Network security situation assessment system and method based on large model
Through a large-scale network security situation evaluation system, combined with dynamic graph neural network and attack graph technology, a network security situation evaluation report is generated, which solves the real-time and comprehensiveness of network security situation evaluation and provides accurate defense strategy suggestions.
Patent Information
- Application Number
- CN202510432095.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-08
- Publication Date
- 2025-07-11
AI Technical Summary
The existing technology is difficult to achieve comprehensive, real-time assessment and effective disposal of network security situations, resulting in a lack of operational decision-making basis for network security defense systems.
A network security situation evaluation system based on a large model is adopted, data is collected through the network status monitoring module, combined with dynamic graph neural network and attack graph technology, and a thinking chain is used to guide the large language model to generate a network security situation evaluation report, realizing the detection and analysis of potential network risks and vulnerabilities.
It provides high readability and professional network security situation reports, reduces the complexity of network security operation and maintenance, and realizes comprehensive analysis of the overall network situation and accurate suggestions for defense strategies.
Smart Images

Figure CN120301641A_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of network security, and particularly relates to a network security situation assessment system and method based on large models. Background Art
[0002] With the acceleration of the global digital transformation and the continuous development of artificial intelligence technology, network security threats present a severe situation of coexisting scale, concealment, and complexity, greatly increasing the difficulty of comprehensively controlling and effectively disposing of network security situations in real time. Therefore, how to timely and comprehensively evaluate the network security situation and generate a security assessment report has gradually attracted extensive attention in the academic and industrial fields.
[0003] By performing multi-dimensional dynamic analysis on network topology, threat intelligence, vulnerability distribution, attack elements, etc., regularly quantifying and evaluating the security risk level, identifying vulnerable defense links, and predicting potential attack paths, it can effectively provide an operable security decision-making basis for network security defense systems and operation and maintenance personnel. Summary of the Invention
[0004] The purpose of this application is to disclose an intelligent system and method based on a network security situation assessment report to overcome the problems of the prior art. This application uses the network operation log data collected by the network status monitoring log collection module, combines technologies such as retrieval-augmented generation and dynamic graph neural networks to accurately analyze the network threat situation, realizes the detection and analysis of potential risk paths in the network topology based on the attack graph technology, and finally realizes the automated generation of network security situation assessment reports through the chain of thought to guide the large language model (LLM), so as to improve the perception and maintenance efficiency of network operation and maintenance personnel for the overall network security situation.
[0005] On the one hand, the purpose of this application is achieved through the following technical solutions:
[0006] A network security situation assessment system based on a large model, the network security situation assessment system includes: terminal devices, network devices, a network status monitoring module, a network monitoring data collection module, a network operation status analysis module, a network potential risk detection module, and a network security situation report generation module;
[0007] The network monitoring data collection module is configured to collect operation index monitoring data of network terminals and network devices based on the network status monitoring module;
[0008] The network operation status analysis module is configured to analyze the corresponding indicators in the network monitoring data collected by the network monitoring data collection module according to the natural language query input by the user, and generate an analysis result of the current network operation situation;
[0009] The network potential risk detection module is configured to analyze the overall network potential threats and vulnerabilities based on the attack graph, and give the analysis results of network potential risks and vulnerabilities;
[0010] The network security situation report generation module is based on the analysis results of the received network operation status analysis module and the network potential risk detection module. Through the thought chain prompt, it guides the large language model LLM to fuse the analysis results of the network operation status analysis module and the network potential risk detection module to form an overall analysis result of the network security situation, and gives defense measure suggestions based on the overall analysis result, and generates a report template and a network security situation assessment report.
[0011] According to a preferred embodiment, the network monitoring data collection module is configured to monitor the bandwidth utilization rate, network latency, packet loss rate, and response time indicators of terminal devices and network devices to achieve network operation status indicator monitoring.
[0012] According to a preferred embodiment, the network monitoring data collection module is configured to draw a line chart of preset network key indicators, so as to dynamically display the network operation status.
[0013] According to a preferred embodiment, after the network monitoring data collection module completes data collection, it removes redundant information from the data and uploads it to the network monitoring index database for storage at preset time intervals. The network monitoring index database uses the relational database MySQL for storage.
[0014] According to a preferred embodiment, the network operation status analysis module is configured to perform network security situation analysis according to the following method, including:
[0015] When encoding information, first, use natural language processing tools to map the user input query into a tree structure, then perform semantic analysis and causal relationship analysis on the natural language query input by the user based on the pre-trained language model, and fuse the obtained analysis information into the tree structure to form an enhanced abstract syntax tree; then generate an initial multi-data table graph model based on the graph neural network and multi-data tables, and then adjust the weights in the multi-data table graph model in combination with the extracted semantic information to generate a dynamic multi-data table graph model for different natural language queries. Finally, fuse the enhanced syntax tree and the dynamic multi-data table graph model to generate a final joint information graph model;
[0016] When decoding information and generating SQL query statements, it is mainly divided into two parts. First, decode the structure, and update the node feature representation in the joint information graph model through a graph-based search strategy; second, perform label prediction, and for each generated node, predict its corresponding SQL keyword or table name, and select the label with a probability greater than the preset probability as the final predicted label of the node.
[0017] Finally, RAG extracts data using the generated SQL query statements and analyzes it through the pre-trained large language model LLM to achieve the analysis of the network security situation.
[0018] According to a preferred embodiment, during information encoding, the nodes of the tree structure are represented as syntactic components with different attributes, and the edges represent the syntactic and semantic relationships between the nodes; in the initial multi-data table graph model, the nodes are represented as each data table, and the edges represent the weight relationships between the data tables.
[0019] According to a preferred embodiment, the attack graph generation process includes: based on the MulVAL tool, collecting the topological structure, host services, network connections, and attacker information of the network where the system is located, detecting network vulnerabilities in combination with a vulnerability scanning tool, then configuring the obtained information into an input file in the format specified by MulVAL, and finally using the logical reasoning engine of MulVAL to perform reachability analysis and cost analysis reasoning to generate an attack graph.
[0020] According to a preferred embodiment, the network security situation report generation module gradually decomposes complex network situation analysis problems into several sub-problems based on the chain of thought guiding the large language model LLM, and performs reasoning in sequence according to the logical order to generate a comprehensive analysis result of the network security situation in the style of a network security expert.
[0021] According to a preferred embodiment, while performing a comprehensive analysis of the network security situation, the network security situation report generation module guides the large language model LLM through prompts to construct a report template and perform content matching according to the analysis content of each part to generate a final network security situation assessment report.
[0022] On the other hand, the present application also discloses:
[0023] A network security situation assessment method based on a large model, which uses the aforementioned network security situation assessment system, and the network security situation assessment method includes the following steps:
[0024] S1: The network monitoring data collection module automatically collects and stores the operation index monitoring data of terminal devices and network devices in the entire network;
[0025] S2: The network operation status analysis module accurately extracts the corresponding indicators in the network monitoring data according to the natural language query input by the user for analysis, and generates an analysis result of the current network operation situation;
[0026] S3: The network potential risk detection module analyzes the potential threats and vulnerabilities of the overall network based on the attack graph, and gives the analysis results of network potential risks and vulnerabilities;
[0027] S4: The analysis results of the network operation status analysis module and the network potential risk detection module are input into the network security situation report generation module. Through the thought chain prompt, the large model is guided to integrate the two analysis results of the network operation status analysis module and the network potential risk detection module to form an overall analysis result of the network security situation, and based on this, suggestions for defense measures are given, and a report template and a network security situation assessment report are automatically generated.
[0028] The main solution of the present application and its various further alternative solutions can be freely combined to form multiple solutions, all of which are solutions that can be adopted and claimed in the present application. Those skilled in the art can understand that there are various combinations according to the prior art and common general knowledge after understanding the solution of the present application, all of which are the technical solutions to be protected by the present application, and will not be enumerated here.
[0029] Advantages of the present application:
[0030] In view of the increasingly complex network security maintenance situation, the present application proposes an intelligent system and method for generating a network security situation assessment report. By combining mechanisms such as dynamic graph neural network mechanism, attack graph technology, and generative adversarial network, the generation of a network situation security report with high readability and high professionalism is realized, effectively reducing the complexity of network security operation and maintenance. Compared with the prior art, it has the following beneficial effects and advantages:
[0031] The causal analysis and dynamic graph neural network mechanism are introduced into the network operation status analysis module, which integrates semantic information and multi-datatable information, realizes the accurate mapping from natural language queries to SQL query statement fields, effectively solves the problem of data query errors caused by the ambiguity and polysemy of natural language, and forms an accurate analysis result of the network operation status.
[0032] Based on the attack graph mechanism, the network potential risks are detected, and the risks and vulnerabilities of the overall network topology are provided. Together with the analysis result of the network operation status, they are used as the input for network security situation assessment, and a more comprehensive and overall analysis and defense strategy suggestions for the overall network operation situation can be realized.
[0033] The thought chain prompt is introduced into the network security situation report module to guide the large model to decompose the complex network situation analysis task into various different subtasks, so as to achieve a more accurate and professional situation analysis result and defense strategy suggestions, providing a more reliable basis for reducing the difficulty of network security operation and maintenance and optimizing the security strategy decision-making. Brief Description of the Drawings
[0034] Figure 1 It is a schematic diagram of the principle of the network security situation assessment system of the present application;
[0035] Figure 2It is the working flowchart of the network monitoring data collection module;
[0036] Figure 3 It is the working flowchart of the network operation status analysis module;
[0037] Figure 4 It is the schematic diagram of the attack graph generation process;
[0038] Figure 5 It is an example of chain-of-thought prompting. Specific implementation manners
[0039] The following uses specific specific examples to illustrate the implementation manners of the present application. Those skilled in the art can easily understand other advantages and effects of the present application from the content disclosed in this specification. The present application can also be implemented or applied through other different specific implementation manners. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present application. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other.
[0040] It should be noted that: similar reference numerals and letters represent similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.
[0041] Embodiment 1
[0042] The present application discloses a network security situation assessment system based on a large model. The network security situation assessment system includes: terminal devices, network devices, a network status monitoring module, a network monitoring data collection module, a network operation status analysis module, a network potential risk detection module, and a network security situation report generation module. The above components are networked to access the network to form a complete intelligent system for generating network security situation assessment reports. The working principle implemented by this patent is independent of the specific deployment method. Therefore, only Figure 1 the system is used to illustrate the working principle.
[0043] Preferably, the network monitoring data collection module is configured to collect operation metric monitoring data of network terminals and network devices based on the network status monitoring module; the network operation status analysis module is configured to analyze corresponding metrics in the network monitoring data collected by the network monitoring data collection module according to a natural language query input by a user, and generate an analysis result of the current network operation situation; the network potential risk detection module is configured to analyze potential threats and vulnerabilities of the overall network based on an attack graph, and give an analysis result of network potential risks and vulnerabilities; the network security situation report generation module is based on the analysis results received from the network operation status analysis module and the network potential risk detection module, and through a chain of thought prompt, guides a large language model (LLM) to fuse the analysis results of the network operation status analysis module and the network potential risk detection module to form an overall analysis result of the network security situation, and gives defense measure suggestions based on the overall analysis result, and generates a report template and a network security situation assessment report.
[0044] Preferably, the network monitoring data collection module is used to monitor and collect the operation status indicators of terminal devices and network devices in the entire network topology and persistently store them. Its working flow chart is as Figure 2 shown.
[0045] The network monitoring data collection module is divided into three parts according to its functions: network operation status indicator monitoring, network key indicator operation graph drawing, and monitoring data uploading and storage.
[0046] Among them, the network operation status indicator monitoring mainly monitors indicators such as bandwidth utilization rate, network latency, packet loss rate, and response time of terminals and network devices. The network key indicator operation graph mainly draws a line graph of preset network key indicators to dynamically display the network operation status. The monitoring data uploading is mainly to remove redundant information from the data after data collection and upload it to the network monitoring indicator database for storage at a certain time interval. The network monitoring indicator database storage uses a relational database MySQL.
[0047] Preferably, the network operation status analysis module is the key to the preliminary assessment of the overall network situation. This application combines causal relationship analysis, dynamic graph neural network (GNN), and retrieval augmentation (RAG) technologies to complete the accurate mapping from natural language to SQL query statements, and realizes the accurate extraction and professional analysis of the data required to generate the corresponding assessment report.
[0048] Specifically, referring to Figure 3 shown, the network operation status analysis module is configured to perform network security situation analysis according to the following method, including:
[0049] When encoding information, first, a natural language processing tool (such as Stanford NLP) is used to map the user input query into a tree structure, where the nodes represent syntactic components with different attributes, and the edges represent the syntactic and semantic relationships between the nodes. Then, semantic analysis and causal relationship analysis are performed on the natural language query input by the user based on a pre-trained language model (such as BERT), and the obtained analysis information is integrated into the tree structure to form an enhanced abstract syntax tree. Next, an initial multi-data table graph model is generated based on a graph neural network (GNN) and multi-data tables, where the nodes represent each data table, and the edges represent the weight relationships between the data tables. Then, the edge weights in the multi-data table graph model are adjusted by combining the previously extracted semantic information to generate a dynamic multi-data table graph model for different natural language queries. Finally, the enhanced syntax tree and the dynamic multi-data table graph model are fused to generate a final joint information graph model.
[0050] When decoding information to generate an SQL query statement, it is mainly divided into two parts. First, the structure is decoded, and the node feature representation in the joint information graph model is updated through a graph-based search strategy (such as Monte Carlo tree search). This process continues until the entire query structure is generated. Second, label prediction is performed. For each generated node, its corresponding SQL keyword or table name is predicted, and the label with a probability greater than the preset probability is selected as the final predicted label of the node.
[0051] Finally, RAG extracts data using the generated SQL query statement and analyzes it through a pre-trained large language model LLM to achieve the analysis of the network security situation.
[0052] This application introduces causal analysis and dynamic graph neural network mechanisms in the network operation status analysis module, integrates semantic information and multi-data table information, realizes the accurate mapping from natural language queries to SQL query statement fields, effectively solves the problem of data query errors caused by the ambiguity and polysemy of natural language, and forms an accurate analysis result of the network operation status.
[0053] Preferably, the attack graph generation process includes: based on the MulVAL tool, collecting the topological structure, host services, network connections, and attacker information of the network where the system is located, detecting network vulnerabilities by combining vulnerability scanning tools such as Nessus and OpenVAS, then configuring the obtained information into an input file in the format specified by MulVAL, and finally using the logical reasoning engine of MulVAL for reachability analysis and cost analysis reasoning to generate an attack graph.
[0054] An attack graph represents vulnerabilities in a network and their interrelationships in the form of a graph, helping security personnel visually assess network security, potential risk paths, and formulate defense strategies. MulVAL is an attack graph generation tool based on logical reasoning. Its core idea is to transform network security problems into logical programming problems, use rule-based formal methods (such as Datalog language) to reason about attack scenarios, and combine vulnerability databases, network topologies, system configurations, and attack logic rules to automatically construct an attack graph.
[0055] This application detects potential network risks based on the attack graph mechanism, provides risk and vulnerability assessments for the entire network topology, and together with the analysis results of the network operating state as input for network security situation assessment, can achieve a more comprehensive and thorough analysis of the overall network operating situation and defense strategy recommendations.
[0056] Preferably, the network security situation report generation module is the core of generating a network security situation assessment report. It comprehensively analyzes the network security situation based on the analysis results of the network operating state analysis module and the network potential risk analysis module, generates a comprehensive analysis result of the network security situation, and gives suggestions on defense measures.
[0057] In order to make the generated analysis results and defense measure suggestions more in line with the style of network security experts, enhance the professionalism and readability of the report, this application introduces the chain of thought technique in this module. By guiding the large language model to gradually decompose complex network situation analysis problems into multiple sub-problems and perform reasoning in logical order, a comprehensive analysis result of the network security situation that is finally close to the style of network security experts is generated. An example of chain of thought prompting is as Figure 5 shown.
[0058] While conducting a comprehensive analysis of the network security situation, the network security situation report generation module guides the large language model LLM through prompt words to construct a report template and perform content matching based on the analysis content of each part, generating the final network security situation assessment report. Thus, it assists network operation and maintenance personnel in comprehensively perceiving the network security operation situation and provides decision-making support for the generation of network defense strategies, thereby quickly and comprehensively completing network security defense.
[0059] Example 2
[0060] On the other hand, based on Example 1, this application also discloses: A network security situation assessment method based on a large model, using the aforementioned network security situation assessment system, and the network security situation assessment method includes the following steps.
[0061] S1: The network monitoring data acquisition module automatically acquires and stores the operation index monitoring data of terminal devices and network devices in the entire network;
[0062] S2: The network operation status analysis module accurately extracts the corresponding metrics from the network monitoring data according to the natural language query input by the user for analysis, and generates the analysis results of the current network operation situation.
[0063] S3: The network potential risk detection module analyzes the overall network potential threats and vulnerabilities based on the attack graph, and gives the analysis results of network potential risks and vulnerabilities.
[0064] S4: The analysis results of the network operation status analysis module and the network potential risk detection module are input into the network security situation report generation module. Through the thought chain prompt, the large model is guided to integrate the two analysis results of the network operation status analysis module and the network potential risk detection module to form the overall analysis result of the network security situation, and based on this, suggestions for defense measures are given, and the report template and the network security situation assessment report are automatically generated.
[0065] The network security situation report module of this application introduces the thought chain prompt, guiding the large model to decompose the complex network situation analysis task into different sub-tasks, so as to achieve more accurate and professional situation analysis results and defense strategy suggestions, providing a more reliable basis for reducing the difficulty of network security operation and maintenance and optimizing the security strategy decision-making.
[0066] The above are only the preferred embodiments of this application, and are not intended to limit this application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of this application shall be included in the protection scope of this application.
Claims
1. A network security situation assessment system based on a large model, characterized in that The network security situation assessment system includes: terminal devices, network devices, a network status monitoring module, a network monitoring data collection module, a network operation status analysis module, a network potential risk detection module, and a network security situation report generation module; The network monitoring data collection module is configured to collect operation index monitoring data of network terminals and network devices based on the network status monitoring module; The network operation status analysis module is configured to extract corresponding indicators from the network monitoring data collected by the network monitoring data collection module according to the natural language query input by the user for analysis, and generate an analysis result of the current network operation situation; The network potential risk detection module is configured to analyze the overall network potential threats and vulnerabilities based on the attack graph, and give the analysis results of network potential risks and vulnerabilities; The network security situation report generation module is based on receiving the analysis results of the network operation status analysis module and the network potential risk detection module. Through the thought chain prompt, it guides the large language model LLM to fuse the analysis results of the network operation status analysis module and the network potential risk detection module to form an overall analysis result of the network security situation, and gives suggestions on defense measures based on the overall analysis result, and generates a report template and a network security situation assessment report.
2. The network security situation assessment system according to claim 1, wherein The network monitoring data collection module is configured to monitor the bandwidth utilization rate, network latency, packet loss rate, and response time indicators of terminal devices and network devices to achieve network operation status index monitoring.
3. The network security situation assessment system according to claim 2, characterized in that The network monitoring data collection module is configured to draw a line chart of preset network key indicators, so as to dynamically display the network operation status.
4. The network security situation assessment system according to claim 3, characterized in that The network monitoring data collection module is configured to, after completing data collection, remove redundant information from the data and upload it to the network monitoring index database for storage at a preset time interval. The network monitoring index database storage uses the relational database MySQL.
5. The network security situation evaluation system according to claim 1, characterized in that, The network operation status analysis module is configured to perform network security situation analysis according to the following method, including: During information encoding, first, use natural language processing tools to map the user input query into a tree structure, then perform semantic analysis and causal relationship analysis on the natural language query input by the user based on the pre-trained language model, and fuse the obtained analysis information into the tree structure to form an enhanced abstract syntax tree; then generate an initial multi-data table graph model based on the graph neural network and multi-data tables, and then adjust the weights in the multi-data table graph model in combination with the extracted semantic information to generate a dynamic multi-data table graph model for different natural language queries. Finally, fuse the enhanced syntax tree and the dynamic multi-data table graph model to generate a final joint information graph model; And during information decoding, when generating the SQL query statement, it is mainly divided into two parts. First, decode the structure, and update the node feature representation in the joint information graph model through a graph-based search strategy; second, perform label prediction. For each generated node, predict its corresponding SQL keyword or table name, and select the label with a probability greater than the preset probability as the final prediction label of the node; Finally, RAG extracts data using the generated SQL query statements and analyzes it through a pre-trained large language model LLM to achieve the analysis of the network security situation.
6. The network security situation assessment system according to claim 5, characterized in that, When encoding information, the nodes of the tree structure are represented as syntactic components with different attributes, and the edges represent the syntactic and semantic relationships between the nodes; in the initial multi-data table graph model, the nodes are represented as individual data tables, and the edges represent the weight relationships between the data tables.
7. The network security situation assessment system according to claim 1, wherein The attack graph generation process includes: based on the MulVAL tool, collecting the topological structure, host services, network connections, and attacker information of the network where the system is located, detecting network vulnerabilities in combination with a vulnerability scanning tool, then configuring the obtained information into an input file in the format specified by MulVAL, and finally using the logical reasoning engine of MulVAL for reachability analysis and cost analysis reasoning to generate an attack graph.
8. The network security situation assessment system according to claim 1, wherein The network security situation report generation module gradually decomposes complex network situation analysis problems into several sub-problems based on the chain of thought to guide the large language model LLM, and performs reasoning in sequence according to the logical order to generate a comprehensive analysis result of the network security situation in the style of a network security expert.
9. The network security situation assessment system according to claim 8, characterized in that, While conducting a comprehensive analysis of the network security situation, the network security situation report generation module guides the large language model LLM through prompts to build a report template and perform content matching based on the analysis content of each part to generate the final network security situation assessment report.
10. A network security situation assessment method based on a large model, characterized in that, Using the network security situation assessment system according to any one of claims 1 to 9, the network security situation assessment method includes the following steps: S1: The network monitoring data collection module automatically collects and stores the operation index monitoring data of terminal devices and network devices in the entire network; S2: The network operation status analysis module accurately extracts the corresponding indicators in the network monitoring data according to the natural language query input by the user for analysis, and generates an analysis result of the current network operation situation; S3: The network potential risk detection module analyzes the potential threats and vulnerabilities of the overall network based on the attack graph, and gives the analysis results of network potential risks and vulnerabilities; The analysis results of the network operation status analysis module and the network potential risk detection module are input into the network security situation report generation module. Through the chain of thought prompt, the large language model LLM fuses the two analysis results of the network operation status analysis module and the network potential risk detection module to form an overall analysis result of the network security situation, and gives suggestions on defense measures accordingly, and automatically generates a report template and a network security situation assessment report.