Network information security protection method, device and system
By calling a large language model to automatically analyze the financial loss attributes of the message authentication code verification system and generate verification attack scripts, the problem of low efficiency and high cost caused by manual intervention in existing technologies is solved, and automated attack and defense drills and problem analysis are realized.
Patent Information
- Application Number
- CN202511295387.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-11
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2045-09-11
AI Technical Summary
Existing technologies rely heavily on manual intervention when conducting attack and defense drills and problem analysis on message authentication code verification systems, resulting in low efficiency and high costs.
By calling a large language model, the analysis results of the financial loss attributes of a preset set of fields are determined. Based on the results, a set of verification attack scripts is determined, the initial sample information is automatically rewritten to execute attack and defense drills, and a problem analysis report is output.
It enables automated attack and defense drills and problem analysis of the message authentication code verification system without human intervention, improving efficiency and reducing costs.
Smart Images

Figure CN120825337B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network information security, and specifically to a method, apparatus and system for protecting network information security. Background Technology
[0002] In scenarios involving cybersecurity risks, such as finance, payments, or reconciliation of financial losses, Message Authentication Code (MAC) verification is a widely adopted data verification mechanism. It verifies the integrity and consistency of data by comparing the MAC codes generated by both systems. Currently, MAC verification is typically implemented by MAC verification systems. However, before official deployment, these systems usually require participation in attack and defense drills and problem analysis to ensure that potential vulnerabilities are identified and fixed in a timely manner, thus avoiding additional financial losses after deployment. Existing technologies heavily rely on manual intervention for attack and defense drills and problem analysis of MAC verification systems, resulting in low efficiency and high costs. Summary of the Invention
[0003] In view of this, embodiments of the present invention provide a network information security protection method, device and system to automatically realize attack and defense drills and problem analysis reports of message authentication code verification systems without human intervention, thereby improving efficiency and reducing costs.
[0004] In a first aspect, embodiments of the present invention aim to provide a method for protecting network information security, the method comprising:
[0005] Determine the list of verification rules for the message authentication code verification system, which is used to perform field verification on the information received by the system.
[0006] Obtain the rule information of each verification rule in the verification rule list;
[0007] The large language model is invoked according to the rule information to determine the financial loss attribute analysis result of the preset field set through the large language model. The financial loss attribute analysis result is used to characterize whether each field in the preset field set has a financial loss attribute.
[0008] Based on the analysis results of the fund loss attributes, a set of verification attack scripts is determined. The set of verification attack scripts is used to rewrite the field data of the corresponding fields with fund loss attributes in the information received by the system.
[0009] The initial sample information is rewritten based on the set of verification attack scripts to obtain the exercise sample information;
[0010] Each of the aforementioned exercise sample information is sent to the message authentication code verification system to execute the attack and defense exercise task;
[0011] Output a problem analysis report based on the task execution results.
[0012] Secondly, embodiments of the present invention aim to provide a network information security protection device, the device comprising:
[0013] The verification rule list determination unit is used to determine the verification rule list of the message authentication code verification system, which is used to perform field verification on the information received by the system.
[0014] The rule information acquisition unit is used to acquire the rule information of each verification rule in the verification rule list;
[0015] The large language model invocation unit is used to invoke the large language model according to the rule information, so as to determine the financial loss attribute analysis result of the preset field set through the large language model, wherein the financial loss attribute analysis result is used to characterize whether each field in the preset field set has a financial loss attribute;
[0016] The script set determination unit is used to determine the verification attack script set based on the analysis results of the fund loss attributes. The verification attack script set is used to rewrite the field data of the corresponding fields with fund loss attributes in the information received by the system.
[0017] The information rewriting unit is used to rewrite the initial sample information according to the set of verification attack scripts to obtain the exercise sample information;
[0018] The task execution unit is used to send the information of each of the exercise samples to the message authentication code verification system in order to execute the attack and defense exercise task;
[0019] The report generation unit is used to output a problem analysis report based on the task execution results.
[0020] Thirdly, embodiments of the present invention aim to provide a computer-readable storage medium having computer program instructions stored thereon, which, when executed by a processor, implement the method described in the first aspect.
[0021] Fourthly, embodiments of the present invention aim to provide an electronic device, the device comprising:
[0022] Memory is used to store one or more computer program instructions;
[0023] A processor, wherein the one or more computer program instructions are executed by the processor to implement the method as described in the first aspect.
[0024] Fifthly, embodiments of the present invention aim to provide a computer program product that, when run on a computer, causes the computer to perform the method described in the first aspect.
[0025] Sixthly, embodiments of the present invention aim to provide a network information security protection system, the system comprising:
[0026] Message authentication code verification system;
[0027] A data repository is used to provide data storage services;
[0028] The model server is used to provide large language model calling services;
[0029] A data processing device is configured to perform the method described in the first aspect.
[0030] This invention utilizes a large language model to determine the financial loss attribute analysis results of a preset field set. Based on these results, it determines a set of verification attack scripts, rewrites initial sample information using these scripts to obtain exercise sample information, and sends each exercise sample to the message authentication code verification system to execute an attack and defense exercise. Finally, it outputs a problem analysis report based on the task execution results. The financial loss attribute analysis results characterize whether each field in the preset field set possesses a financial loss attribute, and the verification attack script set rewrites the field data of the corresponding fields with financial loss attributes in the system's received information. Therefore, attack and defense exercises and problem analysis report output for the message authentication code verification system can be automatically implemented without human intervention, thereby improving efficiency and reducing costs. Attached Figure Description
[0031] The above and other objects, features and advantages of the present invention will become clearer from the following description of embodiments of the invention with reference to the accompanying drawings, in which:
[0032] Figure 1 This is a flowchart of a network information security protection system according to an embodiment of the present invention;
[0033] Figure 2 This is a signaling interaction diagram of the network information security protection system according to an embodiment of the present invention;
[0034] Figure 3 This is a flowchart of a network information security protection method according to an embodiment of the present invention;
[0035] Figure 4 This is a flowchart of the fund loss attribute analysis method according to an embodiment of the present invention;
[0036] Figure 5This is a flowchart of the method for determining the set of verification attack scripts according to an embodiment of the present invention;
[0037] Figure 6 This is a flowchart illustrating the method for determining the attack numerator field set and the attack denominator field set according to an embodiment of the present invention.
[0038] Figure 7 This is a flowchart of a preset verification attack script generation method according to an embodiment of the present invention;
[0039] Figure 8 This is a flowchart of the analysis report generation method according to an embodiment of the present invention;
[0040] Figure 9 This is a schematic diagram illustrating the execution process of the network information security protection method according to an embodiment of the present invention;
[0041] Figure 10 This is a schematic diagram of a network information security protection device according to an embodiment of the present invention;
[0042] Figure 11 This is a schematic diagram of an electronic device according to an embodiment of the present invention. Detailed Implementation
[0043] The present application is described below based on embodiments, but it is not limited to these embodiments. In the detailed description of the present application below, certain specific details are described in detail. Those skilled in the art can fully understand the present application without these details. To avoid obscuring the substance of the present application, well-known methods, processes, flows, elements, and circuits are not described in detail.
[0044] Furthermore, those skilled in the art should understand that the accompanying drawings provided herein are for illustrative purposes only and are not necessarily drawn to scale.
[0045] Unless the context explicitly requires it, words such as "including" or "contains" throughout the application should be interpreted as including rather than exclusive or exhaustive; that is, meaning "including but not limited to".
[0046] In the description of this application, it should be understood that the terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance. Furthermore, in the description of this application, unless otherwise stated, "a plurality of" means two or more.
[0047] The solutions described in this specification and embodiments, if involving the processing of personal information, will be processed only on the premise of having a legal basis (such as obtaining the consent of the personal information subject, or being necessary for the performance of a contract), and will only be processed within the scope stipulated or agreed upon. A user's refusal to process personal information beyond what is necessary for basic functions will not affect the user's use of basic functions.
[0048] The technical solution of this invention can be applied to the transaction and delivery services of instant e-commerce platforms, such as Taobao Flash Sale, Taoxianda, Ele.me takeaway and retail.
[0049] Figure 1 This is a flowchart of a network information security protection system according to an embodiment of the present invention. Figure 1 As shown, the network information security protection system includes a data processing device 11, a message authentication code verification system 12, a data storage device 13, and a model server 14. The data processing device 11 can be a device with data processing capabilities, such as a tablet computer, laptop computer, server, or desktop computer. The message authentication code verification system 12 can be a message authentication code verification system required for attack and defense drills. Optionally, the message authentication code verification system 12 can be an authentication code verification system implemented using software modules, hardware devices, cloud platforms, embedded functional components, or any other method; this application does not impose any limitations on this. The data storage device 13 can be a data storage device capable of providing data storage services externally, such as a database. The model server 14 can be a server internally deployed with a large language model and capable of providing large language model invocation services externally. It should be understood that the data processing device 11, the message authentication code verification system 12, the data storage device 13, and the model server 14 can be connected via a network to achieve instruction and data exchange between them. Specifically, in this embodiment of the invention, the data processing device 11 can serve as the execution object for automatic attack and defense drills and problem analysis report output operations. The message authentication code verification system 12 can serve as the applicable object for automatic attack and defense drills and problem analysis report output operations. The data storage repository 13 and the model server 14 can be used to provide related services to support the data processing device 11 in performing automatic attack and defense drills and problem analysis report output operations on the message authentication code verification system 12.
[0050] Figure 2 This is a signaling interaction diagram of a network information security protection system according to an embodiment of the present invention. Figure 2 As shown, the network information security protection system includes a data processing device 21, a model server 22, and a message authentication code verification system 23. The data processing device 21, model server 22, and message authentication code verification system 23 can specifically perform the following signaling interaction steps:
[0051] It should be understood that the network information security protection system may also include a data repository (not shown in the figure), which can be used by data processing devices to store relevant data generated by the data processing devices during the execution of steps.
[0052] Step S1000: Data processing device 21 determines the list of verification rules.
[0053] Specifically, the data processing device 21 can determine the verification rule list of the message authentication code verification system 23.
[0054] Optionally, in step S1000, as a method for determining the verification rule list, the verification rule list can be obtained by the data processing device 21 from the message authentication code verification system 23, and the verification rule list information can be parsed to determine the verification rule list.
[0055] Step S2000: Data processing device 21 acquires the rule information of each verification rule.
[0056] Specifically, after determining the verification rule list of the message authentication code verification system 23, the data processing device 21 can obtain the rule information of each verification rule in the verification rule list. The rule attributes can be a set of parameters used to define and configure the verification rules.
[0057] Optionally, in step S2000, as a method of obtaining rule information, the rule information of each verification rule can be obtained synchronously by the data processing device 21 while parsing the verification rule list information to determine the verification rule list. Alternatively, as another method of obtaining rule information, the rule information of each verification rule can also be obtained by the data processing device 21 after determining the verification rule list, through direct interaction with the message authentication code verification system 23 based on the verification rule list.
[0058] Step S3000: Data processing device 21 determines the financial loss attribute analysis results of the preset field set.
[0059] Specifically, the data processing device 21 can interact with the model server 22 to call the large language model based on rule information to determine the financial loss attribute analysis results of the preset field set. The financial loss attribute analysis results are used to characterize whether each field in the preset field set possesses a financial loss attribute.
[0060] Step S4000: Data processing device 21 determines multiple preset verification attack scripts.
[0061] Specifically, the data processing device 21 can interact with the model server 22 to call the large language model based on rule information to determine multiple preset verification attack scripts. Each preset verification attack script can be used to rewrite the field data of the corresponding field in the information received by the system.
[0062] In step S5000, the data processing device 21 combines preset verification attack scripts based on the analysis results of the financial loss attributes to determine the set of verification attack scripts.
[0063] Specifically, after calling the large language model to determine the analysis results of the financial loss attributes of the preset field set and multiple preset verification attack scripts, the data processing device 21 can combine the preset verification attack scripts according to the financial loss attribute analysis results to determine the verification attack script set. The verification attack script set is used to rewrite the field data of all fields with financial loss attributes in the system-received information, or it is used to rewrite the field data of fields with financial loss attributes in the system-received information that are not covered by the supported verification scope of the message authentication code verification system 23.
[0064] In step S6000, the data processing device 21 rewrites the initial sample information according to the set of verification attack scripts to obtain the exercise sample information.
[0065] Specifically, after determining the set of verification attack scripts, the data processing device 21 can rewrite the initial sample information according to the set of verification attack scripts to obtain the exercise sample information.
[0066] Step S7000: Data processing device 21 performs attack and defense drills.
[0067] Specifically, the data processing device 21 can send the information of each exercise sample to the message authentication code verification system 23 to perform the attack and defense exercise task.
[0068] Step S8000: Data processing device 21 outputs a problem analysis report based on the task execution results.
[0069] Specifically, after the attack and defense exercise is completed, the data processing device 21 can output a problem analysis report based on the results of the exercise.
[0070] Figure 3 This is a flowchart illustrating a network information security protection method according to an embodiment of the present invention. It is intended to illustrate that by executing... Figure 3 The network information security protection method shown allows the data processing device to perform automatic attack and defense drills and output problem analysis reports for the message authentication code verification system. For example... Figure 3 As shown, the network information security protection method may specifically include the following steps:
[0071] Step S100: Determine the verification rule list of the message authentication code verification system.
[0072] Specifically, the data processing device can determine the verification rule list of the message authentication code verification system that currently requires attack and defense drills. The message authentication code verification system is used to verify fields in the information received by the system. The verification rule list can be used to record the various verification rules used by the message authentication code verification system when performing message authentication code verification operations. Each verification rule in the verification rule list can be used to support the message authentication code verification system in verifying the integrity and consistency of the corresponding field data in the received information. Furthermore, the fields supported for verification by different verification rules may overlap or not; this application does not impose any restrictions on this. It should be noted that in this embodiment of the invention, a field can refer to the composite field itself containing multiple subfields, or it can refer to the subfields contained within the composite field; this application does not impose any restrictions on this.
[0073] Optionally, in step S100, depending on the actual application scenario, the verification rules in the verification rule list determined by the data processing device can exist in different forms. This application does not specifically limit the form in which the verification rules exist in the verification rule list. For example, each verification rule can exist in the form of executable code. Alternatively, each verification rule can also exist in the form of a descriptive language.
[0074] Optionally, in step S100, as a method for determining the verification rule list, the data processing device can obtain the verification rule list information of the message authentication code verification system by directly interacting with the system. Then, the data processing device can parse the obtained verification rule list information to determine the verification rule list of the message authentication code verification system.
[0075] Step S200: Obtain the rule information of each verification rule in the verification rule list.
[0076] Specifically, after determining the verification rule list of the message authentication code verification system, the data processing device can obtain the rule information of each verification rule in the verification rule list.
[0077] Optionally, in step S200, the rule information of the verification rules acquired by the data processing device may specifically include rule attributes, rule tasks, and rule alarms. Rule attributes may be a set of parameters used to define and configure verification rules, indicating the execution conditions, supported verification fields, and execution priority of the verification rules. Rule tasks may be the specific steps executed by the system when implementing the verification rules. Rule alarms may be the subsequent processing methods and notification mechanisms that the system needs to take when faced with different verification results generated after the verification rules are executed.
[0078] Further optionally, in step S200, as a method of obtaining rule information, the rule information of each verification rule can be obtained synchronously by the data processing device when parsing the verification rule list information to determine the verification rule list. Alternatively, as another method of obtaining rule information, the rule information of each verification rule can also be obtained by the data processing device after determining the verification rule list, through direct interaction between the verification rule list and the message authentication code verification system.
[0079] It should be understood that in practical applications, the data processing device can also combine the above two methods to obtain the rule information of each verification rule. Illustratively, when parsing the verification rule list information to determine the verification rule list, the data processing device can simultaneously obtain the rule attributes of each verification rule. Furthermore, after determining the verification rule list, the data processing device can directly interact with the message authentication code verification system based on the verification rule list to obtain the rule tasks and rule alarms of each verification rule.
[0080] Step S300: Invoke the large language model according to the rule information to determine the financial loss attribute analysis results of the preset field set through the large language model. The financial loss attribute analysis results are used to characterize whether each field in the preset field set possesses a financial loss attribute.
[0081] Specifically, after obtaining the rule information of each verification rule in the verification rule list, the data processing device can call the large language model according to the rule information to analyze whether each field in the preset field set has the attribute of financial loss, thereby determining the analysis result of the financial loss attribute of the preset field set. It should be noted that, in this embodiment of the invention, whether a field has the attribute of financial loss can specifically be used to characterize whether the field, if maliciously rewritten, forged, bypassed, or incorrectly processed during a transaction, payment, or settlement process, will lead to direct or indirect financial losses for the enterprise or user.
[0082] It is important to clarify that Large Language Models (LLMs) can refer to deep learning models with a large number of parameters that can understand and perform operations such as information extraction, logical reasoning, content generation, code writing, and mathematical calculations based on natural language instructions.
[0083] Optionally, in this embodiment of the invention, the large language model used for data processing devices to call can be the Deepseek large language model, the Qwen large language model, the Wenxin Yiyan large language model, or any other large language model; this application does not impose any limitations on this. Furthermore, in this embodiment, the large language model used for data processing devices to call can be deployed locally or on an online server; this application does not impose any limitations on this. Specifically, when the large language model is deployed locally, the audio file generation device can directly call the large language model locally. When the large language model is deployed on an online server, the data processing device can directly interact with the online server through an API (Application Programming Interface) to call the large language model.
[0084] Figure 4 This is a flowchart of a method for analyzing the attributes of financial losses according to an embodiment of the present invention. It should be understood that by executing... Figure 4 The method for analyzing the attributes of financial losses shown allows the data processing device to call a large language model based on rule information. This model analyzes whether each field in a preset field set possesses the attribute of financial loss, thereby determining the analysis result of the financial loss attributes of the preset field set, i.e., achieving step S300 above. Figure 4 As shown, the method for analyzing the attributes of financial losses may specifically include the following steps:
[0085] Step S310: Construct attribute analysis prompts based on the rule information. The attribute analysis prompts are used to guide the large language model in determining the result of the financial loss attribute analysis.
[0086] Specifically, the data processing device can construct attribute analysis prompts based on rule information. It should be noted that these attribute analysis prompts can be a piece of text input that guides the large language model to analyze whether each field in a preset field set possesses the attribute of financial loss, and outputs the expected analysis results.
[0087] Optionally, in step S310, as a method of constructing attribute analysis prompts, the attribute analysis prompts can be constructed by the data processing device filling rule information into the attribute analysis prompt template. The attribute analysis prompt template can be a statement template prepared in advance by relevant personnel. The specific content included in the attribute analysis prompt template can be set and adjusted by relevant personnel according to actual needs, and this application does not impose any restrictions on this.
[0088] Alternatively, as a configuration method, the attribute analysis prompt template can be set to include attribute analysis instructions, analysis reference information, and result output requirements.
[0089] The attribute analysis instructions can be those specifying the tasks the large language model needs to complete. For example, an attribute analysis instruction could be, "Please analyze whether each field in the preset field set possesses the 'funds loss' attribute based on the input information, and provide the analysis results. The preset field set includes fields A, B, C, and D." Analysis reference information can be provided to the model to assist it in understanding the instructions and executing the analysis task. For example, analysis reference information could be, "Whether a field possesses the 'funds loss' attribute is used to characterize whether malicious rewriting, forgery, bypassing, or incorrect processing of this field during transactions, payments, or settlements would lead to direct or indirect funds loss for the enterprise or user." Result output requirements can instruct the large language model to output the analysis results according to specified requirements. For example, a result output requirement could be, "The analysis result only needs to directly provide a yes or no conclusion."
[0090] For example, the attribute analysis prompts constructed by the data processing device could be: [The rule information for each verification rule in the verification rule list of the message authentication code verification system is "xxx". Please analyze whether each field in the preset field set has the attribute of financial loss based on the input information, and provide the analysis results. The preset field set includes fields A, B, C, and D. Whether a field has the attribute of financial loss is used to characterize whether the field, if maliciously rewritten, forged, bypassed, or incorrectly processed during a transaction, payment, or settlement process, will lead to direct or indirect financial losses for the enterprise or user. The analysis results only need to provide a direct yes or no conclusion].
[0091] It should be understood that the content included in the attribute analysis prompt template above and the attribute analysis prompt words constructed based on the template are merely for illustration. In actual application, the content included in the attribute analysis prompt template and the attribute analysis prompt words constructed based on the template are not limited to this.
[0092] Optionally, when constructing attribute analysis prompts, if the preset field set is only a part of all fields in the information received by the system, the data processing device can first filter out the rule information that supports the verification rules for each field in the preset field set from the rule information of multiple verification rules, and then fill the filtered rule information into the attribute analysis prompt template to construct the attribute analysis prompts. Furthermore, the data processing device can also fill in the support relationship information between each rule information and each field together with the rule information into the attribute analysis prompt template to construct the attribute analysis prompts. The support relationship information can be used to characterize the support verification relationship of the verification rule corresponding to the rule information for each field. Therefore, this embodiment can improve the analysis efficiency and accuracy of large language models.
[0093] Step S320 inputs the attribute analysis prompts into the large language model to determine the financial loss attribute analysis results through the large language model.
[0094] Specifically, after constructing attribute analysis prompts, the data processing device can input the attribute analysis prompts into a large language model to determine the results of the financial loss attribute analysis using the large language model.
[0095] Step S400: Determine the set of verification attack scripts based on the analysis results of the fund loss attributes. The set of verification attack scripts is used to rewrite the field data of the corresponding fields with fund loss attributes in the information received by the system.
[0096] Specifically, after determining the analysis results of the financial loss attributes of the preset field set, the data processing device can determine a set of verification attack scripts based on the financial loss attribute analysis results to rewrite the field data of the corresponding fields with financial loss attributes in the information received by the system.
[0097] Figure 5 This is a flowchart illustrating a method for determining a set of verification attack scripts according to an embodiment of the present invention. It should be understood that by executing... Figure 5 The method for determining the set of verification attack scripts shown allows the data processing device to determine, based on the analysis results of financial loss attributes, a set of verification attack scripts used to rewrite the field data of corresponding fields with financial loss attributes in the information received by the system; that is, to implement step S400 above. Figure 5 As shown, the method for determining the set of verification attack scripts may specifically include the following steps:
[0098] Step S410: Determine the attack numerator field set and the attack denominator field set based on the analysis results of the fund loss attributes. The attack numerator field set includes fields in the system-received information that possess fund loss attributes but are not covered by the supported verification range of the message authentication code verification system. The attack denominator field set includes all fields in the system-received information that possess fund loss attributes. The supported verification range of the message authentication code verification system is the sum of the supported verification ranges of all verification rules in the verification rule list.
[0099] Specifically, the data processing device can filter out all fields in the system-received information that have the attribute of financial loss to obtain the attack denominator field set. Additionally, the data processing device can filter out fields in the system-received information that have the attribute of financial loss but are not covered by the supported verification scope of the message authentication code verification system to obtain the attack element field set.
[0100] Figure 6 This is a flowchart illustrating a method for determining the attack numerator field set and the attack denominator field set according to an embodiment of the present invention. It should be understood that by performing... Figure 6 The method for determining the attack numerator and denominator field sets shown allows the data processing equipment to determine these sets based on the financial loss attribute analysis results, thus implementing step S410 above. Figure 6 As shown, the method for determining the attack numerator field set and the attack denominator field set may specifically include the following steps:
[0101] It should be noted that whether fields in the system-received information that are not covered by the verification scope of the message authentication code verification system possess financial loss attributes cannot usually be determined by directly performing financial loss attribute analysis on each field. Therefore, in order to filter out fields that possess financial loss attributes but are not supported for verification by the message authentication code verification system, the preset field set can be set to include a first field set and a second field set. The first field set can include all fields in the system-received information, and the second field set can include fields in the system-received information that are supported for verification by the message authentication code verification system. It should be understood that, for the first field set and the second field set, by performing the above steps, the data processing device can determine the financial loss attribute analysis results for the first field set and the second field set, respectively.
[0102] Step S411: Determine the attack denominator field set based on the analysis results of the capital loss attributes of the first field set.
[0103] Specifically, the data processing device can filter out fields with financial loss attributes from the first field set based on the analysis results of the financial loss attributes of the first field set, so as to determine the attack denominator field set.
[0104] Step S412: Determine the attacker's field set based on the analysis results of the financial loss attributes of the first field set and the analysis results of the financial loss attributes of the second field set.
[0105] Specifically, the data processing device can filter out fields with financial loss attributes from the first field set based on the financial loss attribute analysis results, and filter out fields with financial loss attributes from the second field set based on the financial loss attribute analysis results. Furthermore, the data processing device can determine the fields that were filtered out in the first field set but not in the second field set, thereby obtaining the attacker's field set.
[0106] Step S420: Determine the set of verification attack scripts by combining preset verification attack scripts according to the set of attack numerator fields or the set of attack denominator fields.
[0107] Specifically, after determining the attack numerator field set and the attack denominator field set, the data processing device can pre-set a verification attack script based on the attack numerator field set or the attack denominator field set to determine the verification attack script set.
[0108] Optionally, in step S420, when combining a preset verification attack script based on the attack numerator field set, the verification attack script set determined by the data processing device can be used to rewrite the field data of each attack numerator field in the system received information. When combining a preset verification attack script based on the attack denominator field set, the verification attack script set determined by the data processing device can be used to rewrite the field data of each attack denominator field in the system received information. Therefore, this embodiment can meet the different attack and defense exercise requirements of the message authentication code verification system.
[0109] Optionally, each preset verification attack script can be a script used to rewrite the field data of corresponding fields in the information received by the system. In step S420, when combining preset verification attack scripts according to the attack numerator field set or the attack denominator field set, the data processing device can specifically select at least one preset verification attack script that supports rewriting the field data of each attack denominator field from multiple preset verification attack scripts, and combine the selected preset verification attack scripts into a verification attack script set. Alternatively, the data processing device can specifically select at least one preset verification attack script that supports rewriting the field data of each attack numerator field from multiple preset verification attack scripts, and combine the selected preset verification attack scripts into a verification attack script set.
[0110] For example, preset verification attack script 1 is a script used to rewrite the field data of field A1 in the system received information, preset verification attack script 2 is a script used to rewrite the field data of field A2 in the system received information, preset verification attack script 3 is a script used to rewrite the field data of field A3 in the system received information, and preset verification attack script 4 is a script used to rewrite the field data of field B1 in the system received information. Taking the attack element field set as an example, when the attack element field set includes fields A1 and B1, the data processing device can specifically select preset verification attack scripts 1 and 4 that support rewriting fields A1 and B1 from multiple preset verification attack scripts, and combine preset verification attack scripts 1 and 4 into a verification attack script set.
[0111] Optionally, when determining the set of verification attack scripts, if there are multiple preset combinations of verification attack scripts that enable the rewriting scope to cover the required fields (i.e., each field in the set of attack numerator fields, or each field in the set of attack denominator fields), the data processing device can also generate corresponding sets of verification attack scripts respectively. This application does not impose any restrictions on this.
[0112] Further optionally, in this embodiment of the invention, each verification rule may have a corresponding preset verification attack script. Specifically, the preset verification attack script corresponding to each verification rule can be used to rewrite the field data of the supporting verification fields of each verification rule in the information received by the system. Furthermore, as a method for generating preset verification attack scripts, each preset verification attack script can be pre-generated by the data processing device calling a large language model based on the rule information.
[0113] Figure 7 This is a flowchart of a preset verification attack script generation method according to an embodiment of the present invention. It should be understood that by executing... Figure 7 The method for generating preset verification attack scripts shown allows the data processing device to call a large language model to pre-generate multiple preset verification attack scripts that meet the requirements. For example... Figure 7 As shown, the method for generating the preset verification attack script may specifically include the following steps:
[0114] Step S431: Construct script-generated prompts based on the rule information. The script-generated prompts are used to guide the large language model in generating each of the preset verification attack scripts.
[0115] Specifically, for each rule, the data processing device can construct scripts to generate prompts based on the rule information. It should be noted that the script-generated prompts can be a piece of text input, which can be used to guide the large language model to generate multiple preset verification attack scripts that meet the requirements.
[0116] Optionally, in step S431, as a method of constructing script generation prompts, the script generation prompts can be constructed by the data processing device filling rule information into the script generation prompt template. The script generation prompt template can be a statement template prepared in advance by relevant personnel. The specific content included in the script generation prompt template can be set and adjusted by relevant personnel according to actual needs, and this application does not impose any restrictions on this.
[0117] Alternatively, as a configuration method, the script generation prompt template can be set to include script generation instructions, generation reference information, and result output requirements.
[0118] The script generation instructions can be those specifying the tasks the large language model needs to complete. For example, a script generation instruction could be, "Give a script to rewrite the field data of the supporting verification fields in the system's received information based on the rule information of the input verification rule." The generation reference information can be provided to the model to assist it in understanding the instructions and generating the script. For example, the generation reference information could be example rule information and a pre-defined verification attack script written by relevant personnel for that example rule information. The result output requirements can instruct the large language model to output the analysis results according to specified requirements. For example, the result output requirements could be, "Please output the generated script in JSON format, excluding any unmentioned fields."
[0119] For example, the script generation prompt generated by the data processing device could be: [The rule information for the verification rule is "xxx". Please generate a script based on the input rule information for the verification rule to rewrite the field data of the supported verification fields in the system received information. Please refer to the above examples for the generated script, namely example xxx, example xxx, and example xxx. Please output the script in JSON format, excluding any unmentioned fields].
[0120] It should be understood that the content included in the script generation prompt template above and the script generation prompt words constructed based on the template are merely for illustration. In actual application, the content included in the script generation prompt template and the script generation prompt words constructed based on the template are not limited to this.
[0121] Step S432: Input the script generation prompt words into the large language model to generate each of the preset verification attack scripts through the large language model.
[0122] Specifically, after constructing attribute analysis prompts, the data processing device can input the prompts generated by each script into the large language model, so as to use the large language model to generate each preset verification attack script.
[0123] It should be noted that for fields covered by the verification scope of the message authentication code verification system, if a verification attack script is arbitrarily generated to rewrite the internal field data, it is very likely that the rewritten field data will happen to pass the message authentication code verification. This embodiment of the invention addresses this by having a data processing device execute... Figure 7 The method for generating preset verification attack scripts shown can generate multiple preset verification attack scripts, ensuring that, without the aforementioned issues, multiple preset verification attack scripts are generated with a rewriting scope that covers the supported verification scope of the message authentication code verification system.
[0124] Optionally, in this embodiment of the invention, for fields not covered by the supported verification scope of the message authentication code verification system, since there will not be a situation where the rewritten field data can just pass the message authentication code verification, the data processing device can directly call the large language model to determine a preset verification attack script for it.
[0125] Step S500: Rewrite the initial sample information according to the set of verification attack scripts to obtain the exercise sample information.
[0126] Specifically, after determining the set of verification attack scripts, the data processing device can rewrite the initial sample information based on the set of verification attack scripts to obtain the training sample information. The initial sample information can be information generated through the actual operational scenario of the simulated message authentication code verification system. The training sample information can be the initial sample information after the field data of the corresponding internal fields has been rewritten.
[0127] It should be understood that in the embodiments of the present invention, the field data rewritten by the data processing device using the verification attack script set needs to follow the relevant rules of the field. For example, for a field whose field data is numerical data, the field data rewritten by the data processing device when using the verification attack script set for that field needs to also be numerical data.
[0128] Optionally, in step S500, when rewriting the initial sample information, the data processing device may use a set of verification attack scripts to rewrite the field data of all writable fields in the initial sample information, or it may use a set of verification attack scripts to rewrite the field data of some writable fields in the initial sample information. This application does not impose any restrictions on this. Furthermore, for different initial sample information, the fields selected by the data processing device for rewriting may be the same or different; this application does not impose any restrictions on this.
[0129] Optionally, in step S500, if multiple sets of verification attack scripts are generated in advance, the data processing device can also rewrite the initial sample information according to each set of verification attack scripts to obtain multiple training sample information.
[0130] Step S600: Send the information of each exercise sample to the message authentication code verification system to execute the attack and defense exercise task.
[0131] Specifically, after obtaining the exercise sample information, the data processing equipment can send the information of each exercise sample to the message authentication code verification system to execute the attack and defense exercise task.
[0132] Optionally, while sending the information of each training sample to the message authentication code verification system, the data processing device can also detect the reception result of the message authentication code verification system for each training sample information. For training sample information that the message authentication code verification system fails to receive, the data processing device can resend it to the message authentication code verification system in subsequent transmissions until it is successfully received by the message authentication code verification system.
[0133] Step S700: Output a problem analysis report based on the task execution results.
[0134] Specifically, after sending all the exercise sample information to the message authentication code verification system, that is, after completing the attack and defense exercise, the data processing equipment can output a problem analysis report based on the task execution results.
[0135] Figure 8 This is a flowchart of an analysis report generation method according to an embodiment of the present invention. It should be understood that by executing... Figure 8 The analysis report generation method shown allows the data processing device to output a problem analysis report based on the task execution results, thus achieving step S700 above. For example... Figure 8 As shown, the method for generating the analysis report may specifically include the following steps:
[0136] Step S710: Receive the message authentication code and verify the attack and defense exercise results fed back by the system.
[0137] Specifically, the data processing equipment can receive the attack and defense exercise results fed back by the message authentication code verification system. It should be noted that the attack and defense exercise results can specifically include the identification results of the message authentication code verification system on the modified fields in the information of each exercise sample, that is, whether the modified fields have been identified.
[0138] Step S720: Obtain the attack numerator field identification information and the attack denominator field identification information.
[0139] Specifically, the data processing device can acquire attack numerator field identification information and attack denominator field identification information. It should be noted that the attack numerator field identification information may specifically include the field identifiers of each attack numerator field. The attack denominator field identification information may specifically include the field identifiers of each attack denominator field.
[0140] Step S730: Integrate the attack numerator field identification information, the attack denominator field identification information, and the attack and defense exercise results to generate the problem analysis report.
[0141] Specifically, the data processing equipment can integrate attack numerator field identification information, attack denominator field identification information, and attack and defense exercise results to generate a problem analysis report.
[0142] Step S740: Output the problem analysis report.
[0143] Specifically, after generating the problem analysis report, the data processing device can output the problem analysis report.
[0144] It should be understood that the problem analysis report output by the data processing equipment can be displayed to relevant personnel through corresponding display devices, thereby providing relevant personnel with a basis for repairing potential vulnerabilities in the message authentication code verification system.
[0145] Figure 9 This is a schematic diagram illustrating the execution process of the network information security protection method according to an embodiment of the present invention. Figure 9 As shown, for a message authentication code verification system 91 that requires attack and defense drills, the data processing device can determine the verification rule list of the message authentication code verification system 91 and obtain the rule information 92 of each verification rule in the verification rule list.
[0146] Furthermore, after determining the rule information 92 for each verification rule, the data processing device can invoke the large language model 93 based on the rule information 92 to analyze whether each field in the preset field set possesses the financial loss attribute, thereby determining the financial loss attribute analysis result 94 of the preset field set. Simultaneously, the data processing device can invoke the large language model 93 based on the rule information 92 to generate multiple preset verification attack scripts 95. Each of the multiple preset verification attack scripts 95 can be used to rewrite the field data of the corresponding field in the information received by the system.
[0147] Furthermore, after determining the financial loss attribute analysis result 94 of the preset field set and generating multiple preset verification attack scripts 95, the data processing device can determine the attack numerator field set 941 and the attack denominator field set 942 based on the financial loss attribute analysis result 94, and combine the attack numerator field set 941 or the attack denominator field set 942 into a verification attack script set 96 based on the multiple preset verification attack scripts 95. The verification attack script set 96 can be used to rewrite the field data of each field in the attack numerator field set 941 or the attack denominator field set 942 in the information received by the system.
[0148] Furthermore, after determining the set of verification attack scripts 96, the data processing device can rewrite the initial sample information according to the set of verification attack scripts 96 to obtain the exercise sample information, and send each exercise sample information to the message authentication code verification system 91 to execute the attack and defense exercise task.
[0149] Furthermore, after the attack and defense exercise is completed, the data processing equipment can integrate the attack numerator field identification information, the attack denominator field identification information, and the attack and defense exercise results fed back by the message authentication code verification system 91 to generate a problem analysis report 97 and output the problem analysis report 97.
[0150] This invention utilizes a large language model to determine the financial loss attribute analysis results of a preset field set. Based on these results, it determines a set of verification attack scripts, rewrites initial sample information using these scripts to obtain exercise sample information, and sends each exercise sample to the message authentication code verification system to execute an attack and defense exercise. Finally, it outputs a problem analysis report based on the task execution results. The financial loss attribute analysis results characterize whether each field in the preset field set possesses a financial loss attribute, and the verification attack script set rewrites the field data of the corresponding fields with financial loss attributes in the system's received information. Therefore, attack and defense exercises and problem analysis report output for the message authentication code verification system can be automatically implemented without human intervention, thereby improving efficiency and reducing costs.
[0151] The following will explain the above process in detail with specific examples. Assume there exists a message authentication code verification system. The complete set of fields in the system's received information includes A1, A2, A3, B1, B2, B3, C1, C2, C3, D1, D2, D3, E1, E2, and E3. The verification rules include condition1, condition2, condition3, condition4, condition5, and condition6. Conditions 1, 2, 3, 4, 5, and 6 are used to support the message authentication code verification system in verifying the integrity and consistency of the field data in fields A1, B1, B2, C1, D1, and E1 of the received information.
[0152] To automatically generate attack and defense drills and problem analysis reports for the message authentication code verification system, the data processing device can first determine the verification rule list for the system (this list records condition1, condition2, condition3, condition4, condition5, and condition6). Furthermore, after determining the verification rule list, the data processing device can obtain the rule information for each verification rule.
[0153] Furthermore, after acquiring the rule information for each verification rule, the data processing device can use the large language model to determine the financial loss attribute analysis results for the preset field sets based on the rule information. Specifically, this means determining the financial loss attribute analysis results for the first field set and the second field set. The first field set includes A1, A2, A3, B1, B2, B3, C1, C2, C3, D1, D2, D3, E1, E2, and E3. The second field set includes A1, B1, B2, C1, D1, and E1. Simultaneously, the data processing device can use the large language model to generate multiple preset verification attack scripts based on the rule information. Here, it is assumed that the determined multiple preset verification attack scripts include preset verification attack scripts 1-15. These preset verification attack scripts 1-15 are used to rewrite the field data in fields A1, A2, A3, B1, B2, B3, C1, C2, C3, D1, D2, D3, E1, E2, and E3 in the information received by the system.
[0154] Furthermore, after determining the analysis results of the capital loss attributes of the preset field set, the data processing device can determine the attack denominator field set based on the analysis results of the capital loss attributes of the first field set, and determine the attack numerator field set based on the analysis results of the capital loss attributes of the first field set and the second field set. Here, it is assumed that the determined attack denominator field set may include A1, A2, A3, B1, B2, C1, D1, and E1. Correspondingly, the attack numerator field set may include A2, A3, and C1.
[0155] Furthermore, after determining the attack denominator field set and the attack numerator field set, the data processing device can combine multiple preset verification attack scripts based on the attack denominator field set or the attack numerator field set to determine the verification attack script set. Here, assuming that the verification attack script set is determined by combining multiple preset verification attack scripts based on the attack denominator field set, the verification attack script set combined by the data processing device may include preset verification attack scripts 1, 2, 3, 4, 5, 7, 10, and 13.
[0156] Furthermore, after determining the set of verification attack scripts, the data processing device can rewrite the initial sample information according to the set of verification attack scripts to obtain the exercise sample information, and send each exercise sample information to the message authentication code verification system to execute the attack and defense exercise task.
[0157] Furthermore, after the attack and defense exercise is completed, the data processing equipment can output a problem analysis report based on the results of the exercise.
[0158] Therefore, the data processing equipment can automatically perform attack and defense drills and output problem analysis reports for the message authentication code verification system without human intervention, thereby improving efficiency and reducing costs.
[0159] Figure 10 This is a schematic diagram of a network information security protection device according to an embodiment of the present invention. Figure 10 As shown, the network information security protection device of this embodiment includes a rule list determination unit 101, a rule information acquisition unit 102, a large language model calling unit 103, a script set determination unit 104, an information rewriting unit 105, a task execution unit 106, and a report generation unit 107.
[0160] Specifically, the verification rule list determination unit 101 is used to determine the verification rule list of the message authentication code verification system, and the message authentication code verification system is used to perform field verification on the information received by the system.
[0161] The rule information acquisition unit 102 is used to acquire the rule information of each verification rule in the verification rule list.
[0162] The large language model invocation unit 103 is used to invoke the large language model according to the rule information, so as to determine the financial loss attribute analysis result of the preset field set through the large language model, wherein the financial loss attribute analysis result is used to characterize whether each field in the preset field set has a financial loss attribute.
[0163] The script set determination unit 104 is used to determine the verification attack script set based on the analysis results of the fund loss attributes. The verification attack script set is used to rewrite the field data of the corresponding fields with fund loss attributes in the information received by the system.
[0164] The information rewriting unit 105 is used to rewrite the initial sample information according to the verification attack script set to obtain the exercise sample information.
[0165] The task execution unit 106 is used to send the information of each of the exercise samples to the message authentication code verification system in order to execute the attack and defense exercise task.
[0166] The report generation unit 107 is used to output a problem analysis report based on the task execution results.
[0167] This invention utilizes a large language model to determine the financial loss attribute analysis results of a preset field set. Based on these results, it determines a set of verification attack scripts, rewrites initial sample information using these scripts to obtain exercise sample information, and sends each exercise sample to the message authentication code verification system to execute an attack and defense exercise. Finally, it outputs a problem analysis report based on the task execution results. The financial loss attribute analysis results characterize whether each field in the preset field set possesses a financial loss attribute, and the verification attack script set rewrites the field data of the corresponding fields with financial loss attributes in the system's received information. Therefore, attack and defense exercises and problem analysis report output for the message authentication code verification system can be automatically implemented without human intervention, thereby improving efficiency and reducing costs.
[0168] Figure 11 This is a schematic diagram of an electronic device according to an embodiment of the present invention. It should be understood that... Figure 11 The electronic device shown can specifically be the data processing device described in the above embodiments. For example... Figure 11As shown, the electronic device includes at least one processor 111; a memory 112 communicatively connected to at least one processor 111; and a communication component 113 communicatively connected to a scanning device, wherein the communication component 113 receives and transmits data under the control of the processor 111; wherein the memory 112 stores instructions executable by at least one processor 111, the instructions being executed by at least one processor 111 to implement the aforementioned network information security protection method.
[0169] Specifically, the electronic device includes: one or more processors 111 and a memory 112. Figure 11 Taking a processor 111 as an example, the processor 111 and the memory 112 can be connected via a bus or other means. Figure 11 Taking a bus connection as an example, memory 112, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. Processor 111 executes various functional applications and data processing of the device by running the non-volatile software programs, instructions, and modules stored in memory 112, thereby realizing the aforementioned network information security protection method.
[0170] Memory 112 may include a program storage area and a data storage area, wherein the program storage area may store the operating system and applications required for at least one function; the data storage area may store an option list, etc. Furthermore, memory 112 may include high-speed random access memory and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other non-volatile solid-state storage device. In some embodiments, memory 112 may optionally include memory remotely located relative to processor 111, and these remote memories may be connected to external devices via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0171] One or more modules are stored in memory 112, and when executed by one or more processors 111, they perform the network information security protection method in any of the above method embodiments.
[0172] The above-mentioned products can perform the methods provided in the embodiments of this application, and have the corresponding functional modules and beneficial effects of performing the methods. For technical details not described in detail in this embodiment, please refer to the methods provided in the embodiments of this application.
[0173] This invention utilizes a large language model to determine the financial loss attribute analysis results of a preset field set. Based on these results, it determines a set of verification attack scripts, rewrites initial sample information using these scripts to obtain exercise sample information, and sends each exercise sample to the message authentication code verification system to execute an attack and defense exercise. Finally, it outputs a problem analysis report based on the task execution results. The financial loss attribute analysis results characterize whether each field in the preset field set possesses a financial loss attribute, and the verification attack script set rewrites the field data of the corresponding fields with financial loss attributes in the system's received information. Therefore, attack and defense exercises and problem analysis report output for the message authentication code verification system can be automatically implemented without human intervention, thereby improving efficiency and reducing costs.
[0174] Another embodiment of the present invention relates to a non-volatile storage medium for storing a computer-readable program for use by a computer to execute some or all of the above-described method embodiments.
[0175] That is, those skilled in the art will understand that all or part of the steps in the methods of the above embodiments can be implemented by a program instructing related hardware. This program is stored in a storage medium and includes several instructions to cause a device (which may be a microcontroller, chip, etc.) or processor to execute all or part of the steps of the methods described in the embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, a portable hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0176] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.
Claims
1. A method for protecting network information security, characterized in that, The method includes: Determine the list of verification rules for the message authentication code verification system, which is used to perform field verification on the information received by the system. Obtain the rule information of each verification rule in the verification rule list; The large language model is invoked according to the rule information to determine the financial loss attribute analysis result of the preset field set through the large language model. The financial loss attribute analysis result is used to characterize whether each field in the preset field set has a financial loss attribute. Whether a field has a financial loss attribute is used to characterize whether the field will cause direct or indirect financial loss to the enterprise or user if it is maliciously rewritten, forged, bypassed or mishandled during the transaction, payment or settlement process. Based on the analysis results of the fund loss attributes, a set of verification attack scripts is determined. The set of verification attack scripts is used to rewrite the field data of the corresponding fields with fund loss attributes in the information received by the system. The initial sample information is rewritten based on the set of verification attack scripts to obtain the exercise sample information; Each of the aforementioned exercise sample information is sent to the message authentication code verification system to execute the attack and defense exercise task; Output a problem analysis report based on the task execution results.
2. The method according to claim 1, characterized in that, The set of verification attack scripts determined based on the analysis results of the fund loss attributes includes: Based on the analysis results of the fund loss attributes, the attack numerator field set and the attack denominator field set are determined. The attack numerator field set includes fields in the system-received information that have fund loss attributes but are not covered by the support verification range of the message authentication code verification system. The attack denominator field set includes all fields in the system-received information that have fund loss attributes. The support verification range of the message authentication code verification system is the sum of the support verification ranges of each verification rule in the verification rule list. The set of verification attack scripts is determined by combining the set of attack numerator fields or the set of attack denominator fields with a preset verification attack script.
3. The method according to claim 2, characterized in that, Each of the aforementioned preset verification attack scripts is used to rewrite the field data of the corresponding fields in the information received by the system; The step of determining the set of verification attack scripts by combining preset verification attack scripts based on the set of attack numerator fields or the set of attack denominator fields includes: Among the multiple preset verification attack scripts, at least one preset verification attack script that supports rewriting the field data of each attack denominator field is selected, and the selected preset verification attack scripts are combined into the verification attack script set; or Among the multiple preset verification attack scripts, at least one preset verification attack script that supports rewriting the field data of each attacker's field is selected, and the selected preset verification attack scripts are combined into the verification attack script set.
4. The method according to claim 2, characterized in that, The preset field set includes a first field set and a second field set. The first field set includes all fields in the system received information, and the second field set includes fields in the system received information that are supported for verification by the message authentication code verification system. The process of determining the attack numerator field set and attack denominator field set based on the analysis results of the fund loss attributes includes: The attack denominator field set is determined based on the analysis results of the capital loss attributes of the first field set; The attacker's field set is determined based on the analysis results of the financial loss attributes of the first field set and the analysis results of the financial loss attributes of the second field set.
5. The method according to claim 1, characterized in that, The step of calling the large language model based on the rule information to determine the financial loss attribute analysis results of the preset field set through the large language model includes: Attribute analysis prompts are constructed based on the rule information, wherein the attribute analysis prompts are used to guide the large language model to determine the result of the financial loss attribute analysis; The attribute analysis prompts are input into the large language model to determine the financial loss attribute analysis results through the large language model.
6. The method according to claim 3, characterized in that, Each of the verification rules has a corresponding preset verification attack script, and the preset verification attack script corresponding to each of the verification rules is used to rewrite the field data of the supported verification fields of each of the verification rules in the system received information; Before determining the target verification attack script based on the analysis results of the fund loss attributes, the method further includes: The large language model is invoked based on the rule information to generate a preset verification attack script corresponding to each of the verification rules.
7. The method according to claim 6, characterized in that, The step of invoking a large language model based on the rule information to generate a preset verification attack script corresponding to each of the verification rules includes: The script generates prompts based on the rule information, wherein the script generates prompts to guide the large language model to generate each of the preset verification attack scripts; The script-generated prompts are input into the large language model to generate each of the preset verification attack scripts.
8. The method according to claim 1, characterized in that, The process of outputting a problem analysis report based on the task execution results includes: Receive the message authentication code and verify the attack and defense exercise results fed back by the system; Obtain the attack numerator field identification information and the attack denominator field identification information; The attack numerator field identification information, the attack denominator field identification information, and the attack and defense exercise results are integrated to generate the problem analysis report; Output the problem analysis report.
9. The method according to claim 1, characterized in that, The rule information includes rule attributes, rule tasks, and rule alarms.
10. A network information security protection device, characterized in that, The device includes: The verification rule list determination unit is used to determine the verification rule list of the message authentication code verification system, which is used to perform field verification on the information received by the system. The rule information acquisition unit is used to acquire the rule information of each verification rule in the verification rule list; The large language model invocation unit is used to invoke the large language model according to the rule information, so as to determine the financial loss attribute analysis result of the preset field set through the large language model. The financial loss attribute analysis result is used to characterize whether each field in the preset field set has a financial loss attribute. Whether a field has a financial loss attribute is used to characterize whether the field will cause direct or indirect financial loss to the enterprise or user if it is maliciously rewritten, forged, bypassed or mishandled during the transaction, payment or settlement process. The script set determination unit is used to determine the verification attack script set based on the analysis results of the fund loss attributes. The verification attack script set is used to rewrite the field data of the corresponding fields with fund loss attributes in the information received by the system. The information rewriting unit is used to rewrite the initial sample information according to the set of verification attack scripts to obtain the exercise sample information; The task execution unit is used to send the information of each of the exercise samples to the message authentication code verification system in order to execute the attack and defense exercise task; The report generation unit is used to output a problem analysis report based on the task execution results.
11. A computer-readable storage medium storing computer program instructions thereon, characterized in that, The computer program instructions, when executed by a processor, implement the method as described in any one of claims 1-9.
12. An electronic device, characterized in that, The device includes: Memory is used to store one or more computer program instructions; A processor, wherein the one or more computer program instructions are executed by the processor to implement the method as described in any one of claims 1-9.
13. A computer program product, characterized in that, When the computer program product is run on a computer, it causes the computer to perform the method as described in any one of claims 1-9.
14. A network information security protection system, characterized in that, The system includes: Message authentication code verification system; A data repository is used to provide data storage services; The model server is used to provide large language model calling services; A data processing device is configured to perform the method as described in any one of claims 1-9.
Citation Information
Patent Citations
Method and device for password-free payment based on digital currency
CN114462990A
Chinese multi-modal adversarial sample defense method based on adversarial training and comparative learning
CN115309897A