Safe operation system of intelligent computing proprietary cloud center
By building a security operation system for the intelligent computing proprietary cloud center and utilizing modules such as data collection and enrichment, and autonomous agent artificial intelligence language models, we have achieved an intelligent closed-loop security response for the intelligent computing center, solving the problems of untimely response and lack of in-depth analysis in the existing system, and improving the efficiency and adaptability of security operations.
Patent Information
- Application Number
- CN202510894975.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-30
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2045-06-30
AI Technical Summary
The existing intelligent computing proprietary cloud center security operation system does not respond in a timely manner and does not conduct in-depth analysis. It lacks the ability to adapt to complex scenarios such as multi-tenants, multiple models, and heterogeneous computing power. It is difficult to effectively deal with dynamic attacks and abnormal behaviors, and there is a problem of isolated security operations.
By adopting data collection and enrichment modules, response planning modules based on autonomous agent artificial intelligence language models, task decomposition and script generation modules, human-machine verification modules, execution modules and monitoring and feedback modules, combined with vector databases, we build a smart computing proprietary cloud center security operation system to achieve intelligent closed-loop security response.
It significantly shortens the closed-loop response time for high-risk incidents, improves the coverage of automated disposal, bridges the linkage gap between computing power business and security operations, and provides a forward-looking security protection system to adapt to the security protection needs of highly complex computing environments.
Smart Images

Figure CN120675780A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of cloud computing technology, and in particular to a secure operation system for an intelligent computing proprietary cloud center. Background Art
[0002] With the rapid development of computing-intensive businesses like artificial intelligence and big data, intelligent computing dedicated cloud centers, serving as the core infrastructure supporting intelligent computing tasks, have gradually become key resource nodes for key industries such as scientific research, high-end manufacturing, and energy. Intelligent computing dedicated cloud centers integrate high-performance resources such as large-scale GPUs and AI accelerators. Their operating environment faces a highly complex network structure and widely open access rights, making them a key target for emerging attacks such as advanced persistent threats (APTs) and supply chain attacks.
[0003] At present, although some intelligent computing proprietary cloud centers have deployed traditional SOAR platforms for unified orchestration of security tools and automated processing of security incidents, these systems are mostly built based on static templates and preset processes, and lack the ability to adapt to complex scenarios such as multi-tenant, multi-model, and heterogeneous computing power in intelligent computing environments. It is difficult to respond to dynamic attacks and abnormal behaviors against intelligent computing resources in a timely and accurate manner, and there are problems such as untimely response, lack of in-depth analysis, and isolated security operations. Summary of the Invention
[0004] In view of the above technical problems, the present invention provides a smart computing proprietary cloud center security operation system to solve the problems of untimely response, lack of in-depth analysis, and isolated security operations in the cloud center in the existing technology.
[0005] Other features and advantages of the present invention will become apparent from the following detailed description, or may be learned in part by practice of the present invention.
[0006] According to the present invention, a security operation system for a dedicated intelligent computing cloud center is proposed, and the security operation system includes: The data collection and enrichment module is used to collect security event data from security information system and event management system logs, terminal telemetry, and threat intelligence data. The module enriches the security event data, maps the extracted attack information to the MITRE ATT&CK knowledge base, and standardizes the event process based on the five-stage processing structure of the cybersecurity response model to generate structured technical steps and assess the event risk. A response planning module based on a language model of autonomous agent artificial intelligence, the response planning module is used to analyze the enriched security event data using an integrated large-scale language model and automatically generate a response plan for the security event data, the response plan including multiple ordered technical mitigation steps; A task decomposition and script generation module is used to decompose the response plan into a sequence of executable subtasks, evaluate the target system environment and collect feedback information from previous tasks, adjust subsequent action steps based on quantitative risk assessment, and automatically build corresponding mitigation scripts; A human-machine verification module is used to provide a human-machine interactive interface for security analysts to review and adjust the technical steps before executing the mitigation script, and submit the response plan for execution after approval and confirmation; An execution module, configured to invoke security tools and agents to execute the mitigation script on the target system according to the verified response scheme, including utilizing static and dynamic analysis tools to detect malicious files and behaviors, triggering active response actions to block malicious network connections and isolate infected hosts, dynamically executing customized scripts through a code interpreter, and sending commands to distributed terminals through a WebSocket proxy client to obtain execution results; A monitoring and feedback module is used to continuously monitor the security status of the target environment after the execution module completes all the mitigation scripts, evaluate the threat elimination effect, compare the execution results with expectations, and trigger the response planning module to adjust the response plan and iteratively execute it if residual threats are found. The effective response action results are stored in the knowledge base for continuous optimization, forming a closed-loop security response process that combines investigation, verification, and active monitoring; A vector database is used to store vectorized representations of historical security event data and corresponding response measures, wherein the response planning module and the task decomposition and script generation module retrieve historical event information with similar characteristics to the current event based on the vector database to provide decision support.
[0007] Furthermore, the response planning module adopts a multi-agent architecture, which includes at least two large-scale language model agents with different functions and an agent routing unit; wherein, one of the large-scale language model agents focuses on wide-area security policy analysis, general text processing and strategic threat mitigation, and the other large-scale language model agent focuses on deep security analysis and advanced query parsing; the agent routing unit assigns the security event data analysis and response generation requests to the corresponding large-scale language model agent for processing based on predefined routing rules, model expertise or real-time performance indicators, and enhances the analysis of event context information in combination with similar case retrieval results of the vector database.
[0008] Furthermore, the vector database stores vectorized feature representations of the historical security event data and corresponding handling records. The response planning module generates a query vector based on the current security event and performs a similarity search in the vector database to retrieve historical events and their response measures that are similar to the current event in attack characteristics or context, and uses the retrieval results to assist the large language model agent in formulating corresponding response plans.
[0009] Furthermore, the task decomposition and script generation module specifically includes a step splitting submodule, an environment assessment submodule, a risk assessment submodule and a script construction submodule; the step splitting submodule is used to divide the response plan into several independently executable technical steps; the environment assessment submodule is used to collect status information of the target system before and after the execution of each technical step, and dynamically adjust the execution strategy of the subsequent steps according to the feedback results of the previous step; the risk assessment submodule is used to evaluate the possible impact and risk level of each technical step, and adjust and optimize the response plan under high-risk situations; the script construction submodule is used to automatically generate corresponding executable scripts or instruction sequences according to the technical steps to implement corresponding threat mitigation operations.
[0010] Furthermore, the execution module includes static and dynamic analysis components, active response components, a code interpreter and a remote execution proxy client; the static and dynamic analysis components are used to perform static analysis and dynamic behavior monitoring on target files and processes during the response execution process to detect potential malicious code and abnormal activities; the active response component is used to automatically execute real-time threat containment measures, and the containment measures include blocking malicious IP addresses, isolating infected hosts, and deploying security patches to stop the spread of attacks; the code interpreter is used to dynamically interpret or run code snippets when executing the mitigation script to support custom script execution and unconventional response steps; the remote execution proxy client communicates with the central orchestration service through a persistent network connection, receives commands issued by the task decomposition and script generation module in real time, executes the commands on distributed target hosts, and transmits the execution results and related feedback to the monitoring and feedback module.
[0011] Furthermore, the human-machine verification module has a manual review interface, which enables security analysts to review and edit the automatically generated technical steps before the response plan is executed, so that only the response plan that has been manually verified and approved is executed by the execution module, thereby introducing expert judgment into the automated response process to improve the accuracy and effectiveness of the response measures.
[0012] Furthermore, after executing all steps of the response plan, the monitoring and feedback module continuously monitors the security status of the target system and evaluates whether the threat has been completely eliminated; if residual malicious activities or new abnormal signs are detected, the response planning module is triggered to update the response plan and iteratively execute the newly added mitigation script; for response measures that successfully eliminate the threat, the monitoring and feedback module marks the result as verified and stores it in the vector database or knowledge base, so that the security operation system can refer to the verified disposal strategy in subsequent security event data, thereby achieving continuous improvement in the active monitoring stage.
[0013] The technical solution of the present invention has the following beneficial effects: This invention provides a hyper-automated security orchestration and response security operations system for intelligent computing proprietary cloud centers. By integrating large-scale language models with Agentic AI technology, it enables intelligent, closed-loop security response for highly complex computing environments. The system understands security data from diverse components, including GPU nodes, AI containers, and computing power scheduling platforms, and automatically generates context-aware response strategies to meet the high-concurrency, multi-scenario, and multi-attack chain security protection requirements of intelligent computing centers.
[0014] Furthermore, while ensuring intelligent and rapid responses, this invention introduces a vector database to achieve event similarity matching and experience reuse, and ensures the safety and controllability of key mitigation operations through a human-machine collaborative mechanism. This invention significantly shortens the closed-loop response time for high-risk events, improves the coverage of automated disposal, and effectively bridges the gap between computing power services and security operations. It possesses scalable and self-evolving security operational capabilities, providing a forward-looking security protection system support for intelligent computing infrastructure. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Figure 1 This is a structural block diagram of a smart computing proprietary cloud center security operation system in an embodiment of this specification. DETAILED DESCRIPTION
[0016] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be implemented in many forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that the present invention will be more comprehensive and complete and the concepts of the example embodiments will be fully conveyed to those skilled in the art. The described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments. In the following description, many specific details are provided to provide a full understanding of the embodiments of the present invention. However, those skilled in the art will appreciate that the technical solutions of the present invention may be practiced while omitting one or more of the specific details, or that other methods, components, devices, steps, etc. may be employed. In other cases, well-known technical solutions are not shown or described in detail to avoid obscuring various aspects of the present invention.
[0017] The accompanying drawings are merely schematic illustrations of the present invention. Identical reference numerals in the drawings denote identical or similar components, and thus repetitive descriptions thereof will be omitted. Some of the blocks shown in the accompanying drawings represent functional entities that do not necessarily correspond to physically or logically independent entities. These functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.
[0018] The present invention provides a product intelligent computing proprietary cloud center security operation system. Figure 1 The figure shows a block diagram of a security operation system for a dedicated intelligent computing cloud center according to an embodiment of the present invention. The security operation system includes: The data collection and enrichment module 101 is used to collect security event data, which is derived from security information system and event management system logs, terminal telemetry and threat intelligence data, and to enrich the security event data. The extracted attack information is mapped to the MITRE ATT&CK knowledge base, and the event process is standardized and decomposed with reference to the five-stage processing structure in the network security response model to generate structured technical steps, while assessing the event risk.
[0019] Data collection and enrichment module 101 is used to collect multi-source data related to current security incidents. This data includes, but is not limited to, security information and event management (SIEM) logs, terminal telemetry data, and intelligence data from external threat intelligence sources (such as IOC platforms, APT intelligence reports, and known attack indicator libraries). This module uses a multi-dimensional collection mechanism to form a contextual understanding of attack behavior. Combined with forensic analysis, it identifies the root cause of the incident and potential threat vectors, prioritizing attack paths involving high-value assets and critical vulnerabilities.
[0020] During the process of semantically understanding and structuring the collected data, this module maps attack indicators and behavioral information to the MITRE ATT&CK attack technical knowledge base, standardizing the raw data into comparable and actionable technical steps. Furthermore, the module divides the incident lifecycle into phases, drawing on leading international cybersecurity response models (such as the five-phase structure of the NIST framework: identify, protect, detect, respond, and recover), to assist subsequent modules in planning phased response strategies.
[0021] To further enhance the scientific nature and controllability of incident response, the Data Collection and Enrichment Module 101 uses QRA (Quantitative Risk Assessment) methodology to quantify and score the risk factors involved in an incident. This categorization creates risk level labels based on incident severity, attack complexity, propagation path, and resource impact, serving as a crucial reference for prioritizing response plans and assigning strategies. Through this mechanism, the Data Collection and Enrichment Module supports the initial phase of the "investigation-verification-active monitoring" closed-loop structure, providing high-quality, structured, and traceable threat information for subsequent response planning and task orchestration.
[0022] A response planning module 102 based on a language model of autonomous agent artificial intelligence is used to analyze the enriched security event data using an integrated large-scale language model and automatically generate a response plan for the security event data, wherein the response plan includes multiple ordered technical mitigation steps.
[0023] Among them, the response planning module 102 is based on autonomous agent artificial intelligence technology and integrates multiple large-scale language models with different functions to conduct in-depth semantic analysis of structured security event data processed by the data collection and enrichment module. The response planning module 102 adopts the Agentic AI method to identify attack paths and infer potential impacts in the enriched event context through the language model agent, and automatically generates a response plan for the current security incident based on historical event response experience. The response plan can cover multiple aspects such as attack tracing, initial containment, threat mitigation, and system repair, and also outputs multiple orderly technical mitigation steps in a structured form. Each step can be executed independently and can be dynamically adjusted to adapt to the current target environment. The response plan generated by this type of model is flexible, adaptable, and semantically coherent, which can significantly improve the efficiency and accuracy of response decisions in complex scenarios, avoid the drawbacks of fixed script templates and rigid rules in traditional SOAR platforms, and thus support intelligent, context-driven network security automatic response processes.
[0024] The task decomposition and script generation module 103 is used to decompose the response plan into an executable subtask sequence, evaluate the target system environment and collect feedback information of the previous tasks, adjust subsequent action steps based on the quantitative risk assessment, and automatically construct the corresponding mitigation script.
[0025] Among them, the task decomposition and script generation module 103 is specifically used to refine the response plan generated by the language model, specifically including breaking the response plan into a set of executable subtask sequences with a logical sequence relationship, and dynamically evaluating the reachability and impact range of each task in combination with the current target system's operating environment, resource status, and permission configuration. The task decomposition and script generation module 103 further supports real-time adjustment of the execution conditions and paths of subsequent tasks based on the execution feedback of the previous task, especially when the development trend of the security incident changes, with the ability to flexibly reconstruct the response chain. In addition, the task decomposition and script generation module 103 can have a built-in risk quantification model to score the potential system impact, security benefits, and business interruption costs of each mitigation step, and sort and filter tasks based on the risk-benefit ratio to ensure that the system balances security and availability during execution. After the task logic is confirmed, the task decomposition and script generation module 103 can automatically build a standardized mitigation script based on the task type and target environment. It supports multiple scripting languages or command interfaces, such as Bash, PowerShell, Python, YARA rules, etc., to achieve cross-platform automated execution.
[0026] The human-machine verification module 104 is used to provide a human-machine interactive interface for security analysts to review and adjust the technical steps before executing the mitigation script, and submit the response plan for execution after approval and confirmation.
[0027] Among them, the human-machine verification module 104 is used to provide a manual review mechanism after the security operation system automatically generates a response plan and before the mitigation script is officially executed, constructing a visual human-machine interaction interface for security analysts to intervene and operate. This module allows analysts to view the response steps planned by the language model, the task decomposition results, and the automatically constructed script content, review, adjust, or overwrite each technical step one by one, and judge the necessity and risk of script execution based on contextual information. The module is equipped with an interrupt mechanism that can manually terminate the automatic issuance of specific steps in high-risk or uncertain scenarios to prevent misoperation or excessive response. Only tasks that have been manually reviewed and approved can enter the final execution process, ensuring that expert judgment is embedded in intelligent automation and balancing system autonomy and security controllability.
[0028] The execution module 105 is used to call security tools and agents to execute the mitigation script on the target system according to the verified response plan. During execution, it includes using static and dynamic analysis tools to detect malicious files and behaviors, triggering active response actions to block malicious network connections and isolate infected hosts, dynamically executing customized scripts through a code interpreter, and sending commands to distributed terminals through a WebSocket proxy client to obtain execution results.
[0029] Execution module 105 is used to invoke preconfigured security tools and endpoint agents based on manually verified response plans to automatically implement mitigation actions on target systems. Execution module 105 encompasses multiple execution paths: First, it utilizes static analysis tools (such as signature-based scanners) and a dynamic behavioral analysis engine to deeply inspect malicious and suspicious files to identify potential attack payloads or hidden behavior chains. Second, it triggers built-in active response policies to block detected malicious network connections and isolate infected hosts to prevent lateral movement of attacks. For complex or unstructured tasks, the execution module can also embed a code interpreter that parses and executes dynamically generated script instructions in real time to meet differentiated response requirements. Furthermore, execution module 105 can deploy a WebSocket protocol proxy client to maintain persistent connections with large-scale distributed terminals, enabling immediate command issuance and transmission of execution results, ensuring efficient, secure, and verifiable command transmission within the closed response loop.
[0030] The monitoring and feedback module 106 is used to continuously monitor the security status of the target environment after the execution module completes all the mitigation scripts, evaluate the threat elimination effect, compare the execution results with expectations, and trigger the response planning module to adjust the response plan and iteratively execute if any residual threats are found, and store the effective response action results in the knowledge base for continuous optimization, forming a closed-loop security response process that combines investigation, verification and active monitoring.
[0031] Among them, the monitoring and feedback module 106 is used to continuously monitor the operating status of the target system after the execution module completes all mitigation scripts, and actively evaluate whether the threat has been completely eliminated. The monitoring and feedback module 106 collects data such as terminal behavior, network traffic and asset status in real time, and compares and analyzes it with the security baseline and preset mitigation effect before the response to determine whether the threat still exists and whether new abnormal indicators appear. When residual attack behavior or execution deviation is detected, the system will automatically trigger the response planning module to re-evaluate the current event context and adjust the response strategy to form an iterative closed loop. For cases of successful mitigation, the monitoring and feedback module 106 will archive the corresponding execution steps, key judgment basis and disposal results into the knowledge base as a reference for subsequent event similarity matching and response strategy recommendation. In addition, the monitoring and feedback module 106 adopts a three-stage response model of "investigation-verification-active monitoring" to achieve self-evolution and long-term optimization of response capabilities while ensuring closed-loop control.
[0032] The vector database 107 is used to store the vectorized representation of the historical security event data and the corresponding response measures, wherein the response planning module and the task decomposition and script generation module retrieve historical event information with similar characteristics to the current event based on the vector database to provide decision support.
[0033] Specifically, the vector database 107 is used to efficiently store the semantic vector representations of historical security events and their corresponding response and disposal measures. The vector representation is generated by encoding structured security events (including attack paths, attack techniques, environmental characteristics, etc.) using a large model or a specific embedding mechanism, thereby preserving contextual features and attack behavior semantics. The vector database 107 supports vector similarity retrieval. The response planning module and the task decomposition and script generation module can generate query vectors based on the current pending event and compare them with historical data to screen out historical cases that are highly similar to the current event in terms of attack method, asset impact range, or mitigation path. The response steps or mitigation scripts in these similar cases can then be evaluated, reconstructed, and reused as candidate solutions, providing data-driven decision support for the current response process, significantly improving planning efficiency and action reliability, and promoting the continuous learning and evolution capabilities of the entire system.
[0034] In one embodiment, the response planning module adopts a multi-agent architecture, which includes at least two large-scale language model agents with different functions and an agent routing unit; wherein, one of the large-scale language model agents focuses on wide-area security policy analysis, general text processing and strategic threat mitigation, and the other large-scale language model agent focuses on deep security analysis and advanced query parsing; the agent routing unit assigns the security event data analysis and response generation requests to the corresponding large-scale language model agent for processing based on predefined routing rules, model expertise or real-time performance indicators, and enhances the analysis of event context information in combination with similar case retrieval results from the vector database.
[0035] Specifically, the response planning module 102 utilizes a multi-agent architecture to support intelligent response decisions in complex threat environments. This multi-agent architecture includes at least two large language model (LLM) agents with distinct functionalities, and an agent routing unit for intelligent task allocation. Specifically, one LLM agent performs broad-area security policy analysis, general text semantic processing, and strategic threat mitigation tasks, excelling at developing comprehensive response strategies from a macro perspective. The other LLM agent focuses on fine-grained security event analysis and complex semantic query parsing, suitable for handling in-depth investigations and technical detail assessments. To achieve efficient division of labor, the agent routing unit dynamically and intelligently routes security event analysis requests and response generation tasks to the appropriate LLM agent based on predefined routing rules, model expertise, or real-time performance metrics. To enhance the completeness and accuracy of the response context, each LLM agent automatically retrieves historical event records from a vector database during processing. Using a vector similarity matching mechanism, it retrieves cases similar to the current event in terms of attack structure, technical path, and contextual patterns. These cases serve as auxiliary knowledge injection to enhance understanding of the current event and tailor the response strategy. By building a multi-agent collaborative architecture and combining semantic intelligent routing with similar case enhancement mechanisms, we have achieved explainable, high-precision, and self-learning security response decision-making capabilities, effectively breaking through the technical bottlenecks of script solidification and knowledge silos in traditional SOAR systems.
[0036] In one embodiment, the vector database stores vectorized feature representations of historical security event data and corresponding handling records. The response planning module generates a query vector based on the current security event and performs a similarity search in the vector database to retrieve historical events and their response measures that are similar to the current event in attack characteristics or context, and uses the retrieval results to assist the large language model agent in formulating corresponding response plans.
[0037] Specifically, the vector database 107 is used to store vectorized feature representations of historical security events and their corresponding response and disposition records. The vectorized features are generated by embedding and calculating the contextual information, attack techniques, affected systems, and response results of the security event using a language model or embedding model, forming a high-dimensional semantic vector that supports semantic similarity retrieval. Each record in the database not only retains the structural description of the event but also includes the mitigation measures taken at the time and the execution feedback, forming a complete empirical knowledge entry. During operation, the response planning module inputs the current security event to be analyzed into the large language model agent for preprocessing, generating a semantically representative query vector. This query vector is then used as a search key to perform a similarity search in the vector database to find historical event records that are similar to the current event in terms of attack structure, behavioral characteristics, asset impact, and other aspects. The retrieved similar events and their corresponding response steps are injected into the large language model agent as prompts, assisting it in formulating more reasonable and empirically supported response strategies, thereby improving the accuracy, execution success rate, and industry adaptability of the response plan. Through a similarity matching mechanism driven by a vector database, an intelligent response system with the capabilities of "case reuse" and "experience self-evolution" was constructed, which enables knowledge reuse and solution migration in a dynamic threat environment, effectively enhancing the generalization capability of response planning and the credibility of decision-making.
[0038] In one embodiment, the task decomposition and script generation module specifically includes a step splitting submodule, an environment assessment submodule, a risk assessment submodule and a script construction submodule; the step splitting submodule is used to divide the response plan into a number of independently executable technical steps; the environment assessment submodule is used to collect status information of the target system before and after the execution of each technical step, and dynamically adjust the execution strategy of the subsequent steps according to the feedback results of the previous step; the risk assessment submodule is used to evaluate the possible impact and risk level of each technical step, and adjust and optimize the response plan under high-risk situations; the script construction submodule is used to automatically generate corresponding executable scripts or instruction sequences according to the technical steps to implement corresponding threat mitigation operations.
[0039] Specifically, the task decomposition and script generation module 103 further includes a step decomposition submodule, an environment assessment submodule, a risk assessment submodule, and a script construction submodule, which are used to achieve a structured transformation from response strategies to executable operations. The step decomposition submodule receives the overall response plan generated by the language model agent and breaks it down into several independently executable technical steps with clear semantic boundaries. The environment assessment submodule calls the target system's status interface before and after each technical step to collect environmental information (including system status, network connectivity, service operation status, etc.), and dynamically adjusts subsequent operational processes based on the execution feedback of the current step. For example, if the previous step fails to successfully block the threat or the system returns an abnormal status code, a backup path will be automatically triggered or the priority will be adjusted. The risk assessment submodule is used to evaluate the potential impact of each technical step on the target system, including the possibility of service interruption, resource utilization, potential side effects, etc., and generates a risk level label based on quantitative criteria. If a certain operational step is determined to be high-risk or a critical path node, the language model will be used to replan the response plan to avoid systemic damage. The script construction submodule is responsible for converting the decomposed and adjusted technical steps into a specific executable instruction sequence. Supported output formats include but are not limited to Bash / Python scripts, PowerShell commands, YARA rules, or API call configurations. During the script generation process, the module considers factors such as the operating system type of the execution host, command compatibility, and environment variables to ensure cross-platform consistency and security. Through the coordinated operation of these four submodules, the security operations system can complete the policy implementation and operational execution of the automated response process while ensuring execution effectiveness and system stability, building an intelligent security execution system with high scalability and dynamic adaptability.
[0040] In one embodiment, the execution module includes a static and dynamic analysis component, an active response component, a code interpreter, and a remote execution proxy client; the static and dynamic analysis component is used to perform static analysis and dynamic behavior monitoring on target files and processes during the response execution process to detect potential malicious code and abnormal activities; the active response component is used to automatically execute real-time threat containment measures, and the containment measures include blocking malicious IP addresses, isolating infected hosts, and deploying security patches to stop the spread of attacks; the code interpreter is used to dynamically interpret or run code snippets when executing the mitigation script to support custom script execution and unconventional response steps; the remote execution proxy client communicates with the central orchestration service through a persistent network connection, receives commands issued by the task decomposition and script generation module in real time, executes the commands on distributed target hosts, and transmits the execution results and related feedback to the monitoring and feedback module.
[0041] The static and dynamic analysis components are used to comprehensively inspect target files, processes, and behavioral paths during the response execution process, identifying potential malicious code and abnormal behavior. Static analysis locks down suspicious objects through hash matching and signature scanning, while dynamic analysis monitors indicators such as system calls, memory changes, and external behavior. To support dynamic and flexible responses, this embodiment also includes an embedded code interpreter that can parse and run custom script code output by the task decomposition and script generation module in real time during execution. This is particularly suitable for scenarios where the response plan includes unconventional processes, interactive commands, or platform-specific scripts. The remote execution proxy client is deployed in distributed terminals or controlled nodes and maintains communication with the central orchestration service through a persistent connection (such as the WebSocket protocol). Upon receiving a task command, the client immediately parses the instruction and executes it in the local system environment. At the same time, it transmits the task execution status, return output, and exception information back to the monitoring and feedback module in real time, serving as one of the key feedback nodes in the closed-loop process.
[0042] In one embodiment, the human-machine verification module has a manual review interface, which enables security analysts to review and edit the automatically generated technical steps before the response plan is executed, so that only the response plan that has been manually verified and approved is executed by the execution module, thereby introducing expert judgment into the automated response process to improve the accuracy and effectiveness of the response measures.
[0043] Among them, the manual review interface can display the complete technical steps and mitigation scripts automatically generated by the response planning module and the task decomposition module in a visual form for security analysts to review, adjust, reorganize or confirm item by item. When analysts identify unreasonable instructions, potential misjudgments or the need for additional strategies, they can edit or overwrite the relevant steps before execution to prevent the automated system from making inappropriate responses in unknown or uncertain situations. By embedding a manual verification process, the human-machine verification module described in the present invention introduces a layer of expert decision-making guarantee mechanism for the fully automatic response process, which effectively reduces the risk of misjudgment and over-response while ensuring execution efficiency. It is particularly suitable for critical business systems that need to ensure continuity and high availability in intelligent computing private cloud environments.
[0044] In one embodiment, after executing all steps of the response plan, the monitoring and feedback module continuously monitors the security status of the target system and evaluates whether the threat is completely eliminated; if residual malicious activities or new abnormal signs are detected, the response planning module is triggered to update the response plan and iteratively execute the newly added mitigation script; for response measures that successfully eliminate the threat, the monitoring and feedback module marks the result as verified and stores it in the vector database or knowledge base, so that the security operation system can refer to the verified disposal strategy in subsequent security event data, thereby achieving continuous improvement in the active monitoring stage.
[0045] Among them, by collecting data such as system behavior, network traffic, service status and user activity logs in real time, and comparing them with the baseline status before mitigation and the expected response results, it is possible to identify whether there are residual threats, abnormal behaviors or new signs of intrusion. When it is detected that the anomaly persists or new signs of threats appear, the monitoring and feedback module will automatically trigger the response planning module to update the response plan, and iteratively generate a new mitigation script, which will be sent to the target environment again through task decomposition and execution path, thereby realizing a closed-loop iteration of the response process. For mitigation operations that successfully eliminate threats, the system will mark the execution results as "verified passed" and store them in the form of structured records in the vector database or knowledge base as an experience data resource for subsequent security incident analysis and response generation. By embedding the closed loop of monitoring-evaluation-feedback-learning into the automated response process, this module realizes a continuous improvement mechanism under the active monitoring stage, significantly improving the adaptive defense and regeneration capabilities of the security operation system in highly complex environments such as intelligent computing private clouds.
[0046] As demonstrated in the aforementioned implementations, the present invention provides a hyper-automated security orchestration and response security operations system for intelligent computing private cloud centers. This system integrates large-scale language models with Agentic AI technology to achieve intelligent, closed-loop security response for highly complex computing environments. The system understands security data from diverse components, including GPU nodes, AI containers, and computing power scheduling platforms, and automatically generates context-aware response strategies to meet the high-concurrency, multi-scenario, and multi-attack chain security protection requirements of intelligent computing centers.
[0047] Furthermore, while ensuring intelligent and rapid responses, this invention introduces a vector database to achieve event similarity matching and experience reuse, and ensures the safety and controllability of key mitigation operations through a human-machine collaborative mechanism. This invention significantly shortens the closed-loop response time for high-risk events, improves the coverage of automated disposal, and effectively bridges the gap between computing power services and security operations. It possesses scalable and self-evolving security operational capabilities, providing a forward-looking security protection system support for intelligent computing infrastructure.
[0048] Through the description of the above embodiments, it is easy for those skilled in the art to understand that the example embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solution according to the embodiment of the present invention can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes a number of instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the exemplary embodiment of the present invention.
[0049] Furthermore, the figures above are merely illustrative of the processes included in the method according to exemplary embodiments of the present invention and are not intended to be limiting. It is readily understood that the processes illustrated in the figures above do not indicate or limit the temporal order of these processes. Furthermore, it is readily understood that these processes may be executed synchronously or asynchronously, for example, in multiple modules.
[0050] It should be noted that, although several modules or units of the device for action execution are mentioned in the above detailed description, this division is not mandatory. In fact, according to an exemplary embodiment of the present invention, the features and functions of two or more modules or units described above can be concretized in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided into multiple modules or units to be concretized.
[0051] Those skilled in the art will readily identify other embodiments of the present invention after considering the specification and practicing the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein. The description and embodiments are to be considered as exemplary only, with the true scope and spirit of the invention being indicated by the claims.
[0052] It should be understood that the present invention is not limited to the exact construction described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present invention is limited only by the appended claims.
Claims
1. A smart computing proprietary cloud center security operation system, characterized by: The security operation system includes: The data collection and enrichment module is used to collect security event data from security information system and event management system logs, terminal telemetry, and threat intelligence data. The module enriches the security event data, maps the extracted attack information to the MITRE ATT&CK knowledge base, and standardizes the event process based on the five-stage processing structure of the cybersecurity response model to generate structured technical steps and assess the event risk. A response planning module based on a language model of autonomous agent artificial intelligence, the response planning module is used to analyze the enriched security event data using an integrated large-scale language model and automatically generate a response plan for the security event data, the response plan including multiple ordered technical mitigation steps; A task decomposition and script generation module is used to decompose the response plan into a sequence of executable subtasks, evaluate the target system environment and collect feedback information from previous tasks, adjust subsequent action steps based on quantitative risk assessment, and automatically build corresponding mitigation scripts; A human-machine verification module is used to provide a human-machine interactive interface for security analysts to review and adjust the technical steps before executing the mitigation script, and submit the response plan for execution after approval and confirmation; An execution module, configured to invoke security tools and agents to execute the mitigation script on the target system according to the verified response scheme, including utilizing static and dynamic analysis tools to detect malicious files and behaviors, triggering active response actions to block malicious network connections and isolate infected hosts, dynamically executing customized scripts through a code interpreter, and sending commands to distributed terminals through a WebSocket proxy client to obtain execution results; A monitoring and feedback module is used to continuously monitor the security status of the target environment after the execution module completes all the mitigation scripts, evaluate the threat elimination effect, compare the execution results with expectations, and trigger the response planning module to adjust the response plan and iteratively execute it if residual threats are found. The effective response action results are stored in the knowledge base for continuous optimization, forming a closed-loop security response process that combines investigation, verification, and active monitoring; A vector database is used to store vectorized representations of historical security event data and corresponding response measures, wherein the response planning module and the task decomposition and script generation module retrieve historical event information with similar characteristics to the current event based on the vector database to provide decision support.
2. The intelligent computing private cloud center security operation system according to claim 1 is characterized in that: The response planning module adopts a multi-agent architecture, which includes at least two large-scale language model agents with different functions and an agent routing unit; wherein, one of the large-scale language model agents focuses on wide-area security policy analysis, general text processing and strategic threat mitigation, and the other large-scale language model agent focuses on deep security analysis and advanced query parsing; the agent routing unit assigns the security event data analysis and response generation requests to the corresponding large-scale language model agent for processing based on predefined routing rules, model expertise or real-time performance indicators, and enhances the analysis of event context information in combination with similar case retrieval results from the vector database.
3. The intelligent computing private cloud center security operation system according to claim 1 is characterized in that: The vector database stores the vectorized feature representation of the historical security event data and the corresponding handling records. The response planning module generates a query vector based on the current security event and performs a similarity search in the vector database to retrieve historical events and their response measures that are similar to the current event in attack characteristics or context. The retrieval results are used to assist the large language model agent in formulating corresponding response plans.
4. The intelligent computing private cloud center security operation system according to claim 1 is characterized in that: The task decomposition and script generation module specifically includes a step splitting submodule, an environment assessment submodule, a risk assessment submodule and a script construction submodule; the step splitting submodule is used to divide the response plan into several independently executable technical steps; the environment assessment submodule is used to collect the status information of the target system before and after the execution of each technical step, and dynamically adjust the execution strategy of the subsequent steps according to the feedback results of the previous step; the risk assessment submodule is used to evaluate the possible impact and risk level of each technical step, and adjust and optimize the response plan in high-risk situations; the script construction submodule is used to automatically generate corresponding executable scripts or instruction sequences according to the technical steps to implement corresponding threat mitigation operations.
5. The intelligent computing private cloud center security operation system according to claim 1 is characterized in that: The execution module includes static and dynamic analysis components, an active response component, a code interpreter, and a remote execution proxy client; the static and dynamic analysis components are used to perform static analysis and dynamic behavior monitoring on target files and processes during the response execution process to detect potential malicious code and abnormal activities; the active response component is used to automatically execute real-time threat containment measures, such as blocking malicious IP addresses, isolating infected hosts, and deploying security patches to stop the spread of attacks; the code interpreter is used to dynamically interpret or run code snippets when executing the mitigation script to support customized script execution and unconventional response steps; The remote execution agent client communicates with the central orchestration service through a persistent network connection, receives commands issued by the task decomposition and script generation module in real time, executes the commands on the distributed target host, and transmits the execution results and related feedback to the monitoring and feedback module.
6. The intelligent computing private cloud center security operation system according to claim 1 is characterized in that: The human-machine verification module has a manual review interface, which enables security analysts to review and edit the automatically generated technical steps before the response plan is executed, so that only the response plan that has been manually verified and approved is executed by the execution module, thereby introducing expert judgment into the automated response process to improve the accuracy and effectiveness of the response measures.
7. The intelligent computing private cloud center security operation system according to claim 1 is characterized in that: After executing all steps of the response plan, the monitoring and feedback module continuously monitors the security status of the target system and assesses whether the threat has been completely eliminated; if residual malicious activity or new abnormal signs are detected, the response planning module is triggered to update the response plan and iteratively execute the newly added mitigation script; For response measures that successfully eliminate threats, the monitoring and feedback module marks the results as verified and stores them in the vector database or knowledge base, so that the security operation system can refer to the verified disposal strategy in subsequent security event data, thereby achieving continuous improvement in the active monitoring stage.
Citation Information
Patent Citations
SOAR automatic arrangement and response network security system
CN116346441A
Method for realizing security arrangement automation and response based on large language model
CN117828602A
Information security risk assessment whole-process management system
CN119939591A
Network security compliance intelligent protection system for enterprise multi-source data fusion
CN119966735A