Security report generation system and method, medium, electronic device and program product

Through the collaboration of multi-agent subsystem, data engine module and report generation module in the security report generation system, the security report generation is automatically generated, which solves the time-consuming and labor-intensive problem of manual analysis in the prior art, and achieves efficient and accurate security report generation.

CN120185894AInactive Publication Date: 2025-06-20BEIJING VOLCANO ENGINE TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510378159.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-27
Publication Date
2025-06-20
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing security reports are generated rely on manual analysis, are time-consuming, error-prone, and difficult to meet the growing security needs.

Method used

Provides a security report generation system, including a multi-agent subsystem, a data engine module and a report generation module, and automates data query and report generation through the collaboration of the main agent and the editing agent.

Benefits of technology

It significantly improves the efficiency of security reports generation, reduces manual intervention, saves costs, ensures the accuracy and consistency of reports, and can quickly respond to and process alarm data to meet real-time security monitoring and analysis needs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120185894A_ABST
    Figure CN120185894A_ABST
Patent Text Reader

Abstract

The invention discloses a security report generation system and method, a medium, electronic equipment and a program product. The system comprises a multi-agent subsystem, a data engine module and a report generation module, wherein the multi-agent subsystem comprises a main agent and N editing agents; the main agent is used for determining at least one first editing agent participating in the safety report generation from the N editing agents according to a safety report generation instruction; for each first editing agent, calling the first editing agent to obtain first data matched with the security report generation instruction and corresponding to the first editing agent through a data engine module, and obtaining chapter content generated by the first editing agent according to the first data; and calling a report generation module to generate a security report according to the chapter content generated by the at least one first editing agent. Through the security report generation system based on multiple agents, the security report can be automatically generated, and the generation efficiency and accuracy of the security report are improved, so that a complex and changeable network environment can be better coped with.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of network security technology. Specifically, it relates to a security report generation system, method, medium, electronic device, and program product. Background Art

[0002] In today's information society, the demand for network security is increasing day by day. Both enterprises and individuals hope to protect the security of their own data and systems. With the continuous update of network attack means, it has become a top priority to identify and defend against risk items such as security vulnerabilities, misconfigurations, and weak passwords. Security reports have emerged in this context, which can help comprehensively evaluate the security status of the system, timely discover and repair potential security problems, and thus effectively prevent security incidents such as hacker attacks, virus propagation, and data leakage. In addition, more and more industries and organizations have strict requirements for system security, and regular security assessments to meet compliance requirements are also the trend today.

[0003] There are a wide variety of existing security products, and the amount of alarm information generated is huge and complex. Traditional security analysis relies on professionals to pick out real security threats from a large amount of alarms, which is not only time-consuming and laborious, but also prone to omissions or misjudgments. The generation of existing security service reports mainly relies on manual mining and analysis. The whole process is not only time-consuming and laborious, but also easily limited by the personal experience and knowledge level of analysts, resulting in uneven quality of security reports. In addition, manually generating security reports has problems such as low efficiency, easy errors, and high costs, and it is difficult to meet the growing security needs. Summary of the Invention

[0004] This Summary of the Invention section is provided to introduce concepts in a brief form, which will be described in detail in the following Detailed Implementation section. This Summary of the Invention section is not intended to identify key features or essential features of the claimed technical solution, nor is it intended to be used to limit the scope of the claimed technical solution.

[0005] In a first aspect, the present disclosure provides a security report generation system, which includes a multi-agent subsystem, a data engine module, and a report generation module. Among them, the multi-agent subsystem includes a main agent and N editing agents, where N≥1; The main agent is used for: Determining at least one first editing agent participating in the generation of the current security report from the N editing agents according to a security report generation instruction; For each of the at least one first editing agent, invoking the first editing agent to obtain, through the data engine module, first data corresponding to the first editing agent that matches the security report generation instruction, and obtaining chapter content generated by the first editing agent according to the first data; Invoke the report generation module to generate a security report based on the chapter content respectively generated by the at least one first editing agent.

[0006] In a second aspect, the present disclosure provides a method for generating a security report, the method comprising: Determine at least one first editing agent participating in the generation of the current security report from N editing agents according to a security report generation instruction, where N≥1; For each of the at least one first editing agent, invoke the first editing agent to obtain, through a data engine module, first data corresponding to the first editing agent that matches the security report generation instruction, and obtain the chapter content generated by the first editing agent based on the first data; Invoke the report generation module to generate a security report based on the chapter content respectively generated by the at least one first editing agent.

[0007] In a third aspect, the present disclosure provides a computer-readable medium having a computer program stored thereon, and when the computer program is executed by a processing device, it implements the steps performed by the agent or module in the security report generation system provided in the first aspect of the present disclosure or the steps of the security report generation method provided in the second aspect of the present disclosure.

[0008] In a fourth aspect, the present disclosure provides an electronic device, comprising: A storage device having a computer program stored thereon; A processing device configured to execute the computer program in the storage device to implement the steps performed by the agent or module in the security report generation system provided in the first aspect of the present disclosure or the steps of the security report generation method provided in the second aspect of the present disclosure.

[0009] In a fifth aspect, the present disclosure provides a computer program product comprising a computer program, and when the computer program is executed by a processor, it implements the steps performed by the agent or module in the security report generation system provided in the first aspect of the present disclosure or the steps of the security report generation method provided in the second aspect of the present disclosure.

[0010] In the above technical solution, a security report generation system is provided. The system includes a multi-agent subsystem, a data engine module, and a report generation module. Among them, the multi-agent subsystem includes a main agent and N editing agents, where N ≥ 1. The main agent is used to: according to the security report generation instruction, determine at least one first editing agent participating in the current security report generation from the N editing agents; for each first editing agent among the at least one first editing agent, call the first editing agent to obtain, through the data engine module, first data corresponding to the first editing agent that matches the security report generation instruction, and obtain the chapter content generated by the first editing agent based on the first data; call the report generation module to generate a security report according to the chapter content generated by each of the at least one first editing agent. In this way, through the cooperation among multiple agents and modules in the security report generation system, automated data query and report generation can be achieved, significantly improving the generation efficiency of security reports. In addition, the security report generation system based on multiple agents can process multiple security report generation tasks in parallel, reducing manual intervention and saving labor costs, making the security report generation process faster and more efficient. The security report generation system based on multiple agents can quickly respond to and process alarm data, generate security reports in real time, meet the needs of enterprises and individuals for real-time security monitoring and analysis, and thus can quickly identify and repair security problems, effectively preventing the occurrence of security incidents such as hacker attacks, virus propagation, and data leakage. In addition, through the automated security report generation system, each step of report generation can be standardized to ensure that each generated report is consistent and accurate, avoiding omissions and errors that may occur in manual operations. Therefore, through the security report generation system based on multiple agents, security reports can be automatically generated, improving the generation efficiency and accuracy of security reports, and thus better coping with the complex and changeable network environment.

[0011] Other features and advantages of the present disclosure will be described in detail in the subsequent specific implementation part. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] In combination with the accompanying drawings and with reference to the following specific implementation manners, the above and other features, advantages, and aspects of the embodiments of the present disclosure will become more obvious. Throughout the accompanying drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic, and the original elements and elements are not necessarily drawn to scale. In the drawings: Figure 1 is a block diagram of a security report generation system shown according to an exemplary embodiment.

[0013] Figure 2 is a block diagram of a security report generation system shown according to another exemplary embodiment.

[0014] Figure 3It is a topology diagram of a security report generation system shown according to an exemplary embodiment.

[0015] Figure 4 It is a flowchart of a security report generation method shown according to an exemplary embodiment.

[0016] Figure 5 It is a schematic structural diagram of an electronic device shown according to an exemplary embodiment. Detailed implementation manners

[0017] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes and are not used to limit the protection scope of the present disclosure.

[0018] It should be understood that the steps recited in the method embodiments of the present disclosure can be executed in a different order and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this regard.

[0019] The term "including" and its variants used herein are open-ended, that is, "including but not limited to". The term "based on" is "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". The relevant definitions of other terms will be given in the following description.

[0020] It should be noted that the concepts such as "first" and "second" mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependent relationships.

[0021] It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive. Those skilled in the art should understand that unless otherwise clearly indicated in the context, it should be understood as "one or more".

[0022] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only for illustrative purposes and are not used to limit the scope of these messages or information.

[0023] It is understandable that before using the technical solutions disclosed in the embodiments of the present disclosure, the types, usage scopes, usage scenarios, etc. of the personal information involved in the present disclosure should be informed to users and the authorization of users should be obtained through appropriate means in accordance with relevant laws and regulations.

[0024] For example, when responding to an active request from a user, a prompt message is sent to the user to clearly prompt the user that the operation requested by the user will require obtaining and using the user's personal information. Thus, the user can autonomously choose whether to provide personal information to software or hardware such as an electronic device, an application program, a server, or a storage medium that performs the operations of the technical solutions of the present disclosure according to the prompt message.

[0025] As an optional but non-limiting implementation manner, the manner of sending a prompt message to the user in response to receiving an active request from the user may be, for example, in the form of a pop-up window, and the prompt message may be presented in text in the pop-up window. In addition, the pop-up window may also carry a selection control for the user to choose "agree" or "disagree" to provide personal information to the electronic device.

[0026] It is understandable that the above process of notifying and obtaining user authorization is only illustrative and does not constitute a limitation on the implementation manner of the present disclosure. Other manners that meet relevant laws and regulations can also be applied to the implementation manner of the present disclosure.

[0027] Meanwhile, it is understandable that the data involved in the technical solutions of the present disclosure (including but not limited to the data itself, the acquisition or use of the data) should comply with the requirements of the corresponding laws, regulations and related provisions.

[0028] As discussed in the background art, the generation of existing security service reports mainly relies on manual mining and analysis, and the process is complex and time-consuming. Among them, security analysts need to manually extract a large amount of alarm data from various security products and screen, classify and analyze these data through professional knowledge. The specific steps include: (1) Data collection: Collect original alarm data from various security devices and systems, including firewalls, intrusion detection systems, anti-virus software, etc.

[0029] (2) Data screening: Security analysts need to manually screen out real threat information from a large amount of alarm data and eliminate false alarms and low-priority alarms.

[0030] (3) Data analysis: Deeply analyze the screened data to identify potential security vulnerabilities and risk items, such as software vulnerabilities, configuration errors, weak passwords, etc.

[0031] (4) Report writing: Write a security service report according to the analysis results. The content of the report includes risk assessment, details of vulnerabilities, repair suggestions, etc.

[0032] Since most of the above steps rely on manual operations, the entire process is not only time-consuming and laborious, but also easily restricted by the personal experience and knowledge level of analysts, resulting in uneven quality of reports. In addition, there are problems such as low efficiency, error-proneness, and high costs in manually generating security reports, making it difficult to meet the growing security needs.

[0033] In view of this, the present disclosure provides a security report generation system, method, medium, electronic device, and program product.

[0034] The following further explains the embodiments of the present disclosure with reference to the accompanying drawings.

[0035] Figure 1 is a block diagram of a security report generation system shown according to an exemplary embodiment. As Figure 1 shown, the security report generation system may include a multi-agent subsystem 10, a data engine module 20, and a report generation module 30. Among them, the multi-agent subsystem 10 includes a main agent 101 and N editing agents 102. The N editing agents 102 correspond to N chapters one by one, and N≥1. Among them, the number of editing agents 102 in the multi-agent subsystem 10 may be one or more, and each editing agent is respectively used to generate the chapter content of the corresponding chapter.

[0036] The multi-agent subsystem 10 is a system architecture that uses multiple autonomous agents to work together to solve complex problems. Each agent can communicate and cooperate with other agents to complete distributed tasks. This architecture has extensive applications in fields such as robotics, network management, and e-commerce.

[0037] The main agent 101 in the multi-agent subsystem 10 serves as the coordination center of the system, responsible for coordinating the overall structure of the security report and promoting the editing communication and feedback between different chapters and functions. The editing agents 102 in the multi-agent subsystem 10 are used to generate the natural language report content and structured picture and table content of the subsection according to the report functions and focuses of the corresponding chapters. The data engine module 20 is responsible for docking with the underlying alarm data and performing data query, sampling, aggregation, and multi-dimensional statistical analysis. The report generation module 30 is responsible for sorting out and writing the structured and unstructured data generated by the multi-agent subsystem 10, and finally generating a security report.

[0038] In one implementation, the above N chapters may include at least one of security alarm trends, alarm type distributions, attacker analysis, security situation awareness, critical security event analysis, vulnerability analysis, and alarm classification interpretation.

[0039] Among them, the security alert trend section is used to analyze the security alert trend within the reporting time period, identify the changes and fluctuations in the number of alerts. Specifically, charts (such as line charts and bar charts) can be used to display the time trend of the number of alerts, helping readers intuitively understand the changes in the security situation.

[0040] The alert type distribution section is used to classify and count different types of security alerts, analyze the proportions and changes of various alerts. Specifically, pie charts, bar charts and other charts can be used to display the distribution of different types of alerts.

[0041] The attacker analysis section is used to identify and analyze information about potential attackers, including source Internet Protocol (IP), geographical location, attack behavior patterns, etc. For example, an attacker profile can be provided to help understand the attack behavior and characteristics.

[0042] The security situation awareness section is used to comprehensively analyze the overall security situation within the reporting time period, provide a comprehensive assessment of security risks. Specifically, tools such as radar charts and risk matrices can be used to display the overall security situation.

[0043] The key security event analysis section is used to describe the key security events that occurred within the reporting time period, analyze the impacts and handling situations of the events. Specifically, a detailed description, alert interpretation and handling suggestions for each key event can be provided. Among them, the key events can be alert events whose risk levels reach the preset levels, or alert events that users are concerned about.

[0044] The vulnerability analysis section is used for vulnerabilities existing in the software system, including software vulnerabilities, configuration errors, weak passwords, etc. Specifically, a detailed description, risk assessment and repair suggestions for the vulnerabilities can be provided.

[0045] The alert classification and interpretation section is used to interpret each alert within the reporting time period, explain the triggering reasons and impacts of the alerts, and at the same time provide handling suggestions for each alert to help users take effective security measures.

[0046] Specifically, the above-mentioned main agent 101 is used for: Determine at least one first editing agent participating in the generation of the current security report from N editing agents according to the security report generation instruction; For each first editing agent among the at least one first editing agent, call the first editing agent to obtain, through the data engine module, first data corresponding to the first editing agent that matches the security report generation instruction, and obtain the chapter content generated by the first editing agent according to the first data; Call the report generation module to generate a security report according to the chapter content generated by each of the at least one first editing agent.

[0047] In the present disclosure, as Figure 3 shown, the security report generation instruction can be triggered periodically according to a preset period, or can be actively triggered by the user. The first data corresponding to the first editing agent and matching the security report generation instruction may include original alarm data, data obtained by sampling / aggregating the original alarm data by the data engine module, data obtained by performing multi-dimensional data analysis on the original alarm data and the sampled / aggregated data, etc. The main agent 101 can determine which chapters the security report to be generated involves according to the specific content of the security report generation instruction, and then determine the editing agent corresponding to the involved chapter as the first editing agent.

[0048] Exemplarily, the security report generation instruction is "generate a security alarm trend chart for the most recent week". At this time, the security report to be generated involves the security alarm trend chapter. At this time, the editing agent corresponding to the security alarm trend chapter can be determined as the first editing agent.

[0049] Another example, the security report generation instruction is "generate a security report for the most recent month". At this time, it is default that the security report to be generated involves each of the above N chapters. At this time, the above N editing agents can be determined as the first editing agents.

[0050] In a possible implementation manner, for each first editing agent 102 among at least one first editing agent, the main agent 101 can generate a data query instruction corresponding to the first editing agent 102 according to the security report generation instruction, and send the data query instruction to the first editing agent 102 or the data engine module 20; then, the first editing agent 102 can obtain the first data matching the data query instruction through the data engine module 20, and generate the chapter content of the chapter corresponding to the first editing agent 102 according to the first data.

[0051] In another possible implementation manner, for each first editing agent 102 among at least one first editing agent, the main agent 101 can generate a data query instruction corresponding to the first editing agent 102 according to the security report generation instruction, and send the data query instruction to the data engine module 20; then, the data engine module 20 can obtain the first data matching the received data query instruction, and feedback the first data to the first editing agent 102; the first editing agent 102 generates the chapter content of the chapter corresponding to the first editing agent 102 according to the received first data.

[0052] Among them, the functions of different editing agents are different, and the data on which the chapter content of the corresponding chapter is generated may also be different. Therefore, the data query instructions generated by the main agent for different editing agents are also different.

[0053] Specifically, the main agent 101 can input a security report generation instruction into the second large language model to obtain a data query instruction corresponding to the first editing agent 102.

[0054] In one implementation, after the first editing agent 102 obtains the first data through the data engine module 20, it can fill the first data into the report template corresponding to the first editing agent 102 to obtain the chapter content of the chapter corresponding to the first editing agent 102.

[0055] In another implementation, after the first editing agent 102 obtains the first data through the data engine module 20, it can input the first data into the first large language model corresponding to the first editing agent 102 to obtain the chapter content of the chapter corresponding to the first editing agent 102. This method can generate the corresponding chapter content by calling the first large language model, which is convenient and fast.

[0056] In the above technical solution, a security report generation system is provided. The system includes a multi-agent subsystem, a data engine module, and a report generation module. Among them, the multi-agent subsystem includes a main agent and N editing agents, N≥1; the main agent is used to: determine at least one first editing agent participating in the current security report generation from the N editing agents according to the security report generation instruction; for each first editing agent among the at least one first editing agent, call the first editing agent to obtain the first data corresponding to the first editing agent that matches the security report generation instruction through the data engine module, and obtain the chapter content generated by the first editing agent according to the first data; call the report generation module to generate a security report according to the chapter content generated by each of the at least one first editing agent. In this way, through the cooperation among multiple agents and modules in the security report generation system, automated data query and report generation can be realized, significantly improving the generation efficiency of the security report. In addition, the security report generation system based on multiple agents can process multiple security report generation tasks in parallel, reducing manual intervention and saving labor costs, making the security report generation process faster and more efficient. The security report generation system based on multiple agents can quickly respond to and process alarm data, generate security reports in real time, meet the needs of enterprises and individuals for real-time security monitoring and analysis, and thus can quickly identify and repair security problems, effectively preventing the occurrence of security incidents such as hacker attacks, virus propagation, and data leakage. In addition, through the automated security report generation system, each step of report generation can be standardized to ensure that each generated report is consistent and accurate, avoiding omissions and errors that may occur in manual operations. Therefore, through the security report generation system based on multiple agents, security reports can be automatically generated, improving the generation efficiency and accuracy of security reports, so as to better cope with the complex and changeable network environment.

[0057] In a possible implementation, the main agent 101 is further configured to obtain second historical information, where the second historical information includes: historical data query instructions generated by the main agent in the most recent L times and corresponding to the first editing agent 102, and historical security report generation instructions received in the most recent L times, where L≥1. That is, the security report generation instructions (i.e., historical security report generation instructions) received by the main agent 101 when generating security reports in the most recent L times, and historical data query instructions corresponding to the first editing agent 102 generated based on the historical security report generation instructions. At this time, the main agent 101 is configured to generate a data query instruction corresponding to the first editing agent 102 according to the security report generation instruction and the second historical information.

[0058] In an implementation, after obtaining the second historical information, the main agent 101 may input the security report generation instruction and the second historical information into a second large language model to obtain a data query instruction corresponding to the first editing agent 102.

[0059] In the above implementation, when generating the data query instruction corresponding to the first editing agent 102, the second historical information is referred to at the same time. In this way, when generating the data query instruction corresponding to the first editing agent 102, the context information (equivalent to the chat background) of the main agent 101 can be fully considered, so as to be able to generate a more accurate data query instruction, and further improve the accuracy of the first data and the security report.

[0060] In a possible implementation, the above-mentioned main agent 101 is further configured to obtain second associated information of the security report generation instruction from a second knowledge base, where the second knowledge base may store knowledge related to the security report generation instruction; the main agent 101 is configured to input the security report generation instruction, the second historical information, the second associated information, and a second prompt word corresponding to the first editing agent 102 into a second large language model to obtain a data query instruction corresponding to the first editing agent 102, where the second prompt word is used to guide the second large language model to generate a data query instruction corresponding to the security report generation instruction.

[0061] In the above implementation, when generating the data query instruction corresponding to the first editing agent 102, the second historical information, the knowledge base, and the prompt word are referred to at the same time. In this way, when generating the data query instruction corresponding to the first editing agent 102, the context information (equivalent to the chat background) and associated information of the main agent 101 can be fully considered, and the generation of the data query instruction can be guided by the prompt word, so as to be able to generate a more accurate data query instruction, and further improve the accuracy of the first data and the security report.

[0062] In a possible implementation, the above-mentioned first editing agent 102 is further configured to obtain first historical information, where the first historical information includes the historical chapter content generated by the first editing agent 102 in the most recent M times and the historical data referred to when generating the historical chapter content, M≥1, that is, the first data (i.e., historical data) based on which the first editing agent 102 generated security reports in the most recent M times and the chapter content generated based on the historical data; at this time, the first editing agent 102 is configured to generate the chapter content of the corresponding chapter of the first editing agent 102 according to the first data and the first historical information.

[0063] In an implementation, after obtaining the first data and the first historical information, the first editing agent 102 may input the first data and the first historical information into the first large language model corresponding to the first editing agent 102 to obtain the chapter content of the corresponding chapter of the first editing agent 102.

[0064] In the above implementation, when generating the chapter content of the corresponding chapter of the first editing agent 102, the first historical information is referred to at the same time. In this way, when generating the chapter content of the corresponding chapter of the current security report, the context information (equivalent to the chat background) of the first editing agent 102 can be fully considered, so that the chapter content that meets the user's intention can be generated, and further the accuracy of the security report can be improved.

[0065] In a possible implementation, the above-mentioned first editing agent 102 is further configured to obtain the first association information of the first data from the first knowledge base, where the first knowledge base may store knowledge related to alarm data. For example, the first knowledge base may be a large security knowledge base of security products and security threats in different fields. At this time, the above-mentioned first editing agent 102 may be configured to input the first data, the first historical information, the first association information, and the first prompt word into the first large language model corresponding to the first editing agent to obtain the chapter content, where the first prompt word is used to guide the first large language model to generate the chapter content of the corresponding chapter of the first editing agent 102.

[0066] Exemplarily, the prompt word of the first editing agent 102 corresponding to the alarm type distribution chapter may be to classify and count different types of security alarms, analyze the proportion and change of each type of alarm, and use a pie chart to show the distribution of different types of alarms.

[0067] The first editing agent 102 can obtain the first data matching the data query instruction in various ways by using the data engine module 20. Specifically, in one implementation, the main agent 101 can first convert the data query instruction in natural language form into a data query statement (the first query statement), for example, a database query statement, and then send the first query statement to the data engine module 20; the data engine module 20 can obtain the first query result according to the received first query statement, perform multi-dimensional data analysis on the first query result to obtain the first data, and feed back the first data to the first editing agent 102.

[0068] In another implementation, as Figure 2 shown, the multi-agent subsystem further includes a query statement generation agent 40; wherein, the first editing agent 102 or the data engine module 20 is configured to send the received data query instruction to the query statement generation agent 40; the query statement generation agent 40 is configured to generate the first query statement according to the received data query instruction and send the first query statement to the data engine module 20; the data engine module 20 is configured to obtain the first query result according to the first query statement, perform multi-dimensional data analysis on the first query result to obtain the first data, and feed back the first data to the first editing agent 102.

[0069] Among them, the data engine module 20 is responsible for docking with the underlying alarm data for data query, sampling, aggregation, and multi-dimensional statistical analysis. Specifically, the data engine module 20 can be used to dock with various security systems and monitoring, collect and query the corresponding original alarm data according to the first query statement to obtain the first query result, and then perform operations such as sampling, aggregation, and multi-dimensional data analysis on the first query result to obtain the first data. Among them, the data engine module 20 can be docked with various security devices and software systems through an Application Programming Interface (API), and adopt corresponding efficient data query algorithms for different data storage paradigms to ensure the real-time and accuracy of data query. Data sampling and aggregation can adopt big data processing technologies and implement fast processing and aggregation analysis of massive data through a distributed computing framework.

[0070] Exemplarily, as Figure 3As shown in the figure, the first editing agent can send the received data query instruction to the query statement generation agent; the query statement generation agent generates a first query statement according to the received data query instruction and sends the first query statement to the data engine module; the data engine module queries the corresponding original alarm data via the API using the first query statement, and performs operations such as sampling, aggregation, and multi-dimensional data analysis on the original alarm data to obtain aggregated data, full-volume data, sampled data, etc., and feeds these data back to the first editing agent as the first data.

[0071] In the above two implementation manners, when generating the chapter content corresponding to the first editing agent 102, the first historical information, the knowledge base, and the prompt words are referred to simultaneously. In this way, when generating the chapter content of the corresponding chapter of the current security report, the context information (equivalent to the chat background) and associated information of the first editing agent 102 can be fully considered, and the generation of the chapter content can be guided by the prompt words, so that the security issues can be interpreted and analyzed in a simple and profound way, and the chapter content that better meets the user's intention can be generated, thereby improving the accuracy of the security report. In addition, the prompt words can also guide the first editing agent 102 to generate a detailed risk assessment, vulnerability details, and specific repair suggestions, making the content of the finally generated security report easy to understand and operate. Even non-professionals can take corresponding security measures according to the report content, enhancing the practicality and operability of the security report.

[0072] In a possible implementation manner, the query statement generation agent 40 can input the received data query instruction into the third large language model to obtain the first query statement.

[0073] In the above implementation manner, by adding a query statement generation agent to the multi-agent subsystem to convert the data query instruction in natural language form into a data query statement, in this way, the query instruction conversion operation can be separated from each editing agent. In this way, it is not necessary to set the query instruction conversion function for each editing agent, which can simplify the code complexity of the editing agent.

[0074] In a possible implementation manner, the query statement generation agent 40 is further configured to obtain the third historical information, where the third historical information includes the historical query statements generated by the query statement generation agent 40 in the most recent K times and the historical data query instructions referred to when generating the historical query statements, K≥1, that is, the data query instructions (historical data query instructions) and the corresponding historical query statements on which the query statement generation agent 40 relies when generating the security report in the most recent K times; at this time, the query statement generation agent 40 is configured to generate the first query statement according to the data query instruction and the third historical information.

[0075] In one implementation, after obtaining the data query instruction and the third historical information, the query statement generation agent 40 can input the data query instruction and the third historical information into the third large language model to obtain the first query statement corresponding to the data query instruction.

[0076] In the above implementation, when generating the first query statement corresponding to the data query instruction, the query statement generation agent 40 refers to the third historical information at the same time. In this way, when generating the first query statement corresponding to the data query instruction, the context information (equivalent to the chat background) of the query statement generation agent 40 can be fully considered, so as to generate a more accurate query statement, and then improve the accuracy of the first data and security report.

[0077] In a possible implementation, the above query statement generation agent 40 is further configured to obtain the third association information of the data query instruction from the third knowledge base, where the third knowledge base may store knowledge related to the data query instruction; the query statement generation agent 40 is configured to input the data query instruction, the third historical information, the third association information, and the third prompt word into the third large language model to obtain the first query statement, where the third prompt word is used to guide the third large language model to convert the data query instruction into the first query statement.

[0078] In the above implementation, when generating the first query statement corresponding to the data query instruction, the query statement generation agent 40 refers to the third historical information, the knowledge base, and the prompt word at the same time. In this way, when generating the first query statement corresponding to the data query instruction, the context information (equivalent to the chat background) and the association information of the query statement generation agent 40 can be fully considered, and the conversion of the data query instruction can be guided by the prompt word, so that the query statement generation agent 40 can understand the logical structure, field meaning, aggregation method, etc. of different databases, so as to generate a more accurate query statement to obtain the required data, and then improve the accuracy of the first data and security report.

[0079] In addition, when generating chapter content according to the instructions of the main agent, in order to improve the accuracy and integrity of the chapter content, the first editing agent 102 can interact and provide feedback with the data engine module 20 multiple times. Specifically, the first editing agent 102 is also used to generate an overview information of the chapter content corresponding to the chapter of the first editing agent 102 and send the overview information to the main agent 101. Among them, the first editing agent 102 can concisely summarize the core viewpoints, main content, structural framework, etc. of the chapter content generated this time to obtain the overview information of the chapter content. The main agent 101 is also used to: generate a first instruction according to the overview information, where the first instruction is used to indicate the next operation of the first editing agent; when the first instruction indicates that the first editing agent continues to edit the chapter content, send the first instruction to the first editing agent or the data engine module. The first editing agent 102 is also used to obtain second data matching the received first instruction through the data engine module 20 and continue to generate chapter content according to the second data; the main agent 101 is used to, when each first instruction corresponding to each first editing agent 102 indicates that the corresponding first editing agent ends editing the chapter content, call the report generation module to generate a security report according to the chapter content generated by at least one first editing agent respectively.

[0080] Among them, the first instruction can be a further data query instruction. At this time, the first instruction is used to indicate that the first editing agent continues to edit the chapter content. The first instruction can also be used to indicate that the first editing agent ends editing the chapter content. In a possible implementation manner, the main agent 101 can input the overview information into the second large language model to obtain the first instruction.

[0081] After each time the first editing agent 102 generates new chapter content, it feeds back the overview information of the chapter content to the main agent 101. After receiving the overview information, the main agent 101 generates a first instruction according to the overview information. If the first instruction indicates that the first editing agent continues to edit the chapter content, the first editing agent 102 interacts with the data engine module 20 multiple times according to the first instruction to continue generating chapter content; if the first instruction indicates that the first editing agent ends editing the chapter content, it means that the first editing agent 102 has generated complete chapter content. At this time, the first editing agent 102 stops interacting with the data engine module 20.

[0082] Specifically, the first editing agent 102 can be used to send a first instruction to the query statement generation agent 40; the query statement generation agent 40 is further configured to generate a second query statement according to the received first instruction and send the second query statement to the data engine module 20; the data engine module 20 is further configured to obtain a second query result according to the second query statement, perform data analysis on the second query result to obtain second data that matches the first instruction, and feed back the second data to the first editing agent 102; the first editing agent 102 is further configured to continue to generate chapter content according to the second data.

[0083] The report generation module 30 is responsible for sorting and writing the structured and unstructured data generated by the multi-agent subsystem 10, and finally generating a security report. Specifically, the report generation module 30 can sort the chapter content generated by at least one first editing agent respectively, that is, sort and summarize the structured and unstructured data, and generate security report content including risk assessment, vulnerability details, and repair suggestions according to the data sorting result. In order to intuitively display the data analysis result, the report generation module 30 can also use a graphics library, a front-end visualization framework, etc. to draw schematic diagrams and tables, that is, Figure 3 the structured tabular data and structured graphic data shown in to achieve visual display of the data. In addition, for the convenience of distribution and storage of the security report, the report generation module 30 can also generate report files in formats such as PDF and dox through a document generation library to ensure the unity and readability of the report format.

[0084] As Figure 3 shown, in order to facilitate users to understand the overall security status, the main agent can also summarize the chapter content generated by at least one first editing agent respectively and the first data reported by the data engine module to obtain a more comprehensive security report.

[0085] The present disclosure also provides a security report generation method, which is applied to a security report generation system. The security report generation system includes a multi-agent subsystem, a data engine module, and a report generation module. The multi-agent subsystem includes a main agent and N editing agents, where N≥1. As Figure 4 shown, the security report generation method may include the following S201~S203.

[0086] In S201, according to a security report generation instruction, at least one first editing agent participating in the generation of the current security report is determined from the N editing agents.

[0087] In S202, for each of at least one first editing agent among the first editing agents, call the first editing agent to obtain, through the data engine module, first data corresponding to the first editing agent that matches the security report generation instruction, and obtain the chapter content generated by the first editing agent based on the first data.

[0088] In S203, call the report generation module to generate a security report based on the chapter content generated by each of at least one first editing agent.

[0089] Among them, S201 to S203 are all executed by the main agent.

[0090] In the above technical solution, the main agent determines, according to the security report generation instruction, at least one first editing agent participating in the generation of the current security report from N editing agents; for each of at least one first editing agent among the first editing agents, the main agent calls the first editing agent to obtain, through the data engine module, first data corresponding to the first editing agent that matches the security report generation instruction, and obtain the chapter content generated by the first editing agent based on the first data; the main agent calls the report generation module to generate a security report based on the chapter content generated by each of at least one first editing agent. In this way, automated data query and report generation can be realized, significantly improving the generation efficiency of the security report, and being able to quickly respond to and process alarm data, generate a security report in real time, meet the needs of enterprises and individuals for real-time security monitoring and analysis, and thus be able to quickly identify and repair security problems, effectively preventing the occurrence of security incidents such as hacker attacks, virus propagation, and data leakage.

[0091] Optionally, for each of at least one first editing agent among the first editing agents, calling the first editing agent to obtain, through the data engine module, first data corresponding to the first editing agent that matches the security report generation instruction, and obtain the chapter content generated by the first editing agent based on the first data includes: Through the main agent, for each of at least one first editing agent among the first editing agents, according to the security report generation instruction, generate a data query instruction corresponding to the first editing agent, and send the data query instruction to the first editing agent or the data engine module; Through the first editing agent, obtain the first data that matches the data query instruction through the data engine module, and generate the chapter content based on the first data.

[0092] Optionally, the method further includes: Obtain first historical information through a first editing agent, where the first historical information includes the historical chapter content generated by the first editing agent in the most recent M times and the historical data referred to when generating the historical chapter content, M≥1; The generating, by the first editing agent, the chapter content according to the first data includes: Generate the chapter content through the first editing agent according to the first data and the first historical information.

[0093] Optionally, the method further includes: Obtain first associated information of the first data from a first knowledge base through the first editing agent; The generating, by the first editing agent, the chapter content according to the first data and the first historical information includes: Input the first data, the first historical information, the first associated information, and a first prompt word into a first large language model corresponding to the first editing agent through the first editing agent to obtain the chapter content, where the first prompt word is used to guide the first large language model to generate the chapter content.

[0094] Optionally, the method further includes: Obtain second historical information through the main agent, where the second historical information includes: historical data query instructions corresponding to the first editing agent generated by the main agent in the most recent L times, and historical security report generation instructions received in the most recent L times, L≥1; The generating, by the main agent, a data query instruction corresponding to the first editing agent according to the security report generation instruction includes: Generate the data query instruction corresponding to the first editing agent through the main agent according to the security report generation instruction and the second historical information.

[0095] Optionally, the method further includes: Obtain second associated information of the security report generation instruction from a second knowledge base through the main agent; The generating, by the main agent, the data query instruction corresponding to the first editing agent according to the security report generation instruction and the second historical information includes: Input the security report generation instruction, the second historical information, the second associated information, and a second prompt word corresponding to the first editing agent into a second large language model to obtain the data query instruction corresponding to the first editing agent, where the second prompt word is used to guide the second large language model to generate a data query instruction corresponding to the security report generation instruction.

[0096] Optionally, the multi-agent subsystem further includes a query statement generation agent; The step of the first editing agent obtaining the first data that matches the received data query instruction through the data engine module includes: Sending the received data query instruction to the query statement generation agent through the first editing agent or the data engine module; Generating a first query statement by the query statement generation agent according to the received data query instruction, and sending the first query statement to the data engine module; Obtaining a first query result by the data engine module according to the first query statement, performing multi-dimensional data analysis on the first query result to obtain the first data, and feeding back the first data to the first editing agent.

[0097] Optionally, the method further includes: Obtaining third historical information by the query statement generation agent, where the third historical information includes the historical query statements generated by the query statement generation agent in the most recent K times and the historical data query instructions referred to when generating the historical query statements, K≥1; The step of the query statement generation agent generating a first query statement according to the received data query instruction includes: Generating the first query statement by the query statement generation agent according to the data query instruction and the third historical information.

[0098] Optionally, the method further includes: Obtaining third association information of the data query instruction by the query statement generation agent from a third knowledge base; The step of the query statement generation agent generating the first query statement according to the data query instruction and the third historical information includes: Inputting the data query instruction, the third historical information, the third association information, and a third prompt word into a third large language model by the query statement generation agent to obtain the first query statement, where the third prompt word is used to guide the third large language model to convert the data query instruction into the first query statement.

[0099] Optionally, the method further includes: Generating summary information of the chapter content by the first editing agent and sending the summary information to the main agent; The main agent generates a first instruction according to the overview information, where the first instruction is used to indicate the next operation of the first editing agent; when the first instruction indicates that the first editing agent continues to edit the chapter content, the first instruction is sent to the first editing agent or the data engine module; The first editing agent obtains second data matching the first instruction through the data engine module, and continues to generate the chapter content according to the second data; Optionally, the N editing agents correspond to N chapters one by one, and the N chapters include at least one of security alert trend, alert type distribution, attacker analysis, security situation awareness, critical security event analysis, vulnerability analysis, and alert classification interpretation.

[0100] Based on the same concept, the present disclosure also provides a computer-readable medium on which a computer program is stored. When the computer program is executed by a processing device, it implements the steps performed by the agent or module in the above security report generation system provided by the present disclosure or the steps of the above security report generation method provided by the present disclosure.

[0101] Based on the same concept, the present disclosure also provides an electronic device, including: A storage device on which a computer program is stored; A processing device for executing the computer program in the storage device to implement the steps performed by the agent or module in the above security report generation system provided by the present disclosure or the steps of the above security report generation method provided by the present disclosure.

[0102] Based on the same concept, the present disclosure also provides a computer program product, including a computer program. When the computer program is executed by a processor, it implements the steps performed by the agent or module in the above security report generation system provided by the present disclosure or the steps of the above security report generation method provided by the present disclosure.

[0103] Next, refer to Figure 5 , which shows a schematic structural diagram of an electronic device 600 suitable for implementing the embodiments of the present disclosure. The terminal device in the embodiments of the present disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Tablet Computers), PMPs (Portable Multimedia Players), in-vehicle terminals (such as in-vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 5 The electronic device shown is only an example and should not impose any limitation on the functions and usage scope of the embodiments of the present disclosure.

[0104] As Figure 5As shown, the electronic device 600 may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 601, which may perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 602 or a program loaded from a storage device 608 into a random access memory (RAM) 603. In the RAM 603, various programs and data required for the operation of the electronic device 600 are also stored. The processing device 601, the ROM 602, and the RAM 603 are connected to each other through a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.

[0105] Generally, the following devices may be connected to the I / O interface 605: an input device 606 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 607 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 608 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 609. The communication device 609 may allow the electronic device 600 to communicate with other devices wirelessly or wirelessly to exchange data. Although Figure 5 an electronic device 600 with various devices is shown, it should be understood that it is not required to implement or have all the shown devices. Instead, more or fewer devices may be implemented or had.

[0106] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart may be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program includes program codes for performing the method shown in the flowchart. In such an embodiment, the computer program may be downloaded and installed from a network through the communication device 609, or installed from the storage device 608, or installed from the ROM 602. When the computer program is executed by the processing device 601, the above functions defined in the method of the embodiment of the present disclosure are executed.

[0107] It should be noted that the above-mentioned computer-readable medium in the present disclosure can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, a computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device. In the present disclosure, a computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, and this computer-readable signal medium can send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted by any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.

[0108] In some embodiments, communication can be carried out using any currently known or future-developed network protocol such as HTTP (HyperText Transfer Protocol), and can be interconnected with digital data communication in any form or medium (for example, a communication network). Examples of communication networks include local area networks ("LAN"), wide area networks ("WAN"), the Internet (for example, the Internet), and end-to-end networks (for example, ad hoc end-to-end networks), as well as any currently known or future-developed networks.

[0109] The above-mentioned computer-readable medium can be included in the above-mentioned electronic device; it can also exist separately and not be assembled into the electronic device.

[0110] The above computer-readable medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to: generate an instruction according to a security report, determine at least one first editing agent participating in the generation of the current security report from N editing agents, where N≥1; for each of the at least one first editing agent, call the first editing agent to obtain, through a data engine module, first data corresponding to the first editing agent and matching the security report generation instruction, and obtain the chapter content generated by the first editing agent according to the first data; call a report generation module to generate a security report according to the chapter content generated by each of the at least one first editing agent.

[0111] Computer program code for performing the operations of the present disclosure may be written in one or more programming languages or combinations thereof. The programming languages include, but are not limited to, object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer, or entirely on the remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).

[0112] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that, in some alternative implementations, the functions marked in the blocks may occur in an order different from that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system for performing the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.

[0113] The modules involved in the embodiments of the present disclosure can be implemented in software or in hardware. In some cases, the name of a module does not constitute a limitation on the module itself.

[0114] The functions described above herein can be performed, at least in part, by one or more hardware logic components. By way of example, and without limitation, the types of hardware logic components that may be used include: Field Programmable Gate Arrays (FPGA), Application Specific Integrated Circuits (ASIC), Application Specific Standard Products (ASSP), System on a Chip (SOC), Complex Programmable Logic Devices (CPLD), and the like.

[0115] In the context of the present disclosure, a machine-readable medium may be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a Random Access Memory (RAM), a Read-Only Memory (ROM), an Erasable Programmable Read-Only Memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0116] According to one or more embodiments of the present disclosure, Example 1 provides a security report generation system, the system including a multi-agent subsystem, a data engine module, and a report generation module, wherein the multi-agent subsystem includes a main agent and N editing agents, N≥1; The main agent is configured to: Determine at least one first editing agent participating in the generation of the current security report from the N editing agents according to a security report generation instruction; For each of the at least one first editing agent, call the first editing agent to obtain, through the data engine module, first data corresponding to the first editing agent that matches the security report generation instruction, and obtain the chapter content generated by the first editing agent according to the first data; Call the report generation module to generate a security report according to the chapter content generated by each of the at least one first editing agent.

[0117] According to one or more embodiments of the present disclosure, Example 2 provides the system of Example 1. The main agent is used to generate, for each of the at least one first editing agent, a data query instruction corresponding to the first editing agent according to the security report generation instruction, and send the data query instruction to the first editing agent or the data engine module; The first editing agent is used to obtain the first data matching the data query instruction through the data engine module, and generate the chapter content according to the first data.

[0118] According to one or more embodiments of the present disclosure, Example 3 provides the system of Example 2. The first editing agent is further used to obtain first historical information, where the first historical information includes the historical chapter content generated by the first editing agent in the most recent M times and the historical data referred to when generating the historical chapter content, M≥1; The first editing agent is used to generate the chapter content according to the first data and the first historical information.

[0119] According to one or more embodiments of the present disclosure, Example 4 provides the system of Example 3. The first editing agent is further used to obtain first association information of the first data from a first knowledge base; The first editing agent is used to input the first data, the first historical information, the first association information, and a first prompt word into a first large language model corresponding to the first editing agent to obtain the chapter content, where the first prompt word is used to guide the first large language model to generate the chapter content.

[0120] According to one or more embodiments of the present disclosure, Example 5 provides the system of Example 2. The main agent is further used to obtain second historical information, where the second historical information includes: the historical data query instructions corresponding to the first editing agent generated by the main agent in the most recent L times, and the historical security report generation instructions received in the most recent L times, L≥1; The main agent is used to generate the data query instruction corresponding to the first editing agent according to the security report generation instruction and the second historical information.

[0121] According to one or more embodiments of the present disclosure, Example 6 provides the system of Example 5. The main agent is further used to obtain second association information of the security report generation instruction from a second knowledge base; The main agent is configured to input the security report generation instruction, the second historical information, the second association information, and a second prompt word corresponding to the first editing agent into a second large language model to obtain the data query instruction corresponding to the first editing agent, where the second prompt word is used to guide the second large language model to generate a data query instruction corresponding to the security report generation instruction.

[0122] According to one or more embodiments of the present disclosure, Example 7 provides the system of Example 2, and the multi-agent subsystem further includes a query statement generation agent; The first editing agent or the data engine module is configured to send the received data query instruction to the query statement generation agent; The query statement generation agent is configured to generate a first query statement according to the received data query instruction and send the first query statement to the data engine module; The data engine module is configured to obtain a first query result according to the first query statement, perform multi-dimensional data analysis on the first query result to obtain the first data, and feed back the first data to the first editing agent.

[0123] According to one or more embodiments of the present disclosure, Example 8 provides the system of Example 7, and the query statement generation agent is further configured to obtain third historical information, where the third historical information includes the historical query statements generated by the query statement generation agent in the most recent K times and the historical data query instructions referred to when generating the historical query statements, and K≥1; The query statement generation agent is configured to generate the first query statement according to the data query instruction and the third historical information.

[0124] According to one or more embodiments of the present disclosure, Example 9 provides the system of Example 8, and the query statement generation agent is further configured to obtain third association information of the data query instruction from a third knowledge base; The query statement generation agent is configured to input the data query instruction, the third historical information, the third association information, and a third prompt word into a third large language model to obtain the first query statement, where the third prompt word is used to guide the third large language model to convert the data query instruction into the first query statement.

[0125] According to one or more embodiments of the present disclosure, Example 10 provides the system of Example 2, and the first editing agent is further configured to generate an overview information of the chapter content and send the overview information to the main agent; The primary agent is further configured to: generate a first instruction according to the overview information, where the first instruction is used to indicate the next operation of the first editing agent; when the first instruction instructs the first editing agent to continue editing the chapter content, send the first instruction to the first editing agent or the data engine module; The first editing agent is further configured to obtain second data matching the first instruction through the data engine module, and continue to generate the chapter content according to the second data.

[0126] According to one or more embodiments of the present disclosure, Example 11 provides the system of any one of Examples 1-10, where the N editing agents correspond to N chapters one by one, and the N chapters include at least one of security alert trend, alert type distribution, attacker analysis, security situation awareness, critical security event analysis, vulnerability analysis, and alert classification interpretation.

[0127] According to one or more embodiments of the present disclosure, Example 12 provides a method for generating a security report, the method comprising: Determine at least one first editing agent participating in the current security report generation from N editing agents according to a security report generation instruction, N≥1; For each of the at least one first editing agent, call the first editing agent to obtain, through the data engine module, first data corresponding to the first editing agent that matches the security report generation instruction, and obtain the chapter content generated by the first editing agent according to the first data; Call a report generation module to generate a security report according to the chapter content generated by each of the at least one first editing agent.

[0128] According to one or more embodiments of the present disclosure, Example 13 provides a computer-readable medium, on which a computer program is stored, and when the computer program is executed by a processing device, the steps performed by an agent or module in the security report generation system of any one of Examples 1-11 or the steps of the security report generation method of Example 12 are implemented.

[0129] According to one or more embodiments of the present disclosure, Example 14 provides an electronic device, comprising: A storage device, on which a computer program is stored; A processing device, configured to execute the computer program in the storage device to implement the steps performed by an agent or module in the security report generation system of any one of Examples 1-11 or the steps of the security report generation method of Example 12.

[0130] According to one or more embodiments of the present disclosure, Example 15 provides a computer program product including a computer program, which when executed by a processor implements the steps performed by an agent or a module in the security report generation system described in any one of Examples 1-11 or the steps of the security report generation method described in Example 12.

[0131] The above description is only a preferred embodiment of the present disclosure and an explanation of the applied technical principles. Those skilled in the art should understand that the scope of disclosure involved in the present disclosure is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above disclosure concept. For example, the technical solutions formed by mutually replacing the above features with the technical features (but not limited to) having similar functions disclosed in the present disclosure.

[0132] In addition, although the operations are depicted in a particular order, this should not be construed as requiring that the operations be performed in the particular order shown or in a sequential order. In certain environments, multitasking and parallel processing may be advantageous. Similarly, although a number of specific implementation details are included in the above discussion, these should not be construed as limiting the scope of the present disclosure. Certain features described in the context of separate embodiments may also be implemented combinatorially in a single embodiment. Conversely, the various features described in the context of a single embodiment may also be implemented separately or in any suitable sub-combination in multiple embodiments.

[0133] Although the subject matter has been described in language specific to structural features and / or methodological act logic, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. On the contrary, the specific features and acts described above are merely example forms of implementing the claims. Regarding the device in the above embodiments, the specific manner in which each module performs operations has been described in detail in the embodiments related to the method, and will not be elaborated herein.

Claims

1. A safety report generation system, characterized in that: The system includes a multi-agent subsystem, a data engine module and a report generation module, wherein the multi-agent subsystem includes a master agent and N editing agents, N≥1; The master agent is used to: According to the security report generation instruction, determining at least one first editing agent from the N editing agents that participates in generating the current security report; For each of the at least one first editing agent, calling the first editing agent to obtain, through the data engine module, first data that matches the security report generation instruction and corresponds to the first editing agent, and obtaining chapter content generated by the first editing agent according to the first data; The report generation module is called to generate a security report according to the chapter content generated by each of the at least one first editing agents.

2. The system according to claim 1, characterized in that The master agent is used to generate, for each of the at least one first editing agent, a data query instruction corresponding to the first editing agent according to the security report generation instruction, and send the data query instruction to the first editing agent or the data engine module; The first editing agent is used to obtain the first data matching the data query instruction through the data engine module, and generate the chapter content according to the first data.

3. The system according to claim 2, characterized in that The first editing agent is further used to obtain first historical information, wherein the first historical information includes historical chapter contents generated by the first editing agent for the most recent M times and historical data referenced when generating the historical chapter contents, M≥1; The first editing agent is used to generate the chapter content according to the first data and the first historical information.

4. The system according to claim 3, characterized in that The first editing agent is further used to obtain first associated information of the first data from a first knowledge base; The first editing agent is used to input the first data, the first historical information, the first associated information and the first prompt word into a first large language model corresponding to the first editing agent to obtain the chapter content, wherein the first prompt word is used to guide the first large language model to generate the chapter content.

5. The system according to claim 2, characterized in that The master agent is further used to obtain second historical information, wherein the second historical information includes: historical data query instructions generated by the master agent for the last L times and corresponding to the first editing agent, and historical security report generation instructions received for the last L times, L≥1; The master agent is used to generate the data query instruction corresponding to the first editing agent according to the security report generation instruction and the second historical information.

6. The system according to claim 5, characterized in that The master agent is further used to obtain second associated information of the security report generation instruction from a second knowledge base; The master agent is used to input the security report generation instruction, the second historical information, the second associated information and the second prompt word corresponding to the first editing agent into a second large language model to obtain the data query instruction corresponding to the first editing agent, wherein the second prompt word is used to guide the second large language model to generate a data query instruction corresponding to the security report generation instruction.

7. The system according to claim 2, characterized in that The multi-agent subsystem also includes a query statement generation agent; The first editing agent or the data engine module is used to send the received data query instruction to the query statement generation agent; The query statement generating agent is used to generate a first query statement according to the received data query instruction, and send the first query statement to the data engine module; The data engine module is used to obtain a first query result according to the first query statement, perform multi-dimensional data analysis on the first query result to obtain the first data, and feed the first data back to the first editing agent.

8. The system according to claim 7, characterized in that The query statement generation agent is further used to obtain third historical information, wherein the third historical information includes the historical query statements generated by the query statement generation agent for the most recent K times and the historical data query instructions referenced when generating the historical query statements, K≥1; The query statement generating agent is used to generate the first query statement according to the data query instruction and the third historical information.

9. The system according to claim 8, characterized in that The query statement generating agent is further used to obtain third associated information of the data query instruction from a third knowledge base; The query statement generation agent is used to input the data query instruction, the third historical information, the third associated information and the third prompt word into a third language model to obtain the first query statement, wherein the third prompt word is used to guide the third language model to convert the data query instruction into the first query statement.

10. The system according to claim 2, characterized in that The first editing agent is further used to generate summary information of the chapter content and send the summary information to the master agent; The master agent is further configured to: generate a first instruction according to the summary information, wherein the first instruction is used to instruct the first editing agent of a next operation; and send the first instruction to the first editing agent or the data engine module when the first instruction instructs the first editing agent to continue editing the chapter content; The first editing agent is further used to obtain second data matching the first instruction through the data engine module, and continue to generate the chapter content according to the second data.

11. The system according to any one of claims 1 to 10, characterized in that: The N editing agents correspond one-to-one to N chapters, and the N chapters include at least one of security alert trends, alert type distribution, attacker analysis, security situation awareness, key security event analysis, vulnerability analysis, and alert classification interpretation.

12. A method for generating a safety report, characterized in that: The method comprises: According to the security report generation instruction, determining at least one first editing agent participating in the generation of the security report from N editing agents, where N≥1; For each of the at least one first editing agent, calling the first editing agent to obtain, through a data engine module, first data that matches the security report generation instruction and corresponds to the first editing agent, and obtaining chapter content generated by the first editing agent according to the first data; The report generation module is called to generate a security report according to the chapter content generated by each of the at least one first editing agents.

13. A computer readable medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processing device, the steps performed by the agent or module in the security report generation system of any one of claims 1 to 11 or the steps of the security report generation method of claim 12 are implemented.

14. An electronic device, characterized in that: include: a storage device having a computer program stored thereon; A processing device, used to execute the computer program in the storage device to implement the steps performed by the agent or module in the security report generation system of any one of claims 1 to 11 or the steps of the security report generation method of claim 12.

15. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps performed by the agent or module in the security report generation system of any one of claims 1 to 11 or the steps of the security report generation method of claim 12 are implemented.

Citation Information

Patent Citations

  • Risk assessment report generation method and device, equipment and storage medium

    CN110619568A

  • Offshore wind power structure monitoring report automatic reorganizing method and system

    CN118446184A

  • Power distribution network feasibility research report automatic generation method based on LDA probability model

    CN119047432A

  • Information security TARA report automatic generation system based on SQL database

    CN119202036A

  • LLM-based security report generation method, electronic equipment and storage medium

    CN119415678A