Intelligent early warning and decision making system and method based on large model driving

By using a large-model-driven intelligent early warning and decision-making system, which combines rule and strategy filtering, intelligent deep large-model analysis, and a multi-dimensional risk database, the system solves the problem of limited intelligent early warning and decision-making capabilities in existing technologies. It achieves efficient and accurate anomaly detection and closed-loop automated defense, improving the system's stability and response speed.

CN120934814APending Publication Date: 2025-11-11FUJIAN FUJITSU COMM SOFTWARE CO LTD

Patent Information

Application Number
CN202511090795.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-05
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

Existing technologies suffer from several problems in log processing, risk analysis, and defense execution, including an imbalance between the accuracy and efficiency of abnormal log filtering, a lack of multi-dimensional knowledge support for risk analysis, a lack of closed-loop management in defense execution, and insufficient modular collaboration in the technical architecture. These issues limit intelligent early warning and decision-making capabilities.

Method used

An intelligent early warning and decision-making system based on a large model is adopted, including a server log data layer, a filtering layer, a retrieval layer, an agent analysis and decision-making layer, a defense layer, an execution layer, a monitoring layer, and an inspection layer. It combines parallel filtering of rules and policies, intelligent deep large model analysis, a multi-dimensional risk database, and standardized data interaction design to form a closed-loop automated process.

Benefits of technology

It achieves efficient and accurate anomaly detection, deep intelligent risk analysis, closed-loop automated defense system, and highly collaborative technical architecture, improving the comprehensiveness and accuracy of anomaly log detection, ensuring the effective execution of defense measures, providing clear risk decision-making information, and enhancing system stability and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120934814A_ABST
    Figure CN120934814A_ABST
Patent Text Reader

Abstract

The invention discloses an intelligent early warning and decision making system and method based on large model driving. The intelligent early warning and decision making system comprises a server log data layer which is responsible for collecting various log data generated in the operation process of a server; the filtering layer is used for undertaking a task of quickly screening abnormal log information; the retrieval layer is used for matching similar or relevant information in a risk library for each abnormal log; the Agent analysis and decision-making layer is used for carrying out deep analysis on abnormal conditions by utilizing natural language processing and knowledge reasoning capability of an intelligent deep large model so as to identify attack types and formulate personalized defense schemes; the defense layer is responsible for calling a built-in defense tool library to execute a defense scheme; the execution layer is used for converting an instruction of the defense layer into a specific operation automatically executed through a script; the monitoring layer is used for monitoring results in and after scheme execution in real time; the inspection layer is used for automatically inspecting the production line after monitoring is normal; and the analysis layer is used for carrying out automatic chart analysis on attack or risk data. According to the invention, automatic processing from attack detection to system recovery is realized, and the response efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data security analysis technology, and in particular to an intelligent early warning and decision-making system and method based on large model-driven approaches. Background Technology

[0002] Existing technologies suffer from the following key deficiencies in the entire process of log processing, risk analysis, and defense execution, resulting in limited intelligent early warning and decision-making capabilities: 1. Imbalance between accuracy and efficiency in abnormal log filtering: Current rule engines (such as CN109840327B) rely on static rule bases, resulting in a false negative rate of up to 23% when facing attack logs containing variant features (such as modified XSS attack payloads). While machine learning-based filtering methods (such as LSTM models) can identify unknown patterns, the processing latency for a single log entry reaches 120ms, failing to meet real-time requirements (the financial industry requires latency <50ms). Neither approach achieves an organic integration of rule strategies and intelligent models, making it difficult to balance accuracy and efficiency. 2. Lack of multi-dimensional knowledge support for risk analysis: Existing large-scale model analysis solutions (such as CN118626359B) directly process raw log text without constructing a dedicated risk database containing historical attack cases, vulnerability knowledge bases, and asset vulnerability information. For example, in attack level assessment, existing technologies can only make judgments based on the magnitude of abnormal traffic in the logs. 3. Lack of closed-loop management in defense execution: Although the defense tool of patent US11258432B2 can perform actions such as IP blocking, it has three major defects: (1) Single defense scheme: It only supports five preset basic defense actions and cannot generate combined defense strategies for complex attacks (such as supply chain attacks); (2) Lack of effect verification: It does not monitor the actual execution results of actions such as "disabling attacker IP" (such as whether the IP actually exists and whether the blocking is effective), resulting in 31% of defense actions failing to be perceived; (3) System recovery gap: After the attack ends, the existing technology does not perform automated health checks on key modules of the production line (such as "order processing API" and "database connection pool"). 4. Insufficient modular collaboration of technical architecture: The log filtering, risk analysis, and defense execution modules of the existing system are mostly deployed independently, with poor interface compatibility. For example, the three security systems (log analysis, WAF, and intrusion detection) deployed by a certain bank have inconsistent data formats, which makes the cross-system correlation analysis of attack events take up to 30 minutes, missing the best defense opportunity. Summary of the Invention

[0003] The purpose of this invention is to provide an intelligent early warning and decision-making system and method based on a large model to address the five core deficiencies in log processing, risk analysis, and defense execution.

[0004] The technical solution adopted in this invention is: A large-model-driven intelligent early warning and decision-making system includes: Server log data layer: As the foundation of system operation, it is responsible for collecting various log data generated during server operation; Specifically, the logs come from a wide range of sources, including operating system logs, application logs, and network device logs. These logs exist in structured (e.g., JSON, CSV) or unstructured (plain text) formats, containing key information such as server operating status, user operation records, and network request information. To ensure data integrity and real-time performance, the system employs distributed log collection technology. By deploying lightweight log collection agents on each server node, log data is transmitted to the data center in real time, avoiding the impact of data transmission delays on subsequent processing efficiency.

[0005] Filtering layer: It is responsible for quickly filtering abnormal log information. The filtering layer adopts a dual-track filtering mechanism of rules and policies. Specifically, regarding rules, a predefined basic rule base based on regular expressions and threshold judgments is established. For example, specific SQL keyword matching rules are set for SQL injection attacks; for abnormal traffic, request volume thresholds are set, and alarms are triggered when the number of requests exceeds the threshold within a unit of time. Regarding strategies, a dynamic adaptive strategy engine is introduced to automatically adjust filtering strategies based on historical abnormal log data and the current network security situation. Simultaneously, machine learning algorithms are used to perform preliminary feature extraction and classification of log data, such as using Support Vector Machine (SVM) algorithms to identify common attack patterns. Through the collaborative work of rules and strategies, preliminary screening of massive amounts of log data can be completed within milliseconds, improving the efficiency of abnormal log extraction to over 95% and significantly reducing the amount of data processed subsequently.

[0006] Retrieval Layer: Its core function is to match similar or related information in the risk database for each abnormal log entry; the risk database is a structured knowledge storage system that integrates historical attack cases, vulnerability knowledge bases, asset vulnerability information, and industry security standard data; Specifically, the system employs vector embedding-based retrieval technology, transforming key features of abnormal logs into vector form and using a cosine similarity algorithm for rapid retrieval and matching within a risk database. For instance, when an abnormal log containing specific attack characteristics is detected, the system searches the risk database for historical cases with similar attack vectors to obtain information such as attack methods, impact scope, and historical handling experience for that type of attack. This retrieval method not only improves retrieval accuracy but also provides rich background information for subsequent analysis and decision-making, enabling the system to make more comprehensive and accurate judgments about abnormal situations.

[0007] Agent Analysis and Decision Layer: This is the core intelligent module of the system. It receives anomaly logs and related information provided by the retrieval layer, and uses the natural language processing and knowledge reasoning capabilities of the intelligent deep model to conduct in-depth analysis of anomalies in order to identify attack types and formulate personalized defense plans. Furthermore, the agent analysis and decision-making layer is built based on intelligent deep large models.

[0008] Furthermore, the intelligent deep large model is the DeepSeek large model.

[0009] Specifically, in attack type identification, the large-scale model accurately determines attack types, such as DDoS attacks and XSS attacks, through semantic understanding of log text and risk database information. In attack severity assessment, it quantifies the attack severity by combining data such as changes in server performance indicators and the scope of affected services. Based on the attack type and severity, it determines the attack level according to established security level assessment standards. Furthermore, the DeepSeek large-scale model can also develop personalized defense plans based on the analysis results, combined with defense experience in the risk database and the current system resource status. For example, for low-level attacks, it recommends traffic scrubbing; for high-level attacks, it develops a combined defense plan including IP blocking, service degradation, and other measures to ensure the effectiveness and relevance of the defense plan. Defense layer: Responsible for calling the built-in defense tool library to execute defense plans. The defense tool library integrates various types of security defense tools. Furthermore, security defense tools include firewall policy management tools, intrusion detection and prevention systems (IDS / IPS), and access control list (ACL) configuration tools.

[0010] Specifically, these security defense tools integrate with the system through standardized API interfaces, ensuring compatibility and scalability. Once the Agent analysis and decision-making layer generates a defense plan, the defense layer invokes the corresponding defense tools based on the plan's content. For example, if the plan requires disabling the attacker's IP address, the defense layer will invoke the firewall policy management tool to add access control rules to the firewall, prohibiting access from that IP address; if it involves disabling permissions, it will invoke the permission management tool to modify the permission settings of relevant users or roles, quickly blocking attack behavior and reducing the damage caused by the attack.

[0011] Execution layer: This is the actual execution unit of the defense scheme, responsible for translating the instructions of the defense layer into specific operations that are automatically executed by scripts.

[0012] Furthermore, the execution layer employs automated execution technology, using scripting languages ​​(such as Python and Shell) to write execution scripts, thereby automating the processing of various defense operations.

[0013] Specifically, for operations such as disabling attacker IPs and disabling permissions, the execution layer executes the corresponding commands by calling the command-line interface of the operating system or network device. Regarding alert reporting, the execution layer sends alert information to the security management platform, maintenance personnel's email addresses, or mobile terminals according to preset communication protocols (such as HTTP and SMTP), ensuring that relevant personnel are promptly informed of the attack situation. Simultaneously, the execution layer also has an operation rollback mechanism; if an anomaly is detected during execution, the executed operations can be automatically revoked, ensuring the stability and security of the system.

[0014] Monitoring layer: Used for real-time monitoring of the results during and after the execution of the plan; The monitoring layer employs multi-dimensional monitoring technology to monitor the system status from multiple aspects, including network traffic, system performance, and security events.

[0015] Specifically, in network traffic monitoring, traffic monitoring devices are deployed to collect network traffic data in real time, analyze indicators such as traffic size, flow direction, and protocol type to determine if abnormal traffic exists. For system performance, parameters such as server CPU utilization, memory usage, and disk I / O are monitored to promptly identify performance degradation issues caused by attacks or defensive operations. Regarding security event monitoring, it connects to intrusion detection systems, firewall logs, and other security devices to obtain security event information in real time. Once an anomaly is detected, the monitoring layer immediately generates alarm information and feeds it back to the Agent analysis and decision-making layer so that the system can adjust its defense strategies promptly. Inspection layer: Used to perform automated inspections on the production line after monitoring is normal, to ensure that the attacked modules are functioning properly.

[0016] Furthermore, the inspection layer employs probe-based detection technology to deploy detection probes in key modules of the production line to monitor the module's operating status in real time.

[0017] Specifically, the checks include the functional integrity of modules, data consistency, and interface response time metrics. For example, for web application modules, the check layer simulates user requests to test whether the page displays correctly and whether the data is submitted correctly; for database modules, it verifies whether data CRUD operations are executed correctly. If anomalies are found in the attacked module, the check layer will report the problem to the Agent analysis and decision-making layer, which will then formulate a new remediation plan to ensure the stable operation of the production line. Analysis layer: Used for automated chart analysis of attack or risk data, providing intuitive basis for security decisions.

[0018] Furthermore, the analysis layer uses data visualization technology to integrate and process the collected data, and then displays it visually through charts or dashboards.

[0019] Furthermore, the analysis results automatically generate security analysis reports, providing strong support for security managers to formulate long-term security strategies and optimize defense systems.

[0020] Specifically, the analysis layer employs data visualization technology to integrate and process collected log data, risk analysis results, and defense execution data, displaying them through charts (such as bar charts, line charts, and heatmaps) and dashboards. For example, an attack frequency trend chart visually presents the changes in the frequency of attack events over different time periods; a high-risk vulnerability distribution map displays the high-risk vulnerabilities present in each module of the system. Simultaneously, the analysis layer supports multi-dimensional cross-analysis of data, allowing users to delve deeper into the information behind the data by filtering conditions (such as attack type, time range, and asset category). Furthermore, the system can automatically generate security analysis reports based on the analysis results, providing strong support for security managers to formulate long-term security strategies and optimize the defense system.

[0021] The intelligent early warning and decision-making method based on large model-driven approaches includes the following steps: Step 1: Collect various log data generated during server operation. Step 2: Use a dual-track filtering mechanism of rules and strategies to quickly filter log data in order to extract abnormal log information; Step 3: Search each abnormal log in the risk database to match similar or related information; the risk database is a structured knowledge storage system that integrates historical attack cases, vulnerability knowledge base, asset vulnerability information and industry security standard data; Step 4: Receive the anomaly logs and matching related information, and use the natural language processing and knowledge reasoning capabilities of the intelligent deep large model to conduct in-depth analysis of the anomaly in order to identify the attack type and formulate a personalized defense plan. Step 5: Invoke the built-in defense tool library to execute the defense plan and generate corresponding defense instructions; the defense tool library integrates various types of security defense tools; Step 6: Translate the defense instructions into specific operations and execute them; Step 7: Monitor the results of the plan during and after execution in real time to determine whether it is executing normally; if yes, proceed to step 8; otherwise, generate alarm information and feed back the abnormal information to the Agent analysis and decision-making layer and proceed to step 4. Step 8: After monitoring is normal, perform automated inspection of the production line and monitor the operating status in real time; and when an abnormal problem is detected, feed the abnormal information back to the Agent analysis and decision-making layer and execute step 4. Furthermore, in step 7, the monitored anomaly information is sent to the analysis layer, which performs automated chart analysis on the attack or risk data, providing an intuitive basis for security decisions.

[0022] This invention, employing the above technical solutions, offers the following advantages compared to existing technologies: 1. Highly efficient and accurate anomaly detection: Combining rule / policy filtering with large-scale model analysis, it can quickly handle known attack patterns and effectively identify new, unknown attacks, improving the comprehensiveness and accuracy of anomaly log detection. 2. Deeply intelligent risk analysis: Utilizing a risk database combined with the DeepSeek large-scale model, it analyzes anomaly logs from multiple dimensions, providing more accurate judgments on attack types, severity, and levels, offering a reliable basis for defense decisions. 3. Closed-loop automated defense system: From defense plan formulation and execution to result monitoring and production line inspection, a complete automated closed-loop process is formed, ensuring effective execution of defense measures, timely recovery of attacked modules, and guaranteeing normal business operations. 4. Data-driven decision support: Through automated chart analysis, it deeply mines the value of attack / risk data, presenting the security situation in an intuitive and visual way, providing management with clear and comprehensive risk decision-making information, and assisting in the formulation of scientific security strategies. 5. Highly collaborative technical architecture: Standardized data interaction design enables efficient collaboration between modules, breaking down information silos, improving the overall system response speed and processing capacity, and enhancing system stability and reliability. Attached Figure Description

[0023] The present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments; Figure 1 This is a schematic diagram of the intelligent early warning and decision-making system architecture based on a large model driven by the present invention; Figure 2 This is a flowchart illustrating the intelligent early warning and decision-making method based on a large model driven by the present invention. Detailed Implementation

[0024] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings.

[0025] like Figure 1 As shown in Figure 2, this invention discloses an intelligent early warning and decision-making system based on a large model, which includes the following: Server Log Data Layer: As the foundation of system operation, this layer is responsible for collecting various log data generated during server operation. Log sources are diverse, covering operating system logs, application logs, network device logs, etc. These logs exist in structured (e.g., JSON, CSV) or unstructured (plain text) formats, containing key information such as server operating status, user operation records, and network request information. To ensure data integrity and real-time performance, the system employs distributed log collection technology. By deploying lightweight log collection agents on each server node, log data is transmitted to the data center in real time, avoiding the impact of data transmission delays on subsequent processing efficiency.

[0026] Filtering Layer: This layer is responsible for quickly filtering abnormal log information. It employs a dual-track filtering mechanism of rules and policies. On the rules side, a predefined basic rule base based on regular expressions and threshold judgments is used. For example, specific SQL keyword matching rules are set for SQL injection attacks; for traffic anomalies, request volume thresholds are set, triggering alarms when the number of requests exceeds the threshold within a unit of time. On the policies side, a dynamic adaptive policy engine is introduced to automatically adjust filtering policies based on historical abnormal log data and the current network security situation. Simultaneously, machine learning algorithms are used for preliminary feature extraction and classification of log data, such as using Support Vector Machine (SVM) algorithms to identify common attack patterns. Through the collaborative work of rules and policies, preliminary filtering of massive amounts of log data can be completed in milliseconds, improving the efficiency of abnormal log extraction to over 95% and significantly reducing the amount of data processed subsequently. Retrieval Layer: The core function is to match each abnormal log entry with similar / related information in the risk database. The risk database is a structured knowledge storage system that integrates historical attack cases, vulnerability knowledge bases, asset vulnerability information, and industry security standards. The system employs vector embedding-based retrieval technology, converting the key features of abnormal logs into vector form and using a cosine similarity algorithm for rapid retrieval and matching within the risk database. For example, when an abnormal log entry containing specific attack characteristics is detected, the system searches the risk database for historical cases with similar attack vectors to obtain information such as attack methods, impact scope, and historical handling experience for that type of attack. This retrieval method not only improves the accuracy of the retrieval but also provides rich background information for subsequent analysis and decision-making, making the system's judgment of abnormal situations more comprehensive and accurate.

[0027] The Agent Analysis and Decision Layer is the core intelligent module of the system, built upon the DeepSeek big model. This layer receives anomaly logs and related information from the retrieval layer and leverages the powerful natural language processing and knowledge reasoning capabilities of the DeepSeek big model to conduct in-depth analysis of anomalies. In attack type identification, the big model accurately determines attack types, such as DDoS and XSS attacks, through semantic understanding of log text and risk database information. For attack severity assessment, it quantifies the attack severity by combining data such as changes in server performance indicators and the scope of affected services. Based on the attack type and severity, it determines the attack level according to established security level assessment standards. Furthermore, the DeepSeek big model can also formulate personalized defense plans based on the analysis results, combined with defense experience in the risk database and the current system resource status. For example, for low-level attacks, traffic scrubbing is recommended; for high-level attacks, a combined defense plan including IP blocking and service degradation is developed to ensure the effectiveness and relevance of the defense plan. Defense Layer: Responsible for executing defense plans by invoking the built-in defense tool library. This library integrates various types of security defense tools, including firewall policy management tools, intrusion detection and prevention systems (IDS / IPS), and access control list (ACL) configuration tools. These tools integrate with the system through standardized API interfaces, ensuring compatibility and scalability. After the Agent analysis and decision-making layer generates a defense plan, the defense layer invokes the corresponding defense tools based on the plan's content. For example, if the plan requires disabling the attacker's IP address, the defense layer will invoke the firewall policy management tool to add access control rules to the firewall, prohibiting access from that IP address; if it involves disabling permissions, it will invoke the permission management tool to modify the permission settings of relevant users or roles, quickly blocking attack behavior and reducing the damage caused by the attack. The execution layer is the actual execution unit of the defense scheme, responsible for translating the instructions from the defense layer into specific operations that are automatically executed via scripts. This layer employs automated execution technology, using scripting languages ​​(such as Python and Shell) to write execution scripts to automate various defense operations. For operations such as disabling attacker IPs or disabling permissions, the execution layer executes the corresponding commands by calling the command-line interface of the operating system or network device. Regarding alert reporting, the execution layer sends alert information to the security management platform, maintenance personnel's email addresses, or mobile terminals according to preset communication protocols (such as HTTP and SMTP), ensuring that relevant personnel are promptly informed of the attack situation. Simultaneously, the execution layer also has an operation rollback mechanism; if an anomaly is detected during execution, the executed operations can be automatically revoked, ensuring the stability and security of the system. Monitoring Layer: Used for real-time monitoring of the results during and after the execution of the plan. This layer employs multi-dimensional monitoring technology to monitor the system status from multiple aspects, including network traffic, system performance, and security events. For network traffic monitoring, traffic monitoring devices are deployed to collect network traffic data in real time, analyzing indicators such as traffic size, flow direction, and protocol type to determine if abnormal traffic exists. For system performance, parameters such as server CPU utilization, memory usage, and disk I / O are monitored to promptly identify performance degradation issues caused by attacks or defensive operations. Regarding security event monitoring, it connects to intrusion detection systems, firewall logs, and other security devices to obtain security event information in real time. Once an anomaly is detected, the monitoring layer immediately generates alarm information and feeds it back to the Agent analysis and decision-making layer so that the system can adjust its defense strategy in a timely manner. Inspection Layer: After confirming normal operation, this layer performs automated checks on the production line to ensure the attacked modules function correctly. This layer employs probe-based detection technology, deploying probes on key production line modules to monitor their operational status in real time. The checks include metrics such as module functional integrity, data consistency, and interface response time. For example, for web application modules, the inspection layer simulates user requests to test whether the page displays correctly and whether data submission is correct; for database modules, it verifies whether CRUD operations are executed correctly. If anomalies are detected in the attacked module, the inspection layer reports the issue to the Agent analysis and decision-making layer, which then develops a remediation plan to ensure the stable operation of the production line. Analysis Layer: This layer performs automated chart analysis on attack / risk data, providing intuitive support for security decisions. Utilizing data visualization technology, it integrates and processes collected log data, risk analysis results, and defense execution data, displaying them through charts (such as bar charts, line charts, and heatmaps) and dashboards. For example, an attack frequency trend chart visually presents changes in the frequency of attack events over different time periods; a high-risk vulnerability distribution map displays the high-risk vulnerabilities present in various system modules. Furthermore, the analysis layer supports multi-dimensional cross-analysis of data, allowing users to delve deeper into the information behind the data by filtering conditions (such as attack type, time range, and asset category). In addition, the system can automatically generate security analysis reports based on the analysis results, providing strong support for security managers to develop long-term security strategies and optimize defense systems.

[0028] The intelligent early warning and decision-making method based on large model-driven approaches includes the following steps: Step 1: Collect various log data generated during server operation. Step 2: Use a dual-track filtering mechanism of rules and strategies to quickly filter log data in order to extract abnormal log information; Step 3: Search each abnormal log in the risk database to match similar or related information; the risk database is a structured knowledge storage system that integrates historical attack cases, vulnerability knowledge base, asset vulnerability information and industry security standard data; Step 4: Receive the anomaly logs and matching related information, and use the natural language processing and knowledge reasoning capabilities of the intelligent deep large model to conduct in-depth analysis of the anomaly in order to identify the attack type and formulate a personalized defense plan. Step 5: Invoke the built-in defense tool library to execute the defense plan and generate corresponding defense instructions; the defense tool library integrates various types of security defense tools; Step 6: Translate the defense instructions into specific operations and execute them; Step 7: Monitor the results of the plan during and after execution in real time to determine whether it is executing normally; if yes, proceed to step 8; otherwise, generate alarm information and feed back the abnormal information to the Agent analysis and decision-making layer and proceed to step 4. Step 8: After monitoring is normal, perform automated inspection of the production line and monitor the operating status in real time; and when an abnormal problem is detected, feed the abnormal information back to the Agent analysis and decision-making layer and execute step 4. Furthermore, in step 7, the monitored anomaly information is sent to the analysis layer, which performs automated chart analysis on the attack or risk data, providing an intuitive basis for security decisions.

[0029] This invention, employing the above technical solutions, offers the following advantages compared to existing technologies: 1. Highly efficient and accurate anomaly detection: Combining rule / policy filtering with large-scale model analysis, it can quickly handle known attack patterns and effectively identify new, unknown attacks, improving the comprehensiveness and accuracy of anomaly log detection. 2. Deeply intelligent risk analysis: Utilizing a risk database combined with the DeepSeek large-scale model, it analyzes anomaly logs from multiple dimensions, providing more accurate judgments on attack types, severity, and levels, offering a reliable basis for defense decisions. 3. Closed-loop automated defense system: From defense plan formulation and execution to result monitoring and production line inspection, a complete automated closed-loop process is formed, ensuring effective execution of defense measures, timely recovery of attacked modules, and guaranteeing normal business operations. 4. Data-driven decision support: Through automated chart analysis, it deeply mines the value of attack / risk data, presenting the security situation in an intuitive and visual way, providing management with clear and comprehensive risk decision-making information, and assisting in the formulation of scientific security strategies. 5. Highly collaborative technical architecture: Standardized data interaction design enables efficient collaboration between modules, breaking down information silos, improving the overall system response speed and processing capacity, and enhancing system stability and reliability.

[0030] Obviously, the described embodiments are only a part of the embodiments of this application, not all of them. Without conflict, the embodiments and features in the embodiments of this application can be combined with each other. The components of the embodiments of this application described and illustrated herein can generally be arranged and designed in various different configurations. Therefore, the detailed description of the embodiments of this application is not intended to limit the scope of the claimed application, but merely to illustrate selected embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.

Claims

1. A large-model-driven intelligent early warning and decision-making system, characterized in that: It includes: Server log data layer: As the foundation of system operation, it is responsible for collecting various log data generated during server operation; Filtering layer: It is responsible for quickly filtering abnormal log information. The filtering layer adopts a dual-track filtering mechanism of rules and policies. Retrieval layer: Its core function is to match similar or related information in the risk database for each abnormal log entry; The risk database is a structured knowledge storage system that integrates historical attack cases, vulnerability knowledge bases, asset vulnerability information, and industry security standard data. Agent Analysis and Decision Layer: This is the core intelligent module of the system. It receives anomaly logs and related information provided by the retrieval layer, and uses the natural language processing and knowledge reasoning capabilities of the intelligent deep model to conduct in-depth analysis of anomalies in order to identify attack types and formulate personalized defense plans. Defense layer: responsible for calling the built-in defense tool library to execute defense plans. The defense tool library integrates various types of security defense tools; Execution layer: This is the actual execution unit of the defense plan, responsible for translating the instructions of the defense layer into specific operations that are automatically executed by scripts; Monitoring layer: Used for real-time monitoring of the results during and after the execution of the plan; Inspection layer: Used to perform automated inspections on the production line after monitoring is normal, to ensure that the attacked modules are functioning properly; Analysis layer: Used for automated chart analysis of attack or risk data, providing intuitive basis for security decisions.

2. The intelligent early warning and decision-making system based on large model-driven approach according to claim 1, characterized in that: Log data includes operating system logs, application logs, and network device logs; log data exists in structured or unstructured form.

3. The intelligent early warning and decision-making system based on large model-driven approach according to claim 1, characterized in that: In terms of rules, the filtering layer predefines a basic rule base based on regular expressions and threshold judgment; in terms of strategy, it introduces a dynamic adaptive strategy engine to automatically adjust the filtering strategy based on historical abnormal log data and the current network security situation; at the same time, it combines machine learning algorithms to perform preliminary feature extraction and classification of log data in order to identify attack patterns.

4. The intelligent early warning and decision-making system based on large model-driven approach according to claim 1, characterized in that: The retrieval layer employs vector embedding-based retrieval technology, transforming key features of abnormal logs into vector form and using a cosine similarity algorithm for rapid retrieval and matching in the risk database.

5. The intelligent early warning and decision-making system based on large model-driven as described in claim 1, characterized in that: In terms of attack type identification, the intelligent big data model in the Agent analysis and decision-making layer accurately determines the attack type through semantic understanding of log text and risk database information. In terms of attack severity assessment, it quantifies the attack severity by combining changes in server performance indicators and data on the scope of affected services. Based on the attack type and severity, it determines the attack level according to established security level assessment standards. Based on the analysis results, combined with defense experience in the risk database and the current system resource status, the intelligent big data model in the Agent analysis and decision-making layer formulates personalized defense plans.

6. The intelligent early warning and decision-making system based on large model-driven approach according to claim 1, characterized in that: The inspection layer employs probe-based detection technology to deploy detection probes in key modules of the production line to monitor the module's operating status in real time.

7. The intelligent early warning and decision-making system based on large model-driven approach according to claim 1, characterized in that: The analysis layer uses data visualization technology to integrate and process the collected data, and then displays it visually through charts or dashboards. The analysis results automatically generate security analysis reports, providing strong support for security managers to formulate long-term security strategies and optimize defense systems.

8. A large-model-driven intelligent early warning and decision-making method, as described in any one of claims 1 to 7, characterized in that: The method includes the following steps: Step 1: Collect various log data generated during server operation. Step 2: Use a dual-track filtering mechanism of rules and strategies to quickly filter log data in order to extract abnormal log information; Step 3: Search each abnormal log in the risk database to find similar or related information; The risk database is a structured knowledge storage system that integrates historical attack cases, vulnerability knowledge bases, asset vulnerability information, and industry security standard data. Step 4: Receive the anomaly logs and matching related information, and use the natural language processing and knowledge reasoning capabilities of the intelligent deep large model to conduct in-depth analysis of the anomaly in order to identify the attack type and formulate a personalized defense plan. Step 5: Invoke the built-in defense tool library to execute the defense plan and generate corresponding defense instructions; the defense tool library integrates various types of security defense tools; Step 6: Translate the defense instructions into specific operations and execute them; Step 7: Monitor the results of the plan during and after execution in real time to determine whether it is executing normally; if yes, proceed to step 8; otherwise, generate alarm information and feed back the abnormal information to the Agent analysis and decision-making layer and proceed to step 4. Step 8: After monitoring is normal, perform automated inspection of the production line and monitor the operating status in real time; when an abnormal problem is detected, the abnormal information is fed back to the Agent analysis and decision-making layer and step 4 is executed.

9. The intelligent early warning and decision-making method based on large model-driven approach according to claim 8, characterized in that: Step 1 employs distributed log collection technology, which involves deploying lightweight log collection agents on each server node to obtain log data in real time.

10. The intelligent early warning and decision-making method based on large model-driven approach according to claim 8, characterized in that: In step 7, the monitored anomaly information is sent to the analysis layer, which then performs automated chart analysis on the attack or risk data, providing an intuitive basis for security decisions.

Citation Information

Patent Citations

  • A word recognition method and device

    CN109840327B

  • A log analysis method and system based on large language model

    CN118626359B

  • Deglitcher circuit with integrated non-overlap function

    US11258432B1

Cited By

  • Coding strategy generation method for code vulnerabilities and related equipment

    CN121585483A