Network security processing method, device, equipment, medium and program product based on large language model

Through the generation of large language models and dynamic adjustment of network security emergency response plans, the problem of poor adaptability to network topology changes in the existing technology is solved, and efficient and accurate plan generation and real-time updates are achieved.

CN120110808BActive Publication Date: 2025-09-02ZIGUANG HENGYUE TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510591877.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-09
Publication Date
2025-09-02
Estimated Expiration
2045-05-09

AI Technical Summary

Technical Problem

Existing network security emergency response plan generation tools cannot perceive changes in network topology structure in real time, resulting in disconnection between the plan content and the actual network environment and low adaptability and accuracy.

Method used

The large language model is used to generate initial emergency response plans, and dynamically adjust the plan content to adapt to topological changes and security events by monitoring network topology changes in real time to adapt to topological changes and security events, including security event identification, device isolation, file recovery and security event repair.

Benefits of technology

It improves the efficiency and accuracy of plan generation, can respond to network topology changes and the latest threat situations in real time, and ensures the adaptability and timeliness of the plan.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120110808B_ABST
    Figure CN120110808B_ABST
Patent Text Reader

Abstract

The embodiments of the present application provide a network security processing method, apparatus, device, medium and program product based on a large language model, which relate to the field of network security technology. The method includes: generating an initial emergency response plan for a network topology structure based on an input plan generation request using a large language model; monitoring changes in the network topology structure in real time to generate a first topology change event; adjusting the initial emergency response plan using a large language model to add an emergency response plan for the first topology change event; if a security event is detected, generating a second topology change event; adjusting the initial emergency response plan using a large language model to add an emergency response plan for the second topology change event; and being able to update the plan content according to the changing dynamics of the network topology structure and security events to improve the accuracy and adaptability of the plan.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and more specifically, to a network security processing method, apparatus, device, medium, and program product based on a large language model. Background Art

[0002] Cybersecurity emergency response plans are crucial tools for organizations responding to security incidents like cyberattacks and data breaches. Currently, the generation and updating of cybersecurity emergency response plans primarily rely on the following technical solutions: Manually written plans, where cybersecurity experts manually create emergency response plans based on an organization's network architecture, security policies, and potential threats. Plans typically include incident identification, isolation measures, recovery steps, and post-event analysis; templated plan generation tools, which use predefined templates or frameworks to generate plans, with users filling in the details based on their needs; and automated, rule-based plan generation, which utilizes rule engines or scripting tools to generate plans based on predefined rules.

[0003] Although existing technical solutions have met the needs of cybersecurity emergency response to a certain extent, they still have the following shortcomings:

[0004] Manually writing emergency plans is inefficient and time-consuming, especially in large-scale network environments, making it difficult to quickly generate high-quality plans. Plan content is easily influenced by the author's subjective experience, which may lead to the omission of key steps or details. Templated plans lack flexibility. Templated plan generation tools are usually based on a fixed framework and are difficult to adapt to diverse network environments and attack scenarios. Users need to manually adjust the template content, which increases the complexity of use and the risk of errors. Rule-based automated plan generation has significant limitations. Rule engines or scripting tools rely on predefined rules and are difficult to deal with complex and unknown attack scenarios. Rule updates require manual intervention and cannot respond to the latest threat situations in real time. The adaptability to network topology changes is poor. Existing plan generation tools are usually unable to perceive changes in network topology in real time, resulting in a disconnect between the plan content and the actual network environment. For example, after adding new equipment or adjusting network segments, existing plans may not cover new attack paths. Summary of the Invention

[0005] The purpose of the embodiments of the present application is to provide a network security processing method, device, equipment, medium and program product based on a large language model, so as to solve the problem that existing plan generation tools are usually unable to perceive changes in network topology in real time, resulting in the plan content being out of touch with the actual network environment and low adaptability and accuracy.

[0006] In a first aspect, an embodiment of the present application provides a network security processing method based on a large language model, the method comprising:

[0007] Based on the input plan generation request, a large language model is used to generate an initial emergency response plan for the network topology. The initial emergency response plan includes security incident identification, device isolation measures, file recovery measures, and security incident remediation.

[0008] Monitor changes in the network topology in real time and generate a first topology change event; wherein the first topology change event includes a newly added first device and a connection structure of the first device;

[0009] The initial emergency response plan is adjusted using a large language model to add an emergency response plan for the first topology change event;

[0010] If a security event is detected, a second topology change event is generated; wherein the second topology change event includes the second device where the security event occurs and the connection structure of the second device;

[0011] The initial emergency response plan is adjusted using a large language model to add an emergency response plan for the second topology change event.

[0012] In the above implementation process, based on the input plan generation request, a large language model is used to generate an initial emergency response plan for the network topology structure; wherein, the initial emergency response plan includes security incident identification, device isolation measures, file recovery measures and security incident repair; the changes in the network topology structure are monitored in real time to generate a first topology change event; wherein, the first topology change event includes a newly added first device and the connection structure of the first device; the large language model is used to adjust the initial emergency response plan to add an emergency response plan for the first topology change event; if a security incident is detected, a second topology change event is generated; wherein, the second topology change event includes a second device where the security incident occurs and the connection structure of the second device; the large language model is used to adjust the initial emergency response plan to add an emergency response plan for the second topology change event; the plan content can be updated according to the changing dynamics of the network topology structure and security incidents, thereby improving the accuracy and adaptability of the plan.

[0013] Furthermore, after generating an initial emergency response plan based on the input plan generation request and using a large language model for the network topology structure, the method further includes:

[0014] Securely process the network topology based on the initial emergency response plan.

[0015] During the above implementation process, security processing is performed according to the initial emergency response plan to ensure the security of the network topology.

[0016] Furthermore, the security processing of the network topology structure based on the initial emergency response plan includes:

[0017] If the monitoring tool detects that the files on the third device are encrypted, it is confirmed that the third device is infected by the ransomware;

[0018] Add the IP address of the third device to the firewall blacklist to block its communication with other network devices;

[0019] Restore files affected by encryption from backup files;

[0020] Analyze the ransomware's propagation path and fix security vulnerabilities based on the propagation path.

[0021] During the above implementation process, security processing is performed according to the initial emergency response plan to ensure the security of the network topology.

[0022] Furthermore, the emergency response plan for adding the first topology change event includes:

[0023] The first device and the connection structure of the first device are added to a monitoring list of security events.

[0024] In the above implementation process, the plan is dynamically updated to respond to network topology changes and the latest threats in real time.

[0025] Furthermore, the emergency response plan for adding a second topology change event includes:

[0026] Checking whether a security incident occurs on a connected device of the second device;

[0027] If a security event occurs in the connection device of the second device, performing security processing on the connection device of the second device;

[0028] If there is no security event for the connected device of the second device, the connected device of the second device is added to a monitoring list of security events.

[0029] In the above implementation process, the plan is dynamically updated to respond to network topology changes and the latest threats in real time.

[0030] Furthermore, the plan generation request includes a target scenario and a network environment description.

[0031] In the above implementation process, the emergency plan is automatically generated according to the emergency plan generation request, thereby improving the efficiency of emergency plan generation.

[0032] In a second aspect, an embodiment of the present application further provides a network security processing device based on a large language model, the device comprising:

[0033] The initial generation module is used to generate an initial emergency response plan based on the input plan generation request and the network topology using a large language model. The initial emergency response plan includes security incident identification, device isolation measures, file recovery measures, and security incident remediation.

[0034] A real-time monitoring module, configured to monitor changes in the network topology in real time and generate a first topology change event; wherein the first topology change event includes a newly added first device and a connection structure of the first device;

[0035] A plan adjustment module, configured to adjust the initial emergency response plan using a large language model to add an emergency response plan for the first topology change event;

[0036] A security monitoring module, configured to generate a second topology change event if a security event is detected; wherein the second topology change event includes a second device where the security event occurs and a connection structure of the second device;

[0037] The security adjustment module is used to adjust the initial emergency response plan by using a large language model to add an emergency response plan for a second topology change event.

[0038] In a third aspect, an embodiment of the present application provides an electronic device, including:

[0039] A processor, a memory and a bus, wherein the processor is connected to the memory via the bus, and the memory stores computer-readable instructions. When the computer-readable instructions are executed by the processor, they are used to implement the network security processing method based on the large language model as described above.

[0040] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a server, the network security processing method based on the large language model as described above is implemented.

[0041] In a fifth aspect, an embodiment of the present application provides a computer program product, which includes instructions. When the instructions are executed by a computer, the computer implements the network security processing method based on the large language model as described above. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments of the present application. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without creative work.

[0043] Figure 1 A flowchart of a network security processing method based on a large language model provided in an embodiment of the present application;

[0044] Figure 2 A schematic diagram of a flow chart of a network security processing device based on a large language model provided in an embodiment of the present application;

[0045] Figure 3 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0046] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.

[0047] It should be noted that similar reference numerals and letters represent similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined or explained in subsequent drawings. At the same time, in the description of this application, the terms "first", "second", etc. are only used to distinguish the description and should not be understood as indicating or implying relative importance.

[0048] Please see Figure 1 , Figure 1 A flowchart of a network security processing method based on a large language model provided in an embodiment of the present application. The network security processing method based on a large language model includes:

[0049] 100. Based on the input plan generation request, a large language model is used to generate an initial emergency response plan for the network topology structure; wherein the initial emergency response plan includes security incident identification, device isolation measures, file recovery measures and security incident repair.

[0050] Optionally, the contingency plan generation request includes a target scenario and a description of the network environment. Exemplary target scenarios include ransomware attacks and DDoS attacks. Exemplary contingency plan generation requests include, but are not limited to, network topology details (e.g., connection methods and locations of core switches, firewalls, server clusters, and terminal devices), potential security incident types (e.g., DDoS attacks, ransomware infections, internal data leaks), business criticality (determining which business systems are critical to the organization's operations), and relevant security policies and compliance requirements.

[0051] Optionally, the request for emergency plan generation is input in natural language. The large language model can understand the user's intent and needs and convert them into key information for emergency plan generation. Based on the input network topology and security threat information, the large language model applies predefined emergency plan generation logic and rules, combined with its own reasoning capabilities, to generate an initial emergency response plan.

[0052] For example, security incident identification can involve real-time traffic analysis of key nodes in the network topology (such as core switches and perimeter firewalls), or analysis of log information generated by network devices, servers, and applications. Device isolation measures, for example, involve immediately isolating devices or network areas affected by a security incident within the network topology. File recovery measures include file backup and recovery, data reconstruction, and security incident remediation, including vulnerability repair, malware removal, and security configuration optimization.

[0053] 200. Monitor changes in the network topology in real time and generate a first topology change event; wherein the first topology change event includes a newly added first device and a connection structure of the first device.

[0054] Specifically, the addition, deletion or connection relationship change of devices in the network topology structure is continuously detected; when a change is detected, a first topology change event including the newly added device information and its connection structure is generated.

[0055] Optionally, automatically discover physically connected devices through device discovery protocols and regularly poll device status; regularly scan active devices on the network through network scanning tools and compare them with a list of known devices; analyze source / destination IPs in network traffic to discover potential new connections.

[0056] Optionally, the collected device information (IP, MAC, port) and connection relationship (port-port mapping) are stored as a graph structure (such as a node-edge model); the current topology is compared with the topology at the previous moment, and new devices, deleted devices, or connection changes are marked; a time threshold for device offline / online is set (such as marking it offline if it does not respond within 30 seconds); when a new device is detected, its IP address, MAC address, connection port, and peer device information are recorded.

[0057] 300. Use the large language model to adjust the initial emergency response plan to add an emergency response plan for the first topology change event.

[0058] Specifically, the first device and its connection structure are added to the security event monitoring list. For example, the first device and its connection structure (including its directly connected upstream and downstream devices, etc.) are added to the security event monitoring list. Subsequently, comprehensive security event monitoring will be conducted on this device and its connection structure, including but not limited to network traffic anomalies, unauthorized access attempts, and data leakage risks. For example, when a new device is added, the emergency plan update engine will generate isolation and recovery steps for that device.

[0059] 400. If a security event is detected, generate a second topology change event; wherein the second topology change event includes a second device where the security event occurs and a connection structure of the second device.

[0060] Specifically, when a security incident is detected in the second device and its connection structure, a second topology change event is automatically generated, and the monitoring scope is extended to the second device (i.e., the device that triggered the security incident) and its connection structure, to achieve dynamic tracking of security incidents and risk diffusion analysis.

[0061] Optionally, security events include network attacks (such as DDoS and SQL injection), abnormal traffic (such as port scanning and data leakage), and device anomalies (such as CPU / memory usage surges and service interruptions).

[0062] Among them, the second topology change event is defined as follows: Second device: the device that triggers the security event (such as an attacked server or an infected terminal); Connection structure: the directly connected device of the second device (such as an upstream switch or a downstream client) and the network path.

[0063] 500. Use the large language model to adjust the initial emergency response plan to add an emergency response plan for the second topology change event.

[0064] Specifically, the second device and its connection structure are added to the security event monitoring list. For example, the second device and its connection structure (including its directly connected upstream and downstream devices, etc.) are added to the security event monitoring list. Subsequently, comprehensive security event monitoring will be conducted on the device and its connection structure, including but not limited to network traffic anomalies, illegal access attempts, data leakage risks, etc.

[0065] 510. Check whether a connected device of the second device has a security incident.

[0066] 520. If a security event occurs in the connection device of the second device, perform security processing on the connection device of the second device.

[0067] For example, if an abnormality occurs in the second device or its connection structure, the following operations are triggered: isolating the second device (such as closing a switch port); updating firewall rules to block related traffic; and notifying the security team to conduct in-depth analysis.

[0068] 530. If there is no security event for the connected device of the second device, add the connected device of the second device to a monitoring list of security events.

[0069] Optionally, the updated plan is stored in the plan storage and distribution module and automatically pushed to relevant personnel or systems.

[0070] As described above, the embodiment of the present application uses a large language model to generate an initial emergency response plan for the network topology structure based on the input plan generation request; wherein, the initial emergency response plan includes security incident identification, device isolation measures, file recovery measures and security incident repair; monitors changes in the network topology structure in real time to generate a first topology change event; wherein, the first topology change event includes a newly added first device and the connection structure of the first device; uses a large language model to adjust the initial emergency response plan to add an emergency response plan for the first topology change event; if a security incident is detected, generates a second topology change event; wherein, the second topology change event includes a second device where the security incident occurs and the connection structure of the second device; uses a large language model to adjust the initial emergency response plan to add an emergency response plan for the second topology change event; can update the plan content according to the changing dynamics of the network topology structure and security incidents, and improve the accuracy and adaptability of the plan.

[0071] Based on the above embodiment, the network security processing method based on the large language model of the embodiment of the present application can also be concretized as follows: after generating an initial emergency response plan for the network topology structure using the large language model according to the input plan generation request, it also includes:

[0072] Securely process the network topology based on the initial emergency response plan.

[0073] Specifically, if the monitoring tool detects that the files of the third device are encrypted, it is confirmed that the third device is infected by ransomware; the IP address of the third device is added to the firewall blacklist to block its communication with other network devices; the files affected by the encryption are restored from the backup files; the propagation path of the ransomware is analyzed, and security vulnerabilities are repaired based on the propagation path.

[0074] For example, a company's network environment contains 100 hosts, 5 firewalls and 2 core switches. One day, the security team detected that a host was infected by ransomware, and it was necessary to immediately generate an emergency response plan and dynamically update it. The implementation method of the embodiment of the present application is as follows: 1) Plan generation: User input: The user describes the scenario in natural language, such as "generate an emergency response plan for ransomware attacks, the network contains 100 hosts and 5 firewalls"; the large language model generates plans: Event identification: The EDR tool detects that the files on host A are encrypted and confirms the ransomware infection; Isolation measures: Add the IP address of host A to the firewall blacklist to block its communication with the network; Recovery steps: Restore the files affected by the encryption from the backup to ensure that the backup data is not infected; Post-analysis: Analyze the propagation path of the ransomware and fix related vulnerabilities.

[0075] 2) Network topology monitoring: Network topology perception module: monitors network structure changes in real time and discovers the connection relationship between host A and core switch 1; topology change event: generates the event "host A is connected to core switch 1".

[0076] 3) Dynamic update of the plan: Plan update engine: Call the large language model based on topology change events to adjust the plan content; Add a new step: Check other connected devices of core switch 1 to prevent ransomware from spreading through the switch; Update isolation measures: Add other connected devices of core switch 1 to the monitoring list.

[0077] 4) Plan storage and distribution: The updated plan is stored in the database; the plan is pushed to the security team via email and SIEM system.

[0078] The embodiments of the present application improve the efficiency of plan generation: traditional plan generation relies on manual writing, which is time-consuming and labor-intensive and prone to missing key details. The embodiments of the present application utilize a large language model to quickly generate high-quality, structured plan content, significantly improving the efficiency of plan generation.

[0079] This embodiment enhances the accuracy and applicability of emergency plans: a large language model generates emergency plans based on extensive network security knowledge and best practices, providing more accurate and comprehensive response strategies. Furthermore, a dynamic update mechanism ensures that emergency plans can adapt to changes in network topology and the latest threat landscape in real time.

[0080] This embodiment of the application enables dynamic updates of emergency plans: Traditional emergency plan updates rely on manual intervention and cannot respond to network topology changes and the latest threats in real time. This embodiment of the application uses a network topology perception module and an emergency plan update engine to achieve dynamic updates of emergency plans, ensuring the timeliness and applicability of the plans.

[0081] The above steps are not to be performed in a strict order as described in the numbers, but should be understood as an overall solution.

[0082] In the second aspect, based on the above embodiment, the embodiment of the present application further provides a network security processing device based on a large language model, referring to Figure 2 The network security processing device based on the large language model provided in this embodiment specifically includes: an initial generation module 201, a real-time monitoring module 202, a plan adjustment module 203, a security monitoring module 204 and a security adjustment module 205.

[0083] Among them, the initial generation module 201 is used to generate an initial emergency response plan for the network topology structure based on the input plan generation request using a large language model; wherein, the initial emergency response plan includes security incident identification, device isolation measures, file recovery measures and security incident repair; the real-time monitoring module 202 is used to monitor changes in the network topology structure in real time and generate a first topology change event; wherein, the first topology change event includes a newly added first device and the connection structure of the first device; the plan adjustment module 203 is used to adjust the initial emergency response plan using a large language model to add an emergency response plan for the first topology change event; the security monitoring module 204 is used to generate a second topology change event if a security incident is detected; wherein, the second topology change event includes a second device where the security incident occurs and the connection structure of the second device; the security adjustment module 205 is used to adjust the initial emergency response plan using a large language model to add an emergency response plan for the second topology change event.

[0084] As described above, the embodiment of the present application uses a large language model to generate an initial emergency response plan for the network topology structure based on the input plan generation request; wherein, the initial emergency response plan includes security incident identification, device isolation measures, file recovery measures and security incident repair; monitors changes in the network topology structure in real time to generate a first topology change event; wherein, the first topology change event includes a newly added first device and the connection structure of the first device; uses a large language model to adjust the initial emergency response plan to add an emergency response plan for the first topology change event; if a security incident is detected, generates a second topology change event; wherein, the second topology change event includes a second device where the security incident occurs and the connection structure of the second device; uses a large language model to adjust the initial emergency response plan to add an emergency response plan for the second topology change event; can update the plan content according to the changing dynamics of the network topology structure and security incidents, and improve the accuracy and adaptability of the plan.

[0085] In a third aspect, an embodiment of the present application further provides an electronic device that can integrate the network security processing device based on a large language model and the user-mode polling mechanism provided in an embodiment of the present application. Figure 3 This is a schematic diagram of the structure of an electronic device provided by an embodiment of the present application. Figure 3The electronic device includes: an input device 43, an output device 44, a memory 42, and one or more processors 41; the memory 42 is used to store one or more programs; when the one or more programs are executed by the one or more processors 41, the one or more processors 41 implement the network security processing method based on the large language model of the user-mode polling mechanism provided in the above embodiment. The input device 43, the output device 44, the memory 42, and the processor 41 can be connected by a bus or other means. Figure 3 The bus connection is taken as an example.

[0086] The processor 41 executes various functional applications and data processing of the device by running software programs, instructions and modules stored in the memory 42, that is, implements the network security processing method based on the large language model of the above-mentioned user-mode polling mechanism.

[0087] The electronic device provided above can be used to execute the network security processing method based on the large language model of the user-mode polling mechanism provided in the above embodiment, and has corresponding functions and beneficial effects.

[0088] In a fourth aspect, an embodiment of the present application also provides a computer-readable storage medium, which includes a stored computer program; wherein, when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the network security processing method based on the large language model as described above, and can achieve the same beneficial effects.

[0089] Of course, the storage medium containing computer-executable instructions provided in an embodiment of the present application is not limited to the network security processing method based on the large language model as described above, and can also execute related operations in the network security processing method based on the large language model provided in any embodiment of the present application.

[0090] In a fifth aspect, the embodiments of the present application further provide a computer program product. The methods described in the various embodiments of the present application can be implemented in whole or in part through software, hardware, firmware, or any combination thereof. When implemented using software, they can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the various embodiments of the present application are executed in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, a core network device, an OAM (Open Application Model) or other programmable device.

[0091] The computer program or instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer program or instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired or wireless method. The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium, such as a floppy disk, a hard disk, or a magnetic tape; an optical medium, such as a digital video disk; or a semiconductor medium, such as a solid-state drive. The computer-readable storage medium may be a volatile or non-volatile storage medium, or may include both volatile and non-volatile types of storage media.

[0092] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions and operations of the devices, methods and computer program products according to the multiple embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a part of the code, and the module, program segment or a part of the code contains one or more executable instructions for implementing the specified logical functions. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart, can be implemented using a dedicated hardware-based system that performs the specified function or action, or can be implemented using a combination of dedicated hardware and computer instructions.

[0093] In addition, the functional modules in each embodiment of the present application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0094] If the functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, and other media that can store program code.

[0095] The foregoing is merely an embodiment of the present application and is not intended to limit the scope of protection of the present application. Various modifications and variations are possible for those skilled in the art. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application shall be included within the scope of protection of the present application. It should be noted that similar reference numerals and letters represent similar items in the following figures. Therefore, once an item is defined in one figure, it does not need to be further defined or explained in subsequent figures.

[0096] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.

[0097] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply the existence of any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device comprising the element.

Claims

1. A network security processing method based on a large language model, characterized in that: The method comprises: Based on the input plan generation request, the large language model uses predefined plan generation logic and rules, combined with its own reasoning capabilities, to generate an initial emergency response plan based on the input network topology and security threat information. The initial emergency response plan includes security incident identification, device isolation measures, file recovery measures, and security incident remediation. The plan generation request includes a description of the target scenario and network environment. Monitor changes in the network topology in real time and generate a first topology change event; wherein the first topology change event includes a newly added first device and a connection structure of the first device; The initial emergency response plan is adjusted using a large language model to add an emergency response plan for the first topology change event; If a security event is detected, a second topology change event is generated; wherein the second topology change event includes the second device where the security event occurs and the connection structure of the second device; The initial emergency response plan is adjusted using a large language model to add an emergency response plan for the second topology change event; Automatically discover physically connected devices and regularly poll device status using device discovery protocols; regularly scan active devices on the network using network scanning tools and compare them with a list of known devices; and analyze source / destination IP addresses in network traffic to discover potential new connections. The collected device information and connection relationships are stored as a graph structure, and the current topology is compared with the topology at the previous moment. New devices, deleted devices, or connection changes are marked; time thresholds for device offline / online are set; when a new device is detected, its IP address, MAC address, connection port, and peer device information are recorded.

2. The network security processing method based on a large language model according to claim 1, characterized in that: After generating an initial emergency response plan based on the input plan generation request and using a large language model for the network topology structure, the method further includes: Securely process the network topology based on the initial emergency response plan.

3. The network security processing method based on a large language model according to claim 2, characterized in that: The security processing of the network topology structure based on the initial emergency response plan includes: If the monitoring tool detects that the files on the third device are encrypted, it is confirmed that the third device is infected by ransomware; Add the IP address of the third device to the firewall blacklist to block its communication with other network devices; Restore files affected by encryption from backup files; Analyze the ransomware's propagation path and fix security vulnerabilities based on the propagation path.

4. The network security processing method based on a large language model according to claim 1, characterized in that: The emergency response plan for adding a first topology change event includes: The first device and the connection structure of the first device are added to a monitoring list of security events.

5. The network security processing method based on a large language model according to claim 2, characterized in that: The emergency response plan for adding a second topology change event includes: Checking whether a security incident occurs on a connected device of the second device; If a security event occurs in the connection device of the second device, performing security processing on the connection device of the second device; If there is no security event for the connected device of the second device, the connected device of the second device is added to a monitoring list of security events.

6. The network security processing method based on a large language model according to claim 1, characterized in that: The plan generation request includes a target scenario and a network environment description.

7. A network security processing device based on a large language model, characterized in that: The device comprises: An initial generation module is used to generate a request for a plan based on the input. Based on the input network topology and security threat information, the large language model uses predefined plan generation logic and rules, combined with its own reasoning capabilities, to generate an initial emergency response plan. The initial emergency response plan includes security incident identification, device isolation measures, file recovery measures, and security incident remediation. The plan generation request includes a description of the target scenario and network environment. A real-time monitoring module, configured to monitor changes in the network topology in real time and generate a first topology change event; wherein the first topology change event includes a newly added first device and a connection structure of the first device; A plan adjustment module, configured to adjust the initial emergency response plan using a large language model to add an emergency response plan for the first topology change event; A security monitoring module, configured to generate a second topology change event if a security event is detected; wherein the second topology change event includes a second device where the security event occurs and a connection structure of the second device; A security adjustment module, configured to adjust the initial emergency response plan using a large language model to add an emergency response plan for a second topology change event; Automatically discover physically connected devices and regularly poll device status using device discovery protocols; regularly scan active devices on the network using network scanning tools and compare them with a list of known devices; and analyze source / destination IP addresses in network traffic to discover potential new connections. The collected device information and connection relationships are stored as a graph structure, and the current topology is compared with the topology at the previous moment. New devices, deleted devices, or connection changes are marked; time thresholds for device offline / online are set; when a new device is detected, its IP address, MAC address, connection port, and peer device information are recorded.

8. An electronic device, characterized in that: include: A processor, a memory, and a bus, wherein the processor is connected to the memory via the bus, and the memory stores computer-readable instructions. When the computer-readable instructions are executed by the processor, they are used to implement the network security processing method based on a large language model as described in any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which, when executed by a server, implements the network security processing method based on a large language model as described in any one of claims 1 to 6.

10. A computer program product, characterized in that The computer program product comprises instructions which, when executed by a computer, cause the computer to implement the method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Method for realizing security arrangement automation and response based on large language model

    CN117828602A