Network security auxiliary analysis and decision-making method based on generative large model
Through the generative large model, intelligent correlation analysis of network security is solved, the attack problem of data centers in digital power grid network security is achieved, efficient threat detection and decision support is achieved, and the automated processing capabilities and decision-making accuracy of network security are improved.
Patent Information
- Application Number
- CN202411842833.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-13
- Publication Date
- 2025-07-04
AI Technical Summary
The network security of digital power grids faces problems such as network bandwidth exhaustion, data theft, system tampering and wrong decision-making in data centers, and the existing technology lacks an effective analysis framework and data labeling difficulties.
Generative large-scale models are used to perform intelligent correlation analysis of network security, combined with firewall logs, intrusion detection system logs and vulnerability scanning reports, multi-dimensional data correlation is achieved through question-and-answer analysis mode, predict attack behavior and provide decision-making suggestions, use distributed databases to store data and analyze it using Transformer architecture, and combine visualization tools and security mechanisms for display and control.
It improves the automatic processing capabilities of network security data, provides real-time security situation awareness, threat detection and decision-making support, reduces false alarms and missed reports, and improves the work efficiency and decision-making accuracy of security teams.
Smart Images

Figure CN120263437A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of system research and development and demonstration, and specifically provides a network security assisted analysis and decision-making method based on a generative large model. Background Art
[0002] As the core hub of the digital power grid, the data center is responsible for processing and storing a large amount of power data and control information, so its security is of vital importance. A distributed denial-of-service attack can cause the network bandwidth of the data center to be exhausted, affecting data transmission and service availability. Attackers may invade the data center through malware to steal sensitive data, encrypt data for ransom, or even damage system functions. The data center stores a large amount of power user data, operation data, and control information, which may be illegally obtained and utilized. Attackers may tamper with the data in the data center, causing the power system to make incorrect decisions and affecting the stable operation of the power grid.
[0003] Combined with the characteristics of power network security attack and defense service data and the defense structure, a digital power grid network security large model is studied and designed to solve the problems faced by the digital power grid network security large model, such as insufficient power network security attack and defense confrontation training data, difficulty in annotating large-scale massive data, difficulty in modeling the analysis framework, and lack of analysis and evaluation techniques. Summary of the Invention
[0004] In view of the above problems, the present invention is proposed.
[0005] Therefore, the present invention provides a network security assisted analysis and decision-making method based on a generative large model, which can solve the problems mentioned in the background art.
[0006] To solve the above technical problems, the present invention provides the following technical solution: A network security assisted analysis and decision-making method based on a generative large model, including: collecting data from firewall logs, intrusion detection system logs, and vulnerability scan reports and performing preprocessing;
[0007] Performing network security intelligent correlation analysis based on the generative large model, and implementing multi-dimensional data correlation using a question-and-answer analysis mode;
[0008] Learning and analyzing historical network security data, predicting attack behaviors, and issuing early warnings;
[0009] Generating decision suggestions and action plans according to the threat detection and analysis results;
[0010] Visualizing and displaying through a security situation map, a threat heat map, and an attack path map;
[0011] Issuing alarm notifications according to preset rules and thresholds.
[0012] As a preferred solution of the network security assisted analysis and decision-making method based on the generative large model of the present invention, wherein: a distributed database is used to store network security data, and a language model based on the Transformer architecture is used for data analysis and prediction;
[0013] The network security intelligent correlation analysis adopts clustering algorithms, classification algorithms and regression algorithms; The visual display uses D3.js or Echarts to implement question-and-answer interaction;
[0014] During the data processing process, data encryption, access control and identity authentication are adopted, and security audits and vulnerability scans are regularly performed.
[0015] As a preferred solution of the network security assisted analysis and decision-making method based on the generative large model of the present invention, wherein: through network security attack and defense comparison verification tests, the attack recognition accuracy, alarm response speed and automated disposal capabilities are verified.
[0016] As a preferred solution of the network security assisted analysis and decision-making method based on the generative large model of the present invention, wherein: computing resources and system environments are configured according to the business scale, and a data processing platform and a monitoring and recording system are established.
[0017] As a preferred solution of the network security assisted analysis and decision-making method based on the generative large model of the present invention, wherein: computing resources and system environments are configured according to the business scale, and a data processing platform and a monitoring and recording system are established.
[0018] As a preferred solution of the network security assisted analysis and decision-making method based on the generative large model of the present invention, wherein: a question-and-answer service for laws, regulations, rules and regulations, and network security knowledge is provided through an intelligent question-and-answer module.
[0019] As a preferred solution of the network security assisted analysis and decision-making method based on the generative large model of the present invention, wherein: vector indexing, similarity calculation and inverted index technologies are adopted for data retrieval; System management is realized through user management, permission management, log management and configuration management.
[0020] To further solve the above technical problems, the present invention provides the following technical solution: a network security assisted analysis and decision-making system based on a generative large model, including: a data processing unit, configured to collect and preprocess data from firewall logs, intrusion detection system logs and vulnerability scan reports;
[0021] A threat analysis unit, configured to perform network security intelligent correlation analysis based on a generative large model and realize multi-dimensional data correlation through a question-and-answer analysis mode;
[0022] An attack prediction unit for learning and analyzing historical network security data and predicting attack behaviors;
[0023] A decision support unit for providing decision-making suggestions and action plans based on the threat detection and analysis results;
[0024] An interactive display unit for visual display through security situation maps, threat heat maps, and attack path maps;
[0025] An alarm control unit for sending alarm notifications according to preset rules and thresholds.
[0026] A computer device comprising a memory and a processor, the memory storing a computer program, characterized in that when the processor executes the computer program, the steps of the above-mentioned network security assisted analysis and decision-making method based on the generative large model are implemented.
[0027] A computer-readable storage medium having a computer program stored thereon, characterized in that when the computer program is executed by a processor, the steps of the above-mentioned network security assisted analysis and decision-making method based on the generative large model are implemented.
[0028] Advantages of the present invention: The present invention aims to utilize the capabilities of the generative large model to analyze network security data and provide decision support. It can automatically process and understand a large amount of network security information, providing real-time security situation awareness, threat detection, attack prediction, and decision-making suggestions.
[0029] A large model knowledge base and a plugin library are designed to enhance the flexibility and scalability of the system. The knowledge base stores rich security knowledge, providing a solid foundation for quickly responding to various security events; the plugin library continuously expands the functional boundaries of the system through linkage with third-party products to adapt to the complex and changing network environment.
[0030] 1. Improve efficiency: The system can automatically process and analyze a large amount of network security data, greatly improving the work efficiency of the security team.
[0031] 2. Improve accuracy: Based on the generative large model and machine learning algorithms, the system can detect and predict threats more accurately, reducing false positives and false negatives.
[0032] 3. Provide decision support: The system can provide decision-making suggestions and action plans based on the threat detection and analysis results, helping the security team make more informed decisions. The system can monitor the network security status in real time, promptly discover and handle security events, and improve the response speed of network security. Description of the Drawings
[0033] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.
[0034] Figure 1 It is a schematic diagram of the overall process of a network security assisted analysis and decision-making method based on a generative large model proposed by the present invention;
[0035] Figure 2 It is a diagram of a computer device in a network security assisted analysis and decision-making method based on a generative large model proposed by the present invention. Detailed implementation manners
[0036] To make the above objects, features, and advantages of the present invention more obvious and understandable, the following will provide a detailed description of the specific implementation manners of the present invention in conjunction with the accompanying drawings of the specification. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0037] In the following description, many specific details are set forth to facilitate a full understanding of the present invention. However, the present invention can also be implemented in other ways different from those described herein. Those skilled in the art can make similar extensions without departing from the connotation of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.
[0038] Example 1, referring to Figure 1 , which is an embodiment of the present invention, and provides a network security assisted analysis and decision-making method based on a generative large model.
[0039] S1. Data collection and preprocessing: The system collects data from various network security data sources, including firewall logs, intrusion detection system logs, and vulnerability scan reports; then, preprocesses these data to ensure data quality and consistency;
[0040] S2. Threat detection and analysis: Based on the research of network security intelligent association analysis technology based on a generative large model, combined with the existing network security analysis system, design a question-and-answer-based network security intelligent analysis mode, and improve the efficiency of network security detection and analysis through multi-dimensional data association analysis;
[0041] Based on the generative large model, the system performs real-time analysis on network security data, detects potential threats and attack behaviors; identifies abnormal traffic, malware, and network scans, and provides detailed threat reports and analysis;
[0042] S3. Attack Prediction: By learning and analyzing historical cybersecurity data, the system predicts future attack behaviors and issues early warnings to help the security team take corresponding preventive measures.
[0043] S4. Decision Support: Based on the results of threat detection and analysis, the system provides decision-making suggestions and action plans. It can assist the security team in formulating response strategies, optimizing security configurations, and enhancing network security defense capabilities. For real-time intelligent decision support, the system processes and analyzes a large amount of data within a short period and gives accurate decision-making suggestions, which requires extremely high technical requirements.
[0044] The cybersecurity assisted analysis and decision-making system based on the generative large model demonstrates powerful technical strength and practical value with its advanced technology integration, clear goals and implementation steps, and prominent key technologies.
[0045] S5. Interaction and Display: The system presents cybersecurity data to users in a visual manner, and the visual methods include security situation maps, threat heat maps, and attack path maps. This can help users more intuitively understand the cybersecurity situation and make quick decisions. To achieve seamless docking and intelligent linkage with existing security devices, the system not only needs to process complex security event data but also interact with security devices in real time and efficiently.
[0046] S6. Intelligent Alarm: The system automatically sends alarm notifications according to the rules and thresholds set by users. Alarm notifications can be sent to relevant personnel via email, text message, instant messaging, etc., to ensure that they timely learn about cybersecurity events.
[0047] This system covers core functional modules such as cybersecurity model training, cybersecurity assisted analysis, and cybersecurity control decision-making. With the cooperation of cybersecurity plugins that are seamlessly docked with border cybersecurity devices, it realizes comprehensive linkage analysis and rapid disposal of cybersecurity risks.
[0048] Monitor the cybersecurity situation in real time, promptly detect and handle security incidents, and enhance network security defense capabilities. Protect critical information infrastructure, prevent cyberattacks and information leakage. Prevent financial crimes such as cyber fraud and money laundering, and ensure financial security. Protect user privacy and data security.
[0049] In a specific embodiment of the present invention, the system uses a distributed database or data warehouse to store network security data; these databases can provide efficient data storage and query capabilities and support large-scale data processing. The system generates large models including language models of the Transformer architecture to analyze and predict network security data. These models can automatically learn patterns and rules in the data and generate corresponding analysis results and prediction reports.
[0050] In a specific embodiment of the present invention, the system uses machine learning algorithms including clustering algorithms, classification algorithms and regression algorithms to further analyze and process network security data. These algorithms can help the system better understand the data and improve the accuracy of threat detection and attack prediction.
[0051] The visualization tools used include D3.js or Echarts, which present network security data to users in a visual question-and-answer interactive manner. These tools can provide rich visualization effects to help users understand network security status more intuitively.
[0052] In the specific implementation of the present invention, the system adopts a security mechanism, which includes data encryption, access control and identity authentication to ensure the security and confidentiality of network security data. At the same time, the system also regularly conducts security audits and vulnerability scans to timely discover and repair security vulnerabilities.
[0053] In a specific embodiment of the present invention, a network security attack and defense comparison verification test is used to simulate actual network attacks to focus on verifying the system's recognition accuracy, alarm response speed and automated handling capabilities for network attacks. Invite a third-party organization to use a variety of attack methods to test the actual combat effectiveness and stability of the system. The goal is to ensure that the system can operate stably in a complex network environment and provide a solid barrier for the network security of the digital power grid. This attack and defense comparison is not only a test of technical achievements, but also an important assessment of the practicality and reliability of the system. It is hoped that this will demonstrate the advancement and practicality of the technology and help improve the network security protection capabilities of the digital power grid; based on the security demonstration application of network attack and defense verification, the project effect is fully verified through third-party network security attack and defense tests.
[0054] In a specific implementation of the present invention, appropriate computing resources are evaluated and purchased according to the business scale, and a compatible and stable system environment is configured. Secondly, a data processing and model training platform is built, and a monitoring and logging system is implemented. At the model level, large models are developed and optimized according to the network security needs of the power industry, and efficient and accurate network security analysis is achieved through training, fine-tuning, evaluation and compression. Furthermore, a stable and scalable API interface is designed and deployed at the service layer, and detailed documentation and developer training are provided. Finally, a network security auxiliary analysis and decision-making system is developed at the application layer to achieve intelligent linkage with network security equipment, provide training and technical support to users, and continuously monitor and optimize the system. This technical route will provide the power industry with a comprehensive and intelligent network security solution and enhance security protection capabilities.
[0055] In a specific embodiment of the present invention, the generative big model-based system includes an association analysis module, an auxiliary analysis module, an intelligent disposal module, and a summary analysis module. Association analysis module: performs in-depth analysis of risk assets, attackers, security incidents, and vulnerabilities to help users fully understand the security situation. Auxiliary analysis module: provides functions such as attack load analysis, intent analysis, link restoration, and security recommendations to assist users in making quick and accurate responses. Intelligent disposal module: Automates operations such as blocking, diversion, speed limiting, and frequency limiting to effectively respond to network security threats. Summary analysis module: generates an overall security overview, security incident overview, attacker overview, and security operation report to help users grasp the overall situation and optimize security strategies.
[0056] In a specific embodiment of the present invention, an intelligent question-and-answer module is provided for interaction and display, which is used to provide question-and-answer services such as laws and regulations, company rules and regulations, network security knowledge, and security product knowledge, so as to enhance users' security awareness and response capabilities; an intuitive web interface and an efficient API interface are used at the interaction and display level to ensure that all types of users can easily obtain the required information and make decisions quickly. Data visualization supports Text2Viz, which converts complex data sets into intuitive visual charts, providing decision makers with clear and easy-to-understand data presentations, and helping to quickly gain insight into the key information behind the data. The data architecture of this system has made breakthroughs in advancement, feasibility, and key technical difficulties, providing strong data support for network security analysis and decision-making.
[0057] In a specific embodiment of the present invention, a data retrieval mechanism is provided, which includes utilizing vector indexing, similarity calculation and inverted indexing technology to achieve rapid retrieval and positioning of data, thereby meeting the system's demand for instant query of data.
[0058] In a specific embodiment of the present invention, a system management component is provided. The system management component includes functions such as user management, permission management, log management, API interfaces, and configuration management. These functions jointly ensure the stability, security, and usability of the system while providing basic support for other modules.
[0059] The security operation module covers sub-modules such as correlation analysis, auxiliary judgment, intelligent disposal, summary analysis, and intelligent Q&A. Through these sub-modules, the system can provide comprehensive network security analysis and decision-making support to help users effectively cope with various network security challenges. Correlation analysis: Deeply analyze key information such as risk assets, attacker behavior, security incidents, and vulnerabilities. Auxiliary judgment: Analyze attack payloads, attack intentions, and link restoration and provide targeted security suggestions. Intelligent disposal: Automatically execute security response measures such as blocking, diversion, speed limiting, and frequency limiting. Summary analysis: Generate comprehensive security profiles, security incident, and attacker analysis reports to help users optimize security policies. Intelligent Q&A: Provide intelligent Q&A services on laws and regulations, company rules and regulations, network security, and security product knowledge.
[0060] The knowledge base module supports the uploading, management, retrieval, etc. of knowledge, providing rich knowledge reserves for the system and facilitating the security analysis and decision-making process.
[0061] The plugin module realizes the linkage with third-party security products and expands the functions and adaptability of the system through functions such as plugin management, plugin scheduling, parameter extraction, and scheduling result parsing. At the same time, it also supports the query and result parsing of network security databases, improving the overall efficiency of the system.
[0062] This system serves four types of roles: Ordinary users: Can conveniently query information such as laws and regulations and process specifications. Security operation decision-makers: Can quickly understand the overall security information of the system, such as alarm summaries and risk points, through the system and use large models for efficient summarization. Security operation personnel: Can obtain disposal suggestions for specific security alarms, improving the response speed and accuracy. System administrators: Responsible for comprehensively managing the operation and maintenance of the system to ensure the stability and security of the system.
[0063] Beneficial effects: This system aims to utilize the capabilities of generative large models to analyze network security data and provide decision-making support. It can automatically process and understand a large amount of network security information, providing real-time security situation awareness, threat detection, attack prediction, and decision-making suggestions;
[0064] The data architecture of this system adheres to the design principles of high efficiency, scalability, and security to meet the data requirements of the network security assisted analysis and decision-making system based on generative large models. The system integrates diverse data sources, including real-time network security data, enterprise asset data, and a knowledge base covering key content such as vulnerability knowledge and business information, ensuring the comprehensiveness and timeliness of the data. Through an efficient data update mechanism, the system can continuously absorb the latest information, providing a solid data foundation for analysis and decision-making.
[0065] Research on the key technologies of network security attack and defense collaboration and disposal based on large models, combined with the existing network security defense situation, improves the level of network security confrontation through methods such as plug-in docking, intelligent orchestration defense, and collaborative confrontation.
[0066] At the data processing level, the system adopts advanced technical means, such as NL2SQL technology, to achieve the automatic conversion of natural language to database query statements, greatly improving the efficiency and accuracy of data retrieval. At the same time, the application of Text2Viz technology makes it possible to visualize complex data, helping users more intuitively understand the logic and relationships behind the data.
[0067] It can accurately locate the required information in a vast amount of knowledge. This not only improves the accuracy of security analysis but also enhances the system's ability to respond to complex security events.
[0068] In addition, the key technical difficulty in the data architecture lies in how to ensure the timeliness, accuracy, and security of the data. To this end, the system has taken strict data encryption measures and designed multiple data verification mechanisms to ensure the security of the data during transmission, storage, and use.
[0069] Database and knowledge base: The system centrally stores network security data and asset data through the database, and at the same time saves structured and unstructured data including vulnerability knowledge, business information, and security product knowledge through the knowledge base.
[0070] Data synchronization and update: Establish a regular and real-time data update mechanism to ensure that the data in the database and knowledge base always remains up-to-date.
[0071] The network security assisted analysis and decision-making system based on generative large models is a cutting-edge technology platform designed specifically to enhance the network security of digital power grids. The system architecture takes an advanced generative large model as the core, integrates professional knowledge and technologies in the field of network security, and constructs an all-round and multi-level intelligent security defense system.
[0072] The foundation of the system is a powerful large-scale model technology, which has deep data processing and pattern recognition capabilities and can quickly and accurately analyze network security threats. On top of this, combined with the characteristics of network security in the power industry, an expert model has been customized and developed, including auxiliary research and analysis, disposal analysis and other functions, to provide intelligent and precise support for security operations.
[0073] The network security attack and defense comparison verification test is a key link in the comprehensive effect verification of the network security auxiliary analysis and decision-making system developed by this project. This test will simulate real network attack scenarios to strictly evaluate the detection, analysis, and response capabilities of the system. The test content includes but is not limited to the recognition accuracy of various network attacks, the alarm response time, and the effectiveness of the system's automated disposal. A third-party professional team will be invited to use a variety of attack methods to test the robustness and actual combat performance of the system. Through the attack and defense comparison verification, it aims to ensure that the system can operate stably in a complex and changeable network environment and provide a solid network security guarantee for the digital power grid. This test is not only a test of technical achievements, but also an important consideration for the future practicality and reliability of the system. It is expected that through the rigorous verification of this link, the advancement and practicality of the technology of this project will be fully demonstrated, laying a solid foundation for improving the network security level of the digital power grid.
[0074] In order to enhance the flexibility and scalability of the system, a large model knowledge base and plug-in library are designed. The knowledge base reserves a wealth of security knowledge, providing a solid backing for rapid response to various security incidents; the plug-in library continuously expands the functional boundaries of the system through linkage with third-party products to adapt to the complex and changing network environment.
[0075] The generative large-model network security auxiliary analysis and decision-making system was trial-produced. A network security auxiliary analysis and decision-making system based on a large model was developed. The system also covers core functional modules such as network security model training, network security auxiliary analysis, and network security control decision-making. These modules work together to build a comprehensive, multi-level network security protection system. Through continuous learning and optimization of the generative large-model network security auxiliary analysis and decision-making system, pilot verification and application are carried out to improve the level of network security confrontation; network security solutions can process and analyze network security data more efficiently and accurately, provide real-time security situation awareness, threat detection, attack prediction and decision-making recommendations, and improve network security defense capabilities.
[0076] This paper proposes a network security intelligent confrontation technology based on a large model, which transforms traditional manual confrontation into machine confrontation and greatly improves the efficiency of network security confrontation. It has the following practical significance:
[0077] (1) Improve the efficiency of confrontation treatment:
[0078] The network security intelligent countermeasure technology based on large models can automatically analyze, identify, respond to, and defend against network attacks, greatly improving the efficiency of countermeasure handling. Compared with traditional manual countermeasures, machine countermeasures can process a large amount of data, make decisions quickly, and are not affected by factors such as human fatigue and emotions, ensuring the timeliness and accuracy of countermeasure handling.
[0079] (2) Real-time response to network threats:
[0080] As the frequency and complexity of network attacks continue to increase, the requirement for the real-time nature of network security protection is also getting higher and higher. The intelligent countermeasure technology based on large models can monitor the network status in real time, give early warnings of potential threats, and respond quickly, thus effectively preventing the occurrence of attack behaviors or reducing their impacts.
[0081] (3) Reduce the human burden:
[0082] Traditional network security countermeasures require a large amount of human resources, including security experts, analysts, etc. The intelligent countermeasure technology based on large models can automatically complete most of the work, reducing the human burden and enabling security personnel to focus more on complex analysis and strategy formulation.
[0083] (4) Intelligent decision-making support:
[0084] The intelligent countermeasure technology can provide intelligent decision-making support for security personnel through the learning and reasoning capabilities of large models. It can predict the behavior patterns and attack paths of attackers based on historical data and real-time situations, helping security personnel formulate more effective defense strategies.
[0085] (5) Enhance network security defense capabilities:
[0086] The application of intelligent countermeasure technology will greatly enhance the network security defense capabilities. It can automatically identify and respond to various complex network attacks, reduce the likelihood of successful attacks, and protect important information and systems from damage.
[0087] The system utilizes the powerful processing capabilities of generative large models to perform in-depth learning and intelligent analysis on the network security situation of the power grid, aiming to achieve more efficient network security monitoring and response. Through pilot verification applications, we expect to significantly improve the network security countermeasure level of the digital power grid, providing solid technical support for the stable operation of the power grid; this system will not only strengthen the network security defense line of the power grid but also promote the development of network security management towards a more intelligent and automated direction, thus more effectively preventing and responding to various network security threats and ensuring the safe and reliable operation of the digital power grid.
[0088] The network security assisted analysis and decision-making system based on generative large models acts as the core of network security intelligent analysis. Just like a precise brain, it controls the entire security analysis process. This system ingeniously integrates existing network security analysis systems, enabling in-depth intelligent analysis of network security threats and joint judgment across departments and fields. By mining and analyzing various security data, the system can accurately identify potential threats and provide scientific and effective suggestions for network security risk handling accordingly.
[0089] As the decision-making center for network security analysis and handling, this assisted analysis and decision-making system not only has powerful data analysis capabilities. Through seamless docking of network security plugins with border network security devices, it realizes comprehensive linkage analysis and rapid handling of network security risks, significantly improving the efficiency and accuracy of network security prevention.
[0090] Example 2, which is an example of the present invention, provides a network security assisted analysis and decision-making system based on generative large models, including:
[0091] A data processing unit for collecting and preprocessing data from firewall logs, intrusion detection system logs, and vulnerability scan reports;
[0092] A threat analysis unit for performing intelligent correlation analysis of network security based on generative large models and achieving multi-dimensional data correlation through a question-and-answer analysis mode;
[0093] An attack prediction unit for learning and analyzing historical network security data and predicting attack behaviors;
[0094] A decision support unit for providing decision suggestions and action plans based on threat detection and analysis results;
[0095] An interactive display unit for visual display through security situation maps, threat heat maps, and attack path maps;
[0096] An alarm control unit for sending alarm notifications according to preset rules and thresholds.
[0097] Example 3, referring to Figure 2, which is an embodiment of the present invention. The difference from the previous embodiment is that when the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.
[0098] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a definite sequence list of executable instructions for implementing logical functions, and can be specifically implemented in any computer-readable medium for use by an instruction execution system, apparatus, or device (such as a computer-based system, a system including a processor, or other systems that can fetch instructions from the instruction execution system, apparatus, or device and execute the instructions), or in combination with these instruction execution systems, apparatus, or devices. For the purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device.
[0099] More specific examples (non-exhaustive list) of computer-readable media include the following: an electrical connection part (electronic device) having one or more wirings, a portable computer disk cartridge (magnetic device), random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber device, and portable compact disc read-only memory (CDROM). Additionally, the computer-readable medium can even be paper or other suitable media on which the program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other media, then editing, interpreting, or otherwise processing it as appropriate, and then storing it in a computer memory.
[0100] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, any one or a combination of the following techniques well known in the art can be used: discrete logic circuits having logic gate circuits for implementing logical functions on data signals, application specific integrated circuits having appropriate combinational logic gate circuits, programmable gate arrays (PGAs), field programmable gate arrays (FPGAs), etc.
[0101] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered within the scope of the claims of the present invention.
Claims
1. A network security assisted analysis and decision-making method based on a generative large model, characterized in that, Including: Collect and preprocess data from firewall logs, intrusion detection system logs, and vulnerability scan reports; Conduct network security intelligent correlation analysis based on generative large models, and achieve multi-dimensional data correlation through a question-and-answer analysis mode; Learn and analyze historical network security data, predict attack behaviors, and issue early warnings; Generate decision-making suggestions and action plans according to the threat detection and analysis results; Visualize through security situation maps, threat heat maps, and attack path maps; Send alarm notifications according to preset rules and thresholds.
2. The network security assisted analysis and decision-making method based on the generative large model according to claim 1, wherein: Adopt a distributed database to store network security data, and use a language model based on the Transformer architecture for data analysis and prediction; The network security intelligent correlation analysis adopts clustering algorithms, classification algorithms, and regression algorithms; the visualization is implemented using D3.js or Echarts to achieve question-and-answer interaction; Adopt data encryption, access control, and identity authentication during the data processing process, and regularly perform security audits and vulnerability scans.
3. The network security assisted analysis and decision-making method based on the generative large model according to claim 2, wherein: Verify the attack recognition accuracy, alarm response speed, and automated handling capabilities through network security attack and defense comparison verification tests.
4. The network security assisted analysis and decision-making method based on the generative large model according to claim 3, wherein: Configure computing resources and system environments according to the business scale, and establish a data processing platform and a monitoring and recording system.
5. The network security assisted analysis and decision-making method based on the generative large model according to claim 4, characterized in that: Adopt modules including correlation analysis, auxiliary judgment, intelligent handling, and summary analysis for data processing.
6. The network security assisted analysis and decision-making method based on the generative large model according to claim 5, characterized in that: Provide question-and-answer services for laws, regulations, rules, and network security knowledge through an intelligent question-and-answer module.
7. The network security assisted analysis and decision-making method based on a generative large model according to claim 6, characterized in that: Adopt vector indexing, similarity calculation, and inverted index technologies for data retrieval; achieve system management through user management, permission management, log management, and configuration management.
8. A network security assisted analysis and decision-making system based on a generative large model, based on the network security assisted analysis and decision-making method based on the generative large model according to any one of claims 1 to 7, characterized in that: Including, A data processing unit for collecting and preprocessing data from firewall logs, intrusion detection system logs, and vulnerability scan reports; A threat analysis unit for conducting network security intelligent correlation analysis based on generative large models and achieving multi-dimensional data correlation through a question-and-answer analysis mode; An attack prediction unit for learning and analyzing historical network security data and predicting attack behaviors; A decision support unit for providing decision-making suggestions and action plans according to the threat detection and analysis results; An interactive display unit for visualizing through security situation maps, threat heat maps, and attack path maps; An alarm control unit for sending alarm notifications according to preset rules and thresholds.
9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the network security auxiliary analysis and decision-making method based on generative large models according to any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the network security auxiliary analysis and decision-making method based on generative large models according to any one of claims 1 to 7.
Citation Information
Cited By
Computer network intelligent security protection system based on big data
CN120896761A