Network security situation awareness method and system based on large model and threat assessment
Through the network security situation awareness method based on large models and threat assessment, the problems of traditional methods in perception granularity, rule maintenance cost and difficulty in multi-source data fusion are solved, dynamic identification and response to complex attacks are achieved, and the perception accuracy and adaptability of network security are improved.
Patent Information
- Application Number
- CN202511107190.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-08
- Publication Date
- 2025-09-05
- Estimated Expiration
- 2045-08-08
AI Technical Summary
Traditional network security protection methods have shortcomings in perception granularity, rule maintenance costs and multi-source data fusion. They find it difficult to identify advanced persistent threats and multi-stage penetration attacks, and are unable to dynamically adapt to emerging attack situations in real time.
A network security situational awareness method based on large models and threat assessment is adopted. By fine-tuning the situational awareness large model and threat assessment algorithm, combining multi-source data for situational reasoning and evaluation, and using LoRA parameters to efficiently fine-tune the large language model, dynamic identification and response to complex attacks can be achieved.
It significantly improves the ability to detect and respond to complex attacks, increases perception granularity and accuracy, dynamically adapts to emerging attack situations, reduces rule maintenance costs, and builds a reliable and efficient situational awareness system.
Smart Images

Figure CN120602240A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security intelligent technology, in particular to a test training system, and relates to a network security situation awareness method and system based on a large model and threat assessment. Background Art
[0002] With the rapid evolution of experimental training towards digitalization and intelligence, the means of network attacks faced by its information and communication networks are becoming increasingly diverse and complex.
[0003] Traditional network security protection methods rely primarily on signature-based intrusion detection systems (IDS), security event management (SIEM), and rule engines. These often suffer from the following issues: (1) Limited perception granularity: It can only generate alerts for known threats or abnormal behaviors, and has difficulty identifying advanced persistent threats (APTs) and multi-stage penetration attacks; (2) High rule maintenance cost: It relies on manual definition and updating of the rule base and cannot dynamically adapt to emerging attack situations in real time; (3) Difficulty in fusing multi-source data: Currently, the test and training system contains multimodal information such as real-time measurement and control data, log data, topology information, and external threat intelligence. Traditional methods are insufficient in the correlation analysis and semantic understanding of heterogeneous data. Summary of the Invention
[0004] In response to the above-mentioned problems, the present invention provides a network security situation awareness method and system based on large models and threat assessment, which is used to solve the problems of limited perception granularity, high rule maintenance cost and difficulty in multi-source data fusion in current network security protection methods.
[0005] In a first aspect, the present invention provides a network security situation awareness method based on a large model and threat assessment, the method comprising: Collect current network security situational environment data, input it into the fine-tuned situational awareness model for analysis and judgment, and obtain situational reasoning results; Extract threat assessment parameters from the situation environment data to obtain a situation assessment result; The situation reasoning result and the situation assessment result are compared for consistency, and the situation awareness result of the current network security is output.
[0006] Furthermore, the situational environment data includes but is not limited to network traffic logs, access behavior, security alarm events, asset topology information, and threat intelligence.
[0007] Furthermore, the consistency comparison includes: If the situation reasoning result is consistent with the situation assessment result, the current network security situation awareness result is directly output; Otherwise, the system will enter a cyclic correction process, and automatically adjust the threat assessment parameters or re-evaluate according to the feedback within the set maximum number of cycles until the two results are consistent. If the two results are always inconsistent within the set maximum number of cycles, the current result will be output and prompted for manual review.
[0008] Furthermore, the establishment of the fine-tuning situational awareness large model includes: Collect multiple sets of historical network security situational environment data for preprocessing and generate fine-tuning sample data sets; Based on the LoRA parameter efficient fine-tuning method, the large language model is used as the basic model, and the basic model is trained using the fine-tuning sample data set to obtain the fine-tuning situation awareness large model.
[0009] Furthermore, the method for generating the fine-tuning sample dataset includes: using one or more methods of a rule template generation method, a large language model generation method, and a manual intervention generation method to generate a fine-tuning sample dataset with semantic consistency and attack diversity.
[0010] Furthermore, the rule template generation method is as follows: combining the threat intelligence knowledge base with the experimental training business semantics to preset a structured extraction template; automatically parsing the original log through regular rules and context matching strategies to extract structured samples, and assigning labels to the situation environment data based on the structured samples; The large language model generation method comprises: based on the structured sample, using the pre-trained language model to guide the generation of situation awareness corpus samples, and assigning labels to situation environment data according to the situation awareness corpus samples; The manual intervention generation method is to review and correct the sample labels obtained by the rule template generation method and the large language model generation method.
[0011] Furthermore, the threat assessment parameters include threat value, vulnerability value, asset value and defense strength.
[0012] Furthermore, obtaining the situation reasoning result includes: Calculating a threat assessment value based on the threat assessment parameters; Output the situation reasoning result according to the threat assessment value and the set assessment level.
[0013] Furthermore, the threat assessment value The calculation formula is: ;or, ; in, Indicates the threat value, which is used to describe the threat posed by the attacker to the target, ranging from 0 to 100. The higher the value, the stronger the attacker's ability or the clearer the attack intention; Indicates the vulnerability value, which is used to describe the possibility of the target being attacked, ranging from 0 to 100. The higher it is, the easier it is to attack the target; Indicates asset value, used to describe the importance of the target, ranging from 0 to 100. The higher it is, the more important the goal is; Indicates the defense strength, which is used to describe the effectiveness of existing defense measures, ranging from 0 to 100. The higher the value, the stronger the defense. The lower.
[0014] In a second aspect, the present invention provides a network security situation awareness system based on a large model and threat assessment, comprising a memory, a processor, and a computer program stored on the memory, wherein the processor executes the computer program to implement the steps of any of the above methods.
[0015] In general, the present invention provides a network security situation awareness method and system based on a large model and threat assessment. The technical solution conceived by the present invention can achieve the following beneficial effects compared with the existing technology: (1) The present invention constructs a network security situation awareness method and system for experimental training systems. On the one hand, by combining the deep semantic understanding ability of the large model with the refined threat assessment algorithm, the fine-tuning large model and dynamic threat assessment are introduced, which can dynamically adapt to emerging attack situations, significantly improve the detection and response capabilities of complex and variable attacks, and provide a strong guarantee for the safe and stable operation of the experimental training system; on the other hand, the situation reasoning results and situation assessment results are obtained respectively through dual-channel parallel operation, and the two are compared for consistency. The online feedback mechanism and actual detection results are used to continuously optimize and update the large model to ensure that it can adapt to emerging attack methods in a timely manner and dynamically identify various threat events, avoiding the manual definition and update of the rule base. It not only has good robustness and controllability, but also greatly improves the perception granularity, the accuracy and timeliness of network situation awareness; it provides key support for building a reliable and efficient situation awareness system for experimental training.
[0016] (2) The present invention fine-tunes the large situational awareness model specifically for the test and training field, enabling it to have a deep semantic understanding of network behaviors and security events unique to the test and training system, thereby improving the recognition accuracy of complex attack patterns and thus greatly improving the perception granularity.
[0017] (3) The present invention introduces a threat assessment calculation method based on multi-source data fusion, which can quantify the risk level of security events in real time, thereby outputting a more accurate situation threat level based on the fine-grained environmental data, realizing dynamic assessment and priority sorting of potential threats, and improving the accuracy of network situation awareness when performing consistency comparison. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0019] Figure 1 This is a schematic diagram of the method steps of a network security situation awareness system based on a large model and threat assessment provided by the present invention; Figure 2 This is a schematic diagram of the method principle of a network security situation awareness system based on a large model and threat assessment provided by the present invention; Figure 3 This is a schematic diagram of generating a fine-tuning sample data set for a network security situation awareness system based on a large model and threat assessment provided by the present invention. DETAILED DESCRIPTION
[0020] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings and embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.
[0021] It should be noted that, in the description of the embodiments of the present invention, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a method, step, or apparatus comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such method, step, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the method, step, or apparatus comprising the element.
[0022] In order to strengthen the security network situation awareness technology for test and training systems, the problems of limited perception granularity, high rule maintenance cost and difficulty in multi-source data fusion in current network security protection methods are solved.
[0023] The present invention provides a network security situation awareness method and system based on a large model and threat assessment. By collecting, processing and constructing a situation awareness fine-tuning sample data set, a fine-tuning situation awareness large model that meets the business needs of the actual test training network environment is fine-tuned based on the LoRA framework; the situation environment data is input into the fine-tuning situation awareness large model for analysis and judgment to obtain a situation reasoning result; the input situation environment data is further analyzed by a threat assessment algorithm to obtain a situation assessment result; finally, the results output by the fine-tuning situation awareness large model and the results output by the threat assessment algorithm are compared and analyzed to construct a standardized, intelligent and automated situation analysis engine, which dynamically outputs a highly granular and accurate situation awareness result.
[0024] First, as Figure 1 and Figure 2 As shown, the method specifically includes: Step 101: Collect the current network security situation environment data, input it into the fine-tuning situation awareness model for analysis and judgment, and obtain the situation reasoning result.
[0025] It should be noted that situational environment data is raw data collected from multiple heterogeneous data sources within the test and training system, including but not limited to network traffic logs, access behavior, security alerts, asset topology information, threat intelligence, and other key network situational environment data. This data is high-dimensional, unstructured, and multimodal.
[0026] To enhance the large-scale model's ability to identify, correlate, and reason about threat events in complex and ever-changing network environments, and to achieve accurate situational awareness and intelligent decision-making support, this paper constructs a situational awareness fine-tuning sample dataset for network security scenarios in experimental training systems. Based on this sample dataset, the large-scale model is fine-tuned to obtain a fine-tuned situational awareness large-scale model.
[0027] As an embodiment of the present invention, fine-tuning the establishment of a large situational awareness model includes: Step 201: Collect multiple sets of historical network security situation environment data, perform preprocessing, and generate a fine-tuning sample data set.
[0028] It should be noted that historical network security situational environment data is also raw data collected from multiple heterogeneous data sources in historical test and training systems. It includes but is not limited to network traffic logs, access behavior, security alerts, asset topology information, threat intelligence, and other key network situational environment data. This data constitutes the basic raw material for subsequent training corpus and is characterized by high dimensionality, unstructuredness, and multimodality.
[0029] The input situational environment data is first preprocessed to complete preprocessing operations such as format unification, noise filtering, data normalization and context construction to ensure the stability and accuracy of subsequent model and algorithm processing.
[0030] In order to achieve accurate situational awareness for network security scenarios of experimental training systems, the present invention proposes a sample data set generation method based on multi-source heterogeneous data fusion, multi-strategy driven data enhancement and semantic annotation strategies. As an example, Figure 3 As shown, the fine-tuning sample dataset is generated using one or more of the following methods: rule template generation, large language model generation, and manual intervention generation. This fine-tuning sample dataset can be a combined set of data generated using these three methods, or it can be generated using the rule template generation method, large language model generation method, and manual intervention generation method in three stages. This ensures that the resulting sample dataset is high quality, highly adaptable, and highly generalizable.
[0031] The rule template generation method is based on template generation of specific rules, and performs structured restoration of typical attack paths, security incidents and response processes.
[0032] Specifically, the rule template generation method is as follows: combining the threat intelligence knowledge base with the business semantics of experimental training, presetting a structured extraction template; automatically parsing the original log through regular rules and context matching strategies, extracting structured samples, and assigning labels to the situation environment data based on the structured samples.
[0033] For example, first, common situational data in the experimental training network environment is obtained, such as lateral penetration, slow scanning, and privilege escalation. Next, a structured extraction template is pre-set, combining the threat intelligence knowledge base with the actual business semantics of the experimental training to design a unified annotation template format, including one or more fields such as event category, event time, attack path, attack behavior, threat level, trigger condition, response action, and target asset. Regular rules and context matching strategies are then used to automatically parse the original log and extract structured samples. For example, taking the log entry "On October 14, 2024, the core substation boundary firewall suffered continuous and high-frequency access from external IP addresses," fields such as event time, target asset, and attack behavior can be automatically extracted, and the event can be classified as a "suspected DDoS detection" event. Finally, the event is given an initial label: "Medium-level threat."
[0034] The large language model generation method combines the large language model for AI generation, and generates high-quality situation descriptions and threat judgment instructions by constructing multi-round contextual dialogue scenarios.
[0035] Specifically, the large language model generation method involves using a pre-trained language model to guide the generation of situational awareness corpus samples based on structured samples, and then assigning labels to the situational environment data based on the situational awareness corpus samples. The pre-trained language model can be a guided large language model such as ChatGLM or Qwen.
[0036] For example, using a structured sample formatted as "event triples + attack context + response mechanism" and a prompt such as "An abnormal remote login occurred in a large power generation control center, and the account logged in with the default password," the large model can generate a corresponding situational narrative: "The system detected high-risk remote access behavior and determined it to be an exploit of a weak password vulnerability. It is recommended to immediately block the account and strengthen the identity authentication mechanism." This large language model generation method effectively expands the long-tail event corpus and improves the semantic richness and scenario coverage of the fine-tuning data.
[0037] The manual intervention generation method is aimed at boundary scenarios or high-risk attack chains, relying on the experience of security experts to construct samples of real and complex reasoning instructions.
[0038] Specifically, the manual intervention generation method is to review and correct the sample labels obtained by the rule template generation method and the large language model generation method.
[0039] In other words, in order to address the problems of semantic ambiguity, label errors, etc. in the sample label generation process of the rule template generation method and the large language model generation method, the present invention also introduces a "human-machine collaborative verification mechanism". Security experts can quickly review and optimize labels based on the system-recommended samples. At the same time, the current network security system records modification behaviors for training future automatic labeling, thereby generating an automatic review large model to review and correct sample labels with semantic ambiguity and label errors.
[0040] For example, if the generated sample "An attacker exploited the default port for remote brute force, but the system indicated normal access, indicating a low risk level" was judged by experts to be "high," the large model deviation was corrected. This manual intervention generation method significantly improved the quality of the dataset and formed a closed-loop optimization mechanism.
[0041] In order to ensure the semantic accuracy and logical validity of the generated sample data, the present invention also proposes a data accuracy verification mechanism, which combines the preliminary judgment of the large model with the manual verification mechanism. That is, after each sample data is obtained, it is reviewed and verified using the manual intervention generation method to evaluate the rationality of the data, and sample data with contradictions or defects are eliminated or corrected, thereby significantly improving the quality of the fine-tuning sample data set.
[0042] The sample data generated by the rule template generation method, the large language model generation method, and the manual intervention generation method were unified and fused to construct a fine-tuning sample dataset with semantic consistency and attack diversity. Furthermore, based on the structural stability of the samples generated by the rule template generation method, the semantic diversity of the samples generated by the large language model generation method, and the accuracy of the methods generated by the manual intervention generation method, the three methods complement each other to construct a situational awareness fine-tuning sample dataset that is highly consistent with the test training security context. This provides solid support for the LoRA fine-tuning of the situational awareness large model and significantly improves the large model's ability to understand and judge complex situational environments.
[0043] Step 202: Based on the LoRA parameter efficient fine-tuning method, the large language model is used as the basic model, and the basic model is trained using the fine-tuning sample data set to obtain a fine-tuned situation awareness large model.
[0044] This paper, based on the efficient parameter fine-tuning technology LoRA (Low-Rank Adaptation), selects mainstream large language models such as ChatGLM, Qwen, and Baichuan as the base model, and uses the generated fine-tuning sample dataset to fine-tune the base model's instructions. Compared to full parameter fine-tuning, this paper utilizes LoRA technology to significantly reduce training costs while maintaining the original model's reasoning capabilities. Its modular plug-and-play capability also facilitates flexible deployment in different scenarios in the future.
[0045] The fine-tuned situational awareness model, derived from previous fine-tuning, combines historically acquired fine-tuned sample datasets with the current context to analyze and determine evolving trends in network security, outputting inference results in structured JSON format. This inference path offers significant advantages, including strong contextual modeling capabilities, deep semantic understanding, and high adaptability to new attacks.
[0046] The fine-tuned situational awareness large model constructed by the present invention not only greatly improves the understanding ability and task generalization ability of the fine-tuned situational awareness large model in the context of experimental training security, but also realizes instruction-driven situational awareness task modeling in the field of experimental training network security for the first time, providing a high-quality semantic foundation and knowledge expression ability for subsequent threat assessment and system reasoning. It has significant advantages in innovation and adaptability, and is the basic core link for building an intelligent and automated situational awareness system.
[0047] As an example, situational context data is first received from perimeter network security devices, including network traffic logs, access behavior, security alerts, and threat intelligence. This data is then fed into a fine-tuned situational awareness model and subjected to standardized preprocessing. Based on the embedded historical situational knowledge and semantic understanding of the current context, the fine-tuned situational awareness model automatically infers the current network security threat landscape. For example, "The core control host has abnormal external connection behavior, which may be a C2 communication attempt." This output is returned in a structured JSON format with a confidence score and interpretable labels, providing the current network security situation inference results based on the fine-tuned situational awareness model.
[0048] Step 102: extract threat assessment parameters from the situation environment data to obtain a situation assessment result.
[0049] It should be noted that the method for extracting threat assessment parameters from situation environment data may be: extracting key elements from the situation environment data, and then obtaining threat assessment parameters based on the key elements.
[0050] Key elements can be extracted directly from situational environment data, or by inputting situational environment data into a fine-tuned situational awareness model. Key elements include attack type, attack path, target importance, threat source characteristics, and protection status.
[0051] Attack type: such as DDoS attack, SQL injection, malicious code propagation, etc.
[0052] Attack Path: Used to evaluate possible attacker paths, determine path complexity, and the possibility of bypassing existing protection measures. Target importance: also known as asset value, targets are scored based on business impact and asset value.
[0053] Threat source characteristics: attacker capabilities, tools, intentions, and resources, which can be obtained from threat intelligence.
[0054] Protection status: coverage of existing protection measures, protection strength, and response capabilities of protective equipment.
[0055] Based on the key factors, threat assessment parameters can be derived. The training parameter extraction model can be trained by using the key factors and threat assessment parameters as training samples. The parameter extraction model takes the key factors as input and outputs the threat assessment parameters, or risk factors, as specific numerical values.
[0056] Among them, threat assessment parameters include Threat Value (TV), Vulnerability Score (VS), Asset Value (AV) and Defense Strength (DS).
[0057] As an embodiment, obtaining the situation reasoning result includes: calculating based on the threat assessment parameters to obtain a threat assessment value; and outputting the situation reasoning result according to the threat assessment value and a set assessment level.
[0058] Furthermore, the threat assessment value The calculation formula can be: ;or, ; When using Calculated satisfy When directly output On the contrary, if you are not satisfied When , use the calculation formula Recalculate In other words, no matter which formula is used, the threat assessment value needs to be normalized to within 100, so that the situation assessment result is between 0 and 100, and the higher the value, the higher the threat.
[0059] Preferably, the threat assessment value of the present invention is calculated as follows: ; in, Indicates the threat value, which is used to describe the threat posed by the attacker to the target, ranging from 0 to 100. The higher the value, the stronger the attacker's ability or the clearer the attack intention; Indicates the vulnerability value, which is used to describe the possibility of the target being attacked, ranging from 0 to 100. The higher it is, the easier it is to attack the target; Indicates asset value, used to describe the importance of the target, ranging from 0 to 100. The higher it is, the more important the goal is; Indicates the defense strength, which is used to describe the effectiveness of existing defense measures, ranging from 0 to 100. The higher the value, the stronger the defense. The lower.
[0060] The set assessment level can be evenly divided according to the range of threat assessment values to obtain multiple assessment levels; for example, the assessment level is divided into four levels: when the threat assessment value is 0-25, it is marked as low threat; when the threat assessment value is 26-50, it is marked as medium threat; when the threat assessment value is 51-75, it is marked as high threat; when the threat assessment value is 76-100, it is marked as severe threat.
[0061] The evaluation path proposed in this invention is parallel to the reasoning path and is used to extract key risk factors from situational environment data, such as attack type, target importance, vulnerability, current defense capability, etc., and call the threat scoring function for quantitative evaluation, and then calculate the threat level in the current environment to provide quantitative support for the judgment results.
[0062] For example, a database server in a test and training system is a key defense target. Recently, a SQL injection attack alert was received against the server, and the system needs to assess the threat level. The input situational environment data includes the attack type, target importance, vulnerability value, and defense strength.
[0063] The attack type (SQL injection) is highly efficient and covert, with a Threat Value (TV) of 85. The target importance (database server), as the database stores sensitive user data and core business information, is assessed at an Asset Value (AV) of 90. Because the vulnerability scanner detected a high-risk SQL injection vulnerability in the target, the Vulnerability Value (VS) is assessed at 80. The existing WAF (Web Application Firewall) partially covers SQL injection, but does not enable strict checking for all requests. Therefore, the Defense Strength (DS) is assessed at 70.
[0064] Therefore, the threat assessment value However, since the original formula may lead to excessive values, it is necessary to reset reasonable weights and perform deformation and normalization processing. calculate The correction can simplify the scoring and ensure normalization, so that the range of threat assessment values is within a reasonable range.
[0065] The comprehensive calculation based on the normalized weight is: ; Therefore, the threat assessment value , marked as a low threat level.
[0066] On the basis of fine-tuning the preliminary reasoning of the situational awareness model, the threat assessment calculation formula is called at the same time. The key risk factors in the situational reasoning results are automatically extracted and the threat assessment values are calculated. Perform quantitative calculations.
[0067] For example, for the identified "weak password remote login event", the automatically extracted threat assessment parameters are: 、 、 、 ; The threat assessment value is calculated: , marked as "Low Threat Level." This assessment path achieves seamless linkage from semantic situational awareness to quantitative risk assessment, ensuring that the perception results are business-relevant.
[0068] Step 103: Perform consistency comparison between the situation reasoning result and the situation assessment result, and output the situation awareness result of the current network security.
[0069] That is, through dual channels (inference channel + evaluation channel), the situation reasoning results and situation assessment results are obtained in parallel, and the two are compared for consistency. The online feedback mechanism and actual detection results are used to continuously optimize and update the large model to ensure that it can adapt to emerging attack methods in a timely manner and dynamically identify various threat events.
[0070] Furthermore, to ensure the stability of situational reasoning results and the accuracy of situational assessments, this invention incorporates a "situational result comparison and verification" mechanism, which compares the situational reasoning results with the situational assessment results for consistency. If the two conclusions disagree, the system determines whether to output the results or request manual review based on the number of cycles and a verification threshold, thus ensuring the coexistence of system intelligence and robustness.
[0071] More specifically, as an embodiment, the consistency comparison includes: If the situation reasoning result is consistent with the situation assessment result, the current network security situation awareness result is directly output; Otherwise, the system will enter a cyclic correction process, and automatically adjust the threat assessment parameters or re-evaluate according to the feedback within the set maximum number of cycles until the two results are consistent. If the two results are always inconsistent within the set maximum number of cycles, the current result will be output and prompted for manual review.
[0072] By integrating, comparing and fine-tuning the semantic reasoning capabilities of the large situational awareness model and the intelligent situational awareness capabilities of the threat assessment quantification mechanism, a closed-loop intelligent analysis process from data input, model reasoning, threat calculation to output results is achieved. At the same time, the network situation environment data of a certain experimental training system can be used as input, and the system can be run by simulating actual scenarios to verify its intelligent analysis and accurate judgment capabilities.
[0073] For example, if the fine-tuned situational awareness model outputs a "high threat" situational reasoning result for current cybersecurity situational environment data, while the situational assessment result is "low threat," a reassessment will be conducted up to three times, or a "manual review required" label will be output. This "situational result comparison and verification" mechanism demonstrates robustness and controllability, providing critical support for building a reliable and efficient situational awareness intelligent system for experimental training.
[0074] It should be noted that the present invention introduces two complementary processing paths in parallel: The first is the inference path: Based on a fine-tuned large-scale situational awareness model, it uses historical data and current context to analyze and judge situational evolution trends, and outputs the situational inference results in structured JSON format. This path offers significant advantages, including strong contextual modeling capabilities, deep semantic understanding, and high adaptability to new attacks.
[0075] The second is the evaluation path: extract key risk factors from the situation environment data, and call the threat assessment value calculation formula for quantitative evaluation, calculate the threat level of the current network security environment, and obtain the situation assessment results.
[0076] After obtaining the situational reasoning and assessment results, the system enters the "situational result comparison and verification" mechanism, performing cross-validation through consistency comparison. If the judgment results are consistent, the situational awareness results are directly output. If they are inconsistent, a cyclic correction process is entered, automatically adjusting the threat assessment parameters or reassessing based on feedback within the set maximum number of cycles until the two results are consistent. If the results remain inconsistent within the set maximum number of cycles, the current result is output and prompted for manual review to ensure the interpretability and accuracy of the results. This method provides a highly intelligent and robust security situational awareness solution for test and training systems, with extremely high practical value and technological promotion prospects.
[0077] In a second aspect, the present invention also provides a network security situational awareness system based on a large model and threat assessment, comprising a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the steps of any of the aforementioned methods. The system employs a modular design to enhance its intelligent decision-making capabilities, adaptability, and continuous evolution capabilities. The technical features of the system and the method are consistent and will not be further elaborated here.
[0078] In summary, the present invention constructs a network security situation awareness method and system for experimental training systems. On the one hand, by combining the deep semantic understanding ability of the large model with the refined threat assessment algorithm, the fine-tuning large model and dynamic threat assessment are introduced, which can dynamically adapt to emerging attack situations, significantly improve the detection and response capabilities of complex and changeable attacks, and provide a strong guarantee for the safe and stable operation of the experimental training system; on the other hand, through dual-channel parallel operation, the situation reasoning results and situation assessment results are obtained respectively, and the two are compared for consistency. The online feedback mechanism and actual detection results are used to continuously optimize and update the large model to ensure that it can adapt to emerging attack methods in a timely manner, dynamically identify various threat events, and avoid manually defining and updating the rule base. It not only has good robustness and controllability, but also greatly improves the perception granularity, the accuracy and timeliness of network situation awareness; it provides key support for building a reliable and efficient situation awareness system for experimental training.
[0079] It should be noted that for the aforementioned embodiments, for simplicity of description, they are all expressed as a series of action combinations, but those skilled in the art should be aware that this application is not limited by the order of the actions described, because according to this application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all preferred embodiments, and the actions and modules involved are not necessarily required by this application.
[0080] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0081] In the several embodiments provided in this application, it should be understood that the disclosed methods or systems can be implemented in other ways. For example, the embodiments described above are merely illustrative, and the division of the units described is merely a logical functional division. In actual implementation, other division methods may be used, such as combining or integrating multiple units or components into another system, or ignoring or not implementing certain features.
[0082] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0083] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0084] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of this application, or the part that contributes to the existing technology, or all or part of the technical solution can be embodied in the form of a software product. This computer software product is stored in a memory and includes a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of this application.
[0085] Those skilled in the art will appreciate that all or part of the various circuits in the above embodiments may be implemented by instructing related hardware through a program. The program may be stored in a computer-readable memory, which may include a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0086] The above is only an exemplary embodiment of the present disclosure and cannot be used to limit the scope of the present disclosure. That is, any equivalent changes and modifications made according to the teachings of the present disclosure are still within the scope of the present disclosure. After considering the specification and practicing the disclosure herein, those skilled in the art will easily think of the implementation scheme of the present disclosure. This application is intended to cover any variation, use or adaptation of the present disclosure, which follows the general principles of the present disclosure and includes common knowledge or customary technical means in the art that are not recorded in the present disclosure. The description and examples are to be regarded as exemplary only, and the scope and spirit of the present disclosure are defined by the claims.
[0087] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0088] It will be easily understood by those skilled in the art that the above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A network security situation awareness method based on a large model and threat assessment, characterized in that: The method comprises: Collect current network security situational environment data, input it into the fine-tuned situational awareness model for analysis and judgment, and obtain situational reasoning results; Extract threat assessment parameters from the situation environment data to obtain a situation assessment result; The situation reasoning result and the situation assessment result are compared for consistency, and the situation awareness result of the current network security is output.
2. A network security situation awareness method based on a large model and threat assessment according to claim 1, characterized in that: The situational environment data includes but is not limited to network traffic logs, access behaviors, security alarm events, asset topology information, and threat intelligence.
3. A network security situation awareness method based on a large model and threat assessment according to claim 1, characterized in that: The consistency comparison includes: If the situation reasoning result is consistent with the situation assessment result, the current network security situation awareness result is directly output; Otherwise, the system will enter a cyclic correction process, and automatically adjust the threat assessment parameters or re-evaluate according to the feedback within the set maximum number of cycles until the two results are consistent. If the two results are always inconsistent within the set maximum number of cycles, the current result will be output and prompted for manual review.
4. A network security situation awareness method based on a large model and threat assessment according to claim 1, characterized in that: The establishment of the fine-tuning situational awareness model includes: Collect multiple sets of historical network security situational environment data for preprocessing and generate fine-tuning sample data sets; Based on the LoRA parameter efficient fine-tuning method, the large language model is used as the basic model, and the basic model is trained using the fine-tuning sample data set to obtain the fine-tuning situation awareness large model.
5. A network security situation awareness method based on a large model and threat assessment according to claim 4, characterized in that: The method for generating the fine-tuning sample data set includes: using one or more methods of a rule template generation method, a large language model generation method, and a manual intervention generation method to generate a fine-tuning sample data set with semantic consistency and attack diversity.
6. A network security situation awareness method based on a large model and threat assessment according to claim 5, characterized in that: The rule template generation method is as follows: combining the threat intelligence knowledge base with the business semantics of experimental training to preset a structured extraction template; automatically parsing the original log through regular rules and context matching strategies to extract structured samples, and assigning labels to the situation environment data based on the structured samples; The large language model generation method comprises: based on the structured sample, using the pre-trained language model to guide the generation of situation awareness corpus samples, and assigning labels to situation environment data according to the situation awareness corpus samples; The manual intervention generation method is to review and correct the sample labels obtained by the rule template generation method and the large language model generation method.
7. The network security situation awareness method based on large model and threat assessment according to claim 1 is characterized in that: The threat assessment parameters include threat value, vulnerability value, asset value and defense strength.
8. The network security situation awareness method based on a large model and threat assessment according to claim 7, wherein obtaining the situation reasoning result comprises: Calculating a threat assessment value based on the threat assessment parameters; Output the situation reasoning result according to the threat assessment value and the set assessment level.
9. A network security situation awareness method based on a large model and threat assessment according to claim 8, wherein the threat assessment value The calculation formula is: ;or, ; in, Indicates the threat value, which is used to describe the threat posed by the attacker to the target, ranging from 0 to 100. The higher the value, the stronger the attacker's ability or the clearer the attack intention; Indicates the vulnerability value, which is used to describe the possibility of the target being attacked, ranging from 0 to 100. The higher it is, the easier it is to attack the target; Indicates asset value, used to describe the importance of the target, ranging from 0 to 100. The higher it is, the more important the goal is; Indicates the defense strength, which is used to describe the effectiveness of existing defense measures, ranging from 0 to 100. The higher the value, the stronger the defense. The lower.
10. A network security situation awareness system based on a large model and threat assessment, comprising a memory, a processor, and a computer program stored in the memory, characterized in that: The processor executes the computer program to implement the steps of the method according to any one of claims 1 to 9.
Citation Information
Patent Citations
Network security situation sensing system and method based on multi-layer multi-angle analysis
CN101459537A
Network security situation awareness system based on big data
CN108696515A
SAA-SSA-BPNN-based network security situation assessment method
CN116846565A
Multi-source data fusion network security situation awareness method and device
CN117240541A
Adversarial data detection method and device, equipment and storage medium
CN119623571A
Cited By
Network security situation awareness method and application
CN120880781A
Network security situation real-time early warning system
CN120880813A
Sandbox basic behavior point score dynamic iterative optimization method and system
CN122069066A