Implementation method of security Agent system oriented to operating system
By deploying a security agent system in the operating system, using multi-task learning and large language models for threat analysis and policy adjustment, the problem that traditional security protection mechanisms are difficult to deal with complex threats is solved, and higher security detection accuracy and adaptive protection capabilities are achieved.
Patent Information
- Application Number
- CN202510654363.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-21
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2045-05-21
AI Technical Summary
Traditional operating system security protection mechanisms are difficult to deal with advanced persistent threats and zero-day attacks, and show limited capabilities when facing complex threat scenarios.
By deploying an operating system-oriented security agent system in the operating system, the system includes local agents and security knowledge bases, and using the multi-task learning help model and RAG large language model, it realizes the perception of operating system resources, threat analysis and dynamic adjustment of security policies.
It improves security detection accuracy and adaptability, can monitor operating system status in real time, identify complex attack modes, and dynamically adjust security policies based on threat events to achieve adaptive protection.
Abstract
Description
Technical Field
[0001] The present invention relates to the field of operating system security, and particularly to a method for implementing a security Agent system for an operating system. Background Art
[0002] In modern operating systems, with the rapid development of technology, the complexity and diversity of security threats have increased significantly. Traditional security monitoring and protection mechanisms have become difficult to cope with increasingly complex attack methods and changing threat scenarios. Therefore, the security protection of operating systems urgently needs more intelligent and automated solutions to ensure the robustness and security of the system.
[0003] Traditional operating system security protection mechanisms are usually based on static rules and predefined protection policies. Although such methods can cope with conventional known threats, they often show relatively limited capabilities when facing advanced persistent threats and zero-day attacks. Especially in the current network environment, attackers often bypass traditional protection means to perform malicious activities, such as disguising as legitimate operations through specific malicious behavior patterns, or obtaining critical permissions of the system through means such as social engineering, and then further carrying out data theft or destruction operations. Therefore, the intelligence of the operating system security center has become the key to coping with these complex threats.
[0004] In recent years, the rise of large language model technology has brought new opportunities for the intelligent development of security systems. Large language models can realize the analysis of threat intelligence, the identification of abnormal behaviors, and the decision-making ability of real-time response through deep learning of a large amount of security data. The security system based on large language models can automatically learn the behavior patterns of attackers through comprehensive analysis of multi-source data, and then identify potential threats faster and more accurately, and take corresponding protection measures.
[0005] The local Agent, as the core component of the operating system security center, is responsible for the collection, analysis, and preliminary response of security data. Traditional local Agents often rely on rule engines and static signature libraries, and their detection effects often depend on the update speed of the known threat library. However, with the development of attack technologies, attackers can attack by circumventing signature detection technologies or exploiting system vulnerabilities. Therefore, it has become an inevitable trend to adopt a more intelligent local Agent system. Summary of the Invention
[0006] To solve the above problems, the object of the present invention is to provide a method for implementing a security Agent system for an operating system. Through the local Agent, higher security detection accuracy and wider adaptability can be achieved, and the local Agent can also cooperate with the cloud Agent for protection.
[0007] Implementation method of a security Agent system for operating systems, the security Agent system includes a local Agent and a security knowledge base; the local Agent has a multi-task learning assistance model; The implementation method includes the following steps: Step S1: Initialize the local Agent and mount the security knowledge base; the security knowledge base is constructed by combining the RAG large language model and the knowledge graph; Step S2: The local Agent loads the multi-task learning assistance model, enabling the local Agent to have the ability to generate and adjust security policies; Step S3: The local Agent perceives and monitors the resources of the operating system and collects the resource data of the operating system; Step S4: The local Agent calls the RAG large language model to preliminarily analyze the security status of the operating system based on the resource data to determine whether there is a threat event; if there is a threat event, further analyze to obtain the analysis result of the threat event; Step S5: The local Agent generates and adjusts security policies based on the analysis result of the threat event and the load situation of the operating system through the multi-task learning assistance model.
[0008] A further improvement of the present invention lies in that the process of combining the security knowledge base with the knowledge graph and the RAG large language model is as follows: Step S101, entity recognition: Extract entities in the security field from security data; the entities include attackers, target systems, attack methods, vulnerability types, and mitigation measures; each entity is assigned a unique identifier; the security data includes security-related text data, threat intelligence, event logs, and intrusion detection rules; Step S102, relationship extraction: Analyze the relationships between entities in the security data, extract the interconnections between entities, and construct a knowledge graph based on this; the relationships between entities are abstracted as the interconnections between entity nodes and adjacent entity nodes in the knowledge graph; Step S103: Generate a vector representation with neighborhood information based on the constructed knowledge graph neighborhood expansion, and input the vector representation into the RAG large language model, so that the RAG large language model has the ability to match the context when calling the security knowledge base for retrieval and parsing.
[0009] A further improvement of the present invention lies in that the construction process of the multi-task learning assistance model is as follows: Step S201: Determine multiple tasks to be solved by the multi-task learning assistance model; The multi-task learning assistance model is used to solve multiple tasks related to threat events; the multiple tasks are classification tasks, regression tasks, and generation tasks; the classification task classifies threat events to determine threat categories and threat levels; the regression task performs threat risk scoring on threat events; the generation task determines and generates corresponding security policies based on the threat risk score. Step S202: Prepare a data set based on the multiple tasks to be solved; the data set includes a classification data set, a regression data set, and a generation data set. Step S203: Construct the architecture of the basic pre-trained model. The basic pre-trained model includes a shared layer and task-specific layers; the task-specific layers include a classification task output layer, a regression task output layer, and a generation task output layer; the shared layer has multiple layers, and the shared layer is used to extract general features of threat events; the classification task output layer uses a softmax layer to classify threat events and judge threat categories and threat levels; the regression task output layer uses a linear layer to output threat risk scores; the generation task output layer uses a decoder layer to generate security policies. Step S204: Input the data set into the basic pre-trained model for training to obtain the multi-task learning assistance model.
[0010] A further improvement of the present invention is that step S4 includes the following steps: Step S41, data cleaning and standardization: Perform data cleaning and standardization processing on the collected resource data of the operating system. Step S42, the local Agent calls the RAG large language model to perform a preliminary analysis on the resource data of the operating system that has completed data cleaning and standardization, and detects whether there are threat events in the form of detection tasks. Step S43, if there are threat events, the local Agent divides the detection tasks into multiple subtasks to further analyze the threat events and obtains the analysis results of the multiple subtasks. Step S44, based on the analysis results of the multiple subtasks, the local Agent obtains the analysis results of the threat events.
[0011] A further improvement of the present invention is that the subtasks include abnormal network traffic analysis, system vulnerability repair suggestion generation, and threat tracing. Abnormal network traffic analysis: The local Agent analyzes whether there is continuous malicious traffic or DDoS attacks in the threat event. System vulnerability repair suggestion generation: If the threat event is a vulnerability, the local Agent checks the vulnerability and generates preliminary repair suggestions. Threat tracing: The local Agent traces the origin and propagation path of the threat event.
[0012] A further improvement of the present invention lies in that, in step S5, the local Agent calculates the threat risk score of the threat event through multi-task learning assistance model according to the analysis result of the threat event and the load condition of the operating system, and selects and adjusts the security policy according to the threat risk score of the threat event; The threat risk score of the threat event is based on the dynamic response algorithm to evaluate the risk value of the threat event; the risk value corresponds to a high-risk threat or a low-risk threat; if the risk value of the threat event corresponds to a high-risk threat, the security policy adopted is traffic filtering or intrusion detection; if the risk value of the threat event corresponds to a low-risk threat, the security policy adopted is alarm notification or log monitoring.
[0013] A further improvement of the present invention lies in that the calculation formula of the threat risk score is as follows: Threat risk score = a · threat level score + b · impact factor score + c · system load score; Wherein, a is the weight factor of the threat level score, b is the weight factor of the impact factor score, and c is the weight factor of the system load score; the threat level score is determined based on the threat category and threat level of the threat event; the impact factor score is determined based on the potential impact of the threat event on the system resources and services of the operating system; the system load score is determined based on the current load condition of the operating system; The dynamic response algorithm means setting a risk score threshold for distinguishing the risk value of the threat event. If the threat risk score of the threat event is greater than the risk score threshold, the risk value of the threat event corresponds to a high-risk threat; if the threat risk score of the threat event is less than or equal to the risk score threshold, the risk value of the threat event corresponds to a low-risk threat.
[0014] A further improvement of the present invention lies in that the security Agent system further includes a cloud Agent; In step S5, if the local Agent determines that the threat event cannot be processed, the local Agent will request the cloud Agent to assist in the analysis; The specific steps for the cloud Agent to assist in the analysis are as follows: Threat data upload: The local Agent uploads the data related to the threat event to the cloud Agent, and the cloud Agent performs format standardization processing on the uploaded data related to the threat event; Cloud Agent analysis: The cloud Agent analyzes the data related to the threat event after format standardization processing through distributed computing resources; Feedback cloud threat report: After the cloud Agent completes the analysis, the cloud Agent generates a cloud threat report and feeds the cloud threat report back to the local Agent.
[0015] A further improvement of the present invention lies in that it further includes step S6; step S6: The local Agent generates a security status summary report, which records the security status of the operating system and threat events.
[0016] Advantages of the present invention: The local Agent empowered by the large language model in the present invention can achieve higher security detection accuracy and broader adaptability. The local Agent can not only monitor the running status of the operating system in real time, but also perform intelligent analysis on abnormal behaviors to determine whether the operating system is under attack or in an abnormal state. In addition, the local Agent can dynamically adjust security policies according to the operating conditions of the operating system to achieve adaptive protection. At the same time, the local Agent can also form a linkage with other components in the security center to build a closed-loop security protection system covering monitoring, detection, decision-making, and response, so as to achieve all-round protection of the operating system security. Specific implementation manners
[0017] Next, in combination with the embodiments of the present invention, the technical solutions in the embodiments of the present invention will be described clearly and completely. Many specific details are set forth in the following description in order to fully understand the present invention, but the present invention can also be implemented in other ways different from those described herein. Those skilled in the art can make similar promotions without departing from the connotation of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.
[0018] The present invention proposes a method for implementing a security Agent system for an operating system. By deploying an intelligent local Agent inside the operating system, the running status of the operating system is monitored in real time and security analysis is performed. The local Agent uses large language model technology to perform in-depth learning and parsing on data such as system logs and operation behaviors, and can identify complex attack patterns, especially zero-day attacks and advanced persistent threats, greatly improving the accuracy of detection. The security Agent system can automatically adjust security policies according to the real-time analysis results to ensure effective security responses under different threat events. In addition, the local Agent has an adaptive ability and can intelligently coordinate the computing resources of the cloud Agent for collaborative protection according to the task complexity, urgency, and local computing power conditions, ensuring that the security detection task can still be efficiently completed in a resource-constrained environment.
[0019] Through the cooperation of the local Agent and the cloud Agent, the present invention constructs a closed-loop security protection system covering monitoring, detection, and response. The security Agent system can not only cope with traditional known threats but also has the ability to automatically learn and adapt to new types of attacks, thus realizing all-round intelligent security protection for the operating system. The security Agent system ensures that in the face of complex attacks, it can make full use of local resources and rely on the support of the cloud Agent through a dynamic task allocation and resource management mechanism, ensuring the stable and secure operation of the operating system in a high-threat environment.
[0020] The security Agent system includes a local Agent, a security knowledge base, and a cloud Agent. The local Agent has a multi-task learning assistance model. The local Agent has multiple modules.
[0021] A method for implementing a security Agent system for an operating system according to the present invention includes the following steps: Step S1: Initialize the local Agent and mount the security knowledge base to enable it to have the ability to analyze various threat events, their attack patterns, and common vulnerabilities.
[0022] The security knowledge base is constructed by combining the RAG large language model and the knowledge graph, which can achieve more accurate context understanding and reasoning capabilities. The security knowledge base combines the entity relationship information in the knowledge graph with the generation and retrieval capabilities of the RAG large language model. By constructing a knowledge graph in the security domain and introducing the entity relationships in the knowledge graph during querying, in-depth semantic understanding and dynamic context matching are achieved.
[0023] The specific process is as follows: Step S101, entity recognition: Extract the core entities in the security domain from security data. The security data is text data related to security, threat intelligence, event logs, intrusion detection rules, etc. Entities include attackers, target systems, attack methods, vulnerability types, mitigation measures, etc. Each entity is assigned a unique identifier for easy tracking and association.
[0024] Step S102, relationship extraction: Analyze the relationships between entities in the security data, extract the mutual connections between entities, and construct a knowledge graph based on this. The relationships between entities are abstracted as the mutual connections between entity nodes and adjacent entity nodes in the knowledge graph.
[0025] The relationships between entities include: Belong to: A certain attack method belongs to a certain attack type.
[0026] Contain: A certain vulnerability contains multiple mitigation measures.
[0027] Dependency: A certain operating system depends on a specific security configuration.
[0028] Impact: The impact of a certain attack method on the security of the target operating system.
[0029] Step S103: Generate a vector representation with neighborhood information based on the neighborhood expansion of the knowledge graph, and input the vector representation into the retrieval module of the RAG large language model, enabling the retrieval module to perform precise context matching capabilities when retrieving and analyzing the security knowledge base.
[0030] Through the neighborhood expansion of the knowledge graph, the entity node corresponding to the query entity and its adjacent entity nodes (neighbor nodes) can be represented as a vector representation of a context subgraph, enabling the retrieval module of the RAG large language model to have broader context matching and generation capabilities.
[0031] Assume that the query entity node v has N neighbor nodes in the knowledge graph. The following formula is used to generate the vector representation of the context subgraph of the entity node v: ; E context represents the vector representation of the context subgraph of the query entity; E v represents the vector representation of the query entity node v; represents the vector representation of the i-th neighbor node; represents the graph distance between the query entity node v and its neighbor nodes (such as the number of hops or edge weights in the knowledge graph), which is used to measure the relevance of the neighbor nodes to the query entity node v.
[0032] α and β are balance factors used to control the weights of the query entity node v and its adjacent entity nodes (neighbor nodes), generating a vector representation E context , and this vector representation E context not only contains the basic information of the query entity but also introduces a broader context through the influence of the neighbor nodes. This vector representation E context is input into the retrieval module of the RAG large language model for more precise context matching, thereby significantly enhancing the semantic relevance of the retrieval.
[0033] The vector representation E contextAfter entering the retrieval module of the RAG large language model, the RAG large language model also needs to perform retrieval through a multi-path expansion algorithm (search algorithm). The multi-path expansion algorithm is guided by a knowledge graph and is an information retrieval algorithm with the ability to associate context information. The multi-path expansion algorithm can search for context information spanning multiple entity nodes, integrate this information into the context subgraph, and combine to generate a context vector representation of multi-layer paths. The context vector representation of multi-layer paths is passed into the generation module of the RAG large language model to meet the requirements of querying complex contexts.
[0034] Suppose we query a set of multi-level context paths related to an entity node v in the knowledge graph. The steps of the multi-path expansion algorithm are as follows: 1. Initialization: Set the maximum expansion depth k and initialize the set of entity nodes of the path , that is, starting from the queried entity node v.
[0035] 2. Iterative expansion: For each entity node at the i-th layer, search for all entity nodes adjacent to the entity node u and add them to the set P i+1 , and at the same time record the path information from the queried entity node v to the entity node u.
[0036] 3. Path selection: Filter all paths reaching the terminating entity nodes, and retain the set P k of the most relevant paths according to indicators such as edge weights, path lengths, or node importance scores in the knowledge graph.
[0037] 4. Path embedding: Convert the entity nodes and relationships on the path into vector representations, and combine them into a context representation of multi-layer paths as the input to the generation module of the RAG large language model.
[0038] 5. The final context vector representation of multi-layer paths is generated through the following formula: ; Where: E path : The context vector representation of the queried multi-layer paths.
[0039] P j : The set of path nodes at the j-th layer.
[0040] γ j : The layer weight factor, used to adjust the influence of different layers (usually gradually decreasing as the number of layers increases).
[0041] Step S2: The local Agent loads the multi-task learning assistance model to enable the local Agent to have the ability to generate and adjust security policies.
[0042] In the design of the local Agent, the core capabilities rely on multi-task learning to assist in the multi-dimensional fine-tuning of the model, especially in collaborative optimization for key tasks such as threat category, severity assessment (threat level), and security policy generation. Multi-task fine-tuning enables the local Agent to respond quickly and accurately in various complex security scenarios, achieving dynamic security policy adjustment and real-time protection.
[0043] The process of constructing the multi-task learning assistance model is as follows: Step S201: Determine the tasks to be solved by the multi-task learning assistance model; To enhance the local Agent's global understanding in the security field, the multi-task learning assistance model simultaneously solves multiple security-related tasks. These tasks are not only interrelated but also share features, thereby improving the multi-task learning assistance model's ability to respond to threat events. The following are several main tasks: Classification task: This task is used to classify threat events, including threat categories (such as DDoS, malware, data leakage, etc.) and threat levels (such as high, medium, low). Therefore, the purpose of the classification task is to help the multi-task learning assistance model identify the threat category and threat level of threat events, and then make priority rankings in the response plan.
[0044] Regression task: The regression task is mainly used to predict the numerical indicators of threat events, such as threat risk scores. Through the regression prediction of the regression task, the multi-task learning assistance model can assign a risk score (threat risk score) to each threat event, further helping the local Agent evaluate the severity of threat events.
[0045] Generation task: The generation task allows the multi-task learning assistance model to generate recommended response strategies based on the threat category and severity of threat events. These strategies may include specific measures such as isolating the target system, blocking malicious access, and performing virus scans. The generation task enables the local Agent to provide flexible and targeted security policies for each threat event.
[0046] Step S202: Prepare the corresponding data sets based on the multiple tasks to be solved.
[0047] To support multi-task learning, it is necessary to prepare a dedicated data set for each task, enabling the multi-task learning assistance model to share information between different tasks and perform efficient training. The data sets include classification data sets, regression data sets, and generation data sets.
[0048] The classification data set includes the "threat category" and "threat level" labels for each sample (threat event), helping the multi-task learning assistance model judge the threat category and threat level of threat events.
[0049] Regression dataset: Records the threat risk scores for each threat event (e.g., calculated based on attack type, scope of impact, etc.), providing quantitative threat assessment for the multi-task learning assistance model.
[0050] Generation dataset: Includes security policies recommended for specific threat categories, threat levels, and threat risk scores. The security policies in this dataset can be described in natural language to train the multi-task learning assistance model to generate specific security policies.
[0051] Step S203: Determine the architecture of the base pre-trained model; In multi-task fine-tuning, in addition to the basic underlying, middle, and upper layers, the base pre-trained model also designs a structure of a shared layer and task-specific layers to ensure efficient information sharing among multiple tasks and improve feature extraction capabilities.
[0052] Shared layer: The first few layers of the base pre-trained model (such as Transformer encoder layers) are used to extract general features, which are shared by multiple tasks, enabling each task to benefit from the general features and improving the generalization ability of feature representation.
[0053] Task-specific layers: Based on the shared layer, specialized output layers are designed for each task and optimized according to the requirements of different tasks. The task-specific layers include a classification task output layer, a regression task output layer, and a generation task output layer.
[0054] Classification task output layer: Uses a softmax layer to predict threat events and judge threat categories and threat levels. Threat levels include high, medium, and low.
[0055] Regression task output layer: Uses a linear layer to output the threat risk score for quantitatively evaluating the harm of threat events. The threat risk score is a quantitative value obtained by integrating threat levels, impact factors, and system load.
[0056] Generation task output layer: Uses the decoder layer of Transformer to generate natural language countermeasures and generate specific security policies for threat events.
[0057] Step S204: Input the dataset into the base pre-trained model for training to obtain the multi-task learning assistance model.
[0058] Input the dataset into the basic pre-trained model for training to fine-tune the basic pre-trained model. To improve the efficiency and effect of fine-tuning, the basic pre-trained model adopts the strategy of freezing some layers and training other layers. Specifically, the low-level and shared layers of the basic pre-trained model can be frozen, and the network parameters of the task-related exclusive layers and some middle and high-level layers are focused on training. This strategy helps to retain the general features already learned in the basic pre-trained model while performing adaptive fine-tuning for specific tasks.
[0059] The loss of each task is assigned a weight factor λ according to the different importance of the task. class 、λ reg and λ gen , and these weights control the contribution degree of each task in the final optimization. The task parameter update is carried out through the following formula: ; where: W updated : The updated model parameters; W orig : The original model parameters; η: Learning rate; ▽ W L class 、▽ W L reg 、▽ W L gen : Respectively represent the gradients of the loss functions of the classification task, regression task, and generation task with respect to the model parameters; λ class 、λ reg 、λ gen : Respectively represent the weight factors of the classification task, regression task, and generation task, controlling the contribution of each task to the parameter update.
[0060] Training is completed to obtain a multi-task learning assistance model.
[0061] Step S3: The local Agent perceives and monitors the resources of the operating system, collects and analyzes the resource data of the operating system.
[0062] When the local Agent starts, it calls the system environment perception module to intelligently perceive and monitor the resource status of the operating system. The system environment perception module monitors the resource status based on system events triggering and dynamically adjusts the monitoring strategy based on the dynamic perception algorithm.
[0063] System event-triggered monitoring includes monitoring of file system events and subscription to key system events.
[0064] Monitoring of file system events: For file and disk resources, system event monitoring tools (such as inotify on Linux) are used to monitor changes to files or directories. When a file or directory in the file system changes, relevant events are triggered to initiate subsequent monitoring operations. For example, when a log file changes, it can trigger further monitoring of disk usage or other resource status, without frequently polling the file system, thus avoiding unnecessary performance overhead.
[0065] Subscription to key system events: Dynamically start monitoring by subscribing to key system events (such as excessive CPU or memory load). When the load approaches a preset threshold, relevant monitoring tasks are triggered to provide more timely feedback and response when the load is high. This mechanism can effectively avoid excessive monitoring when the operating system is overburdened and reduce resource waste.
[0066] The local Agent uses a dynamic perception algorithm to dynamically adjust the monitoring strategy according to the resource status of the operating system, reducing the impact on the performance of the operating system and providing timely security responses when needed.
[0067] The dynamic perception algorithm is as follows: Set a usage threshold T threshold , if the usage amount R(t) of a certain resource exceeds the usage threshold T threshold , then trigger monitoring: if R(t) > T threshold , then trigger intensive monitoring Meanwhile, the monitoring frequency f(t) is dynamically adjusted according to the resource usage: ; Where: R(t): The resource status of the operating system at time t.
[0068] T threshold : The set usage threshold for determining whether to trigger monitoring.
[0069] f1: Low-frequency monitoring (when resource usage is low); f2: High-frequency monitoring (when resource usage is high).
[0070] The local Agent can dynamically adjust the monitoring strategy according to the actual resource status, thereby reducing the impact on the performance of the operating system and providing timely security responses when needed.
[0071] In this step, the resource data of the operating system collected includes the system environment data of the operating system, the real-time data of key resources, and system logs. Key resources refer to CPU, memory, disk usage, etc. System environment data refers to basic information such as the hardware configuration of the operating system, network status, running processes, network traffic data, static code files, etc.
[0072] After the local Agent collects the system logs, the system logs can be structured through the log collection framework (Elastic Stack) to obtain structured system logs, so as to improve the efficiency and accuracy of subsequent analysis. System logs include system events, network connections, process behaviors, user login records, etc.
[0073] Step S4: The local Agent makes a preliminary analysis of the security status of the operating system based on the resource data to determine whether there are threat events; if there are threat events, the analysis results of the threat events are further determined.
[0074] Specifically, it includes the following steps: Step S41, data cleaning and standardization: The resource data of the operating system collected is subjected to data cleaning and standardization processing to ensure that its structure is consistent and there is no redundant information. System logs will be formatted to extract key events (such as login failures, abnormal processes, etc.); network traffic data is parsed into a structured data format through traffic analysis tools; static code files are scanned through code scanning tools (SonarQube) to mark potential security vulnerabilities.
[0075] Step S42, the RAG large language model makes a preliminary analysis to determine whether there are threat events. After the data preprocessing is completed, the local Agent calls the RAG large language model to make a preliminary analysis of the resource data of the operating system that has completed data cleaning and standardization. Through historical threat patterns, the RAG large language model detects whether there are threat events (abnormal behaviors, potential malicious activities, security vulnerabilities, etc.) in the operating system in the form of detection tasks. The preliminary analysis helps to screen out preliminary security risks and provide a basis for subsequent response and handling.
[0076] Step S43, if there are threat events, the local Agent calls the task decomposition module to break down the detection task corresponding to the threat event into multiple subtasks for further analysis and confirmation of the threat event.
[0077] According to the type, complexity of the threat and the current state of the operating system, the detection task corresponding to the threat event is broken down into multiple subtasks. The subtasks include: network traffic analysis, generation of system vulnerability repair suggestions, threat tracing, etc.
[0078] The subtask allocation is as follows: Abnormal network traffic analysis: The local agent calls the traffic analysis module to further analyze whether there is continuous malicious traffic or DDoS attacks.
[0079] System vulnerability repair suggestion generation: For detected vulnerabilities, the local agent calls the static code analysis module to deeply check the unrepaired vulnerabilities and generate preliminary repair suggestions.
[0080] Threat tracing: During real-time monitoring, the local agent automatically records the behavior paths of each process, network connection, and key events in the operating system. These behavior path data include process startup and termination records, user access behavior, network request links, and other information. These data are stored in a structured manner so that after detecting abnormal activities or potential threats, the source and propagation path of the threat can be quickly traced.
[0081] The specific process of threat tracing is as follows: Behavior path recording: During the operation of the operating system, the local agent continuously collects and records the behavior path of the operating system and generates detailed operation logs, including file operations, port access, system calls, etc. This process ensures that the execution order and dependency of each operation are completely preserved.
[0082] Source tracing analysis: Once an abnormal activity or threat event is detected, the local agent will call the source tracing module to conduct an in-depth analysis of the previously recorded behavior path. By comparing the behavior paths before and after the threat event, the local agent can restore the attack chain and identify the initial trigger point of the threat, the propagation path, and the affected system components.
[0083] Visualization of threat propagation chain: The local agent will visualize the threat tracing results, showing the attacker's action path and the threat's spread process in the operating system. The tracing results (information) displayed in the chart include not only the attack source and the affected modules, but also the attacker's operation behavior on each node, helping administrators quickly understand the full picture of the threat event.
[0084] After analyzing each subtask, the analysis result of the subtask is obtained.
[0085] Step S44: Based on the analysis results of the subtasks, the local Agent obtains the analysis results of the threat events.
[0086] When resources are scarce or the detection task is too complex, the local Agent evaluates the computing power requirements of the detection task in real time to determine whether to call the computing resources of the cloud Agent. If it is necessary to call the cloud Agent, the local Agent uploads necessary data such as system logs and static code to the cloud Agent, and the large language model of the cloud Agent performs in-depth analysis and vulnerability detection. After the analysis by the large language model of the cloud Agent is completed, targeted patches are automatically generated, and the patch test results and deployment suggestions are fed back to the local Agent.
[0087] Step S5: The local Agent generates and adjusts security policies based on the analysis results of threat events and the load conditions of the operating system through the multi-task learning assistance model.
[0088] The local Agent calculates the threat risk score through the multi-task learning assistance model based on the analysis results of threat events and the load conditions of the operating system, and intelligently selects and adjusts security policies according to the threat risk score. In addition, when the local Agent is unable to handle complex threats, the local Agent will request the cloud Agent to assist in the analysis and adjust the security policies according to the feedback from the cloud Agent.
[0089] In order to reasonably evaluate the risk of threat events and determine appropriate security policies, the local Agent will perform threat risk scoring on each threat event through the multi-task learning assistance model.
[0090] The calculation formula for the threat risk score is as follows: Risk Score=a·Threat Level + b·Impact Factor + c·System Load Risk Score: Threat risk score.
[0091] Threat Level (threat level score): Based on the RAG large language model and analysis results, classify and judge threat events (threat categories: such as DDoS attacks, data breaches, etc.), determine the severity of threat events (threat levels), and assign a threat level score to them. Threat Level reflects the urgency of threat events.
[0092] Impact Factor (impact factor score): Measures the potential impact of threat events on the system resources and services of the operating system, such as whether it will cause network interruptions, data loss, etc. Impact Factor reflects the degree of damage caused by threat events.
[0093] System Load (System Load Score): Evaluate the load situation of the current operating system, avoid executing complex security policies when the resources of the operating system are insufficient, and reduce the impact on the system performance of the operating system. System Load is evaluated by monitoring the usage of resources such as CPU, memory, and network of the operating system.
[0094] a, b, c: Weight factors that control the impact of each factor on the final threat risk score. The weight factors can be adjusted according to the actual situation to balance the roles of different factors.
[0095] After calculating the threat risk score, the local Agent can assign a specific risk value to each threat event and select the most appropriate security policy based on this.
[0096] The risk value corresponds to a high-risk threat or a low-risk threat, which is implemented based on a dynamic response algorithm.
[0097] The dynamic response algorithm refers to a set risk score threshold used to distinguish whether the risk value of a threat event is a high-risk threat or a low-risk threat. The dynamic response algorithm is as follows: If Risk Score > T threshold , then Trigger High-Level Defense Strategy If Risk Score≤T threshold , then Trigger Low-Level Defense Strategy T threshold : Risk score threshold; High-Level Defense Strategy: Security policy for high-risk threats; Low-Level Defense Strategy: Security policy for low-risk threats.
[0098] If the threat risk score is greater than the risk score threshold, the risk value of the threat event corresponds to a high-risk threat, and the security policy for high-risk threats is adopted; if the threat risk score is less than or equal to the risk score threshold, the risk value of the threat event corresponds to a low-risk threat, and the security policy for low-risk threats is adopted.
[0099] The specific security policies are as follows: Security policy for high-risk threats: (such as a severe DDoS attack) Trigger more complex and timely protection policies, such as traffic filtering, IP blocking, etc.
[0100] Security policies for low-risk threats (such as minor system configuration errors) only require triggering alerts or performing lightweight resource checks.
[0101] For example: a: The classification task identifies the threat as "DDoS attack" (threat category) and "high" level (threat level).
[0102] b. The regression task calculates its threat risk score Risk Score = 85 (assuming the risk score threshold is 80).
[0103] c. The dynamic response algorithm determines the risk value as a high-risk threat (85>80).
[0104] d. Generate task output security policy: "Start traffic filtering and request cloud agent assistance".
[0105] Step S6: The local agent generates a security status summary report, which records the security status and threat events of the operating system. The security status summary report is based on the natural language generation function of the RAG large language model, and concisely describes the detected threat events, possible impact scope, and recommended security policies. The security status summary report displays threat tracing information in the form of visual charts to help administrators quickly understand the overall picture of threat events, and is stored in the security center for review.
[0106] The local agent helps the model calculate the threat risk score through multi-task learning based on the threat events and the load of the operating system, and intelligently selects and adjusts the security policy based on the threat risk score. In addition, when the local agent cannot cope with complex threats, the local agent will request the cloud agent to assist in analysis and adjust the security policy based on the feedback from the cloud agent.
[0107] When the local agent finds that some complex threats cannot be handled alone, the local agent will request the assistance of the cloud agent through the security agent. The cloud agent uses its powerful computing power to conduct in-depth analysis of the uploaded threat data and identify complex attacks such as advanced persistent threats (APT) or cross-system attacks.
[0108] The processing flow of the cloud agent is as follows: Threat data upload: The local agent uploads relevant threat data (such as log fragments, abnormal network traffic, suspicious code files, etc.) to the cloud agent. The format of these threat data will be standardized so that the cloud agent can process them quickly.
[0109] Cloud Agent Analysis: The large language model of the Cloud Agent efficiently analyzes data through distributed computing resources to identify the complexity of threats and the attack chain. The powerful computing ability of the Cloud Agent enables it to process a large amount of data and perform deep learning to discover attack patterns that cannot be identified by local Agent detection methods.
[0110] The specific process of Cloud Agent analysis is as follows: 1. Advanced Threat Detection: By integrating data from multiple systems, the Cloud Agent can identify distributed attacks and advanced persistent threats (APTs). This step identifies potential attackers, attack methods, and their correlations with other events through multi-level in-depth analysis.
[0111] 2. Threat Chain Analysis: Combining with the global threat database, the Cloud Agent can identify the attack patterns, attack paths, and propagation chains of attackers. This provides rich context information for generating targeted security policies and helps local Agents understand the overall situation of the attack.
[0112] 3. Feedback of Cloud Threat Report: After the analysis is completed, the Cloud Agent generates a detailed Cloud Threat Report, which contains information such as the attack chain, threat level, techniques that the attacker may use, and its potential impact on the operating system. After the Cloud Threat Report is fed back to the local Agent, the local Agent can adjust the security policy based on the analysis results of the Cloud Agent.
[0113] Local security policy adjustment means that based on the Cloud Threat Report of the Cloud Agent, the local Agent can automatically adjust the security policy. For example: Firewall Rule Update: Reconfigure the firewall according to the cloud analysis results to restrict suspicious network access.
[0114] Isolate Infected Nodes: If the Cloud Agent analysis finds that some nodes are under attack, isolation operations can be triggered to prevent the threat from spreading.
[0115] Operating System Security Policy Update: According to the suggestions provided by the Cloud Agent, the local Agent can update the security policy of the operating system to improve the protection ability.
[0116] Advantages of the present invention: 1. Real-time monitoring and global perception capabilities: In this invention, the operating system security center is upgraded to a local Agent, enabling it to monitor the security status of the operating system in real time and perform global perception. Compared with traditional static rule systems, the local Agent can dynamically analyze the system environment, identify potential threats, and make intelligent decisions. This real-time perception capability allows the operating system to proactively respond to threats and achieve proactive protection.
[0117] 2. Intelligent decision-making and task coordination: This invention can not only automatically identify complex attack patterns but also flexibly coordinate the computing capabilities of local and cloud large models according to the complexity, urgency, and local computing power conditions of tasks. As a result, the resource utilization efficiency of the operating system is greatly improved, enabling high-complexity threat detection and security protection tasks to be completed through the intelligent supplementation of cloud resources even in local environments with limited resources.
[0118] 3. Efficient threat detection and response mechanism: The local Agent can automatically learn new threat patterns, getting rid of the traditional mode that relies on manual rule updates. The security Agent system has an adaptive threat detection and response mechanism that can quickly identify and handle advanced threats, improving the accuracy and speed of detection. In addition, through cooperation with the cloud Agent, this invention can handle more diverse threat types, thus strengthening the comprehensive protection of the operating system security.
[0119] 4. Dynamic local and cloud resource collaboration: The limitation of local computing power in the prior art is one of the bottlenecks of the threat detection system. This invention breaks this limitation by intelligently coordinating the capabilities of local and cloud large models. When local resources are insufficient, the security Agent system can automatically transfer complex tasks to the cloud Agent for processing, ensuring that the operating system can still maintain strong security detection and protection capabilities under high load.
[0120] The above are only the preferred embodiments of the present invention. The protection scope of the present invention is not limited to the above embodiments. All technical solutions falling within the concept of the present invention belong to the protection scope of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements should also be regarded as within the protection scope of the present invention.
Claims
1. A method for implementing a secure Agent system for an operating system, characterized in that: The security agent system includes a local agent and a security knowledge base; the local agent has a multi-task learning assistance model; The implementation method includes the following steps: Step S1: Initialize the local Agent and mount the security knowledge base; the security knowledge base is constructed by combining the RAG large language model and the knowledge graph; Step S2: The local agent loads the multi-task learning assistance model, so that the local agent has the ability to generate and adjust security policies; Step S3: The local agent senses and monitors the resources of the operating system and collects resource data of the operating system; Step S4: The local Agent calls the RAG large language model to perform a preliminary analysis on the security status of the operating system based on the resource data to determine whether there is a threat event; if there is a threat event, further analysis is performed to obtain the analysis result of the threat event; Step S5: The local agent helps the model generate and adjust security policies through multi-task learning based on the analysis results of threat events and the load of the operating system.
2. The method for implementing a secure Agent system for an operating system according to claim 1, characterized in that: The process of combining the security knowledge base with the knowledge graph and the RAG large language model is as follows: Step S101, entity identification: extracting entities in the security field from security data; the entities include attackers, target systems, attack methods, vulnerability types, and mitigation measures; each entity is assigned a unique identifier; the security data includes security-related text data, threat intelligence, event logs, and intrusion detection rules; Step S102, relationship extraction: analyzing the relationship between entities in the security data, extracting the mutual connection between entities, and constructing a knowledge graph based on this; the relationship between entities is abstracted in the knowledge graph as the mutual connection between entity nodes and adjacent entity nodes; Step S103: Generate a vector representation with neighborhood information based on the constructed knowledge graph neighborhood expansion, and pass the vector representation into the RAG large language model, so that the RAG large language model has context matching capabilities when calling the security knowledge base for retrieval and analysis.
3. The method for implementing a secure Agent system for an operating system according to claim 1, characterized in that: The construction process of the multi-task learning helper model is as follows: Step S201: Determine multiple tasks that the multi-task learning helps the model to solve; The multi-task learning helps the model to solve multiple tasks related to threat events; the multiple tasks are classification tasks, regression tasks and generation tasks; the classification task classifies threat events and determines threat categories and threat levels; the regression task scores threat risk for threat events; The generation task determines and generates corresponding security policies based on the threat risk score; Step S202: preparing a data set based on the multiple tasks solved; The data sets include classification data sets, regression data sets, and generation data sets; Step S203: constructing the architecture of the basic pre-training model; The basic pre-training model includes a shared layer and a task-specific layer; the task-specific layer includes a classification task output layer, a regression task output layer and a generation task output layer; the shared layer has multiple layers, and the shared layer is used to extract common features of threat events; The classification task output layer uses a softmax layer to classify threat events and determine the threat category and threat level; The output layer of the regression task uses a linear layer to output the threat risk score; The generation task output layer generates a security policy using a decoder layer; Step S204: input the data set into the basic pre-training model for training to obtain a multi-task learning assistance model.
4. The method for implementing a secure Agent system for an operating system according to claim 1, characterized in that: Step S4 includes the following steps: Step S41, data cleaning and standardization: performing data cleaning and standardization processing on the collected resource data of the operating system; Step S42, the local agent calls the RAG large language model to perform preliminary analysis on the resource data of the operating system that has completed data cleaning and standardization, and detects whether there is a threat event in the operating system in the form of a detection task; Step S43, if there is a threat event, the local Agent subdivides the detection task into multiple subtasks to further analyze the threat event and obtain analysis results of the multiple subtasks; Step S44: Based on the analysis results of the multiple subtasks, the local Agent obtains the analysis results of the threat event.
5. The method for implementing a secure Agent system for an operating system according to claim 4, characterized in that: The subtasks include abnormal network traffic analysis, system vulnerability repair suggestion generation, and threat tracing; Abnormal network traffic analysis: The local agent analyzes the threat event to see if there is persistent malicious traffic or DDoS attack; System vulnerability repair suggestion generation: If the threat event is a vulnerability, the local agent checks the vulnerability and generates preliminary repair suggestions; Threat tracing: The local agent tracks the origin and propagation path of threat events.
6. The method for implementing a secure Agent system for an operating system according to claim 1, characterized in that: In step S5, the local agent helps the model calculate the threat risk score of the threat event through multi-task learning based on the analysis results of the threat event and the load of the operating system, and selects and adjusts the security policy based on the threat risk score of the threat event; The threat risk score of a threat event is based on the dynamic response algorithm to assess the risk value of the threat event; The risk value corresponds to a high-risk threat or a low-risk threat; If the risk value of the threat event corresponds to a high-risk threat, the security strategy adopted is traffic filtering or intrusion detection; If the risk value of the threat event corresponds to a low-risk threat, the security strategy adopted is alarm notification or log monitoring.
7. The method for implementing a secure Agent system for an operating system according to claim 6, characterized in that: The calculation formula of the threat risk score is as follows: Threat risk score = a·threat level score + b·impact factor score + c·system load score; Among them, a is the weight factor of the threat level score, b is the weight factor of the impact factor score, and c is the weight factor of the system load score; the threat level score is determined based on the threat category and threat level of the threat event; the impact factor score is determined based on the potential impact of the threat event on the system resources and services of the operating system; the system load score is determined based on the current load of the operating system; The dynamic response algorithm refers to setting a risk score threshold to distinguish the risk value of a threat event. If the threat risk score of a threat event is greater than the risk score threshold, the risk value of the threat event corresponds to a high-risk threat; if the threat risk score of a threat event is less than or equal to the risk score threshold, the risk value of the threat event corresponds to a low-risk threat.
8. The method for implementing a secure Agent system for an operating system according to claim 5, characterized in that: The security agent system also includes a cloud agent; In step S5, if the local agent determines that the threat event cannot be processed, the local agent will request the cloud agent to assist in analysis; The specific steps of cloud agent-assisted analysis are as follows: Threat data upload: The local agent uploads data related to threat events to the cloud agent, and the cloud agent standardizes the format of the uploaded threat event-related data; Cloud Agent Analysis: Cloud Agent uses distributed computing resources to analyze data related to threat events after format standardization. Feedback of cloud threat report: After the cloud agent completes the analysis, the cloud agent generates a cloud threat report and feeds the cloud threat report back to the local agent.
9. The method for implementing a secure Agent system for an operating system according to claim 1, characterized in that: Also includes step S6; Step S6: The local Agent generates a security status summary report, which records the security status and threat events of the operating system.
Citation Information
Patent Citations
Safety prediction system based on multi-Agent technology
CN105629916A
Network security threat perception identification response method based on security knowledge graph
CN119011251A
Open source threat intelligence acquisition method and system based on large language model
CN119474510A
Multi-level information security policy generation method based on knowledge graph
CN119728302A
Method and system for generating and evaluating security policy of network / security equipment based on large language model
CN119996085A
Cited By
An operating system security architecture, method, and system based on an unbypassable review chain.
CN122571679A