single model in complex scenarios, enables the system to flexibly respond to the diverse needs of power network security operations, and provides efficient and accurate support for threat analysis.

[0089] Building an attack heatmap involves obtaining high-value alert data after noise reduction and attack chain restoration results from the second threat analysis response, mapping alert types to MITRE ATT&CK tactics and techniques using a predefined rule engine, and automatically supplementing alert labels that are not clearly mapped using security knowledge models.

[0090] Obtain threat frequency and threat level; count the number of alarms per unit time for each tactic or technique to obtain the threat frequency; calculate the comprehensive threat score of the tactic or technique based on the preset risk value of the alarm to obtain the threat level; the risk value includes high risk, medium risk, and low risk;

[0091] With ATT&CK tactics as the horizontal axis and technology as the vertical axis, the ECharts library is used to generate a matrix heat map. The color gradient is represented as follows: red represents high frequency or high risk, yellow represents medium frequency or medium risk, and green represents low frequency or low risk.

[0092] In this embodiment, by obtaining high-value alarm data after noise reduction and the attack link restoration results in the second threat analysis response, predefined rules are used to guide alarms to map alarm types to MITRE ATT&CK tactics and techniques, and the security knowledge model is used to automatically supplement alarm labels that are not clearly mapped. At the same time, the number of alarms corresponding to each tactic or technique in unit time is counted to determine the threat frequency. The comprehensive threat score is weighted and calculated according to the high, medium and low risk values ​​preset in the alarm to obtain the threat level. Finally, with ATT&CK tactics as the horizontal axis and technology as the vertical axis, the ECharts library is used to generate a matrix heat map with red, yellow and green gradients to represent different threat frequencies and levels. This map can intuitively and accurately display the threat distribution and severity in the radio and television network, and realize the visualization of attack patterns, allowing security operations personnel to quickly identify high-frequency and high-risk threat areas, clearly grasp the tactics and techniques corresponding to the attack links, thereby improving the perception and response efficiency of the overall threat situation, and providing an intuitive and reliable decision-making basis for formulating targeted defense strategies.

[0093] Broadcasting and television network security operation system based on large models, including data collection module, threat detection module and feedback optimization module

[0094] The data acquisition module is used to collect multi-source heterogeneous data in real time, perform data cleaning and sample balancing, and output standardized data to the Kafka message queue;

[0095] The threat detection module is used to perform AI intelligent noise reduction, RAG knowledge base enhancement and multi-model MOE architecture multi-model collaborative analysis to output high-value threat analysis results;

[0096] The feedback optimization module is used to dynamically adjust system parameter configurations based on the threat detection results displayed in the heat map and manual annotation feedback.

[0097] By collecting multi-source heterogeneous data in real time and combining it with an AI intelligent noise reduction module, and using the XLM-RoBERTa model and multiple classification models for noise filtering, efficient noise reduction processing is achieved for massive log, traffic and terminal behavior data in the radio and television network. This can improve data quality, reduce false positives and missed reports, and thus provide a high-value data foundation for subsequent threat analysis. By dynamically adjusting noise reduction parameters and model weights, the system's adaptive capabilities are further optimized to ensure high accuracy in different business scenarios.

[0098] Through the collaborative work of the RAG knowledge base module and the multi-model MOE architecture, in-depth mining and intelligent analysis of threat intelligence are achieved. The RAG knowledge base module uses semantic retrieval and context enhancement technology to generate accurate first threat analysis responses; the multi-model MOE architecture dynamically allocates tasks to different expert models through a gated network, and combines a weighted voting mechanism to output second threat analysis responses and attack heat maps. It can fully restore the attack chain, provide multi-dimensional disposal suggestions, and use heat maps to intuitively display threat distribution, thereby improving the security operation efficiency and global threat perception capabilities of the radio and television network.

[0099] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a fully hardware embodiment, a fully software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media containing computer-usable program code. The storage medium may be implemented by any type of volatile or non-volatile storage device, or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0100] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.

Claims

1. A radio and television network security operation method based on a large model, characterized by: The specific steps include: Step S100: Real-time collection of multi-source heterogeneous data, including log data, network traffic data, and terminal behavior data. The multi-source heterogeneous data is stored in a Kafka message queue. An AI intelligent noise reduction module receives the multi-source heterogeneous data from the Kafka message queue and performs noise reduction processing. The AI ​​intelligent noise reduction module uses the XLM-RoBERTa model to extract semantic features of the alarm text, and combines a fully connected neural network, XGBoost, a convolutional neural network, and a bidirectional long short-term memory network classification model to perform noise filtering to obtain high-value data after noise reduction. Step S200: Inputting the security document knowledge corresponding to the high-value data and network threat intelligence into the RAG knowledge base module, generating enhanced context information data through knowledge extraction, vectorized storage, and similarity retrieval, inputting the context information data into the prompt word of the response model, and the response model outputting a first threat analysis response based on the prompt word; Step S300: Input the high-value data and the first threat analysis response into a multi-model MOE architecture, which includes an expert network and a gated network. The gated network allocates tasks and integrates the output results of each expert network to generate a second threat analysis response and a corresponding attack heat map. Step S400: performing feedback optimization operations based on the second threat analysis response, wherein the feedback optimization operations include dynamic adjustment of noise reduction parameters, incremental update of the knowledge base, multi-model MOE architecture weight optimization, and model iteration.

2. The large-scale model-based broadcasting and television network security operation method according to claim 1, characterized in that: Step S100 specifically includes: Step S101: collect the log data in real time through a distributed probe collection system; use a bypass-deployed traffic probe to mirror protocol traffic data to obtain the network traffic data; monitor terminal behavior events through an EDR agent to obtain the terminal behavior data, where the terminal behavior events include process creation, file operations, and abnormal registry access; and perform data cleaning and sample balancing on the collected multi-source heterogeneous data; Step S102: Denoise the multi-source heterogeneous data using an AI intelligent denoising module, wherein the AI ​​intelligent denoising module includes an XLM-ROBERTa model and a classification model. Use the XLM-ROBERTa model to perform multi-language semantic embedding on multi-source heterogeneous data, generate a 768-dimensional vector representation, and obtain the XLM-R vector; The classification model includes a fully connected neural network, XGBoost, a convolutional neural network, and a bidirectional long short-term memory network; the XLM-R vector is input into the fully connected neural network, and a binary classification result is output through three hidden layers, wherein the three hidden layers include 512, 256, and 128 nodes respectively; Using the XLM-R vector as a feature, the learning depth of the XGBoost is set to 6, and the learning rate is set to 0.1; the convolutional neural network uses a 1D convolution kernel to capture local semantic expressions, with a corresponding convolution kernel width of 3 and a number of channels of 6. The corresponding classification probability is output through a global maximum pooling layer and a fully connected layer. The bidirectional long short-term memory network has 128 hidden units, models the temporal dependency of multi-source heterogeneous data, and outputs the corresponding binary classification results through a fully connected layer. The binary classification results include safety event alerts and dangerous event alerts. Step S103: The outputs of each model are integrated through weighted voting, and the weights of the fully connected neural network, XGBoost, convolutional neural network, and bidirectional long short-term memory network are set to 0.3, 0.3, 0.2, and 0.2 respectively; a five-fold cross-validation is performed using the expert-labeled sample set, and training is stopped when the accuracy is greater than 0.92; The trained denoising model is deployed as a microservice, which receives the multi-source heterogeneous data and outputs the denoised high-value data.

3. The large-scale model-based broadcasting and television network security operation method according to claim 2, characterized in that: Step S200 specifically includes: Step S201, the knowledge extraction and vectorized storage specifically includes: obtaining security document knowledge, the security document knowledge including network security knowledge, a vulnerability library, and user private data; performing text segmentation on the security document knowledge to obtain corresponding paragraph sets, the paragraph sets including a network security paragraph set, a vulnerability library paragraph set, and a user private data paragraph set; and performing multilingual semantic embedding on the paragraph sets using the XLM-ROBERTa model to obtain a vector database; Step S201, similarity retrieval specifically includes: obtaining user question data and performing semantic enrichment, performing multilingual semantic embedding on the semantically enriched user question data using the XLM-ROBERTa model to obtain a question data vector, performing similarity retrieval on the question data vector and a vector database, returning a set of paragraphs with the greatest similarity, injecting the set of paragraphs with the user question data and the user question data into the prompt word of the large model, and the large model outputting a first threat analysis response based on the prompt word.

4. The large-scale model-based broadcast and television network security operation method according to claim 3, characterized in that: Step S300 specifically includes: Step S301: Input the high-value data and the first threat analysis response into a multi-model MOE architecture, which includes a gated network, an expert network, and an integration mechanism. The high-value data and the first threat analysis response are received, and task types are parsed through the gated network to obtain corresponding task types, including structured tasks, unstructured tasks, and real-time tasks, and the task types are assigned to corresponding expert network models. Step S302: The expert network model includes multiple expert models with different parameters, including a security knowledge model, a multimodal model, and a conversation model. The expert network model performs specialized analysis based on corresponding task types. Step S303 : performing weighted voting on the outputs of the expert models with different parameters, dynamically adjusting the output weights corresponding to the outputs of the expert models with different parameters according to the historical accuracy, and outputting the second threat analysis response.

5. The large-scale model-based broadcasting and television network security operation method according to claim 4, characterized in that: Step S400 specifically includes: Step S401: extract false positive samples and missed negative samples from the security event alarms of the Kafka message queue, calculate the false positive rate and missed negative rate based on the output of the noise reduction model, and perform parameter optimization based on the false positive rate and missed negative rate. The parameter optimization specifically includes: Adaptively adjust the semantic similarity threshold of the XLM-ROBERTa model based on false positives and false negatives, dynamically adjust the voting weights of the fully connected neural network and XGBoost models through reinforcement learning, and update the microservice configuration of the denoising model based on the adjusted weights; Step S402: Extract the newly added IOC data and vulnerability exploitation techniques from the second threat analysis response and perform NER entity extraction. After marking, the data is stored in the vector database. Based on the timeliness, the original data is automatically downgraded or archived. Step S403: Count the task processing accuracy of each expert model, dynamically adjust the task allocation weight, and add a new expert model branch; In step S404, based on the false alarm rate, missed alarm rate and the corresponding vector database after being marked, the corresponding incremental training set in the newly added knowledge of the RAG knowledge base is obtained, and the XLM-RoBERTa and classification models of the denoising model are retrained based on the adjusted parameters in combination with the business scenario annotation to ensure that the cross-validation accuracy is greater than 92%; additional training data is added for the weak scenarios of the MOE expert model to update the corresponding model parameters.

6. The large-scale model-based broadcasting and television network security operation method according to claim 5, characterized in that: The adaptive adjustment of the semantic similarity threshold corresponding to the XLM-ROBERTa model specifically includes: for the false positive sample, lowering the similarity threshold of the XLM-ROBERTa semantic similarity; For the missed samples, the similarity threshold of the XLM-ROBERTa semantic similarity is increased.

7. The large-scale model-based broadcasting and television network security operation method according to claim 6, characterized in that: The first threat analysis reply includes first pre-processing suggestion data corresponding to the alarm text and corresponding attacker activity records, and the second threat analysis reply includes second pre-processing suggestion data corresponding to the alarm text and attack link restoration, and the second pre-processing suggestion data is supplemented and verified by the first pre-processing suggestion data.

8. The large-scale model-based broadcasting and television network security operation method according to claim 7, characterized in that: The parsing logic of the gating network for task type parsing specifically includes: receiving the high-value data after the first threat response analysis and noise reduction, and analyzing the corresponding matching requirements; If the matching requirement is an exact matching rule or a knowledge base query, the corresponding task type is a structured task and is assigned to the security knowledge model; If the matching requirement is multimodal understanding or semantic understanding, the corresponding task type is an unstructured task and a multimodal model is assigned; If the matching requirement is a low-latency response, the corresponding task type is a real-time task and is assigned to the conversation model with 7B parameters.

9. The large-scale model-based broadcasting and television network security operation method according to claim 8, characterized in that: Building an attack heatmap involves obtaining high-value alert data after noise reduction and attack chain restoration results from the second threat analysis response, mapping alert types to MITRE ATT&CK tactics and techniques using a predefined rule engine, and automatically supplementing alert labels that are not clearly mapped using security knowledge models. Obtain threat frequency and threat level; count the number of alarms per unit time for each tactic or technique to obtain the threat frequency; calculate the comprehensive threat score of the tactic or technique based on the preset risk value of the alarm to obtain the threat level; the risk value includes high risk, medium risk, and low risk; With ATT&CK tactics as the horizontal axis and technology as the vertical axis, the ECharts library is used to generate a matrix heat map. The color gradient is represented as follows: red represents high frequency or high risk, yellow represents medium frequency or medium risk, and green represents low frequency or low risk.

10. The large-model-based broadcasting and television network security operation system according to claim 9, comprising the large-model-based broadcasting and television network security operation method according to any one of claims 1 to 9, characterized in that: Including data collection module, threat detection module and feedback optimization module The data acquisition module is used to collect multi-source heterogeneous data in real time, perform data cleaning and sample balancing, and output standardized data to the Kafka message queue; The threat detection module is used to perform AI intelligent noise reduction, RAG knowledge base enhancement and multi-model MOE architecture multi-model collaborative analysis to output high-value threat analysis results; The feedback optimization module is used to dynamically adjust system parameter configurations based on the threat detection results displayed in the heat map and manual annotation feedback.

Citation Information

Cited By

  • Network security event handling method and system based on knowledge consistency verification

    CN121441642A

  • Network defense agent system based on large language model

    CN121462260A

  • Network security alarm information processing scheme generation method and system based on large language model

    CN122027220A

  • A broadcasting transmitting station fault diagnosis method and system

    CN122548582A