A method and system for realizing secure access based on an AI large model
By using a cloud firewall based on an AI-powered big data model, resources and policies can be detected and dynamically adjusted in real time, solving the problems of intelligence and flexibility of cloud firewalls, achieving efficient automated security protection capabilities, and meeting complex and ever-changing business needs.
Patent Information
- Application Number
- CN202411517911.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-29
- Publication Date
- 2025-12-09
- Estimated Expiration
- 2044-10-29
AI Technical Summary
Existing cloud firewalls lack intelligence and flexibility, cannot dynamically scale up and adjust resources on demand, cannot continuously assess security risks, cannot intelligently configure security policies, and cannot meet complex and ever-changing business security needs.
A security firewall is built based on a large AI model. By extending the functionality of the cloud-native security firewall through a cloud computing architecture, it can detect network traffic and business needs in real time, dynamically adjust resources and policies, and continuously learn new security knowledge to achieve intelligent security protection.
It enables continuous detection of security risks, real-time adjustment of security rules, improvement of protection capabilities, avoidance of bottlenecks caused by limited resources, meeting complex and ever-changing business security needs, keeping pace with the latest attack technologies, and achieving automated security protection.
Smart Images

Figure CN119276595B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of cloud native security, and in particular to a method and system for realizing secure access based on an AI large model. BACKGROUND
[0002] A cloud firewall is a network security device provided in a cloud computing environment, which protects data and applications in the cloud environment through virtualized firewalls. With the continuous development of cloud computing technology, the current cloud firewall has been unable to meet the complex and variable business security needs of users.
[0003] Traditional cloud firewall solutions lack intelligence and flexibility, and cannot dynamically expand and adjust resources on demand based on complex and variable business needs, nor can they continuously assess security risks and intelligently configure security policies.
[0004] To solve the above problems, the present application provides a method and system for realizing secure access based on an AI large model. SUMMARY
[0005] The present application provides a simple and efficient method and system for realizing secure access based on an AI large model to overcome the shortcomings of the prior art.
[0006] The present application is achieved by the following technical solutions:
[0007] A method for realizing secure access based on an AI large model, characterized by: extending the cloud native security firewall function based on a cloud computing architecture, comprising the following steps:
[0008] Step S1, constructing an AI security large model based on a pre-trained large model and industry security data;
[0009] Step S2, creating cloud hosts, virtual routers and cloud firewalls through a cloud platform controller based on a cloud computing architecture;
[0010] Step S3, real-time detection of network traffic data and task logs of the cloud firewall, analysis of security risk data, and acquisition of business data from the business system to detect real-time changes in business security requirements;
[0011] Step S4, based on security risk data and business security requirements, the AI security large model analyzes and reasons the security risk and business security level requirements in real time;
[0012] Step S5, based on security risk data and business security requirements, calling a cloud platform interface to dynamically adjust the required resources of the cloud firewall, calling a security control interface to intelligently adjust the security policy, and intelligently improving the security protection capability;
[0013] Step S6, training and optimizing the AI security large model in real time according to the detected new security risks and business data.
[0014] In step S3, the method for detecting business security requirements in real time adopts any one of the following methods: analyzing data packets in real time through packet parsing, analyzing business log data in real time through a large model, or analyzing business process changes in real time through acquired business data.
[0015] In step S4, the AI security large model generates security rules and resource requirements using knowledge enhancement generation technology, and uses N large model retrieval methods, N≥1, to obtain K optimal results, K≥1, and then combines N×K results to obtain the optimal answer from the AI security large model.
[0016] In step S6, the new security risks include new attack methods and new viruses, and the new business data includes changes in production processes and production procedures.
[0017] A system for implementing secure access based on an AI large model, which adopts a cloud computing architecture and includes a cloud host, a virtual router, and a cloud firewall. In addition, it also includes a real-time detection module, a security large model inference module, and a continuous security learning module.
[0018] The real-time detection module is responsible for real-time detection of network traffic data and task logs of the cloud firewall, analysis of security risk data, and acquisition of business data from the business system to detect changes in business security requirements in real time.
[0019] The security large model inference module is responsible for constructing an AI security large model based on a pre-trained large model and industry security data, analyzing and reasoning security risks and business security level requirements in real time based on security risk data and business security requirements, dynamically adjusting the required resources of the cloud firewall through a cloud platform interface, intelligently adjusting security policies through a security control interface, and intelligently improving security protection capabilities.
[0020] The continuous security learning module is responsible for continuously training and optimizing the AI security large model based on new security risks and business security requirements, and automatically optimizing the model response based on feedback.
[0021] The real-time detection module detects business security requirements in real time using any one of the following methods: analyzing data packets in real time through packet parsing, analyzing business log data in real time through a large model, or analyzing business process changes in real time through acquired business data.
[0022] In the security large model reasoning module, the AI security large model generates security rules and resource requirements by using a knowledge enhancement generation technology, and adopts N large model retrieval methods, N>=1, each method obtains K optimal results, K>=1, and the N*K results are combined, and the AI security large model takes out the optimal answer from the combined results.
[0023] In the continuous security learning module, the new security risks include new attack means and new viruses, and the new business data includes changes in production processes and changes in production procedures.
[0024] A computing device for implementing secure access based on an AI large model, characterized by comprising:
[0025] One or more processors, one or more memories, and one or more programs, wherein the one or more programs are stored in the one or more memories and configured to be executed by the one or more processors, and the one or more programs include instructions for executing any of the above methods.
[0026] A computer-readable storage medium storing one or more programs, characterized in that the one or more programs include instructions that, when executed by a computing device for implementing secure access based on an AI large model, cause the computing device for implementing secure access based on an AI large model to execute any of the above methods.
[0027] The method and system for implementing secure access based on an AI large model have the following beneficial effects: they can continuously detect security risks, adjust security rules in real time, and improve security protection capabilities; they can also cooperate with actual business, dynamically adjust the resources required by the security firewall, avoid resource limitations that lead to security protection bottlenecks, and improve reliability; at the same time, by continuously learning new security knowledge, they can keep pace with the latest attack techniques, meet complex and changing business security requirements, and achieve automated security protection capabilities. BRIEF DESCRIPTION OF DRAWINGS
[0028] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiment or prior art description. Obviously, the drawings in the following description are some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained without creative labor.
[0029] APPENDIX Figure 1 The method for implementing secure access based on an AI large model of the present application is shown in the figure.
[0030] APPENDIX Figure 2 The system for implementing secure access based on an AI large model of the present application is shown in the figure. DETAILED DESCRIPTION
[0031] In order to better understand the technical solutions in the present application, the technical solutions in the embodiments of the present application will be described clearly and completely below in combination with the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art without creative work should fall within the protection scope of the present application.
[0032] The method for realizing safe access based on an AI large model extends the cloud-native security firewall function based on a cloud computing architecture, including the following steps:
[0033] Step S1, constructing an AI security large model based on a pre-trained large model and industry security data;
[0034] Step S2, creating a cloud host, a virtual router and a cloud firewall through a cloud platform controller based on a cloud computing architecture;
[0035] Step S3, detecting network traffic data and task logs of the cloud firewall in real time, analyzing security risk data, and simultaneously acquiring business data from a business system to detect changes in business security requirements in real time;
[0036] Step S4, based on the security risk data and the business security requirements, the AI security large model analyzes and reasons the security risk and the business security level requirements in real time;
[0037] Step S5, based on the security risk data and the business security requirements, calling a cloud platform interface to dynamically adjust the required resources of the cloud firewall, calling a security control interface to intelligently adjust security policies, and intelligently improving security protection capabilities;
[0038] Step S6, training and optimizing the AI security large model in real time according to the detected new security risk and business data.
[0039] In the step S3, the method for detecting business security requirements in real time adopts any one of the following methods: analyzing data packets in real time through packet analysis, analyzing business log data in real time through a large model, or analyzing business process changes in real time by acquiring business data.
[0040] In the step S4, the AI security large model generates security rules and resource requirements using knowledge enhancement generation technology, uses N large model retrieval methods, N≥1, obtains K optimal results for each method, K≥1, combines N×K results, and then takes the optimal answer from the combined results by the AI security large model.
[0041] The new security risks include new attack means and new viruses, and the new business data includes changes in production processes and changes in production procedures.
[0042] The system for realizing secure access based on the AI large model adopts a cloud computing architecture, and includes a cloud host, a virtual router, and a cloud firewall.
[0043] The real-time detection module is responsible for real-time detection of network traffic data and task logs of the cloud firewall, analysis of security risk data, and acquisition of business data from a business system to realize real-time detection of business security requirement changes.
[0044] The security large model inference module is responsible for constructing an AI security large model based on a pre-trained large model and industry security data, real-time analysis and inference of security risks and business security level requirements based on security risk data and business security requirements, calling of a cloud platform interface to dynamically adjust resources required by the cloud firewall, calling of a security control interface to intelligently adjust security policies, and intelligent improvement of security protection capabilities.
[0045] The continuous security learning module is responsible for continuously training and optimizing the AI security large model based on new security risks and business security requirements, and automatically optimizing model responses based on feedback.
[0046] The real-time detection module adopts any one of the following methods to realize real-time detection of business security requirements: real-time analysis of data packets through packet analysis, real-time analysis of business log data through a large model, or real-time analysis of business process changes through acquisition of business data.
[0047] In the security large model inference module, the AI security large model generates security rules and resource requirements using knowledge enhancement generation technology, adopts N large model retrieval methods (N≥1), obtains K optimal results (K≥1) for each method, combines N×K results, and selects an optimal answer from the combined results.
[0048] In the continuous security learning module, the new security risks include new attack means and new viruses, and the new business data includes changes in production processes and changes in production procedures.
[0049] The computing device for realizing secure access based on the AI large model includes:
[0050] One or more processors, one or more memories, and one or more programs, wherein the one or more programs are stored in the one or more memories and configured to be executed by the one or more processors, and the one or more programs include instructions for executing any one of the above methods.
[0051] The computer readable storage medium stores one or more programs, and the one or more programs include instructions which, when executed by a computing device implementing AI large model-based security access, cause the computing device implementing AI large model-based security access to perform any of the above methods.
[0052] The method and system for implementing AI large model-based security access can continuously detect security risks, adjust security rules in real time, and improve security protection capabilities. It can also cooperate with actual business, dynamically adjust the resources required by the security firewall, avoid resource limitations that lead to security protection bottlenecks, and improve reliability. At the same time, by continuously learning new security knowledge, it can keep pace with the latest attack techniques, meet complex and changing business security needs, and achieve automated security protection capabilities. The above-described embodiments are only one of the specific implementations of the present application, and any changes and substitutions made by those skilled in the art within the scope of the technical solutions of the present application should be included within the protection scope of the present application.
Claims
1. A method for implementing secure access based on an AI large model, characterized in that: The cloud computing architecture is used to expand the cloud native security firewall function, including the following steps: Step S1, constructing an AI security large model based on a pre-trained large model and industry security data; Step S2, creating cloud hosts, virtual routers and cloud firewalls through a cloud platform controller based on a cloud computing architecture; Step S3, real-time detection of network traffic data and task logs of the cloud firewall, analysis of security risk data, and real-time detection of changes in business security requirements by obtaining business data from a business system; In step S3, the method for real-time detection of business security requirements is any one of real-time analysis of data packets through message parsing, real-time analysis of business log data through a large model, or real-time analysis of business process changes by obtaining business data; Step S4, the AI security large model analyzes and reasons the security risk and business security level requirements in real time based on security risk data and business security requirements; In step S4, the AI security large model generates security rules and resource requirements using knowledge enhancement generation technology, and uses N large model retrieval methods, N≥1, to obtain K optimal results, K≥1, and then combines N×K results to obtain the optimal answer from the AI security large model; Step S5, based on security risk data and business security requirements, calling a cloud platform interface to dynamically adjust the required resources of the cloud firewall, calling a security control interface to intelligently adjust security policies, and intelligently improving security protection capabilities; Step S6, real-time training and optimization of the AI security large model according to the detected new security risks and business data; In step S6, the new security risks include new attack methods and new viruses, and the new business data includes changes in production processes and production procedures.
2. A system for realizing secure access based on an AI large model, characterized in that: The cloud computing architecture includes cloud hosts, virtual routers and cloud firewalls; in addition, it also includes a real-time detection module, a security large model reasoning module and a continuous security learning module; The real-time detection module is responsible for real-time detection of network traffic data and task logs of the cloud firewall, analysis of security risk data, and real-time detection of changes in business security requirements by obtaining business data from a business system; The real-time detection module uses any one of real-time analysis of data packets through message parsing, real-time analysis of business log data through a large model, or real-time analysis of business process changes by obtaining business data to real-time detect business security requirements; The security large model reasoning module is responsible for constructing an AI security large model based on a pre-trained large model and industry security data, real-time analysis and reasoning of security risk and business security level requirements by the AI security large model based on security risk data and business security requirements, dynamic adjustment of the required resources of the cloud firewall by calling a cloud platform interface, intelligent adjustment of security policies by calling a security control interface, and intelligent improvement of security protection capabilities; In the security large model reasoning module, the AI security large model generates security rules and resource requirements using knowledge enhancement generation technology, and uses N large model retrieval methods, N≥1, to obtain K optimal results, K≥1, and then combines N×K results to obtain the optimal answer from the AI security large model; The continuous security learning module is responsible for continuously training and optimizing the AI security large model based on new security risks and business security needs, and automatically optimizing the model response based on feedback. In the continuous security learning module, the new security risks include new attack means and new viruses, and the new business data includes changes in production processes and changes in production procedures.
3. A computing device for implementing secure access based on an AI large model, characterized in that: including: one or more processors, one or more memories, and one or more programs, wherein the one or more programs are stored in the one or more memories and configured to be executed by the one or more processors, and the one or more programs include instructions for executing any of the methods according to claim 1.
4. A computer-readable storage medium storing one or more programs, the one or more programs comprising instructions that when executed by a computer cause the computer to perform a method comprising: The one or more programs include instructions that, when executed by a computing device that implements security access based on an AI large model, cause the computing device that implements security access based on the AI large model to perform any of the methods according to claim 1.
Citation Information
Patent Citations
Heterogeneous firewall policy centralized management method, device and system
CN114567494A
Network threat active defense system and method based on large model
CN118316736A