Security event processing method and system, computer equipment and storage medium
Through the voice command processing method, identity identification features are extracted and permissions are verified, and converted into text commands to input local large-scale models, solving the problems of low processing efficiency of massive logs and security risks in the existing technology, and achieving rapid and secure security incident handling.
Patent Information
- Application Number
- CN202510022386.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-07
- Publication Date
- 2025-05-13
AI Technical Summary
When existing network security protection systems process massive security logs and heterogeneous security devices, the threshold is high and the efficiency is low, and the identity verification method is difficult to continuously identify the operator's identity, which poses security risks.
Through the voice command processing method, voice commands are obtained and identity recognition features are extracted. After verifying user permissions, the voice commands are converted into text commands, and input local big model for standardization processing, triggering the corresponding security incident handling process.
It simplifies the operation process, improves the speed and efficiency of security incident handling, reduces the possibility of operational errors, enhances the security of the system, and realizes continuous identity and permission verification.
Smart Images

Figure CN119989318A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security protection technology, and in particular to a security incident processing technology. Background Art
[0002] A complete network security protection system often has a variety of heterogeneous network security devices, each of which generates a large number of network security logs. Network security protection personnel need to find related events in the massive logs of various security devices and handle corresponding problems by operating different interfaces. Situational awareness can already handle the problem of log correlation well, but the massive logs and the lack of unified operating standards have caused the security protection personnel to have a high threshold and low efficiency.
[0003] Since the handling of network security incidents has certain risks, it is necessary to accurately identify the identity and authority of specific operators. Currently, username and password methods or multi-factor authentication methods are usually used. This method is difficult to continuously identify the identity of the operator and poses a major security risk.
[0004] Existing solutions: Strengthen the identity authentication process through multi-factor authentication and limit the operator's permissions through permission grouping. Each security vendor has developed its own automated security incident handling tools, but generally requires all security devices to be of the same brand, which is not friendly to the environment of heterogeneous security products.
[0005] In addition, the handling of security incidents requires confirmation of the operator's identity. The current method is to confirm the operator's authority through account and password, and once the account and password are leaked, it may cause some uncontrollable consequences. Most of the improvement methods are to strengthen the strength of the account and password or add multi-factor authentication methods such as Ukey, but this authentication is not continuous and cannot verify the operator's identity in real time. Summary of the invention
[0006] To achieve the above-mentioned purpose, according to one aspect of the present application, some embodiments of the present application provide a security incident handling method, including: obtaining voice instructions and extracting identity recognition features in the voice instructions; verifying user authority based on the identity recognition features; after passing the user authority verification, converting the voice instructions into text instructions; converting the text instructions into standardized inputs and inputting them into a local large model; wherein, the local large model establishes a security incident knowledge base including multiple security incidents, and each security incident is respectively provided with a security incident handling process and a handling process triggering instruction; the standardized input is associated with the handling process triggering instruction to trigger the security incident handling process.
[0007] Optionally, the step of obtaining voice instructions includes: receiving voice instructions issued by the user through a language recognition module; performing preliminary noise filtering on the received voice instructions; digitizing the filtered voice instructions to form a digital voice signal; performing feature extraction on the digital voice signal to obtain a voice feature vector; comparing the voice feature vector with a pre-stored user identity feature vector; and determining the identity recognition feature in the voice instruction based on the comparison result.
[0008] Optionally, the step of verifying user authority based on the identity recognition feature includes: matching the extracted identity recognition feature with user authority information stored in the system; judging whether the user has authority to execute the voice command based on the matching result; if the user does not have authority, refusing to execute the voice command and giving corresponding prompt information.
[0009] Optionally, the step of converting the text instructions into standardized input includes: performing grammatical and semantic analysis on the text instructions to ensure that they conform to a preset input format; converting the analyzed text instructions into a standardized input format recognizable by the system; and matching the converted standardized input with the security event knowledge base in the local large model to determine the corresponding handling process.
[0010] Optionally, the step of associating the standardized input with the handling process trigger instruction includes: retrieving the corresponding handling process trigger instruction from the security incident knowledge base based on the matching result; associating the retrieved handling process trigger instruction with the standardized input; and triggering the security incident handling process corresponding to the standardized input through the association operation.
[0011] Optionally, the method also includes: pre-building and training a local big model, which includes: docking security devices and docking the security logs of the security devices to the log management system, extracting log information of each security log, and parsing it into a standard log; the log information includes: source IP, destination IP, port, event description and alarm level information; performing correlation analysis on each log source, aggregating the security logs of each security device through keywords of the log information; defining security events, establishing security event handling processes for various types of security events, and defining handling process trigger instructions; establishing a local knowledge base, importing the defined security event handling processes and handling process trigger instructions into the local knowledge base to train the local big model, and obtain a local security event knowledge base.
[0012] Optionally, the handling process of the triggered security incident includes: handling the security incident according to the defined security incident handling process and confirming the security incident handling result; archiving the handled security incident and the processing result and / or forming a security incident handling report.
[0013] On the other hand, the present application also provides a security event processing system, including:
[0014] An identity recognition module, used to obtain voice instructions and extract identity recognition features from the voice instructions; and verify user authority based on the identity recognition features;
[0015] A language recognition module, used to convert the voice command into a text command after passing the user authority verification;
[0016] A standard input module, used for converting the text instruction into a standardized input and then inputting it into a local large model; wherein the local large model is established with a security event knowledge base module including a plurality of security events, each of which is respectively provided with a security event handling process and a handling process triggering instruction;
[0017] The event handling module is used to associate the standardized input with the handling process triggering instruction to trigger the handling process of the security event.
[0018] In another aspect, the present application provides a computer device, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein:
[0019] The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can perform the security event processing method as described above.
[0020] The present application also provides a computer-readable storage medium storing a computer program, characterized in that when the computer program is executed by a processor, the security incident processing method as described above is implemented.
[0021] The beneficial effect of this solution is that the use of voice commands simplifies the operation process, making the handling of security incidents faster and more convenient. Users do not need to enter commands manually, thereby reducing the possibility of operational errors and improving work efficiency. The extraction of identity recognition features and the verification of user permissions ensure that only authorized personnel can perform the handling of security incidents, which greatly enhances the security of the system. Specifically, by extracting the operator's voiceprint features and binding the operator's permissions, the operator must issue instructions by voice when performing specific operations, realizing continuous identity and permission verification, which can better make up for the determination of existing technologies. In addition, the introduction of the local large model makes the handling process of security incidents more intelligent and automated. By associating the handling process to trigger instructions, the system can respond quickly and execute corresponding disposal measures, thereby shortening the disposal time. In addition, since the local large model contains a rich knowledge base of security events, it can accurately identify and classify various security events, ensuring the pertinence and effectiveness of the disposal measures. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] Figure 1 A flowchart of a security incident handling method provided in one embodiment of the present application;
[0023] Figure 2 A flowchart of a security incident handling method provided by another embodiment of the present application;
[0024] Figure 3 A schematic diagram of the structure of a security incident handling system provided in an embodiment of the present application;
[0025] Figure 4 A schematic diagram of the structure of a computer device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0026] In order to make the purpose, technical solution and advantages of the embodiments of the present application clearer, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0027] like Figure 1 As shown, the present application is an embodiment that provides a security incident processing method, including:
[0028] Step S101: Acquire a voice command and extract identity recognition features from the voice command;
[0029] Step S102: verifying the user authority according to the identity recognition feature; specifically, the relationship between the identity recognition feature and the authority needs to be bound in advance; specifically, the operator can be prompted to read a text, and the voiceprint feature of the user is extracted through a voiceprint feature extraction algorithm and input into a database; the user's voiceprint feature is bound to the user identity by connecting to the identity management system, and the user identity is bound to the user authority.
[0030] Step S103: after passing the user authority verification, converting the voice command into a text command;
[0031] Step S104: converting the text instruction into a standardized input and inputting it into a local big model; wherein the local big model establishes a security event knowledge base including a plurality of security events, and each security event is respectively provided with a security event handling process and a handling process triggering instruction;
[0032] Step S105: Associating the standardized input with the handling process triggering instruction to trigger the handling process of the security incident.
[0033] Step S106: automatically handle the event according to the defined event handling process, confirm the event handling result, and archive the event;
[0034] Step S107: Analyze and summarize the event archive information to form an event handling report.
[0035] According to another embodiment of the present application, the step of obtaining a voice instruction includes: receiving a voice instruction issued by a user through a language recognition module; performing preliminary noise filtering on the received voice instruction; digitizing the filtered voice instruction to form a digital voice signal; extracting features from the digital voice signal to obtain a voice feature vector; comparing the voice feature vector with a pre-stored user identity feature vector; and determining the identity recognition feature in the voice instruction based on the comparison result. Specifically, the identity recognition feature includes: voiceprint feature.
[0036] In this embodiment, in order to further improve the accuracy and efficiency of security incident processing, the security incident processing method further includes the following steps:
[0037] Step S108: In step S106, after the event is automatically handled, the system will automatically collect key data in the event handling process, including but not limited to handling time, handling steps, operator information, etc.; in addition, the system will also record the type of event, scope of impact, and possible subsequent impacts to ensure that the comprehensiveness and depth of event handling can be fully evaluated.
[0038] Step S109: Compare and analyze the collected key data with the historical event data to evaluate the effectiveness of the disposal process and the disposal efficiency of the operator; further, through machine learning algorithms, the system can identify potential problems and improvement points in the disposal process, providing a scientific basis for future process optimization.
[0039] Step S110: Based on the analysis results of step S109, dynamically adjust the handling process and trigger instructions in the security event knowledge base to optimize future event handling strategies; the system will update the knowledge base in real time based on the latest security threat trends and the processing effects of historical events to ensure the timeliness and adaptability of the handling strategy.
[0040] Step S111: Regularly conduct in-depth analysis of event handling reports to identify potential security risks and deficiencies in the handling process, and provide data support for the formulation of new security strategies; through periodic security audits and risk assessments, the system can promptly discover and resolve new security challenges, ensuring the foresight and effectiveness of the enterprise's security strategy.
[0041] Through these steps, the security incident handling method can not only achieve rapid response and automated disposal, but also improve the overall security management level and the ability to deal with emergencies through continuous learning and optimization. In addition, in order to enhance the security of the system and user experience, this embodiment also introduces the following innovations:
[0042] Before step S101, the system will first perform environmental noise detection to ensure that voice commands are received in a low-noise environment to avoid voice recognition errors caused by environmental noise interference; the system will also dynamically adjust the sensitivity of the voice recognition algorithm according to changes in environmental noise to adapt to different environmental conditions and ensure accurate recognition of voice commands.
[0043] In step S103, when converting voice instructions into text instructions, the system will also perform semantic understanding and verification on the text instructions to ensure that the converted text instructions accurately reflect the user's intentions and avoid erroneous operations caused by misunderstandings; the system uses natural language processing technology to conduct in-depth analysis of the context and semantics of the instructions to ensure the correct execution of the instructions.
[0044] In order to protect user privacy and data security, the system will encrypt, store and transmit all sensitive information during the processing process, and set strict access control to ensure that only authorized personnel can access relevant data; the system uses advanced encryption technology to encrypt data end-to-end to ensure the security of data during transmission and storage.
[0045] The system also has self-diagnosis and fault recovery functions, which can monitor the operating status in real time. Once an abnormality or fault is detected, it can automatically trigger the recovery mechanism to ensure the continuous and stable operation of the system. Through continuous health checks and self-repair mechanisms, the system can minimize downtime and improve system availability and reliability.
[0046] In summary, the security incident handling method provided in this embodiment not only has efficient and accurate incident handling capabilities, but also focuses on user privacy and data security, as well as system stability and self-healing capabilities, providing a comprehensive and reliable solution for enterprise security management.
[0047] In another embodiment, the step of obtaining the voice command further includes: prompting the user to perform identity authentication through the user interface before the user issues the voice command. Identity authentication can be performed by entering a password, scanning a fingerprint, facial recognition, or voiceprint recognition. Once the user's identity is verified, the system will allow the user to issue a voice command. In addition, the system can also limit the type of instructions that the user can issue based on the user's permission level to ensure that only users with corresponding permissions can perform specific operations.
[0048] In this embodiment, after receiving the voice command issued by the user through the language recognition module, the system will further process the voice command. First, the system will use the noise suppression algorithm to reduce the noise of the voice signal to improve the accuracy of voice recognition. Then, the system will perform feature extraction on the noise-reduced voice signal, extract the key information in the voice signal, and form a voice feature vector. These feature vectors will be used in the subsequent command recognition and identity authentication process.
[0049] During the identity authentication process, the system compares the extracted voice feature vector with the pre-stored user identity feature vector. The pre-stored user identity feature vector is collected and stored during the previous user registration, including voiceprint features, voice content features, etc. Through comparison, the system can accurately identify the identity recognition features in the voice command, thereby verifying the user's identity. If the identity authentication is successful, the system will allow the user to continue to execute the subsequent instruction processing flow (if the user has permission, the voice command will be converted into a text command.); if the identity authentication fails, the system will prompt the user to re-authenticate or refuse to execute the command.
[0050] In order to further enhance the security of the system, this embodiment introduces a dynamic password. When the user authenticates the user, a one-time dynamic password is generated when the voice feature vector is compared, and the user is prompted to enter it through the user interface. This dynamic password will become invalid in a short time, ensuring that even if the voice feature vector is illegally intercepted, unauthorized users cannot pass the verification. In addition, the system can also dynamically adjust the strictness of identity authentication based on the user's behavior patterns and historical data. For example, for accounts with frequent login failures, the system can add additional verification steps, such as secondary verification or increase waiting time, thereby effectively preventing malicious attacks and unauthorized access.
[0051] In summary, this embodiment provides a more secure and accurate voice command processing method. By combining identity authentication and voice feature extraction technology, the system can effectively identify the user identity and ensure the security of voice commands. In addition, by limiting the scope of command execution for users with different permissions, the system further enhances the security of operations and prevents unauthorized operations from occurring.
[0052] According to another embodiment of the present application, the step of verifying user authority according to the identity recognition feature includes:
[0053] Match the extracted identity recognition features with the user authority information stored in the system;
[0054] Determining whether the user has the authority to execute the voice command based on the matching result;
[0055] If the user does not have permission, the voice command will be rejected and a corresponding prompt message will be given.
[0056] In this embodiment, in order to further enhance the flexibility of the system and user experience, an adaptive learning mechanism is introduced to automatically adjust the permission settings based on the user's historical operation records and feedback to adapt to the user's actual needs. For example, if the system detects that a user frequently executes specific voice commands, the system can automatically reduce the permission level of these commands, thereby reducing the user's verification steps when executing these commands and improving operational efficiency. At the same time, the system can also identify abnormal behavior patterns, such as frequent permission request failures, which may be a sign of unauthorized access, and the system will automatically trigger a higher level of security checks to ensure the security of the system.
[0057] In addition, this embodiment also considers the permission management in a multi-user environment. In the scenario where multiple users share the same device, the system distinguishes different users based on their voiceprint characteristics and assigns an independent permission profile to each user. In this way, when each user uses the device, the system can provide personalized permission control to ensure that the user can only access the instructions and data for which he is authorized, thereby protecting user privacy and data security.
[0058] In summary, this embodiment provides a more secure, flexible and user-friendly voice command processing system by introducing dynamic passwords, adaptive learning mechanisms and multi-user authority management.
[0059] In a further embodiment, the system may also record detailed information of each identity verification, including verification time, verification results, and instructions executed by the user, etc., to facilitate subsequent security auditing and analysis.
[0060] In addition, in order to improve the flexibility of the system and user experience, the system can also provide personalized services according to the user's authority level. For example, for users with advanced permissions, the system can provide richer function options and faster response speed.
[0061] In order to ensure the stability and reliability of the system, this embodiment also involves the design of a fault-tolerant mechanism. When the system detects an abnormal situation, such as multiple consecutive identity authentication failures, the system will automatically start the safe mode, limit or suspend the user's operating authority, and notify the administrator to check.
[0062] Finally, this embodiment also takes into account the scalability of the system. With the development of technology and changes in user needs, the system can easily add new identity authentication methods and rights management strategies to adapt to the ever-changing security needs.
[0063] According to another embodiment of the present application, the step of converting the text instruction into a standardized input includes: performing grammatical and semantic analysis on the text instruction to ensure that it conforms to a preset input format; converting the analyzed text instruction into a standardized input format that the system can recognize; matching the converted standardized input with the security event knowledge base in the local large model to determine the corresponding handling process. The local large model can include two types of models. One is to use the open source model for fine-tuning. Since it is a general large model, this type of model will require slightly more resources; the other is to start from scratch and build a "small model". This type of model consumes very little resources and is all security-related data, which may be only a dozen M in size.
[0064] In practical applications, this standardized input conversion method based on text instructions can significantly improve the efficiency and accuracy of security incident handling. For example, when the system receives the text instruction "block IP address", through grammatical and semantic analysis, the system can recognize that this is a security disposal instruction and convert it into a standardized input format. Subsequently, the system will match this standardized input with the security incident knowledge base in the local large model to determine the specific disposal process, such as finding the relevant IP address and performing the blocking operation.
[0065] In addition, using a local large model for matching can effectively reduce dependence on cloud resources, especially when processing sensitive data, and can better protect user privacy. For general large models with high resource consumption, fine-tuning can be used to make them more suitable for specific security incident processing needs. For "small models" with low resource consumption, they can be quickly deployed on various devices to achieve immediate security incident response.
[0066] In summary, by converting text instructions into standardized inputs and matching them with the local large model, this embodiment not only improves the efficiency of security event processing, but also enhances the flexibility and scalability of the system, while ensuring the security and reliability of the processing process.
[0067] According to another embodiment of the present application, the step of associating the standardized input with the treatment process trigger instruction includes:
[0068] According to the matching results, the corresponding handling process triggering instructions are retrieved from the security event knowledge base;
[0069] Associating the retrieved disposal process trigger instructions with the standardized input;
[0070] Through the association operation, a security incident handling process corresponding to the standardized input is triggered.
[0071] like Figure 2 As shown, according to another embodiment of the present application, the method further includes: pre-building and training a local large model, which includes:
[0072] Step S201: Connect the security device and connect the security log of the security device to the log management system, extract the log information of each security log, and parse it into a standard log; the log information includes: source IP, destination IP, port, event description and alarm level information; receive the log of each device through the standard SYSLOG protocol, each manufacturer's log rules are different, and log parsing is required, using the parsing engine in the log audit system to extract the source IP, destination IP, port, event description, alarm level, etc. Finally, it is also parsed into a standard SYSLOG log.
[0073] After completing the extraction and parsing of log information, the security event processing system will further analyze and process these standardized log information. First, the system will use the preset rule engine to classify and preliminarily analyze the logs to identify potential security events. These rules may include abnormal traffic detection, intrusion behavior identification, malware propagation, etc. In this way, the system can quickly screen out security events that need attention.
[0074] Next, the system will match the extracted security event information with the security event knowledge base in the local large model. This knowledge base contains a large number of known security event cases and corresponding handling processes. Through matching, the system can determine the type of each security event and find the corresponding handling process trigger instructions. For example, if an intrusion attempt is detected, the system will find a matching handling process, such as immediately blocking the relevant IP address, notifying the administrator, etc.
[0075] In order to improve processing efficiency and accuracy, the system also has the ability to learn and self-optimize. Through machine learning algorithms, the system can continuously adjust and optimize the rule engine and knowledge base based on historical data and processing results. In this way, over time, the system's identification and handling of security incidents will become more accurate and efficient.
[0076] Finally, the security incident handling system will record the processing results in the log management system to provide data support for future security analysis and auditing. These records include not only detailed information about the security incident, but also the disposal measures taken by the system and the feedback on the results. In this way, administrators can monitor the security status in real time and make long-term security strategy plans based on historical data.
[0077] When connecting to various security devices, if the connecting device can provide an API interface (such as telnet, ssh, RESTfulAPI, Web API, database API, etc.), we will complete the device connection according to the API interface specification. If the connecting device cannot provide an interface or the cost of providing an interface is too high, RPA (http / https simulated request) is used to complete the device connection. This application connects all security devices through interface connection and RPA, solves the problem of heterogeneous device connection, and adapts to all security management environments.
[0078] Step S202: Perform correlation analysis on each log source, and aggregate the security logs of each security device through the keywords of the log information; the purpose of correlation is to integrate the logs of each device together, which is helpful for comprehensive analysis of security events. The content of correlation is the security logs of each device, and the logs are aggregated through keywords such as source IP, destination IP, timestamp, etc.
[0079] Through correlation analysis, the system can identify potential security threat patterns and abnormal behaviors. For example, when the same source IP address appears in the logs of multiple devices, and the time interval between these log records is very short, the system can infer that this may be the same attacker conducting a distributed denial of service (DDoS) attack. In addition, by comparing timestamps, the order of events can be determined, thereby helping administrators reconstruct the process of events and providing a basis for subsequent investigations and evidence collection. The system can also identify the target range of the attack based on the aggregate analysis of the destination IP address, thereby focusing on protecting key assets. Through these aggregate and correlation analyses, the security event processing system not only improves the response speed to security threats, but also enhances the ability to predict and prevent security incidents.
[0080] Step S203: define security events, establish security event handling procedures for various security events, and define handling procedure triggering instructions; currently defined security events include: external network attack events, illegal external connection events of intranet compromised hosts, lateral attack events of intranet hosts, zombie worm (e.g., ransomware, etc.) events, vulnerability handling events, tracking suyuan events, etc. The security event handling process is as follows: for example, the external network attack handling method is to execute the IP ban; the intranet lateral attack handling method needs to first determine how the intranet IP is connected to the network. If it is authentication, the account is banned in the authentication system. If it is the Internet of Things, the ACL is banned through the linkage switch.
[0081] On the basis of defining security incidents, further refine the handling process to ensure that each step has clear execution standards and responsible persons. For example, for external network attack incidents, in addition to blocking IP addresses, it should also include tracking and analysis of the attack source, as well as rapid isolation and repair of affected systems. For illegal external connection incidents of compromised hosts on the intranet, in addition to account blocking, terminal security protection measures should be strengthened, such as regularly updating antivirus software and operating system patches, and implementing stricter access control policies. For lateral attack incidents on intranet hosts, in addition to linking switches to perform ACL blocking, network monitoring should be strengthened to promptly detect and respond to abnormal traffic.
[0082] Step S204: Establish a local knowledge base, import the defined security incident handling process and handling process triggering instructions into the local knowledge base to train the local large model, and obtain a local security incident knowledge base.
[0083] Specifically, the local knowledge base contains user private information, which is stored in the knowledge base in the form of questions and answers (data structure).
[0084] Import process example: According to the defined content, enter the questions and answers into the database table, for example: Q: How to enable SSH service on Deep Firewall; A: By executing the ssh enable command.
[0085] Taking IP blocking as an example, the issues involved include: 1. Determine whether the IP to be blocked is in the whitelist; 2. Determine whether the IP to be blocked has been blocked; 3. Block the IP on the specified device; 4. Determine whether the blocking is successful; each corresponding answer is a SQL query statement.
[0086] During the training process, the training data mainly includes public vulnerability libraries, intelligence libraries, papers, textbooks, attack and defense cases, security equipment operation manuals, etc. related to network security.
[0087] The training methods mainly include pre-training and instruction training. Public vulnerability libraries, intelligence libraries, papers, textbooks, attack and defense cases, security equipment operation manuals, etc. are used as inputs for the big model. The output is the trained model. The training process includes:
[0088] During training, first, historical security event data is collected, including but not limited to log information, disposal records, and security event reports, as well as public vulnerability libraries, intelligence libraries, papers, textbooks, attack and defense cases, and security equipment operation manuals related to network security. Then, these data are cleaned and preprocessed to ensure data quality for subsequent model training.
[0089] Secondly, according to the type and characteristics of security events, design corresponding feature extraction algorithms to convert data into the format required for model training. Feature extraction is a key step that directly affects the performance and accuracy of the model.
[0090] Next, select a suitable machine learning algorithm or deep learning model, such as decision tree, random forest, neural network, etc., and train the model according to the security incident handling process and trigger instructions in the local knowledge base.
[0091] During the model training process, it is necessary to continuously adjust parameters and optimize algorithms to improve the generalization ability and accuracy of the model. Through cross-validation and other techniques, the performance of the model is evaluated, and iterative optimization is performed based on the evaluation results.
[0092] Finally, the trained model is deployed to the local environment for real-time or regular security incident analysis and disposal. At the same time, a feedback mechanism is established to continuously adjust and optimize the model based on the actual disposal effect to ensure the timeliness and effectiveness of the local security incident knowledge base.
[0093] The specific training process can be achieved through existing technologies and will not be elaborated on here.
[0094] As an optional embodiment, the handling process of triggering a security event includes:
[0095] Handle security incidents according to the defined security incident handling process
[0096] Confirm the results of security incident handling;
[0097] The handled security incidents and handling results shall be archived and / or a security incident handling report shall be generated.
[0098] As an optional embodiment, security events are monitored in real time, and when a new security event is detected, the corresponding security event handling process is automatically triggered.
[0099] Real-time monitoring of security events, including: receiving security logs from security devices in real time through the log management system;
[0100] Analyze security logs received in real time to identify new security events;
[0101] Automatically match the security incident handling process predefined in the local knowledge base based on the identified new security incidents;
[0102] Execute the handling process corresponding to the new security incident, including but not limited to isolating the attack source, blocking the attack port, notifying the administrator, etc.
[0103] As an optional embodiment, the method further includes: evaluating the effectiveness of the executed security incident handling process, and optimizing the local knowledge base according to the evaluation result.
[0104] Evaluate the effectiveness of the security incident handling process, including: collecting security log information after the handling process is executed;
[0105] Analyze security log information and evaluate the effectiveness of the disposal process;
[0106] Adjust and optimize the security incident handling process in the local knowledge base based on the assessment results;
[0107] Through continuous optimization, the local large model's ability to identify and handle security incidents will be improved.
[0108] like Figure 3 As shown, another embodiment of the present application further provides a security event processing system, including:
[0109] An identity recognition module, used to obtain voice instructions and extract identity recognition features from the voice instructions; and verify user authority based on the identity recognition features;
[0110] A language recognition module, used to convert the voice command into a text command after passing the user authority verification;
[0111] A standard input module, used for converting the text instruction into a standardized input and then inputting it into a local large model; wherein the local large model is established with a security event knowledge base module including a plurality of security events, each of which is respectively provided with a security event handling process and a handling process triggering instruction;
[0112] The event handling module is used to associate the standardized input with the handling process triggering instruction to trigger the handling process of the security event.
[0113] The archiving module automatically handles events according to the defined event handling process, confirms the event handling results, and archives the events.
[0114] The report module performs data analysis and summary on event archive information to form an event handling report.
[0115] For the specific definition of the security incident handling system, please refer to the definition of the security incident handling method above, which will not be repeated here. Each module / unit in the above-mentioned security incident handling system can be implemented in whole or in part by software, hardware and a combination thereof. The above-mentioned modules / units can be embedded in or independent of the processor in the computer device in the form of hardware, or can be stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above modules.
[0116] The present application also provides a computer device, comprising: at least one processor; and
[0117] A memory communicatively connected to the at least one processor; wherein the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can perform the method as described above.
[0118] like Figure 4 As shown, as an example: the computer device specifically includes a memory, a processor, a user interface, a communication interface and a bus. Among them, the memory, the processor, the user interface and the communication interface are connected to each other through the bus.
[0119] In addition, the user interface may include a display screen (Display), a keyboard (Keyboard), and the optional user interface may also include a standard wired interface and a wireless interface. The communication interface may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface).
[0120] The memory may be a read-only memory (ROM), a static storage device, a dynamic storage device or a random access memory (RAM). The memory may store a program, and when the program stored in the memory is executed by the processor, the processor 1001 and the communication interface are used to execute the various steps of the security event processing method of the embodiment of the present application.
[0121] The processor can be a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), a graphics processing unit (GPU) or one or more integrated circuits to execute relevant programs to implement the functions required to be performed by the units in the computer device described in the above embodiments, or to execute the various steps of the security event processing method of the embodiments of the present application.
[0122] The processor may also be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the security event processing method of the embodiment of the present application can be completed by the hardware integrated logic circuit or software instructions in the processor. The above-mentioned processor may also be a general-purpose processor, a digital signal processor (Digital Signal Processing, DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (Field Programmable Gate Array, FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components. The disclosed methods, steps and logic block diagrams in the embodiments of the present application can be implemented or executed. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The various steps of the security event processing method in combination with the embodiment of the present application can be directly embodied as a hardware decoding processor to be executed, or a combination of hardware and software modules in the decoding processor to be executed. The software module may be located in a mature storage medium in the field such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the functions required to be performed by the units included in the computer device described in the above embodiments, or executes the various steps of the security incident handling method of the embodiments of the present application.
[0123] The communication interface uses a transceiver such as, but not limited to, a transceiver to implement communication between the computer device and other devices or communication networks. For example, network security event information and security-related information data, such as security logs of other security devices, can be obtained through the communication interface.
[0124] A bus may include a path that transfers information between various components of a computer device (eg, memory, processor, user interface, communication interface).
[0125] It should be noted that although the computer device shown in the figure only shows a memory, a processor, a user interface, and a communication interface, in the specific implementation process, those skilled in the art should understand that the computer device also includes other devices necessary for normal operation. At the same time, according to specific needs, those skilled in the art should understand that the computer device may also include hardware devices that implement other additional functions. In addition, those skilled in the art should understand that the computer device may also only include the devices necessary to implement the embodiments of the present application, and does not necessarily include all the devices shown in the figure.
[0126] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0127] In the several embodiments provided in the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0128] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0129] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0130] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application can be essentially or partly embodied in the form of a computer program product that contributes to the prior art, and the computer program product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0131] An embodiment of the present application also provides a chip, which includes a processor and a data interface. The processor reads instructions stored in a memory through the data interface to execute a security event processing method.
[0132] Optionally, as an implementation, the chip system includes a processor for supporting a computer device (client or server) to implement the functions of the controller involved in the above method, such as processing the data and / or information involved in the above method. In one possible design, the chip system also includes a memory for storing necessary program instructions and data. The chip system can be composed of a chip or a chip and other discrete devices.
[0133] In another possible design, when the chip system is a chip in a user device or access network, the chip includes: a processing unit and a communication unit. The processing unit may be, for example, a processor, and the communication unit may be, for example, an input / output interface, a pin or a circuit. The processing unit may execute computer-executable instructions stored in the storage unit so that the chip in the client or management server may perform the steps of the common sense question answering method. Optionally, the storage unit is a storage unit in the chip, such as a register, a cache, etc. The storage unit may also be a storage unit located outside the chip in the client or management server, such as a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM), etc.
[0134] It should be understood that the methods and / or embodiments in the embodiments of the present application can be implemented as computer software programs. For example, the embodiments of the present disclosure include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes program code for executing the method shown in the flowchart. When the computer program is executed by the processing unit, the above functions defined in the method of the present application are executed.
[0135] It should be understood that the controller or processor mentioned in the above embodiments of the present application may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or the processor may be any conventional processor, etc.
[0136] It should also be understood that the number of processors or controllers in the computer device or chip system in the above embodiments of the present application can be one or more, and can be adjusted according to the actual application scenario. This is only an exemplary description and is not limited. The number of memories in the embodiments of the present application can be one or more, and can be adjusted according to the actual application scenario. This is only an exemplary description and is not limited.
[0137] Optionally, the present application also provides a computer-readable storage medium storing a computer program, wherein the computer program implements the above-mentioned security incident method when executed by a processor.
[0138] It should be noted that the computer-readable medium described in the present application may be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, a computer-readable medium may be any tangible medium containing or storing a program that can be used by or in combination with an instruction execution system, device or device.
[0139] In the present application, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries a computer-readable program code. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, device, or device. The program code contained on the computer-readable medium may be transmitted using any suitable medium, including but not limited to: wireless, wire, optical cable, RF, etc., or any suitable combination of the above.
[0140] Computer program code for performing the operations of the present application may be written in one or more programming languages or a combination thereof, including object-oriented programming languages, such as Java, Smalltalk, C++, and conventional procedural programming languages, such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0141] The flow chart or block diagram in the accompanying drawings shows the possible architecture, function and operation of the equipment, method and computer program product according to various embodiments of the present application. In this regard, each square box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some implementations as replacements, the functions marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two square boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be implemented with a dedicated system for hardware that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0142] As another aspect, the embodiments of the present application further provide a computer-readable medium, which may be included in the device described in the above embodiments; or may exist independently without being assembled into the device. The above computer-readable medium carries one or more computer-readable instructions, which may be executed by a processor to implement the steps of the methods and / or technical solutions of the above-mentioned multiple embodiments of the present application. The computer may be the above-mentioned computer device (client or server or other computer network communication device).
[0143] In a typical configuration of the present application, the terminal and the equipment of the service network each include one or more processors (CPU), input / output interface, network interface and memory.
[0144] The memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0145] Computer readable media include permanent and non-permanent, removable and non-removable media, and can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, modules of programs or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, read-only compact disk (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage or other magnetic storage devices or any other non-transmission medium that can be used to store information that can be accessed by a computing device.
[0146] In addition, an embodiment of the present application further provides a computer program, which is stored in a computer device, so that the computer device executes the method for controlling code execution.
[0147] It should be noted that the present application can be implemented in software and / or a combination of software and hardware, for example, can be implemented using an application specific integrated circuit (ASIC), a general purpose computer or any other similar hardware device. In certain embodiments, the software program of the present application can be executed by a processor to implement the above steps or functions. Similarly, the software program of the present application (including related data structures) can be stored in a computer-readable recording medium, for example, a RAM memory, a magnetic or optical drive or a floppy disk and similar devices. In addition, some steps or functions of the present application can be implemented using hardware, for example, as a circuit that cooperates with a processor to perform each step or function.
[0148] It is obvious to those skilled in the art that the present application is not limited to the details of the above exemplary embodiments, and that the present application can be implemented in other specific forms without departing from the spirit or basic features of the present application. Therefore, from any point of view, the embodiments should be regarded as exemplary and non-restrictive, and the scope of the present application is defined by the attached claims rather than the above description, and it is intended that all changes falling within the meaning and scope of the equivalent elements of the claims are included in the present application. Any figure mark in the claims should not be regarded as limiting the claims involved. In addition, the terms used in the embodiments of the present application are for the purpose of describing specific embodiments only and are not intended to limit the present invention.
[0149] It should be noted that the terms "first", "second", etc. in the specification and claims of this application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the invention described herein can be implemented in an order other than those illustrated or described herein. The singular forms "a", "an", and "the" used in the embodiments of the present application are also intended to include the plural forms, unless the context clearly indicates otherwise.
[0150] In addition, the terms "comprises," "comprising," and "having," and any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus that includes a series of steps or elements is not necessarily limited to those steps or elements explicitly listed, but may include other steps or elements not explicitly listed or inherent to such process, method, product, or apparatus.
[0151] In the description of the present application, unless otherwise specified, " / " indicates that the objects associated before and after are in an "or" relationship, for example, A / B can represent A or B; "and / or" in the present application is only a kind of association relationship describing the associated objects, indicating that there can be three relationships, for example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. Depending on the context, the words "if" or "if" as used herein can be interpreted as "at the time of" or "when" or "in response to determination" or "in response to detection". Similarly, depending on the context, the phrases "if it is determined" or "if (stated condition or event) is detected" can be interpreted as "when determined" or "in response to determination" or "when (stated condition or event) is detected" or "in response to detection (stated condition or event)".
[0152] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, a person of ordinary skill in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features thereof may be replaced by equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the scope of the technical solutions of the embodiments of the present application.
Claims
1. A security incident processing method, characterized in that: include: Acquire voice commands and extract identity recognition features from the voice commands; Verifying user authority based on the identity recognition feature; After passing the user authority verification, converting the voice command into a text command; The text instructions are converted into standardized input and then input into a local large model; wherein the local large model is established with a security event knowledge base including multiple security events, and each security event is respectively provided with a security event handling process and a handling process triggering instruction; The standardized input is associated with the handling process triggering instruction to trigger the handling process of the security event.
2. The method according to claim 1, characterized in that: The step of obtaining the voice command comprises: Receiving a voice command issued by a user through a language recognition module; Perform preliminary noise filtering on the received voice commands; Digitally convert the filtered voice commands to form digital voice signals; Extracting features from the digital speech signal to obtain a speech feature vector; Comparing the speech feature vector with a pre-stored user identity feature vector; The identity recognition feature in the voice instruction is determined according to the comparison result.
3. The method according to claim 1, characterized in that: The step of verifying the user's authority according to the identity recognition feature comprises: Match the extracted identity recognition features with the user authority information stored in the system; Determining whether the user has the authority to execute the voice command based on the matching result; If the user does not have permission, the voice command will be refused to execute and a corresponding prompt message will be given; If the user has permission, the voice command is converted into a text command.
4. The method according to claim 1, characterized in that: The step of converting the text instruction into a standardized input comprises: Performing grammatical and semantic analysis on the text instruction to ensure that it complies with a preset input format; Convert the analyzed text instructions into a standardized input format that the system can recognize; The converted standardized input is matched with the security event knowledge base in the local large model to determine the corresponding handling process.
5. The method according to claim 1, characterized in that: The step of associating the standardized input to the treatment process trigger instruction comprises: According to the matching results, the corresponding handling process triggering instructions are retrieved from the security event knowledge base; Associating the retrieved disposal process trigger instructions with the standardized input; Through the association operation, a security incident handling process corresponding to the standardized input is triggered.
6. The method according to claim 1, characterized in that The method further includes: pre-building and training a local large model, which includes: Connect security devices and connect security logs of security devices to log management system, extract log information of each security log, and parse it into standard log; the log information includes: source IP, destination IP, port, event description and alarm level information; Perform correlation analysis on each log source, and aggregate the security logs of each security device by using the keywords of the log information; Define security incidents, establish security incident handling processes for various security incidents, and define handling process trigger instructions; Establish a local knowledge base, import the defined security incident handling process and handling process trigger instructions into the local knowledge base to train the local large model, and obtain a local security incident knowledge base.
7. The method according to claim 1, characterized in that The handling process of triggering a security incident includes: Handle security incidents according to the defined security incident handling process Confirm the results of security incident handling; The handled security incidents and handling results shall be archived and / or a security incident handling report shall be generated.
8. A security incident processing system, characterized in that: include: An identity recognition module, used to obtain voice instructions and extract identity recognition features from the voice instructions; and verifying user authority based on the identity identification features; A language recognition module, used to convert the voice command into a text command after passing the user authority verification; A standard input module, used for converting the text instruction into a standardized input and then inputting it into a local large model; wherein the local large model is established with a security event knowledge base module including a plurality of security events, each of which is respectively provided with a security event handling process and a handling process triggering instruction; The event handling module is used to associate the standardized input with the handling process triggering instruction to trigger the handling process of the security event.
9. A computer device, characterized in that: The computer device comprises: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can perform the method according to any one of claims 1 to 7.
10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.
Citation Information
Cited By
Situation awareness method based on RAG and decision tree algorithm
CN120528715A