Intelligent device security threat collaborative analysis method
By constructing a fusion security threat intelligence knowledge graph and layered network for smart devices, combined with a large language model, the problem of fragmented security analysis for smart devices is solved, enabling collaborative analysis of information security and functional safety, and improving the efficiency and coverage of threat analysis.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-03
- Publication Date
- 2026-03-24
AI Technical Summary
Existing security analysis technologies for smart devices separate information security from functional safety, resulting in fragmented intelligence information that is difficult to analyze comprehensively and cannot form effective collaborative protection.
We construct a knowledge graph that integrates information security and functional safety threat intelligence, perform automated analysis using a large language model, and combine it with the hardware and software architecture of smart devices to achieve entity recognition and relationship extraction from multi-source heterogeneous data. We then build a layered and integrated security network for collaborative threat analysis.
It enables multi-dimensional and hierarchical threat analysis of smart devices, improving the coverage and efficiency of threat analysis, breaking the limitations of traditional independent analysis, and generating threat description texts for different security systems and business scenarios.
Smart Images

Figure CN120750582B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of intelligent device technology, and more specifically, relates to a collaborative analysis method for security threats to intelligent devices. Background Technology
[0002] Intelligent devices are electronic devices with sensing, computing, connectivity, and interaction capabilities. They have been deeply integrated into all aspects of social production and daily life, becoming a core driving force for technological and economic development in the digital age. The information security and functional safety of intelligent devices are crucial for their stable and reliable operation. Conducting systematic and comprehensive security threat analysis helps to adopt effective protection measures against different security threats, protecting them from malicious attacks, data breaches, and functional abuse.
[0003] Traditional functional safety analysis focuses primarily on system anomalies caused by physical component failures, neglecting functional anomalies triggered by non-physical interference sources such as cyberattacks. Recent research and practice have shown that in smart devices, cybersecurity incidents often trigger functional safety failures, and vice versa, exhibiting a clear coupling and interaction relationship. Against this backdrop, existing security analysis techniques face numerous limitations, particularly the disconnect between cybersecurity and functional safety development processes, which hinders the effective synergy of security protection systems for smart devices. Furthermore, the lack of effective correlation between existing cybersecurity threat intelligence and functional safety threat intelligence, coupled with fragmented information, makes comprehensive analysis of both cybersecurity threats and functional safety hazards difficult. Summary of the Invention
[0004] The purpose of this invention is to overcome the shortcomings of existing technologies and provide a collaborative analysis method for security threats to smart devices. By constructing a knowledge graph that integrates information security and functional safety threat intelligence, it collaboratively analyzes multi-source heterogeneous security information and uses a large language model to achieve automatic analysis of security threats to smart devices, thereby improving the coverage and efficiency of threat analysis.
[0005] To achieve the above-mentioned objectives, the intelligent device security threat collaborative analysis method of the present invention includes the following steps:
[0006] S1: Collect TARA and HARA data from several smart devices; for each TARA data point, extract the natural language description of the damage scenario and attack path to form an information security threat scenario description text, and then extract the assets and corresponding keyword sets, including vulnerability keywords and exploit keywords; for each HARA data point, extract the natural language description of the damage scenario and attack path to form a functional safety threat scenario description text, and then extract the functional systems and corresponding keyword sets, including failure mode keywords and application environment keywords; use the assets or functional systems corresponding to each data point and the corresponding keyword set as input, and the corresponding threat scenario description text as output, to form training samples for fine-tuning the large language model;
[0007] S2: Select a large language model according to actual needs, and fine-tune the large language model using the training samples of the large language model obtained in step S1;
[0008] S3: Collect information security threat intelligence data and functional safety threat intelligence data of smart devices according to actual needs. The information security threat intelligence data includes smart device asset data, vulnerability data, weakness data and attack pattern data, while the functional safety threat intelligence data includes smart device functional system data, failure mode data and application environment data.
[0009] S4: For information security threat intelligence data, associate assets, vulnerabilities, weaknesses and attack patterns in different data, and then construct an information security knowledge graph. The nodes include assets, vulnerabilities, weaknesses and attack patterns, and the relationships include the relationship between vulnerabilities and assets, the relationship between vulnerabilities and weaknesses, and the relationship between weaknesses and attack patterns.
[0010] For functional safety threat intelligence data, functional systems and failure modes in different data are associated, and the application environment of the accident is classified according to the preset scenario characteristics to obtain several typical application environments. Failure modes and application environments are matched by keywords in the description of failure modes and application environments to realize the association between failure modes and application environments. Then, a functional safety knowledge graph is constructed, where nodes include functional systems, failure modes and application environments, and relationships include the association between functional systems and failure modes, and the association between failure modes and application environments.
[0011] S5: Match the descriptive keywords of vulnerabilities, weaknesses and attack patterns in the information security knowledge graph with the failure modes in the functional safety knowledge graph. If the match is successful, establish a relationship in the corresponding node; otherwise, do not perform any operation, thereby integrating the information security knowledge graph and the functional safety knowledge graph into a fused knowledge graph.
[0012] S6: Builds a layered, converged security network based on the hardware and software architecture of smart devices, including four analysis layers:
[0013] 1) The business scenario layer includes the functional business of smart devices;
[0014] 2) The functional system layer includes the functional systems corresponding to each business scenario;
[0015] 3) The component layer includes the key components that constitute the functional system;
[0016] 4) The component asset layer includes the specific assets within the component;
[0017] S7: Perform integrated security threat analysis on the business scenario to be analyzed, including the following steps:
[0018] S7.1: For the business scenario to be analyzed, analyze the key functional systems involved in the business scenario and decompose the relevant components and their corresponding component assets;
[0019] S7.2: For the decomposed component assets, retrieve their related information security elements in the integrated security knowledge graph, including vulnerabilities, weaknesses, and attack patterns associated with the component assets. Extract the corresponding vulnerability keywords and weakness keywords from the knowledge graph to form a keyword set. Input the asset and keyword set into the fine-tuned large language model to obtain the information security threat scenario description text of the business scenario to be analyzed.
[0020] S7.3: For the key functional systems mapped out and the information security elements associated with the previous step, match and integrate the functional security elements in the security knowledge graph, including the fault modes and application environments associated with the functional systems. Extract the corresponding fault mode keywords and application environment keywords from the knowledge graph to form a keyword set. Input the functional systems and keyword set into the fine-tuned large language model to obtain the functional security threat scenario description text of the business scenario to be analyzed.
[0021] This invention discloses a collaborative analysis method for security threats to intelligent devices. It extracts training samples of a large language model from the TARA and HARA datasets of intelligent devices, fine-tunes the large language model, collects information security threat intelligence data and functional safety threat intelligence data from intelligent devices, constructs information security knowledge graphs and functional safety knowledge graphs, integrates them into a fused knowledge graph, and then constructs a layered fused security network based on the hardware and software architecture of the intelligent devices. Finally, based on the fused knowledge graph and the layered fused security network, it analyzes to obtain assets, functional systems, and corresponding keyword sets, inputting these into the fine-tuned large language model to generate corresponding threat scenario description text.
[0022] The present invention has the following beneficial effects:
[0023] 1) This invention performs entity recognition and relationship extraction on multi-source heterogeneous data of security threat intelligence fused from smart devices, designs a method for associating information such as assets, vulnerabilities, weaknesses, functional systems, failure modes and application environments of smart devices, and constructs a visualized and reasonable fused security knowledge graph to realize semantic expression and query between assets, vulnerabilities, functional systems and failure modes.
[0024] 2) This invention establishes a multi-dimensional, hierarchical integrated security threat analysis framework from the perspective of intelligent device hardware and software architecture and typical business scenarios. It breaks through the limitations of traditional independent analysis of information security and functional safety, and realizes collaborative security element management and integrated threat analysis.
[0025] 3) This invention takes typical business scenarios as its starting point, and gradually parses out the functional system and asset information related to the scenario by layering and integrating security networks and knowledge graphs. Combined with a large language model, it realizes an automated threat analysis process, which can generate threat analysis description text for different security systems and typical business scenarios, thereby improving the efficiency of threat analysis. Attached Figure Description
[0026] Figure 1 This is a structural diagram illustrating a specific implementation of the intelligent device security threat collaborative analysis method of the present invention;
[0027] Figure 2 This is an example diagram of the information security knowledge graph in this embodiment;
[0028] Figure 3 This is a flowchart illustrating the integration of security threat analysis in this invention. Detailed Implementation
[0029] The specific embodiments of the present invention will now be described with reference to the accompanying drawings to enable those skilled in the art to better understand the invention. It should be particularly noted that in the following description, detailed descriptions of known functions and designs that might obscure the main content of the invention will be omitted here.
[0030] Example
[0031] Figure 1 This is a structural diagram illustrating a specific implementation of the intelligent device security threat collaborative analysis method of the present invention. (See diagram below.) Figure 1 As shown, the specific steps of the intelligent device security threat collaborative analysis method of the present invention include:
[0032] S101: Obtain training samples:
[0033] In this invention, to achieve integrated security threat analysis of smart devices, including information security threat analysis and functional safety threat analysis, a large language model is required. To adapt this large language model to the application environment of this invention, fine-tuning is necessary; therefore, training samples need to be constructed for the large language model. TARA (Threat Analysis and Risk Assessment) is a core method for assessing the security of smart devices, while HARA (Harm Analysis and Risk Assessment) is a method for identifying and assessing potential hazards of smart devices. Therefore, this invention extracts training samples from the TARA and HARA datasets, specifically as follows:
[0034] Collect TARA and HARA data from several smart devices. For each TARA data point, extract natural language descriptions of the damage scenario and attack path to form an information security threat scenario description text. Then, extract assets and corresponding keyword sets, including vulnerability keywords and exploit keywords. For each HARA data point, extract natural language descriptions of the damage scenario and attack path to form a functional safety threat scenario description text. Then, extract functional systems and corresponding keyword sets, including failure mode keywords and application environment keywords. Use the keyword set corresponding to each TARA data point as input and the corresponding threat scenario description text as output to form training samples for fine-tuning the large language model.
[0035] Through the above processing, the TARA and HARA data can be transformed into training datasets suitable for fine-tuning large language models. Table 1 is an example table of training samples in this embodiment.
[0036]
[0037] Table 1
[0038] In practical applications, the collected TARA and HARA data can first be cleaned and preprocessed, including removing duplicate data and filtering noisy data. Keyword extraction can be done manually or using algorithms.
[0039] S102: Fine-tuning the large language model:
[0040] Select a large language model according to actual needs, and fine-tune the large language model using the training samples obtained in step S101.
[0041] In this embodiment, approximately 70%-80% of the data from all large language model training samples is selected as the training set for training the large language model; approximately 10%-15% of the data is selected as the validation set for adjusting hyperparameters during model training; and approximately 10%-15% of the data is retained as the test set for evaluating the final performance of the model. In this embodiment, the large language model fine-tuning employs the LoRA (Low-Rank Adaptation of Large Language Models) fine-tuning algorithm. This method achieves targeted enhancement of the model's capabilities by inserting trainable low-rank matrices into a portion of the model's attention weight matrix, while avoiding the computational cost and overfitting risks associated with large-scale parameter updates. Compared to traditional full-parameter fine-tuning, LoRA significantly reduces the size of the training parameters.
[0042] Furthermore, since this invention produces two types of output: information security threat scenario description text and functional safety threat scenario description text, to differentiate between these two types of threat scenario description text and improve the accuracy of threat analysis, a structured prompt can be preset for both information security threat analysis and functional safety threat analysis. The prompt is then populated with corresponding keyword sets before being input into the large language model. For example, the prompt for information security threat analysis is as follows: "Please perform a threat analysis on the asset based on the following: Asset: [Field to be filled]. Vulnerability keywords: [Field to be filled]. Vulnerability keywords: [Field to be filled]." The prompt for functional safety threat analysis is as follows: "Please perform a threat analysis on the functional system based on the following: Functional system: [Field to be filled]. Failure mode keywords: [Field to be filled]. Application environment keywords: [Field to be filled]."
[0043] S103: Obtain raw security threat intelligence data:
[0044] To subsequently build a converged security knowledge graph for smart devices, information security threat intelligence data and functional safety threat intelligence data for smart devices are first collected according to actual needs. The information security threat intelligence data includes smart device asset data, vulnerability data, weakness data, and attack pattern data, while the functional safety threat intelligence data includes smart device functional system data, failure mode data, and application environment data.
[0045] In this embodiment, information security threat intelligence data is extracted from publicly available CVE (Common Vulnerabilities and Exposures) datasets, CPE (Common Platform Enumeration) datasets, CWE (Common Weakness Enumeration) datasets, and CAPEC (Common Attack Pattern Enumeration and Classification) datasets. CVE and CPE data can be accessed via a RESTful API provided by the NVD (National Vulnerability Database) website, and the data format is a structured JSON file. CVEs provide vulnerability IDs, affected components, vulnerability descriptions, and mappings to CPEs and CWEs. CPEs identify the specific software or hardware platform involved in the vulnerability (such as a specific processor type, operating system version, etc.). CWE and CAPEC data are typically published in CSV table format, including vulnerability IDs, vulnerability descriptions, category labels, and mappings to other attack patterns.
[0046] Functional safety threat intelligence data can be obtained from historical fault reports of smart devices. For example, functional safety threat intelligence data for smart cars can be extracted from publicly released vehicle recall records and road accident investigation data.
[0047] In practical applications, to make the knowledge graph generated later more accurate, the original security threat intelligence data can be cleaned and preprocessed, including removing duplicate data, filling in missing values, and standardizing data formats to ensure compatibility and consistency between various data sources.
[0048] S104: Constructing a knowledge graph:
[0049] For information security threat intelligence data, assets, vulnerabilities, weaknesses, and attack patterns in different data are associated, and then an information security knowledge graph is constructed. The nodes include assets, vulnerabilities, weaknesses, and attack patterns, and the relationships include the association between vulnerabilities and assets (i.e., the asset has a vulnerability), the association between vulnerabilities and weaknesses (the vulnerability has a corresponding weakness), and the association between weaknesses and attack patterns.
[0050] In this embodiment, based on the "cpe_match" and "problemtype" fields of the CVE entry, vulnerability records are associated with corresponding CWE and CPE information, respectively. Simultaneously, the "Related Weaknesses" field in the CWE entry establishes a hierarchical relationship with other vulnerabilities, and the "Related Attack Patterns" field establishes a semantic mapping between CWE and CAPEC attack patterns. CAPEC, in turn, establishes a hierarchical relationship with other attack patterns through the "Related Attack Patterns" field. Figure 2 This is an example diagram of the information security knowledge graph in this embodiment. For example... Figure 2 As shown, the information security knowledge graph displays the relationships between various types of information security threat intelligence.
[0051] For functional safety threat intelligence data, functional systems and failure modes in different data are associated, and the application environment of the accident is classified according to the preset scenario characteristics to obtain several typical application environments. Failure modes and application environments are matched by keywords in the description of failure modes and application environments to realize the association between failure modes and application environments. Then, a functional safety knowledge graph is constructed, where nodes include functional systems, failure modes and application environments, and relationships include the association between functional systems and failure modes, and the association between failure modes and application environments.
[0052] This embodiment uses a smart car as an example to illustrate its functional safety threat intelligence data. Based on the functional system field and fault description field in the recall data, fault modes can be extracted and their correlation with functional systems can be constructed. For example, some recall records for steering systems show problems such as power steering failure or steering wheel sticking. Table 2 is an example table of the correlation between functional systems and fault modes in this embodiment.
[0053]
[0054] Table 2
[0055] When extracting typical application environments, scene features can be selected based on the actual application environment of the smart device. For example, for automobiles, conditions such as weather, road conditions, and lighting conditions can be used. Then, keyword matching methods are used to associate the application environment with specific fault modes. For example, if the description of a fault mode includes phrases such as "the vehicle's steering system lags during a turn," the fault mode can be associated with the application environment of "curved road sections."
[0056] S105: Constructing a Fusion Knowledge Graph
[0057] This method involves matching descriptive keywords of vulnerabilities, weaknesses, and attack patterns in the information security knowledge graph with failure modes in the functional safety knowledge graph. If a match is found, a relationship is established in the corresponding node; otherwise, no action is taken. This integrates the information security and functional safety knowledge graphs into a fused knowledge graph. By merging the two knowledge graphs into a single structured knowledge graph, potential connections between information security and functional safety entities can be identified, effectively demonstrating the relationships between various information items and providing support for the generation of subsequent damage and hazard scenarios.
[0058] The specific method for keyword matching in this embodiment is as follows: For two nodes to be matched, the TF-IDF algorithm is used to obtain candidate keywords from the descriptions of the two nodes respectively, and the KeyBERT algorithm is used to extract keywords from the candidate keywords of the two nodes. Then, the BERT model is used to obtain the embedding vector of each keyword. For each node, the semantic embedding of the node is generated based on the embedding vectors of all its keywords (e.g., averaging the embedding vectors of all keywords). The similarity between the semantic embeddings of the two nodes to be matched is calculated. If the similarity is greater than a preset threshold, the match is successful; otherwise, the match fails.
[0059] S106: Building a Layered and Unified Security Network
[0060] A layered, converged security network is constructed based on the hardware and software architecture of smart devices to support hierarchical modeling and graded analysis of converged security threats. This network vertically decomposes key security elements involved in typical business scenarios, forming a multi-level mapping relationship from system behavior to underlying assets. Specifically, this layered, converged security network includes the following four analysis layers:
[0061] 1) The business scenario layer includes the functional business of smart devices, such as remote communication and target recognition. This layer focuses on high-level functional behaviors that are perceptible to users, serving as the initial entry point for scenario-driven security analysis.
[0062] 2) The functional system layer includes the functional systems corresponding to various business scenarios, such as the perception fusion system, the execution control system, and the infotainment system. This layer focuses on the functional boundaries and collaboration mechanisms of intelligent devices and is an important node for integrated security analysis.
[0063] 3) The component layer includes key components that make up the functional system, such as cameras, radar, actuators, and electronic control units. This layer is a further refinement of the functional system layer.
[0064] 4) The component asset layer includes specific assets within the component, such as specific software modules, operating system platforms, communication protocol stacks, and hardware chips. These are the security analysis elements within the component, corresponding to the attack surface and risk points in the field of information security.
[0065] By modeling the mapping relationships at the four levels mentioned above, the semantic path between "business scenario – functional system – component – component asset" is established. With typical business scenarios, functional systems, and component assets as the core analysis dimensions, a multi-layered integrated security mapping system from scenario-driven to component implementation is established.
[0066] S107: Integrated Security Threat Analysis
[0067] Building upon a layered, converged security network, information security elements such as vulnerabilities, weaknesses, and attack patterns, as well as functional security elements such as failure modes and application environments, are introduced and associated with the asset and functional system layers, respectively. This allows for the construction of a vertical analysis pathway from a converged security perspective, resulting in a security threat model that supports multi-dimensional converged threat analysis. This model is used to identify potential security issues in business scenarios across both information security and functional security dimensions. The security threat model primarily includes the following three dimensions:
[0068] 1) Layered dimensions of converged security network: Based on the layered converged security network, typical business scenarios of smart devices are divided into four layers.
[0069] 2) Security Element Integration Dimension: Threat analysis elements are divided into information security and functional security dimensions. In terms of information security, the focus is on the relationship between assets and their associated vulnerabilities, weaknesses, and attack patterns; in terms of functional security, the combination and matching of functional systems, failure modes, and application environments are considered.
[0070] 3) Integrating threat analysis dimensions: In terms of information security, from the perspective of threats / attacks, identify the loss of information security attributes such as authenticity, freshness, integrity, and confidentiality of component assets; in terms of functional safety, from the perspective of hazards / failures, and based on the decomposition of functional safety-critical systems, identify possible failure modes and corresponding hazard events.
[0071] Based on this integrated security threat model, integrated security threat analysis of smart devices can be achieved. In order to achieve unified identification and collaborative assessment of information security threats and functional safety hazards in smart devices, this invention takes business-driven approaches as its starting point, uses the functional business scenarios of smart devices as the analysis entry point, and unfolds threat identification and analysis tasks step by step according to the three dimensions of the integrated security threat model. Figure 3 This is a flowchart illustrating the integration of security threat analysis in this invention. For example... Figure 3 As shown, the specific steps of integrating security threat analysis in this invention include:
[0072] S301: Business Scenario Analysis:
[0073] For the business scenario to be analyzed (such as remote communication and target recognition), the key functional systems involved in the business scenario are analyzed, and the relevant components and their corresponding component assets are decomposed.
[0074] S302: Information Security Threat Analysis
[0075] For the decomposed component assets, relevant information security elements are retrieved from the integrated security knowledge graph, including vulnerabilities, weaknesses, and attack patterns associated with the component assets. Corresponding vulnerability keywords and weakness keywords are extracted from the knowledge graph to form a keyword set. The assets and keyword set are input into the fine-tuned large language model to obtain the information security threat scenario description text of the business scenario to be analyzed.
[0076] S303: Functional Safety Hazard Analysis
[0077] For the key functional systems mapped out and the information security elements associated in the previous step, the functional security elements in the security knowledge graph are matched and integrated, including the fault modes and application environments associated with the functional systems. The corresponding fault mode keywords and application environment keywords are extracted from the knowledge graph to form a keyword set. The functional systems and keyword set are input into the fine-tuned large language model to obtain the functional security threat scenario description text of the business scenario to be analyzed.
[0078] Although the illustrative specific embodiments of the present invention have been described above to enable those skilled in the art to understand the invention, it should be understood that the invention is not limited to the scope of the specific embodiments. For those skilled in the art, various changes are obvious as long as they are within the spirit and scope of the invention as defined and determined by the appended claims, and all inventions utilizing the concept of the present invention are protected.
Claims
1. A collaborative analysis method for security threats to intelligent devices, characterized in that, Includes the following steps: S1: Collect TARA and HARA data from several smart devices; for each TARA data point, extract the natural language description of the damage scenario and attack path to form an information security threat scenario description text, and then extract the assets and corresponding keyword sets, including vulnerability keywords and exploit keywords; for each HARA data point, extract the natural language description of the damage scenario and attack path to form a functional safety threat scenario description text, and then extract the functional systems and corresponding keyword sets, including failure mode keywords and application environment keywords; use the assets or functional systems corresponding to each data point and the corresponding keyword set as input, and the corresponding threat scenario description text as output, to form training samples for fine-tuning the large language model; S2: Select a large language model according to actual needs, and fine-tune the large language model using the training samples of the large language model obtained in step S1; S3: Collect information security threat intelligence data and functional safety threat intelligence data of smart devices according to actual needs. The information security threat intelligence data includes smart device asset data, vulnerability data, weakness data and attack pattern data, while the functional safety threat intelligence data includes smart device functional system data, failure mode data and application environment data. S4: For information security threat intelligence data, associate assets, vulnerabilities, weaknesses and attack patterns in different data, and then construct an information security knowledge graph. The nodes include assets, vulnerabilities, weaknesses and attack patterns, and the relationships include the relationship between vulnerabilities and assets, the relationship between vulnerabilities and weaknesses, and the relationship between weaknesses and attack patterns. For functional safety threat intelligence data, functional systems and failure modes in different data are associated, and the application environment of the accident is classified according to the preset scenario characteristics to obtain several typical application environments. Failure modes and application environments are matched by keywords in the description of failure modes and application environments to realize the association between failure modes and application environments. Then, a functional safety knowledge graph is constructed, where nodes include functional systems, failure modes and application environments, and relationships include the association between functional systems and failure modes, and the association between failure modes and application environments. S5: Match the descriptive keywords of vulnerabilities, weaknesses and attack patterns in the information security knowledge graph with the failure modes in the functional safety knowledge graph. If the match is successful, establish a relationship in the corresponding node; otherwise, do not perform any operation, thereby integrating the information security knowledge graph and the functional safety knowledge graph into a fused knowledge graph. S6: Builds a layered, converged security network based on the hardware and software architecture of smart devices, including four analysis layers: 1) The business scenario layer includes the functional business of smart devices; 2) The functional system layer includes the functional systems corresponding to each business scenario; 3) The component layer includes the key components that constitute the functional system; 4) The component asset layer includes the specific assets within the component; S7: Perform integrated security threat analysis on the business scenario to be analyzed, including the following steps: S7.1: For the business scenario to be analyzed, analyze the key functional systems involved in the business scenario and decompose the relevant components and their corresponding component assets; S7.2: For the decomposed component assets, retrieve their related information security elements in the integrated security knowledge graph, including vulnerabilities, weaknesses, and attack patterns associated with the component assets. Extract the corresponding vulnerability keywords and weakness keywords from the knowledge graph to form a keyword set. Input the asset and keyword set into the fine-tuned large language model to obtain the information security threat scenario description text of the business scenario to be analyzed. S7.3: For the key functional systems mapped out and the information security elements associated with the previous step, match and integrate the functional security elements in the security knowledge graph, including the fault modes and application environments associated with the functional systems. Extract the corresponding fault mode keywords and application environment keywords from the knowledge graph to form a keyword set. Input the functional systems and keyword set into the fine-tuned large language model to obtain the functional security threat scenario description text of the business scenario to be analyzed.
2. The collaborative analysis method for security threats to intelligent devices according to claim 1, characterized in that, In step S2, the large language model fine-tuning adopts the LoRA fine-tuning algorithm.
3. The collaborative analysis method for security threats to intelligent devices according to claim 1, characterized in that, When the keyword set is input into the large language model for fine-tuning, a structured prompt is preset for information security threat analysis and functional safety threat analysis respectively. The prompt is then filled with the corresponding keyword set before being input into the large language model.
4. The collaborative analysis method for security threats to intelligent devices according to claim 1, characterized in that, In step S3, the information security threat intelligence data is extracted from publicly available CVE datasets, CPE datasets, CWE datasets, and CAPEC datasets.
5. The collaborative analysis method for security threats to intelligent devices according to claim 1, characterized in that, The information security threat intelligence data is extracted from the historical fault reports of the intelligent device in step S3.
6. The collaborative analysis method for security threats to intelligent devices according to claim 1, characterized in that, The specific method for keyword matching in step S5 is as follows: For two nodes to be matched, the TF-IDF algorithm is used to obtain candidate keywords from the descriptions of the two nodes respectively, the KeyBERT algorithm is used to extract keywords from the candidate keywords of the two nodes, and then the BERT model is used to obtain the embedding vector of each keyword; for each node, the semantic embedding of the node is generated based on the embedding vectors of all its keywords, and the similarity between the semantic embeddings of the two nodes to be matched is calculated. If the similarity is greater than a preset threshold, the matching is successful; otherwise, the matching fails.
Citation Information
Patent Citations
Security target collaborative analysis method and device, equipment and medium
CN118722668A
Network threat knowledge graph construction method based on SecBABC
CN119106141A