An exception level recognition system based on exception traceability

Through an exception level identification system based on exception traceability, the target object and its associated objects are analyzed step by step, solving the problem of low accuracy of exception recognition in traditional network security technology, and achieving higher exception level identification accuracy and network security defense capabilities.

CN119848702BActive Publication Date: 2025-07-11CIVIL AVIATION UNIV OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510322716.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-19
Publication Date
2025-07-11
Estimated Expiration
2045-03-19

AI Technical Summary

Technical Problem

Traditional network security technologies are difficult to conduct a comprehensive and overall assessment of the abnormal situation of the target object, resulting in low accuracy of abnormal identification, affecting the reliability of data protection, threat prevention and risk identification.

Method used

An exception level recognition system based on exception traceability is adopted, and the abnormal data of the target object and its associated objects are analyzed step by step through a large language model and a trained classification model, and the exception source and propagation path are identified. Combined with the abnormal data of the target object itself, the traceability analysis is carried out step by step to improve the accuracy of the recognition of the exception level.

Benefits of technology

Through step-by-step traceability analysis and feature extraction, the accuracy of the identification of the target object's abnormal level is significantly improved, providing a reliable basis for subsequent decision-making and processing, and enhancing the defense capabilities of network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119848702B_ABST
    Figure CN119848702B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of data processing, and in particular, to an abnormal level recognition system based on abnormal traceability. Data analysis is performed on target abnormal data and associated abnormal data of the first i levels based on a preset large language model to determine whether there is an abnormal source among the associated objects of the i-th level. When the abnormal source is not determined, the associated abnormal data of the next level is added to the input data of the large language model, so as to determine whether there is an abnormal source among the associated objects of the next level. By gradually updating the data input in the large language model, hierarchical traceability analysis of the abnormal source of the target object is carried out to obtain a target abnormal report, which is used to characterize the abnormal situation and its propagation situation corresponding to the target object. Further, based on the target abnormal report, feature extraction and mapping are performed on relevant abnormal data through a classification model to identify the target abnormal level of the target object, improving the recognition accuracy of the target abnormal level.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data processing, and in particular to an anomaly level recognition system based on anomaly traceability. Background Art

[0002] With the rapid development of the global Internet, network security issues have become increasingly severe. Traditional network security technologies mainly focus on passive defense measures such as firewalls, intrusion detection systems, intrusion prevention systems, and anti-virus software. With the rapid development of means such as big data analysis and behavior analysis, active defense technologies relying on big data analysis, anomaly intelligence, behavior analysis, etc. have gradually become research hotspots. By sorting out blacklists and analyzing the abnormal behaviors and traffic characteristics of target objects, potential attack risks of target objects can be predicted in advance, significantly improving the overall defense ability of network security.

[0003] Although the above technologies can defend against known threats to a certain extent, in the face of continuously evolving new attack means and complex correlation relationships between objects, traditional technologies focus on considering the abnormal behaviors and traffic characteristics of target objects themselves, making it difficult to comprehensively and overall evaluate the abnormal situations of target objects, resulting in low accuracy of abnormal recognition of target objects and being somewhat powerless in aspects such as data protection, threat prevention, and risk identification.

[0004] Therefore, how to improve the recognition accuracy of the anomaly level of target objects, thereby improving the reliability of anomaly recognition results in fields such as data protection, threat protection, and risk identification has become an urgent problem to be solved. Summary of the Invention

[0005] In view of the above technical problems, the technical solution adopted by the present invention is an anomaly level recognition system based on anomaly traceability. The anomaly level recognition system based on anomaly traceability includes a processor and a memory storing a computer program. The memory also stores a trained classification model, target anomaly data A corresponding to a target object 0 , a set of associated anomaly data A = {A 1 , A 2 , ……, A i , ……, A M} corresponding to the target object, where A i = {A i 1, A i 2, ……, A i j(i) , ……, A i N(i)}, A i j(i)It refers to the associated abnormal data corresponding to the j(i)-th i-level associated object corresponding to the target object. The associated abnormal data includes the corresponding target abnormal data and the corresponding degree of abnormality. Here, i = 1, 2, ……, M, where M refers to the number of levels of the associated objects corresponding to the target object, and j(i) = 1, 2, ……, N(i), where N(i) refers to the total number of the i-th associated objects corresponding to the target object. When the computer program is executed by the processor, the following steps are implemented:

[0006] S1, Initialize i = 1.

[0007] S2, Input A 0 、A 1 , ……, A i into a preset large language model to obtain an intermediate abnormal report and an abnormal source identification result. Among them, the intermediate abnormal report includes an intermediate abnormal source, an intermediate abnormal means, and an intermediate abnormal path, and the abnormal source identification result is a determined abnormal source or an undetermined abnormal source.

[0008] S3, If the abnormal source identification result is an undetermined abnormal source, then update i = i + 1, and return to execute step S2 until a preset condition is met, and use the intermediate abnormal report corresponding to when the preset condition is met as the target abnormal report. Among them, the target abnormal report includes a target abnormal source, a target abnormal means, and a target abnormal path, and the target abnormal path includes a target abnormal source, a target object, and several target associated objects between the target abnormal source and the target object.

[0009] S4, According to A and the target abnormal report, input the associated abnormal data corresponding to the target abnormal source, the target abnormal data A 0 corresponding to the target object, the associated abnormal data corresponding to several target associated objects between the target abnormal source and the target object, and the target abnormal report into a trained classification model to obtain the target abnormal level corresponding to the target object.

[0010] The present invention has at least the following beneficial effects: Initialize i = 1, input A 0 、A 1 , ……, A i into a preset large language model to obtain an intermediate abnormal report and an abnormal source identification result. If the abnormal source identification result is an undetermined abnormal source, then update i = i + 1, return to execute the operation steps of the large language model until a preset condition is met, and use the intermediate abnormal report corresponding to when the preset condition is met as the target abnormal report. According to A and the target abnormal report, input the associated abnormal data corresponding to the target abnormal source, the target abnormal data A 0The associated abnormal data corresponding to several target associated objects between the target abnormal source and the target object, and the target abnormal report are input into the trained classification model to obtain the target abnormal level corresponding to the target object. It can be seen that when performing data analysis through a preset large language model, the associated abnormal data of the next level of associated objects is added to determine whether there is an abnormal source corresponding to the target object in the next level of associated objects. By gradually updating the data input into the large language model, a step-by-step traceability analysis of the abnormal source corresponding to the target object is carried out. Finally, when the preset conditions are met, the corresponding intermediate abnormal report is used as the target abnormal report to represent the abnormal situation corresponding to the target object and its propagation situation. Further, based on the target abnormal report, feature extraction and mapping are performed on the relevant abnormal data through the classification model to identify the target abnormal level of the target object, thereby improving the accuracy of identifying the target abnormal level. Brief Description of the Drawings

[0011] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the drawings required for the description of the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0012] Figure 1 It is a flowchart implemented by a processor of an abnormal level recognition system based on abnormal traceability provided by an embodiment of the present invention when executing a computer program. Detailed Embodiments

[0013] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present invention.

[0014] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It can be understood that, under appropriate circumstances, the above terms for distinguishing similar objects can be interchanged so that the present invention can also implement other embodiments other than the illustrated embodiments or described embodiments. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or server including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.

[0015] The first embodiment provides an abnormality level identification system based on abnormality tracing, and the abnormality level identification system based on abnormality tracing includes a processor and a memory storing a computer program, and the memory also stores a trained classification model, target abnormal data A corresponding to the target object, and a 0 , the associated abnormal data set A corresponding to the target object = {A 1 , A 2 , ..., A i , ..., A M}, where A i ={A i 1. A i 2, ..., A i j(i) , ..., A i N(i)}, A i j(i) It refers to the associated abnormal data corresponding to the j(i)th i-th level associated object corresponding to the target object, the associated abnormal data includes the corresponding target abnormal data and the corresponding abnormal degree, i=1, 2, ..., M, M refers to the number of levels of the associated objects corresponding to the target object, j(i)=1, 2, ..., N(i), N(i) refers to the total number of i-th associated objects corresponding to the target object, when the computer program is executed by the processor, the following steps are implemented, such as Figure 1 As shown:

[0016] S1, initialize i=1.

[0017] Among them, the target object can refer to the object that needs to be identified by abnormal level, such as IP, domain name and other objects to be identified in the field of network security. By identifying the abnormal level of the target object, potential abnormal risks can be warned in advance, and the overall defense capability of network security in the fields of data protection, threat prevention, risk identification, etc. can be improved.

[0018] The associated object corresponding to the target object may refer to an object that has multiple association relationships with the target object, such as communication relationship, business relationship, attack relationship, etc. By analyzing the associated abnormal data of the associated object corresponding to the target object and combining it with the target abnormal data of the target object itself, the abnormal situation of the target object can be deeply analyzed and understood, thereby improving the accuracy of identifying the abnormal level of the target object and providing a reliable basis for subsequent decision-making and processing.

[0019] For example, when the target object is a target IP, the associated object corresponding to the target object can be an associated IP corresponding to the target IP. There can be various association relationships between the target IP and the associated IP, as well as among several associated IPs, such as client-server relationship, peer-to-peer communication relationship, same subnet relationship, same network architecture relationship, same business system relationship, same supply chain relationship, attacker-victim relationship, etc. Data is exchanged between the target IP and the associated IPs, and among several associated IPs. The abnormal situation of the associated IP will affect the abnormal situation of the target IP.

[0020] The target abnormal data can include relevant data such as data update time, data creation time, object affected by the anomaly, direct source object of the anomaly, anomaly type, and anomaly description.

[0021] Among them, the specific categories of the anomaly type can be set by the implementer according to the actual situation. For example, in the field of network security, the anomaly types corresponding to an IP can include various anomaly types such as denial-of-service attack, port scan attack, malware infection, SQL injection attack, ARP spoofing attack, and zero-day vulnerability attack.

[0022] The direct source object of the anomaly can refer to the direct source of the abnormal situation corresponding to the target object. In this embodiment, it is necessary to trace the original source of the abnormal situation corresponding to the target object to conduct a comprehensive and in-depth analysis of the abnormal situation of the target object, thereby improving the accuracy of identifying the abnormal level of the target object.

[0023] The degree of anomaly is used to characterize the possibility and severity of the corresponding associated object having an anomaly, and can be obtained by performing several anomaly level identifications on the associated object within a historical time and analyzing the obtained several anomaly levels.

[0024] Specifically, in this embodiment, the target abnormal data of the target object and the associated abnormal data of the associated object are analyzed step by step to identify the source of the abnormal situation of the target object, that is, to identify the anomaly source corresponding to the target object, so as to clarify the anomaly propagation situation corresponding to the abnormal situation of the target object, improve the analysis depth and comprehensiveness of the abnormal situation of the target object, thereby improving the accuracy of identifying the abnormal level of the target object, and providing a reliable basis for subsequent decision-making and processing.

[0025] In a specific embodiment, the memory also stores several initial objects, as well as the association relationships between each initial object and other initial objects and the target object. Among them, the association relationships include direct association and non-direct association. The associated objects of the target object are obtained through the following steps:

[0026] S10. According to the association relationship between each initial object and the target object, determine the initial object directly associated with the target object as the first-level associated object corresponding to the target object.

[0027] S20. According to the association relationship between each initial object and other initial objects, determine the initial object directly associated with each u-level associated object corresponding to the target object as the (u + 1)-level associated object corresponding to the target object, where u = 1, 2, ……, M - 1.

[0028] Among them, after determining the first u-level associated objects corresponding to the target object, from the initial objects that have not been determined as associated objects, determine the initial object directly associated with each u-level associated object as the (u + 1)-level associated object corresponding to the target object, so as to gradually determine the associated objects at all levels of the target object.

[0029] As described above, through the association relationship between the initial object and other initial objects and the target object, the associated objects at all levels of the target object are systematically and comprehensively determined in a step-by-step progressive manner, which has a good analysis effect on complex object relationship networks, can assist in analyzing the propagation path and source of abnormal situations, better understand the behavior characteristics and mutual influence relationships of the object group, and thus improve the recognition accuracy of the abnormal level of the target object.

[0030] In a specific embodiment, the target abnormal data A corresponding to the target object 0 is obtained through the following steps:

[0031] S100. Obtain the initial abnormal data corresponding to the target object.

[0032] S200. Perform data cleaning on the initial abnormal data to obtain the first intermediate abnormal data corresponding to the target object.

[0033] S300. Perform word vector conversion on the first intermediate abnormal data to obtain the second intermediate abnormal data corresponding to the target object.

[0034] S400. Perform standardization processing on the second intermediate abnormal data to obtain the target abnormal data A corresponding to the target object 0 .

[0035] Among them, data cleaning may refer to operations such as noise filtering, missing value filling, and outlier processing on the initial abnormal data to improve data quality.

[0036] Word vector conversion may refer to converting the first intermediate abnormal data into a vector representation of a preset dimension through word vector technology.

[0037] The standardization process may refer to converting the processed data into a format acceptable to the model, such as standardization methods like padding text sequences to a fixed length, min-max standardization, z-score regularization, etc., to meet the input requirements of the classification model.

[0038] Among them, those skilled in the art know that any data cleaning method, word vector technology, and standardization process in the prior art fall within the protection scope of the present invention, and will not be elaborated herein.

[0039] Among them, the method for obtaining the associated abnormal data corresponding to each associated object is the same as the method for obtaining the target abnormal data, and will not be elaborated herein.

[0040] In a specific embodiment, the memory further stores K historical abnormal levels corresponding to each associated object of the target object. The historical abnormal levels include the explanatory level, general level, important level, and urgent level. The abnormal degree corresponding to the associated object is obtained through the following steps:

[0041] S500, obtain the first preset urgency degree corresponding to the explanatory level, the second preset urgency degree corresponding to the general level, the third preset urgency degree corresponding to the important level, and the fourth preset urgency degree corresponding to the urgent level.

[0042] S600, according to the K historical abnormal levels corresponding to each associated object, the first preset urgency degree, the second preset urgency degree, the third preset urgency degree, and the fourth preset urgency degree, obtain the average value of the urgency degrees corresponding to each associated object.

[0043] S700, determine the average value of the urgency degrees corresponding to each associated object as the abnormal degree corresponding to each associated object.

[0044] Among them, in the order of the explanatory level, general level, important level, and urgent level, the preset urgency degrees corresponding to the abnormal levels gradually increase. Correspondingly, the first preset urgency degree < the second preset urgency degree < the third preset urgency degree < the fourth preset urgency degree.

[0045] For any associated object, calculate the average value of the urgency degrees corresponding to the K historical abnormal levels of the current associated object based on the first preset urgency degree, the second preset urgency degree, the third preset urgency degree, and the fourth preset urgency degree. Then, the larger the average value of the urgency degrees, the higher the possibility and severity of the current associated object having an abnormality. Therefore, determine the average value of the urgency degrees corresponding to each associated object as the abnormal degree corresponding to each associated object.

[0046] As described above, based on the K historical abnormal levels corresponding to the associated object and the preset urgency levels corresponding to each type of historical abnormal level, the average urgency level corresponding to the associated object is obtained and used as the corresponding abnormal level to characterize the probability and severity of the current associated object having an abnormality. When analyzing abnormal situations by combining the associated abnormal data of the associated object and the target abnormal data of the target object itself, it provides a data basis for determining the abnormal source and abnormal path, thereby improving the accuracy of identifying the abnormal level of the target object.

[0047] S2, input A 0 and A 1 , ……, A i into the preset large language model to obtain an intermediate abnormal report and an abnormal source identification result. Among them, the intermediate abnormal report includes an intermediate abnormal source, an intermediate abnormal means, and an intermediate abnormal path, and the abnormal source identification result includes a determined abnormal source and an undetermined abnormal source.

[0048] Among them, the target abnormal data and the associated abnormal data corresponding to the first i levels of associated objects are input into the preset large language model for data analysis to determine whether there is abnormal source data of the abnormal situation of the target object in the associated abnormal data corresponding to the i-th level of associated objects, that is, whether there is an abnormal source corresponding to the target object in the i-th level of associated objects, which is used as the intermediate abnormal source for tracing the abnormal situation of the target object. And obtain the abnormal means corresponding to the target object, which is used as the intermediate abnormal means to determine the target abnormal means. And determine the path of abnormal propagation according to the association relationship between the intermediate abnormal source and the associated object, which is used as the intermediate abnormal path to determine the target abnormal path.

[0049] The preset large language model can be trained based on the abnormal related data of each object in the relevant field of the target object to improve the matching of the preset large language model with the target object and the associated object, thereby improving the analysis accuracy of the target abnormal data and the associated abnormal data, and further improving the accuracy of identifying the abnormal level of the target object.

[0050] As described above, based on the preset large language model, data analysis is performed on the target abnormal data and the associated abnormal data corresponding to the first i levels of associated objects to determine whether there is an abnormal source corresponding to the target object in the i-th level of associated objects, which serves as the data basis for determining the target abnormal report, improving the analysis accuracy of the abnormal propagation situation, and further improving the accuracy of identifying the abnormal level of the target object.

[0051] S3. If the abnormal source identification result is an undetermined abnormal source, update i = i + 1, and return to execute step S2 until a preset condition is met. Then, use the intermediate abnormal report corresponding to when the preset condition is met as the target abnormal report. The target abnormal report includes the target abnormal source, the target abnormal means, and the target abnormal path. The target abnormal path includes the target abnormal source, the target object, and several target associated objects between the target abnormal source and the target object.

[0052] Among them, if the abnormal source identification result is an undetermined abnormal source, the corresponding intermediate abnormal source, intermediate abnormal means, and intermediate abnormal path of this abnormal source identification result are empty. Then update i = i + 1, and continue to input the target abnormal data and the associated abnormal data corresponding to the first i levels of associated objects into the preset large language model for data analysis. That is, when performing data analysis, add the associated abnormal data of the next level of associated objects, so as to determine whether there is an abnormal source corresponding to the target object in the next level of associated objects. By gradually updating the data input into the large language model, perform a step-by-step traceability analysis on the abnormal source corresponding to the target object. Finally, when the preset condition is met, use the corresponding intermediate abnormal report as the target abnormal report to represent the abnormal situation of the target object and its propagation situation, providing a data basis for identifying the abnormal level of the target object.

[0053] The target abnormal source can refer to the fundamental source or starting factor that can cause the target object to have an abnormal situation and is finally determined through a series of analysis and traceability processes. It is the initial cause of the entire abnormality. Other associated abnormal situations and abnormal propagation paths often have direct or indirect associations with the target abnormal source.

[0054] The target abnormal means can refer to the specific operations, behaviors, methods, or ways that are finally determined and are related to causing the target object to have an abnormal situation. That is, the direct or indirect acting method that actually causes the target object to have an abnormal situation. By clarifying the target abnormal means, the specific process and impact of the abnormality can be understood more clearly.

[0055] In a specific embodiment, meeting the preset condition means that the abnormal source identification result is a determined abnormal source.

[0056] In a specific embodiment, when the abnormal source identification result is a determined abnormal source, the target abnormal source refers to the associated object with the highest abnormal degree among the i-th level of associated objects corresponding to the target object.

[0057] In a specific embodiment, meeting the preset condition means inputting A 0 , A 1 , ……, A M into the preset large language model, and the obtained abnormal source identification result is an undetermined abnormal source.

[0058] In a specific embodiment, if A is input 0 and A 1 , ……, A M to a preset large language model, and the obtained abnormal source recognition result is that the abnormal source is undetermined, then the target abnormal source refers to the associated object with the highest degree of abnormality among the M-level associated objects corresponding to the target object.

[0059] As described above, when the abnormal source is undetermined, when performing data analysis through a preset large language model, the associated abnormal data of the next-level associated object is added to determine whether there is an abnormal source corresponding to the target object among the next-level associated objects. By gradually updating the data input to the large language model, the abnormal source corresponding to the target object is traced step by step. Finally, when the preset conditions are met, the corresponding intermediate abnormal report is used as the target abnormal report to characterize the abnormal situation and its propagation corresponding to the target object, providing a data basis for identifying the abnormal level of the target object, thereby improving the accuracy of identifying the abnormal level of the target object.

[0060] S4. According to A and the target abnormal report, the associated abnormal data corresponding to the target abnormal source, the target abnormal data A 0 corresponding to the target object, the associated abnormal data corresponding to several target associated objects between the target abnormal source and the target object, and the target abnormal report are input to the trained classification model to obtain the target abnormal level corresponding to the target object.

[0061] Among them, the pre-trained classification model is used to extract features and map the input data, and output the target abnormal level corresponding to the target object, which is used to characterize the abnormal degree of the target object, providing a reliable basis for subsequent decision-making and processing.

[0062] The classification model can be trained based on the abnormal data and corresponding abnormal levels of each object in the field corresponding to the target object to improve the classification accuracy of the classification model, thereby improving the accuracy of identifying the abnormal level of the target object.

[0063] In a specific embodiment, the trained classification model includes a first classification model and a second classification model. The target abnormal data includes target sequence data and target text data, and the associated abnormal data includes associated sequence data and associated text data. S4 also includes the following steps:

[0064] S41. The associated sequence data corresponding to the target abnormal source, the target sequence data corresponding to the target object, and the associated sequence data corresponding to several target associated objects between the target abnormal source and the target object are input to the first classification model to obtain the first abnormal level corresponding to the target object.

[0065] S42. Input the associated text data corresponding to the target anomaly source, the target text data corresponding to the target object, the associated text data corresponding to several target associated objects between the target anomaly source and the target object, and the target anomaly report into the second classification model to obtain the second anomaly level corresponding to the target object.

[0066] S43. Obtain the target anomaly level corresponding to the target object according to the first anomaly level and the second anomaly level.

[0067] Among them, the target sequence data may include data related to the time series such as the data update time and data creation time corresponding to the target object, and the target text data may include data related to the text such as the object affected by the anomaly, the direct source object of the anomaly, the anomaly type, and the anomaly description.

[0068] The first classification model can focus on analyzing time series related data, and the second classification model can focus on analyzing text related data. For example, the first classification model can refer to the GRU (Gated Recurrent Unit) model, and the second classification model can refer to the XLNet model.

[0069] The architecture design of the GRU model includes an input layer, an embedding layer, a GRU layer, and a fully connected layer. Among them, the input layer receives the associated sequence data corresponding to the target anomaly source, the target sequence data corresponding to the target object, and the associated sequence data corresponding to several target associated objects between the target anomaly source and the target object. The embedding layer maps the input sequence data into a low-dimensional vector representation. The GRU layer extracts the time-dependent relationships and features in the sequence data through its gating mechanism. The fully connected layer maps the output of the GRU layer to the classification result, effectively classifying the anomaly level at the level of time series data.

[0070] The XLNet model is a pre-trained language model based on Transformer, with powerful text understanding and generation capabilities. The architecture of the XLNet model includes an input layer, a Transformer layer, and a fully connected layer. Among them, the input layer receives the associated text data corresponding to the target anomaly source, the target text data corresponding to the target object, the associated text data corresponding to several target associated objects between the target anomaly source and the target object, and the target anomaly report. The Transformer layer extracts the context relationships and features in the input text data. The fully connected layer maps the output of the Transformer layer to the classification result, effectively classifying the anomaly level at the level of text data.

[0071] Therefore, the target sequence data and target text data corresponding to the target object, as well as the associated sequence data and associated text data corresponding to the associated object are obtained respectively, so as to perform feature extraction and mapping on the associated sequence data corresponding to the target anomaly source, the target sequence data corresponding to the target object, and the associated sequence data corresponding to several target associated objects between the target anomaly source and the target object based on the first classification model, and obtain the first anomaly level corresponding to the target object. Based on the second classification model, feature extraction and mapping are performed on the associated text data corresponding to the target anomaly source, the target text data corresponding to the target object, the associated text data corresponding to several target associated objects between the target anomaly source and the target object, and the target anomaly report, and the second anomaly level corresponding to the target object is obtained.

[0072] Further, according to the first anomaly level and the second anomaly level, the target anomaly level corresponding to the target object is obtained, so as to comprehensively consider the analysis results of the anomaly data related to the time series and the anomaly data related to the text, improve the comprehensiveness of the analysis of the anomaly situation of the target object, and further improve the recognition accuracy of the target anomaly level.

[0073] In a specific embodiment, the first anomaly level and the second anomaly level include an explanation level, a general level, an important level, and an emergency level, and in the order of the explanation level, the general level, the important level, and the emergency level, the preset emergency degree corresponding to the anomaly level gradually increases. S43 includes the following steps:

[0074] S431, if the first anomaly level and the second anomaly level are the same, then the first anomaly level is determined as the target anomaly level.

[0075] S432, if the first anomaly level and the second anomaly level are different, then the anomaly level with the highest preset emergency degree among the first anomaly level and the second anomaly level is determined as the target anomaly level.

[0076] As described above, initialize i = 1, and input A 0 、A 1 , ……, A i into the preset large language model, obtain the intermediate anomaly report and the anomaly source recognition result. If the anomaly source recognition result is that the anomaly source is not determined, then update i = i + 1, return to execute the operation steps of the large language model until the preset condition is met, and use the intermediate anomaly report corresponding to when the preset condition is met as the target anomaly report. According to A and the target anomaly report, the associated anomaly data corresponding to the target anomaly source, the target anomaly data A 0The associated abnormal data corresponding to several target associated objects between the target abnormal source and the target object, and the target abnormal report are input into the trained classification model to obtain the target abnormal level corresponding to the target object. It can be seen that when performing data analysis through a preset large language model, the associated abnormal data of the next-level associated object is added to determine whether there is an abnormal source corresponding to the target object in the next-level associated object. By gradually updating the data input in the large language model, a step-by-step traceability analysis of the abnormal source corresponding to the target object is carried out. Finally, when the preset conditions are met, the corresponding intermediate abnormal report is used as the target abnormal report to characterize the abnormal situation corresponding to the target object and its propagation situation. Further, on the basis of the target abnormal report, the classification model extracts features and maps the relevant abnormal data to identify the target abnormal level of the target object, thereby improving the recognition accuracy of the target abnormal level.

[0077] Although some specific embodiments of the present invention have been described in detail by way of examples, those skilled in the art should understand that the above examples are only for illustration and not for limiting the scope of the present invention. Those skilled in the art should also understand that various modifications can be made to the embodiments without departing from the scope and spirit of the present invention. The scope of the present invention disclosed is defined by the appended claims.

Claims

1. An exception level recognition system based on exception traceability, characterized in that, The anomaly level recognition system based on anomaly traceability includes a processor and a memory storing a computer program. The memory also stores a trained classification model and target anomaly data A corresponding to a target object 0 and an associated anomaly data set A={A 1 , A 2 , ……, A i , ……, A M}, where A i ={A i 1, A i 2, ……, A i j(i) , ……, A i N(i)}, A i j(i) refers to the associated anomaly data corresponding to the j(i)-th i-level associated object corresponding to the target object. The associated anomaly data includes the corresponding target anomaly data and the corresponding degree of anomaly. The target object is the target IP. The target anomaly data includes the data update time, data creation time, object affected by the anomaly, direct source object of the anomaly, anomaly type, and anomaly description. The associated object is the associated IP corresponding to the target IP. i = 1, 2, ……, M, where M refers to the number of levels of the associated objects corresponding to the target object, and j(i) = 1, 2, ……, N(i), where N(i) refers to the total number of the i-level associated objects corresponding to the target object. When the computer program is executed by the processor, the following steps are implemented: S1. Initialize i = 1; S2, input A 0 and A 1 , ……, A i into a preset large language model to obtain an intermediate anomaly report and an anomaly source identification result. Among them, the intermediate anomaly report includes an intermediate anomaly source, an intermediate anomaly means, and an intermediate anomaly path, and the anomaly source identification result is a determined anomaly source or an undetermined anomaly source; S3. If the abnormal source recognition result is an undetermined abnormal source, update i = i + 1, return to execute step S2 until a preset condition is met, and use the intermediate abnormal report corresponding to when the preset condition is met as the target abnormal report. Wherein, the target abnormal report includes a target abnormal source, a target abnormal means, and a target abnormal path, and the target abnormal path includes the target abnormal source, the target object, and several target associated objects between the target abnormal source and the target object; S4. According to A and the target exception report, input the associated exception data corresponding to the target exception source, the target exception data A corresponding to the target object 0 , the associated exception data corresponding to several target associated objects between the target exception source and the target object, and the target exception report into the trained classification model, and obtain the target exception level corresponding to the target object. Among them, the trained classification model includes a first classification model and a second classification model. The target exception data includes target sequence data and target text data, and the associated exception data includes associated sequence data and associated text data. S4 further includes the following steps: S41. Input the associated sequence data corresponding to the target abnormal source, the target sequence data corresponding to the target object, and the associated sequence data corresponding to several target associated objects between the target abnormal source and the target object into the first classification model to obtain the first abnormal level corresponding to the target object; S42. Input the associated text data corresponding to the target abnormal source, the target text data corresponding to the target object, the associated text data corresponding to several target associated objects between the target abnormal source and the target object, and the target abnormal report into the second classification model to obtain the second abnormal level corresponding to the target object; S43. Obtain the target abnormal level corresponding to the target object according to the first abnormal level and the second abnormal level.

2. The anomaly level recognition system based on anomaly traceability according to claim 1, wherein The memory also stores several initial objects, and the association relationships between each initial object and other initial objects and the target object. Wherein, the association relationships include direct associations and non-direct associations. The associated objects of the target object are obtained through the following steps: S10. According to the association relationship between each initial object and the target object, determine the initial object directly associated with the target object as the first-level associated object corresponding to the target object; S20. According to the association relationship between each initial object and other initial objects, determine the initial object directly associated with each u-level associated object corresponding to the target object as the (u + 1)-level associated object corresponding to the target object, where u = 1, 2,..., M - 1.

3. The anomaly level recognition system based on anomaly traceability according to claim 1, characterized in that The target abnormal data A corresponding to the target object 0 Obtained through the following steps: S100. Obtain the initial abnormal data corresponding to the target object; S200. Clean the initial abnormal data to obtain the first intermediate abnormal data corresponding to the target object; S300. Perform word vector conversion on the first intermediate abnormal data to obtain the second intermediate abnormal data corresponding to the target object; S400, perform a normalization process on the second intermediate abnormal data to obtain the target abnormal data A corresponding to the target object 0 .

4. The anomaly level recognition system based on anomaly traceability according to claim 1, characterized in that, The memory also stores K historical abnormal levels corresponding to each associated object of the target object. The historical abnormal levels include the description level, the general level, the important level, and the emergency level. The abnormal degree of the associated object is obtained through the following steps: S500. Obtain the first preset emergency degree corresponding to the description level, the second preset emergency degree corresponding to the general level, the third preset emergency degree corresponding to the important level, and the fourth preset emergency degree corresponding to the emergency level; S600. Obtain the average value of the urgency level corresponding to each associated object according to the K historical anomaly levels corresponding to each associated object, the first preset urgency level, the second preset urgency level, the third preset urgency level, and the fourth preset urgency level. S700. Determine the average value of the urgency level corresponding to each associated object as the anomaly level corresponding to each associated object.

5. The anomaly level recognition system based on anomaly traceability according to claim 1, characterized in that The satisfaction of the preset condition means that the anomaly source recognition result is a determined anomaly source.

6. The anomaly level recognition system based on anomaly traceability according to claim 5, wherein When the anomaly source recognition result is a determined anomaly source, the target anomaly source refers to the associated object with the highest anomaly level among the i-th level associated objects corresponding to the target object.

7. The anomaly level recognition system based on anomaly traceability according to claim 1, characterized in that Said meeting the preset conditions means taking A 0 , A 1 , ……, A M After inputting into a preset large language model, the obtained abnormal source recognition result is that the abnormal source is undetermined.

8. The anomaly level recognition system based on anomaly traceability according to claim 7, wherein If A is input 0 , A 1 , ……, A M to a preset large language model and the obtained abnormal source recognition result is an undetermined abnormal source, then the target abnormal source refers to the associated object with the highest degree of abnormality among the M-level associated objects corresponding to the target object.

9. The anomaly level recognition system based on anomaly traceability according to claim 1, characterized in that The first anomaly level and the second anomaly level include the explanatory level, the general level, the important level, and the urgent level, and in the order of the explanatory level, the general level, the important level, and the urgent level, the preset urgency level corresponding to the anomaly level gradually increases. S43 includes the following steps: S431. If the first anomaly level and the second anomaly level are the same, determine the first anomaly level as the target anomaly level. S432. If the first anomaly level and the second anomaly level are different, determine the anomaly level with the highest preset urgency level among the first anomaly level and the second anomaly level as the target anomaly level.

Citation Information

Patent Citations

  • Sentiment classification method and device, equipment, storage medium and program product

    CN117216266A

  • Abnormal degree identification method and device based on large language model, medium and equipment

    CN118673445A