Data resource library security assessment method and device based on large language model
Through the data resource library security evaluation method based on large language model, sensitive data in incremental business data are identified and analyzed, multi-dimensional dynamic characteristics are constructed, and security evaluation coefficients are predicted, and the reliability and cost problems of security evaluation in the existing technology are solved, real-time security risk prediction and prevention are achieved.
Patent Information
- Application Number
- CN202510274014.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-10
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2045-03-10
AI Technical Summary
In the prior art, the security assessment of the data resource database has high labor costs, low reliability, and can only evaluate the current security status of the data resource database, which is highly risky.
The security evaluation method of data resource library based on large language models is adopted. By identifying sensitive data, determining type, and analyzing incremental business data, and building multi-dimensional dynamic features, combining deep confidence networks and long-term memory networks, security evaluation coefficients are predicted and security risk warnings are generated.
It improves the reliability and accuracy of the security assessment of the data resource library, reduces labor costs, can predict security risks in real time, perform security maintenance in advance, and avoid data security accidents.
Smart Images

Figure CN120217427A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data security technology, and in particular, to a method and device for evaluating the security of a data resource library based on a large language model. Background Art
[0002] During the operation of corresponding enterprises, governments, etc., a lot of business data (such as call data, order data, user information, or employee information, etc.) will be generated, and the business data generated during the operation is usually stored in a data resource library. The data resource library needs to maintain a certain level of security. For example, the data in the data resource library should maintain confidentiality, integrity, and comply with laws and regulations.
[0003] Currently, the evaluation method for the security of a data resource library usually adopts a manual evaluation method, which has high labor costs, low reliability, and can only evaluate the current security status of the data resource library, with high risks. Summary of the Invention
[0004] This application provides a method and device for evaluating the security of a data resource library based on a large language model, which is used to solve the problems in the prior art that the security evaluation of the data resource library has high labor costs, low reliability, and can only evaluate the current security status of the data resource library, with high risks.
[0005] In a first aspect, this application provides a method for evaluating the security of a data resource library based on a large language model, including:
[0006] During the current target time period, for each piece of incremental business data in a preset data resource library, based on a pre-trained large language model, identify whether there is sensitive data in the incremental business data, where the large language model is obtained by training multiple first training samples input into a deep learning network, and each first training sample includes historical business data and a corresponding label, and the label is used to characterize whether the historical business data includes sensitive data;
[0007] If there is sensitive data, determine the type of the sensitive data;
[0008] Count the total number of incremental business data, the first number of sensitive data identified, and the second data volume of sensitive data belonging to the target type during the current target time period, where the target type at least includes voice type, picture type, and video type;
[0009] Determine the first proportion of the first number of sensitive data identified to the total number of incremental business data, and the second proportion of the second number of sensitive data of the target type to the first number of sensitive data identified;
[0010] During the current target time period, count the number of operations on the data repository and the number of newly added users with access rights to the data repository;
[0011] Based on the total amount of incremental business data, the first quantity of identified sensitive data, the second data volume of sensitive data belonging to the target type, the first proportion, the second proportion, the number of operations on the data repository, and the number of newly added users with access rights to the data repository, construct the current multi-dimensional dynamic features for characterizing the security evolution of the data repository;
[0012] Obtain the first historical multi-dimensional dynamic features for characterizing the security evolution of the data repository in the previous 1 target time period and the second historical multi-dimensional dynamic features for characterizing the security evolution of the data repository in the subsequent 1 historical time period that is equal in duration and continuous with the previous 1 target time period;
[0013] Extract the first dependency relationship between the first historical multi-dimensional dynamic features and the second historical multi-dimensional dynamic features according to the deep belief network, and extract the second dependency relationship between the first historical multi-dimensional dynamic features and the current multi-dimensional dynamic features;
[0014] Input the first historical multi-dimensional dynamic features, the second historical multi-dimensional dynamic features, the first dependency relationship, the current multi-dimensional dynamic features, and the second dependency relationship into the pre-trained first long short-term memory network model to obtain the first predicted multi-dimensional dynamic features in the subsequent 1 time period that is equal in duration and continuous with the current target time period. Among them, the first long short-term memory network model is obtained by training multiple first training samples input into the initial long short-term memory network. Each first training sample includes the first historical multi-dimensional dynamic features in the previous 1 target time period in history, the second historical multi-dimensional dynamic features in the subsequent 1 historical time period that is equal in duration and continuous with the previous 1 target time period in history, and the corresponding historical first dependency relationship, the historical current multi-dimensional dynamic features in the historical current target time period, the second dependency relationship between the first historical multi-dimensional dynamic features in the previous 1 target time period in history and the historical current multi-dimensional dynamic features in the historical current target time period, and the corresponding historical actual multi-dimensional dynamic features in the subsequent 1 time period that is equal in duration and continuous with the historical current target time period;
[0015] Input the preset multi-dimensional static features and the first predicted multi-dimensional dynamic features into a pre-trained security assessment prediction model to obtain the security assessment coefficient of the data repository for the next 1 time period that is equal in duration and continuous with the current target time period. The multi-dimensional static features at least include the cracking difficulty of the encryption key for the business data in the data repository, the storage environment category of the multi-dimensional static features, and the geographical distribution breadth of the server running the data repository. The security assessment prediction model is obtained by training a first neural network with multiple second training samples. Each second training sample includes historical multi-dimensional static features, historical first predicted multi-dimensional dynamic features, and a historical actual security assessment coefficient used to represent the next 1 time period that is equal in duration and continuous with the historical target time period.
[0016] When the security assessment coefficient is greater than the set assessment coefficient threshold, generate a warning prompt indicating that there is a security risk in the data repository.
[0017] In a possible implementation manner, after obtaining the first predicted multi-dimensional dynamic features for the next 1 time period that is equal in duration and continuous with the current target time period, the method provided by this application further includes:
[0018] Obtain multiple historical third multi-dimensional dynamic features respectively corresponding to the previous N time periods that are equal in duration and continuous with the current target time period;
[0019] Determine the change rule of the multi-dimensional dynamic features of the data repository according to the multiple historical third multi-dimensional dynamic features and the current multi-dimensional dynamic features corresponding to the current target time period;
[0020] Predict the second predicted multi-dimensional dynamic features for the next 1 time period that is equal in duration and continuous with the current target time period according to the change rule of the multi-dimensional dynamic features of the data repository;
[0021] Correct the first predicted multi-dimensional dynamic features according to the second predicted multi-dimensional dynamic features.
[0022] In a possible implementation manner, correcting the first predicted multi-dimensional dynamic features according to the second predicted multi-dimensional dynamic features includes:
[0023] Perform weighted averaging on the feature values with the same dimensions in the second predicted multi-dimensional dynamic features and the first predicted multi-dimensional dynamic features to obtain the corrected first predicted multi-dimensional dynamic features.
[0024] In a possible implementation manner, the method provided by this application further includes:
[0025] When the security evaluation coefficient is greater than the set evaluation coefficient threshold, the first predicted multi-dimensional dynamic feature is input into the pre-trained database maintenance policy model to obtain the preventive maintenance policy of the data resource library, where the database maintenance policy model is obtained by inputting multiple historical first predicted multi-dimensional dynamic features and the corresponding standard preventive maintenance policies into the second neural network for training;
[0026] The preventive maintenance policy of the data resource library is transmitted to the remote terminal for display.
[0027] In a possible implementation manner, within the current target time period, before identifying whether there is sensitive data in each piece of incremental business data in the preset data resource library based on the pre-trained large language model, the method provided by this application further includes:
[0028] Obtain the first historical multi-dimensional dynamic features of multiple historical 1 target time periods, the second historical multi-dimensional dynamic features of the subsequent 1 historical time period that is equal in duration and continuous with the historical 1 target time period, as well as the corresponding historical first dependency relationship, the historical current multi-dimensional dynamic features of the historical current target time period, the second dependency relationship between the first historical multi-dimensional dynamic features of the historical 1 target time period and the historical current multi-dimensional dynamic features of the historical current target time period, and the corresponding historical actual multi-dimensional dynamic features of the subsequent 1 time period that is equal in duration and continuous with the historical current target time period, and construct multiple first training samples;
[0029] Input the multiple first training samples into the initial long short-term memory network for training to obtain the first long short-term memory network model.
[0030] In a second aspect, a data resource library security evaluation device provided by this application includes:
[0031] A sensitive data recognition unit, configured to, within the current target time period, for each piece of incremental business data in the preset data resource library, based on the pre-trained large language model, identify whether there is sensitive data in the incremental business data, where the large language model is obtained by inputting multiple first training samples into the deep learning network for training, and each first training sample includes historical business data and the corresponding label, and the label is used to characterize whether the historical business data includes sensitive data;
[0032] A sensitive data type recognition unit, configured to determine the type of the sensitive data if there is sensitive data;
[0033] A data statistics unit for counting the total quantity of incremental service data, the first quantity of sensitive data identified, and the second data volume of sensitive data belonging to the target type during the current target time period, where the target type includes at least the voice type, the picture type, and the video type;
[0034] The data statistics unit is further configured to determine the first ratio of the first quantity of sensitive data identified to the total quantity of incremental service data, and the second ratio of the second quantity of sensitive data of the target type to the first quantity of sensitive data identified;
[0035] The data statistics unit is further configured to count the number of operations on the data repository and the number of newly added users with access rights to the data repository during the current target time period;
[0036] A feature construction unit for constructing the current multi-dimensional dynamic feature for characterizing the security evolution of the data repository according to the total quantity of incremental service data, the first quantity of sensitive data identified, the second data volume of sensitive data belonging to the target type, the first ratio, the second ratio, the number of operations on the data repository, and the number of newly added users with access rights to the data repository;
[0037] A feature acquisition unit for acquiring the first historical multi-dimensional dynamic feature for characterizing the security evolution of the data repository in the previous 1 target time period and the second historical multi-dimensional dynamic feature for characterizing the security evolution of the data repository in the subsequent 1 historical time period that is equal in duration and continuous with the previous 1 target time period;
[0038] A feature relationship determination unit for extracting the first dependency relationship between the first historical multi-dimensional dynamic feature and the second historical multi-dimensional dynamic feature according to a deep belief network, and extracting the second dependency relationship between the first historical multi-dimensional dynamic feature and the current multi-dimensional dynamic feature;
[0039] A feature prediction unit, configured to input the first historical multi-dimensional dynamic feature, the second historical multi-dimensional dynamic feature, the first dependency relationship, the current multi-dimensional dynamic feature, and the second dependency relationship into a pre-trained first long short-term memory network model, to obtain a first predicted multi-dimensional dynamic feature for the next 1 consecutive time period equal in duration to the current target time period, where the first long short-term memory network model is obtained by training an initial long short-term memory network with multiple first training samples, and each first training sample includes a first historical multi-dimensional dynamic feature of a historical target time period, a second historical multi-dimensional dynamic feature of the next 1 consecutive historical time period equal in duration to the historical target time period, and the corresponding historical first dependency relationship, the historical current multi-dimensional dynamic feature of the historical current target time period, the second dependency relationship between the first historical multi-dimensional dynamic feature of the historical target time period and the historical current multi-dimensional dynamic feature of the historical current target time period, and the corresponding historical actual multi-dimensional dynamic feature of the next 1 consecutive time period equal in duration to the historical current target time period;
[0040] A security assessment unit, configured to input a preset multi-dimensional static feature and the first predicted multi-dimensional dynamic feature into a pre-trained security assessment prediction model, to obtain a security assessment coefficient of the data resource library for the next 1 consecutive time period equal in duration to the current target time period, where the multi-dimensional static feature at least includes the cracking difficulty of the encryption key for the business data in the data resource library, the storage environment category of the multi-dimensional static feature, and the geographical distribution breadth of the server running the data resource library, and the security assessment prediction model is obtained by training a first neural network with multiple second training samples, and each second training sample includes a historical multi-dimensional static feature, a historical first predicted multi-dimensional dynamic feature, and a historical actual security assessment coefficient used to represent the next 1 consecutive time period equal in duration to the historical target time period;
[0041] A risk warning unit, configured to generate a warning prompt indicating that there is a security risk in the data resource library when the security assessment coefficient is greater than a set assessment coefficient threshold.
[0042] In a possible implementation manner, the feature acquisition unit is further configured to acquire multiple historical third multi-dimensional dynamic features respectively corresponding to the previous N consecutive time periods equal in duration to the current target time period recorded;
[0043] The feature prediction unit is further configured to determine the change rule of the multi-dimensional dynamic feature of the data resource library according to the multiple historical third multi-dimensional dynamic features and the current multi-dimensional dynamic feature corresponding to the current target time period; and predict a second predicted multi-dimensional dynamic feature for the next 1 consecutive time period equal in duration to the current target time period according to the change rule of the multi-dimensional dynamic feature of the data resource library;
[0044] The apparatus provided by this application further includes: a feature correction unit, configured to correct the first predicted multi-dimensional dynamic feature according to the second predicted multi-dimensional dynamic feature.
[0045] In a possible implementation manner, the feature correction unit is specifically configured to perform weighted averaging on the feature values with the same dimension in the second predicted multi-dimensional dynamic feature and the first predicted multi-dimensional dynamic feature to obtain the corrected first predicted multi-dimensional dynamic feature.
[0046] In a possible implementation manner, the apparatus provided by this application further includes:
[0047] A preventive maintenance strategy determination unit, configured to, when the security evaluation coefficient is greater than a set evaluation coefficient threshold, input the first predicted multi-dimensional dynamic feature into a pre-trained database maintenance strategy model to obtain a preventive maintenance strategy for the data resource library, where the database maintenance strategy model is obtained by training a second neural network with multiple historical first predicted multi-dimensional dynamic features and corresponding standard preventive maintenance strategies;
[0048] A data transmission unit, configured to transmit the preventive maintenance strategy of the data resource library to a remote terminal for display.
[0049] In a possible implementation manner, the apparatus provided by this application further includes:
[0050] A model training unit, configured to obtain multiple first historical multi-dimensional dynamic features of 1 target time period in history, second historical multi-dimensional dynamic features of the subsequent 1 historical time period that is equal in duration and continuous with the 1 target time period in history, as well as corresponding historical first dependencies, historical current multi-dimensional dynamic features of the historical current target time period, second dependencies between the first historical multi-dimensional dynamic features of 1 target time period in history and the historical current multi-dimensional dynamic features of the historical current target time period, and corresponding historical actual multi-dimensional dynamic features of the subsequent 1 time period that is equal in duration and continuous with the historical current target time period, and construct multiple first training samples; input the multiple first training samples into an initial long short-term memory network for training to obtain a first long short-term memory network model.
[0051] This application provides a method and apparatus for security evaluation of a data resource library based on a large language model, which can, within the current target time period, identify whether there is sensitive data in each piece of incremental service data in a preset data resource library based on a pre-trained large language model. Since the large language model is obtained by training multiple first training samples in a deep learning network, each first training sample includes historical service data and a corresponding label, and the label is used to characterize whether the historical service data includes sensitive data; thus, the reliability and accuracy of identifying sensitive data are high.
[0052] If there is sensitive data, determine the type of the sensitive data; count the total quantity of incremental service data, the first quantity of identified sensitive data, and the second quantity of sensitive data belonging to the target type in the current target time period, where the target type includes at least the voice type, the picture type, and the video type; determine the first ratio of the first quantity of identified sensitive data to the total quantity of incremental service data, and the second ratio of the second quantity of sensitive data of the target type to the first quantity of identified sensitive data; in the current target time period, count the number of operations on the data resource library and the number of newly added users with access rights to the data resource library.
[0053] Since the current multi-dimensional dynamic features representing the security evolution of the data resource library include: the total quantity of incremental service data, the first quantity of identified sensitive data, the second quantity of sensitive data belonging to the target type, the first ratio, the second ratio, the number of operations on the data resource library, and the number of newly added users with access rights to the data resource library; thus, it can more accurately represent the security evolution of the data resource library.
[0054] Obtain the first historical multi-dimensional dynamic features for representing the security evolution of the data resource library in the previous 1 target time period and the second historical multi-dimensional dynamic features for representing the security evolution of the data resource library in the subsequent 1 historical time period that is equal in duration and continuous with the previous 1 target time period; extract the first dependency relationship between the first historical multi-dimensional dynamic features and the second historical multi-dimensional dynamic features according to the deep belief network, and extract the second dependency relationship between the first historical multi-dimensional dynamic features and the current multi-dimensional dynamic features. It can be understood that the evolution law of the multi-dimensional dynamic features of the data resource library has a certain correlation with the time period. For example, there is a first dependency relationship between the first historical multi-dimensional dynamic features at 9:00-10:00 on December 1 (i.e., the previous 1 target time period) and the second multi-dimensional dynamic features at 10:00-11:00 on December 1 (i.e., the subsequent 1 historical time period that is equal in duration and continuous with the previous 1 target time period); there is a second dependency relationship between the current multi-dimensional dynamic features at 9:00-10:00 on December 2 (i.e., the current target time period) and the first historical multi-dimensional dynamic features at 9:00-10:00 on December 1 (i.e., the previous 1 target time period).
[0055] Input the first historical multi-dimensional dynamic feature, the second historical multi-dimensional dynamic feature, the first dependency relationship, the current multi-dimensional dynamic feature, and the second dependency relationship into the pre-trained first long short-term memory network model to obtain the first predicted multi-dimensional dynamic feature for the subsequent 1 time period that is equal in duration and continuous with the current target time period. For example, the first predicted multi-dimensional dynamic feature for 10:00 - 11:00 on December 2 (i.e., the subsequent 1 time period that is equal in duration and continuous with the current target time period) can be predicted based on the current multi-dimensional dynamic feature from 9:00 - 10:00 on December 2, the first historical multi-dimensional dynamic feature from 9:00 - 10:00 on December 1, and the second multi-dimensional dynamic feature from 10:00 - 11:00 on December 1.
[0056] Moreover, since the first long short-term memory network model is obtained by training multiple first training samples input into the initial long short-term memory network, each first training sample includes the first historical multi-dimensional dynamic feature of 1 target time period in history, the second historical multi-dimensional dynamic feature of the subsequent 1 historical time period that is equal in duration and continuous with 1 target time period in history, and the corresponding historical first dependency relationship, the historical current multi-dimensional dynamic feature of the historical current target time period, the second dependency relationship between the first historical multi-dimensional dynamic feature of 1 target time period in history and the historical current multi-dimensional dynamic feature of the historical current target time period, and the corresponding historical actual multi-dimensional dynamic feature of the subsequent 1 time period that is equal in duration and continuous with the historical current target time period. Thus, the accuracy of the predicted first predicted multi-dimensional dynamic feature is very high.
[0057] Input the preset multi-dimensional static features and the first predicted multi-dimensional dynamic features into the pre-trained security assessment prediction model to obtain the security assessment coefficient of the data resource library in the next 1 time period that is equal in duration and continuous with the current target time period. Since the accuracy of the first predicted multi-dimensional dynamic features obtained by prediction is very high, and the multi-dimensional static features at least include the cracking difficulty of the encryption key for the business data in the data resource library, the storage environment category of the multi-dimensional static features, and the geographical distribution breadth of the server running the data resource library, and the security assessment prediction model is obtained by training multiple second training samples input into the first neural network, each second training sample includes historical multi-dimensional static features, historical first predicted multi-dimensional dynamic features, and the historical actual security assessment coefficient used to characterize the next 1 time period that is equal in duration and continuous with the historical target time period. In this way, the accuracy of the predicted security assessment coefficient of the data resource library in the next 1 time period that is equal in duration and continuous with the current target time period can be very high. When the security assessment coefficient is greater than the set assessment coefficient threshold, a warning prompt for the existence of security risks in the data resource library is generated. In this way, when there is no security risk in the data resource library yet, it can be extracted to remind the maintenance personnel that there is a security risk in the data resource library in the next 1 time period, so that the maintenance personnel can perform security maintenance on the data resource library in advance, and further avoid data security accidents in the data resource library. Description of the Drawings
[0058] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0059] Figure 1 It is a flowchart of the data resource library security assessment method based on the large language model provided by the embodiments of the present application;
[0060] Figure 2 It is a functional module block diagram of the data resource library security assessment device provided by the embodiments of the present application. Detailed Embodiments
[0061] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. Based on the embodiments of the present application, all other embodiments made by those of ordinary skill in the art under the inspiration of this embodiment belong to the scope of protection of the present application.
[0062] In the description and claims of this application and the above-mentioned drawings, terms such as "first", "second", "third", "fourth", etc. (if any) are used to distinguish similar objects and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of this application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.
[0063] Please refer to Figure 1 , an embodiment of this application provides a method for security assessment of a data resource library based on a large language model, which is applied to a supervision server of the data resource library. The method provided by the embodiment of this application includes:
[0064] S101: In the current target time period, for each piece of incremental business data in a preset data resource library, based on a pre-trained large language model, identify whether there is sensitive data in the incremental business data.
[0065] Among them, the large language model is obtained by inputting a plurality of first training samples into a deep learning network. Each first training sample includes historical business data and a corresponding label, and the label is used to characterize whether the historical business data includes sensitive data. The large language model LMM (Large Language Model, LLM) refers to a deep learning model that uses a large number of training samples. The large language model can generate natural language text or understand the meaning of data; and the large language model has powerful general modeling ability and generalization ability. Exemplarily, the large language model can be, but is not limited to, the ChatGLM-6B large model. Sensitive data can be, but is not limited to, user privacy information (such as identity information, phone numbers, etc.), texts, videos, or pictures that violate laws and regulations.
[0066] Exemplarily, the large language model provided in the embodiments of the present application is a sensitive data automatic recognition model based on LLaMA-2. LLaMA-2 (language modeling with explicit memory) is an open-source large language model. In the training phase of the sensitive data automatic recognition model based on LLaMA-2, first, when inputting sensitive data training samples (sensitive data training samples consist of historical sensitive data texts and corresponding labels), LLaMA-2 will use the byte pair encoding (BPE) tokenization algorithm to decompose the historical sensitive data text into finer-grained words or phrases to form a Token sequence. The Embedding model then continues to transform the Token sequence into an Embedding sequence. Then, the Embedding sequence is processed through a multi-layer Transformer architecture, where the Transformer framework uses a dynamic self-attention mechanism, enabling the model to capture information of other words in the text and better understand the context relationship of the sensitive data text. Finally, through a fully connected layer and a Softmax activation function, the probability of the classification result is obtained. By performing supervised learning repeatedly in this way, the large language model can distinguish the differences between ordinary data texts and sensitive data texts as much as possible, resulting in a very high accuracy rate for the large language model to recognize.
[0067] S102: If there is sensitive data, determine the type of the sensitive data.
[0068] S103: Count the total number of incremental business data, the first number of sensitive data recognized, and the second data volume of sensitive data belonging to the target type in the current target time period.
[0069] Among them, the target type includes at least the voice type, the picture type, and the video type.
[0070] S104: Determine the first ratio of the first number of sensitive data recognized to the total number of incremental business data, and the second ratio of the second number of sensitive data of the target type to the first number of sensitive data recognized.
[0071] It can be understood that the first ratio and the second ratio can characterize the security evolution of the data repository, and the first ratio and the second ratio are negatively correlated with the security of the data repository.
[0072] S105: In the current target time period, count the number of operations on the data repository and the number of newly added users with access rights to the data repository.
[0073] Understandably, the number of operations on the data repository and the number of newly added users with access rights to the data repository can characterize the security evolution of the data repository, and the number of operations on the data repository and the number of newly added users with access rights to the data repository are negatively correlated with the security of the data repository.
[0074] S106: Construct a current multi-dimensional dynamic feature for characterizing the security evolution of the data repository based on the total number of incremental service data, the first number of sensitive data identified, the second data volume of sensitive data belonging to the target type, the first ratio, the second ratio, the number of operations on the data repository, and the number of newly added users with access rights to the data repository.
[0075] Understandably, the current multi-dimensional dynamic feature can comprehensively and accurately characterize the security evolution of the data repository.
[0076] S107: Obtain the first historical multi-dimensional dynamic feature for characterizing the security evolution of the data repository in the previous target time period and the second historical multi-dimensional dynamic feature for characterizing the security evolution of the data repository in the subsequent historical time period that is equal in duration and continuous with the previous target time period.
[0077] S108: Extract the first dependency relationship between the first historical multi-dimensional dynamic feature and the second historical multi-dimensional dynamic feature according to the deep belief network, and extract the second dependency relationship between the first historical multi-dimensional dynamic feature and the current multi-dimensional dynamic feature.
[0078] S109: Input the first historical multi-dimensional dynamic feature, the second historical multi-dimensional dynamic feature, the first dependency relationship, the current multi-dimensional dynamic feature, and the second dependency relationship into the pre-trained first long short-term memory network model to obtain the first predicted multi-dimensional dynamic feature in the subsequent time period that is equal in duration and continuous with the current target time period.
[0079] Among them, the first long short-term memory network model is obtained by training multiple first training samples in an initial long short-term memory network. Each first training sample includes the first historical multi-dimensional dynamic features of 1 target time period in history, the second historical multi-dimensional dynamic features of the next 1 historical time period that is equal in duration and continuous with the 1 target time period in history, as well as the corresponding historical first dependency relationship, the historical current multi-dimensional dynamic features of the historical current target time period, the second dependency relationship between the first historical multi-dimensional dynamic features of 1 target time period in history and the historical current multi-dimensional dynamic features of the historical current target time period, and the corresponding historical actual multi-dimensional dynamic features of the next 1 time period that is equal in duration and continuous with the historical current target time period. Among them, since the initial long short-term memory (LSTM, Long Short-Term Memory) network is a type of time recurrent neural network model, it is specifically designed to solve the long-term dependency problem existing in ordinary RNNs (recurrent neural networks). Due to its unique design structure, LSTM is suitable for processing and predicting important events with very long intervals and delays in time series. The ingenuity of the LSTM network is to design the weight coefficients between connections by adding an input gate, a forget gate, and an output gate, enabling the LSTM network to accumulate long-term connections between nodes that are far apart and achieve long-term memory of data. Thus, the first long short-term memory network model obtained through such training can be accurately obtained.
[0080] It can be understood that the law of the evolution of the multi-dimensional dynamic features of the data resource library has a certain correlation with the time period. For example, there is a first dependency relationship between the first historical multi-dimensional dynamic features at 9:00 - 10:00 on December 1st (i.e., the previous 1 target time period) and the second multi-dimensional dynamic features at 10:00 - 11:00 on December 1st (i.e., the next 1 historical time period that is equal in duration and continuous with the previous 1 target time period); there is a second dependency relationship between the current multi-dimensional dynamic features at 9:00 - 10:00 on December 2nd (i.e., the current target time period) and the first historical multi-dimensional dynamic features at 9:00 - 10:00 on December 1st (i.e., the previous 1 target time period).
[0081] Input the first historical multi-dimensional dynamic feature, the second historical multi-dimensional dynamic feature, the first dependency relationship, the current multi-dimensional dynamic feature, and the second dependency relationship into the pre-trained first long short-term memory network model to obtain the first predicted multi-dimensional dynamic feature for the next 1 time period that is equal in duration and continuous with the current target time period. For example, the first predicted multi-dimensional dynamic feature for 10:00-11:00 on December 2 (i.e., the next 1 time period that is equal in duration and continuous with the current target time period) can be predicted based on the current multi-dimensional dynamic feature for 9:00-10:00 on December 2, the first historical multi-dimensional dynamic feature for 9:00-10:00 on December 1, and the second multi-dimensional dynamic feature for 10:00-11:00 on December 1.
[0082] It should be noted that in one possible implementation, before S101, the method provided in the embodiments of the present application further includes: obtaining the first historical multi-dimensional dynamic feature of multiple historical 1 target time periods, the second historical multi-dimensional dynamic feature of the next 1 historical time period that is equal in duration and continuous with the historical 1 target time period, the corresponding historical first dependency relationship, the historical current multi-dimensional dynamic feature of the historical current target time period, the second dependency relationship between the first historical multi-dimensional dynamic feature of the historical 1 target time period and the historical current multi-dimensional dynamic feature of the historical current target time period, and the corresponding historical actual multi-dimensional dynamic feature of the next 1 time period that is equal in duration and continuous with the historical current target time period, and constructing multiple first training samples; inputting the multiple first training samples into the initial long short-term memory network for training to obtain the first long short-term memory network model.
[0083] S110: Input the preset multi-dimensional static feature and the first predicted multi-dimensional dynamic feature into the pre-trained security assessment prediction model to obtain the security assessment coefficient of the data resource library for the next 1 time period that is equal in duration and continuous with the current target time period.
[0084] Among them, the multi-dimensional static feature at least includes the cracking difficulty of the encryption key for the business data in the data resource library, the storage environment category of the multi-dimensional static feature, and the geographical distribution breadth of the server running the data resource library, and the security assessment prediction model is obtained by inputting multiple second training samples into the first neural network. Each second training sample includes the historical multi-dimensional static feature, the historical first predicted multi-dimensional dynamic feature, and the historical actual security assessment coefficient used to represent the next 1 time period that is equal in duration and continuous with the historical target time period.
[0085] S111: Generate a warning prompt for the security risk of the data resource library when the security assessment coefficient is greater than the set assessment coefficient threshold.
[0086] In a possible implementation manner, after S109, the method provided by the embodiments of the present application further includes:
[0087] Step 1: Obtain a plurality of historical third multi-dimensional dynamic features respectively corresponding to the previous N time periods that are equal in duration and continuous to the current target time period and are recorded.
[0088] Step 2: Determine the change rule of the multi-dimensional dynamic features of the data resource library according to the plurality of historical third multi-dimensional dynamic features and the current multi-dimensional dynamic features corresponding to the current target time period.
[0089] Step 3: Predict the second predicted multi-dimensional dynamic features of the subsequent 1 time period that is equal in duration and continuous to the current target time period according to the change rule of the multi-dimensional dynamic features of the data resource library.
[0090] Among them, the change rule of the multi-dimensional dynamic features of the data resource library can be input into a pre-trained dynamic feature prediction model to predict the second predicted multi-dimensional dynamic features of the subsequent 1 time period that is equal in duration and continuous to the current target time period. Among them, the dynamic feature prediction model is trained by inputting the change rules of a plurality of historical multi-dimensional dynamic features into a gated recurrent neural network. The gated recurrent neural network (GRU) can better capture the dependencies with a large time step distance in the time series. It controls the flow of information through learnable gates. In this way, the second predicted multi-dimensional dynamic features can be accurately obtained.
[0091] Step 4: Correct the first predicted multi-dimensional dynamic features according to the second predicted multi-dimensional dynamic features.
[0092] Specifically, the feature values with the same dimensions in the second predicted multi-dimensional dynamic features and the first predicted multi-dimensional dynamic features are weighted and averaged to obtain the corrected first predicted multi-dimensional dynamic features. In this way, more accurate first predicted multi-dimensional dynamic features can be obtained.
[0093] In addition, in a possible implementation manner, the method provided by the embodiments of the present application further includes: when the security evaluation coefficient is greater than the set evaluation coefficient threshold, input the first predicted multi-dimensional dynamic features into a pre-trained database maintenance policy model to obtain the preventive maintenance policy of the data resource library. Among them, the database maintenance policy model is trained by inputting a plurality of historical first predicted multi-dimensional dynamic features and the corresponding standard preventive maintenance policies into a second neural network; transmit the preventive maintenance policy of the data resource library to the remote terminal for display. In this way, the maintenance personnel can be timely warned to perform security maintenance on the resource database, and the occurrence of data security accidents can be avoided.
[0094] Please refer to Figure 2 , a security evaluation device for a data resource library based on a large language model provided by an embodiment of the present application. It should be noted that the basic principle and the technical effects generated by the security evaluation device for the data resource library based on the large language model provided by the embodiment of the present application are the same as those of the above embodiment. For a brief description, for the parts not mentioned in the embodiment of the present application, reference can be made to the corresponding content in the above embodiment. The security evaluation device for the data resource library based on the large language model provided by the present application includes a sensitive data identification unit, a sensitive data type identification unit, a data statistics unit, a feature construction unit, a feature acquisition unit, a feature relationship determination unit, a feature prediction unit, a security evaluation unit, and a risk warning unit. Among them,
[0095] The sensitive data identification unit is used to, within the current target time period, for each piece of incremental service data in the preset data resource library, based on a pre-trained large language model, identify whether there is sensitive data in the incremental service data. Among them, the large language model is obtained by inputting a plurality of first training samples into a deep learning network. Each first training sample includes historical service data and a corresponding label, and the label is used to characterize whether the historical service data includes sensitive data;
[0096] The sensitive data type identification unit is used to, if there is sensitive data, determine the type of the sensitive data;
[0097] The data statistics unit is used to count the total number of incremental service data, the first number of sensitive data identified, and the second data volume of sensitive data belonging to the target type within the current target time period. Among them, the target type includes at least the voice type, the picture type, and the video type;
[0098] The data statistics unit is further used to determine the first proportion of the first number of sensitive data identified to the total number of incremental service data, and the second proportion of the second number of sensitive data of the target type to the first number of sensitive data identified;
[0099] The data statistics unit is further used to, within the current target time period, count the number of operations on the data resource library and the number of newly added users with access rights to the data resource library;
[0100] The feature construction unit is used to construct the current multi-dimensional dynamic feature for characterizing the security evolution of the data resource library according to the total number of incremental service data, the first number of sensitive data identified, the second data volume of sensitive data belonging to the target type, the first proportion, the second proportion, the number of operations on the data resource library, and the number of newly added users with access rights to the data resource library;
[0101] A feature acquisition unit, configured to acquire a first historical multi-dimensional dynamic feature for characterizing the security evolution of a data repository in the previous target time period and a second historical multi-dimensional dynamic feature for characterizing the security evolution of the data repository in a subsequent historical time period that is equal in duration and continuous with the previous target time period;
[0102] A feature relationship determination unit, configured to extract a first dependency relationship between the first historical multi-dimensional dynamic feature and the second historical multi-dimensional dynamic feature according to a deep belief network, and extract a second dependency relationship between the first historical multi-dimensional dynamic feature and the current multi-dimensional dynamic feature;
[0103] A feature prediction unit, configured to input the first historical multi-dimensional dynamic feature, the second historical multi-dimensional dynamic feature, the first dependency relationship, the current multi-dimensional dynamic feature, and the second dependency relationship into a pre-trained first long short-term memory network model to obtain a first predicted multi-dimensional dynamic feature for a subsequent time period that is equal in duration and continuous with the current target time period. The first long short-term memory network model is obtained by training an initial long short-term memory network with a plurality of first training samples. Each first training sample includes a first historical multi-dimensional dynamic feature in the previous target time period in history, a second historical multi-dimensional dynamic feature in a subsequent historical time period that is equal in duration and continuous with the previous target time period in history, and a corresponding historical first dependency relationship, a historical current multi-dimensional dynamic feature in the historical current target time period, a second dependency relationship between the first historical multi-dimensional dynamic feature in the previous target time period in history and the historical current multi-dimensional dynamic feature in the historical current target time period, and a corresponding historical actual multi-dimensional dynamic feature for a subsequent time period that is equal in duration and continuous with the historical current target time period;
[0104] A security assessment unit, configured to input a preset multi-dimensional static feature and the first predicted multi-dimensional dynamic feature into a pre-trained security assessment prediction model to obtain a security assessment coefficient for the data repository in a subsequent time period that is equal in duration and continuous with the current target time period. The multi-dimensional static feature at least includes the cracking difficulty of the encryption key for the business data in the data repository, the storage environment category of the multi-dimensional static feature, and the geographical distribution breadth of the server running the data repository. The security assessment prediction model is obtained by training a first neural network with a plurality of second training samples. Each second training sample includes a historical multi-dimensional static feature, a historical first predicted multi-dimensional dynamic feature, and a historical actual security assessment coefficient for a subsequent time period that is equal in duration and continuous with the historical target time period;
[0105] A risk warning unit, configured to generate a warning prompt indicating that there is a security risk in the data repository when the security assessment coefficient is greater than a set assessment coefficient threshold.
[0106] In a possible implementation, the feature acquisition unit is further configured to acquire a plurality of historical third multi-dimensional dynamic features respectively corresponding to the first N time periods that are recorded and have the same duration as the current target time period and are continuous;
[0107] The feature prediction unit is further configured to determine the change rule of the multi-dimensional dynamic features of the data resource library according to the plurality of historical third multi-dimensional dynamic features and the current multi-dimensional dynamic features corresponding to the current target time period; and predict the second predicted multi-dimensional dynamic features of the next 1 time period that has the same duration as the current target time period and is continuous according to the change rule of the multi-dimensional dynamic features of the data resource library;
[0108] The device provided by the present application further includes: a feature correction unit, configured to correct the first predicted multi-dimensional dynamic features according to the second predicted multi-dimensional dynamic features.
[0109] In a possible implementation, the feature correction unit is specifically configured to perform weighted averaging on the feature values with the same dimensions in the second predicted multi-dimensional dynamic features and the first predicted multi-dimensional dynamic features to obtain the corrected first predicted multi-dimensional dynamic features.
[0110] In a possible implementation, the device provided by the present application further includes:
[0111] A preventive maintenance strategy determination unit, configured to input the first predicted multi-dimensional dynamic features into a pre-trained database maintenance strategy model to obtain a preventive maintenance strategy for the data resource library when the safety evaluation coefficient is greater than a set evaluation coefficient threshold, where the database maintenance strategy model is obtained by training a second neural network with a plurality of historical first predicted multi-dimensional dynamic features and corresponding standard preventive maintenance strategies;
[0112] A data transmission unit, configured to transmit the preventive maintenance strategy of the data resource library to a remote terminal for display.
[0113] In a possible implementation, the device provided by the present application further includes:
[0114] A model training unit is configured to obtain first historical multi-dimensional dynamic features of multiple historical target time periods, second historical multi-dimensional dynamic features of the subsequent historical time period that is equal in duration and continuous with the historical target time period, as well as corresponding historical first dependencies, historical current multi-dimensional dynamic features of the historical current target time period, second dependencies between the first historical multi-dimensional dynamic features of the historical target time period and the historical current multi-dimensional dynamic features of the historical current target time period, and corresponding historical actual multi-dimensional dynamic features of the subsequent time period that is equal in duration and continuous with the historical current target time period, and construct multiple first training samples; input the multiple first training samples into an initial long short-term memory network for training to obtain a first long short-term memory network model.
[0115] In summary, the embodiments of the present application provide a method and device for security assessment of a data resource library based on a large language model, which can, within the current target time period, for each piece of incremental business data in a preset data resource library, based on a pre-trained large language model, identify whether there is sensitive data in the incremental business data. Since the large language model is obtained by inputting multiple first training samples into a deep learning network, each first training sample includes historical business data and a corresponding label, and the label is used to characterize whether the historical business data includes sensitive data; thus, the reliability and accuracy of identifying sensitive data are high.
[0116] If there is sensitive data, determine the type of the sensitive data; count the total number of incremental business data in the current target time period, the first number of identified sensitive data, and the second data volume of sensitive data belonging to the target type, where the target type at least includes voice type, picture type, and video type; determine the first ratio of the first number of identified sensitive data to the total number of incremental business data, and the second ratio of the second number of sensitive data of the target type to the first number of identified sensitive data; within the current target time period, count the number of operations on the data resource library and the number of newly added users with access rights to the data resource library.
[0117] Since the current multi-dimensional dynamic features representing the security evolution of the data resource library include: the total number of incremental business data, the first number of identified sensitive data, and the second data volume, first ratio, second ratio of sensitive data belonging to the target type, the number of operations on the data resource library, and the number of newly added users with access rights to the data resource library; thus, it can more accurately represent the security evolution of the data resource library.
[0118] Obtain the first historical multi-dimensional dynamic features for characterizing the security evolution of the data repository in the previous target time period of the record, and the second historical multi-dimensional dynamic features for characterizing the security evolution of the data repository in the subsequent historical time period that is equal in duration and continuous with the previous target time period; extract the first dependency relationship between the first historical multi-dimensional dynamic features and the second historical multi-dimensional dynamic features, and extract the second dependency relationship between the first historical multi-dimensional dynamic features and the current multi-dimensional dynamic features according to the deep belief network. It can be understood that there is a certain correlation between the evolution law of the multi-dimensional dynamic features of the data repository and the time period. For example, there is a first dependency relationship between the first historical multi-dimensional dynamic features at 9:00-10:00 on December 1 (i.e., the previous target time period) and the second multi-dimensional dynamic features at 10:00-11:00 on December 1 (i.e., the subsequent historical time period that is equal in duration and continuous with the previous target time period); there is a second dependency relationship between the current multi-dimensional dynamic features at 9:00-10:00 on December 2 (i.e., the current target time period) and the first historical multi-dimensional dynamic features at 9:00-10:00 on December 1 (i.e., the previous target time period).
[0119] Input the first historical multi-dimensional dynamic features, the second historical multi-dimensional dynamic features, the first dependency relationship, the current multi-dimensional dynamic features, and the second dependency relationship into the pre-trained first long short-term memory network model to obtain the first predicted multi-dimensional dynamic features in the subsequent time period that is equal in duration and continuous with the current target time period. For example, the first predicted multi-dimensional dynamic features at 10:00-11:00 on December 2 (i.e., the subsequent time period that is equal in duration and continuous with the current target time period) can be predicted based on the current multi-dimensional dynamic features at 9:00-10:00 on December 2, the first historical multi-dimensional dynamic features at 9:00-10:00 on December 1, and the second multi-dimensional dynamic features at 10:00-11:00 on December 1.
[0120] And since the first long short-term memory network model is trained by inputting multiple first training samples into the initial long short-term memory network, each first training sample includes the first historical multi-dimensional dynamic features in the previous target time period in history, the second historical multi-dimensional dynamic features in the subsequent historical time period that is equal in duration and continuous with the previous target time period in history, and the corresponding historical first dependency relationship, the historical current multi-dimensional dynamic features in the historical current target time period, the second dependency relationship between the first historical multi-dimensional dynamic features in the previous target time period in history and the historical current multi-dimensional dynamic features in the historical current target time period, and the corresponding historical actual multi-dimensional dynamic features in the subsequent time period that is equal in duration and continuous with the historical current target time period. Thus, the accuracy of the predicted first predicted multi-dimensional dynamic features is very high.
[0121] Input the preset multi-dimensional static features and the first predicted multi-dimensional dynamic features into the pre-trained security assessment prediction model to obtain the security assessment coefficient of the data resource library in the next 1 time period that is equal in duration and continuous with the current target time period. Since the accuracy of the first predicted multi-dimensional dynamic features obtained by prediction is very high, and the multi-dimensional static features at least include the cracking difficulty of the encryption key for the business data in the data resource library, the storage environment category of the multi-dimensional static features, and the geographical distribution breadth of the server running the data resource library, and the security assessment prediction model is obtained by training multiple second training samples into the first neural network, each second training sample includes historical multi-dimensional static features, historical first predicted multi-dimensional dynamic features, and the historical actual security assessment coefficient used to represent the next 1 time period that is equal in duration and continuous with the historical target time period. In this way, the accuracy of the predicted security assessment coefficient of the data resource library in the next 1 time period that is equal in duration and continuous with the current target time period can be very high. When the security assessment coefficient is greater than the set assessment coefficient threshold, a warning prompt for the existence of a security risk in the data resource library is generated. In this way, in the case where the data resource library has not yet had a security risk, it can be extracted to remind the maintenance personnel that there is a security risk in the data resource library in the next 1 time period, so that the maintenance personnel can perform security maintenance on the data resource library in advance, and further avoid data security accidents in the data resource library.
[0122] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, and are not intended to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present application.
Claims
1. A data resource library security assessment method based on a large language model, characterized in that: The method comprises: In the current target time period, for each piece of incremental business data in a preset data resource library, based on a pre-trained large language model, identify whether the incremental business data contains sensitive data, wherein the large language model is trained by inputting a plurality of first training samples into a deep learning network, each of the first training samples includes historical business data and a corresponding label, and the label is used to characterize whether the historical business data includes sensitive data; If sensitive data exists, determining the type of the sensitive data; Counting the total amount of incremental business data in the current target time period, the first amount of identified sensitive data, and the second amount of sensitive data belonging to a target type, wherein the target type includes at least a voice type, a picture type, and a video type; Determine a first ratio of a first amount of the identified sensitive data to a total amount of the incremental business data, and a second ratio of a second amount of sensitive data of the target type to the first amount of the identified sensitive data; In the current target time period, count the number of operations on the data resource library and the number of newly added users with access rights to the data resource library; Constructing a current multi-dimensional dynamic feature for characterizing the security evolution of the data resource library according to the total amount of the incremental business data, the first amount of the identified sensitive data, the second amount of sensitive data belonging to the target type, the first proportion, the second proportion, the number of operations on the data resource library, and the number of newly added users with access rights to the data resource library; Obtaining a first historical multi-dimensional dynamic feature for characterizing the security evolution of the data resource library within the last target time period and a second historical multi-dimensional dynamic feature for characterizing the security evolution of the data resource library within a subsequent historical time period that is equal to and continuous with the last target time period; Extracting a first dependency relationship between a first historical multi-dimensional dynamic feature and a second historical multi-dimensional dynamic feature according to a deep belief network, and extracting a second dependency relationship between the first historical multi-dimensional dynamic feature and the current multi-dimensional dynamic feature; Input the first historical multidimensional dynamic feature, the second historical multidimensional dynamic feature, the first dependency, the current multidimensional dynamic feature, and the second dependency into a pre-trained first long short-term memory network model to obtain a first predicted multidimensional dynamic feature of a subsequent time period that is equal to and continuous with the duration of the current target time period, wherein the first long short-term memory network model is trained by inputting a plurality of first training samples into an initial long short-term memory network, and each of the first training samples includes a first historical multidimensional dynamic feature of a historical target time period, a second historical multidimensional dynamic feature of a subsequent historical time period that is equal to and continuous with the duration of a historical target time period, and a corresponding historical first dependency, a historical current multidimensional dynamic feature of a historical current target time period, a second dependency between the first historical multidimensional dynamic feature of a historical target time period and the historical current multidimensional dynamic feature of the historical current target time period, and a corresponding historical actual multidimensional dynamic feature of a subsequent time period that is equal to and continuous with the duration of the historical current target time period; Input the preset multi-dimensional static features and the first predicted multi-dimensional dynamic features into the pre-trained security assessment prediction model to obtain the security assessment coefficient of the data resource library in the next time period that is equal to and continuous with the current target time period, wherein the multi-dimensional static features at least include the difficulty of cracking the encryption key of the business data in the data resource library, the storage environment category of the multi-dimensional static features, and the geographical distribution breadth of the server running the data resource library, and the security assessment prediction model is obtained by inputting multiple second training samples into the first neural network for training, each of the second training samples includes historical multi-dimensional static features, historical first predicted multi-dimensional dynamic features, and a historical actual security assessment coefficient for characterizing the next time period that is equal to and continuous with the historical target time period; When the security assessment coefficient is greater than a set assessment coefficient threshold, an early warning prompt is generated indicating that the data resource library has a security risk.
2. The method according to claim 1, characterized in that After obtaining the first predicted multi-dimensional dynamic feature of a subsequent time period that is equal in length to and continuous with the current target time period, the method further includes: Acquire multiple historical third multi-dimensional dynamic features corresponding to the first N consecutive time periods that are equal in length to the current target time period; Determine a change rule of the multidimensional dynamic features of the data resource library according to the plurality of historical third multidimensional dynamic features and the current multidimensional dynamic features corresponding to the current target time period; According to the changing rules of the multi-dimensional dynamic features of the data resource library, predict a second predicted multi-dimensional dynamic feature of a subsequent time period that is equal to and continuous with the current target time period; The first predicted multi-dimensional dynamic feature is modified according to the second predicted multi-dimensional dynamic feature.
3. The method according to claim 2, characterized in that The modifying the first predicted multi-dimensional dynamic feature according to the second predicted multi-dimensional dynamic feature includes: The feature values of the same dimension in the second predicted multi-dimensional dynamic feature and the first predicted multi-dimensional dynamic feature are weighted averaged to obtain a modified first predicted multi-dimensional dynamic feature.
4. The method according to claim 1, characterized in that: The method further comprises: In the case where the safety assessment coefficient is greater than a set assessment coefficient threshold, the first predicted multi-dimensional dynamic feature is input into a pre-trained database maintenance strategy model to obtain a preventive maintenance strategy for the data resource library, wherein the database maintenance strategy model is obtained by inputting a plurality of historical first predicted multi-dimensional dynamic features and corresponding standard preventive maintenance strategies into a second neural network for training; The preventive maintenance strategy of the data resource library is transmitted to a remote terminal for display.
5. The method according to any one of claims 1 to 4, characterized in that: Before identifying, for each piece of incremental business data in a preset data resource library within the current target time period, whether sensitive data exists in the incremental business data based on a pre-trained large language model, the method further includes: Acquire a plurality of first historical multidimensional dynamic features of a target time period in history, a second historical multidimensional dynamic feature of a subsequent historical time period that is equal in length to and continuous with a target time period in history, and a corresponding first historical dependency relationship, a historical current multidimensional dynamic feature of a historical current target time period, a second dependency relationship between the first historical multidimensional dynamic feature of a target time period in history and the historical current multidimensional dynamic feature of the historical current target time period, and a corresponding historical actual multidimensional dynamic feature of a subsequent time period that is equal in length to and continuous with the current target time period in history, and construct a plurality of first training samples; The multiple first training samples are input into an initial long short-term memory network for training to obtain the first long short-term memory network model.
6. A data resource library security assessment device based on a large language model, characterized in that: The device comprises: A sensitive data identification unit is used to identify, within a current target time period, for each piece of incremental business data in a preset data resource library, whether the incremental business data contains sensitive data based on a pre-trained large language model, wherein the large language model is trained by inputting a plurality of first training samples into a deep learning network, each of the first training samples includes historical business data and a corresponding label, and the label is used to characterize whether the historical business data includes sensitive data; A sensitive data type identification unit, used to determine the type of sensitive data if there is sensitive data; a data statistics unit, configured to count the total amount of incremental service data in the current target time period, the first amount of identified sensitive data, and the second amount of sensitive data belonging to a target type, wherein the target type includes at least a voice type, a picture type, and a video type; The data statistics unit is further used to determine a first ratio of a first quantity of the identified sensitive data to a total quantity of the incremental business data, and a second ratio of a second quantity of sensitive data of the target type to the first quantity of the identified sensitive data; The data statistics unit is further used to count the number of operations on the data resource library and the number of newly added users with access rights to the data resource library within the current target time period; a feature construction unit, configured to construct a current multi-dimensional dynamic feature for characterizing the security evolution of the data resource library according to the total amount of the incremental business data, the first amount of the identified sensitive data, the second amount of sensitive data belonging to the target type, the first proportion, the second proportion, the number of operations on the data resource library, and the number of newly added users with access rights to the data resource library; A feature acquisition unit, used to acquire a first historical multi-dimensional dynamic feature recorded in a previous target time period for characterizing the security evolution of the data resource library and a second historical multi-dimensional dynamic feature recorded in a subsequent historical time period that is equal in length to and continuous with the previous target time period for characterizing the security evolution of the data resource library; A feature relationship determination unit, configured to extract a first dependency relationship between a first historical multi-dimensional dynamic feature and a second historical multi-dimensional dynamic feature according to a deep belief network, and to extract a second dependency relationship between the first historical multi-dimensional dynamic feature and the current multi-dimensional dynamic feature; A feature prediction unit, used for inputting the first historical multidimensional dynamic feature, the second historical multidimensional dynamic feature, the first dependency, the current multidimensional dynamic feature, and the second dependency into a pre-trained first long short-term memory network model to obtain a first predicted multidimensional dynamic feature of a subsequent time period that is equal to and continuous with the duration of the current target time period, wherein the first long short-term memory network model is trained by inputting a plurality of first training samples into an initial long short-term memory network, each of the first training samples comprising a first historical multidimensional dynamic feature of a historical target time period, a second historical multidimensional dynamic feature of a subsequent historical time period that is equal to and continuous with the duration of a historical target time period, and a corresponding historical first dependency relationship, a historical current multidimensional dynamic feature of a historical current target time period, a second dependency relationship between the first historical multidimensional dynamic feature of a historical target time period and the historical current multidimensional dynamic feature of the historical current target time period, and a corresponding historical actual multidimensional dynamic feature of a subsequent time period that is equal to and continuous with the duration of the historical current target time period; A security assessment unit, used for inputting the preset multi-dimensional static features and the first predicted multi-dimensional dynamic features into a pre-trained security assessment prediction model, to obtain a security assessment coefficient of the data resource library in a subsequent time period that is equal to and continuous with the current target time period, wherein the multi-dimensional static features at least include the difficulty of cracking the encryption key of the business data in the data resource library, the storage environment category of the multi-dimensional static features, and the geographical distribution breadth of the server running the data resource library, and the security assessment prediction model is obtained by inputting a plurality of second training samples into the first neural network for training, each of the second training samples includes a historical multi-dimensional static feature, a historical first predicted multi-dimensional dynamic feature, and a historical actual security assessment coefficient for characterizing a subsequent time period that is equal to and continuous with the historical target time period; The risk warning unit is used to generate a warning prompt that the data resource library has a security risk when the security assessment coefficient is greater than a set assessment coefficient threshold.
7. The device according to claim 6, characterized in that The feature acquisition unit is further used to acquire a plurality of historical third multi-dimensional dynamic features corresponding to the first N time periods that are equal in length to the current target time period and continuous; The feature prediction unit is further used to determine the change law of the multidimensional dynamic features of the data resource library according to the multiple historical third multidimensional dynamic features and the current multidimensional dynamic features corresponding to the current target time period; and predict the second predicted multidimensional dynamic features of a subsequent time period that is equal to and continuous with the current target time period according to the change law of the multidimensional dynamic features of the data resource library; The device also includes: a feature correction unit, configured to correct the first predicted multi-dimensional dynamic feature according to the second predicted multi-dimensional dynamic feature.
8. The device according to claim 7, characterized in that The feature correction unit is specifically used to perform weighted averaging of feature values of the same dimension in the second predicted multi-dimensional dynamic feature and the first predicted multi-dimensional dynamic feature to obtain a corrected first predicted multi-dimensional dynamic feature.
9. The device according to claim 6, characterized in that The device also includes: a preventive maintenance strategy determination unit, configured to input the first predicted multi-dimensional dynamic feature into a pre-trained database maintenance strategy model to obtain a preventive maintenance strategy for the data resource library when the safety assessment coefficient is greater than a set assessment coefficient threshold, wherein the database maintenance strategy model is obtained by inputting a plurality of historical first predicted multi-dimensional dynamic features and corresponding standard preventive maintenance strategies into a second neural network for training; The data transmission unit is used to transmit the preventive maintenance strategy of the data resource library to a remote terminal for display.
10. The device according to any one of claims 6 to 9, characterized in that: The device also includes: A model training unit is used to obtain a first historical multidimensional dynamic feature of a target time period in history, a second historical multidimensional dynamic feature of a subsequent historical time period that is equal to and continuous with a target time period in history, and the corresponding first historical dependency relationship, the historical current multidimensional dynamic feature of a current target time period in history, the second dependency relationship between the first historical multidimensional dynamic feature of a target time period in history and the historical current multidimensional dynamic feature of the current target time period in history, and the corresponding actual historical multidimensional dynamic feature of a subsequent time period that is equal to and continuous with the current target time period in history, and construct a plurality of first training samples; input the plurality of first training samples into an initial long short-term memory network for training to obtain the first long short-term memory network model.
Citation Information
Patent Citations
Service system security condition prediction method and device, equipment and medium
CN115509880A
Enterprise risk prediction method based on big data, control device and storage medium
CN115660410A
Alarm log analysis method and system based on large language model
CN117544397A