Safety tool access method for safety protection system and related device
By automatically generating and verifying security tool access schemes using artificial intelligence models, the problems of low efficiency and poor compatibility in accessing third-party tools in security protection systems have been solved. This has enabled automated access of security tools and unified data formats, thereby improving the system's alarm analysis and handling capabilities.
Patent Information
- Application Number
- CN202511217922.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-28
- Publication Date
- 2025-11-18
AI Technical Summary
Existing security protection systems are inefficient and have poor compatibility when integrating third-party security tools, and lack unified standards, resulting in chaotic data formats and affecting the efficiency of alarm analysis and handling.
Artificial intelligence models are used to automatically generate security tool access schemes, and the correctness of the access schemes is verified through operation logs. A knowledge base is built to optimize the access process, thereby achieving automated access of security tools and unified management of data formats.
It improves the timeliness and compatibility of the security protection system in connecting to third-party security tools, enhances the number of data sources, alarm analysis capabilities, and handling capabilities, and ensures the accuracy and efficiency of the access solution.
Smart Images

Figure CN120979754A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to a security tool access method for a security protection system, a security tool access device for a security protection system, an electronic device, and a computer-readable storage medium. Background Technology
[0002] With the continuous development of cloud computing technology, security protection systems for cloud security testing have emerged. For example, security protection systems may include products such as cloud security centers and cloud workload protection platforms (CWPP) that protect workloads in cloud environments.
[0003] With the development of large-scale model technology, security protection systems can also provide security detection services in the form of security intelligent agents. Security intelligent agents are comprehensive intelligent security applications built on large-scale security models and various security tools / plugins. Depending on the capabilities of the tools / plugins and the security model, they can perform various security tasks.
[0004] The security protection system can detect alarm information, analyze the alarm information, and feed back the alarm analysis results to the user (such as security operations personnel) so that the user can handle the alarm based on the alarm analysis results.
[0005] In the actual operation of these security systems, third-party security tools may need to be invoked. As security protection becomes more complex, the types and number of third-party security tools integrated into security systems are increasing. Summary of the Invention
[0006] This summary section is provided to briefly introduce the concepts, which will be described in detail in the detailed description section below. This summary section is not intended to identify key or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.
[0007] At least one embodiment of this disclosure provides a method for accessing a security tool in a security protection system, comprising: acquiring first guidance information of a first security tool; analyzing the first guidance information using a first artificial intelligence model to generate a first access scheme for the first security tool, wherein the first access scheme is used to invoke the first security tool; acquiring a first operation log, wherein the first operation log includes: operation logs generated by invoking the first security tool based on the first access scheme; and, in response to the first operation log indicating that the first access scheme has a logical error, analyzing the first operation log using a second artificial intelligence model to determine a corrected first access scheme.
[0008] At least another embodiment of this disclosure provides a security tool access device for a security protection system, comprising: a first acquisition module configured to: acquire first guidance information of a first security tool; a generation module configured to: analyze the first guidance information using a first artificial intelligence model to generate a first access scheme for the first security tool, wherein the first access scheme is used to invoke the first security tool; a second acquisition module configured to: acquire a first operation log, wherein the first operation log includes: operation logs generated by invoking the first security tool based on the first access scheme; and a verification module configured to: in response to the first operation log indicating that the first access scheme has a logical error, analyze the first operation log using a second artificial intelligence model to determine a corrected first access scheme.
[0009] At least one further embodiment of this disclosure provides an electronic device, including: a processing device; and a storage device including one or more computer program instructions; wherein the one or more computer program instructions are executed by the processing device to perform the security tool access method for a security protection system provided in at least one embodiment of this disclosure.
[0010] At least one further embodiment of this disclosure provides a computer-readable storage medium that non-transitory stores computer-readable instructions, wherein when the computer-readable instructions are executed by a processor, they implement the security tool access method for a security protection system provided in at least one embodiment of this disclosure.
[0011] At least one embodiment of this disclosure provides a computer program product, including a computer program that, when executed by a processor, implements the security tool access method for a security protection system provided in at least one embodiment of this disclosure. Attached Figure Description
[0012] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and the originals and elements are not necessarily drawn to scale.
[0013] Figure 1 This illustration schematically depicts an application scenario of a security protection system provided by at least one embodiment of the present disclosure;
[0014] Figure 2 The illustration schematically shows a flowchart of a security tool access method for a security protection system provided in at least one embodiment of the present disclosure;
[0015] Figure 3The illustration schematically shows a flowchart of another security tool access method for a security protection system provided in at least one embodiment of the present disclosure;
[0016] Figure 4 This schematically illustrates a structural diagram of a security tool access device for a security protection system according to at least one embodiment of the present disclosure; and
[0017] Figure 5 A schematic diagram of the structure of an electronic device suitable for implementing embodiments of the present disclosure is shown. Detailed Implementation
[0018] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.
[0019] It should be understood that the steps described in the method embodiments of this disclosure may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this disclosure is not limited in this respect.
[0020] The term "comprising" and its variations as used herein are open-ended inclusions, meaning "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Definitions of other terms will be given in the description below.
[0021] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.
[0022] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".
[0023] The names of the messages or information exchanged between the various devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of these messages or information.
[0024] It is understood that the data involved in this technical solution (including but not limited to the data itself, the acquisition, use, storage or deletion of the data) shall comply with the requirements of relevant laws, regulations and related provisions.
[0025] It is understood that before using the technical solutions disclosed in the various embodiments of this disclosure, relevant users should be informed of the type, scope of use, and usage scenarios of the information involved in this disclosure through appropriate means in accordance with relevant laws and regulations, and authorization should be obtained from the relevant users. Among them, relevant users may include any type of rights holder, such as individuals, enterprises, and groups.
[0026] For example, in response to receiving an active request from a user, a prompt message is sent to the relevant user to clearly indicate that the operation requested by the user will require obtaining and using the user's information. This allows the relevant user to choose whether to provide information to the software or hardware such as the electronic device, application, server, or storage medium that performs the operation of any embodiment of the present disclosure based on the prompt message.
[0027] As an optional but non-restrictive implementation, in response to a user's active request, a prompt message can be sent to the user, such as a pop-up window, where the prompt message can be presented in text format. Furthermore, the pop-up window can also include a selection control allowing the user to choose "agree" or "disagree" to provide information to the electronic device.
[0028] It is understood that the above notification and user authorization process are merely illustrative and do not constitute a limitation on the implementation of this disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of this disclosure.
[0029] With the continuous development of cloud computing technology, security protection systems for cloud security testing have emerged. These systems can perform multi-faceted security testing across various operational scenarios. For example, a security protection system can be a cloud workload protection platform (CWPP), which can test host security and network security. Another example is a host-based intrusion detection system (HIDS), which can perform security testing on the behavior and state of computer systems. Yet another example is an endpoint detection and response (EDR) system, which can perform security testing on the system-level behavior of endpoints. Finally, a security protection system can be a container security platform (CSP), which provides multi-faceted security testing for containers.
[0030] With the development of large-scale model technology, artificial intelligence-driven agents have been widely used. These agents are typically capable of perceiving information, making decisions, and taking actions to achieve specific goals or tasks within their environment. For example, in the field of security detection, security protection systems can also provide security detection services in the form of security agents. These security agents are comprehensive intelligent security applications built upon large-scale security models and various security tools / plugins. Depending on the capabilities of the tools / plugins and the security model, they can perform various security tasks.
[0031] The security protection system can detect alarm information, analyze the alarm information, and feed back the alarm analysis results to the user (such as security operations personnel) so that the user can handle the alarm based on the alarm analysis results.
[0032] In the actual operation of a security protection system, it may need to call third-party security tools. For example, the security protection system can call third-party security tools to collect alarm data, perform alarm feature matching, or conduct log auditing.
[0033] As security protection becomes more complex, the types and number of third-party security tools integrated into security protection systems are increasing, making it important to improve the integration efficiency of third-party security tools into security protection systems.
[0034] In related technologies, the security tool integration process is primarily led manually. In some instances, when a security protection system needs to integrate a new security tool, security operations personnel study the relevant documentation of the security tool to be integrated, such as the Representational State Transfer (REST) application programming interface (API) specification document and the software development kit (SDK) development guide document, write an integration plan for the security tool, and then integrate the security tool into the security protection system based on the integration plan. If a security tool is subsequently updated, the above manual operation must be repeated.
[0035] In the aforementioned security tool integration methods, the timeliness and compatibility of integration depend on the security operations personnel's understanding of the security tool. Furthermore, with the increasing heterogeneity of security tool interface protocols, the integration time for these methods may extend to several weeks, resulting in low efficiency in integrating security tools into the security protection system and impacting the system's functional iteration pace.
[0036] Furthermore, the inventors of this disclosure noted in their research that different security tools output data in diverse formats, and the lack of a unified standard for the access methods of these security tools can easily lead to confusion in the data formats output by different security tools, causing data flow bottlenecks across security tools. In the face of sudden alarm events, it is difficult to quickly call multiple security tools to respond collaboratively, further affecting the alarm analysis and alarm handling efficiency of the security protection system.
[0037] To at least partially solve the above-mentioned technical problem, at least one embodiment of this disclosure provides a method for accessing a security tool in a security protection system. The method includes: obtaining first guidance information of a first security tool; analyzing the first guidance information using a first artificial intelligence model to generate a first access scheme for the first security tool, wherein the first access scheme is used to call the first security tool; obtaining a first running log, wherein the first running log includes: running log generated by calling the first security tool based on the first access scheme; in response to the first running log indicating that the first access scheme has a logical error; analyzing the first running log using a second artificial intelligence model to determine a corrected first access scheme.
[0038] Based on the security tool access method for a security protection system provided in at least one embodiment of this disclosure, at least one embodiment of this disclosure also provides a security tool access device, electronic device, computer-readable storage medium, and computer program product for a security protection system.
[0039] This disclosure provides at least one embodiment of a security tool access method for a security protection system. For a first security tool to be accessed, the method uses guidance information from the first security tool and an artificial intelligence model to automatically generate an access scheme for the security tool. This eliminates the need for repetitive security tool access work by investing development manpower. Furthermore, by acquiring operational logs, the method uses the artificial intelligence model to verify the correctness of the access scheme, ensuring its accuracy. When applied to security protection systems such as security intelligent agents, this method enables the security protection system to quickly and efficiently access different types of third-party security tools, improving the number of data sources, alarm analysis capabilities, and alarm handling capabilities of the security protection system.
[0040] The embodiments and some examples of this disclosure will now be described in detail with reference to the accompanying drawings.
[0041] Figure 1 The illustration shows an application scenario of a security protection system provided by at least one embodiment of the present disclosure.
[0042] like Figure 1 As shown, the application scenario of this embodiment includes a security protection system 101. The embodiments of this disclosure do not limit the form of the security protection system 101. For example, the security protection system 101 can provide cloud security protection-related services in the form of a security AI agent. The security protection system 101 can be a cloud security platform, a cloud security plugin, a cloud security cloud service, etc.
[0043] The security protection system 101 can access one or more security tools, such as security tool 1021, security tool 1022, ..., security tool 102n. In the embodiments of this disclosure, an access scheme for the security tools is generated using an artificial intelligence model 104 to achieve automatic access of the security tools to the security protection system 101. For example, the artificial intelligence model 104 may include any one or a combination of multiple of the following: a large language model, a large visual model, a large audio model, and a large multimodal model. For example, the artificial intelligence model 104 may be a model built based on a transformer architecture, a model built based on a recurrent neural network, a model built based on an attention mechanism, etc. Alternatively, the artificial intelligence model 104 may also be a model obtained by improving upon the transformer architecture, such as a mixture of experts (MoE) model.
[0044] In some embodiments, guidance information 103 for security tools is obtained. This guidance information 103 may describe content related to accessing the security tool, such as content provided by the security tool provider or other parties. In other embodiments, reference information, such as web search results or historical access schemes, may also be obtained from a knowledge base 105. The artificial intelligence model 104 may generate an access scheme 106 for the security tool based on the guidance information 103 and the reference information obtained from the knowledge base 105.
[0045] Furthermore, after generating access scheme 106, operation log 107 can be obtained, and access scheme 106 can be corrected using artificial intelligence model 104 to form a corrected access scheme 106. In this way, the operation log 107 can be used to determine whether there are logical errors in access scheme 106. If so, access scheme 106 can be repaired to achieve verification of access scheme 106.
[0046] Furthermore, the access scheme 106 for security tools returned by the artificial intelligence model 104 can also be stored in the knowledge base 105. When other security tool access schemes are generated in the future, it can be used as reference information for the artificial intelligence model 104 to improve the quality of subsequent access scheme generation and form a security tool access process of "knowledge-driven - intelligent generation - closed-loop optimization".
[0047] It should be noted that, in this disclosure, the artificial intelligence model 104 (e.g., it can be a first artificial intelligence model, a second artificial intelligence model, a third artificial intelligence model, or a fourth artificial intelligence model) can be obtained in various ways. For example, the artificial intelligence model 104 can be an existing, open-source general artificial intelligence model. Alternatively, the artificial intelligence model 104 can be an artificial intelligence model obtained by fine-tuning (e.g., full parameter fine-tuning or partial parameter fine-tuning) based on a pre-trained model using historical security data from the security protection system 101 (e.g., guidance information for third-party security tools accessing the security protection system, access schemes for calling third-party security tools, etc.).
[0048] The following will combine Figure 2 and Figure 3 This disclosure provides a detailed description of a security tool access method for a security protection system, based on at least one embodiment.
[0049] Figure 2 The illustration shows a flowchart of a security tool access method for a security protection system provided in at least one embodiment of the present disclosure.
[0050] like Figure 2As shown, the security tool access method for a security protection system in this embodiment includes steps S201 to S204. For example, the executing entity of this security tool access method can be an electronic device with a client deployed, an electronic device with a server deployed, or any electronic device that communicates between the client and the server; the embodiments of this disclosure do not limit this.
[0051] Step S201: Obtain first guidance information for the first security tool.
[0052] The first security tool can be understood as a security tool that needs to be connected to the security protection system. For example, the first security tool can be a third-party security tool outside the security protection system. In the embodiments of this disclosure, the first security tool can provide security protection-related functions for the security protection system to call during actual operation. For example, the first security tool can be a vulnerability scanner, threat intelligence platform, log auditing system, or other third-party security tools, or it can be a security model, etc.
[0053] To facilitate the use of third-party security tools by business users (such as service providers of security protection systems), these service providers typically offer guidance information. This guidance information helps business users learn and understand how to use the third-party security tools. In the embodiments of this disclosure, a first security tool corresponds to first guidance information. This first guidance information can be understood as information describing the usage method and access process of the first security tool. That is, the first guidance information can be used to help business users learn the access process of the first security tool. For example, the first guidance information may include one or more of the following: the API reference manual of the first security tool, the developer guide of the first security tool, and the command-line help text of the first security tool.
[0054] The embodiments disclosed herein do not limit the method of obtaining the first guidance information of the first security tool. In some possible implementations, the first guidance information of the first security tool can be downloaded from the official website of the first security tool. In other possible implementations, guidance information related to the first security tool can be searched online, and the first guidance information of the first security tool can be obtained based on the search results.
[0055] Step S202: Analyze the first guidance information using the first artificial intelligence model to generate the first access scheme for the first security tool.
[0056] In embodiments of this disclosure, a first access scheme for a first security tool is generated by a first artificial intelligence model. Considering that the first guidance information typically describes content related to the access of the first security tool in natural language (e.g., interface information, code information, etc.), the first artificial intelligence model can have natural language processing capabilities, enabling it to understand the meaning of natural language and handle different types of natural language tasks. The first artificial intelligence model can also have multimodal information processing capabilities, enabling it to understand the meaning of multimodal information and handle different types of multimodal tasks.
[0057] By leveraging the natural language processing capabilities of the first artificial intelligence model, the first guidance information of the first security tool is analyzed, and a first access scheme for invoking the first security tool is generated.
[0058] In some possible implementations, the first AI model can generate a first access scheme based on prompt learning technology, according to a first prompt word. The prompt word can be used to guide the AI model to make specific outputs in generative tasks (such as text generation tasks, question answering tasks, and dialogue tasks). By configuring the prompt word, the AI model can understand the background and requirements of the task, enabling the AI model to handle different types of processing tasks without retraining the AI model, thereby increasing the scalability and flexibility of the AI model.
[0059] For example, generating a first prompt word, sending the first prompt word to a first artificial intelligence model, and receiving the first access scheme of the first security tool returned by the first artificial intelligence model.
[0060] The first prompt may include: first guidance information and prompt information for instructing the generation of an access scheme for the first security tool. For example, the prompt information for instructing the generation of an access scheme for the first security tool may be: prompt information for instructing the first artificial intelligence model to generate a first access scheme for invoking the first security tool based on the first guidance information.
[0061] Figure 3 The illustration shows a flowchart of another security tool access method for a security protection system provided in at least one embodiment of the present disclosure.
[0062] like Figure 3 As shown, in some embodiments, first reference information can also be obtained from a knowledge base.
[0063] In this disclosure, the knowledge base can be understood as a database storing knowledge information related to the access of security tools. For example, the knowledge base may store access schemes for different security tools. The implementation of this disclosure does not limit the form and implementation of the knowledge base. The first reference information can be understood as knowledge information related to the first security tool obtained from the knowledge base. For example, the first reference information includes at least one of the following: network search results related to calling the first security tool and historical access schemes of the first security tool.
[0064] In other words, the first reference information can be information existing on the network that is related to accessing the first security tool. For example, the first reference information can be a question and answer post in a forum. The first reference information can also be the previous access schemes of the first security tool. For example, the first reference information can be the access scheme corresponding to a previous version of the first security tool.
[0065] The embodiments of this disclosure do not limit the method of obtaining the first reference information from the knowledge base. For example, the first security tool can be used as an index to search the knowledge base, obtain the search results, and then select the search results belonging to the network search results and / or historical access schemes as the first reference information.
[0066] By obtaining first reference information from the knowledge base, more knowledge related to connecting the first security tool to the security protection system can be obtained. In this case, the first prompt word may also include the first reference information. The prompt information used to indicate the generation of the access scheme for the first security tool may be: prompt information used to instruct the first artificial intelligence model to generate a first access scheme for calling the first security tool based on the first guidance information and the first reference information.
[0067] In other words, by constructing a knowledge base, the knowledge information stored in the knowledge base is used as reference information for the first artificial intelligence model during the process of generating access solutions. This allows the first artificial intelligence model to generate the first access solution with the help of the reference information, thereby improving the generation quality of the first artificial intelligence model.
[0068] By sending the first prompt word to the first artificial intelligence model, the first artificial intelligence model can analyze the first guidance information and determine the information related to calling the first security tool (such as interface information) by leveraging the prompt word's prompting capabilities, and generate the first access scheme for the first security tool.
[0069] In the embodiments of this disclosure, the first access scheme can be used to invoke the first security tool. In other words, the first access scheme can be understood as the invocation code of the first security tool. For example, the first access scheme may include code for passing data to the first security tool, code for invoking the API of the first security tool, code for receiving data returned by the first security tool, code for further processing the data returned by the first security tool, etc.
[0070] By leveraging the artificial intelligence capabilities of the first artificial intelligence model, the first guidance information of the first security tool is automatically analyzed, and then the first access scheme for calling the first security tool is automatically generated, enabling the first security tool to automatically access the security protection system. This is applicable to the access of first security tools of different types, functions, and protocols.
[0071] Furthermore, after the first artificial intelligence model returns the first access scheme of the first security tool, the first access scheme can be associated with the identification information of the first security tool and stored in the knowledge base.
[0072] For example, the identification information of the first security tool and the first access scheme are stored in a knowledge base in the form of key-value pairs; for example, in the knowledge base, the identification information of the first security tool is the key and the first access scheme is the value.
[0073] In this way, the newly generated first access scheme is stored as knowledge information in the knowledge base. During the subsequent access process of security tools, it serves as reference information for the first artificial intelligence model, thereby improving the quality of the subsequently generated access schemes and forming a closed-loop optimization logic.
[0074] Considering that different security tools have different data output formats, that is, the data returned by different security tools may be in different formats, in at least one embodiment of this disclosure, in order to facilitate unified management and subsequent alarm analysis or alarm handling, the data output format of the security tools connected to the security protection system can also be converted.
[0075] In some embodiments, the data output format of the first security tool may be a non-target format, which can be understood as a format other than the target format, and the target format can be understood as the format that needs to be converted.
[0076] In this case, the first prompt may further include: a prompt message indicating that code for converting the data output format should be added to the access scheme of the first security tool. That is, when the data output format of the first security tool itself is not the target format, a prompt message indicating that code for converting the data output format should be added to the first prompt message is included. For example, a prompt message indicating that code should be generated to convert the data output by the first security tool into the target format is added, facilitating the standardization of the data output formats of different security tools accessed by the security protection system.
[0077] By adding the aforementioned prompt information to the first prompt word and sending the first prompt word to the first artificial intelligence model, the first artificial intelligence model can, based on the prompting capability of the first prompt word, add code for converting the data output format to the first access scheme of the output first security tool. That is, the first access scheme may include: code for converting a non-target format to a target format.
[0078] Thus, when the first security tool is invoked using the first access scheme, the data output by the first security tool can be converted from a non-target format to the target format because the first access scheme contains code for data output format conversion. In this way, on the one hand, the access schemes of each security tool connected to the security protection system all include code for data output format conversion, ensuring that the data output by each security tool is ultimately converted to the target format, achieving unified management of the data output format for security tools; on the other hand, performing data output format conversion at the security tool's access layer is more efficient than performing format conversion at the business layer, and can avoid business errors caused by inconsistent data output formats.
[0079] See also Figure 3 In at least one embodiment of this disclosure, the first access scheme for the first security tool output by the first artificial intelligence model can be modified according to the operating conditions, which will be described below.
[0080] S203: Obtain the first runtime log.
[0081] The first operational log may include: operational logs generated by calling the first security tool based on the first access scheme. In other words, after the first artificial intelligence model returns the first access scheme, the first access scheme is actually run, and the first operational log is used to determine whether the first access scheme can be actually used, whether it meets expectations, and whether there are redundant steps, etc.
[0082] S204: In response to the first operation log indicating that there is a logical error in the first access scheme, the second artificial intelligence model is used to analyze the first operation log to determine the corrected first access scheme.
[0083] If the first operation log indicates that the first access scheme has a logical error, that is, the first access scheme cannot run or the verification of the first access scheme fails, then the second artificial intelligence model is used to automatically correct the first access scheme.
[0084] Similar to the first AI model, the second AI model can have natural language processing capabilities, be able to understand the meaning of natural language, and handle different types of natural language tasks. The second AI model can also have multimodal information processing capabilities, be able to understand the meaning of multimodal information, and handle different types of multimodal tasks. The second AI model can also be based on cue learning technology to modify the first access scheme according to the second cue word.
[0085] It should be noted that in some embodiments, the second artificial intelligence model may be the same as the first artificial intelligence model, or in other embodiments, it may be a different model from the first artificial intelligence model.
[0086] For example, a second prompt word is generated, the second prompt word is sent to a second artificial intelligence model, and the corrected first access scheme is received from the second artificial intelligence model.
[0087] The second prompt word may include: a first operation log, a first access scheme, and prompting information indicating that the first access scheme should be corrected based on the first operation log. For example, the prompting information indicating that the first access scheme should be corrected based on the first operation log could be: prompting information indicating that the first access scheme should be corrected based on the analysis of the first operation log to find out the cause of the logical error. Thus, by sending the second prompt word to the second artificial intelligence model, the second artificial intelligence model can analyze the first operation log, determine the logical error in the first access scheme, correct it, and output the corrected first access scheme, ensuring the operability and correctness of the first access scheme, enabling the security protection system to successfully connect to the first security tool.
[0088] In some other possible implementations, based on the first operation log, the fault data of the first security tool and the state parameters associated with the fault data are determined. Then, the fault data of the first security tool and the state parameters associated with the fault data are analyzed using a third language model to determine the second access scheme of the first security tool.
[0089] The fault data of the first security tool can be understood as the operation log in the first operation log that represents the failure caused by calling the first security tool. For example, when there is an error message in the first operation log, the operation log corresponding to the error message can be the fault data of the first security tool.
[0090] The state parameters associated with fault data can be understood as the state parameters at the time the fault data was generated. In some embodiments, the state parameters associated with fault data include at least one of the following: state parameters associated with fault data that characterize the network state; and state parameters associated with fault data that characterize the operational state of the first security tool.
[0091] In other words, in at least one embodiment of this disclosure, in addition to determining the operation log that caused the failure from the actual use of the first security tool, the network status parameters and operation status parameters of the first security tool at the time of the failure will also be determined. For example, the status parameters associated with the failure data and characterizing the network status can be network stability parameters, and the status parameters associated with the failure data and characterizing the operation status of the first security tool can be load status parameters of the first security tool.
[0092] By acquiring the operation logs that caused the failure, as well as the network status parameters and operation status parameters of the first security tool at the time of the failure, it is helpful to accurately determine the cause of the failure when calling the first security tool (e.g., the operation did not meet expectations). Then, the third artificial intelligence model can be used to make targeted and evidence-based corrections to the first access scheme of the first security tool.
[0093] Similar to the first AI model, the third AI model can have natural language processing capabilities, understand the meaning of natural language, and handle different types of natural language tasks. The third AI model can also have multimodal information processing capabilities, understand the meaning of multimodal information, and handle different types of multimodal tasks. The third AI model can also use prompting learning technology to modify the first access scheme based on the third prompt word and generate a new second access scheme. This second access scheme, as the modified first access scheme, can also be used to call the first security tool.
[0094] It should be noted that in some embodiments, the third artificial intelligence model may be the same model as the first artificial intelligence model, or in other embodiments, it may be a different model from the first artificial intelligence model.
[0095] For example, a third prompt word is generated, the third prompt word is sent to a third artificial intelligence model, and the second access scheme of the first security tool is received from the third artificial intelligence model.
[0096] The third prompt can include: the first access scheme, fault data of the first security tool, status parameters associated with the fault data, and prompting information to indicate the correction of the first access scheme. For example, the prompting information to indicate the correction of the first access scheme could be: prompting information to analyze the content that can be optimized in the first access scheme based on the fault data of the first security tool and the status parameters associated with the fault data, and to optimize and correct the first access scheme. Thus, by sending the third prompt to the third artificial intelligence model, the third artificial intelligence model can analyze the fault data of the first security tool and the status parameters associated with the fault data, determine the content in the first access scheme related to the occurrence of the fault, correct the content in the first access scheme related to the occurrence of the fault, output the second access scheme, and optimize the calling logic of the first security tool.
[0097] In some embodiments, for the fault data of the first security tool and the state parameters associated with the fault data, the second access scheme adds code to prevent the occurrence of faults. For example, when the fault data of the first security tool and the state parameters associated with the fault data indicate that there is an API with occasional timeout problems in the first security tool, the second access scheme adds a dynamic retry mechanism and a timeout degradation strategy; or, for example, when the fault data of the first security tool and the state parameters associated with the fault data indicate that there is a call frequency limit for the first security tool, the second access scheme configures a request time window to avoid triggering the limit.
[0098] In some other possible implementations, the status information of the first security tool is detected, and in response to a change in the status information of the first security tool, second guidance information of the first security tool is obtained. Then, the second guidance information is analyzed using a fourth artificial intelligence model to generate a third access scheme for the first security tool.
[0099] The status information of the first security tool can be used to determine whether the first security tool has changed. For example, the status information of the first security tool can be the version identifier of the first security tool, or it can be the guidance information of the first security tool.
[0100] A change in the status information of the first security tool can be understood as a change in the first security tool itself. When the first security tool changes, it indicates that the original access scheme may no longer be applicable. Therefore, the second guidance information of the first security tool is obtained, that is, the guidance information after the first security tool changes.
[0101] For example, in response to a change in the version identifier of the first security tool (e.g., a new version of the first security tool is released), second guidance information for the first security tool is obtained; or, in response to a change in the first guidance information for the first security tool, second guidance information for the first security tool is obtained.
[0102] In other words, when the version identifier of the first security tool changes, it indicates that the first security tool has undergone a version iteration. At this time, the guidance information of the first security tool may also change. Therefore, the second guidance information of the first security tool is obtained so that the access scheme of the first security tool can be updated using the fourth artificial intelligence model. When the first guidance information of the first security tool changes, it indicates that some guidance information of the first security tool has changed, such as the interface of the first security tool has changed. In this case, the second guidance information of the first security tool is obtained so that the access scheme of the first security tool can be corrected using the fourth artificial intelligence model.
[0103] Similar to the first AI model, the fourth AI model can have natural language processing capabilities, understand the meaning of natural language, and handle different types of natural language tasks. The fourth AI model can also have multimodal information processing capabilities, understand the meaning of multimodal information, and handle different types of multimodal tasks. The fourth AI model can also update the first access scheme based on the fourth prompt word using prompt learning technology to generate a new third access scheme. This third access scheme, as a modified first access scheme, can also be used to call the first security tool.
[0104] It should be noted that in some embodiments, the fourth artificial intelligence model may be the same as the first artificial intelligence model, or in other embodiments, it may be a different model from the first artificial intelligence model.
[0105] For example, a fourth prompt word is generated, the fourth prompt word is sent to the fourth artificial intelligence model, and the third access scheme of the first security tool is received from the fourth artificial intelligence model.
[0106] The fourth prompt can include: first guidance information, second guidance information, a first access scheme, and prompts indicating that the first access scheme should be corrected based on the differences between the first and second guidance information. For example, prompts indicating that the first access scheme should be updated based on the differences between the first and second guidance information could be prompts indicating that the affected content in the first access scheme should be reconstructed based on the differences between the first and second guidance information. Thus, by sending the fourth prompt to the fourth AI model, the fourth AI model can compare the first and second guidance information, determine the differences in the guidance information before and after the change of the first security tool, identify the content in the first access scheme related to the differences, correct the content in the first access scheme related to the differences based on the second guidance information, and output a third access scheme. This ensures that the access scheme of the first security tool remains consistent with the current state of the first security tool, achieving adaptive adjustment and automated version management of the access scheme of the first security tool.
[0107] As described above, in at least one embodiment of this disclosure, an artificial intelligence model is used to automatically generate and correct access schemes for security tools. Furthermore, a database of knowledge information related to security tool access is constructed, storing access schemes for different security tools and versions. Thus, during the actual operation of the security protection system, different security tools can be invoked to perform alarm analysis and alarm handling.
[0108] In some embodiments, a first alarm message is received, and based on the description information of multiple candidate security tools, multiple target security tools and the invocation order of the multiple target security tools are determined from the multiple candidate security tools. Then, in response to the multiple target security tools including a first security tool, a first access scheme of the first security tool is obtained.
[0109] The first alarm information can be understood as the alarm information detected by the security protection system that is pending alarm analysis and alarm handling. Since the security protection system accesses different types and functions of candidate security tools, it analyzes the capabilities of multiple candidate security tools through their description information, selects the target security tool that can be used to handle the first alarm information from among the multiple candidate security tools, and determines the calling order of multiple target security tools to form a security tool calling chain.
[0110] At least one embodiment of this disclosure does not limit the method for determining multiple target security tools and their invocation order. For example, an artificial intelligence model can be used to analyze the descriptive information (e.g., functional description information) of multiple candidate security tools to determine the target security tools that can be used for alarm analysis of the first alarm information and their invocation order. Alternatively, the descriptive information of the multiple candidate security tools may include the correspondence between candidate security tools and keywords, as well as the set invocation order of the multiple candidate security tools. The first alarm information is matched with the keywords corresponding to each candidate security tool, and the candidate security tools corresponding to the matched keywords are determined as target security tools. The invocation order of the multiple target security tools is then determined according to the set invocation order of the multiple candidate security tools.
[0111] Next, when the target security tool includes a first security tool, a first access scheme for the first security tool is determined from the knowledge base. This first access scheme can be used to generate call code for alarm analysis of the first alarm information based on the calling order of multiple target security tools. In other words, the access schemes corresponding to the multiple target security tools are combined according to the calling order of the multiple target security tools to form call code, so that the call code can be used to call multiple target security tools for alarm analysis.
[0112] For example, the first alert information can involve the entire chain of a network attack event. Multiple target security tools can include log analysis tools, threat intelligence tools, sandbox tools, and asset mapping tools. The order in which these tools are invoked can be: first, the log analysis tool is invoked to extract the attack timeline; then, the threat intelligence tool is invoked to verify the associated Internet Protocol (IP) addresses; next, the sandbox tool is invoked to reproduce the malicious code behavior; and finally, the asset mapping tool is invoked to locate the affected area. The first invocation code includes code for invoking the aforementioned target security tools, code for passing parameters within these tools, and code for generating the final alert analysis results.
[0113] In this way, during the actual use of the security protection system, the calling code for calling various security tools is automatically constructed, realizing the automatic calling of the security tool calling chain, thereby realizing the automatic analysis of alarm information and improving the resource utilization efficiency and adaptability of the security protection system to diverse security tools.
[0114] Based on the security tool access method for a security protection system provided in at least one embodiment of this disclosure, at least one embodiment of this disclosure also provides a security tool access device for a security protection system. The following will be combined with... Figure 4 This security tool access device used in the security protection system is described in detail.
[0115] Figure 4 The illustration shows a schematic diagram of a security tool access device for a security protection system provided in at least one embodiment of the present disclosure.
[0116] like Figure 4 As shown, the security tool access device 400 for a security protection system in this embodiment includes a first acquisition module 401, a generation module 402, a second acquisition module 403, and a verification module 404. For example, these units or modules can be implemented by hardware (e.g., circuit) modules or software modules, as is the case in the following embodiments, and will not be repeated here. For example, these units or modules can be implemented by a central processing unit (CPU), a general-purpose graphics processor (GPGPU), a graphics processing unit (GPU), a tensor processor (TPU), a field-programmable gate array (FPGA), or other forms of processing units with data processing capabilities and / or instruction execution capabilities, along with corresponding computer instructions.
[0117] The first acquisition module 401 is configured to acquire first guidance information of the first security tool. For example, the first acquisition module 401 can be configured to execute step S201 described above. The specific implementation principle can be referred to the relevant description of step S201, which will not be repeated here.
[0118] The generation module 402 is configured to: analyze the first guidance information using a first artificial intelligence model to generate a first access scheme for the first security tool, wherein the first access scheme is used to invoke the first security tool. For example, the generation module 402 can be configured to execute step S202 described above; its specific implementation principle can be found in the relevant description of step S202, and will not be repeated here.
[0119] The second acquisition module 403 is configured to acquire a first operation log, wherein the first operation log includes an operation log generated by calling the first security tool based on the first access scheme. For example, the second acquisition module 403 can be configured to execute step S203 described above; its specific implementation principle can be found in the relevant description of step S203, and will not be repeated here.
[0120] The verification module 404 is configured to: in response to the first operation log indicating a logical error in the first access scheme, analyze the first operation log using a second artificial intelligence model to determine the corrected first access scheme. For example, the verification module 404 can be configured to execute step S204 described above; its specific implementation principle can be found in the relevant description of step S204, and will not be repeated here.
[0121] In at least one embodiment of this disclosure, the generation module 402 is further configured to: generate a first prompt word, wherein the first prompt word includes: the first guidance information and prompt information for indicating the generation of an access scheme for the first security tool; send the first prompt word to the first artificial intelligence model, and receive the first access scheme for the first security tool returned by the first artificial intelligence model.
[0122] In at least one embodiment of this disclosure, the first acquisition module 401 is further configured to: acquire first reference information from a knowledge base, wherein the first reference information includes at least one of the following: network search results related to calling the first security tool; historical access schemes of the first security tool; the first prompt word further includes: the first reference information.
[0123] In at least one embodiment of this disclosure, the security tool access device 400 for a security protection system further includes a storage module configured to associate the first access scheme with the identification information of the first security tool and store it in the knowledge base.
[0124] In at least one embodiment of this disclosure, the verification module 404 is further configured to: generate a second prompt word, wherein the second prompt word includes: the first operation log, the first access scheme, and prompt information for indicating that the first access scheme is corrected based on the first operation log; send the second prompt word to the second artificial intelligence model, and receive the corrected first access scheme returned by the second artificial intelligence model.
[0125] In at least one embodiment of this disclosure, the security tool access device 400 for a security protection system further includes a correction module configured to: determine fault data of the first security tool and state parameters associated with the fault data based on the first operation log; and analyze the fault data of the first security tool and the state parameters associated with the fault data using a third language model to determine a second access scheme for the first security tool.
[0126] In at least one embodiment of this disclosure, the correction module is further configured to: generate a third prompt word, wherein the third prompt word includes: the first access scheme, fault data of the first security tool, status parameters associated with the fault data, and prompt information for indicating correction of the first access scheme; send the third prompt word to a third artificial intelligence model, and receive a second access scheme of the first security tool returned by the third artificial intelligence model.
[0127] In at least one embodiment of this disclosure, the status parameters associated with the fault data include at least one of the following: status parameters associated with the fault data that characterize the network status; and status parameters associated with the fault data that characterize the operating status of the first security tool.
[0128] In at least one embodiment of this disclosure, the correction module is further configured to: detect the status information of the first security tool; in response to a change in the status information of the first security tool, obtain second guidance information of the first security tool; and analyze the second guidance information using a fourth artificial intelligence model to generate a third access scheme for the first security tool.
[0129] In at least one embodiment of this disclosure, the correction module is further configured to: generate a fourth prompt word, wherein the fourth prompt word includes: the first guidance information, the second guidance information, the first access scheme, and prompt information for indicating that the first access scheme should be corrected based on the difference between the first guidance information and the second guidance information; send the fourth prompt word to a fourth artificial intelligence model, and receive a third access scheme of the first security tool returned by the fourth artificial intelligence model.
[0130] In at least one embodiment of this disclosure, the correction module is further configured to: obtain second guidance information of the first security tool in response to a change in the version identifier of the first security tool; or obtain second guidance information of the first security tool in response to a change in the first guidance information of the first security tool.
[0131] In at least one embodiment of this disclosure, the data output format of the first security tool is a non-target format; the first prompt word further includes: prompt information for indicating that code for converting the data output format is added to the access scheme of the first security tool; the first access scheme includes: code for converting the non-target format to the target format.
[0132] In at least one embodiment of this disclosure, the security tool access device 400 for a security protection system further includes a third acquisition module, which is configured to: receive first alarm information; determine multiple target security tools and their invocation order from the multiple candidate security tools based on description information of multiple candidate security tools; and, in response to the multiple target security tools including the first security tool, acquire a first access scheme for the first security tool, wherein the first access scheme for the first security tool is used to generate invocation code for alarm analysis of the first alarm information based on the invocation order of the multiple target security tools.
[0133] It should be noted that, for clarity and brevity, this disclosure does not show all the constituent units of the security tool access device 400 for a security protection system. To achieve the necessary functions of this device, those skilled in the art can provide or configure other constituent units (not shown) according to specific needs, and this disclosure does not impose any limitations on this.
[0134] At least one embodiment of this disclosure also provides an electronic device, including: a processing device; a storage device including one or more computer program modules; wherein the one or more computer program modules are stored in the storage device and configured to be executed by the processing device, and the one or more computer program modules are used to implement the security tool access method provided in any embodiment of this disclosure.
[0135] For example, the processing device may be a central processing unit (CPU), digital signal processor (DSP), image processor (GPU), general-purpose graphics processor (GPGPU), or other form of processing unit with data processing capabilities and / or instruction execution capabilities. It may be a general-purpose processor or a dedicated processor and may control other components in the electronic device to perform the desired functions.
[0136] For example, the storage device may include one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may, for example, include random access memory (RAM) and / or cache memory. The non-volatile memory may, for example, include read-only memory (ROM), hard disk, flash memory, etc. One or more computer program instructions may be stored on the computer-readable storage medium, and a processing device may execute these program instructions to implement the functions (implemented by the processing device) in the embodiments of this disclosure and / or other desired functions. Various application programs and various data may also be stored in the computer-readable storage medium, which is not limited in the embodiments of this disclosure.
[0137] The following is for reference. Figure 5 The diagram illustrates a structural schematic of an electronic device (e.g., a terminal device or a server) 500 suitable for implementing embodiments of the present disclosure. The terminal device in the embodiments of the present disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 5 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments disclosed herein.
[0138] like Figure 5 As shown, the electronic device 500 may include a processing unit (e.g., a central processing unit, a graphics processor, etc.) 501, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 502 or a program loaded from a storage device 508 into a random access memory (RAM) 503. The RAM 503 also stores various programs and data required for the operation of the electronic device 500. The processing unit 501, ROM 502, and RAM 503 are interconnected via a bus 504. An input / output (I / O) interface 505 is also connected to the bus 504.
[0139] Typically, the following devices can be connected to I / O interface 505: input devices 506 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 507 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 508 including, for example, magnetic tapes, hard disks, etc.; and communication devices 509. Communication device 509 allows electronic device 500 to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 5 An electronic device 500 with various devices is shown; however, it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed alternatively.
[0140] In particular, according to embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device 509, or installed from a storage device 508, or installed from a ROM 502. When the computer program is executed by the processing device 501, it performs the functions defined in the methods of embodiments of this disclosure.
[0141] It should be noted that the computer-readable medium described in this disclosure can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this disclosure, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in connection with an instruction execution system, apparatus, or device. In this disclosure, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.
[0142] In some implementations, clients and servers can communicate using any currently known or future-developed network protocol such as HTTP (Hypertext Transfer Protocol) and can interconnect with digital data communication (e.g., communication networks) of any form or medium. Examples of communication networks include local area networks (“LANs”), wide area networks (“WANs”), the Internet (e.g., the Internet of Things), and end-to-end networks (e.g., ad hoc end-to-end networks), as well as any currently known or future-developed networks.
[0143] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device.
[0144] The aforementioned computer-readable medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to: acquire first guidance information of a first security tool; analyze the first guidance information using a first artificial intelligence model to generate a first access scheme for the first security tool; acquire a first operation log; and, in response to the first operation log indicating a logical error in the first access scheme, analyze the first operation log using a second artificial intelligence model to determine a corrected first access scheme.
[0145] Computer program code for performing the operations of this disclosure can be written in one or more programming languages or a combination thereof, including but not limited to object-oriented programming languages such as Java, Smalltalk, and C++, as well as conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0146] Embodiments of this disclosure also provide a computer program product comprising one or more computer instructions. When the computer instructions are loaded and executed on a computing device, all or part of the processes or functions described in any embodiment of this disclosure are generated.
[0147] The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, or data center to another website, computer, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means.
[0148] When the computer program product is executed by a computer, the computer executes any of the aforementioned security tool access methods. The computer program product can be a software installation package; when any of the aforementioned security tool access methods is required, the computer program product can be downloaded and executed on the computer.
[0149] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0150] The units or modules described in the embodiments of this disclosure can be implemented in software or hardware. The names of the units or modules do not necessarily constitute a limitation on the unit or module itself.
[0151] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: Field Programmable Gate Arrays (FPGAs), Application-Specific Integrated Circuits (ASICs), Application Standard Products (ASSPs), System-on-Chip (SoCs), Complex Programmable Logic Devices (CPLDs), and so on.
[0152] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0153] According to one or more embodiments of this disclosure, Example 1 provides a method for accessing security tools in a security protection system, including:
[0154] Obtain first guidance information for the first security tool;
[0155] The first guidance information is analyzed using a first artificial intelligence model to generate a first access scheme for the first security tool, wherein the first access scheme is used to invoke the first security tool;
[0156] Obtain the first operation log, wherein the first operation log includes: the operation log generated by calling the first security tool based on the first access scheme;
[0157] In response to the first operation log indicating a logical error in the first access scheme, the second artificial intelligence model is used to analyze the first operation log and determine the corrected first access scheme.
[0158] According to one or more embodiments of this disclosure, Example 2 provides a first access scheme for the first security tool, which utilizes a first artificial intelligence model to analyze the first guidance information and generate the first access scheme, as described in Example 1.
[0159] Generate a first prompt word, wherein the first prompt word includes: the first guidance information and prompt information for instructing the access scheme for generating the first security tool;
[0160] The first prompt word is sent to the first artificial intelligence model, and the first access scheme of the first security tool is received from the first artificial intelligence model.
[0161] According to one or more embodiments of this disclosure, Example 3 provides the method of Example 1, further comprising:
[0162] Obtain first reference information from a knowledge base, wherein the first reference information includes at least one of the following:
[0163] Web search results related to calling the first security tool;
[0164] The historical access scheme of the first security tool;
[0165] The first prompt word also includes: the first reference information.
[0166] According to one or more embodiments of this disclosure, Example 4 provides the method of Example 3, further comprising:
[0167] The identification information of the first access scheme and the first security tool is associated and stored in the knowledge base.
[0168] According to one or more embodiments of this disclosure, Example 5 provides the method of analyzing the first operation log using a second artificial intelligence model as in Example 1 to determine the corrected first access scheme, including:
[0169] Generate a second prompt word, wherein the second prompt word includes: the first operation log, the first access scheme, and prompt information for indicating that the first access scheme should be corrected based on the first operation log;
[0170] The second prompt word is sent to the second artificial intelligence model, and the corrected first access scheme is received from the second artificial intelligence model.
[0171] According to one or more embodiments of this disclosure, Example Six provides the method of Example One, further comprising:
[0172] Based on the first operation log, determine the fault data of the first security tool and the status parameters associated with the fault data;
[0173] By using a third language model to analyze the fault data of the first security tool and the state parameters associated with the fault data, a second access scheme for the first security tool is determined.
[0174] According to one or more embodiments of this disclosure, Example 7 provides the method of analyzing fault data of the first security tool and state parameters associated with the fault data using a third language model, as in Example 6, to determine a second access scheme for the first security tool, including:
[0175] Generate a third prompt word, wherein the third prompt word includes: the first access scheme, the fault data of the first security tool, the status parameter associated with the fault data, and prompt information for indicating that the first access scheme should be corrected;
[0176] The third prompt word is sent to the third artificial intelligence model, and the second access scheme of the first security tool is received from the third artificial intelligence model.
[0177] According to one or more embodiments of this disclosure, Example 8 provides the status parameters associated with the fault data in Example 7, including at least one of the following:
[0178] State parameters that characterize the network state and are associated with the fault data;
[0179] Status parameters associated with the fault data that characterize the operational status of the first safety tool.
[0180] According to one or more embodiments of this disclosure, Example Nine provides the method of Example One, further comprising:
[0181] Detect the status information of the first security tool;
[0182] In response to a change in the status information of the first security tool, second guidance information of the first security tool is obtained;
[0183] The second known information is analyzed using a fourth artificial intelligence model to generate a third access scheme for the first security tool.
[0184] According to one or more embodiments of this disclosure, Example 10 provides the method of analyzing the second known information using a fourth artificial intelligence model, as in Example 9, to generate a third access scheme for the first security tool, including:
[0185] Generate a fourth prompt word, wherein the fourth prompt word includes: the first guidance information, the second guidance information, the first access scheme, and prompt information for indicating that the first access scheme should be corrected based on the difference between the first guidance information and the second guidance information;
[0186] The fourth prompt word is sent to the fourth artificial intelligence model, and the third access scheme of the first security tool is received from the fourth artificial intelligence model.
[0187] According to one or more embodiments of this disclosure, Example 11 provides, as in Example 9, obtaining second guidance information for the first security tool in response to a change in the status information of the first security tool, including:
[0188] In response to a change in the version identifier of the first security tool, obtain second guidance information for the first security tool; or
[0189] In response to a change in the first guidance information of the first security tool, the second guidance information of the first security tool is obtained.
[0190] According to one or more embodiments of this disclosure, Example Twelve provides that the data output format of the first security tool in Example One is a non-target format;
[0191] The first prompt word also includes: a prompt message indicating that code for converting data output format should be added to the access scheme of the first security tool;
[0192] The first access scheme includes code for converting the non-target format to the target format.
[0193] According to one or more embodiments of this disclosure, Example Thirteen provides a method from any of Examples One to Twelve, further comprising:
[0194] Receive the first alarm message;
[0195] Based on the description information of multiple candidate security tools, determine multiple target security tools and the invocation order of the multiple target security tools from the multiple candidate security tools;
[0196] In response to the plurality of target security tools including the first security tool, a first access scheme for the first security tool is obtained, wherein the first access scheme for the first security tool is used to generate call code for alarm analysis of the first alarm information based on the calling order of the plurality of target security tools.
[0197] According to one or more embodiments of this disclosure, Example Fourteen provides a security tool access device for a security protection system, comprising:
[0198] The first acquisition module is configured to: acquire the first guidance information of the first security tool;
[0199] The generation module is configured to: analyze the first guidance information using a first artificial intelligence model to generate a first access scheme for the first security tool, wherein the first access scheme is used to invoke the first security tool;
[0200] The second acquisition module is configured to acquire a first operation log, wherein the first operation log includes: an operation log generated by calling the first security tool based on the first access scheme;
[0201] The verification module is configured to: in response to the first operation log indicating that there is a logical error in the first access scheme, analyze the first operation log using a second artificial intelligence model to determine the corrected first access scheme.
[0202] According to one or more embodiments of this disclosure, Example Fifteen provides an electronic device, including:
[0203] Processing device; and
[0204] Storage device, including one or more computer program instructions;
[0205] The one or more computer program instructions are executed by a processing device to perform the security tool access method for a security protection system provided in at least one embodiment of the present disclosure.
[0206] According to one or more embodiments of the present disclosure, Example Sixteen provides a computer-readable storage medium that non-transitory stores computer-readable instructions, wherein when the computer-readable instructions are executed by a processor, they implement the security tool access method for a security protection system provided in at least one embodiment of the present disclosure.
[0207] The above description is merely a preferred embodiment of this disclosure and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features disclosed in this disclosure that have similar functions.
[0208] Furthermore, while the operations are described in a specific order, this should not be construed as requiring these operations to be performed in the specific order shown or in a sequential order. In certain environments, multitasking and parallel processing may be advantageous. Similarly, while several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of this disclosure. Certain features described in the context of individual embodiments may also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments.
[0209] Although the subject matter has been described using language specific to structural features and / or methodological logic, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are merely illustrative examples of implementing the claims.
Claims
1. A method for accessing security tools in a security protection system, comprising: Obtain first guidance information for the first security tool; The first guidance information is analyzed using a first artificial intelligence model to generate a first access scheme for the first security tool, wherein the first access scheme is used to invoke the first security tool; Obtain the first operation log, wherein the first operation log includes: the operation log generated by calling the first security tool based on the first access scheme; In response to the first operation log indicating a logical error in the first access scheme, the second artificial intelligence model is used to analyze the first operation log and determine the corrected first access scheme.
2. The method according to claim 1, wherein, The step of analyzing the first guidance information using a first artificial intelligence model to generate a first access scheme for the first security tool includes: Generate a first prompt word, wherein the first prompt word includes: the first guidance information and prompt information for instructing the access scheme for generating the first security tool; The first prompt word is sent to the first artificial intelligence model, and the first access scheme of the first security tool is received from the first artificial intelligence model.
3. The method according to claim 1, further comprising: Obtain first reference information from a knowledge base, wherein the first reference information includes at least one of the following: Web search results related to calling the first security tool; The historical access scheme of the first security tool; The first prompt word also includes: the first reference information.
4. The method according to claim 3, further comprising: The identification information of the first access scheme and the first security tool is associated and stored in the knowledge base.
5. The method according to claim 1, wherein, The step of analyzing the first operation log using a second artificial intelligence model to determine the corrected first access scheme includes: Generate a second prompt word, wherein the second prompt word includes: the first operation log, the first access scheme, and prompt information for indicating that the first access scheme should be corrected based on the first operation log; The second prompt word is sent to the second artificial intelligence model, and the corrected first access scheme is received from the second artificial intelligence model.
6. The method according to claim 1, further comprising: Based on the first operation log, determine the fault data of the first security tool and the status parameters associated with the fault data; By using a third language model to analyze the fault data of the first security tool and the state parameters associated with the fault data, a second access scheme for the first security tool is determined.
7. The method according to claim 6, wherein, The step of analyzing the fault data of the first security tool and the state parameters associated with the fault data using a third language model to determine the second access scheme for the first security tool includes: Generate a third prompt word, wherein the third prompt word includes: the first access scheme, the fault data of the first security tool, the status parameter associated with the fault data, and prompt information for indicating that the first access scheme should be corrected; The third prompt word is sent to the third artificial intelligence model, and the second access scheme of the first security tool is received from the third artificial intelligence model.
8. The method according to claim 7, wherein, The status parameters associated with the fault data include at least one of the following: State parameters that characterize the network state and are associated with the fault data; Status parameters associated with the fault data that characterize the operational status of the first safety tool.
9. The method according to claim 1, further comprising: Detect the status information of the first security tool; In response to a change in the status information of the first security tool, second guidance information of the first security tool is obtained; The second known information is analyzed using a fourth artificial intelligence model to generate a third access scheme for the first security tool.
10. The method according to claim 9, wherein, The step of analyzing the second known information using a fourth artificial intelligence model to generate a third access scheme for the first security tool includes: Generate a fourth prompt word, wherein the fourth prompt word includes: the first guidance information, the second guidance information, the first access scheme, and prompt information for indicating that the first access scheme should be corrected based on the difference between the first guidance information and the second guidance information; The fourth prompt word is sent to the fourth artificial intelligence model, and the third access scheme of the first security tool is received from the fourth artificial intelligence model.
11. The method according to claim 9, wherein, The step of obtaining second guidance information for the first security tool in response to a change in the status information of the first security tool includes: In response to a change in the version identifier of the first security tool, obtain second guidance information for the first security tool; or In response to a change in the first guidance information of the first security tool, the second guidance information of the first security tool is obtained.
12. The method according to claim 1, wherein, The data output format of the first security tool is a non-target format; The first prompt word also includes: a prompt message indicating that code for converting data output format should be added to the access scheme of the first security tool; The first access scheme includes code for converting the non-target format into the target format.
13. The method according to any one of claims 1 to 12, further comprising: Receive the first alarm message; Based on the description information of multiple candidate security tools, determine multiple target security tools and the invocation order of the multiple target security tools from the multiple candidate security tools; In response to the plurality of target security tools including the first security tool, a first access scheme for the first security tool is obtained, wherein the first access scheme for the first security tool is used to generate call code for alarm analysis of the first alarm information based on the calling order of the plurality of target security tools.
14. A security tool access device for a security protection system, comprising: The first acquisition module is configured to: acquire the first guidance information of the first security tool; The generation module is configured to: analyze the first guidance information using a first artificial intelligence model to generate a first access scheme for the first security tool, wherein the first access scheme is used to invoke the first security tool; The second acquisition module is configured to acquire a first operation log, wherein the first operation log includes: an operation log generated by calling the first security tool based on the first access scheme; The verification module is configured to: in response to the first operation log indicating that there is a logical error in the first access scheme, analyze the first operation log using a second artificial intelligence model to determine the corrected first access scheme.
15. An electronic device comprising: Processing device; as well as Storage device, including one or more computer program instructions; The one or more computer program instructions are executed by the processing device according to any one of claims 1 to 13.
16. A computer-readable storage medium for non-transitory storage of computer-readable instructions, wherein, The method of any one of claims 1 to 13 is implemented when the computer-readable instructions are executed by a processor.
Citation Information
Patent Citations
Secure access method and device for service product
CN114493370A
An integrated ai-driven system for automating it and cybersecurity operations
WO2024145209A1
Detecting and repairing reliability issues in operating systems and applications using a generative artificial intelligence system
WO2025029426A1
Cited By
Model-based application access method and device, equipment and medium
CN121636001A