Firewall methods for detecting automated attacks based on large models

By using a large model-based approach, matching network log data with attack rules and fine-tuning the large model, the problem of missed detections in the detection of automated attacks by existing firewalls is solved, achieving higher detection accuracy and universality.

CN120614160BActive Publication Date: 2026-04-03BEIJING VOLCANO ENGINE TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510727325.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-30
Publication Date
2026-04-03
Estimated Expiration
2045-05-30

AI Technical Summary

Technical Problem

Existing web application firewalls are unable to effectively detect automated attacks, especially since statistical methods cannot exhaust all statistical scenarios, leading to frequent missed detections. Furthermore, pre-built statistical features based on experience cannot discover potential attack behaviors in custom fields.

Method used

A large model-based approach is adopted, which obtains tags by matching network log data with attack rules, and then inputs the tags and log data into the large model for classification. The detection accuracy is improved by fine-tuning the large model, and the detection and analysis can be performed on all fields, not just general fields.

Benefits of technology

It improves the accuracy and versatility of automated attack detection, adapts to flexible and ever-changing business types, and realizes automated detection of automated attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120614160B_ABST
    Figure CN120614160B_ABST
Patent Text Reader

Abstract

A firewall method, storage medium, electronic device, and program product for detecting automated attacks based on a large model are disclosed. The method includes: acquiring multiple first network log data belonging to a first user; matching the multiple first network log data with attack rules to obtain a first label for the first user, characterizing whether automated attack characteristics exist in the multiple first network log data; inputting the first label and the multiple first network log data into a large first model to obtain a classification result characterizing whether the first user is the source of an automated attack; and fine-tuning the large model to obtain a large first model. This large first model enables automatic detection of automated attacks without setting statistical rules, performing detection and analysis on all fields, not just general fields, thus solving the problem of missed attacks due to the inability of statistical methods to exhaustively cover all statistical scenarios, improving the accuracy of automated attack detection, and making automated attack detection more universal and automated.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of network security technology, and more specifically, to a firewall method and storage medium, electronic device and program product for detecting automated attacks based on a large model. Background Technology

[0002] With the development of information technology, network security is becoming increasingly important. Some individuals use automated scripts to attack and deceive user networks and programs, causing losses to users.

[0003] Currently, attacks using automated scripts are becoming increasingly covert. Modern web application firewalls typically employ statistical methods for detecting automated attacks, analyzing the characteristics of repeated, large-scale requests. However, this method cannot exhaustively cover all statistical scenarios, leading to missed detections. Furthermore, the statistical features rely heavily on experience, pre-setting and selecting common, general fields, failing to uncover potential automated attack behaviors from a broader range of custom fields. Summary of the Invention

[0004] This summary section is provided to briefly introduce the concepts, which will be described in detail in the detailed description section below. This summary section is not intended to identify key or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.

[0005] Firstly, this disclosure provides a firewall method for detecting automated attacks based on a large model, including:

[0006] Retrieve multiple first network log entries belonging to the first user;

[0007] The multiple first network log data are matched with attack rules to obtain the first tag of the first user, wherein the first tag is used to characterize whether there are automated attack features in the multiple first network log data;

[0008] The first label and the multiple first network log data are input into the first large model to obtain the classification result; wherein, the classification result is used to characterize whether the first user is an automated attack source, and the first large model is obtained by fine-tuning the pre-trained large model.

[0009] Secondly, this disclosure provides a firewall device for detecting automated attacks based on a large model, comprising:

[0010] The first acquisition module is used to acquire multiple first network log data belonging to the first user;

[0011] The first determining module is used to match the multiple first network log data with attack rules to obtain the user's first tag, wherein the first tag is used to characterize whether there are automated attack features in the multiple first network log data;

[0012] The classification module is used to input the first label and the multiple first network log data into the first large model to obtain the classification result; wherein, the classification result is used to characterize whether the first user is an automated attack source, and the first large model is obtained by fine-tuning the pre-trained large model.

[0013] Thirdly, this disclosure provides a computer-readable medium having a computer program stored thereon, which, when executed by a processing device, implements the steps of the firewall apparatus method for detecting automated attacks based on a large model provided in the first aspect of this disclosure.

[0014] Fourthly, this disclosure provides an electronic device, comprising:

[0015] A storage device on which computer programs are stored;

[0016] A processing device is configured to execute the computer program in the storage device to implement the steps of the firewall apparatus method for detecting automated attacks based on a large model provided in the first aspect of this disclosure.

[0017] Fifthly, this disclosure provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the firewall apparatus method for detecting automated attacks based on a large model provided in the first aspect of this disclosure.

[0018] In the above technical solution, after acquiring multiple first network log data belonging to the first user, these first network log data can be matched with attack rules to obtain a first label characterizing whether automated attack characteristics exist in the multiple first network log data. Then, the first label and the multiple first network log data are input into a first large model to obtain a classification result characterizing whether the first user is the source of an automated attack. The first large model is obtained by fine-tuning a pre-trained large model. Thus, automated attack detection can be achieved through the first large model based on the large model, without the need for pre-setting statistical rules. It can also perform detection and analysis on all fields, not just general fields, thereby solving the problem of statistical methods failing to exhaustively cover all statistical scenarios and thus missing some cases. This improves the accuracy of automated attack detection, making it more universal and automated to adapt to increasingly flexible and diverse business types. Furthermore, using the first label characterizing whether automated attack characteristics exist in the multiple first network log data as input to the model can further improve the accuracy of automated attack detection.

[0019] Other features and advantages of this disclosure will be described in detail in the following detailed description section. Attached Figure Description

[0020] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and the originals and elements are not necessarily drawn to scale. In the drawings:

[0021] Figure 1 This is a flowchart illustrating a firewall method for detecting automated attacks based on a large model, according to an exemplary embodiment.

[0022] Figure 2 This is a schematic diagram illustrating the fine-tuning and inference process of a first large model according to an exemplary embodiment.

[0023] Figure 3 This is a flowchart illustrating a method for fine-tuning a first large model according to an exemplary embodiment.

[0024] Figure 4 This is a block diagram illustrating a firewall apparatus for detecting automated attacks based on a large model, according to an exemplary embodiment.

[0025] Figure 5 This is a block diagram illustrating a fine-tuning device for a first large model according to an exemplary embodiment.

[0026] Figure 6This is a schematic diagram of the structure of an electronic device according to an exemplary embodiment. Detailed Implementation

[0027] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.

[0028] It should be understood that the steps described in the method embodiments of this disclosure may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this disclosure is not limited in this respect.

[0029] The term "comprising" and its variations as used herein are open-ended inclusions, meaning "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Definitions of other terms will be given in the description below.

[0030] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.

[0031] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".

[0032] The names of messages or information exchanged between multiple devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of such messages or information.

[0033] It is understood that before using the technical solutions disclosed in the various embodiments of this disclosure, users should be informed of the types, scope of use, and usage scenarios of the personal information involved in this disclosure in an appropriate manner in accordance with relevant laws and regulations, and user authorization should be obtained.

[0034] For example, upon receiving a user's active request, a prompt message is sent to the user to explicitly inform them that the requested operation will require the acquisition and use of the user's personal information. This allows the user to independently choose whether to provide personal information to the software or hardware, such as the electronic device, application, server, or storage medium performing the operations of this disclosed technical solution, based on the prompt message.

[0035] As an optional but non-limiting implementation, in response to a user's active request, sending a prompt message to the user can be done via a pop-up window, where the prompt message can be presented in text format. Furthermore, the pop-up window can also include a selection control allowing the user to choose "agree" or "disagree" to provide personal information to the electronic device.

[0036] It is understood that the above notification and user authorization process are merely illustrative and do not constitute a limitation on the implementation of this disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of this disclosure.

[0037] Meanwhile, it is understood that the data involved in this technical solution (including but not limited to the data itself, the acquisition or use of the data) shall comply with the requirements of relevant laws, regulations and related provisions.

[0038] Figure 1 This is a flowchart illustrating a firewall method for detecting automated attacks based on a large model, according to an exemplary embodiment. Figure 1 As shown, this firewall method for detecting automated attacks based on a large model may include the following steps S101 to S103.

[0039] In S101, multiple first network log data belonging to the first user are retrieved.

[0040] In one implementation, network log data within a preset time period can be obtained first, and then, based on the client identifier in the network log data (such as...),... Figure 2 The network log data shown includes the _gid, where _gid is a globally unique identifier. This allows us to obtain network log data belonging to the first user, resulting in multiple first network log data entries belonging to the first user.

[0041] In another implementation, multiple pieces of second network log data can be acquired firstly. Then, these pieces of second network log data can be grouped by user to obtain multiple first data groups. Subsequently, the first data group corresponding to the first user among the multiple first data groups can be identified as multiple pieces of first network log data. The first user can be any one of the users corresponding to the multiple first data groups.

[0042] In S102, multiple first network log data are matched with attack rules to obtain the first user's first tag.

[0043] In this disclosure, the first label is used to characterize whether there are automated attack features in multiple first network log data. Automated attacks are attacks initiated by automated scripts, and the automated attack features can be BOT features.

[0044] The aforementioned attack rules may include security rules such as lists of automated attack IP addresses and lists of automated attack user agents. The list of automated attack IP addresses can be generated based on a threat intelligence database, and the list of automated attack user agents can be generated based on a managed signature database.

[0045] like Figure 2 As shown, automated attack characteristics can include automated attack IP addresses, automated attack user agents (UAs), and other rules.

[0046] In one implementation, the first label includes classification information characterizing whether automated attack features exist in the plurality of first network log data. The classification information can be "yes" or "no," or it can be a flag characterizing "yes" or "no," for example, using flag "0" to represent "no" and flag "1" to represent "yes." When there are multiple automated attack features, if the plurality of first network log data includes any one of the multiple automated attacks, the classification information is "yes"; otherwise, the classification information is "no."

[0047] In another embodiment, the first label includes not only the aforementioned classification information but also automated attack characteristics (e.g., the identifier or name of the automated attack characteristic). When there is only one automated attack characteristic, the first label includes classification information indicating whether such an automated attack characteristic exists in multiple first network log data entries, and the automated attack characteristic itself. When there are multiple automated attack characteristics, the first label may include multiple automated attack characteristics and the aforementioned classification information, or the first label may include multiple automated attack characteristics and their respective classification information.

[0048] In S103, the first label and multiple first network log data are input into the first large model to obtain the classification result.

[0049] like Figure 2 As shown, after obtaining the first label and multiple first network log data (constituting a behavioral sequence), they can be converted into the input format of an LLM (Local Management Model), and then input into the first large model to obtain the classification result. The classification result is used to characterize whether the first user is an automated attack source. The first large model is obtained by fine-tuning the pre-trained large model.

[0050] In this disclosure, when the first label indicates the presence of automated attack characteristics in multiple first network log data, it suggests that the first user is suspected of being the source of an automated attack. At this point, based on the first label and multiple first network logs, a first major model can be used to further determine whether the first user is indeed the source of an automated attack. The source of an automated attack can be one or more automated scripts, and multiple automated scripts can initiate network requests (attacks) representing the same user.

[0051] In this disclosure, the large model can be a large language model or a multimodal large model. A multimodal large model can handle various types of data, such as text, images, audio, and other multimodal data.

[0052] In the above technical solution, after acquiring multiple first network log data belonging to the first user, these first network log data can be matched with attack rules to obtain a first label characterizing whether automated attack characteristics exist in the multiple first network log data. Then, the first label and the multiple first network log data are input into a first large model to obtain a classification result characterizing whether the first user is the source of an automated attack. The first large model is obtained by fine-tuning a pre-trained large model. Thus, automated attack detection can be achieved through the first large model based on the large model, without the need for pre-setting statistical rules. It can also perform detection and analysis on all fields, not just general fields, thereby solving the problem of statistical methods failing to exhaustively cover all statistical scenarios and thus missing some cases. This improves the accuracy of automated attack detection, making it more universal and automated to adapt to increasingly flexible and diverse business types. Furthermore, using the first label characterizing whether automated attack characteristics exist in the multiple first network log data as input to the model can further improve the accuracy of automated attack detection.

[0053] The following is a detailed description of the specific implementation method for matching multiple pieces of first network log data with attack rules to obtain the first tag of the first user in S102 above. Specifically, S102 above may include at least one of the following steps:

[0054] If any of the IP addresses contained in multiple first network log data entries are IP addresses listed in the aforementioned automated attack IP address list, then it is determined that there are automated attack IP addresses in the multiple first network log data entries.

[0055] If any of the user agents contained in multiple first network log data entries are user agents listed in the aforementioned automated attack user agent list, then it is determined that an automated attack user agent exists in multiple first network log data entries.

[0056] In this disclosure, the network log data includes information such as the IP address and user agent of the client that initiated the request.

[0057] In one possible implementation, the first network log data may include header information and body information. Since automated attack characteristics are usually contained in the header information and rarely appear in the body information, in order to reduce the model classification cost and improve the return on investment, automated attack classification can be performed based solely on the header information of the network log data. Specifically, before S103 above, the firewall for detecting automated attacks based on the large model may further include the following steps:

[0058] Extract the header information of each first network log data from multiple first network log data to obtain multiple first header information.

[0059] At this point, S103 above may include: inputting the first label and multiple first head information into the first large model to obtain the classification result.

[0060] In addition, to improve the accuracy of the primary model, a reward mechanism can be used to fine-tune it through reinforcement learning. Specifically, the aforementioned firewall for automated attack detection based on the primary model can also include the following two steps:

[0061] Based on the classification results, at least one reward signal is generated;

[0062] The first large model is fine-tuned using reinforcement learning with at least one reward signal.

[0063] In this disclosure, the aforementioned at least one reward signal may include the reward signal for the classification accuracy of the first large model (i.e., Figure 2 The accuracy reward shown), and the reward signal of the context window of the first large model (i.e. Figure 2 The reward for length of thought shown) and the reward signal for the readability of the classification results (i.e., the reward for length of thought shown) and the reward signal for readability of the classification results. Figure 2 The reward is at least one of the following: the thinking format reward shown. The context window of the first model refers to the length of contextual information considered by the first model during classification. Introducing multiple consideration signals can dynamically adjust the classification behavior of the first model, making it more aligned with the needs of the current classification task or user signals. The corresponding reward value can be obtained through a reward model or manual annotation, serving as the reward signal.

[0064] like Figure 2As shown, when fine-tuning the first large model using reinforcement learning with at least one reward signal, at least one reward signal can be input into the first large model. The first large model adjusts its parameters according to at least one reward signal, so that the machine classification model achieves optimal performance in terms of classification accuracy, length of contextual information considered during classification, and readability of classification results.

[0065] like Figure 2 As shown, when using the reward mechanism to fine-tune the first model through reinforcement learning, in order to improve the efficiency of reinforcement learning fine-tuning, the reward mechanism can be used to fine-tune the first model through the Low-Rank Adaptation (LoRA) fine-tuning technique.

[0066] In addition, to improve the accuracy of the first model's understanding of user needs and classification results, such as... Figure 2 As shown, prompt words can be used as input to the first large-scale model. Specifically, the firewall for automated attack detection based on the large-scale model described above can also include the following steps:

[0067] Obtain the first prompt word, which is used to guide the classification results of the first major model.

[0068] At this point, S103 may include inputting the first label, multiple first network log data, and the first prompt word into the first large model to obtain the classification result.

[0069] like Figure 2 Therefore, the prompt word (Insruction) can be: As an automated attack detection expert, given user log data, please determine whether the user is the source of an automated attack.

[0070] The following section details the fine-tuning methods for the first major model mentioned above. Specifically, it can be achieved through... Figure 3 The S201~S204 shown in the diagram are used to fine-tune the pre-trained large model to obtain the first large model.

[0071] In S201, a fine-tuning sample set is obtained, which includes multiple third-party network log data.

[0072] In S202, multiple third network log data are grouped according to users to obtain multiple second data groups.

[0073] like Figure 2 As shown, after obtaining multiple pieces of third network log data, these data can be associated with users based on the user identifiers in the third network log data. That is, multiple pieces of third network log data are grouped according to users to obtain multiple second data groups.

[0074] like Figure 2 As shown, third network log data containing _gid 1688… can be associated with user 1; and third network log data containing _gid 2455… can be associated with user 2.

[0075] In S203, for each of the multiple second data groups, the second data group is matched with the attack rules to obtain the second tag of the second user corresponding to the second data group, and the third tag of the second user is obtained.

[0076] In this disclosure, the second label is used to characterize whether there are automated attack features in the second data group, and the third label is used to characterize whether the second user is the source of the automated attack.

[0077] It should be noted that a similar method can be used, as described in S102 above, to match multiple first network log data with attack rules to obtain the first tag of the first user, to match the second data group with attack rules to obtain the second tag of the second user corresponding to the second data group. This disclosure will not elaborate further.

[0078] In 204, the model is fine-tuned by using the second label and the second data set as input to the large model and the third label as the target output of the large model to obtain the first large model.

[0079] In this disclosure, the second data set and the second label corresponding to the second data set can be used as a fine-tuning sample, thereby obtaining multiple fine-tuning samples, which can be used to fine-tune the large model.

[0080] like Figure 2 As shown, after obtaining the second label and the second data set (which constitutes the behavioral sequence sample), they can be converted into the input format of LLM, and then input into the large model to fine-tune the model parameters of the large model based on the difference between the model's predicted classification results and the third label.

[0081] When fine-tuning the large model, referencing a second label used to characterize the presence of automated attack features in the second dataset can improve the model's accuracy and training efficiency.

[0082] The following is a detailed description of the specific implementation method for obtaining the fine-tuning sample set in S201 above. Specifically, it can be implemented through various methods. In one implementation method, multiple original network log data can be obtained first, and then the multiple original network log data can be divided into a fine-tuning sample set and a test sample set according to a preset ratio (for example, 7:3).

[0083] In another implementation, multiple raw network log data entries can be acquired first; then, these entries can be segmented according to a time window to obtain multiple network log data segments, such as... Figure 2 As shown, multiple raw network log data entries are divided into four segments: Window1, Window2, Window3, and Window4. Figure 2 As shown, the time window length is 500s; then, the multiple network log data segments are divided into a fine-tuning sample set and a test sample set.

[0084] For example, if the raw network log data includes raw network log data within 2000 seconds before the current time, and the time window length is 500 seconds, then multiple raw network log data can be divided into 4 segments. The raw network log data within 0 seconds to 500 seconds before the current time constitutes one network log data segment, the raw network log data within 501 seconds to 1000 seconds before the current time constitutes another network log data segment, the raw network log data within 1001 seconds to 1500 seconds before the current time constitutes another network log data segment, and the raw network log data within 1500 seconds to 2000 seconds before the current time constitutes yet another network log data segment.

[0085] The fine-tuning sample set includes segments from multiple network log data. For example, if multiple original network log data are divided into 100 segments, and these original network log data are divided into a fine-tuning sample set and a test sample set in a 7:3 ratio, then the fine-tuning sample set includes 70 network log data segments, and the test sample set includes 30 network log data segments.

[0086] Since log data is contextually related, dividing the original log data into time windows before dividing the fine-tuning sample set and the test sample set can avoid disrupting the continuity of the log data, thereby improving the training speed and accuracy of the model.

[0087] In one possible implementation, the aforementioned third network log data includes header information and body information. Since automated attack characteristics are usually contained in the header information and rarely appear in the body information, in order to reduce the cost of model fine-tuning and improve the return on investment, model fine-tuning can be performed only based on the header information of the network log data. Specifically, before S202 above, the fine-tuning method of the aforementioned first model may also include the following steps:

[0088] Extract the header information of each third network log data from multiple third network log data to obtain multiple second header information;

[0089] At this point, 202 above may include: grouping multiple second header information according to users to obtain multiple second data groups.

[0090] In addition, to improve the efficiency of model fine-tuning, such as Figure 2 As shown, low-rank adaptive fine-tuning technology can be used to fine-tune the model parameters of large models. This involves introducing certain weights of the large model into low-rank decomposition to reduce the number of parameters required for model updates, thereby adjusting only some of the model's parameters. This reduces the computational cost and storage requirements of fine-tuning while maintaining the model's classification performance.

[0091] In addition, to improve the accuracy of the larger model, the fine-tuning method for the first larger model mentioned above can also include the following steps:

[0092] Obtain the second cue word, which is used to guide the output of the large model.

[0093] At this point, S204 may include: fine-tuning the model by using the second label, the second data set, and the second prompt word as input to the large model, and using the third label as the target output of the large model, to obtain the first large model.

[0094] Figure 4 This is a block diagram illustrating a firewall apparatus for detecting automated attacks based on a large model, according to an exemplary embodiment. Figure 4 As shown, the firewall device 300 for detecting automated attacks based on a large model includes:

[0095] The first acquisition module 301 is used to acquire multiple first network log data belonging to the first user;

[0096] The first determining module 302 is used to match the plurality of first network log data with attack rules to obtain the first tag of the first user, wherein the first tag is used to characterize whether there are automated attack features in the plurality of first network log data;

[0097] The classification module 303 is used to input the first label and the multiple first network log data into the first large model to obtain the classification result; wherein, the classification result is used to characterize whether the first user is an automated attack source, and the first large model is obtained by fine-tuning the pre-trained large model.

[0098] In the above technical solution, after acquiring multiple first network log data belonging to the first user, these first network log data can be matched with attack rules to obtain a first label characterizing whether automated attack characteristics exist in the multiple first network log data. Then, the first label and the multiple first network log data are input into a first large model to obtain a classification result characterizing whether the first user is the source of an automated attack. The first large model is obtained by fine-tuning a pre-trained large model. Thus, automated attack detection can be achieved through the first large model based on the large model, without the need for pre-setting statistical rules. It can also perform detection and analysis on all fields, not just general fields, thereby solving the problem of statistical methods failing to exhaustively cover all statistical scenarios and thus missing some cases. This improves the accuracy of automated attack detection, making it more universal and automated to adapt to increasingly flexible and diverse business types. Furthermore, using the first label characterizing whether automated attack characteristics exist in the multiple first network log data as input to the model can further improve the accuracy of automated attack detection.

[0099] Optionally, the first network log data includes header information and body information;

[0100] The firewall device 300 for detecting automated attacks based on a large model also includes:

[0101] Before the classification module 303 inputs the first label and the multiple first network log data into the first large model to obtain the classification result, the header information of each first network log data in the multiple first network log data is extracted to obtain multiple first header information;

[0102] The classification module 303 is used to input the first label and the plurality of first head information into the first large model to obtain the classification result.

[0103] Optionally, the attack rules include at least one of an automated attack IP address list and an automated attack user agent list, wherein the automated attack features include at least one of the automated attack IP and the automated attack user agent;

[0104] The first determining module 302 includes at least one of the following:

[0105] The first determining submodule is used to determine that there is an automated attack IP in the multiple first network log data if there is an IP address in the list of automated attack IP addresses among the IP addresses contained in the multiple first network log data.

[0106] The second determining submodule is used to determine that an automated attack user agent exists in the multiple first network log data if there is a user agent in the automated attack user agent list among the user agents included in the multiple first network log data.

[0107] Optionally, the firewall device 300 for detecting automated attacks based on a large model further includes:

[0108] A generation module is configured to generate at least one reward signal based on the classification result, wherein the at least one reward signal includes at least one of the following: a reward signal for the classification accuracy of the first large model, a reward signal for the context window of the first large model, and a reward signal for the readability of the classification result.

[0109] The reinforcement learning fine-tuning module is used to perform reinforcement learning fine-tuning on the first large model using the at least one reward signal.

[0110] Optionally, the firewall device 300 for detecting automated attacks based on a large model further includes:

[0111] The second acquisition module is used to acquire a first prompt word, wherein the first prompt word is used to guide the classification result of the first large model;

[0112] The classification module 303 is used to input the first label, the multiple first network log data, and the first prompt word into the first large model to obtain the classification result.

[0113] Optionally, the first acquisition module 301 includes:

[0114] The first acquisition submodule is used to acquire multiple pieces of second network log data;

[0115] The grouping submodule is used to group the multiple second network log data according to users to obtain multiple first data groups;

[0116] The third determining submodule is used to determine the first data group corresponding to the first user among the plurality of first data groups as the plurality of first network log data.

[0117] Optionally, the first label includes:

[0118] Classification information used to characterize whether the automated attack characteristics exist in the multiple first network log data; or

[0119] The automated attack characteristics and the classification information.

[0120] Optionally, the large model can be fine-tuned using the fine-tuning device 400 of the first large model to obtain the first large model. For example... Figure 5 As shown, the fine-tuning device 400 of the first large model includes:

[0121] The third acquisition module 401 is used to acquire a fine-tuning sample set, wherein the fine-tuning sample set includes multiple third network log data;

[0122] Grouping module 402 is used to group the multiple third network log data according to users to obtain multiple second data groups;

[0123] The second determining module 403 is used to match each of the plurality of second data groups with the attack rules to obtain a second tag of the second user corresponding to the second data group, and to obtain a third tag of the second user, wherein the second tag is used to characterize whether the automated attack features exist in the second data group, and the third tag is used to characterize whether the second user is an automated attack source.

[0124] The fine-tuning module 404 is used to fine-tune the model by taking the second label and the second data group as input to the large model and the third label as the target output of the large model, so as to obtain the first large model.

[0125] Optionally, the third acquisition module 401 includes:

[0126] The second acquisition submodule is used to acquire multiple raw network log data;

[0127] The segmentation submodule is used to segment the multiple original network log data according to time windows to obtain multiple segments of network log data;

[0128] The partitioning submodule is used to divide the multiple network log data segments into the fine-tuning sample set and the test sample set, wherein the fine-tuning sample set includes a portion of the multiple network log data segments.

[0129] Optionally, the third network log data includes header information and body information;

[0130] The fine-tuning device 400 of the first large model also includes:

[0131] The extraction module is used to extract the header information of each third network log data in the multiple third network log data before the grouping module 402 groups the multiple third network log data according to the user to obtain multiple second data groups, so as to obtain multiple second header information;

[0132] The grouping module 402 is used to group the plurality of second header information according to users to obtain the plurality of second data groups.

[0133] Optionally, the model parameters of the large model can be fine-tuned using low-rank adaptive fine-tuning techniques.

[0134] Optionally, the fine-tuning device 400 of the first large model further includes:

[0135] The fourth acquisition module is used to acquire the second prompt word, wherein the second prompt word is used to guide the output of the large model;

[0136] The fine-tuning module 404 is used to fine-tune the model by taking the second label, the second data group, and the second prompt word as inputs to the large model and taking the third label as the target output of the large model, so as to obtain the first large model.

[0137] In addition, this disclosure also provides a computer-readable medium having a computer program stored thereon, which, when executed by a processing device, implements the steps of the firewall method for detecting automated attacks based on a large model provided in this disclosure.

[0138] This disclosure also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the firewall method for detecting automated attacks based on a large model provided in this disclosure.

[0139] The following is for reference. Figure 6 The diagram illustrates a structural schematic of an electronic device (e.g., a terminal device or a server) 600 suitable for implementing embodiments of the present disclosure. The terminal device in the embodiments of the present disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 6 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments disclosed herein.

[0140] like Figure 6As shown, electronic device 600 may include a processing device (e.g., a central processing unit, a graphics processor, etc.) 601, which can perform various appropriate actions and processes according to a program stored in read-only memory (ROM) 602 or a program loaded from storage device 608 into random access memory (RAM) 603. RAM 603 also stores various programs and data required for the operation of electronic device 600. Processing device 601, ROM 602, and RAM 603 are interconnected via bus 604. Input / output (I / O) interface 605 is also connected to bus 604.

[0141] Typically, the following devices can be connected to I / O interface 605: input devices 606 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 607 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 608 including, for example, magnetic tapes, hard disks, etc.; and communication devices 609. Communication device 609 allows electronic device 600 to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 6 An electronic device 600 with various devices is shown; however, it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed alternatively.

[0142] In particular, according to embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device 609, or installed from a storage device 608, or installed from a ROM 602. When the computer program is executed by the processing device 601, it performs the functions defined in the methods of embodiments of this disclosure.

[0143] It should be noted that the computer-readable medium described in this disclosure can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this disclosure, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this disclosure, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.

[0144] In some implementations, clients and servers can communicate using any currently known or future-developed network protocol such as HTTP (Hypertext Transfer Protocol) and can interconnect with digital data communication (e.g., communication networks) of any form or medium. Examples of communication networks include local area networks (“LANs”), wide area networks (“WANs”), the Internet (e.g., the Internet of Things), and peer-to-peer networks (e.g., ad hoc peer-to-peer networks), as well as any currently known or future-developed networks.

[0145] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device.

[0146] The aforementioned computer-readable medium carries one or more programs that, when executed by the electronic device, cause the electronic device to: acquire multiple pieces of first network log data belonging to a first user; match the multiple pieces of first network log data with attack rules to obtain a first label for the first user, wherein the first label is used to characterize whether there are automated attack features in the multiple pieces of first network log data; input the first label and the multiple pieces of first network log data into a first large model to obtain a classification result; wherein the classification result is used to characterize whether the first user is an automated attack source, and the first large model is obtained by fine-tuning the pre-trained large model.

[0147] Computer program code for performing the operations of this disclosure can be written in one or more programming languages ​​or a combination thereof, including but not limited to object-oriented programming languages ​​such as Java, Smalltalk, and C++, as well as conventional procedural programming languages ​​such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0148] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0149] The modules described in the embodiments of this disclosure can be implemented in software or in hardware. The name of a module does not necessarily limit the module itself; for example, the first acquisition module can also be described as "a module that acquires multiple pieces of first network log data belonging to a first user".

[0150] The functions described above in this document can be performed at least in part by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip (SoCs), complex programmable logic devices (CPLDs), and so on.

[0151] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0152] According to one or more embodiments of this disclosure, Example 1 provides a firewall method for detecting automated attacks based on a large model, comprising:

[0153] Retrieve multiple first network log entries belonging to the first user;

[0154] The multiple first network log data are matched with attack rules to obtain the first tag of the first user, wherein the first tag is used to characterize whether there are automated attack features in the multiple first network log data;

[0155] The first label and the multiple first network log data are input into the first large model to obtain the classification result; wherein, the classification result is used to characterize whether the first user is an automated attack source, and the first large model is obtained by fine-tuning the pre-trained large model.

[0156] According to one or more embodiments of this disclosure, Example 2 provides the method of Example 1, wherein the first network log data includes header information and body information;

[0157] Before the step of inputting the first label and the plurality of first network log data into the first large model to obtain the classification result, the method further includes: extracting the header information of each first network log data in the plurality of first network log data to obtain a plurality of first header information;

[0158] The step of inputting the first tag and the multiple first network log data into the first large model to obtain the classification result includes: inputting the first tag and the multiple first header information into the first large model to obtain the classification result.

[0159] According to one or more embodiments of this disclosure, Example 3 provides the method of Example 1, wherein the attack rules include at least one of an automated attack IP address list and an automated attack user agent list, wherein the automated attack features include at least one of automated attack IPs and automated attack user agents;

[0160] The step of matching the multiple first network log data with the attack rules to obtain the first user's first tag includes at least one of the following:

[0161] If any of the IP addresses contained in the plurality of first network log data are IP addresses that are in the list of automated attack IP addresses, then it is determined that there is an automated attack IP address in the plurality of first network log data.

[0162] If any of the user agents included in the plurality of first network log data are user agents listed in the automated attack user agent list, then it is determined that an automated attack user agent exists in the plurality of first network log data.

[0163] According to one or more embodiments of this disclosure, Example 4 provides the method of Example 1, the method further comprising:

[0164] Based on the classification result, at least one reward signal is generated, wherein the at least one reward signal includes at least one of the following: a reward signal for the classification accuracy of the first large model, a reward signal for the context window of the first large model, and a reward signal for the readability of the classification result.

[0165] The first large model is fine-tuned using reinforcement learning with the at least one reward signal.

[0166] According to one or more embodiments of this disclosure, Example 5 provides the method of Example 1, the method further comprising:

[0167] Obtain the first prompt word, wherein the first prompt word is used to guide the classification result of the first large model;

[0168] The step of inputting the first tag and the multiple first network log data into the first large model to obtain the classification result includes: inputting the first tag, the multiple first network log data, and the first prompt word into the first large model to obtain the classification result.

[0169] According to one or more embodiments of this disclosure, Example 6 provides the method described in Example 1, wherein obtaining multiple first network log data belonging to a first user includes:

[0170] Retrieve multiple second network log entries;

[0171] The multiple second network log data are grouped according to users to obtain multiple first data groups;

[0172] The first data group corresponding to the first user among the plurality of first data groups is determined as the plurality of first network log data.

[0173] According to one or more embodiments of this disclosure, Example 7 provides the method of Example 1, wherein the first label includes:

[0174] Classification information used to characterize whether the automated attack characteristics exist in the multiple first network log data; or

[0175] The automated attack characteristics and the classification information.

[0176] According to one or more embodiments of this disclosure, Example 8 provides a method of any one of Examples 1-7 to fine-tune the large model to obtain the first large model in the following manner:

[0177] Obtain a fine-tuning sample set, wherein the fine-tuning sample set includes multiple third-party network log data;

[0178] The multiple third network log data are grouped according to users to obtain multiple second data groups;

[0179] For each of the plurality of second data groups, the second data group is matched with the attack rules to obtain a second tag for the second user corresponding to the second data group, and a third tag for the second user is obtained. The second tag is used to characterize whether the automated attack features exist in the second data group, and the third tag is used to characterize whether the second user is an automated attack source.

[0180] The first large model is obtained by fine-tuning the model by using the second label and the second data set as inputs to the large model and the third label as the target output of the large model.

[0181] According to one or more embodiments of this disclosure, Example 9 provides the method of Example 8, wherein obtaining the fine-tuned sample set includes:

[0182] Obtain multiple raw network log data entries;

[0183] The original network log data is segmented according to time windows to obtain multiple segments of network log data;

[0184] The multiple network log data segments are divided into the fine-tuning sample set and the test sample set, wherein the fine-tuning sample set includes a portion of the multiple network log data segments.

[0185] According to one or more embodiments of this disclosure, Example 10 provides the method of Example 8, wherein the third network log data includes header information and body information;

[0186] Before the step of grouping the multiple third network log data according to users to obtain multiple second data groups, the fine-tuning method of the first large model further includes:

[0187] Extract the header information of each third network log data from the multiple third network log data to obtain multiple second header information;

[0188] The process of grouping the multiple third network log data according to users to obtain multiple second data groups includes:

[0189] The multiple second header information is grouped according to the user to obtain the multiple second data groups.

[0190] According to one or more embodiments of this disclosure, Example 11 provides the method of Example 8, which uses low-rank adaptive fine-tuning techniques to fine-tune the model parameters of the large model.

[0191] According to one or more embodiments of this disclosure, Example 12 provides the method of Example 8, wherein the fine-tuning of the first large model further includes:

[0192] Obtain a second prompt word, wherein the second prompt word is used to guide the output of the large model;

[0193] The method of fine-tuning the model by using the second label and the second data set as input to the large model and the third label as the target output of the large model to obtain the first large model includes:

[0194] The first large model is obtained by fine-tuning the model by using the second label, the second data group, and the second prompt word as inputs to the large model and using the third label as the target output of the large model.

[0195] According to one or more embodiments of this disclosure, Example 13 provides a firewall apparatus for detecting automated attacks based on a large model, comprising:

[0196] The first acquisition module is used to acquire multiple first network log data belonging to the first user;

[0197] The first determining module is used to match the plurality of first network log data with attack rules to obtain the first tag of the first user, wherein the first tag is used to characterize whether there are automated attack features in the plurality of first network log data;

[0198] The classification module is used to input the first label and the multiple first network log data into the first large model to obtain the classification result; wherein, the classification result is used to characterize whether the first user is an automated attack source, and the first large model is obtained by fine-tuning the pre-trained large model.

[0199] According to one or more embodiments of the present disclosure, Example 14 provides a computer-readable medium having a computer program stored thereon that, when executed by a processing device, implements the steps of the method described in any one of Examples 1-12.

[0200] According to one or more embodiments of this disclosure, Example 15 provides an electronic device, including:

[0201] A storage device on which computer programs are stored;

[0202] A processing device for executing the computer program in the storage device to implement the steps of any one of the methods in Examples 1-12.

[0203] According to one or more embodiments of the present disclosure, Example 16 provides a computer program product including a computer program that, when executed by a processor, implements the steps of the method described in any one of Examples 1-12.

[0204] The above description is merely a preferred embodiment of this disclosure and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features disclosed in this disclosure that have similar functions.

[0205] Furthermore, while the operations are described in a specific order, this should not be construed as requiring these operations to be performed in the specific order shown or in a sequential order. In certain environments, multitasking and parallel processing may be advantageous. Similarly, while several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of this disclosure. Certain features described in the context of individual embodiments may also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments.

[0206] Although the subject matter has been described using language specific to structural features and / or methodological logic, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are merely illustrative forms of implementing the claims. Regarding the apparatus in the above embodiments, the specific manner in which the various modules perform their operations has been described in detail in the embodiments relating to the method, and will not be elaborated upon here.

Claims

1. A firewall method for detecting automated attacks based on a large model, characterized in that, include: Retrieve multiple first network log entries belonging to the first user; The multiple first network log data are matched with attack rules to obtain the first tag of the first user, wherein the first tag is used to characterize whether there are automated attack features in the multiple first network log data; The first label and the multiple first network log data are input into the first large model to obtain the classification result; wherein, the classification result is used to characterize whether the first user is an automated attack source, and the first large model is obtained by fine-tuning the pre-trained large model; The first large model is obtained by fine-tuning the large model in the following way: Obtain a fine-tuning sample set, wherein the fine-tuning sample set includes multiple third-party network log data; The multiple third network log data are grouped according to users to obtain multiple second data groups; For each of the plurality of second data groups, the second data group is matched with the attack rules to obtain a second tag for the second user corresponding to the second data group, and a third tag for the second user is obtained. The second tag is used to characterize whether the automated attack features exist in the second data group, and the third tag is used to characterize whether the second user is an automated attack source. The first large model is obtained by fine-tuning the model by using the second label and the second data set as inputs to the large model and the third label as the target output of the large model.

2. The method according to claim 1, characterized in that, The first network log data includes header information and body information; Before the step of inputting the first label and the plurality of first network log data into the first large model to obtain the classification result, the method further includes: extracting the header information of each first network log data in the plurality of first network log data to obtain a plurality of first header information; The step of inputting the first tag and the multiple first network log data into the first large model to obtain the classification result includes: inputting the first tag and the multiple first header information into the first large model to obtain the classification result.

3. The method according to claim 1, characterized in that, The attack rules include at least one of the automated attack IP address list and the automated attack user agent list, wherein the automated attack features include at least one of the automated attack IP and the automated attack user agent; The step of matching the multiple first network log data with the attack rules to obtain the first user's first tag includes at least one of the following: If any of the IP addresses contained in the plurality of first network log data are IP addresses that are in the list of automated attack IP addresses, then it is determined that there is an automated attack IP address in the plurality of first network log data. If any of the user agents included in the plurality of first network log data are user agents listed in the automated attack user agent list, then it is determined that an automated attack user agent exists in the plurality of first network log data.

4. The method according to claim 1, characterized in that, The method further includes: Based on the classification result, at least one reward signal is generated, wherein the at least one reward signal includes at least one of the following: a reward signal for the classification accuracy of the first large model, a reward signal for the context window of the first large model, and a reward signal for the readability of the classification result. The first large model is fine-tuned using reinforcement learning with the at least one reward signal.

5. The method according to claim 1, characterized in that, The method further includes: Obtain the first prompt word, wherein the first prompt word is used to guide the classification result of the first large model; The step of inputting the first tag and the multiple first network log data into the first large model to obtain the classification result includes: inputting the first tag, the multiple first network log data, and the first prompt word into the first large model to obtain the classification result.

6. The method according to claim 1, characterized in that, The acquisition of multiple first network log data belonging to the first user includes: Retrieve multiple second network log entries; The multiple second network log data are grouped according to their respective users to obtain multiple first data groups; The first data group corresponding to the first user among the plurality of first data groups is determined as the plurality of first network log data.

7. The method according to claim 1, characterized in that, The first tag includes: Classification information used to characterize whether the automated attack characteristics exist in the multiple first network log data; or The automated attack characteristics and the classification information.

8. The method according to claim 1, characterized in that, The acquisition of the fine-tuning sample set includes: Obtain multiple raw network log data entries; The original network log data is segmented according to time windows to obtain multiple segments of network log data; The multiple network log data segments are divided into the fine-tuning sample set and the test sample set, wherein the fine-tuning sample set includes a portion of the multiple network log data segments.

9. The method according to claim 1, characterized in that, The third network log data includes header information and body information; Before the step of grouping the multiple third network log data according to users to obtain multiple second data groups, the fine-tuning method of the first large model further includes: Extract the header information of each third network log data from the multiple third network log data to obtain multiple second header information; The process of grouping the multiple third network log data according to users to obtain multiple second data groups includes: The multiple second header information is grouped according to the user to obtain the multiple second data groups.

10. The method according to claim 1, characterized in that, The model parameters of the large model are fine-tuned using low-rank adaptive fine-tuning techniques.

11. The method according to claim 1, characterized in that, The fine-tuning methods for the first large model also include: Obtain a second prompt word, wherein the second prompt word is used to guide the output of the large model; The method of fine-tuning the model by using the second label and the second data set as input to the large model and the third label as the target output of the large model to obtain the first large model includes: The first large model is obtained by fine-tuning the model by using the second label, the second data group, and the second prompt word as inputs to the large model and using the third label as the target output of the large model.

12. A firewall device for detecting automated attacks based on a large model, characterized in that, include: The first acquisition module is used to acquire multiple first network log data belonging to the first user; The first determining module is used to match the plurality of first network log data with attack rules to obtain the first tag of the first user, wherein the first tag is used to characterize whether there are automated attack features in the plurality of first network log data; The classification module is used to input the first label and the multiple first network log data into the first large model to obtain the classification result; wherein, the classification result is used to characterize whether the first user is an automated attack source, and the first large model is obtained by fine-tuning the pre-trained large model through the fine-tuning device of the first large model; The fine-tuning device for the first large model includes: The third acquisition module is used to acquire a fine-tuning sample set, wherein the fine-tuning sample set includes multiple third network log data; The grouping module is used to group the multiple third network log data according to users to obtain multiple second data groups; The second determining module is used to match each of the plurality of second data groups with the attack rules to obtain a second tag of the second user corresponding to the second data group, and to obtain a third tag of the second user, wherein the second tag is used to characterize whether the automated attack features exist in the second data group, and the third tag is used to characterize whether the second user is an automated attack source. The fine-tuning module is used to fine-tune the model by using the second label and the second data set as inputs to the large model and the third label as the target output of the large model, so as to obtain the first large model.

13. A computer-readable medium having a computer program stored thereon, characterized in that, When executed by a processing device, the computer program performs the steps of the method described in any one of claims 1-11.

14. An electronic device, characterized in that, include: A storage device on which computer programs are stored; A processing device for executing the computer program in the storage device to implement the steps of the method according to any one of claims 1-11.

15. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1-11.

Citation Information

Patent Citations

  • Question and answer model training method and device, question and answer method and device and readable storage medium

    CN119848208A

  • Network security auxiliary system based on large model and construction method

    CN119996028A