Emergency response automatic alarm processing system with large language model as kernel

By designing an emergency response automated alarm handling system with a large language model as the core, the problem that existing tools cannot effectively deal with new types of alarms is solved, and higher alarm analysis accuracy and efficiency are achieved.

CN119945703AActive Publication Date: 2025-05-06ZHEJIANG UNIV +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202411713924.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-11-27
Publication Date
2025-05-06
Estimated Expiration
2044-11-27

AI Technical Summary

Technical Problem

Existing automated alarm handling tools cannot effectively handle new types of alarms, have problems with false alarms and underreporting, and face challenges in diversity and complexity of alarm data.

Method used

An emergency response automated alarm handling system with a large language model as the core is designed, including a suspicious factor module, an auxiliary analysis data module, a weight allocation module, a data packaging module and a result determination module. Through the coordinated work of these modules, suspicious factors in the alarm are extracted and analyzed, false positive index judgment is carried out, and the accuracy of alarm analysis is improved.

Benefits of technology

It effectively reduces false alarms and missed reports, improves the accuracy of alarm analysis, can better process different types of alarm data, and improves the work efficiency of security engineers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945703A_ABST
    Figure CN119945703A_ABST
Patent Text Reader

Abstract

The invention discloses an emergency response automatic alarm processing system with a large language model as a kernel. The operation process of the system comprises the following steps: inputting alarm content of target equipment; analyzing the alarm content, and outputting suspicious factors and descriptions thereof; analyzing and outputting auxiliary analysis data types of the suspicious factors; analyzing the weight of each auxiliary analysis data type; obtaining original data; extracting auxiliary analysis data in a combined manner and packaging the auxiliary analysis data; packaging the extracted various types of auxiliary analysis data and weights; outputting a false alarm index and a reason of the suspicious factor based on the packaged weight and the data; and calculating and outputting an average false alarm index and reasons of all suspicious factors. According to the invention, a plurality of processing agents based on emergency response alarm analysis, research and judgment are constructed by using the text analysis and reasoning capabilities of the large model, a set of automatic alarm processing system is realized through reasonable task arrangement, and a new technical means is provided for automatic analysis of equipment alarms.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of emergency response, and in particular to an emergency response automatic alarm handling system with a large language model as its core. Background Art

[0002] Emergency response engineering specifically refers to the ability to locate the attack point in time and quickly deploy defenses to prevent further exploitation by external attackers when the unit is attacked by a network. Generally speaking, we use some alarm devices to monitor the activities of each host in the intranet. When the host exhibits abnormal behavior, an alarm will be triggered. Then the security engineer will further analyze the generated attack alarm to check whether it is a real intrusion attack.

[0003] As the network environment becomes more complex and the intranet of enterprises and units becomes larger, the number of attack alarms generated is also increasing. At the same time, the on-duty pressure faced by security engineers is also increasing. In order to reduce the pressure on security engineers to check the alarm content and improve their work efficiency, in addition to improving the quality of the alarm matching rules of the equipment itself, it is also possible to aggregate historical alarm features and train models to automatically handle historical alarm content. However, when faced with new types of alarms, due to the lack of independent analysis and judgment capabilities, the trained models are still unable to automatically analyze, judge and handle new types of alarms.

[0004] The large model trained based on massive data has certain reasoning and code generation capabilities, and has a high knowledge reserve in various fields. It is widely used in various language processing tasks, such as text generation, language translation, code generation, etc., and can infer the potential meaning expressed by the text. Based on these characteristics, by designing appropriate frameworks and prompts, problems that conventional models cannot handle can be solved in specific fields. For example, in development work, the large model can be used as a code completion tool to understand the developer's intentions and generate usable code. In vulnerability repair work, it can help humans quickly audit the defective parts of the code and propose modification suggestions.

[0005] Therefore, combined with the characteristics of the large model, it can be found that it is very suitable for solving the problems faced by the automatic alarm handling of emergency response engineering. However, the development of automatic alarm handling tools with large models as the core still faces many challenges:

[0006] (1) False alarms and missed alarms are common problems in the alarm handling process. Traditional rule-matching alarm devices are prone to generating a large number of false alarms. Although large models have reasoning capabilities, they still make inaccurate judgments when faced with new attack methods. Therefore, how to design model training and optimization mechanisms to improve the accuracy of alarm analysis and reduce false alarms and missed alarms remains a major challenge.

[0007] (2) Diversity and complexity of alarm data: Enterprise network environments are usually very complex, and the alarms generated involve different types of attack methods and device information. Although large models have powerful data analysis capabilities, the diversity of alarm data sources, differences in data formats, and incomplete or noisy data will affect the performance of the model. How to effectively clean and standardize data and ensure that the model can handle different types of alarms is a challenge that must be overcome.

[0008] The characteristics exhibited by the large model are consistent with the capabilities required for automated alarm handling. However, due to the above difficulties, there is a lack of relevant automated alarm handling tools. Therefore, it is important and necessary to design relevant utilization methods and utilization systems. Summary of the invention

[0009] In view of the problem that existing automated alarm handling tools cannot automatically handle new alarms, the present invention provides an emergency response automated alarm handling system with a large language model as its core.

[0010] The specific technical solution adopted by the present invention is as follows:

[0011] The first aspect of the present invention provides an emergency response automated alarm handling system with a large language model as the core, comprising a suspicious factor module, an auxiliary analysis data module, a weight distribution module, a data encapsulation module and a result determination module;

[0012] The suspicious factor module is used to obtain the alarm brief of the current alarm in the target device, and extract the suspicious factors in the alarm brief through the large language model and generate the description of each suspicious factor; the suspicious factors include the files uploaded, the commands executed or the processes running during the current alarm, and the description of the suspicious factors includes the type of the suspicious factors;

[0013] The auxiliary analysis data module is used to obtain all the original data involved in this alarm, and based on the type of each suspicious factor, extract different types of auxiliary analysis data corresponding to each suspicious factor from the original data through a large language model, analyze the auxiliary analysis data at the same time, and output different types of auxiliary analysis data and analysis results;

[0014] The weight allocation module allocates weights to various types of auxiliary analysis data through a large language model;

[0015] The data encapsulation module is used to encapsulate suspicious factors and their descriptions, auxiliary analysis data and their analysis results and weights through a large language model;

[0016] The result judgment module judges the false alarm index of the suspicious factor based on the encapsulation result of the data encapsulation module through a large language model, calculates the average false alarm index by comprehensively considering the false alarm index of each suspicious factor, judges whether the current alarm is a false alarm based on the average false alarm index, and outputs the judgment result and the judgment reason of each suspicious factor.

[0017] The second aspect of the present invention provides an emergency response automation equipment alarm handling method based on a large model as the core, which is implemented based on the above-mentioned equipment alarm handling system, and the method includes the following steps:

[0018] The suspicious factor module obtains the alarm briefing of the target device, extracts the suspicious factors in the alarm briefing through the large language model, and generates a description of each suspicious factor;

[0019] The auxiliary analysis data module obtains all the original data involved in this alarm, and based on the type of each suspicious factor, extracts different types of auxiliary analysis data corresponding to each suspicious factor from the original data through a large language model, analyzes the auxiliary analysis data at the same time, and outputs different types of auxiliary analysis data and their analysis results;

[0020] The weight allocation module allocates weights to various auxiliary analysis data through a large language model;

[0021] The data encapsulation module encapsulates suspicious factors and their descriptions, auxiliary analysis data and their analysis results and weights through a large language model;

[0022] Based on the encapsulation results of the data encapsulation module, the result judgment module uses a large language model to judge the false alarm index of suspicious factors, calculates the average false alarm index based on the false alarm index of each suspicious factor, and determines whether the current alarm is a false alarm based on the average false alarm index. The judgment result and the judgment reason of each suspicious factor are output.

[0023] Compared with the prior art, the present invention has the following beneficial effects:

[0024] The present invention provides an automated equipment alarm handling method and system with a big model as the core for emergency response engineering, proposes an automated alarm handling tool based on the big model, and establishes a systematic practical framework for solving how to apply the big model to the field of automated alarm handling, which is practical; the present invention provides a personalized Prompt strategy for each subtask of alarm handling in emergency response, and provides an effective method for improving the ability of the big model in completing each subtask of alarm handling. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] Figure 1 This is a schematic diagram of the overall structure of the emergency response automated alarm handling system with a large language model as the core. DETAILED DESCRIPTION

[0026] The present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be pointed out that the embodiments described below are intended to facilitate the understanding of the present invention and do not have any limiting effect on the present invention.

[0027] like Figure 1 As shown, the present invention proposes an emergency response automatic alarm handling system with a large language model as the core, which is mainly divided into a suspicious factor module, an auxiliary analysis data module, a weight distribution module, a data encapsulation module, and a result judgment module. The system is suitable for automatic alarm handling. The large model described in the present invention refers to a large language model, such as a GPT model.

[0028] In the automated alarm handling system, the suspicious factor module is used to obtain the alarm briefing of the target device and split and extract the suspicious factors in the alarm briefing. Specifically, the suspicious factor module obtains the alarm ID, calls the API to obtain the alarm briefing corresponding to the alarm platform through the alarm ID; sends the obtained event briefing to the big model, and based on the content setting of the Prompt template, the big model will split the suspicious factors for the alarm briefing and make corresponding descriptions;

[0029] In this embodiment, the target device is an EDR device or a SIEM system. The alarm ID described is the alarm identifier in the target device, which is used to mark each alarm. The specific ID format varies with the target devices of different manufacturers. The alarm brief described is a description of the alarm content on the alarm platform, including the attack behavior involved in the alarm.

[0030] The suspicious factors described are specifically the decomposition of the attack behavior content in the alarm brief, such as uploaded files, executed commands, operation behaviors, related processes, etc.

[0031] The described Prompt template includes: describing the thinking mode of splitting the suspicious factors for the big model, and providing small samples and thinking chains for the big model to learn the reasoning thinking process.

[0032] In one embodiment of the present invention, the alarm brief obtained this time is: "A certain file executes a certain command, which poses certain security risks"; a certain file or a certain command in the alarm brief is a suspicious factor.

[0033] The thinking patterns include:

[0034] (1) Analyze and extract key information: Identify suspicious elements from the input initial alarm information, such as internal IP, external IP, process, file, etc. (2) Classification and induction: Classify the identified suspicious information according to categories (such as process type, file type, command type, etc.). (3) Infer the suspicious cause: Infer the suspicious elements based on the characteristics of the alarm information and explain their possible risk sources or causes. (4) Generate structured output: Return the analysis results in the specified format (JSON), ensuring that each suspicious information has a clear type description, relevant detailed description, and status (such as "Pending Review").

[0035] The auxiliary analysis data module is used to analyze the original data types required for the suspicious factors. The auxiliary analysis data module includes four submodules: data type determination submodule, data acquisition, data analysis and optimization, and data encapsulation. First, the auxiliary analysis data type corresponding to the suspicious factor is determined, and the original data is obtained based on the auxiliary analysis data type, and each type of original data and its analysis are output.

[0036] The data type determination submodule obtains the split suspicious factors. Based on the content setting of the prompt template, the large model will analyze the suspicious factors and determine the required auxiliary analysis data type and corresponding content description;

[0037] The described prompt template includes: describing the reasoning process of using suspicious factor analysis to obtain auxiliary analysis data types for the large model, and providing small samples and thought chain prompts for the large model to learn the reasoning thinking process. The reasoning process specifically includes: based on the category to which the content of the suspicious factor belongs, analyzing and obtaining the original data type that may be helpful for analysis.

[0038] The auxiliary analysis data types described are mainly data types that can be used to support the analysis of suspicious factors. For example, for suspicious factors of file type, the corresponding auxiliary analysis data types may be the file size, path, content and suffix name, etc.; for suspicious factors of command type, the corresponding auxiliary analysis data types may be the original text of the command; for suspicious factors of file type, the corresponding auxiliary analysis data types may be the file size, path and content, etc.; for suspicious factors of process type, the corresponding auxiliary analysis data types may be the parent process, child process and content of the process, etc. The specific corresponding auxiliary analysis data types are determined by the big model.

[0039] In one embodiment of the present invention, for a certain suspicious factor, taking a certain file as an example, the auxiliary analysis data type required is the reputation of the file, and the description of this type is the reputation of the file on the threat intelligence website.

[0040] The data acquisition submodule is used to call the API to obtain all the original data involved in this alarm, including the commands, processes, file types, etc. involved in this alarm. The original data described is mainly the detailed relevant information about the processes, files, commands, etc. of this alarm in the forensic system.

[0041] The data analysis and optimization submodule is used to extract the data that meets the description of the auxiliary analysis data type from the acquired original data and perform certain analysis. Specifically, the data analysis and optimization submodule uses the big model to extract the content that meets the requirements from the original data under the guidance of the prompt according to the classification results of the original data. The extracted data is the auxiliary analysis data, and the big model is used to perform a brief analysis on the extracted auxiliary analysis data according to the prompt description.

[0042] The described prompt template includes: describing how to accurately extract and analyze the content that meets the definition of the original data type from a large amount of raw data for the large model, and encapsulate it, and provide small samples and thought chain prompts for the large model to learn the reasoning and thinking process. The description of how to extract and analyze specifically includes: according to the classification and description of the original data type, extract the most relevant content from the original data text, and analyze the command, file content, and process context. Specifically, if the auxiliary analysis data is command data, analyze the function and execution result of the command; if the auxiliary analysis data is file-related data, analyze and summarize the content of the file, and analyze whether the file contains malicious code; if the auxiliary analysis data is process data, analyze the function and operation result of the process.

[0043] The data encapsulation submodule is used to encapsulate the auxiliary analysis data type, the extracted raw data and the analysis results. Specifically, the data encapsulation submodule uses the large model to encapsulate the auxiliary analysis data type, auxiliary analysis data content and auxiliary analysis data analysis results output by the above data type determination submodule, data acquisition submodule and data analysis and optimization submodule according to the prompt description.

[0044] The weight allocation module is used to assign weights to various types of raw data based on the description of the auxiliary analysis data type.

[0045] The weight allocation module obtains the auxiliary analysis data type and the corresponding content description and sends it to the big model. Based on the content setting of the Prompt template, the big model is used to analyze and assign weights based on the original data type and description content.

[0046] The described prompt template includes: describing the reasoning process of obtaining the weight of each auxiliary analysis data type based on the description of the auxiliary analysis data type for the large model, and providing small samples and thought chain prompts for the large model to learn the reasoning thinking process. The reasoning process specifically includes: according to the classification of the auxiliary analysis data type, combined with its description of the importance of autonomous analysis and the relevance to the current alarm, weights are assigned to each auxiliary analysis data type to further evaluate the weight of the dangerous information. The rule for weight assignment is: take a value in the range of 0 to 1, and the sum of the weights of all auxiliary analysis data types is equal to 1. According to the reasoning process, the large model first understands the content of the auxiliary analysis data type based on the auxiliary analysis data type description, then analyzes various types of auxiliary analysis data in the original data, and judges its importance based on the weight of each auxiliary analysis data type.

[0047] The data encapsulation module is used to encapsulate the auxiliary analysis data and the corresponding weights. Specifically, the data encapsulation module encapsulates the above-mentioned suspicious factor module, the auxiliary analysis data module, the suspicious factor type and description obtained by weight allocation, each type of auxiliary analysis data and its analysis, and the weight of each auxiliary analysis data type and sends them to the big model. Based on the guidance of the prompt template, the big model will output the encapsulation results.

[0048] The described Prompt template includes: providing a suspicious factor encapsulation module, an auxiliary analysis data module, and a format of data content obtained by a weight distribution module for a large model, and providing examples to guide the encapsulation structure of the large model.

[0049] The result judgment module is used to judge the false alarm index and the reason for the suspicious factor based on the acquired original data and weights, and output the false alarm index and the reason for the analysis. Specifically, the result judgment module obtains the encapsulation result of the data encapsulation module and sends it to the large model. Based on the content setting of the Prompt template, the large model will output the false alarm index and the reason for the suspicious factor based on the content and weight of each original data; calculate the average false alarm index of each suspicious factor, integrate the reasons, judge whether the alarm is a false alarm based on the average false alarm index, and output the final false alarm index and the corresponding reason for each suspicious factor.

[0050] The described prompt template includes: providing a thinking process for the large model, specifically analyzing the original data and weight parameters to prove the false alarm index of the suspicious factor and providing an analysis process, providing a small sample and a thinking chain prompt for the large model to learn the reasoning thinking process. The analysis process is the judgment reason, indicating why the suspicious factor is judged as a false alarm or not a false alarm.

[0051] In this embodiment, the false alarm index is limited to the range of 0 to 100. If the average false alarm index of each suspicious factor is greater than 50, it is determined to be a false alarm, otherwise it is determined not to be a false alarm.

[0052] In one embodiment of the present invention, the final average false alarm index is 10, which is determined to be not a false alarm, and the output determination reason is: "Taking the suspicious factor of the file type as an example, the determination reason may be that the file type has a good reputation on the threat intelligence website and has not been marked as a file with a high risk value by any user."

[0053] The workflow of the entire automated alarm handling system includes the following steps:

[0054] (10) Enter the alarm ID.

[0055] (11) Obtain alarm event briefing through alarm ID.

[0056] (12) Use a large model to extract suspicious factors from event briefings.

[0057] (13) Use large models to analyze the original data types required to support the assessment of suspicious factors.

[0058] (14) Obtain the original data related to the alarm in the device.

[0059] (15) Use large models to extract and analyze the original data in the form of auxiliary analysis data required to identify suspicious factors.

[0060] (16) Use the large model output to assist in analyzing the weights of each type of data.

[0061] (17) Use a large model to encapsulate suspicious factors and their descriptions, auxiliary analysis data types, auxiliary analysis data, and weights.

[0062] (18) Use the large model to analyze the packaged data, generate the false alarm index of the suspicious factors and the analysis process, calculate and output the average false alarm index and judgment reasons of all suspicious factors.

[0063] In summary, a research and judgment report based on the alarm will eventually be output, which includes the average false alarm index of all suspicious factors of the alarm and the reasons for the judgment.

Claims

1. An emergency response automated alarm handling system based on a large language model, characterized in that: It includes suspicious factor module, auxiliary analysis data module, weight distribution module, data encapsulation module and result determination module; The suspicious factor module is used to obtain the alarm brief of the current alarm in the target device, and extract the suspicious factors in the alarm brief through the large language model and generate the description of each suspicious factor; the suspicious factor includes the uploaded file, executed command or running process during the current alarm, and the description of the suspicious factor includes the type of the suspicious factor; The auxiliary analysis data module is used to obtain all the original data involved in this alarm, and based on the type of each suspicious factor, extract different types of auxiliary analysis data corresponding to each suspicious factor from the original data through a large language model, analyze the auxiliary analysis data at the same time, and output different types of auxiliary analysis data and analysis results; The weight allocation module allocates weights to various types of auxiliary analysis data through a large language model; The data encapsulation module is used to encapsulate suspicious factors and their descriptions, auxiliary analysis data and their analysis results and weights through a large language model; The result judgment module judges the false alarm index of the suspicious factor based on the encapsulation result of the data encapsulation module through a large language model, calculates the average false alarm index by comprehensively considering the false alarm index of each suspicious factor, judges whether the current alarm is a false alarm based on the average false alarm index, and outputs the judgment result and the judgment reason of each suspicious factor.

2. The emergency response automatic alarm handling system with a large language model as the core according to claim 1 is characterized in that: The method of obtaining the alarm briefing of the target device specifically includes: obtaining the alarm ID of the target device, and obtaining the alarm briefing corresponding to the alarm ID by calling the API of the target device; the alarm briefing is a description of the alarm on the alarm platform of the target device, including the suspicious operation content involved in the alarm.

3. The emergency response automatic alarm handling system with a large language model as the core according to claim 1 is characterized in that: The method of extracting suspicious factors in the alarm briefing by using the large language model and generating descriptions of each suspicious factor specifically comprises: sending the alarm briefing to the large language model, and inputting prompt words for extracting suspicious factors into the large language model, so that the large language model returns the suspicious factors in the alarm briefing and their descriptions; The prompt words for extracting the suspicious factors include: 1) Identify suspicious factors from the input alarm briefing; 2) Classifying the identified suspicious factors into different types, including processes, files, and commands; 3) Based on the content of the alarm briefing, infer the suspicious factors and explain their possible risk sources or causes; 4) Integrate each suspicious factor, the type of the suspicious factor, and a description of the source or cause of the risk of the suspicious factor into an analysis result, and return all analysis results; wherein the type of the suspicious factor and the description of the source or cause of the risk of the suspicious factor are the description of the suspicious factor.

4. The emergency response automatic alarm handling system with a large language model as the core according to claim 1 is characterized in that: The auxiliary data analysis module includes a data type determination submodule, a data acquisition submodule, a data analysis optimization submodule and a data encapsulation submodule; The data type determination submodule is used to determine the auxiliary analysis data type through the large language model based on the type of each suspicious factor, and generate a description of each auxiliary analysis data type, wherein the description is used to help the large language model understand the meaning of the auxiliary analysis data type; the auxiliary analysis data type is an original data type that is helpful for the analysis of the suspicious factor, including the original text of the command executed by this alarm, the parent process content, the child process content and the current process content of the process run by this alarm, and also includes the size, path and file content of the file uploaded by this alarm; The data acquisition submodule is used to call the API of the target device to obtain all the original data involved in this alarm, and the original data includes all the commands, processes and files involved in this alarm; The data analysis and optimization submodule is used to extract data that meets the description of the auxiliary analysis data type from all the original data involved in this alarm through a large language model and analyze it, and regard the extracted data as auxiliary analysis data; The data encapsulation submodule is used to encapsulate the type name of the auxiliary analysis data type, the auxiliary analysis data and the analysis results thereof through the large language model.

5. The emergency response automatic alarm handling system with a large language model as the core according to claim 4 is characterized in that: The method of extracting and analyzing the data that meets the description of the auxiliary analysis data type from all the original data involved in this alarm through the large language model is as follows: Input the auxiliary analysis data type and its description into the large language model, and let the large language model extract the most relevant content from all the original data texts of this alarm according to the auxiliary analysis data type and its description. The extracted data is the auxiliary analysis data, and the large language model is required to perform the following analysis on the auxiliary analysis data: if the auxiliary analysis data is command data, then analyze the function and execution result of the command; if the auxiliary analysis data is file-related data, then analyze and summarize the content of the file, and analyze whether the file contains malicious code; if the auxiliary analysis data is process data, then analyze the function and running result of the process.

6. The emergency response automatic alarm handling system with a large language model as the core according to claim 1 is characterized in that: The method of assigning weights to various types of auxiliary analysis data through a large language model is specifically as follows: the auxiliary analysis data type and its description are sent to the large language model, and the large model is instructed to autonomously analyze the importance of each auxiliary analysis data type and its relevance to the current alarm based on the auxiliary analysis data type and its description, and weights are assigned to each auxiliary analysis data type based on the importance and relevance analysis results.

7. The emergency response automatic alarm handling system with a large language model as the core according to claim 1 is characterized in that: The encapsulation of suspicious factors and their descriptions, auxiliary analysis data and their analysis results and weights through the large language model is specifically: sending the suspicious factors and their corresponding descriptions, auxiliary analysis data and their corresponding analysis results and the weights of the auxiliary analysis data to the large language model, and providing the large language model with a packaging format, and providing the large language model with a packaging case, so that the large language model encapsulates the input data.

8. The emergency response automatic alarm handling system with a large language model as the core according to claim 1 is characterized in that: The false alarm index determination of the suspicious factor is specifically as follows: the encapsulation result of the data encapsulation module is input into the large language model, and the large language model is made to analyze the auxiliary analysis data and its weight to confirm the false alarm index of the suspicious factor. When the false alarm index is greater than the set threshold, it is determined to be a false alarm, otherwise it is determined not to be a false alarm, and the determination result and the analysis process of the auxiliary analysis data and its weight are returned. This analysis process is the determination reason of the suspicious factor.

9. A method for handling emergency response automation equipment alarms based on a large model, characterized in that: Based on the implementation of the alarm handling system according to claim 1, the device alarm handling method comprises the following steps: The suspicious factor module obtains the alarm briefing of the target device, extracts the suspicious factors in the alarm briefing through the large language model, and generates a description of each suspicious factor; The auxiliary analysis data module obtains all the original data involved in this alarm, and based on each suspicious factor, extracts different types of auxiliary analysis data corresponding to each suspicious factor from the original data through a large language model, analyzes the auxiliary analysis data at the same time, and outputs different types of auxiliary analysis data and their analysis results; The weight allocation module allocates weights to various auxiliary analysis data through a large language model; The data encapsulation module encapsulates suspicious factors and their descriptions, auxiliary analysis data and their analysis results and weights through a large language model; Based on the encapsulation results of the data encapsulation module, the result judgment module uses a large language model to judge the false alarm index of suspicious factors, calculates the average false alarm index based on the false alarm index of each suspicious factor, and determines whether the current alarm is a false alarm based on the average false alarm index. The judgment result and the judgment reason of each suspicious factor are output.

Citation Information

Patent Citations

  • Static application security detection false alarm discrimination method based on large-scale language model

    CN117077153A

  • Method for automatically tracing security event through large model

    CN117857193A

  • LLM-driven industrial network intrusion detection method and response system

    CN118381627A

  • Triaging alerts using machine learning

    EP4160504A1

  • Apparatus and method for generating security threat detection report using language model

    KR102575129B1