Network security threat alarm identification method and device based on large language model, equipment and medium
By embedding threat alert knowledge graphs in the large language model and combining data convergence rules, the accuracy and stability of the large language model in network security threat alert recognition is solved, and the accurate analysis and display of threat alert information is achieved, which improves corporate network security.
Patent Information
- Application Number
- CN202510482354.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-17
- Publication Date
- 2025-07-08
AI Technical Summary
The existing large language model has problems of insufficient accuracy and vague knowledge in the identification of network security threat alarms, making it difficult to effectively analyze and display threat alarm information.
By constructing a threat alert knowledge graph and embedding it into the initial large language model, combining preset threat alert data convergence rules, identify whether the alarm event to be identified meets the false threat alert conditions, generate target threat alert information and formulate a resistance plan.
It realizes accurate analysis and intuitive display of threat alarm information, enhances the stability of the large language model, avoids knowledge ambiguity, and improves the enterprise network security level.
Smart Images

Figure CN120281546A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security, and particularly to a method, device, equipment and medium for identifying network security threat warnings based on large language models. Background Art
[0002] Large language models are mainly machine learning models that can operate on massive data parameters and complex structure type data sets. These machine learning models can usually have a certain learning ability through continuous iterative training, can process massive data sets, and can learn and extract deeper data features from massive data sets. Currently, large language models have achieved remarkable results in the fields of natural language processing, computer vision, and speech recognition. Although a large amount of data and computing resources are consumed during the iterative training process of large language models, and a relatively long model training time is also required. However, with the continuous research and application of large language models, there are already many high-performance computing cluster training solutions at the present stage. At the same time, various optimization algorithms and some accelerated iterative algorithms have also been proposed through continuous in-depth research, greatly improving the accuracy and stability of large language models.
[0003] Many problems have also emerged during the development of large language models, such as quantity leakage, data bias, uncontrollable results, and fuzzy knowledge. The large language model can be fused with the knowledge graph, and the large language model can also be fused with data convergence rules, thereby ensuring the stability of the iterative model and avoiding the problem of fuzzy knowledge. The present invention applies the large language model to the security field and proposes the concept of a security large language model. The security large language model is the result of the deep integration of Internet information security and large language models, and is a unique large language model in the field of network security.
[0004] In summary, how to accurately analyze threat warning information and be able to intuitively display threat warning information by using a large language model embedded with a knowledge graph and data convergence rules is an urgent problem to be solved at present. Summary of the Invention
[0005] In view of this, the purpose of the present invention is to provide a method, device, equipment and medium for identifying network security threat warnings based on large language models, which can accurately analyze threat warning information and can also intuitively display threat warning information by using a large language model embedded with a knowledge graph and data convergence rules. The specific solutions are as follows:
[0006] In the first aspect, the present application provides a method for identifying network security threat warnings based on large language models, including:
[0007] Obtain open-source threat alert data, and extract target entities, target relationships between target entities, IP information, and alert event feature information from the open-source threat alert data based on a preset deep learning extraction method to obtain a target threat alert event dataset;
[0008] Construct a threat alert knowledge graph based on the target threat alert event dataset, and embed the threat alert knowledge graph into an initial large language model to obtain a threat alert large language model;
[0009] Construct a preset threat alert data convergence rule, and use the threat alert large language model and the preset threat alert data convergence rule to determine whether the alert event to be recognized meets the preset false threat alert condition;
[0010] If the alert event to be recognized meets the preset false threat alert condition, generate corresponding target threat alert information, and determine a target threat resistance plan according to the target threat alert information.
[0011] Optionally, the constructing a threat alert knowledge graph based on the target threat alert event dataset includes:
[0012] Construct a knowledge graph entity set based on the target entities and IP information in the target threat alert event dataset;
[0013] Construct a knowledge graph relationship set according to the target relationships between target entities and the alert event feature information in the target threat alert event dataset;
[0014] Use the knowledge graph entity set and the knowledge graph relationship set to determine a threat alert knowledge graph.
[0015] Optionally, the embedding the threat alert knowledge graph into an initial large language model includes:
[0016] Use a first embedding operation to convert the tuples in the threat alert knowledge graph into training input data, and pre-train the initial large language model based on the training input data to obtain a threat alert large language model;
[0017] Use a second embedding operation to analyze the entity-entity relationships in the threat alert knowledge graph through the initial large language model, and update the initial large language model based on the obtained analysis results to obtain a threat alert large language model.
[0018] Optionally, the preset threat alert data convergence rule includes any one or more of a preset merge convergence rule, a preset five-tuple convergence rule, a preset URL convergence rule, and a preset custom convergence rule.
[0019] Optionally, determining whether the to-be-identified alarm event meets the preset false threat alarm condition by using the threat alarm large language model and the preset threat alarm data convergence rule includes:
[0020] If the preset threat alarm data convergence rule is the preset merge convergence rule, aggregate the to-be-identified alarm events obtained within a preset time, and store the aggregation result in a preset alarm log, so as to determine whether the to-be-identified alarm event meets the preset false threat alarm condition according to the first aggregation result in the preset alarm log;
[0021] If the preset threat alarm data convergence rule is the preset five-tuple convergence rule, obtain the association information of the to-be-identified alarm events of different alarm types, so as to aggregate the to-be-identified alarm events that meet the preset association condition according to the association information, so as to determine whether the to-be-identified alarm event meets the preset false threat alarm condition according to the second aggregation result;
[0022] If the preset threat alarm data convergence rule is the preset URL convergence rule, obtain the URL path corresponding to the to-be-identified alarm event, so as to determine whether the to-be-identified alarm event meets the preset false threat alarm condition according to the URL path corresponding to the to-be-identified alarm event;
[0023] If the preset threat alarm data convergence rule is the preset custom convergence rule, obtain a preset alarm filtering list, so as to determine whether the to-be-identified alarm event meets the preset false threat alarm condition according to the preset alarm filtering list.
[0024] Optionally, determining whether the to-be-identified alarm event meets the preset false threat alarm condition by using the threat alarm large language model and the preset threat alarm data convergence rule includes:
[0025] Extract the target IP and alarm event feature information corresponding to the to-be-identified alarm event;
[0026] Use the threat alarm large language model to identify the target entity corresponding to the target IP;
[0027] Determine the first vulnerability set of the target entity corresponding to the target IP;
[0028] Based on the threat alarm knowledge graph, determine the second vulnerability set corresponding to the alarm event feature information;
[0029] Judge whether there is an intersection between the first vulnerability set and the second vulnerability set;
[0030] If there is an intersection between the first vulnerability set and the second vulnerability set, it is determined that the to-be-identified alarm event does not meet the preset false threat alarm condition;
[0031] If there is no intersection between the first vulnerability set and the second vulnerability set, it is determined that the to-be-identified alarm event meets the preset false threat alarm condition.
[0032] Optionally, the method further includes:
[0033] Inject the attack data in the to-be-identified alarm event into a preset sandbox simulation environment to obtain the attack data corresponding to the to-be-identified alarm event;
[0034] Identify the attack characteristics of the to-be-identified alarm event based on the attack data corresponding to the to-be-identified alarm event;
[0035] Optimize the preset threat alarm data convergence rule according to the attack characteristics of the to-be-identified alarm event to obtain an optimized preset threat alarm data convergence rule, so as to determine whether the to-be-identified alarm event meets the preset false threat alarm condition based on the optimized preset threat alarm data convergence rule.
[0036] In a second aspect, the present application provides a network security threat alarm recognition device based on a large language model, including:
[0037] A data set acquisition module, configured to acquire open-source threat alarm data, and extract target entities, target relationships between target entities, IP information, and alarm event feature information in the open-source threat alarm data based on a preset deep learning extraction method to obtain a target threat alarm event data set;
[0038] A model acquisition module, configured to construct a threat alarm knowledge graph based on the target threat alarm event data set, and embed the threat alarm knowledge graph into an initial large language model to obtain a threat alarm large language model;
[0039] An event judgment module, configured to construct a preset threat alarm data convergence rule, and use the threat alarm large language model and the preset threat alarm data convergence rule to determine whether a to-be-identified alarm event meets the preset false threat alarm condition;
[0040] A solution generation module, configured to generate corresponding target threat alarm information if the to-be-identified alarm event meets the preset false threat alarm condition, and determine a target threat resistance solution according to the target threat alarm information.
[0041] In a third aspect, the present application provides an electronic device, including:
[0042] A memory, configured to store a computer program;
[0043] A processor for executing the computer program to implement the network security threat warning recognition method based on the large language model as described above.
[0044] In a fourth aspect, the present application provides a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the network security threat warning recognition method based on the large language model as described above is implemented.
[0045] In summary, the present application first obtains open-source threat warning data, extracts target entities, target relationships between target entities, IP information, and warning event feature information from the open-source threat warning data based on a preset deep learning extraction method to obtain a target threat warning event dataset; constructs a threat warning knowledge graph based on the target threat warning event dataset, and embeds the threat warning knowledge graph into an initial large language model to obtain a threat warning large language model; constructs a preset threat warning data convergence rule, and uses the threat warning large language model and the preset threat warning data convergence rule to determine whether a warning event to be recognized meets the preset false threat warning condition; if the warning event to be recognized meets the preset false threat warning condition, a corresponding target threat warning information is generated, and a target threat resistance plan is determined according to the target threat warning information. As can be seen from the above, the present application first obtains open-source threat warning data, extracts target entities, target relationships between target entities, IP information, and warning event feature information from it through a preset deep learning extraction method to obtain a target threat warning event dataset, then constructs a threat warning knowledge graph based on this dataset and embeds it into an initial large language model to obtain a threat warning large language model, then constructs a preset threat warning data convergence rule, uses the threat warning large language model and the preset threat warning data convergence rule to determine whether a warning event to be recognized meets the preset false threat warning condition, if it meets, a target threat warning information is generated, and a target threat resistance plan is determined based on the target threat warning information. In this way, the present application embeds a knowledge graph into the large language model, which can enhance the threat warning large language model through the knowledge graph and avoid the phenomenon of knowledge ambiguity in the large language model. Description of the Drawings
[0046] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.
[0047] Figure 1 It is a flowchart of a network security threat warning recognition method based on a large language model disclosed in the present application;
[0048] Figure 2 A specific flowchart for identifying alarm events disclosed in this application;
[0049] Figure 3 A specific flowchart for a method of identifying network security threat alarms based on a large language model disclosed in this application;
[0050] Figure 4 A schematic structural diagram of a device for identifying network security threat alarms based on a large language model disclosed in this application;
[0051] Figure 5 A structural diagram of an electronic device disclosed in this application. Specific implementation manners
[0052] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0053] Currently, large language models have achieved remarkable results in the fields of natural language processing, computer vision, and speech recognition. Such as the DeepSeek model, Tongyi Qianwen model, etc. Although a large amount of data and computing resources are consumed during the iterative training process of large language models, and a long model training time is also required. However, with the continuous research and application of large language models, there are already many high-performance computing cluster training solutions at present. At the same time, various optimization algorithms and some accelerated iterative algorithms have also been proposed through continuous in-depth research, greatly improving the accuracy and stability of large language models. Many problems have also emerged during the development of large language models, such as quantity leakage, data bias, uncontrollable results, knowledge ambiguity, etc. To solve the above technical problems, this application discloses a method, device, equipment, and medium for identifying network security threat alarms based on a large language model, which can achieve accurate analysis of threat alarm information and can also intuitively display threat alarm information by using a large language model embedded with a knowledge graph and data convergence rules.
[0054] See Figure 1 As shown, the embodiments of the present invention disclose a method for identifying network security threat alarms based on a large language model, including:
[0055] Step S11: Obtain open-source threat alert data, and extract target entities, target relationships between target entities, IP information, and alert event feature information from the open-source threat alert data based on a preset deep learning extraction method to obtain a target threat alert event dataset.
[0056] In this embodiment, obtain relevant datasets related to open-source threat alerts, such as host datasets, alert datasets, etc. Extract target entities, target relationships and attributes between target entities, extraction of IP information, and extraction of alert event feature information from the open-source threat alert data according to the deep learning method. Package the extracted information into a target threat alert event dataset.
[0057] Step S12: Construct a threat alert knowledge graph based on the target threat alert event dataset, and embed the threat alert knowledge graph into an initial large language model to obtain a threat alert large language model.
[0058] In this embodiment, after obtaining the target threat alert event dataset, construct a knowledge graph entity set based on the target entities and IP information in the target threat alert event dataset; construct a knowledge graph relationship set according to the target relationships between the target entities and the alert event feature information in the target threat alert event dataset; use the knowledge graph entity set and the knowledge graph relationship set to determine the threat alert knowledge graph. Specifically, based on the target entities in the target threat alert event dataset and the corresponding IP information of the target entities, determine the devices for each attack, vulnerability, or monitoring, that is, the knowledge graph entity set. Based on the target relationships between the target entities in the target threat alert event dataset and the alert event feature information, determine the set of edges in the knowledge graph, that is, the knowledge graph relationship set, and then construct the corresponding threat alert knowledge graph G according to the knowledge graph entity set and the knowledge graph relationship set:
[0059] ;
[0060] Among them, V represents the devices for attack, vulnerability, or monitoring; E represents the set of edges in the knowledge graph; G represents the threat alert knowledge graph.
[0061] In a specific embodiment, if there is an exploit-type SQL attack on a device, generate a corresponding threat alert knowledge graph according to this attack event:
[0062] ;
[0063] Among them, is the threat alert knowledge graph generated according to the exploit-type SQL attack; is the node of the SQL attack; is a vulnerability or weakness; "ex" stands for "exploit", representing an act of malicious operation. For example, in the field of computer security, "exploit" usually refers to the act of using vulnerabilities in programs or systems to perform malicious operations. represents a device for a certain attack, vulnerability or monitoring.
[0064] In another specific embodiment, if there is an attack event of SQL injection attack on a device, a corresponding threat warning knowledge graph is generated according to this attack event:
[0065] ;
[0066] Among them, represents the threat warning knowledge graph generated according to the SQL injection attack; is the node of the SQL attack; represents a device for a certain attack, vulnerability or monitoring; is an ordinary entity or attribute in the knowledge graph; "insOf" stands for "instance of", representing an attack behavior. For example, in the field of computer security, "instance of" usually refers to the SQL injection attack behavior.
[0067] In this embodiment, after obtaining the threat warning knowledge graph, it is necessary to embed the threat warning knowledge graph into the initial large language model to achieve the deep integration of the knowledge graph and the large language model. It should be noted that there are currently three fusion methods according to the actual threat warning analysis requirements.
[0068] In a specific embodiment, the tuples in the threat warning knowledge graph are converted into training input data by using the first embedding operation, and the initial large language model is pre-trained based on the training input data to obtain a threat warning large language model. Specifically, the knowledge graph is introduced in the pre-training stage and the warning inference stage of the threat warning large language model. For example, the tuples constructed by the knowledge graph can be converted into a piece of Token text as the input value, and the entities and relationships in the original triple are covered for pre-training, so that the threat warning large language model directly learns the knowledge contained in the threat warning knowledge graph in the pre-training stage and obtains the threat warning large language model.
[0069] In another specific embodiment, the second embedding operation is used to analyze the entity-entity relationships in the threat alert knowledge graph through the initial large language model, and the initial large language model is updated based on the obtained analysis results to obtain a threat alert large language model. Specifically, the semantic understanding and generation capabilities of the large language model for threat alerts are used to enhance the construction, completion, and reasoning tasks of the threat alert knowledge graph, and finally a threat alert large language model is obtained. For example, the large language model can be used to extract alert entities and relationship information from the original dataset and construct a threat alert knowledge graph, or the large language model can be used to reason about the missing data in the threat alert knowledge graph.
[0070] In the third specific embodiment, the large language model is used in conjunction with the threat alert knowledge graph, that is, the large language model and the threat alert knowledge graph are used in alert knowledge explicit or reasoning tasks, and the model is trained during the reasoning process to obtain a threat alert large language model.
[0071] Step S13: Construct a preset threat alert data convergence rule, and use the threat alert large language model and the preset threat alert data convergence rule to determine whether the to-be-identified alert event meets the preset false threat alert condition.
[0072] In this embodiment, a preset threat alert data convergence rule is constructed according to the actual needs of the user, and the preset threat alert data convergence rule is called to retrieve and analyze the alert data of the to-be-identified alert event. Among them, the preset threat alert data convergence rule includes any one or several of a preset merge convergence rule, a preset five-tuple convergence rule, a preset URL convergence rule, and a preset custom convergence rule. Whether the to-be-identified alert event is a real alert is judged by extracting the IP information of the to-be-identified alert event, analyzing the vulnerability information, etc.
[0073] In a specific embodiment, if the preset threat alert data convergence rule is the preset merge convergence rule, the to-be-identified alert events obtained within the preset time are aggregated, and the aggregation result is stored in the preset alert log, so as to determine whether the to-be-identified alert event meets the preset false threat alert condition according to the first aggregation result in the preset alert log. Specifically, the to-be-identified alert events obtained within the preset time are aggregated by quickly converging through a completely consistent small window (1 minute). However, due to the large amount of stored data, the to-be-identified alert events may not be saved to the Postgressql database, and the Elasticsearch log is directly used, and only the data volume is counted without list display.
[0074] In another specific embodiment, if the preset threat alert data convergence rule is the preset five-tuple convergence rule, obtain the association information of the to-be-identified alert events of different alert types, so as to aggregate the to-be-identified alert events that meet the preset association conditions according to the association information, and determine whether the to-be-identified alert events meet the preset false threat alert conditions according to the second aggregation result. Specifically, based on the different alert types of the to-be-identified alert events, converge the to-be-identified alert events with the same source / destination IP. For example, within 10 minutes to 24 hours, converge the to-be-identified alert events of different alert types sent from the same source IP address.
[0075] In the third specific embodiment, if the preset threat alert data convergence rule is the preset URL convergence rule, obtain the URL path corresponding to the to-be-identified alert event, so as to determine whether the to-be-identified alert event meets the preset false threat alert conditions according to the URL path corresponding to the to-be-identified alert event. Specifically, based on specific WEB type attacks, such as SQL, XSS, and scanning types, converge the attack events of the same alert type or the same URL into one alert.
[0076] In the fourth specific embodiment, if the preset threat alert data convergence rule is the preset custom convergence rule, obtain the preset alert filtering list, so as to determine whether the to-be-identified alert event meets the preset false threat alert conditions according to the preset alert filtering list. Specifically, perform custom alerts according to the preset alert filtering list. For example, if the target software is included in the preset alert filtering list, ignore all threat alerts for the target software.
[0077] Step S14: If the to-be-identified alert event meets the preset false threat alert conditions, generate corresponding target threat alert information, and determine a target threat defense plan according to the target threat alert information.
[0078] In this embodiment, it is necessary to extract the target IP corresponding to the to-be-identified alert event and the alert event feature information; use the threat alert large language model to identify the target entity corresponding to the target IP; determine the first vulnerability set of the target entity corresponding to the target IP; determine the second vulnerability set corresponding to the alert event feature information based on the threat alert knowledge graph; judge whether there is an intersection between the first vulnerability set and the second vulnerability set; if there is an intersection between the first vulnerability set and the second vulnerability set, it is determined that the to-be-identified alert event does not meet the preset false threat alert conditions; if there is no intersection between the first vulnerability set and the second vulnerability set, it is determined that the to-be-identified alert event meets the preset false threat alert conditions. Specifically, such as Figure 2As shown in the figure, it is determined whether to extract the target IP. If so, the event target IP is extracted; if not, the event number is extracted. Based on the extracted IP, it is determined whether there is a target entity corresponding to the IP. If so, the first vulnerability set of the target entity is directly extracted; if not, the target entity corresponding to the IP needs to be searched based on the knowledge graph, then the target entity is added to the memory, and the first vulnerability set is extracted. At the same time, after the alarm event feature information is extracted, the second vulnerability set corresponding to the alarm event feature information is searched based on the knowledge graph, and it is determined whether the vulnerability set is empty. If so, the event is retained; if not, it needs to continue to execute. Then, it is determined whether there is an intersection between the first vulnerability set and the second vulnerability set. If so, it is determined as a real alarm; if not, it is determined as a false alarm. Finally, the detailed information or overview information of the corresponding threat alarm is generated, and a security defense plan is formulated based on the detailed information of the threat alarm, so as to improve the enterprise network security level.
[0079] In addition, the attack data in the to-be-identified alarm event can be injected into a preset sandbox simulation environment to obtain the attack data corresponding to the to-be-identified alarm event; the attack characteristics of the to-be-identified alarm event are identified based on the attack data corresponding to the to-be-identified alarm event; the preset threat alarm data convergence rule is optimized according to the attack characteristics of the to-be-identified alarm event to obtain an optimized preset threat alarm data convergence rule, so as to determine whether the to-be-identified alarm event meets the preset false threat alarm condition based on the optimized preset threat alarm data convergence rule. Specifically, through the sandbox, the attack process in the threat alarm and the possible impacts caused by the attack in this threat alarm can be explored. For example, the research purpose of false threat alarm identification and simulation of the alarm attack process is to discover the vulnerabilities and hidden dangers in enterprise network security. Because attackers can forge false alarm data and penetrate purposefully by taking advantage of the vulnerabilities in enterprise network security to cover up real security attack information.
[0080] As can be seen from the above, in the embodiment of the present application, first, open-source threat alarm data is obtained, and the target entity, the target relationship between target entities, IP information, and alarm event feature information are extracted from it through a preset deep learning extraction method to obtain a target threat alarm event data set. Then, a threat alarm knowledge graph is constructed based on this data set and embedded into an initial large language model to obtain a threat alarm large language model. Next, a preset threat alarm data convergence rule is constructed, and the threat alarm large language model and the preset threat alarm data convergence rule are used to determine whether the to-be-identified alarm event meets the preset false threat alarm condition. If it meets, target threat alarm information is generated, and a target threat defense plan is determined based on the target threat alarm information. In this way, in the embodiment of the present application, the knowledge graph is embedded in the large language model, and the threat alarm large language model can be enhanced through the knowledge graph, avoiding the phenomenon of knowledge ambiguity in the large language model.
[0081] Based on the previous embodiment, the present application discloses a method for identifying network security threat alerts based on a large language model, which can accurately analyze threat alert information and can also intuitively display threat alert information by using a large language model embedded with a knowledge graph and data convergence rules. Next, a method for identifying network security threat alerts based on a large language model as shown in Figure 3 will be described in detail.
[0082] First, the present application obtains an open-source threat alert-related data set, extracts target entities, target relationships and attributes between target entities, and IP information, and extracts alert event feature information from the open-source threat alert data according to deep learning methods. These extracted information are packaged into a target threat alert event data set.
[0083] Secondly, after obtaining the target threat alert event data set, based on the target entities in the target threat alert event data set and the corresponding IP information of the target entities, determine each device for attack, vulnerability or monitoring, that is, the knowledge graph entity set. Based on the target relationships between the target entities in the target threat alert event data set and the alert event feature information, determine the set of edges in the knowledge graph, that is, the knowledge graph relationship set. Then, construct a corresponding threat alert knowledge graph according to the knowledge graph entity set and the knowledge graph relationship set. After obtaining the threat alert knowledge graph, it is necessary to embed the threat alert knowledge graph into the initial large language model to achieve the deep integration of the knowledge graph and the large language model, so as to obtain a threat alert large language model.
[0084] Next, construct a preset threat alert data convergence rule according to the actual needs of the user. Among them, the preset threat alert data convergence rule includes any one or several of a preset merge convergence rule, a preset five-tuple convergence rule, a preset URL convergence rule, and a preset custom convergence rule. Call the preset threat alert data convergence rule to retrieve and analyze the alert data of the alert event to be identified, and judge whether the alert event to be identified is a real alert by extracting the IP information of the alert event to be identified and analyzing the vulnerability information.
[0085] Finally, if the alert event to be identified meets the preset false threat alert condition, generate the detailed information or overview information of the corresponding threat alert, and formulate a security defense plan based on the detailed information of the threat alert, so as to improve the enterprise network security level.
[0086] See Figure 4 shown, the embodiment of the present invention discloses a device for identifying network security threat alerts based on a large language model, including:
[0087] The dataset acquisition module 11 is used to obtain open-source threat alert data, and extract target entities, target relationships between target entities, IP information, and alert event feature information from the open-source threat alert data based on a preset deep learning extraction method to obtain a target threat alert event dataset;
[0088] The model acquisition module 12 is used to construct a threat alert knowledge graph based on the target threat alert event dataset, and embed the threat alert knowledge graph into an initial large language model to obtain a threat alert large language model;
[0089] The event judgment module 13 is used to construct a preset threat alert data convergence rule, and use the threat alert large language model and the preset threat alert data convergence rule to determine whether the alert event to be identified meets the preset false threat alert condition;
[0090] The solution generation module 14 is used to generate corresponding target threat alert information if the alert event to be identified meets the preset false threat alert condition, and determine a target threat resistance solution according to the target threat alert information.
[0091] As can be seen from the above, this application first obtains open-source threat alert data, extracts target entities, target relationships between target entities, IP information, and alert event feature information from it through a preset deep learning extraction method to obtain a target threat alert event dataset, then constructs a threat alert knowledge graph based on this dataset and embeds it into an initial large language model to obtain a threat alert large language model, then constructs a preset threat alert data convergence rule, uses the threat alert large language model and the preset threat alert data convergence rule to judge whether the alert event to be identified meets the preset false threat alert condition, and if it meets, generates target threat alert information, and determines a target threat resistance solution according to the target threat alert information. In this way, this application embeds a knowledge graph into the large language model, which can enhance the threat alert large language model through the knowledge graph and avoid the phenomenon of knowledge ambiguity in the large language model.
[0092] In some specific implementation manners, the model acquisition module 12 may specifically include:
[0093] The knowledge graph entity set construction unit is used to construct a knowledge graph entity set based on the target entities and IP information in the target threat alert event dataset;
[0094] The knowledge graph relationship set construction unit is used to construct a knowledge graph relationship set according to the target relationships between the target entities and the alert event feature information in the target threat alert event dataset;
[0095] A threat alert knowledge graph construction unit is used to determine a threat alert knowledge graph by using the knowledge graph entity set and the knowledge graph relationship set.
[0096] In some specific embodiments, the model acquisition module 12 may specifically include:
[0097] A first model training unit is used to convert the tuples in the threat alert knowledge graph into training input data by using a first embedding operation, and pre-train the initial large language model based on the training input data to obtain a threat alert large language model;
[0098] A second model training unit is used to analyze the entity and entity relationship in the threat alert knowledge graph through the initial large language model by using a second embedding operation, and update the initial large language model based on the obtained analysis result to obtain a threat alert large language model.
[0099] In some specific embodiments, the preset threat alert data convergence rule includes any one or several of a preset merging convergence rule, a preset five-tuple convergence rule, a preset URL convergence rule, and a preset custom convergence rule.
[0100] In some specific embodiments, the event judgment module 13 may specifically include:
[0101] A first alert judgment unit is used to aggregate the to-be-identified alert events obtained within a preset time if the preset threat alert data convergence rule is the preset merging convergence rule, and store the aggregation result in a preset alert log, so as to determine whether the to-be-identified alert events meet the preset false threat alert condition according to the first aggregation result in the preset alert log;
[0102] A second alert judgment unit is used to obtain the association information of the to-be-identified alert events of different alert types if the preset threat alert data convergence rule is the preset five-tuple convergence rule, so as to aggregate the to-be-identified alert events that meet the preset association condition according to the association information, so as to determine whether the to-be-identified alert events meet the preset false threat alert condition according to the second aggregation result;
[0103] A third alert judgment unit is used to obtain the URL path corresponding to the to-be-identified alert event if the preset threat alert data convergence rule is the preset URL convergence rule, so as to determine whether the to-be-identified alert event meets the preset false threat alert condition according to the URL path corresponding to the to-be-identified alert event;
[0104] The fourth alarm judgment unit is used to obtain a preset alarm filtering list if the preset threat alarm data convergence rule is the preset custom convergence rule, so as to determine whether the to-be-identified alarm event meets the preset false threat alarm condition according to the preset alarm filtering list.
[0105] In some specific embodiments, the event judgment module 13 may specifically include:
[0106] The information extraction unit is used to extract the target IP corresponding to the to-be-identified alarm event and the alarm event feature information;
[0107] The target entity recognition unit is used to recognize the target entity corresponding to the target IP by using the threat alarm large language model;
[0108] The first vulnerability set determination unit is used to determine the first vulnerability set of the target entity corresponding to the target IP;
[0109] The second vulnerability set determination unit is used to determine the second vulnerability set corresponding to the alarm event feature information based on the threat alarm knowledge graph;
[0110] The set intersection determination unit is used to determine whether there is an intersection between the first vulnerability set and the second vulnerability set;
[0111] The first alarm event determination unit is used to determine that the to-be-identified alarm event does not meet the preset false threat alarm condition if there is an intersection between the first vulnerability set and the second vulnerability set;
[0112] The second alarm event determination unit is used to determine that the to-be-identified alarm event meets the preset false threat alarm condition if there is no intersection between the first vulnerability set and the second vulnerability set.
[0113] In some specific embodiments, the network security threat alarm recognition device based on the large language model may further include:
[0114] The attack data acquisition module is used to inject the attack data in the to-be-identified alarm event into a preset sandbox simulation environment to obtain the attack data corresponding to the to-be-identified alarm event;
[0115] The attack feature recognition module is used to recognize the attack features of the to-be-identified alarm event based on the attack data corresponding to the to-be-identified alarm event;
[0116] The optimized preset threat alarm data convergence rule acquisition module is used to optimize the preset threat alarm data convergence rule according to the attack characteristics of the to-be-identified alarm event, so as to obtain the optimized preset threat alarm data convergence rule, and determine whether the to-be-identified alarm event meets the preset false threat alarm condition based on the optimized preset threat alarm data convergence rule.
[0117] Furthermore, an embodiment of the present application also discloses an electronic device. Figure 5 It is a structural diagram of an electronic device 20 shown according to an exemplary embodiment. The content in the figure should not be considered as any limitation on the scope of use of the present application.
[0118] Figure 5 It is a schematic structural diagram of an electronic device 20 provided by an embodiment of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. Among them, the memory 22 is used to store a computer program, and the computer program is loaded and executed by the processor 21 to implement the relevant steps in the method for identifying network security threat alarms based on a large language model disclosed in any of the foregoing embodiments. In addition, the electronic device 20 in this embodiment may specifically be an electronic computer.
[0119] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows is any communication protocol applicable to the technical solution of the present application, and no specific limitation is imposed on it here; the input / output interface 25 is used to obtain external input data or output data to the outside, and its specific interface type can be selected according to specific application needs, and no specific limitation is made here.
[0120] In addition, as a carrier for resource storage, the memory 22 may be a read-only memory, a random access memory, a disk, or an optical disc, etc. The resources stored thereon may include an operating system 221, a computer program 222, etc., and the storage method may be short-term storage or permanent storage.
[0121] Among them, the operating system 221 is used to manage and control each hardware device on the electronic device 20 and the computer program 222, and it may be Windows Server, Netware, Unix, Linux, etc. In addition to the computer program that can be used to complete the method for identifying network security threat alarms based on a large language model executed by the electronic device 20 disclosed in any of the foregoing embodiments, the computer program 222 may further include computer programs that can be used to complete other specific tasks.
[0122] Furthermore, the present application also discloses a computer-readable storage medium for storing a computer program. When the computer program is executed by a processor, it implements the aforementioned network security threat warning recognition method based on a large language model. For the specific steps of this method, reference can be made to the corresponding content disclosed in the foregoing embodiments, and details will not be elaborated herein.
[0123] The various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts among the various embodiments, reference can be made to each other. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple. For related parts, reference can be made to the description in the method section.
[0124] Those skilled in the art can further realize that the units and algorithm steps of the examples described in conjunction with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the examples have been generally described according to their functions in the above description. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.
[0125] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be directly implemented by hardware, software modules executed by a processor, or a combination of both. The software modules can be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium well-known in the technical field.
[0126] Finally, it should also be noted that in this document, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variation thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising a..." does not exclude the existence of additional identical elements in the process, method, article or device comprising the element.
[0127] The above has introduced the technical solution provided by this application in detail. Specific examples are used in this article to elaborate on the principle and implementation manner of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, according to the idea of this application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to this application.
Claims
1. A method for identifying network security threat alerts based on large language models, characterized in that, Including: Obtain open-source threat alert data, and extract target entities, target relationships between target entities, IP information, and alert event feature information from the open-source threat alert data based on a preset deep learning extraction method to obtain a target threat alert event dataset; Construct a threat alert knowledge graph based on the target threat alert event dataset, and embed the threat alert knowledge graph into an initial large language model to obtain a threat alert large language model; Construct a preset threat alert data convergence rule, and use the threat alert large language model and the preset threat alert data convergence rule to determine whether the to-be-identified alert event meets the preset false threat alert condition; If the to-be-identified alert event meets the preset false threat alert condition, generate corresponding target threat alert information, and determine a target threat resistance plan according to the target threat alert information.
2. The method for identifying network security threat alerts based on large language models according to claim 1, wherein The constructing a threat alert knowledge graph based on the target threat alert event dataset includes: Construct a knowledge graph entity set based on the target entities and IP information in the target threat alert event dataset; Construct a knowledge graph relationship set according to the target relationships between the target entities and the alert event feature information in the target threat alert event dataset; Use the knowledge graph entity set and the knowledge graph relationship set to determine a threat alert knowledge graph.
3. The method for identifying network security threat alerts based on a large language model according to claim 1, wherein, The embedding the threat alert knowledge graph into an initial large language model includes: Use a first embedding operation to convert the tuples in the threat alert knowledge graph into training input data, and pre-train the initial large language model based on the training input data to obtain a threat alert large language model; Use a second embedding operation to analyze the entity-entity relationships in the threat alert knowledge graph through the initial large language model, and update the initial large language model based on the obtained analysis results to obtain a threat alert large language model.
4. The method for identifying network security threat alerts based on a large language model according to claim 1, wherein, The preset threat alert data convergence rule includes any one or several of a preset merge convergence rule, a preset five-tuple convergence rule, a preset URL convergence rule, and a preset custom convergence rule.
5. The method for identifying network security threat alerts based on a large language model according to claim 4, wherein, The using the threat alert large language model and the preset threat alert data convergence rule to determine whether the to-be-identified alert event meets the preset false threat alert condition includes: If the preset threat alert data convergence rule is the preset merge convergence rule, aggregate the to-be-identified alert events obtained within a preset time, and store the aggregation result in a preset alert log, so as to determine whether the to-be-identified alert event meets the preset false threat alert condition according to the first aggregation result in the preset alert log; If the preset threat alert data convergence rule is the preset five-tuple convergence rule, obtain the association information of the to-be-identified alert events of different alert types, so as to aggregate the to-be-identified alert events that meet the preset association condition according to the association information, so as to determine whether the to-be-identified alert event meets the preset false threat alert condition according to the second aggregation result; If the preset threat alert data convergence rule is the preset URL convergence rule, obtain the URL path corresponding to the alert event to be identified, so as to determine whether the alert event to be identified meets the preset false threat alert condition according to the URL path corresponding to the alert event to be identified; If the preset threat alert data convergence rule is the preset custom convergence rule, obtain the preset alert filtering list, so as to determine whether the alert event to be identified meets the preset false threat alert condition according to the preset alert filtering list.
6. The method for identifying network security threat alerts based on a large language model according to any one of claims 1 to 5, characterized in that The determining whether the alert event to be identified meets the preset false threat alert condition by using the threat alert large language model and the preset threat alert data convergence rule includes: Extracting the target IP and alert event feature information corresponding to the alert event to be identified; Identifying the target entity corresponding to the target IP by using the threat alert large language model; Determining the first vulnerability set of the target entity corresponding to the target IP; Determining the second vulnerability set corresponding to the alert event feature information based on the threat alert knowledge graph; Judging whether there is an intersection between the first vulnerability set and the second vulnerability set; If there is an intersection between the first vulnerability set and the second vulnerability set, determine that the alert event to be identified does not meet the preset false threat alert condition; If there is no intersection between the first vulnerability set and the second vulnerability set, determine that the alert event to be identified meets the preset false threat alert condition.
7. The method for identifying network security threat alerts based on a large language model according to claim 6, wherein, It also includes: Injecting the attack data in the alert event to be identified into a preset sandbox simulation environment to obtain the attack data corresponding to the alert event to be identified; Identifying the attack characteristics of the alert event to be identified based on the attack data corresponding to the alert event to be identified; Optimizing the preset threat alert data convergence rule according to the attack characteristics of the alert event to be identified to obtain an optimized preset threat alert data convergence rule, so as to determine whether the alert event to be identified meets the preset false threat alert condition based on the optimized preset threat alert data convergence rule.
8. A network security threat warning recognition device based on a large language model, characterized in that, It includes: A data set acquisition module, configured to acquire open-source threat alert data, and extract target entities, target relationships between target entities, IP information, and alert event feature information in the open-source threat alert data based on a preset deep learning extraction method to obtain a target threat alert event data set; A model acquisition module, configured to construct a threat alert knowledge graph based on the target threat alert event data set, and embed the threat alert knowledge graph into an initial large language model to obtain a threat alert large language model; An event judgment module, configured to construct a preset threat alert data convergence rule, and use the threat alert large language model and the preset threat alert data convergence rule to determine whether the alert event to be identified meets the preset false threat alert condition; A solution generation module, configured to generate corresponding target threat alert information if the alert event to be identified meets the preset false threat alert condition, and determine a target threat resistance solution according to the target threat alert information.
9. An electronic device, characterized in that, It includes: A memory, configured to store a computer program; A processor for executing the computer program to implement the method for identifying network security threat alerts based on a large language model according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, For storing a computer program; wherein, when the computer program is executed by a processor, it implements the method for identifying network security threat alerts based on a large language model according to any one of claims 1 to 7.
Citation Information
Cited By
Network security alarm data research and judgment method, electronic equipment, storage medium and program product
CN120639447A
Alarm noise reduction method and system based on large model of power system
CN121998403A