Safe operation method and device, terminal and computer readable storage medium
By decomposing the security operation task scenario and building a digital object service cluster, the problem of enterprises needing to invest a lot of labor costs in security operations is solved, and efficient and automatic security operation task processing is achieved.
Patent Information
- Application Number
- CN202411805288.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-09
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2044-12-09
AI Technical Summary
Enterprises need to invest more labor costs to support the safe operation of enterprise systems and equipment, especially in the face of automated attack weapons.
By decomposing the scene vertical task of the security operation task scenario, at least two vertical security models corresponding to the scene vertical task information are determined, and digital object services are generated based on these models. The digital object services are coordinated and correlated with the scene vertical task information to obtain a digital object service cluster, so as to use the digital object service cluster for security operations in the security operation task scenario.
It realizes efficient and automatic security operation task processing, improves the accuracy and efficiency of security operations, and reduces dependence on labor costs.
Smart Images

Figure CN120197175A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular, to a security operation method, device, terminal, and computer-readable storage medium. Background Art
[0002] In recent years, with the frequent occurrence of network attack events, enterprises have paid more attention to their security operation capabilities. Usually, the security operation of enterprises mainly relies on manual viewing of alarms, checking of alarms, and analysis. However, on the attack side, many organizations have used GPT (Generative Pre-Trained) models or dedicated tools to create automated attack weapons, forcing enterprises to invest a large amount of labor costs to support the security operation of enterprise systems and devices. Summary of the Invention
[0003] Embodiments of this application provide a security operation method, device, terminal, and computer-readable storage medium, which can solve the technical problem that enterprises need to invest more labor costs to support the security operation of enterprise systems and devices.
[0004] In a first aspect, embodiments of this application provide a security operation method, which includes:
[0005] Determine a security operation task scenario, and perform scenario vertical task decomposition processing on the security operation task scenario to obtain scenario vertical task information;
[0006] Determine at least two vertical security large models corresponding to the scenario vertical task information, generate digital object services corresponding to each vertical security large model based on the scenario vertical task information, and perform collaborative association processing on the digital object services through the scenario vertical task information to obtain a digital object service cluster;
[0007] Under the security operation task scenario, use the digital object service cluster for security operation.
[0008] Optionally, the performing scenario vertical task decomposition processing on the security operation task scenario to obtain scenario vertical task information includes:
[0009] Perform scenario vertical task splitting processing on the security operation task scenario to obtain at least two scenario vertical security tasks;
[0010] Determine the vertical task collaboration relationship between the at least two scenario vertical security tasks for the security operation task scenario;
[0011] Obtain scenario vertical task information based on the at least two scenario vertical security tasks and the vertical task collaboration relationship.
[0012] Optionally, determining at least two vertical security large models corresponding to the scenario vertical task information includes:
[0013] Input the scenario vertical security task in the scenario vertical task information into a vertical security label classification model, and output the vertical security label corresponding to the scenario vertical security task based on the vertical security label classification model;
[0014] Obtain a vertical security large model library, use the vertical security label to perform model matching in the vertical security large model library, obtain the vertical security large model matching the vertical security label, and determine the vertical security large model corresponding to the scenario vertical security task, so as to obtain at least two vertical security large models corresponding to the scenario vertical task information;
[0015] Among them, the vertical security label classification model is a model obtained by training a basic large model with sample scenario vertical security tasks and sample vertical security labels corresponding to the sample scenario vertical security tasks.
[0016] Optionally, generating digital object services corresponding to each vertical security large model based on the scenario vertical task information includes:
[0017] Obtain a virtual digital human for the vertical security large model, determine the input specification corresponding to the vertical security large model, determine input normalization configuration information based on the input specification, configure the input module of the virtual digital human using the input normalization configuration information and the scenario vertical security task, and generate an output module for the virtual digital human; determine the model interface configuration information of the vertical security large model, and configure the model call module of the virtual digital human using the model interface configuration information;
[0018] Perform module association processing on the input module, model call module, and output module in the virtual digital human to obtain a target virtual digital human, so that the model call module controls the vertical security large model to perform model processing on the data output by the input module, and controls the output module to obtain and output the model output data of the vertical security large model;
[0019] Determine the target virtual digital human corresponding to each vertical security large model, and obtain the digital object service corresponding to each vertical security large model based on the target virtual digital human.
[0020] Optionally, performing collaborative association processing on the digital object services through the scenario vertical task information to obtain a digital object service cluster includes:
[0021] Determine the vertical task collaboration relationship in the scenario vertical task information, and determine the service collaboration relationship between the digital object services based on the vertical task collaboration relationship; wherein, the service collaboration relationship includes service call information and service information interaction information;
[0022] Perform service association processing on the digital object services based on the service collaboration relationship to obtain a digital object service cluster.
[0023] Optionally, the performing service association processing on the digital object services based on the service collaboration relationship to obtain a digital object service cluster includes:
[0024] Determine the service call relationship configuration information between the digital object services based on the service call information;
[0025] Determine the service information interaction configuration information between the digital object services based on the service information interaction information;
[0026] Perform service association processing on the digital object services by using the service call relationship configuration information and the service information interaction configuration information to obtain a digital object service cluster.
[0027] Optionally, in the security operation task scenario, using the digital object service cluster for security operation includes:
[0028] Obtain the security operation tasks corresponding to the security operation task scenario, and determine the data to be processed corresponding to the security operation tasks;
[0029] Input the security operation tasks and the data to be processed into the digital object service cluster. For the security operation tasks, the data to be processed is collaboratively processed by the digital object services in the digital object service cluster, and a task processing result for the security operation tasks is output based on the digital object service cluster.
[0030] Optionally, the security operation task scenario includes a browser security operation task scenario.
[0031] Optionally, the performing collaborative association processing on the digital object services through the scenario vertical task information to obtain a digital object service cluster includes:
[0032] Perform collaborative association processing on the digital object services corresponding to all vertical security large models through the scenario vertical task information to obtain a digital object service cluster;
[0033] Among them, the digital object services corresponding to all vertical security large models include at least two of sample analysis services, alarm research and judgment services, attack traceability services, intelligence notice analysis services, and heavy protection situation analysis services.
[0034] Optionally, the method further includes:
[0035] When it is detected that the processing progress information of the vertical security large model for the scenario vertical security task changes, determining the processing progress information, obtaining the preset virtual digital human state corresponding to the processing progress information, and the digital human state image information corresponding to the preset virtual digital human state;
[0036] Performing an image update process on the current digital image of the target virtual digital human based on the digital human state image information.
[0037] In a second aspect, an embodiment of the present application provides a security operation device, and the device includes:
[0038] A scenario vertical task information determination module, adapted to determine a security operation task scenario, and perform a scenario vertical task decomposition process on the security operation task scenario to obtain scenario vertical task information;
[0039] A determination module, adapted to determine at least two vertical security large models corresponding to the scenario vertical task information, generate digital object services corresponding to each vertical security large model based on the scenario vertical task information, and perform collaborative association processing on the digital object services through the scenario vertical task information to obtain a digital object service cluster;
[0040] A security operation module, adapted to perform security operation by using the digital object service cluster in the security operation task scenario.
[0041] In a third aspect, an embodiment of the present application provides a terminal, and the terminal includes:
[0042] A processor; and
[0043] A memory arranged to store computer-executable instructions, and when the executable instructions are executed, the processor executes the method described in any one of the above.
[0044] In a third aspect, an embodiment of the present application provides a computer-readable storage medium, and the computer-readable storage medium stores one or more programs, and when the one or more programs are executed by a processor, the method described in any one of the above is implemented.
[0045] The beneficial effects brought by the technical solution provided in the embodiment of the present application at least include: by performing scenario vertical task decomposition processing on the security operation task scenario to obtain scenario vertical task information, thereby determining at least two vertical security large models corresponding to the scenario vertical task information, each vertical security large model is used to execute the security task of its corresponding scenario vertical task information, and then using the scenario vertical task information to generate digital object services corresponding to each vertical security large model, and performing collaborative association processing on the digital object services through the scenario vertical task information to obtain a digital object service cluster. Since each vertical security large model is used to execute the security task of its corresponding scenario vertical task information, the digital object service cluster obtained by the collaborative association processing can efficiently and automatically perform security operations on the security operation tasks in the security operation task scenario, and since each digital object service can call the corresponding vertical security large model to efficiently and accurately complete the tasks in the corresponding vertical security field under the security operation task, the accuracy and efficiency of security operations are improved. Thus, the technical problem that enterprises need to invest more labor costs to support the security operations of enterprise systems and equipment is solved. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those skilled in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0047] Figure 1 An exemplary system architecture diagram of a security operation method provided in an embodiment of the present application;
[0048] Figure 2 A flowchart of a security operation method provided in an embodiment of the present application;
[0049] Figure 3 A flowchart of a security operation method using a digital object service cluster provided in an embodiment of the present application;
[0050] Figure 4 A flowchart of a method for determining scenario vertical task information provided in an embodiment of the present application;
[0051] Figure 5 A flowchart of a method for determining at least two vertical security large models corresponding to scenario vertical task information provided in an embodiment of the present application;
[0052] Figure 6 A flowchart of a method for generating digital object services provided in an embodiment of the present application;
[0053] Figure 7 Schematic diagram of the image of a virtual digital human provided by an embodiment of the present application;
[0054] Figure 8 Schematic diagram of the process for determining a digital object service cluster provided by an embodiment of the present application;
[0055] Figure 9 Schematic diagram of the process for obtaining a digital object service cluster provided by an embodiment of the present application;
[0056] Figure 10 Schematic diagram of the interface of a digital object service cluster plugin embedded in a browser provided by an embodiment of the present application;
[0057] Figure 11 Schematic diagram of the process for image update provided by an embodiment of the present application;
[0058] Figure 12 Schematic diagram of the image change of the target virtual digital human for image update provided by an embodiment of the present application;
[0059] Figure 13 Schematic diagram of the interface of the target virtual digital human as an attack traceability digital human provided by an embodiment of the present application;
[0060] Figure 14 Schematic diagram of the structure of a security operation device provided by an embodiment of the present application;
[0061] Figure 15 Schematic diagram of the structure of a terminal provided by an embodiment of the present application. Detailed implementation manners
[0062] To make the features and advantages of the embodiments of the present application more obvious and understandable, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the embodiments of the present application, all other embodiments obtained by those skilled in the art without creative efforts fall within the protection scope of the embodiments of the present application.
[0063] In the related art, the security operation of the software and hardware of an enterprise often relies on manual work. However, information communication between people is inevitably prone to errors, and when multiple people perform security operations, the security operation intelligence data collected by each person is often relatively scattered and difficult to effectively summarize and analyze. However, on the attack side, many organizations have used GPT models or dedicated tools to create automated attack weapons, forcing enterprises to invest more human costs to support the security operation of enterprise systems and devices.
[0064] To solve the technical problems existing in the related art, an embodiment of the present application provides a security operation method, which includes: determining a security operation task scenario, performing scenario vertical task decomposition processing on the security operation task scenario to obtain scenario vertical task information; determining at least two vertical security large models corresponding to the scenario vertical task information, generating digital object services corresponding to each vertical security large model based on the scenario vertical task information, and performing collaborative association processing on the digital object services through the scenario vertical task information to obtain a digital object service cluster; and performing security operation by using the digital object service cluster in the security operation task scenario, thereby solving the technical problem that an enterprise needs to invest more labor costs to support the security operation of enterprise systems and devices.
[0065] Please refer to Figure 1 , Figure 1 which is an exemplary system architecture diagram of a security operation method provided by an embodiment of the present application.
[0066] As Figure 1 shown, the system architecture may include a terminal 101, a network 102, and a server 103. The network 102 is used to provide a medium for a communication link between the terminal 101 and the server 103. The network 102 may include various types of wired communication links or wireless communication links. For example, the wired communication links include optical fibers, twisted pairs, or coaxial cables, and the wireless communication links include Bluetooth communication links, Wireless-Fidelity (Wi-Fi) communication links, or microwave communication links, etc.
[0067] The terminal 101 may interact with the server 103 through the network 102 to receive messages from the server 103 or send messages to the server 103, or the terminal 101 may interact with the server 103 through the network 102 to further receive messages or data sent by other users to the server 103. The terminal 101 may be hardware or software. When the terminal 101 is hardware, it may be various electronic devices, including but not limited to smart watches, smart phones, tablet computers, laptop portable computers, and desktop computers, etc. When the terminal 101 is software, it may be installed in the above-listed electronic devices, and it may be implemented as multiple software or software modules (for example, used to provide distributed services), or it may be implemented as a single software or software module, which is not specifically limited herein.
[0068] Server 103 may be a business server that provides various services. It should be noted that server 103 may be hardware or software. When server 103 is hardware, it can be implemented as a distributed server cluster composed of multiple servers or as a single server. When server 103 is software, it can be implemented as multiple software or software modules (such as those used to provide distributed services) or as a single software or software module, and specific limitations are not made here.
[0069] In the embodiments of the present application, the terminal 101 may determine a secure operation task scenario, perform scenario vertical task decomposition processing on the secure operation task scenario to obtain scenario vertical task information; determine at least two vertical security large models corresponding to the scenario vertical task information, generate digital object services corresponding to each vertical security large model based on the scenario vertical task information, perform collaborative association processing on the digital object services through the scenario vertical task information to obtain a digital object service cluster; and perform secure operation using the digital object service cluster in the secure operation task scenario.
[0070] It should be understood that Figure 1 the numbers of terminals, networks, and servers in
[0071] Please refer to Figure 2 , Figure 2 which is a schematic flowchart of a secure operation method provided by the embodiments of the present application. The execution subject of the embodiments of the present application may be a terminal that executes the secure operation method, or a processor in the terminal that executes the secure operation method, or a secure operation service in the terminal that executes the secure operation method. For the convenience of description, the following takes the execution subject as the processor in the terminal as an example to introduce the specific execution process of the secure operation method.
[0072] The secure operation method includes:
[0073] S202: Determine a secure operation task scenario, and perform scenario vertical task decomposition processing on the secure operation task scenario to obtain scenario vertical task information.
[0074] Among them, the secure operation task scenario may be a scenario corresponding to the same type of secure operation task, and the task types of the secure operation tasks include, but are not limited to, threat monitoring and analysis task types, intelligence tracing task types, traffic analysis task types, and security report task types, etc.
[0075] When it is determined that the task type of the security operation task corresponding to the security operation task scenario is the threat monitoring and analysis task type, the security operation task under this security operation task scenario is used for sample analysis and alarm judgment for threats. After sample analysis, it is determined whether to generate an alarm signal based on the analysis results. After receiving the alarm signal, the alarm type, alarm reason, and the impact brought by the alarm threat are determined through analysis, judgment, and evaluation, and corresponding measures are taken.
[0076] When it is determined that the task type of the security operation task corresponding to the security operation task scenario is the intelligence tracing task type, the security operation task under this security operation task scenario is used for intelligence notification analysis and attack tracing for attacks. Intelligence notification analysis is used to integrate and analyze attack intelligence, so as to locate the attack behavior and then trace the attack behavior, such as the source country and specific region of the attack behavior.
[0077] When it is determined that the task type of the security operation task corresponding to the security operation task scenario is the traffic analysis task type, the security operation task under this security operation task scenario is used for analyzing daily traffic and answering security knowledge. Analyzing daily traffic includes, but is not limited to, accurately analyzing threats to the uploaded traffic packets or pcap files. Security knowledge answering can be used for automatically annotating the results of threat analysis and answering users' questions.
[0078] When it is determined that the task type of the security operation task corresponding to the security operation task scenario is the security report task type, the security operation task under this security operation task scenario is used for critical security protection situation analysis and security report generation. Here, critical security protection refers to security measures that adopt multiple safeguard mechanisms in the security field. By dispersing risks, strengthening supervision and control, improving emergency response, and other means, the security and integrity of the system and data are ensured. Critical security protection situation analysis is used to comprehensively evaluate network security protection, and security report generation is used to analyze and integrate the evaluation results to generate corresponding security reports.
[0079] After determining the security operation task scenario, perform scenario vertical task decomposition on the security operation task scenario, so as to perform scenario vertical task decomposition on the security operation tasks of the same type corresponding to this security operation task scenario. That is, the security operation tasks of the same type are vertically classified according to the vertical type of the data processing nodes corresponding to the data processing process. For example, when multiple data processing nodes are used to cooperate with each other to achieve data processing of the same fine-grained task item, these data processing nodes can be classified into the same vertical category at this time. Scenario vertical task decomposition is used to split the security operation tasks of the same type into scenario vertical security tasks, and each scenario vertical security task is used to achieve data processing of its corresponding task item.
[0080] After performing scenario vertical task decomposition on the security operation task scenario to obtain scenario vertical task information, the scenario vertical task information is used to represent the vertical task information corresponding to the same type of security operation tasks. The scenario vertical task information includes at least two scenario vertical security tasks corresponding to the security operation task scenario and the vertical task collaboration relationship between the at least two scenario vertical security tasks for the security operation task scenario.
[0081] S204: Determine at least two vertical security large models corresponding to the scenario vertical task information, generate digital object services corresponding to each vertical security large model based on the scenario vertical task information, and perform collaborative association processing on the digital object services through the scenario vertical task information to obtain a digital object service cluster.
[0082] Among them, after determining the scenario vertical task information, use the scenario vertical task information for model search to determine at least two vertical security large models corresponding to the scenario vertical task information. Since the scenario vertical task information is used to represent the vertical task information corresponding to the same type of security operation tasks, the scenario vertical task information used to represent the vertical task information corresponding to the same type of security operation tasks can be used to search for at least two vertical security large models corresponding to the security operation task scenario after scenario vertical task decomposition.
[0083] Each vertical security large model corresponds to a scenario vertical security task, and each vertical security large model is used to execute its corresponding scenario vertical security task.
[0084] After determining at least two vertical security large models corresponding to the scenario vertical task information, use the scenario vertical task information to construct corresponding digital object services for each vertical security large model. Each vertical security large model corresponds to a digital object service, and the digital object service can call the corresponding vertical security large model to execute the corresponding scenario vertical security task. When the digital object service is displayed to the user, it can be displayed in the image of a virtual digital human, and at the same time, it can also directly interact with the user in the image of a virtual digital human.
[0085] Since each vertical security large model corresponds to a digital object service, at least two vertical security large models can correspond to at least two digital object services. When the number of vertical security large models is N, the number of corresponding digital object services is also N. At this time, in order to complete the security operation tasks in the security operation task scenario, the digital object services can be collaboratively associated and processed using the scenario vertical task information to obtain a digital object service cluster. Each digital object service can call the corresponding vertical security large model to execute the corresponding scenario vertical security task, and the security operation tasks in the security operation task scenario include multiple scenario vertical security tasks. The multiple scenario vertical security tasks cooperate with each other to complete the security operation tasks. Therefore, the digital object services can be service-associated and processed using the vertical task collaboration relationship to obtain a digital object service cluster. The digital object service cluster can be a set composed of multiple digital object services corresponding to the scenario vertical task information, and the multiple digital object services cooperate with each other to complete the security operation tasks in the security operation task scenario.
[0086] Optionally, the digital object services are collaboratively associated and processed using the scenario vertical task information to obtain a digital object service cluster, including:
[0087] The digital object services corresponding to all vertical security large models are collaboratively associated and processed using the scenario vertical task information to obtain a digital object service cluster;
[0088] Among them, the digital object services corresponding to all vertical security large models include at least two of sample analysis service, alarm judgment service, attack traceability service, intelligence notice analysis service, and key protection situation analysis service.
[0089] When the security operation task is a threat monitoring and analysis task, the digital object services corresponding to all vertical security large models include sample analysis service and alarm judgment service; when the security operation task is an intelligence traceability task, at this time, the digital object services corresponding to all vertical security large models include attack traceability service and intelligence notice analysis service; when the security operation task is a system security operation task, at this time, the digital object services corresponding to all vertical security large models include sample analysis service, alarm judgment service, attack traceability service, intelligence notice analysis service, and key protection situation analysis service. Of course, in other embodiments, the digital object services corresponding to all vertical security large models include three, four, or five of sample analysis service, alarm judgment service, attack traceability service, intelligence notice analysis service, and key protection situation analysis service, which will not be elaborated here.
[0090] S206: In the security operation task scenario, use the digital object service cluster for security operation.
[0091] Among them, in the scenario of security operation tasks, security operation tasks are determined. The security operation tasks can be tasks input by users or tasks automatically generated by terminals. After that, the digital object service cluster is used to obtain the security operation tasks and perform data processing on the security operation tasks, so as to complete the security operation tasks through the cooperation of digital object services in the digital object service cluster.
[0092] Exemplarily, please refer to Figure 3 , Figure 3 which is a schematic flowchart of a method for security operation using a digital object service cluster provided by an embodiment of the present application. In S206, in the scenario of security operation tasks, using the digital object service cluster for security operation includes:
[0093] S302: Obtain the security operation tasks corresponding to the security operation task scenario, and determine the data to be processed corresponding to the security operation tasks.
[0094] Among them, when performing security operation, first obtain the security operation tasks corresponding to the security operation task scenario, and at the same time obtain the data to be processed corresponding to the security operation tasks. The data to be processed corresponding to the security operation tasks is the data that needs to be further analyzed and processed for this task. Commonly, when the task type of the security operation task is the intelligence tracing task type, the data to be processed for the security operation task at this time can be the domain name to be traced.
[0095] S304: Input the security operation tasks and the data to be processed into the digital object service cluster. For the security operation tasks, use the digital object services in the digital object service cluster to collaboratively process the data to be processed, and output the task processing results for the security operation tasks based on the digital object service cluster.
[0096] Among them, after determining the data to be processed corresponding to the security operation tasks, input the security operation tasks and the data to be processed into the digital object service cluster. The digital object service cluster includes a cluster input and a cluster output. The cluster input and the cluster output are docked with multiple digital object services according to the service collaboration relationship between the digital object services. Use the digital object services in the digital object service cluster to collaboratively process the data to be processed for the security operation tasks, so as to obtain the task processing results for the security operation tasks.
[0097] After the security operation tasks and the data to be processed are input into the digital object service cluster, the digital object services in the digital object service cluster call the corresponding vertical security large models to process them sequentially or collaboratively, so as to gradually complete the security operation tasks until the security operation tasks are finally completed, thereby obtaining the task processing results for the security operation tasks, and then realizing the automated security operation of the security operation tasks in the security operation task scenario. And because each digital object service can call the corresponding vertical security large model to efficiently and accurately complete the tasks in the corresponding vertical security field under the security operation tasks, the accuracy and efficiency of security operation are improved. At the same time, each digital object service can be presented to the user in a visual presentation manner, making the user experience better and facilitating the subsequent review, traceability, and verification of the data.
[0098] In the embodiment provided by the present application, the scenario vertical task information is obtained by performing scenario vertical task decomposition processing on the security operation task scenario, so as to determine at least two vertical security large models corresponding to the scenario vertical task information. Each vertical security large model is used to execute the security tasks corresponding to its corresponding scenario vertical task information. Then, the digital object services corresponding to each vertical security large model are generated by using the scenario vertical task information, and the digital object services are collaboratively associated and processed through the scenario vertical task information to obtain a digital object service cluster. Because each vertical security large model is used to execute the security tasks corresponding to its corresponding scenario vertical task information, the digital object service cluster obtained by the collaborative association processing can efficiently and automatically perform the security operation tasks in the security operation task scenario. And because each digital object service can call the corresponding vertical security large model to efficiently and accurately complete the tasks in the corresponding vertical security field under the security operation tasks, the accuracy and efficiency of security operation are improved. Thus, the technical problem that enterprises need to invest more labor costs to support the security operation of enterprise systems and equipment is solved.
[0099] Please refer to Figure 4 , Figure 4 which is a schematic flowchart of a process for determining scenario vertical task information provided by an embodiment of the present application. As Figure 4 shown, in S202, performing scenario vertical task decomposition processing on the security operation task scenario to obtain scenario vertical task information includes:
[0100] S402: Performing scenario vertical task splitting processing on the security operation task scenario to obtain at least two scenario vertical security tasks.
[0101] Among them, since the security operation task scenario is the scenario corresponding to the same type of security operation task, the scenario vertical task splitting process for the security operation task scenario can be understood as the vertical task splitting for the same type of security operation task, that is, dividing the same type of security operation task into at least two scenario vertical security tasks, so as to facilitate the determination of the general processing strategy for this type of security operation task.
[0102] Exemplarily, the security operation task corresponding to the security operation task scenario can be A, and the at least two scenario vertical security tasks obtained after the scenario vertical task splitting process for A are a1, a2, etc.
[0103] Specifically, when it is determined that the task type of the security operation task corresponding to the security operation task scenario is the threat monitoring and analysis task type, at this time, the vertical task splitting for this security operation task can obtain the sample analysis task and the alarm research and judgment task. For another example, when it is determined that the task type of the security operation task corresponding to the security operation task scenario is the intelligence traceability task type, at this time, the vertical task splitting for this security operation task can obtain the intelligence notice analysis task and the attack traceability task. For another example, when it is determined that the task type of the security operation task corresponding to the security operation task scenario is the traffic analysis task type, at this time, the vertical task splitting for this security operation task can obtain the daily traffic analysis task and the task of answering security knowledge. For another example, when it is determined that the task type of the security operation task corresponding to the security operation task scenario is the security report task type, at this time, the vertical task splitting for this security operation task can obtain the key protection situation analysis task and the security report generation task.
[0104] S404: Determine the vertical task collaboration relationship for the security operation task scenario among at least two scenario vertical security tasks.
[0105] Among them, since the scenario vertical security task is obtained after the scenario vertical task splitting of the security operation task scenario, in order to complete the scenario vertical security task, the scenario vertical security tasks need to collaborate with each other.
[0106] Therefore, the vertical task collaboration relationship for the security operation task scenario among at least two scenario vertical security tasks can be determined. The vertical task collaboration relationship includes but is not limited to the task connection relationship, the task data flow order, etc.
[0107] S406: Obtain the scenario vertical task information based on at least two scenario vertical security tasks and the vertical task collaboration relationship.
[0108] Among them, after determining at least two scenario vertical security tasks and the vertical task collaboration relationship, use at least two scenario vertical security tasks and the vertical task collaboration relationship to obtain the scenario vertical task information.
[0109] In the embodiments provided in this application, the security operation task scenario is split into at least two scenario vertical security tasks through scenario vertical task splitting processing. Then, the vertical task collaboration relationship between the at least two scenario vertical security tasks for the security operation task scenario is determined, so as to determine the scenario vertical task information corresponding to the security operation task scenario. By performing task vertical segmentation on the security operation task scenario, an efficient execution strategy is provided for automatically executing all operation task scenarios in the security operation task scenario.
[0110] Please refer to Figure 5 , Figure 5 which is a schematic flowchart of a process for determining at least two vertical security large models corresponding to scenario vertical task information provided by an embodiment of this application. As Figure 5 shown, determining at least two vertical security large models corresponding to scenario vertical task information in S204 includes:
[0111] S502: Input the scenario vertical security tasks in the scenario vertical task information into the vertical security label classification model, and based on the output of the vertical security label classification model, obtain the vertical security labels corresponding to the scenario vertical security tasks; among them, the vertical security label classification model is a model obtained by training a basic large model with sample scenario vertical security tasks and sample vertical security labels corresponding to the sample scenario vertical security tasks.
[0112] Among them, after determining the scenario vertical security tasks, input the scenario vertical security tasks into the vertical security label classification model. After the vertical security label classification model performs model processing on the scenario vertical security tasks, the vertical security labels corresponding to the scenario vertical security tasks are obtained. The vertical security labels can be set based on scenario requirements.
[0113] In order to obtain the vertical security label classification model, first obtain sample scenario vertical security tasks and sample vertical security labels corresponding to the sample scenario vertical security tasks, and at the same time determine the basic large model. Input the sample scenario vertical security tasks into the basic large model, and the basic large model outputs reference vertical security labels for the sample scenario vertical security tasks. Then, use the parameters corresponding to the reference vertical security labels and the sample vertical security labels to construct a loss function, determine the model loss value of the loss function corresponding to the reference vertical security labels and the sample vertical security labels, and then use the model loss value to adjust the model parameters of the basic large model. After multiple rounds of model training, until the basic large model is completed, the vertical security label classification model is obtained.
[0114] S504: Obtain a vertical security large model library, use the vertical security labels to perform model matching in the vertical security large model library, obtain the vertical security large models that match the vertical security labels, and determine the vertical security large models corresponding to the scenario vertical security tasks, so as to obtain at least two vertical security large models corresponding to the scenario vertical task information.
[0115] Among them, after determining the vertical security label corresponding to the scenario vertical security task, obtain the pre-established vertical security large model library, which includes multiple pre-generated vertical security large models. Different vertical security large models are used to execute different scenario vertical security tasks.
[0116] Each vertical security label can correspond to a vertical security large model. The vertical security large model is used to execute the scenario vertical security task corresponding to its corresponding vertical security label. The vertical security label and the vertical security large model are in one-to-one correspondence. Therefore, the vertical security large model matching the vertical security label can be obtained by performing model matching in the vertical security large model library using the vertical security label, so as to obtain at least two vertical security large models corresponding to at least two scenario vertical security tasks under the scenario vertical task information.
[0117] In the embodiment provided by the present application, the vertical security label classification model is used to determine the vertical security label corresponding to the scenario vertical security task, and then the vertical security large model corresponding to the vertical security label is matched from the vertical security large model library, so as to determine at least two vertical security large models corresponding to the scenario vertical task information, realizing the fast and accurate matching of at least two vertical security large models corresponding to the scenario vertical task information.
[0118] Please refer to Figure 6 , Figure 6 which is a schematic flow diagram of a digital object service generation provided by an embodiment of the present application. Please refer to Figure 7 , Figure 7 which is a schematic diagram of the image of a virtual digital human provided by an embodiment of the present application. As Figure 6 shown, generating digital object services corresponding to each vertical security large model based on the scenario vertical task information in S204 includes:
[0119] S602: Obtain a virtual digital human for the vertical security large model, determine the input specification corresponding to the vertical security large model, determine the input normalization configuration information based on the input specification, and configure the input module of the virtual digital human using the input normalization configuration information and the scenario vertical security task to generate the output module of the virtual digital human.
[0120] Among them, in order to distinguish the virtual digital humans of different vertical security large models, different vertical security large models can correspond to virtual digital humans with different images. As Figure 7 shown, Figure 7The virtual digital human corresponding to A is the digital human corresponding to the vertical security large model for performing sample analysis tasks. The virtual digital human corresponding to B is the digital human corresponding to the vertical security large model for performing alarm research and judgment tasks. The virtual digital human corresponding to C is the digital human corresponding to the vertical security large model for performing attack traceability tasks. The virtual digital human corresponding to D is the digital human corresponding to the vertical security large model for performing intelligence notice analysis tasks. The virtual digital human corresponding to E is the digital human corresponding to the vertical security large model for performing important guarantee situation analysis tasks.
[0121] After determining the virtual digital human corresponding to the vertical security large model, determine the input specifications corresponding to the vertical security large model. The input specifications corresponding to the vertical security large model include, but are not limited to, input format specifications, input length specifications, etc. Then, generate input normalization configuration information using the input specifications corresponding to the vertical security large model. The scenario vertical security task can be the scenario vertical task target. Then, configure the input module of the virtual digital human using the input normalization configuration information and the scenario vertical task target. The input module is used to normalize the data input into the input module and extract the data corresponding to the task target to meet the input specifications corresponding to the vertical security large model, thereby improving the learning and understanding efficiency and processing efficiency of the vertical security large model.
[0122] At the same time, an output module can also be configured for the virtual digital human. The output module can be a general output module.
[0123] S604: Determine the model interface configuration information of the vertical security large model, and configure the model call module of the virtual digital human using the model interface configuration information.
[0124] Among them, the model interface configuration information of the vertical security large model includes interface address, request method, request parameters, authentication information, etc. The interface address is the key information for the model to communicate with the external system, which specifies the specific location for data sending and receiving. The request method specifies the way to send requests to the interface. The request parameters are the format and type of the data sent to the model. The authentication information is used for security authentication during interface docking, such as authentication through tokens, etc. After obtaining the model interface configuration information of the vertical security large model, configure the model call module of the virtual digital human using the model interface configuration information so that the model call module can efficiently call the corresponding vertical security large model.
[0125] S606: Perform module association processing on the input module, model call module, and output module in the virtual digital human to obtain the target virtual digital human, so that the model call module controls the vertical security large model to perform model processing on the data output by the input module, and controls the output module to obtain and output the model output data of the vertical security large model.
[0126] Among them, after determining the input module, model call module, and output module in the virtual digital human, module association processing is performed on the input module, model call module, and output module so that the model call module controls the vertical security large model to perform model processing on the data output by the input module, and controls the output module of the target virtual digital human to obtain and output the model output data of the vertical security large model. After the module association processing of the input module, model call module, and output module in the virtual digital human, the virtual digital human is updated to the target virtual digital human, and the image of the target virtual digital human does not change compared with the corresponding virtual digital human.
[0127] S608: Determine the target virtual digital human corresponding to each vertical security large model, and obtain the digital object service corresponding to each vertical security large model based on the target virtual digital human.
[0128] Among them, after obtaining the target virtual digital human corresponding to each vertical security large model, the target virtual digital human corresponding to each vertical security large model is used as the target virtual digital human corresponding to the vertical security large model. At this time, the digital object service can receive data and call the corresponding vertical security large model to perform model processing on the data and output the data output by the model.
[0129] In the embodiment provided in the present application, digital object services corresponding to each vertical security large model are generated by using scenario vertical task information, so that the interaction with the vertical security large model can be visually displayed. At the same time, the configured input module, model call module, and output module can improve the learning and understanding efficiency and model processing efficiency of the vertical security large model for data, and improve the accuracy of model processing.
[0130] Please refer to Figure 8 , Figure 8 , which is a schematic flowchart of a process for determining a digital object service cluster provided by an embodiment of the present application. As Figure 8 shown, in S204, collaborative association processing is performed on the digital object service through scenario vertical task information to obtain a digital object service cluster, including:
[0131] S802: Determine the vertical task collaboration relationship in the scenario vertical task information, and determine the service collaboration relationship between digital object services based on the vertical task collaboration relationship; among them, the service collaboration relationship includes service call information and service information interaction information.
[0132] Among them, after obtaining the scenario vertical task information, the vertical task collaboration relationship in the scenario vertical task information is obtained. The vertical task collaboration relationship includes task connection relationships, task data flow directions, etc. Then, the service call information and service information interaction information between digital object services are determined by using the task connection relationships and task data flow directions, so as to determine the service collaboration relationship between digital object services.
[0133] S804: Perform service association processing on digital object services based on service collaboration relationships to obtain a digital object service cluster.
[0134] Among them, after determining the service collaboration relationships, use service invocation information to construct invocation relationships between digital object services, and use service information interaction information to construct information interaction relationships between digital object services, thereby obtaining a digital object service cluster.
[0135] In the embodiments provided in this application, use vertical task collaboration relationships to determine service collaboration relationships between digital object services, and then perform service association processing on digital object services using the service collaboration relationships to obtain a digital object service cluster.
[0136] Please refer to Figure 9 , Figure 9 which is a schematic flowchart of a process for obtaining a digital object service cluster provided in an embodiment of this application. As Figure 9 shown, in S804, perform service association processing on digital object services based on service collaboration relationships to obtain a digital object service cluster, including:
[0137] S902: Determine service invocation relationship configuration information between digital object services based on service invocation information.
[0138] Among them, after determining the service invocation information, use the service invocation information to construct invocation relationships between digital object services, and then use the invocation relationships to determine service invocation relationship configuration information between digital object services.
[0139] S904: Determine service information interaction configuration information between digital object services based on service information interaction information.
[0140] Among them, after determining the service information interaction information, use the service information interaction information to construct information interaction relationships between digital object services, and then use the information interaction relationships to determine service information interaction configuration information between digital object services.
[0141] S906: Perform service association processing on digital object services using service invocation relationship configuration information and service information interaction configuration information to obtain a digital object service cluster.
[0142] Among them, after determining the service invocation relationship configuration information and service information interaction configuration information, perform service association on each digital object service using the service invocation relationship configuration information and service information interaction configuration information, so that each digital object service can cooperate with each other to complete the corresponding security operation tasks in the security operation task scenario.
[0143] Please refer to Figure 10 , Figure 10The figure is a schematic diagram of an interface for embedding a digital object service cluster plugin in a browser provided by an embodiment of this application. As Figure 10 shown, when the security operation task scenario includes the browser security operation task scenario, at this time, the digital object service cluster can be embedded in the display interface of the browser in the form of a browser plugin (see the right area of Figure 10 ). At this time, the digital object service cluster can be displayed in the form of a unified digital human image, and at the same time, it can prompt "Hi, what can I do for you?". The user can click on the blank area on the right to enter. The digital object service cluster can deeply dock with the business system functions of the enterprise business scenario, provide services in aspects such as business analysis, security analysis, report analysis and summary, schedule management, and to-do tracking. In addition, it can also assist users in AI (Artificial Intelligence) search, document writing, PDF (Portable Document Format) parsing, media parsing, intelligent chat, etc.
[0144] Please refer to Figure 11 , Figure 11 which is a schematic diagram of a process for image update provided by an embodiment of this application. As Figure 11 shown, the method includes:
[0145] S1102: When it is detected that the processing progress information of the vertical security large model for the scenario vertical security task changes, determine the processing progress information, obtain the preset virtual digital human state corresponding to the processing progress information, and the digital human state image information corresponding to the preset virtual digital human state.
[0146] Among them, when the vertical security large model has not processed the data of the vertical security large model, its processing progress information is unprocessed, and at this time, the preset virtual digital human state is the standby state; when the vertical security large model is processing the data of the vertical security large model, its processing progress information is in processing, and at this time, the preset virtual digital human state is the thinking and analyzing state. Different processing progress information can correspond to different preset virtual digital human states at this time, and each preset virtual digital human state corresponds to a digital human state image information. Based on the digital human state image information, the corresponding digital human image can be displayed. When the processing progress information changes, obtain the current processing progress information and then determine the digital human state image information.
[0147] S1104: Based on the digital human state image information, perform image update processing on the current digital image of the target virtual digital human.
[0148] Among them, after determining the state image information of the digital human, the corresponding digital human image is determined using the state image information of the digital human. Then, the current digital image of the target virtual digital human is updated using the digital human image corresponding to the state image information of the digital human, so that the user can quickly obtain the processing progress information of the vertical security large model for the vertical security tasks of the scenario based on the image of the digital human.
[0149] Please refer to Figure 12 , Figure 12 which is a schematic diagram of the image change of a target virtual digital human for image update provided by an embodiment of this application. As Figure 12 shown, exemplarily, when it is detected that the processing progress information of the vertical security large model for the vertical security tasks of the scenario changes, and the processing progress information changes from unprocessed to in-process, at this time, the preset virtual digital human state changes from the standby state to the thinking and analyzing state.
[0150] Please refer to Figure 13 , Figure 13 which is a schematic diagram of the interface of a target virtual digital human being an attack tracing digital human provided by an embodiment of this application. Of course, in other embodiments, when the target virtual digital human is the digital human corresponding to the vertical security large model for the attack tracing task, that is, the attack tracing digital human, when the processing progress information of the vertical security large model is in-process, at this time, the attack tracing digital human can also display the current specific progress through text. Figure 13 In
[0151] Please refer to Figure 14 , Figure 14 which is a schematic diagram of the structure of a security operation device provided by an embodiment of this application. As Figure 14 shown, the security operation device 1400 includes:
[0152] A scene vertical task information determination module 1410, adapted to determine the security operation task scenario, and perform scene vertical task decomposition processing on the security operation task scenario to obtain scene vertical task information;
[0153] A determination module 1420, adapted to determine at least two vertical security large models corresponding to the scene vertical task information, generate digital object services corresponding to each vertical security large model based on the scene vertical task information, and perform collaborative association processing on the digital object services through the scene vertical task information to obtain a digital object service cluster;
[0154] The security operation module 1430 is suitable for performing security operations by using a digital object service cluster in a security operation task scenario.
[0155] Optionally, the scenario vertical task information determination module 1410 includes:
[0156] A splitting unit, suitable for performing scenario vertical task splitting processing on the security operation task scenario to obtain at least two scenario vertical security tasks;
[0157] A determination unit, suitable for determining the vertical task collaboration relationship between at least two scenario vertical security tasks for the security operation task scenario;
[0158] A scenario vertical task information acquisition unit, suitable for obtaining scenario vertical task information based on at least two scenario vertical security tasks and the vertical task collaboration relationship.
[0159] Optionally, the determination module 1420 includes:
[0160] A model processing unit, suitable for inputting the scenario vertical security tasks in the scenario vertical task information into a vertical security label classification model, and outputting the vertical security labels corresponding to the scenario vertical security tasks based on the vertical security label classification model;
[0161] A matching unit, suitable for obtaining a vertical security large model library, performing model matching in the vertical security large model library by using the vertical security labels, obtaining the vertical security large models matching the vertical security labels, and determining the vertical security large models corresponding to the scenario vertical security tasks, so as to obtain at least two vertical security large models corresponding to the scenario vertical task information;
[0162] Among them, the vertical security label classification model is a model obtained by training a basic large model with sample scenario vertical security tasks and sample vertical security labels corresponding to the sample scenario vertical security tasks.
[0163] Optionally, the determination module 1420 includes:
[0164] An input and output module determination unit, suitable for obtaining a virtual digital human for the vertical security large model, determining the input specification corresponding to the vertical security large model, determining the input normalization configuration information based on the input specification, configuring the input module of the virtual digital human by using the input normalization configuration information and the scenario vertical security task, and generating the output module of the virtual digital human;
[0165] A model call module determination unit, suitable for determining the model interface configuration information of the vertical security large model, and configuring the model call module of the virtual digital human by using the model interface configuration information;
[0166] The association unit is adapted to perform module association processing on the input module, model call module, and output module in the virtual digital human to obtain the target virtual digital human, so that the model call module controls the vertical security large model to perform model processing on the data output by the input module, and controls the output module to obtain and output the model output data of the vertical security large model;
[0167] The digital object service determination unit is adapted to determine the target virtual digital human corresponding to each vertical security large model, and obtain the digital object service corresponding to each vertical security large model based on the target virtual digital human.
[0168] Optionally, the determination module 1420 includes:
[0169] The service collaboration relationship determination unit is adapted to determine the vertical task collaboration relationship in the scenario vertical task information, and determine the service collaboration relationship between digital object services based on the vertical task collaboration relationship; wherein, the service collaboration relationship includes service call information and service information interaction information;
[0170] The digital object service cluster determination unit is adapted to perform service association processing on digital object services based on the service collaboration relationship to obtain a digital object service cluster.
[0171] Optionally, the digital object service cluster determination unit includes:
[0172] The first determination subunit is adapted to determine the service call relationship configuration information between digital object services based on the service call information;
[0173] The second determination subunit is adapted to determine the service information interaction configuration information between digital object services based on the service information interaction information;
[0174] The digital object service cluster determination subunit is adapted to perform service association processing on digital object services by using the service call relationship configuration information and the service information interaction configuration information to obtain a digital object service cluster.
[0175] Optionally, the security operation module 1430 includes:
[0176] The data to be processed determination unit is adapted to obtain the security operation task corresponding to the security operation task scenario, and determine the data to be processed corresponding to the security operation task;
[0177] The output unit is adapted to input the security operation task and the data to be processed into the digital object service cluster, and for the security operation task, perform collaborative processing on the data to be processed through the digital object services in the digital object service cluster, and output the task processing result for the security operation task based on the digital object service cluster.
[0178] Optionally, the security operation task scenario includes a browser security operation task scenario.
[0179] Optionally, the determination module 1420 is further adapted to:
[0180] Perform collaborative association processing on the digital object services corresponding to all vertical security large models through scenario vertical task information to obtain a digital object service cluster;
[0181] Among them, the digital object services corresponding to all vertical security large models include at least two of sample analysis service, alarm research and judgment service, attack traceability service, intelligence notice analysis service, and heavy protection situation analysis service.
[0182] Optionally, the security operation device 1400 further includes:
[0183] A detection module, adapted to determine the processing progress information, obtain the preset virtual digital human state corresponding to the processing progress information, and the digital human state image information corresponding to the preset virtual digital human state when detecting a change in the processing progress information of the vertical security large model for the scenario vertical security task;
[0184] An update module, adapted to perform image update processing on the current digital image of the target virtual digital human based on the digital human state image information.
[0185] In an embodiment of the present application, there is also provided a computer-readable storage medium storing one or more programs, which when executed by a processor, implement the method described in any one of the above.
[0186] Please refer to Figure 15 , Figure 15 which is a schematic structural diagram of a terminal provided in an embodiment of the present application. As Figure 15 shown, the terminal 1500 may include: at least one processor 1501, at least one network interface 1504, a user interface 1503, a memory 1505, and at least one communication bus 1502.
[0187] Among them, the communication bus 1502 is used to implement connection communication between these components.
[0188] Among them, the user interface 1503 may include a display screen (Display) and a camera (Camera). Optionally, the user interface 1503 may further include a standard wired interface and a wireless interface.
[0189] Among them, the network interface 1504 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface).
[0190] Among them, the processor 1501 may include one or more processing cores. The processor 1501 connects various parts within the entire terminal 1500 through various interfaces and lines. By running or executing instructions, programs, code sets, or instruction sets stored in the memory 1505, and by calling the data stored in the memory 1505, it performs various functions of the terminal 1500 and processes data. Optionally, the processor 1501 may be implemented in at least one hardware form of digital signal processing (DSP), field-programmable gate array (FPGA), or programmable logic array (PLA). The processor 1501 may integrate a combination of one or several of a central processing unit (CPU), a graphics processing unit (GPU), and a modem, etc. Among them, the CPU mainly processes the operating system, user interface, application programs, etc.; the GPU is responsible for rendering and drawing the content to be displayed on the display screen; the modem is used to process wireless communications. It can be understood that the above-mentioned modem may not be integrated into the processor 1501 and may be implemented separately by a single chip.
[0191] Among them, the memory 1505 may include random access memory (RAM) and may also include read-only memory (ROM). Optionally, the memory 1505 includes a non-transitory computer-readable storage medium. The memory 1505 can be used to store instructions, programs, code, code sets, or instruction sets. The memory 1505 may include a program storage area and a data storage area. Among them, the program storage area may store instructions for implementing the operating system, instructions for at least one function (such as touch function, sound playback function, image playback function, etc.), instructions for implementing the above-mentioned various method embodiments, etc.; the data storage area may store the data involved in the above-mentioned various method embodiments. Optionally, the memory 1505 may also be at least one storage device located far from the aforementioned processor 1501. As Figure 15 shown, the memory 1505, as a computer storage medium, may include an operating system, a network communication module, a user interface module, and a security operation program.
[0192] In Figure 15In the terminal 1500 shown, the user interface 1503 is mainly used to provide an interface for the user to input data and obtain the data input by the user; while the processor 1501 can be used to call the security operation program stored in the memory 1505 and specifically perform the following operations:
[0193] Determine the security operation task scenario, and perform scenario vertical task decomposition processing on the security operation task scenario to obtain scenario vertical task information;
[0194] Determine at least two vertical security large models corresponding to the scenario vertical task information, generate digital object services corresponding to each vertical security large model based on the scenario vertical task information, and perform collaborative association processing on the digital object services through the scenario vertical task information to obtain a digital object service cluster;
[0195] In the security operation task scenario, use the digital object service cluster for security operation.
[0196] Optionally, when the processor 1501 performs scenario vertical task decomposition processing on the security operation task scenario to obtain scenario vertical task information, it specifically performs:
[0197] Perform scenario vertical task splitting processing on the security operation task scenario to obtain at least two scenario vertical security tasks;
[0198] Determine the vertical task collaboration relationship between at least two scenario vertical security tasks for the security operation task scenario;
[0199] Obtain scenario vertical task information based on at least two scenario vertical security tasks and the vertical task collaboration relationship.
[0200] Optionally, when the processor 1501 determines at least two vertical security large models corresponding to the scenario vertical task information, it specifically performs:
[0201] Input the scenario vertical security tasks in the scenario vertical task information into the vertical security label classification model, and output the vertical security labels corresponding to the scenario vertical security tasks based on the vertical security label classification model;
[0202] Obtain the vertical security large model library, use the vertical security labels to perform model matching in the vertical security large model library, obtain the vertical security large models matching the vertical security labels, and determine the vertical security large models corresponding to the scenario vertical security tasks, so as to obtain at least two vertical security large models corresponding to the scenario vertical task information;
[0203] Among them, the vertical security label classification model is a model obtained by training the basic large model with sample scenario vertical security tasks and sample vertical security labels corresponding to the sample scenario vertical security tasks.
[0204] Optionally, when the processor 1501 executes to generate digital object services corresponding to each vertical security large model based on scenario vertical task information, it specifically executes:
[0205] Obtain a virtual digital human for the vertical security large model, determine the input specification corresponding to the vertical security large model, determine the input normalization configuration information based on the input specification, use the input normalization configuration information and the scenario vertical security task to configure the input module of the virtual digital human, and generate the output module of the virtual digital human; determine the model interface configuration information of the vertical security large model, and use the model interface configuration information to configure the model call module of the virtual digital human;
[0206] Perform module association processing on the input module, model call module, and output module in the virtual digital human to obtain a target virtual digital human, so that the model call module controls the vertical security large model to perform model processing on the data output by the input module, and controls the output module to obtain and output the model output data of the vertical security large model;
[0207] Determine the target virtual digital human corresponding to each vertical security large model, and obtain the digital object service corresponding to each vertical security large model based on the target virtual digital human.
[0208] Optionally, when the processor 1501 executes to perform collaborative association processing on digital object services through scenario vertical task information to obtain a digital object service cluster, it specifically executes:
[0209] Determine the vertical task collaboration relationship in the scenario vertical task information, and determine the service collaboration relationship between digital object services based on the vertical task collaboration relationship; among them, the service collaboration relationship includes service call information and service information interaction information;
[0210] Perform service association processing on digital object services based on the service collaboration relationship to obtain a digital object service cluster.
[0211] Optionally, when the processor 1501 executes to perform service association processing on digital object services based on the service collaboration relationship to obtain a digital object service cluster, it specifically executes:
[0212] Determine the service call relationship configuration information between digital object services based on the service call information;
[0213] Determine the service information interaction configuration information between digital object services based on the service information interaction information;
[0214] Perform service association processing on digital object services using the service call relationship configuration information and the service information interaction configuration information to obtain a digital object service cluster.
[0215] Optionally, when the processor 1501 executes security operations using the digital object service cluster in a security operation task scenario, it specifically executes:
[0216] Obtain the security operation tasks corresponding to the security operation task scenario, and determine the data to be processed corresponding to the security operation tasks;
[0217] Input the security operation tasks and the data to be processed into the digital object service cluster. For the security operation tasks, the data to be processed is collaboratively processed through the digital object services in the digital object service cluster, and a task processing result for the security operation tasks is output based on the digital object service cluster.
[0218] Optionally, the security operation task scenario includes a browser security operation task scenario.
[0219] Optionally, the processor 1501 executes collaborative association processing on the digital object services through the scenario vertical task information, and the digital object service cluster processor 1501 executes
[0220] Perform collaborative association processing on the digital object services corresponding to all vertical security large models through the scenario vertical task information to obtain a digital object service cluster;
[0221] Among them, the digital object services corresponding to all vertical security large models include at least two of sample analysis services, alarm research and judgment services, attack traceability services, intelligence notice analysis services, and key protection situation analysis services.
[0222] Optionally, the processor 1501 is also suitable for executing
[0223] When it is detected that the processing progress information of the vertical security large model for the scenario vertical security task changes, determine the processing progress information, obtain the preset virtual digital human state corresponding to the processing progress information, and the digital human state image information corresponding to the preset virtual digital human state;
[0224] Perform image update processing on the current digital image of the target virtual digital human based on the digital human state image information.
[0225] In several embodiments provided in the embodiments of the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only illustrative. For example, the division of the modules is only a logical function division. In actual implementation, there may be other division methods. For example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point, the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces, and the indirect coupling or communication connection of the device or module can be in an electrical, mechanical or other form.
[0226] The module described as a separation component may or may not be physically separated. The component shown as a module may or may not be a physical module, that is, it may be located in one place or distributed across multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0227] In addition, in each embodiment of this application, each functional module can be integrated into one processing module, or each module can exist physically alone, or two or more modules can be integrated into one module. The above-mentioned integrated modules can be implemented in the form of hardware or in the form of software functional modules.
[0228] If the above-mentioned integrated module is implemented in the form of a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiments of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the embodiments of this application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.
[0229] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the embodiments of this application are not limited by the described action sequence, because according to the embodiments of this application, some steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the embodiments of this application.
[0230] In the above embodiments, the descriptions of each embodiment have their own focuses. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0231] The above is the description of a security operation method, device, terminal, and computer-readable storage medium provided by the embodiments of the present application. For those skilled in the art, according to the idea of the embodiments of the present application, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the embodiments of the present application.
Claims
1. A security operation method, wherein: The method comprises: Determine a safety operation task scenario, and perform scenario vertical task decomposition processing on the safety operation task scenario to obtain scenario vertical task information; Determine at least two vertical security big models corresponding to the scene vertical task information, generate digital object services corresponding to each vertical security big model based on the scene vertical task information, and perform collaborative association processing on the digital object services through the scene vertical task information to obtain a digital object service cluster; In the security operation task scenario, the digital object service cluster is used to perform security operations.
2. The method according to claim 1, wherein: The step of performing scene vertical task decomposition processing on the safety operation task scene to obtain scene vertical task information includes: Splitting the security operation task scenario into vertical tasks to obtain at least two vertical security tasks; Determine a vertical task collaboration relationship between the at least two scenario vertical security tasks for the security operation task scenario; The scene vertical task information is obtained based on the at least two scene vertical safety tasks and the collaborative relationship between the vertical tasks.
3. The method according to claim 2, wherein: The determining of at least two vertical safety macro models corresponding to the scene vertical task information includes: Inputting the scene vertical safety task in the scene vertical task information into the vertical safety label classification model, and outputting the vertical safety label corresponding to the scene vertical safety task based on the vertical safety label classification model; Obtain a vertical security big model library, use the vertical security label to perform model matching in the vertical security big model library, obtain the vertical security big model matched by the vertical security label, determine the vertical security big model corresponding to the scene vertical security task, and obtain at least two vertical security big models corresponding to the scene vertical task information; Among them, the vertical safety label classification model is a model obtained after the basic large model is trained with the sample scenario vertical safety tasks and the model of the sample vertical safety labels corresponding to the sample scenario vertical safety tasks.
4. The method according to claim 2, wherein: The generating of digital object services corresponding to each vertical security macro model based on the scene vertical task information includes: Obtain a virtual digital human for the vertical safety big model, determine the input specification corresponding to the vertical safety big model, determine input normalization configuration information based on the input specification, configure the input module of the virtual digital human using the input normalization configuration information and the vertical safety task of the scene, and generate the output module of the virtual digital human; determine the model interface configuration information of the vertical safety big model, and configure the model calling module of the virtual digital human using the model interface configuration information; Performing module association processing on the input module, model calling module and output module in the virtual digital human to obtain a target virtual digital human, so that the model calling module controls the vertical safety big model to perform model processing on the data output by the input module, and controls the output module to obtain and output the model output data of the vertical safety big model; Determine the target virtual digital human corresponding to each vertical security big model, and obtain the digital object service corresponding to each vertical security big model based on the target virtual digital human.
5. The method according to claim 2, wherein: The step of performing collaborative association processing on the digital object service through the scene vertical task information to obtain a digital object service cluster includes: Determine the vertical task collaboration relationship in the scene vertical task information, and determine the service collaboration relationship between the digital object services based on the vertical task collaboration relationship; wherein the service collaboration relationship includes service call information and service information interaction information; The digital object services are subjected to service association processing based on the service collaboration relationship to obtain a digital object service cluster.
6. The method according to claim 5, wherein: The performing service association processing on the digital object service based on the service collaboration relationship to obtain a digital object service cluster includes: Determine the service calling relationship configuration information between the digital object services based on the service calling information; Determining service information interaction configuration information between the digital object services based on the service information interaction information; The digital object service is subjected to service association processing by using the service call relationship configuration information and the service information interaction configuration information to obtain a digital object service cluster.
7. The method according to claim 1, wherein: In the security operation task scenario, using the digital object service cluster to perform security operations includes: Obtaining a security operation task corresponding to the security operation task scenario, and determining the to-be-processed data corresponding to the security operation task; The security operation task and the data to be processed are input into the digital object service cluster. For the security operation task, the data to be processed are collaboratively processed by the digital object service in the digital object service cluster, and the task processing result for the security operation task is output based on the digital object service cluster.
8. A security operation device, wherein: The device comprises: A scenario vertical task information determination module is adapted to determine a safe operation task scenario, and to perform scenario vertical task decomposition processing on the safe operation task scenario to obtain scenario vertical task information; A determination module, adapted to determine at least two vertical security macro models corresponding to the scene vertical task information, generate digital object services corresponding to each vertical security macro model based on the scene vertical task information, and perform collaborative association processing on the digital object services through the scene vertical task information to obtain a digital object service cluster; The security operation module is suitable for performing security operations using the digital object service cluster in the security operation task scenario.
9. A terminal, wherein: The terminal includes: Processor; and A memory arranged to store computer executable instructions which, when executed, cause the processor to perform a method according to any one of claims 1 to 7.
10. A computer-readable storage medium, wherein: The computer-readable storage medium stores one or more programs, which, when executed by a processor, implement the method of any one of claims 1 to 7.
Citation Information
Patent Citations
Service configuration method, device and equipment and storage medium
CN110166560A
Business model monitoring method and device and electronic equipment
CN113704058A
Cross-target-range task cooperation implementation method, system and device and storage medium
CN116684301A
Service recommendation method, electronic equipment and readable storage medium
CN117093770A
Digital factory creating system based on domain model
CN117390831A