Security operation method and device, terminal and computer readable storage medium

By decomposing and model-matching security operation task scenarios, a digital object service cluster is generated, which solves the problem of high human resource costs in enterprise security operations and achieves efficient and automated security operations.

CN120197175BActive Publication Date: 2025-12-16BEIJING HONGTENG INTELLIGENT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411805288.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-09
Publication Date
2025-12-16
Estimated Expiration
2044-12-09

AI Technical Summary

Technical Problem

Enterprises need to invest a lot of human resources to support the secure operation of systems and equipment. Existing technologies rely on manual review and analysis of alarms, making it difficult to efficiently collect security operation intelligence data.

Method used

By decomposing security operation tasks into scenario-specific tasks, determining the vertical security model and generating digital object services, and using the digital object service cluster for collaborative and related processing, automated security operations can be achieved.

Benefits of technology

It improved the accuracy and efficiency of safety operations, reduced labor costs, and enabled automated and efficient collaborative processing of safety operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120197175B_ABST
    Figure CN120197175B_ABST
Patent Text Reader

Abstract

The embodiment of the application discloses a kind of safe operation method, device, terminal and computer readable storage medium, the method includes: the scene vertical task decomposition processing of safe operation task scene is obtained scene vertical task information;Determine at least two vertical security large models corresponding to scene vertical task information, generate digital object service corresponding to each vertical security large model based on scene vertical task information, through scene vertical task information, the cooperative association processing of digital object service is carried out, and digital object service cluster is obtained;In the safe operation task scene, using digital object service cluster carries out safe operation.Each digital object service can call corresponding vertical security large model to complete the task of corresponding vertical security field under safe operation task, so as to improve the accuracy of safe operation and the efficiency of safe operation. Thus, the technical problem that enterprises need to invest more manpower cost to support the safe operation of enterprise system and equipment is solved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of computers, and in particular to a secure operation method and device, a terminal, and a computer readable storage medium. BACKGROUND

[0002] In recent years, with the frequent occurrence of network attack events, enterprises have paid more and more attention to security operation capabilities. Usually, the security operation of an enterprise mainly relies on manual alarm checking, alarm analysis, and the like. However, on the attack side, many organizations have created automated attack weapons using GPT (Generative Pre-Trained) models or special tools, so that enterprises need to invest a large amount of human resources to support the security operation of enterprise systems and devices. SUMMARY

[0003] The embodiments of the present application provide a secure operation method, device, terminal, and computer readable storage medium, which can solve the technical problem that enterprises need to invest more human resources to support the security operation of enterprise systems and devices.

[0004] In a first aspect, the embodiments of the present application provide a secure operation method, which comprises:

[0005] determining a security operation task scenario, and performing scene vertical task decomposition processing on the security operation task scenario to obtain scene vertical task information;

[0006] determining at least two vertical security large models corresponding to the scene vertical task information, generating a digital object service corresponding to each vertical security large model based on the scene vertical task information, and performing collaborative association processing on the digital object services based on the scene vertical task information to obtain a digital object service cluster;

[0007] performing security operation under the security operation task scenario by using the digital object service cluster.

[0008] Optionally, the scene vertical task information obtained by performing scene vertical task decomposition processing on the security operation task scenario comprises:

[0009] performing scene vertical task decomposition processing on the security operation task scenario to obtain at least two scene vertical security tasks;

[0010] determining a vertical task collaboration relationship between the at least two scene vertical security tasks for the security operation task scenario;

[0011] obtaining scene vertical task information based on the at least two scene vertical security tasks and the vertical task collaboration relationship.

[0012] Optionally, the determining the at least two vertical safety large models corresponding to the scene vertical task information comprises:

[0013] inputting a scene vertical safety task in the scene vertical task information into a vertical safety label classification model, and outputting a vertical safety label corresponding to the scene vertical safety task based on the vertical safety label classification model;

[0014] obtaining a vertical safety large model library, performing model matching in the vertical safety large model library by using the vertical safety label, obtaining a vertical safety large model matched by the vertical safety label, determining a vertical safety large model corresponding to the scene vertical safety task, and obtaining the at least two vertical safety large models corresponding to the scene vertical task information;

[0015] The vertical safety label classification model is a model obtained by performing model training on a basic large model by using a sample scene vertical safety task and a sample vertical safety label corresponding to the sample scene vertical safety task.

[0016] Optionally, the generating a digital object service corresponding to each vertical safety large model based on the scene vertical task information comprises:

[0017] obtaining a virtual digital person corresponding to the vertical safety large model, determining input specification corresponding to the vertical safety large model, determining input normalization configuration information based on the input specification, configuring an input module of the virtual digital person by using the input normalization configuration information and the scene vertical safety task, generating an output module of the virtual digital person, determining model interface configuration information of the vertical safety large model, and configuring a model calling module of the virtual digital person by using the model interface configuration information;

[0018] performing module association processing on the input module, the model calling module and the output module in the virtual digital person to obtain a target virtual digital person, so that the model calling module controls the vertical safety large model to perform model processing on data output by the input module, and controls the output module to obtain and output model output data of the vertical safety large model;

[0019] determining a target virtual digital person corresponding to each vertical safety large model, and obtaining a digital object service corresponding to each vertical safety large model based on the target virtual digital person.

[0020] Optionally, the performing collaborative association processing on the digital object service by using the scene vertical task information to obtain a digital object service cluster comprises:

[0021] determine a vertical task coordination relationship in the vertical task information of the scene, determine a service coordination relationship between the digital object services based on the vertical task coordination relationship; wherein the service coordination relationship comprises service calling information and service information interaction information;

[0022] perform service association processing on the digital object services based on the service coordination relationship, to obtain a digital object service cluster.

[0023] Optionally, the service association processing on the digital object services based on the service coordination relationship, to obtain a digital object service cluster, comprises:

[0024] determine service calling relationship configuration information between the digital object services based on the service calling information;

[0025] determine service information interaction configuration information between the digital object services based on the service information interaction information;

[0026] perform service association processing on the digital object services based on the service calling relationship configuration information and the service information interaction configuration information, to obtain a digital object service cluster.

[0027] Optionally, the utilization of the digital object service cluster for security operation in the security operation task scene comprises:

[0028] obtain a security operation task corresponding to the security operation task scene, and determine to-be-processed data corresponding to the security operation task;

[0029] input the security operation task and the to-be-processed data into the digital object service cluster, perform coordinated processing on the to-be-processed data by the digital object services in the digital object service cluster for the security operation task, and output a task processing result for the security operation task based on the digital object service cluster.

[0030] Optionally, the security operation task scene comprises a browser security operation task scene.

[0031] Optionally, the coordinated association processing on the digital object services based on the vertical task information of the scene comprises:

[0032] perform coordinated association processing on digital object services corresponding to all vertical security large models based on the vertical task information of the scene, to obtain a digital object service cluster;

[0033] wherein the digital object services corresponding to all vertical security large models comprise at least two of a sample analysis service, an alarm research and judgment service, an attack traceability service, an intelligence notice analysis service, and a heavy protection situation analysis service.

[0034] Optionally, the method further comprises:

[0035] When it is detected that the processing progress information of the vertical safety large model for the scene vertical safety task changes, determining the processing progress information, obtaining a preset virtual digital human state corresponding to the processing progress information, and digital human state image information corresponding to the preset virtual digital human state;

[0036] Based on the digital human state image information, performing image updating processing on the current digital image of the target virtual digital human.

[0037] In a second aspect, an embodiment of the present application provides a safety operation device, the device comprising:

[0038] A scene vertical task information determination module is adapted to determine a safety operation task scene, and perform scene vertical task decomposition processing on the safety operation task scene to obtain scene vertical task information.

[0039] A determination module is adapted to determine at least two vertical safety large models corresponding to the scene vertical task information, generate digital object services corresponding to each vertical safety large model based on the scene vertical task information, and perform collaborative association processing on the digital object services through the scene vertical task information to obtain a digital object service cluster.

[0040] A safety operation module is adapted to utilize the digital object service cluster to perform safety operation in the safety operation task scene.

[0041] In a third aspect, an embodiment of the present application provides a terminal, the terminal comprising:

[0042] A processor; and

[0043] A memory arranged to store computer executable instructions that, when executed, cause the processor to perform any of the above methods.

[0044] In a third aspect, an embodiment of the present application provides a computer readable storage medium, the computer readable storage medium storing one or more programs, the one or more programs, when executed by a processor, implementing any of the above methods.

[0045] The technical scheme provided by the embodiments of the present application has at least the following beneficial effects: the scene vertical task information is obtained by performing scene vertical task decomposition processing on the safe operation task scene, at least two vertical safety large models corresponding to the scene vertical task information are determined, each vertical safety large model is used to perform a safety task corresponding to the scene vertical task information of the vertical safety large model, then a digital object service corresponding to each vertical safety large model is generated by using the scene vertical task information, the digital object service cluster is obtained by performing cooperative association processing on the digital object service through the scene vertical task information, since each vertical safety large model is used to perform a safety task corresponding to the scene vertical task information of the vertical safety large model, the digital object service cluster obtained by cooperative association processing can efficiently and automatically perform a safety operation on the safety operation task in the task scene, and since each digital object service can call the corresponding vertical safety large model to efficiently and accurately complete a task in the corresponding vertical safety field under the safety operation task, the safety operation accuracy and the safety operation efficiency are improved. Thus, the technical problem that an enterprise needs to invest more manpower to support the safety operation of the enterprise system and equipment is solved. BRIEF DESCRIPTION OF DRAWINGS

[0046] In order to more clearly illustrate the technical schemes in the embodiments of the present application or the prior art, the drawings needed to be used in the embodiments or the prior art description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0047] Figure 1 An exemplary system architecture diagram of a safety operation method provided by the embodiments of the present application;

[0048] Figure 2 A flowchart of a safety operation method provided by the embodiments of the present application;

[0049] Figure 3 A flowchart of a safety operation method provided by the embodiments of the present application;

[0050] Figure 4 A flowchart of determining scene vertical task information provided by the embodiments of the present application;

[0051] Figure 5 A flowchart of determining at least two vertical safety large models corresponding to the scene vertical task information provided by the embodiments of the present application;

[0052] Figure 6 A flowchart of generating a digital object service provided by the embodiments of the present application;

[0053] Figure 7 A virtual digital human image schematic diagram provided for an embodiment of the present application;

[0054] Figure 8 A flowchart for determining a digital object service cluster provided for an embodiment of the present application;

[0055] Figure 9 A flowchart for obtaining a digital object service cluster provided for an embodiment of the present application;

[0056] Figure 10 An interface schematic diagram for embedding a digital object service cluster plug-in in a browser provided for an embodiment of the present application;

[0057] Figure 11 A flowchart for updating an image provided for an embodiment of the present application;

[0058] Figure 12 An image change schematic diagram of a target virtual digital human for updating an image provided for an embodiment of the present application;

[0059] Figure 13 An interface schematic diagram of a target virtual digital human for tracing an attack digital human provided for an embodiment of the present application;

[0060] Figure 14 A structural schematic diagram of a secure operation device provided for an embodiment of the present application;

[0061] Figure 15 A structural schematic diagram of a terminal provided for an embodiment of the present application. DETAILED DESCRIPTION

[0062] In order to make the features and advantages of the embodiments of the present application more obvious and easy to understand, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all embodiments. Based on the embodiments in the embodiments of the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the embodiments of the present application.

[0063] In the related art, the security operation of the hardware and software of an enterprise often depends on manual work. However, errors are inevitable in information communication between people, and when multiple people perform security operation, the security operation intelligence data collected by each person is often scattered and difficult to effectively analyze. However, on the attack side, many organizations have created automated attack weapons using GPT models or special tools, so that enterprises have to invest more manpower to support the security operation of enterprise systems and devices.

[0064] To solve the technical problems in the related art, the embodiment of the present application provides a safe operation method, which comprises the following steps: determining a safe operation task scene, performing scene vertical task decomposition processing on the safe operation task scene to obtain scene vertical task information; determining at least two vertical safety large models corresponding to the scene vertical task information, generating a digital object service corresponding to each vertical safety large model based on the scene vertical task information, performing collaborative association processing on the digital object service through the scene vertical task information to obtain a digital object service cluster; and using the digital object service cluster to perform safe operation in the safe operation task scene, thereby solving the technical problem that an enterprise needs to invest more manpower to support the safe operation of the enterprise system and equipment.

[0065] Please refer to Figure 1 , Figure 1 An exemplary system architecture diagram of a safe operation method provided by the embodiment of the present application is shown in the following figure.

[0066] As Figure 1 shown, the system architecture can include a terminal 101, a network 102 and a server 103. The network 102 is used to provide a communication link medium between the terminal 101 and the server 103. The network 102 can include various types of wired communication links or wireless communication links, for example: the wired communication links include optical fiber, twisted pair or coaxial cable, and the wireless communication links include Bluetooth communication link, Wireless-Fidelity (Wi-Fi) communication link or microwave communication link, etc.

[0067] The terminal 101 can interact with the server 103 through the network 102 to receive messages from the server 103 or send messages to the server 103, or the terminal 101 can interact with the server 103 through the network 102 to receive messages or data sent by other users to the server 103. The terminal 101 can be hardware or software. When the terminal 101 is hardware, it can be various electronic devices, including but not limited to smart watches, smart phones, tablet computers, laptop computers and desktop computers, etc. When the terminal 101 is software, it can be installed in the above-mentioned electronic devices, which can be implemented as multiple software or software modules (for example: used to provide distributed services) or a single software or software module, which is not specifically limited here.

[0068] The server 103 can be a service server providing various services. It should be noted that the server 103 can be hardware or software. When the server 103 is hardware, it can be implemented as a distributed server cluster composed of multiple servers or as a single server. When the server 103 is software, it can be implemented as multiple software or software modules (for example, to provide distributed services) or as a single software or software module, which is not specifically limited here.

[0069] In the embodiment of the present application, the terminal 101 can determine a security operation task scenario, perform scene vertical task decomposition processing on the security operation task scenario to obtain scene vertical task information, determine at least two vertical security large models corresponding to the scene vertical task information, generate digital object services corresponding to each vertical security large model based on the scene vertical task information, perform collaborative association processing on the digital object services through the scene vertical task information to obtain a digital object service cluster, and perform security operation by using the digital object service cluster in the security operation task scenario.

[0070] It should be understood that Figure 1 The number of terminals, networks, and servers in the above description is only illustrative, and can be any number of terminals, networks, and servers according to the needs of implementation.

[0071] Please refer to Figure 2 , Figure 2 A flowchart of a security operation method provided by an embodiment of the present application is shown. The execution subject of the embodiment of the present application can be a terminal executing the security operation method, a processor in the terminal executing the security operation method, or a security operation service in the terminal executing the security operation method. For convenience of description, the specific execution process of the security operation method is introduced below by taking the execution subject as the processor in the terminal.

[0072] The security operation method includes:

[0073] S202: Determine a security operation task scenario, and perform scene vertical task decomposition processing on the security operation task scenario to obtain scene vertical task information.

[0074] The security operation task scenario can be a scenario corresponding to the same type of security operation task, and the task type of the security operation task includes but is not limited to a threat monitoring and analysis task type, an intelligence traceability task type, a traffic analysis task type, and a security report task type.

[0075] When it is determined that the task type of the security operation task corresponding to the security operation task scene is the threat monitoring and analysis task type, the security operation task in the security operation task scene is used for sample analysis and alarm judgment on threats. After sample analysis, it is determined whether an alarm signal is generated based on the analysis result. After receiving the alarm signal, the alarm type, alarm reason and impact of the alarm threat are determined through analysis, judgment and evaluation, so that corresponding measures are taken.

[0076] When it is determined that the task type of the security operation task corresponding to the security operation task scene is the intelligence traceability task type, the security operation task in the security operation task scene is used for intelligence notification analysis and attack traceability on attacks. Intelligence notification analysis is used for integrated analysis of attack intelligence, so as to locate attack behavior and further trace the attack behavior, such as the source country and specific region of the attack behavior.

[0077] When it is determined that the task type of the security operation task corresponding to the security operation task scene is the traffic analysis task type, the security operation task in the security operation task scene is used for analyzing daily traffic and providing security knowledge answers. Analyzing daily traffic includes but is not limited to accurate threat analysis of uploaded traffic messages or pcap packets. Security knowledge answers can be used for automatic annotation of threat analysis results and answering user questions.

[0078] When it is determined that the task type of the security operation task corresponding to the security operation task scene is the security report task type, the security operation task in the security operation task scene is used for security posture analysis and security report generation. Here, security posture analysis is used for comprehensive evaluation of network security protection, and security report generation is used for analysis and integration of evaluation results to generate corresponding security reports.

[0079] After determining the security operation task scene, the security operation task scene is processed by scene vertical task decomposition, so as to decompose the same type of security operation task corresponding to the security operation task scene. That is, the same type of security operation task is vertically divided according to the vertical type of the data processing node corresponding to the data processing flow. When multiple data processing nodes are used to cooperate to realize the data processing of the same subcategory task item, these data processing nodes can be divided into the same vertical category. Scene vertical task decomposition is used to vertically split the same type of security operation task to determine scene vertical security tasks. Each scene vertical security task is used to realize the data processing of its corresponding task item.

[0080] The scene vertical task information is obtained by performing scene vertical task decomposition processing on the safety operation task scene, and is used to represent vertical task information corresponding to the same type of safety operation task. The scene vertical task information includes at least two scene vertical safety tasks corresponding to the safety operation task scene and a vertical task coordination relationship between the at least two scene vertical safety tasks for the safety operation task scene.

[0081] S204: Determine at least two vertical safety large models corresponding to the scene vertical task information, generate a digital object service corresponding to each vertical safety large model based on the scene vertical task information, and perform cooperative association processing on the digital object service through the scene vertical task information to obtain a digital object service cluster.

[0082] Wherein, after determining the scene vertical task information, the scene vertical task information is used for model searching, so as to determine at least two vertical safety large models corresponding to the scene vertical task information. Since the scene vertical task information is used to represent vertical task information corresponding to the same type of safety operation task, the scene vertical task information can be used to represent at least two vertical safety large models corresponding to the safety operation task scene after scene vertical task decomposition.

[0083] Each vertical safety large model corresponds to a scene vertical safety task, and each vertical safety large model is used to execute the scene vertical safety task corresponding thereto.

[0084] After determining the at least two vertical safety large models corresponding to the scene vertical task information, a corresponding digital object service is constructed for each vertical safety large model using the scene vertical task information. Each vertical safety large model corresponds to a digital object service, and the digital object service can call the corresponding vertical safety large model to execute the corresponding scene vertical safety task. When the digital object service is displayed to the user, it can be displayed in the form of a virtual digital person, and it can also directly interact with the user in the form of a virtual digital person.

[0085] Since each vertical security large model corresponds to a digital object service, at least two vertical security large models can correspond to at least two digital object services, when the number of vertical security large models is N, the number of corresponding digital object services is also N, at this time in order to complete the security operation task in the security operation task scene, the scene vertical task information can be used to cooperatively associate the digital object service to obtain a digital object service cluster, each digital object service can call the corresponding vertical security large model to execute the corresponding scene vertical security task, and the security operation task in the security operation task scene includes multiple scene vertical security tasks, multiple scene vertical security tasks cooperate with each other to complete the security operation task, therefore, the vertical task cooperative relationship can be used to service-associate the digital object service to obtain a digital object service cluster. The digital object service cluster can be a set composed of multiple digital object services corresponding to the scene vertical task information, and the multiple digital object services cooperate with each other to complete the security operation task in the security operation task scene.

[0086] Optionally, the digital object service is cooperatively associated by the scene vertical task information to obtain a digital object service cluster, including:

[0087] The digital object service corresponding to all vertical security large models is cooperatively associated by the scene vertical task information to obtain a digital object service cluster.

[0088] The digital object service corresponding to all vertical security large models includes at least two of a sample analysis service, an alarm research and judgment service, an attack traceability service, an intelligence notification analysis service, and a heavy protection situation analysis service.

[0089] When the security operation task is a threat monitoring and analysis task, the digital object service corresponding to all vertical security large models includes a sample analysis service and an alarm research and judgment service; when the security operation task is an intelligence traceability task, the digital object service corresponding to all vertical security large models includes an attack traceability service and an intelligence notification analysis service; when the security operation task is a system security operation task, the digital object service corresponding to all vertical security large models includes a sample analysis service, an alarm research and judgment service, an attack traceability service, an intelligence notification analysis service, and a heavy protection situation analysis service. Of course, in other embodiments, the digital object service corresponding to all vertical security large models includes three, four, or five of the sample analysis service, the alarm research and judgment service, the attack traceability service, the intelligence notification analysis service, and the heavy protection situation analysis service, which will not be described here.

[0090] S206: In the security operation task scene, the digital object service cluster is used for security operation.

[0091] In the security operation task scenario, the security operation task is determined, which can be a task input by a user or a task automatically generated by a terminal. Then, the security operation task is obtained by using the digital object service cluster, and data processing is performed on the security operation task, so that the digital object services in the digital object service cluster are coordinated to complete the security operation task.

[0092] For example, refer to Figure 3 , Figure 3 A flowchart of a security operation method using a digital object service cluster is provided for the embodiments of the present application. In S206, the digital object service cluster is used for security operation in the security operation task scenario, including:

[0093] S302: Obtain the security operation task corresponding to the security operation task scenario, and determine the to-be-processed data corresponding to the security operation task.

[0094] In the security operation, the security operation task corresponding to the security operation task scenario is first obtained, and the to-be-processed data corresponding to the security operation task is also obtained. The to-be-processed data corresponding to the security operation task is data that needs to be further analyzed and processed for the task. For example, when the task type of the security operation task is an intelligence traceability task type, the to-be-processed data of the security operation task can be a domain name to be traced.

[0095] S304: Input the security operation task and the to-be-processed data into the digital object service cluster. For the security operation task, the to-be-processed data is processed by the digital object services in the digital object service cluster, and the task processing result for the security operation task is output based on the digital object service cluster.

[0096] After the to-be-processed data corresponding to the security operation task is determined, the security operation task and the to-be-processed data are input into the digital object service cluster. The digital object service cluster includes cluster input and cluster output, and the cluster input and the cluster output are connected to multiple digital object services according to the service coordination relationship between the digital object services. The to-be-processed data is processed by the digital object services in the digital object service cluster for the security operation task, so that the task processing result for the security operation task is obtained.

[0097] After the security operation task and the to-be-processed data are input into the digital object service cluster, the digital object services in the digital object service cluster call corresponding vertical security large models in sequence or cooperatively to process, so that the security operation task is gradually completed, until the security operation task is finally completed, so that the task processing result for the security operation task is obtained, and the automatic security operation of the security operation task in the security operation task scenario is realized. Moreover, each digital object service can call the corresponding vertical security large model to efficiently and accurately complete the task in the corresponding vertical security field under the security operation task, so that the security operation accuracy and the security operation efficiency are improved. Meanwhile, each digital object service can be presented to the user in a visual manner, so that the service experience of the user is better, and the subsequent review and traceability verification of data are facilitated.

[0098] In the embodiments provided in the present application, the scene vertical task information is obtained by performing scene vertical task decomposition processing on the security operation task scenario, so as to determine at least two vertical security large models corresponding to the scene vertical task information. Each vertical security large model is used to execute the security task of the corresponding scene vertical task information. Then, the digital object services corresponding to each vertical security large model are generated by using the scene vertical task information. The digital object services are cooperatively associated by using the scene vertical task information, so as to obtain a digital object service cluster. Since each vertical security large model is used to execute the security task of the corresponding scene vertical task information, the digital object service cluster obtained by the cooperative association can efficiently and automatically perform the security operation of the security operation task in the security operation task scenario. Moreover, each digital object service can call the corresponding vertical security large model to efficiently and accurately complete the task in the corresponding vertical security field under the security operation task, so that the security operation accuracy and the security operation efficiency are improved. Thus, the technical problem that the enterprise needs to invest more manpower to support the security operation of the enterprise system and equipment is solved.

[0099] Please refer to Figure 4 , Figure 4 A flowchart for determining scene vertical task information is provided in the embodiments of the present application. As shown in Figure 4 S202, the scene vertical task information is obtained by performing scene vertical task decomposition processing on the security operation task scenario, including:

[0100] S402: The security operation task scenario is processed by scene vertical task decomposition, to obtain at least two scene vertical security tasks.

[0101] ​The security operation task scene corresponds to a security operation task. The security operation task scene is a scene corresponding to a same type of security operation task. The security operation task scene is divided into at least two scene vertical security tasks by the scene vertical task division processing. The scene vertical task division processing can be understood as vertical task division of the same type of security operation task, that is, the same type of security operation task is divided into at least two scene vertical security tasks, so as to determine a general processing strategy of the security operation task of the type.

[0102] For example, the security operation task corresponding to the security operation task scene can be A. After the scene vertical task division processing is performed on A, at least two scene vertical security tasks a1, a2, and the like are obtained.

[0103] Specifically, when it is determined that the task type of the security operation task corresponding to the security operation task scene is a threat monitoring and analysis task type, the vertical task division of the security operation task can obtain a sample analysis task and an alarm judgment task. For another example, when it is determined that the task type of the security operation task corresponding to the security operation task scene is an intelligence traceability task type, the vertical task division of the security operation task can obtain an intelligence notification analysis task and an attack traceability task. For another example, when it is determined that the task type of the security operation task corresponding to the security operation task scene is a traffic analysis task type, the vertical task division of the security operation task can obtain a routine traffic analysis task and a security knowledge answering task. For another example, when it is determined that the task type of the security operation task corresponding to the security operation task scene is a security report task type, the vertical task division of the security operation task can obtain a heavy protection situation analysis task and a security report generation task.

[0104] S404: determining a vertical task cooperation relationship between the at least two scene vertical security tasks for the security operation task scene.

[0105] The scene vertical security task is obtained by performing the scene vertical task division processing on the security operation task scene. In order to complete the scene vertical security task, the scene vertical security tasks need to cooperate with each other.

[0106] Therefore, the vertical task cooperation relationship between the at least two scene vertical security tasks for the security operation task scene can be determined. The vertical task cooperation relationship includes but is not limited to a task connection relationship, a task data flow direction sequence, and the like.

[0107] S406: obtaining scene vertical task information based on the at least two scene vertical security tasks and the vertical task cooperation relationship.

[0108] After the at least two scene vertical security tasks and the vertical task cooperation relationship are determined, the scene vertical task information is obtained based on the at least two scene vertical security tasks and the vertical task cooperation relationship.

[0109] In the embodiments provided in the present application, the scene vertical task splitting processing is performed on the security operation task scene to obtain at least two scene vertical security tasks, and then the vertical task cooperation relationship between the at least two scene vertical security tasks for the security operation task scene is determined, so as to determine the scene vertical task information corresponding to the security operation task scene. Through the vertical task splitting of the security operation task scene, an efficient execution strategy is provided for the automatic execution of the full operation task scene in the security operation task scene.

[0110] Please refer to Figure 5 , Figure 5 A flowchart for determining at least two vertical security large models corresponding to the scene vertical task information is provided in the embodiments of the present application. As shown in Figure 5 , the determination of the at least two vertical security large models corresponding to the scene vertical task information in S204 includes:

[0111] S502: input the scene vertical security task in the scene vertical task information into the vertical security label classification model, and output the vertical security label corresponding to the scene vertical security task based on the vertical security label classification model; wherein the vertical security label classification model is a model obtained after the model training of the basic large model on the sample scene vertical security task and the sample vertical security label corresponding to the sample scene vertical security task.

[0112] Wherein, after the scene vertical security task is determined, the scene vertical security task is input into the vertical security label classification model, and the vertical security label corresponding to the scene vertical security task is obtained after the model processing of the vertical security label classification model on the scene vertical security task. The vertical security label can be set based on the scene demand.

[0113] In order to obtain the vertical security label classification model, firstly, the sample scene vertical security task and the sample vertical security label corresponding to the sample scene vertical security task are obtained, and the basic large model is determined. The sample scene vertical security task is input into the basic large model, and the basic large model outputs the reference vertical security label for the sample scene vertical security task. Then, the loss function is constructed by using the parameters corresponding to the reference vertical security label and the sample vertical security label, the model loss value of the loss function corresponding to the reference vertical security label and the sample vertical security label is determined, and then the model parameter adjustment is performed on the basic large model by using the model loss value. After multiple rounds of model training, until the basic large model is trained, the vertical security label classification model is obtained.

[0114] S504: obtain a vertical security large model library, perform model matching in the vertical security large model library by using the vertical security label, obtain the vertical security large model matched by the vertical security label, determine the vertical security large model corresponding to the scene vertical security task, and obtain at least two vertical security large models corresponding to the scene vertical task information.

[0115] wherein, after determining the vertical safety label corresponding to the scene vertical safety task, a pre-established vertical safety large model library is obtained, the vertical safety large model library including a plurality of pre-generated vertical safety large models, different vertical safety large models being used to perform different scene vertical safety tasks.

[0116] Each vertical safety label can correspond to a vertical safety large model, the vertical safety large model being used to perform the scene vertical safety task corresponding to the vertical safety label corresponding thereto, the vertical safety label and the vertical safety large model corresponding one by one, so that the vertical safety label can be used to perform model matching in the vertical safety large model library to obtain the vertical safety large model matched by the vertical safety label, thereby obtaining at least two vertical safety large models corresponding to at least two scene vertical safety tasks under the scene vertical safety task information.

[0117] In the embodiments provided in the present application, the vertical safety label classification model is used to determine the vertical safety label corresponding to the scene vertical safety task, and then the vertical safety large model corresponding to the vertical safety label is matched from the vertical safety large model library, and at least two vertical safety large models corresponding to the scene vertical safety task information are determined, thereby realizing the rapid and accurate matching of the at least two vertical safety large models corresponding to the scene vertical safety task information.

[0118] Please refer to Figure 6 , Figure 6 for a flowchart of generating a digital object service provided by an embodiment of the present application. Please refer to Figure 7 , Figure 7 for an image diagram of a virtual digital person provided by an embodiment of the present application. As shown in Figure 6 , the generation of the digital object service corresponding to each vertical safety large model based on the scene vertical safety task information in S204 includes:

[0119] S602: obtaining a virtual digital person for the vertical safety large model, determining the input specification corresponding to the vertical safety large model, determining the input normalization configuration information based on the input specification, and configuring the input module of the virtual digital person using the input normalization configuration information and the scene vertical safety task, and generating the output module of the virtual digital person.

[0120] wherein, in order to distinguish the virtual digital persons of different vertical safety large models, different vertical safety large models can correspond to virtual digital persons with different images, as shown in Figure 7 , Figure 7The virtual digital person corresponding to A is a digital person corresponding to a vertical security large model for performing a sample analysis task, the virtual digital person corresponding to B is a digital person corresponding to a vertical security large model for performing an alarm judgment task, the virtual digital person corresponding to C is a digital person corresponding to a vertical security large model for performing an attack tracing task, the virtual digital person corresponding to D is a digital person corresponding to a vertical security large model for performing an intelligence notification analysis task, and the virtual digital person corresponding to E is a digital person corresponding to a vertical security large model for performing a heavy protection situation analysis task.

[0121] After determining the virtual digital person corresponding to the vertical security large model, the input specification corresponding to the vertical security large model is determined, which includes but is not limited to input format specification, input length specification, etc. Then, the input specification configuration information is generated by using the input specification corresponding to the vertical security large model. The scene vertical security task can be a scene vertical task target, and then the input module of the virtual digital person is configured by using the input specification configuration information and the scene vertical task target. The input module is used to normalize the data input into the input module and extract the data corresponding to the task target to meet the input specification of the vertical security large model, thereby improving the learning and understanding efficiency and processing efficiency of the vertical security large model.

[0122] Meanwhile, the output module can also be configured for the virtual digital person, which can be a general output module.

[0123] S604: Determine the model interface configuration information of the vertical security large model, and configure the model calling module of the virtual digital person by using the model interface configuration information.

[0124] The model interface configuration information of the vertical security large model includes interface address, request method, request parameter and authentication information, etc. The interface address is the key information for the model to communicate with the external system, which specifies the specific location of data sending and receiving. The request method specifies the way of sending a request to the interface. The request parameter is the format and type of data sent to the model. The authentication information is used for security authentication when the interface is connected, such as authentication through token, etc. After obtaining the model interface configuration information of the vertical security large model, the model calling module of the virtual digital person is configured by using the model interface configuration information, so that the model calling module can efficiently call the corresponding vertical security large model.

[0125] S606: Perform module association processing on the input module, the model calling module and the output module in the virtual digital person to obtain a target virtual digital person, so that the model calling module controls the vertical security large model to process the data output by the input module, and controls the output module to obtain and output the model output data of the vertical security large model.

[0126] Wherein, after determining the input module, model calling module and output module in the virtual digital person, the input module, model calling module and output module are subjected to module association processing to make the model calling module control the vertical class safety large model to process the data output by the input module, and control the output module of the target virtual digital person to obtain and output the model output data of the vertical class safety large model. After the input module, model calling module and output module in the virtual digital person are subjected to module association processing, the virtual digital person is updated to the target virtual digital person, and the appearance of the target virtual digital person does not change compared with the corresponding virtual digital person.

[0127] S608: Determine the target virtual digital person corresponding to each vertical class safety large model, and obtain the digital object service corresponding to each vertical class safety large model based on the target virtual digital person.

[0128] Wherein, after obtaining the target virtual digital person corresponding to each vertical class safety large model, the target virtual digital person corresponding to each vertical class safety large model is taken as the target virtual digital person corresponding to the vertical class safety large model. At this time, the digital object service can receive data and call the corresponding vertical class safety large model to process the data and output the data output by the model.

[0129] In the embodiments provided in the present application, the digital object service corresponding to each vertical class safety large model is generated by using the scene vertical class task information, so that the interaction with the vertical class safety large model can be visually displayed, and the input module, model calling module and output module configured can improve the learning and understanding efficiency of the vertical class safety large model for data and the model processing efficiency, and improve the accuracy of model processing.

[0130] Please refer to Figure 8 , Figure 8 A flowchart for determining a digital object service cluster is provided in the embodiments of the present application. As shown in Figure 8 , the digital object service cluster is obtained by cooperating and associating the digital object service with the scene vertical class task information in S204, including:

[0131] S802: Determine the vertical class task cooperation relationship in the scene vertical class task information, and determine the service cooperation relationship between the digital object services based on the vertical class task cooperation relationship; wherein the service cooperation relationship includes service calling information and service information interaction information.

[0132] Wherein, after obtaining the scene vertical class task information, the vertical class task cooperation relationship in the scene vertical class task information is obtained, which includes task connection relationship, task data flow direction sequence, etc., and then the service calling information and service information interaction information between the digital object services are determined by using the task connection relationship and task data flow direction sequence, so as to determine the service cooperation relationship between the digital object services.

[0133] S804: service association processing is performed on the digital object services based on the service coordination relationship, to obtain a digital object service cluster.

[0134] The service coordination relationship between the digital object services is determined based on the service invocation information, and the information interaction relationship between the digital object services is determined based on the service information interaction information, to obtain the digital object service cluster.

[0135] In the embodiments provided in the present application, the service coordination relationship between the digital object services is determined based on the vertical task coordination relationship, and then the service association processing is performed on the digital object services based on the service coordination relationship to obtain the digital object service cluster.

[0136] Referring to Figure 9 , Figure 9 is a flowchart for obtaining a digital object service cluster provided by an embodiment of the present application. As shown in Figure 9 , the service association processing is performed on the digital object services based on the service coordination relationship in S804 to obtain the digital object service cluster, including:

[0137] S902: service invocation relationship configuration information between the digital object services is determined based on the service invocation information.

[0138] The service invocation relationship between the digital object services is determined based on the service invocation information, and then the service invocation relationship configuration information between the digital object services is determined based on the service invocation relationship.

[0139] S904: service information interaction configuration information between the digital object services is determined based on the service information interaction information.

[0140] The information interaction relationship between the digital object services is determined based on the service information interaction information, and then the service information interaction configuration information between the digital object services is determined based on the information interaction relationship.

[0141] S906: service association processing is performed on the digital object services based on the service invocation relationship configuration information and the service information interaction configuration information, to obtain a digital object service cluster.

[0142] The service association processing is performed on the digital object services based on the service invocation relationship configuration information and the service information interaction configuration information, to make the digital object services can be coordinated with each other to complete the corresponding security operation task in the security operation task scenario.

[0143] Referring to Figure 10 , Figure 10An interface schematic diagram of embedding a digital object service cluster plug-in in a browser is provided for an embodiment of the present application. As shown in Figure 10 When the security operation task scenario includes the browser security operation task scenario, at this time the digital object service cluster can be embedded into the display interface of the browser in the form of a browser plug-in (see Figure 10 the right side area), at this time the digital object service cluster can be displayed in a unified digital human image, and can prompt "Hi, what can I do for you?". The user can input by clicking the blank area on the right. The digital object service cluster can be deeply connected to the business system function of the enterprise business scenario, and provide services in terms of business analysis, security analysis, report analysis and summary, schedule management, and to-do tracking, in addition to assisting the user in AI (Artificial Intelligence) search, document writing, PDF (Portable Document Format) analysis, media analysis, intelligent chat, etc.

[0144] Please refer to Figure 11 , Figure 11 A flowchart of an image updating process is provided for an embodiment of the present application. As shown in Figure 11 The method comprises the following steps:

[0145] S1102: When it is detected that the vertical security large model processing progress information for the vertical security task of the scene changes, the processing progress information is determined, the preset virtual digital human state corresponding to the processing progress information is obtained, and the digital human state image information corresponding to the preset virtual digital human state is obtained.

[0146] Among them, when the vertical security large model does not process the data of the vertical security large model, the processing progress information of the vertical security large model is not processed, at this time the preset virtual digital human state is standby state; when the vertical security large model processes the data of the vertical security large model, the processing progress information of the vertical security large model is processing, at this time the preset virtual digital human state is thinking and analyzing state, different processing progress information can correspond to different preset virtual digital human state, each preset virtual digital human state corresponds to a digital human state image information, based on the digital human state image information, the corresponding digital human image can be displayed. When the processing progress information changes, the current processing progress information is obtained to determine the digital human state image information.

[0147] S1104: Based on the digital human state image information, the current digital image of the target virtual digital human is updated.

[0148] Wherein, after determining the digital human state image information, the corresponding digital human image is determined by using the digital human state image information, and then the current digital image of the target virtual digital human is updated by using the digital human image corresponding to the digital human state image information, so that the user can quickly obtain the processing progress information of the vertical safety large model for the scene vertical safety task based on the image of the digital human.

[0149] Please refer to Figure 12 , Figure 12 The image change schematic diagram of the target virtual digital human for image updating is provided for the embodiments of the present application. As shown in Figure 12 , for example, when it is detected that the processing progress information of the vertical safety large model for the scene vertical safety task changes, the processing progress information changes from unprocessed to processing, and at this time, the preset virtual digital human state changes from standby state to thinking and analyzing state.

[0150] Please refer to Figure 13 , Figure 13 The interface schematic diagram of the target virtual digital human as an attack tracing digital human is provided for the embodiments of the present application. Of course, in other embodiments, when the target virtual digital human is the digital human corresponding to the vertical safety large model for the attack tracing task, that is, the attack tracing digital human, when the processing progress information of the vertical safety large model is processing, the attack tracing digital human can also show the current specific progress through text. Figure 13 The "47.94.138.223" can be a domain name to be traced provided by other target virtual digital humans, and the attack tracing digital human can perform attack tracing, such as performing association XX security big data domain name query, after receiving "47.94.138.223".

[0151] Please refer to Figure 14 , Figure 14 The structural schematic diagram of the security operation device is provided for the embodiments of the present application. As shown in Figure 14 , the security operation device 1400 includes:

[0152] The scene vertical task information determination module 1410 is adapted to determine a security operation task scene, and performs scene vertical task decomposition processing on the security operation task scene to obtain scene vertical task information;

[0153] The determination module 1420 is adapted to determine at least two vertical safety large models corresponding to the scene vertical task information, generate digital object services corresponding to each vertical safety large model based on the scene vertical task information, and perform cooperative association processing on the digital object services through the scene vertical task information to obtain a digital object service cluster;

[0154] The security operation module 1430 is adapted to utilize the digital object service cluster for security operation in a security operation task scenario.

[0155] Optionally, the scenario vertical task information determination module 1410 comprises:

[0156] The splitting unit is adapted to perform scenario vertical task splitting processing on the security operation task scenario to obtain at least two scenario vertical security tasks;

[0157] The determination unit is adapted to determine a vertical task coordination relationship between the at least two scenario vertical security tasks for the security operation task scenario;

[0158] The scenario vertical task information obtaining unit is adapted to obtain scenario vertical task information based on the at least two scenario vertical security tasks and the vertical task coordination relationship.

[0159] Optionally, the determination module 1420 comprises:

[0160] The model processing unit is adapted to input the scenario vertical security task in the scenario vertical task information into a vertical security label classification model, and output a vertical security label corresponding to the scenario vertical security task based on the vertical security label classification model;

[0161] The matching unit is adapted to obtain a vertical security large model library, perform model matching in the vertical security large model library using the vertical security label, obtain a vertical security large model matched by the vertical security label, determine a vertical security large model corresponding to the scenario vertical security task, and obtain at least two vertical security large models corresponding to the scenario vertical task information;

[0162] The vertical security label classification model is a model obtained by model training of a basic large model based on a sample scenario vertical security task and a sample vertical security label corresponding to the sample scenario vertical security task.

[0163] Optionally, the determination module 1420 comprises:

[0164] The input and output module determination unit is adapted to obtain a virtual digital person for the vertical security large model, determine an input specification corresponding to the vertical security large model, determine input normalization configuration information based on the input specification, configure an input module of the virtual digital person using the input normalization configuration information and the scenario vertical security task, and generate an output module of the virtual digital person;

[0165] The model calling module determination unit is adapted to determine model interface configuration information of the vertical security large model, and configure a model calling module of the virtual digital person using the model interface configuration information.

[0166] The association unit is suitable for performing module association processing on the input module, the model calling module and the output module in the virtual digital person to obtain a target virtual digital person, so that the model calling module controls the vertical safety large model to perform model processing on the data output by the input module, and controls the output module to obtain and output the model output data of the vertical safety large model.

[0167] The digital object service determination unit is suitable for determining target virtual digital persons corresponding to each vertical safety large model, and obtaining digital object services corresponding to each vertical safety large model based on the target virtual digital persons.

[0168] Optionally, the determination module 1420 includes:

[0169] The service coordination relationship determination unit is suitable for determining a vertical task coordination relationship in the scene vertical task information, and determining a service coordination relationship between the digital object services based on the vertical task coordination relationship; wherein the service coordination relationship includes service calling information and service information interaction information.

[0170] The digital object service cluster determination unit is suitable for performing service association processing on the digital object services based on the service coordination relationship to obtain a digital object service cluster.

[0171] Optionally, the digital object service cluster determination unit includes:

[0172] The first determination sub-unit is suitable for determining service calling relationship configuration information between the digital object services based on the service calling information.

[0173] The second determination sub-unit is suitable for determining service information interaction configuration information between the digital object services based on the service information interaction information.

[0174] The digital object service cluster determination sub-unit is suitable for performing service association processing on the digital object services by using the service calling relationship configuration information and the service information interaction configuration information to obtain a digital object service cluster.

[0175] Optionally, the security operation module 1430 includes:

[0176] The to-be-processed data determination unit is suitable for obtaining a security operation task corresponding to a security operation task scene, and determining to-be-processed data corresponding to the security operation task.

[0177] The output unit is suitable for inputting the security operation task and the to-be-processed data into the digital object service cluster, performing collaborative processing on the to-be-processed data by the digital object services in the digital object service cluster for the security operation task, and outputting a task processing result for the security operation task based on the digital object service cluster.

[0178] Optionally, the security operation task scene includes a browser security operation task scene.

[0179] Optionally, the determining module 1420 is further adapted to:

[0180] perform collaborative association processing on the digital object services corresponding to all vertical security large models through the scene vertical task information, to obtain a digital object service cluster;

[0181] The digital object services corresponding to all vertical security large models include at least two of sample analysis services, alarm research and judgment services, attack traceability services, intelligence notification analysis services, and heavy protection situation analysis services.

[0182] Optionally, the security operation apparatus 1400 further includes:

[0183] The detecting module is adapted to, when detecting that the vertical security large model changes the processing progress information for the scene vertical security task, determine the processing progress information, acquire a preset virtual digital human state corresponding to the processing progress information, and acquire digital human state image information corresponding to the preset virtual digital human state.

[0184] The updating module is adapted to perform image updating processing on the current digital image of the target virtual digital human based on the digital human state image information.

[0185] In the embodiments of the present application, a computer readable storage medium is also provided, which stores one or more programs, and the one or more programs, when executed by a processor, implement the method of any one of the above.

[0186] Please refer to Figure 15 , Figure 15 A structural schematic diagram of a terminal is provided in the embodiments of the present application. As shown in the figure, the terminal 1500 can include at least one processor 1501, at least one network interface 1504, a user interface 1503, a memory 1505, and at least one communication bus 1502. Figure 15 The communication bus 1502 is used to realize the connection and communication between the components.

[0187] The user interface 1503 can include a display screen (Display), a camera (Camera), and optionally the user interface 1503 can also include a standard wired interface and a wireless interface.

[0188] The network interface 1504 can optionally include a standard wired interface and a wireless interface (such as a WI-FI interface).

[0189]

[0190] ​The processor 1501 can include one or more processing cores. The processor 1501 connects various parts within the terminal 1500 through various interfaces and lines, and performs various functions of the terminal 1500 and processes data by running or executing instructions, programs, code sets, or instruction sets stored in the memory 1505, and calling data stored in the memory 1505. Alternatively, the processor 1501 can be implemented in at least one of a hardware form of a digital signal processor (DSP), a field-programmable gate array (FPGA), a programmable logic array (PLA). The processor 1501 can be integrated with a combination of one or more of a central processing unit (CPU), a graphics processing unit (GPU), and a modem. Among them, the CPU mainly processes an operating system, a user interface, and an application program; the GPU is responsible for rendering and drawing the content to be displayed on the display screen; and the modem is used for processing wireless communication. It can be understood that the above-mentioned modem can also not be integrated into the processor 1501, but can be realized by a separate chip.

[0191] The memory 1505 can include a random access memory (RAM) and can also include a read-only memory (ROM). Alternatively, the memory 1505 includes a non-transitory computer-readable storage medium. The memory 1505 can be used to store instructions, programs, codes, code sets, or instruction sets. The memory 1505 can include a program storage area and a data storage area, wherein the program storage area can store instructions for implementing an operating system, instructions for at least one function (such as a touch function, a sound playing function, an image playing function, etc.), instructions for implementing the above-mentioned various method embodiments, etc.; the data storage area can store data involved in the above-mentioned various method embodiments, etc. The memory 1505 can alternatively be at least one storage device located away from the aforementioned processor 1501. As shown, the memory 1505 as a computer storage medium can include an operating system, a network communication module, a user interface module, and a secure operation program. Figure 15

[0192] In Figure 15 ​In the terminal 1500 shown, the user interface 1503 is mainly used to provide an interface for user input and obtain user input data; and the processor 1501 can be used to call the security operation program stored in the memory 1505 and specifically perform the following operations:

[0193] Determine the security operation task scenario, and perform scene vertical task decomposition processing on the security operation task scenario to obtain scene vertical task information.

[0194] Determine at least two vertical security large models corresponding to the scene vertical task information, generate digital object services corresponding to each vertical security large model based on the scene vertical task information, and perform collaborative association processing on the digital object services through the scene vertical task information to obtain a digital object service cluster.

[0195] In the security operation task scenario, the digital object service cluster is used for security operation.

[0196] Optionally, when the processor 1501 performs scene vertical task decomposition processing on the security operation task scenario to obtain scene vertical task information, it specifically performs:

[0197] Perform scene vertical task decomposition processing on the security operation task scenario to obtain at least two scene vertical security tasks.

[0198] Determine the vertical task cooperation relationship between the at least two scene vertical security tasks for the security operation task scenario.

[0199] Obtain scene vertical task information based on the at least two scene vertical security tasks and the vertical task cooperation relationship.

[0200] Optionally, when the processor 1501 determines at least two vertical security large models corresponding to the scene vertical task information, it specifically performs:

[0201] Input the scene vertical security task in the scene vertical task information into the vertical security label classification model, and output the vertical security label corresponding to the scene vertical security task based on the vertical security label classification model.

[0202] Obtain a vertical security large model library, perform model matching in the vertical security large model library using the vertical security label, obtain a vertical security large model matched by the vertical security label, determine the vertical security large model corresponding to the scene vertical security task, and obtain at least two vertical security large models corresponding to the scene vertical task information.

[0203] The vertical security label classification model is a model obtained by training a basic large model with sample scene vertical security tasks and sample vertical security labels corresponding to the sample scene vertical security tasks.

[0204] Optionally, when the processor 1501 performs generating a digital object service corresponding to each vertical safety large model based on the scene vertical task information, the following specific implementation is performed:

[0205] Obtaining a virtual digital person for the vertical safety large model, determining input specification corresponding to the vertical safety large model, determining input normalization configuration information based on the input specification, configuring an input module of the virtual digital person by using the input normalization configuration information and the scene vertical safety task, generating an output module of the virtual digital person; determining model interface configuration information of the vertical safety large model, and configuring a model calling module of the virtual digital person by using the model interface configuration information;

[0206] Performing module association processing on the input module, the model calling module and the output module in the virtual digital person to obtain a target virtual digital person, so that the model calling module controls the vertical safety large model to perform model processing on the data output by the input module, and controls the output module to obtain and output model output data of the vertical safety large model;

[0207] Determining the target virtual digital person corresponding to each vertical safety large model, and obtaining a digital object service corresponding to each vertical safety large model based on the target virtual digital person.

[0208] Optionally, when the processor 1501 performs cooperative association processing on the digital object service through the scene vertical task information to obtain a digital object service cluster, the following specific implementation is performed:

[0209] Determining a vertical task cooperative relationship in the scene vertical task information, and determining a service cooperative relationship between the digital object services based on the vertical task cooperative relationship; wherein the service cooperative relationship includes service calling information and service information interaction information;

[0210] Performing service association processing on the digital object services based on the service cooperative relationship to obtain the digital object service cluster.

[0211] Optionally, when the processor 1501 performs service association processing on the digital object services based on the service cooperative relationship to obtain the digital object service cluster, the following specific implementation is performed:

[0212] Determining service calling relationship configuration information between the digital object services based on the service calling information;

[0213] Determining service information interaction configuration information between the digital object services based on the service information interaction information;

[0214] Performing service association processing on the digital object services by using the service calling relationship configuration information and the service information interaction configuration information to obtain the digital object service cluster.

[0215] Optionally, the processor 1501 performs the following specific implementation when performing security operation by using the digital object service cluster in the security operation task scenario:

[0216] Obtains a security operation task corresponding to the security operation task scenario, and determines to-be-processed data corresponding to the security operation task.

[0217] Inputs the security operation task and the to-be-processed data into the digital object service cluster, performs collaborative processing on the to-be-processed data by using a digital object service in the digital object service cluster for the security operation task, and outputs a task processing result for the security operation task based on the digital object service cluster.

[0218] Optionally, the security operation task scenario includes a browser security operation task scenario.

[0219] Optionally, the processor 1501 performs collaborative association processing on the digital object service by using the scenario vertical task information, and obtains a digital object service cluster.

[0220] Collaboratively associates all vertical security large models corresponding to the digital object service by using the scenario vertical task information, and obtains a digital object service cluster.

[0221] The digital object service corresponding to all vertical security large models includes at least two of a sample analysis service, an alarm research and judgment service, an attack traceability service, an intelligence notice analysis service, and a heavy protection situation analysis service.

[0222] Optionally, the processor 1501 is further adapted to perform

[0223] When detecting that the processing progress information of the vertical security large model for the scenario vertical security task changes, determines the processing progress information, obtains preset virtual digital person state corresponding to the processing progress information, and obtains digital person state image information corresponding to the preset virtual digital person state.

[0224] Performs image updating processing on a current digital image of the target virtual digital person based on the digital person state image information.

[0225] In several embodiments provided in the present application, it should be understood that the disclosed apparatus and method can be implemented in other manners. For example, the above-described apparatus embodiments are merely schematic. Taking the division of the modules as an example, the actual implementation can have another division manner, for example, a plurality of modules or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the shown or discussed modules can be indirect coupling or communication connection through some interfaces, apparatuses or modules, and can be electrical, mechanical or in other forms.

[0226] The modules described as separate components may or may not be physically separate, and the components shown as modules may or may not be physical modules, i.e., may be located in one place or distributed to multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the purpose of the embodiment.

[0227] In addition, the functional modules in each of the embodiments of the present application can be integrated into one processing module, or each module can exist physically, or two or more modules can be integrated into one module. The integrated module can be realized in the form of hardware or in the form of a software functional module.

[0228] The integrated module, if realized in the form of a software functional module and sold or used as an independent product, can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the embodiments of the present application essentially or the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a number of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various program code storage media.

[0229] It should be noted that, for the foregoing method embodiments, in order to facilitate description, they are all described as a combination of a series of actions, but those skilled in the art should know that the present application is not limited by the order of the described actions, because according to the present application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should know that the embodiments described in the specification all belong to preferred embodiments, and the actions and modules involved are not necessarily all necessary for the present application.

[0230] In the above embodiments, the description of each embodiment has its own emphasis, and the parts not described in detail in a certain embodiment can be referred to the related description of other embodiments.

[0231] The above is a description of the security operation method, device, terminal and computer readable storage medium provided by the embodiments of the present application. For those skilled in the art, according to the idea of the embodiments of the present application, there will be changes in specific implementation manners and application ranges. In conclusion, the content of the specification should not be understood as a limitation of the embodiments of the present application.

Claims

1. A safe operation method, wherein, The method includes: Determine the security operation task scenario, and perform scenario-based task decomposition processing on the security operation task scenario to obtain scenario-based task information; Identify at least two vertical security models corresponding to the scenario vertical task information, generate digital object services corresponding to each vertical security model based on the scenario vertical task information, and perform collaborative association processing on the digital object services through the scenario vertical task information to obtain a digital object service cluster. In the aforementioned security operation task scenario, the digital object service cluster is used for security operations. The step of performing scenario-based task decomposition on the security operation task scenario to obtain scenario-based task information includes: performing scenario-based task splitting on the security operation task scenario to obtain at least two scenario-based security tasks; determining the vertical task collaboration relationship between the at least two scenario-based security tasks for the security operation task scenario; and obtaining scenario-based task information based on the at least two scenario-based security tasks and the vertical task collaboration relationship. The step of determining at least two large-scale vertical security models corresponding to the scenario-specific task information includes: inputting the scenario-specific security task from the scenario-specific task information into a vertical security label classification model, and outputting the vertical security label corresponding to the scenario-specific security task based on the vertical security label classification model; obtaining a large-scale vertical security model library, performing model matching in the large-scale vertical security model library using the vertical security label, obtaining the large-scale vertical security model matched by the vertical security label, and determining the large-scale vertical security model corresponding to the scenario-specific security task, thereby obtaining at least two large-scale vertical security models corresponding to the scenario-specific task information; wherein, the vertical security label classification model is a model obtained by training the basic large-scale model with sample scenario-specific security tasks and sample vertical security labels corresponding to the sample scenario-specific security tasks. The step of generating digital object services corresponding to each vertical security model based on the scenario-specific task information includes: obtaining a virtual digital person for the vertical security model; determining the input specifications corresponding to the vertical security model; determining input normalization configuration information based on the input specifications; configuring the input module of the virtual digital person using the input normalization configuration information and the scenario-specific security task; generating the output module of the virtual digital person; determining the model interface configuration information of the vertical security model; configuring the model calling module of the virtual digital person using the model interface configuration information; performing module association processing on the input module, model calling module, and output module in the virtual digital person to obtain a target virtual digital person, so that the model calling module controls the vertical security model to perform model processing on the data output by the input module, and controls the output module to obtain and output the model output data of the vertical security model; determining the target virtual digital person corresponding to each vertical security model, and obtaining the digital object services corresponding to each vertical security model based on the target virtual digital person; The step of performing collaborative association processing on the digital object services through the scenario-specific task information to obtain a digital object service cluster includes: determining the vertical task collaboration relationship in the scenario-specific task information; determining the service collaboration relationship between the digital object services based on the vertical task collaboration relationship; wherein the service collaboration relationship includes service call information and service information interaction information; and performing service association processing on the digital object services based on the service collaboration relationship to obtain a digital object service cluster.

2. The method according to claim 1, wherein, The step of performing service association processing on the digital object services based on the service collaboration relationship to obtain a digital object service cluster includes: Based on the service call information, determine the service call relationship configuration information between the digital object services; Based on the service information interaction information, determine the service information interaction configuration information between the digital object services; The digital object service is associated with the service call relationship configuration information and the service information interaction configuration information to obtain a digital object service cluster.

3. The method according to claim 1, wherein, The security operation scenario described above, utilizing the digital object service cluster for security operations, includes: Obtain the security operation task corresponding to the security operation task scenario, and determine the data to be processed corresponding to the security operation task; The security operation task and the data to be processed are input into the digital object service cluster. For the security operation task, the data to be processed is collaboratively processed by the digital object service in the digital object service cluster. Based on the digital object service cluster, the task processing result for the security operation task is output.

4. The method according to claim 1, wherein, The security operation task scenarios include browser security operation task scenarios.

5. The method according to claim 1, wherein, The step of collaboratively associating the digital object services using the scenario-specific task information to obtain a digital object service cluster includes: By using the scenario-specific task information, the digital object services corresponding to all vertical security models are collaboratively associated to obtain a digital object service cluster. Among them, the digital object services corresponding to all vertical security big models include at least two of the following: sample analysis service, alarm analysis service, attack tracing service, intelligence notification analysis service, and critical protection situation analysis service.

6. The method according to claim 1, wherein, The method further includes: When a change in the processing progress information of the vertical security big model for the vertical security task of the scenario is detected, the processing progress information is determined, and the preset virtual digital human state corresponding to the processing progress information and the digital human state image information corresponding to the preset virtual digital human state are obtained. The target virtual digital human's current digital image is updated based on the digital human's status and image information.

7. A safety operation device, wherein, The device includes: The scenario vertical task information determination module is suitable for determining security operation task scenarios and performing scenario vertical task decomposition processing on the security operation task scenarios to obtain scenario vertical task information. The determination module is adapted to determine at least two vertical security models corresponding to the scenario vertical task information, generate digital object services corresponding to each vertical security model based on the scenario vertical task information, and perform collaborative association processing on the digital object services through the scenario vertical task information to obtain a digital object service cluster. The security operations module is adapted to perform security operations using the digital object service cluster in the security operations task scenario. The scenario-specific task information determination module includes: The splitting unit is suitable for splitting the security operation task scenario into scenario-specific tasks to obtain at least two scenario-specific security tasks. The determining unit is adapted to determine the vertical task collaboration relationship between the at least two scenario-based vertical security tasks for the security operation task scenario; The scenario vertical task information acquisition unit is adapted to obtain scenario vertical task information based on the at least two scenario vertical security tasks and the collaborative relationship between the vertical tasks; The determining module includes: The model processing unit is adapted to input the scene vertical security task from the scene vertical task information into the vertical security label classification model, and output the vertical security label corresponding to the scene vertical security task based on the vertical security label classification model. The matching unit is adapted to obtain a large vertical security model library, perform model matching in the large vertical security model library using the vertical security tags, obtain the large vertical security model matched by the vertical security tags, determine the large vertical security model corresponding to the vertical security task of the scenario, so as to obtain at least two large vertical security models corresponding to the vertical task information of the scenario. The vertical security label classification model is a model obtained by training the basic large model with the sample scene vertical security task and the sample vertical security label corresponding to the sample scene vertical security task. The determining module includes: The input and output module determining unit is adapted to acquire a virtual digital human for the vertical security model, determine the input specifications corresponding to the vertical security model, determine input normalization configuration information based on the input specifications, configure the input module of the virtual digital human using the input normalization configuration information and the scenario vertical security task, and generate the output module of the virtual digital human. The model invocation module determining unit is adapted to determine the model interface configuration information of the vertical security big model, and to configure the model invocation module of the virtual digital human using the model interface configuration information; The association unit is adapted to perform module association processing on the input module, model calling module and output module in the virtual digital human to obtain the target virtual digital human, so that the model calling module controls the vertical security big model to perform model processing on the data output by the input module, and controls the output module to obtain and output the model output data of the vertical security big model; The digital object service determination unit is adapted to determine the target virtual digital person corresponding to each vertical security big model, and obtain the digital object service corresponding to each vertical security big model based on the target virtual digital person; The determining module includes: The service collaboration relationship determination unit is adapted to determine the vertical task collaboration relationship in the scenario vertical task information, and to determine the service collaboration relationship between the digital object services based on the vertical task collaboration relationship; wherein, the service collaboration relationship includes service call information and service information interaction information; The digital object service cluster determination unit is adapted to perform service association processing on the digital object services based on the service collaboration relationship to obtain a digital object service cluster.

8. The apparatus according to claim 7, wherein, The digital object service cluster determination unit includes: The first determining subunit is adapted to determine service call relationship configuration information between the digital object services based on the service call information; The second determining subunit is adapted to determine service information interaction configuration information between the digital object services based on the service information interaction information. The digital object service cluster determines a sub-unit, which is suitable for using the service call relationship configuration information and the service information interaction configuration information to perform service association processing on the digital object service, thereby obtaining the digital object service cluster.

9. The apparatus according to claim 7, wherein, The security operation module includes: The data to be processed determination unit is adapted to acquire the security operation task corresponding to the security operation task scenario and determine the data to be processed corresponding to the security operation task. The output unit is adapted to input the security operation task and the data to be processed into the digital object service cluster, and to perform collaborative processing of the data to be processed through the digital object services in the digital object service cluster for the security operation task, and to output the task processing result for the security operation task based on the digital object service cluster.

10. The apparatus according to claim 7, wherein, The security operation task scenarios include browser security operation task scenarios.

11. The apparatus according to claim 7, wherein, The determining module is also adapted to: By using the scenario-specific task information, the digital object services corresponding to all vertical security models are collaboratively associated to obtain a digital object service cluster. Among them, the digital object services corresponding to all vertical security big models include at least two of the following: sample analysis service, alarm analysis service, attack tracing service, intelligence notification analysis service, and critical protection situation analysis service.

12. The apparatus according to claim 7, wherein, The safety operation device also includes: The detection module is adapted to determine the processing progress information when it detects a change in the processing progress information of the vertical security model for the scenario vertical security task, and to obtain the preset virtual digital human state corresponding to the processing progress information, as well as the digital human state image information corresponding to the preset virtual digital human state. The update module is adapted to update the current digital image of the target virtual digital human based on the digital human status image information.

13. A terminal, wherein, The terminal includes: Processor; and A memory configured to store computer-executable instructions, which, when executed, cause the processor to perform the method according to any one of claims 1 to 6.

14. A computer-readable storage medium, wherein, The computer-readable storage medium stores one or more programs that, when executed by a processor, implement the method of any one of claims 1 to 6.

Citation Information

Patent Citations

  • Service recommendation method, electronic equipment and readable storage medium

    CN117093770A

  • Driving interaction method, system and device, medium and program product

    CN118800234A