Large model training method in network security field based on generative large model
Through the big model training method in the field of network security based on generative large models, the problems of difficulty in obtaining and labeling of data in the field of power network security, insufficient generalization capabilities of model and poor adaptability to application scenarios are solved, and efficient and intelligent network security protection and management are achieved.
Patent Information
- Application Number
- CN202411742847.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-29
- Publication Date
- 2025-05-02
- Estimated Expiration
- 2044-11-29
AI Technical Summary
In the field of power network security, the existing technology faces the problems of data acquisition and labeling, insufficient generalization capabilities of model and poor adaptability to application scenarios, resulting in the effective application of generative large models in the field of network security.
A large-model training method in the field of network security based on generative large-scale models is proposed. By acquiring network security data of the power system for preprocessing, the general-purpose large-scale model is improved to adapt to the characteristics of power network security, and the intelligent analysis of network security data and the coordinated treatment of offense and defense confrontation are realized through fine-tuning model and intelligent correlation analysis.
It improves the efficiency and accuracy of network security protection, makes network security management more intelligent and automated, enhances the generalization ability of the model and the adaptability of application scenarios, can more accurately tap potential threats and attack modes, and realizes intelligent linkage and coordinated defense between devices.
Smart Images

Figure CN119917851A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of electric power network security, and in particular to a large model training method in the field of network security based on a generative large model. Background Art
[0002] With the rapid development of information technology and the Internet, digital transformation has become an inevitable trend in the development of the power industry. In this context, network security issues have become increasingly prominent and have become a key factor restricting the stable operation of digital power grids. Especially in the process of smart grid construction, the deep integration of key infrastructure such as industrial control systems and distribution automation systems with the Internet has led to the continuous expansion of the threat of network attacks, and the means of attack have also become intelligent and concealed. Traditional network security protection methods based on rule matching and feature recognition have become difficult to cope with increasingly complex and changeable network threats. In this case, artificial intelligence technology, especially the emergence of generative big models, has provided new solutions for network security protection. With its powerful knowledge representation and reasoning capabilities, generative big models can better understand the patterns and characteristics of network attacks and provide more intelligent security protection solutions. Therefore, developing a big model training method in the field of network security based on generative big models to improve the intelligence level of network security has become a technical problem that needs to be solved urgently.
[0003] Although there have been some application attempts based on generative big models in the existing technology, there are still many challenges in the field of network security, especially in power network security; the primary problem is the difficulty of data acquisition and labeling. Since network attack data is scarce and time-sensitive, and requires accurate labeling by professionals, the cost of obtaining high-quality training data is high; secondly, the generalization ability of existing models is insufficient, and it is difficult to cope with unknown types of network attacks, especially targeted attacks on power systems; in addition, the network environment and business scenarios of different power companies vary greatly, resulting in poor adaptability of the model's application scenarios and difficulty in rapid deployment and migration. These problems seriously restrict the effective application of generative big models in the field of network security. Summary of the invention
[0004] In view of the above-mentioned problems, the present invention is proposed.
[0005] Therefore, the problem to be solved by the present invention is how to provide a large model training method in the field of network security based on a generative large model, aiming to improve the current network security field, especially the power network security, which seriously restricts the effective application of generative large models in the field of network security, such as difficulties in data acquisition and labeling, insufficient model generalization ability and poor adaptability to application scenarios.
[0006] In order to solve the above technical problems, the present invention provides the following technical solutions:
[0007] In the first aspect, an embodiment of the present invention provides a large model training method in the field of network security based on a generative large model, which includes obtaining network security data of the power system and preprocessing it to obtain a training data set; using a general large model as a basic model, and improving and pre-training the basic model according to the security characteristics of the power network to obtain a pre-trained model; using the training data set to fine-tune the pre-trained model to obtain a fine-tuned model; performing intelligent correlation analysis on the network security data based on the fine-tuned model to obtain an analysis result; designing an intelligent plug-in mechanism based on the analysis result, connecting the intelligent plug-in mechanism with the network security equipment, and performing coordinated attack and defense confrontation.
[0008] As a preferred solution of the large model training method in the field of network security based on the generative large model described in the present invention, the preprocessing includes cleaning, classification, labeling, privacy correction of data and compliance checking.
[0009] As a preferred solution of the large model training method in the field of network security based on the generative large model described in the present invention, the basic model is improved and pre-trained according to the characteristics of power network security, including the following steps: selecting a general large model as the basic model; customizing and improving the basic model according to the characteristics of power network security to obtain a customized improved model; using a large-scale data set to pre-train the customized improved model to obtain a pre-trained model; using LORA instruction fine-tuning technology, while keeping the parameters of the pre-trained model unchanged, by adding trainable parameters to adapt to specific tasks in the field of power network security.
[0010] As a preferred solution of the large model training method in the field of network security based on the generative large model described in the present invention, the method of obtaining the fine-tuning model includes the following steps: using the training data set to fine-tune the pre-trained model, adjusting the model parameters, and obtaining the fine-tuning model; according to the characteristics and requirements of the network security task, using prompt optimization technology, designing prompts to guide the fine-tuning model to perform reasoning and judgment; using the designed prompts to train the fine-tuning model, and adjusting the structure and content of the prompts according to the training results.
[0011] As a preferred solution of the large model training method in the field of network security based on the generative large model described in the present invention, the intelligent correlation analysis includes the following steps: constructing a large model base for power network security analysis based on the fine-tuning model; acquiring general knowledge, network security knowledge and power network security attack and defense confrontation data and integrating them with the large model base for power network security analysis to obtain a fused large model base for power network security analysis; using the fused large model base for power network security analysis to perform intelligent correlation analysis on network security data to obtain analysis results.
[0012] As a preferred solution of the large model training method in the field of network security based on the generative large model described in the present invention, wherein: the analysis results include potential threats and attack patterns.
[0013] As a preferred solution of the large model training method in the field of network security based on the generative large model described in the present invention, the collaborative handling of attack and defense includes the following steps: designing an intelligent plug-in mechanism based on the analysis results to achieve seamless connection with the network security device, and establishing an intelligent linkage mechanism between network security devices to achieve collaborative defense; designing an attack and defense analysis framework based on the generative large model to achieve intelligent linkage and collaborative defense between devices; introducing a collaborative defense mechanism to link multiple network security devices or systems, and when a potential attack is detected, automatically generating a corresponding defense strategy, and distributing the defense strategy to related devices for execution; building an attack and defense knowledge base to accumulate and share experience and knowledge in the attack and defense process.
[0014] On the second aspect, in order to further solve the security problems existing in the power network security, the embodiment of the present invention provides a large model training system in the field of network security based on a generative large model, which includes: a data acquisition module, which is used to acquire the network security data of the power system and pre-process it to obtain a training data set; a model training module, which is used to use the general large model as the basic model, and customize and improve the basic model according to the characteristics of power network security and pre-train it to obtain a pre-trained model; a model fine-tuning module, which is used to fine-tune the pre-trained model using the training data set to obtain a fine-tuned model; an intelligent analysis module, which is used to perform intelligent correlation analysis on the network security data based on the fine-tuning model, and to mine potential threats and attack patterns; an attack and defense confrontation module, which is used to design an intelligent plug-in mechanism based on the analysis results, connect the intelligent plug-in mechanism with the network security equipment, and perform coordinated attack and defense confrontation.
[0015] In a third aspect, an embodiment of the present invention provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: when the computer program is executed by the processor, it implements any step of the large model training method in the field of network security based on the generative large model as described in the first aspect of the present invention.
[0016] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein: when the computer program is executed by a processor, it implements any step of the method for training a big model in the field of network security based on a generative big model as described in the first aspect of the present invention.
[0017] Beneficial effects of the invention: The invention proposes a large model training method in the field of network security based on a generative large model. By introducing a generative large model, the invention realizes intelligent analysis and decision support for network security data, which not only improves the efficiency and accuracy of network security protection, but also makes network security management more intelligent and automated. Traditional manual analysis methods are often time-consuming and labor-intensive and it is difficult to fully cover all potential threats. Generative large models can quickly process and analyze massive data to timely discover and respond to network security risks; through data collection and preprocessing, model base selection and pre-training, and fine-tuning and optimization steps, the professionalism and practicality of the model in the field of network security are significantly improved, especially for power The model is customized and improved based on the characteristics of network security, so that it can better adapt to the particularity of the power network environment, and improve the generalization ability of the model and the adaptability of application scenarios; by designing intelligent correlation analysis and attack and defense collaborative disposal steps, the coordination and integrity of network security protection are further enhanced, and by building a large model base for power network security analysis, integrating general knowledge, network security knowledge and power network security attack and defense confrontation data, the automatic identification and association of scattered network security data is realized, so that potential threats and attack patterns can be more accurately excavated; at the same time, an attack and defense confrontation analysis framework based on a generative large model is designed to realize intelligent linkage and collaborative defense between devices, and improve the ability to respond to complex threats. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work. Among them:
[0019] Figure 1 This is an overall flow chart of the big model training method in the field of network security based on the generative big model in Example 1.
[0020] Figure 2 This is a schematic diagram of the structure of the computer device in Example 3. DETAILED DESCRIPTION
[0021] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are described in detail below in conjunction with the accompanying drawings.
[0022] In the following description, many specific details are set forth to facilitate a full understanding of the present invention, but the present invention may also be implemented in other ways different from those described herein, and those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.
[0023] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The term "in one embodiment" that appears in different places in this specification does not necessarily refer to the same embodiment, nor does it refer to a separate or selective embodiment that is mutually exclusive with other embodiments.
[0024] Example 1
[0025] Reference Figure 1 , which is the first embodiment of the present invention, and this embodiment provides a large model training method in the field of network security based on a generative large model.
[0026] The existing large-model training methods in the field of network security have the following main problems: the first problem is the difficulty of data acquisition and labeling. Since network attack data is scarce and time-sensitive, and requires accurate labeling by professionals, the cost of obtaining high-quality training data is high; secondly, the generalization ability of existing models is insufficient, and it is difficult to cope with unknown types of network attacks, especially targeted attacks on power systems; in addition, the network environment and business scenarios of different power companies vary greatly, resulting in poor adaptability of the model to application scenarios and difficulty in rapid deployment and migration. These problems seriously restrict the effective application of generative large models in the field of network security.
[0027] The present application provides an effective solution to the above-mentioned problems. Next, multiple embodiments will be combined to explain in detail how to implement the large model training method in the field of network security based on the generative large model.
[0028] Figure 1 The overall flow chart of the large model training method in the field of network security based on the generative large model is shown, including:
[0029] S1: Obtain and preprocess the network security data of the power system to obtain a training data set.
[0030] Preferably, the network security data includes log data, flow data and event record data.
[0031] Specifically, the specific formula for the data set of network security data is as follows:
[0032] D={d1,d2,...,dn}
[0033] Wherein, D is a data set of network security data; dn is the nth piece of network security data.
[0034] Preferably, preprocessing includes cleaning, classification, labeling, privacy correction of data, and compliance checking to ensure the legitimacy and security of the data.
[0035] Specifically, cleaning refers to removing invalid or erroneous data to ensure the accuracy and completeness of the data. The specific formula for the cleaned data set is as follows:
[0036] D'=filter(D)
[0037] Among them, D′ is the cleaned data set.
[0038] Specifically, classification refers to classifying data by type or severity, including attack type and impact level. The specific formula is as follows:
[0039] Dc=classify(D')
[0040] Among them, Dc is the classified data set.
[0041] Specifically, labeling refers to adding labels to network security data to facilitate subsequent model training and analysis. The specific formula is as follows:
[0042] Dl=label(Dc)
[0043] Among them, D1 is the labeled dataset.
[0044] It should be noted that in order to enhance the diversity of data collection and preprocessing, in the data collection stage, in addition to collecting data from within the power system, it is also possible to consider obtaining data from external network security databases or public security incident reporting channels to increase the diversity and comprehensiveness of the data; or generate data through simulated attack experiments. These data can simulate various attack scenarios and attack methods, providing more actual samples for model training; in the data cleaning stage, more advanced data cleaning technologies can be introduced, such as anomaly detection algorithms based on machine learning, which can more accurately identify and remove invalid or erroneous data; in the data labeling stage, semi-automatic or automated labeling tools can be used, combined with manual review, to improve labeling efficiency and accuracy.
[0045] Furthermore, privacy review and compliance checks on data include ensuring that data collection complies with relevant laws and regulations and protects user privacy, ensuring the legality and security of data, and avoiding legal disputes or privacy leaks during model training and use. The following steps are included: Identify potential privacy risks and loopholes that may exist in data processing practices, including a comprehensive review of data collection, storage, use, transmission, and disclosure.
[0046] Conduct compliance assessments of data processing practices in accordance with applicable privacy regulations and standards (e.g., GDPR, CCPA), including checking whether data processing complies with regulatory requirements and whether appropriate security measures are in place to protect personal data.
[0047] Based on the assessment results, improvement measures and recommendations are proposed to improve the compliance and security of data processing and protection practices, including strengthening data encryption, restricting data access rights, improving data backup and recovery strategies, etc.
[0048] Preferably, the present invention ensures the high quality of input data and improves the effectiveness of training data sets by utilizing cleaning, classification and labeling techniques, thereby solving the problem of complex and changeable network security data; at the same time, compliance checking and privacy correction technologies ensure the legitimacy of data, avoid data leakage during the use of the model, and improve the reliability and legal compliance of the model.
[0049] S2: The general large model is used as the basic model, and the basic model is improved and pre-trained according to the security characteristics of the power network to obtain a pre-trained model.
[0050] Preferably, improving and pre-training the basic model according to the security characteristics of the power network includes the following steps: selecting a general large model as the basic model, wherein the general large model includes BERT and GPT.
[0051] According to the characteristics of power network security, the basic model is customized and improved, including adjusting the model structure and adding vocabulary in specific fields, to obtain a customized and improved model. The specific formula is as follows:
[0052] M'=customize(M)
[0053] Among them, M′ is the customized improved model; M is the general large model.
[0054] Use a large-scale data set to pre-train the customized improved model to obtain a pre-trained model that has basic language understanding and analysis capabilities. The specific formula is as follows:
[0055] Mp=pretrain(M')
[0056] Among them, Mp is the pre-training model.
[0057] By adopting LORA instruction fine-tuning technology, while keeping the parameters of the pre-trained model unchanged, the trainable parameters are added to adapt to specific tasks in the field of power network security.
[0058] Preferably, by adopting LORA instruction fine-tuning technology, it is possible to adapt to specific tasks in the field of power network security by adding a small number of trainable parameters while keeping the original model parameters unchanged. LORA instruction fine-tuning technology can reduce the time and resource consumption of model training while maintaining the stability and performance of the original model.
[0059] Specifically, the LORA instruction fine-tuning technology includes the following steps: select a task-related pre-trained model as a starting point. This model is trained on a large dataset and has strong representation ability and generalization performance.
[0060] During fine-tuning, most of the weights of the pre-trained model are frozen and only a small part of the trainable layers (such as the rank-factorization matrix) are updated, reducing the number of parameters that need to be trained and reducing computing resources and time costs.
[0061] Trainable layers are injected into each Transformer block to learn relevant knowledge for specific tasks. By training these layers, the pre-trained model can be fine-tuned to better adapt to new data sets and tasks.
[0062] Use the new dataset to train the model and evaluate its performance. Based on the evaluation results, adjust the training parameters and the structure of the trainable layers to further improve the performance of the model.
[0063] It should be noted that in order to achieve diversified selection of model bases, in addition to the BERT and GPT general large models, you can also consider choosing special large models that are more suitable for the field of network security as the base, such as special models for security text analysis. Different large model bases can be selected for different security needs to achieve more refined security analysis and prediction; in terms of pre-training, you can introduce self-supervised learning or contrastive learning pre-training strategies to enable the model to learn useful feature representations on unlabeled data and improve the generalization ability of the model. At the same time, combined with specific tasks in the field of network security, design customized pre-training tasks, including security text classification and security event prediction, to enhance the model's adaptability to the field of network security.
[0064] S3: Use the training dataset to fine-tune the pre-trained model to obtain a fine-tuned model.
[0065] Preferably, obtaining the fine-tuning model includes the following steps: fine-tuning the pre-trained model using the training data set, adjusting the model parameters, obtaining the fine-tuning model, and improving the professionalism and practicality of the model in the field of network security, such as improving the ability to recognize specific attack types or improving analysis accuracy.
[0066] According to the characteristics and requirements of network security tasks, prompt optimization technology is used to design appropriate prompts to guide the fine-tuning model to perform reasoning and judgment.
[0067] The fine-tuning model is trained using the designed prompts, and the structure and content of the prompts are adjusted according to the training results to improve the model's ability to understand network security data and the accuracy of its analysis.
[0068] Specifically, the specific formula of the fine-tuning model is as follows:
[0069] Mf=finetune(Mp,Dl)
[0070] Among them, Mf is the fine-tuning model; Mp is the pre-training model; Dl is the labeled dataset.
[0071] Furthermore, before fine-tuning the pre-trained model using the training dataset, differentiated fine-tuning strategies can be designed according to different network security application scenarios.
[0072] Specifically, the differentiated fine-tuning strategies include malware detection task strategy and network attack prediction task strategy.
[0073] Specifically, the malware detection task strategy refers to the malware detection task, by increasing the training data containing malicious code samples and adjusting the weights and parameters of the model to make it more sensitive to the training data containing malicious code samples, and then focusing on optimizing the model's learning ability for malicious code features, so that it can more accurately identify the features of malicious code, such as specific code patterns and behavior patterns.
[0074] Specifically, the network attack prediction task strategy refers to the network attack prediction task, which introduces historical attack data and constructs a time series model or pattern recognition model to enable the model to predict future attack behaviors, thereby enhancing the model's ability to recognize attack patterns and trends, and being able to identify the patterns and trends of network attacks.
[0075] Furthermore, prompt optimization technology is used to improve the model's ability to understand and analyze network security data. The prompt optimization technology guides the model to better understand and analyze network security data by designing appropriate prompts, which can improve the model's ability to understand and analyze network security data and the accuracy of analysis, thereby improving the practicality and reliability of the model. The following steps are included: According to the characteristics and requirements of network security tasks, appropriate prompts are designed to guide the model to reason and judge. The prompts include problem descriptions, contextual information, and examples, which help the model better understand task objectives and data characteristics.
[0076] Use Prompt to train the model and adjust the structure and content of Prompt based on the training results. By continuously optimizing Prompt, the model's ability to identify and analyze network security data can be improved.
[0077] The optimized model is applied to actual network security tasks and its performance is evaluated. Based on the evaluation results, Prompt and model parameters are further adjusted to achieve better performance.
[0078] It should be noted that in order to improve the training efficiency and performance of the model, transfer learning methods can also be introduced to use the knowledge learned in other fields to assist in model fine-tuning in the field of network security, thereby accelerating learning on new tasks; secondly, in terms of the application of optimization technology, in addition to the prompt optimization technology, you can also consider introducing hyperparameter tuning, model pruning, and knowledge distillation optimization technology to further improve the performance and efficiency of the model. Hyperparameter tuning tunes the hyperparameters of the model, such as learning rate and batch size, to find the optimal model configuration; model pruning reduces the complexity and computational complexity of the model by removing redundant parameters or neurons in the model while maintaining the performance of the model; knowledge distillation compresses the knowledge of the large model into the small model while maintaining the performance of the model, which can be achieved by training the small model to imitate the output of the large model.
[0079] Preferably, by introducing prompt optimization technology, the model can be guided to more accurately identify and analyze data in task-specific scenarios, improve its recognition accuracy of attack patterns, optimize the adaptability of the model, reduce the training cycle, and improve security in practical applications through targeted fine-tuning.
[0080] S4: Perform intelligent correlation analysis on network security data based on the fine-tuning model to obtain analysis results.
[0081] Preferably, the intelligent correlation analysis includes the following steps: constructing a large model base for power network security analysis based on the fine-tuning model.
[0082] General knowledge, network security knowledge and power network security attack and defense confrontation data are acquired and integrated with the power network security analysis large model base to obtain the integrated power network security analysis large model base.
[0083] The integrated power network security analysis large model base is used to perform intelligent correlation analysis on network security data, obtain analysis results, and realize automatic identification and correlation of dispersed network security data.
[0084] Specifically, the analysis results include potential threats and attack modes. The specific formula is as follows:
[0085] R = analyze(Mf,D_large)
[0086] Among them, R is the analysis result; Mf is the fine-tuning model; D_large is the massive network security data.
[0087] It should be noted that in order to deepen and improve intelligent correlation analysis, we can build more complex correlation analysis models, such as models based on graph neural networks, to better capture the correlation between network security data; in addition, we can also introduce real-time correlation analysis technology to achieve real-time monitoring and rapid response to network security data.
[0088] Furthermore, by constructing a large model base for power network security analysis, integrating general knowledge, network security knowledge and power network security attack and defense confrontation data, the automatic identification and association of scattered network security data can be achieved, including the following steps: collecting data related to power network security, including network traffic data, log data and vulnerability information, and integrating and cleaning these data to eliminate redundant and erroneous information.
[0089] The integration of general knowledge, cybersecurity knowledge, and power network security attack and defense confrontation data into the large model base can be achieved through knowledge graphs or ontology technology, which helps the model better understand the concepts and relationships in the field of cybersecurity.
[0090] Use the integrated data to train the model, and adjust the model structure and parameters based on the training results. By continuously optimizing the model, its ability to identify and analyze power network security data is improved.
[0091] Apply the trained model to actual power network security tasks and verify its performance. Based on the verification results, further adjust the model and optimize the algorithm to achieve better performance.
[0092] It should be noted that there are no specific formulas or data format requirements in this process. The key lies in how to effectively integrate and utilize various data sources and knowledge resources to build a large model base, and improve the performance of the model through training and optimization. The integration of multiple knowledge can enhance the model's analytical capabilities and accuracy for complex network security issues, and provide security teams with more comprehensive and in-depth threat intelligence.
[0093] Preferably, by using the fused large-scale power network security analysis model base to perform intelligent correlation analysis of multi-source data, it is possible to identify potential threats and attack patterns in real time, capture complex attack patterns and potential security threats, and automatically associate different security data. This fusion of deep learning and knowledge graphs can effectively improve the ability to predict attack behaviors and provide stronger data support for decision-making.
[0094] S5: Design an intelligent plug-in mechanism based on the analysis results, connect the intelligent plug-in mechanism with network security equipment, and conduct coordinated attack and defense.
[0095] Preferably, the coordinated attack and defense confrontation includes the following steps: designing an intelligent plug-in mechanism based on the analysis results to achieve seamless connection with network security devices, and establishing an intelligent linkage mechanism between network security devices to achieve coordinated defense. The specific formula of the coordinated defense strategy is as follows:
[0096] S=defense_strategy(Mf,Devices)
[0097] Among them, S is the collaborative defense strategy; Devices is the existing network security devices.
[0098] An attack and defense analysis framework based on a generative large model is designed to achieve intelligent linkage and collaborative defense between devices and improve the ability to respond to complex threats. The attack scenarios are constructed through sequence generation technology, and adversarial training technology is used to optimize attack identification.
[0099] A collaborative defense mechanism is introduced to link multiple network security devices or systems. When a potential attack is detected, the corresponding defense strategy is automatically generated and distributed to related devices for execution, achieving more efficient defense and response.
[0100] Build an attack and defense knowledge base to accumulate and share the experience and knowledge in the attack and defense process to improve the overall security level.
[0101] Specifically, the specific formula for coordinated handling of attack and defense confrontation is as follows:
[0102] T=attack_defense(Mf,Threats)
[0103] Among them, T is the result of intelligent attack and defense confrontation; Threats is the detected network threat.
[0104] Furthermore, an attack-defense confrontation analysis framework based on the generative big model is designed to realize intelligent linkage and collaborative defense among devices, including the following steps: Clarifying the specific scenarios and goals of the attack-defense confrontation, including the types of attacks and defense strategies, helps to determine the design requirements and functional requirements of the framework.
[0105] Use attack and defense adversarial data to train a generative large model so that it can generate various possible attack and defense strategies, which can be achieved through sequence generation or adversarial training techniques.
[0106] Integrate the generative big model into the communication and coordination mechanism between devices to realize intelligent linkage and collaborative defense between devices. When a potential attack is detected, the framework can automatically generate corresponding defense strategies and distribute them to relevant devices for execution.
[0107] According to the actual results and feedback data of the attack and defense confrontation, the generative large model and collaborative defense mechanism are continuously optimized through online learning or reinforcement learning technology to improve the adaptability and robustness of the framework.
[0108] It should be noted that the design and implementation of the attack and defense confrontation analysis framework based on generative big models needs to comprehensively consider the complexity of attack and defense confrontation, the communication and coordination mechanism between devices, and the performance and scalability factors of the generative big models. Through continuous optimization and improvement, a more efficient, intelligent and reliable attack and defense confrontation collaborative disposal solution can be achieved; the attack and defense confrontation analysis framework based on generative big models can enhance the overall defense level of network security, achieve rapid response and effective response to complex threats, and at the same time, this framework can also promote the collaborative work between different security devices and improve the overall security effectiveness.
[0109] It should be noted that, for the overall system architecture and implementation of the present invention, in terms of system architecture design, by designing a system architecture based on a microservice architecture, the data collection, model training, intelligent correlation analysis, and attack and defense collaborative disposal modules are decoupled and independently deployed to improve the scalability and flexibility of the system; a technology stack suitable for big data processing and machine learning is selected, such as Hadoop, Spark, TensorFlow, or PyTorch, to achieve efficient data processing and model training; cloud native technologies, such as cloud computing, cloud storage, and cloud monitoring, are introduced to improve the availability and reliability of the system; the introduction of containerization technologies, such as Docker and Kubernetes, is crucial to achieving rapid deployment and automated management of the system.
[0110] Furthermore, Docker is used to create, deploy, and manage containerized applications, packaging applications and their dependencies into an independent container to achieve rapid deployment and consistent operation; Kubernetes, as an open source container orchestration system, is used to automate the deployment, expansion, and management of containers, and manage the life cycle of containerized applications, including deployment, monitoring, expansion, and fault recovery; Hadoop is used to provide a reliable and economical solution for massive data storage, and implements parallel data processing and fault tolerance mechanisms through its distributed file system HDFS and MapReduce programming model; Spark is used to become a popular open-source computing platform with its speed, ease of use, and in-memory computing advantages. It is an ideal choice for processing complex data streams and real-time analysis, providing a highly abstract data processing interface to make data processing logic more concise and efficient. As deep learning frameworks, TensorFlow and PyTorch support efficient model training and reasoning, and are the basis for implementing machine learning algorithms. Cloud computing is used to provide on-demand computing resources and services, including virtual machines, containers, databases, etc., supporting elastic expansion and pay-as-you-go. Cloud storage is used to provide high-availability and scalable data storage services, supporting data backup, recovery, and cross-regional replication. Cloud monitoring is used to provide real-time monitoring and alarm functions for system performance and operating status, helping to promptly discover and handle potential problems.
[0111] In summary, the present invention proposes a large model training method in the field of network security based on a generative large model. By introducing a generative large model, intelligent analysis and decision support for network security data are realized, which not only improves the efficiency and accuracy of network security protection, but also makes network security management more intelligent and automated. Traditional manual analysis methods are often time-consuming and labor-intensive and it is difficult to fully cover all potential threats. The generative large model can quickly process and analyze massive data to timely discover and respond to network security risks; through data collection and preprocessing, model base selection and pre-training, and fine-tuning and optimization steps, the professionalism and practicality of the model in the field of network security are significantly improved, especially for power network security. The model is customized and improved based on its full features, so that it can better adapt to the particularity of the power network environment, and improve the generalization ability of the model and the adaptability of application scenarios; by designing intelligent correlation analysis and attack and defense collaborative disposal steps, the coordination and integrity of network security protection are further enhanced, and by building a large model base for power network security analysis, integrating general knowledge, network security knowledge and power network security attack and defense confrontation data, it realizes the automatic identification and association of scattered network security data, so as to more accurately mine potential threats and attack patterns; at the same time, the attack and defense confrontation analysis framework based on the generative large model is designed to realize intelligent linkage and collaborative defense between devices, and improve the ability to respond to complex threats.
[0112] Embodiment 2 is an embodiment of the present invention, which provides a large model training system in the field of network security based on a generative large model, including: a data acquisition module, used to acquire the network security data of the power system and pre-process it to obtain a training data set; a model training module, used to use the general large model as the basic model, and customize and improve the basic model according to the security characteristics of the power network, and pre-train it to obtain a pre-trained model; a model fine-tuning module, used to fine-tune the pre-trained model using the training data set to obtain a fine-tuned model; an intelligent analysis module, used to perform intelligent correlation analysis on the network security data based on the fine-tuning model, and to mine potential threats and attack patterns; an attack and defense confrontation module, used to design an intelligent plug-in mechanism based on the analysis results, connect the intelligent plug-in mechanism with the network security equipment, and perform coordinated attack and defense confrontation.
[0113] Embodiment 3 is an embodiment of the present invention, which is different from the previous embodiment in that:
[0114] like Figure 2 As shown, if the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk and other media that can store program codes.
[0115] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by an instruction execution system, device or apparatus (such as a computer-based system, a system including a processor, or other system that can fetch instructions from an instruction execution system, device or apparatus and execute instructions), or in conjunction with such instruction execution systems, devices or apparatuses. For the purposes of this specification, "computer-readable medium" can be any device that can contain, store, communicate, propagate or transmit a program for use by an instruction execution system, device or apparatus, or in conjunction with such instruction execution systems, devices or apparatuses.
[0116] More specific examples of computer-readable media (a non-exhaustive list) include the following: an electrical connection with one or more wires (electronic device), a portable computer disk case (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disk read-only memory (CDROM). In addition, the computer-readable medium may even be a paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, deciphering or, if necessary, processing in another suitable manner, and then stored in a computer memory.
[0117] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware or a combination thereof. In the above-mentioned embodiments, a plurality of steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, it can be implemented by any one of the following technologies known in the art or their combination: a discrete logic circuit having a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.
[0118] Example 4 is an embodiment of the present invention, which provides a large model training method in the field of network security based on a generative large model. In order to verify the beneficial effects of the present invention, scientific demonstration is carried out through simulation experiments.
[0119] In this example, by designing a system architecture based on a microservice architecture, data collection, model training, intelligent correlation analysis, and attack and defense collaborative processing modules are decoupled and independently deployed to improve the scalability and flexibility of the system. In selecting a technology stack suitable for big data processing and machine learning, the speed of Hadoop technology and Spark technology in processing tasks is compared to select a technology stack that is more suitable for the present invention. The specific data is shown in Table 1.
[0120] Table 1 Data processing performance comparison table
[0121] Dataset size Processing tasks Spark (seconds) Hadoop (seconds) 1GB Sorting 10 30 10GB polymerization 30 120 100GB filter 120 480
[0122] By introducing cloud native technologies, such as cloud computing, cloud storage or cloud monitoring, the availability and reliability of the system can be improved. Table 2 and Table 3 show the performance data tables of cloud storage and cloud monitoring.
[0123] Table 2 Performance data of cloud storage
[0124] Storage Services Read and write speed (MB / s) Delay (ms) Availability (%) AWSS3 200 10 99.99
[0125] Table 3 Performance data of cloud monitoring
[0126] Monitoring indicators Threshold setting Number of alarms CPU usage >80% 2 times Memory usage >90% 1 time Network bandwidth >1Gbps 3 times
[0127] In the data collection and preprocessing steps, in order to ensure the legality and security of the data, the network security data is also subjected to privacy correction and compliance checks. Table 4 shows the privacy correction and compliance check result table.
[0128] Table 4 Privacy revision and compliance check results
[0129] Data Types Privacy risk level Compliance Check Results User Personal Information high pass Transaction History middle pass System log Low pass
[0130] When fine-tuning the pre-trained model using the training data set to obtain the fine-tuned model, the prompt optimization technology is used to design appropriate prompts to guide the model to better understand and analyze network security data, improve the model's ability to understand network security data and the accuracy of analysis, thereby improving the practicality and reliability of the model. Table 5 shows the prompt optimization experiment results.
[0131] Table 5 Prompt optimization experiment results
[0132] Prompt Design Accuracy improvement (%) Basic Prompt 0 Optimize Prompt1 +5 Optimize Prompt2 +8
[0133] Finally, by using the fine-tuning model to perform intelligent correlation analysis on network security data, the analysis results are obtained. Based on the analysis results, an intelligent plug-in mechanism is designed, and the intelligent plug-in mechanism is connected to the network security equipment to perform attack and defense collaborative processing. Table 6 shows the attack and defense collaborative processing experiment results.
[0134] Table 6 Results of attack-defense collaborative processing experiment
[0135] Attack Types Defensive Strategy Success rate (%) SQL Injection Input Validation 100 DDoS attacks Traffic cleaning 98 Malware Behavioral analysis 95
[0136] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.
Claims
1. A large model training method in the field of network security based on a generative large model, characterized by: include: Acquire and preprocess the network security data of the power system to obtain a training data set; The general large model is used as a basic model, and the basic model is improved and pre-trained according to the security characteristics of the power network to obtain a pre-trained model; Fine-tuning the pre-trained model using the training data set to obtain a fine-tuned model; Perform intelligent correlation analysis on network security data based on the fine-tuning model to obtain analysis results; Based on the analysis results, an intelligent plug-in mechanism is designed, and the intelligent plug-in mechanism is connected to the network security equipment to carry out coordinated attack and defense confrontation.
2. The network security field large model training method based on the generative large model as claimed in claim 1, characterized in that: The preprocessing includes cleaning, classification, labeling, privacy correction of data and compliance checking.
3. The network security field large model training method based on the generative large model as claimed in claim 2, characterized in that: Improving and pre-training the basic model according to the characteristics of power network security includes the following steps: Select the general large model as the base model; Customizing and improving the basic model according to the security characteristics of the power network to obtain a customized and improved model; Use a large-scale data set to pre-train the customized improved model to obtain a pre-trained model; By adopting LORA instruction fine-tuning technology, while keeping the parameters of the pre-trained model unchanged, the trainable parameters are added to adapt to specific tasks in the field of power network security.
4. The network security field large model training method based on the generative large model as claimed in claim 3, characterized in that: The obtaining of the fine-tuning model comprises the following steps: Fine-tune the pre-trained model using the training data set, adjust model parameters, and obtain a fine-tuned model; According to the characteristics and requirements of network security tasks, prompt optimization technology is used to design prompts to guide the fine-tuning model to perform reasoning and judgment; The fine-tuning model is trained using the designed prompt, and the structure and content of the prompt are adjusted according to the training results.
5. The network security field large model training method based on the generative large model as claimed in claim 4, characterized in that: The intelligent association analysis comprises the following steps: Building a large model base for power network security analysis based on the fine-tuning model; Acquire general knowledge, network security knowledge and power network security attack and defense confrontation data and integrate them with the power network security analysis large model base to obtain the integrated power network security analysis large model base; The fused large-scale model base for power network security analysis is used to conduct intelligent correlation analysis on network security data to obtain analysis results.
6. The network security field large model training method based on the generative large model as claimed in claim 5, characterized in that: The analysis results include potential threats and attack patterns.
7. The network security field large model training method based on the generative large model as claimed in claim 6, characterized in that: The attack and defense confrontation collaborative processing comprises the following steps: Based on the analysis results, an intelligent plug-in mechanism is designed to achieve seamless connection with network security devices, and an intelligent linkage mechanism is established between network security devices to achieve collaborative defense; Design an attack and defense analysis framework based on a generative large model to achieve intelligent linkage and collaborative defense between devices; Introduce a collaborative defense mechanism to link multiple network security devices or systems. When a potential attack is detected, the corresponding defense strategy is automatically generated and distributed to related devices for execution. Build an attack and defense knowledge base to accumulate and share the experience and knowledge in the attack and defense process.
8. A network security field large model training system based on a generative large model, based on the network security field large model training method based on a generative large model according to any one of claims 1 to 7, characterized in that: include, A data acquisition module, used to acquire and pre-process the network security data of the power system to obtain a training data set; The model training module is used to use the general large model as the basic model, and customize and improve the basic model according to the security characteristics of the power network to obtain a pre-trained model; A model fine-tuning module is used to fine-tune the pre-trained model using the training data set to obtain a fine-tuned model; Intelligent analysis module, which is used to perform intelligent correlation analysis on network security data based on fine-tuning models to mine potential threats and attack patterns; The attack and defense confrontation module is used to design an intelligent plug-in mechanism based on the analysis results, connect the intelligent plug-in mechanism with the network security equipment, and conduct coordinated attack and defense confrontation.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the large model training method in the field of network security based on the generative large model are implemented as described in any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the large model training method in the field of network security based on a generative large model are implemented as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Large anesthesia model training method and device
CN117095827A
Customer service scene-oriented generation matching type large model construction method, medium and equipment
CN117709969A
Network security defense system and method based on artificial intelligence
CN118337476A
Intelligent Web application protection method based on AI semantics
CN119030732A
System and method for DNN-based cyber-security using federated learning-based generative adversarial network
US20230308465A1