Cybersecurity situation awareness method and system based on large model and threat assessment
Through a network security situational awareness method based on large models and threat assessment, combined with fine-tuning of the situational awareness large model and threat assessment algorithm, the problems of limited perception granularity, high rule maintenance cost and difficulty in multi-source data fusion in existing technologies are solved, and efficient identification and dynamic adaptation of complex attacks are achieved, thereby improving the situational awareness capability of network security.
Patent Information
- Application Number
- CN202511107190.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-08
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2045-08-08
AI Technical Summary
Existing network security protection methods have shortcomings in perception granularity, rule maintenance costs and multi-source data fusion. They find it difficult to identify advanced persistent threats and multi-stage penetration attacks, and are unable to dynamically adapt to emerging attack situations in real time.
A network security situation awareness method based on large models and threat assessment is adopted. By fine-tuning the situation awareness large model and threat assessment algorithm, combined with multi-source data fusion, consistency comparison of situation reasoning and assessment results is achieved, threat assessment parameters are dynamically adjusted, and fine-grained situation awareness results are output.
It significantly improves the detection and response capabilities for complex and variable attacks, increases perception granularity and accuracy, dynamically adapts to emerging attack situations, reduces rule maintenance costs, and builds a reliable and efficient situational awareness system.
Smart Images

Figure CN120602240B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security intelligence, especially for a test training system, and relates to a network security situation awareness method and system based on a large model and threat assessment. BACKGROUND
[0002] With the rapid evolution of test training towards digitization and intelligence, the network attack means faced by its information communication network are increasingly diversified and complex.
[0003] Traditional network security protection methods mainly rely on intrusion detection systems (IDS) based on feature signatures, event management systems (SIEM) and rule engines; there are usually the following problems:
[0004] (1) Limited perception granularity: only known threats or abnormal behavior can be alarmed, and it is difficult to identify advanced persistent threats (APT) and multi-stage penetration attacks;
[0005] (2) High rule maintenance cost: relying on manual definition and updating of rule library, unable to adapt to emerging attack situation in real time and dynamically;
[0006] (3) Difficult multi-source data fusion: the current test training system contains real-time measurement and control data, log data, topology information and external threat intelligence, etc. multi-modal information, and the traditional method is insufficient in the aspects of heterogeneous data correlation analysis and semantic understanding. SUMMARY
[0007] In view of the above problems, the present application provides a network security situation awareness method and system based on a large model and threat assessment, which is used to solve the problems of limited perception granularity, high rule maintenance cost and difficult multi-source data fusion of the current network security protection method.
[0008] In a first aspect, the present application provides a network security situation awareness method based on a large model and threat assessment, which comprises:
[0009] Collecting the current network security situation environment data and inputting it into the fine-tuning situation awareness large model for analysis and judgment to obtain a situation reasoning result;
[0010] Extracting threat assessment parameters from the situation environment data to obtain a situation assessment result;
[0011] Comparing the situation reasoning result and the situation assessment result for consistency, and outputting the current network security situation awareness result.
[0012] Further, the situation environment data includes but is not limited to network traffic logs, access behavior, security alarm events, asset topology information, and threat intelligence.
[0013] Further, the consistency comparison includes:
[0014] If the situation inference result and the situation assessment result are consistent, the current network security situation awareness result is directly outputted;
[0015] Otherwise, a loop correction process is entered, and the threat assessment parameters are automatically adjusted or re-evaluated according to the feedback within a set maximum number of loops until the results of the two are consistent; if they are always inconsistent within the set maximum number of loops, the current result is outputted and a manual review is prompted.
[0016] Further, the establishment of the fine-tuned situation awareness large model includes:
[0017] A plurality of sets of historical network security situation environment data are collected and preprocessed to generate a fine-tuned sample data set;
[0018] Based on the LoRA parameter efficient fine-tuning method, a large language model is used as a base model, and the base model is trained using the fine-tuned sample data set to obtain the fine-tuned situation awareness large model.
[0019] Further, the fine-tuned sample data set is generated in one or more of the following ways: a rule template generation method, a large language model generation method, and a manual intervention generation method to generate fine-tuned sample data sets with semantic consistency and attack diversity.
[0020] Further, the rule template generation method is: combining threat intelligence knowledge base and experimental training business semantics, presetting a structured extraction template; automatically analyzing the original log through regular rules and context matching strategies to extract structured samples, and labeling the situation environment data according to the structured samples;
[0021] The large language model generation method is: on the basis of the structured sample, a pre-trained language model is used to guide the generation of situation awareness corpus samples, and the situation environment data is labeled according to the situation awareness corpus samples;
[0022] The manual intervention generation method is: the sample labels obtained by the rule template generation method and the large language model generation method are audited and corrected.
[0023] Further, the threat assessment parameters include threat value, vulnerability value, asset value, and defense strength.
[0024] Further, the situation inference result includes:
[0025] The threat assessment value is calculated based on the threat assessment parameters;
[0026] According to the threat evaluation value and a set evaluation level, a situation reasoning result is output.
[0027] Further, the threat evaluation value The calculation formula is:
[0028] ; or, ;
[0029] wherein, represents a threat value, used to describe the threat posed by the attacker to the target, ranging from 0 to 100, The higher, the stronger the attacker's ability or the more explicit the attack intention; represents a vulnerability value, used to describe the possibility of the target being attacked, ranging from 0 to 100, The higher, the easier the target is attacked; represents an asset value, used to describe the importance of the target, ranging from 0 to 100, The higher, the more important the target; represents a defense strength, used to describe the effectiveness of the existing defense measures, ranging from 0 to 100, The higher, the stronger the defense, The lower.
[0030] In a second aspect, the present application provides a network security situation awareness system based on a large model and threat evaluation, comprising a memory, a processor and a computer program stored in the memory, and the processor executes the computer program to realize the steps of the method of any one of the above aspects.
[0031] Overall, the present application provides a network security situation awareness method and system based on a large model and threat evaluation, which can achieve the following beneficial effects compared with the prior art:
[0032] (1) The application constructs a network security situation awareness method and system for test training system, on the one hand, by combining the deep semantic understanding ability of the large model with the refined threat evaluation algorithm, the fine-tuning large model and dynamic threat evaluation are introduced, which can dynamically adapt to emerging attack situation, significantly improve the detection and response ability of complex and variable attacks, and provide strong guarantee for the safe and stable operation of the test training system; on the other hand, the situation reasoning result and the situation evaluation result are obtained through the double-channel parallel respectively, the consistency comparison is carried out on the two, the online feedback mechanism and the actual detection result are used to continuously optimize and update the large model, so as to ensure that the emerging attack methods can be adapted in time, various threat events can be dynamically identified, and the manual definition and rule library updating are avoided, not only good robustness and controllability are obtained, but also the perception granularity, the accuracy and timeliness of network situation awareness are greatly improved; key support is provided for the test training to build a credible and efficient situation awareness system.
[0033] (2) The application is fine-tuned in the test training field, so that the fine-tuned situation awareness large model has the deep semantic understanding ability of the network behavior and security events specific to the test training system, and the identification accuracy of complex attack modes is improved, so that the perception granularity is greatly improved.
[0034] (3) The application introduces a threat evaluation calculation method based on multi-source data fusion, which can quantize the risk level of security events in real time, so as to output more accurate situation threat levels for the fine-grained environment data, realize dynamic evaluation and priority sorting of potential threats, and improve the accuracy of network situation awareness when consistency comparison is carried out. BRIEF DESCRIPTION OF DRAWINGS
[0035] In order to more clearly illustrate the technical solutions in the application or prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are some embodiments of the application, and those skilled in the art can also obtain other drawings according to these drawings without creative labor.
[0036] Figure 1 It is a method step schematic diagram of a network security situation awareness system based on a large model and threat evaluation provided by the application;
[0037] Figure 2 It is a method principle schematic diagram of a network security situation awareness system based on a large model and threat evaluation provided by the application;
[0038] Figure 3 It is a fine-tuning sample data set generation schematic diagram of a network security situation awareness system based on a large model and threat evaluation provided by the application. DETAILED DESCRIPTION
[0039] In order to make the objects, technical solutions and advantages of the present application clearer, the technical solutions in the present application will be described clearly and completely below with reference to the drawings and embodiments in the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art without creative work fall within the protection scope of the present application.
[0040] It should be noted that, in the description of the embodiments of the present application, the terms “comprise”, “contain” or any other variants thereof are intended to cover non-exclusive inclusion, so that the method, step or device comprising a series of elements not only includes those elements, but also includes other elements not explicitly listed, or includes elements inherent to such method, step or device. Without more limitation, the element defined by the sentence “comprises a…” does not exclude the presence of another same element in the method, step or device comprising the element.
[0041] In order to strengthen the security network situation awareness technology of the test training system, the problems of limited perception granularity, high rule maintenance cost and difficult multi-source data fusion of the current network security protection method are solved.
[0042] The present application provides a network security situation awareness method and system based on a large model and threat assessment, which collects, processes and constructs a situation awareness fine-tuning sample data set, fine-tunes a fine-tuning situation awareness large model conforming to the actual test training network environment business demand based on a LoRA framework, inputs the situation environment data into the fine-tuning situation awareness large model for analysis and judgment to obtain a situation reasoning result, further analyzes the input situation environment data through a threat assessment algorithm to obtain a situation assessment result, and finally compares and analyzes the results output by the fine-tuning situation awareness large model and the results output by the threat assessment algorithm, constructs a standardized, intelligent and automated situation analysis engine, and dynamically outputs a fine-grained and accurate situation awareness result.
[0043] In a first aspect, as shown in Figure 1 and Figure 2 , the method specifically comprises:
[0044] Step 101: collect the situation environment data of the current network security, input into the fine-tuning situation awareness large model for analysis and judgment to obtain a situation reasoning result.
[0045] It should be noted that the situational environment data is raw data collected from multiple heterogeneous data sources in the test training system, including but not limited to network flow logs, access behavior, security alarm events, asset topology information, threat intelligence and other network situational environment key data. These data have characteristics such as high dimensionality, unstructured, multi-modal, etc.
[0046] In order to improve the identification, correlation and reasoning ability of large models to threat events in complex and variable network environment, and realize accurate perception and intelligent decision support of situation, the present application constructs a situational awareness fine-tuning sample data set for the network security scene of the test training system, and fine-tunes the large model based on the sample data set, and then obtains a fine-tuned situational awareness large model.
[0047] As an embodiment of the present application, the establishment of the fine-tuned situational awareness large model includes:
[0048] Step 201: Collect multiple sets of historical network security situational environment data for preprocessing to generate a fine-tuning sample data set.
[0049] It should be noted that the historical network security situational environment data is also raw data collected from multiple heterogeneous data sources in the historical test training system, including but not limited to network flow logs, access behavior, security alarm events, asset topology information, threat intelligence and other network situational environment key data. These data constitute the basis of the original material for subsequent training corpus, and have characteristics such as high dimensionality, unstructured, multi-modal, etc.
[0050] The input situational environment data is first preprocessed to complete format unification, noise filtering, data normalization and context construction and other preprocessing operations to ensure the stability and accuracy of subsequent model and algorithm processing.
[0051] In order to realize accurate situational awareness for the network security scene of the test training system, the present application proposes a sample data set generation method of multi-source heterogeneous data fusion and multi-strategy driven data enhancement and semantic annotation strategy. As an embodiment, as shown in Figure 3 The generation method of the fine-tuning sample data set includes: generating a fine-tuning sample data set with semantic consistency and attack diversity by using one or more of a rule template generation method, a large language model generation method and a manual intervention generation method. The fine-tuning sample data set can be a merged set of data generated according to the three methods respectively, or the rule template generation method, the large language model generation method and the manual intervention generation method can be used as three stages in turn to generate the final data, so as to ensure that the finally generated sample data set has high quality, high adaptability and high generalization ability.
[0052] The rule template generation method is based on the template generation of specific rules, and the typical attack path, security event and response process are structured and reduced.
[0053] Specifically, the rule template generation method is: combining threat intelligence knowledge base and training business semantics, presetting structured extraction templates; automatically analyzing the original log through regular rules and context matching strategy, extracting structured samples, and assigning labels to situational environment data according to the structured samples.
[0054] For example, first, the common situational environment data in the training network environment is obtained, such as horizontal penetration, slow scanning, privilege escalation, etc.; then, the structured extraction template is preset, the unified labeling template format is designed combining the threat intelligence knowledge base and the actual training business semantics, including one or more fields of event category, event time, attack path, attack behavior, threat level, trigger condition, response action, target asset, etc.; then, the structured samples are extracted by automatically analyzing the original log through regular rules and context matching strategy. For example, taking a log "2024 October 14, the core substation border firewall is subjected to external IP continuous high-frequency access" as an example, the event time, target asset, attack behavior, etc. can be automatically extracted, and the event can be classified as "suspected DDoS detection" event; finally, the event is assigned an initial label: "medium level threat".
[0055] The large language model generation method is to generate AI by combining a large language model, and to generate high-quality situational description and threat judgment instructions through the construction of multi-round context dialogue scene.
[0056] Specifically, the large language model generation method is: on the basis of structured samples, using a pre-trained language model to guide the generation of situational awareness corpus samples, and assigning labels to situational environment data according to the situational awareness corpus samples. The pre-trained language model can be ChatGLM, Qwen, etc. guided large language model.
[0057] For example, taking the structured sample of "event triple + attack background + response mechanism" as the input format, and inputting "abnormal remote login in large power generation control center, account for default password login" as the prompt, the large model can generate the corresponding situational narrative: "the system detects high-risk remote access behavior, judges as weak password vulnerability, and suggests blocking the account immediately and strengthening the identity authentication mechanism." The large language model generation method effectively expands the long-tail event corpus, and improves the semantic richness and scene coverage of the fine-tuning data.
[0058] The artificial intervention generation method is to construct real and complex reasoning type instruction samples relying on the experience of security experts for boundary scenes or high-risk attack chains.
[0059] Specifically, the artificial intervention generation method is to correct the sample labels obtained by the rule template generation method and the large language model generation method.
[0060] In other words, for the semantic ambiguity and label errors in the sample label generation process of the rule template generation method and the large language model generation method, the application also introduces a "human-computer collaborative verification mechanism". Security experts can quickly audit and optimize labels based on system recommended samples, and the current network security system records modification behavior for training future automatic labeling. In this way, an automatic audit large model is generated to correct the existing semantic ambiguity and label errors in the sample label.
[0061] For example, for the generated sample "attackers use default ports for remote blasting, and the system prompts normal access, the risk level should be low", the expert judges that the risk level should be "high", and the large model deviation is corrected. The artificial intervention generation method significantly improves the quality of the data set and forms a closed-loop optimization mechanism.
[0062] To ensure the semantic accuracy and logical validity of the generated sample data, the application also proposes a data accuracy verification mechanism. The preliminary judgment of the large model and the artificial verification mechanism are combined, that is, after obtaining sample data each time, the artificial intervention generation method is used to audit and verify it, so as to evaluate the data rationality. The sample data with contradictions and defects is eliminated or corrected, thereby significantly improving the quality of the fine-tuning sample data set.
[0063] The sample data generated by the rule template generation method, the large language model generation method and the artificial intervention generation method are unified in format and fused, thereby constructing a fine-tuning sample data set with semantic consistency and attack diversity. In addition, based on the structural stability of the samples generated by the rule template generation method, the semantic diversity of the samples generated by the large language model generation method, and the accuracy of the artificial intervention generation method, the three methods complement each other, and a situation awareness fine-tuning sample data set highly consistent with the security context of the test training is constructed. LoRA fine-tuning for situation awareness large model provides solid support and significantly improves the understanding and judgment ability of the large model for complex situation environment.
[0064] Step 202: Based on the LoRA parameter efficient fine-tuning method, taking the large language model as the base model, the base model is trained by using the fine-tuning sample data set to obtain a fine-tuning situation awareness large model.
[0065] The application is based on the LoRA (Low-Rank Adaptation) parameter efficient fine-tuning technology, selects mainstream large language models such as ChatGLM, Qwen and Baichuan as the basic model, and uses the generated fine-tuning sample data set to fine-tune the basic model. Compared with full parameter fine-tuning, the LoRA technology can significantly reduce the training cost while maintaining the original model inference ability, and has modular plug-in capability, which is convenient for flexible deployment in different scenarios in the future.
[0066] The fine-tuning situational awareness large model is a situational awareness large model obtained by fine-tuning in the early stage, which is used to analyze and judge the evolution trend of the current network security in combination with the historical fine-tuning sample data set and the current context, and outputs the inference result in the form of structured JSON. This inference path has the significant advantages of strong context modeling ability, deep semantic understanding and high adaptability to new attacks.
[0067] The fine-tuning situational awareness large model constructed by the application not only greatly improves the understanding ability and task generalization ability of the fine-tuning situational awareness large model in the experimental training security context, but also first realizes the instruction-driven situational awareness task modeling in the experimental training network security field, providing high-quality semantic basis and knowledge expression ability for subsequent threat assessment and system reasoning, and having significant advantages in innovation and adaptability. It is the basic and core link of building an intelligent and automatic situational awareness system.
[0068] As an embodiment, first, the situational environment data from the boundary network security device is received, including network traffic logs, access behavior, security alarm events, threat intelligence, etc. The data is input to the fine-tuning situational awareness large model for standardization preprocessing. The fine-tuning situational awareness large model is based on historical situational knowledge embedding and current context semantic understanding, and automatically infers the threat situation of the current network security, for example, "the core control host has abnormal external connection behavior, and it is speculated that it may be a C2 communication attempt". The output is returned in the form of structured JSON, with confidence score and explainable label, and the fine-tuning situational awareness large model gives the situational reasoning result of the current network security.
[0069] Step 102: extracting threat assessment parameters from the situational environment data to obtain a situational assessment result.
[0070] It should be noted that the method of extracting threat assessment parameters from the situational environment data can be: extracting key elements from the situational environment data, and then obtaining threat assessment parameters according to the key elements.
[0071] The key elements can be extracted directly from the situational environment data or input into the fine-tuned situational awareness large model for extraction. The key elements include: attack type, attack path, target importance, threat source characteristics, and defense status.
[0072] Attack type: such as DDoS attack, SQL injection, malicious code propagation, etc.
[0073] Attack path: used to assess the possible path of the attacker, determine the path complexity and the possibility of bypassing existing protection measures.
[0074] Target importance: that is, asset value, score the target according to business impact and asset value.
[0075] Threat source characteristics: attacker's ability, tools, intentions and resources, which can be obtained from threat intelligence.
[0076] Defense status: coverage, defense strength, and response capability of defense equipment of existing protection measures.
[0077] According to the key elements, threat assessment parameters can be obtained, and the key elements and threat assessment parameters can be used as training sample sets to train the parameter extraction large model. The input of the parameter extraction large model is the key elements, and the output is the threat assessment parameter, that is, the risk factor, which is a specific numerical value.
[0078] Among them, the threat assessment parameters include threat value (Threat Value, TV), vulnerability score (Vulnerability Score, VS), asset value (Asset Value, AV) and defense strength (Defense Strength, DS).
[0079] As an embodiment, the obtaining of the situational reasoning result includes: calculating a threat assessment value based on the threat assessment parameters; and outputting the situational reasoning result according to the threat assessment value and a set evaluation level.
[0080] Further, the calculation formula of the threat assessment value may be:
[0081] ; or, ;
[0082] When the threat assessment value calculated by the calculation formula satisfies the condition , the threat assessment value is directly outputted; otherwise, if the condition is not satisfied, the threat assessment value is recalculated by the calculation formula In other words, no matter which formula is used, the threat assessment value needs to be normalized to be within 100, so that the situation assessment result is between 0 and 100, and the higher the value, the higher the threat.
[0083] Preferably, the threat assessment value of the present application is calculated as follows:
[0084] ;
[0085] wherein, represents a threat value, used to describe the threat posed by the attacker to the target, ranging from 0 to 100, the higher, the stronger the attacker's ability or the more explicit the attack intention; represents a vulnerability value, used to describe the possibility of the target being attacked, ranging from 0 to 100, the higher, the easier the target is attacked; represents an asset value, used to describe the importance of the target, ranging from 0 to 100, the higher, the more important the target; represents a defense strength, used to describe the effectiveness of the existing defense measures, ranging from 0 to 100, the higher, the stronger the defense, the lower.
[0086] The evaluation level set can be evenly divided according to the range of the threat assessment value to obtain a plurality of evaluation levels; for example, the evaluation level is divided into four levels: when the threat assessment value is 0-25, it is marked as low threat; when the threat assessment value is 26-50, it is marked as medium threat; when the threat assessment value is 51-75, it is marked as high threat; and when the threat assessment value is 76-100, it is marked as serious threat.
[0087] The evaluation path parallel to the reasoning path proposed in the present application is used to extract key risk elements in the situation environment data, such as attack type, target importance, vulnerability, and current defense capability, and call a threat scoring function for quantitative evaluation, and then calculate the threat level under the current environment, to provide quantitative support for the judgment result.
[0088] For example, the database server of a certain test training system is a key defense target, and recently received an SQL injection attack alarm against the server, and the system needs to assess the threat level. The input situation environment data is attack type, target importance, vulnerability value and defense strength.
[0089] Among them, the attack type (SQL injection) has high efficiency and concealment, and the threat value (TV) is evaluated as 85; the target importance (database server), the database stores user sensitive data and business core information, and the asset value (AV) is evaluated as 90; since the vulnerability scanner detects that the target has a high-risk SQL injection vulnerability, the vulnerability value (VS) is evaluated as 80; the existing WAF (Web Application Firewall) partially covers SQL injection, but does not enable strict checking for all requests, so the defense strength (DS) is evaluated as 70.
[0090] Therefore, the threat assessment value . But because the original formula can cause the value to exceed the standard, it needs to be reset with reasonable weights and deformed and normalized, so the formula is used to calculate . After correction, the score can be simplified and normalized to ensure that the threat assessment value is within a reasonable range.
[0091] Based on the normalized weights, the comprehensive calculation is:
[0092] ;
[0093] Therefore, the threat assessment value , which is marked as a low threat level.
[0094] Based on the preliminary reasoning of the fine-tuned situational awareness large model, the threat assessment calculation formula is called at the same time, and the key risk elements in the situational reasoning result are automatically extracted, and the threat assessment value is quantitatively calculated.
[0095] For example, for the identified "weak password remote login event", the automatically extracted threat assessment parameters are: , , , ; the threat assessment value calculated is: , which is marked as "low threat level". This evaluation path realizes seamless linkage from semantic situational awareness to quantitative risk assessment, ensuring that the perception result is business decision-making.
[0096] Step 103: Compare the situational reasoning result and the situational assessment result for consistency, and output the situational awareness result of the current network security.
[0097] That is, or, through the parallel of the double channels (reasoning channel + evaluation channel), the situational reasoning result and the situational assessment result are obtained respectively, and the consistency of the two is compared, and the online feedback mechanism and the actual detection result are used to continuously optimize and update the large model, so as to ensure that it can adapt to new attack methods in time, and dynamically identify various threat events.
[0098] Further, in order to ensure the stability of the situation reasoning result and the accuracy of the situation assessment result, the application also introduces a "situation result comparison verification" mechanism to compare the consistency of the situation reasoning result and the situation assessment result. When the conclusions of the two are inconsistent, the system can decide whether to output the result or switch to manual review according to the number of cycles and the verification threshold, thereby ensuring the coexistence of system intelligence and robustness.
[0099] More specifically, as an embodiment, the consistency comparison includes:
[0100] If the situation reasoning result and the situation assessment result are consistent, the current network security situation awareness result is directly outputted;
[0101] Otherwise, a cycle correction process is entered, and within the set maximum number of cycles, the threat assessment parameters are automatically adjusted or re-evaluated until the results of the two are consistent; if they are always inconsistent within the set maximum number of cycles, the current result is outputted and manual review is prompted.
[0102] By fusing the semantic reasoning ability of the fine-tuned situation awareness large model and the intelligent situation awareness ability of the threat assessment quantitative mechanism, a closed-loop intelligent analysis process is realized from data input, model reasoning, threat calculation to output result. At the same time, the network situation environment data of a certain test training system can be taken as the input object, and the system can be run by simulating the actual scene, so as to verify its intelligent analysis and accurate judgment ability.
[0103] For example, if the fine-tuned situation awareness large model outputs a situation reasoning result of "high threat" for the current network security situation environment data, and the situation assessment result is "low threat", at most three rounds of rejudgment or the label of "manual review is needed" will be outputted. The "situation result comparison verification" mechanism has good robustness and controllability, and provides key support for building a reliable and efficient situation awareness intelligent system for test training.
[0104] It should be noted that the application introduces two complementary processing paths in parallel:
[0105] One is the reasoning path: based on the fine-tuned situation awareness large model, the historical data and the current context are used to analyze and judge the situation evolution trend, and the situation reasoning result is outputted in the form of structured JSON. This path has the significant advantages of strong context modeling ability, deep semantic understanding, and high adaptability to new attacks.
[0106] The second is the assessment path: the key risk elements in the situation environment data are extracted, and the threat assessment value calculation formula is called to perform quantitative assessment, calculate the threat level of the current network security environment, and obtain the situation assessment result.
[0107] After obtaining the situation reasoning result and the situation assessment result, a situation result comparison and verification mechanism is entered, cross verification is performed through consistency comparison, if the judgment results are consistent, the situation awareness result is directly output, if the judgment results are inconsistent, a loop correction process is entered, within the set maximum number of loops, the threat assessment parameters are automatically adjusted or re-evaluated according to the feedback until the results are consistent, if the results are always inconsistent within the set maximum number of loops, the current result is output and manual review is prompted to ensure the interpretability and accuracy of the result. The method provides a high-intelligence, strong-robustness security situation awareness solution for the test training system, and has high practical value and technical popularization prospect.
[0108] In a second aspect, the present application also provides a network security situation awareness system based on a large model and threat assessment, comprising a memory, a processor and a computer program stored in the memory, and the processor executes the computer program to realize the steps of any one of the above methods. The system adopts modular design to improve the intelligent decision-making level, adaptability and continuous evolution ability of the system. The technical features of the system and method are consistent, and will not be described one by one here.
[0109] In summary, the present application constructs a network security situation awareness method and system for a test training system. On the one hand, by combining the deep semantic understanding ability of a large model with a refined threat assessment algorithm, a fine-tuned large model and dynamic threat assessment are introduced, which can dynamically adapt to emerging attack situations, significantly improving the detection and response ability to complex and variable attacks, and providing a strong guarantee for the safe and stable operation of the test training system. On the other hand, by obtaining situation reasoning results and situation assessment results through double-channel parallel, consistency comparison is performed on the two results, and online feedback mechanism and actual detection results are used to continuously optimize and update the large model, so as to ensure that the large model can adapt to new attack methods in time, dynamically identify various threat events, and avoid manual definition and update of the rule library. Not only does it have good robustness and controllability, but also greatly improves the awareness granularity, accuracy and timeliness of network situation awareness. It provides key support for building a trusted and efficient situation awareness system for test training.
[0110] It should be noted that, for the foregoing various embodiments, in order to simply describe, they are all expressed as a series of action combinations, but those skilled in the art should know that the present application is not limited by the order of the described actions, because according to the present application, certain steps can be performed in other order or simultaneously. Secondly, those skilled in the art should know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily necessary for the present application.
[0111] In the above embodiments, the description of each embodiment focuses on different aspects, and the parts not described in detail in a certain embodiment can be referred to the relevant description of other embodiments.
[0112] In several embodiments provided in the present application, it should be understood that the disclosed method or system can be implemented in other ways. For example, the above-described embodiments are merely illustrative, for example, the division of the units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed.
[0113] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, that is, they can be located in one place or distributed on a plurality of network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment.
[0114] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.
[0115] When the integrated unit is realized in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application essentially or the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product, which is stored in a storage medium and includes a plurality of instructions for making a computer device (which can be a personal computer, a server or a network device, etc.) execute all or part of the steps of the methods described in each embodiment of the present application.
[0116] Those of ordinary skill in the art can understand that all or part of each circuit in the above embodiments can be instructed by a program to complete the related hardware, and the program can be stored in a computer readable storage medium, which can include a flash disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.
[0117] The above-described embodiments are merely exemplary embodiments of the present disclosure, and the present disclosure is not limited thereto. That is, any equivalent changes and modifications made in accordance with the teachings of the present disclosure are still included in the scope of the present disclosure. Embodiments of the present disclosure will be readily apparent to those skilled in the art in view of the disclosure herein with the description and practice of the present disclosure. The present application is intended to cover any variations, uses, or adaptations of the present disclosure following the general principles thereof and including such insubstantial variations and modifications thereof as come within the scope of the present disclosure. The scope of the present disclosure is defined by the appended claims rather than the description and embodiments thereof.
[0118] Any of the technical features of the above embodiments can be combined, and for the sake of brevity, not all possible combinations of the various technical features described above are repeated, however, any combination of the technical features should be considered as within the scope of the present disclosure, as long as the combination does not result in a contradiction.
[0119] Those skilled in the art easily understand that the above-mentioned is only the preferred embodiment of the present application, and is not used to limit the present application, any modification, equivalent replacement and improvement made in the spirit and principle of the present application should be included in the protection scope of the present application.
Claims
1. A network security situation awareness method based on a large model and threat assessment, characterized in that: The method comprises: The current network security situation and environmental data are collected and input into a fine-tuned situation awareness model for analysis and judgment to obtain situation inference results. The fine-tuned situation awareness model is based on a large language model. Based on the historical situation knowledge embedding and current context semantic understanding, it automatically infers the current network security threat situation. The fine-tuned sample data set is used to train the basic model. The sample data generated by the three methods of rule template generation method, large language model generation method and manual intervention generation method are unified in format and fused to construct a fine-tuned sample data set with semantic consistency and attack diversity. Extract threat assessment parameters from the situation environment data to obtain a situation assessment result; the threat assessment parameters include threat value, vulnerability value, asset value and defense strength; Comparing the situational reasoning result with the situational assessment result for consistency, and outputting a situational awareness result of the current network security; The consistency comparison includes: if the situation reasoning result and the situation assessment result are consistent, the current network security situation awareness result is directly output; otherwise, a cyclic correction process is entered, and within the set maximum number of cycles, the threat assessment parameters are automatically adjusted and re-evaluated according to feedback until the two results are consistent; if they are always inconsistent within the set maximum number of cycles, the current result is output and a manual review is prompted.
2. A network security situation awareness method based on a large model and threat assessment according to claim 1, characterized in that: The situational environment data includes network traffic logs, access behavior, security alarm events, asset topology information, and threat intelligence.
3. A network security situation awareness method based on a large model and threat assessment according to claim 1, characterized in that: The establishment of the fine-tuning situational awareness model includes: Collect multiple sets of historical network security situational environment data for preprocessing and generate fine-tuning sample data sets; Based on the LoRA parameter efficient fine-tuning method, the large language model is used as the basic model, and the basic model is trained using the fine-tuning sample data set to obtain the fine-tuning situation awareness large model.
4. A network security situation awareness method based on a large model and threat assessment according to claim 1, characterized in that: The rule template generation method is as follows: combining the threat intelligence knowledge base with the business semantics of experimental training to preset a structured extraction template; automatically parsing the original log through regular rules and context matching strategies to extract structured samples, and assigning labels to the situation environment data based on the structured samples; The large language model generation method comprises: based on the structured sample, using the pre-trained language model to guide the generation of situation awareness corpus samples, and assigning labels to situation environment data according to the situation awareness corpus samples; The manual intervention generation method is to review and correct the sample labels obtained by the rule template generation method and the large language model generation method.
5. The network security situation awareness method based on a large model and threat assessment according to claim 1, wherein obtaining the situation reasoning result comprises: Calculating a threat assessment value based on the threat assessment parameters; Output the situation reasoning result according to the threat assessment value and the set assessment level.
6. A network security situation awareness method based on a large model and threat assessment according to claim 5, wherein the threat assessment value The calculation formula is: ;or, ; in, Indicates the threat value, which is used to describe the threat posed by the attacker to the target, ranging from 0 to 100. The higher the value, the stronger the attacker's ability or the clearer the attack intention; Indicates the vulnerability value, which is used to describe the possibility of the target being attacked, ranging from 0 to 100. The higher it is, the easier it is to attack the target; Indicates asset value, used to describe the importance of the target, ranging from 0 to 100. The higher it is, the more important the goal is; Indicates the defense strength, which is used to describe the effectiveness of existing defense measures, ranging from 0 to 100. The higher the value, the stronger the defense. The lower.
7. A network security situation awareness system based on a large model and threat assessment, comprising a memory, a processor, and a computer program stored in the memory, characterized in that: The processor executes the computer program to implement the steps of the method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Network security situation sensing system and method based on multi-layer multi-angle analysis
CN101459537A
SAA-SSA-BPNN-based network security situation assessment method
CN116846565A