Chatbot-based Threat Perception Method, Device and Application
Through the situational awareness system, the interactive information between the chat object and the chat robot is analyzed, and the threat situation is identified and defended against threat situations is solved, which solves the information security problem of chat robots that are prone to abuse and ensures the information security of chat robots.
Patent Information
- Application Number
- CN202310467304.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-04-27
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2043-04-27
AI Technical Summary
In the prior art, chat robots are prone to abuse and lead to information security risks. Users perform illegal operations through chat robots, threatening the information security of enterprises and users.
Use the situational awareness system to analyze the interactive information between chat objects and chat robots, obtain interactive security situation information, identify and defend against threat situations, and ensure information security.
Through situational awareness systems, identify and defend against threat situations in chatbot interactions, ensure the security of chatbot information and prevent information leakage and illegal operations.
Smart Images

Figure CN116566934B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to a threat perception method based on a chatbot. Background Art
[0002] Sophisticated chatbots, such as data-driven and predictive (conversational) chatbots, also known as digital assistants, can process data based on technologies such as artificial intelligence (AI), automated rules, natural language processing, and machine learning, and respond to a variety of user requests.
[0003] As a dialogue tool, chatbots can efficiently perform many daily tasks, thereby helping enterprises improve operational efficiency, save costs, provide more convenient and value-added services for internal employees and external customers, and at the same time easily solve various customer problems, handle customer query requests, and reduce the need for manual interaction.
[0004] In addition to helping enterprises improve efficiency and reduce costs, chatbots can also effectively improve the customer experience. For example: Chatbots enable enterprises to interact with an unlimited number of customers in a personalized way. In other words, with the help of chatbots, enterprises can proactively provide personalized services to countless users in a humanized way at the same time.
[0005] However, while chatbots serve users and enterprises, it should also be considered that chatbots may be attacked or threatened, which may lead to potential risks to the information security of enterprises and / or users.
[0006] In particular, the following situations may exist. There are users in the network who abuse chatbots, and these users will use chatbots to perform certain means that threaten enterprises and / or other users. For example, if the user's identity is a hacker, the hacker user can manipulate the chatbot to obtain more data information of the enterprise, such as the core data of the enterprise, the user data stored on the enterprise server, the operation parameters on the enterprise server, and other information.
[0007] Among them, the user can give operation instructions through the dialogue, and the operation instructions can be used to perform the following situations including but not limited to:
[0008] Situation 1, using the chatbot to create dark web market scripts; these scripts can run an automated dark web market for buying and selling stolen account details, credit card information, malware, etc.
[0009] Situation 2, using the chatbot to develop malicious tools, and even in some cases, allowing low-level cybercriminals with low or even no coding skills to create malware.
[0010] In the third scenario, a chatbot is used to recreate malware variants and write common malware.
[0011] In the fourth scenario, a chatbot is used to create a Python-based stealer to search the entire system for common file types (such as Office documents, PDFs, and images). And if any interesting files are found, the malware will copy the files to a temporary directory, compress them, and send them over the network.
[0012] In the fifth scenario, the capabilities of the chatbot are used to impersonate young women to carry out social engineering attacks on vulnerable targets.
[0013] Based on the above scenarios, users can use the corresponding information provided by the chatbot to launch malicious attacks on other users, which will make the network security situation more complex and severe, and at the same time force the chatbot to become a criminal tool for users.
[0014] Although the preset service terms for using the chatbot clearly prohibit the generation of malware, and warnings about content moderation are implemented in the chatbot, in actual operation, users can easily bypass the current system and avoid punishment.
[0015] Therefore, it is necessary to strengthen the supervision of the conversation information and even the interaction information between users and the chatbot to avoid the chatbot from disclosing relevant information of users and enterprises, and also to prevent users from using the aforementioned chatbot to illegally obtain the information stored on the enterprise-level server.
[0016] To prevent the above situation from occurring, the present invention proposes a threat perception method, device, and application based on a chatbot. By using a situation awareness system to analyze the interaction security status of the chat object and the chatbot, corresponding security defenses are given to interaction events with a threat situation, which is an urgent technical problem to be solved currently. Summary of the Invention
[0017] The purpose of the present invention is to overcome the deficiencies of the prior art and provide a threat perception method, device, and application based on a chatbot. The present invention can use a situation awareness system to analyze the interaction security status of the chat object and the chatbot, so as to give corresponding security defenses to interaction events with a threat situation to ensure the information security of the chatbot.
[0018] To solve the existing technical problems, the present invention provides the following technical solutions:
[0019] A threat perception method based on a chatbot, including:
[0020] Information acquisition step: Acquire the interaction information between the chat object and the chatbot;
[0021] Information processing step: Process the aforementioned interaction information to obtain at least one piece of information to be analyzed;
[0022] Information analysis step: Analyze the aforementioned information to be analyzed based on the situation awareness system to obtain the interaction security situation information between the chat object and the chatbot; the interaction security situation information includes the threat situation information of the aforementioned chat object against the chatbot.
[0023] Further, the chat object includes a user and other chatbots controlled by the user.
[0024] Further, the interaction information includes the conversation information and operation information generated by the chat object interacting with the chatbot; the interaction information is expressed through the content in codes, operation instructions, pictures, texts, audios, and / or videos.
[0025] Further, the information to be analyzed includes the operation instruction information for commanding the chatbot to execute, the change information of the chatbot's operation permissions, the interaction security intention information of the chat object, and the security information of the network environment where the chatbot is located.
[0026] Further, the processing in the information processing step specifically includes: extracting the interaction information initiated by the aforementioned chat object and setting it as the first interaction information; obtaining the interaction requirement information of the aforementioned chat object from the aforementioned first interaction information; the interaction requirement information refers to the interaction requirement expressed in the aforementioned first interaction information; according to the preset mapping rules, matching the interaction requirement information with the information to be analyzed.
[0027] Further, the interaction requirement information can also be obtained after comprehensively analyzing the aforementioned first interaction information, the security attribute information of the first interaction information, the context information of the first interaction information, and the security attribute information of the context information.
[0028] Further, when analyzing the aforementioned information to be analyzed based on the situation awareness system, it specifically includes: sorting the aforementioned information to be analyzed based on the threat situation of the aforementioned interaction surface, so as to preferentially analyze the information to be analyzed with a high threat situation in the order from high to low of the aforementioned threat situation; determining the interaction security situation information of the interaction between the chat object corresponding to the aforementioned information to be analyzed and the chatbot based on the order from high to low of the aforementioned threat situation; wherein, the threatened objects corresponding to the threat situation include the aforementioned chat object, the network environment where the aforementioned chat object is located, the chatbot, and / or the network environment where the chatbot is located; both the threat situation and the threatened objects corresponding to the threat situation are recorded in the threat situation information.
[0029] A threat perception device based on a chatbot, comprising a structure:
[0030] An information acquisition unit for acquiring the interaction information between the chat object and the chatbot;
[0031] An information processing unit for processing the foregoing interaction information to obtain at least one piece of information to be analyzed;
[0032] An information analysis unit for analyzing the foregoing information to be analyzed based on a situation awareness system to obtain the interaction security situation information between the chat object and the chatbot; the interaction security situation information includes the threat situation information of the foregoing user against the chatbot.
[0033] A threat perception system based on a chatbot, comprising:
[0034] A network node for receiving and sending data;
[0035] An information security interaction module for protecting the secure interaction between the chat object and the chatbot;
[0036] A system server, the system server being connected to the network node and the information security interaction module;
[0037] The system server is configured to: acquire the interaction information between the chat object and the chatbot; process the foregoing interaction information to obtain at least one piece of information to be analyzed; analyze the foregoing information to be analyzed based on a situation awareness system to obtain the interaction security situation information between the chat object and the chatbot; the interaction security situation information includes the threat situation information of the foregoing user against the chatbot.
[0038] A computer-readable storage medium, in which a computer program is stored, and when the computer program is executed by a processor, the threat perception method based on a chatbot described in any one of the above is implemented.
[0039] Based on the above advantages and positive effects, the advantages of the present invention are: by comparing the operation permissions before and after the chatbot executes an operation for a user instruction, the operation difference information before and after the change of the operation permissions of the chatbot is obtained, so as to determine whether the chatbot is threatened, so as to ensure the information security of the chatbot in the foregoing chat process. Description of the Drawings
[0040] Figure 1 It is a flowchart for implementing the method provided by an embodiment of the present invention.
[0041] Figure 2 It is a flowchart for implementing information processing in the method provided by an embodiment of the present invention.
[0042] Figure 3 This is a flowchart for analyzing information to be analyzed in the method provided by an embodiment of the present invention.
[0043] Figure 4 This is a schematic structural diagram of the device provided by an embodiment of the present invention.
[0044] Figure 5 This is a schematic structural diagram of the system provided by an embodiment of the present invention.
[0045] Description of reference numerals:
[0046] Device 200, information acquisition unit 201, information processing unit 202, information analysis unit 203;
[0047] System 300, network node 301, information security interaction module 302, system server 303. Embodiment
[0048] The following further elaborates in detail a threat perception method, device, and application based on a chatbot disclosed by the present invention in conjunction with the accompanying drawings and specific embodiments. It should be noted that the technical features or combinations of technical features described in the following embodiments should not be considered isolated, and they can be combined with each other to achieve better technical effects. In the accompanying drawings of the following embodiments, the same reference numerals in each drawing represent the same features or components, which can be applied to different embodiments. Therefore, once an item is defined in one drawing, it does not need to be further discussed in subsequent drawings.
[0049] It should be noted that the structures, ratios, sizes, etc. shown in the drawings of this specification are only used to cooperate with the content disclosed in the specification for those skilled in this technology to understand and read, and are not used to limit the limiting conditions for the implementation of the invention. Any modification of the structure, change of the proportional relationship, or adjustment of the size, without affecting the efficacy that the invention can produce and the purpose that can be achieved, should fall within the scope covered by the technical content disclosed by the invention. The scope of the preferred embodiment of the present invention includes additional implementations, in which the functions can be executed in a substantially simultaneous manner or in the reverse order according to the functions involved, rather than in the order described or discussed. This should be understood by those skilled in the technical field to which the embodiments of the present invention belong.
[0050] For technologies, methods, and devices known to those of ordinary skill in the relevant field, they may not be discussed in detail, but in appropriate cases, the said technologies, methods, and devices should be regarded as part of the authorization specification. In all the examples shown and discussed here, any specific value should be interpreted as merely exemplary, rather than as a limitation. Therefore, other examples of the exemplary embodiments may have different values. Embodiment
[0051] The methods, devices, systems, and storage media mentioned in this embodiment are preferably applicable to data-driven and predictive (conversational) chatbots.
[0052] The chatbot can perceive the context and continuously learn using natural language understanding, natural language processing, and machine learning technologies, so as to provide users with more personalized experience services and even predict user needs.
[0053] See Figure 1 As shown, it is a flowchart provided by the present invention. The implementation steps S100 of the method are as follows:
[0054] S101, Information acquisition step: Acquire the interaction information between the chat object and the chatbot.
[0055] In this embodiment, the chat object is preferably a party that interacts with the chatbot, can interact with the chatbot, and generates interaction information during the interaction.
[0056] The interaction information preferably includes the conversation information and operation information generated by the chat object interacting with the chatbot.
[0057] These interaction information can be expressed through the content in codes, operation instructions, pictures, texts, audios, and / or videos, and can be presented on the interaction interface where the chat object interacts with the chatbot.
[0058] In addition, the interaction information can be divided into the interaction information initiated by the chat object and the interaction information replied by the chatbot due to the different identities of the two interacting parties.
[0059] S102, Information processing step: Process the aforementioned interaction information to obtain at least one piece of information to be analyzed.
[0060] The information to be analyzed includes but is not limited to the operation instruction information for commanding the chatbot to execute, the operation permission change information of the chatbot, the interaction security intention information of the chat object, and the security information of the network environment where the chatbot is located.
[0061] When processing the aforementioned interaction information, at least one piece of information to be analyzed can be obtained.
[0062] Taking the operation instruction information for commanding the chatbot to execute in the information to be analyzed as an example, the reason is as follows:
[0063] One of the reasons is that the interaction information initiated by the chat object actually reflects that there are multiple pieces of operation instruction information for commanding the chatbot to execute.
[0064] For example, the chat partner initiates multiple interaction messages, and each interaction message reflects an operation instruction message for the chatbot to execute.
[0065] For another example, the chat partner initiates a long interaction message. After processing the information content reflected by this interaction message based on technologies such as artificial intelligence, automatic rules, natural language processing, and machine learning, multiple operation instruction messages for the chatbot to execute are obtained.
[0066] The second reason is that the interaction message initiated by the chat partner actually reflects one operation instruction message for the chatbot to execute.
[0067] For example, the chat partner initiates an interaction message, and this interaction message can completely reflect one operation instruction message for the chatbot to execute.
[0068] For another example, when an interaction message initiated by the chat partner cannot completely reflect one operation instruction message for the chatbot to execute, the context interaction messages before and after this interaction message of the chat partner, that is, the context interaction messages of this interaction message, will be combined to analyze and obtain at least one operation instruction message for the chatbot to execute.
[0069] It should also be noted that since the information to be analyzed includes but is not limited to the operation instruction message for the chatbot to execute, the operation permission change information of the chatbot, the interaction security intention information of the chat partner, and the security information of the network environment where the chatbot is located.
[0070] Therefore, when the information to be analyzed is the above information, the information to be analyzed can be analyzed and obtained by extracting the information content in the foregoing interaction message from the perspectives of obtaining the above operation instruction message for the chatbot to execute, the operation permission change information of the chatbot, the interaction security intention information of the chat partner, and the security information of the network environment where the chatbot is located.
[0071] When an interaction message initiated by a chat partner cannot be analyzed and obtained the information to be analyzed by extracting the information content in the foregoing interaction message from the perspective of obtaining the foregoing operation instruction message for the chatbot to execute, it can also be analyzed and obtained the information to be analyzed from the perspectives of the operation permission change information of the chatbot, the interaction security intention information of the chat partner, and the security information of the network environment where the chatbot is located by extracting the information content in the foregoing interaction message.
[0072] Based on this, when processing the foregoing interaction message, at least one piece of information to be analyzed can be obtained.
[0073] S103, Information analysis step: Analyze the aforementioned information to be analyzed based on the situation awareness system to obtain the interaction security situation information between the chat object and the chatbot; the interaction security situation information includes the threat situation information of the aforementioned chat object against the chatbot.
[0074] The situation awareness system has the ability to obtain, understand, display, and predict the future development trend of network security based on security elements that can cause changes in the network situation in a large-scale network environment.
[0075] The aforementioned information to be analyzed is obtained by analyzing the aforementioned interaction information. Analyzing the aforementioned information to be analyzed in the aforementioned situation awareness system can, based on the perception ability of the situation awareness system, analyze security elements that can cause changes in the network situation from the aforementioned information to be analyzed, so as to obtain the interaction security situation information of the chat object and the chatbot for interaction.
[0076] Here, it should be noted that the security elements that can cause changes in the network situation analyzed from the aforementioned information to be analyzed can be pre-set. The security elements can match the aforementioned information to be analyzed. The security elements can include but are not limited to operation instructions for commanding the chatbot to execute, the operation permissions of the chatbot, the interaction security intentions of the chat object, and the security status of the network environment where the chatbot is located.
[0077] Preferably, the chat object includes a user and other chatbots controlled by the user.
[0078] In this embodiment, in the case of a user abusing the chatbot, there are two situations for the chat object:
[0079] First, the chat object is a user; considering that the user can break the operation permissions of the chatbot through interaction with the chatbot, and then obtain relevant information that exceeds the operation permissions of the chatbot originally, or obtain malicious software that threatens other users or chatbots, such as Trojan programs.
[0080] Second, the chat object is other chatbots controlled by the user; considering that after the user obtains the operation permissions of other chatbots, especially after the user controls other chatbots with high operation permissions and sends operation instructions to chatbots with low operation permissions, the chatbot will execute operations according to the operation instructions sent by the other chatbots with high operation permissions due to the trust relationship.
[0081] Preferably, the interaction information includes conversation information and operation information generated by the chat object interacting with the chatbot; the interaction information is expressed by the content in codes, operation instructions, pictures, texts, audios, and / or videos.
[0082] The conversation information refers to the communication and / or conversation between the chat object and the chatbot in a way that can recognize human language.
[0083] The operation information refers to the operations executed by the chatbot after obtaining the operation instruction information, and the operations include but are not limited to copying, pasting, providing links, editing, deleting, accessing, and / or writing.
[0084] Preferably, the information to be analyzed includes operation instruction information for commanding the chatbot to execute, operation permission change information of the chatbot, the interactive security intention information of the chat object, and the security information of the network environment where the chatbot is located.
[0085] Among them, the interactive security intention information of the chat object refers to the evaluation information for evaluating whether the operation instruction information given by the chat object in the interaction with the chatbot will pose a threat to the security of the network environment where the chatbot is located. This evaluation information can be set in advance.
[0086] See Figure 2 As shown, it is a flowchart for implementing information processing provided by an embodiment of the present invention. The processing in the information processing steps specifically includes step S110:
[0087] S111, extract the interaction information initiated by the aforementioned chat object and set it as the first interaction information.
[0088] In the process of information processing, considering that most of the network threats caused by the interaction information are caused by the aforementioned chat object who initiated the interaction information. Based on this, it is preferred to analyze the interaction information initiated by the aforementioned chat object.
[0089] S112, obtain the interaction requirement information of the aforementioned chat object from the aforementioned first interaction information; the interaction requirement information refers to the interaction requirement expressed in the aforementioned first interaction information.
[0090] Since the aforementioned first interaction information can be expressed by the content in codes, operation instructions, pictures, texts, audios, and / or videos.
[0091] Therefore, by identifying the information content reflected by the aforementioned first interaction information and mining the information content reflected by the aforementioned first interaction information based on technologies such as artificial intelligence, automatic rules, natural language processing, and machine learning, the interaction requirement information expressed by the aforementioned first interaction information is finally determined.
[0092] S113. Match the information to be analyzed with the interactive requirement information according to a preset mapping rule.
[0093] Considering that the interactive requirement information expressed by the foregoing first interactive information can be recognized and executed by the chatbot. During the execution process, it is necessary to ensure the information security of the chatbot and the security of the network environment where the chatbot is located, so as to avoid situations such as the leakage of user information stored on the network server where the chatbot is located, the destruction of the operation permissions of the chatbot, and the installation of Trojan viruses on the network server where the chatbot is located.
[0094] Therefore, when the chatbot recognizes and executes the interactive requirement information expressed by the foregoing first interactive information, according to the preset mapping rule, match the information to be analyzed with the interactive requirement information from the perspective of network security. Its advantage lies in: using the mapping rule to set the rule for matching the information to be analyzed with the interactive requirement information, and through the interactive requirements expressed in the foregoing first interactive information, multiple pieces of information to be analyzed can be correspondingly matched, so as to determine the interactive security status of the chat object and the chatbot by analyzing the foregoing information to be analyzed, and thus give corresponding security defenses to interactive events in a threatening situation to ensure the information security of the chatbot.
[0095] In this embodiment, each sending and execution of operation instruction information is recorded as an interactive event.
[0096] Preferably, the interactive requirement information can also be obtained after comprehensively analyzing the foregoing first interactive information, the security attribute information of the first interactive information, the context information of the first interactive information, and the security attribute information of the context information.
[0097] When the information content reflected by the first interactive information is too single, it is difficult to extract the interactive requirement information actually expressed by the chat object from the information content reflected by the foregoing first interactive information.
[0098] At this time, by comprehensively analyzing the foregoing first interactive information, the security attribute information of the first interactive information, the context information of the first interactive information, and the security attribute information of the context information to obtain the interactive requirement information expressed by the chat object, the data to be analyzed can be made richer, and thus it is more likely to extract the interactive requirement information expressed by the chat object.
[0099] See Figure 3 As shown, it is a flowchart for analyzing the information to be analyzed provided by an embodiment of the present invention. When analyzing the foregoing information to be analyzed based on the situation awareness system, it specifically includes step S120:
[0100] S121. Sort the aforementioned information to be analyzed based on the threat situation faced by the aforementioned interaction interface, so as to preferentially analyze the information to be analyzed with a high threat situation in descending order of the aforementioned threat situation.
[0101] Considering that preferentially analyzing the information to be analyzed with a high threat situation can, with a greater probability, ensure network security and timely give corresponding defense strategies when facing a higher threat situation to ensure network security.
[0102] Therefore, when analyzing the aforementioned information to be analyzed based on the situation awareness system, it is preferable to obtain corresponding scores for the information to be analyzed according to preset threat situation indicators to determine the development trend of the threat situation pointed to by the aforementioned information to be analyzed and the threatened objects corresponding to the threat situation, and then use the corresponding defense strategies given by the aforementioned situation awareness system to contain the aforementioned threat situation and even eliminate the impact of the aforementioned threat situation on network security.
[0103] It should be noted that the threatened objects corresponding to the threat situation include the aforementioned chat object, the network environment where the aforementioned chat object is located, the chat robot, and / or the network environment where the chat robot is located.
[0104] Both the threat situation and the threatened objects corresponding to the threat situation are recorded in the threat situation information.
[0105] S122. Based on the descending order of the aforementioned threat situation, determine the interactive security situation information of the interaction between the chat object corresponding to the aforementioned information to be analyzed and the chat robot.
[0106] The interactive security situation information refers to the situation information related to interactive security in the aforementioned interaction process.
[0107] The interactive security situation information includes, but is not limited to, the threat situation information, security situation information, and vulnerability situation information of the aforementioned chat object against the chat robot.
[0108] Other technical features refer to the previous embodiments and will not be elaborated here.
[0109] See Figure 4 As shown, the present invention also gives an embodiment, providing a threat perception device 200 based on a chat robot, including the following structure:
[0110] An information acquisition unit 201 for acquiring the interaction information between the chat object and the chat robot.
[0111] An information processing unit 202 for processing the aforementioned interaction information to obtain at least one piece of information to be analyzed.
[0112] An information analysis unit 203 is configured to analyze the aforementioned information to be analyzed based on the situation awareness system, so as to obtain the interactive security situation information of the chat object and the chatbot; the interactive security situation information includes the threat situation information of the aforementioned user against the chatbot.
[0113] In addition, as shown in Figure 5 the present invention also provides an embodiment of a threat perception system 300 based on a chatbot, including:
[0114] A network node 301 for receiving and transmitting data.
[0115] An information security interaction module 302 for protecting the secure interaction between the chat object and the chatbot.
[0116] A system server 303, where the system server 303 is connected to the network node 301 and the information security interaction module 302.
[0117] The system server 303 is configured to: obtain the interaction information between the chat object and the chatbot; process the aforementioned interaction information to obtain at least one piece of information to be analyzed; analyze the aforementioned information to be analyzed based on the situation awareness system to obtain the interactive security situation information of the chat object and the chatbot; the interactive security situation information includes the threat situation information of the aforementioned user against the chatbot.
[0118] For other technical features, please refer to the previous embodiments and will not be elaborated here.
[0119] In addition, an embodiment of the present invention also provides a computer-readable storage medium, in which a computer program is stored for use in the aforementioned threat perception device based on a chatbot, and when the computer program is executed by a processor, it implements the threat perception method based on a chatbot described in any one of the above.
[0120] For other technical features, please refer to the previous embodiments and will not be elaborated here.
[0121] In the above description, within the scope of the object protection of the present disclosure, the components can be selectively and operably combined in any number. In addition, terms such as "including", "comprising" and "having" should be construed as inclusive or open by default, rather than exclusive or closed, unless it is explicitly defined to have the opposite meaning. All technical, scientific or other terms conform to the meaning understood by those skilled in the art, unless it is defined to have the opposite meaning. Common terms found in the dictionary should not be interpreted too idealistically or too unrealistically in the context of relevant technical documents, unless the present disclosure explicitly defines it as such.
[0122] While example aspects of the present disclosure have been described for purposes of illustration, those skilled in the art will recognize that the foregoing description is only of the preferred embodiments of the invention and is not any limitation on the scope of the invention. The scope of the preferred embodiments of the invention includes additional implementations, where functions may be performed in an order different from that presented or discussed. Any changes and modifications made by those of ordinary skill in the art based on the foregoing disclosure fall within the scope of the claims.
Claims
1. A threat perception method based on a chatbot, characterized in that, Including: Information acquisition step: acquiring the interaction information between the chat object and the chatbot; Information processing step: processing the aforementioned interaction information to obtain at least one piece of information to be analyzed; The interaction information can be expressed through the content in code, operation instructions, pictures, text, audio and / or video, and presented on the interaction interface where the chat object interacts with the chatbot; Information analysis step: analyzing the aforementioned information to be analyzed based on the situation awareness system to obtain the interaction security situation information between the chat object and the chatbot; the information to be analyzed includes the operation instruction information for commanding the chatbot to execute, the change information of the operation permission of the chatbot, the interaction security intention information of the chat object, and the security information of the network environment where the chatbot is located; The interaction security situation information includes the threat situation information, security situation information and vulnerability situation information of the aforementioned chat object against the chatbot; among them, when analyzing the aforementioned information to be analyzed based on the situation awareness system, it specifically includes: sorting the aforementioned information to be analyzed based on the threat situation on the interaction surface, so as to analyze the information to be analyzed with a high threat situation preferentially in the order from high to low of the aforementioned threat situation; determining the interaction security situation information of the chat object and the chatbot corresponding to the aforementioned information to be analyzed based on the order from high to low of the aforementioned threat situation.
2. The method according to claim 1, wherein The chat object includes a user and other chatbots controlled by the user.
3. The method according to claim 1, characterized in that The interaction information includes the conversation information and operation information generated by the chat object interacting with the chatbot; the interaction information is expressed through the content in code, operation instructions, pictures, text, audio and / or video.
4. The method according to claim 1, wherein The processing in the information processing step specifically includes: extracting the interaction information initiated by the aforementioned chat object and setting it as the first interaction information; obtaining the interaction requirement information of the aforementioned chat object from the aforementioned first interaction information; the interaction requirement information refers to the interaction requirement expressed in the aforementioned first interaction information; matching the information to be analyzed for the interaction requirement information according to the preset mapping rule.
5. The method according to claim 4, wherein The interaction requirement information can also be obtained after comprehensively analyzing the aforementioned first interaction information, the security attribute information of the first interaction information, the context information of the first interaction information, and the security attribute information of the context information.
6. The method according to claim 1, characterized in that Wherein, The threatened object corresponding to the threat situation includes the aforementioned chat object, the network environment where the chat object is located, the chatbot, and / or the network environment where the chatbot is located; both the threat situation and the threatened object corresponding to the threat situation are recorded in the threat situation information.
7. A chatbot-based threat perception device according to the method of any one of claims 1-6, characterized in that, Including structure: An information acquisition unit for acquiring the interaction information between the chat object and the chatbot; An information processing unit for processing the aforementioned interaction information to obtain at least one piece of information to be analyzed; the interaction information can be expressed through the content in code, operation instructions, pictures, text, audio and / or video, and presented on the interaction interface where the chat object interacts with the chatbot; An information analysis unit is configured to analyze the aforementioned information to be analyzed based on a situation awareness system, so as to obtain the interactive security situation information of the chat object and the chatbot; the information to be analyzed includes operation instruction information for commanding the chatbot to execute, operation permission change information of the chatbot, interactive security intention information of the chat object, and security information of the network environment where the chatbot is located. The interactive security situation information includes the threat situation information, security situation information, and vulnerability situation information of the aforementioned user with respect to the chatbot; wherein, when analyzing the aforementioned information to be analyzed based on the situation awareness system, it specifically includes: sorting the aforementioned information to be analyzed based on the threat situation faced by the interaction surface, so as to analyze the information to be analyzed with a high threat situation preferentially in the order from high to low of the aforementioned threat situation; determining the interactive security situation information of the chat object corresponding to the aforementioned information to be analyzed and the chatbot to interact based on the order from high to low of the aforementioned threat situation.
8. A chatbot-based threat perception system according to the method of any one of claims 1-6, characterized in that It includes: A network node for receiving and transmitting data. An information security interaction module for protecting the secure interaction between the chat object and the chatbot. A system server, and the system server is connected to the network node and the information security interaction module. The system server is configured to: obtain the interaction information between the chat object and the chatbot; process the aforementioned interaction information to obtain at least one piece of information to be analyzed; the interaction information can be expressed through the content in code, operation instructions, pictures, texts, audios, and / or videos, and is presented on the interaction interface where the chat object and the chatbot interact; analyze the aforementioned information to be analyzed based on the situation awareness system to obtain the interactive security situation information of the chat object and the chatbot; the information to be analyzed includes operation instruction information for commanding the chatbot to execute, operation permission change information of the chatbot, interactive security intention information of the chat object, and security information of the network environment where the chatbot is located. The interactive security situation information includes the threat situation information, security situation information, and vulnerability situation information of the aforementioned user with respect to the chatbot; wherein, when analyzing the aforementioned information to be analyzed based on the situation awareness system, it specifically includes: sorting the aforementioned information to be analyzed based on the threat situation faced by the interaction surface, so as to analyze the information to be analyzed with a high threat situation preferentially in the order from high to low of the aforementioned threat situation; determining the interactive security situation information of the chat object corresponding to the aforementioned information to be analyzed and the chatbot to interact based on the order from high to low of the aforementioned threat situation.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the method according to any one of claims 1-6.
Citation Information
Patent Citations
Method and system for preventing malicious search chatting robot loopholes
CN112559724A
Negotiative conversation chat bot
US20200169554A1