Training Method, Device and Equipment for Large Model of Vulnerability and Attack Technique and Tactics Correlation Analysis

Through network security knowledge graph analysis and large-scale model training, the problem of inaccurate network vulnerability analysis in the existing technology is solved, and accurate analysis of network vulnerabilities and generation of security defense strategies are achieved.

CN120046758BActive Publication Date: 2025-07-01PENG CHENG LAB
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510512026.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-23
Publication Date
2025-07-01
Estimated Expiration
2045-04-23

AI Technical Summary

Technical Problem

The existing technology of network security incident prevention methods based on human experience makes it difficult to accurately analyze and repair network vulnerabilities, resulting in the occurrence of network security accidents such as software damage and hardware damage of computer equipment.

Method used

Through the network security knowledge graph, multiple associated entities at different levels of each network vulnerability are determined, network vulnerability features and entity features are obtained, and the features are aggregated to generate aggregated network vulnerability features. Similar aggregated network vulnerability features are determined through similarity analysis. Finally, prompt text is generated and input into the vulnerability and attack technology tactical correlation analysis model, and the predicted security analysis results are output.

Benefits of technology

It realizes accurate analysis of network vulnerabilities to be processed, outputs target security analysis results, including technologies and tactics that network vulnerabilities may be exploited, and improves the scientificity and practicality of network security defense.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120046758B_ABST
    Figure CN120046758B_ABST
Patent Text Reader

Abstract

The embodiments of the present application disclose a method, device, and equipment for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics. Multiple associated entities at different levels corresponding to each network vulnerability are determined according to the network security knowledge graph, and the network vulnerability features corresponding to each network vulnerability and the entity features of each associated entity are determined; the aggregated network vulnerability features corresponding to each network vulnerability are determined according to the network vulnerability features and entity features; the similar aggregated network vulnerability features corresponding to each network vulnerability are determined according to the similarity between different aggregated network vulnerability features; the prompt text corresponding to each network vulnerability is determined according to the aggregated network vulnerability features and the similar aggregated network vulnerability features and input into the large model for analyzing the association between vulnerabilities and attack techniques and tactics, and the predicted security analysis results of each network vulnerability are output; the large model is trained according to the difference between the labeled security analysis results and the predicted security analysis results of each network vulnerability to obtain the trained large model.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and specifically relates to a method, device, and equipment for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics. Background Technique

[0002] With the development of network technology, network security is becoming increasingly important at present. Network security incidents in the network may occur at any time. If the vulnerability analysis of network security incidents is not carried out in time, network security accidents will occur, such as network intrusion, network attack, data theft and other network security accidents. Therefore, it is necessary to prevent network security incidents to ensure network security.

[0003] In related technologies, for the prevention of network security incidents, it is often based on human experience. For example, a security database is set up to find the network vulnerabilities corresponding to network security incidents through the security database, and then the network vulnerabilities are analyzed and repaired. However, due to limited human experience, the network vulnerabilities corresponding to network security incidents cannot be accurately analyzed, resulting in the inability to repair the network vulnerabilities, and ultimately causing network security accidents such as software damage and hardware damage of computer devices. Summary of the Invention

[0004] The embodiments of this application provide a method, device, and equipment for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics. The trained large model for analyzing the association between vulnerabilities and attack techniques and tactics can accurately analyze the network vulnerabilities to be processed and output the target security analysis results.

[0005] To achieve the above object, on the one hand, the embodiments of this application provide a method for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics, including:

[0006] Determine multiple associated entities at different levels corresponding to each network vulnerability according to the network security knowledge graph, and determine the network vulnerability features corresponding to each network vulnerability and the entity features corresponding to each associated entity;

[0007] Determine the aggregated network vulnerability features corresponding to each network vulnerability according to the network vulnerability features and the entity features;

[0008] Determine the similar aggregated network vulnerability features corresponding to each network vulnerability according to the similarity between different aggregated network vulnerability features;

[0009] Determine the hint text corresponding to each network vulnerability according to the aggregated network vulnerability features and the similar aggregated network vulnerability features, and input the hint text into the large model for analyzing the association between vulnerabilities and attack techniques and tactics to output the predicted security analysis results corresponding to each network vulnerability, and the predicted security analysis results include the technologies and tactics corresponding to each network vulnerability.

[0010] Determine the difference between the label security analysis result corresponding to each network vulnerability and the predicted security analysis result, and train the large model for vulnerability and attack technique - tactic association analysis according to the difference to obtain the trained large model for vulnerability and attack technique - tactic association analysis.

[0011] To achieve the above object, on the one hand, an embodiment of the present application provides a large model training device for vulnerability and attack technique - tactic association analysis, including:

[0012] The first determination module is used to determine multiple associated entities at different levels corresponding to each network vulnerability according to the network security knowledge graph, and determine the network vulnerability features corresponding to each network vulnerability and the entity features corresponding to each associated entity;

[0013] The second determination module is used to determine the aggregated network vulnerability features corresponding to each network vulnerability according to the network vulnerability features and the entity features;

[0014] The third determination module is used to determine the similar aggregated network vulnerability features corresponding to each network vulnerability according to the similarity between different aggregated network vulnerability features;

[0015] The input module is used to determine the prompt text corresponding to each network vulnerability according to the aggregated network vulnerability features and the similar aggregated network vulnerability features, and input the prompt text into the large model for vulnerability and attack technique - tactic association analysis to output the predicted security analysis result corresponding to each network vulnerability, where the predicted security analysis result includes the techniques and tactics corresponding to each network vulnerability;

[0016] The training module is used to determine the difference between the label security analysis result corresponding to each network vulnerability and the predicted security analysis result, and train the large model for vulnerability and attack technique - tactic association analysis according to the difference to obtain the trained large model for vulnerability and attack technique - tactic association analysis.

[0017] In some embodiments, the second determination module includes a first processing sub - module, a first fusion sub - module, a second processing sub - module, a second fusion sub - module, and a determination sub - module;

[0018] The first processing sub - module is used to determine the to - be - processed associated entity at the current level in the associated entities and the to - be - processed associated entity features corresponding to the to - be - processed associated entity;

[0019] The first fusion sub - module is used to perform feature fusion processing on the to - be - processed associated entity features and the network vulnerability features to generate the updated network vulnerability features corresponding to each network vulnerability;

[0020] A second processing sub-module, configured to determine, from the associated entities, the to-be-processed associated entities at the next level of the current level and the to-be-processed associated entity features corresponding to the to-be-processed associated entities;

[0021] A second fusion sub-module, configured to perform feature fusion processing on the to-be-processed associated entity features corresponding to the next level and the updated network vulnerability features to generate the target updated network vulnerability features corresponding to each network vulnerability;

[0022] A determination sub-module, configured to determine the target updated network vulnerability features as the updated network vulnerability features, determine the next level as the current level, and return to execute to determine the to-be-processed associated entities at the next level of the current level and the to-be-processed associated entity features corresponding to the to-be-processed associated entities in the associated entities, until the current level is the highest level, and determine the updated network vulnerability features corresponding to the highest level as the aggregated network vulnerability features corresponding to each network vulnerability.

[0023] In some embodiments, the first fusion sub-module is configured to:

[0024] Sum up each of the to-be-processed associated entity features and then calculate the mean value to obtain the first entity feature;

[0025] Perform weighted summation on the first entity feature and the network vulnerability features to obtain the updated network vulnerability features corresponding to each network vulnerability.

[0026] In some embodiments, the first fusion sub-module is configured to:

[0027] Obtain the first weight value corresponding to the first entity feature and the second weight value corresponding to the network vulnerability features;

[0028] Multiply the first weight value by the first entity feature to obtain the first feature;

[0029] Multiply the second weight value by the network vulnerability features to obtain the second feature;

[0030] Add the first feature and the second feature to obtain the updated network vulnerability features corresponding to each network vulnerability.

[0031] In some embodiments, the second fusion sub-module is configured to:

[0032] Sum up each of the to-be-processed associated entity features corresponding to the next level and then calculate the mean value to obtain the second entity feature;

[0033] Perform weighted summation on the second entity feature and the updated network vulnerability features to obtain the target updated network vulnerability features corresponding to each network vulnerability.

[0034] In some embodiments, a first determination module is configured to:

[0035] Obtain the first description text corresponding to each network vulnerability and the second description text corresponding to each associated entity;

[0036] Input the first description text into a pre-trained text processing model to output the network vulnerability features corresponding to each network vulnerability;

[0037] Input the second description text into a pre-trained text processing model to output the entity features corresponding to each associated entity.

[0038] In some embodiments, a third determination module is configured to:

[0039] Determine the similarity between the aggregated network vulnerability features corresponding to each network vulnerability and other aggregated network vulnerability features;

[0040] Determine the aggregated network vulnerability features corresponding to other network vulnerabilities with a similarity greater than a preset similarity as the similar aggregated network vulnerability features corresponding to each network vulnerability.

[0041] In some embodiments, the vulnerability and attack technique and tactic association analysis large model training device further includes a graph generation module, which is configured to:

[0042] Before determining multiple different levels of associated entities corresponding to each network vulnerability according to the network security knowledge graph, determine multiple network vulnerabilities in the network security database, and determine the vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to each network vulnerability;

[0043] Determine the entity relationships between each network vulnerability, the vulnerability weakness instances, the vulnerability attack instances, the techniques, and the tactics;

[0044] Construct a network security knowledge graph corresponding to the multiple network vulnerabilities according to the entity relationships, each network vulnerability, the vulnerability weakness instances, the vulnerability attack instances, the techniques, and the tactics.

[0045] In some embodiments, an input module is configured to:

[0046] Determine the vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to each network vulnerability according to the aggregated network vulnerability features;

[0047] Generate a first association path text and a first vulnerability description text according to the vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to each network vulnerability;

[0048] Determine the vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to the similar network vulnerabilities of each network vulnerability according to the described similar aggregation network vulnerability characteristics;

[0049] Generate a second associated path text and a second vulnerability description text according to the vulnerability instances, vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to the similar network vulnerabilities;

[0050] Generate the prompt text corresponding to each network vulnerability according to the first associated path text, the first vulnerability description text, the second associated path text, and the second vulnerability description text.

[0051] To achieve the above object, an embodiment of the present application provides a network security analysis method on the one hand, including:

[0052] Determine multiple target associated entities at different levels corresponding to the network vulnerability to be processed according to the network security knowledge graph, and determine the target network vulnerability characteristics corresponding to the network vulnerability to be processed and the target entity characteristics corresponding to each target associated entity;

[0053] Determine the target aggregation network vulnerability characteristics corresponding to the network vulnerability to be processed according to the target network vulnerability characteristics and the target entity characteristics;

[0054] Determine the target similar aggregation network vulnerability characteristics corresponding to the network vulnerability to be processed according to the similarity between different target aggregation network vulnerability characteristics;

[0055] Determine the target prompt text corresponding to the network vulnerability to be processed according to the target aggregation network vulnerability characteristics and the target similar aggregation network vulnerability characteristics;

[0056] Input the target prompt text into the trained vulnerability and attack technique and tactic association analysis large model, and output the target security analysis result corresponding to the network vulnerability to be processed. The target security analysis result includes the techniques and tactics corresponding to the network vulnerability to be processed, where the trained vulnerability and attack technique and tactic association analysis large model is trained based on the vulnerability and attack technique and tactic association analysis large model training method provided by the embodiment of the present application.

[0057] To achieve the above object, an embodiment of the present application provides a network security analysis device on the one hand, including:

[0058] An entity determination module, configured to determine multiple target associated entities at different levels corresponding to the network vulnerability to be processed according to the network security knowledge graph, and determine the target network vulnerability characteristics corresponding to the network vulnerability to be processed and the target entity characteristics corresponding to each target associated entity;

[0059] A feature determination module, configured to determine a target aggregated network vulnerability feature corresponding to the to-be-processed network vulnerability according to the target network vulnerability feature and the target entity feature;

[0060] A similarity determination module, configured to determine a target similar aggregated network vulnerability feature corresponding to the to-be-processed network vulnerability according to the similarity between different target aggregated network vulnerability features;

[0061] A text generation module, configured to determine a target prompt text corresponding to the to-be-processed network vulnerability according to the target aggregated network vulnerability feature and the target similar aggregated network vulnerability feature;

[0062] A prediction module, configured to input the target prompt text into a trained large model for analyzing the association between vulnerabilities and attack techniques and tactics, and output a target security analysis result corresponding to the to-be-processed network vulnerability, where the target security analysis result includes the techniques and tactics corresponding to the to-be-processed network vulnerability. The trained large model for analyzing the association between vulnerabilities and attack techniques and tactics is trained based on the method for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics provided in the embodiments of the present application.

[0063] To achieve the above object, on the one hand, an embodiment of the present application provides a computer-readable storage medium, which stores multiple instructions, and the instructions are suitable for being loaded by a processor to execute the method for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics provided in the embodiments of the present application or the network security analysis method provided in the embodiments of the present application.

[0064] To achieve the above object, on the one hand, an embodiment of the present application provides a computer device, including a memory, a processor, and a computer program stored in the memory and capable of running on the processor. When the processor executes the computer program, the method for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics provided in the embodiments of the present application or the network security analysis method provided in the embodiments of the present application is implemented.

[0065] In an embodiment of the present application, multiple associated entities at different levels corresponding to each network vulnerability are determined according to the network security knowledge graph, and the network vulnerability features corresponding to each network vulnerability and the entity features corresponding to each associated entity are determined; the aggregated network vulnerability features corresponding to each network vulnerability are determined according to the network vulnerability features and entity features; the similar aggregated network vulnerability features corresponding to each network vulnerability are determined according to the similarity between different aggregated network vulnerability features; the prompt text corresponding to each network vulnerability is determined according to the aggregated network vulnerability features and the similar aggregated network vulnerability features, and the prompt text is input into the large model for analyzing the association between vulnerabilities and attack techniques and tactics to output the predicted security analysis results corresponding to each network vulnerability; the difference between the label security analysis results and the predicted security analysis results corresponding to each network vulnerability is determined, and the large model for analyzing the association between vulnerabilities and attack techniques and tactics is trained according to the difference to obtain the trained large model for analyzing the association between vulnerabilities and attack techniques and tactics.

[0066] Thus, multiple associated entities at different levels corresponding to each network vulnerability are determined through the network security knowledge graph, and then the network vulnerability features corresponding to each network vulnerability and the entity features corresponding to each associated entity are obtained. Then, according to the network vulnerability features of each network vulnerability combined with the entity features of the corresponding associated entities, the aggregated network vulnerability features corresponding to each network vulnerability are obtained, realizing the combination of each network vulnerability with the associated multi-level associated entities, enabling the aggregated network vulnerability features to represent the context information of the network security knowledge graph. Then, the similar aggregated network vulnerability features corresponding to each network vulnerability are determined according to the similarity between different aggregated network vulnerability features, and the prompt text corresponding to each network vulnerability is determined through the aggregated network vulnerability features and the similar aggregated network vulnerability features. The determined prompt text can represent the context information corresponding to each network vulnerability in the network security knowledge graph and the information of similar network vulnerabilities similar to each network vulnerability, thereby making the prompt text input into the large model for analyzing the association between vulnerabilities and attack techniques and tactics more comprehensive, enabling the large model for analyzing the association between vulnerabilities and attack techniques and tactics to learn more network security knowledge, and thus realizing the efficient training of the large model for analyzing the association between vulnerabilities and attack techniques and tactics. Compared with the related technology of determining the security analysis results corresponding to network vulnerabilities based on human experience, the trained large model for analyzing the association between vulnerabilities and attack techniques and tactics of the present application can accurately analyze the network vulnerabilities to be processed and output the target security analysis results, and the target security analysis results include the techniques and tactics for attacking the network vulnerabilities to be processed.

[0067] Other features and advantages of the present application will be described in the following specification, and, in part, will be obvious from the specification, or will be understood by implementing the present application. The objectives and other advantages of the present application can be achieved and obtained through the structures specifically pointed out in the specification, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0068] To more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those skilled in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0069] Figure 1 It is a schematic diagram of the system framework corresponding to the method for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics and the network security analysis method provided by the embodiments of the present application;

[0070] Figure 2 It is a schematic diagram of the processing process corresponding to the network security analysis method provided by the embodiments of the present application;

[0071] Figure 3 It is a schematic diagram of the flow of the method for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics provided by the embodiments of the present application;

[0072] Figure 4 It is a schematic diagram of the network security knowledge graph provided by the embodiments of the present application;

[0073] Figure 5 It is a schematic diagram of the flow included in step 220 provided by the embodiments of the present application;

[0074] Figure 6 It is another schematic diagram of the flow of the method for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics provided by the embodiments of the present application;

[0075] Figure 7 It is a schematic diagram of the flow of the network security analysis method provided by the present application;

[0076] Figure 8 It is a schematic diagram of the structure of the device for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics provided by the embodiments of the present application;

[0077] Figure 9 It is a schematic diagram of the structure of the network security analysis device provided by the embodiments of the present application;

[0078] Figure 10 It is a schematic diagram of the structure of the computer device provided by the embodiments of the present application. Detailed implementation manners

[0079] To enable those skilled in the art to better understand the solution of this application, the following will clearly and completely describe the technical solutions in the embodiments of this application with reference to the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of this application.

[0080] It should be noted that in each specific implementation manner of this application, when it comes to relevant processing based on data related to network security information, the permission or consent of the object will be obtained first. Moreover, the collection, use, and processing of these data will comply with relevant laws, regulations, and standards. In addition, when the embodiments of this application need to obtain sensitive personal information of the object, the object's separate permission or separate consent will be obtained through methods such as pop-up windows or jumping to a confirmation page. After clearly obtaining the object's separate permission or separate consent, the necessary object-related data for the normal operation of the embodiments of this application will be obtained.

[0081] It should be noted that in some processes described in the specification, claims, and the above-mentioned accompanying drawings, there are multiple steps that appear in a specific order. However, it should be clearly understood that these steps can be executed not in the order in which they appear in this article or in parallel. The step numbers are only used to distinguish different steps, and the numbers themselves do not represent any execution order. In addition, descriptions such as "first", "second", or "target" in this article are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence.

[0082] The method for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics and the network security analysis method provided by the embodiments of this application relate to the field of artificial intelligence technology. The method for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics and the network security analysis method provided by the embodiments of this application can be applied to terminals, can also be applied to server sides, or can also be software running on terminals or server sides. In some embodiments, the terminal can be a smart phone, a tablet computer, a laptop computer, a desktop computer, etc.; the server side can be configured as an independent physical server, can also be configured as a server cluster or distributed system composed of multiple physical servers, or can also be configured as a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms; the software can be an application that implements the method for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics and the network security analysis method, but is not limited to the above forms.

[0083] Before further elaborating on the embodiments of the present application, the nouns and terms involved in the embodiments of the present application are explained. The nouns and terms involved in the embodiments of the present application are applicable to the following explanations:

[0084] Network Vulnerability: A network vulnerability refers to a security flaw or weakness existing in the design, implementation, configuration, or maintenance process of a computer network system (including hardware, software, network protocols, etc.). These vulnerabilities make the network system vulnerable to exploitation by attackers, leading to security incidents such as information leakage, system damage, and service interruption. For example, a buffer overflow vulnerability in software code may give an attacker the opportunity to execute malicious code on the target system. In the present application, a network vulnerability can be a Common Vulnerabilities and Exposures (CVE). CVE is used to assign unique identifiers to information security vulnerabilities and exposures. It is like a unified "ID card" system that numbers and records various software, hardware, system, etc. security issues.

[0085] Vulnerability Weakness Instance: Specifically, it can be a Common Weakness Enumeration (CWE), which is used to classify and describe security weaknesses in software and hardware systems. A CVE vulnerability usually can be mapped to one or more CWE weakness categories.

[0086] Vulnerability Attack Instance: Specifically, it can be a Common Attack Pattern Enumeration and Classification (CAPEC). CAPEC is a comprehensive knowledge base of attack patterns, used to classify and enumerate network attack patterns. It is like a "tactical manual" for attackers, describing how to exploit vulnerabilities and weaknesses to conduct attacks. CWE defines the weaknesses in the system, while CAPEC shows how to exploit these weaknesses for attacks. The association between them helps security defenders think from the perspective of attackers, thus better formulating defense measures. CAPEC is the basis of Tactic and Technique. Tactic guides the use of Technique, and Technique is the specific means to implement the attack patterns in CAPEC.

[0087] Technique: That is, attack technique, which refers to the specific technical means adopted by an attacker during the implementation of an attack, such as using specific tools, scripts, or code to achieve the attack purpose.

[0088] Tactic: That is, the attack tactic, which is a higher-level plan. It is a series of strategic actions taken by an attacker to achieve goals (such as obtaining data, destroying a system, etc.), including selecting attack targets, timing, and combining multiple attack techniques.

[0089] Knowledge Graph: A knowledge graph is a semantic network with extremely strong expressive power and modeling flexibility. Essentially, it is a semantic knowledge base that depicts various concepts in the real world and their relationships with each other in symbolic form. The basic unit is the triple of "entity-relationship-entity". A knowledge graph can be regarded as a graph composed of nodes and edges. Nodes represent entities or concepts in the physical world, and edges represent various semantic relationships between entities or concepts. Through such a graph structure, the complex associations between various entities can be clearly displayed, integrating fragmented knowledge into an organic whole.

[0090] The above are the noun explanations of the relevant technical terms involved in this application. If there are other technical terms involved in the following text, they will be explained later.

[0091] First, describe the technical problems existing in the related technologies:

[0092] With the development of network technology, network security is becoming increasingly important currently. Network security incidents in the network may occur at any time. If the vulnerability analysis of network security incidents is not carried out in a timely manner, network security accidents will occur, such as network intrusions, network attacks, data theft and other network security accidents. Therefore, it is necessary to prevent network security incidents to ensure network security.

[0093] In the related technologies, the prevention of network security incidents often relies on human experience. For example, a security database is set up, and the network vulnerabilities corresponding to network security incidents are found through the security database, and then the network vulnerabilities are analyzed and repaired. However, due to limited human experience, the network vulnerabilities corresponding to network security incidents cannot be accurately analyzed, resulting in the network vulnerabilities not being repaired, and ultimately causing network security accidents such as software damage and hardware damage of computer devices.

[0094] To solve the above technical problems, the embodiments of the present application provide a method for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics, as well as a network security analysis method, device, computer device, and storage medium. Among them, multiple associated entities at different levels corresponding to each network vulnerability are determined through a network security knowledge graph, and then the network vulnerability features corresponding to each network vulnerability and the entity features corresponding to each associated entity are obtained. Then, according to the network vulnerability features of each network vulnerability combined with the entity features of the corresponding associated entity, the aggregated network vulnerability features corresponding to each network vulnerability are obtained, realizing that each network vulnerability is combined with the multi-level associated entities, so that the aggregated network vulnerability features can represent the context information of the network security knowledge graph. Then, the similar aggregated network vulnerability features corresponding to each network vulnerability are determined through the similarity between different aggregated network vulnerability features, and the prompt text corresponding to each network vulnerability is determined through the aggregated network vulnerability features and the similar aggregated network vulnerability features. The prompt text determined in this way can represent the context information corresponding to each network vulnerability in the network security knowledge graph and the information of the similar network vulnerabilities similar to each network vulnerability, so that the prompt text input into the large model for analyzing the association between vulnerabilities and attack techniques and tactics is more comprehensive, enabling the large model for analyzing the association between vulnerabilities and attack techniques and tactics to learn more network security knowledge, thereby realizing the efficient training of the large model for analyzing the association between vulnerabilities and attack techniques and tactics. Compared with the solution in the related art that determines the security analysis result corresponding to a network vulnerability based on human experience, the large model for analyzing the association between vulnerabilities and attack techniques and tactics trained in this application can accurately analyze the network vulnerability to be processed and output the target security analysis result, and the target security analysis result includes the techniques and tactics for attacking the network vulnerability to be processed.

[0095] A method for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics, as well as a network security analysis method, device, computer device, and storage medium provided by the embodiments of the present application will be described in detail later.

[0096] Please refer to Figure 1 , Figure 1 FIG. is a schematic diagram of the system framework corresponding to the method for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics and the network security analysis method provided by the embodiments of the present application. The method for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics and the network security analysis method provided by the embodiments of the present application can be applied to this system framework.

[0097] It includes a terminal 140, the Internet 130, a gateway 120, a server 110, etc.

[0098] The terminal 140 or the server 110 can be a device that executes the method for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics or the network security analysis method.

[0099] The terminal 140 includes, but is not limited to, mobile phones, computers, intelligent voice interaction devices, smart home appliances, vehicle-mounted terminals, aircraft, etc. The embodiments of the present application can be applied to various scenarios, including but not limited to network security, network defense, etc. Additionally, it can be a single device or a collection of multiple devices combined. For example, multiple desktop computers are interconnected through a local area network, share a single display, etc. to work collaboratively, jointly constituting a terminal 140. The terminal 140 can communicate with the Internet 130 in a wired or wireless manner to exchange data.

[0100] The server 110 refers to a computer system that can provide certain services to the terminal 140. Compared with ordinary terminals 140, the server 110 has higher requirements in terms of stability, security, performance, etc. The server 110 can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers. It can also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, as well as big data and artificial intelligence platforms.

[0101] The gateway 120 is also known as an inter-network connector and protocol converter. The gateway realizes network interconnection at the transport layer and is a computer system or device that acts as a converter. Between two systems using different communication protocols, data formats, or languages, and even with completely different architectures, the gateway is a translator. At the same time, the gateway can also provide filtering and security functions. Messages sent from the terminal 140 to the server 110 need to be sent to the corresponding server 110 through the gateway 120. Messages sent from the server 110 to the terminal 140 also need to be sent to the corresponding terminal 140 through the gateway 120.

[0102] The method for training the vulnerability and attack technique and tactics association analysis large model and the network security analysis method in the embodiments of the present application can be applied to various scenarios, such as cloud services, network security, etc. The scenarios to which the method for training the vulnerability and attack technique and tactics association analysis large model and the network security analysis method in the present application are applied are not limited herein.

[0103] Please refer to Figure 2 , Figure 2 which is a schematic diagram of the processing process corresponding to the network security analysis method provided by the embodiments of the present application.

[0104] In the present application, network security analysis is mainly based on the trained vulnerability and attack technique and tactics association analysis large model. When a network vulnerability to be processed is found in the network, multiple target associated entities at different levels corresponding to the network vulnerability to be processed are determined according to the network security knowledge graph.

[0105] For example, network knowledge related to the network vulnerability to be processed can be obtained from the network security knowledge graph. For example, vulnerability weakness instances, vulnerability attack instances, tactics, and techniques corresponding to the network vulnerability to be processed can be obtained. These entities can be used as the target associated entities corresponding to the network vulnerability to be processed. These target associated entities can be the neighbor entities corresponding to the network vulnerability to be processed, or other entities associated with the neighbor entities corresponding to the network vulnerability to be processed. Therefore, multiple target associated entities correspond to multiple levels. The closer the target associated entity is to the network vulnerability to be processed, the lower the corresponding level, and the farther the target associated entity is from the network vulnerability to be processed, the higher the corresponding level.

[0106] Then, determine the target network vulnerability features corresponding to the network vulnerability to be processed and the target entity features corresponding to each target associated entity. For example, the description texts corresponding to the network vulnerability to be processed and each target associated entity can be obtained, and then the target network vulnerability features corresponding to the network vulnerability to be processed and the target entity features corresponding to each target associated entity are generated based on the respectively corresponding description texts.

[0107] Next, determine the target aggregated network vulnerability features corresponding to the network vulnerability to be processed based on the target network vulnerability features and the target entity features. Determine the target similar aggregated network vulnerability features corresponding to the network vulnerability to be processed according to the similarity between different target aggregated network vulnerability features.

[0108] Among them, the target similar aggregated network vulnerability features specifically correspond to the target similar network vulnerabilities similar to the network vulnerability to be processed. And the target aggregated network vulnerability features correspond to the network vulnerability to be processed.

[0109] Finally, determine the target prompt text corresponding to the network vulnerability to be processed based on the target aggregated network vulnerability features and the target similar aggregated network vulnerability features, and input the target prompt text into the trained large model for analyzing the association between vulnerabilities and attack techniques and tactics to output the target security analysis result corresponding to the network vulnerability to be processed.

[0110] For example, the target aggregated network vulnerability features and the target similar aggregated network vulnerability features can be respectively input into a pre-trained text generation model to output target prompt text. Finally, the target prompt text is input into the trained large model for analyzing the association between vulnerabilities and attack techniques and tactics to output the target security analysis result corresponding to the network vulnerability to be processed. For example, the association analysis result of the technology and tactics corresponding to the network vulnerability to be processed is output, including the technology and tactics that the network vulnerability to be processed may be exploited, as well as relevant explanations and defense deployment suggestions. For example, for the network vulnerability to be processed, the trained large model for analyzing the association between vulnerabilities and attack techniques and tactics can not only give the associated technology (such as "Command and Scripting Interpreter") and tactics (such as "Execution"), but also provide specific defense measures (such as "implement input validation" or "enable log monitoring").

[0111] As can be seen from the above, the trained large model for analyzing the association between vulnerabilities and attack techniques and tactics in this application can achieve accurate analysis of the network vulnerability to be processed, so as to obtain the target network security analysis result. Compared with the solution in the related technology that can only perform security analysis on the network vulnerability to be processed based on human experience, the trained large model for analyzing the association between vulnerabilities and attack techniques and tactics in this application can accurately analyze the network vulnerability to be processed and output the target security analysis result, and the target security analysis result includes the technology and tactics for the network vulnerability to be attacked.

[0112] To understand more clearly the trained large model for analyzing the association between vulnerabilities and attack techniques and tactics provided in the embodiments of this application, please refer to Figure 3 , Figure 3 which is a schematic flowchart of the method for training the large model for analyzing the association between vulnerabilities and attack techniques and tactics provided in the embodiments of this application. The method for training the large model for analyzing the association between vulnerabilities and attack techniques and tactics may include the following steps:

[0113] Step 210: Determine multiple associated entities at different levels corresponding to each network vulnerability according to the network security knowledge graph, and determine the network vulnerability features corresponding to each network vulnerability and the entity features corresponding to each associated entity;

[0114] Step 220: Determine the aggregated network vulnerability features corresponding to each network vulnerability according to the network vulnerability features and the entity features;

[0115] Step 230: Determine the similar aggregated network vulnerability features corresponding to each network vulnerability according to the similarity between different aggregated network vulnerability features;

[0116] Step 240: Determine the prompt text corresponding to each network vulnerability based on the aggregated network vulnerability characteristics and similar aggregated network vulnerability characteristics, and input the prompt text into the large model for correlation analysis of vulnerabilities and attack techniques and tactics to output the predicted security analysis results corresponding to each network vulnerability. The predicted security analysis results include the techniques and tactics corresponding to each network vulnerability.

[0117] Step 250: Determine the differences between the label security analysis results and the predicted security analysis results corresponding to each network vulnerability, and train the large model for correlation analysis of vulnerabilities and attack techniques and tactics based on the differences to obtain the trained large model for correlation analysis of vulnerabilities and attack techniques and tactics.

[0118] Before describing Steps 210 to 250 in detail, first explain the generation process of the network security knowledge graph.

[0119] Before determining the multiple different-level associated entities corresponding to each network vulnerability based on the network security knowledge graph, it also includes:

[0120] (1.1) Determine multiple network vulnerabilities in the network security database, and determine the vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to each network vulnerability.

[0121] (1.2) Determine the entity relationships between each network vulnerability, vulnerability weakness instance, vulnerability attack instance, technique, and tactic.

[0122] (1.3) Construct the network security knowledge graph corresponding to multiple network vulnerabilities based on the entity relationships, each network vulnerability, vulnerability weakness instance, vulnerability attack instance, technique, and tactic.

[0123] Among them, network security knowledge data in the network security knowledge base can be obtained, and then these network security knowledge data are analyzed and sorted to obtain multiple entities and the entity relationships between entities. For example, the entities include network vulnerabilities, vulnerability weakness instances corresponding to network vulnerabilities, vulnerability attack instances, techniques, and tactics. Among them, network vulnerabilities can be Common Vulnerabilities and Exposures (CVE), vulnerability weakness instances can be Common Weakness Enumeration (CWE), vulnerability attack instances can be Attack Pattern Enumeration and Classification (CAPEC), techniques can be Attack Techniques (Technique), and tactics can be Attack Tactics (Tactic).

[0124] Then determine the entity relationships between each network vulnerability, vulnerability weakness instance, vulnerability attack instance, technique, and tactic in the network security knowledge database. For example, a certain network vulnerability has a certain vulnerability weakness instance, a certain vulnerability weakness instance has a certain vulnerability attack instance, a certain vulnerability attack instance is based on a certain technique, and a certain technique corresponds to a certain tactic.

[0125] Finally, multiple cybersecurity knowledge graphs corresponding to network vulnerabilities are constructed based on entity relationships, each network vulnerability, vulnerability weakness instances, vulnerability attack instances, techniques, and tactics. For example, each entity can be used as a node, that is, each network vulnerability, vulnerability weakness instance, vulnerability attack instance, technique, and tactic can be used as nodes, and the entity relationships between entities can be used as edges, thereby constructing multiple cybersecurity knowledge graphs corresponding to network vulnerabilities.

[0126] It should be noted that other types of entities can also be included in the constructed cybersecurity knowledge graph, and the entities described above do not constitute a limitation on the cybersecurity knowledge graph.

[0127] For details, please refer to Figure 4 , Figure 4 which is a schematic diagram of the cybersecurity knowledge graph of the embodiments of the present application.

[0128] Among them, the cybersecurity knowledge graph contains multiple nodes, such as nodes cve1, cwe1, cwe2, capec1, capec2, capec3, capec4, Technique1, Tactic3, Tactic5, Tactic6, Tactic8, etc. The Chinese and English explanations of these nodes can be found above. Each node can be understood as an entity. For example, cve1 represents a network vulnerability, and the number of this network vulnerability is 1. The edges between different nodes are determined by the entity relationships between entities.

[0129] After generating the cybersecurity knowledge graph, each entity and its associated entities can be quickly found through the cybersecurity knowledge graph. It should be noted that Figure 4 the cybersecurity knowledge graph shown in Figure 4 is only for illustration, and the content shown in

[0130] Steps 210 to 250 will be described in detail below.

[0131] In step 210, multiple associated entities at different levels corresponding to each network vulnerability are determined according to the cybersecurity knowledge graph, and the network vulnerability characteristics corresponding to each network vulnerability and the entity characteristics corresponding to each associated entity are determined.

[0132] Among them, for each network vulnerability, multiple associated entities at different levels corresponding to each network vulnerability can be determined in the cybersecurity knowledge graph. The level can be understood as the degree of closeness of the relationship between the associated entity and the network vulnerability. Taking Figure 4For example, where cve1 is a network vulnerability and cwe1 is a neighbor entity of cve1, then cwe1 has the lowest corresponding level, while cwe2, capec2, and capec3 have an indirect relationship with cve1 respectively, so the corresponding levels of cwe2, capec2, and capec3 are higher than the level of cve1.

[0133] Then, determine the network vulnerability features corresponding to each network vulnerability and the entity features corresponding to each associated entity. Among them, each network vulnerability corresponds to a corresponding description text for describing the relevant information of each network vulnerability. Each associated entity also has a corresponding description text. For example, cwe1 corresponds to relevant weakness descriptions, scoring details of the CVSS (Common Vulnerability Scoring System) matrix (such as attack complexity, scope of impact, etc.), the name of the Vendor (i.e., the company or organization providing software products or hardware devices) and its relevant product information, etc. The features corresponding to each entity can be generated according to the description text corresponding to each entity.

[0134] In some embodiments, determining the network vulnerability features corresponding to each network vulnerability and the entity features corresponding to each associated entity includes:

[0135] (1.1) Obtain the first description text corresponding to each network vulnerability and the second description text corresponding to each associated entity;

[0136] (1.2) Input the first description text into a pre-trained text processing model to output the network vulnerability features corresponding to each network vulnerability;

[0137] (1.3) Input the second description text into a pre-trained text processing model to output the entity features corresponding to each associated entity.

[0138] Among them, the first description text corresponding to each network vulnerability and the second description text corresponding to each associated entity can be obtained. For example, the first description text describes the exposure allocation identification number of the network vulnerability and can also describe the specific content: "There is a memory corruption vulnerability in the document processing module of a certain well-known office software suite (versions X.Y and below).".

[0139] For example, the second description text describes the content of the vulnerability weakness instance corresponding to the network vulnerability, and the specific content is: "This is a security weakness in a Web application where a malicious attacker injects scripts into the web pages browsed by legitimate users to obtain user information or perform other malicious operations."

[0140] The first description text can be input into a pre-trained text processing model to output the network vulnerability features corresponding to each network vulnerability. The second description text is input into the pre-trained text processing model to output the entity features corresponding to each associated entity. Among them, the pre-trained text processing model can be a BERT model, a Sentence-BERT model, etc., which can encode the first description text and the second description text, so as to generate vectors corresponding to the first description text and the second description text respectively, that is, network vulnerability features and entity features.

[0141] In step 220, the aggregated network vulnerability features corresponding to each network vulnerability are determined according to the network vulnerability features and the entity features.

[0142] Among them, the network vulnerability features can be used to characterize the characteristics of the network vulnerabilities described in the first description text corresponding to the network vulnerabilities. However, in the process of security analysis of network vulnerabilities, other information related to the network vulnerabilities also needs to be considered, so as to realize a more comprehensive, objective and accurate security analysis of the network vulnerabilities.

[0143] Taking this into account, in this application, the network vulnerability features and the entity features of each associated entity are aggregated to combine the semantic information of the network vulnerabilities and the semantic information of the associated entities corresponding to the network vulnerabilities, so as to obtain the aggregated network vulnerability features. The aggregated network vulnerability features are used to characterize the context information of the network vulnerabilities and the respective associated entities in the network security knowledge graph. Therefore, the aggregated network vulnerability features can express the network knowledge related to the network vulnerabilities more accurately.

[0144] Please refer to Figure 5 , Figure 5 which is a schematic flow diagram included in step 220 provided by an embodiment of the present application. In some embodiments, determining the aggregated network vulnerability features corresponding to each network vulnerability according to the network vulnerability features and the entity features includes:

[0145] Step 301, determine the to-be-processed associated entity at the current level and the to-be-processed associated entity features corresponding to the to-be-processed associated entity among the associated entities;

[0146] Step 302, perform feature fusion processing on the to-be-processed associated entity features and the network vulnerability features to generate updated network vulnerability features corresponding to each network vulnerability;

[0147] Step 303, determine the to-be-processed associated entity at the next level and the to-be-processed associated entity features corresponding to the to-be-processed associated entity among the associated entities;

[0148] Step 304: Perform feature fusion processing based on the to-be-processed associated entity features corresponding to the next level and the updated network vulnerability features to generate the target updated network vulnerability features corresponding to each network vulnerability;

[0149] Step 305: Determine the target updated network vulnerability features as the updated network vulnerability features, determine the next level as the current level, and return to execute to determine the to-be-processed associated entities and the to-be-processed associated entity features corresponding to the to-be-processed associated entities at the next level in the associated entities until the current level is the highest level. Determine the updated network vulnerability features corresponding to the highest level as the aggregated network vulnerability features corresponding to each network vulnerability.

[0150] Steps 301 to 305 will be described in detail below.

[0151] In Step 301, determine the to-be-processed associated entities and the to-be-processed associated entity features corresponding to the to-be-processed associated entities at the current level in the associated entities.

[0152] Among them, in the associated entities, the first determined level is the first level, that is, the level corresponding to the neighbor entity most closely associated with the network vulnerability. Determine the first level as the current level, and then determine the to-be-processed associated entities and the to-be-processed associated entity features corresponding to the to-be-processed associated entities at the current level.

[0153] For example, please combine Figure 4 , cve1 is a network vulnerability, and cwe1 is a neighbor entity of cve1. Then the level corresponding to cwe1 is the first level, that is, the current level. cwe1 can be determined as the to-be-processed associated entity at the current level, and the entity features of cwe1 can be determined as the to-be-processed associated entity features.

[0154] In Step 302, perform feature fusion processing on the to-be-processed associated entity features and the network vulnerability features to generate the updated network vulnerability features corresponding to each network vulnerability.

[0155] The to-be-processed associated entities and the network vulnerability features at the current level can be subjected to feature fusion processing to generate the updated network vulnerability features corresponding to each network vulnerability. For example, the to-be-processed associated entity features and the network vulnerability features are actually vectors, and these vectors can be added and fused to obtain the updated network vulnerability features corresponding to each network vulnerability.

[0156] In some embodiments, performing feature fusion processing on the to-be-processed associated entity features and the network vulnerability features to generate the updated network vulnerability features corresponding to each network vulnerability includes:

[0157] (1.1) Calculate the mean value after adding each to-be-processed associated entity feature to obtain the first entity feature;

[0158] (1.2) Perform a weighted sum of the first entity feature and the network vulnerability feature to obtain an updated network vulnerability feature corresponding to each network vulnerability.

[0159] Among them, each to-be-processed associated entity feature can be added to obtain an addition result, then the total quantity corresponding to the to-be-processed associated entity feature is determined, and then the addition result is divided by the total quantity to obtain the first entity feature, and the first entity feature is also a vector.

[0160] Then perform a weighted sum of the first entity feature and the network vulnerability feature to obtain an updated network vulnerability feature corresponding to each network vulnerability. The updated network vulnerability feature realizes the aggregation of the context information of the associated entities at the current level corresponding to each network vulnerability, so as to more accurately represent the corresponding semantic features of each network vulnerability in the network security knowledge graph.

[0161] In some embodiments, performing a weighted sum of the first entity feature and the network vulnerability feature to obtain an updated network vulnerability feature corresponding to each network vulnerability includes:

[0162] (1.2.1) Obtain a first weight value corresponding to the first entity feature and a second weight value corresponding to the network vulnerability feature;

[0163] (1.2.2) Multiply the first weight value by the first entity feature to obtain a first feature;

[0164] (1.2.3) Multiply the second weight value by the network vulnerability feature to obtain a second feature;

[0165] (1.2.4) Add the first feature and the second feature to obtain an updated network vulnerability feature corresponding to each network vulnerability.

[0166] Among them, the relationship between different levels and the first weight value can be pre-set. When the level is higher, the first weight value is lower, and the sum of the first weight value and the second weight value is equal to 1. The reason for this is that in the network security knowledge graph, the nearest neighbor entity of the network vulnerability has the most direct impact on it, while the neighbor entity's neighbor entity corresponding to the network vulnerability has an indirect impact on it. Therefore, the mapping relationship between different levels and the first weight value can be set, that is, the higher the level, the lower the first weight value.

[0167] The advantage of this is that it can ensure the influence of the associated entities closer to the network vulnerability on the network vulnerability, while weakening the influence of the associated entities farther away from the network vulnerability on the network vulnerability. When calculating the updated network vulnerability feature of the network vulnerability later, it not only retains the context information of the associated entities corresponding to the network vulnerability, but also ensures the influence of the context information of the associated entities at different levels on the network vulnerability.

[0168] Therefore, the value of the current level can be obtained first, and then the first weight value corresponding to the associated entity to be processed at the current level can be determined according to this value in the above preset mapping relationship. Then, by subtracting the first weight value from 1, the second weight value corresponding to the network vulnerability feature is obtained.

[0169] Next, multiply the first weight value by the first entity feature to obtain the first feature, and multiply the second weight value by the network vulnerability feature to obtain the second feature. Both the first feature and the second feature are vectors.

[0170] Finally, add the first feature and the second feature to obtain the updated network vulnerability feature corresponding to each network vulnerability. This updated network vulnerability feature aggregates the network vulnerability feature and the context information of the associated entity to be processed at the current level, so as to be able to represent the features of network vulnerabilities more accurately and comprehensively, such as the features in terms of network security knowledge.

[0171] In step 303, determine the associated entity to be processed at the next level of the current level and the associated entity feature corresponding to the associated entity to be processed in the associated entities.

[0172] For example, if the current level is the first level, the next level of the first level is the second level. In the network security knowledge graph, it is the entity adjacent to the neighbor entity corresponding to the network vulnerability entity. Combining Figure 4 , assuming that the network vulnerability is cve1 and the entity at the current level is cwe1, then the entities at the next level of the current level are cwe2 and capec2, that is, the associated entities to be processed at the next level of the current level. Then, obtain the associated entity features corresponding to cwe2 and capec2 respectively.

[0173] In step 304, perform feature fusion processing according to the associated entity feature corresponding to the next level and the updated network vulnerability feature to generate the target updated network vulnerability feature corresponding to each network vulnerability.

[0174] Among them, after determining the associated entity to be processed at the next level of the current level and the associated entity feature corresponding to the associated entity to be processed, the associated entity feature at the next level and the updated network vulnerability feature obtained above can be subjected to feature fusion processing, so as to generate the target updated network vulnerability feature corresponding to each network vulnerability.

[0175] In this way, the aggregation of the context information of the associated entity to be processed at the next level is realized, and the target updated network vulnerability feature with richer feature information is obtained. The target updated network vulnerability feature can more accurately represent the context information between the network vulnerability and the associated entity, and can more accurately represent the network security knowledge about network vulnerabilities in the network security knowledge graph.

[0176] In some embodiments, feature fusion processing is performed based on the to-be-processed associated entity features corresponding to the next level and the updated network vulnerability features to generate the target updated network vulnerability features corresponding to each network vulnerability, including:

[0177] (1.1) Add each of the to-be-processed associated entity features corresponding to the next level and then calculate the average value to obtain the second entity feature;

[0178] (1.2) Perform weighted summation on the second entity feature and the updated network vulnerability features to obtain the target updated network vulnerability features corresponding to each network vulnerability.

[0179] Among them, each of the to-be-processed associated entity features corresponding to the next level can be obtained, and then each of the to-be-processed associated entity features at this level is added to obtain the target addition result. Then, the number of each of the to-be-processed associated entity features at this level is determined, and finally, the target addition result is divided by the number to obtain the second entity feature.

[0180] Then, the value at this level is determined, and then the first weight value corresponding to the to-be-processed associated entity at this level is determined according to this value in the above preset mapping relationship. Since the level of this level is high, the first weight value corresponding to this level is smaller than the first weight value corresponding to the previous level. Then, subtract the first weight value from 1 to obtain the second weight value corresponding to the updated network vulnerability features.

[0181] Multiply the first weight value by the first entity feature, multiply the second weight value by the updated network vulnerability features, and add the results of the two multiplications to obtain the target updated network vulnerability features corresponding to each network vulnerability.

[0182] The target updated network vulnerability features aggregate the previous updated network vulnerability features and the context information of the to-be-processed associated entities at this level, so as to be able to represent the features of network vulnerabilities more accurately and comprehensively, such as the features in terms of network security knowledge.

[0183] In step 305, the target updated network vulnerability features are determined as the updated network vulnerability features, the next level is determined as the current level, and the process returns to execute to determine the to-be-processed associated entities and the to-be-processed associated entity features corresponding to the to-be-processed associated entities at the next level of the current level in the associated entities until the current level is the highest level, and the updated network vulnerability features corresponding to the highest level are determined as the aggregated network vulnerability features corresponding to each network vulnerability.

[0184] Then, determine the target updated network vulnerability feature as the updated network vulnerability feature, determine the next level as the current level, and then determine whether the current level corresponds to the highest level of the associated entity of the network vulnerability. If not, return and execute the to-be-processed associated entity that determines the next level of the current level in the associated entity and the to-be-processed associated entity feature corresponding to the to-be-processed associated entity until the current level is the highest level, and determine the updated network vulnerability feature corresponding to the highest level as the aggregated network vulnerability feature corresponding to each network vulnerability.

[0185] If the current level is the highest level of the associated entity corresponding to the network vulnerability, then directly determine the target updated network vulnerability feature as the aggregated network vulnerability feature corresponding to the network vulnerability.

[0186] As can be seen from steps 301 to 305, in this application, by fusing each network vulnerability feature and the entity feature of the associated entity of each network vulnerability, the context information aggregation of each network vulnerability and the associated entity in the network knowledge graph is realized, and the aggregated network vulnerability feature containing context information is obtained. The aggregated network vulnerability feature will serve as the basis for subsequent association analysis and provide high-quality semantic features for the association reasoning of the technical tactics of network vulnerabilities.

[0187] In step 230, determine the similar aggregated network vulnerability feature corresponding to each network vulnerability according to the similarity between different aggregated network vulnerability features.

[0188] Among them, for each network vulnerability, the aggregated network vulnerability feature of each network vulnerability can be determined through the above method, and then the similarity between the aggregated network vulnerability features corresponding to every two network vulnerabilities is determined. Determine the similar aggregated network vulnerability feature corresponding to each network vulnerability according to the similarity between different aggregated network vulnerability features.

[0189] In some embodiments, determining the similar aggregated network vulnerability feature corresponding to each network vulnerability according to the similarity between different aggregated network vulnerability features includes:

[0190] (1.1) Determine the similarity between the aggregated network vulnerability feature corresponding to each network vulnerability and other aggregated network vulnerability features;

[0191] (1.2) Determine the aggregated network vulnerability features corresponding to other network vulnerabilities with a similarity greater than the preset similarity as the similar aggregated network vulnerability features corresponding to each network vulnerability.

[0192] Specifically, the cosine similarity between the aggregated network vulnerability features can be determined, and this cosine similarity is determined as the similarity between the aggregated network vulnerability features corresponding to every two network vulnerabilities.

[0193] Then, the aggregated network vulnerability features corresponding to other network vulnerabilities with a similarity greater than the preset similarity are determined as the similar aggregated network vulnerability features corresponding to each network vulnerability. For example, when the similarity is greater than 80%, it is determined that two network vulnerabilities are similar.

[0194] In this way, the similar aggregated network vulnerability features corresponding to each network vulnerability can be determined. It is also possible to determine the aggregated network vulnerability features corresponding to other network vulnerabilities with a similarity greater than the preset similarity and the maximum similarity as the similar aggregated network vulnerability features corresponding to each network vulnerability.

[0195] In step 240, the hint text corresponding to each network vulnerability is determined based on the aggregated network vulnerability features and the similar aggregated network vulnerability features, and the hint text is input into the large model for analyzing the association between vulnerabilities and attack techniques and tactics to output the predicted security analysis result corresponding to each network vulnerability. The predicted security analysis result includes the techniques and tactics corresponding to each network vulnerability.

[0196] Among them, the aggregated network vulnerability features can be input into a pre-trained text generation model, and the pre-trained text generation model outputs the first text. Each of the similar aggregated network vulnerability features is input into the pre-trained text generation model respectively, and the second text corresponding to each similar aggregated network vulnerability feature is output. Finally, the first text and the second text are determined as the hint text corresponding to each network vulnerability. Then, the hint text is input into the large model for analyzing the association between vulnerabilities and attack techniques and tactics to output the predicted security analysis result corresponding to each network vulnerability. The predicted security analysis result includes the techniques and tactics corresponding to each network vulnerability.

[0197] Due to the large sparsity of the network security knowledge graph, it may not be possible to extract enough available information (such as the network vulnerability → technology / tactic path) starting from a single current network vulnerability. Therefore, by introducing a set of entities of similar network vulnerabilities, the missing entity information of the current network vulnerability is effectively supplemented. Specifically, when the current network vulnerability lacks a complete vulnerability → technology / tactic path in the knowledge graph, the network security knowledge information associated with the network vulnerability with a high similarity to it can be used for supplementation. For example, if there is no directly associated technology or tactic path for the current network vulnerability entity, the possible association relationship can be inferred through the network security knowledge information associated with its similar network vulnerabilities. This method not only alleviates the sparsity problem of the network security knowledge graph but also significantly improves the integrity and accuracy of the analysis of the current network vulnerability, providing more reliable data support for subsequent reasoning and early warning.

[0198] In some embodiments, determining the hint text corresponding to each network vulnerability according to the aggregated network vulnerability features and the similar aggregated network vulnerability features includes:

[0199] (1.1) Determine the vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to each network vulnerability based on the aggregated network vulnerability characteristics;

[0200] (1.2) Generate the first associated path text and the first vulnerability description text based on the vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to each network vulnerability;

[0201] (1.3) Determine the vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to the similar network vulnerabilities of each network vulnerability based on the similar aggregated network vulnerability characteristics;

[0202] (1.4) Generate the second associated path text and the second vulnerability description text based on the vulnerability instances, vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to the similar network vulnerabilities;

[0203] (1.5) Generate the hint text corresponding to each network vulnerability based on the first associated path text, the first vulnerability description text, the second associated path text, and the second vulnerability description text.

[0204] Among them, the current network vulnerability can be determined based on the aggregated network vulnerability characteristics, then the current network vulnerability can be determined in the network security knowledge graph, and the associated vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to the network vulnerability can be determined.

[0205] Then generate the first associated path text and the first vulnerability description text based on the vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to each network vulnerability. For example, the form of the first associated path text is: network vulnerability - vulnerability weakness - vulnerability attack - technique - tactic. In a specific scenario, for example, it can be expressed as: cve-2022-30318 -> cwe-798 -> capec-70 -> T1078 -> Defense Evasion, cve-2022-30318 -> cwe-798 -> capec-70 -> T1078 -> Defense Evasion. That is to say, the first associated path text can be multiple. Among them, cve-2022-30318 is the network vulnerability numbered 2022-30318, cwe-798 is the vulnerability weakness instance numbered 798, capec-70 is the vulnerability attack instance numbered 70, T1078 is the attack technique numbered 1078, and Defense Evasion is the defense evasion measure of the technique.

[0206] The first vulnerability description text is used to describe network security knowledge information about network vulnerabilities and the associated entities of network vulnerabilities. For example, the first vulnerability description text is: "cve-2022-30318 - Honeywell ControlEdge through R151.1 uses Hard-coded Credentials. According to FSCT-2022-0056, there is a Honeywell ControlEdge hardcoded credentials issue. The affected components are characterized as: SSH...

[0207] cwe-798-...".

[0208] Specifically, it means: cve-2022-30318 - Honeywell ControlEdge version R151.1 uses hard-coded credentials. According to FSCT-2022-0056, there is a hard-coded credentials issue with Honeywell ControlEdge. The affected components are characterized as: SSH... cwe-798...

[0209] Among them, Honeywell ControlEdge is a product name launched by Honeywell, and its specific functions and uses may vary depending on different application scenarios. It may be a control system, software, or other products related to the fields of industrial automation, control, etc.

[0210] According to the similar aggregation of network vulnerability characteristics, similar network vulnerabilities similar to the network vulnerability can be determined, and then the vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to the similar network vulnerabilities of each network vulnerability can be determined in the network security knowledge graph.

[0211] Then, the second associated path text and the second vulnerability description text are generated through the vulnerability instances, vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to the similar network vulnerabilities. The form of the second associated path text is: network vulnerability - vulnerability weakness - vulnerability attack - technique - tactic. The second vulnerability description text is used to describe network security knowledge information about similar network vulnerabilities and the associated entities of similar network vulnerabilities.

[0212] Finally, the prompt text corresponding to each network vulnerability is generated based on the first associated path text, the first vulnerability description text, the second associated path text, and the second vulnerability description text. The prompt text is as follows:

[0213] "Target vulnerability: cve-2022-30318

[0214] Target vulnerability path:

[0215] cve-2022-30318 ->cwe-798 ->capec-70 ->T1078 ->Defense Evasion

[0216] cve-2022-30318 ->cwe-798 ->capec-70 ->capec-560 ->T1078 ->DefenseEvasion

[0217] ……

[0218] Similar vulnerabilities:

[0219] cve-xxxx-xxxx

[0220] cve-xxxx-xxxx

[0221] ……

[0222] Similar vulnerability paths:

[0223] cve-xxxx-xxxx ->cwe-xxx ->capec-xx ->Txxxx ->xxxxxx

[0224] ……

[0225] Entity description:

[0226] cve-2022-30318:

[0227] Honeywell ControlEdge through R151.1 uses Hard-coded Credentials.According to FSCT-2022-0056, there is a Honeywell ControlEdge hardcodedcredentials issue. The affected components are characterized as: SSH. ……

[0228] cwe-798:……

[0229] cve-xxxx-xxxx……

[0230] ……”。

[0231] Among them, capec-560 is the vulnerability attack instance numbered 560. Other English interpretations have been described above.

[0232] Input these prompt texts into the large model for vulnerability and attack technique - tactic correlation analysis. The large model for vulnerability and attack technique - tactic correlation analysis can generate corresponding predicted security analysis results for each network vulnerability by combining these prompt texts. The predicted security analysis results can include the techniques and tactics by which a network vulnerability may be exploited, as well as relevant explanations and defense deployment suggestions, etc.

[0233] As can be seen from the above, in this application, by combining the network security knowledge of each network vulnerability and its similar network vulnerabilities, more accurate prompt texts can be generated, making the content in the prompt texts richer, so as to help the large model for vulnerability and attack technique - tactic correlation analysis obtain more accurate prompt information, thereby realizing the learning of network security knowledge for generating more accurate security analysis results for network security vulnerabilities subsequently.

[0234] In step 250, determine the difference between the labeled security analysis result and the predicted security analysis result corresponding to each network vulnerability, and train the large model for vulnerability and attack technique - tactic correlation analysis based on the difference to obtain the trained large model for vulnerability and attack technique - tactic correlation analysis.

[0235] Among them, after obtaining the predicted security analysis result corresponding to each network vulnerability, the predicted security analysis result can be compared with the labeled security analysis result corresponding to each network vulnerability to determine the difference between the two.

[0236] For example, taking a certain network vulnerability as an example, the predicted security analysis result output by the security model is the techniques and tactics of network attacks that may exist in this network vulnerability. Then, compare the techniques and tactics of this network attack with the real techniques and tactics of network attacks corresponding to this network vulnerability to determine the difference between the two. Specifically, the dissimilarity between the predicted techniques and tactics of network attacks and the real techniques and tactics of network attacks can be determined, and this dissimilarity is used as the difference between the two. If when this dissimilarity is greater than the preset difference value, it means that the predicted security analysis result output by the large model for vulnerability and attack technique - tactic correlation analysis is inaccurate, and the large model for vulnerability and attack technique - tactic correlation analysis needs to be continuously trained. If when this dissimilarity is not greater than the preset difference value, it means that the predicted security analysis result output by the large model for vulnerability and attack technique - tactic correlation analysis is relatively accurate, and other training data can be continuously input for verification. If the dissimilarity between the predicted security analysis result and the labeled security analysis result corresponding to each training data is not greater than the preset difference value, it means that the training of the large model for vulnerability and attack technique - tactic correlation analysis is completed.

[0237] It should be noted that the vulnerability and attack technique and tactics correlation analysis large model in this application can be a large language model, and the LoRA (Low-Rank Adaptation of Large Language Models) technology can be used to fine-tune the parameters of the large language model, so that the large language model is applicable to the scenario of security analysis of network vulnerabilities in this application.

[0238] In this application, by determining network vulnerabilities and similar network vulnerabilities corresponding to the network vulnerabilities in the network security knowledge graph, and then generating prompt text based on the relevant entity description information of the network vulnerabilities and similar network vulnerabilities, the prompt text provides rich context information for the vulnerability and attack technique and tactics correlation analysis large model, so that the vulnerability and attack technique and tactics correlation analysis large model can perform more accurate security analysis on network vulnerabilities.

[0239] In the embodiment of this application, multiple different levels of associated entities corresponding to each network vulnerability are determined according to the network security knowledge graph, and the network vulnerability features corresponding to each network vulnerability and the entity features corresponding to each associated entity are determined; the aggregated network vulnerability features corresponding to each network vulnerability are determined according to the network vulnerability features and entity features; the similar aggregated network vulnerability features corresponding to each network vulnerability are determined according to the similarity between different aggregated network vulnerability features; the prompt text corresponding to each network vulnerability is determined according to the aggregated network vulnerability features and similar aggregated network vulnerability features, and the prompt text is input into the vulnerability and attack technique and tactics correlation analysis large model to output the predicted security analysis results corresponding to each network vulnerability, and the predicted security analysis results include the techniques and tactics corresponding to each network vulnerability; the difference between the labeled security analysis results and the predicted security analysis results corresponding to each network vulnerability is determined, and the vulnerability and attack technique and tactics correlation analysis large model is trained according to the difference to obtain the trained vulnerability and attack technique and tactics correlation analysis large model.

[0240] Thus, multiple associated entities at different levels corresponding to each network vulnerability are determined through the network security knowledge graph. Then, the network vulnerability features corresponding to each network vulnerability and the entity features corresponding to each associated entity are obtained. Next, based on the network vulnerability features of each network vulnerability combined with the entity features of the corresponding associated entities, the aggregated network vulnerability features corresponding to each network vulnerability are obtained, realizing that each network vulnerability is combined with the multi-level associated entities, so that the aggregated network vulnerability features can represent the context information of the network security knowledge graph. Then, the similar aggregated network vulnerability features corresponding to each network vulnerability are determined through the similarity between different aggregated network vulnerability features. The prompt text corresponding to each network vulnerability is determined through the aggregated network vulnerability features and the similar aggregated network vulnerability features. The determined prompt text can represent the context information corresponding to each network vulnerability in the network security knowledge graph and the information of the similar network vulnerabilities similar to each network vulnerability, so that the prompt text input into the vulnerability and attack technique and tactic association analysis large model is more comprehensive, enabling the vulnerability and attack technique and tactic association analysis large model to learn more network security knowledge, thereby realizing the efficient training of the vulnerability and attack technique and tactic association analysis large model. Compared with the solution in the related art that determines the security analysis result corresponding to the network vulnerability based on human experience, the vulnerability and attack technique and tactic association analysis large model trained in this application can accurately analyze the network vulnerability to be processed and output the target security analysis result, and the target security analysis result includes the techniques and tactics for the network vulnerability to be processed to be attacked.

[0241] Please refer to Figure 6 , Figure 6 which is another schematic flowchart of the method for training the vulnerability and attack technique and tactic association analysis large model provided by the embodiment of the present application. The method for training the vulnerability and attack technique and tactic association analysis large model may include the following steps:

[0242] Step 401: Determine multiple network vulnerabilities in the network security database, and determine the vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to each network vulnerability;

[0243] Step 402: Determine the entity relationships among each network vulnerability, vulnerability weakness instance, vulnerability attack instance, technique, and tactic;

[0244] Step 403: Construct a network security knowledge graph corresponding to multiple network vulnerabilities according to the entity relationships, each network vulnerability, vulnerability weakness instance, vulnerability attack instance, technique, and tactic;

[0245] Step 404: Obtain the first description text corresponding to each network vulnerability and the second description text corresponding to each associated entity;

[0246] Step 405: Input the first description text into the pre-trained text processing model to output the network vulnerability features corresponding to each network vulnerability;

[0247] Step 406: Input the second description text into the pre-trained text processing model to output the entity features corresponding to each associated entity;

[0248] Step 407: Determine the to-be-processed associated entity at the current level in the associated entities and the corresponding to-be-processed associated entity features of the to-be-processed associated entity;

[0249] Step 408: Perform feature fusion processing on the to-be-processed associated entity features and the network vulnerability features to generate the updated network vulnerability features corresponding to each network vulnerability;

[0250] Step 409: Determine the to-be-processed associated entity at the next level of the current level in the associated entities and the corresponding to-be-processed associated entity features of the to-be-processed associated entity;

[0251] Step 410: Perform feature fusion processing based on the to-be-processed associated entity features corresponding to the next level and the updated network vulnerability features to generate the target updated network vulnerability features corresponding to each network vulnerability;

[0252] Step 411: Determine the target updated network vulnerability features as the updated network vulnerability features, determine the next level as the current level, and return to execute determining the to-be-processed associated entity at the next level of the current level in the associated entities and the corresponding to-be-processed associated entity features of the to-be-processed associated entity until the current level is the highest level, and determine the updated network vulnerability features corresponding to the highest level as the aggregated network vulnerability features corresponding to each network vulnerability;

[0253] Step 412: Determine the similar aggregated network vulnerability features corresponding to each network vulnerability according to the similarity between different aggregated network vulnerability features;

[0254] Step 413: Determine the prompt text corresponding to each network vulnerability according to the aggregated network vulnerability features and the similar aggregated network vulnerability features, and input the prompt text into the large model for associated analysis of vulnerabilities and attack techniques and tactics to output the predicted security analysis results corresponding to each network vulnerability, where the predicted security analysis results include the techniques and tactics corresponding to each network vulnerability;

[0255] Step 414: Determine the difference between the label security analysis results and the predicted security analysis results corresponding to each network vulnerability, and train the large model for associated analysis of vulnerabilities and attack techniques and tactics according to the difference to obtain the trained large model for associated analysis of vulnerabilities and attack techniques and tactics.

[0256] In the above embodiments, the descriptions of the respective embodiments have their own emphases. For parts not detailed in a certain embodiment, reference may be made to the detailed description of the above-mentioned method for training the vulnerability and attack technique and tactic correlation analysis large model, which will not be elaborated here.

[0257] Please refer to Figure 7 , Figure 7 which is a schematic flowchart of the network security analysis method provided by an embodiment of the present application. The network security analysis method may include the following steps:

[0258] Step 510: Determine multiple target associated entities at different levels corresponding to the network vulnerability to be processed according to the network security knowledge graph, and determine the target network vulnerability feature corresponding to the network vulnerability to be processed and the target entity feature corresponding to each target associated entity;

[0259] Step 520: Determine the target aggregated network vulnerability feature corresponding to the network vulnerability to be processed according to the target network vulnerability feature and the target entity feature;

[0260] Step 530: Determine the target similar aggregated network vulnerability feature corresponding to the network vulnerability to be processed according to the similarity between different target aggregated network vulnerability features;

[0261] Step 540: Determine the target prompt text corresponding to the network vulnerability to be processed according to the target aggregated network vulnerability feature and the target similar aggregated network vulnerability feature;

[0262] Step 550: Input the target prompt text into the trained vulnerability and attack technique and tactic correlation analysis large model, and output the target security analysis result corresponding to the network vulnerability to be processed. The target security analysis result includes the techniques and tactics corresponding to the network vulnerability to be processed, where the trained vulnerability and attack technique and tactic correlation analysis large model is trained based on the method for training the vulnerability and attack technique and tactic correlation analysis large model provided by the embodiment of the present application.

[0263] The following will describe steps 510 to 550 in detail.

[0264] In step 510, multiple target associated entities at different levels corresponding to the network vulnerability to be processed are determined according to the network security knowledge graph, and the target network vulnerability feature corresponding to the network vulnerability to be processed and the target entity feature corresponding to each target associated entity are determined.

[0265] For example, entities such as vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to the network vulnerability to be processed can be determined according to the network security knowledge graph, and then the target description texts corresponding to the network vulnerability to be processed and each target associated entity are determined. Then, each target description text is encoded to generate the target network vulnerability feature corresponding to the network vulnerability to be processed and the target entity feature corresponding to each target associated entity.

[0266] In step 520, the target aggregated network vulnerability feature corresponding to the network vulnerability to be processed is determined according to the target network vulnerability feature and the target entity feature.

[0267] Among them, the target to-be-processed associated entity at the current level and the target to-be-processed associated entity feature corresponding to the target to-be-processed associated entity can be determined in the target associated entity; the feature fusion process is performed on the target to-be-processed associated entity feature and the target network vulnerability feature to generate the first updated network vulnerability feature corresponding to the network vulnerability to be processed; the target to-be-processed associated entity at the next level and the target to-be-processed associated entity feature corresponding to the target to-be-processed associated entity are determined in the target associated entity; the feature fusion process is performed according to the target to-be-processed associated entity feature corresponding to the next level and the first updated network vulnerability feature to generate the second updated network vulnerability feature corresponding to the network vulnerability to be processed; the second updated network vulnerability feature is determined as the first updated network vulnerability feature, the next level is determined as the current level, and the process of determining the target to-be-processed associated entity at the current level and the target to-be-processed associated entity feature corresponding to the target to-be-processed associated entity in the target associated entity is returned and executed until the current level is the highest level, and the first updated network vulnerability feature corresponding to the highest level is determined as the target aggregated network vulnerability feature corresponding to the network vulnerability to be processed.

[0268] In step 530, the target similar aggregated network vulnerability feature corresponding to the network vulnerability to be processed is determined according to the similarity between different target aggregated network vulnerability features.

[0269] The target similarity between the target aggregated network vulnerability feature corresponding to the network vulnerability to be processed and other target aggregated network vulnerability features is determined; the target aggregated network vulnerability features corresponding to other network vulnerabilities with the target similarity greater than the preset target similarity are determined as the target similar aggregated network vulnerability features corresponding to the network vulnerability to be processed.

[0270] In step 540, the target prompt text corresponding to the network vulnerability to be processed is determined according to the target aggregated network vulnerability feature and the target similar aggregated network vulnerability feature.

[0271] Among them, vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to the network vulnerability to be processed can be determined according to the target aggregated network vulnerability characteristics; a target first associated path text and a target first vulnerability description text can be generated according to the vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to the network vulnerability to be processed; vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to the target similar network vulnerability of the network vulnerability to be processed can be determined according to the target similar aggregated network vulnerability characteristics; a target second associated path text and a target second vulnerability description text can be generated according to the vulnerability instances, vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to the target similar network vulnerability; and a prompt text corresponding to the network vulnerability to be processed can be generated according to the target first associated path text, the target first vulnerability description text, the target second associated path text, and the target second vulnerability description text.

[0272] In step 550, the target prompt text is input into the trained vulnerability and attack technique and tactic association analysis large model, and a target security analysis result corresponding to the network vulnerability to be processed is output. The target security analysis result includes the techniques and tactics corresponding to the network vulnerability to be processed, where the trained vulnerability and attack technique and tactic association analysis large model is trained based on the vulnerability and attack technique and tactic association analysis large model training method provided in the embodiments of the present application.

[0273] Finally, the target prompt text corresponding to the network vulnerability to be processed can be input into the trained vulnerability and attack technique and tactic association analysis large model, and a target security analysis result corresponding to the network vulnerability to be processed is output. The target security analysis result includes the techniques and tactics that the network vulnerability to be processed may be exploited, as well as relevant explanations and defense deployment suggestions. For example, for the network vulnerability to be processed input by the user, the model can not only give the associated techniques (such as "Command and Scripting Interpreter") and tactics (such as "Execution"), but also provide specific defense measures (such as "Implement input validation" or "Enable log monitoring"). In this way, the present invention realizes the accurate association analysis from the network vulnerability to be processed to techniques and tactics, and provides scientific and practical decision-making support for network security defense.

[0274] As can be seen from the above, in the present application, the trained vulnerability and attack technique and tactic association analysis large model can accurately analyze the network vulnerability to be processed and output the target security analysis result. The target security analysis result includes the techniques and tactics for the network vulnerability to be processed to be attacked.

[0275] Please refer to Figure 8 , Figure 8It is a schematic structural diagram of a vulnerability and attack technique and tactics correlation analysis large model training device provided by an embodiment of the present application. This vulnerability and attack technique and tactics correlation analysis large model training device can execute the above-mentioned vulnerability and attack technique and tactics correlation analysis large model training method.

[0276] In the embodiments of the present application, the term "module" or "unit" refers to a computer program with a predetermined function or a part of a computer program, which works together with other related parts to achieve a predetermined goal, and can be fully or partially implemented by using software, hardware (such as processing circuits or memories), or a combination thereof. Similarly, one processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be a part of the overall module or unit that includes the function of the module or unit.

[0277] The vulnerability and attack technique and tactics correlation analysis large model training device 600 includes:

[0278] The first determination module 610 is configured to determine multiple different levels of associated entities corresponding to each network vulnerability according to the network security knowledge graph, and determine the network vulnerability features corresponding to each network vulnerability and the entity features corresponding to each associated entity;

[0279] The second determination module 620 is configured to determine the aggregated network vulnerability features corresponding to each network vulnerability according to the network vulnerability features and entity features;

[0280] The third determination module 630 is configured to determine the similar aggregated network vulnerability features corresponding to each network vulnerability according to the similarity between different aggregated network vulnerability features;

[0281] The input module 640 is configured to determine the prompt text corresponding to each network vulnerability according to the aggregated network vulnerability features and the similar aggregated network vulnerability features, and input the prompt text into the vulnerability and attack technique and tactics correlation analysis large model, and output the predicted security analysis result corresponding to each network vulnerability, where the predicted security analysis result includes the techniques and tactics corresponding to each network vulnerability;

[0282] The training module 650 is configured to determine the difference between the labeled security analysis result and the predicted security analysis result corresponding to each network vulnerability, and train the vulnerability and attack technique and tactics correlation analysis large model according to the difference to obtain the trained vulnerability and attack technique and tactics correlation analysis large model.

[0283] In some embodiments, the second determination module 620 includes a first processing sub-module, a first fusion sub-module, a second processing sub-module, a second fusion sub-module, and a determination sub-module;

[0284] The first processing sub-module is used to determine the to-be-processed associated entity at the current level and the to-be-processed associated entity features corresponding to the to-be-processed associated entity in the associated entities;

[0285] The first fusion sub-module is used to perform feature fusion processing on the to-be-processed associated entity features and the network vulnerability features to generate updated network vulnerability features corresponding to each network vulnerability;

[0286] The second processing sub-module is used to determine the to-be-processed associated entity at the next level and the to-be-processed associated entity features corresponding to the to-be-processed associated entity in the associated entities at the next level of the current level;

[0287] The second fusion sub-module is used to perform feature fusion processing according to the to-be-processed associated entity features corresponding to the next level and the updated network vulnerability features to generate target updated network vulnerability features corresponding to each network vulnerability;

[0288] The determination sub-module is used to determine the target updated network vulnerability features as the updated network vulnerability features, determine the next level as the current level, and return to execute to determine the to-be-processed associated entity at the next level and the to-be-processed associated entity features corresponding to the to-be-processed associated entity in the associated entities until the current level is the highest level, and determine the updated network vulnerability features corresponding to the highest level as the aggregated network vulnerability features corresponding to each network vulnerability.

[0289] In some embodiments, the first fusion sub-module is used for:

[0290] Add the to-be-processed associated entity features for each one and then calculate the mean value to obtain the first entity feature;

[0291] Perform weighted summation on the first entity feature and the network vulnerability features to obtain updated network vulnerability features corresponding to each network vulnerability.

[0292] In some embodiments, the first fusion sub-module is used for:

[0293] Obtain the first weight value corresponding to the first entity feature and the second weight value corresponding to the network vulnerability features;

[0294] Multiply the first weight value by the first entity feature to obtain the first feature;

[0295] Multiply the second weight value by the network vulnerability features to obtain the second feature;

[0296] Add the first feature and the second feature to obtain updated network vulnerability features corresponding to each network vulnerability.

[0297] In some embodiments, the second fusion sub-module is used for:

[0298] Sum the features of each to-be-processed associated entity corresponding to the next level and then calculate the average to obtain the second entity feature;

[0299] Perform a weighted sum of the second entity feature and the updated network vulnerability feature to obtain the target updated network vulnerability feature corresponding to each network vulnerability.

[0300] In some embodiments, the first determination module 610 is configured to:

[0301] Obtain the first description text corresponding to each network vulnerability and the second description text corresponding to each associated entity;

[0302] Input the first description text into the pre-trained text processing model, and output the network vulnerability feature corresponding to each network vulnerability;

[0303] Input the second description text into the pre-trained text processing model, and output the entity feature corresponding to each associated entity.

[0304] In some embodiments, the third determination module 630 is configured to:

[0305] Determine the similarity between the aggregated network vulnerability feature corresponding to each network vulnerability and other aggregated network vulnerability features;

[0306] Determine the aggregated network vulnerability features corresponding to other network vulnerabilities with a similarity greater than the preset similarity as the similar aggregated network vulnerability features corresponding to each network vulnerability.

[0307] In some embodiments, the vulnerability and attack technique and tactic association analysis large model training device 600 further includes a graph generation module, which is configured to:

[0308] Before determining multiple associated entities at different levels corresponding to each network vulnerability according to the network security knowledge graph, determine multiple network vulnerabilities in the network security database, and determine the vulnerability weakness instances, vulnerability attack instances, technologies, and tactics corresponding to each network vulnerability;

[0309] Determine the entity relationships between each network vulnerability, vulnerability weakness instance, vulnerability attack instance, technology, and tactic;

[0310] Construct a network security knowledge graph corresponding to multiple network vulnerabilities according to the entity relationships, each network vulnerability, vulnerability weakness instance, vulnerability attack instance, technology, and tactic.

[0311] In some embodiments, the input module 640 is configured to:

[0312] Determine the vulnerability weakness instances, vulnerability attack instances, technologies, and tactics corresponding to each network vulnerability according to the aggregated network vulnerability feature;

[0313] Generate the first associated path text and the first vulnerability description text based on the vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to each network vulnerability;

[0314] Determine the vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to the similar network vulnerabilities of each network vulnerability according to the similar aggregated network vulnerability characteristics;

[0315] Generate the second associated path text and the second vulnerability description text based on the vulnerability instances, vulnerability weakness instances, vulnerability attack instances, techniques, and tactics corresponding to the similar network vulnerabilities;

[0316] Generate the prompt text corresponding to each network vulnerability based on the first associated path text, the first vulnerability description text, the second associated path text, and the second vulnerability description text.

[0317] In the above embodiments, the descriptions of the respective embodiments have their own emphases. For the parts not elaborated in a certain embodiment, reference may be made to the detailed description of the above-mentioned vulnerability and attack technique and tactic association analysis large model training method, which will not be repeated here.

[0318] In the embodiments of the present application, the first determination module 610 determines multiple associated entities at different levels corresponding to each network vulnerability according to the network security knowledge graph, and determines the network vulnerability characteristics corresponding to each network vulnerability and the entity characteristics corresponding to each associated entity; the second determination module 620 determines the aggregated network vulnerability characteristics corresponding to each network vulnerability according to the network vulnerability characteristics and the entity characteristics; the third determination module 630 determines the similar aggregated network vulnerability characteristics corresponding to each network vulnerability according to the similarity between different aggregated network vulnerability characteristics; the input module 640 determines the prompt text corresponding to each network vulnerability according to the aggregated network vulnerability characteristics and the similar aggregated network vulnerability characteristics, and inputs the prompt text into the vulnerability and attack technique and tactic association analysis large model to output the predicted security analysis result corresponding to each network vulnerability, and the predicted security analysis result includes the techniques and tactics corresponding to each network vulnerability; the training module 650 determines the difference between the labeled security analysis result and the predicted security analysis result corresponding to each network vulnerability, and trains the vulnerability and attack technique and tactic association analysis large model according to the difference to obtain the trained vulnerability and attack technique and tactic association analysis large model.

[0319] Thus, multiple associated entities at different levels corresponding to each network vulnerability are determined through the network security knowledge graph. Then, the network vulnerability features corresponding to each network vulnerability and the entity features corresponding to each associated entity are obtained. Next, based on the network vulnerability features of each network vulnerability and combined with the entity features of the corresponding associated entities, the aggregated network vulnerability features corresponding to each network vulnerability are obtained, realizing that each network vulnerability is combined with the multi-level associated entities. This enables the aggregated network vulnerability features to represent the context information of the network security knowledge graph. Then, the similar aggregated network vulnerability features corresponding to each network vulnerability are determined through the similarity between different aggregated network vulnerability features. The prompt text corresponding to each network vulnerability is determined through the aggregated network vulnerability features and the similar aggregated network vulnerability features. The determined prompt text can represent the context information corresponding to each network vulnerability in the network security knowledge graph and the information of the similar network vulnerabilities similar to each network vulnerability. Thus, the prompt text input into the vulnerability and attack technique and tactic association analysis large model is more comprehensive, enabling the vulnerability and attack technique and tactic association analysis large model to learn more network security knowledge, thereby realizing the efficient training of the vulnerability and attack technique and tactic association analysis large model. Compared with the solution in the related art that determines the security analysis result corresponding to the network vulnerability based on human experience, the vulnerability and attack technique and tactic association analysis large model trained in this application can accurately analyze the network vulnerability to be processed and output the target security analysis result, where the target security analysis result includes the techniques and tactics for attacking the network vulnerability to be processed.

[0320] Please refer to Figure 9 , Figure 9 which is a schematic structural diagram of the network security analysis device provided by an embodiment of the present application. This network security analysis device can execute the above network security analysis method.

[0321] The network security analysis device 700 includes:

[0322] An entity determination module 710, configured to determine multiple target associated entities at different levels corresponding to the network vulnerability to be processed according to the network security knowledge graph, and determine the target network vulnerability features corresponding to the network vulnerability to be processed and the target entity features corresponding to each target associated entity;

[0323] A feature determination module 720, configured to determine the target aggregated network vulnerability features corresponding to the network vulnerability to be processed according to the target network vulnerability features and the target entity features;

[0324] A similarity determination module 730, configured to determine the target similar aggregated network vulnerability features corresponding to the network vulnerability to be processed according to the similarity between different target aggregated network vulnerability features;

[0325] A text generation module 740, configured to determine a target prompt text corresponding to a network vulnerability to be processed according to the target aggregated network vulnerability features and the target similar aggregated network vulnerability features;

[0326] A prediction module 750, configured to input the target prompt text into a trained large model for analyzing the association between vulnerabilities and attack techniques and tactics, and output a target security analysis result corresponding to the network vulnerability to be processed, where the target security analysis result includes the techniques and tactics corresponding to the network vulnerability to be processed. The trained large model for analyzing the association between vulnerabilities and attack techniques and tactics is trained based on the method for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics provided in the embodiments of the present application.

[0327] In the above embodiments, the descriptions of the respective embodiments have their own focuses. For parts not detailed in a certain embodiment, reference may be made to the detailed description of the above network security analysis method, which will not be elaborated here.

[0328] The embodiments of the present application further provide a computer device, which includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the method for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics or the network security analysis method described above is implemented. The computer device may be any device including a computer, a server, etc.

[0329] Please refer to Figure 10 , Figure 10 , which shows the hardware structure of a computer device in another embodiment. The computer device includes:

[0330] A processor 901, which may be implemented in a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, etc., and is configured to execute relevant programs to implement the technical solutions provided in the embodiments of the present application;

[0331] A memory 902, which may be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM), etc. The memory 902 may store an operating system and other application programs. When implementing the technical solutions provided in the embodiments of this specification through software or firmware, the relevant program codes are stored in the memory 902, and the processor 901 is called to execute the method for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics or the network security analysis method of the embodiments of the present application;

[0332] An input / output interface 903, configured to implement information input and output;

[0333] A communication interface 904, which is used to implement the communication interaction between this device and other devices, can achieve communication through a wired method (such as USB, network cable, etc.), or can also achieve communication through a wireless method (such as mobile network, WIFI, Bluetooth, etc.);

[0334] A bus 905 transmits information between various components of the device (such as a processor 901, a memory 902, an input / output interface 903, and a communication interface 904);

[0335] Among them, the processor 901, the memory 902, the input / output interface 903, and the communication interface 904 achieve communication connections with each other inside the device through the bus 905.

[0336] The embodiment of this application also provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it implements the above-mentioned vulnerability and attack technique and tactic association analysis large model training method or network security analysis method.

[0337] As a non-transitory computer-readable storage medium, the memory can be used to store non-transitory software programs and non-transitory computer-executable programs. In addition, the memory can include high-speed random access memory, and can also include non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory optionally includes a memory remotely set relative to the processor, and these remote memories can be connected to the processor through a network. Examples of the above-mentioned network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.

[0338] The method, device, and equipment for training a large model for analyzing the association between vulnerabilities and attack techniques and tactics provided by the embodiments of the present application determine multiple associated entities at different levels corresponding to each network vulnerability according to a network security knowledge graph, and determine the network vulnerability features corresponding to each network vulnerability and the entity features corresponding to each associated entity; determine the aggregated network vulnerability features corresponding to each network vulnerability according to the network vulnerability features and entity features; determine the similar aggregated network vulnerability features corresponding to each network vulnerability according to the similarity between different aggregated network vulnerability features; determine the prompt text corresponding to each network vulnerability according to the aggregated network vulnerability features and the similar aggregated network vulnerability features, and input the prompt text into the large model for analyzing the association between vulnerabilities and attack techniques and tactics to output the predicted security analysis result corresponding to each network vulnerability, where the predicted security analysis result includes the techniques and tactics corresponding to each network vulnerability; determine the difference between the labeled security analysis result and the predicted security analysis result corresponding to each network vulnerability, and train the large model for analyzing the association between vulnerabilities and attack techniques and tactics according to the difference to obtain the trained large model for analyzing the association between vulnerabilities and attack techniques and tactics.

[0339] In this way, multiple associated entities at different levels corresponding to each network vulnerability are determined according to the network security knowledge graph, then the network vulnerability features corresponding to each network vulnerability and the entity features corresponding to each associated entity are obtained, and then the aggregated network vulnerability features corresponding to each network vulnerability are obtained by combining the network vulnerability features of each network vulnerability with the entity features of the corresponding associated entities, realizing the combination of each network vulnerability with the associated multi-level associated entities, so that the aggregated network vulnerability features can represent the context information of the network security knowledge graph. Then, the similar aggregated network vulnerability features corresponding to each network vulnerability are determined according to the similarity between different aggregated network vulnerability features, and the prompt text corresponding to each network vulnerability is determined by the aggregated network vulnerability features and the similar aggregated network vulnerability features. The determined prompt text can represent the context information corresponding to each network vulnerability in the network security knowledge graph and the information of the similar network vulnerabilities similar to each network vulnerability, so that the prompt text input into the large model for analyzing the association between vulnerabilities and attack techniques and tactics is more comprehensive, enabling the large model for analyzing the association between vulnerabilities and attack techniques and tactics to learn more network security knowledge, thereby realizing the efficient training of the large model for analyzing the association between vulnerabilities and attack techniques and tactics. Compared with the solution in the related art that determines the security analysis result corresponding to a network vulnerability based on human experience, the trained large model for analyzing the association between vulnerabilities and attack techniques and tactics of the present application can accurately analyze the network vulnerability to be processed and output the target security analysis result, where the target security analysis result includes the techniques and tactics for attacking the network vulnerability to be processed.

[0340] The embodiments described in the embodiments of the present application are to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. As can be known to those skilled in the art, with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of the present application are also applicable to similar technical problems.

[0341] Those skilled in the art can understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than those shown in the figures, or combine certain steps, or different steps.

[0342] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0343] Those of ordinary skill in the art can understand that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, and their appropriate combinations.

[0344] The terms "first", "second", "third", "fourth", etc. (if any) in the specification of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.

[0345] It should be understood that in this application, "at least one (item)" means one or more, and "a plurality" means two or more. "And / or" is used to describe the association relationship of associated objects and indicates that three relationships can exist. For example, "A and / or B" can mean: only A exists, only B exists, and both A and B exist simultaneously. Here, A and B can be singular or plural. The character " / " generally indicates that the associated objects before and after are in an "or" relationship. "At least one (item) of the following" or its similar expressions refer to any combination of these items, including any combination of single items (items) or plural items (items). For example, at least one (item) of a, b, or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.

[0346] In several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the above units is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of devices or units can be in electrical, mechanical, or other forms.

[0347] The units described above as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0348] In addition, in each embodiment of this application, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.

[0349] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes multiple instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods of various embodiments of this application. The aforementioned storage medium includes: various media that can store programs, such as USB flash drives, mobile hard disks, read-only memories (ROM), random access memories (RAM), magnetic disks, or optical discs.

[0350] The preferred embodiments of the embodiments of this application have been described above with reference to the accompanying drawings, and thus do not limit the scope of the rights of the embodiments of this application. Any modifications, equivalent replacements, and improvements made by those skilled in the art without departing from the scope and essence of the embodiments of this application shall be within the scope of the rights of the embodiments of this application.

Claims

1. A large model training method for vulnerability and attack technique and tactic correlation analysis, characterized in that: include: Determine, according to the network security knowledge graph, a plurality of associated entities at different levels corresponding to each network vulnerability, and determine a network vulnerability feature corresponding to each network vulnerability and an entity feature corresponding to each associated entity; Determine, according to the network vulnerability feature and the entity feature, an aggregated network vulnerability feature corresponding to each network vulnerability; Determine the similar aggregated network vulnerability feature corresponding to each network vulnerability according to the similarity between the different aggregated network vulnerability features; Determine a prompt text corresponding to each network vulnerability according to the aggregated network vulnerability feature and the similar aggregated network vulnerability feature, input the prompt text into a large model for analyzing the association between vulnerability and attack techniques and tactics, and output a predicted security analysis result corresponding to each network vulnerability, wherein the predicted security analysis result includes techniques and tactics corresponding to each network vulnerability; Determine the difference between the label security analysis result corresponding to each network vulnerability and the predicted security analysis result, and train the vulnerability and attack technique and tactics association analysis model based on the difference to obtain the trained vulnerability and attack technique and tactics association analysis model.

2. The method for training a large model for vulnerability and attack technique and tactical correlation analysis according to claim 1 is characterized in that: The determining, according to the network vulnerability feature and the entity feature, an aggregated network vulnerability feature corresponding to each network vulnerability includes: Determining, among the associated entities, associated entities to be processed at the current level and associated entity features to be processed corresponding to the associated entities to be processed; Performing feature fusion processing on the to-be-processed associated entity features and the network vulnerability features to generate updated network vulnerability features corresponding to each network vulnerability; Determining, among the associated entities, associated entities to be processed at a level below the current level and associated entity features to be processed corresponding to the associated entities to be processed; Perform feature fusion processing on the to-be-processed associated entity features and the updated network vulnerability features corresponding to the next level to generate target updated network vulnerability features corresponding to each network vulnerability; The target updated network vulnerability feature is determined as the updated network vulnerability feature, the next level is determined as the current level, and the associated entities to be processed and the associated entity features to be processed corresponding to the associated entities to be processed are returned to be executed until the current level is the highest level, and the updated network vulnerability feature corresponding to the highest level is determined as the aggregated network vulnerability feature corresponding to each network vulnerability.

3. The method for training a large model for vulnerability and attack technique and tactical correlation analysis according to claim 2 is characterized in that: The step of performing feature fusion processing on the to-be-processed associated entity feature and the network vulnerability feature to generate an updated network vulnerability feature corresponding to each network vulnerability includes: Adding each of the associated entity features to be processed and calculating the average value to obtain a first entity feature; A weighted sum is performed on the first entity feature and the network vulnerability feature to obtain an updated network vulnerability feature corresponding to each network vulnerability.

4. The method for training a large model for vulnerability and attack technique and tactical correlation analysis according to claim 3 is characterized in that: The step of performing weighted summation on the first entity feature and the network vulnerability feature to obtain an updated network vulnerability feature corresponding to each network vulnerability includes: Obtaining a first weight value corresponding to the first entity feature and a second weight value corresponding to the network vulnerability feature; Multiplying the first weight value by the first entity feature to obtain a first feature; Multiplying the second weight value by the network vulnerability feature to obtain a second feature; The first feature and the second feature are added together to obtain an updated network vulnerability feature corresponding to each network vulnerability.

5. The method for training a large model for vulnerability and attack technique and tactical correlation analysis according to claim 2 is characterized in that: The step of performing feature fusion processing on the associated entity features to be processed and the updated network vulnerability features corresponding to the next level to generate the target updated network vulnerability features corresponding to each network vulnerability includes: Adding and averaging each of the to-be-processed associated entity features corresponding to the next level to obtain a second entity feature; A weighted sum is performed on the second entity feature and the updated network vulnerability feature to obtain a target updated network vulnerability feature corresponding to each network vulnerability.

6. The method for training a large model for vulnerability and attack technique and tactical correlation analysis according to claim 1 is characterized in that: The determining of the network vulnerability feature corresponding to each network vulnerability and the entity feature corresponding to each associated entity includes: Obtaining a first description text corresponding to each network vulnerability and a second description text corresponding to each associated entity; Inputting the first description text into a pre-trained text processing model, and outputting network vulnerability features corresponding to each network vulnerability; The second description text is input into a pre-trained text processing model, and entity features corresponding to each associated entity are output.

7. The method for training a large model for vulnerability and attack technique and tactical correlation analysis according to claim 1 is characterized in that: The determining, according to the similarity between the different aggregated network vulnerability features, the similar aggregated network vulnerability feature corresponding to each network vulnerability comprises: Determine the similarity between the aggregated network vulnerability feature corresponding to each network vulnerability and other aggregated network vulnerability features; The aggregated network vulnerability features corresponding to other network vulnerabilities with a similarity greater than a preset similarity are determined as the similar aggregated network vulnerability features corresponding to each network vulnerability.

8. The method for training a large model for vulnerability and attack technique and tactical correlation analysis according to claim 1 is characterized in that: Before determining the associated entities of different levels corresponding to each network vulnerability according to the network security knowledge graph, the method further includes: Identify multiple network vulnerabilities in the network security database and identify vulnerability weakness instances, vulnerability attack instances, techniques and tactics corresponding to each network vulnerability; Determine the entity relationship between each of the network vulnerabilities, the vulnerability weakness instances, the vulnerability attack instances, the techniques, and the tactics; A network security knowledge graph corresponding to the multiple network vulnerabilities is constructed according to the entity relationship, each network vulnerability, the vulnerability weakness instance, the vulnerability attack instance, the technology and the tactics.

9. The method for training a large model for vulnerability and attack technique and tactical correlation analysis according to claim 8 is characterized in that: The step of determining the prompt text corresponding to each network vulnerability according to the aggregated network vulnerability feature and the similar aggregated network vulnerability feature includes: Determine vulnerability instances, vulnerability attack instances, techniques and tactics corresponding to each network vulnerability according to the aggregated network vulnerability features; Generate a first association path text and a first vulnerability description text according to the vulnerability weakness instance, vulnerability attack instance, technique and tactics corresponding to each network vulnerability; Determine vulnerability instances, vulnerability attack instances, techniques and tactics corresponding to similar network vulnerabilities of each network vulnerability according to the similar aggregated network vulnerability features; Generate a second association path text and a second vulnerability description text according to the vulnerability instances, vulnerability weakness instances, vulnerability attack instances, techniques and tactics corresponding to the similar network vulnerabilities; Generate a prompt text corresponding to each network vulnerability according to the first associated path text, the first vulnerability description text, the second associated path text and the second vulnerability description text.

10. A network security analysis method, characterized in that: include: Determine a plurality of target-related entities at different levels corresponding to the network vulnerability to be processed according to the network security knowledge graph, and determine a target network vulnerability feature corresponding to the network vulnerability to be processed and a target entity feature corresponding to each target-related entity; Determine the target aggregated network vulnerability feature corresponding to the network vulnerability to be processed according to the target network vulnerability feature and the target entity feature; Determine the target similar aggregated network vulnerability feature corresponding to the network vulnerability to be processed according to the similarity between the different target aggregated network vulnerability features; Determine a target prompt text corresponding to the to-be-processed network vulnerability according to the target aggregated network vulnerability feature and the target similar aggregated network vulnerability feature; The target prompt text is input into the trained vulnerability and attack technique and tactics correlation analysis model, and the target security analysis result corresponding to the network vulnerability to be processed is output, wherein the target security analysis result includes the technology and tactics corresponding to the network vulnerability to be processed, wherein the trained vulnerability and attack technique and tactics correlation analysis model is trained based on the vulnerability and attack technique and tactics correlation analysis model training method according to any one of claims 1 to 9.

11. A large model training device for vulnerability and attack technique and tactical correlation analysis, characterized in that: include: A first determination module is used to determine, according to the network security knowledge graph, a plurality of associated entities at different levels corresponding to each network vulnerability, and determine a network vulnerability feature corresponding to each network vulnerability and an entity feature corresponding to each associated entity; A second determination module, configured to determine an aggregated network vulnerability feature corresponding to each network vulnerability according to the network vulnerability feature and the entity feature; A third determination module is used to determine the similar aggregated network vulnerability feature corresponding to each network vulnerability according to the similarity between the different aggregated network vulnerability features; An input module, used to determine a prompt text corresponding to each network vulnerability according to the aggregated network vulnerability feature and the similar aggregated network vulnerability feature, and input the prompt text into a large model for analyzing the association between vulnerability and attack techniques and tactics, and output a predicted security analysis result corresponding to each network vulnerability, wherein the predicted security analysis result includes techniques and tactics corresponding to each network vulnerability; The training module is used to determine the difference between the label security analysis result corresponding to each network vulnerability and the predicted security analysis result, and train the vulnerability and attack technique and tactics association analysis model according to the difference to obtain the trained vulnerability and attack technique and tactics association analysis model.

12. A network security analysis device, characterized in that: include: An entity determination module is used to determine a plurality of target-related entities of different levels corresponding to the network vulnerability to be processed according to the network security knowledge graph, and to determine a target network vulnerability feature corresponding to the network vulnerability to be processed and a target entity feature corresponding to each target-related entity; A feature determination module, used to determine a target aggregated network vulnerability feature corresponding to the network vulnerability to be processed according to the target network vulnerability feature and the target entity feature; A similarity determination module, used to determine the target similar aggregated network vulnerability feature corresponding to the network vulnerability to be processed according to the similarity between different target aggregated network vulnerability features; A text generation module, used to determine a target prompt text corresponding to the to-be-processed network vulnerability according to the target aggregated network vulnerability feature and the target similar aggregated network vulnerability feature; A prediction module is used to input the target prompt text into a trained large model for analyzing the association between vulnerabilities and attack techniques and tactics, and output a target security analysis result corresponding to the network vulnerability to be processed, wherein the target security analysis result includes techniques and tactics corresponding to the network vulnerability to be processed, wherein the trained large model for analyzing the association between vulnerabilities and attack techniques and tactics is trained based on the large model training method for analyzing the association between vulnerabilities and attack techniques and tactics described in any one of claims 1 to 9.

13. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a plurality of instructions, which are suitable for being loaded by a processor to execute the large-model training method for vulnerability and attack technique and tactics correlation analysis described in any one of claims 1 to 9 or the network security analysis method described in claim 10.

14. A computer device comprising a memory, a processor, and a computer program stored in the memory and capable of running on the processor, characterized in that: When the processor executes the computer program, it implements the large model training method for vulnerability and attack technique and tactics correlation analysis described in any one of claims 1 to 9 or the network security analysis method described in claim 10.

Citation Information

Patent Citations

  • Method and device for automatically mapping vulnerabilities to attack techniques and tactics based on large language model

    CN118368103A

  • Network space vulnerability clustering method based on feature value similarity calculation

    CN119203160A