Verification method and device for network vulnerability based on LLM large model

Through the network vulnerability verification method based on the LLM large model, the trained large model is used to generate POC scripts and integrate them into existing libraries, solving the problem that the existing technology cannot efficiently identify and verify new network vulnerabilities, and achieving more efficient and accurate vulnerability verification.

CN120017336APending Publication Date: 2025-05-16BEIJING CHANGYANG TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510093924.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-21
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

The existing technology cannot efficiently and accurately identify and verify new network vulnerabilities, resulting in a greater security risk to the network.

Method used

Using a network vulnerability verification method based on the LLM large model, a specific POC script is generated by training the sample set of known vulnerabilities, and integrating it with the known POC script library to quickly match and verify the vulnerability information to be detected.

Benefits of technology

Improves the efficiency and accuracy of vulnerability verification, can quickly deal with new vulnerability threats, and reduces the burden on security researchers to manually analyze and write POC scripts.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017336A_ABST
    Figure CN120017336A_ABST
Patent Text Reader

Abstract

The invention relates to a network vulnerability verification method and device based on an LLM large model. The method comprises the following steps: training a pre-constructed LLM large model based on a known vulnerability sample set to obtain a trained target large model; each vulnerability sample in the vulnerability sample set is labeled with a key information label and a POC code snippet label; the key information comprises vulnerability types, severity and related technical stacks; aiming at a specific vulnerability requirement, generating a corresponding specific POC script based on the target large model; the specific POC script and the known POC script are integrated, and a final POC script library is obtained; and for the to-be-verified target vulnerability information, calling a target POC script matched with the target vulnerability information from the final POC script library based on a pre-constructed vulnerability verification framework so as to perform vulnerability verification by using the target POC script, and generating a vulnerability verification report. According to the method, the vulnerability verification efficiency and accuracy can be improved, and novel vulnerability threats can be quickly dealt with.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network vulnerability verification, and in particular to a network vulnerability verification method and device based on an LLM large model. Background Art

[0002] With the rapid development of information technology, network security is facing increasingly severe challenges. The discovery and verification of vulnerabilities are crucial to ensuring system security. Traditional vulnerability verification mainly relies on known POC (Proof of Concept) scripts and the empirical analysis of security researchers. However, the number of known POC scripts is limited and they are not updated in a timely manner, making it difficult to cope with the emergence of new vulnerabilities. At the same time, it is inefficient for security researchers to manually analyze vulnerabilities and write POC scripts, which requires deep professional knowledge. Therefore, existing technologies cannot efficiently and accurately identify and verify new network vulnerabilities, and the network is subject to greater security risks.

[0003] Based on this, there is an urgent need for a network vulnerability verification method and device based on the LLM large model to solve the above problems. Summary of the invention

[0004] The present invention provides a network vulnerability verification method and device based on the LLM large model, which can improve the efficiency and accuracy of vulnerability verification and quickly respond to new vulnerability threats. The technical solution is as follows:

[0005] In a first aspect, an embodiment of the present invention provides a method for verifying network vulnerabilities based on an LLM large model, the method comprising:

[0006] The pre-built LLM big model is trained based on the known vulnerability sample set to obtain a trained target big model; each vulnerability sample in the vulnerability sample set is annotated with a key information label and a POC code snippet label; the key information includes the vulnerability type, severity and the technology stack involved; the POC code snippet is used to characterize the function call, data construction method and network request format required to verify the vulnerability;

[0007] According to specific vulnerability requirements, a corresponding specific POC script is generated based on the target large model;

[0008] Integrate the specific POC script with the known POC script to obtain a final POC script library;

[0009] For the target vulnerability information to be verified, based on the pre-built vulnerability verification framework, a target POC script matching the target vulnerability information is called from the final POC script library to perform vulnerability verification using the target POC script and generate a vulnerability verification report.

[0010] In a second aspect, an embodiment of the present invention further provides a network vulnerability verification device based on the LLM large model, the device comprising:

[0011] A training unit is used to train a pre-built LLM large model based on a known vulnerability sample set to obtain a trained target large model; each vulnerability sample in the vulnerability sample set is annotated with a key information label and a POC code snippet label; the key information includes the vulnerability type, severity, and the technology stack involved; the POC code snippet is used to characterize the function call, data construction method, and network request format required to verify the vulnerability;

[0012] A generation unit, used to generate a corresponding specific POC script based on the target large model according to a specific vulnerability requirement;

[0013] An integration unit, used to integrate the specific POC script with known POC scripts to obtain a final POC script library;

[0014] The verification unit is used to call a target POC script matching the target vulnerability information from the final POC script library based on a pre-built vulnerability verification framework for the target vulnerability information to be verified, so as to perform vulnerability verification using the target POC script and generate a vulnerability verification report.

[0015] In a third aspect, an embodiment of the present invention further provides an electronic device, including a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the method described in any embodiment of this specification is implemented.

[0016] In a fourth aspect, an embodiment of the present invention further provides a computer-readable storage medium having a computer program stored thereon, which, when executed in a computer, enables the computer to execute the method described in any embodiment of this specification.

[0017] In a fifth aspect, an embodiment of the present invention further provides a computer program product, including a computer program, which implements the steps of the method described above when executed by a processor.

[0018] The embodiment of the present invention provides a method and device for verifying network vulnerabilities based on the LLM large model. First, the LLM large model is trained using a large amount of known vulnerability information so that it can understand the concepts and principles related to the vulnerability and has the ability to generate POC code snippets according to the vulnerability characteristics. In this way, when faced with specific vulnerability requirements, the trained target large model can be used to generate the corresponding POC script, thereby eliminating the need for security engineers to manually write it, thereby improving the generation efficiency and accuracy of the POC script. Then, the script generated by the large model is integrated with the known POC script library to obtain a more comprehensive script library. Finally, for the target vulnerability information to be verified, the appropriate script can be quickly matched from the integrated script library and the vulnerability verification can be performed to generate an accurate verification report. It can be seen that the present application can improve the efficiency and accuracy of vulnerability verification and quickly respond to new vulnerability threats. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0020] Figure 1 It is a flow chart of a method for verifying network vulnerabilities based on the LLM large model provided by one embodiment of the present invention;

[0021] Figure 2 It is a structural diagram of a network vulnerability verification device based on the LLM large model provided by an embodiment of the present invention;

[0022] Figure 3 is a hardware architecture diagram of a computer device provided by an embodiment of the present invention;

[0023] Figure 4 It is a schematic diagram of a vulnerability sample set processing process provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0024] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.

[0025] The specific implementation of the above concept is described below.

[0026] Please refer to Figure 1 , an embodiment of the present invention provides a network vulnerability verification method based on the LLM large model, the method comprising:

[0027] Step 100, training the pre-built LLM big model based on the known vulnerability sample set to obtain a trained target big model; each vulnerability sample in the vulnerability sample set is annotated with a key information label and a POC code snippet label; the key information includes the vulnerability type, severity, and the technology stack involved; the POC code snippet is used to characterize the function call, data construction method, and network request format required to verify the vulnerability;

[0028] Step 102, generating a corresponding specific POC script based on the target large model for specific vulnerability requirements;

[0029] Step 104, integrating the specific POC script with the known POC script to obtain a final POC script library;

[0030] Step 106, for the target vulnerability information to be verified, based on the pre-built vulnerability verification framework, call the target POC script matching the target vulnerability information from the final POC script library to perform vulnerability verification using the target POC script and generate a vulnerability verification report.

[0031] In this embodiment, the LLM large model is first trained using a large amount of known vulnerability information so that it can understand the concepts and principles related to vulnerabilities and has the ability to generate POC code snippets based on vulnerability features. In this way, when faced with specific vulnerability requirements, the trained target large model can be used to generate the corresponding POC script, thereby eliminating the need for security engineers to manually write it, thereby improving the generation efficiency and accuracy of the POC script. Then, the script generated by the large model is integrated with the known POC script library to obtain a more comprehensive script library. Finally, for the target vulnerability information to be verified, the appropriate script can be quickly matched from the integrated script library and vulnerability verification can be performed to generate an accurate verification report. It can be seen that the present application can improve the efficiency and accuracy of vulnerability verification and quickly respond to new vulnerability threats.

[0032] Described below Figure 1 How the various steps are performed.

[0033] First, with respect to step 100, the pre-built LLM large model is trained based on a known vulnerability sample set to obtain a trained target large model.

[0034] In this step, if Figure 4 As shown in the figure, the vulnerability sample set is determined in the following way:

[0035] Collect several known original vulnerability data, each of which includes vulnerability type, vulnerability description, affected system and version, and related security patches;

[0036] Perform data cleaning on each raw vulnerability data to remove noise data and duplicate data;

[0037] Categorize the cleaned vulnerability data by vulnerability type and affected system;

[0038] Mark the classified vulnerability data and generate key information tags and POC code snippet tags;

[0039] The format of the annotated vulnerability data is unified and the data is vectorized to obtain a vulnerability sample set in a preset format.

[0040] In addition, known raw vulnerability data is collected from multiple channels such as major security agency websites, open source vulnerability databases, etc. through web crawler technology, and the preset format can be vector representation.

[0041] In some implementations, step 100 is implemented as follows:

[0042] The pre-built LLM big model is trained based on the known vulnerability sample set to obtain the trained target big model, including:

[0043] Input known vulnerability sample sets into the LLM large model in batches for training;

[0044] For each round of training, the corresponding POC code snippets are generated based on the big model's ability to understand key information in the vulnerability samples and its logical reasoning ability; the deviation between the generated POC code snippets and the corresponding POC code snippet labels is compared, and the model parameters are adjusted based on the deviation;

[0045] And so on, until the accuracy of the POC code snippet output by the large model meets the precision requirements, a trained large model is obtained.

[0046] In this step, during the training process, the large model gradually grasps the semantics, syntax, and logical relationships of vulnerabilities by learning a large amount of vulnerability text information. For example, it learns how to generate corresponding code logic ideas based on vulnerability descriptions and understands the relationship between different vulnerability types and specific code structures. A combination of supervised learning and unsupervised learning is used. Supervised learning uses labeled vulnerability data, such as known vulnerability descriptions and corresponding POC code snippet labels to guide the model to learn the correct generation method; unsupervised learning focuses on mining potential patterns and rules from a large amount of unlabeled vulnerability-related texts to enhance the model's ability to generalize and understand vulnerability information.

[0047] During the training process, the large model is evaluated regularly, for example, using the validation set data to test the accuracy, completeness and rationality of the model in generating POC script ideas or code snippets. The training parameters of the model are adjusted according to the evaluation results. For example, if it is found that the model has deviations when generating POCs for a certain type of vulnerability, the learning weights of the vulnerability data of this type are adjusted or the relevant layer structure of the model is optimized.

[0048] In addition, the LLM large model adopts the Transformer model architecture and determines the scale (number of parameters) of the model based on computing resources and requirements. The model is initialized, including configuring the model's hyperparameters, such as learning rate, batch size, number of training rounds, etc., to prepare for subsequent training.

[0049] In some implementations, step 102 includes:

[0050] For vulnerability data with specific requirements, extract the vulnerability name, vulnerability type, involved technology stack, affected system and version, severity and vulnerability discovery environment in the vulnerability data to obtain pre-processed vulnerability data;

[0051] Convert the preprocessed vulnerability data into vulnerability data in a preset format;

[0052] Input the vulnerability data in the preset format into the target large model to obtain the corresponding specific POC script.

[0053] In this step, when a verification task for a specific vulnerability is received, the detailed information of the vulnerability (such as vulnerability name, affected system and version, vulnerability discovery environment, etc.) is organized into a format suitable for LLM large model input, such as converting it into a structured text description or a specific vector representation.

[0054] The formatted vulnerability information is input into the target big model. Based on the learned knowledge and experience, the LLM big model generates the framework and core code logic of the POC script, which may include key elements such as function calls, data construction methods, and network request formats required to determine the vulnerability.

[0055] Refine and improve the code of the generated preliminary POC script framework. The LLM large model may further supplement the variable definition, error handling mechanism, code adjustment adapted to the target system environment and other details in the code to generate a relatively complete and executable POC script. Perform preliminary verification and optimization on the generated POC script. Check whether the script has syntax errors, logical loopholes or potential operational risks through simulation operation or static code analysis. If problems are found, use the error correction and optimization capabilities of the LLM large model to adjust the script to ensure that it can run effectively in the target vulnerability environment and accurately verify the existence and exploitability of the vulnerability.

[0056] With respect to step 104, the specific POC script is integrated with the known POC script to obtain a final POC script library.

[0057] In this step, existing POC scripts are obtained from well-known security code repositories, open source security projects, etc., and their code is reviewed and adapted so that they can run in a unified framework environment. They are then merged with the newly generated POC scripts of the LLM large model and stored in the POC script library to form a comprehensive POC script library.

[0058] For step 106, the vulnerability verification framework includes an input module, a POC script matching and calling module, a vulnerability verification execution module, and a result output module;

[0059] The input module is used to receive the target vulnerability information to be verified and transmit it to the POC script matching and calling module;

[0060] The POC script matching and calling module is used to find and call the corresponding POC script in the final POC script library;

[0061] The vulnerability verification execution module is used to execute the POC script matching and call the script found by the module to perform vulnerability verification;

[0062] The result output module is used to organize the vulnerability verification results and output a detailed vulnerability verification report, including whether the vulnerability exists, the severity of the vulnerability and the scope of impact.

[0063] From the above scheme, it can be seen that the application method can effectively integrate the resources of known vulnerability libraries and the learning ability of large language models, quickly generate accurate POC scripts, build an efficient vulnerability verification framework, significantly improve the efficiency and quality of network security vulnerability verification, and provide strong support for ensuring the security of information systems.

[0064] like Figure 2 , Figure 3 As shown, the embodiment of the present invention provides a network vulnerability verification device based on the LLM large model. The device embodiment can be implemented by software, or by hardware or a combination of software and hardware. From the hardware level, Figure 2 As shown, it is a hardware architecture diagram of a computing device where a network vulnerability verification device based on the LLM large model provided by an embodiment of the present invention is located, except Figure 2 In addition to the processor, memory, network interface, and non-volatile memory shown in the figure, the computing device in which the device is located in the embodiment may also generally include other hardware, such as a forwarding chip responsible for processing messages, etc. Taking software implementation as an example, Figure 3As shown, as a device in a logical sense, the CPU of the computing device in which it is located reads the corresponding computer program in the non-volatile memory into the internal memory and runs it.

[0065] Please refer to Figure 3 The embodiment of the present invention provides a network vulnerability verification device based on the LLM large model, the device comprising:

[0066] The training unit 300 is used to train the pre-built LLM large model based on the known vulnerability sample set to obtain a trained target large model; each vulnerability sample in the vulnerability sample set is annotated with a key information label and a POC code snippet label; the key information includes the vulnerability type, severity and the technology stack involved; the POC code snippet is used to characterize the function call, data construction method and network request format required to verify the vulnerability;

[0067] A generating unit 302 is used to generate a corresponding specific POC script based on a target large model for specific vulnerability requirements;

[0068] An integration unit 304 is used to integrate the specific POC script with the known POC script to obtain a final POC script library;

[0069] The verification unit 306 is used to call the target POC script matching the target vulnerability information from the final POC script library based on the pre-built vulnerability verification framework for the target vulnerability information to be verified, so as to perform vulnerability verification using the target POC script and generate a vulnerability verification report.

[0070] In some implementations, the vulnerability sample set is determined by:

[0071] Collect several known original vulnerability data, each of which includes vulnerability type, vulnerability description, affected system and version, and related security patches;

[0072] Perform data cleaning on each raw vulnerability data to remove noise data and duplicate data;

[0073] Categorize the cleaned vulnerability data by vulnerability type and affected system;

[0074] Mark the classified vulnerability data and generate key information tags and POC code snippet tags;

[0075] The format of the annotated vulnerability data is unified and the data is vectorized to obtain a vulnerability sample set in a preset format.

[0076] In some implementations, the training unit 300 is configured to perform the following operations:

[0077] Input known vulnerability sample sets into the LLM large model in batches for training;

[0078] For each round of training, the corresponding POC code snippets are generated based on the big model's ability to understand key information in the vulnerability samples and its logical reasoning ability; the deviation between the generated POC code snippets and the corresponding POC code snippet labels is compared, and the model parameters are adjusted based on the deviation;

[0079] And so on, until the accuracy of the POC code snippet output by the large model meets the precision requirements, a trained large model is obtained.

[0080] In some embodiments, the training process of the LLM large model adopts a combination of supervised learning and unsupervised learning.

[0081] In some implementations, the generating unit 302 is configured to perform the following operations:

[0082] For vulnerability data with specific requirements, extract the vulnerability name, vulnerability type, involved technology stack, affected system and version, severity and vulnerability discovery environment in the vulnerability data to obtain pre-processed vulnerability data;

[0083] Convert the preprocessed vulnerability data into vulnerability data in a preset format;

[0084] Input the vulnerability data in the preset format into the target large model to obtain the corresponding specific POC script.

[0085] In some embodiments, the vulnerability verification framework includes an input module, a POC script matching and calling module, a vulnerability verification execution module, and a result output module;

[0086] The input module is used to receive the target vulnerability information to be verified and transmit it to the POC script matching and calling module;

[0087] The POC script matching and calling module is used to find and call the corresponding POC script in the final POC script library;

[0088] The vulnerability verification execution module is used to execute the POC script matching and call the script found by the module to perform vulnerability verification;

[0089] The result output module is used to organize the vulnerability verification results and output a detailed vulnerability verification report, including whether the vulnerability exists, the severity of the vulnerability and the scope of impact.

[0090] In some implementations, the LLM large model uses a Transformer model architecture.

[0091] It should be noted that the network vulnerability verification device based on the LLM large model provided in the above embodiment is only illustrated by the division of the above functional modules. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the network vulnerability verification device based on the LLM large model provided in the above embodiment and the network vulnerability verification method embodiment based on the LLM large model belong to the same concept. The specific implementation process is detailed in the method embodiment and will not be repeated here.

[0092] The embodiment of the present application also provides a computer device, please refer to Figure 3 The computer device includes a processor and a memory, in which at least one instruction, at least one program, code set or instruction set is stored, and the at least one instruction, at least one program, code set or instruction set is loaded and executed by the processor to implement the network vulnerability verification method based on the LLM large model provided by the above-mentioned method embodiments.

[0093] An embodiment of the present application also provides a computer-readable storage medium, on which is stored at least one instruction, at least one program, code set or instruction set, and the at least one instruction, at least one program, code set or instruction set is loaded and executed by a processor to implement the network vulnerability verification method based on the LLM large model provided by the above-mentioned method embodiments.

[0094] An embodiment of the present application also provides a computer program product, which includes a computer program. A processor of a computer device reads the computer program from a computer-readable storage medium, and the processor executes the computer program, so that the computer device executes the network vulnerability verification method based on the LLM large model described in any of the above embodiments.

[0095] For the convenience of description, the above system or device is described by dividing it into various modules or units according to its functions. Of course, when implementing the present application, the functions of each unit can be implemented in the same or multiple software and / or hardware.

[0096] It can be known from the description of the above implementation methods that those skilled in the art can clearly understand that the present application can be implemented by means of software plus a necessary general hardware platform. Based on such an understanding, the technical solution of the present application can be essentially or partly contributed to the prior art in the form of a software product, which can be stored in a storage medium such as ROM / RAM, a magnetic disk, an optical disk, etc., and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in the various embodiments of the present application or certain parts of the embodiments.

[0097] Finally, it should be noted that, in this article, relational terms such as first, second, third and fourth are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the statement "comprise a ..." do not exclude the presence of other identical elements in the process, method, article or device including the elements.

[0098] The above is only a preferred implementation of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.

Claims

1. A network vulnerability verification method based on the LLM large model, characterized in that: The method comprises: The pre-built LLM big model is trained based on the known vulnerability sample set to obtain a trained target big model; each vulnerability sample in the vulnerability sample set is annotated with a key information label and a POC code snippet label; the key information includes the vulnerability type, severity and the technology stack involved; the POC code snippet is used to characterize the function call, data construction method and network request format required to verify the vulnerability; According to specific vulnerability requirements, a corresponding specific POC script is generated based on the target large model; Integrate the specific POC script with the known POC script to obtain a final POC script library; For the target vulnerability information to be verified, based on the pre-built vulnerability verification framework, a target POC script matching the target vulnerability information is called from the final POC script library to perform vulnerability verification using the target POC script and generate a vulnerability verification report.

2. The method according to claim 1, characterized in that The vulnerability sample set is determined in the following way: Collecting a number of known original vulnerability data, each of which includes vulnerability type, vulnerability description, affected system and version, and related security patches; Performing data cleaning on each of the original vulnerability data to remove noise data and duplicate data; Categorize the cleaned vulnerability data by vulnerability type and affected system; Marking the classified vulnerability data to generate the key information label and the POC code snippet label; The format of the annotated vulnerability data is unified and the data is vectorized to obtain a vulnerability sample set in a preset format.

3. The method according to claim 2, characterized in that The pre-built LLM big model is trained based on the known vulnerability sample set to obtain a trained target big model, including: Input the known vulnerability sample set into the LLM large model in batches for training; For each round of training, the corresponding POC code snippets are generated based on the large model's ability to understand key information and logical reasoning in the vulnerability samples; the deviation between the generated POC code snippets and the corresponding POC code snippet labels is compared, and the model parameters are adjusted based on the deviation; And so on, until the accuracy of the POC code snippet output by the large model meets the precision requirement, a trained large model is obtained.

4. The method according to any one of claims 1 to 3, characterized in that: The training process of the LLM large model adopts a combination of supervised learning and unsupervised learning.

5. The method according to claim 2, characterized in that: The specific POC script is generated based on the target large model for specific vulnerability requirements, including: For vulnerability data with specific requirements, extract the vulnerability name, vulnerability type, involved technology stack, affected system and version, severity and vulnerability discovery environment in the vulnerability data to obtain pre-processed vulnerability data; Converting the preprocessed vulnerability data into vulnerability data in the preset format; The vulnerability data in the preset format is input into the target macro model to obtain a corresponding specific POC script.

6. The method according to claim 1, characterized in that The vulnerability verification framework includes an input module, a POC script matching and calling module, a vulnerability verification execution module and a result output module; The input module is used to receive the target vulnerability information to be verified and transmit it to the POC script matching and calling module; The POC script matching and calling module is used to search and call the corresponding POC script in the final POC script library; The vulnerability verification execution module is used to execute the script found by the POC script matching and calling module to perform vulnerability verification; The result output module is used to organize the vulnerability verification results and output a detailed vulnerability verification report, including whether the vulnerability exists, the severity of the vulnerability and the scope of impact.

7. The method according to any one of claims 1 to 3, characterized in that: The LLM large model adopts the Transformer model architecture.

8. A network vulnerability verification device based on the LLM large model, characterized in that: The device comprises: A training unit is used to train a pre-built LLM large model based on a known vulnerability sample set to obtain a trained target large model; each vulnerability sample in the vulnerability sample set is annotated with a key information label and a POC code snippet label; the key information includes the vulnerability type, severity, and the technology stack involved; the POC code snippet is used to characterize the function call, data construction method, and network request format required to verify the vulnerability; A generation unit, used to generate a corresponding specific POC script based on the target large model according to a specific vulnerability requirement; An integration unit, used to integrate the specific POC script with known POC scripts to obtain a final POC script library; The verification unit is used to call a target POC script matching the target vulnerability information from the final POC script library based on a pre-built vulnerability verification framework for the target vulnerability information to be verified, so as to perform vulnerability verification using the target POC script and generate a vulnerability verification report.

9. A computing device, comprising a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the method according to any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium having a computer program stored thereon, which, when executed in a computer, causes the computer to execute the method according to any one of claims 1 to 7.