Large model-based security orchestration script generation method and system
Through the secure choreography script generation method based on the big model, a script candidate collection is constructed and scripts that meet the security script constraints are generated, which solves the problem of limited response capabilities in the face of new security risks in the existing technology, and achieves a more adaptable secure choreography script generation.
Patent Information
- Application Number
- CN202510043014.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-10
- Publication Date
- 2025-05-16
AI Technical Summary
When the existing technology faces new security risks with no historical experience or expert templates, its response capabilities are limited and it is difficult to generate security choreography scripts that adapt to new security scenarios.
A safe choreography script generation method based on large models is adopted to build a script candidate set, obtain the script candidates with the highest similarity to the abstract to be arranged, and generate a safe choreography script based on the abstract to be arranged and a security script constraint.
When facing new security scenarios without corresponding expert templates, more adaptable security choreography scripts can be generated, improving the ability to respond to new security risks.
Smart Images

Figure CN120012920A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a method and system for generating a security orchestration script based on a large model. Background Art
[0002] With the continuous iteration of network attack technology, attack methods such as distributed attacks, ransomware, and phishing are gradually turning to automation. However, many companies have limited investment in the construction and operation of information security, so there are often problems such as insufficient operators and low operational efficiency. In order to solve the above problems, researchers have proposed security orchestration technology, which is to pre-orchestrated the security scheduling plan process for possible security incidents. The security orchestration script is the blueprint for the security scheduling plan. The generation of the security orchestration script is a long text generation task, which is to take the summary of the security information to be orchestrated as input, and finally generate a security orchestration script that meets the requirements.
[0003] Traditional security script generation methods are based on existing expert templates or past cases, and have limited response capabilities and lack of initiative when facing new risks for which there is no historical experience or expert template. The emergence of large language models provides new ideas for the generation algorithm of security orchestration scripts. Through the learning of security knowledge, the understanding of security atomic capability knowledge, and the demonstration of existing scenario expert scripts, large language models can show better adaptability than other generation algorithms through their generalization ability when facing new security scenarios for which there are no corresponding expert templates. Summary of the invention
[0004] The present invention provides a method and system for generating a security orchestration script based on a large model, which can provide a more adaptable security script in the face of a new security scenario for which there is no corresponding expert template.
[0005] To achieve the above objectives, the technical solution of the present invention includes the following contents.
[0006] A method for generating a security orchestration script based on a large model, the method comprising:
[0007] Based on the security script library, a script candidate set is constructed, each script candidate in the script candidate set includes: a security summary a p and the expert safety playbook for this safety brief p ;
[0008] In the script candidate set, n script candidates i with the highest similarity to the summary to be arranged are obtained, and a safe arrangement script is generated based on the summary to be arranged, the safe script constraint and the script candidate i. The security script constraints include: format constraints, organization constraints and natural language constraints;
[0009] In n security orchestration playbooks Output the corresponding security orchestration script when the consistency requirements are met
[0010] Furthermore, the construction of a script candidate set based on the security script library includes:
[0011] Take a security summary a from the security script library p and the security summary a p Corresponding expert safety scriptm p ;
[0012] According to the security summary p Generate prompt word z p , and the prompt word z p Input into the large model to obtain the output result r p ;
[0013] Calculate the output result r p and expert safety scripts p The similarity S p , and at the similarity S p If the security summary a is not less than the first set threshold, p And the expert safety scriptm p As a script candidate, it is added to the script candidate set.
[0014] Furthermore, in the script candidate set, n script candidates i with the highest similarity to the summary to be arranged are obtained, including:
[0015] Get the summary to be compiled and the security summary a p The specific type of data includes: time type data, text type data, value type data and object type data;
[0016] Calculate the similarity between each specific type of data respectively;
[0017] The similarity is weighted according to the weight of each specific type to obtain the summary to be compiled and the security summary a p The overall similarity between
[0018] Based on the overall similarity, n script candidates are selected from the script candidate set.
[0019] Furthermore, based on the summary to be arranged, the security script constraints and the script candidate i, a security orchestration script is generated include:
[0020] According to the summary to be arranged, the safety script constraints and the script candidate i are embedded into the safety orchestration script template, the context generation prompt words are generated
[0021] Generate prompt words from context Embedded into the security orchestration script generation template, and obtain the security orchestration script based on the big model
[0022] Furthermore, in n security orchestration scripts Output the corresponding security orchestration script when the consistency requirements are met include:
[0023] Computational Security Orchestration Playbook The consistency between them is calculated, and the security orchestration script with the largest number of consistency is output. Among them, in any two security orchestration scripts If none of them are consistent, the output security orchestration script generation fails.
[0024] Furthermore, the format constraints include:
[0025] The security orchestration script must contain a start node and an end node;
[0026] The starting node exists and only exists once, and can only point to other nodes;
[0027] The end node exists and only exists once, and can only be pointed to by other nodes;
[0028] The security orchestration script cannot have nodes with zero in- and out-degrees.
[0029] All nodes in the security orchestration script must be on a path starting from the start node and ending at the end node;
[0030] The conditional branches in the security orchestration script must ensure that each branch can be connected to the end node;
[0031] A coverage constraint, wherein the coverage constraint means that the successor nodes of a branch node need to cover all branch conditions of the branch node;
[0032] The organizational constraints include:
[0033] When the relationship between two security atomic capabilities in the security orchestration script is a serial relationship, the two security atomic capabilities are required to be executed at the same time or not executed at the same time, and when executed at the same time, they must be executed in a predefined sequence;
[0034] When the relationship between two security atomic capabilities in the security orchestration script is a parallel relationship, the execution of the two security atomic capabilities is independent of each other;
[0035] When the relationship between two security atomic capabilities in the security orchestration script is a branch relationship, it is required that the two security atomic capabilities can only execute one of the security atomic capabilities;
[0036] The natural language constraints include:
[0037] The large model has the ability to understand natural language and incorporates natural language constraints and expert knowledge into the prompt words.
[0038] Furthermore, the output corresponds to the security orchestration script After that, it also includes:
[0039] Convert the security orchestration script into a directed acyclic graph G, and check the satisfaction of other format constraints except the coverage constraint based on the in-degree and out-degree of each node;
[0040] Add the starting node to an empty queue;
[0041] Start a breadth-first search from the starting node in the directed acyclic graph G to obtain the coverage constraint satisfaction of the security orchestration script;
[0042] The format constraint satisfaction of the security orchestration script is obtained by combining the satisfaction of other format constraints except the coverage constraint and the satisfaction of the coverage constraint;
[0043] Traversing the security orchestration script based on the organizational constraint to obtain the organizational constraint satisfaction of the security orchestration script;
[0044] Based on the large language model, obtain the natural language constraint satisfaction of the security orchestration script;
[0045] The constraint satisfaction of the security orchestration script is obtained by integrating the format constraint satisfaction, the organization constraint satisfaction and the natural language constraint satisfaction; the attribute coverage is calculated according to the summary security atomic capability key-value pair set, the script security atomic capability set and the script security atomic capability key-value pair set;
[0046] Based on the weighted sum of the attribute coverage and the constraint satisfaction, an evaluation of the security orchestration script is obtained.
[0047] Furthermore, the breadth-first search is started from the starting node in the directed acyclic graph G to obtain the coverage constraint satisfaction of the security orchestration script, including:
[0048] Start breadth-first search from the starting node in the directed acyclic graph G, and take out the current head of the queue, cur_node;
[0049] Calculate whether the coverage constraint of the current team head cur_node is violated; if the current team head cur_node is a branch path and the successor node cannot cover all branch conditions, the coverage constraint is violated;
[0050] Add the security atomic capability and security atomic capability key-value pair of the current team head cur_node to the script security atomic capability set and the script security atomic capability key-value pair set respectively;
[0051] After marking the current team head cur_node as visited, and adding the nodes adjacent to the current team head cur_node and not visited to the queue, re-execute the breadth-first search starting from the starting node in the directed acyclic graph G based on the nodes adjacent to the current team head cur_node and not visited, and take out the current team head cur_node;
[0052] Until the queue is empty, the coverage constraint satisfaction of the security orchestration script is obtained.
[0053] Furthermore, the calculation of attribute coverage according to the summary security atomic capability key-value pair set, the script security atomic capability set and the script security atomic capability key-value pair set includes:
[0054] The intersection S and the union T of the script security atomic capability set and the security atomic capability set of the security script library are calculated respectively, and the security atomic capability coverage is calculated based on the intersection S and the union T; wherein the security atomic capability set of the security script library is the union of the security atomic capability sets of all security information summaries in the security script library;
[0055] Based on the script security atomic capability key-value pair set, check whether the keys of the call parameters in the security orchestration script meet the requirements of the corresponding security atomic capabilities, and count the number of keys that meet the requirements;
[0056] According to the summary security atomic capability key-value pair set and the script security atomic capability key-value pair set, check whether the key value of the security orchestration script is consistent with the information of the summary to be orchestrated, and count the number of key values that meet the requirements;
[0057] The call parameter coverage is obtained according to the number of keys that meet the requirements and the proportion of the number of key values that meet the requirements in the script security atomic capability key-value pair set;
[0058] Based on the weighted sum of the security atomic capability coverage and the call parameter coverage, the attribute coverage is obtained.
[0059] A large model-based security orchestration script generation system, the system comprising:
[0060] A preprocessing module is used to construct a script candidate set based on the security script library, each script candidate in the script candidate set includes: a security summary a p and the expert safety playbook for this safety brief p ;
[0061] A safety script generation module is used to obtain n script candidates i with the highest similarity to the summary to be arranged from the script candidate set, and generate a safety script based on the summary to be arranged, the safety script constraints and the script candidate i.
[0062] Self-consistency module for orchestrating scripts in n security Output the corresponding security orchestration script when the consistency requirements are met
[0063] Compared with the prior art, the present invention has at least the following beneficial effects.
[0064] By using big model technology, the present invention overcomes the shortcomings of the existing technology that relies on security script templates written by experts and is difficult to deal with new security scenarios. For new security scenarios, the present invention can use the generalization ability of big models and combine existing expert scripts to generate more adaptable security scripts than the existing technology, thereby more flexibly dealing with new security risks. BRIEF DESCRIPTION OF THE DRAWINGS
[0065] Figure 1 Flowchart of the approach for generating scripts for big model-based security orchestration.
[0066] Figure 2 This is a DoS security script generated according to an embodiment of the present invention.
[0067] Figure 3 A Bruteforce security orchestration script generated according to an embodiment of the present invention.
[0068] Figure 4 A Port Scan security script generated according to an embodiment of the present invention.
[0069] Figure 5 A security orchestration script without additional constraints generated according to an embodiment of the present invention.
[0070] Figure 6 A branch constraint safety script is generated according to an embodiment of the present invention.
[0071] Figure 7 A parallel constraint safety orchestration script generated according to an embodiment of the present invention.
[0072] Figure 8A sequence reversal safety orchestration script generated according to an embodiment of the present invention. DETAILED DESCRIPTION
[0073] In order to more clearly understand the purpose, technical solutions and advantages of the present application, the present invention is described and illustrated below in conjunction with the accompanying drawings.
[0074] The method for generating a security orchestration script based on the big model technology of the present invention is as follows: Figure 1 As shown, it can be divided into three stages: preprocessing stage, security orchestration script generation stage and self-consistency stage.
[0075] Phase 1: Preprocessing phase.
[0076] The preprocessing stage mainly selects the security information summary-expert scripts with good performance on the large language model as reference script candidates, and returns the security information summary-expert script pairs with poor performance for modification. The preprocessing stage includes the following steps 1.1 to 1.4.
[0077] Step 1.1: Take a security summary a from the security script library p and the corresponding expert safety script m p .
[0078] Step 1.2: Based on the security summary a p Generate prompt word z p , and z p Input into the large model to obtain the output result r p .
[0079] Step 1.3: According to the output result r p and expert safety scripts p Calculate the similarity S p , if S p If it is greater than or equal to the threshold T, the security summary a p and expert safety scripts p As a reference script candidate, otherwise the security summary a p and expert safety scripts p The return is left for modification.
[0080] Step 1.4: Repeat steps 1.1 to 1.3 until all contents in the security script library are traversed.
[0081] Phase 2: Security orchestration script generation phase.
[0082] The security orchestration script generation phase selects approximate security information summary-expert script pairs as context-assisted inputs in the prompt through the security information summary matching algorithm. Repeat the above steps five times to generate a sufficient number of candidate scripts. The security orchestration script generation phase includes the following steps 2.1 to 2.3.
[0083] Step 2.1: For the security summary to be compiled a q Use the security information summary similarity matching algorithm to find the five closest candidate security summaries and security scripts
[0084] In one embodiment, the data structure of the security summary includes time type, text type, value type, and object type. Therefore, it is necessary to select a matching similarity calculation method according to the characteristics of each field, and finally weight them to form a comprehensive security information summary matching algorithm.
[0085] After completing the similarity calculation of each security orchestration script generation algorithm design field, it is necessary to weight each field according to its weight to obtain the overall similarity measurement:
[0086]
[0087] where ω j is the weight of each attribute, satisfying
[0088]
[0089] Here is j ,Q j Is a security summary q ,a p Different attributes of q, Q represent security summaries a q ,a p The text embedding vector of , typeof(j) is the attribute numbered j.
[0090] Specifically, for the text type (text), the similarity measure is:
[0091]
[0092] For numeric types, if it is a continuous value (continuous), the similarity measure is:
[0093]
[0094] For discrete values, the similarity measure is:
[0095]
[0096] For object types, the similarity measure is:
[0097]
[0098] in,<q,Q> represents the inner product operation of the text embedding vector q, Q, and ||·|| represents the norm of the text embedding vector.
[0099] Step 2.2: According to the security summary to be compiled a q Security script constraints and script candidates Generate prompt words as context
[0100] In one embodiment, without fine-tuning, constraints need to be added to the prompts to guide the large language model to generate a security orchestration script that meets the design requirements of this article. The constraints include: format constraints, organization constraints, and natural language constraints.
[0101] 1) Format constraints.
[0102] Security playbooks usually have the following format constraints:
[0103] a. The security orchestration script must contain a start node and an end node;
[0104] b. There is only one start node, and it can only point to other nodes;
[0105] c. There is only one end node, and it can only be pointed to by other nodes;
[0106] d. There cannot be any nodes with zero in- and out-degrees in the security orchestration script;
[0107] e. All nodes in the security orchestration script must be on a path starting from the start node and ending at the end node;
[0108] f. The conditional branches in the security orchestration script must ensure that each branch can be connected to the end node.
[0109] g. Coverage constraint: The successor nodes of a branch node need to cover all branch conditions of the branch node.
[0110] 2) Organizational constraints.
[0111] In the process of arranging security scripts, constraints can be imposed on the organization of security atomic capabilities. In the field of information security, the security atomic capability refers to a minimum, indivisible security function or operation that can independently complete a specific security task in the system. Considering the relationship between security atomic capabilities in the security orchestration script, it can be divided into three categories: serial, parallel, and branch. Serial requires that two security atomic capabilities are executed at the same time or not at the same time. If they are executed, they must be executed in a predefined order; parallel means that the execution of the two security atomic capabilities is independent of each other; the condition requires that only one of the two security atomic capabilities can be executed. There can also be mixed organizational constraints on top of these three basic organizational constraints.
[0112] 3) Natural language constraints.
[0113] Since the large language model has the ability to understand natural language, natural language constraints can also be added to the prompt words, and some expert knowledge can also be added to the prompts in this part. For example:
[0114] a. Higher-level security information summaries need to be compiled first;
[0115] b. The summary of safety information with a more recent date needs to be arranged first;
[0116] c. A summary of security information related to physical security needs to be compiled as a priority.
[0117] Step 2.3: As input to the large model, the output is
[0118] Stage 3: Self-consistency stage.
[0119] The self-consistency stage selects the candidate script with the most repetitions as the output result. If the five outputs are different, the output fails. If the output is successful, the generated security information summary-security orchestration script pair is stored in the security orchestration script library. The self-consistency stage includes the following steps 3.1 to 3.2.
[0120] Step 3.1: Check the five generated scripts Whether there is consistency. If there are more than 3 identical scripts, the most security orchestration scripts will be output. If there is a pair of identical scripts, any one of them will be generated, otherwise the generation will fail.
[0121] Step 3.2: If the generation is successful, the generated security summary-generated security script pair (a q ,r q ) is stored in the security orchestration script library and marked as a candidate script.
[0122] In one embodiment of the present invention, since the newly generated security orchestration script cannot be evaluated and corrected by experts in real time, the present invention also includes a fourth stage: security orchestration script evaluation.
[0123] In the security orchestration script evaluation stage, the present invention designs a set of evaluation algorithms for the security orchestration script generation capability to score the newly generated security orchestration scripts, providing a reference for security operators to select security orchestration scripts or make modifications.
[0124] The steps of the evaluation algorithm are as follows:
[0125] Step 4.1. Convert the security orchestration script into a directed acyclic graph G = (V, E), where V is a node in the directed acyclic graph and E is an edge in the directed acyclic graph. Calculate the in-degree and out-degree of each node and check whether the format constraints a. to f. are satisfied.
[0126] Step 4.2. Add the starting node to an empty queue.
[0127] Step 4.3. Start breadth-first search from the starting node in the directed acyclic graph G, take out the head cur_node of the current queue, and perform calculations in steps 4.4 to 4.6.
[0128] Step 4.4. Calculate whether the coverage constraint is violated: If cur_node is a branch path and the successor node cannot cover all branch conditions, the coverage constraint is violated.
[0129] Step 4.5. Add the secure atomic capability and secure atomic capability key-value pair of cur_node to the script secure atomic capability set and the script secure atomic capability key-value pair set respectively.
[0130] Step 4.6. Mark cur_node as visited and add the nodes adjacent to cur_node that have not been visited to the queue.
[0131] Step 4.7. Repeat steps 4.3 to 4.6 until the queue is empty.
[0132] Step 4.8. Calculate the attribute coverage (including security atomic capability coverage and call parameter coverage) and constraint satisfaction based on the parameters collected in the script security atomic capability set and the script security atomic capability key-value pair set (including security atomic capability key-value pairs and coverage constraint satisfaction) and security atomic capabilities.
[0133] Step 4.9: Perform weighted calculation on attribute coverage and constraint satisfaction to obtain the safety orchestration script evaluation.
[0134] Among them, when calculating the attribute coverage, the union of the security atomic capability sets of each element in the security information summary of the security script library is used as the reference set, and the intersection of the security atomic capability set involved in the generated security orchestration script and the reference set is taken as the satisfied capability set to calculate the satisfied security atomic capability coverage. For the calling parameters, in addition to checking whether the key of the calling parameter meets the requirements of the corresponding security atomic capability, it is also necessary to check whether the key value meets the existing value in the security information summary. If a key value is missing in the security information summary, it is necessary to check whether it has been completed in this step. Check the coverage of the calling parameters of the security atomic capability based on the security atomic capability-parameter pairs in the security information summary and the security orchestration script. The specific steps are:
[0135] Step A: Calculate the security atomic capability coverage.
[0136] Step A1: Obtain the script security atomic capability set A.
[0137] Step A2: Calculate the security atomic capability set B involved in the security information summary of the security script library.
[0138] Step A3: Calculate the intersection S and union T of set A and set B, and calculate the security atomic capability coverage
[0139] Step B: Calculate the call parameter coverage.
[0140] Step B1: Based on the script security atomic capability key-value pair set, check whether the keys of the call parameters in the generated security script meet the requirements of the corresponding security atomic capabilities, and count the number of keys that meet the requirements.
[0141] Step B2: Based on the summary security atomic capability key-value pair set and the script security atomic capability key-value pair set, check whether the key value of the generated security script is consistent with the information in the corresponding security summary, and count the number of key values that meet the requirements.
[0142] Step B3: Calculate the proportion of the number of keys and key values that meet the requirements to the total number of security scripts, that is, obtain the corresponding call parameter coverage.
[0143] Step C: Comprehensively combine the security atomic capability coverage and the call parameter coverage to obtain the attribute coverage of the security orchestration script.
[0144] When evaluating constraint satisfaction, the present invention uses prompt engineering to let the large language model determine whether the natural language constraints are satisfied. The large language model here can be a large language model that generates security arrangements or other large language models with strong reasoning capabilities, called a security assessment large model. A specific natural language constraint check prompt word is organized as follows:
[0145]
[0146] Here, the content of context is the security script that RAG retrieves from the security script library, which can be automatically retrieved by RAG. Question is the input security script to be checked, which can also be automatically retrieved by RAG. Rule is the constraint that the security script to be checked needs to meet, which needs to be manually changed according to different rule constraints. The specific steps are:
[0147] Step a: input the prompt word template into the safety assessment model.
[0148] Step b: input the security scenario to be checked into the security assessment model to obtain output.
[0149] Step c: Determine whether the safety script meets the constraint conditions according to the output result. If the output is 0, it means that the constraint conditions are not met; if the output is 1, it means that the constraint conditions are met; if the output is "unable to check", it means that the check fails.
[0150] The following is an adaptive security orchestration generation experiment and a composite security orchestration generation experiment to illustrate the large model-based security orchestration script generation method provided by the present invention.
[0151] 1. Experimental Preparation
[0152] The researchers selected CVEs of DoS vulnerabilities, phishing vulnerabilities, Trojan horse vulnerabilities, brute force cracking and port scanning in recent years as the source of security information summaries for generating security orchestration scripts, and then selected relevant vulnerability information and corresponding scripts to build a reference script library.
[0153] The selected vulnerability information is shown in Table 1:
[0154]
[0155]
[0156] The part of the security script information used in Table 1 is shown in Table 2.
[0157]
[0158]
[0159] Table 2 generates the prompt word templates used in the experiment, as shown in Table 3.
[0160]
[0161] Table 3
[0162] In the experiment, the rule part is filled with the constraints described in the previous article, and the content of the security capability tool part is as follows: starting vertex a: begin node.
[0163] Security atomic capability b: Network traffic management-abnormal traffic cleaning.
[0164] Security Atomic Capability C: Network Access Control-Access Permission Control.
[0165] Security operation d: Notify the security operator via email.
[0166] Security Operation e: SMS notification to security operators.
[0167] Security atomic capability f: brute force cracking detection.
[0168] Safe Behavior g: IP blocking.
[0169] Security Actions: Change passwords and access permissions.
[0170] Security Atom Capability I: Server and Threat Monitoring - Phishing Email Detection.
[0171] Safety behaviorj:Isolation.
[0172] Security Atomic Capability K: Server and Threat Monitoring - Trojan Attack Monitoring.
[0173] Security Atom Capability 1: Network Threat Protection-Port Scan Monitoring.
[0174] Security atomic capability m: boundary security protection-port hiding.
[0175] End vertex z:end node.
[0176] 2. Adaptive Security Orchestration Generation Experiment
[0177] The adaptive security orchestration generation experiment is used to verify the adaptability of the generated security orchestration script to the constraints. The specific steps of the experiment are as follows:
[0178] Step 1: Load the safety script library prepared in the experiment into the knowledge base, load the prompt word template and constraint conditions into the safety script generation model, and load the prompt word template into the safety constraint evaluation model.
[0179] Step 2: Input the summary of the security vulnerability information to be orchestrated, execute the security orchestration generation algorithm, and obtain the security orchestration script and evaluation results of the security vulnerability after the preprocessing stage, security orchestration generation stage, and self-consistency stage.
[0180] Step 3: Count the security orchestration scripts and evaluation scores of each security vulnerability information to obtain the experimental results.
[0181] in, Figure 2 , Figure 3 , Figure 4 They are the DoS security orchestration script, Bruteforce security orchestration script, and Port Scan security orchestration script generated in the adaptive security orchestration generation experiment.
[0182] 3. Composite Security Orchestration Generation Experiment
[0183] Killchain is a classic concept in network security, which includes all stages from early detection of attackers, exploitation of vulnerabilities to the completion of the final goal. When a traditional SOAR system detects an attack in one of the links, it will automatically call the corresponding security orchestration script to complete the subsequent protection work. With the gradual development of intelligent confrontation, the attacker's security strategy will also change according to the system's response measures. The kill chain has gradually turned to a dynamic chain or mesh structure, and the limited pre-set security orchestration scripts may not be able to fully cover the new security scenarios. In order to meet the security needs in the new scenario, it is necessary for the security analysis atomic capability to automatically or the security operator to manually select the related security orchestration set, and then dynamically generate the security orchestration script based on the real-time security information summary set. This part of the experiment will orchestrate security vulnerabilities that include both Port Scan and DoS vulnerabilities. It is expected that the output will cover security scripts for both risk response measures. Compound vulnerability information such as
[0184] As shown in Table 4.
[0185]
[0186]
[0187] Table 4
[0188] The specific steps of the composite security orchestration generation experiment are as follows:
[0189] Step 1: Load the safety script library prepared in the experiment into the knowledge base, load the prompt word template and constraint conditions into the safety script generation model, and load the prompt word template into the safety constraint evaluation model.
[0190] Step 2: Input the summary of the composite security vulnerability information to be orchestrated, execute the security orchestration generation algorithm, and obtain the security orchestration script and evaluation results of the security vulnerability after the preprocessing stage, security orchestration generation stage, and self-consistency stage.
[0191] Step 3: If Figure 6 and Figure 7As shown in Table 5, new constraints are added to the prompt word template: branch, parallel, order reversal and other constraints, new variants of the security choreography script are generated, and the results are evaluated respectively. Taking the branch constraint as an example, the prompt word template changes are shown in Table 5.
[0192]
[0193] Table 5
[0194] Step 4: Count the security orchestration scripts and evaluation scores of each security vulnerability information generated by the security script generation algorithm to obtain the experimental results.
[0195] in, Figures 5 to 8 They are the security orchestration scripts without additional constraints, branch constraint security orchestration scripts, parallel constraint security orchestration scripts, and order reversal security orchestration scripts generated in the composite security orchestration generation experiment.
[0196] The above description is only an explanation of a specific example of the present invention and does not impose any limitation on the present invention. Obviously, for those with professional knowledge in this field, once the content and principle of the present invention are understood, it is possible to make various modifications and changes in form and details without violating the original principle and structure of the present invention. However, these amendments and changes based on the idea of the present invention are still considered to be within the scope of protection of the claims of the present invention.
Claims
1. A method for generating a security orchestration script based on a large model, characterized in that: The method comprises: Based on the security script library, a script candidate set is constructed, each script candidate in the script candidate set includes: a security summary a p and the expert safety playbook for this safety brief p ; In the script candidate set, n script candidates i with the highest similarity to the summary to be arranged are obtained, and a safe arrangement script is generated based on the summary to be arranged, the safe script constraint and the script candidate i. The security script constraints include: format constraints, organization constraints and natural language constraints; In n security orchestration playbooks Output the corresponding security orchestration script when the consistency requirements are met 2. The method according to claim 1, characterized in that: The method of constructing a script candidate set based on the security script library includes: Take a security summary a from the security script library p and the security summary a p Corresponding expert safety script m p ; According to the security summary p Generate prompt word z p , and the prompt word z p Input into the large model to obtain the output result r p ; Calculate the output result r p and expert safety scripts p The similarity S p , and at the similarity S p If the security summary a is not less than the first set threshold, p And the expert safety scriptm p As a script candidate, it is added to the script candidate set.
3. The method according to claim 1, characterized in that In the script candidate set, n script candidates i with the highest similarity to the summary to be edited are obtained, including: Get the summary to be compiled and the security summary a p The specific type of data includes: time type data, text type data, value type data and object type data; Calculate the similarity between each specific type of data respectively; The similarity is weighted according to the weight of each specific type to obtain the summary to be compiled and the security summary a p The overall similarity between Based on the overall similarity, n script candidates are selected from the script candidate set.
4. The method according to claim 1, characterized in that: Generate a security orchestration script based on the summary to be orchestrated, security script constraints and script candidate i include: According to the summary to be arranged, the safety script constraints and the script candidate i are embedded into the safety orchestration script template, the context generation prompt words are generated Generate prompt words from context Embedded into the security orchestration script generation template, and obtain the security orchestration script based on the big model 5. The method according to claim 1, characterized in that In n security orchestration playbooks Output the corresponding security orchestration script when the consistency requirements are met include: Computational Security Orchestration Playbook The consistency between them is calculated, and the security orchestration script with the largest number of consistency is output. Among them, in any two security orchestration scripts If none of them are consistent, the output security orchestration script generation fails.
6. The method according to claim 1, characterized in that The format constraints include: The security orchestration script must contain a start node and an end node; The starting node exists and only exists once, and can only point to other nodes; The end node exists and only exists once, and can only be pointed to by other nodes; The security orchestration script cannot have nodes with zero in- and out-degrees. All nodes in the security orchestration script must be on a path starting from the start node and ending at the end node; The conditional branches in the security orchestration script must ensure that each branch can be connected to the end node; A coverage constraint, wherein the coverage constraint means that the successor nodes of a branch node need to cover all branch conditions of the branch node; The organizational constraints include: When the relationship between two security atomic capabilities in the security orchestration script is a serial relationship, the two security atomic capabilities are required to be executed at the same time or not executed at the same time, and when executed at the same time, they must be executed in a predefined sequence; When the relationship between two security atomic capabilities in the security orchestration script is a parallel relationship, the execution of the two security atomic capabilities is independent of each other; When the relationship between two security atomic capabilities in the security orchestration script is a branch relationship, it is required that the two security atomic capabilities can only execute one of the security atomic capabilities; The natural language constraints include: The large model has the ability to understand natural language and incorporates natural language constraints and expert knowledge into the prompt words.
7. The method according to claim 6, characterized in that The output corresponds to the security orchestration script After that, it also includes: Convert the security orchestration script into a directed acyclic graph G, and check the satisfaction of other format constraints except the coverage constraint based on the in-degree and out-degree of each node; Add the starting node to an empty queue; Start a breadth-first search from the starting node in the directed acyclic graph G to obtain the coverage constraint satisfaction of the security orchestration script; The format constraint satisfaction of the security orchestration script is obtained by combining the satisfaction of other format constraints except the coverage constraint and the satisfaction of the coverage constraint; Traversing the security orchestration script based on the organizational constraint to obtain the organizational constraint satisfaction of the security orchestration script; Based on the large language model, obtain the natural language constraint satisfaction of the security orchestration script; The constraint satisfaction of the security orchestration script is obtained by integrating the format constraint satisfaction, the organization constraint satisfaction and the natural language constraint satisfaction; the attribute coverage is calculated according to the summary security atomic capability key-value pair set, the script security atomic capability set and the script security atomic capability key-value pair set; Based on the weighted sum of the attribute coverage and the constraint satisfaction, an evaluation of the security orchestration script is obtained.
8. The method according to claim 7, characterized in that The breadth-first search is started from the starting node in the directed acyclic graph G to obtain the coverage constraint satisfaction of the security orchestration script, including: Start breadth-first search from the starting node in the directed acyclic graph G, and take out the current head of the queue, cur_node; Calculate whether the coverage constraint of the current team head cur_node is violated; if the current team head cur_node is a branch path and the successor node cannot cover all branch conditions, the coverage constraint is violated; Add the security atomic capability and security atomic capability key-value pair of the current team head cur_node to the script security atomic capability set and the script security atomic capability key-value pair set respectively; After marking the current team head cur_node as visited, and adding the nodes adjacent to the current team head cur_node and not visited to the queue, re-execute the breadth-first search starting from the starting node in the directed acyclic graph G based on the nodes adjacent to the current team head cur_node and not visited, and take out the current team head cur_node; Until the queue is empty, the coverage constraint satisfaction of the security orchestration script is obtained.
9. The method according to claim 7, characterized in that: The calculating of attribute coverage according to the summary security atomic capability key-value pair set, the script security atomic capability set and the script security atomic capability key-value pair set includes: The intersection S and the union T of the script security atomic capability set and the security atomic capability set of the security script library are calculated respectively, and the security atomic capability coverage is calculated based on the intersection S and the union T; wherein the security atomic capability set of the security script library is the union of the security atomic capability sets of all security information summaries in the security script library; Based on the script security atomic capability key-value pair set, check whether the keys of the call parameters in the security orchestration script meet the requirements of the corresponding security atomic capabilities, and count the number of keys that meet the requirements; According to the summary security atomic capability key-value pair set and the script security atomic capability key-value pair set, check whether the key value of the security orchestration script is consistent with the information of the summary to be orchestrated, and count the number of key values that meet the requirements; The call parameter coverage is obtained according to the number of keys that meet the requirements and the proportion of the number of key values that meet the requirements in the script security atomic capability key-value pair set; Based on the weighted sum of the security atomic capability coverage and the call parameter coverage, the attribute coverage is obtained.
10. A security orchestration script generation system based on a large model, characterized in that: The system comprises: A preprocessing module is used to construct a script candidate set based on the security script library, each script candidate in the script candidate set includes: a security summary a p and the expert safety playbook for this safety brief p ; A safety script generation module is used to obtain n script candidates i with the highest similarity to the summary to be arranged from the script candidate set, and generate a safety script based on the summary to be arranged, the safety script constraints and the script candidate i. Self-consistency module for orchestrating security scripts in n Output the corresponding security orchestration script when the consistency requirements are met