Method and device for adjusting network security policy, and electronic equipment
By using large language models and knowledge bases in network security policies, we automatically identify false positive events and generate optimization measures, and solve the problems of inefficient network security policies and difficult to quickly adapt to dynamic changes in the existing technology, and achieve efficient and accurate policy adjustments.
Patent Information
- Application Number
- CN202510173813.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-17
- Publication Date
- 2025-05-16
AI Technical Summary
Due to redundancy and conflict rules, existing network security policies have reduced processing speed, increased resource waste, and frequent false positive problems. Traditional security policy optimization methods based on static rules are difficult to quickly adapt to the dynamic changes in the network security environment.
By determining the network events that trigger the network security policy, obtain suspected false positive data, and input them with the preset prompt text to the large language model, combine the knowledge base to output the optimization measures of the network security policy, automatically identify false positive events and configure adjustment plans.
It improves the efficiency and accuracy of network security policy adjustment, reduces dependence on expert experience, can quickly adapt to changes in the network environment, and reduces false positive rates and resource waste.
Smart Images

Figure CN120017378A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security or other related technical fields, and in particular to a method for adjusting a network security strategy, a device thereof, and an electronic device. Background Art
[0002] With the development of the digital age, the complexity and uncertainty of cyberspace are increasing, and the means of cyber attacks are becoming more diverse and intelligent, which poses unprecedented challenges to network security. In order to cope with these challenges, major enterprises and organizations have deployed various network security protection devices and systems, such as firewalls, intrusion detection and prevention systems, security information and event management systems, etc., to monitor network traffic, identify potential threats and take corresponding measures.
[0003] However, despite the sophisticated and comprehensive security policies of these security devices and systems, their efficiency and effectiveness still need to be improved. Security policies are usually composed of a large number of rules, designed to block malicious traffic, detect abnormal behavior, and prevent various security threats. But over time, these policies will accumulate a large number of redundant and conflicting rules, resulting in slow processing speed, increased resource waste, and frequent false positives. False positives not only consume the valuable time of security teams, but also may have a negative impact on business operations by mistakenly blocking legitimate traffic, especially for industries that are highly dependent on network communications, such as finance, healthcare, and education.
[0004] In addition, the dynamic changes in the network security environment require security policies to quickly adapt to new threat situations. However, traditional security policy optimization methods based on static rules are difficult to meet this demand. In related technologies, iterative updates of network security policies are often based on manual analysis by security experts, but this policy adjustment and optimization method is inefficient, consumes a lot of time and energy, and is difficult to respond to emerging threats in real time.
[0005] To address the above-mentioned problems, no effective solution has been proposed yet. Summary of the invention
[0006] The embodiments of the present invention provide a network security policy adjustment method and device, and an electronic device, so as to at least solve the technical problem of low efficiency in the related art of manually analyzing and adjusting massive network security policies based on expert experience.
[0007] According to one aspect of an embodiment of the present invention, there is provided a method for adjusting a network security policy, comprising: determining a network event that triggers the network security policy, and obtaining suspected false alarm data based on the network event; inputting the suspected false alarm data and a preset prompt text into a large language model, and outputting optimization measures for the network security policy through the large language model in combination with a knowledge base, wherein the large language model is used to provide optimization measures for the network security policy, and the knowledge base pre-stores knowledge data, and the knowledge data includes at least one of the following: user behavior data, historical attack data, and security standard data; and adjusting the network security policy according to the optimization measures for the network security policy.
[0008] Optionally, the step of outputting optimization measures for network security policies through the large language model in combination with a knowledge base includes: extracting target knowledge data from the knowledge base through the large language model, and comparing and analyzing the extracted target knowledge data with the suspected false alarm data to obtain an analysis result; when the analysis result indicates that the suspected false alarm data is real false alarm data, outputting optimization measures for the network security policy.
[0009] Optionally, the step of comparing and analyzing the extracted target knowledge data with the suspected false alarm data includes: the large language model performs chain reasoning based on the system prompts and thinking chain prompts in the prompt text, compares the target knowledge data with the suspected false alarm data, and identifies whether the suspected false alarm data is real false alarm data according to the comparison result to obtain a recognition result; when the recognition result indicates that the suspected false alarm data is real false alarm data, the large language model performs deep reasoning based on the functional prompts in the prompt text to identify the cause of the false alarm; and generates the analysis result based on the real false alarm data and the cause of the false alarm.
[0010] Optionally, after adjusting the network security policy according to the optimization measures of the network security policy, it also includes: collecting feedback information after the adjustment of the network security policy; inputting the feedback information into the large language model as input data for the next time the large language model outputs the optimization measures of the network security policy. Optionally, the large language model is obtained by fine-tuning the initial large language model after pre-training, and the fine-tuning training process includes: obtaining a training set, the training set includes multiple historical false alarm data and a policy optimization label configured for each of the historical false alarm data; calling a pre-built knowledge base, and fine-tuning the initial large language model based on the training set and the prompt text.
[0011] Optionally, before inputting the suspected false alarm data into the large language model, it also includes: performing a data cleaning operation on the suspected false alarm data to obtain the cleaned suspected false alarm data, wherein the data cleaning operation includes at least one of the following: removing incomplete data records, filtering invalid data, removing noise in the suspected false alarm data, and eliminating outliers in the suspected false alarm data; formatting and standardizing the cleaned suspected false alarm data to obtain the processed suspected false alarm data.
[0012] Optionally, adjusting the network security policy according to the optimization measures of the network security policy includes: displaying the optimization measures to a user terminal through a visual interface; receiving operation instructions from the user terminal for the optimization measures, and adjusting the network security policy based on the operation instructions, wherein the operation instructions include one of the following: automatic adjustment instructions, manual adjustment instructions.
[0013] According to another aspect of an embodiment of the present invention, there is also provided a device for adjusting a network security policy, comprising: an acquisition unit, used to determine a network event that triggers a network security policy, and to acquire suspected false alarm data based on the network event; an output unit, used to input the suspected false alarm data and a preset prompt text into a large language model, and output optimization measures for the network security policy through the large language model in combination with a knowledge base, wherein the large language model is used to provide optimization measures for the network security policy, and the knowledge base pre-stores knowledge data, and the knowledge data includes at least one of the following: user behavior data, historical attack data, and security standard data; an adjustment unit, used to adjust the network security policy according to the optimization measures for the network security policy.
[0014] Optionally, the output unit includes: a first analysis module, used to extract target knowledge data from the knowledge base through the large language model, and compare and analyze the extracted target knowledge data with the suspected false alarm data to obtain an analysis result; a first output module, used to output optimization measures of the network security policy when the analysis result indicates that the suspected false alarm data is real false alarm data.
[0015] Optionally, the first analysis module includes: a first reasoning sub-module, which is used for the large language model to perform chain reasoning based on the system prompts and thinking chain prompts in the prompt text, compare the target knowledge data with the suspected false alarm data, and identify whether the suspected false alarm data is real false alarm data according to the comparison result to obtain a recognition result; a second reasoning sub-module, which is used for the large language model to perform deep reasoning based on the functional prompts in the prompt text to identify the cause of the false alarm when the recognition result indicates that the suspected false alarm data is real false alarm data; and a first generation sub-module, which is used to generate the analysis result based on the real false alarm data and the cause of the false alarm.
[0016] Optionally, the adjustment unit includes: a first acquisition module, used to collect feedback information after adjusting the network security policy; and a first serving module, used to input the feedback information into the large language model as input data for the next time the large language model outputs optimization measures for the network security policy.
[0017] Optionally, the large language model is obtained by fine-tuning an initial large language model after pre-training, and the network security policy adjustment device also includes a training unit, which is used to: obtain a training set, the training set includes multiple historical false alarm data and a policy optimization label configured for each of the historical false alarm data; call a pre-built knowledge base, and fine-tune the initial large language model based on the training set and the prompt text.
[0018] Optionally, the network security policy adjustment device also includes a preprocessing unit, which includes: a first cleaning module, used to perform data cleaning operations on the suspected false alarm data to obtain the cleaned suspected false alarm data, wherein the data cleaning operation includes at least one of the following: removing incomplete data records, filtering invalid data, removing noise in the suspected false alarm data, and eliminating abnormal values in the suspected false alarm data; a first processing module, used to format and standardize the cleaned suspected false alarm data to obtain the processed suspected false alarm data.
[0019] Optionally, the adjustment unit includes: a first display module, used to display the optimization measures to the user terminal through a visual interface; a first adjustment module, used to receive the user terminal's operation instructions for the optimization measures, and adjust the network security policy based on the operation instructions, wherein the operation instructions include one of the following: automatic adjustment instructions, manual adjustment instructions.
[0020] According to another aspect of an embodiment of the present invention, a computer-readable storage medium is also provided, wherein the computer-readable storage medium includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute any one of the above-mentioned network security policy adjustment methods.
[0021] According to another aspect of an embodiment of the present invention, there is also provided an electronic device, comprising one or more processors and a memory, wherein the memory is used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement any one of the above-mentioned methods for adjusting the network security policies.
[0022] In the present application, the collected suspected false alarm data and pre-formulated prompt text are input into a pre-built large language model, which is guided to perform chain reasoning and deep analysis, automatically identify false alarm events, and configure network security policy adjustment plans for false alarm events to adapt to the ever-changing network environment, thereby achieving the purpose of intelligently adjusting and optimizing network security policies, and achieving the technical effect of improving the efficiency of network security policy adjustment, thereby solving the technical problem of low efficiency in the related technology of relying on expert experience to manually analyze and adjust massive network security policies. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of this application. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:
[0024] Figure 1 is a flow chart of an optional method for adjusting a network security policy according to an embodiment of the present invention;
[0025] Figure 2 is an optional network security policy adjustment system architecture diagram according to an embodiment of the present invention;
[0026] Figure 3 is a schematic diagram of an optional adjustment process of a network security policy according to an embodiment of the present invention;
[0027] Figure 4 is a schematic diagram of an optional network security policy adjustment device according to an embodiment of the present invention;
[0028] Figure 5 The present invention is a hardware structure block diagram of an electronic device (or mobile device) for executing a method for adjusting a network security policy according to an embodiment of the present invention. DETAILED DESCRIPTION
[0029] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.
[0030] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0031] It should be noted that the relevant information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data comply with the relevant laws, regulations and standards of the relevant regions, take necessary confidentiality measures, do not violate public order and good customs, and provide corresponding operation entrances for users to choose to authorize or refuse. For example, an interface is set up between this system and relevant users or organizations. Before obtaining relevant information, it is necessary to send an acquisition request to the aforementioned user or organization through the interface, and obtain relevant information after receiving the consent information fed back by the aforementioned user or organization.
[0032] The embodiments or examples of the present disclosure are not exhaustive, but are only illustrative of some embodiments or examples, and are not intended to be specific limitations on the scope of protection of the present disclosure. In the absence of contradiction, each step in a certain embodiment or example can be implemented as an independent example, and the steps can be combined arbitrarily. For example, the scheme after removing some steps in a certain embodiment or example can also be implemented as an independent example, and the order of the steps in a certain embodiment or example can be arbitrarily exchanged. In addition, the optional methods or optional examples in a certain embodiment or example can be combined arbitrarily; in addition, the various embodiments or examples can be combined arbitrarily, for example, some or all steps of different embodiments or examples can be combined arbitrarily, and a certain embodiment or example can be combined arbitrarily with the optional methods or optional examples of other embodiments or examples.
[0033] It should be noted that the network security policy adjustment method and device in the present application can be used in the field of network security when the network security policy is intelligently adjusted based on a large model, and can also be used in any field other than the network security field when the network security policy is intelligently adjusted based on a large model. The application field of the network security policy adjustment method and device in the present application is not limited.
[0034] The following embodiments of the present invention can be applied to various network security policy adjustment systems / applications / devices. The present invention uses the computing power of a large model and the step-by-step reasoning ability of a thinking chain to quickly and accurately generate network security policy adjustment plans and optimization suggestions, significantly improving the efficiency and accuracy of policy adjustment and optimization.
[0035] At the same time, the present invention can integrate multi-source network security data, such as user behavior data, threat intelligence, real-time device data and historical attack records, to form a comprehensive data analysis framework, thereby making the adjustment plan more comprehensive and effective.
[0036] The present invention is described in detail below in conjunction with various embodiments.
[0037] Embodiment 1
[0038] According to an embodiment of the present invention, an embodiment of a method for adjusting a network security policy is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0039] The network security policy adjustment method of the embodiment of the present invention is executed by a network security policy adjustment system. Figure 1is a flow chart of an optional method for adjusting a network security policy according to an embodiment of the present invention, such as Figure 1 As shown, the method comprises the following steps:
[0040] Step S101, determining a network event that triggers a network security policy, and obtaining suspected false alarm data based on the network event.
[0041] In the above step S101, the network security policy is a set of pre-set rules that aims to guide and control data flows and access behaviors in the network environment to protect the network from security threats such as unauthorized access, attacks and data leakage, and plays an important role in the daily operation of the system.
[0042] Network security policies can include firewall rules, intrusion detection policies, access control lists, etc.
[0043] When a network event triggers a network security policy, the system will take a series of actions based on the preset rules and response mechanisms of the network security policy, such as sending alarm notifications, blocking or isolating, and recording the network event in a log for subsequent tracing.
[0044] Here, network events refer to behavioral events detected in network traffic or system logs that match predefined network security policies. For example, when certain features (such as IP addresses, ports, protocols, behavioral patterns, etc.) in network traffic or system logs match the rules in the network security policy, they are recorded as network events that trigger the network security policy.
[0045] Here, suspected false positive data refers to network event records that may be misclassified as threats. A network event record may include: event type (e.g., malicious domain name access), trigger time, source IP address, target IP address, event description (e.g., user attempt to access known malicious domain name detected), severity level, and response measures.
[0046] In some examples, each network event record classified as a threat can be recorded as suspected false positive data.
[0047] In other examples, preset rules or algorithms can be used to filter out network event records that may be false alarms as suspected false alarm data. For example, if the policy rules triggered by the network event are known to have false alarm problems, it is marked as a suspected false alarm; if the source IP or target IP of the network event is in the whitelist, it is marked as a suspected false alarm; if the characteristics of the network event match the known false alarm characteristics, it is marked as a suspected false alarm; or if threat events occur frequently over a period of time, they can also be marked as suspected false alarms.
[0048] It is understandable that network security strategies are not static. As the network environment changes and network attack methods continue to update, network security strategies must also be constantly adjusted and updated.
[0049] Specifically, when adjusting the network security policy, first determine which network events triggered the current security policy through information such as network logs, alarm data, and traffic analysis. In this way, each trigger during the execution of the network security policy can be identified to obtain suspected false alarm data.
[0050] Network events may be, for example, interception of data packets, denial of access requests, or detection of abnormal traffic. These events are the direct result of policy execution and can reflect the real-time effect of the policy.
[0051] After obtaining the network event that triggers the network security policy, trace the source of the network event to obtain suspected false alarm data. The suspected false alarm data may include: event identifier, timestamp, source IP address and target IP address, port number and protocol information, triggered network security policy, event description, etc.
[0052] Optionally, before inputting the suspected false alarm data into the large language model, it also includes: performing a data cleaning operation on the suspected false alarm data to obtain cleaned suspected false alarm data, wherein the data cleaning operation includes at least one of the following: removing incomplete data records, filtering invalid data, removing noise in the suspected false alarm data, and eliminating outliers in the suspected false alarm data; formatting and standardizing the cleaned suspected false alarm data to obtain processed suspected false alarm data, and the processed suspected false alarm data is used as input data for the large language model.
[0053] In some embodiments, after obtaining the data basis for policy adjustment, all collected data are integrated into the system data layer, and the data is pre-processed to ensure the consistency and availability of the data, so as to ensure the accuracy and reliability of subsequent analysis.
[0054] Specifically, when performing data preprocessing, the data is first cleaned. The data cleaning operations include: removing incomplete data records, filtering invalid data, removing noise in suspected false alarm data, and eliminating outliers in suspected false alarm data. Removing incomplete data records can be done by checking whether each data record contains all necessary fields and eliminating records that are missing key information to avoid misleading in the analysis process; filtering invalid data refers to identifying and removing data that is not relevant to the current analysis, such as outdated threat intelligence or irrelevant attack events; removing noise in suspected false alarm data can filter out data that does not meet the conditions through predefined rules or thresholds; eliminating outliers in suspected false alarm data can use statistical methods or machine learning algorithms to identify abnormal data in suspected false alarm data that is significantly different from normal data, thereby reducing interference and false alarms in the analysis process.
[0055] Step S102, inputting the suspected false alarm data and the preset prompt text into the large language model, and outputting the optimization measures of the network security strategy through the large language model in combination with the knowledge base.
[0056] In the above step S102, the large language model is used to provide optimization measures for the network security strategy, and the knowledge base also pre-stores multi-source knowledge data, and the knowledge data specifically includes at least one of the following: user behavior data, historical attack data and security standard data.
[0057] User behavior data is used to record various behaviors of users on the Internet, such as visiting websites, downloading files, and other behavioral data.
[0058] Historical attack data is used to record historical network attack events, including detailed information such as attack type, attack method, attack source, and attack target.
[0059] Security standard data may include various network security standards and specifications, such as data encryption standards, access control policies, security audit requirements, etc.
[0060] Optionally, the large language model is obtained by fine-tuning an initial large language model after pre-training, and the fine-tuning training process includes: obtaining a training set, the training set including multiple historical false alarm data and a strategy optimization label configured for each historical false alarm data; calling a pre-built knowledge base, and fine-tuning the initial large language model based on the training set and the prompt text.
[0061] In some embodiments, through fine-tuning training of a large language model, the model learns to generate effective policy adjustment solutions based on false positive data and threat intelligence, device status and historical events provided by multi-source data. In this way, the system has the ability of automated analysis and policy optimization, reduces dependence on manpower, and improves the efficiency and effectiveness of policy adjustment.
[0062] For example, in the fine-tuning process of the large language model, firstly, the historical false alarm data that triggered the network security policy in the historical time period is collected from the log data, alarm data and other channels of the network equipment to build a comprehensive and representative sample set as the basis for training the large language model. Based on the collected historical false alarm data and the pre-built prompt text, the model is guided to conduct in-depth analysis and reasoning in combination with the knowledge data in the knowledge base.
[0063] The prompt text includes system prompts, thinking chain prompts and function prompts, ensuring that the model simulates the thinking logic of experts when processing data and follows a reasonable logical flow and thinking pattern.
[0064] Build sample data based on historical false positive data, and configure optimized labels for each piece of sample data. For example, network security experts can mark the optimal policy adjustment results for these historical data, provide clear goals and feedback for the model, and enhance the guidance and effect of model learning. Build sample data sets using historical false positive data and optimized labels. Sample data sets are the materials for model training and contain all the information that the model needs to learn.
[0065] In some examples, in order to ensure the accuracy of model training and evaluation, sample data is divided into training sets and test sets. The training set is used to train the model, while the test set is used to evaluate the performance of the model on unlearned data and verify the generalization ability and optimization effect of the model.
[0066] Large language models usually have powerful data processing and logical reasoning capabilities and can perform complex reasoning. Based on the training set, the initial large language model is fine-tuned and trained. By adjusting the model parameters, the model can more accurately learn how to generate policy adjustment plans indicated by optimization labels based on prompt text and historical data. After completing the fine-tuning training, the trained large language model is tested using the test set to evaluate its accuracy and effectiveness when processing new data. The test results reflect the generalization ability of the model, that is, whether the model can correctly identify problems in network policies and propose effective optimization measures when processing untrained data. If the test results show that the model can pass the test, that is, its performance meets the predetermined standards, then this model can be used as a trained large language model for actual network security policy optimization tasks.
[0067] In the above steps, guided training and rigorous testing ensure that the optimization strategies learned by the model are targeted and effective.
[0068] In the embodiment of the present invention, a pre-constructed knowledge base is used to assist the large language model in analysis. The large language model stores multi-source knowledge data collected from multiple channels, involving real-time data and historical data, which may specifically include: user behavior data, historical attack data and security standard data. In addition, it may also include real-time operation data of network equipment, third-party threat intelligence and historical attack event records, and network security policies.
[0069] Specifically, through the preset interface or probe, you can pull real-time operation data from network devices, including but not limited to device status, traffic information, alarm events and configuration details. This is to ensure that the analysis is based on the latest network status and can promptly reflect changes and potential threats in the network environment. When new changes or potential threats occur, it is necessary to add new network security policies to resist external threats. The types of the above network devices include but are not limited to: desktop computers, firewalls, servers, virtual machines and other devices.
[0070] In addition, the system can establish connections with multiple third-party security intelligence platforms to automatically obtain the latest threat intelligence and security standard data, such as known malicious IP addresses, domain names, vulnerability information, attack methods, traffic thresholds, etc. This is of great significance for identifying potential threats and attack behaviors in the network and improving the pertinence and effectiveness of policy optimization.
[0071] In an optional embodiment, the system can extract attack event records from the historical database, including historical security events, attack sources, attack times, event processing results, etc. Based on the historical attack event records, the use of network security policies can be identified to determine whether the network security policies are real false positive data, thereby better guiding policy adjustment and optimization.
[0072] In an optional embodiment, the system can obtain the currently configured network security policies from the network device, which may include firewall rules, intrusion detection policies, access control lists, etc., so that the model can fully understand the current network protection measures and identify possible abnormal situations, such as policy redundancy, policy conflicts, etc., to provide basic data for policy adjustment.
[0073] The embodiment of the present invention constructs a comprehensive analysis framework by integrating multi-source data, providing a comprehensive data foundation for in-depth analysis and intelligent optimization of network security strategies, and improving the effectiveness and comprehensiveness of network security strategies.
[0074] Optionally, the step of outputting optimization measures for network security policies through a large language model in combination with a knowledge base includes: extracting target knowledge data from the knowledge base through a large language model, and comparing and analyzing the extracted target knowledge data with suspected false alarm data to obtain analysis results; when the analysis results indicate that the suspected false alarm data is real false alarm data, outputting optimization measures for the network security policy.
[0075] In an embodiment of the present invention, the large language model identifies the false alarm attributes of suspected false alarm data through a series of data comparison and analysis, and then outputs optimization measures of the network security policy based on the false alarm attributes. Specifically, after receiving the suspected false alarm data, the large language model calls the knowledge base, and extracts the knowledge data of the corresponding target from the knowledge base based on the characteristics such as the type of network event involved in the suspected false alarm data and the triggered network security policy, and then compares and analyzes the relevant features of the suspected false alarm data with the target knowledge data. For example: using the pattern recognition ability of the large model, it is determined whether the suspected false alarm data matches the legitimate network activity pattern in the knowledge base; or, the features in the suspected false alarm data are compared with known threat intelligence to determine whether it is a real threat. Thus, the false alarm attributes of the suspected false alarm data are determined according to the analysis results. If the suspected false alarm data is indeed false alarm data, the optimization measures of the network security policy are output.
[0076] Optionally, the step of comparing and analyzing the extracted target knowledge data with the suspected false alarm data includes: the large language model performs chain reasoning based on the system prompts and thinking chain prompts in the prompt text, compares the target knowledge data with the suspected false alarm data, and identifies whether the suspected false alarm data is real false alarm data based on the comparison result to obtain a recognition result; when the recognition result indicates that the suspected false alarm data is real false alarm data, the large language model performs deep reasoning based on the functional prompts in the prompt text to identify the cause of the false alarm; and generates an analysis result based on the real false alarm data and the cause of the false alarm.
[0077] Furthermore, when comparing and analyzing the extracted target knowledge data with the suspected false alarm data, the large language model performs chain reasoning and deep reasoning based on the pre-built prompt text to identify the data in the suspected false alarm data that are actually true false alarm data, and determine the cause of the false alarm, thereby filtering out the true false alarm data from the suspected false alarm data.
[0078] Specifically, first, the large language model performs chain reasoning based on the system prompts and thinking chain prompts in the prompt text. The system prompts define the model's code of conduct to ensure that its reasoning process follows the standards and rules in the field of network security; while the thinking chain prompts guide the model on how to analyze the problem step by step to form a logically coherent reasoning chain. Based on the system prompts and thinking chain prompts, the large language model gradually compares the extracted "target knowledge data" with the "suspected false alarm data" in detail, identifies the similarities, differences and potential associations between the two, and thus determines whether the suspected false alarm data is really true false alarm data. Furthermore, for network events that are true false alarm data, deep reasoning is performed based on the functional prompts in the prompt text to ensure that the model focuses on specific aspects of the false alarm data for analysis, such as rule settings, algorithm defects, business processes, etc. Through deep reasoning, the model can identify the specific reasons for false positives, including but not limited to: the rules are too broad, misjudging normal network behavior as a threat; the thresholds set by the rules are inaccurate, resulting in legitimate traffic being intercepted incorrectly; the system is not adaptable enough to specific network environments, making it difficult to distinguish between normal activities and abnormal behaviors; historical data or third-party intelligence is biased, affecting the accuracy of the strategy. Finally, based on the suspected false positive data that is real false positive data and the analyzed false positive causes, false positive data is generated as a technology to output network security strategy optimization measures.
[0079] For example, system prompts can establish the behavioral framework and basic principles of the model. For example, the system prompts may include: "You are a world-class AI system with complex reasoning and reflection capabilities. When processing cybersecurity data, you must conduct a comprehensive, natural and unfiltered thinking process before responding." The system prompts ensure that the model's behavior is consistent with the expectations of cybersecurity policy optimization and avoid the model from producing reasoning results that are inconsistent with the goals.
[0080] The thinking chain prompts guide the model on how to think through chain thinking, draw conclusions, and self-evaluate and reflect on whether the conclusions are correct. For example, the thinking chain prompts may include: "Your thinking sequence should follow the following process: first contact, form an initial impression and consider the broader context of the problem; problem exploration, break down the problem into core parts, determine explicit and implicit requirements, and consider any constraints or limitations; knowledge synthesis, connect different information, including what you know and what is provided, and conduct comprehensive analysis. Multiple hypothesis generation, write down multiple possible explanations for the problem, consider multiple solutions, and avoid premature commitment to a single explanation; natural discovery process, in the thinking process, start from the obvious aspects, pay attention to patterns or connections, question the initial assumptions and establish new connections, and gradually build deeper insights; testing and verification, test preliminary conclusions, and look for potential flaws or gaps; error identification and correction, naturally admit mistakes, explain why previous ideas are incomplete or incorrect, and rethink; self-evaluation and output, when you are sure that your output can solve the problem raised, output your answer." By following the thought chain prompts, the model can systematically analyze network security data, reason step by step according to the complexity of the problem, ensure the consistency and depth of the analysis process, and improve the quality of strategy optimization recommendations.
[0081] Functional prompts are used to restrict and align the model's thinking process to ensure that the model is more refined and accurate in policy optimization tasks. For example, a functional prompt may be described as: "You will help optimize the network security policies of devices such as firewalls and intrusion detection systems to achieve more accurate threat detection and fewer false positives. Your goal is to optimize policy rules and reduce false positives while ensuring detection capabilities. You will find the best balance between false positive reduction and detection accuracy through fine-tuning of policies." Functional prompts clarify the model's specific goals in the current task, point out the direction of optimization strategies for the model, and ensure that the recommendations it generates are directly targeted at the problems existing in the network security policies of network security devices, achieving the pertinence and effectiveness of the task.
[0082] In this embodiment, the system pre-builds prompt texts including system prompts, thought chain prompts, and function prompts to guide the model to reason and analyze specific strategy optimization tasks, ensuring the depth, logic, and goal orientation of the model reasoning process.
[0083] Another optional embodiment compares the target knowledge data with the suspected false alarm data, and identifies whether the suspected false alarm data is real false alarm data based on the comparison result, and obtains the comparison result including: extracting features through the chain reasoning layer of the large language model, and extracting features from the historical attack event data, user behavior data and security standard data in the target knowledge data and the suspected false alarm data under the guidance of system prompts and function prompts of the chain reasoning layer, so as to obtain network security identification features and suspected false alarm features; comparing the network security identification features with the suspected false alarm features to obtain a comparison result; identifying the false alarm network security policy through the comparison result to obtain an identification result.
[0084] In the above step S102, the network security strategy is intelligently optimized through the large language model to ensure that the network security strategy can meet the changes in the network environment and maintain the efficiency, intelligence and flexibility of the strategy optimization to resist malicious attacks. The large language model is used to provide optimization measures for the network security strategy, and is trained through a large amount of historical data and expert knowledge to enable it to understand the complexity of the network security strategy and the diversity of the network environment. The core of the large language model is to use the thinking chain technology for step-by-step reasoning, and identify false positives of the network security strategy by simulating the decision-making process of experts.
[0085] In addition, the embodiments of the present invention can also identify redundancy, conflict in network security policies and anomalies in the network environment based on multi-source data, and then adjust the existing network security policies according to the redundancy, conflict and network security anomalies in the network security policies.
[0086] In an optional embodiment, after the suspected false alarm data and the prompt text are input into the large language model, the knowledge base is called, and the network security data in the knowledge base is feature extracted through the feature extraction layer of the large language model to obtain network security features; the network security features are input into the chain reasoning layer of the large language model, and the network security features are analyzed through the chain reasoning layer to identify abnormal features of the network security policy, wherein the abnormal features are used to characterize abnormal situations of the network security policy, and the abnormal situations include policy redundancy and policy conflict; the network security features and the abnormal features are input into the deep reasoning layer of the large language model, and the potential abnormal behavior features of the network device and the false alarm cause features of the policy false alarm are identified through the deep reasoning layer; through the large language model, optimization measures are configured for the network security policy based on the prompt text, abnormal features, and potential abnormal behavior features, and the optimization measures are output.
[0087] For example, first, the network security data collected in real time, including network device logs, traffic information, and attack event records, are stored in the knowledge base. The feature extraction layer uses machine learning technology to conduct in-depth analysis of multi-source data in the knowledge base and extract key features that can characterize the network environment status and policy operation status, such as traffic patterns, access frequency, distribution of source and destination IP addresses, policy types, policy actions, etc. These network security features are the basis for subsequent reasoning and optimization.
[0088] Subsequently, the extracted network security features are passed to the chain reasoning layer of the large language model. The chain reasoning layer simulates the logical reasoning process of experts and adopts the "thinking chain" reasoning method to analyze the network security features step by step. The goal of the chain reasoning layer is to identify abnormal features corresponding to abnormal situations in network security policies, including policy redundancy, policy conflict, and policy false positives. Redundant policies refer to the existence of multiple rules with similar functions in the network, resulting in resource waste and reduced efficiency; conflicting policies refer to contradictions between rules, which may cause security vulnerabilities; false positive policies are due to improper rule settings, which mistakenly identify normal traffic as threats, increasing the workload of administrators. Through chain reasoning, the model can accurately locate abnormal features and provide a clear direction for subsequent in-depth analysis.
[0089] The deep reasoning layer of the large language model further processes network security features and abnormal features, identifying potential abnormal behavior features of network devices, such as abnormal traffic patterns, abnormal access attempts, etc. At the same time, this layer can also analyze abnormal features and identify specific reasons for policy false positives, such as overly broad rule settings and algorithm misidentification. The work of the deep reasoning layer is not limited to surface feature matching. More importantly, it can combine historical data and third-party intelligence to gain insight into the deep-seated reasons behind potential security threats and false positives, providing a more comprehensive and in-depth basis for policy optimization.
[0090] Based on the above analysis results, the last stage of the large language model is to generate optimization measures. This process is guided by the prompt text. The large language model combines abnormal characteristics, potential abnormal behavior characteristics, and false alarm cause characteristics to propose specific optimization measures, such as adjusting rule thresholds, merging similar rules, updating policy matching algorithms, and adding new network security policies. The output optimization measures are customized solutions for the current network environment and policy configuration, aiming to effectively solve the identified problems and improve the accuracy and efficiency of the policy.
[0091] In another optional embodiment, the above-mentioned step of analyzing network security features through a chain reasoning layer to identify abnormal features of network security policies specifically includes: extracting features of each network security policy through a chain reasoning layer to obtain policy features corresponding to the network security policies, wherein the policy features include at least one of the following: policy action features, policy execution environment features, and policy execution condition features; comparing the policy features of each network security policy to obtain a first comparison result; identifying redundant network security policies and conflicting network security policies through the first comparison result; and generating abnormal features of the network security policies based on the redundant network security policies and conflicting network security policies.
[0092] Exemplarily, when identifying abnormal features of network security policies, it specifically includes the identification of redundant policy features and conflicting policy features. First, the chain reasoning layer of the large language model extracts features for each network security policy to obtain policy features, which include but are not limited to policy action features, policy execution environment features, and policy execution condition features. Policy action features involve specific operations defined in the policy, such as allow, deny, monitor, etc.; policy execution environment features consider the network context information of policy execution, including network topology, device type, operating system version, etc.; policy execution condition features focus on the prerequisites for the policy to take effect, such as time, geographic location, traffic type, etc. By extracting these features for each policy, the model can understand the intent and scope of application of the policy, and provide structured data support for subsequent analysis.
[0093] Next, the extracted policy features are compared to obtain the first comparison result to identify similar or conflicting policies, namely redundant network security policies and conflicting network security policies. Redundant policies refer to policies with overlapping functions or repeated conditions. The existence of honor policies not only wastes network resources, but also may lead to inefficient policy execution. Conflicting policies refer to logical contradictions between two or more policies, which may cause security policies to fail to execute correctly or create security vulnerabilities. Through feature comparison, the large language model can accurately identify these abnormal policies and provide clear goals for the generation of optimization measures.
[0094] Another optional embodiment extracts the operation status data of the network device and a third party from the knowledge base, and extracts the operation status features and threat features from the operation status data and threat data respectively; and matches the operation status features of the network device with the threat features. When the two are successfully matched, it is determined that the network device has an operation abnormality, and potential abnormal behavior features are obtained, thereby identifying the abnormal behavior existing in the network device.
[0095] Through the above steps, based on the identification of redundant network security policies and conflicting network security policies, the chained reasoning layer generates abnormal features of network security policies, which provides a solid foundation for the generation of policy optimization measures.
[0096] Step S103: adjusting the network security policy according to the optimization measure of the network security policy.
[0097] In step S103, after obtaining the optimization measures generated by the large language model, the system will adjust the network security policy according to the corresponding optimization measures. The optimization measures may include adjusting the thresholds of certain policy rules, merging repeated or similar rules, deleting redundant or conflicting policies, updating the policy matching algorithm, and adding new security network policies for specific attack behaviors.
[0098] Optionally, after adjusting the network security policy according to the optimization measures of the network security policy, it also includes: collecting feedback information after the adjustment of the network security policy; inputting the feedback information into the large language model as input data for the next time the large language model outputs the optimization measures of the network security policy.
[0099] In some embodiments, after the network security policy is adjusted and implemented, the system begins to collect feedback information. Feedback information can come from multiple channels, including but not limited to real-time performance data of network devices, user experience feedback, alarm records of security events, etc. The purpose of this step is to collect actual effect data after the policy adjustment, as well as any possible side effects or new problems, to provide updated environmental information and optimization requirements for the large language model.
[0100] The system preprocesses and analyzes the collected feedback information to extract features and indicators related to the policy effect. Preprocessing may include data cleaning, standardization, and formatting to ensure data consistency and comparability. This analysis process helps the system understand the real effect of policy adjustments, including changes in alarm rates, improvements or declines in network performance, user satisfaction feedback, etc., providing accurate data support for subsequent optimization.
[0101] The analyzed feedback information is input into the large language model as input data for the next large language model output optimization measures. This ensures that the model can learn based on the latest network environment status and policy adjustment effects, continuously optimize its reasoning logic and optimization strategy, and realize an adaptive and self-learning intelligent optimization process. At the same time, the model will combine historical data and feedback information to evaluate the effectiveness of the current output optimization measures and identify any areas that need further adjustment.
[0102] The self-assessment mechanism of the embodiment of the present invention builds a closed-loop intelligent optimization process to ensure the continuous improvement and adaptability of network security policies. By collecting adjusted feedback information and inputting it into the large language model, the system can learn and adjust based on actual results, reducing dependence on experts and improving the automation and standardization of policy optimization.
[0103] Optionally, adjusting the network security policy according to the optimization measures of the network security policy includes: displaying the optimization measures to the user terminal through a visual interface; receiving operation instructions for the optimization measures from the user terminal, and adjusting the network security policy based on the operation instructions, wherein the operation instructions include one of the following: automatic adjustment instructions, manual adjustment instructions.
[0104] Specifically, the system presents the generated optimization measures to the user through an intuitive and interactive visual interface. The interface lists each optimization suggestion in detail, including the background of the suggestion, the expected effect, the implementation steps, and the possible impact. It may contain various charts, data comparisons, and text descriptions to help users quickly understand the content and purpose of the optimization measures. For example, the chart can intuitively show the change in alarm frequency before and after the policy adjustment, network performance improvement and other indicators, helping users evaluate the necessity of implementing policy adjustments.
[0105] Furthermore, users can operate the displayed optimization measures through the visual interface. Operation instructions mainly include two types: automatic adjustment instructions. Users choose this instruction to agree that the system will automatically execute optimization measures without manual intervention. The system will automatically adjust the policy configuration of network devices according to the optimization suggestions to achieve rapid response and policy optimization; manual adjustment instructions. Users can also choose manual adjustment instructions. Manual adjustment and application optimization measures allow users to customize the recommended optimization measures, such as adjusting rule thresholds, modifying rule conditions, etc., to adapt to specific business needs or security policies. After the user completes the manual adjustment, he can choose to apply the optimization measures, and the system will make policy adjustments based on the user's modified optimization measures.
[0106] Through the above steps, the accuracy and compliance of policy adjustments are ensured, which not only meets the efficient requirements of automation, but also retains the flexibility of manual adjustment, so that policy adjustments can take into account both efficiency and accuracy.
[0107] Through the above steps, the network events that trigger the network security policy are determined, and suspected false alarm data is obtained based on the network events; the suspected false alarm data and the preset prompt text are input into the large language model, and the optimization measures of the network security policy are output through the large language model in combination with the knowledge base, wherein the large language model is used to provide optimization measures for the network security policy, and the knowledge base pre-stores knowledge data, and the knowledge data includes at least one of the following: user behavior data, historical attack data and security standard data; the network security policy is adjusted according to the optimization measures of the network security policy.
[0108] In this embodiment, the collected suspected false alarm data and the pre-formulated prompt text are input into a pre-built large language model, which is guided to perform chain reasoning and deep analysis, automatically identify false alarm events, and configure network security policy adjustment plans for false alarm events to adapt to the ever-changing network environment, thereby achieving the purpose of intelligently adjusting and optimizing network security policies, and achieving the technical effect of improving the efficiency of network security policy adjustment, thereby solving the technical problem of low efficiency in the related technology of relying on expert experience to manually analyze and adjust massive network security policies.
[0109] Another optional specific implementation is described in detail below.
[0110] Figure 2 is an optional network security policy adjustment system architecture diagram according to an embodiment of the present invention, such as Figure 2 As shown, the network security strategy adjustment system includes a data acquisition module, a data analysis and large model reasoning module, an optimization measure generation and self-assessment module, and a display and application module.
[0111] The data collection module is used to collect data from multiple sources, including network equipment operation data, third-party threat intelligence, historical attack event records, and industry security standards, and build a knowledge base. The knowledge base is used to assist the large language model in chain reasoning and in-depth analysis, ensuring the extensiveness and real-time nature of the data, and providing comprehensive and rich data support for subsequent analysis.
[0112] Data analysis and large model reasoning module, which uses large models and thought chain technology to conduct in-depth analysis of collected data. Its main tasks include data preprocessing, large model thought chain reasoning and anomaly identification.
[0113] Data preprocessing is to format and standardize data from different sources to ensure data consistency.
[0114] The thought chain reasoning task uses the chain reasoning ability of the large model to analyze the data step by step to identify redundancy, conflict and false positives in network policies.
[0115] Pattern recognition uses the deep reasoning capabilities of large models to discover potential attack patterns and abnormal behaviors of network devices, as well as the root causes of false alarms, laying the foundation for policy optimization.
[0116] The optimization measure generation and self-assessment module generates optimization suggestions for network security policies based on the results of analysis and reasoning, and generates specific policy optimization suggestions in combination with the security policy library, risk assessment standards and current network environment characteristics. Optimization suggestions can include adjusting rule priorities, adding or deleting policy items, etc., and ensure the effectiveness of the policy through automated preliminary verification. At the same time, in this module, users / big models / third-party data can provide feedback on the generated optimization suggestions, obtain feedback information, and incorporate these feedback information as input information into the next big language model reasoning process, and make adjustments directly through chain thinking to improve the accuracy of policy suggestions. The system also regularly checks the policy through the self-assessment mechanism, and dynamically verifies and adjusts the optimization plan in combination with the actual effect of real-time device operation data. With the help of feedback and self-assessment mechanisms, the system can adapt in real time to the ever-changing network environment and realize intelligent self-optimization of network security policies.
[0117] The display and application module displays optimization measures through a visual interface, providing users with detailed optimization content, expected results and implementation suggestions. It also provides users with manual application mechanisms and automatic application mechanisms, providing users with multiple application options. Users can review and adjust the optimization measures generated by the system through the manual application mechanism to ensure that the suggestions meet actual needs.
[0118] Figure 3 FIG. 1 is a schematic diagram of an optional adjustment process of a network security policy according to an embodiment of the present invention. Figure 3 As shown in the figure, the network security policy adjustment process specifically includes:
[0119] Step 1, start;
[0120] Step 2: Pre-process the recent data on the device and sort out the suspected false positive data;
[0121] Step 3: Combine user behavior data, historical attack data, and the latest security standards, and obtain multi-source third-party data to build a knowledge base;
[0122] Step 4: Input the suspected false alarm data and prompt text into the large model (corresponding to the large language model mentioned above);
[0123] Step 5: Use the big model combined with the thinking chain mechanism to reason and analyze to identify whether there is an anomaly. If so, proceed to step 6. If not, there is no need to optimize the strategy and proceed to step 10.
[0124] Step 6: Identify abnormal strategies;
[0125] Step 7: Generate strategy optimization measures;
[0126] Step 8: The model self-evaluates the quality of the optimization measures. If the evaluation passes, step 9 is executed. If the evaluation fails, steps 7 to 8 are repeated after retrieving relevant knowledge from a multi-source third-party knowledge base.
[0127] Step nine, generating policy optimization measures, and adjusting the network security policy through the policy optimization measures;
[0128] Step 10, end.
[0129] In the embodiment of the present invention, the computing power of the large model and the step-by-step reasoning ability of the thinking chain can be used to quickly and accurately generate adjustment plans and optimization suggestions for network security policies, significantly improving the efficiency and accuracy of policy adjustment and optimization. At the same time, multi-source network security data, including threat intelligence, real-time device data and historical attack records, are integrated to form a comprehensive analysis framework, making the adjustment plan more comprehensive and effective.
[0130] Embodiment 2
[0131] A network security policy adjustment device provided in this embodiment includes multiple implementation units, each implementation unit corresponds to each implementation step in the above-mentioned embodiment 1. Its specific implementation method and beneficial effects can refer to the above-mentioned method embodiment and will not be repeated here.
[0132] Figure 4 is a schematic diagram of an optional network security policy adjustment device according to an embodiment of the present invention, such as Figure 4 As shown, the network security policy adjustment device may include: an acquisition unit 41, an output unit 42, and an adjustment unit 43, wherein:
[0133] An acquisition unit 41 is used to determine a network event that triggers a network security policy, and acquire suspected false alarm data based on the network event;
[0134] The output unit 42 is used to input the suspected false alarm data and the preset prompt text into the large language model, and output the optimization measures of the network security strategy through the large language model and the knowledge base, wherein the large language model is used to provide optimization measures for the network security strategy, and the knowledge base pre-stores knowledge data, and the knowledge data includes at least one of the following: user behavior data, historical attack data, and security standard data;
[0135] The adjusting unit 43 is used to adjust the network security policy according to the optimization measure of the network security policy.
[0136] The above-mentioned network security policy adjustment device determines the network event that triggers the network security policy through the acquisition unit 41, and obtains suspected false alarm data based on the network event; inputs the suspected false alarm data and the preset prompt text into the large language model through the output unit 42, and outputs the optimization measures of the network security policy through the large language model in combination with the knowledge base, wherein the large language model is used to provide optimization measures for the network security policy, and the knowledge base pre-stores knowledge data, and the knowledge data includes at least one of the following: user behavior data, historical attack data and security standard data; and adjusts the network security policy according to the optimization measures of the network security policy through the adjustment unit 43.
[0137] In this embodiment, the collected suspected false alarm data and the pre-formulated prompt text are input into a pre-built large language model, which is guided to perform chain reasoning and deep analysis, automatically identify false alarm events, and configure network security policy adjustment plans for false alarm events to adapt to the ever-changing network environment, thereby achieving the purpose of intelligently adjusting and optimizing network security policies, and achieving the technical effect of improving the efficiency of network security policy adjustment, thereby solving the technical problem of low efficiency in the related technology of relying on expert experience to manually analyze and adjust massive network security policies.
[0138] Optionally, the output unit includes: a first analysis module, used to extract target knowledge data from the knowledge base through a large language model, and compare and analyze the extracted target knowledge data with the suspected false alarm data to obtain an analysis result; a first output module, used to output optimization measures for the network security policy when the analysis result indicates that the suspected false alarm data is real false alarm data.
[0139] Optionally, the first analysis module includes: a first reasoning sub-module, which is used for the large language model to perform chain reasoning based on the system prompts and thinking chain prompts in the prompt text, compare the target knowledge data with the suspected false alarm data, and identify whether the suspected false alarm data is real false alarm data according to the comparison result to obtain the recognition result; a second reasoning sub-module, which is used for the large language model to perform deep reasoning based on the functional prompts in the prompt text to identify the cause of the false alarm when the recognition result indicates that the suspected false alarm data is real false alarm data; and a first generation sub-module, which is used to generate analysis results based on the real false alarm data and the cause of the false alarm.
[0140] Optionally, the adjustment unit 43 includes: a first collection module, used to collect feedback information after adjusting the network security policy; and a first serving module, used to input the feedback information into the large language model as input data for the next time the large language model outputs optimization measures for the network security policy.
[0141] Optionally, the large language model is obtained by fine-tuning an initial large language model after pre-training. The network security policy adjustment device also includes a training unit, which is used to: the process of fine-tuning training includes: obtaining a training set, the training set includes multiple historical false alarm data and a policy optimization label configured for each historical false alarm data; calling a pre-built knowledge base, and fine-tuning the initial large language model based on the training set and the prompt text.
[0142] Optionally, the network security policy adjustment device also includes a preprocessing unit, which includes: a first cleaning module, used to perform data cleaning operations on suspected false alarm data to obtain cleaned suspected false alarm data, wherein the data cleaning operation includes at least one of the following: removing incomplete data records, filtering invalid data, removing noise in suspected false alarm data, and eliminating abnormal values in suspected false alarm data; a first processing module, used to format and standardize the cleaned suspected false alarm data to obtain processed suspected false alarm data.
[0143] Optionally, the adjustment unit 43 includes: a first display module, used to display optimization measures to the user terminal through a visual interface; a first adjustment module, used to receive operation instructions from the user terminal for the optimization measures, and adjust the network security policy based on the operation instructions, wherein the operation instructions include one of the following: automatic adjustment instructions, manual adjustment instructions.
[0144] It should be noted that the acquisition unit 41, output unit 42, and adjustment unit 43 correspond to steps S101 to S103 in the first embodiment. The examples and application scenarios implemented by the four modules and the corresponding steps are the same, but are not limited to the contents disclosed in the first embodiment.
[0145] The above-mentioned network security policy adjustment device may also include a processor and a memory. The above-mentioned acquisition unit 41, output unit 42, adjustment unit 43, etc. are all stored in the memory as program units, and the processor executes the above-mentioned program units stored in the memory to implement corresponding functions.
[0146] The processor includes a kernel, which retrieves the corresponding program unit from the memory. One or more kernels can be set, and the network security strategy can be intelligently optimized by adjusting kernel parameters.
[0147] The above-mentioned memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one storage chip.
[0148] According to another aspect of an embodiment of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium including a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute any one of the above-mentioned network security policy adjustment methods.
[0149] According to another aspect of an embodiment of the present invention, there is also provided an electronic device, comprising one or more processors and a memory, wherein the memory is used to store one or more programs, wherein when the one or more programs are executed by one or more processors, the one or more processors implement any one of the above-mentioned methods for adjusting the network security policies.
[0150] According to another aspect of an embodiment of the present invention, a computer program product is further provided. The computer program product includes a computer program, wherein when the computer program is executed by a processor, any one of the above-mentioned methods for adjusting the network security policy is implemented.
[0151] The present application also provides a computer program product, which, when executed on a data processing device, is suitable for executing a program that initializes the following method steps: determining a network event that triggers a network security policy, and obtaining suspected false alarm data based on the network event; inputting the suspected false alarm data and a preset prompt text into a large language model, and outputting optimization measures for the network security policy through the large language model in combination with a knowledge base, wherein the large language model is used to provide optimization measures for the network security policy, and the knowledge base pre-stores knowledge data, and the knowledge data includes at least one of the following: user behavior data, historical attack data, and security standard data; and adjusting the network security policy according to the optimization measures of the network security policy.
[0152] Optionally, the step of outputting optimization measures for network security policies through a large language model in combination with a knowledge base includes: extracting target knowledge data from the knowledge base through a large language model, and comparing and analyzing the extracted target knowledge data with suspected false alarm data to obtain analysis results; when the analysis results indicate that the suspected false alarm data is real false alarm data, outputting optimization measures for the network security policy.
[0153] Optionally, the step of comparing and analyzing the extracted target knowledge data with the suspected false alarm data includes: the large language model performs chain reasoning based on the system prompts and thinking chain prompts in the prompt text, compares the target knowledge data with the suspected false alarm data, and identifies whether the suspected false alarm data is real false alarm data based on the comparison result to obtain a recognition result; when the recognition result indicates that the suspected false alarm data is real false alarm data, the large language model performs deep reasoning based on the functional prompts in the prompt text to identify the cause of the false alarm; and generates an analysis result based on the real false alarm data and the cause of the false alarm.
[0154] Optionally, after adjusting the network security policy according to the optimization measures of the network security policy, it also includes: collecting feedback information after the adjustment of the network security policy; inputting the feedback information into the large language model as input data for the next time the large language model outputs the optimization measures of the network security policy.
[0155] Optionally, the large language model is obtained by fine-tuning an initial large language model after pre-training, and the fine-tuning training process includes: obtaining a training set, the training set including multiple historical false alarm data and a strategy optimization label configured for each historical false alarm data; calling a pre-built knowledge base, and fine-tuning the initial large language model based on the training set and the prompt text.
[0156] Optionally, before inputting the suspected false alarm data into the large language model, it also includes: performing a data cleaning operation on the suspected false alarm data to obtain cleaned suspected false alarm data, wherein the data cleaning operation includes at least one of the following: removing incomplete data records, filtering invalid data, removing noise in the suspected false alarm data, and eliminating outliers in the suspected false alarm data; formatting and standardizing the cleaned suspected false alarm data to obtain processed suspected false alarm data.
[0157] Optionally, adjusting the network security policy according to the optimization measures of the network security policy includes: displaying the optimization measures to the user terminal through a visual interface; receiving operation instructions for the optimization measures from the user terminal, and adjusting the network security policy based on the operation instructions, wherein the operation instructions include one of the following: automatic adjustment instructions, manual adjustment instructions.
[0158] Figure 5 1 is a hardware structure block diagram of an electronic device (or mobile device) for executing a method for adjusting a network security policy according to an embodiment of the present invention. Figure 5 As shown, the electronic device may include one or more processors ( Figure 5 502a, 502b, ..., 502n are used to illustrate that the processor may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA, etc.), a memory 505 for storing data. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the I / O interface), a network interface, a keyboard, a power supply and / or a camera. A person skilled in the art can understand that Figure 5 The structure shown is only for illustration and does not limit the structure of the above electronic device. Figure 5 More or fewer components as shown, or with Figure 5 Different configurations are shown.
[0159] The serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages or disadvantages of the embodiments.
[0160] In the above embodiments of the present invention, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0161] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only schematic. For example, the division of units can be a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.
[0162] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed over multiple units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0163] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0164] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for a computer device (which can be a personal computer, a server or a network device, etc.) to perform all or part of the steps of the methods of each embodiment of the present invention. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, magnetic disk or optical disk and other media that can store program codes.
[0165] The above are only preferred embodiments of the present invention. It should be pointed out that, for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.
Claims
1. A method for adjusting a network security strategy, characterized in that: include: Determine a network event that triggers a network security policy, and obtain suspected false positive data based on the network event; Inputting the suspected false alarm data and the preset prompt text into a large language model, and outputting optimization measures for the network security strategy through the large language model and in combination with a knowledge base, wherein the large language model is used to provide optimization measures for the network security strategy, and the knowledge base pre-stores knowledge data, and the knowledge data includes at least one of the following: user behavior data, historical attack data, and security standard data; The network security policy is adjusted according to the optimization measures of the network security policy.
2. The method according to claim 1, characterized in that The steps of outputting optimization measures of network security strategies by combining the large language model with the knowledge base include: Extracting target knowledge data from the knowledge base through the large language model, and comparing and analyzing the extracted target knowledge data with the suspected false positive data to obtain an analysis result; When the analysis result indicates that the suspected false alarm data is real false alarm data, an optimization measure of the network security policy is output.
3. The method according to claim 2, characterized in that The step of comparing and analyzing the extracted target knowledge data with the suspected false positive data to obtain the analysis result comprises: The large language model performs chain reasoning based on the system prompts and the thought chain prompts in the prompt text, compares the target knowledge data with the suspected false alarm data, and identifies whether the suspected false alarm data is real false alarm data according to the comparison result to obtain a recognition result; In the case where the recognition result indicates that the suspected false alarm data is real false alarm data, the large language model performs deep reasoning based on the functional prompt in the prompt text to identify the cause of the false alarm; The analysis result is generated based on the actual false alarm data and the false alarm cause.
4. The method according to claim 1, characterized in that: After adjusting the network security policy according to the optimization measure of the network security policy, the method further includes: Collecting feedback information after adjusting the network security strategy; The feedback information is input into the large language model as input data for the next time the large language model outputs optimization measures for the network security policy.
5. The method according to claim 1, characterized in that The large language model is obtained by fine-tuning the initial large language model after pre-training, and the process of fine-tuning includes: Acquire a training set, wherein the training set includes a plurality of historical false alarm data and a strategy optimization label configured for each piece of the historical false alarm data; A pre-built knowledge base is called, and fine-tuning training is performed on the initial large language model based on the training set and the prompt text.
6. The method according to claim 1, characterized in that Before inputting the suspected false positive data into the large language model, the method further includes: Performing a data cleaning operation on the suspected false alarm data to obtain the cleaned suspected false alarm data, wherein the data cleaning operation includes at least one of the following: removing incomplete data records, filtering invalid data, removing noise in the suspected false alarm data, and eliminating abnormal values in the suspected false alarm data; The cleaned suspected false alarm data is formatted and standardized to obtain the processed suspected false alarm data.
7. The method according to claim 1, characterized in that Adjusting the network security policy according to the optimization measure of the network security policy includes: Displaying the optimization measures to the user terminal through a visual interface; Receive an operation instruction from the user terminal for the optimization measure, and adjust the network security policy based on the operation instruction, wherein the operation instruction includes one of the following: an automatic adjustment instruction and a manual adjustment instruction.
8. A network security policy adjustment device, characterized in that: include: An acquisition unit, configured to determine a network event that triggers a network security policy, and acquire suspected false alarm data based on the network event; an output unit, used to input the suspected false alarm data and the preset prompt text into a large language model, and output optimization measures of the network security strategy through the large language model in combination with a knowledge base, wherein the large language model is used to provide optimization measures for the network security strategy, and the knowledge base pre-stores knowledge data, and the knowledge data includes at least one of the following: user behavior data, historical attack data, and security standard data; An adjustment unit is used to adjust the network security policy according to the optimization measure of the network security policy.
9. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored computer program, wherein when the computer program is executed, the device where the computer-readable storage medium is located is controlled to execute the method for adjusting the network security policy according to any one of claims 1 to 7.
10. An electronic device, characterized in that: It includes one or more processors and a memory, wherein the memory is used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the method for adjusting the network security policy described in any one of claims 1 to 7.
Citation Information
Cited By
Security alarm information processing method and device based on multi-agent cooperation
CN120378229A
Network security decision-making method and device based on large language model
CN120856385A
Large model-based research and judgment strategy optimization method, apparatus and device, and storage medium
CN121256419A