AI agent calling method for safe operation

By setting intention categories and intention parameters for AI agents, combined with SuperFunc language, the contradiction between ease of use and accuracy of AI agents in network security operations is solved, providing an interactive method that takes into account convenience and functional expression capabilities, and improving the efficiency and accuracy of secure operations.

CN120386576APending Publication Date: 2025-07-29NAT COMP NETWORK & INFORMATION SECURITY MANAGEMENT CENT +1
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510305106.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-14
Publication Date
2025-07-29

AI Technical Summary

Technical Problem

There is a contradiction between ease of use and accuracy in existing AI agents in network security operations. Professional users tend to use complex API interfaces, while ordinary users use natural language input to easily lead to misjudgment.

Method used

The mixed use mechanism of formatted instructions and natural language instructions is adopted. By setting intent categories and intent parameters for each function of the AI agent, an intent dictionary is established, and instructions are parsed and executed using SuperFunc language, supporting mixed inputs of structured and natural languages.

Benefits of technology

It enables ordinary users to enter structured instructions directly in the text box, which is both convenient and accurately describes the security operation requirements, is both safe and scalable, and supports permission control and seamless integration with existing systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120386576A_ABST
    Figure CN120386576A_ABST
Patent Text Reader

Abstract

The invention discloses an AI agent calling method for safe operation. The AI agent calling method comprises the following steps: 1) setting a corresponding intention category for each function of an AI agent; modeling the execution interface parameter of each function into an intention parameter; 2) taking each intention category and the corresponding intention parameter as a dictionary item in an intention dictionary to obtain an intention dictionary; 3) establishing mapping between the intention parameter and the execution interface of the function, wherein the mapping is used for converting the semantics of each dictionary item into the semantics of the corresponding execution interface; 4) the AI agent receives an instruction input by a user, analyzes an intention category corresponding to the instruction, and queries the intention dictionary according to the intention category of the instruction to obtain a matched dictionary item; and 5) converting the semantics of the matched dictionary item into the semantics of the corresponding execution interface by the AI agent, matching and calling the corresponding execution interface to execute the instruction according to the semantics of the execution interface, and returning the operation result of the instruction to the user.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of artificial intelligence and relates to an AI agent calling method for network security operations. Background Art

[0002] With the rapid development of artificial intelligence technology, AI agents are increasingly widely used in network security operations. Such AI agents intelligently encapsulate a set of traditional security operation tools and, with the assistance of large language models, help users more conveniently match, orchestrate, and call security operation tools. Functionally, AI agents retain the capabilities of traditional security tools, form new capabilities generated by combining multiple tools, and are also strengthened and expanded to a certain extent with the support of large models, such as knowledge answering and text analysis capabilities.

[0003] To use an AI agent, a user must describe their intention so that the AI agent can translate the user's intention into its own functions and generate a correct response by executing the corresponding functions. Traditional security operation tools usually provide users with standardized API interfaces or command-line interfaces, and users express their intentions through the parameter items in the interfaces. An AI agent can be designed to provide a standardized API interface or choose to provide a non-standardized natural language interface. There is a contradiction between ease of use and accuracy in the usage methods of existing AI agents. For example, client developers tend to use complex API interfaces, which can accurately generate unambiguous instructions, but the process of describing the instructions requires professional knowledge and tools and is difficult for ordinary users to master; while ordinary users tend to use natural language input, which is very convenient, but the ambiguity of natural language limits the accurate expression ability of instructions and easily causes the AI agent to misjudge the user's intention. Therefore, there is an urgent need for an AI agent calling method that is both easy to use and has a powerful function expression ability. Summary of the Invention

[0004] Aiming at the problems existing in the prior art, the purpose of the present invention is to provide an instruction communication method for security operations, and the core is a mixed mechanism of formatted instructions and natural language instructions.

[0005] The technical solution of the present invention is as follows:

[0006] An AI agent calling method for security operations, the steps of which include:

[0007] 1) Set a corresponding intention category for each function of the AI agent; model the execution interface parameters of each function as an intention parameter;

[0008] 2) Take each intention category and its corresponding intention parameter as a dictionary item in an intention dictionary to obtain an intention dictionary;

[0009] 3) Establish a mapping between the intention parameter and the execution interface of the function, for converting the semantics of each dictionary entry into the semantics of the corresponding execution interface;

[0010] 4) The AI agent receives the instruction input by the user and parses the intention category corresponding to the instruction, then queries the intention dictionary according to the intention category of the instruction to obtain the matching dictionary entry;

[0011] 5) The AI agent converts the semantics of the matching dictionary entry into the semantics of the corresponding execution interface, then matches and invokes the corresponding execution interface according to the semantics of the execution interface to execute the instruction, and returns the operation result of the instruction to the user.

[0012] Furthermore, the intention parameter is a structured superfunc parameter, using @SuperFunc as the instruction identifier, and at least includes four fields: instruction name, version number, authorization code, and parameter data; among them, the instruction name contains intention category information; the parameter data contains the user's intention category and intention parameter.

[0013] Furthermore, the structured superfunc parameter contains a natural language prompt parameter sf_prompt, which is used to provide a mixing mechanism of formatted instructions and natural language instructions, facilitating the user to generate a superfunc instruction that conforms to the structured superfunc parameter according to the prompt to input information.

[0014] Furthermore, the AI agent detects whether the instruction input by the user contains @SuperFunc; if it contains, it enters the superfunc instruction parsing process; otherwise, it enters the natural language instruction processing process of the AI agent; during the superfunc instruction parsing process, if sf_prompt is recognized, the combined natural language instruction is generated by combining the instruction name and sf_prompt information; during the superfunc instruction parsing process, if sf_prompt is not recognized, the superfunc instruction semantics is converted into the execution interface semantics, and if the superfunc instruction semantics cannot be converted into the execution interface semantics, the superfunc instruction semantics is converted into a natural language instruction.

[0015] Furthermore, the superfunc instruction and the natural language instruction share the input control.

[0016] Furthermore, the instruction input by the user is an instruction described by the user using the structured superfunc parameter or an instruction described by natural language.

[0017] Furthermore, the range of the intention parameters corresponds exactly to the range of the execution interface parameters of the corresponding function; or the parameters in the intention parameters are the same as the parameters in the execution interface parameters of the corresponding function.

[0018] The present invention aims to provide an interaction method that takes into account both convenience and functional expression ability for AI agents in the field of network security, allowing users to input structured instructions in a text box, which can be easily understood and written by humans and quickly recognized and parsed by AI systems.

[0019] This method includes links such as intention definition, instruction description, and instruction parsing. The intention definition link occurs in the design stage of the AI agent, analyzing and summarizing the functions of the AI agent to establish an intention dictionary. The instruction description link occurs on the user side during the operation stage of the AI agent, referring to the user using methods such as APIs or natural language to describe their intentions, forming a call instruction for the AI agent. The instruction parsing link occurs on the service side during the operation stage of the AI agent, referring to the AI agent analyzing the user's call instruction, identifying the user's intention, and completing the mapping from the user's intention to the function of the AI agent in combination with the intention dictionary.

[0020] If the user uses the AI agent improperly, the user's intention may exceed the functional scope of the AI agent. After the instruction parsing link is completed, if the AI agent finds that the user's intention exceeds its own functional scope, it should not execute any predefined functions of the AI agent; otherwise, it should execute the function corresponding to the user's intention.

[0021] The specific function execution method is not the focus of this article. For all functions, the AI agent has corresponding function execution interfaces. These function execution interfaces are structured and come from the encapsulation of traditional tool APIs / command lines or are provided natively by the AI agent. The execution of specific functions is triggered by calling these interfaces. The function execution interfaces are called inside the AI agent and are not exposed to users; while the interface provided by the AI agent to users is called the superfunc interface in this article.

[0022] In this method, the AI agent has both the ability to understand natural language instructions and a certain structured API interface specification.

[0023] The work of the intention definition link includes intention category enumeration, intention parameter design, and function execution interface specification mapping. Specifically, when implemented, the work of the intention definition link is completed manually or gradually by a large model.

[0024] The output of the intent definition phase is an intent dictionary. The dictionary entries of the intent dictionary mainly involve intent category information and intent parameter information, with each entry corresponding to an intent category and its intent parameters. This method models the instruction intent as a combination of an intent category and intent parameters. For example, for an AI agent in the security operation category, threat intelligence query and vulnerability scanning are two different intent categories. For the intent category of threat intelligence query, the network elements to be queried, time range filtering conditions, etc. can be modeled as intent parameters.

[0025] In the intent definition phase, all the functions supported by the AI agent are enumerated and classified into different intent categories according to a certain strategy. Here, it is assumed that the AI agent has provided a set of function execution interfaces. The intent definition phase can simply create an intent category for each function execution interface; or it can consider other specific situations, where the intent categories do not strictly correspond one-to-one with the function execution interfaces, but only maintain a corresponding overall scope. For example, assume that the AI agent provides two function execution interfaces: threat intelligence query and vulnerability scanning. The intent definition phase can simply classify them into two intent categories, corresponding to these two function execution interfaces respectively; or it can further divide the threat intelligence query intent into "domain name threat intelligence" intent and "other threat intelligence query" intent; or it can merge the threat intelligence query and vulnerability scanning intents into one "threat intelligence query and vulnerability scanning" intent.

[0026] In the intent definition phase, based on the definition of intent categories, the instruction semantic space supported by the AI agent is divided and modeled as intent parameters according to a certain strategy. Here, it is assumed that the AI agent has provided interface parameter descriptions for each function execution interface. Therefore, for a specific intent category, first, the function execution interfaces corresponding to this intent category and their interface parameter descriptions need to be filtered out. Then, based on these interface parameter descriptions, intent parameters are designed. Each function execution interface parameter can be simply modeled as an intent parameter, or other specific situations can be considered, where the intent parameters do not strictly correspond one-to-one with the function execution interface parameters, but only maintain a corresponding overall scope. For example, assume that the function execution interface of vulnerability scanning provides three parameters: IP range, port range, and vulnerability range list. We can model this function as the intent category of "vulnerability scanning", and then create two intent parameters: "IP - port range description" and "vulnerability range description".

[0027] In the intent definition phase, an attempt should be made to establish a mapping between the structured superfunc parameter and the function execution interface, and convert the instruction semantics contained in superfunc into the semantics of the function execution interface.

[0028] This method includes an instruction description language, hereinafter referred to as superfunc.

[0029] The main features include:

[0030] - Using @SuperFunc as the instruction identifier - Adopting a JSON-like structure for easy recognition to distinguish it from natural language;

[0031] - Containing four main fields: instruction name, version number, authorization code, and parameter data;

[0032] - The instruction name contains intent category information;

[0033] - The parameter data adopts the standard JSON format and supports complex nested structures.

[0034] - The parameter data contains the user's intent category and intent parameters.

[0035] - superfunc can contain a special parameter representing a natural language prompt, which can be named sf_prompt in the embodiment. Temporarily call this parameter sf_prompt below. sf_prompt provides a mechanism for mixing formatted instructions and natural language instructions. When sf_prompt is enabled, the superfunc instruction can not contain other formatted intent parameters, and the intent semantics can be completely conveyed by sf_prompt. sf_prompt can also be used in combination with other formatted intent parameters to more accurately convey the intent semantics. When sf_prompt and other formatted intent parameters are used together but there is a semantic conflict, the AI agent judges the priority of the two semantics.

[0036] The instruction description process occurs on the user side of the AI agent. The calling instruction for the AI agent can be either natural language or a structured calling instruction. The user can describe their intent by writing an unstructured natural language prompt or writing structured interface call parameters to form a calling instruction for the AI agent.

[0037] In the instruction description process, the user can choose to use superfunc for instruction description, or choose to describe the instruction through pure natural language, or even achieve a mix of the two through the sf_prompt parameter.

[0038] The feature of the instruction description process is that the superfunc instruction and the natural language instruction share the input control. For example, the superfunc instruction itself can be converted into text and input into the text input box originally used for asking questions. In this way, there is no need to change the user interface of the AI agent.

[0039] The instruction parsing process occurs on the service side of the AI agent.

[0040] When the service side receives an instruction in text form sent by the user side, it uses a text parsing tool to detect whether it contains the special character @SuperFunc. If this character is included, it enters the superfunc instruction parsing process; otherwise, it enters the original natural language instruction processing process of the AI agent.

[0041] During the superfunc instruction parsing process, if sf_prompt is recognized, a combined natural language instruction is generated by combining the instruction name and the sf_prompt information. As a specific implementation example, the instruction name can be used as the prefix of the sf_prompt.

[0042] During the superfunc instruction parsing process, if there is no sf_prompt, it enters the structured instruction parsing. If the superfunc instruction semantics can be successfully converted into the semantics of the function execution interface, the problem is transformed into the execution of the function execution interface; if this semantic conversion cannot be successfully established, the superfunc instruction semantics are converted into natural language instructions, and the problem is transformed into the original natural language instruction processing process of the AI agent.

[0043] Compared with the prior art, the positive effects of the present invention are as follows:

[0044] · Ease of use: Ordinary users can directly enter structured instructions in the text box without the need for professional tools.

[0045] · Expressiveness: It supports complex parameter structures and can accurately describe various security operation requirements.

[0046] · Scalability: The version number field supports the continuous evolution of the language.

[0047] · Security: It has a built-in authorization code field for permission control.

[0048] · Compatibility: It can be seamlessly integrated with existing natural language processing systems. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] Figure 1 is the overall flowchart of the present invention.

[0050] Figure 2 is the flowchart of the user side.

[0051] Figure 3 is the flowchart of the service side. DETAILED DESCRIPTION OF THE INVENTION

[0052] The present invention will be further described in detail below with reference to the accompanying drawings. The examples given are only for explaining the present invention and are not intended to limit the scope of the present invention.

[0053] The core structure of the SuperFunc language is as follows:

[0054] @SuperFunc{

[0055] "name":"Instruction Name",

[0056] "version":"Format Version Number",

[0057] "auth":"Authorization Code",

[0058] "params":{

[0059] / / Parameter data in JSON format

[0060] }

[0061] }

[0062] The main features include:

[0063] - Use @SuperFunc as the instruction identifier - Adopt a JSON-like structure for easy parsing;

[0064] - Contain four main fields: instruction name, version number, authorization code, and parameter data;

[0065] - The parameter data is in standard JSON format and supports complex nested structures.

[0066] The following are several practical application examples of the SuperFunc language:

[0067] Example 1: Start threat intelligence query

[0068] @SuperFunc{

[0069] "name":"threat_intel_query",

[0070] "version":"1.0",

[0071] "auth":"abc123xyz",

[0072] "params":{

[0073] "domain":"example.com"

[0074] }

[0075] }

[0076] Example 2: Perform vulnerability scanning

[0077] @SuperFunc{

[0078] "name": "vulnerability_scan",

[0079] "version": "1.0",

[0080] "auth": "def456uvw",

[0081] "params": {

[0082] "ip_range": ["192.168.1.1", "192.168.1.255"],

[0083] "scan_type": "full"

[0084] }

[0085] }

[0086] The implementation of the SuperFunc language mainly includes the following steps:

[0087] a) Instruction recognition:

[0088] – The AI system detects whether the @SuperFunc identifier exists in the input text;

[0089] – If it exists, enter the structured instruction parsing process; otherwise, process it as ordinary natural language. b) Instruction parsing:

[0090] – Use a JSON parser to extract each field of the instruction;

[0091] – Verify whether the necessary fields (name, version, auth, params) exist.

[0092] c) Authorization verification:

[0093] – Check whether the authorization code in the auth field is valid.

[0094] d) Version compatibility check:

[0095] – Ensure that the system supports the instruction format of this version according to the version field.

[0096] e) Parameter processing:

[0097] – Parse the JSON data in the params field;

[0098] – Call the corresponding processing module according to the instruction name (name field).

[0099] f) Instruction execution:

[0100] – Perform corresponding security operations (such as threat intelligence query, vulnerability scanning, etc.).

[0101] g) Result return:

[0102] – Return the operation result to the user in an appropriate format.

[0103] The SuperFunc structured prompt language proposed by the present invention provides an innovative interaction method for AI agents in the field of network security. It not only retains the accuracy and powerfulness of structured instructions but also takes into account the usability for ordinary users. By this method, the efficiency and accuracy of security operations can be significantly improved, paving the way for the wide application of AI in the field of network security.

[0104] Although specific embodiments of the present invention are disclosed for illustrative purposes, which are intended to help understand the content of the present invention and implement it accordingly, those skilled in the art can understand that various substitutions, changes, and modifications are possible without departing from the spirit and scope of the present invention and the appended claims. Therefore, the present invention should not be limited to the content disclosed in the best embodiments, and the scope of protection required by the present invention shall be defined by the scope defined in the claims.

Claims

1. An AI agent invocation method for secure operation, the steps of which include: 1) Set a corresponding intent category for each function of the AI agent; Model the execution interface parameters of each function as an intent parameter; 2) Take each intent category and its corresponding intent parameter as an item in an intent dictionary to obtain an intent dictionary; 3) Establish a mapping between the intent parameter and the execution interface of the function for converting the semantics of each item into the semantics of the corresponding execution interface; 4) The AI agent receives an instruction input by the user and parses the intent category corresponding to the instruction, then queries the intent dictionary according to the intent category of the instruction to obtain a matching item; 5) The AI agent converts the semantics of the matching item into the semantics of the corresponding execution interface, then invokes the corresponding execution interface to execute the instruction according to the semantics of the execution interface, and returns the operation result of the instruction to the user.

2. The method according to claim 1, wherein The intent parameter is a structured superfunc parameter, using @SuperFunc as the instruction identifier, and at least including four fields: instruction name, version number, authorization code, and parameter data; Among them, the instruction name contains intent category information; the parameter data contains the user's intent category and intent parameter.

3. The method according to claim 2, wherein The structured superfunc parameter contains a natural language prompt parameter sf_prompt, which is used to provide a mechanism for mixing formatted instructions and natural language instructions, facilitating the user to generate superfunc instructions that conform to the structured superfunc parameter according to the prompt to input information.

4. The method according to claim 3, wherein The AI agent detects whether the instruction input by the user contains @SuperFunc; if it contains, it enters the superfunc instruction parsing process; otherwise, it enters the natural language instruction processing process of the AI agent; in the superfunc instruction parsing process, if sf_prompt is recognized, a fused natural language instruction is generated by combining the instruction name and sf_prompt information; in the superfunc instruction parsing process, if sf_prompt is not recognized, the superfunc instruction semantics is converted into the semantics of the execution interface. If the superfunc instruction semantics cannot be converted into the semantics of the execution interface, the superfunc instruction semantics is converted into a natural language instruction.

5. The method according to claim 2, characterized in that, The superfunc instruction and the natural language instruction share an input control.

6. The method according to claim 2, wherein The instruction input by the user is an instruction described by the user using a structured superfunc parameter or an instruction described by natural language.

7. The method according to claim 1, wherein The range of the intent parameter corresponds to the range of the execution interface parameters of the corresponding function; or the parameters in the intent parameter are the same as the parameters in the execution interface parameters of the corresponding function.

Citation Information

Cited By

  • Replay content confirmation method and device, storage medium and program product

    CN122240818A