Cloud intelligent active defense method based on large language model
By using large language models for intelligent and proactive defense in the cloud computing environment, the problem of complex security threats in the cloud computing environment is solved, and efficient and intelligent defense strategies are dynamically updated and threat response is achieved.
Patent Information
- Application Number
- CN202510071936.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-16
- Publication Date
- 2025-05-09
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
There are complex security threats in the cloud computing environment, including IP spoofing, DDOS attacks and security risks brought by multi-tenant environments. Traditional defense solutions are difficult to effectively deal with dynamically changing cloud service scenarios.
Adopt cloud intelligent active defense method based on large language model, and automatically call security tools to collect and reconstruct network data through LLM, realize intelligent risk assessment and fault detection, and decompose defense tasks to reason and decision-making for subtasks, and dynamically deploy and update defense strategies.
It significantly improves the security of the cloud platform, provides comprehensive, intelligent and defense capabilities that can deal with unknown threats, dynamically updates the defense strategy library to deal with new threats, and gradually improves the protection effect.
Smart Images

Figure CN119966694A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a cloud-based intelligent active defense method based on a large language model, belonging to the technical field of active defense. Background Art
[0002] The rapid development of cloud computing has made it an important paradigm for service-oriented computing. Its birth stems from the growing demand for large-scale data processing in the Internet era. Today, cloud computing is widely used in all walks of life and is increasingly closely connected with people's lives due to its high efficiency, scalability, high cost-effectiveness and geographically independent access to cloud resources. However, the popularity of cloud computing and its increasing complexity also bring new security challenges.
[0003] The diversity and complexity of cloud computing components, such as networks, architectures, APIs, and hardware, have caused people to be highly concerned about security. Due to the use of standard Internet protocols and virtualization methods, cloud computing components are easily threatened by potential security vulnerabilities. According to existing research, threats that may appear in traditional network environments also exist in cloud environments, such as IP spoofing, address resolution protocol (ARP) attacks, distributed denial of service (DDOS) attacks, etc., which pose a major threat to cloud services; at the same time, the security risks brought by the multi-tenant environment of cloud platforms are also becoming increasingly serious. Attackers can break through isolation measures through co-resident attacks and side-channel attacks, affecting the security of the entire cloud platform; in addition, the endless stream of zero-day attacks also brings huge challenges to traditional defense solutions.
[0004] In order to deal with the above threats, several active defense solutions have been proposed, including mobile target defense (MTD), deception defense, mimicry defense, etc. These methods emphasize active identification, warning and response to threats through automated and adaptive mechanisms before or during attacks, thereby effectively reducing security risks and potential losses. These solutions have overcome the shortcomings of traditional defense solutions to a certain extent, but the dynamic changes in cloud environments (such as real-time updates of network topology and virtual container configurations) and the wide range of attacks (distributed architecture increases the attack surface) make it difficult for any specific strategy to apply to time-varying cloud service scenarios. In addition, current defense decisions and deployments mainly rely on heuristics, machine learning or deep learning algorithms. There is an urgent need for a new, intelligent and adaptable defense technology to improve active defense strategies in cloud environments.
[0005] As a typical example of the generative foundation model (GFM), the large language model (LLM) has had a profound impact on academic research and engineering application fields. It can understand defense requirements through contextual learning and prompt word engineering, decompose complex tasks into sub-modules, adaptively solve defense tasks through its step-by-step reasoning and reflection capabilities, and make defense decisions based on rich prior knowledge. Based on these advantages, existing studies have used LLM as a network security knowledge expert to develop automated security tools such as vulnerability mining and code repair. It can be seen that using LLM to empower active defense technology can provide a feasible solution for comprehensive protection of dynamic cloud security scenarios. Summary of the invention
[0006] To solve the above problems, the present invention proposes a cloud-based intelligent active defense method based on a large language model. First, we use LLM to automatically call multiple security tools to collect and reconstruct cloud platform network data, realizing an automated and easily expandable cloud network data collection tool. After parsing the collected data, intelligent risk assessment and fault detection of the cloud environment are realized based on the LLM text comprehension ability. Subsequently, we decompose the defense task into multiple subtasks and call LLM for reasoning and defense decision-making. On the basis of considering security indicators, resource utilization and user experience can be fully guaranteed. At the same time, through the programming ability of LLM, the automatic deployment and update of defense strategies are realized. Finally, LLM evaluates and feedbacks the resource consumption and service quality of the defense strategy execution, and gradually improves the comprehensive protection capability of this method. The technical solution disclosed in this study can provide the cloud platform with comprehensive, intelligent and unknown threat-response capabilities, significantly improving the security of the cloud platform.
[0007] The present invention adopts the following technical solution: a cloud-based intelligent active defense method based on a large language model, the method comprising the following steps:
[0008] Step (1): Data acquisition and reconstruction,
[0009] Step (2): Status and hazard assessment,
[0010] Step (3): Task reasoning and decision making,
[0011] Step (4): Deployment and execution of defenses,
[0012] Step (5): Effect evaluation and feedback.
[0013] The specific contents of the steps are as follows:
[0014] Step (1): Data collection and reconstruction, specifically, using LLM as a data collector, designing collection and reconstruction tasks through prompt words, including collection time, callable tools, collection content, output format, etc., and then using LLM's function call function or code writing ability to adaptively call the corresponding security tool to collect network data, and use LLM to aggregate and remove redundancy from the data, then extract key information from the data to generate a security briefing for the target network, and finally output the data to a specified output format (JSON, CSV, etc.).
[0015] Step (2): Status and risk assessment, specifically as follows: First, LLM reads the data file obtained in step (1) and extracts status information of the system hardware, network, and application, and models the system status matrix state; secondly, LLM identifies potential threats based on the comparison of status data with historical normal status data, and quantifies the risk level risk according to the threat scope, impact, and duration; for cloud network failures caused by high-risk attacks, this module can use the existing status data to locate the failure, effectively identify the attack target, and use it for subsequent defense target generation; then, the system status matrix state, risk level risk, failure source and other data are used as input for subsequent steps,
[0016] Step (3): Task reasoning and decision-making, as follows: In advanced threat scenarios involving multiple defense targets, it is very important to clearly plan and reasonably divide defense tasks. This module uses a decomposition function to decompose the overall defense task into H independent subtasks, and uses LLM to set task goals and execution constraints for each subtask, and flexibly formulates defense strategies for each subtask; then, according to the risk level risk obtained in step (2) and the dependency relationship between subtasks, the execution priority is assigned to the subtask, and the defense preference is set through prompt words. On the basis of ensuring the success of defense, the loss of defense resources can be reduced and the user experience can be maintained. The defense preference can be preset by the developer and dynamically adjusted during the implementation process; for each subtask, LLM understands the task goal and execution constraint, and gradually infers the defense action and defense effect, and solves the best defense strategy considering the defense preference.
[0017] Step (4): Defense deployment and execution, as follows: First, parse the defense strategy obtained in step (3) to obtain the defense action action. Action is an integer between 0 and l-1, which is the numerical representation of the defense strategy. l is the number of defense strategies in the defense strategy library S. Secondly, call the query function according to action to query whether this defense strategy exists in the defense strategy library S. If it exists, further parse the defense strategy to obtain the deployment target server, defense script and execution parameters. If it does not exist, parse the defense strategy to obtain the defense requirements, use LLM programming capabilities to write a new defense script, and compile it in real time to verify its executability. After that, the strategy execution module automatically deploys the defense script to the target server and automatically executes all subtasks according to the specified parameters and execution priority. Finally, the newly created defense strategy strategy is deployed. new Add to the defense strategy library, and its defense action number is action new = l, the number of defense strategies is updated to l = l + 1, and the defense strategy library is updated to S new This enables dynamic expansion of defense strategies to meet flexible defense needs.
[0018] Step (5): Effect evaluation and feedback. The details are as follows. After step (4) is completed, first determine whether the defense strategy is successfully executed. execute If the execution fails, get the reason for the failure. execute , used by LLM to reflect on and improve defense parameter selection; then judge whether this round of defense is successful based on security indicators, that is, success defense If the defense fails, the reason for the failure is obtained. defense , and conduct a comprehensive evaluation of the defense effects such as recovery time, resource consumption, and service quality; finally, regardless of whether the defense succeeds or fails, the current round of defense strategy and the above-mentioned defense evaluation indicators are given to LLM for reflection, and the current round of defense experience summarized by LLM is obtained. The defense strategy, defense evaluation indicators, and defense experience are stored in the memory module for the next round of reasoning and defense, so that it can dynamically learn and improve the defense strategy in the feedback loop.
[0019] Among them, the step 1: data collection and reconstruction, this paper designs a workflow based on LLM that can flexibly call multiple security tools for automated data collection and reconstruction, as follows:
[0020] Step (1.1) Collection task setting: Set the collection task for the LLM collector through prompt words, including collection target, collection duration, output format and collection tool.
[0021] Step (1.2) Adaptive data collection: LLM can flexibly call the specified tool to complete the collection task on the target network through function call or code writing capabilities. When a new collection tool needs to be expanded, it only needs to modify the prompt word to give LLM a new task prompt.
[0022] Step (1.3) Data aggregation and redundancy removal: After the LLM-based data collector collects data at a specified time step, it uses LLM to analyze the relationship between different data sources for aggregation and reorganization, and removes redundant and invalid data.
[0023] Step (1.4) Extraction of key information: Input the collected data into LLM as text, use LLM's text understanding ability to extract key information and generate a security briefing for the target network.
[0024] Step (1.5) Standard format output: LLM converts the processed data into a specified output format (JSON, CSV, etc.) for storage and next step processing.
[0025] In step 2: state and hazard assessment, this paper uses LLM to analyze and model various system states, quantify risk levels and locate faults, as follows:
[0026] Step (2.1) Status information extraction: Read the data file output by step (1.5) and extract system status data from the specified fields, such as hardware status (power consumption), network status (network throughput), and application status (number of connections).
[0027] Step (2.2) System state modeling: LLM models the current system state based on the state data obtained in step (2.1), expressed as a state matrix state, reduces redundant information, and is used to derive the constraints of subsequent sub-defense tasks.
[0028] Step (2.3) Risk Assessment: LLM compares the status data in (2.1) with the historical normal status data to identify potential threats and anomalies, and quantifies the risk level according to the scope, impact and duration of the threat, which can be used to arrange subsequent sub-defense tasks.
[0029] Step (2.4) Fault location: For cloud network failures caused by severe attacks, LLM can use status data to locate the fault, effectively identify the attack target and use it for subsequent defense target generation.
[0030] Step (2.5) Information aggregation: Aggregate the system status matrix, risk level, fault location and other results obtained in steps (2.2) and (2.3) as input for subsequent steps.
[0031] Step 3: Task reasoning and decision-making. This paper uses LLM to perform task decomposition and reasoning decisions, and combines factors such as security factors and resource consumption to solve the best defense action, as follows:
[0032] Step (3.1) Task decomposition: In a complex cloud environment, multiple threat points may appear, which requires achieving multiple defense goals simultaneously in a single overall task. Therefore, the overall task needs to be decomposed into H independent subtasks, and LLM is used to set task goals and execution constraints for each subtask.
[0033] Step (3.2) Subtask priority assignment: Assign execution priorities to subtasks based on the risk levels and dependencies between subtasks obtained in step (2.3).
[0034] Step (3.3) Set defense preferences: By setting defense preferences, LLM can take into account multiple factors such as reducing defense resources and ensuring user experience while achieving defense effects. These preferences can be preset by developers and dynamically adjusted during implementation.
[0035] Step (3.4) Reasoning and decision-making: For each subtask, LLM obtains the task objectives and execution constraints set in step (3.1), and gradually reasons about the defense actions and defense effects. Considering the defense preferences set in step (3.2), it solves the best defense strategy from the available defense strategies.
[0036] In step 4: defense deployment and execution, this paper uses LLM programming capabilities to dynamically update the defense strategy library and realize automatic deployment and execution of defense strategies, as follows:
[0037] Step (4.1) Defense strategy analysis: First, analyze the defense strategy obtained in step (3) to obtain the defense action action. Action is an integer between 0 and l-1, which is the numerical representation of the defense strategy. l is the number of defense strategies in the defense strategy library S.
[0038] Step (4.2) Defense strategy query: Call the query function according to the action to query whether this defense strategy exists in the defense strategy library S. If it exists, further parse the defense strategy to obtain the deployment target server, defense script and execution parameters. If it does not exist, parse the defense strategy to obtain the defense requirements, use LLM programming capabilities to write a new defense script, and compile it in real time to verify its executability.
[0039] Step (4.3) Defense strategy execution: The defense script obtained by query or created is combined with the specified defense parameters and execution priority to automatically execute and deploy defense subtasks on the target cloud network to achieve effective and efficient deployment.
[0040] Step (4.4) Defense strategy update: Update the newly created defense strategy strategy new Add to the defense strategy library, and its defense action number is action new = l, the number of defense strategies is updated to l = l + 1, and the defense strategy library is updated to S new This enables dynamic expansion of defense strategies to respond to emerging threats and improve protection capabilities.
[0041] Step 5: Effect evaluation and feedback. This paper evaluates the defense effect and reflects on the defense strategy based on the LLM reasoning and reflection ability, as follows:
[0042] Step (5.1) Security status assessment: After step (4) is completed, first determine whether the defense strategy is executed successfully, that is, success execute If the execution fails, get the reason for the failure. execute , used by LLM to reflect on and improve defense parameter selection; then judge whether this round of defense is successful based on security indicators, that is, success defense If the defense fails, the reason for the failure is obtained. defense
[0043] Step (5.2) Evaluation of other indicators: In addition to security indicators, it is also necessary to comprehensively evaluate the defense effects such as service recovery time, resource consumption generated by the specified defense strategy, and service quality to measure the quality of the defense actions.
[0044] Step (5.3) Defense strategy reflection: Regardless of whether the defense succeeds or fails, the current defense strategy and the above defense evaluation indicators are given to LLM for reflection, and the defense experience of this round is summarized by LLM.
[0045] Step (5.4) Reflection memory update: The defense strategy, defense evaluation index and defense experience are stored in the memory module for the next round of reasoning and defense, so that it can dynamically learn and improve the defense strategy in the feedback loop.
[0046] An electronic device comprises a memory, a processor and a computer program stored in the memory and executable on the processor. When the processor executes the program, the cloud-based intelligent active defense method based on a large language model is implemented.
[0047] A computer-readable storage medium stores computer instructions, which, when executed by a processor, implement the cloud-based intelligent active defense method based on a large language model.
[0048] Compared with the prior art, the present invention has the following advantages:
[0049] (1) Automatic and scalable data collection module construction: In order to solve the data collection tasks of different network structures and different security data sources in the cloud, the present invention uses the function calling capability of LLM to realize automatic and scalable data collection. First, different security tools are adaptively called to collect network data. At the same time, after the data is collected, it is analyzed and reconstructed, and redundant data is removed and output in a specified data format, so as to realize the automation of complex heterogeneous network data collection in the cloud; in addition, the collection requirements, callable security tools, collection time and output format and other collection tasks are adjusted by modifying the prompt words, which makes the user operation less difficult and realizes the deployment and expansion of lightweight collection tasks.
[0050] (2) Intelligent and proactive defense reasoning, decision-making and deployment: In the face of complex threat scenarios in the cloud, the present invention implements intelligent and proactive defense decision-making and defense deployment strategies. The task reasoning and decision-making module breaks down the overall defense task into several independent subtasks according to the network structure, defense objectives, etc., uses LLM to set subtask objectives for each subtask and perform step-by-step reasoning, reduces the decision action space, and improves the decision effect; LLM makes decisions based on the subtask reasoning results and defense preferences. The setting of defense preferences not only ensures that the defense decision achieves the security goal, but also considers preference factors such as resource consumption and user experience to achieve intelligent defense decision-making; finally, the defense deployment and execution module automatically deploys and executes existing or newly created defense scripts based on the best defense decision, so that the defense strategy can intelligently and efficiently proactively defend against malicious threats in complex cloud environments.
[0051] (3) Dynamic update of the defense strategy library to effectively respond to unknown threats: The present invention implements dynamic update of the defense strategy library, greatly improving the defense capabilities against unknown threats such as zero-day attacks. When the task reasoning and defense decision module encounters a new unknown threat, the defense strategy already in the defense strategy library cannot effectively defend against it. At this time, the LLM obtains a new defense decision, and in the subsequent defense deployment and execution module, the LLM's programming capabilities are called to write a new defense script to achieve dynamic update of the defense action library. The dynamic update of the defense action library can continuously explore new defense strategies and achieve active and effective defense against known and unknown threats.
[0052] (4) The effect evaluation and feedback module realizes the round-by-round improvement of defense effect: The present invention realizes an efficient defense experience utilization mechanism in the effect evaluation and feedback module, and continuously improves the defense strategy by summarizing the experience of the previous round, thereby optimizing and improving the defense effect. After each round of defense, the effect evaluation and feedback module evaluates security indicators such as the success or failure of the defense, as well as evaluation indicators such as resource utilization and service quality, and uses the LLM reflection ability to summarize the defense experience and record it in the memory module. Through the mechanism of defense effect evaluation and feedback, the present invention continuously accumulates defense experience and gradually improves defense effectiveness. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] Figure 1 Design a framework diagram for the cloud-based intelligent active defense method based on a large language model;
[0054] Figure 2 This is a system architecture diagram of the cloud-based intelligent active defense method based on a large language model. DETAILED DESCRIPTION
[0055] In combination with the above-described steps, this section implements some cases in combination with the description of the relevant technical solution steps in the specification.
[0056] Embodiment 1:
[0057] A large language model-driven active defense approach against denial-of-service attacks (DoS) in the cloud.
[0058] Step (1): Data acquisition and reconstruction,
[0059] Step (2): Status and hazard assessment,
[0060] Step (3): Task reasoning and decision making,
[0061] Step (4): Deployment and execution of defenses,
[0062] Step (5): Effect evaluation and feedback.
[0063] The step (1): data collection and reconstruction is as follows. First, the experimental environment setting is introduced. This paper implements an elastic web service, which is distributed and deployed on H cloud hosts. It can create up to M Apache container copies and has a resource pool of P pods. The LLM-based data collector is deployed on the cloud server. The Linux system status monitoring management program htop is directly called through the function call function of LLM to collect system memory usage, the number of online running containers and other information. The API interface of the resource management service Metrics-Server built-in in the container management platform Kubernetes is called through the LLM script to collect the number of resources and the number of connections of each container pod. The collection time step and output format are given to LLM through prompt words. The prompt words can be modified to realize the flexible adjustment of the collection task. This experiment specifies the output format as JSON format. After collecting data at the specified time step, the LLM-based data collector merges the memory usage, the number of online running containers, the number of connections and other status information into a file. After removing redundant and invalid data, the key information is extracted to generate a safety briefing, which is then output as a JSON file.
[0064] The step (2): status and risk assessment is specifically as follows: first, LLM reads the JSON data file obtained in step (1) and extracts status information such as memory usage, number of online running containers, number of pod resources, number of connections, etc., and models the system status at this time as an m*n state matrix state, where m is the number of containers and n is the number of container status indicators; secondly, LLM compares the current round of status data with the historical normal status data to identify and quantify the risk level risk, which is quantified as an integer between 0 and 10. Here, the prompt word informs LLM that the risk level risk can be based on the connection load rate C d 、Memory load rate M d The calculation formulas are respectively expressed as and where con i for and mem i are the number of connections and memory usage of the i-th container at this time, and con max and mem max Then, LLM analyzes the current status data to see if there are any compromised or downed containers, and records them in the dangerous container list pod d ; Finally, the system state matrix state and safety index C d and M d , risk level risk and dangerous container list pod d The data is used for input in subsequent steps.
[0065] Step (3): Task reasoning and decision-making, as follows: In the experiment, the overall defense task is divided into H independent defense subtasks according to the number of service hosts deployed by the service, and the task goal and execution constraint are set for each subtask according to the service status, and a defense strategy is flexibly formulated for each subtask; LLM assigns execution priority to the subtask according to the subtask goal and execution constraint, as well as the risk level risk obtained in step (2.3). If risk = 0, it indicates that the subtask does not need to execute the defense strategy; then, the defense preference is set for LLM through the prompt word. This experiment requires reducing the defense resource loss and maintaining the user experience on the basis of ensuring the success of the defense. Each defense strategy execution consumes one Given the resources, how to choose the best defense strategy needs to be combined with the defense experience of the previous rounds, and finally evaluated and improved in step (5). The defense preference can be preset by the developer and dynamically adjusted during the implementation process; in each subtask, LLM performs step-by-step reasoning and decision-making to finally obtain the best defense strategy. In this experiment, carefully designed prompt words are used to guide LLM to perform step-by-step reasoning, which is followed by three steps: attack type determination, reference to the best action in the previous round, and defense decision-making. Among them, attack type determination refers to inferring the attack type through the state data obtained in step (2). After that, the existing successful actions are obtained from the memory module in step (5). LLM selects the best defense strategy based on the defense effect and a certain probability rate. refer Choose whether to refer to previous actions. Finally, after the above two steps of reasoning, LLM considers the subtask goals, the current service state, and the dangerous container list pod d , the decision is to get the best defense strategy strategy,
[0066] Step (4): Defense deployment and execution. Specifically, the defense strategy execution module first parses the defense action action from the defense strategy strategy obtained in step (3). action is an integer between 0 and l-1, which is the numerical representation of the defense strategy. l is the number of defense strategies in the defense strategy library S. Secondly, according to action, the query function is called to query whether this defense strategy exists in the defense strategy library S. If it exists, the defense strategy is further parsed to obtain the deployment target server, defense script and execution parameters. If it does not exist, the defense strategy is parsed to obtain the defense requirements, and a new defense script is written using LLM programming capabilities, and its executable is verified in real time. After that, the strategy execution module automatically deploys the defense script to the target server and automatically executes all subtasks according to the specified parameters and execution priority. Finally, the newly created defense strategy strategy is deployed. new Add to the defense strategy library, and its defense action number is action new = l, the number of defense strategies is updated to l = l + 1, and the defense strategy library is updated to S newThis enables dynamic expansion of defense strategies.
[0067] Step (5): Effect evaluation and feedback. The details are as follows. After step (4) is completed, first determine whether the defense strategy is successfully executed. execute If the execution fails, get the reason for the failure. execute , used for LLM reflection to improve defense parameter selection; then according to the service state after defense * Recalculate connection load factor Memory load rate and a list of hazardous containers LLM determines whether the current defense strategy successfully prevents attack traffic and ensures that the service is available, i.e. success. defense If the defense fails, the reason for the failure is obtained. defense , such as excessive connection load, and at the same time evaluate the resource consumption cost generated by executing the defense strategy and the service delay at this time; finally, regardless of whether the defense succeeds or fails, the current defense strategy strategy and the above defense evaluation indicators are given to LLM for reflection, and the defense experience summarized by LLM is obtained. Finally, the defense strategy, defense evaluation indicators and defense experience are stored in the memory module for the next round of reasoning and defense, so that it can dynamically learn and improve the defense strategy in the feedback loop.
[0068] Step (1.1) Collection task setting: Set the collection task for the LLM collector through the prompt word. The collection target is the memory usage, number of online running containers, number of pod resources, number of connections and other status information of the M Apache containers on the elastic web service. The data output format is specified as JSON format.
[0069] Step (1.2) Adaptive data collection: LLM directly calls the Linux system status monitoring management program htop through the function call function to collect information such as system memory usage and the number of online running containers. LLM writes scripts to call the API interface of the built-in resource management service Metrics-Server of the container management platform Kubernetes to collect information such as the number of resources and connections of each container pod. When it is necessary to expand new collection tools, you only need to modify the prompt words to give LLM new task prompts.
[0070] Step (1.3) Data aggregation and redundancy removal: After collecting data at a specified time step, the LLM-based data collector merges status information such as memory usage, number of online running containers, number of connections, etc. into one file, uses LLM to analyze the relationship between different data sources for aggregation and reorganization, and removes redundant and invalid data.
[0071] Step (1.4) Extraction of key information: Input the collected data into LLM as text, use LLM's text understanding ability to extract key information and generate a security briefing for the target network.
[0072] Step (1.5) Standard format output: LLM converts the processed data into JSON format for storage and next step processing.
[0073] In step 2: state and hazard assessment, this paper uses LLM to analyze and model various system states, quantify risk levels and locate faults, as follows:
[0074] Step (2.1) Status information extraction: LLM reads the JSON data file obtained in step (1) and extracts status information such as memory usage, number of online running containers, number of pod resources, number of connections, etc.
[0075] Step (2.2) System state modeling: LLM models the current system state based on the state data obtained in step (2.1) to obtain an m*n state matrix state, where m is the number of containers and n is the number of container state indicators.
[0076] Step (2.3) Risk Assessment: LLM compares the current state data with the historical normal state data to identify and quantify the risk level risk. Risk is quantified as an integer between 0 and 10. Here, the prompt word informs LLM that the risk level risk can be based on the connection load rate C d 、Memory load rate M d The calculation formulas are respectively expressed as where con i for and mem i are the number of connections and memory usage of the i-th container at this time, and con max and mem max They represent the maximum number of connections and memory usage of the container, respectively, and can be used to generate task objectives and set priorities for subsequent sub-defense tasks.
[0077] Step (2.4) Fault location: LLM can use status data to locate faults, that is, whether there are containers that have been compromised or down due to serious attacks, and record them in the dangerous container list pod d , effectively identify the attack target and use it for subsequent sub-defense task target generation,
[0078] Step (2.5) Information aggregation: Aggregate steps (2.2) and (2.3) to obtain the system state matrix state and safety index C d and M d, risk level risk and dangerous container list pod d The data is used for input in subsequent steps.
[0079] Step 3: Task reasoning and decision-making. This paper uses LLM to perform task decomposition and reasoning decisions, and combines security factors and resource consumption to solve the best defense strategy, as follows:
[0080] Step (3.1) Task decomposition: In the experiment, the overall defense task is divided into H independent defense subtasks according to the number of service hosts deployed, and task objectives and execution constraints are set for each subtask according to the service status, and defense strategies are flexibly formulated for each subtask.
[0081] Step (3.2) Subtask priority assignment: LLM then assigns execution priorities to subtasks based on the subtask objectives and execution constraints, as well as the risk level obtained in step (2.3). If risk = 0, it means that the subtask does not need to execute the defense strategy.
[0082] Step (3.3) Set defense preference: Set defense preference for LLM through prompt words. This experiment requires reducing defense resource loss and maintaining user experience on the basis of ensuring defense success. Each defense strategy execution consumes a certain amount of resources. How to choose the best defense strategy needs to be combined with the defense experience of the previous rounds. Finally, it is evaluated and improved in step (5). Defense preference can be preset by developers and dynamically adjusted during implementation.
[0083] Step (3.4) Reasoning and decision-making: In each subtask, LLM performs step-by-step reasoning and decision-making, and finally obtains the best defense strategy. In this experiment, carefully designed prompt words are used to guide LLM to perform step-by-step reasoning, which is divided into three steps: attack type determination, reference to the best action in the previous round, and defense decision-making. Among them, attack type determination refers to inferring the attack type through the state data obtained in step (2). After that, the existing successful actions are obtained from the memory module in step (5). LLM makes a decision based on the defense effect and a certain probability rate. refer Choose whether to refer to previous actions. Finally, after the above two steps of reasoning, LLM considers the subtask goals, the current service state, and the dangerous container list pod d , the decision is to get the best defense strategy strategy,
[0084] In step 4: defense deployment and execution, this paper uses LLM programming capabilities to dynamically update the defense strategy library and realize automatic deployment and execution of defense strategies, as follows:
[0085] Step (4.1) Defense strategy analysis: The defense strategy execution module first analyzes the defense action action from the defense strategy strategy obtained in step (3). Action is an integer between 0 and l-1, which means the unique number of the defense strategy. l is the number of defense strategies in the defense strategy library S. Initially, there are 6 defense strategies in the defense strategy library, namely, add replicas, reduce replicas, expand replicas, reduce replicas, port jump, and no action. That is, S = {s replica-increase ,s replica-reduction ,s replica-expansion ,s replica-scaling ,s port-hopping ,s no-action},
[0086] Step (4.2) Defense strategy query: Call the query function according to the action to query whether this defense strategy exists in the defense strategy library S. If it exists, further parse the defense strategy to obtain the deployment target server, defense script and execution parameters. If it does not exist, parse the defense strategy to obtain the defense requirements, use LLM programming capabilities to write a new defense script, and compile it in real time to verify its executability.
[0087] Step (4.3) Defense strategy execution: The strategy execution module automatically deploys the defense script to the target server, automatically executes and deploys all subtasks on the target cloud network according to the specified parameters and execution priority, and achieves effective and efficient deployment.
[0088] Step (4.4) Defense strategy update: Update the newly created defense strategy strategy new Added to the defense strategy library, its defense action is action new = l, the number of defense strategies is updated to l = l + 1, and the defense strategy library is updated to S new ={s replica-increase ,s replica-reduction ,s replica-expansion ,s replica-scaling ,s port-hopping ,s no-action ,s new This allows for dynamic expansion of defense strategies to respond to emerging threats and improve protection capabilities.
[0089] Step 5: Effect evaluation and feedback. This paper evaluates the defense effect and reflects on the defense strategy based on the LLM reasoning and reflection ability, as follows:
[0090] Step (5.1) Security status assessment: After step (4) is completed, first determine whether the defense strategy is executed successfully, that is, success execute If the execution fails, get the reason for the failure.execute , used for LLM reflection to improve defense parameter selection, and then based on the service state after defense * Recalculate connection load factor Memory load rate and a list of hazardous containers LLM determines whether the current defense strategy successfully prevents attack traffic and ensures that the service is available, i.e. success. defense If the defense fails, the reason for the failure is obtained. defense , such as the connected load is too high,
[0091] Step (5.2) Evaluation of other indicators: Measure and evaluate the resource consumption cost and service delay generated after executing the defense strategy to measure the quality of the defense action.
[0092] Step (5.3) Defense strategy reflection: Regardless of whether the defense succeeds or fails, the current defense strategy and the above defense evaluation indicators are given to LLM for reflection, and the defense experience of this round is summarized by LLM.
[0093] Step (5.4) Reflection memory update: Finally, the defense strategy, defense evaluation index and defense experience are stored in the memory module for the next round of reasoning and defense, so that it can dynamically learn and improve the defense strategy in the feedback loop.
[0094] It should be noted that the above embodiments are not intended to limit the protection scope of the present invention, and equivalent changes or substitutions made on the basis of the above technical solutions all fall within the protection scope of the claims of the present invention.
Claims
1. A cloud-based intelligent active defense method based on a large language model, characterized by: The defense method comprises the following steps: Step (1): Data acquisition and reconstruction, Step (2): Status and hazard assessment, Step (3): Task reasoning and decision making, Step (4): Deployment and execution of defenses, Step (5): Effect evaluation and feedback.
2. The cloud-based intelligent active defense method based on a large language model according to claim 1 is characterized in that: Step (1): Data collection and reconstruction, specifically, using LLM as a data collector, designing collection and reconstruction tasks through prompt words, including collection time, callable tools, collection content, and output format, and then using LLM's function calling function or code writing ability to adaptively call the specified security tool to collect network data, and use LLM to aggregate and remove redundancy from the data, then extract key information from the data to generate a security briefing for the target network, and finally output the data to the specified output format. Step (2): Status and risk assessment, specifically as follows: First, LLM reads the data file obtained in step (1) and extracts the status information of the system hardware, network, and application, and models the system status matrix; secondly, LLM identifies potential threats based on the comparison of status data with historical normal status data, and quantifies the risk level according to the threat scope, impact, and duration; for cloud network failures caused by high-risk attacks, this module can use the existing status data to locate the fault, effectively identify the attack target, and use it for subsequent defense target generation; then, the system status matrix, risk level, fault source and other data are used as input for subsequent steps, Step (3): Task reasoning and decision-making, as follows: In advanced threat scenarios involving multiple defense targets, it is very important to clearly plan and reasonably divide defense tasks. This module uses a decomposition function to decompose the overall defense task into multiple independent subtasks, and uses LLM to set task goals and execution constraints for each subtask, and flexibly formulates defense strategies for each subtask; then, according to the risk level obtained in step (2) and the dependency relationship between subtasks, the execution priority is assigned to the subtask, and the defense preference is set through prompt words. On the basis of ensuring the success of defense, the defense resource loss is reduced and the user experience is maintained. The defense preference can be preset by the developer and dynamically adjusted during the implementation process; for each subtask, LLM understands the task goal and execution constraint, and gradually infers the defense action and defense effect, and solves the best defense strategy considering the defense preference. Step (4): Defense deployment and execution, specifically as follows: first, parse the defense strategy solved in step (3) to obtain the defense action; second, call the query function according to the defense action to query whether this defense strategy exists in the defense strategy library. If it exists, further parse the defense strategy to obtain the deployment target server, defense script and execution parameters. If it does not exist, parse the defense strategy to obtain the defense requirements, use the LLM programming ability to write a new defense script, and compile it in real time to verify its executability. After that, the strategy execution module automatically deploys the defense script to the target server and automatically executes all subtasks according to the specified parameters and execution priority; finally, add the newly created defense strategy to the defense strategy library, so as to achieve dynamic expansion of the defense strategy and meet flexible defense needs. Step (5): Effect evaluation and feedback. Specifically, after step (4) is completed, first determine whether the defense strategy is executed successfully. If it fails, obtain the reason for the failure for LLM to reflect on and improve the defense parameter selection; then determine whether this round of defense is successful based on the security indicators, and conduct a comprehensive evaluation of the defense effects such as recovery time, resource consumption, and service quality; finally, regardless of whether the defense succeeds or fails, give the current round of defense strategy and the above-mentioned defense evaluation indicators to LLM for reflection, obtain the defense experience summarized by LLM, and store the defense strategy, defense evaluation indicators and defense experience in the memory module for the next round of reasoning and defense, so that it can dynamically learn and improve the defense strategy in the feedback loop.
3. The cloud-based intelligent active defense method based on a large language model according to claim 1, characterized in that: The step 1: data collection and reconstruction, the specific process is as follows: Step (1.1) Collection task setting: Set the collection task for the LLM collector through prompt words, including collection time, callable tools, collection content, and output format. Step (1.2) Adaptive data collection: LLM can flexibly call the specified tool to complete the collection task on the target network through code writing capabilities. When a new collection tool needs to be expanded, it only needs to modify the prompt word to give LLM a new task prompt. Step (1.3) Data aggregation and redundancy removal: Use LLM to analyze the relationship between different data sources for aggregation and reorganization, and remove redundant and invalid data. Step (1.4) Extraction of key information: Input the collected data into LLM as text, use LLM's text understanding ability to extract key information and generate a security briefing for the target network. Step (1.5) Standard format output: LLM converts the processed data into the specified output format for storage and next step processing.
4. The cloud-based intelligent active defense method based on a large language model according to claim 1, characterized in that: The specific process of step 2: status and risk assessment is as follows: Step (2.1) Status information extraction: Read the data file output by step (1.5), and read the system status data from the specified fields, such as hardware status (power consumption), network status (network throughput), and application status (number of connections). Step (2.2) System state modeling: LLM models the current system state as a state matrix based on the state data obtained in step (2.1), reduces redundant information, and is used to derive the constraints of subsequent sub-defense tasks. Step (2.3) Hazard Assessment: LLM identifies potential threats and anomalies based on the comparison of the status data in (2.1) with the historical normal status data, and quantifies the risk level according to the scope, impact and duration of the threat, which can be used for the scheduling of subsequent sub-defense tasks. Step (2.4) Fault location: For cloud network failures caused by severe attacks, LLM uses status data to locate the fault, effectively identify the attack target and use it for subsequent defense target generation. Step (2.5) Information aggregation: Aggregate the results obtained in steps (2.2), (2.3) and (2.4) as input for subsequent steps.
5. The cloud-based intelligent active defense method based on a large language model according to claim 1 is characterized in that: The specific process of step 3: task reasoning and decision making is as follows: Step (3.1) Task decomposition: In a complex cloud environment, multiple threat points may appear, which requires achieving multiple defense goals simultaneously in a single overall task. Therefore, the overall task needs to be decomposed into multiple independent subtasks, and LLM is used to set task goals and execution constraints for each subtask. Step (3.2) Subtask priority assignment: Assign execution priorities to subtasks based on the risk levels and dependencies between subtasks obtained in step (2.3). Step (3.3) Set defense preferences: By setting defense preferences, LLM can take into account multiple factors such as reducing defense resources and ensuring user experience while achieving defense effects. These preferences can be preset by developers and dynamically adjusted during implementation. Step (3.4) Reasoning and decision-making: For each subtask, LLM obtains the task objectives and execution constraints set for it in step (3.1), performs step-by-step reasoning on the defense actions and defense effects, and solves the best defense strategy from the available defense strategies while considering the defense preferences set in step (3.2).
6. The cloud-based intelligent active defense method based on a large language model according to claim 1, characterized in that: The specific process of step 4: defense deployment and execution is as follows: Step (4.1) Defense strategy analysis: Analyze the defense strategy obtained in step (3.2) to obtain the defense action. Step (4.2) Defense strategy query: query the defense action obtained in step (4.1) in the defense strategy library. If it exists, further parse the defense strategy to obtain the deployment target server, defense script and execution parameters. If it does not exist, parse the defense strategy to obtain the defense requirements, use LLM programming capabilities to write a new defense script, and compile it in real time to verify its executability. Step (4.3) Defense strategy execution: The defense script obtained by query or created is combined with the specified defense parameters and execution priority to automatically execute and deploy all subtasks on the target cloud network to achieve automation and efficiency of deployment. Step (4.4) Defense strategy update: associate the newly created defense script with the defense action and put it into the defense strategy library to achieve self-update of the defense strategy library to respond to emerging threats and improve protection capabilities.
7. The cloud-based intelligent active defense method based on a large language model according to claim 1, characterized in that: The specific process of step 5: effect evaluation and feedback is as follows: Step (5.1) Security status assessment: First, determine whether the defense strategy is executed successfully. If it fails, obtain the reason for the failure for LLM to reflect on and improve the defense parameter selection. Then, determine whether the current round of defense is successful based on the security indicators. If it fails, the reason for the failure is also fed back to LLM. Step (5.2) Evaluation of other indicators: In addition to security indicators, it is also necessary to comprehensively evaluate the defense effects such as service recovery time, resource consumption generated by the specified defense strategy, and service quality to measure the quality of the defense actions. Step (5.3) Defense strategy reflection: Regardless of whether the defense is successful or not, the current defense strategy and the above defense evaluation indicators are given to LLM for reflection, and the defense experience of this round is summarized by LLM. Step (5.4) Reflection memory update: The defense strategy, defense evaluation index and defense experience are stored in the memory module for the next round of reasoning and defense, so that it can dynamically learn and improve the defense strategy in the feedback loop.
8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the cloud-based intelligent active defense method based on a large language model as described in any one of claims 1 to 7 above is implemented.
9. A computer-readable storage medium having computer instructions stored thereon, characterized in that: When the computer instruction is executed by the processor, the cloud-based intelligent active defense method based on a large language model as described in any one of claims 1-7 is implemented.
Citation Information
Patent Citations
Active defense method for containerized edge scene low-rate distributed denial of service attack
CN116032632A
Systems and methods for quantitative assessment of a computer defense technique
US20190173923A1
Cited By
Network security decision-making method and device based on large language model
CN120856385A