Network security incident correlation analysis and judgment large model training method, device and equipment
By conducting semantic analysis and database query on network security issues, a prompt text training model is generated, which solves the accuracy and consistency of network security event analysis in the existing technology, and achieves efficient and accurate analysis of network security events.
Patent Information
- Application Number
- CN202510572167.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-06
- Publication Date
- 2025-08-19
- Estimated Expiration
- 2045-05-06
AI Technical Summary
In the prior art, network security incident analysis relies on expert experience and preset rules, making it difficult to ensure accuracy and consistency. Especially when facing complex and changeable cyber attacks, it is difficult to achieve fast and accurate security analysis.
By obtaining the matching of network security problems and preset problems, conducting semantic analysis, determining generalized and narrow keywords, combining network security knowledge base and threat database to generate prompt text, training network security event association analysis and analysis large models, output predicted security analysis results and conducting model training.
It realizes accurate analysis of network security incidents, outputs professional and accurate security analysis results, and improves the research and judgment ability of network security incidents.
Smart Images

Figure CN120216687B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and specifically to a method, device and equipment for training a large model for correlation analysis of network security events. Background Art
[0002] With the rapid development of computer and network technologies, cyberspace faces increasingly complex security challenges. Cyber threats, such as zero-day vulnerabilities and advanced persistent threats, are characterized by sophistication, high risk, high concealment, and long duration. These threats can cause business interruptions and data leaks, resulting in significant economic losses for businesses. They can even disrupt the normal operations of critical infrastructure industries, significantly impacting network security. Therefore, conducting security analysis of cybersecurity incidents to rapidly detect and identify potential cyber risks has become a pressing technical challenge.
[0003] In related technologies, one approach relies heavily on expert experience and the technical expertise of security analysts for cybersecurity incident analysis, making it difficult to ensure the accuracy and consistency of security analysis results and hindering scalable application. Another approach involves existing cybersecurity incident analysis, which primarily relies on pre-set rules. This lacks flexibility and makes it difficult to address complex and ever-changing cyberattack patterns. This is especially true when faced with new attacks or advanced persistent threats, where lags in pre-set rule updates significantly reduce the accuracy of cybersecurity analysis results. Summary of the Invention
[0004] The embodiments of the present application provide a method, device and equipment for training a large model for network security event correlation analysis and judgment. The trained large model for network security event correlation analysis and judgment can accurately analyze the network security events to be analyzed and output target security analysis results.
[0005] To achieve the above objectives, the present invention provides a method for training a large model for network security event correlation analysis, including:
[0006] Obtaining a network security issue corresponding to the network security event, and matching the network security issue with a preset network security issue in a preset network security issue library to obtain a matched sample preset network security issue;
[0007] Performing semantic analysis on the network security issue and the sample preset network security issue to obtain a plurality of semantic keywords;
[0008] Determining broad keywords and narrow keywords from the plurality of semantic keywords, and determining sample network security knowledge corresponding to the network security problem in a network security knowledge base based on the broad keywords;
[0009] Determining sample network threat data corresponding to the network security issue in a network threat database based on the narrow keyword;
[0010] Generate a prompt text based on the network security issue, the sample network security knowledge, and the sample network threat data, input the prompt text into a network security event correlation analysis model, and output a predicted security analysis result corresponding to the network security event;
[0011] Determine the difference between the label security analysis result corresponding to the network security event and the predicted security analysis result, and train the network security event association analysis model based on the difference to obtain the trained network security event association analysis model.
[0012] To achieve the above objectives, the present invention provides a large-scale model training device for network security event correlation analysis, including:
[0013] An acquisition module is configured to acquire a network security issue corresponding to a network security event, and match the network security issue with a preset network security issue in a preset network security issue library to obtain a matched sample preset network security issue;
[0014] An analysis module, configured to perform semantic analysis on the network security issue and the sample preset network security issue to obtain a plurality of semantic keywords;
[0015] a knowledge determination module, configured to determine broad keywords and narrow keywords from the plurality of semantic keywords, and determine sample network security knowledge corresponding to the network security problem in a network security knowledge base based on the broad keywords;
[0016] a data determination module, configured to determine sample network threat data corresponding to the network security issue in a network threat database based on the narrow keyword;
[0017] a generation module, configured to generate a prompt text based on the network security issue, the sample network security knowledge, and the sample network threat data, input the prompt text into a network security event correlation analysis model, and output a predicted security analysis result corresponding to the network security event;
[0018] The training module is used to determine the difference between the label security analysis result corresponding to the network security event and the predicted security analysis result, and train the network security event association analysis model based on the difference to obtain the trained network security event association analysis model.
[0019] In some embodiments, the acquisition module is configured to:
[0020] Inputting the network security issue into a pre-trained text processing model, and outputting a first semantic feature corresponding to the network security issue;
[0021] Inputting each preset network security issue in the preset network security issue library into the pre-trained text processing model, and outputting a second semantic feature corresponding to each preset network security issue;
[0022] A first similarity between the first semantic feature and the second semantic feature is determined, and a preset network security issue corresponding to a second semantic feature whose first similarity is greater than a first preset similarity is determined as a sample preset network security issue matching the network security issue.
[0023] In some embodiments, the analysis module is configured to:
[0024] Performing text segmentation processing on the network security issue and the sample preset network security issue respectively to obtain a plurality of subtexts corresponding to the network security issue and the sample preset network security issue respectively;
[0025] The multiple subtexts are subjected to non-network-related text filtering processing to obtain multiple semantic keywords.
[0026] In some embodiments, the knowledge determination module is configured to:
[0027] Input the multiple semantic keywords into the pre-trained word vector model respectively, and output the first word vector corresponding to each semantic keyword;
[0028] Determine a plurality of professional terminology entities in the network security knowledge base, input each professional terminology entity into a pre-trained word vector model, and output a second word vector corresponding to each professional terminology entity;
[0029] Calculating similarity between the first word vector and the second word vector to obtain a second similarity between the first word vector and the second word vector;
[0030] The semantic keywords corresponding to the first word vectors whose second similarity is greater than a second preset similarity are determined as broad keywords, and the semantic keywords other than the broad keywords among the multiple semantic keywords are determined as narrow keywords.
[0031] In some embodiments, the knowledge determination module is configured to:
[0032] Generate a first query statement according to each of the broad keywords;
[0033] A network security knowledge base is queried according to the first query statement to obtain sample network security knowledge corresponding to the network security problem.
[0034] In some embodiments, the data determination module is configured to:
[0035] generating a second query statement according to each of the narrow keywords;
[0036] A network threat database is queried according to the second query statement to obtain sample network threat data corresponding to the network security issue.
[0037] In some embodiments, a generating module is configured to:
[0038] Generate domain knowledge text corresponding to the network security issue based on the sample network security knowledge;
[0039] Generating threat data text corresponding to the network security issue based on the sample network threat data;
[0040] A prompt text is generated according to the domain knowledge text, the threat data text and the network security issue.
[0041] In some embodiments, a generating module is configured to:
[0042] Determine the network security scenario corresponding to the network security issue;
[0043] Filtering a target prompt template from a plurality of preset prompt templates according to a mapping relationship between the network security scenario and the preset prompt template;
[0044] The domain knowledge text, the threat data text and the network security issue are input into the target prompt template to generate a prompt text.
[0045] In some embodiments, the network security event correlation analysis and judgment large model training device further includes a construction module for:
[0046] Before determining the sample network threat data corresponding to the network security issue in the network threat database based on the narrow keyword, obtaining a plurality of network security entities corresponding to the network log data, network traffic data, and network security incident analysis and judgment report data in the target network environment;
[0047] Constructing network knowledge graphs corresponding to the network log data, the network traffic data, and the network security incident analysis and judgment report data respectively according to the multiple network security entities;
[0048] Aligning nodes of the network knowledge graphs corresponding to the network log data, the network traffic data, and the network security incident analysis and judgment report data, respectively, to determine aligned nodes and conflicting nodes that cannot be aligned;
[0049] Determining the data source priority corresponding to each of the conflicting nodes, and determining the reliability score of the conflicting node in each network knowledge graph based on the data source priority;
[0050] A target node is screened out from the conflicting nodes according to the reliability score, a target network knowledge graph is constructed according to the target node and the aligned nodes, and a network threat database is generated according to data corresponding to the target network knowledge graph.
[0051] In some embodiments, building blocks are provided for:
[0052] Obtaining the network attack correlation strength and network attack correlation time corresponding to each of the conflict nodes;
[0053] A reliability score of the conflicting node in each network knowledge graph is determined according to the data source priority, the network attack correlation strength, and the network attack correlation time.
[0054] To achieve the above objectives, the present invention provides a method for analyzing network security events, including:
[0055] Obtaining a target network security issue corresponding to the network security event to be analyzed, and matching the target network security issue with a preset network security issue in a preset network security issue library to obtain a matched target preset network security issue;
[0056] Performing semantic analysis on the target network security issue and the target preset network security issue to obtain a plurality of target semantic keywords;
[0057] Determining broad target keywords and narrow target keywords from the plurality of target semantic keywords, and determining target network security knowledge corresponding to the target network security problem in a network security knowledge base based on the broad target keywords;
[0058] Determining target network threat data corresponding to the target network security issue in a network threat database based on the narrow target keyword;
[0059] A target prompt text is generated based on the target network security issue, the target network security knowledge and the target network threat data, and the target prompt text is input into the trained network security event association analysis model to output the target security analysis result corresponding to the network security event to be analyzed.
[0060] To achieve the above objectives, an embodiment of the present application provides a network security event analysis device, including:
[0061] A problem acquisition module is used to acquire a target network security problem corresponding to the network security event to be analyzed, and match the target network security problem with a preset network security problem in a preset network security problem library to obtain a matched target preset network security problem;
[0062] A semantic analysis module, configured to perform semantic analysis on the target network security issue and the target preset network security issue to obtain a plurality of target semantic keywords;
[0063] a first determining module, configured to determine broad target keywords and narrow target keywords from the plurality of target semantic keywords, and determine target network security knowledge corresponding to the target network security problem in a network security knowledge base based on the broad target keywords;
[0064] A second determination module is configured to determine target network threat data corresponding to the target network security issue in a network threat database based on the narrow target keyword;
[0065] The analysis module is used to generate a target prompt text based on the target network security issue, the target network security knowledge and the target network threat data, and input the target prompt text into the trained network security event association analysis model to output the target security analysis result corresponding to the network security event to be analyzed.
[0066] In order to achieve the above-mentioned purpose, on the one hand, an embodiment of the present application provides a computer-readable storage medium, which stores multiple instructions, and the instructions are suitable for a processor to load to execute the network security event correlation analysis and judgment large model training method provided by the embodiment of the present application or the network security event analysis method provided by the embodiment of the present application.
[0067] In order to achieve the above-mentioned objectives, on the one hand, an embodiment of the present application provides a computer device, including a memory, a processor, and a computer program stored in the memory and capable of running on the processor. When the processor executes the computer program, it implements the network security event correlation analysis and judgment large model training method provided by the embodiment of the present application or the network security event analysis method provided by the embodiment of the present application.
[0068] In an embodiment of the present application, a network security issue corresponding to a network security incident is obtained, and the network security issue is matched with a preset network security issue in a preset network security issue library to obtain a matched sample preset network security issue; semantic analysis is performed on the network security issue and the sample preset network security issue to obtain a plurality of semantic keywords; broad keywords and narrow keywords are determined from the plurality of semantic keywords, and sample network security knowledge corresponding to the network security issue is determined in a network security knowledge base based on the broad keywords; sample network threat data corresponding to the network security issue is determined in a network threat database based on the narrow keywords; prompt text is generated based on the network security issue, the sample network security knowledge and the sample network threat data, and the prompt text is input into a network security incident association analysis and judgment big model to output a predicted security analysis result corresponding to the network security incident; the difference between the label security analysis result and the predicted security analysis result corresponding to the network security incident is determined, and the network security incident association analysis and judgment big model is trained based on the difference to obtain a trained network security incident association analysis and judgment big model.
[0069] To this end, we first obtain sample pre-set cybersecurity issues similar to those in cybersecurity incidents. Semantic analysis is then performed on the network security issues and sample pre-set cybersecurity issues to obtain multiple semantic keywords, thereby increasing the richness of the semantic keywords. Broad and narrow keywords are then identified from these multiple semantic keywords. Based on the broad keywords, sample cybersecurity knowledge corresponding to the cybersecurity issues is identified from the cybersecurity knowledge base. Based on the narrow keywords, sample cyberthreat data corresponding to the cybersecurity issues is identified from the network threat database. This allows us to acquire knowledge related to cybersecurity issues from a cybersecurity knowledge base that encompasses knowledge in various network domains, and to obtain data related to cybersecurity issues from historical cybersecurity incidents in the network threat database. Then, a prompt text is generated based on network security issues, sample network security knowledge, and sample network threat data, which can increase the richness of the information contained in the prompt text. The prompt text can provide professional network security knowledge to the network security event association analysis model, and can also provide accurate network threat data. In combination with network security issues, a prompt text that more accurately describes the network security event is generated. Finally, the prompt text is input into the network security event association analysis model to output the predicted security analysis result corresponding to the network security event; the difference between the label security analysis result and the predicted security analysis result corresponding to the network security event is determined, and the network security event association analysis model is trained based on the difference to obtain the trained network security event association analysis model. Compared with the scheme in the related art that relies on human experience to analyze and evaluate network security events, the trained network security event association analysis model in this application can more accurately analyze the network security event to be analyzed, so as to output professional and accurate target security analysis results. The target security analysis result realizes accurate research and judgment of the network security event to be analyzed.
[0070] Other features and advantages of the present application will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present application. The purposes and other advantages of the present application can be achieved and obtained through the structures particularly pointed out in the description, claims and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0071] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative work.
[0072] Figure 1This is a schematic diagram of the system framework corresponding to the network security event correlation analysis and judgment large model training method and the network security event analysis method provided in the embodiments of the present application;
[0073] Figure 2 This is a schematic diagram of a scenario for network security incident analysis provided by an embodiment of the present application;
[0074] Figure 3 This is a flowchart of a large-scale model training method for network security event correlation analysis and judgment provided by an embodiment of the present application;
[0075] Figure 4 This is another flowchart of the method for training a large model for network security event correlation analysis and judgment provided by an embodiment of the present application;
[0076] Figure 5 This is a flowchart of the network security incident analysis method provided by the present application;
[0077] Figure 6 This is a schematic diagram of the structure of a large-scale model training device for network security event correlation analysis and judgment provided by an embodiment of the present application;
[0078] Figure 7 This is a schematic diagram of the structure of a network security event analysis device provided in an embodiment of the present application;
[0079] Figure 8 It is a structural diagram of the computer device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0080] In order to enable those skilled in the art to better understand the solutions of this application, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without making any creative efforts shall fall within the scope of protection of this application.
[0081] It should be noted that in each specific embodiment of the present application, when it comes to the need to perform relevant processing based on data related to network security information, the permission or consent of the subject will be obtained first, and the collection, use and processing of such data will comply with relevant laws, regulations and standards. In addition, when the embodiment of the present application needs to obtain the sensitive personal information of the subject, the subject's separate permission or consent will be obtained through a pop-up window or by jumping to a confirmation page. After clearly obtaining the subject's separate permission or consent, the necessary object-related data for the normal operation of the embodiment of the present application will be obtained.
[0082] It should be noted that some processes described in the specification, claims, and figures above include multiple steps that appear in a specific order. However, it should be understood that these steps may be executed in a different order than the order in which they appear herein or in parallel. The step numbers are used solely to distinguish between the different steps and do not themselves represent any order of execution. Furthermore, terms such as "first," "second," or "target" are used herein to distinguish similar objects and are not necessarily used to describe a specific order or precedence.
[0083] The network security event correlation analysis and judgment large model training method and network security event analysis method provided in the embodiments of the present application relate to the field of artificial intelligence technology. The network security event correlation analysis and judgment large model training method and network security event analysis method provided in the embodiments of the present application can be applied to the terminal, can also be applied to the server side, and can also be software running in the terminal or the server side. In some embodiments, the terminal can be a smart phone, tablet computer, laptop computer, desktop computer, etc.; the server side can be configured as an independent physical server, or can be configured as a server cluster or distributed system composed of multiple physical servers, and can also be configured as a cloud server that provides cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms and other basic cloud computing services; the software can be an application that implements the network security event correlation analysis and judgment large model training method and network security event analysis method, etc., but is not limited to the above forms.
[0084] Before further explaining the embodiments of the present application in detail, the nouns and terms involved in the embodiments of the present application are explained. The nouns and terms involved in the embodiments of the present application are subject to the following interpretations:
[0085] Network vulnerabilities: Network vulnerabilities refer to security flaws or weaknesses in the design, implementation, configuration, or maintenance of computer network systems (including hardware, software, network protocols, etc.). These vulnerabilities make network systems vulnerable to exploitation by attackers, leading to security incidents such as information leakage, system damage, and service interruptions. For example, a buffer overflow vulnerability in software code may allow an attacker to execute malicious code on the target system. In this application, network vulnerabilities can be Common Vulnerabilities and Exposures (CVEs). CVEs are used to assign unique identifiers to information security vulnerabilities and exposures. They act like a unified "identity card" system, numbering and recording various security issues in software, hardware, systems, and so on.
[0086] Vulnerability and weakness examples: These can be the Common Weakness Enumeration (CWE), which is used to categorize and describe security weaknesses in software and hardware systems. A CVE vulnerability can typically be mapped to one or more CWE weakness categories.
[0087] Vulnerability attack examples: A specific example is the Common Attack Pattern Enumeration and Classification (CAPEC). CAPEC is a comprehensive attack pattern knowledge base that categorizes and enumerates network attack patterns, acting like an attacker's "playbook," describing how to exploit vulnerabilities and weaknesses. CWE defines system vulnerabilities, while CAPEC demonstrates how to exploit these vulnerabilities. The connection between these two helps security defenders think from the attacker's perspective, leading to better defenses. CAPEC forms the foundation for both tactics and techniques. Tactics guide the use of techniques, while techniques provide the specific means of implementing the attack patterns outlined in CAPEC.
[0088] Technique: Attack technology refers to the specific technical means used by attackers in the process of implementing attacks, such as using specific tools, scripts or codes to achieve the attack objectives.
[0089] Tactics: Attack tactics are a higher-level plan. They are a series of strategic actions taken by attackers to achieve their goals (such as obtaining data or destroying systems). They include selecting attack targets, timing, and combining multiple attack techniques.
[0090] Knowledge Graph: A knowledge graph is a semantic network with extremely strong expressive power and modeling flexibility. Essentially, it is a semantic knowledge base that symbolically depicts various real-world concepts and their relationships. Its basic unit is the "entity-relationship-entity" triple. A knowledge graph can be viewed as a graph consisting of nodes and edges. Nodes represent entities or concepts in the physical world, while edges represent the various semantic relationships between entities or concepts. This graph structure clearly demonstrates the complex connections between various entities and integrates fragmented knowledge into an organic whole.
[0091] The above is the definition of the relevant professional terms involved in this application. If other professional terms are involved later, they will be explained later.
[0092] First, let’s describe the technical problems existing in related technologies:
[0093] With the rapid development of computer and network technologies, cyberspace faces increasingly complex security challenges. Cyber threats, such as zero-day vulnerabilities and advanced persistent threats, are characterized by sophistication, high risk, high concealment, and long duration. These threats can cause business interruptions and data leaks, resulting in significant economic losses for businesses. They can even disrupt the normal operations of critical infrastructure industries, significantly impacting network security. Therefore, conducting security analysis of cybersecurity incidents to rapidly detect and identify potential cyber risks has become a pressing technical challenge.
[0094] In related technologies, one approach relies heavily on expert experience and the technical expertise of security analysts for cybersecurity incident analysis, making it difficult to ensure the accuracy and consistency of security analysis results and hindering scalable application. Another approach involves existing cybersecurity incident analysis, which primarily relies on pre-set rules. This lacks flexibility and makes it difficult to address complex and ever-changing cyberattack patterns. This is especially true when faced with new attacks or advanced persistent threats, where lags in pre-set rule updates significantly reduce the accuracy of cybersecurity analysis results.
[0095] In order to solve the above technical problems, the embodiments of the present application provide a large-scale model training method for network security event correlation analysis and a network security event analysis method, device, computer equipment and storage medium. Among them, by obtaining sample preset network security issues similar to the network security issues of the network security incident, and then performing semantic analysis on the network security issues and the sample preset network security issues, a plurality of semantic keywords are obtained, which can increase the richness of the semantic keywords. Then, broad keywords and narrow keywords are determined from the multiple semantic keywords, and sample network security knowledge corresponding to the network security issues is determined in the network security knowledge base based on the broad keywords, and sample network threat data corresponding to the network security issues is determined in the network threat database based on the narrow keywords. In this way, it is possible to obtain knowledge related to network security issues in the network security knowledge base that contains a variety of network field knowledge, and it is possible to obtain data related to network security issues in historical network security events in the network threat database. Then, a prompt text is generated based on network security issues, sample network security knowledge, and sample network threat data, which can increase the richness of the information contained in the prompt text. The prompt text can provide professional network security knowledge to the network security event association analysis model, and can also provide accurate network threat data. In combination with network security issues, a prompt text that more accurately describes the network security event is generated. Finally, the prompt text is input into the network security event association analysis model to output the predicted security analysis result corresponding to the network security event; the difference between the label security analysis result and the predicted security analysis result corresponding to the network security event is determined, and the network security event association analysis model is trained based on the difference to obtain the trained network security event association analysis model. Compared with the scheme in the related art that relies on human experience to analyze and evaluate network security events, the trained network security event association analysis model in this application can more accurately analyze the network security event to be analyzed, so as to output professional and accurate target security analysis results. The target security analysis result realizes accurate research and judgment of the network security event to be analyzed.
[0096] The network security event correlation analysis and judgment large-scale model training method and network security event analysis method, device, computer equipment and storage medium provided in the embodiments of the present application will be described in detail later.
[0097] See also Figure 1 , Figure 1 This is a schematic diagram of the system framework corresponding to the network security event correlation analysis and judgment large model training method and network security event analysis method provided in the embodiment of this application. The network security event correlation analysis and judgment large model training method and network security event analysis method provided in the embodiment of this application can be applied to this system framework.
[0098] It includes a terminal 140, the Internet 130, a gateway 120, a server 110, and the like.
[0099] The terminal 140 or the server 110 may be a device for executing a large-scale model training method for network security event correlation analysis or a network security event analysis method.
[0100] Terminal 140 includes, but is not limited to, mobile phones, computers, intelligent voice interaction devices, smart home appliances, vehicle-mounted terminals, aircraft, and the like. Embodiments of the present application can be applied in various scenarios, including, but not limited to, network security and network defense. Furthermore, it can be a single device or a combination of multiple devices. For example, multiple desktop computers connected via a local area network, sharing a common display, and working collaboratively, collectively constitute a terminal 140. Terminal 140 can communicate with Internet 130 via wired or wireless means to exchange data.
[0101] Server 110 refers to a computer system that provides certain services to terminal 140. Compared to ordinary terminal 140, server 110 has higher requirements in terms of stability, security, and performance. Server 110 can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms.
[0102] Gateway 120, also known as a gateway or protocol converter, implements network interconnection at the transport layer and is a computer system or device that performs a conversion function. It acts as a translator between two systems using different communication protocols, data formats, languages, or even completely different architectures. Gateways can also provide filtering and security functions. Messages sent from terminal 140 to server 110 are sent through gateway 120 to the corresponding server 110. Messages sent from server 110 to terminal 140 are also sent through gateway 120 to the corresponding terminal 140.
[0103] The network security event correlation analysis and judgment large model training method and network security event analysis method in the embodiments of this application can be applied to a variety of scenarios, such as cloud services, network security, etc. This does not limit the scenarios in which the network security event correlation analysis and judgment large model training method and network security event analysis method in this application are applied.
[0104] See also Figure 2 , Figure 2 This is a scenario diagram of network security incident analysis provided in an embodiment of the present application.
[0105] In this application, network security incident analysis is mainly based on the trained network security incident correlation analysis model. When a network security incident to be analyzed is found in the network, the object can write an initial target network security problem based on the network security incident to be analyzed and input it.
[0106] The computer device may match the target network security issue with the preset network security issues in the preset network security issue library to obtain a matching target preset network security issue. For example, the computer device may obtain a target semantic feature of the target network security issue and then match the target semantic feature with the semantic features of multiple preset network security issues to obtain a matching target preset network security issue.
[0107] Then, semantic analysis is performed on the target cybersecurity issue and the target pre-set cybersecurity issue to obtain multiple target semantic keywords. For example, keywords with semantic similarities to the target cybersecurity issue can be found in multiple subtexts within the target cybersecurity issue, and keywords with semantic similarities to the target pre-set cybersecurity issue can be found in multiple subtexts within the target pre-set cybersecurity issue. These keywords are then identified as target semantic keywords. This avoids inaccurate information representation caused by inaccurate input of the target cybersecurity issue or limited input content.
[0108] Then, broad target keywords and narrow target keywords are determined from the multiple target semantic keywords, and target network security knowledge corresponding to the target network security problem is determined from the network security knowledge base based on the broad target keywords. Target network threat data corresponding to the target network security problem is determined from the network threat database based on the narrow target keywords.
[0109] Finally, a target prompt text is generated based on the target network security problem, target network security knowledge, and target network threat data, and the target prompt text is input into the trained network security event association analysis model to output the target security analysis result corresponding to the network security event to be analyzed. For example, network security professional knowledge text and log data text can be output based on the target network security knowledge and target network threat data, and then a prompt text can be generated in combination with the target network security problem to increase the network security information about the network security event to be analyzed in the prompt text, so as to more accurately guide the trained network security event association analysis model to output a more accurate target security analysis result corresponding to the network security event to be analyzed. The target security analysis result can be the correlation analysis result after the network security event to be analyzed is studied and judged, such as the correlation between the network security event and the attack technology and attack tactics. Compared with the scheme in the related art that relies on human experience to analyze and evaluate network security events, the network security event association analysis model trained in this application can more accurately analyze the network security event to be analyzed to output professional and accurate target security analysis results, which realize the accurate research and judgment of the network security event to be analyzed.
[0110] In order to more clearly understand the trained network security event correlation analysis model provided by the embodiment of this application. Figure 3 , Figure 3 This is a flow chart of a method for training a large model for network security event correlation analysis and judgment provided by an embodiment of the present application. The method for training a large model for network security event correlation analysis and judgment may include the following steps:
[0111] Step 210: Obtain a network security issue corresponding to the network security event, and match the network security issue with a preset network security issue in a preset network security issue library to obtain a matching sample preset network security issue.
[0112] Step 220: Perform semantic analysis on the network security issue and the sample preset network security issue to obtain multiple semantic keywords;
[0113] Step 230: Determine broad keywords and narrow keywords from the plurality of semantic keywords, and determine sample network security knowledge corresponding to the network security problem in the network security knowledge base based on the broad keywords;
[0114] Step 240: Determine sample network threat data corresponding to the network security issue in the network threat database based on the narrow keyword;
[0115] Step 250: Generate prompt text based on the network security issue, sample network security knowledge, and sample network threat data, input the prompt text into the network security event correlation analysis model, and output the predicted security analysis result corresponding to the network security event;
[0116] Step 260: Determine the difference between the label security analysis result and the predicted security analysis result corresponding to the network security event, and train the network security event association analysis model based on the difference to obtain the trained network security event association analysis model.
[0117] Steps 210 to 260 will be described in detail below.
[0118] In step 210, a network security issue corresponding to the network security event is obtained, and the network security issue is matched with a preset network security issue in a preset network security issue library to obtain a matching sample preset network security issue.
[0119] Cybersecurity incidents can be events that impact network security, such as network vulnerability attacks, traffic hijacking, and advanced persistent threat attacks. These incidents require targeted analysis and research to identify the attack techniques and tactics that led to them, and then implement corresponding countermeasures to protect network security.
[0120] Users input cybersecurity questions corresponding to cybersecurity incidents. Cybersecurity questions are questions posed to address the incident. However, because human input questions may be incomplete or inaccurate, the cybersecurity incident correlation analysis model may not receive accurate instruction information and thus cannot accurately generate answers to cybersecurity questions, specifically, it cannot accurately generate research and judgment results related to the cybersecurity incident.
[0121] To address this issue, this application matches network security issues with pre-set network security issues in a pre-set network security issue library to obtain matching sample pre-set network security issues. This allows the pre-set network security issues that are similar to the network security issues to be screened from the relatively professional and standard pre-set network security issues already included in the pre-set network security issue library, thereby supplementing the network security issues and avoiding the subsequent inaccurate instructions contained in the generated prompt text due to insufficient network security issues. This allows the network security event correlation analysis model to provide accurate and comprehensive prediction and analysis results for network security events.
[0122] In some implementations, the network security question is matched with a preset network security question in a preset network security question library to obtain a matching sample preset network security question, including:
[0123] (1.1) Inputting the cybersecurity issue into the pre-trained text processing model and outputting the first semantic feature corresponding to the cybersecurity issue;
[0124] (1.2) Inputting each preset cybersecurity issue in the preset cybersecurity issue library into the pre-trained text processing model, and outputting a second semantic feature corresponding to each preset cybersecurity issue;
[0125] (1.3) Determine a first similarity between the first semantic feature and the second semantic feature, and determine a preset network security issue corresponding to the second semantic feature whose first similarity is greater than the first preset similarity as a sample preset network security issue that matches the network security issue.
[0126] Among them, the network security issue can be input into the pre-trained text processing model to output the first semantic feature corresponding to the network security issue. The pre-trained text processing model can extract the semantic features contained in the text. The pre-trained text processing model can be a pre-trained model such as BERT, Sentence-BERT, etc. The network security issue is actually equivalent to a text. The network security issue is input into the pre-trained text processing model. The pre-trained text processing model can perform semantic extraction on the network security issue based on the context information in the network security issue, thereby obtaining the first semantic feature.
[0127] Alternatively, each pre-set cybersecurity question in the pre-set cybersecurity question library can be input into the pre-trained text processing model to output a second semantic feature corresponding to each pre-set cybersecurity question. Similarly, the pre-trained text processing model can perform semantic extraction on each pre-set security question based on the contextual information contained in each pre-set security question, thereby obtaining a second semantic feature corresponding to each pre-set security question.
[0128] The first semantic feature and the second semantic feature are actually both vectors, and the first similarity between the first semantic feature and the second semantic feature can be determined. For example, the cosine similarity between the first semantic feature and the second semantic feature can be determined, and the cosine similarity can be used as the first similarity between the first semantic feature and the second semantic feature. For another example, the Euclidean distance between the first semantic feature and the second semantic feature can be determined, and then the mapping relationship between the Euclidean distance and the similarity value can be determined to determine the first similarity between the first semantic feature and the second semantic feature, wherein the larger the Euclidean distance, the smaller the similarity value, and conversely, the smaller the Euclidean distance, the greater the similarity value.
[0129] Finally, the preset cybersecurity issue corresponding to the second semantic feature whose first similarity is greater than the first preset similarity is determined as a sample preset cybersecurity issue that matches the cybersecurity issue. For example, the preset cybersecurity issue library includes preset cybersecurity issue A and preset cybersecurity issue B. If the first similarity between the second semantic feature corresponding to preset cybersecurity issue A and the first semantic feature is greater than the first preset similarity, then preset cybersecurity issue A is determined as a sample preset cybersecurity issue that matches the cybersecurity issue. If the first similarity between the second semantic feature corresponding to preset cybersecurity issue B and the first semantic feature is not greater than the first preset similarity, then preset cybersecurity issue B is not a sample preset cybersecurity issue that matches the cybersecurity issue.
[0130] The pre-set cybersecurity question database includes a seed question sub-database and a historical question sub-database. The seed question sub-database contains pre-defined typical cybersecurity questions and their corresponding standard answers, covering scenarios such as common attack patterns, vulnerability exploitation, threat intelligence analysis, and attack behavior analysis. The historical question sub-database contains historical cybersecurity questions and their corresponding answers, reflecting the diverse question formats and research needs in real-world scenarios.
[0131] As can be seen from the above, by determining the similarity between the semantic features of cybersecurity issues and pre-set cybersecurity issues, we can identify sample pre-set cybersecurity issues that match the cybersecurity issues, thereby ensuring the accuracy of the identified sample pre-set cybersecurity issues. This can effectively address issues such as the diverse forms of user input questions and the lack of professional information, and improve the accuracy of the instructions contained in the prompt text subsequently input into the large-scale cybersecurity incident correlation analysis model.
[0132] In step 220, semantic analysis is performed on the network security issue and the sample preset network security issue to obtain a plurality of semantic keywords.
[0133] Among them, network security issues and sample preset network security issues are both long texts, which require semantic analysis to find multiple semantic keywords related to network security in the long texts.
[0134] In some implementations, semantic analysis is performed on the network security issues and the sample preset network security issues to obtain multiple semantic keywords, including:
[0135] (1.1) Performing text segmentation processing on the network security issues and the sample preset network security issues respectively to obtain multiple subtexts corresponding to the network security issues and the sample preset network security issues respectively;
[0136] (1.2) Filter the non-network-related texts of the multiple sub-texts to obtain multiple semantic keywords.
[0137] Among them, we can first determine the grammar corresponding to the network security issues and the sample preset network security issues, and then divide and process the network security issues and the sample preset network security issues according to the grammar to obtain multiple sub-texts corresponding to the network security issues and the sample preset network security issues.
[0138] For example, consider a network security question like "How to analyze the payload of IP8.8.8.8 in the attack alert log?" After segmentation, we obtain subtexts such as "how," "analysis," "IP8.8.8.8," "attack," and "payload."
[0139] The multiple subtexts are then filtered for non-network-related text to obtain multiple semantic keywords. For example, each subtext can be matched with preset stop words. If a match is successful, the matched subtexts are filtered. The parts of speech corresponding to some subtexts can also be determined. Based on the parts of speech, some subtexts that do not contribute much to the semantics are then identified and filtered. Finally, multiple semantic keywords are obtained. Semantic keywords can be understood as words that make a significant contribution to the semantics of the entire network security issue or the sample preset network security issue. They are keywords that can represent the core semantics of these long texts.
[0140] In step 230 , broad keywords and narrow keywords are determined from the plurality of semantic keywords, and sample network security knowledge corresponding to the network security problem is determined in the network security knowledge base based on the broad keywords.
[0141] Among these, multiple semantic keywords include broad keywords and narrow keywords. Broad keywords can be understood as keywords related to professional terminology in the field of network security, while broad keywords are equivalent to summarizing one or more concepts. For example, in the above semantic keyword "load," this keyword has a corresponding definition in the network security knowledge base and is considered a broad keyword. However, the semantic keyword "IP8.8.8.8" has no corresponding definition in the network security knowledge base and is a keyword with a definite meaning, so it is a narrow keyword.
[0142] In some implementations, determining broad keywords and narrow keywords from a plurality of semantic keywords includes:
[0143] (1.1) Input multiple semantic keywords into the pre-trained word vector model and output the first word vector corresponding to each semantic keyword;
[0144] (1.2) Identify multiple professional terminology entities in the cybersecurity knowledge base, input each professional terminology entity into a pre-trained word vector model, and output a second word vector corresponding to each professional terminology entity;
[0145] (1.3) Calculating the similarity between the first word vector and the second word vector to obtain a second similarity between the first word vector and the second word vector;
[0146] (1.4) Determine the semantic keyword corresponding to the first word vector whose second similarity is greater than the second preset similarity as a broad keyword, and determine the semantic keywords other than the broad keyword among the multiple semantic keywords as narrow keywords.
[0147] Among them, multiple semantic keywords can be input into the pre-trained word vector model respectively, and the first word vector corresponding to each semantic keyword can be output. The pre-trained word vector model can encode each semantic keyword, thereby generating a vector of a certain dimension, that is, the first word vector.
[0148] Then, multiple professional terminology entities are identified in the cybersecurity knowledge base. Professional terminology entities can be understood as entities that describe cybersecurity knowledge, such as cybersecurity vulnerabilities (CVE), vulnerability weakness examples (CWE), vulnerability attack examples (CAPEC), technology (Technique), tactics (Tactic), and other professional terminology entities corresponding to cybersecurity knowledge. Professional terminology entities are actually text.
[0149] Each professional term entity is then input into the pre-trained word vector model, and the second word vector corresponding to each professional term entity is output. The pre-trained word vector model can encode each professional term entity, thereby generating a vector of a certain dimension, namely the second word vector.
[0150] Then, similarity is calculated between the first word vector and the second word vector to obtain a second similarity between the first word vector and the second word vector. For example, the cosine similarity between the first word vector and the second word vector can be calculated and used as the second similarity between the first word vector and the second word vector.
[0151] Finally, the semantic keywords corresponding to the first word vectors whose second similarity is greater than the second preset similarity are determined as broad keywords, and the semantic keywords other than the broad keywords among the multiple semantic keywords are determined as narrow keywords. For example, if the second similarity corresponding to a first word vector is greater than the second preset similarity, it means that the first word vector matches the professional term entity in the cybersecurity knowledge base, and the first word vector is then treated as a broad keyword.
[0152] By analogy, all broad keywords among the multiple semantic keywords can be determined, and then the remaining semantic keywords can be determined as narrow keywords.
[0153] After the broad keywords and the narrow keywords are determined, sample network security knowledge corresponding to the network security issues can be determined in the network security knowledge base based on the broad keywords.
[0154] In some implementations, determining sample network security knowledge corresponding to network security issues in a network security knowledge base based on broad keywords includes:
[0155] (2.1) generating a first query statement based on each broad keyword;
[0156] (2.2) Query the network security knowledge base according to the first query statement to obtain sample network security knowledge corresponding to the network security problem.
[0157] Among them, after obtaining the broad keywords, a first query statement can be generated according to each broad keyword. The first query statement can specifically be an SQL query statement. Through the first query statement, the network security knowledge base can be queried to determine the relevant sample network security knowledge containing the narrow keywords.
[0158] For example, the first query statement is: SELECT * FROM mitre_techniques WHERE descriptionLIKE '%payload%' OR description LIKE '%malware%'. This query statement can be used to query the network security knowledge base.
[0159] The sample network security knowledge can be understood as a description of the network security content of a broad keyword. For example, if the broad keyword is "attack payload", the sample network security knowledge is "attack payload refers to the malicious code or data delivered by malware during the attack process."
[0160] The advantage of doing this is that it is possible to accurately search for network security knowledge through broad keywords, and through the professional network security knowledge in the network security knowledge base, it is possible to supplement the prompt text subsequently input into the network security event correlation analysis model with network security knowledge, making the information contained in the prompt text more accurate and richer.
[0161] In some implementations, before determining sample network threat data corresponding to network security issues in a network threat database based on narrow keywords, the method further includes:
[0162] (3.1) Obtain multiple network security entities corresponding to network log data, network traffic data, and network security incident analysis and assessment report data in the target network environment;
[0163] (3.2) Constructing network knowledge graphs corresponding to network log data, network traffic data, and network security incident analysis and judgment report data based on multiple network security entities;
[0164] (3.3) Align the nodes of the network knowledge graphs corresponding to the network log data, network traffic data, and network security incident assessment report data to determine aligned nodes and conflicting nodes that cannot be aligned;
[0165] (3.4) Determine the data source priority corresponding to each conflicting node, and determine the reliability score of the conflicting node in each network knowledge graph based on the data source priority;
[0166] (3.5) Filter out target nodes from the conflicting nodes based on the reliability scores, construct a target network knowledge graph based on the target nodes and the aligned nodes, and generate a network threat database based on the data corresponding to the target network knowledge graph.
[0167] Among them, this application also includes a network threat database, which contains various types of data, such as a network security incident analysis report. The network security incident analysis report is the analysis result of network security experts after research and judgment on network security incidents. It includes the analyzed network security issues, the logic of analyzing network security incidents corresponding to the network security issues, the rules for analyzing network security incidents, the results of analyzing network security incidents, etc. The report provides the experience and rules for analyzing network security incidents in actual scenarios, which can help subsequent network security incident correlation analysis models learn how to extract key information from complex data and form analysis conclusions on network security incidents.
[0168] The network threat database also includes network logs, such as honey-stepping logs, alarm logs, terminal logs, etc. The network threat database also includes traffic data, such as the data traffic generated during upload and download processes of different IP addresses.
[0169] That is to say, the network threat database in this application contains data from multiple sources, but there may be certain conflicts between these data. Therefore, data cleaning and data filtering are required for these data.
[0170] First, obtain the network log data, network traffic data and network security incident analysis report data in the target network environment. These data are the most original data.
[0171] Then, multiple network security entities corresponding to network log data, network traffic data, and network security incident analysis and assessment reports in the target network environment are obtained. For example, a pre-trained network security entity recognition model is used to identify entities in different data sets, thereby obtaining network security-related entities such as attacker IP addresses, victim hosts, vulnerability CVE-IDs, and attack stage labels.
[0172] Then, based on multiple network security entities, network knowledge graphs corresponding to network log data, network traffic data, and network security incident assessment report data are constructed. For example, a network knowledge graph corresponding to network log data is constructed based on multiple entities corresponding to network log data, a network knowledge graph corresponding to network traffic data is constructed based on multiple entities corresponding to network traffic data, and a network knowledge graph corresponding to network security incident assessment report data is constructed based on multiple entities corresponding to network security incident assessment report data.
[0173] The network knowledge graphs corresponding to network log data, network traffic data, and network security incident analysis and assessment report data are then aligned to identify aligned nodes and conflicting nodes that cannot be aligned. Knowledge graph alignment is a key task in the knowledge graph field, primarily used to discover semantic associations such as equivalent entities and relationships between different knowledge graphs or within the same knowledge graph.
[0174] For example, node alignment can be achieved through graph matching, which views the knowledge graph as a graph structure, with entities as nodes and relationships as edges. Graph matching methods aim to find the best match of nodes and edges between two graphs. For example, subgraph isomorphism algorithms can be used to determine whether subgraphs in two knowledge graphs are similar, thereby identifying aligned nodes and conflicting nodes that cannot be aligned between network knowledge graphs.
[0175] Specifically, conflicting nodes that cannot be aligned (for example, the attacker's IP address 192.168.1.100 appears in a log, but there is no communication record for this IP address in the mirrored traffic) are marked as entity mapping conflicts. The timestamps of the attack event entities in each data source (such as the time of vulnerability exploitation and the time of activation of the lateral movement node) are extracted to construct the attack link timeline. Logical contradictions are detected (for example, a host is marked as "isolated" during the vulnerability exploitation phase, but new alarms appear in the subsequent phase) and marked as temporal logic conflicts. In addition, if a log classifies the attack behavior as "reconnaissance," while the analysis report labels the attack behavior as "initial access," this is marked as a semantic description conflict.
[0176] The data source priority corresponding to each conflicting node is then determined, and the reliability score of the conflicting node in each network knowledge graph is determined based on the data source priority. For example, among the above data sources, the data source priority of the network security incident assessment report data is the highest, the data source priority corresponding to the network log data is the second highest, and the data source priority corresponding to the network traffic data is the lowest. If there is a conflicting node between the network knowledge graph corresponding to the network log data and the network knowledge graph corresponding to the network traffic data, then the conflicting node of the network knowledge graph corresponding to the network log data can be determined as the target node.
[0177] Finally, a target network knowledge graph is constructed based on the target node and the aligned nodes, and a network threat database is generated based on the data corresponding to the target network knowledge graph. For example, a comprehensive target network knowledge graph can be constructed based on the target node and the aligned nodes, which includes the data of entities corresponding to multiple data sources, excluding the data of conflicting nodes that have not been filtered as target nodes. In this way, a network threat database is generated based on the data corresponding to each node in the target network knowledge graph.
[0178] The advantage of this is that conflicting data in multiple data sources can be filtered, so that conflict-free and accurate data can be retained to form a network threat database, ensuring the data reliability of the network threat database.
[0179] In some embodiments, determining the reliability score of the conflicting node in each network knowledge graph based on the data source priority includes:
[0180] (3.4.1) Obtain the network attack correlation strength and network attack correlation time corresponding to each conflict node;
[0181] (3.4.2) Determine the reliability score of the conflicting node in each network knowledge graph based on the data source priority, network attack correlation strength, and network attack correlation time.
[0182] The network attack association strength and network attack association time corresponding to each conflict node can also be obtained. The network attack association strength corresponding to each conflict node is the association strength of the associated entities of each conflict node in the corresponding network knowledge graph. That is, the more associated entities each conflict node has in the corresponding network knowledge graph, the stronger the network attack association strength, and the fewer associated entities each conflict node has in the corresponding network knowledge graph, the weaker the network attack association strength. The network attack association time corresponding to each conflict node is the time when the network event corresponding to each conflict node occurred.
[0183] Then, the reliability score of the conflicting node in each network knowledge graph is determined based on the data source priority, network attack correlation strength, and network attack correlation time. The specific calculation method is as follows:
[0184] .in, Rating for reliability, is the data source priority, is the network attack correlation intensity, is the network attack correlation time, and is the weight coefficient.
[0185] Through the above method, the reliability score of each conflict node can be determined more accurately, thereby accurately screening out the target node from multiple conflict nodes, and improving the data reliability of the subsequently constructed network threat database.
[0186] In step 240 , sample network threat data corresponding to the network security issue is determined in the network threat database based on the narrow keywords.
[0187] Among them, each narrow keyword can be used as an index condition to query the network threat database to determine the sample network threat data corresponding to the network security problem.
[0188] In some implementations, determining sample network threat data corresponding to network security issues in a network threat database based on narrow keywords includes:
[0189] (1.1) Generate a second query statement based on each narrow keyword;
[0190] (1.2) Query the network threat database according to the second query statement to obtain sample network threat data corresponding to the network security issue.
[0191] After obtaining the narrow keywords, a second query statement can be generated according to each narrow keyword. The second query statement can specifically be an SQL query statement. The second query statement can be used to query the network threat database, thereby determining relevant sample network threat data containing the narrow keywords.
[0192] For example, the second query statement is: SELECT * FROM THREAT_LOGS WHERE IP_ADDRESS = '8.8.8.8'. This query statement can be used to query the network threat database.
[0193] Sample network threat data can be understood as real data occurring in the network environment corresponding to narrow keywords, such as alarm logs, traffic data, threat intelligence, etc. related to narrow keywords.
[0194] The advantage of doing this is that it is possible to accurately search for network threat data through narrow keywords, and the real network threat data in the network threat database can be used to supplement the prompt text subsequently input into the network security incident correlation analysis model with real data, making the information contained in the prompt text more real and accurate.
[0195] In step 250, a prompt text is generated based on network security issues, sample network security knowledge and sample network threat data, and the prompt text is input into the network security event correlation analysis model to output the predicted security analysis results corresponding to the network security event.
[0196] Among them, the texts corresponding to network security issues, sample network security knowledge and sample network threat data can be determined respectively, these texts can be integrated to generate prompt texts, the prompt texts can be input into the network security event correlation analysis model, and the predictive security analysis results corresponding to the network security events can be output.
[0197] In some implementations, generating prompt text based on network security issues, sample network security knowledge, and sample network threat data includes:
[0198] (1.1) Generate domain knowledge text corresponding to network security issues based on sample network security knowledge;
[0199] (1.2) Generate threat data text corresponding to network security issues based on sample network threat data;
[0200] (1.3) Generate prompt text based on domain knowledge text, threat data text, and network security issues.
[0201] For example, domain knowledge text corresponding to network security issues is generated based on sample network security knowledge. The domain knowledge text is: attack payload refers to the malicious code or data transmitted by malware during the attack process. Payload analysis is to identify the attacker's intentions and technical means through in-depth research on payload behavior.
[0202] Generate threat data text corresponding to network security issues based on sample network threat data. The threat data text is: IP 8.8.8.8 records the following behavior in the attack alarm log: [specific log content].
[0203] The corresponding text for the network security question is: How to analyze the payload of IP8.8.8.8 in the attack alarm log?
[0204] Then you can generate prompt text based on the above text, for example, the prompt text is:
[0205] As a professional security analyst, please answer the following questions:
[0206] Domain knowledge: Attack payload refers to the malicious code or data delivered by malware during an attack. Payload analysis is the process of identifying the attacker's intentions and technical means through in-depth research on payload behavior.
[0207] Target data: IP 8.8.8.8 recorded the following behavior in the attack alarm log: [specific log content].
[0208] Question: How to analyze the payload of IP 8.8.8.8 in the attack alarm log?
[0209] Constraint: If no relevant alarm logs are found in the target data, please answer: "I cannot answer this question because there are no relevant alarm logs for this IP address in the system."
[0210] Among them, in the process of generating the above-mentioned prompt text, constraints can also be set in it, so as to avoid incorrect answers caused by missing data in traditional methods, and significantly improve the reliability and practicality of the security analysis results output by the large model of network security event correlation analysis.
[0211] From the above, it can be seen that generating prompt text based on network security issues, sample network security knowledge and sample network threat data can avoid the sparse information contained in the generated prompt text due to incomplete expression of network security issues. Network security knowledge can provide professional and accurate knowledge for the prompt text, and network threat data can provide real and reliable data for the prompt text. In this way, the accuracy and professional expression of the prompt text can be achieved, thereby providing clear and reliable instructions for the network security incident correlation analysis model in the future, so as to accurately guide the analysis tasks of the network security incident correlation analysis model and output more accurate security analysis results.
[0212] In some implementations, generating prompt text based on domain knowledge text, threat data text, and network security issues includes:
[0213] (1.3.1) Determine the cybersecurity scenarios corresponding to the cybersecurity issues;
[0214] (1.3.2) Filtering a target prompt template from multiple preset prompt templates based on the mapping relationship between network security scenarios and preset prompt templates;
[0215] (1.3.3) Input domain knowledge text, threat data text, and cybersecurity issues into the target prompt template to generate prompt text.
[0216] Among them, the network security scenario corresponding to the network security problem can be determined. For example, the corresponding network security scenario can be determined based on the keywords in the network security problem. For example, if there is the keyword "attack", the network security scenario of network attack can be determined.
[0217] Then, based on the mapping relationship between network security scenarios and preset alert templates, the target alert template is filtered out from multiple preset alert templates. For example, multiple network security scenarios are pre-set, with corresponding preset alert templates for each scenario. A mapping relationship is then established between the network security scenarios and the preset alert templates. By searching the network security scenarios and the mapping relationship, the target alert template corresponding to the network security issue is found.
[0218] Finally, the domain knowledge text, threat data text and network security issues are input into the target prompt template to generate the prompt text.
[0219] The advantage of doing this is that different preset prompt templates can increase the richness of prompt text generation.
[0220] Finally, the prompt text is input into the cybersecurity incident correlation analysis model, which outputs the predicted security analysis results corresponding to the cybersecurity incident. The predicted security analysis results can be the technologies and tactics associated with the cybersecurity incident.
[0221] In step 260, the difference between the label security analysis result and the predicted security analysis result corresponding to the network security event is determined, and the network security event association analysis model is trained based on the difference to obtain the trained network security event association analysis model.
[0222] After obtaining the predicted security analysis result corresponding to the network security event, the predicted security analysis result and the label security analysis result corresponding to the network security event can be compared to determine the difference between the two.
[0223] For example, the predicted security analysis results output by the security model are the techniques and tactics of the network attack that may exist for the network vulnerability. The techniques and tactics of the network attack are then compared with the techniques and tactics of the actual network attack corresponding to the network vulnerability to determine the difference between the two. Specifically, the dissimilarity between the predicted network attack techniques and tactics and the actual network attack techniques and tactics can be determined, and this dissimilarity is used as the difference between the two. If the dissimilarity is greater than a preset difference value, it indicates that the predicted security analysis results output by the network security incident correlation analysis model are inaccurate, and the network security incident correlation analysis model needs to be further trained. If the dissimilarity is not greater than the preset difference value, it indicates that the predicted security analysis results output by the network security incident correlation analysis model are relatively accurate, and additional training data can be input for verification. If the dissimilarity between the predicted security analysis results and the labeled security analysis results corresponding to each training data is not greater than the preset difference value, the training of the network security incident correlation analysis model is complete.
[0224] It should be noted that the large model for network security incident correlation analysis in this application can be a large language model, and the LoRA (Low-Rank Adaptation of Large Language Models) technology can be used to fine-tune the parameters of the large language model, so that the large language model is suitable for the scenario of security analysis of network security incidents in this application.
[0225] In this application, network security knowledge can be used to provide professional and accurate knowledge for the prompt text, and network threat data can be used to provide real and reliable data for the prompt text. This can achieve accurate and professional expression of the prompt text, thereby providing clear and reliable instructions for the network security event correlation analysis model, so as to accurately guide the network security event correlation analysis model to analyze network security events and output more accurate predictive security analysis results.
[0226] In an embodiment of the present application, a network security issue corresponding to a network security incident is obtained, and the network security issue is matched with a preset network security issue in a preset network security issue library to obtain a matched sample preset network security issue; semantic analysis is performed on the network security issue and the sample preset network security issue to obtain a plurality of semantic keywords; broad keywords and narrow keywords are determined from the plurality of semantic keywords, and sample network security knowledge corresponding to the network security issue is determined in a network security knowledge base based on the broad keywords; sample network threat data corresponding to the network security issue is determined in a network threat database based on the narrow keywords; prompt text is generated based on the network security issue, the sample network security knowledge and the sample network threat data, and the prompt text is input into a network security incident association analysis and judgment big model to output a predicted security analysis result corresponding to the network security incident; the difference between the label security analysis result and the predicted security analysis result corresponding to the network security incident is determined, and the network security incident association analysis and judgment big model is trained based on the difference to obtain a trained network security incident association analysis and judgment big model.
[0227] To this end, we first obtain sample pre-set cybersecurity issues similar to those in cybersecurity incidents. Semantic analysis is then performed on the network security issues and sample pre-set cybersecurity issues to obtain multiple semantic keywords, thereby increasing the richness of the semantic keywords. Broad and narrow keywords are then identified from these multiple semantic keywords. Based on the broad keywords, sample cybersecurity knowledge corresponding to the cybersecurity issues is identified from the cybersecurity knowledge base. Based on the narrow keywords, sample cyberthreat data corresponding to the cybersecurity issues is identified from the network threat database. This allows us to acquire knowledge related to cybersecurity issues from a cybersecurity knowledge base that encompasses knowledge in various network domains, and to obtain data related to cybersecurity issues from historical cybersecurity incidents in the network threat database. Then, a prompt text is generated based on network security issues, sample network security knowledge, and sample network threat data, which can increase the richness of the information contained in the prompt text. The prompt text can provide professional network security knowledge to the network security event association analysis model, and can also provide accurate network threat data. In combination with network security issues, a prompt text that more accurately describes the network security event is generated. Finally, the prompt text is input into the network security event association analysis model to output the predicted security analysis result corresponding to the network security event; the difference between the label security analysis result and the predicted security analysis result corresponding to the network security event is determined, and the network security event association analysis model is trained based on the difference to obtain the trained network security event association analysis model. Compared with the scheme in the related art that relies on human experience to analyze and evaluate network security events, the trained network security event association analysis model in this application can more accurately analyze the network security event to be analyzed, so as to output professional and accurate target security analysis results. The target security analysis result realizes accurate research and judgment of the network security event to be analyzed.
[0228] See also Figure 4 , Figure 4 This is another flow chart of the method for training a large model for network security event correlation analysis and judgment provided by an embodiment of the present application. The method for training a large model for network security event correlation analysis and judgment may include the following steps:
[0229] Step 301: Obtain a network security issue corresponding to a network security event, input the network security issue into a pre-trained text processing model, and output a first semantic feature corresponding to the network security issue;
[0230] Step 302: Input each preset network security issue in the preset network security issue library into the pre-trained text processing model, and output a second semantic feature corresponding to each preset network security issue;
[0231] Step 303: Determine a first similarity between the first semantic feature and the second semantic feature, and determine a preset network security issue corresponding to the second semantic feature whose first similarity is greater than a first preset similarity as a sample preset network security issue that matches the network security issue;
[0232] Step 304: Perform semantic analysis on the network security issue and the sample preset network security issue to obtain multiple semantic keywords;
[0233] Step 305: Input multiple semantic keywords into the pre-trained word vector model respectively, and output the first word vector corresponding to each semantic keyword;
[0234] Step 306: Determine multiple professional terminology entities in the network security knowledge base, input each professional terminology entity into a pre-trained word vector model, and output a second word vector corresponding to each professional terminology entity;
[0235] Step 307: Calculate the similarity between the first word vector and the second word vector to obtain a second similarity between the first word vector and the second word vector;
[0236] Step 308: Determine the semantic keywords corresponding to the first word vectors whose second similarity is greater than the second preset similarity as broad keywords, and determine the semantic keywords other than the broad keywords among the multiple semantic keywords as narrow keywords;
[0237] Step 310: Determine sample network security knowledge corresponding to the network security problem in the network security knowledge base based on the broad keywords;
[0238] Step 310: Determine sample network threat data corresponding to network security issues in a network threat database based on the narrow keywords;
[0239] Step 311: Generate prompt text based on network security issues, sample network security knowledge, and sample network threat data, input the prompt text into the network security event correlation analysis model, and output the predicted security analysis results corresponding to the network security event;
[0240] Step 312: Determine the difference between the label security analysis result and the predicted security analysis result corresponding to the network security event, and train the network security event association analysis model based on the difference to obtain the trained network security event association analysis model.
[0241] In the above embodiments, the description of each embodiment has its own focus. For the part that is not described in detail in a certain embodiment, please refer to the detailed description of the large model training method for correlation analysis of network security events, which will not be repeated here.
[0242] See also Figure 5 , Figure 5 This is a flow chart of a method for analyzing network security incidents provided by the present application. The method for analyzing network security incidents may include the following steps:
[0243] Step 410: Obtain a target network security issue corresponding to the network security event to be analyzed, and match the target network security issue with a preset network security issue in a preset network security issue library to obtain a matched target preset network security issue.
[0244] Step 420: Perform semantic analysis on the target network security issue and the target preset network security issue to obtain multiple target semantic keywords;
[0245] Step 430: Determine broad target keywords and narrow target keywords from the plurality of target semantic keywords, and determine target network security knowledge corresponding to the target network security problem in the network security knowledge base based on the broad target keywords;
[0246] Step 440: Determine target network threat data corresponding to the target network security issue in the network threat database based on the narrow target keyword;
[0247] Step 450: Generate target prompt text based on target network security issues, target network security knowledge, and target network threat data, input the target prompt text into the trained network security event association analysis model, and output the target security analysis results corresponding to the network security event to be analyzed.
[0248] Steps 410 to 450 will be described in detail below.
[0249] In step 410, a target network security issue corresponding to the network security event to be analyzed is obtained, and the target network security issue is matched with a preset network security issue in a preset network security issue library to obtain a matched target preset network security issue.
[0250] Among them, a target network security issue corresponding to the network security event to be analyzed is obtained, the target network security issue is input into a pre-trained text processing model, and a target first semantic feature corresponding to the target network security issue is output; each preset network security issue in a preset network security issue library is input into the pre-trained text processing model, and a target second semantic feature corresponding to each preset network security issue is output; a target first similarity between the target first semantic feature and the target second semantic feature is determined, and a preset network security issue corresponding to the target second semantic feature whose target first similarity is greater than the target first preset similarity is determined as a target preset network security issue that matches the target network security issue.
[0251] In step 420, semantic analysis is performed on the target network security issue and the target preset network security issue to obtain a plurality of target semantic keywords.
[0252] Among them, semantic analysis is performed on the target network security issues and the target preset network security issues to obtain multiple target semantic keywords.
[0253] In step 430 , broad target keywords and narrow target keywords are determined from the plurality of target semantic keywords, and target network security knowledge corresponding to the target network security problem is determined in the network security knowledge base based on the broad target keywords.
[0254] Among them, multiple target semantic keywords are respectively input into the pre-trained word vector model, and the target first word vector corresponding to each target semantic keyword is output; multiple professional terminology entities are determined in the network security knowledge base, and each professional terminology entity is input into the pre-trained word vector model, and the target second word vector corresponding to each professional terminology entity is output; the target first word vector and the target second word vector are similarity calculated to obtain the target second similarity between the target first word vector and the target second word vector; the target semantic keyword corresponding to the target first word vector whose target second similarity is greater than the target second preset similarity is determined as a broad target keyword, and the semantic keywords other than the broad target keywords among the multiple target semantic keywords are determined as narrow target keywords.
[0255] A target first query statement is generated according to each generalized target keyword; a network security knowledge base is queried according to the target first query statement to obtain target network security knowledge corresponding to the target network security problem.
[0256] In step 440 , target network threat data corresponding to the target network security issue is determined in the network threat database based on the narrow target keyword.
[0257] Among them, a target second query statement is generated according to each narrow target keyword; and a network threat database is queried according to the target second query statement to obtain target network threat data corresponding to the target network security issue.
[0258] In step 450, a target prompt text is generated based on the target network security issue, target network security knowledge and target network threat data, and the target prompt text is input into the trained network security event association analysis model to output the target security analysis result corresponding to the network security event to be analyzed.
[0259] Among them, the target domain knowledge text corresponding to the target network security problem is generated based on the target network security knowledge; the target threat data text corresponding to the target network security problem is generated based on the target network threat data; and the target prompt text is generated based on the target domain knowledge text, the target threat data text and the target network security problem.
[0260] Finally, the target prompt text is input into the trained cybersecurity incident correlation analysis model, which outputs the target security analysis results corresponding to the target cybersecurity incident. The target security analysis results can be the techniques and tactics associated with the target cybersecurity incident.
[0261] Compared with the solutions in related technologies that rely on human experience to analyze and evaluate network security incidents, the trained network security incident correlation analysis model in this application can more accurately analyze the network security incidents to be analyzed, and output professional and accurate target security analysis results. The target security analysis results realize accurate research and judgment of the network security incidents to be analyzed.
[0262] See also Figure 6 , Figure 6 This is a schematic diagram of the structure of a large-scale model training device for network security event correlation analysis and judgment provided by an embodiment of the present application. The large-scale model training device for network security event correlation analysis and judgment can execute the large-scale model training method for network security event correlation analysis and judgment.
[0263] In the embodiments of the present application, the term "module" or "unit" refers to a computer program or portion of a computer program that has a predetermined function and works together with other related parts to achieve a predetermined goal. It can be implemented in whole or in part using software, hardware (such as processing circuits or memory), or a combination thereof. Similarly, a processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be part of an overall module or unit that includes the functionality of the module or unit.
[0264] The network security event correlation analysis and judgment large model training device 500 includes:
[0265] An acquisition module 510 is configured to acquire a network security issue corresponding to a network security event, and match the network security issue with a preset network security issue in a preset network security issue library to obtain a matching sample preset network security issue.
[0266] An analysis module 520 is configured to perform semantic analysis on the network security issue and the sample preset network security issue to obtain a plurality of semantic keywords;
[0267] The knowledge determination module 530 is configured to determine broad keywords and narrow keywords from the plurality of semantic keywords, and determine sample network security knowledge corresponding to the network security problem in the network security knowledge base based on the broad keywords;
[0268] A data determination module 540 is configured to determine sample network threat data corresponding to network security issues in a network threat database based on narrow keywords;
[0269] A generation module 550 is configured to generate prompt text based on network security issues, sample network security knowledge, and sample network threat data, input the prompt text into a network security event correlation analysis model, and output a predicted security analysis result corresponding to the network security event;
[0270] The training module 560 is used to determine the difference between the label security analysis results and the predicted security analysis results corresponding to the network security event, and train the network security event correlation analysis model based on the difference to obtain the trained network security event correlation analysis model.
[0271] In some embodiments, the acquisition module 510 is configured to:
[0272] Inputting the network security issue into the pre-trained text processing model and outputting the first semantic feature corresponding to the network security issue;
[0273] Inputting each preset cybersecurity issue in the preset cybersecurity issue library into the pre-trained text processing model, and outputting a second semantic feature corresponding to each preset cybersecurity issue;
[0274] A first similarity between the first semantic feature and the second semantic feature is determined, and a preset network security issue corresponding to the second semantic feature whose first similarity is greater than the first preset similarity is determined as a sample preset network security issue matching the network security issue.
[0275] In some embodiments, the analysis module 520 is configured to:
[0276] Performing text segmentation processing on the network security issue and the sample preset network security issue respectively to obtain a plurality of subtexts corresponding to the network security issue and the sample preset network security issue respectively;
[0277] The non-network-related text filtering process is performed on multiple sub-texts to obtain multiple semantic keywords.
[0278] In some implementations, the knowledge determination module 530 is configured to:
[0279] Input multiple semantic keywords into the pre-trained word vector model respectively, and output the first word vector corresponding to each semantic keyword;
[0280] Identify multiple professional terminology entities in the cybersecurity knowledge base, input each professional terminology entity into a pre-trained word vector model, and output a second word vector corresponding to each professional terminology entity;
[0281] Calculate the similarity between the first word vector and the second word vector to obtain a second similarity between the first word vector and the second word vector;
[0282] The semantic keyword corresponding to the first word vector whose second similarity is greater than the second preset similarity is determined as a broad keyword, and the semantic keywords other than the broad keyword among the multiple semantic keywords are determined as narrow keywords.
[0283] In some implementations, the knowledge determination module 530 is configured to:
[0284] Generate a first query statement according to each broad keyword;
[0285] The network security knowledge base is queried according to the first query statement to obtain sample network security knowledge corresponding to the network security problem.
[0286] In some implementations, the data determination module 540 is configured to:
[0287] Generate a second query statement based on each narrow keyword;
[0288] The network threat database is queried according to the second query statement to obtain sample network threat data corresponding to the network security issue.
[0289] In some embodiments, the generating module 550 is configured to:
[0290] Generate domain knowledge text corresponding to network security issues based on sample network security knowledge;
[0291] Generate threat data text corresponding to network security issues based on sample network threat data;
[0292] Generate prompt text based on domain knowledge text, threat data text and network security issues.
[0293] In some embodiments, the generating module 550 is configured to:
[0294] Determine the cybersecurity scenarios corresponding to cybersecurity issues;
[0295] Filtering a target prompt template from multiple preset prompt templates based on a mapping relationship between network security scenarios and preset prompt templates;
[0296] Domain knowledge text, threat data text, and cybersecurity issues are input into the target prompt template to generate prompt text.
[0297] In some embodiments, the network security event correlation analysis and judgment large model training device 500 further includes a construction module for:
[0298] Before determining sample network threat data corresponding to network security issues in the network threat database based on narrow keywords, multiple network security entities corresponding to network log data, network traffic data, and network security incident analysis and judgment report data in the target network environment are obtained;
[0299] Construct network knowledge graphs corresponding to network log data, network traffic data, and network security incident analysis and judgment report data based on multiple network security entities;
[0300] Align nodes of the network knowledge graphs corresponding to network log data, network traffic data, and network security incident analysis and judgment report data to determine aligned nodes and conflicting nodes that cannot be aligned;
[0301] Determine the data source priority corresponding to each conflicting node, and determine the reliability score of the conflicting node in each network knowledge graph based on the data source priority;
[0302] The target nodes are screened out from the conflicting nodes according to the reliability scores, and a target network knowledge graph is constructed based on the target nodes and the aligned nodes. A network threat database is generated based on the data corresponding to the target network knowledge graph.
[0303] In some embodiments, building blocks are provided for:
[0304] Obtain the network attack correlation strength and network attack correlation time corresponding to each conflict node;
[0305] The reliability score of the conflicting node in each network knowledge graph is determined based on the data source priority, network attack correlation strength and network attack correlation time.
[0306] In the above embodiments, the description of each embodiment has its own focus. For the part that is not described in detail in a certain embodiment, please refer to the detailed description of the large model training method for correlation analysis of network security events, which will not be repeated here.
[0307] In the present application, the acquisition module 510 acquires the network security issues corresponding to the network security events, and matches the network security issues with the preset network security issues in the preset network security issue library to obtain matching sample preset network security issues; the analysis module 520 performs semantic analysis on the network security issues and the sample preset network security issues to obtain multiple semantic keywords; the knowledge determination module 530 determines broad keywords and narrow keywords from the multiple semantic keywords, and determines the sample network security knowledge corresponding to the network security issues in the network security knowledge base based on the broad keywords; the data determination module 540 determines the sample network threat data corresponding to the network security issues in the network threat database based on the narrow keywords; the generation module 550 generates prompt text based on the network security issues, sample network security knowledge and sample network threat data, and inputs the prompt text into the network security event association analysis model, and outputs the predicted security analysis results corresponding to the network security event; the training module 560 determines the difference between the label security analysis results and the predicted security analysis results corresponding to the network security event, and trains the network security event association analysis model based on the difference to obtain the trained network security event association analysis model.
[0308] To this end, we first obtain sample pre-set cybersecurity issues similar to those in cybersecurity incidents. Semantic analysis is then performed on the network security issues and sample pre-set cybersecurity issues to obtain multiple semantic keywords, thereby increasing the richness of the semantic keywords. Broad and narrow keywords are then identified from these multiple semantic keywords. Based on the broad keywords, sample cybersecurity knowledge corresponding to the cybersecurity issues is identified from the cybersecurity knowledge base. Based on the narrow keywords, sample cyberthreat data corresponding to the cybersecurity issues is identified from the network threat database. This allows us to acquire knowledge related to cybersecurity issues from a cybersecurity knowledge base that encompasses knowledge in various network domains, and to obtain data related to cybersecurity issues from historical cybersecurity incidents in the network threat database. Then, a prompt text is generated based on network security issues, sample network security knowledge, and sample network threat data, which can increase the richness of the information contained in the prompt text. The prompt text can provide professional network security knowledge to the network security event association analysis model, and can also provide accurate network threat data. In combination with network security issues, a prompt text that more accurately describes the network security event is generated. Finally, the prompt text is input into the network security event association analysis model to output the predicted security analysis result corresponding to the network security event; the difference between the label security analysis result and the predicted security analysis result corresponding to the network security event is determined, and the network security event association analysis model is trained based on the difference to obtain the trained network security event association analysis model. Compared with the scheme in the related art that relies on human experience to analyze and evaluate network security events, the trained network security event association analysis model in this application can more accurately analyze the network security event to be analyzed, so as to output professional and accurate target security analysis results. The target security analysis result realizes accurate research and judgment of the network security event to be analyzed.
[0309] See also Figure 7 , Figure 7 1 is a schematic diagram of the structure of a network security event analysis device provided in an embodiment of the present application. The network security event analysis device can execute the above-mentioned network security event analysis method.
[0310] The network security event analysis device 600 includes:
[0311] The problem acquisition module 610 is used to acquire a target network security problem corresponding to the network security event to be analyzed, and match the target network security problem with a preset network security problem in a preset network security problem library to obtain a matched target preset network security problem;
[0312] Semantic analysis module 620, configured to perform semantic analysis on the target network security issue and the target preset network security issue to obtain a plurality of target semantic keywords;
[0313] A first determination module 630 is configured to determine broad target keywords and narrow target keywords from the plurality of target semantic keywords, and determine target network security knowledge corresponding to the target network security problem in a network security knowledge base based on the broad target keywords;
[0314] A second determining module 640 is configured to determine target network threat data corresponding to the target network security issue in a network threat database based on the narrow target keyword;
[0315] The analysis module 650 is used to generate a target prompt text based on the target network security issue, the target network security knowledge and the target network threat data, and input the target prompt text into the trained network security event association analysis model to output the target security analysis result corresponding to the network security event to be analyzed.
[0316] In the above embodiments, the description of each embodiment has its own focus. For the part that is not described in detail in a certain embodiment, please refer to the detailed description of the above network security event analysis method, which will not be repeated here.
[0317] The present application also provides a computer device comprising a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the aforementioned large-scale model training method for network security event correlation analysis or network security event analysis method. The computer device can be any device, including a computer and a server.
[0318] See also Figure 8 , Figure 8 The hardware structure of a computer device according to another embodiment is shown. The computer device includes:
[0319] The processor 901 can be implemented as a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of the present application;
[0320] The memory 902 can be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 902 can store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 902 and is called by the processor 901 to execute the network security event correlation analysis model training method or network security event analysis method of the embodiments of this application;
[0321] Input / output interface 903, used to implement information input and output;
[0322] Communication interface 904, used to implement communication interaction between this device and other devices, which can be achieved through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WiFi, Bluetooth, etc.);
[0323] Bus 905 , which transmits information between various components of the device (e.g., processor 901 , memory 902 , input / output interface 903 , and communication interface 904 );
[0324] The processor 901 , the memory 902 , the input / output interface 903 and the communication interface 904 are connected to each other in communication within the device via a bus 905 .
[0325] An embodiment of the present application also provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it implements the above-mentioned network security event correlation analysis and judgment large model training method or network security event analysis method.
[0326] The memory, as a non-transient computer-readable storage medium, can be used to store non-transient software programs and non-transient computer executable programs. In addition, the memory may include a high-speed random access memory and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some embodiments, the memory may optionally include a memory remotely arranged relative to the processor, and these remote memories may be connected to the processor via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0327] The embodiments of the present application provide a method, apparatus, and device for training a large-scale model for network security event association and analysis. The method, apparatus, and device obtain network security issues corresponding to network security events, and match the network security issues with preset network security issues in a preset network security issue library to obtain matched sample preset network security issues; perform semantic analysis on the network security issues and the sample preset network security issues to obtain multiple semantic keywords; determine broad keywords and narrow keywords from the multiple semantic keywords, and determine sample network security knowledge corresponding to the network security issues in a network security knowledge base based on the broad keywords; determine sample network threat data corresponding to the network security issues in a network threat database based on the narrow keywords; generate prompt text based on the network security issues, sample network security knowledge, and sample network threat data, and input the prompt text into the large-scale model for network security event association and analysis to output a predicted security analysis result corresponding to the network security event; determine the difference between the labeled security analysis result and the predicted security analysis result corresponding to the network security event, and train the large-scale model for network security event association and analysis based on the difference to obtain a trained large-scale model for network security event association and analysis.
[0328] To this end, we first obtain sample pre-set cybersecurity issues similar to those in cybersecurity incidents. Semantic analysis is then performed on the network security issues and sample pre-set cybersecurity issues to obtain multiple semantic keywords, thereby increasing the richness of the semantic keywords. Broad and narrow keywords are then identified from these multiple semantic keywords. Based on the broad keywords, sample cybersecurity knowledge corresponding to the cybersecurity issues is identified from the cybersecurity knowledge base. Based on the narrow keywords, sample cyberthreat data corresponding to the cybersecurity issues is identified from the network threat database. This allows us to acquire knowledge related to cybersecurity issues from a cybersecurity knowledge base that encompasses knowledge in various network domains, and to obtain data related to cybersecurity issues from historical cybersecurity incidents in the network threat database. Then, a prompt text is generated based on network security issues, sample network security knowledge, and sample network threat data, which can increase the richness of the information contained in the prompt text. The prompt text can provide professional network security knowledge to the network security event association analysis model, and can also provide accurate network threat data. In combination with network security issues, a prompt text that more accurately describes the network security event is generated. Finally, the prompt text is input into the network security event association analysis model to output the predicted security analysis result corresponding to the network security event; the difference between the label security analysis result and the predicted security analysis result corresponding to the network security event is determined, and the network security event association analysis model is trained based on the difference to obtain the trained network security event association analysis model. Compared with the scheme in the related art that relies on human experience to analyze and evaluate network security events, the trained network security event association analysis model in this application can more accurately analyze the network security event to be analyzed, so as to output professional and accurate target security analysis results. The target security analysis result realizes accurate research and judgment of the network security event to be analyzed.
[0329] The embodiments described in the embodiments of this application are intended to more clearly illustrate the technical solutions of the embodiments of this application and do not constitute a limitation on the technical solutions provided by the embodiments of this application. Those skilled in the art will appreciate that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.
[0330] Those skilled in the art will understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than shown in the figures, or a combination of certain steps, or different steps.
[0331] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, i.e., they may be located in one place or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of this embodiment.
[0332] Those skilled in the art will appreciate that all or some of the steps in the methods, systems, and functional modules / units in the devices disclosed above may be implemented as software, firmware, hardware, or appropriate combinations thereof.
[0333] The terms "first", "second", "third", "fourth", etc. (if any) in the specification of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0334] It should be understood that in this application, "at least one (item)" means one or more, and "plurality" means two or more. "And / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.
[0335] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the above-mentioned units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0336] The units described above as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0337] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0338] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes multiple instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of various embodiments of the present application. The aforementioned storage medium includes: various media that can store programs, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0339] The preferred embodiments of the present invention are described above with reference to the accompanying drawings, but are not intended to limit the scope of the present invention. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and essence of the present invention should be within the scope of the present invention.
Claims
1. A large-scale model training method for network security event correlation analysis, characterized in that: include: Obtaining a network security issue corresponding to the network security event, and matching the network security issue with a preset network security issue in a preset network security issue library to obtain a matched sample preset network security issue; Performing semantic analysis on the network security issue and the sample preset network security issue to obtain a plurality of semantic keywords; Input the multiple semantic keywords into the pre-trained word vector model respectively, and output the first word vector corresponding to each semantic keyword; Determine multiple professional terminology entities in a cybersecurity knowledge base, input each professional terminology entity into a pre-trained word vector model, and output a second word vector corresponding to each professional terminology entity; Calculating similarity between the first word vector and the second word vector to obtain a second similarity between the first word vector and the second word vector; Determine the semantic keywords corresponding to the first word vectors whose second similarity is greater than a second preset similarity as broad keywords, and determine the semantic keywords other than the broad keywords among the multiple semantic keywords as narrow keywords; Determining sample network security knowledge corresponding to the network security issue in a network security knowledge base based on the broad keywords; Determining sample network threat data corresponding to the network security issue in a network threat database based on the narrow keyword; Generate a prompt text based on the network security issue, the sample network security knowledge, and the sample network threat data, input the prompt text into a network security event correlation analysis model, and output a predicted security analysis result corresponding to the network security event; Determine the difference between the label security analysis result corresponding to the network security event and the predicted security analysis result, and train the network security event association analysis model based on the difference to obtain the trained network security event association analysis model.
2. The network security incident correlation analysis and judgment large model training method according to claim 1 is characterized in that: The matching of the network security issue with the preset network security issues in the preset network security issue library to obtain matched sample preset network security issues includes: Inputting the network security issue into a pre-trained text processing model, and outputting a first semantic feature corresponding to the network security issue; Inputting each preset network security issue in the preset network security issue library into the pre-trained text processing model, and outputting a second semantic feature corresponding to each preset network security issue; A first similarity between the first semantic feature and the second semantic feature is determined, and a preset network security issue corresponding to a second semantic feature whose first similarity is greater than a first preset similarity is determined as a sample preset network security issue matching the network security issue.
3. The network security incident correlation analysis and judgment large model training method according to claim 1 is characterized in that: The semantic analysis of the network security issue and the sample preset network security issue is performed to obtain multiple semantic keywords, including: Performing text segmentation processing on the network security issue and the sample preset network security issue respectively to obtain a plurality of subtexts corresponding to the network security issue and the sample preset network security issue respectively; The multiple subtexts are subjected to non-network-related text filtering processing to obtain multiple semantic keywords.
4. The network security incident correlation analysis and judgment large model training method according to claim 1 is characterized in that: Determining sample network security knowledge corresponding to the network security issue in a network security knowledge base based on the broad keywords includes: Generate a first query statement according to each of the broad keywords; A network security knowledge base is queried according to the first query statement to obtain sample network security knowledge corresponding to the network security problem.
5. The network security incident correlation analysis and judgment large model training method according to claim 1 is characterized in that: Determining sample network threat data corresponding to the network security issue in a network threat database based on the narrow keyword includes: generating a second query statement according to each of the narrow keywords; A network threat database is queried according to the second query statement to obtain sample network threat data corresponding to the network security issue.
6. The network security incident correlation analysis and judgment large model training method according to claim 1 is characterized in that: Generating a prompt text according to the network security issue, the sample network security knowledge, and the sample network threat data includes: Generate domain knowledge text corresponding to the network security issue based on the sample network security knowledge; Generating threat data text corresponding to the network security issue based on the sample network threat data; A prompt text is generated according to the domain knowledge text, the threat data text and the network security issue.
7. The network security incident correlation analysis and judgment large model training method according to claim 6 is characterized in that: Generating a prompt text according to the domain knowledge text, the threat data text, and the network security issue includes: Determine the network security scenario corresponding to the network security issue; Filtering a target prompt template from a plurality of preset prompt templates according to a mapping relationship between the network security scenario and the preset prompt template; The domain knowledge text, the threat data text and the network security issue are input into the target prompt template to generate a prompt text.
8. The network security incident correlation analysis and judgment large model training method according to claim 1 is characterized in that: Before determining the sample network threat data corresponding to the network security issue in the network threat database according to the narrow keyword, the method further includes: Obtain multiple network security entities corresponding to network log data, network traffic data, and network security incident analysis and judgment report data in the target network environment; Constructing network knowledge graphs corresponding to the network log data, the network traffic data, and the network security incident analysis and judgment report data respectively according to the multiple network security entities; Aligning nodes of the network knowledge graphs corresponding to the network log data, the network traffic data, and the network security incident analysis and judgment report data, respectively, to determine aligned nodes and conflicting nodes that cannot be aligned; Determining the data source priority corresponding to each of the conflicting nodes, and determining the reliability score of the conflicting node in each network knowledge graph based on the data source priority; A target node is screened out from the conflicting nodes according to the reliability score, a target network knowledge graph is constructed according to the target node and the aligned nodes, and a network threat database is generated according to data corresponding to the target network knowledge graph.
9. The method for training a large model for network security event correlation analysis according to claim 8 is characterized in that: Determining the reliability score of the conflicting node in each network knowledge graph according to the data source priority includes: Obtaining the network attack correlation strength and network attack correlation time corresponding to each of the conflict nodes; A reliability score of the conflicting node in each network knowledge graph is determined according to the data source priority, the network attack correlation strength, and the network attack correlation time.
10. A network security incident analysis method, characterized in that: include: Obtaining a target network security issue corresponding to the network security event to be analyzed, and matching the target network security issue with a preset network security issue in a preset network security issue library to obtain a matched target preset network security issue; Performing semantic analysis on the target network security issue and the target preset network security issue to obtain a plurality of target semantic keywords; Input multiple target semantic keywords into the pre-trained word vector model respectively, and output the target first word vector corresponding to each target semantic keyword; Identify multiple professional terminology entities in the cybersecurity knowledge base, input each professional terminology entity into a pre-trained word vector model, and output a target second word vector corresponding to each professional terminology entity; Calculating similarity between the target first word vector and the target second word vector to obtain a target second similarity between the target first word vector and the target second word vector; Determine the target semantic keyword corresponding to the target first word vector whose target second similarity is greater than the target second preset similarity as the broad target keyword, and determine the semantic keywords other than the broad target keyword among the multiple target semantic keywords as the narrow target keyword; Determining target network security knowledge corresponding to the target network security problem in a network security knowledge base according to the broad target keyword; Determining target network threat data corresponding to the target network security issue in a network threat database based on the narrow target keyword; A target prompt text is generated based on the target network security issue, the target network security knowledge and the target network threat data, and the target prompt text is input into the trained network security event association analysis model to output the target security analysis result corresponding to the network security event to be analyzed.
11. A large-scale model training device for network security event correlation analysis, characterized in that: include: An acquisition module is configured to acquire a network security issue corresponding to a network security event, and match the network security issue with a preset network security issue in a preset network security issue library to obtain a matched sample preset network security issue; An analysis module, configured to perform semantic analysis on the network security issue and the sample preset network security issue to obtain a plurality of semantic keywords; A knowledge determination module, configured to input the plurality of semantic keywords into a pre-trained word vector model, and output a first word vector corresponding to each semantic keyword; Determine multiple professional terminology entities in a cybersecurity knowledge base, input each professional terminology entity into a pre-trained word vector model, and output a second word vector corresponding to each professional terminology entity; Calculating similarity between the first word vector and the second word vector to obtain a second similarity between the first word vector and the second word vector; Determine the semantic keywords corresponding to the first word vectors whose second similarity is greater than a second preset similarity as broad keywords, and determine the semantic keywords other than the broad keywords among the multiple semantic keywords as narrow keywords; Determining sample network security knowledge corresponding to the network security issue in a network security knowledge base based on the broad keywords; a data determination module, configured to determine sample network threat data corresponding to the network security issue in a network threat database based on the narrow keyword; a generation module, configured to generate a prompt text based on the network security issue, the sample network security knowledge, and the sample network threat data, input the prompt text into a network security event correlation analysis model, and output a predicted security analysis result corresponding to the network security event; The training module is used to determine the difference between the label security analysis result corresponding to the network security event and the predicted security analysis result, and train the network security event association analysis model based on the difference to obtain the trained network security event association analysis model.
12. A network security event analysis device, characterized in that: include: A problem acquisition module is used to acquire a target network security problem corresponding to the network security event to be analyzed, and match the target network security problem with a preset network security problem in a preset network security problem library to obtain a matched target preset network security problem; A semantic analysis module, configured to perform semantic analysis on the target network security issue and the target preset network security issue to obtain a plurality of target semantic keywords; A first determination module is used to input multiple target semantic keywords into the pre-trained word vector model respectively, and output a target first word vector corresponding to each target semantic keyword; Identify multiple professional terminology entities in the cybersecurity knowledge base, input each professional terminology entity into a pre-trained word vector model, and output a target second word vector corresponding to each professional terminology entity; Calculating similarity between the target first word vector and the target second word vector to obtain a target second similarity between the target first word vector and the target second word vector; Determine the target semantic keyword corresponding to the target first word vector whose target second similarity is greater than the target second preset similarity as the broad target keyword, and determine the semantic keywords other than the broad target keyword among the multiple target semantic keywords as the narrow target keyword; Determining target network security knowledge corresponding to the target network security problem in a network security knowledge base according to the broad target keyword; A second determination module is configured to determine target network threat data corresponding to the target network security issue in a network threat database based on the narrow target keyword; The analysis module is used to generate a target prompt text based on the target network security issue, the target network security knowledge and the target network threat data, and input the target prompt text into the trained network security event association analysis model to output the target security analysis result corresponding to the network security event to be analyzed.
13. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a plurality of instructions, which are suitable for loading by a processor to execute the network security event correlation analysis and judgment large model training method described in any one of claims 1 to 9 or the network security event analysis method described in claim 10.
14. A computer device comprising a memory, a processor, and a computer program stored in the memory and capable of running on the processor, characterized in that: When the processor executes the computer program, it implements the network security event correlation analysis and judgment large model training method described in any one of claims 1 to 9 or the network security event analysis method described in claim 10.
Citation Information
Patent Citations
Internal network threat intelligent analysis and prediction method and system based on large language model
CN119728171A
An apparatus and method for enhancing cybersecurity of an entity
US20240265114A1