Network security threat detection method and device based on large model
By applying large-scale model technology in DCS systems, screening important features and generating embeddings for similarity measurements, the problems of low efficiency and poor accuracy of DCS network threat detection are solved, and faster, accurate and intelligent threat detection effects are achieved.
Patent Information
- Application Number
- CN202510289011.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-12
- Publication Date
- 2025-06-03
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the prior art, the application of large-scale model technology in the detection of network threats has not been fully explored, resulting in low detection efficiency and poor accuracy.
Using a large-model-based network security threat detection method, by acquiring and processing network traffic data sets, important features are screened using principal component regression or partial least squares regression methods, and embeddings are generated and stored in a vector database. After the real-time network traffic is processed the same, it is compared with the embedding in the database through similarity metrics to achieve threat detection.
It improves the speed, accuracy and intelligence of DCS network threat detection, avoids overfitting problems, and achieves more efficient network threat identification.
Smart Images

Figure CN120090854A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network threat detection, and in particular to a network security threat detection method and device based on a large model, as well as an electronic device and a storage medium. Background Art
[0002] The distributed control system (DCS), also known as the distributed control system, is widely used in the field of industrial automation for monitoring and controlling production processes. Due to its importance and complexity, especially with the continuous evolution of various threat situations such as zero-day attacks, DCS has become an important target for cyberattacks. At present, the application of large models in the DCS network threat detection function remains to be explored. Summary of the Invention
[0003] In view of the technical problems existing in the prior art, embodiments of the present invention provide a network security threat detection method and device based on a large model, introducing large model technology to implement network threat detection for the distributed control system DCS, making the network threat detection for DCS faster, more accurate and more intelligent.
[0004] To achieve the above object, the embodiments of the present invention adopt the following technical solutions: In a first aspect, an embodiment of the present invention provides a network security threat detection method based on a large model, which specifically includes: S1: Obtain a network traffic data set as a training set, and perform data processing on the training set. The data processing includes sorting the input features in the training set by using the principal component regression or partial least squares regression method to evaluate the feature importance, and selecting the first preset number of features as input parameters; S2: Use the features selected in the above step as input parameters and pass them into an embedding generation function to generate embeddings. The embedding generation function uses the embedding API of the large model to convert network features into embeddings, that is, generate a set of vectors with a fixed dimension size; S3: Store all the embeddings generated in the above step in a vector database, and label the embeddings as safe category embeddings or malicious category embeddings; S4: Obtain the real-time network traffic in the distributed control system DCS, and perform the same data processing on the real-time network traffic as in step S1 to select the first preset number of features corresponding to the real-time network traffic as input parameters; S5: Use the features selected in the above step as input, and also pass them into the embedding generation function to generate embeddings; S6: And determine whether the embedding is similar enough to any of the embeddings already stored in the vector database through similarity measurement; S7: Classify the real-time network traffic based on the judgment results in the above steps, so as to achieve network threat detection.
[0005] Optionally, use a network traffic dataset created by generating real attacks in the DCS system. This network traffic dataset is divided into 8 categories: Distributed Denial of Service (DDoS) attack, malware attack, SQL injection attack, packet sniffing attack, Advanced Persistent Threat (APT), zero-day attack (0day), message tampering, and message forgery.
[0006] Optionally, the preset number of features is 7 features, including: time difference from the previous packet, minimum length of packets in the flow, maximum length of packets in the flow, average length of packets in the flow, total length of packets in the flow, number of packets with the RST flag set in the same flow, and length of the header.
[0007] Optionally, the large model is the GPT4.0 model of OpenAI.
[0008] Optionally, the vector database is an open-source search similarity vector database.
[0009] Optionally, the similarity metric includes measuring the distance between two vectors. For two vectors P = {P 1 , P 2 ,..., P n} and Q = {Q 1 , Q 2 ,..., Q n}, we use the following method to measure the distance between the two vectors:
[0010] Second aspect, an embodiment of the present invention further provides a network security threat detection device based on a large model, specifically including: a first acquisition and processing module, configured to acquire a network traffic dataset as a training set and perform data processing on the training set. The data processing includes sorting the input features in the training set using principal component regression or partial least squares regression methods to evaluate feature importance, and selecting the first preset number of features as input parameters; a first embedding generation module, configured to use the features selected by the first acquisition and processing module as input parameters and input them into an embedding generation function to generate embeddings. The embedding generation function uses the embedding API of the large model to convert network features into embeddings, that is, generates a set of vectors with a fixed dimension size; an embedding storage and marking module, configured to store all the embeddings generated by the first embedding generation module into a vector database and mark the embeddings as safe category embeddings or malicious category embeddings; a second acquisition and processing module, configured to acquire real-time network traffic in a distributed control system (DCS) and perform the same data processing as the first acquisition and processing module on the real-time network traffic to select the first preset number of features corresponding to the real-time network traffic as input parameters; a second embedding generation module, configured to use the features selected by the second acquisition and processing module as input and also input them into the embedding generation function to generate embeddings; a similarity measurement module, configured to determine whether the embeddings are similar enough to any of the embeddings already stored in the vector database through similarity measurement; a classification module, configured to classify the real-time network traffic based on the determination result, thereby realizing network threat detection.
[0011] Third aspect, an embodiment of the present invention further provides an electronic device, including: a memory and a processor, the memory and the processor are coupled; the memory stores program instructions, and when the program instructions are executed by the processor, the electronic device executes the above-mentioned network security threat detection method based on a large model.
[0012] Fourth aspect, an embodiment of the present invention further provides a computer-readable storage medium, including a computer program, and when the computer program runs on an electronic device, the electronic device executes the above-mentioned network security threat detection method based on a large model.
[0013] In an embodiment of the present invention, a network traffic dataset is obtained as a training set, and data processing is performed on the training set; the data processing includes sorting the input features in the training set using the principal component regression or partial least squares regression method to evaluate the feature importance, and selecting the first preset number of features as input parameters; using the features selected in the above steps as inputs and passing them into an embedding generation function to generate embeddings; the embedding generation function converts network features into embeddings using the embedding API of a large model, that is, generates a set of vectors with a fixed dimension size; storing all the embeddings generated in the above steps in a vector database; obtaining the real-time network traffic in the distributed control system (DCS), and performing the same data processing on the real-time network traffic to select the first preset number of features corresponding to the real-time network traffic as input parameters; using the features selected above as inputs and also passing them into the embedding generation function to generate embeddings, and determining whether the embeddings are similar enough to any of the embeddings stored in the vector database through similarity measurement; classifying the real-time network traffic based on the judgment result. By introducing large model technology to implement network threat detection for the distributed control system (DCS), the network threat detection for the DCS becomes faster, more accurate, and more intelligent; in addition, a regularization regression method is used to screen out a small number of relatively important input features from a large number of features included in the dataset, avoiding hindering the model performance and causing overfitting.
[0014] The technical solution of the present invention will be further described in detail below with reference to the drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] By describing the embodiments of the present invention in more detail in conjunction with the drawings, the above and other objects, features, and advantages of the present invention will become more obvious. The drawings are used to provide a further understanding of the embodiments of the present invention, and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention, and do not constitute a limitation to the present invention. In the drawings, the same reference numerals generally represent the same components or steps.
[0016] Figure 1 It is a flowchart of the method provided by an exemplary embodiment of the present invention.
[0017] Figure 2 It is a structural diagram of the device provided by an exemplary embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0018] Next, exemplary embodiments of the present invention will be described in detail with reference to the drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments of the present invention. It should be understood that the present invention is not limited by the exemplary embodiments described herein.
[0019] It should be noted that: Unless otherwise specifically stated, the relative arrangements, numerical expressions, and numerical values of the components and steps described in these embodiments do not limit the scope of the present invention.
[0020] Those skilled in the art can understand that terms such as "first", "second", etc. in the embodiments of the present invention are only used to distinguish different steps, devices, or modules, etc., and neither represent any specific technical meaning nor indicate an inevitable logical order between them.
[0021] It should also be understood that in the embodiments of the present invention, "a plurality of" may refer to two or more, and "at least one" may refer to one, two, or more.
[0022] It should also be understood that for any component, data, or structure mentioned in the embodiments of the present invention, in the absence of a clear definition or contrary indication in the context, it can generally be understood as one or more.
[0023] Distributed Control System (DCS): Also known as distributed control system, it adopts the basic design concept of decentralized control, centralized operation and management, and adopts a multi-layer hierarchical and cooperative autonomous structure form. Its main feature is its centralized management and decentralized control. At present, DCS has been extremely widely used in various industries such as electric power, metallurgy, and petrochemical. Reliability is the lifeblood of DCS development. There are mainly three measures to ensure the high reliability of DCS in the prior art: one is to widely apply high-reliability hardware devices and production processes; the second is to widely adopt redundancy technology; the third is to widely implement system fault tolerance technology, fault self-diagnosis, and automatic processing technology, etc. in software design.
[0024] However, attackers may launch various attacks by taking advantage of unpatched vulnerabilities in various devices or communication protocols in DCS. The following are several common types of network attacks against DCS systems: Distributed Denial of Service Attack (DDoS): The attacker floods the DCS system or its network interface with a large number of requests or data traffic, causing the system to be unable to work properly, thereby affecting the production process.
[0025] Malware attack: Including malicious software such as viruses, worms, Trojans, and ransomware, which infect computers or controllers in the DCS system to steal information, damage data, or carry out other malicious activities.
[0026] SQL injection attack: If the DCS system contains a database component, the attacker can inject malicious SQL code into the input field to obtain sensitive information in the database.
[0027] Packet sniffing attack: The attacker intercepts the data packets transmitted by the DCS system network to obtain sensitive information such as control parameters and operation instructions.
[0028] Advanced Persistent Threat (APT): Refers to a long-term and organized cyber attack targeting a specific DCS system, aiming to steal confidential information or disrupt the production process.
[0029] Zero-day attack (0day): An attack that exploits vulnerabilities that have not been publicly disclosed or patched. Such attacks are difficult to defend against because defensive measures often lag behind the development of attack techniques.
[0030] Tampering with messages: Attackers cause abnormal system behavior and affect the production process by changing, deleting, or delaying messages in the DCS system.
[0031] Forging messages: Attackers generate false messages and inject them into the DCS system, causing the system to make incorrect decisions or actions.
[0032] Large models refer to machine learning models with large-scale parameters and complex computational structures, usually constructed by deep neural networks, with billions or even hundreds of billions of parameters. The design purpose of large models is to improve the model's expressive ability and prediction performance, and they can handle more complex tasks and data. These models learn complex patterns and features by training on massive amounts of data, have stronger generalization ability, and can make accurate predictions on unseen data.
[0033] Large models have a wide range of applications in various fields, including natural language processing, computer vision, speech recognition, and recommendation systems, etc. For example, GPT-3 is a language model that can perform various tasks such as text generation, question answering, and translation.
[0034] Embedding is a technique that maps diverse inputs to a compact vector representation, usually with a lower dimension than the original input. This method can ensure that similar data is closely aligned in the vector space. Define embedding as a function that maps each input feature (such as network traffic data) to a low-dimensional vector representation. This low-dimensional space allows for efficient storage and comparison of data. Mathematically, given a set of inputs X = {x 1 , x 2 ,..., x m}, where each x i represents an input feature, embedding can be defined as a function f: X → R n , which maps each input feature x i to an n-dimensional vector representation e i , defined as: e i = f(x i ), where e i is the vector representation of x iThe n-dimensional vector representation (embedding), where n is the dimension of the embedding space, which is less than the dimension m of the original data space. In a DCS network, the embedding can be used to convert network traffic data into a unique vector representation. These representations can then be compared with a database of known attack signatures for faster and more accurate network threat detection.
[0035] Embodiment 1 According to an embodiment of the present invention, there is provided a method embodiment of a network security threat detection method based on a large model. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0036] Figure 1 is a flowchart of a network security threat detection method based on a large model according to an embodiment of the present invention, as Figure 1 shown, the method includes the following steps: S1: Obtain a network traffic data set as a training set, and perform data processing on the training set. The data processing includes sorting the input features in the training set using principal component regression or partial least squares regression methods to evaluate feature importance, and selecting the first preset number of features as input parameters; Use a data set created by generating real attacks in a distributed control system (DCS). This data set was collected from 33 different attacks, divided into 8 categories: distributed denial of service (DDoS) attacks, malware attacks, SQL injection attacks, packet sniffing attacks, advanced persistent threats (APT), zero-day attacks (0day), message tampering, and message forgery.
[0037] Our data set contains a large number of features, which can hinder model performance and lead to overfitting. Sort the input features in the data set according to their correlation to evaluate feature importance. We use a regularization regression method (such as principal component regression or partial least squares regression) feature selection technique to select the first 7 features as input parameters. As shown in the following table:
[0038] S2: Use the features selected in the above step as input parameters and pass them into an embedding generation function to generate embeddings. The embedding generation function uses the embedding API of the large model to convert network features into embeddings, that is, generate a set of vectors with a fixed dimension size; S3: Store all the embeddings generated in the above step in a vector database, and label the embeddings as safe category embeddings or malicious category embeddings; S4: Obtain the real-time network traffic in the distributed control system (DCS), and perform the same data processing on the real-time network traffic as in step S1 to select the first preset number of features corresponding to the real-time network traffic as input parameters; S5: Use the features selected in the above steps as input and also pass them into the embedding generation function to generate embeddings; S6: And determine whether the generated embeddings are similar enough to any of the embeddings stored in the vector database through similarity measurement; Embedding matching is used to evaluate the similarity between network traffic embeddings, thereby identifying deviations that may represent abnormal network activities. This process includes recording tagged network embeddings, providing embedding instances including malicious categories and security categories. Network traffic is converted into embeddings through a specified large model embedding function (such as OpenAI's GPT4.0 model), which serves as the basis for our network embedding library and is stored in the vector database for subsequent analysis.
[0039] When generating embeddings, we use the previously defined network features as input and pass them into the embedding generation function. This function uses the embedding API of the large model to convert network features into embeddings and generates a set of vectors with a fixed dimension size. To store network embeddings, we use an open-source search similarity vector database. For the incoming network traffic, it is evaluated by generating its corresponding embeddings and checking whether there are similar embeddings in our vector database. This comparison enables us to determine whether the incoming traffic is very similar to any of the stored embeddings.
[0040] For two vectors P = {P 1 , P 2 ,..., P n} and Q = {Q 1 , Q 2 ,..., Q n}, we use the following method to measure the distance between the two vectors:
[0041] S7: Classify the real-time network traffic based on the judgment result in the above steps, thereby realizing network threat detection.
[0042] A measure close to zero indicates a high similarity to existing malicious or security category embedding instances, thereby classifying incoming network traffic. The goal of this method is to provide a lightweight network traffic classification method that relies on similarity metrics. To improve the accuracy of the classifier, we define a threshold for the similarity metric. We preset a threshold of 5%, which means that the embedding of incoming network traffic must have a similarity of more than 95% with the stored security type embeddings to be classified as secure traffic. If the similarity of the embedding of incoming network traffic to a stored security type embedding is lower than this value, it indicates that the closest match in our database is not similar enough, indicating that the incoming embedding does not belong to the assumed security category. Therefore, the incoming network traffic is classified as a malicious category for further analysis.
[0043] As can be seen from the above, in the embodiments of the present invention, the embedding API of the large model is used to convert the network features of real-time network traffic in the distributed control system DCS into embeddings, and the similarity metric is used to determine the similarity between the embedding of the incoming real-time network traffic and a stored security category embedding or malicious category embedding, so as to classify the real-time network traffic, thereby realizing more rapid, accurate, and intelligent threat detection for the DCS network. In addition, the regularization regression method is used to screen out a small number of relatively important input features from a large number of features included in the dataset, avoiding overfitting that may hinder the model performance.
[0044] Embodiment 2 According to an embodiment of the present invention, a product embodiment of a network security threat detection device based on a large model is provided.
[0045] Figure 2 is a structural block diagram of a network security threat detection device based on a large model according to an embodiment of the present invention, as Figure 2 shown, including: The first acquisition and processing module 10 is configured to acquire a network traffic dataset as a training set and perform data processing on the training set. The data processing includes sorting the input features in the training set using the principal component regression or partial least squares regression method to evaluate the feature importance, and selecting the top preset number of features as input parameters; The first embedding generation module 20 is configured to use the features selected by the first acquisition and processing module as input parameters and pass them into an embedding generation function to generate embeddings. The embedding generation function uses the embedding API of the large model to convert network features into embeddings, that is, to generate a set of vectors with a fixed dimension size; The embedding storage and marking module 30 is configured to store all the embeddings generated by the first embedding generation module in a vector database and mark the embeddings as security category embeddings or malicious category embeddings; The second acquisition and processing module 40 is configured to acquire the real-time network traffic in the distributed control system (DCS), and perform the same data processing on the real-time network traffic as that in the first acquisition and processing module, so as to select the top preset number of features corresponding to the real-time network traffic as input parameters; The second embedding generation module 50 is configured to use the features selected by the second acquisition and processing module as input, and also input them into the embedding generation function to generate embeddings; The similarity measurement module 60 is configured to determine whether the embedding is similar enough to any of the embeddings stored in the vector database through similarity measurement; The classification module 70 is configured to classify the real-time network traffic based on the determination result, so as to implement network threat detection.
[0046] As can be seen from the above, in the embodiments of the present invention, the real-time network traffic network features in the distributed control system (DCS) are converted into embeddings by using the embedding API of the large model, and the similarity between the embedding of the incoming real-time network traffic and a certain stored security category embedding or malicious category embedding is judged through similarity measurement, so as to classify the real-time network traffic, thereby realizing faster, more accurate and intelligent threat detection for the DCS network. In addition, the regularization regression method is adopted to screen out a small number of relatively important input features from a large number of features included in the dataset, so as to avoid hindering the model performance and causing overfitting.
[0047] The basic principles of the present disclosure have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, advantages, effects, etc. mentioned in the present disclosure are only examples and not limitations, and it cannot be considered that these advantages, advantages, effects, etc. are essential for each embodiment of the present disclosure. In addition, the above-mentioned specific details are only for the purpose of illustration and easy understanding, rather than limitations, and the above details do not limit the present disclosure to necessarily adopt the above specific details to implement.
[0048] Each embodiment in this specification is described in a progressive manner, and the key point of each embodiment is the difference from other embodiments. The same or similar parts between each embodiment can be referred to each other. For the system embodiment, since it basically corresponds to the method embodiment, the description is relatively simple, and the relevant parts can refer to the partial description of the method embodiment.
[0049] The block diagrams of the devices, apparatuses, equipment, and systems involved in this disclosure are only illustrative examples and are not intended to require or imply that they must be connected, arranged, and configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, equipment, and systems can be connected, arranged, and configured in any way. Words such as "including," "comprising," "having," etc. are open-ended terms, meaning "including but not limited to," and can be used interchangeably with each other. The words "or" and "and" used herein refer to the phrase "and / or" and can be used interchangeably with it, unless the context clearly indicates otherwise. The word "such as" used herein refers to the phrase "such as but not limited to" and can be used interchangeably with it.
[0050] The methods and apparatuses of this disclosure can be implemented in many ways. For example, the methods and apparatuses of this disclosure can be implemented by software, hardware, firmware, or any combination of software, hardware, and firmware. The above order of the steps for the methods is for illustration purposes only, and the steps of the methods of this disclosure are not limited to the specific order described above, unless otherwise specifically stated. In addition, in some embodiments, this disclosure can also be implemented as a program recorded on a recording medium, and these programs include machine-readable instructions for implementing the methods according to this disclosure. Therefore, this disclosure also covers the recording medium storing the programs for executing the methods according to this disclosure.
[0051] It should also be noted that in the apparatuses, equipment, and methods of this disclosure, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent solutions of this disclosure. The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use this disclosure. Various modifications to these aspects are very obvious to those skilled in the art, and the general principles defined herein can be applied to other aspects without departing from the scope of this disclosure. Therefore, this disclosure is not intended to be limited to the aspects shown herein, but rather to the broadest scope consistent with the principles and novel features disclosed herein.
[0052] The above description has been given for purposes of illustration and description. In addition, this description is not intended to limit the embodiments of this disclosure to the forms disclosed herein. Although multiple example aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, changes, additions, and sub-combinations thereof.
Claims
1. A network security threat detection method based on a large model, characterized in that: include: S1: obtaining a network traffic data set as a training set, and performing data processing on the training set, wherein the data processing includes sorting the input features in the training set using a principal component regression or partial least squares regression method to evaluate feature importance, and selecting a preset number of features as input parameters; S2: The features selected in the above step are used as input parameters and passed into the embedding generation function to generate embeddings. The embedding generation function uses the embedding API of the large model to convert the network features into embeddings, that is, to generate a set of vectors of fixed dimension size; S3: storing the embeddings generated in the above steps into a vector database, and marking the embeddings as safe category embeddings or malicious category embeddings; S4: obtaining the real-time network traffic in the distributed control system DCS, and performing the same data processing as in step S1 on the real-time network traffic, so as to select a preset number of features corresponding to the real-time network traffic as input parameters; S5: Take the features selected in the above step as input and pass them into the embedding generation function to generate embedding; S6: judging whether the embedding is sufficiently similar to any embedding stored in the vector database by a similarity metric; S7: Classify the real-time network traffic based on the judgment results in the above steps to achieve network threat detection.
2. The method according to claim 1, characterized in that A network traffic dataset created by generating realistic attacks in the DCS system is used.
3. The method according to claim 2, characterized in that The attacks in the network traffic dataset are divided into 8 categories: distributed denial of service attacks (DDoS), malware attacks, SQL injection attacks, packet sniffing attacks, advanced persistent threats (APT), zero-day attacks (0day), tampered messages, and forged messages.
4. The method according to claim 1, characterized in that: The preset number of features is 7 features, including: the time difference with the previous data packet, the minimum length of the data packet in the stream, the maximum length of the data packet in the stream, the average length of the data packet in the stream, the sum of the lengths of the data packets in the stream, the number of data packets with the RST flag set in the same stream, and the length of the header.
5. The method according to claim 1, characterized in that The large model is OpenAI's GPT4.
0.
6. The method according to claim 1, characterized in that The vector database is an open source search similarity vector database.
7. The method according to claim 1, characterized in that The similarity measure includes measuring the distance between two vectors; for two vectors P={P1,P2,...,P n } and Q={Q1,Q2,...,Q n }, use the following method to measure the distance between two vectors: 。 8. A network security threat detection device based on a large model, characterized in that: include: The first acquisition and processing module is used to acquire a network traffic data set as a training set and perform data processing on the training set, wherein the data processing includes sorting the input features in the training set using a principal component regression or partial least squares regression method to evaluate the importance of the features and selecting a preset number of features as input parameters; A first embedding generation module, used to pass the features selected by the first acquisition and processing module as input parameters to the embedding generation function to generate an embedding, wherein the embedding generation function uses the embedding API of the large model to convert the network features into embeddings, that is, to generate a set of vectors of fixed dimension size; An embedding storage and marking module, configured to store the embeddings generated by the first embedding generation module in a vector database, and mark the embeddings as safe category embeddings or malicious category embeddings; The second acquisition and processing module is used to acquire the real-time network traffic in the distributed control system DCS, and perform the same data processing on the real-time network traffic as in the first acquisition and processing module, so as to select a preset number of features corresponding to the real-time network traffic as input parameters; A second embedding generation module is used to take the features selected by the second acquisition and processing module as input and also pass them into the embedding generation function to generate an embedding; a similarity measurement module, configured to determine whether the embedding is sufficiently similar to any embedding stored in the vector database by means of a similarity measurement; A classification module is used to classify the real-time network traffic based on the judgment result, so as to realize network threat detection.
9. An electronic device, characterized in that: The electronic device comprises: a memory and a processor, wherein the memory and the processor are coupled; the memory stores program instructions, and when the program instructions are executed by the processor, the electronic device executes the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The method comprises a computer program, which, when executed on an electronic device, enables the electronic device to execute the method according to any one of claims 1 to 7.