Intelligent security operation method and device based on c4isr and electronic equipment
By constructing a large language model and a multi-agent collaborative architecture in the field of cybersecurity, the problem of handling massive alarm events in SOC was solved, global collaboration and proactive defense were achieved, risk assessment and response efficiency were improved, false alarm rate was reduced and situational awareness was enhanced.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-04-17
- Publication Date
- 2026-06-09
AI Technical Summary
Existing Security Operations Centers (SOCs) face challenges such as difficulty in handling massive alarm events, untimely and inaccurate risk assessment, and a lack of a global command and control model, resulting in high analytical pressure, high false alarm rates, and insufficient situational awareness.
Construct a large language model for the cybersecurity field and embed it into the existing security operations center. Establish a multi-agent mapping model based on C4ISR, design a multi-agent collaborative work architecture, formulate a closed-loop workflow for the multi-agent system, and design a layered and integrated security operations center platform architecture.
It improved the efficiency of risk assessment and response, achieved global collaboration and proactive defense, enhanced asset management and situational awareness capabilities, significantly reduced false alarm rates, and improved the accuracy of analysis and the timeliness of response.
Smart Images

Figure CN122179228A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information security technology, and in particular to intelligent security operation methods, devices and electronic devices based on C4ISR. Background Technology
[0002] To address the increasingly complex and frequent cyber anomaly risks, Security Operations Center (SOC) platforms have emerged. As the core hub of an organization's cybersecurity operations, they have become a major line of defense against evolving cybersecurity risks. Despite advancements in automation and artificial intelligence technologies and their application in SOCs, challenges remain regarding functional capabilities and manpower. Functional challenges include: a lack of automated asset discovery and continuous asset verification in asset management increases vulnerabilities and weakens situational awareness, exacerbated by log capture errors and insufficient storage, expanding the attack surface and thus introducing security risks. Manpower challenges primarily include continuous operational overload, alert fatigue, and analytical pressure. Analysts need to handle a large volume of alerts, many of which are false positives that may mask true potential risks.
[0003] In summary, the existing technical solutions have the following shortcomings: First, the massive number of alarm events and the ongoing risk assessment and handling are difficult to handle in a timely and accurate manner, necessitating the introduction of AI capabilities to further enhance the intelligent analysis, decision-making, and response capabilities of the security management platform.
[0004] Secondly, there is a lack of an overall command and control model or framework that can perform global fusion analysis of collected information from a system-wide perspective, unify planning and dynamically formulate strategies, as well as dynamic linkage control and real-time response to achieve proactive global defense. Summary of the Invention
[0005] To address the aforementioned technical problems, this invention provides an intelligent security operation method based on C4ISR, employing the following technical solution, including the following steps: Constructing a large language model for the cybersecurity field; The aforementioned large language model in the field of cybersecurity is used as the intelligent core and embedded into the existing security operations center; Establish a C4ISR-based multi-agent mapping model; Based on the aforementioned multi-agent mapping model, a multi-agent collaborative working architecture is designed. Develop a closed-loop workflow for multi-agent systems; Design a layered and integrated security operations center platform architecture.
[0006] Preferably, the step of constructing a large language model in the field of cybersecurity specifically includes: Build a knowledge base in the field of cybersecurity; Based on the aforementioned cybersecurity knowledge base, knowledge distillation data is generated; Based on the knowledge distillation data, the student model is fine-tuned, trained, and optimized.
[0007] Preferably, the step of embedding the large language model in the cybersecurity field as the intelligent core into the existing security operations center specifically includes: Based on the aforementioned large language model in the field of network security, automated log and anomaly analysis is performed; Using the aforementioned large language model in the field of network security, structured security early warning information is extracted, correlated, and generated from multi-source heterogeneous anomaly information data; Based on the aforementioned large language model in the field of network security, automated incident response is performed, generating incident reports, response suggestions, and execution scripts.
[0008] Preferably, the step of establishing a C4ISR-based multi-agent mapping model specifically includes: Establish semantic mappings from C4ISR elements to cybersecurity intelligent agents; Each intelligent agent is endowed with AI capabilities and domain knowledge, enabling it to independently complete its assigned tasks while also having interfaces to collaborate with other intelligent agents. Integrate a multi-agent management platform.
[0009] Preferably, the step of designing a multi-agent collaborative working architecture based on the multi-agent mapping model specifically includes: Based on the multi-agent mapping model, design the internal cognitive architecture of the agent; Design a multi-agent cooperation protocol; Enables intelligent agents to reflect and learn continuously.
[0010] Preferably, the step of formulating the closed-loop workflow of the multi-agent system specifically includes: Perform intent recognition and task initialization on the intelligent agent; The task is broken down into subtasks that can be executed in parallel or sequentially by different agents, and the dependencies and execution order are determined. Multiple agents are scheduled to execute subtasks in parallel or serially, the results of task execution are collected and integrated into the final output, and feedback is recorded for optimization.
[0011] Preferably, the steps of designing the layered and integrated security operations center platform architecture specifically include: Design object layer and data acquisition and preprocessing layer; Design a large language model support layer and an intelligent security operation service layer in the fields of AI and cybersecurity; Design the user interaction layer and the response execution layer.
[0012] To address the aforementioned technical problems, this invention also provides an intelligent security operation device based on C4ISR, employing the following technical solution, including: Modules for building large language models in the cybersecurity field; An embedding module is used to embed the large language model in the cybersecurity field as an intelligent core into the existing security operations center; A module is established to build a C4ISR-based multi-agent mapping model; The design module is used to design a multi-agent collaborative architecture based on the multi-agent mapping model. The module is used to define the closed-loop workflow of a multi-agent system. The integration module is used to design a layered and integrated security operations center platform architecture.
[0013] To address the aforementioned technical problems, the present invention also provides an electronic device that employs the technical solution described below, comprising a memory and a processor. The memory stores computer-readable instructions, and the processor executes the computer-readable instructions to implement the steps of the aforementioned intelligent security operation method based on C4ISR.
[0014] To address the aforementioned technical problems, the present invention also provides a computer-readable storage medium, which employs the technical solution described below. The computer-readable storage medium stores computer-readable instructions, which, when executed by a processor, implement the steps of the aforementioned intelligent security operation method based on C4ISR.
[0015] Compared with the prior art, the present invention has the following main advantages: (1) Improved risk assessment and response efficiency: By introducing a large language model in the field of network security as the core of intelligence, it can automatically understand, associate and assess security events, significantly reduce false alarm rate, assist or replace manual preliminary analysis and decision-making, thereby alleviating alarm fatigue and analysis pressure, and improving response timeliness and accuracy.
[0016] (2) Achieved global collaboration and proactive defense: Based on the C4ISR (command, control, communication, computer, intelligence and surveillance and reconnaissance) system, a multi-agent mapping model and collaborative architecture were constructed. Starting from the global system, integrated perception, unified planning, dynamic decision-making and real-time response were carried out to form a closed-loop workflow and achieve a leap from passive response to proactive defense.
[0017] (3) Enhanced asset management and situational awareness capabilities: Through a layered and integrated platform architecture and multi-agent collaboration, it supports automated asset discovery, continuous verification and log integrity monitoring, reduces the attack surface, improves the accuracy and real-time performance of situational awareness, and thus strengthens the overall security operation capabilities. Attached Figure Description
[0018] To more clearly illustrate the solutions in this invention, the accompanying drawings used in the description of the embodiments of this invention will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0019] Figure 1 This is a flowchart of an embodiment of the intelligent security operation method based on C4ISR of the present invention; Figure 2 This is a schematic diagram of the core architecture of the intelligent agent used in the C4ISR-based intelligent security operation method of the present invention; Figure 3 This is a flowchart of the multi-intelligent system workflow used in the C4ISR-based intelligent security operation method of the present invention. Figure 4 This is a schematic diagram showing the connection relationship between the user interaction layer, intelligent security operation service layer, AI and large language model support layer, data acquisition and preprocessing layer, object layer and corresponding execution layer used in the intelligent security operation method based on C4ISR of the present invention. Figure 5 This is a diagram showing the main components and functional modules of the AI and large language model support layer used in the C4ISR-based intelligent security operation method of this invention. Figure 6 This is a schematic diagram of the architecture of the intelligent security operation method based on C4ISR of the present invention, which consists of a user interaction layer, an intelligent security operation service layer, an AI and large language model support layer, a data acquisition and preprocessing layer, an object layer and a corresponding execution layer. Figure 7 This is a flowchart illustrating the construction of a large language model in the cybersecurity domain, used in the C4ISR-based intelligent security operation method of this invention. Figure 8 This is a schematic diagram of the structure of an embodiment of the intelligent safety operation device based on C4ISR of the present invention; Figure 9 This is a schematic diagram of the structure of an embodiment of the electronic device of the present invention. Detailed Implementation
[0020] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains; the terminology used herein in the specification is for the purpose of describing particular embodiments only and is not intended to limit the invention; the terms "comprising" and "having," and any variations thereof, in the specification, claims, and foregoing drawings are intended to cover non-exclusive inclusion. The terms "first," "second," etc., in the specification, claims, or foregoing drawings are used to distinguish different objects and not to describe a particular order.
[0021] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of the invention. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0022] To enable those skilled in the art to better understand the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings.
[0023] It should be noted that the intelligent security operation method based on C4ISR provided in the embodiments of the present invention is generally executed by a server / terminal device, and correspondingly, the intelligent security operation device based on C4ISR is generally installed in the server / terminal device.
[0024] It should be understood that the number of terminal devices, networks, and servers is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be used.
[0025] Example 1 Please refer to Figure 1 The diagram illustrates a flowchart of an embodiment of the C4ISR-based intelligent security operation method of the present invention. The C4ISR-based intelligent security operation method includes the following steps: Step S1: Construct a large language model for the cybersecurity field.
[0026] In this embodiment, the electronic device (e.g., a server / terminal device) running on the C4ISR-based intelligent security operation method can receive C4ISR-based intelligent security operation requests via wired or wireless connections. It should be noted that the aforementioned wireless connection methods may include, but are not limited to, 3G / 4G / 5G connections, WiFi connections, Bluetooth connections, WiMAX connections, Zigbee connections, UWB (ultra-wideband) connections, and other currently known or future-developed wireless connection methods.
[0027] In this embodiment, step S1 may specifically include the following steps: S11, Building a knowledge base in the field of cybersecurity.
[0028] A hybrid storage architecture combining multi-level knowledge graphs and vector databases is adopted. Knowledge extraction and classification: From sources such as documents, standards, vulnerability databases (CVE, CNNVD), virus databases (such as ClamAV signature database), configuration file baselines, behavioral baselines, laws and regulations (Level Protection 2.0, Key Basic Protection Regulations), attack and defense technology manuals, and operation and maintenance cases, Named Entity Recognition (NER) models (such as BERT-based fine-grained entity recognition) are used to extract entities (such as vulnerability CVE-2024-12345), relationships (such as "exploitation relationship" and "mitigation relationship"), and attributes (such as CVSS scores).
[0029] Dependency parsing is used to extract condition-action logic from technical clauses.
[0030] Knowledge Tree Construction: A hierarchical clustering algorithm (bottom-up aggregation) is used to organize the extracted knowledge into a tree structure. The root node represents cybersecurity knowledge, the first-level child nodes represent attack and defense knowledge, compliance knowledge, business knowledge, etc., and the second level and below are subdivided by topic (e.g., vulnerability database → Web vulnerability → SQL injection).
[0031] Each node is stored in JSON-LD format, preserving the original context path.
[0032] Vectorized storage: Each knowledge fragment (node description, case paragraph) is encoded into a 768-dimensional dense vector using a sentence-transformers model (such as paraphrase-multilingual-MiniLM-L12-v2).
[0033] Vectors are stored in Chroma or FAISS vector databases, and an inverted index is created for keyword retrieval. Vector databases support fast cosine similarity retrieval; the retrieval formula is: .
[0034] in: : Represents the query vector With document vectors The cosine similarity between them, the closer the value is to 1, the more related they are; This is the vector representation of the user's query statement. This is a vector representation of a document fragment in the knowledge base. Query vector The modulus (Euclidean norm) is calculated using the following formula: ; Document vectors The modulus length; For vector dimensions, and They are query vectors Document vectors In the The components of a dimension.
[0035] This formula measures the directional consistency between a query and a knowledge fragment in the semantic space; a value closer to 1 indicates greater relevance. Compared to traditional keyword matching, it can capture synonyms and contextual semantics.
[0036] The purpose of step S11 is to provide LLM with a structured and systematic source of professional knowledge, which is the core foundation for the model to become a domain expert. The knowledge base determines the knowledge boundaries and reasoning basis of the model.
[0037] S12 generates knowledge distillation data based on a knowledge base in the field of cybersecurity.
[0038] Automatic question-answer pair generation based on knowledge trees: Traverse each node of the knowledge tree, using the node path as context. For example, if the node path is / attack and defense knowledge / vulnerability database / SQL injection / time-based blind SQL injection, then construct a prompt template: such as "You are a cybersecurity expert." Based on the following knowledge fragments, generate three question-answer pairs (question-answer) of varying difficulty, requiring questions to cover factual, inferential, and application aspects.
[0039] Knowledge fragment: {node_content}; Generation format: Q1: ... A1: ...
[0040] The DeepSeek-V2 model (teacher model) is called to generate the model with a temperature parameter of 0.3 to avoid random divergence.
[0041] Question-answer pair quality filtering: Use regular expressions to remove question-answer pairs that contain uncertain expressions such as "I don't know" or "According to my knowledge".
[0042] Calculate the ROUGE-L (Longest Common Subsequence Recall) score between the answer and the original knowledge fragment in the question-answer pair, and retain question-answer pairs with a score greater than 0.6. The ROUGE-L formula is: .
[0043] in: A metric for evaluating the similarity between generated and standard answers, based on the longest common subsequence; The sequence of words generated by the model for the answer. The original knowledge fragment serves as the word segmentation sequence for the standard answer. :sequence and The length of the longest common subsequence; :sequence The length of the word segmentation (i.e., the number of words); :sequence The length.
[0044] This metric assesses the extent to which the generated answer covers the information in the original text, avoiding the omission of key facts.
[0045] Distillation dataset preparation: Convert the filtered question-answer pairs into standard JSONL format, with each line containing {"instruction": "question", "output": "answer", "knowledge_source": "node path"}.
[0046] Approximately 500,000 high-quality question-answer pairs were generated and divided into training, validation, and test sets in an 8:1:1 ratio.
[0047] The purpose of step S12 is to use the DeepSeek model to transform unstructured and messy raw knowledge into high-quality structured question-answer pairs, providing labeled data for supervised fine-tuning of the student model, and preparing for the transfer of knowledge from large and heavy to small and refined.
[0048] S13, based on knowledge distillation data, performs fine-tuning training and optimized deployment of student models.
[0049] Supervised fine-tuning: The base model chosen is Qwen-14B (14 billion parameters), and the LoRA (Low-Rank Adaptation) efficient fine-tuning method is employed. A low-rank matrix is inserted into the self-attention module of each layer of the Transformer. .
[0050] in: The updated weight matrix after fine-tuning; The weight matrix of the original pre-trained model, with dimensions of... ; The weight increment matrix that needs to be learned; :one Matrix; :one Matrix; The hidden layer dimension of the model (e.g., 5120); The projection dimension of key / value pairs in the attention mechanism; The rank of a low-rank matrix is much smaller than that of a low-rank matrix. The value is usually 8.
[0051] Only update during fine-tuning and The parameters were reduced from 14 billion to about 20 million, and the video memory usage was reduced from about 28GB to about 14GB.
[0052] The loss function used is cross-entropy loss: .
[0053] in: Cross-entropy loss value, which measures the difference between the model's prediction and the true label; : The length of the input sequence (number of tokens); Size of the model vocabulary; : No. The one-hot encoding of the real token at each location, if the real token is a category. ,but Otherwise, it is 0; Model prediction of the first The token at each location is a category. The probability of.
[0054] This loss function measures the difference between the predicted distribution and the true distribution, and the training objective is to minimize this value.
[0055] Knowledge distillation reinforcement: In addition to fine-tuning the data, the output logits of the teacher model (DeepSeek) on the same input are used as soft labels. The student model learns both hard labels (true answers) and soft labels (teacher distribution) simultaneously. The distillation loss formula is: .
[0056] in: Total knowledge distillation loss. Standard cross-entropy loss calculated based on real labels (hard labels). : Balance coefficient, used to control the weight of hard label and soft label loss (e.g., 0.7). Temperature parameter, used to soften the probability distribution, allowing the model to learn from a smoother distribution (e.g., 4). Kullback-Leibler divergence measures the distribution of the teacher model's output. Student model output distribution The differences.
[0057] Introducing distillation loss allows smaller models to mimic the output distribution of larger models, thus improving generalization ability.
[0058] Model compression and deployment: Knowledge distillation (integrated in step S12).
[0059] Model pruning: Structured pruning is used to evaluate the importance of attention heads (based on the product of gradient and activation value), and the 15% of attention heads with the lowest contribution are pruned, reducing the number of parameters by about 12%.
[0060] INT8 quantization: The LLM.int8() method is used to quantize the weight matrix from FP16 to INT8. For each weight matrix, the maximum absolute value is calculated column-wise. .
[0061] in: Weight matrix number 1 The scaling factor of the column. The weight matrix of the first line, number The element values of the column. : in the The maximum absolute value of all elements in the column. 127: The maximum absolute value range for the INT8 data type.
[0062] After quantization, the weight usage is reduced from 2 bytes / parameter to 1 byte / parameter.
[0063] The final model size was compressed from approximately 28GB (FP16) to approximately 7GB, and the inference speed was increased by 3 times, with a single RTX4090 achieving a generation speed of 50 tokens / s.
[0064] The purpose of step S13 is to transfer the knowledge of the teacher model to the lightweight student model (Qwen-14B) and make it privately deployable through model compression technology, thereby significantly reducing resource consumption and inference latency while ensuring inference accuracy.
[0065] Step S1 aims to construct a lightweight, high-precision large language model specifically designed for the cybersecurity field. This model will enable the model to understand, reason, and generate cybersecurity-related text, providing a unified foundation for natural language processing and knowledge reasoning for all subsequent intelligent agents. This step addresses the issues of insufficient domain-specific knowledge, low inference accuracy, and high deployment costs inherent in general-purpose LLMs (Large Language Models).
[0066] Step S2 involves embedding a large language model in the cybersecurity field as the core of intelligence into the existing security operations center.
[0067] In this embodiment, step S2 may specifically include the following steps: S21, based on a large language model in the field of network security, performs automated log and anomaly analysis.
[0068] Log parsing and standardization: The Drain algorithm (a log parse tree) is used to extract templates from the raw logs. Drain, through preprocessing (grouping by length and word count) and rule matching, parses the raw log entry "User 'admin' failed to login from 192.168.1.100 3 times" into the template "User<>failed to loginfrom<>< >times and the parameter list.
[0069] Input the parsed template and data into the LLM, and require the LLM to generate a standardized JSON format: { "event_type": "failed_login", "user": "admin", "src_ip": "192.168.1.100", "count": 3, "severity": "medium" } Context anomaly detection: Utilizing the LLM's context window (8K tokens), a normalized event sequence from the past hour is concatenated into a context. Hint template: Analyze the following security event sequence to identify any anomalous patterns (such as brute-force attacks or lateral movement). Output "Normal" or "Abnormal" and provide the reason.
[0070] Event sequence: {event_sequence}: For numerical features (such as the number of failed login attempts), LLM can be combined with statistical anomaly detection results. First, the mean and standard deviation within the sliding window are calculated: .
[0071] in: : The mean of the data points within the sliding window. Standard deviation of data points within the sliding window. : The size of the sliding window (e.g., the number of data points it contains, such as 5-minute aggregate points within 60 minutes, totaling 12 points). : Index of the current time point. At a certain point in time The characteristic value (such as the number of failed login attempts).
[0072] If the current value If the data is flagged as statistically abnormal, LLM will use this flag as a reference and combine it with semantics to determine whether it is a genuine attack (e.g., to avoid misclassifying legitimate batch tasks).
[0073] Anomaly event enrichment: Upon detecting an anomaly, LLM automatically invokes tool modules (such as the security alert information query API) to correlate the anomaly event with external intelligence. For example, it extracts the source IP, queries VirusTotal, and inserts the returned malicious tags, geographic location, and ASN information into the event log to generate enriched alerts.
[0074] The purpose of step S21 is to automatically parse massive heterogeneous logs (system logs, firewall logs, application logs), detect abnormal patterns and mark potential security events, reduce the workload of manual review, and improve detection accuracy.
[0075] S22 utilizes a large language model in the field of cybersecurity to extract, correlate, and generate structured security early warning information from multi-source heterogeneous anomaly information data.
[0076] Multi-source intelligence extraction: Web crawlers are used to periodically scrape publicly available risk information sources: CVE details pages, MITRE ATT&CK technical descriptions, Twitter security account tweets, and Exploit-DB exploit code descriptions. For each document, LLM is used for information extraction, with the following template provided: Extract the following information from the text: vulnerability ID, affected product, attack type, required permissions, user interaction, and consequences of exploitation. Output JSON text: {text}.
[0077] LLM outputs structured intelligence, which is stored in a graph database (Neo4j). Node types include "vulnerability", "technology", "software", and "attack group", and relationships include "exploitation", "mitigation", and "association".
[0078] Risk Information Association Graph Reasoning: Leveraging the thought chain capabilities of LLM, reasoning is performed on multiple paths within the graph. For example, to query which APT organizations might exploit CVE-2024-12345, the LLM-generated reasoning steps are as follows: (1) Techniques for finding CVE node associations in the graph (such as T1190); (2) Locate the APT group that uses this technology (e.g., APT29); (3) Summarize the results; (4) Generate a natural language report from the reasoning process and conclusion.
[0079] Predictive security alert generation: Inputting historical vulnerability exploitation trends (time series) and ATT&CK technique evolution, LLM generates predictions of potentially active attack techniques for the next three months. Using time-series LLM (such as TimeGPT fine-tuning), historical data is encoded into alerts. The following are the monthly new exploit counts over the past 24 months: [12, 15, 22, 28, ...]. Please predict the values for the next 3 months and explain the reasons for the trend.
[0080] Contextual enhancement by incorporating external factors (such as geopolitics and major events) generates actionable recommendations.
[0081] The purpose of step S22 is to use LLM to extract, correlate, and generate structured security alert information from multi-source heterogeneous anomaly information data (vulnerability reports, attack frameworks, dark web discussions), enabling the security operations team to quickly understand emerging risk information and proactively defend against it.
[0082] S23, based on a large language model in the field of network security, automates incident response, generating incident reports, response suggestions, and execution scripts.
[0083] Event Summary and Impact Assessment: Input the original alert and enriched context, and LLM generates a structured event summary, including: attack entry point, affected assets, attack chain stage, and potential loss assessment. Prompt Template: Generate an event summary based on the following alarm information, in the following format: [Event ID], [Attack Type], [Affected Systems], [Suggested Priority (High / Medium / Low)], [Description of Affected Scope].
[0084] Alert: {alert_json} During the impact assessment, LLM can combine an asset value database (e.g., assigning a value of 1 million yuan to the core trading system) to calculate the risk value: .
[0085] in: This is the quantified safety risk value. The asset value is in ten thousand yuan. To influence the score (1-5, assessed by LLM based on CIA triplet). The probability of occurrence is 0-1, derived from historical statistics and LLM reasoning. This formula quantifies risk and aids in prioritization.
[0086] Response script generation and execution: The LLM retrieves relevant SOPs (Standard Operating Procedures) and similar cases from the knowledge base to generate customized response steps. For example, for "ransomware infection," the following is generated: Isolate the affected hosts (command: iptables -I INPUT -s <ip>-j DROP); Terminate suspicious processes (command: kill -9) <pid>); Initiate the backup and restore process.
[0087] LLM invokes code interpreter tools to convert natural language steps into Python scripts or shell commands, and then sends them to the response execution layer via API.
[0088] Post-incident report generation: After the incident is resolved, the LLM collects all logs, operation records, and timelines to generate an incident report that meets compliance requirements. The report includes: root cause analysis, timeline, response actions, and improvement recommendations. A hybrid approach of template filling and LLM generation is used to ensure consistent formatting and comprehensive content.
[0089] The purpose of step S23 is to automatically generate detailed event reports, response suggestions, and execution scripts when a security incident occurs, and to coordinate the response execution layer to complete isolation, repair, and other operations, thereby significantly shortening the mean time to response (MTTR).
[0090] The purpose of step S2 is to embed the domain LLM constructed in step S1 into the various functional modules of the existing Security Operations Center (SOC) as the intelligent core, significantly improving the automation and intelligence level of key tasks such as security early warning information analysis, log anomaly detection, and event response, and solving the problems of alarm fatigue and response delay in traditional SOCs.
[0091] Step S3: Establish a C4ISR-based multi-agent mapping model.
[0092] In this embodiment, step S3 may specifically include the following steps: S31, Establish semantic mapping from C4ISR elements to cybersecurity agents.
[0093] An ontology-based mapping method is adopted: Building a C4ISR-Network Security Ontology: Use the Protégé tool to build an OWL ontology, defining C4ISR classes (such as "Command" and "Control") and network security classes (such as "PolicyMaker" and "Enforcer").
[0094] Define the mapping relationships: Command ≡ PolicyMaker, Control ≡ Enforcer, Communications ≡ SecureChannel, Computers ≡ ComputeEngine, Intelligence ≡ ThreatIntelAgent, Surveillance ≡ MonitorAgent, Reconnaissance ≡ ProbeAgent.
[0095] Agent Interface Specification: Defines a standardized message format (based on JSON Schema) for each agent, such as the policy message that commands the agent. { "msg_type": "policy_update", "source": "cmd_agent_1", "target": "ctrl_agent_2", "payload": { "policy_id": "P-20241001-001", "action": "block_ip", "params": {"ip": "10.0.0.1", "duration": 3600} }, "timestamp": 1727769600 } Each agent must implement three basic methods: receive(message), process(), and send(message).
[0096] Role Assignment and Hierarchy: Based on network scale, establish a three-tier command system: central level (overall command), regional level (data center / branch), and terminal level (host / device). Command agents form a tree-like hierarchy, with higher levels issuing strategies to lower levels and lower levels reporting the situation to higher levels.
[0097] The purpose of step S31 is to clearly define the responsibility boundaries and input / output interfaces of each intelligent agent, ensuring that the seven types of intelligent agents cover the entire lifecycle of safe operation (detection, analysis, decision-making, and execution).
[0098] Figure 2 This is a schematic diagram of the core architecture of the intelligent agent used in the C4ISR-based intelligent security operation method of this invention. For example... Figure 2 As shown, the intelligent agent depicts how an intelligent system with autonomous thinking, planning, action, and learning capabilities is constructed. The architecture centers on the "intelligent agent," radiating outwards to four core modules: memory, planning, action, and tools. Dashed lines illustrate the interactive and collaborative capabilities between intelligent agents, as well as their internal reflection and optimization mechanisms.
[0099] At the very center, the "intelligent agent" is the decision-making hub of the entire system. It is not a simple program, but a self-aware entity responsible for coordinating and driving the entire system's operation. It acquires information through interaction with the external environment, formulates strategies through its internal planning module, executes operations through its action module, and stores and retrieves knowledge through its memory module. This core "intelligent agent" is the "brain" of the entire architecture, around which all information and control flows revolve.
[0100] Extending upwards from the "agent" is the "memory" module, which is further subdivided into "short-term memory" and "long-term memory." Short-term memory is similar to human "working memory," used to store contextual information for the current task, temporary variables, and ongoing thought processes. It has limited capacity but extremely fast access speed, forming the basis for the agent's real-time decision-making and reasoning. Long-term memory, on the other hand, is similar to human "permanent memory," used to store a vast knowledge base, past experiences, user preferences, and historical interaction records. It has enormous capacity but relatively slow access speed, providing the agent with a deep knowledge base and background information, enabling deeper understanding and reasoning. The collaborative work of short-term and long-term memory allows the agent to focus on the current task while also learning from and drawing upon historical experience.
[0101] Extending to the right from the "Agent" is the "Planning" module, which is the agent's "thinking engine." It's not a single function, but a complex cognitive process encompassing four key sub-modules: "Reflection," "Self-Criticism," "Thinking Chains," and "Sub-Goal Decomposition." The reflection mechanism enables the agent to react quickly and instinctively to simple, patterned inputs, similar to human reflection and debriefing, ensuring the system's responsiveness. The self-criticism mechanism endows the agent with "metacognitive" capabilities, allowing it to review its processing and results after task execution or when encountering difficulties, analyze the reasons for failure, learn from it, and optimize future decision-making strategies. Thinking chains are the core method for solving complex problems; they break down a complex problem into a series of logically clear and step-by-step sub-problems, deriving the final answer through step-by-step reasoning, greatly enhancing the agent's ability to solve complex problems. Sub-goal decomposition breaks down a large, vague goal into a series of specific, actionable, and measurable smaller goals, providing a clear roadmap for the agent's actions.
[0102] Extending downwards from the "agent" is the "action" module, which is the agent's "execution component." It is responsible for translating the strategies and plans generated by the planning module into concrete actions in response to the external environment. This module serves as the interface for the agent to interact with the physical or digital world; for example, it can be a command to control the movement of a robotic arm, an API call to send a query to a database, or text output to send a message to a user. The success or failure of the action module directly determines whether the agent can effectively complete its task.
[0103] Extending to the left from the "Agent" is the "Tools" module, which is the agent's "capability extension package." It provides the agent with the external functions needed to perform specific tasks, greatly expanding the agent's capabilities. The diagram lists tools such as "Calendar()", "Calculator()", "Code Interpreter()", and "Search()". The calendar tool helps the agent manage time and schedule appointments; the calculator tool gives the agent precise mathematical calculation capabilities; the code interpreter enables the agent to write and execute code, thus solving more complex programming and data processing problems; and the search tool allows the agent to obtain the latest information from the outside world in real time. By calling these tools, the agent can efficiently complete various complex tasks, just like humans use various tools. The "More..." in the diagram also suggests that this toolset is open and extensible, and new functions can be continuously added as needed.
[0104] Figure 2 The dotted line at the bottom connects the two "agents" and is labeled "interaction and collaboration." This reveals a higher-level architectural concept—the collaboration of multi-agent systems. The capabilities of a single agent are ultimately limited. By enabling multiple agents to interact and collaborate, they can divide tasks and work together to solve extremely complex tasks that a single agent cannot accomplish. For example, one agent can be responsible for planning, another for execution, and a third for supervision and evaluation. This distributed, collaborative architecture is essential for building more advanced artificial intelligence systems.
[0105] Figure 3 This is a flowchart illustrating the multi-intelligence system workflow used in the C4ISR-based intelligent security operation method of this invention. (For example...) Figure 3 As shown, the process begins with a user request, proceeds through intent recognition, task initialization, task planning, task execution, and result integration, ultimately forming a feedback and optimization closed loop. The entire process is clearly structured and the modules are clearly defined, fully demonstrating the ability of multiple agents to collaboratively handle complex tasks.
[0106] The specific steps mainly include: (1) Intent recognition stage.
[0107] This is the starting point of the entire process. The system first receives user input, which may be multimodal information such as text, voice, or images. At this stage, the system uses natural language understanding and keyword extraction technologies to quickly identify the user's core intent. Simultaneously, the system supports interactive guidance, such as proactively asking questions to clarify when the intent is ambiguous, ensuring accurate understanding. This stage relies on a small model to complete lightweight reasoning, resulting in rapid response and laying the foundation for subsequent steps.
[0108] (2) Task initialization.
[0109] After clarifying the user's intent, the system enters the task initialization phase. At this stage, the system automatically creates independent task directories to isolate task data from different users, ensuring privacy and security. Simultaneously, the system starts an isolation container to ensure each task runs in an independent and controlled environment, preventing resource conflicts or malicious code from affecting the overall system. This phase emphasizes security and traceability; all initialization operations are recorded for subsequent auditing and debugging.
[0110] (3) Task planning.
[0111] This stage is crucial for the system's "brain" to function. The system breaks down the complex task proposed by the user into multiple executable subtasks and defines the dependencies and execution order of each subtask. Simultaneously, the system generates a structured task list, assigns an appropriate agent to each subtask, and sets execution conditions and timeout mechanisms. This stage relies on large language models with strong reasoning capabilities, such as Deepseek-r1, to ensure rational and efficient planning.
[0112] (4) Task execution.
[0113] This is the core stage of multi-agent collaborative work. Based on the planning results, the system schedules multiple specialized agents to execute sub-tasks in parallel or sequentially. For example, the search agent is responsible for retrieving stock data from the network, the coding agent generates and runs Python scripts for data processing, and the data analysis agent performs statistical analysis and visualization. Each agent runs independently in an isolated container, and the results are uniformly written to the task directory. The system monitors the execution status in real time; if an agent fails, it can automatically retry or switch to a backup solution. This stage fully utilizes the capabilities of multimodal models such as Claude-3.7 to support complex logic and cross-modal processing.
[0114] (5) Results integration.
[0115] After all subtasks are completed, the system enters the results integration phase. The system collects the outputs of each agent, performs format standardization, content deduplication, and logical verification, ultimately generating user-friendly results such as reports, charts, or executable code. Simultaneously, the system supports interactive feedback, allowing users to comment on the results or suggest modifications. This feedback is recorded and used for subsequent optimization, forming a closed loop of "execution-feedback-optimization."
[0116] S32 endows each agent with AI capabilities and domain knowledge, enabling it to independently complete its assigned tasks while also providing interfaces for collaboration with other agents.
[0117] Command agent: Core competency: LLM-based strategy planning and decision-making.
[0118] A policy generation model is trained in a simulated environment using reinforcement learning (PPO algorithm). The state space represents the current global risk situation (attack targets, attack intensity, and friendly defense resources), and the action space represents policy adjustments (such as increasing the monitoring level of a certain area or enabling strict access control). The reward function is: .
[0119] in These are weighting coefficients, taken as 0.6, 0.3, and 0.1 respectively. The sum of the asset value (in ten thousand yuan) corresponding to a successfully defended attack. The computational and human resource costs incurred in executing the strategy (equivalent to tens of thousands of yuan). The loss (in ten thousand yuan) caused by the erroneous disruption of normal business operations. After training, the policy network can output the optimal policy in real time.
[0120] Controlling the intelligent agent: Core capability: Analyzing command strategies and translating them into specific equipment instructions.
[0121] A policy translator is built based on a finite state machine (FSM) and a rule engine. The input policy is "block_ip10.0.0.1 for 3600s", and the outputs firewall commands (iptables commands), switch ACL (access control list) commands, and host firewall commands (Windows firewall netsh commands). Template filling technology is used to predefine command templates for each device type.
[0122] Communication agents: Core capability: Establishing end-to-end encrypted channels to ensure the confidentiality and integrity of control commands and intelligence transmission.
[0123] The system employs the SM2 / SM4 / SM3 national cryptographic algorithm suite. SM2 is used for key negotiation (asymmetric), SM4 for bulk data encryption (symmetric), and SM3 for hash verification. A two-way authenticated TLS 1.3 connection is established using pre-configured certificates. The communication agent is also responsible for publish / subscribe management of the message queue (using RabbitMQ), achieving loosely coupled communication.
[0124] Computational analytical agents: Core capabilities: Provides distributed computing power support to accelerate LLM inference and massive log analysis.
[0125] Deploy a Kubernetes cluster to dynamically schedule GPU resources. For LLM inference tasks, use the vLLM inference engine, supporting PagedAttention technology, improving GPU memory utilization to 90%. For numerical analysis tasks (such as time series anomaly detection), use Apache Spark for distributed computing.
[0126] Intelligence agents: Core capabilities: collecting, integrating, and analyzing multi-source security early warning information.
[0127] It integrates the MISP (Malware Information Sharing Platform) standard interface to automatically pull shared intelligence. It uses graph neural networks (GNNs) for intelligence correlation, with the model being R-GCN (Graph Convolutional Network for Relationships). The input is an intelligence graph (with more than 100,000 nodes), and the output is the embedding representation of each node, used for similarity clustering and the discovery of unknown risks.
[0128] Surveillance agents: Core capability: Real-time monitoring of the operational status and attack events of the protected system.
[0129] Deploy eBPF probes to capture system calls and network packets in kernel space. The eBPF program pushes the data to the user-space analytics engine by attaching to kprobes and tracepoints. The monitoring agent maintains event statistics for a sliding window (10-minute window size, 1-minute step) and compares them to a baseline. The baseline is calculated using historical data from the same period and predicted using Holt-Winters exponential smoothing.
[0130] Reconnaissance agent: Core capability: Proactively detect the vulnerabilities and configuration deviations of target systems.
[0131] Integrate Nmap and OpenVAS scanners to perform network and vulnerability scans regularly (daily or weekly). Scan results are compared to a configuration baseline database (CMDB), and the Jaccard similarity coefficient is used to measure configuration deviations. .
[0132] in: :gather and The Jaccard similarity coefficient is used to measure the similarity between two objects; the larger the value, the more similar the two objects are. For the current configuration set (such as a list of open ports, a list of service versions). Configure the baseline set. Set the intersection size (number of consistent items). The size of the union (total number of configuration items). If This will trigger a configuration alarm.
[0133] The purpose of step S32 is to design and implement the specialized functions of each intelligent agent.
[0134] S33 integrates a multi-agent management platform.
[0135] Agent registration and discovery: etcd is used as the service registry. Each agent registers its type, address, capability tags (such as "supports firewall control") with etcd upon startup and sends a heartbeat (every 30 seconds). Other agents discover new agents in real time through a watch mechanism.
[0136] Task scheduling and load balancing: A consistent hashing algorithm is used to distribute tasks. Task characteristics (such as source IP hash) are mapped onto a ring, and agent nodes are also mapped onto the ring. Tasks are assigned to the first agent in a clockwise direction. This ensures that tasks from the same source are always assigned to the same agent, facilitating state maintenance.
[0137] Monitoring and self-healing: Deploy Prometheus to collect resource usage (CPU, memory, GPU), request latency, and error rate for each agent. Set alert rules: If the error rate > 5% for 3 consecutive minutes, trigger automatic restart or migration. Use Grafana to display the global agent topology and health status.
[0138] The purpose of step S33 is to provide a unified registration, discovery, monitoring, and scheduling mechanism so that the seven types of intelligent agents can work together to form an organic whole.
[0139] The purpose of step S3 is to draw on the seven elements of military C4ISR systems—command, control, communication, computer, intelligence, surveillance, and reconnaissance—and map them onto the field of cybersecurity operations, forming seven types of specialized intelligent agents. This breaks down the information silos of traditional security architectures and achieves global collaborative defense.
[0140] Step S4: Based on the multi-agent mapping model, design a multi-agent collaborative working architecture.
[0141] In this embodiment, step S4 may specifically include the following steps: S41, based on a multi-agent mapping model, designs the internal cognitive architecture of agents.
[0142] Employing the ReAct (Reason+Act) model, each agent contains four modules: Memory module: Short-term memory: Uses Redis to store the current session's conversation history, temporary state, and intermediate calculation results. Sets an expiration time of 30 minutes. The storage structure is a list, supporting fast appending and truncation.
[0143] Long-term memory: A vector database (Chroma) is used to store historical success stories and expert knowledge. Memory retrieval employs a weighted self-attention mechanism. .
[0144] in: : query With the A memory The relevance score; This is the current query vector. For the first Memory vector, Using a temperature parameter (set to 0.7), softmax normalizes the dot product into a probability distribution. The top 3 highest-scoring memories are then injected with cue words.
[0145] Planning module: Sub-target decomposition: LLM breaks down high-level targets (such as "hardening the web server") into sub-tasks: scanning open ports; detecting SQL injection vulnerabilities; updating WAF rules; and restarting the service for verification.
[0146] Reasoning Chains: For complex reasoning, LLM explicitly generates intermediate steps. For example, to determine "whether it is an APT attack", the chain is generated as follows: check for phishing emails; check for abnormal external connections; check for persistence mechanisms; if all three are satisfied, it is determined to be an APT attack.
[0147] Self-criticism: After planning, LLM generates a "criticism version" that points out potential problems (such as step S3 potentially disrupting business) and revises the plan.
[0148] Action Module: The abstract actions output by the planning module are translated into concrete API calls. For example, the action scan port is mapped to nmap-p-sV target_ip and executed via subprocess.
[0149] The action results (standard output, error codes) are fed back to the memory module.
[0150] Tools module: The agent can invoke a set of external tools, including: a calculator (for precise arithmetic), a code interpreter (for executing Python code), a search engine (Bing search API), a database query engine (SQL executor), and notifications (for sending emails / DingTalk messages). Tool invocations follow the OpenAPI specification.
[0151] The purpose of step S41 is to endow each intelligent agent with the ability to think, plan, execute, and learn autonomously, enabling it to cope with the dynamically changing network environment.
[0152] S42, design a multi-agent cooperation protocol.
[0153] Communication language: A simplified version based on ACL (Agent Communication Language). The message format includes: sender, receiver, message type (request / response / notification / broadcast), content (JSON), and conversation ID.
[0154] Messages are exchanged via RabbitMQ, supporting both point-to-point and publish / subscribe.
[0155] Collaboration Mode: Master-slave mode: The commanding agent is the master, and others are slaves. The master agent issues tasks, and the slave agents execute them and return the results. This mode is suitable for scenarios with a clear chain of command.
[0156] Peer-to-peer negotiation: Two intelligent agents reach a consensus through multiple rounds of message exchange. For example, a surveillance agent detects an anomaly and requests relevant intelligence from an intelligence agent; if the intelligence agent is unsure, it can ask the surveillance agent for more features; the two negotiate and reach a final judgment.
[0157] Auction Mode: When a task requires specific resources, the commanding agent broadcasts the task. Each agent bids based on its own load and capabilities (returning estimated completion time and cost), and the commanding agent selects the best bidder. The bidding scoring formula is as follows: .
[0158] in: The bidding process for intelligent agents is scored, with the highest score winning. This is the estimated execution time (in seconds). The resource cost (e.g., GPU usage minutes) is considered. This score determines which option has the smallest product of time and cost.
[0159] Conflict resolution: When two agents give conflicting conclusions (e.g., one determines it's normal, the other determines it's abnormal), an arbitration mechanism is introduced: a third-party agent (usually a command or computational analysis agent) synthesizes the evidence from both sides and uses a weighted voting method. .
[0160] in: The final decision after arbitration, the output is positive or negative; : The sign function, which outputs +1 or -1 depending on whether the input is positive or negative; For the first The historical accuracy weights of each agent (initially 1, dynamically adjusted based on validation feedback). For the first The sign of the sign function output by the sign of the agent's judgment (normal = +1, abnormal = -1) determines the final judgment.
[0161] This formula gives high-accuracy agents greater say.
[0162] The purpose of step S42 is to define how agents communicate, negotiate, and delegate tasks to achieve a synergistic effect where 1+1>2.
[0163] S43 enables agents to reflect and learn continuously.
[0164] Offline Reflection: Regularly (e.g., daily) review the task execution logs from the past 24 hours. For failed tasks (e.g., false positives, false negatives, response timeouts), LLM generates a reflection report to analyze the root cause (e.g., "because weekend traffic patterns were not considered").
[0165] The reflection reports were transformed into new training data for the next round of fine-tuning.
[0166] Online learning: Dynamically select the optimal strategy using a multi-armed gambling machine algorithm. For example, the control agent has multiple isolation strategies (complete isolation, rate limiting, alarm only), and adjusts the selection probability based on real-time feedback (business impact, protection effectiveness). The update formula is: .
[0167] in To select a strategy The probability, The learning rate is 0.1. For strategy The instant reward received (calculated based on whether the protection was successful or the block was false). This represents the average reward. The formula automatically adjusts the probability, making high-reward strategies more likely to be selected.
[0168] Knowledge base update: Newly confirmed attack patterns and response cases are automatically added to the vector knowledge base. Before addition, they undergo deduplication (calculating cosine similarity with existing knowledge; if >0.95, they are skipped) and quality verification (manual verification or automatic rules).
[0169] The purpose of step S43 is to enable the agent to learn from its mistakes, continuously optimize its decision-making and behavioral strategies, and adapt to new attack methods.
[0170] The purpose of step S4 is to design an internal cognitive architecture (memory, planning, action, tools) for each agent and define the interaction protocol between multiple agents, so that agents can not only work independently, but also cooperate like a human team to complete complex tasks.
[0171] Step S5: Develop a closed-loop workflow for the multi-agent system.
[0172] In this embodiment, step S5 may specifically include the following steps: S51 performs intent recognition and task initialization for the intelligent agent.
[0173] Multimodal intent recognition: Input can be text (chat box), speech (transcribed to text), or image (dashboard screenshot). For text, a BERT-based intent classifier is used, and the output is a predefined intent category (e.g., query logs, block IPs, generate reports). For images, ViT (Vision Transformer) is used to extract features, which are then mapped to intents.
[0174] If the confidence level is less than 0.7, an interactive clarification is triggered: the agent asks the user, such as "Do you want to query the recent login failure logs, or do you want to modify the login policy?"
[0175] Task initialization: Automatically create a UUID as the task ID, and create a directory / tasks / {task_id} in the file system.
[0176] Start a Docker container and mount this directory. The container contains an isolated Python environment and toolset. The container's network mode is "bridge," which restricts outbound connections to prevent malicious code from leaking data.
[0177] Write the intent parsing results to task.json, which includes the task type, parameters, and priority.
[0178] Environment Sandbox: Container resource limits: CPU no more than 2 cores, memory no more than 4GB, runtime no more than 30 minutes (automatic termination upon timeout). Resource isolation is achieved using cgroups.
[0179] All file operations are restricted to / tasks / {task_id} and cannot access the host system.
[0180] The purpose of step S51 is to accurately understand the user's (security analyst's) natural language instructions and translate them into a machine-executable task description, while preparing an isolated execution environment for the task.
[0181] S52 breaks down the task into subtasks that can be executed in parallel or sequentially by different agents, and determines the dependencies and execution order.
[0182] Hierarchical Task Network (HTN) Planning: Using an HTN planner (such as Pyhop), input the task description (e.g., analyze attack events from last week and generate a report), and the domain knowledge includes decomposition methods. For example, the method for analyzing events can be broken down into sub-tasks: querying the event database; statistically analyzing the distribution of attack types; identifying high-risk events; generating charts; and writing reports.
[0183] Each subtask is labeled with the type of agent performing the task (e.g., query task, intelligence agent, chart generation and computational analysis agent).
[0184] Dependency resolution: Construct a directed acyclic graph (DAG), where nodes represent subtasks and edges represent dependencies (e.g., subtask B depends on the output of A). Use the Kahn algorithm for topological sorting to determine the execution order. If circular dependencies exist, report an error and request manual intervention.
[0185] Set a timeout for each subtask (based on historical P99 time consumption statistics).
[0186] Resource estimation: A regression model is used to estimate the resource requirements (CPU time, memory, GPU time) for each subtask. Model features include task type, input data volume, and the execution time of similar historical tasks. The estimation results are used for scheduling decisions.
[0187] The purpose of step S52 is to perform task planning and decomposition.
[0188] S53 schedules multiple agents to execute subtasks in parallel or serially, collects task execution results and integrates them into the final output, while recording feedback for optimization.
[0189] Agent scheduling and execution: The scheduler places ready subtasks into a priority queue according to the DAG order (priority is determined by the urgency of the task and resource requirements). Each agent pulls a task from the queue and updates its status to "in execution".
[0190] For tasks that can be parallelized (such as scanning 10 network segments simultaneously), the scheduler launches 10 reconnaissance agent instances to execute in parallel. Semaphores are used to control the number of concurrent operations to not exceed the system capacity.
[0191] Results Integration: After all subtasks are completed, aggregate the results. For numerical results (such as the number of potential risks detected), calculate the sum, mean, and quantiles. For textual results (such as event descriptions), use LLM to perform summary merging, with the prompt: "Integrate the following multiple analysis results into a coherent report, removing duplicate information: {results}".
[0192] Generate the final output, which may be in the format of JSON, Markdown report, PNG chart, or executable script, depending on the user's initial intent.
[0193] Feedback loop: Records the execution status (success / failure), time consumption, and resource consumption of each subtask. Users can evaluate the final result (useful / useless). This data is stored in the MLflow tracing system.
[0194] Regularly (weekly) fine-tune the LLM of the planning module using feedback data to make its task decomposition more reasonable. At the same time, update the resource estimation model.
[0195] The purpose of step S53 is to perform task execution, integration, and feedback.
[0196] The purpose of step S5 is to define a complete processing pipeline from user input to task completion, enabling a rapid closure of the Observe-Adjust-Decision-Action (OODA) loop, allowing security operations to respond faster than attackers.
[0197] Step S6: Design a layered and integrated security operations center platform architecture.
[0198] Figure 4 This diagram illustrates the connection relationships between the user interaction layer, intelligent security operation service layer, AI and large language model support layer, data acquisition and preprocessing layer, object layer, and corresponding execution layer used in the C4ISR-based intelligent security operation method of this invention. Figure 4 As shown, in this embodiment, step S6 may specifically include the following steps: S61, Design Object Layer and Data Acquisition Preprocessing Layer.
[0199] Object layer: All objects are managed uniformly through CMDB (Configuration Management Database), including: hosts (servers, terminals), network devices (switches, routers), security devices (firewalls, IDS), application systems (Web, databases), and industrial control equipment (automatic ticket vending and checking machines dedicated to railway passenger ticketing systems).
[0200] Each object is assigned a unique ID and its attributes are recorded (IP address, operating system, importance level, and business category). The object layer provides an API for the data acquisition layer to call.
[0201] Data Acquisition: Deploy Fluentd or Logstash as the log collector, supporting multiple input sources (Syslog, Windows Event Log, file tail). For performance data (CPU, memory), use Prometheus node_exporter.
[0202] Collection frequency: Configuration change events are pushed in real time, status data is pulled every 30 seconds, and complete logs are uploaded in batches every 5 minutes.
[0203] The data format is uniformly JSON, containing the following fields: object_id, timestamp (ISO 8601), metric_type, value, and raw_log (optional).
[0204] Data preprocessing: Data imputation: For missing values, use linear interpolation or forward imputation. Linear interpolation formula: .
[0205] in: At a certain point in time The estimated value; The time point in time when an estimated value is needed; and These are the missing points The most recent valid time point before and after, and , At a certain point in time The actual value; At a certain point in time The actual value.
[0206] This formula assumes that the data changes linearly in the short term, making it simple and effective.
[0207] Data cleaning: Use the Isolation Forest algorithm to identify outliers (such as obviously erroneous data with CPU usage exceeding 100%), mark them as invalid, and remove them.
[0208] Data alignment: Align all timestamps to a 5-second grid. For high-frequency data, use the average value within the grid; for low-frequency data, use the most recent value.
[0209] Data normalization: For numerical features (such as network traffic), use Min-Max normalization to scale to the [0,1] interval. .
[0210] in: : Normalized eigenvalues, ranging from [0, 1]; Original eigenvalues; For the complete historical set of this feature, and These are the minimum and maximum values, respectively.
[0211] After normalization, features of different dimensions can be input into the model together.
[0212] The purpose of step S61 is to define the scope and attributes of the protected assets and design an efficient and reliable data acquisition pipeline to provide high-quality and standardized data input to the upper layer.
[0213] S62 is designed as a large language model support layer and intelligent security operation service layer for the fields of AI and cybersecurity.
[0214] AI & LLM Support Layer: Model inference cluster: Deploys vLLM and Ray, supporting multi-GPU distributed inference. Automatic load balancing allocates more resources to high-priority requests (real-time alarm analysis).
[0215] Algorithm library: Integrates Scikit-learn (traditional machine learning), PyTorch (deep learning), and Stable-Baselines3 (reinforcement learning). Algorithms are exposed as microservices via RESTful APIs.
[0216] Knowledge base service: Chroma vector database cluster, supporting near real-time updates. During updates, both the inverted index and vector index are updated simultaneously to ensure retrieval consistency.
[0217] Intelligent security operation service layer: Asset management service: Based on CMDB data, automatically discovers network topology (using LLDP and SNMP). Provides a visual map of assets.
[0218] Monitoring service: Based on Prometheus + Grafana, it displays key metrics (attack trends, response time, agent health). Alerts are sent via Alertmanager when anomalies occur.
[0219] Intelligent Security Analytics Service: Core service, internally integrated with an event correlation engine (based on the Complex Event Processing (CEP) engine Esper), a risk assessment model (based on CVSS and asset value), and a Security Orchestration Automation and Response (SOAR) script executor.
[0220] Cooperative scheduling service: Based on Apache Airflow, it orchestrates cross-service workflows, such as: monitoring and discovering events → triggering the analysis service → invoking the response execution layer. It supports task retries, dependency management, and visual DAGs.
[0221] The purpose of step S62 is to provide a domain LLM inference engine, AI algorithm library and multi-agent runtime environment, and encapsulate them into various services (asset management, monitoring, analysis, etc.) required for security operations, for upper layer to call.
[0222] S63, design the user interaction layer and response execution layer.
[0223] User interaction layer: Web UI: Built on React + ECharts. Includes: Situational awareness dashboard (displaying attack map and event trends), alarm list (supporting filtering, sorting, and marking handling status), intelligent Q&A interface (natural language input in chat box, background calls LLM), and report download center.
[0224] Interaction Engine: The backend uses WebSocket to maintain bidirectional communication and push new alerts in real time. The frontend supports a "manual takeover" mode: analysts can modify the response plan generated by the LLM and then manually confirm its execution.
[0225] Decision Support Module: When LLM provides decision recommendations, it simultaneously displays confidence level, reference cases, and reasoning path (thinking chain) to help analysts understand and trust the AI.
[0226] Response Execution Layer: Execution Agent: Deploy a lightweight Agent (based on Go language, resource consumption <10MB memory) on each protected host or network device to receive instructions from the control agent through an encrypted channel.
[0227] Standardized instruction set: Defines a unified instruction protocol (Protobuf serialization), including: ExecCmd (execute commands), UpdatePolicy (update firewall rules), Quarantine (isolate hosts), and Rollback (roll back configurations). The Agent translates the instructions into API calls specific to the operating system or device.
[0228] Execution tracking: Each command returns the execution result (stdout, stderr, exit code) and completion time. If execution fails, the Agent automatically retryes up to 3 times; if it still fails, an exception is reported.
[0229] Linked control: For operations that require multi-device collaboration (such as blocking a specific IP across the entire network), the control agent issues instructions to all edge agents in parallel and uses two-phase commit to ensure atomicity: first, pre-execute (to check feasibility), and then officially execute after all are successful; otherwise, roll back.
[0230] The purpose of step S63 is to provide a visual human-machine collaborative interface, enabling security analysts to monitor, intervene in, and optimize the system; at the same time, it transforms decisions into specific operations on the protected objects, achieving closed-loop control.
[0231] The purpose of step S6 is to integrate the technical achievements of the first five steps into a six-layer platform architecture that can be practically deployed and maintained, achieving complete coverage from the bottom layer protected objects to the top layer user interaction, and providing 24 / 7 security operation services.
[0232] Figure 5 This is a diagram illustrating the main components and functional modules of the AI and large language model support layer used in the C4ISR-based intelligent security operation method of this invention. Figure 5 As shown, the AI&LLM support layer includes: Model inference cluster: Deploys vLLM and Ray, supporting multi-GPU distributed inference. Automatic load balancing allocates more resources to high-priority requests (real-time alarm analysis).
[0233] Algorithm library: Integrates Scikit-learn (traditional machine learning), PyTorch (deep learning), and Stable-Baselines3 (reinforcement learning). Algorithms are exposed as microservices via RESTful APIs.
[0234] Knowledge base service: Chroma vector database cluster, supporting near real-time updates. During updates, both the inverted index and vector index are updated simultaneously to ensure retrieval consistency.
[0235] Intelligent security operation service layer: Asset management service: Based on CMDB data, automatically discovers network topology (using LLDP and SNMP). Provides a visual map of assets.
[0236] Monitoring service: Based on Prometheus and Grafana, it displays key metrics (attack trends, response time, agent health). Alerts are sent via Alertmanager when anomalies occur.
[0237] Intelligent Security Analytics Service: Core service, internally integrated with an event correlation engine (based on the Complex Event Processing (CEP) engine Esper), a risk assessment model (based on CVSS and asset value), and a Security Orchestration Automation and Response (SOAR) script executor.
[0238] Cooperative scheduling service: Based on Apache Airflow, it orchestrates cross-service workflows, such as: monitoring and discovering events → triggering the analysis service → invoking the response execution layer. It supports task retries, dependency management, and visual DAGs.
[0239] Figure 6 This is a schematic diagram illustrating the architecture of the C4ISR-based intelligent security operation method of the present invention, comprising a user interaction layer, an intelligent security operation service layer, an AI and large language model support layer, a data acquisition and preprocessing layer, an object layer, and corresponding execution layers. Figure 6 As shown, the layers are tightly coupled through bidirectional data flow and unidirectional command transmission, forming a complete security operation closed loop from business awareness, intelligent analysis, human-machine collaboration to trusted execution, providing 24 / 7 security operation and maintenance services. The logical composition and functional description of each layer are as follows: The object layer consists of the underlying entity objects of the framework, mainly including the objects that are protected in the railway ticketing system. These include terminal host devices (such as terminal hosts, servers, automatic ticket vending machines, mobile terminals, IoT terminals, etc.), network devices (such as switches, routers, etc.), and security devices (such as firewalls, gateways, intrusion detection systems, vulnerability scanning systems, terminal controllers, etc.). The data generated by these devices during operation forms the basis for the work of the upper layers.
[0240] The data acquisition and preprocessing layer is responsible for collecting static configuration and dynamic operation data of various devices in the object layer, cleaning and standardizing multi-source heterogeneous data, and other preprocessing to provide high-quality data input for upper-level analysis, as well as supporting data for LLM training and fine-tuning.
[0241] Data acquisition mainly includes static configuration information of various objects and devices (such as system configuration, storage configuration, hardware and software configuration), dynamic operating status information (such as CPU utilization, memory usage, network throughput, etc.), log information (such as system operation log records, audit logs, error logs, etc.), event information (such as system fault alarms), and other event information.
[0242] After the raw data collection is completed, the data preprocessing stage begins, which includes four key steps: data completion, data cleaning, data alignment, and data normalization. To address potential data gaps, strategies such as time series interpolation or historical pattern inference are used for data completion. Data cleaning identifies and removes invalid and duplicate noise data, improving the signal-to-noise ratio. Data alignment uses entity resolution and association rules to link data records from different sources and standardizes the timestamp format. Finally, data normalization converts heterogeneous data into a unified numerical or vector representation.
[0243] The AI&LLM support layer primarily provides the natural language understanding and processing, as well as various artificial intelligence algorithms and large language models required by the upper-layer multi-agent system. Its main components and functional modules are as follows: Domain Knowledge Base: This provides the knowledge support for intelligent decision-making, integrating various professional knowledge required for cyberspace security protection. This includes a cybersecurity attack and defense knowledge base (such as restricted access lists like vulnerability databases, virus databases, and potential risk databases, as well as trusted access lists like configuration baseline databases and behavior baseline databases), cybersecurity-related knowledge (such as cybersecurity policies, laws and regulations, information security level protection, commercial cryptography applications, national critical information infrastructure security protection standards, cybersecurity attack and defense technology fundamentals and operation and maintenance requirements), and application domain knowledge, such as knowledge related to railway passenger transport and electronic ticketing transactions needed for railway ticketing system security (such as management methods, technical specifications and standards, policy regulations, operation and maintenance manuals, and failure cases in this field). The construction and continuous updating of the domain knowledge base is crucial for training an LLM into an expert system for its application domain.
[0244] AI algorithm model: Integrates algorithms such as machine learning, deep learning, and reinforcement learning for specific tasks such as risk detection, security incident classification, and automated response.
[0245] Domain-Specific LLM: Based on a general foundational model, a domain-specific LLM is constructed through fine-tuning and training using a domain-specific knowledge base. This results in a dedicated LLM for railway passenger ticket security, providing professional and efficient railway safety operation analysis and reasoning capabilities.
[0246] Language processing capabilities include semantic understanding, text generation, and context learning. Semantic understanding enables accurate parsing of text such as host logs and alarm messages, identifying key entities and intents; text generation can automatically generate professional documents such as fault diagnosis, log analysis, and handling suggestions, improving work efficiency.
[0247] The Intelligent Security Operations Service Layer leverages AI & LLM's intelligent processing capabilities, employing a multi-agent system that integrates the C4ISR model. Through the collaborative operation of multiple agents, it provides intelligent security operations services, including asset management, authentication, monitoring, intelligent security analysis, configuration management, collaborative scheduling, backup, and upgrade services. The collaborative scheduling module achieves cross-service module collaboration and resource optimization through service orchestration and resource scheduling. The asset management service module provides asset discovery and network topology discovery functions, enabling visualized monitoring of asset status. The authentication service module provides a unified identity management framework, ensuring that the right personnel access the right resources at the right time through a dynamic permission management mechanism. The monitoring service module covers availability monitoring, performance monitoring, and other aspects, enabling real-time awareness of system operating status. The configuration management service module enables centralized management and automated deployment of configurations. The backup and upgrade service modules construct a complete data protection system. The intelligent security analysis service module is the core of this layer, implementing complete analysis functions from basic detection to advanced intelligent analysis, specifically including event correlation, risk assessment, security orchestration, vulnerability scanning, baseline checks, and risk detection. Through the aforementioned specialized service modules, the intelligent security operation service layer can cover key application scenarios such as full lifecycle asset management, unified identity authentication, real-time monitoring and early warning, and security operation analysis.
[0248] The user interaction layer supports unified control and management of the platform by operations and maintenance personnel, providing a visual human-machine interface and enabling human-machine collaborative decision-making. This layer, centered on an interaction engine, provides operations and maintenance personnel with functions such as user interaction, alarm analysis, fault diagnosis, and decision support. The user interaction module provides a visual human-machine interface, supporting intelligent question-and-answer functionality and enabling large-scale model question-and-answer analysis in areas such as log analysis and cybersecurity knowledge. The alarm analysis module, based on monitoring and intelligent security analysis services, performs real-time location, correlation analysis, and severity assessment of real-time alarms generated by the system. The fault diagnosis module, based on intelligent security analysis services, performs intelligent diagnosis of fault states and fault cause analysis. The decision support module includes a decision strategy library, storing business rules, historical cases, operations and maintenance strategies, and security specifications. Based on the underlying large-scale model capabilities, it generates recommended decision suggestions to assist operations and maintenance personnel in making final decisions, while simultaneously issuing confirmed decision instructions to the response execution layer.
[0249] The response execution layer, as the platform's security policy execution unit, receives policy instructions from various layers and is responsible for translating intelligent decisions into specific security operations. It performs security operations such as access control, vulnerability remediation, and event response on entities within the object layer. Specifically, the access control module achieves precise control over users, devices, and systems through fine-grained permission management; the vulnerability remediation module is responsible for timely handling of identified security vulnerabilities; the security isolation module provides rapid response capabilities, immediately isolating affected systems to prevent the spread of potential risks when potential attacks or abnormal behavior are detected; the system restoration module is the last line of defense against major security incidents, supporting a one-click rapid recovery mechanism; the data backup and recovery module ensures the security and availability of information assets; the patching and upgrade module manages secure updates to the operating system and applications; the risk warning and degradation module intervenes before potential risks cause substantial damage; and the collaborative linkage control module, based on a unified command protocol, enables secure collaborative linkage and automated execution between security components. All of these modules interface with the intelligent security operation service layer through standardized interfaces, receiving manual decisions from the user interaction layer or automated decision-making instructions from the AI&LLM support layer, and feeding back the execution results from the object layer to the monitoring interface.
[0250] The beneficial effects of implementing this embodiment are: (1) Improved risk assessment and response efficiency: By introducing a large language model in the field of network security as the core of intelligence, it can automatically understand, associate and assess security events, significantly reduce false alarm rate, assist or replace manual preliminary analysis and decision-making, thereby alleviating alarm fatigue and analysis pressure, and improving response timeliness and accuracy.
[0251] (2) Achieved global collaboration and proactive defense: Based on the C4ISR (command, control, communication, computer, intelligence and surveillance and reconnaissance) system, a multi-agent mapping model and collaborative architecture were constructed. Starting from the global system, integrated perception, unified planning, dynamic decision-making and real-time response were carried out to form a closed-loop workflow and achieve a leap from passive response to proactive defense.
[0252] (3) Enhanced asset management and situational awareness capabilities: Through a layered and integrated platform architecture and multi-agent collaboration, it supports automated asset discovery, continuous verification and log integrity monitoring, reduces the attack surface, improves the accuracy and real-time performance of situational awareness, and thus strengthens the overall security operation capabilities.
[0253] This invention can be used in a wide variety of general-purpose or special-purpose computer system environments or configurations. Examples include: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, and distributed computing environments including any of the above systems or devices. This invention can be described in the general context of computer-executable instructions, such as program modules, that are executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform specific tasks or implement specific abstract data types. This invention can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.
[0254] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by instructing related hardware through computer-readable instructions. These computer-readable instructions can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. The aforementioned storage medium can be a non-volatile storage medium such as a magnetic disk, optical disk, or read-only memory (ROM), or random access memory (RAM).
[0255] It should be understood that although the steps in the flowcharts of the accompanying figures are shown sequentially as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the accompanying figures may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.
[0256] Example 2 Please refer to Figure 7 This document illustrates a flowchart of the construction of a large language model for the cybersecurity domain, used in the C4ISR-based intelligent security operation method of this invention. The process of constructing the large language model for the cybersecurity domain begins with the original knowledge base. Questions are generated by constructing a knowledge tree and using a DeepSeek teacher model, transforming the chaotic knowledge into structured training data. This data is then preprocessed, fine-tuned using Qwen-14B, and after evaluation and verification, packaged into a usable model. The model is then deployed to an AI application platform, with prompts and an interface configured, and published as an API service. Simultaneously, the RAG system is optimized through title optimization, intelligent slicing, and vectorized storage to improve retrieval performance. When a user asks a question, the system first searches the domain knowledge base, then combines this with model reasoning to generate an answer, which is then refined and output as the final response.
[0257] The process of building a large language model in the field of cybersecurity mainly includes several steps: knowledge distillation data generation, student model distillation training, deployment and application, RAG optimization, and inference service.
[0258] 1. Knowledge distillation data generation.
[0259] The domain's original knowledge base serves as a knowledge source, providing structured and unstructured data. Knowledge tree construction organizes the knowledge base content into a hierarchical structure, facilitating subsequent retrieval and reasoning. DeepSeek's question-answering training data generation process utilizes a powerful teacher model to automatically generate high-quality question-answer pairs from the knowledge tree. The distillation training data preparation step organizes the generated question-answer pairs into a format suitable for student model training.
[0260] 2. Student model distillation training.
[0261] The data preprocessing step cleans, denoises, and formats the distilled data. The Qwen-14B student model is trained using DeepSeek data distillation, employing data generated by the teacher model to train a smaller student model, achieving knowledge transfer. The model evaluation and validation step assesses the performance of the student model using metrics to ensure it meets application standards. The model export and packaging step exports the trained model and packages it into a deployable format.
[0262] 3. Deployment and application phase.
[0263] The large model application platform deployment steps involve deploying the packaged model to a platform that supports LLM execution. The prompt word engineering configuration steps optimize the prompt word design to improve the model's response quality in real-world scenarios. The application interface design steps develop the user interface. The API service publishing steps provide API interfaces for model inference services, supporting external system calls.
[0264] 4. RAG optimization stage.
[0265] The RAG title optimization, semantic condensation, and keyword enhancement steps optimize and condense the title of the search content to improve search accuracy. The intelligent text slicing and semantic boundary detection step segments long texts into smaller fragments based on semantic boundaries, facilitating precise retrieval. The vectorized storage and Chroma / FAISS indexing step vectorizes the text fragments and stores them in an efficient retrieval database. The knowledge base storage step constructs a vectorized knowledge base that can be used for retrieval.
[0266] 5. Reasoning Service Stage.
[0267] User Submission Steps: Users submit questions via the interface or API. Knowledge Base Retrieval Steps: The system retrieves relevant fragments from the vector knowledge base. Qwen-14B Distillation Model Reasoning and Retrieval Result Fusion Steps: The retrieval results are input into the distillation model for reasoning, combining the retrieval content to generate an answer. Answer Refinement and Output Steps: The generated answer undergoes post-processing and refinement before final output.
[0268] The above process demonstrates a complete large-scale model application chain, from knowledge preparation to model training, deployment, optimization, and service launch. Its core features include: using knowledge distillation to transfer the capabilities of large models to lightweight models; combining RAG technology to enhance the model's mastery of professional knowledge; improving knowledge utilization efficiency through semantic slicing and vector retrieval; and ultimately achieving a deployable, scalable, and knowledge-enhancing domain-specific large-scale language model interactive system.
[0269] Example 3 Further reference Figure 8 As a response to the above Figure 1 The present invention provides an embodiment of an intelligent security operation device based on C4ISR, which implements the method shown. Figure 1 Corresponding to the method embodiments shown, this device can be specifically applied to various electronic devices.
[0270] like Figure 8 As shown, the C4ISR-based intelligent security operation device 70 described in this embodiment includes: a construction module 71, an embedding module 72, an establishment module 73, a design module 74, a formulation module 75, and a fusion module 76. Wherein: Module 71 is used to build large language models in the field of cybersecurity; Embedding module 72 is used to embed the large language model in the network security field as an intelligent core into the existing security operations center; Module 73 is established to build a C4ISR-based multi-agent mapping model. Design module 74 is used to design a multi-agent collaborative working architecture based on the multi-agent mapping model; Module 75 is designed to define the closed-loop workflow of a multi-agent system. Fusion Module 76 is used to design a layered and integrated security operations center platform architecture.
[0271] The beneficial effects of implementing this embodiment are: improved risk assessment and response efficiency, realization of global collaboration and proactive defense, and enhanced asset management and situational awareness capabilities.
[0272] Example 4 To address the aforementioned technical problems, embodiments of the present invention also provide an electronic device. Please refer to [link / reference needed]. Figure 9 , Figure 9 This is a basic structural block diagram of the electronic device in this embodiment.
[0273] The aforementioned electronic device 8 includes a memory 81, a processor 82, and a network interface 83 that are interconnected via a system bus. It should be noted that only the electronic device 8 with components 81, 82, and 83 is shown in the figure; however, it should be understood that it is not required to implement all the shown components, and more or fewer components can be implemented alternatively. Those skilled in the art will understand that the electronic device described here is a device capable of automatically performing numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes, but is not limited to, microprocessors, application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), digital signal processors (DSPs), embedded devices, etc.
[0274] The aforementioned electronic devices can be computing devices such as desktop computers, laptops, handheld computers, and cloud servers. These electronic devices can interact with users via keyboards, mice, remote controls, touchpads, or voice-activated devices.
[0275] The aforementioned memory 81 includes at least one type of readable storage medium, including flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, the aforementioned memory 81 may be an internal storage unit of the aforementioned electronic device 8, such as the hard disk or memory of the electronic device 8. In other embodiments, the aforementioned memory 81 may also be an external storage device of the aforementioned electronic device 8, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc., equipped on the electronic device 8. Of course, the aforementioned memory 81 may also include both internal storage units and external storage devices of the aforementioned electronic device 8. In this embodiment, the aforementioned memory 81 is typically used to store the operating system and various application software installed on the aforementioned electronic device 8, such as computer-readable instructions for intelligent security operation methods based on C4ISR. In addition, the aforementioned memory 81 can also be used to temporarily store various types of data that have been output or will be output.
[0276] In some embodiments, the processor 82 may be a central processing unit (CPU), controller, microcontroller, microprocessor, or other data processing chip. The processor 82 is typically used to control the overall operation of the electronic device 8. In this embodiment, the processor 82 is used to execute computer-readable instructions stored in the memory 81 or to process data, for example, to execute the computer-readable instructions of the C4ISR-based intelligent security operation method.
[0277] The aforementioned network interface 83 may include a wireless network interface or a wired network interface, which is typically used to establish communication connections between the aforementioned electronic device 8 and other electronic devices.
[0278] The beneficial effects of implementing this embodiment are: improved risk assessment and response efficiency, realization of global collaboration and proactive defense, and enhanced asset management and situational awareness capabilities.
[0279] Example 5 The present invention also provides another embodiment, namely, providing a computer-readable storage medium storing computer-readable instructions that can be executed by at least one processor to cause the at least one processor to perform the steps of the C4ISR-based intelligent security operation method described above.
[0280] The beneficial effects of implementing this embodiment are: improved risk assessment and response efficiency, realization of global collaboration and proactive defense, and enhanced asset management and situational awareness capabilities.
[0281] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods of the various embodiments of the present invention.
[0282] Obviously, the embodiments described above are merely some embodiments of the present invention, not all embodiments. The accompanying drawings show preferred embodiments of the present invention, but do not limit the patent scope of the present invention. The present invention can be implemented in many different forms; rather, these embodiments are provided to provide a more thorough and complete understanding of the disclosure of the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing specific embodiments, or make equivalent substitutions for some of the technical features. Any equivalent structures made using the content of this specification and drawings, directly or indirectly applied to other related technical fields, are similarly within the patent protection scope of this invention.< / pid> < / ip>
Claims
1. An intelligent security operation method based on C4ISR, characterized in that, Includes the following steps: Constructing a large language model for the cybersecurity field; The aforementioned large language model in the field of cybersecurity is used as the intelligent core and embedded into the existing security operations center; Establish a C4ISR-based multi-agent mapping model; Based on the aforementioned multi-agent mapping model, a multi-agent collaborative working architecture is designed. Develop a closed-loop workflow for multi-agent systems; Design a layered and integrated security operations center platform architecture.
2. The intelligent security operation method based on C4ISR according to claim 1, characterized in that, The specific steps for constructing a large language model in the cybersecurity field include: Build a knowledge base in the field of cybersecurity; Based on the aforementioned cybersecurity knowledge base, knowledge distillation data is generated; Based on the knowledge distillation data, the student model is fine-tuned, trained, and optimized.
3. The intelligent security operation method based on C4ISR according to claim 1, characterized in that, The step of embedding the large language model in the cybersecurity field as the intelligent core into the existing security operations center specifically includes: Based on the aforementioned large language model in the field of network security, automated log and anomaly analysis is performed; Using the aforementioned large language model in the field of network security, structured security early warning information is extracted, correlated, and generated from multi-source heterogeneous anomaly information data; Based on the aforementioned large language model in the field of network security, automated incident response is performed, generating incident reports, response suggestions, and execution scripts.
4. The intelligent security operation method based on C4ISR according to claim 1, characterized in that, The steps for establishing a C4ISR-based multi-agent mapping model specifically include: Establish semantic mappings from C4ISR elements to cybersecurity intelligent agents; Each intelligent agent is endowed with AI capabilities and domain knowledge, enabling it to independently complete its assigned tasks while also having interfaces to collaborate with other intelligent agents. Integrate a multi-agent management platform.
5. The intelligent security operation method based on C4ISR according to claim 1, characterized in that, The steps for designing a multi-agent collaborative architecture based on the multi-agent mapping model specifically include: Based on the multi-agent mapping model, design the internal cognitive architecture of the agent; Design a multi-agent cooperation protocol; Enables intelligent agents to reflect and learn continuously.
6. The intelligent security operation method based on C4ISR according to claim 1, characterized in that, The specific steps for formulating the closed-loop workflow of a multi-agent system include: Perform intent recognition and task initialization on the intelligent agent; The task is broken down into subtasks that can be executed in parallel or sequentially by different agents, and the dependencies and execution order are determined. Multiple agents are scheduled to execute subtasks in parallel or serially, the results of task execution are collected and integrated into the final output, and feedback is recorded for optimization.
7. The intelligent security operation method based on C4ISR according to any one of claims 1 to 6, characterized in that, The specific steps involved in designing the layered and integrated security operations center platform architecture include: Design object layer and data acquisition and preprocessing layer; Design a large language model support layer and an intelligent security operation service layer in the fields of AI and cybersecurity; Design the user interaction layer and the response execution layer.
8. An intelligent safety operation device based on C4ISR, characterized in that, include: Modules for building large language models in the cybersecurity field; An embedding module is used to embed the large language model in the cybersecurity field as an intelligent core into the existing security operations center; A module is established to build a C4ISR-based multi-agent mapping model; The design module is used to design a multi-agent collaborative architecture based on the multi-agent mapping model. The module is used to define the closed-loop workflow of a multi-agent system. The integration module is used to design a layered and integrated security operations center platform architecture.
9. An electronic device, characterized in that, It includes a memory and a processor, wherein the memory stores computer-readable instructions, and the processor executes the computer-readable instructions to implement the steps of the intelligent security operation method based on C4ISR as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-readable instructions, which, when executed by a processor, implement the steps of the C4ISR-based intelligent security operation method as described in any one of claims 1 to 7.