An automated decision-making system and method for information asset large model
Through the information asset large model automated decision-making system, combined with multimodal data and dynamic status, the problem of low efficiency of traditional information asset management is solved, and efficient and accurate information asset management and operation and maintenance optimization are achieved.
Patent Information
- Application Number
- CN202411779891.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-05
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2044-12-05
AI Technical Summary
Traditional information asset management relies on manual monitoring and decision-making, which results in limited management efficiency and is prone to errors. It is difficult to meet the needs of efficient and accurate management, especially when the scale and complexity of information assets increase.
By adopting the information asset big model automated decision-making system, multimodal information asset data is input into the preset big model, combined with the attention mechanism and GRU time series model, automatic label update and resource allocation of information assets are realized, reducing the frequency and workload of manual inspection.
It realizes comprehensive analysis and dynamic status assessment of information assets, improves management efficiency, reduces operation and maintenance costs, ensures the accuracy and timeliness of labels, and supports intelligent management of information assets.
Smart Images

Figure CN119557810B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information asset management, and specifically to an automated decision-making system and method for large-scale information asset models. Background Art
[0002] With the rapid development of information technology, the number and complexity of information assets that businesses and organizations rely on are growing. These information assets, including but not limited to data, software, hardware, and related services, form the core foundation of enterprise operations and business decision-making.
[0003] Traditional information asset management relies primarily on manual monitoring and decision-making. Every step, from asset identification and classification to status monitoring, usage approval, and disposal, requires human involvement. Managers must manually inventory assets, register information, monitor asset status through regular inspections, and make decisions based on this information regarding maintenance, upgrades, or disposal.
[0004] However, human judgment dominates, limiting management efficiency and making it prone to errors. As information assets grow in size and complexity, traditional approaches are no longer able to meet the demands for efficient and accurate management. Summary of the Invention
[0005] This application belongs to the field of information asset management, specifically to an automated decision-making system for large-scale information asset models. It solves the problem that manual information asset management in existing technologies leads to limited management efficiency and is prone to errors. As the scale and complexity of information assets increase, traditional methods have become difficult to meet the needs of efficient and accurate management.
[0006] In a first aspect, an embodiment of the present application provides an information asset large model automated decision-making system, the system comprising:
[0007] A classification module is configured to obtain multimodal information asset data corresponding to an information asset, input the multimodal information asset data into a preset information asset macromodel, obtain a predicted label for the information asset, and update the predicted label to the information asset list; wherein the multimodal information asset data includes an information asset description, an information asset log, and an information asset image;
[0008] An update confirmation module is used to obtain the communication frequency, operating status, and dynamic log of the information asset in real time if no label classification error information transmitted by the control center is received, and input the communication frequency, operating status, and dynamic log into a preset information asset macro model to determine whether an information asset update is required;
[0009] The update module is used to re-output the prediction label of the information asset according to the communication frequency, operation status and dynamic log through the preset information asset model if the information asset needs to be updated, and update the prediction label to the information asset list.
[0010] In a second aspect, an embodiment of the present application provides a method for automated decision-making of an information asset large model, characterized in that the method includes:
[0011] Obtaining multimodal information asset data corresponding to an information asset, inputting the multimodal information asset data into a preset information asset macromodel to obtain a predicted label for the information asset, and updating the predicted label to the information asset list; wherein the multimodal information asset data includes an information asset description, an information asset log, and an information asset image;
[0012] If the tag classification error information transmitted by the control center is not received, the communication frequency, operation status and dynamic log of the information asset are obtained in real time, and the communication frequency, operation status and dynamic log are input into the preset information asset macro model to determine whether the information asset needs to be updated;
[0013] If an information asset needs to be updated, the predicted label of the information asset is re-output according to the communication frequency, operation status and dynamic log through the preset information asset macro model, and the predicted label is updated to the information asset list.
[0014] In an embodiment of the present application, multimodal information asset data corresponding to an information asset is obtained, the multimodal information asset data is input into a preset information asset macro model, a predicted label of the information asset is obtained, and the predicted label is updated to the information asset list; wherein, the multimodal information asset data includes an information asset description, an information asset log, and an information asset picture; if the label classification error information transmitted by the control center is not received, the communication frequency, operating status, and dynamic log of the information asset are obtained in real time, and the communication frequency, operating status, and dynamic log are input into the preset information asset macro model to determine whether an information asset update is required; if an information asset update is required, the predicted label of the information asset is re-output based on the communication frequency, operating status, and dynamic log through the preset information asset macro model, and the predicted label is updated to the information asset list. Through the above-mentioned information asset macro model automated decision-making system, by combining multimodal information and dynamic status, the model can comprehensively analyze the current status of the information asset, and the system can automatically re-evaluate the label when dynamic changes are detected, reducing the frequency and workload of manual inspections and reducing operation and maintenance costs. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Figure 1This is a schematic diagram of the structure of the information asset large model automated decision-making system provided in Example 1 of the present application;
[0016] Figure 2 This is a schematic diagram of the structure of the information asset large model automated decision-making system provided in Example 2 of this application;
[0017] Figure 3 This is a schematic diagram of the structure of the information asset large model automated decision-making system provided in Example 3 of the present application;
[0018] Figure 4 This is a flow chart of the automated decision-making method for the information asset large model provided in Example 4 of the present application. DETAILED DESCRIPTION
[0019] To further clarify the objectives, technical solutions, and advantages of this application, specific embodiments of the present application are described in further detail below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are intended only to illustrate this application and are not intended to limit it. It should also be noted that, for ease of description, the drawings only illustrate portions relevant to this application, not all of them. Before discussing the exemplary embodiments in more detail, it should be noted that some exemplary embodiments are described as processes or methods depicted as flowcharts. Although the flowcharts depict the various operations (or steps) as sequential processes, many of the operations can be performed in parallel, concurrently, or simultaneously. Furthermore, the order of the operations can be rearranged. The process may terminate upon completion of its operations, but may also include additional steps not shown in the accompanying drawings. The process may correspond to a method, function, procedure, subroutine, subprogram, or the like.
[0020] The following will be combined with the accompanying drawings in the embodiments of the present application to clearly describe the technical solutions in the embodiments of the present application. Obviously, the embodiments described are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field are within the scope of protection of this application.
[0021] The terms "first," "second," and the like in the specification and claims of this application are used to distinguish similar objects, and are not used to describe a specific order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate, so that the embodiments of this application can be implemented in an order other than that illustrated or described herein, and that the objects distinguished by "first," "second," and the like are generally of the same type, and do not limit the number of objects; for example, the first object can be one or more. In addition, the term "and / or" in the specification and claims refers to at least one of the connected objects, and the character " / " generally indicates that the objects connected are in an "or" relationship.
[0022] The information asset large model automated decision-making system provided by the embodiment of the present application is described in detail below with reference to the accompanying drawings through specific embodiments and their application scenarios.
[0023] Example 1
[0024] Figure 1 This is a schematic diagram of the structure of the information asset large model automated decision-making system provided in Example 1 of this application. The system includes:
[0025] The classification module 101 is configured to obtain multimodal information asset data corresponding to an information asset, input the multimodal information asset data into a preset information asset macromodel, obtain a predicted label for the information asset, and update the predicted label to the information asset list; wherein the multimodal information asset data includes an information asset description, an information asset log, and an information asset image;
[0026] The update confirmation module 102 is used to obtain the communication frequency, operating status, and dynamic log of the information asset in real time if the tag classification error information transmitted by the control center is not received, and input the communication frequency, operating status, and dynamic log into the preset information asset macro model to determine whether the information asset needs to be updated;
[0027] The updating module 103 is used to re-output the predicted label of the information asset according to the communication frequency, operation status and dynamic log through the preset information asset macro model if an information asset update is required, and update the predicted label to the information asset list.
[0028] First, the usage scenario of this solution can be to predict the labels of information assets through the information asset big model, and determine in real time whether they need to be updated, and update the labels if they need to be updated.
[0029] Based on the above usage scenarios, it can be understood that the executor of this application can be the information asset large model automated decision-making system, and no excessive restrictions are made here.
[0030] In this solution, information assets can be resources with data value or functional value in an enterprise or system, such as databases, servers, virtual machines, applications, network equipment, hosts, databases, etc., which are mainly used to support business operations and decision-making.
[0031] Multimodal data refers to heterogeneous data that comes from multiple sources or exists in multiple forms. Specifically, information asset descriptions can be textual information, such as the asset name, attributes, purpose, deployment location, and responsible individuals. Information asset logs can be time-series records, including asset operation logs, error logs, and access records. Information asset images can be visual data, such as images of the asset's appearance, hardware device screenshots, and monitoring screens.
[0032] The pre-defined information asset model can be a multi-task deep learning model used for multiple tasks, including classification, behavior prediction, resource allocation, scoring, and optimization recommendations. This model consists of the following branches: The classification branch classifies multimodal data and generates prediction labels. The resource allocation branch generates resource allocation recommendations based on performance and demand. The behavior prediction branch detects asset behavior (normal or abnormal) and predicts trends. The scoring branch assesses asset health and generates optimization recommendations.
[0033] It should be noted that in order to fully utilize the complementary information of multimodal data and achieve more accurate classification and prediction, we designed a multimodal collaborative feature fusion method based on the attention mechanism:
[0034] For example, the information asset set is set to …, , for each information asset , we obtain its multimodal data: text description , log data , image data
[0035] Feature extraction for each modal data: Text features: ,;Log features: ; Image features: ,in, These are feature extraction functions for text, logs, and images, respectively. Pre-trained deep learning models such as BERT, LSTM, ResNet, and sequence models can usually be used.
[0036] The fusion method based on attention mechanism is used to collaboratively fuse the features of different modalities to obtain :
[0037]
[0038] in: , , It is a trainable weight matrix. The weight matrix learned during the training process is used to perform linear transformation on the features of different modalities.
[0039] is the self-attention function, defined as:
[0040]
[0041] in, = Represents features extracted from text description data. = Represents features extracted from log data. = Represents the features extracted from image data.
[0042] Attention weight , reflecting the importance of mode j, is calculated as follows:
[0043]
[0044] in: 、 、 are trainable parameters, represents the transpose of the parameter u. is the activation function. More specifically, Is a trainable weight matrix used to adjust the input features ( , , ) performs linear transformation; is a bias vector used to adjust the output of the linear transformation; is a vector used to calculate the attention weight from the activation value. These parameters together determine the weight of each modality feature , thus reflecting the importance of this modality feature to the final fusion representation.
[0045] in 、 、 It is a trainable parameter that is optimized by the backpropagation algorithm during the training process of the model. Specifically, first, the model calculates the loss function (for example, the cross entropy loss in the classification task) through forward propagation.
[0046] Then, the gradient of the loss function with respect to the parameters V, u, and b is calculated through backpropagation. Finally, an optimization algorithm (such as gradient descent, Adam, etc.) is used to update these parameters according to the gradient so that the loss of the model gradually decreases.
[0047] During the training process, the input data is the characteristics of multimodal data (text features , log features , picture features ), these features are extracted by pre-trained models (such as BERT and ResNet). By continuously adjusting V, u, and b, the model learns parameters that better integrate these modal features, thereby improving the discriminability and richness of the overall feature representation. During training, these parameters are dynamically adjusted based on the characteristics of the input data and the loss function of the target task, ultimately learning the weights and biases that optimally integrate multimodal features.
[0048] The self-attention mechanism is used to perform weighted fusion of multimodal features (text features, log features, and image features). The importance of different modal features is expressed through attention weights. Dynamic calculation and weight generation rely on a trainable network, including the weight matrix V, the bias vector b, and the attention vector u. The weighted summation formula of the attention mechanism fuses features from different modalities according to their importance to generate a comprehensive feature representation. This collaborative fusion approach captures the complementarity of multimodal information within the same feature space, making the fused features not only more comprehensive but also more discriminative.
[0049] In processing information asset collection Multimodal data (text description , log data , image data ), the collaborative feature fusion method based on the attention mechanism can capture the complementary relationship between different modal features by dynamically adjusting the importance weights of modal features. In this way, the model can not only comprehensively utilize the key information of text, logs and pictures, but also adaptively improve the richness of feature representation (comprehensive integration of multimodal information) and discriminability (accurate representation of information assets), thereby more effectively supporting the implementation of downstream tasks. In order to solve the problem that different modal data (text, logs, pictures) often have independent information expression capabilities, but a single modality may not be able to fully express the full picture of information assets. Text descriptions may contain key semantic information, while the contribution of image data is relatively small; in other scenarios, pictures may contain richer visual features. The model uses attention weights ( ) calculation, flexibly capturing these differences, and ensuring that the importance of each modal feature in the fusion process matches its actual contribution.
[0050] This fusion method can dynamically adjust the weights according to the importance of each modal feature, achieve collaborative fusion, and improve the richness and discriminability of feature representation.
[0051] In addition, through the collaborative feature fusion method based on the attention mechanism, the model can adaptively capture the importance of features from different modalities, achieve information complementarity, and improve the discriminability and richness of feature representation.
[0052] The prediction label can be a classification or prediction result of the information asset by the large model and the corresponding description. Specifically, it can be an asset category and the corresponding description, for example, core router (normal).
[0053] The information asset list can be a unified record of all information assets in the system, including descriptions, logs, images, performance indicators, etc. of each information asset. The list will be dynamically updated to maintain real-time information.
[0054] Information asset descriptions, operation logs, and images can be collected in real time, and then multimodal data can be preprocessed. Specifically, for text data (information asset descriptions and logs), natural language processing tools (such as BERT and TF-IDF) are used to convert text into semantic vectors. For image data (information asset images), convolutional neural networks (such as ResNet and EfficientNet) are used to extract image features. For time series data (log timestamps), dynamic features are extracted using time series models (such as LSTM and Transformer). Data in modalities such as text, images, and time series are then input into a pre-set multimodal large model. The model integrates the data into a unified feature vector using a multimodal feature fusion module (such as the Attention mechanism). The classification branch then outputs the predicted label for the information asset, such as the asset type (e.g., "Network Device (Normal)" or "Database Server (High Risk)").
[0055] The control center is the central platform for managing and monitoring information assets. It collects, stores, and analyzes operational data and status information for all information assets. It also verifies the classification results of information asset models to determine if there are any classification errors. It then generates and transmits classification error labels to the model update module.
[0056] Label classification error information can refer to feedback information sent by the control center when the model classification result detected by the control center does not match the actual situation. If no error message is received, the current classification result is considered accurate and the current model can continue to be used.
[0057] Communication frequency can be the frequency of communication between information assets and other systems or devices, such as the number of network requests per second or the data transmission rate.
[0058] The operating status can be the current working status of the information asset (such as normal, idle, abnormal, etc.), including hardware performance and software operating status.
[0059] Dynamic logs can be real-time log data generated by information assets, recording events, operations, warnings, and exception information.
[0060] The control center can detect any label classification error messages. If no classification error messages are received, the next step is continued; otherwise, the error message triggers a model update or retraining process. The information asset's communication rate or request count is monitored through the network interface. Real-time status (such as CPU usage and memory usage) is obtained through the built-in status monitoring component. Real-time event data is extracted from the log generation module. The collected data is then formatted and normalized, cleaning invalid data (such as missing values or duplicates). Communication frequency, operating status, and dynamic logs are converted into feature vectors that the model can recognize. The processed data is input into the pre-set information asset master model. The master model uses modules such as the static classification branch and the dynamic classification branch to predict whether the information asset needs to be updated. Based on the model's predictions, it determines whether the information asset's classification label or other information needs to be updated. If the model's prediction indicates an update is necessary, the dynamic classification branch evaluates the input data based on the feature mapping relationships used during model training. The model generates the latest dynamic classification label based on the dynamic data. For example, the original predicted label is "edge router (normal)." The following real-time data is collected from the router: Communication frequency: Current number of packets sent per minute: 2800. Average frequency over the past 10 minutes: 2,500 times. Operating status: CPU utilization: 85% (above the safety threshold of 70%). Memory usage: 90%. Temperature: 75°C (close to the warning value of 80°C). Dynamic log: "The router has reached the bandwidth limit, and some traffic is being rate-limited," "Port 3 connection abnormality, attempting to reconnect." This data is then input into the dynamic classification branch of the information asset model. Model processing: Compares fluctuations in current communication frequency with historical communication characteristics. Analyzes the distribution differences between operating status data and historical normal / abnormal states. Uses NLP technology to parse abnormal events described in the dynamic log. Model output: Predicted label: "Edge router (abnormal)." Finally, the label in the updated information asset list is "Edge router (abnormal)."
[0061] It should be noted that we have designed a dynamic update mechanism based on the real-time communication frequency, operation status and dynamic logs, so that the model can adaptively adjust the prediction results according to the new data.
[0062] Specifically, a gated recurrent unit (GRU) is introduced to process time series data:
[0063] Based on the real-time communication frequency, operation status and dynamic logs, we designed a dynamic update mechanism to enable the model to adaptively adjust the prediction results based on new data.
[0064] Specifically, a Gated Recurrent Unit (GRU) is introduced to process time series data:
[0065]
[0066] in: : In time The dynamic state representation reflects the state characteristics of the information asset at the current moment, which is processed by GRU to process the dynamic state of the previous moment. and the current input features generated; : In time Input features (communication frequency, reflecting the communication activity and operation status of information assets with the outside world, describing the current operation status of information assets, characteristics of dynamic logs, and recording real-time behavior logs of information assets); GRU: gated recurrent unit function; then, using dynamic state representation Update the comprehensive features:
[0067]
[0068] in: is a comprehensive feature representation, is a static feature representation (obtained by multimodal collaborative feature fusion); : Trainable weight matrix; finally, the updated comprehensive features are adopted Make predictions and get more accurate results.
[0069] By introducing the time series model (GRU), the model can adaptively adjust the prediction results based on dynamic data obtained in real time, thereby improving its sensitivity and response speed to state changes.
[0070] In addition, through the combination of multimodal collaborative feature fusion and GRU time series modeling, the model can adaptively capture the complementarity of static modal features and the changing trends of dynamic features of time series, ultimately achieving a comprehensive characterization of information assets and significantly improving the accuracy of predictions, sensitivity to state changes, and real-time response capabilities.
[0071] By combining multimodal static feature fusion based on attention mechanism with GRU dynamic feature modeling, the system has the following significant advantages: static features capture the multimodal basic attributes of information assets, dynamic features reflect real-time state changes, and the comprehensive feature representation generated by the combination of the two It has stronger expressive power and discriminative ability; the system realizes sensitive response to state changes through dynamic modeling, and can quickly update the prediction results when state changes are detected, ensuring the accuracy and timeliness of information asset labels; the dynamic and static combination method makes up for the shortcomings of a single feature and significantly improves the adaptability and robustness of the system in diverse scenarios. The dynamic and static combination technical means give full play to the advantages of multimodal data and time series data, and provide a comprehensive, efficient and intelligent solution for the information asset large-scale model automated decision-making system.
[0072] In an embodiment of the present application, multimodal information asset data corresponding to an information asset is obtained, the multimodal information asset data is input into a preset information asset macro model, a predicted label of the information asset is obtained, and the predicted label is updated to the information asset list; wherein, the multimodal information asset data includes an information asset description, an information asset log, and an information asset picture; if the label classification error information transmitted by the control center is not received, the communication frequency, operating status, and dynamic log of the information asset are obtained in real time, and the communication frequency, operating status, and dynamic log are input into the preset information asset macro model to determine whether an information asset update is required; if an information asset update is required, the predicted label of the information asset is re-output according to the communication frequency, operating status, and dynamic log through the preset information asset macro model, and the predicted label is updated to the information asset list. Through the above-mentioned information asset macro model automated decision-making system, by combining multimodal information and dynamic status, the model can comprehensively analyze the current status of the information asset, and the system can automatically re-evaluate the label when dynamic changes are detected, reducing the frequency and workload of manual inspections and reducing operation and maintenance costs.
[0073] Based on the above technical solution, optionally, the system further includes an information asset update module, which is configured to:
[0074] Acquire network traffic data in the system in real time, and determine whether there are new information assets based on the network traffic data;
[0075] If there are new information assets, obtain the multimodal information asset data corresponding to the new information assets, input the multimodal information asset data into the preset information asset model, obtain the predicted label of the new information assets, and update the predicted label to the information asset list.
[0076] In this solution, network traffic data refers to information about various data streams transmitted on the network. Specifically, it can include traffic rate: the number of bytes or packets transmitted per second. Source IP and destination IP: the IP addresses of the communicating parties. Protocol type: for example, TCP, UDP, HTTP, etc. Port number: the source port and destination port, identifying the communication application. Traffic behavior pattern: for example, sudden high-frequency requests, communications that occupy a specific port for a long time, etc. Packet content characteristics: such as request header, packet size, timestamp, etc.
[0077] Newly added information assets may refer to devices, services, or applications that are identified for the first time in the network and were not previously in the information asset inventory.
[0078] Network traffic can be captured in real time using traffic collection tools (such as Wireshark, NetFlow, sFlow) or dedicated network monitoring equipment. Key feature data, including IP addresses, port numbers, protocol types, and communication behavior, can then be filtered and extracted. The captured traffic is then compared with the existing asset inventory for relevant device or service characteristics to identify unmatched traffic. Machine learning models or pre-set rules can be used to detect whether the traffic exhibits characteristics of newly added assets: persistent traffic patterns (e.g., a device sending requests regularly) or abnormal communication ranges (e.g., an unregistered device sending data to multiple known devices). If data traffic matching the characteristics of newly added assets is found, it is marked as a "suspected newly added information asset." Suspected newly added information assets are then subjected to a deep scan: metadata (device name, model, and version) is collected; initial logs (e.g., boot time and system information) are collected; and images of the device or operating interface (e.g., photos of physical connections or screenshots of remote desktops) are captured. This data is then organized into standardized multimodal information asset data. The model integrates this data into a unified feature vector using a multimodal feature fusion module (e.g., an attention mechanism). The classification branch then outputs a predicted label for the information asset.
[0079] In this solution, the system monitors network traffic in real time and identifies newly added information assets, avoiding security risks and management blind spots caused by information lags. The system automatically identifies, categorizes, and updates assets, eliminating the need for manual comparison and classification. This improves the efficiency of information asset management and saves IT operations teams significant time and effort.
[0080] Based on the above technical solution, optionally, the system further includes a resource allocation module, and the resource allocation module is configured to:
[0081] Update the information asset log of each information asset in the information asset list in real time, obtain the performance indicators and business requirements of each information asset in real time, input the information asset log, performance indicators and business requirements into the preset information asset macro model to determine whether resource allocation is required;
[0082] If resource allocation is required, a resource allocation suggestion is output through a preset information asset macro model, and the resource allocation suggestion is sent to a control center.
[0083] In this solution, performance indicators can be quantitative parameters that describe the operational status of information assets. These include: computing performance: CPU utilization, memory usage, and disk I / O rate; network performance: bandwidth utilization, packet loss rate, and latency; stability: failure rate and mean time between failures (MTBF); and power consumption indicators: real-time power consumption and energy efficiency. Performance indicators reflect the current status and operational capabilities of the device and serve as an important basis for resource allocation decisions.
[0084] Business requirements can be the actual business scenarios and requirements supported by information assets: Computing requirements: required processing power or number of threads (e.g., video encoding, data analysis). Storage requirements: data storage capacity or read / write speeds (e.g., file services, databases). Network requirements: bandwidth, number of connections, or traffic requirements (e.g., real-time communication, streaming media). Business requirements reflect the system's functional priorities and resource allocation goals.
[0085] Resource allocation recommendations can be optimized allocation plans generated by the large model based on current performance indicators and business needs. Specifically, they can include resource allocation strategies: increasing or decreasing computing resources (such as allocating more CPU cores or memory); load balancing optimization: adjusting network traffic distribution or task scheduling; storage optimization recommendations: expanding storage space and clearing cache; and energy management solutions: reducing power consumption or enabling energy-saving mode.
[0086] The system uses monitoring tools to collect real-time performance metrics of information assets. Business requirements (such as computing demands triggered by high-load tasks) are captured through the scheduling system or API. Information asset descriptions, logs, images, communication frequencies, and dynamic logs are collected as input, combined with performance metrics and business requirements, and fed into a pre-set macro model. The resource allocation branch then generates optimization recommendations based on resource allocation history and business rules. Finally, the resource allocation recommendations generated by the model are sent to the control center via an API or message queue. The control center dynamically adjusts resource allocation strategies based on the recommendations.
[0087] In this solution, by obtaining the performance indicators and business requirements of information assets in real time, the system can make accurate judgments on resource allocation needs and avoid over- or under-allocation of resources.
[0088] On the basis of the above technical solution, optionally, the system further includes a health status determination module, and the health status determination module is used to:
[0089] Obtaining historical usage data, real-time status data, and performance degradation data for each information asset in the information asset list, inputting the historical usage data, real-time status data, and performance degradation data into a preset information asset macro model to determine a health status score for each information asset;
[0090] If there is an information asset whose health status score is lower than a preset health threshold, an optimization suggestion for the information asset is output through a preset information asset macro model.
[0091] In this solution, historical usage data can be the usage of information assets over a period of time. This data may include the device's operating time, usage frequency, load, and operation history. It reflects whether the information asset experiences abnormal load or excessive usage during daily use.
[0092] Real-time status data refers to the current state of information assets. This data typically includes the real-time health status of the equipment, operating parameters, and system performance indicators. This data can be acquired in real time through sensors or monitoring tools, reflecting the real-time operating status of the equipment.
[0093] Performance degradation data can be the gradual decline in performance of information assets over the long term due to factors such as natural aging, overuse, or environmental impacts. This data is typically based on historical performance records of the device, such as reduced processing speed, increased energy consumption, and increased failure rates.
[0094] The health status score can be a comprehensive score that measures the overall health level of an information asset, and is usually a numerical value that represents the current health status of the information asset.
[0095] A preset health threshold can be a benchmark used to determine whether an information asset's health status meets standards. Generally speaking, if the health score falls below this threshold, the information asset may be at risk of failure or require maintenance or optimization. This threshold can be set based on industry standards, historical data analysis, or actual usage experience.
[0096] Optimization recommendations can be improvement measures provided for information assets with low health scores. The purpose of optimization recommendations is to help equipment return to normal working condition, extend its service life, or improve performance. Specifically, they can include hardware maintenance: such as cleaning, replacing worn parts, or adding additional cooling equipment. Software upgrades: such as updating firmware, operating systems, or related applications to improve performance or fix known vulnerabilities. Reconfiguration: For example, adjusting resource allocation, optimizing load balancing, or reducing invalid operations.
[0097] Historical usage records of information assets can be collected through databases, device management systems, sensors, or monitoring tools. For example, data can be extracted from device log systems and operation and maintenance management systems to understand information such as device usage frequency and operating hours. Real-time monitoring systems or sensors can be used to obtain the current operating status of information assets. This may include real-time load, temperature, voltage, power consumption, fault alerts, and other information. Long-term performance data can be collected to assess device degradation. This data can be obtained by comparing historical performance records to determine, for example, whether the device's processing capacity, efficiency, and energy consumption have gradually declined over time. The collected historical usage data, real-time status data, and performance degradation data are organized into a format that can be input, ensuring that the data is clean and complete. This organized data is then fed into a large information asset model. This model, which can be a machine learning model, deep learning model, or statistical analysis model, calculates a health score for each information asset based on a pre-set algorithm. The model assesses the health of the information asset based on the input historical usage data, real-time status data, and performance degradation data. The trained large model calculates a health score for each information asset and determines whether it falls below a pre-set health threshold. If the health score falls below a preset threshold, the model will generate specific optimization recommendations based on pre-set rules or learning from historical data. These recommendations are customized based on the specific status of the device and may include hardware repairs, software updates, or configuration adjustments. These recommendations are then communicated to relevant personnel or systems so that necessary optimization or maintenance measures can be taken to prevent device failure or further performance degradation.
[0098] In this solution, real-time monitoring of the health of information assets can promptly identify potential issues and prevent equipment failure or performance degradation. Assessments based on health status scores provide data support, helping decision makers understand the health of their equipment and make more informed decisions.
[0099] Based on the above technical solution, the optional, preset information asset large model training process includes:
[0100] Constructing a large information asset model, obtaining historical multimodal information asset data and corresponding static classification labels, and training a static classification branch of the large information asset model based on the multimodal information asset data and corresponding static classification labels;
[0101] Acquire historical communication frequencies, historical operating states, historical dynamic logs, and dynamic classification labels of historical information assets, create a first data set based on the historical communication frequencies, historical operating states, and historical dynamic logs, and train a dynamic classification branch of the information asset macro model based on the first data set and the dynamic labels;
[0102] Obtaining historical information asset logs, historical performance indicators, historical business requirements, and resource allocation status of historical information assets, creating a second data set based on the historical information asset logs, historical performance indicators, and historical business requirements, and labeling the second data set with a resource allocation tag based on the resource allocation status;
[0103] Obtaining historical information asset logs, historical performance indicators, historical business requirements, and historical resource allocation suggestions for resource allocation, creating a third data set based on the historical information asset logs, historical performance indicators, and historical business requirements for resource allocation, and labeling the third data set with an allocation suggestion tag based on the historical resource allocation suggestions;
[0104] Training a resource allocation branch of the information asset macro model based on the second data set, the corresponding resource allocation tags, the third data set, and the corresponding allocation suggestion tags;
[0105] Acquire historical normal behavior and historical abnormal behavior of historical information assets, and acquire historical traffic data, historical information asset metadata, historical information asset logs, and historical trend information of the historical normal behavior; create a fourth data set based on the historical traffic data, historical information asset metadata, and historical information asset logs of the historical normal behavior; and annotate the fourth data set with a normal behavior label and a trend information label based on the historical normal behavior and historical trend information;
[0106] Acquire historical traffic data, historical information asset metadata, historical information asset logs, historical classification labels, and historical decision results of historical abnormal behaviors, create a fifth data set based on the historical traffic data, historical information asset metadata, and historical information asset logs of the historical abnormal behaviors, and annotate the abnormal behavior labels, classification labels, and decision result labels of the fifth data set based on the historical abnormal behaviors, historical classification labels, and historical abnormal decision results;
[0107] Training the behavior prediction branch of the information asset large model based on the fourth data set, the corresponding normal behavior labels and trend information labels, the fifth data set, the corresponding abnormal behavior labels, the classification labels, and the decision result labels;
[0108] Acquire historical usage data, historical status data, historical performance degradation data, and corresponding historical health status scores of historical information assets, create a sixth data set based on the historical usage data, historical status data, and historical performance degradation data, and annotate the sixth data set with a health status score label based on the historical health status score;
[0109] determining an abnormal health status score based on the historical health status score and a preset health threshold, obtaining historical usage data, historical status data, historical performance degradation data, and historical optimization suggestions corresponding to the abnormal health status score, creating a seventh data set based on the historical usage data, historical status data, and historical performance degradation data corresponding to the abnormal health status score, and labeling the seventh data set with an optimization suggestion tag based on the historical optimization suggestion;
[0110] The scoring branch of the information asset model is trained based on the sixth data set, the corresponding health status scoring label, the seventh data set, and the corresponding optimization suggestion label.
[0111] In this solution, the historical multimodal information asset data can be data from multiple sources or formats.
[0112] Static classification labels can represent fixed attribute classifications of information assets.
[0113] The static classification branch may be a static category branch of the prediction information asset, used to analyze fixed attributes of the asset.
[0114] The historical communication frequency can be the frequency of communication between the asset and other nodes.
[0115] Health status can be a history of whether an asset is functioning properly.
[0116] Dynamic logs can be records of dynamic events, such as alarms and abnormal activities.
[0117] A dynamic category label may be a category label that reflects dynamic attributes.
[0118] The first data set may include dynamic data (communication frequency, operating status, dynamic log) and its corresponding dynamic classification labels, which are used to train the dynamic classification branch.
[0119] The dynamic classification branch can be used to predict the dynamic classification of information assets.
[0120] Historical information assets can be usage records and metadata during the asset life cycle.
[0121] Historical information asset logs can be detailed records of events, errors, or actions.
[0122] Historical performance indicators can be CPU, memory, network latency, etc.
[0123] Historical business requirements can be demands or dependencies on resources.
[0124] The historical resource allocation situation may be the actual amount and configuration of allocated resources.
[0125] The second data set may include logs, performance indicators, business requirements, and corresponding resource allocation tags.
[0126] The resource allocation tag may be a tag indicating a resource allocation situation.
[0127] The third data set may be data focusing on historical resource allocation recommendations for improving allocation strategies.
[0128] The allocation suggestion tag may be a recommended resource allocation action plan.
[0129] The resource allocation branch can be used to predict the optimal resource allocation strategy.
[0130] Historical normal behavior can be an operation record without abnormal situations.
[0131] Historical abnormal behaviors can be abnormal events such as traffic surges and operation interruptions.
[0132] The historical traffic data may be the network communication traffic of the asset.
[0133] Historical information asset metadata can be asset attributes (such as type, location).
[0134] Historical information asset logs can be detailed records of abnormal behavior.
[0135] Historical trend information can be a trend of changes in behavior or performance.
[0136] The fourth data set may be a combination of normal behavior and related data for training a behavior prediction model.
[0137] The normal behavior label may be a label used to mark the fourth data set, describing whether the asset is normal.
[0138] The trend information tag may be a tag used to mark the fourth data set and describe the asset change trend.
[0139] The fifth data set may include relevant data and labels of abnormal behaviors for use in anomaly detection.
[0140] Abnormal behavior labels can mark whether it is abnormal.
[0141] Classification labels can mark abnormal categories.
[0142] Decision result labels can mark the processing results taken on abnormal behaviors.
[0143] The behavior prediction branch can be used to predict asset behavior and classify abnormal situations.
[0144] Historical usage data can be the frequency and duration of resource usage.
[0145] The historical status data may be the operating status of the equipment (normal / faulty).
[0146] Historical performance degradation data can be a trend of performance degradation.
[0147] The historical health score can be a score of the asset's health, which is usually a numerical value based on comprehensive indicators (such as performance and failure rate).
[0148] The sixth data set may include health status related data and score labels.
[0149] The health status score tag can describe the score of the asset's health status.
[0150] An abnormal health status score may be when the health score is below a threshold.
[0151] Historical optimization recommendations can be improvement measures provided for abnormal health scores.
[0152] The seventh data set may include abnormal health status and its corresponding optimization suggestions.
[0153] The optimization suggestion label can describe the specific optimization plan.
[0154] The scoring branch can be used to predict health scores and output optimization recommendations.
[0155] Multimodal data can be obtained from the asset management system. Data sets are generated based on historical records. Label generation is then performed. Specifically, static and dynamic classifications can include asset type and importance level. Resource allocation can include allocation labels and recommendation labels. Behavior prediction can include normal / abnormal behavior labels. Health scoring can include score labels and optimization suggestions. Six main data sets are then constructed, corresponding to static classification, dynamic classification, resource allocation, behavior prediction, and health scoring. These data sets are used to train the static classification branch, dynamic classification branch, resource allocation branch, behavior prediction branch, and scoring branch, respectively. Finally, the performance indicators of each branch are verified, and model parameters are adjusted to improve prediction accuracy.
[0156] In this solution, the big model significantly improves the efficiency, accuracy and security of information asset management through intelligence, real-time and multi-branch collaboration, bringing higher resource utilization and lower operating costs to the organization.
[0157] Example 2
[0158] Figure 2 This is a schematic diagram of the structure of the information asset large model automated decision-making system provided in Example 2 of this application. Figure 2 As shown, specifically including the following:
[0159] The system further includes an abnormality determination module 104, which is configured to:
[0160] Acquire traffic data and information asset metadata of each information asset in the information asset list in real time, and obtain an external threat database, input the traffic data, information asset metadata, information asset logs, and external threat database into a preset information asset macro model to determine whether each information asset has abnormal behavior;
[0161] If there is an information asset with abnormal behavior, the predicted label of the information asset is re-output through the preset information asset model, and the decision result on the abnormal behavior is output.
[0162] In this embodiment, traffic data may refer to the communication data characteristics of each information asset in the network, such as the number, size, and direction of data packets, communication frequency, and protocol type (e.g., HTTP, TCP / IP). Performance metrics such as network latency and throughput are also included. This is used to analyze interaction patterns between information assets and external environments or internal assets.
[0163] Information asset metadata can be static attributes and identification information describing information assets, including asset type (e.g., server, device, application), asset ID, IP address, MAC address, and configuration attributes (e.g., operating system, version information). It is used to model asset characteristics and provide a basis for static classification.
[0164] External threat databases are collections of data containing known security threats and attack patterns, typically maintained by security vendors or organizations. These databases include: malicious IP lists, known attack signatures, vulnerability databases (such as the Common Vulnerability Database), and threat intelligence (such as APT attack methods and phishing website domains). These databases are used to compare and identify external risk factors related to abnormal behavior.
[0165] Abnormal behavior can refer to deviations from normal operating or communication patterns of information assets. This includes: sudden increases in data traffic or unusual protocol usage; unauthorized access attempts; excessively high or low communication frequencies; and communications with external malicious IP addresses or domain names. Large-scale model detection is used to determine whether there are deviations from historical or expected patterns.
[0166] The decision results can be recommendations or actions for the detected abnormal behavior, including whether to isolate the abnormal asset, update the security policy, and specific protective measures (such as blocking traffic, triggering an alert, and performing a patch update).
[0167] Network monitoring tools (such as NetFlow and sFlow) can be used to collect information asset communication traffic data in real time. The data processing module extracts key features (such as packet size, traffic direction, and communication frequency). Asset metadata is synchronized from information asset management systems (such as CMDBs). Newly added asset information (such as IP addresses and operating system versions) is dynamically updated. Updates are pulled in real time from threat intelligence providers (such as VirusTotal and AlienVault). This includes the latest vulnerabilities, malicious IP addresses, and domain names. Traffic data, information asset metadata, information asset logs, and external threat databases are used as multimodal inputs. The large model analyzes multi-dimensional information and combines it with historical behavior data to determine whether abnormal behavior exists. Specifically, the large model uses the behavior prediction branch to classify the input data and mark whether the asset is abnormal. For abnormal information assets, the large model's dynamic classification branch re-outputs the predicted label. The classification information of the asset in the information asset list is updated. Finally, the large model's behavior prediction branch combines historical decision results to output processing recommendations.
[0168] In this embodiment, by acquiring traffic data, metadata, logs, and external threat information in real time, it is possible to quickly detect and identify abnormal behavior in information assets, preventing potential security threats from escalating. Combined with input from an external threat database, it can more comprehensively assess and match abnormal behavior, identifying both known and unknown security risks.
[0169] On the basis of the above technical solution, optionally, the system further includes a trend prediction module, which is used to:
[0170] If there is no abnormal behavior, the trend prediction information is output through the preset information asset big model and sent to the control center.
[0171] In this solution, trend prediction information can be the result of predicting the future status and behavior trends of information assets based on historical and real-time data combined with machine learning models. Specifically, it can include performance trends: predicting performance changes of information assets, such as changes in bandwidth utilization, processing power, storage capacity, etc. Health status trends: predicting whether the health score of information assets has a downward trend or may be close to the threshold. Security threat trends: predicting the increase or decrease trend of potential risks based on the dynamic changes of the external threat database. Usage demand trends: predicting resource allocation that may need to be adjusted in the future, such as traffic peak time, workload changes, etc. Behavior change trends: predicting whether information assets will have possible abnormalities or functional deviations after a period of time.
[0172] If the prediction branch determines that there are no abnormal behaviors, it analyzes real-time and historical data to predict the future operational status and trends of the information asset: Performance trends: resource utilization and load changes; Health trends: changes in health scores; Business demand trends: request volume and peak load times; Potential risk trends: assessing changes in security risks based on threat intelligence. Trend prediction results are sent to the control center in a structured format (such as JSON or XML).
[0173] In this solution, based on trend forecasting, resource allocation can be adjusted according to demand to avoid excessive waste or shortage of resources and optimize operating costs.
[0174] Example 3
[0175] Figure 3 This is a schematic diagram of the structure of the information asset large model automated decision-making system provided in Example 3 of this application. Figure 3 As shown, specifically including the following:
[0176] The system further includes an encryption module 105, which is configured to:
[0177] Generate a symmetric encryption key according to a preset key generation rule, and store the symmetric encryption key in a key management system;
[0178] According to a preset encryption algorithm selection rule, the information asset list is encrypted according to the symmetric encryption key to obtain encrypted data.
[0179] In this embodiment, the preset key generation rules can be a set of algorithms or logic for generating symmetric encryption keys, including key length, generation method, entropy source, etc. For example, common rules may be included: Key length: follow security standards (such as AES uses 128, 192 or 256-bit keys). Randomness: Generate keys through a hardware random number generator or a secure pseudo-random number generator (such as CSPRNG). Use of secure algorithms: such as PBKDF2, HKDF, or a generation mechanism based on a password seed. Update mechanism: including key rotation cycle and expiration handling method.
[0180] A symmetric encryption key may be the core key in an encryption method that uses the same key for both encryption and decryption.
[0181] A key management system can be a secure system for generating, storing, distributing, rotating, and managing cryptographic keys.
[0182] Pre-set encryption algorithm selection rules can be standards or logic that determine which symmetric encryption algorithm to use (such as AES, DES, or ChaCha20). Selection criteria can include data type and sensitivity: a stronger algorithm (such as AES-256) is selected for highly sensitive data. Performance requirements: For low-resource devices, a more efficient encryption algorithm (such as ChaCha20) may be selected. Industry standards: Adherence to industry or regulatory recommendations, such as AES. Compatibility: Consistency with existing systems or protocols.
[0183] Encrypted data can be the ciphertext form of original data (such as information asset list) processed by a symmetric encryption algorithm, which cannot be directly restored to plaintext.
[0184] You can use key generation rules to call a secure random number generator (such as OpenSSL or JavaSecureRandom). Generate a random key based on the required key length (such as 256 bits). Store the key in a key management system (such as AWS KMS or Azure Key Vault) and set access permissions. Then, select a rule based on the preset encryption algorithm (such as AES-256). Set the algorithm parameters (such as encryption mode: CBC or GCM; padding: PKCS#7). Then, obtain the plaintext data to be encrypted (such as an information asset list). Then, import the symmetric encryption key and generate the necessary initialization vector (IV) or random number. Call the encryption library (such as Python's PyCrypto or Java's javax.crypto). Store the encrypted data as a ciphertext file or database record.
[0185] In this embodiment, encryption protection ensures that only authorized users with the key can access the information asset list. Even if the encrypted data is intercepted, the attacker cannot restore the original information. It also prevents sensitive data from being leaked due to system vulnerabilities or malicious attacks.
[0186] On the basis of the above technical solution, optionally, the system further includes a decryption module, and the decryption module is used to:
[0187] If a decryption request is received, verifying user authority based on the decryption request;
[0188] If the user authority verification is passed, the symmetric encryption key is obtained from the key management system, and the decryption algorithm is determined according to the preset encryption algorithm;
[0189] The encrypted data is decrypted according to the decryption algorithm and the symmetric encryption key to obtain the plaintext data of the encrypted data.
[0190] In this solution, a decryption request can be an operation request sent by a user or system to the server to decrypt specific encrypted data. Specifically, it can include user identity information (such as username or ID), the identifier of the encrypted data (such as the data file ID or resource path), and the reason or purpose of decryption (optional, used for log auditing).
[0191] User permissions refer to the legality of a user's access to and decryption of encrypted data. Verification methods can include user identity verification (e.g., password, two-factor authentication), role or permission checks (e.g., administrator, data owner, specific access group), and a permission approval process for decryption operations.
[0192] A decryption algorithm is a mathematical method used to restore encrypted data, and is usually symmetric to the encryption algorithm.
[0193] Plaintext data can be the original information content restored after the encrypted data is decrypted and can be used directly by users.
[0194] The system can listen to the interface (API or other service) for decryption requests. Parse the request content and extract parameters such as user information, target data identifier, and decryption reason. Then call the authentication service to verify the user's identity and authentication information (such as username + password, fingerprint, etc.). Check user permissions (role permission table in the permission management system). Record the decryption request and verification results. If the user's permissions are insufficient, reject the request and record the reason. This can trigger an alarm or notify the administrator. If the user's permissions are verified, the key retrieval interface of the key management system (KMS) can be called. Obtain the corresponding symmetric encryption key through the data identifier. Ensure the security of the key transmission process (such as using HTTPS or end-to-end encryption). Then determine the corresponding decryption algorithm based on the preset encryption algorithm selection rules. Finally, load the decryption algorithm and symmetric encryption key. Use the decryption algorithm to decrypt the encrypted data and restore it to plaintext data.
[0195] In this solution, it can be ensured that only authenticated and authorized users can access encrypted data, preventing unauthorized access.
[0196] Example 4
[0197] Figure 4 This is a flow chart of the information asset large model automated decision-making method provided in Example 4 of this application. Figure 4 As shown, the specific steps include:
[0198] S401, obtain multimodal information asset data corresponding to the information asset, input the multimodal information asset data into a preset information asset macro model, obtain a predicted label for the information asset, and update the predicted label to the information asset list; wherein, the multimodal information asset data includes an information asset description, an information asset log, and an information asset picture.
[0199] S402: If the label classification error information transmitted by the control center is not received, the communication frequency, operation status and dynamic log of the information asset are obtained in real time, and the communication frequency, operation status and dynamic log are input into the preset information asset model to determine whether the information asset needs to be updated.
[0200] S403: If the information asset needs to be updated, the predicted label of the information asset is re-output according to the communication frequency, operation status and dynamic log through the preset information asset macro model, and the predicted label is updated to the information asset list.
[0201] In this embodiment, multimodal information asset data corresponding to an information asset is obtained, the multimodal information asset data is input into a preset information asset macro model, a predicted label for the information asset is obtained, and the predicted label is updated to the information asset list; wherein, the multimodal information asset data includes an information asset description, an information asset log, and an information asset image; if no label classification error information transmitted by the control center is received, the communication frequency, operating status, and dynamic log of the information asset are obtained in real time, and the communication frequency, operating status, and dynamic log are input into the preset information asset macro model to determine whether an information asset update is required; if an information asset update is required, the predicted label of the information asset is re-output based on the communication frequency, operating status, and dynamic log through the preset information asset macro model, and the predicted label is updated to the information asset list. Through the above-mentioned information asset macro model automated decision-making method, by combining multimodal information and dynamic status, the model can comprehensively analyze the current status of the information asset, and the system can automatically re-evaluate the label when dynamic changes are detected, reducing the frequency and workload of manual inspections and lowering operation and maintenance costs.
[0202] It should be noted that, in this article, the terms "comprise", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the statement "comprises a ..." does not exclude the presence of other identical elements in the process, method, article or device comprising the element. In addition, it should be noted that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in the opposite order according to the functions involved. For example, the described method may be performed in an order different from that described, and various steps may also be added, omitted, or combined. In addition, the features described with reference to certain examples may be combined in other examples.
[0203] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better embodiment. Based on this understanding, the technical solution of this application, or the part that contributes to the existing technology, can be embodied in the form of a computer software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in each embodiment of this application.
[0204] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms without departing from the purpose of this application and the scope of protection of the claims, all of which are within the protection of this application.
[0205] The above are only preferred embodiments of the present application and the technical principles employed. The present application is not limited to the specific embodiments described herein, and various obvious changes, readjustments, and substitutions that are possible for those skilled in the art will not depart from the scope of protection of the present application. Therefore, although the present application has been described in more detail through the above embodiments, the present application is not limited to the above embodiments and may include more other equivalent embodiments without departing from the concept of the present application. The scope of the present application is determined by the scope of the claims.
Claims
1. An automated decision-making system for information asset large models, characterized by: The system comprises: A classification module is configured to obtain multimodal information asset data corresponding to an information asset, input the multimodal information asset data into a preset information asset macromodel, obtain a predicted label for the information asset, and update the predicted label to the information asset list; wherein the multimodal information asset data includes an information asset description, an information asset log, and an information asset image; An update confirmation module is used to obtain the communication frequency, operating status, and dynamic log of the information asset in real time if no label classification error information transmitted by the control center is received, and input the communication frequency, operating status, and dynamic log into a preset information asset macro model to determine whether an information asset update is required; An update module, configured to re-output the predicted tag of the information asset based on the communication frequency, operation status, and dynamic logs through a preset information asset macro model if an information asset update is required, and update the predicted tag to the information asset list; The training process of the preset information asset model includes: Constructing a large information asset model, obtaining historical multimodal information asset data and corresponding static classification labels, and training a static classification branch of the large information asset model based on the multimodal information asset data and corresponding static classification labels; Acquire historical communication frequencies, historical operating states, historical dynamic logs, and dynamic classification labels of historical information assets, create a first data set based on the historical communication frequencies, historical operating states, and historical dynamic logs, and train a dynamic classification branch of the information asset macro model based on the first data set and the dynamic classification labels; Obtaining historical information asset logs, historical performance indicators, historical business requirements, and resource allocation status of historical information assets, creating a second data set based on the historical information asset logs, historical performance indicators, and historical business requirements, and labeling the second data set with a resource allocation tag based on the resource allocation status; Obtaining historical information asset logs, historical performance indicators, historical business requirements, and historical resource allocation suggestions for resource allocation, creating a third data set based on the historical information asset logs, historical performance indicators, and historical business requirements for resource allocation, and labeling the third data set with an allocation suggestion tag based on the historical resource allocation suggestions; Training a resource allocation branch of the information asset macro model based on the second data set, the corresponding resource allocation tags, the third data set, and the corresponding allocation suggestion tags; Acquire historical normal behavior and historical abnormal behavior of historical information assets, and acquire historical traffic data, historical information asset metadata, historical information asset logs, and historical trend information of the historical normal behavior; create a fourth data set based on the historical traffic data, historical information asset metadata, and historical information asset logs of the historical normal behavior; and annotate the fourth data set with a normal behavior label and a trend information label based on the historical normal behavior and historical trend information; Acquire historical traffic data, historical information asset metadata, historical information asset logs, historical classification labels, and historical decision results of historical abnormal behaviors, create a fifth data set based on the historical traffic data, historical information asset metadata, and historical information asset logs of the historical abnormal behaviors, and annotate the abnormal behavior labels, classification labels, and decision result labels of the fifth data set based on the historical abnormal behaviors, historical classification labels, and historical abnormal decision results; Training the behavior prediction branch of the information asset large model based on the fourth data set, the corresponding normal behavior labels and trend information labels, the fifth data set, the corresponding abnormal behavior labels, the classification labels, and the decision result labels; Acquire historical usage data, historical status data, historical performance degradation data, and corresponding historical health status scores of historical information assets, create a sixth data set based on the historical usage data, historical status data, and historical performance degradation data, and annotate the sixth data set with a health status score label based on the historical health status score; determining an abnormal health status score based on the historical health status score and a preset health threshold, obtaining historical usage data, historical status data, historical performance degradation data, and historical optimization suggestions corresponding to the abnormal health status score, creating a seventh data set based on the historical usage data, historical status data, and historical performance degradation data corresponding to the abnormal health status score, and labeling the seventh data set with an optimization suggestion tag based on the historical optimization suggestion; The scoring branch of the information asset model is trained based on the sixth data set, the corresponding health status scoring label, the seventh data set, and the corresponding optimization suggestion label.
2. The information asset large model automated decision-making system according to claim 1, characterized in that: The system further includes an information asset updating module, which is configured to: Acquire network traffic data in the system in real time, and determine whether there are new information assets based on the network traffic data; If there are new information assets, obtain the multimodal information asset data corresponding to the new information assets, input the multimodal information asset data into the preset information asset model, obtain the predicted label of the new information assets, and update the predicted label to the information asset list.
3. The information asset large model automated decision-making system according to claim 1, characterized in that: The system further includes a resource allocation module, wherein the resource allocation module is configured to: Update the information asset log of each information asset in the information asset list in real time, obtain the performance indicators and business requirements of each information asset in real time, input the information asset log, performance indicators and business requirements into the preset information asset macro model to determine whether resource allocation is required; If resource allocation is required, a resource allocation suggestion is output through a preset information asset macro model, and the resource allocation suggestion is sent to a control center.
4. The information asset large model automated decision-making system according to claim 1, characterized in that: The system further includes an abnormality determination module, which is configured to: Acquire traffic data and information asset metadata of each information asset in the information asset list in real time, and obtain an external threat database, input the traffic data, information asset metadata, information asset logs, and external threat database into a preset information asset macro model to determine whether each information asset has abnormal behavior; If there is an information asset with abnormal behavior, the predicted label of the information asset is re-output through the preset information asset model, and the decision result on the abnormal behavior is output.
5. The information asset large model automated decision-making system according to claim 4 is characterized in that: The system further includes a trend prediction module, which is configured to: If there is no abnormal behavior, the trend prediction information is output through the preset information asset big model and sent to the control center.
6. The information asset large model automated decision-making system according to claim 1, characterized in that: The system further includes a health status determination module, which is configured to: Obtaining historical usage data, real-time status data, and performance degradation data for each information asset in the information asset list, inputting the historical usage data, real-time status data, and performance degradation data into a preset information asset macro model to determine a health status score for each information asset; If there is an information asset whose health status score is lower than a preset health threshold, an optimization suggestion for the information asset is output through a preset information asset macro model.
7. The information asset large model automated decision system according to claim 1, characterized in that: The system further includes an encryption module, configured to: Generate a symmetric encryption key according to a preset key generation rule, and store the symmetric encryption key in a key management system; According to a preset encryption algorithm selection rule, the information asset list is encrypted according to the symmetric encryption key to obtain encrypted data.
8. The information asset large model automated decision-making system according to claim 7, characterized in that: The system further includes a decryption module, configured to: If a decryption request is received, verifying user authority based on the decryption request; If the user authority verification is passed, the symmetric encryption key is obtained from the key management system, and the decryption algorithm is determined according to the preset encryption algorithm; The encrypted data is decrypted according to the decryption algorithm and the symmetric encryption key to obtain the plaintext data of the encrypted data.
9. An automated decision-making method for a large information asset model, characterized in that: The method comprises: Obtaining multimodal information asset data corresponding to an information asset, inputting the multimodal information asset data into a preset information asset macromodel to obtain a predicted label for the information asset, and updating the predicted label to the information asset list; wherein the multimodal information asset data includes an information asset description, an information asset log, and an information asset image; If the tag classification error information transmitted by the control center is not received, the communication frequency, operation status and dynamic log of the information asset are obtained in real time, and the communication frequency, operation status and dynamic log are input into the preset information asset macro model to determine whether the information asset needs to be updated; If an information asset needs to be updated, the information asset prediction tag is re-output based on the communication frequency, operation status, and dynamic log through the preset information asset macro model, and the prediction tag is updated to the information asset list; The training process of the preset information asset model includes: Constructing a large information asset model, obtaining historical multimodal information asset data and corresponding static classification labels, and training a static classification branch of the large information asset model based on the multimodal information asset data and corresponding static classification labels; Acquire historical communication frequencies, historical operating states, historical dynamic logs, and dynamic classification labels of historical information assets, create a first data set based on the historical communication frequencies, historical operating states, and historical dynamic logs, and train a dynamic classification branch of the information asset macro model based on the first data set and the dynamic classification labels; Obtaining historical information asset logs, historical performance indicators, historical business requirements, and resource allocation status of historical information assets, creating a second data set based on the historical information asset logs, historical performance indicators, and historical business requirements, and labeling the second data set with a resource allocation tag based on the resource allocation status; Obtaining historical information asset logs, historical performance indicators, historical business requirements, and historical resource allocation suggestions for resource allocation, creating a third data set based on the historical information asset logs, historical performance indicators, and historical business requirements for resource allocation, and labeling the third data set with an allocation suggestion tag based on the historical resource allocation suggestions; Training a resource allocation branch of the information asset macro model based on the second data set, the corresponding resource allocation tags, the third data set, and the corresponding allocation suggestion tags; Acquire historical normal behavior and historical abnormal behavior of historical information assets, and acquire historical traffic data, historical information asset metadata, historical information asset logs, and historical trend information of the historical normal behavior; create a fourth data set based on the historical traffic data, historical information asset metadata, and historical information asset logs of the historical normal behavior; and annotate the fourth data set with a normal behavior label and a trend information label based on the historical normal behavior and historical trend information; Acquire historical traffic data, historical information asset metadata, historical information asset logs, historical classification labels, and historical decision results of historical abnormal behaviors, create a fifth data set based on the historical traffic data, historical information asset metadata, and historical information asset logs of the historical abnormal behaviors, and annotate the abnormal behavior labels, classification labels, and decision result labels of the fifth data set based on the historical abnormal behaviors, historical classification labels, and historical abnormal decision results; Training the behavior prediction branch of the information asset large model based on the fourth data set, the corresponding normal behavior labels and trend information labels, the fifth data set, the corresponding abnormal behavior labels, the classification labels, and the decision result labels; Acquire historical usage data, historical status data, historical performance degradation data, and corresponding historical health status scores of historical information assets, create a sixth data set based on the historical usage data, historical status data, and historical performance degradation data, and annotate the sixth data set with a health status score label based on the historical health status score; determining an abnormal health status score based on the historical health status score and a preset health threshold, obtaining historical usage data, historical status data, historical performance degradation data, and historical optimization suggestions corresponding to the abnormal health status score, creating a seventh data set based on the historical usage data, historical status data, and historical performance degradation data corresponding to the abnormal health status score, and labeling the seventh data set with an optimization suggestion tag based on the historical optimization suggestion; The scoring branch of the information asset model is trained based on the sixth data set, the corresponding health status scoring label, the seventh data set, and the corresponding optimization suggestion label.
Citation Information
Patent Citations
Asset identification method, system and equipment based on multi-modal data heterogeneous Transform
CN118013372A
Information security asset network space surveying and mapping system
CN118713927A
Method for optimizing communication spectrum resource allocation by using artificial intelligence
CN118972961A