Network security event processing method and device, electronic equipment and storage medium

By using a large language model and a prompt word model to collaboratively process cybersecurity incidents, the problem of human dependence in traditional methods is solved, enabling timely detection and efficient emergency response to cybersecurity incidents.

CN119182559BActive Publication Date: 2025-11-21BEIJING QIYI CENTURY SCI & TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411116383.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-14
Publication Date
2025-11-21
Estimated Expiration
2044-08-14

AI Technical Summary

Technical Problem

Traditional methods of handling cybersecurity incidents rely on human observation and expertise, making it difficult to detect and handle cybersecurity incidents in a timely manner and efficiently.

Method used

The system uses a large language model to monitor network security incidents, outputs alarm information, generates response strategies based on user interaction information, and automatically instructs the large language model to handle the situation using a prompt word model.

Benefits of technology

It enables timely notification of users when a cybersecurity incident occurs and automatically and efficiently handles cybersecurity incidents, reducing reliance on human intervention and improving processing efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119182559B_ABST
    Figure CN119182559B_ABST
Patent Text Reader

Abstract

The application provides a network security event processing method and device, electronic equipment and storage medium, which belong to the technical field of network security. The method comprises the following steps: in response to receiving a monitoring instruction for a network security event, instructing a large language model to monitor the network security event based on the monitoring instruction; when receiving a monitoring result of the network security event monitored by the large language model, outputting alarm information for the monitoring result; in response to receiving user interaction information input for the alarm information, instructing the large language model to output a response strategy for the network security event based on the user interaction information; inputting the response strategy into a prompt word model to obtain a security response instruction for the network security event; and instructing the large language model to process the network security event based on the security response instruction and output a processing result for the network security event. The processing efficiency of the network security event is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of network security technology, and specifically relates to a method, apparatus, electronic device and storage medium for handling network security incidents. Background Technology

[0002] With the rapid development of information technology, cybersecurity issues are becoming increasingly serious. Traditional cybersecurity defense and emergency response methods typically involve using monitoring devices to monitor specific cybersecurity incidents, providing the monitoring data to users for review, and allowing users to take appropriate action when a cybersecurity incident is detected.

[0003] This approach not only requires users to observe cybersecurity incidents in real time, making it difficult to detect them promptly, but also requires users to possess certain professional knowledge to respond to and handle cybersecurity incidents independently. The efficiency of handling cybersecurity incidents depends on human resources, making it difficult to guarantee the efficiency of handling cybersecurity incidents. Summary of the Invention

[0004] This application provides a method, apparatus, electronic device, and storage medium for handling network security incidents.

[0005] Some embodiments of this application provide a method for handling network security incidents, the method comprising:

[0006] In response to receiving a monitoring instruction for a network security incident, the system instructs a large language model to monitor the network security incident based on the monitoring instruction.

[0007] Upon receiving the monitoring results of the network security event detected by the large language model, an alarm message for the monitoring results is output;

[0008] In response to receiving user interaction information for the alarm information input, the large language model is instructed to generate and output a response strategy for the network security incident based on the user interaction information;

[0009] The response strategy is input into the prompt word model to obtain security response instructions for the network security incident.

[0010] Based on the security response instruction, the large language model is instructed to process the network security incident and output the processing result for the network security incident.

[0011] Some embodiments of this application provide a network security incident handling apparatus, the apparatus comprising:

[0012] A receiving module is configured to respond to receiving a monitoring instruction for a network security incident, and instruct a large language model to monitor the network security incident based on the monitoring instruction;

[0013] The alarm module is used to output alarm information for the monitoring results when it receives the monitoring results of the network security event detected by the large language model;

[0014] An interaction module is used to respond to user interaction information received in response to the alarm information, and to instruct the large language model to generate and output a response strategy for the network security incident based on the user interaction information.

[0015] The response module is used to input the response strategy into the prompt word model to obtain security response instructions for the network security incident;

[0016] Based on the security response instruction, the large language model is instructed to process the network security incident and output the processing result for the network security incident.

[0017] Some embodiments of this application provide a computing processing device, including:

[0018] Memory containing computer-readable code;

[0019] One or more processors, when the computer-readable code is executed by the one or more processors, the computing processing device performs the network security incident handling method as described above.

[0020] Some embodiments of this application provide a computer program, including computer-readable code, which, when executed on a computing processing device, causes the computing processing device to perform the network security event handling method described above.

[0021] Some embodiments of this application provide a non-transient computer-readable medium storing a method for handling network security events as described above.

[0022] The network security incident handling methods, apparatuses, electronic devices, and storage media provided in some embodiments of this application monitor network security incidents using a large language model. When a network security incident occurs, the user can be promptly notified through alarm information. Furthermore, by receiving user interaction information, the large language model can be instructed to analyze the network security incident to obtain a response strategy. In addition, the prompt word model can be used to automatically instruct the large language model to handle the network security incident based on the response strategy. This enables the large language model to assist users in timely detection of network security incidents and to efficiently handle emergency response to network security incidents.

[0023] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, the following are specific embodiments of this application. Attached Figure Description

[0024] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0025] Figure 1 The schematic diagram illustrates a flowchart of a network security incident handling method provided in some embodiments of this application;

[0026] Figure 2 The diagram illustrates a system schematic of a network security incident handling method provided in some embodiments of this application.

[0027] Figure 3 This illustration schematically shows one of the flowcharts of another method for handling network security incidents provided in some embodiments of this application;

[0028] Figure 4 This illustration shows a second flowchart of another method for handling network security incidents provided in some embodiments of this application;

[0029] Figure 5 The third schematic diagram illustrates another method for handling network security incidents provided in some embodiments of this application;

[0030] Figure 6 The fourth schematic diagram illustrates another method for handling network security incidents provided in some embodiments of this application;

[0031] Figure 7 The fifth schematic diagram illustrates another method for handling network security incidents provided in some embodiments of this application;

[0032] Figure 8 The diagram illustrates a system schematic of another method for handling network security incidents provided in some embodiments of this application.

[0033] Figure 9 The schematic diagram illustrates the structure of a network security incident processing apparatus provided in some embodiments of this application;

[0034] Figure 10 The schematic diagram illustrates the structure of an exemplary device provided in some embodiments of this application. Detailed Implementation

[0035] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0036] Figure 1 The schematic diagram illustrates a flowchart of a method for handling network security incidents provided in this application, the method comprising:

[0037] Step 101: In response to receiving a monitoring instruction for a network security incident, instruct the large language model to monitor the network security incident based on the monitoring instruction.

[0038] It should be noted that, in some embodiments of this application, network security events refer to object events that threaten hardware resources, software resources, or data resources in the network system, such as causing damage to the network system, data tampering, data leakage, threatening the continuous normal operation of the network system, or causing network service interruption, etc.

[0039] Large Language Models (LLMs) are deep learning-based natural language processing models characterized by their ability to process massive amounts of text data through large-scale unsupervised or semi-supervised learning methods to understand and serve human language comprehension and generation. The core of LLMs lies in using large-scale data training to mimic the human language cognition and generation process, enabling them to largely simulate human language cognition and generation capabilities. LLM models typically have billions to trillions of parameters and can perform various natural language processing tasks, including but not limited to natural language generation, text classification, text summarization, machine translation, and speech recognition. In some embodiments of this application, the large language models are trained by collecting relevant data on network security incidents. This data may include log files, intrusion detection system alerts, network traffic data, etc. The collected data needs to undergo preprocessing, including noise removal, data cleaning, and standardization, to ensure the accuracy and consistency of subsequent steps. This allows the large language model to perform operations such as monitoring and identification, analysis and evaluation, providing solutions, and response processing for network security incidents.

[0040] Optionally, step 101 above may include:

[0041] S1011. In response to receiving a monitoring instruction for a network security incident, determine the characteristic information of the network security incident based on the monitoring instruction.

[0042] S1012. Input the feature information into the large language model so that the large language model can monitor the network security events represented by the feature information.

[0043] Specifically, in this embodiment, the user can specify the corresponding network security event by inputting the data characteristics and behavioral characteristics of the network security event to be monitored, or input identification information that has a mapping relationship with the data characteristics or behavioral characteristics of the network security event, such as name or event number, to indicate the corresponding network security event. Thus, this embodiment can directly obtain the feature information carried by the monitoring command, or obtain the feature information of the network security event based on the identification information carried by the monitoring command. Then, by inputting the feature information into the large language model, the large language model can be informed of the network security event that needs to be monitored.

[0044] Furthermore, after identifying the network security events to be monitored based on the characteristic information of the network security events carried by the monitoring instructions, the large language model can monitor these events. Specifically, the large language model can collect data on the data transmission process and operational status of the monitored objects corresponding to the network security events, and then compare the collected operational data and operational status with the characteristic information of the network security events to achieve network security event monitoring.

[0045] Step 102: Upon receiving the monitoring results of the network security event detected by the large language model, output alarm information for the monitoring results.

[0046] In this embodiment, when monitoring network security events, the large language model can compare the collected operational data and operational status with the feature information of the network security event. If the comparison is successful, it is determined that a network security event has been detected. This embodiment can send alarm information to the client as the monitoring result, reminding the user to handle it immediately. Specifically, the feature information of the network security event may include the operational data and operational status corresponding to the occurrence of the network security event. Therefore, this embodiment can compare the collected operational data and operational status with the feature information of the network security event. When the collected operational data and operational status are consistent with the feature information of the network security event, the comparison is successful, and it is determined that a network security event has been detected. Correspondingly, when they are inconsistent, the comparison fails, it is determined that no network security event has been detected, and monitoring can continue.

[0047] The client can send alarm information to users via text, images, videos, voice, emails, SMS, and other notification methods. After being notified of the alarm information, users can log in to the client to perform subsequent processing operations.

[0048] Step 103: In response to receiving user interaction information input for the alarm information, instruct the large language model to generate and output a response strategy for the network security incident based on the user interaction information.

[0049] In this embodiment of the application, user interaction information refers to the language information regarding the handling method of the network security event described in the alarm information. Users can input this user interaction information into the client through voice input or text input.

[0050] For example, when the network security incident is a "remote network attack", the user interaction information can be "cut off the source of the network attack", "strengthen firewall protection", etc., so that the embodiments of this application can instruct the large language model to process security based on the user interaction information.

[0051] This application embodiment can extract and identify keyword information from user interaction information, and then input the keyword information into a semantic recognition model to identify the true semantic information of the user interaction information. However, user interaction information often only shows a relatively broad processing approach. To generate more specific response strategies, this application embodiment can input the true semantic information into a large language model. This allows the large language model to assess the threat level of cybersecurity incidents based on third-party threat intelligence data integrated during training (including but not limited to publicly available vulnerability information, hacker organization activities, etc.) and the collected operational data and operational status. Furthermore, it can comprehensively analyze the assessed threat level and the user's true semantic information to obtain a corresponding response strategy, which is then sent to the client for the user to view.

[0052] Step 104: Input the response strategy into the prompt word model to obtain security response instructions for the network security incident.

[0053] Step 105: Based on the security response instruction, instruct the large language model to process the network security event and output the processing result for the network security event.

[0054] In this embodiment, the Prompt Template is a reproducible method for generating prompts. It contains a text string that can receive a set of parameters from the end user to generate prompts. The Prompt Template can contain instructions, a number of instances, and a question posed by a language model. By using the Prompt Template, security response instructions that are more in line with natural language norms and more easily recognized by large language models can be generated, thereby instructing the large language model to perform natural language interaction and handle network security incidents according to the security response instructions.

[0055] Specifically, embodiments of this application can also automatically respond to network security incidents. After the large language model outputs a response strategy, in order to respond to network security incidents promptly and prevent further escalation, the response strategy can be automatically input into the prompt word model to generate a security response instruction. This instruction then instructs the large language model to adopt the response strategy to handle the network security incident. Therefore, without user intervention, network security incidents can be responded to and processed quickly, promptly eliminating the security threats posed by network security incidents to the network system.

[0056] For example, when the response strategy is to block the source IP of a network attack, a security response command of "Block the source IP of the network tool using an IP blocking tool" can be input into the large language model. The large language model will then call any available IP blocking tools to block the identified source IP of the attack. When the response strategy is to limit the number of terminal requests, a security response command of "Limit the bandwidth of the service interface using a bandwidth control tool" can be input into the large language model. The large language model will then call the bandwidth control tool to monitor the traffic of each interface connected to the terminal. When the interface traffic exceeds the bandwidth limit, the interface traffic will be automatically limited to achieve the purpose of limiting the bandwidth of the service interface. Of course, this is only an illustrative description, and the specific response strategy can be set according to actual needs, which is not limited here.

[0057] During the process of handling cybersecurity incidents based on response strategies, the large language model will continuously provide feedback on the processing results to the client, so that users can understand the progress of the cybersecurity incident processing in a timely manner through the client. After viewing the processing results, users can also continue to input user interaction information through the client to instruct the large language model to adjust the response strategy, thereby enabling the large language model to assist users in handling cybersecurity incidents flexibly.

[0058] Specifically, refer to Figure 2 The input interface, "Input Variables," feeds user interaction information into the system application, integrating the Large Language Model (LLM) and Prompt Template (LTM). First, the LLM processes the user interaction information using the Prompt Template, then inputs instructions into the LLM. The LLM then queries the database for corresponding response strategies and tools. Based on the response strategies, the LLM automatically controls the processing of network security incidents using the Prompt Template, and outputs the results to the client through the application's output interface.

[0059] For example, after a user inputs the network security event to be monitored through user interaction information, the large language model will output a response strategy for the user interaction information. This strategy may include the tools to be used, such as the sqlmap plugin. Optionally, before calling the sqlmap plugin to process the network security event based on the response strategy, the large language model can also generate and display a task ID. This task ID can be a unique identifier assigned to the network security event, and the processing result can carry this task ID to distinguish the processing results for different network security events. Finally, after the large language model completes the processing of the network security event, it can output the processing result based on the sqlmap plugin, which may include the detected network security vulnerabilities.

[0060] This application embodiment utilizes a large language model to monitor network security events. When a network security event occurs, it can promptly notify the user through alarm information. Then, by receiving user interaction information, it instructs the large language model to analyze the network security event to obtain a response strategy. Furthermore, it can utilize a prompt word model to automatically instruct the large language model to handle the network security event based on the response strategy. This enables the large language model to assist users in timely detection of network security events and to efficiently handle emergency response to network security events.

[0061] Optionally, refer to Figure 3 Step 103 includes:

[0062] Step 1031: Input the user interaction information into the prompt word model to obtain the prompt word corresponding to the user interaction information.

[0063] Step 1032: Input the prompt words into the large language model to obtain the response strategy for the network security incident.

[0064] In this embodiment, the prompt word model includes a feature string template. Prompt words are generated by extracting keywords from user interaction information and then filling these keywords into the prompt string template. Prompt words generated in this way are more easily and accurately recognized by large language models. Compared to the irregular format and content of user interaction information, since the string template is set based on the recognition performance of the large language model, the resulting prompt words allow the large language model to more accurately understand the actual semantics of the user interaction information, thereby enabling it to more accurately output response strategies that meet the user's interaction needs.

[0065] For example, if the user interaction information is "block access information for Apple", if the user interaction information is directly input into the large language model, the large language model will have difficulty determining whether "Apple" refers to the fruit apple or the Apple brand. However, if the prompt word model is used, the user interaction information can be converted into the prompt word "block access information for Apple brand terminal devices". In this way, the large language model can clearly know that the target is Apple brand terminal devices.

[0066] Of course, this is just an explanation for ease of understanding. The actual use of the prompt word model is to standardize and transform user interaction information, so that the quality of the language information input to the large language model can be guaranteed, thereby improving the accuracy of the large language model in responding to user interaction information.

[0067] Optionally, the prompt words include at least: question information, thinking information, action information, and observation information, as shown in the reference. Figure 4 Step 1032 includes:

[0068] Step 10321: Input the question information into the large language model to obtain the semantic information corresponding to the user interaction information.

[0069] Step 10322: Input the thought information and the semantic information into the large language model to obtain the handling method for the network security incident.

[0070] Step 10323: Input the processing method, tool list and action information into the large language model to obtain the target tool identifier in the tool list for processing the network security incident.

[0071] Step 10324: Input the processing method, target tool identifier and observation information into the large language model to obtain the response strategy.

[0072] In this embodiment of the application, the execution flow template of the prompt word model can be the standard ReAct flow of "thinking -> action -> action input -> observation". Thinking refers to thinking about how to solve the user's problem, action refers to the tools needed to solve the problem, action input refers to the parameters needed by the tools, and observation refers to the results obtained after the tools are executed.

[0073] Specifically, the process begins by generating problem information based on user interaction data. This problem information is then input into a large language model to identify the problem that needs to be solved. Next, the identified semantic and cognitive information is input into the large language model to instruct it to determine the appropriate approach to solve the problem. The approach, a list of available tools, and action information are then input into the large language model, enabling it to output the target tool identifiers and input parameters for the tools needed to solve the problem. Finally, the approach, target tool identifiers, and observation information are input into the large language model to analyze and derive the response strategy.

[0074] For example, the template could be, for instance:

[0075] {tools}

[0076] Please follow the format below:

[0077] Question information: Input questions you must answer;

[0078] Thinking message: You should always consider how to do it;

[0079] Action information: The action to be taken should be one of the {tool_names};

[0080] Execution input: Use tools to solve the problem;

[0081] Observation information: Observe the processing results of the tools;

[0082] ...(Thinking → Action → Action Input → Observation, can be repeated N times)

[0083] Thinking question: Do I know the final answer now?

[0084] Final answer: The final answer to the user interaction information of the original input.

[0085] As you can see, the template has two variables: `tools` and `tool_names`. The `tools` variable is a list of all tools, with each element containing the tool's name and description. The `tool_names` variable is a list of tool names; passing in a specific tool identifier will generate the corresponding tool list. For example, if we have the following two tools, the parsed result will look like this:

[0086] You can use the following public and possible answers to the question:

[0087] Search: A tool for performing online searches;

[0088] Sqlmap: SQL injection scanning tool.

[0089] Of course, the tools described here are only examples, and the specific tools can be set according to actual needs. No limitations are made here.

[0090] This application embodiment uses a process template of questions, thoughts, actions, and observations to transform user interaction information into prompt words for inputting into a large language model. This automatically guides the large language model to respond to user interaction information without requiring continuous user interaction with the large language model, thus improving the efficiency and accuracy of the large language model in outputting response strategies for network security incidents.

[0091] Optionally, refer to Figure 5 Step 10324 includes:

[0092] Step 103241: Input the processing method, target tool identifier and observation information into the large language model to obtain the observation results.

[0093] Step 103242: When the observation results do not meet the expected requirements, proceed to the step of inputting the problem information into the large language model to obtain the semantic information corresponding to the user interaction information.

[0094] Step 103243: When the observation results meet the expected requirements, output a response strategy based on the target tool identifier and the processing method.

[0095] In this embodiment, the process template of questioning, thinking, acting, and observing can be repeated multiple times until the observed results meet the expected requirements. The template has two output variables: input and agent_scratchpad. Input refers to the user interaction information entered by the user, and agent_scratchpad represents the thought process based on the process template, including thinking, acting, action input, and observation. During execution, agent_scratchpad will be substituted with specific values ​​and continuously updated based on the execution process.

[0096] For example, such as:

[0097] Problem information: Please help me check if http: / / testphp.com has an SQL injection vulnerability;

[0098] Information for consideration: We need to monitor this using the sqlmap tool;

[0099] Action information: search;

[0100] Action input: http: / / testphp.com;

[0101] Observation information: Monitoring results of the sqlmap tool for http: / / testphp.com;

[0102] Thinking Information: You should always keep thinking about whether this tool can solve the problem, and if not, what other methods can be used to solve it. If the problem is solved, output the monitoring results.

[0103] If the monitoring results achieve the expected results, a response strategy containing input and agent_scratchpad can be output. This is merely an example; the specific settings for problem information, thought information, action information, action input, and observation information can be configured according to actual needs and are not limited here.

[0104] This application embodiment cyclically executes the process of questioning, thinking, acting, and observing until the observed information meets the expected effect. This allows the large language model to automatically think about and handle response strategies for network security incidents based on user interaction information, without requiring continuous user interaction with the large language model. This improves the efficiency and accuracy of the large language model in outputting response strategies for network security incidents.

[0105] Optionally, refer to Figure 6 The 103 includes:

[0106] Step S1: Decompose the user interaction information to obtain at least two task information.

[0107] Step S2: Input the at least two task information into the large language model respectively to obtain the response strategy corresponding to each task information.

[0108] In this embodiment, the prompt word model can decompose user interaction information into multiple different task information and input them into a large language model for processing. It is understood that user interaction information may contain multiple different task operations, requiring different tools to implement the corresponding processing operations. If directly input into the large language model, the large language model would need to execute the processing operations one by one, which would reduce processing efficiency. However, by decomposing the user interaction information into multiple different task information and inputting them into the large language model, the large language model can process the different task information concurrently, thereby improving the processing efficiency of user interaction information.

[0109] Optionally, refer to Figure 7 Step 105 includes:

[0110] Step 1051: Input the security response instruction corresponding to each task information into the large language model to obtain the processing result corresponding to each task information.

[0111] Step 1052: Merge the processing results of at least two task information to obtain the processing result for the network security incident.

[0112] In this embodiment of the application, after different tools are used to obtain processing results for different task information, in order to enable multiple processing results to provide feedback on a single user interaction information, this embodiment of the application can merge the processing results output by the large language model for different task information and provide feedback to the user, so that the user can intuitively understand the processing results of their input user interaction information.

[0113] For example, refer to Figure 8 In this embodiment, user interaction information is input as a "Prompt" into the system. The system (Agent) uses a prompt word model to break down the user interaction information into task information 1, task information 2, and task information 3. Task information 1 can be executed by tool 1, and task information 2 and task information 3 can be executed by tool 2. After the system assigns different task information to the corresponding tools for execution, it obtains corresponding processing results 1, 2, and 3. Then, the system merges the three processing results and sends them to the client for the user to view. Of course, this is just an illustrative description, and the specific settings can be configured according to actual needs, which is not limited here.

[0114] This application embodiment breaks down user interaction information into multiple task information items, which are then input into a large language model for processing. This allows the large language model to process multiple task information items within the same user interaction information in parallel, and then merge them before outputting the result. This improves the efficiency of the large language model in responding to user interaction information and handling network security incidents.

[0115] Optionally, after step 105, the method further includes: generating a network security report for the network security incident based on the monitoring results, the user interaction information, and the processing results, and outputting the network security report.

[0116] In this embodiment of the application, the large language model can analyze and summarize past cybersecurity incidents, and generate cybersecurity reports based on monitoring results, user interaction information, and processing results generated during the cybersecurity incident handling process.

[0117] Specifically, this cybersecurity report may include, but is not limited to: Introduction: Briefly introduce the purpose and background of the report, as well as its main content and conclusions. Cybersecurity Status Analysis: Describe the current cybersecurity situation, potential security vulnerabilities, and problems that need to be addressed. Cybersecurity Strategies and Measures: Propose specific measures and methods to address cybersecurity threats, including but not limited to strengthening network management, raising security awareness, updating security facilities, and conducting security audits. These measures should be targeted and can be adjusted according to actual circumstances. Cybersecurity Education and Training: Introduce how to improve employees' security awareness and skills through education and training to better address cybersecurity challenges. This may involve regular security training, online courses, and practical drills. Cybersecurity Monitoring and Early Warning: Describe how to utilize existing technologies and methods for cybersecurity monitoring, and how to issue early warnings and respond when potential threats are discovered. Report Conclusions and Recommendations: Summarize the report's content and provide suggestions and expectations for future cybersecurity work.

[0118] This application embodiment generates a network security report based on past data of processed network security incidents and displays it to the user, thereby enabling the user to easily obtain reference cases of network security incidents.

[0119] It should be noted that, for the sake of simplicity, the method embodiments are all described as a series of actions. However, those skilled in the art should understand that the embodiments of this application are not limited to the described order of actions, because according to the embodiments of this application, some steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also understand that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily required by the embodiments of this application.

[0120] Figure 9 The schematic diagram illustrates the structure of a network security incident processing device 20 provided in this application, the device comprising:

[0121] The receiving module 201 is configured to, in response to receiving a monitoring instruction for a network security event, instruct the large language model to monitor the network security event based on the monitoring instruction;

[0122] The alarm module 202 is used to output alarm information for the monitoring result when it receives the monitoring result of the network security event detected by the large language model;

[0123] The interaction module 203 is used to respond to receiving user interaction information input for the alarm information, and instruct the large language model to generate and output a response strategy for the network security incident based on the user interaction information;

[0124] Response module 204 is used to input the response strategy into the prompt word model to obtain security response instructions for the network security incident;

[0125] Based on the security response instruction, the large language model is instructed to process the network security incident and output the processing result for the network security incident.

[0126] Optionally, the interaction module 203 is further configured to:

[0127] The user interaction information is input into the prompt word model to obtain the prompt word corresponding to the user interaction information;

[0128] The prompt words are input into the large language model to obtain the response strategy for the network security incident.

[0129] Optionally, the prompt words may include at least: question information, thinking information, action information, and observation information;

[0130] The interaction module 203 is also used for:

[0131] The question information is input into the large language model to obtain the semantic information corresponding to the user interaction information;

[0132] The thought information and the semantic information are input into the large language model to obtain the handling method for the network security incident;

[0133] The processing method, the tool list, and the action information are input into the large language model to obtain the target tool identifiers in the tool list for processing the network security incident.

[0134] The processing method, target tool identifier, and observation information are input into the large language model to obtain the response strategy.

[0135] Optionally, the interaction module 203 is further configured to:

[0136] The processing method, target tool identifier, and observation information are input into the large language model to obtain the observation results.

[0137] When the observation results do not meet the expected requirements, proceed to the step of inputting the problem information into the large language model to obtain the semantic information corresponding to the user interaction information;

[0138] When the observation results meet the expected requirements, a response strategy is output based on the target tool identifier and the processing method.

[0139] Optionally, the interaction module 203 is further configured to:

[0140] The user interaction information is broken down to obtain at least two task information items;

[0141] The at least two task information are respectively input into the large language model to obtain the response strategy corresponding to each task information.

[0142] Optionally, the response module 204 is further configured to:

[0143] The security response instruction corresponding to each task information is input into the large language model to obtain the processing result corresponding to each task information.

[0144] The processing results of at least two task information are merged to obtain the processing result for the network security incident.

[0145] Optionally, the response module 204 is further configured to:

[0146] Based on the monitoring results, the user interaction information, and the processing results, a network security report for the network security incident is generated and output.

[0147] Optionally, the receiving module 201 is further configured to:

[0148] In response to receiving a monitoring instruction for a network security incident, the system determines the characteristic information of the network security incident based on the monitoring instruction.

[0149] The feature information is input into the large language model so that the large language model can monitor the network security events represented by the feature information.

[0150] This application embodiment utilizes a large language model to monitor network security events. When a network security event occurs, it can promptly notify the user through alarm information. Then, by receiving user interaction information, it instructs the large language model to analyze the network security event to obtain a response strategy. Furthermore, it can utilize a prompt word model to automatically instruct the large language model to handle the network security event based on the response strategy. This enables the large language model to assist users in timely detection of network security events and to efficiently handle emergency response to network security events.

[0151] This application also provides a non-volatile readable storage medium storing one or more modules (programs). When these modules are applied to a device, they enable the device to execute the instructions for the method steps in this application.

[0152] This application provides one or more machine-readable media storing instructions that, when executed by one or more processors, cause an electronic device to perform one or more of the methods described in the above embodiments. In this application, the electronic device includes devices such as servers and terminal devices.

[0153] Embodiments of this disclosure can be implemented as an apparatus with any suitable hardware, firmware, software, or any combination thereof, configured as desired, and the apparatus may include electronic devices such as servers (clusters) and terminals. Figure 10 An exemplary apparatus 1000 that can be used to implement the embodiments described in this application is illustrated schematically.

[0154] In one embodiment, Figure 10 An exemplary device 1000 is shown, which includes one or more processors 1002, a control module (chipset) 1004 coupled to at least one of the processors 1002, a memory 1006 coupled to the control module 1004, a non-volatile memory (NVM) / storage device 1008 coupled to the control module 1004, one or more input / output devices 1010 coupled to the control module 1004, and a network interface 1012 coupled to the control module 1004.

[0155] Processor 1002 may include one or more single-core or multi-core processors, and processor 1002 may include any combination of general-purpose processors or special-purpose processors (e.g., graphics processors, application processors, baseband processors, etc.). In some embodiments, device 1000 can serve as a server, terminal, or other device as described in the embodiments of this application.

[0156] In some embodiments, apparatus 1000 may include one or more computer-readable media (e.g., memory 1006 or NVM / storage device 1008) having instructions 1014 and one or more processors 1002 that are combined with the one or more computer-readable media and configured to execute instructions 1014 to implement modules and thereby perform the actions described in this disclosure.

[0157] In one embodiment, the control module 1004 may include any suitable interface controller to provide any suitable interface to at least one of the processors 1002 and / or any suitable device or component communicating with the control module 1004.

[0158] The control module 1004 may include a memory controller module to provide an interface to the memory 1006. The memory controller module may be a hardware module, a software module, and / or a firmware module.

[0159] Memory 1006 may be used, for example, to load and store data and / or instructions 1014 for device 1000. In one embodiment, memory 1006 may include any suitable volatile memory, such as suitable DRAM. In some embodiments, memory 1006 may include double data rate type quad synchronous dynamic random access memory (DDR4 SDRAM).

[0160] In one embodiment, the control module 1004 may include one or more input / output controllers to provide interfaces to the NVM / storage device 1008 and (one or more) input / output devices 1010.

[0161] For example, NVM / storage device 1008 may be used to store data and / or instructions 1014. NVM / storage device 1008 may include any suitable non-volatile memory (e.g., flash memory) and / or may include any suitable (one or more) non-volatile storage devices (e.g., one or more hard disk drives (HDDs), one or more optical disc drives (CDs), and / or one or more digital universal optical disc (DVD) drives).

[0162] NVM / storage device 1008 may include storage resources that are part of a device on which device 1000 is mounted, or that can be accessed by the device without being part of the device. For example, NVM / storage device 1008 may be accessed via a network via one or more input / output devices 1010.

[0163] One or more input / output devices 1010 may provide an interface for device 1000 to communicate with any other suitable device. Input / output devices 1010 may include communication components, audio components, sensor components, etc. Network interface 1012 may provide an interface for device 1000 to communicate via one or more networks. Device 1000 may wirelessly communicate with one or more components of a wireless network according to any of one or more wireless network standards and / or protocols, such as accessing wireless networks based on communication standards, such as WiFi, 2G, 3G, 4G, 5G, etc., or combinations thereof.

[0164] In one embodiment, at least one of the processors 1002 may be logically packaged with one or more controllers (e.g., memory controller modules) of the control module 1004. In one embodiment, at least one of the processors 1002 may be logically packaged with one or more controllers of the control module 1004 to form a system-in-package (SiP). In one embodiment, at least one of the processors 1002 may be integrated with the logic of one or more controllers of the control module 1004 on the same die. In one embodiment, at least one of the processors 1002 may be integrated with the logic of one or more controllers of the control module 1004 on the same die to form a system-on-a-chip (SoC).

[0165] In embodiments, device 1000 may be, but is not limited to, a server, desktop computing device, or mobile computing device (e.g., laptop computing device, handheld computing device, tablet computer, netbook, etc.). In embodiments, device 1000 may have more or fewer components and / or a different architecture. For example, in some embodiments, device 1000 includes one or more cameras, a keyboard, a liquid crystal display (LCD) screen (including a touchscreen display), a non-volatile memory port, multiple antennas, a graphics chip, an application-specific integrated circuit (ASIC), and a speaker.

[0166] The monitoring device can use a main control chip as a processor or control module, and sensor data, location information, etc. can be stored in a memory or NVM / storage device. The sensor group can be used as an input / output device, and the communication interface can include a network interface.

[0167] This application also provides an electronic device, including: a processor; and a memory storing executable code thereon, which, when executed, causes the processor to perform one or more methods as described in this application.

[0168] This application also provides one or more machine-readable media having executable code stored thereon, which, when executed, causes a processor to perform one or more of the methods described in this application.

[0169] As the device embodiment is basically similar to the method embodiment, the description is relatively simple, and relevant parts can be found in the description of the method embodiment.

[0170] The embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Similar or identical parts between embodiments can be referred to mutually.

[0171] This application describes embodiments with reference to flowchart illustrations and / or block diagrams of methods, terminal devices (systems), and computer program products according to embodiments of this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing terminal device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing terminal device, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0172] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing terminal device to operate in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0173] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal equipment, causing a series of operational steps to be performed on the computer or other programmable terminal equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable terminal equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0174] Although preferred embodiments of the present application have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of the embodiments of the present application.

[0175] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or terminal device. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or terminal device that includes said element.

[0176] The foregoing has provided a detailed description of a method for handling network security incidents, a device for handling network security incidents, an electronic device, and a storage medium provided in this application. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the method and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. A method of processing a network security event, the method comprising: The method comprises the following steps: in response to receiving the monitoring instruction for the network security event, instructing the large language model to monitor the network security event based on the monitoring instruction; when receiving the monitoring result of the network security event monitored by the large language model, outputting alarm information for the monitoring result; in response to receiving user interaction information input for the alarm information, instructing the large language model to generate and output a response strategy for the network security event based on the user interaction information; inputting the response strategy into a prompt word model to obtain a security response instruction for the network security event; based on the security response instruction, instructing the large language model to process the network security event and output a processing result for the network security event.

2. The method of claim 1, wherein, The method comprises the following steps: inputting the user interaction information into the prompt word model to obtain a prompt word corresponding to the user interaction information; inputting the prompt word into the large language model to obtain a response strategy for the network security event.

3. The method of claim 2, wherein, The prompt word at least includes question information, thinking information, action information, and observation information. The method comprises the following steps: inputting the question information into the large language model to obtain semantic information corresponding to the user interaction information; inputting the thinking information and the semantic information into the large language model to obtain a processing method for the network security event; inputting the processing method, a tool list, and the action information into the large language model to obtain a target tool identifier in the tool list for processing the network security event; inputting the processing method, the target tool identifier, and the observation information into the large language model to obtain a response strategy.

4. The method of claim 3, wherein, The method comprises the following steps: inputting the processing method, the target tool identifier, and the observation information into the large language model to obtain an observation result; when the observation result does not meet the expected requirement, inputting the question information into the large language model to obtain semantic information corresponding to the user interaction information; when the observation result meets the expected requirement, outputting a response strategy according to the target tool identifier and the processing method.

5. The method of claim 1, wherein, The method comprises the following steps: splitting the user interaction information to obtain at least two task information; inputting the at least two task information into the large language model respectively to obtain a response strategy corresponding to each task information.

6. The method of claim 5, wherein, The method comprises the following steps: input the security response instruction corresponding to each of the task information into the large language model to obtain a processing result corresponding to each of the task information; merge the processing results of the at least two task information to obtain a processing result for the network security event.

7. The method of claim 1, wherein, After the large language model is instructed to process the network security event based on the security response instruction and outputs a processing result for the network security event, the method further comprises: generating a network security report for the network security event based on the monitoring result, the user interaction information, and the processing result, and outputting the network security report.

8. The method according to any one of claims 1 to 7, characterized in that, In response to receiving a monitoring instruction for a network security event, instructing the large language model to monitor the network security event based on the monitoring instruction, comprises: In response to receiving a monitoring instruction for a network security event, determining feature information of the network security event based on the monitoring instruction; inputting the feature information into the large language model to enable the large language model to monitor the network security event represented by the feature information.

9. A network security event handling apparatus characterized by comprising: The apparatus comprises: a receiving module configured to instruct the large language model to monitor a network security event based on a monitoring instruction for the network security event in response to receiving the monitoring instruction; an alarm module configured to output alarm information for a monitoring result when the large language model monitors the network security event and the monitoring result is received; an interaction module configured to instruct the large language model to generate and output a response strategy for the network security event based on user interaction information input in response to the alarm information in response to receiving the user interaction information; a response module configured to input the response strategy into a prompt word model to obtain a security response instruction for the network security event; instruct the large language model to process the network security event based on the security response instruction, and output a processing result for the network security event.

10. A computing processing device, comprising: comprises: a memory having computer readable code stored therein; one or more processors, when the computer readable code is executed by the one or more processors, the computing device executes the network security event processing method of any one of claims 1-8.

11. A non-transitory computer-readable medium, comprising: a computer program having the network security event processing method of any one of claims 1-8 stored therein.

Citation Information

Patent Citations

  • Network security emergency response method and system based on knowledge graph

    CN111614696A

  • Network security event monitoring method and device, electronic equipment and storage medium

    CN115811421A