Method, device, equipment and product for identifying large model application business risk

By performing business risk detection within the traffic proxy component and decoupling the backend model service, the problem of poor universality of business model detection services across different platforms is solved. This enables efficient business risk detection and large-scale model access, adapting to the needs of different enterprise architectures.

CN120915840APending Publication Date: 2025-11-07BEIJING VOLCANO ENGINE TECH CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511254615.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-03
Publication Date
2025-11-07

AI Technical Summary

Technical Problem

In existing technologies, different business models need to maintain different business risk detection services when deployed on different platforms. This results in poor universality, low development and deployment efficiency, and makes it difficult to provide a universal large-model protection solution in different enterprise architectures.

Method used

The system obtains client task requests through a traffic proxy component and performs business risk detection based on the correspondence between task requests and business models. This decouples the backend model service, eliminating the need to deploy business risk detection services on each platform and enabling unified business risk detection using the traffic proxy component.

Benefits of technology

It improves the efficiency of business model development and deployment, provides a non-intrusive large model access solution, supports business risk detection for different user needs, and improves the coverage and flexibility of risk detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120915840A_ABST
    Figure CN120915840A_ABST
Patent Text Reader

Abstract

The invention discloses a method, a device, equipment and a product for identifying business risks of a large model application. The method comprises the following steps: acquiring a first task request sent to the large model application by a client from a flow agent component; the large model application is associated with at least one service model, the traffic proxy component is used for forwarding the traffic of the client to the back-end server, and the back-end server is used for deploying the at least one service model; according to a corresponding relationship between the first task request and at least one service model, performing service risk detection on the first task request to obtain a detection result; and processing the first task request according to a detection result. By decoupling the business risk detection process and the back-end model service, the task request to be detected can be acquired from the flow agent component without paying attention to whether the business model is deployed on a cloud server of a public cloud, a private cloud and a hybrid cloud or a local server, so that the universality is high, and the efficiency is high. And the development efficiency and deployment efficiency of the business model can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of large model, the technical field of computer, in particular, relates to a method and device for identifying business risk of large model application, equipment and product. BACKGROUND

[0002] With the development of model technology, ensuring model security is the basis for its wide application. In actual business scenarios, one or more business models can be accessed according to the business needs of different users, and different business models can be deployed in the same cloud service, or in different cloud services, or in local servers.

[0003] In related technologies, the deployment platform of different business models can provide business risk detection services for the deployed business models to ensure model security. However, different business models need to maintain different business risk detection services, and if the business models are deployed in different platforms, the corresponding business risk detection services need to be deployed in different platforms, which has poor universality, and needs to be developed and deployed simultaneously for business models and corresponding business risk detection services, which is low in efficiency. SUMMARY

[0004] This summary is provided to introduce a selection of concepts that are further described below in the detailed description. This summary is not intended to identify key or essential features of the claimed subject matter, nor is it used to limit the scope of the claimed subject matter's scope.

[0005] In a first aspect, the present disclosure provides a method for identifying business risk of large model application, the method comprising: obtaining a first task request sent by a client to a large model application from a traffic proxy component; wherein the large model application is associated with at least one business model, the traffic proxy component is used to forward traffic of the client to a backend server, and the backend server is used to deploy the at least one business model, wherein different business models are used to process different types of tasks; performing business risk detection on the first task request according to a correspondence between the first task request and the at least one business model, to obtain a detection result, wherein the detection result is used to represent whether the first task request has business risk; processing the first task request according to the detection result.

[0006] In a second aspect, the present disclosure provides a device for identifying business risk of large model application, the device comprising: The acquisition module is configured to acquire a first task request sent by a client to a large model application from a traffic proxy component, wherein the large model application is associated with at least one business model, the traffic proxy component is configured to forward traffic of the client to a backend server, and the backend server is configured to deploy the at least one business model, wherein different business models are used to process different types of tasks. The detection module is configured to perform business risk detection on the first task request according to a correspondence between the first task request and the at least one business model, to obtain a detection result, wherein the detection result is used to represent whether the first task request has business risk. The processing module is configured to process the first task request according to the detection result.

[0007] In a third aspect, the present disclosure provides a computer readable medium having a computer program stored thereon, wherein the program, when executed by a processing device, implements the steps of the method in the first aspect.

[0008] In a fourth aspect, the present disclosure provides an electronic device, comprising: a storage device having a computer program stored thereon; a processing device configured to execute the computer program in the storage device to implement the steps of the method in the first aspect.

[0009] In a fifth aspect, the present disclosure provides a computer program product comprising a computer program, wherein the computer program, when executed by a processor, implements the steps of the method in the first aspect.

[0010] According to the above technical solution, the first task request sent by the client to the large model application is acquired from the traffic proxy component, and the business risk detection is performed on the first task request according to the correspondence between the first task request and the at least one business model, to obtain the detection result used to represent whether the first task request has business risk, and finally the first task request is processed according to the detection result. By acquiring the task request to be detected from the traffic proxy component used to forward the task request of the client to the backend server, the business risk detection process can be decoupled from the model service of the backend, and it is not necessary to pay attention to whether the business model is deployed on the cloud server or the local server of the public cloud, the private cloud or the hybrid cloud, and the task request to be detected can be acquired from the traffic proxy component for business risk detection without deploying the corresponding business risk detection service on the corresponding backend server, which is high in versatility and does not need to invade the model service, so that the backend business model and the business risk detection process can be maintained separately, thereby improving the development efficiency and deployment efficiency of the business model.

[0011] Other features and advantages of the present disclosure will be described in detail in the following detailed description section. Attached Figure Description

[0012] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and the originals and elements are not necessarily drawn to scale. In the drawings: Figure 1 This is a flowchart illustrating a method for identifying business risks in large-scale application models according to an exemplary embodiment of this disclosure; Figure 2 This is a schematic diagram illustrating the interaction process of various modules of a task request processing system according to an exemplary embodiment of the present disclosure; Figure 3 This is a schematic diagram illustrating a task request forwarding process according to an exemplary embodiment of the present disclosure; Figure 4 This is a structural block diagram of a system for identifying business risks in large-scale application models, according to an exemplary embodiment of this disclosure. Figure 5 This is a structural block diagram of an apparatus for identifying business risks in large-scale application models, according to an exemplary embodiment of this disclosure. Figure 6 This is a schematic diagram of the structure of an electronic device according to an exemplary embodiment of the present disclosure. Detailed Implementation

[0013] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.

[0014] It should be understood that the steps described in the method embodiments of this disclosure may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this disclosure is not limited in this respect.

[0015] The term "comprising" and its variations as used herein are open-ended inclusions, meaning "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Definitions of other terms will be given in the description below.

[0016] It should be noted that the terms "first", "second", and the like in the present disclosure are merely used to distinguish different devices, modules or units, and do not limit the order or interdependence of the functions performed by these devices, modules or units.

[0017] It should be noted that the terms "one", "multiple" in the present disclosure are illustrative and not restrictive, and those skilled in the art should understand that "one or more" should be understood unless otherwise explicitly indicated in the context.

[0018] The names of the messages or information exchanged between the devices in the embodiments of the present disclosure are only for illustrative purposes, and are not intended to limit the scope of the messages or information.

[0019] It can be understood that before using the technical solutions disclosed in the embodiments of the present disclosure, the type, use range, use scenario, etc. of the personal information involved in the present disclosure should be informed to the user and the authorization of the user should be obtained in a proper manner according to relevant laws and regulations.

[0020] For example, in response to receiving the active request of the user, the user is sent prompt information to explicitly prompt the user that the operation requested to be performed will require obtaining and using the personal information of the user. Thus, the user can voluntarily choose whether to provide personal information to the electronic device, application program, server or storage medium, etc. software or hardware performing the operation of the technical solutions of the present disclosure according to the prompt information.

[0021] As an optional but non-limiting implementation manner, in response to receiving the active request of the user, the manner of sending prompt information to the user may, for example, be a pop-up window manner, and the prompt information may be presented in the form of text in the pop-up window. In addition, the pop-up window may also carry selection controls for the user to select "agree" or "disagree" to provide personal information to the electronic device.

[0022] It can be understood that the above notification and user authorization process is only illustrative and does not limit the implementation manner of the present disclosure, and other manners meeting the relevant laws and regulations can also be applied to the implementation manner of the present disclosure.

[0023] At the same time, it can be understood that the data involved in the present technical solution (including but not limited to the data itself, the acquisition or use of the data) should comply with the requirements of the relevant laws and regulations and relevant provisions.

[0024] With the development of model technology, ensuring model security is the basis for its wide application. Taking a business model based on a large model as an example, in an actual business scenario, according to different business needs of different users, for example, one or more business models can be accessed for different businesses or different scenarios, and different business models can be deployed in the same cloud service, or can be deployed in different cloud services, including public cloud, private cloud and hybrid cloud cloud service scenarios, and can also be deployed in a local server.

[0025] In related technologies, the deployment platform of different business models can provide risk detection services for the deployed business models to ensure model security, for example, a platform provides business risk detection services for large models deployed in the public cloud of the platform, but it is not applicable to private cloud and local deployment. That is, different business models need to maintain different business risk detection services, and if the business model is deployed in different platforms, the corresponding business risk detection services need to be deployed in different platforms, which has poor universality, and the business model and the corresponding business risk detection services need to be developed and deployed synchronously, which is low in efficiency.

[0026] Therefore, how to provide a large model protection scheme in the architecture of different enterprises, complete the landing of large models in enterprises, how to provide a non-intrusive large model access scheme for model business, solve the problem of friendly business while maintaining high coverage of risk detection in the process of large-scale promotion and landing of large models, and how to provide different business risk detection modes to support different user needs, are all problems to be solved in the process of model promotion and landing.

[0027] The present disclosure provides a method, device, equipment and product for identifying business risk of large model application to solve the above technical problems.

[0028] The embodiments of the present disclosure are further explained and described below with reference to the accompanying drawings.

[0029] Figure 1 is a flowchart of a method for identifying business risk of large model application according to an exemplary embodiment of the present disclosure, referring to Figure 1 The method for identifying business risk of large model application can include the following steps: S101: Obtain a first task request sent by a client to a large model application from a traffic proxy component; wherein the large model application is associated with at least one business model, the traffic proxy component is used to forward the traffic of the client to a backend server, and the backend server is used to deploy at least one business model, wherein different business models are used to process different types of tasks.

[0030] In this embodiment, the large model application can be understood as an application platform accessing a preset business model. The preset business model can be understood as a business model for different business scenarios, which can be a large language model, a multi-modal large model, or other model architectures. For example, a data analysis platform can access a large language model for data analysis and a question and answer large model for answering user questions. The specific determination can be made according to the actual business scenario, and the present disclosure does not limit this. The backend server can be a public cloud, a private cloud, a hybrid cloud, or a cloud server of other architectures, or a local server. The specific determination can be made according to the server of the business model deployed in the actual business scenario, and the present disclosure does not limit this.

[0031] For example, as shown in Figure 2 The traffic proxy component is an upstream access component, which can be a WAF (Web Application Firewall) component, a VPC (Virtual Private Cloud) component, a NAT (Network Address Translation) component, an API (Application Programming Interface) component, and other intermediate components for forwarding task requests of a client to a backend server. The specific setting can be made according to the demand, and the present disclosure does not limit this.

[0032] It is worth noting that, as shown in Figure 2 The traffic access engine can obtain the task request from the traffic proxy component according to the traffic access document provided by the operation and maintenance personnel. The traffic access document can include technical specifications, interface descriptions, configuration steps, etc., to correctly guide the task request to the traffic access engine. The traffic access engine encapsulates the logic related to the communication protocol layer, is responsible for the traffic connection, routing, etc. of various types of upstream access components of the user, supports various communication protocols, and provides traffic routing, certificate management, protocol analysis, service management, etc.

[0033] S102: According to the correspondence between the first task request and the at least one business model, performing business risk detection on the first task request to obtain a detection result, the detection result being used to represent whether the first task request has a business risk.

[0034] S103: Processing the first task request according to the traffic detection result.

[0035] By using the above method, the business risk detection process can be decoupled from the model service of the backend by obtaining the task request to be detected from the traffic proxy component for forwarding the task request of the client to the backend server, without needing to pay attention to whether the business model is deployed on a cloud server or a local server of a public cloud, a private cloud, a hybrid cloud, etc. The traffic proxy component can be used to obtain the task request to be detected for business risk detection, without the need to deploy a corresponding business risk detection service on the corresponding backend server, which has high universality and does not need to invade the model service, so that the backend business model and the business risk detection process can be maintained separately, thereby improving the development efficiency and deployment efficiency of the business model.

[0036] In a possible manner, the method further includes: storing, by the data processing engine, configuration information corresponding to the first configuration operation of the user in the management platform into the second database in response to the first configuration operation of the user in the management platform; wherein the configuration information includes at least one of business model configuration information, detection rule configuration information, and processing strategy configuration information; wherein the business model configuration information is used to configure a preset business model in at least one business model that needs to be subjected to business risk detection, the detection rule configuration information is used to configure a preset detection rule corresponding to the preset business model, the preset detection rule represents a content matching rule for judging whether business risk detection is needed, and the processing strategy configuration information is used to configure a processing strategy for a task request that has business risk; and the data processing engine is used to distribute the business model configuration information in the second database to the traffic access engine, and distribute the detection rule configuration information and / or the processing strategy configuration information to the traffic analysis proxy.

[0037] In the present embodiment, as shown in Figure 2 The management personnel can perform operation and management of the large model or the agent on the visual management platform, including asset management, service management, policy management, risk management, etc. Asset information, policy information, and service information can be stored in corresponding databases.

[0038] The service management is used to manage the provided business model and related model service, and the model service for business risk detection based on service configuration requirements can obtain service configuration. The asset management is used to manage resources required by the model service, such as routing components and API ports, and the asset management can also configure resource information required for business risk detection to obtain asset configuration. The asset configuration can be understood as a preset detection rule. Routing configuration can also be performed, for example, the model service and assets required by the service are mapped and configured with the corresponding backend server, so as to route traffic to the corresponding backend server according to the routing configuration in the future.

[0039] It should be noted that the preset detection rule can include a special rule for different preset business models, or a general rule for all preset business models.

[0040] On the one hand, the service configuration and the asset configuration can be obtained by the data processing engine and stored into the corresponding database, and on the other hand, the service configuration and the asset configuration can be obtained by the data processing engine from the corresponding database, and the service configuration is issued to the traffic access engine, and the preset detection rule is issued to the traffic analysis agent. The data processing engine decouples the control plane and the data plane, so that the data can be operated asynchronously and do not interfere with each other, improving the management and configuration efficiency of the control plane, facilitating real-time data processing and real-time configuration issuance of the data plane, and providing an architectural basis for isolated management of multiple departments and multiple businesses of SaaS (Software-as-a-Service).

[0041] In addition, the policy management includes the life cycle management, policy issuance, execution, and statistical information of the business risk detection policy of the content security, data security, model abuse, vocabulary, topic, and the like of the large model, and the risk management includes the risk metadata definition, level definition, risk life cycle management, and the like, to meet different business needs of users. A visual dashboard can also be provided to visually display the detection results of the task request for centralized display of key data, indicators, and states, helping users quickly and intuitively understand the overall risk situation.

[0042] It is worth noting that the present embodiment also provides different task request processing modes to adapt to different business risk detection modes. Thus, different user needs can be met.

[0043] In a possible manner, the first task request sent by the client to the large model application is obtained from the traffic agent component, including: in a first mode, the first task request is intercepted from the traffic agent component, and the first mode represents that the task request sent by the client to the large model application is intercepted and processed. The method further includes: in a case where the detection result indicates that the first task request has a business risk and the business risk can be solved, routing the first task request with the solved business risk to a corresponding backend server according to address information carried by the first task request; or, in a case where any of the following conditions is met, routing the first task request to a corresponding backend server according to address information carried by the first task request: the business model corresponding to the first task request does not match a preset business model; wherein the preset business model is a business model in at least one business model that needs to be detected for business risk; the business model corresponding to the first task request matches the preset business model, and the analysis content obtained by analyzing the first task request does not satisfy a preset detection rule corresponding to the preset business model; wherein the preset detection rule represents a content matching rule for judging whether business risk detection is needed; and the detection result indicates that the first task request does not have a business risk.

[0044] In this embodiment, the task request processing mode supporting interception processing of the task request sent by the client to the large model application is equivalent to taking the traffic access engine as a traffic proxy component and an intermediate component between the backend server, so that all task requests sent by the client to the large model application need to pass through business risk detection before determining whether to forward to the backend server, which is suitable for business scenarios that need to strictly detect the business risk of the task request. It can be understood that the business risk of the task request is detected and evaluated before the large model application is processed, and whether it exists business risk is verified.

[0045] Further, assuming that the business model corresponding to the first task request is not a preset business model, it means that the business model corresponding to the task request does not belong to the business model that needs to be detected for business risk, or the analysis content obtained by analyzing the first task request does not meet the preset detection rule, which means that the content of the task request does not hit the detection rule, or the first task request is determined to have no business risk after business risk detection. In the case, the first task request can be forwarded to the backend server. As shown in Figure 3 In this case, the domain name or IP address and the specific location of the resource of the corresponding business model and other address information can be determined according to the Host and Path in the task request, and then the corresponding backend server group is determined according to the routing configuration, and then the first task request is forwarded to the corresponding backend server group.

[0046] Of course, for the first task request that has business risk but can be solved by data processing, the corresponding backend server group can be determined according to the routing configuration after processing the first task request, and then the first task request is forwarded to the corresponding backend server group. For example, for the first task request that contains user privacy data, the user privacy data can be desensitized and then forwarded to the corresponding backend server group, for example, the mobile phone number is "12345678901", and after desensitization, the field becomes "mobile phone number". The specific setting can be made according to the actual business scenario, and the present disclosure does not limit it.

[0047] Thus, the task request can be strictly managed for business risk, and the model security of the backend business model is ensured.

[0048] In a possible manner, the first task request sent by the client to the large model application is obtained from the traffic proxy component, including: copying the first task request from the traffic proxy component in the second mode, and the second mode represents mirroring processing of the task request sent by the client to the large model application.

[0049] In this embodiment, the task request processing mode supporting mirroring processing of the task request sent by the client to the large model application is equivalent to the traffic proxy component normally forwarding the task request sent by the client to the backend server, and the traffic access engine copies the task request passed by the traffic proxy component to mirror data for business risk detection. It is applicable to the business scenario of post-event analysis of the task request, and can be understood as business risk detection and evaluation of the task request processed by the model, verifying whether there is business risk.

[0050] For example, all mirrored task requests can be subjected to business risk detection, or part of the mirrored task requests can be subjected to business risk detection. The specific setting can be based on demand, and the present disclosure does not limit this. Thus, the task request can be subjected to business risk analysis to ensure the model security of the backend business model.

[0051] In a possible manner, the business risk detection of the first task request according to the correspondence between the first task request and the at least one business model comprises: in a case where the business model corresponding to the first task request is a preset business model, performing content analysis on the first task request to obtain first analysis content; wherein the preset business model is a business model in the at least one business model that needs to be subjected to business risk detection; and performing business risk detection on the first analysis content.

[0052] For example, as shown in Figure 2 The traffic access engine can judge whether the business model corresponding to the first task request is a business model that needs to be subjected to business risk detection based on service management. If the business model corresponding to the first task request is a business model that needs to be subjected to business risk detection, the first task request is sent to the traffic analysis proxy. The first task request can be subjected to content analysis according to business requirements, for example, converted into structured data such as JSON format according to a predefined field format. The specific setting can be based on demand, and the present disclosure does not limit this, so as to subsequently perform business risk detection and business risk analysis based on the structured data. Thus, the task request for different business models can be subjected to business risk detection as needed, improving the flexibility and efficiency of business risk detection, and reducing resource waste for subsequent large model analysis data.

[0053] In a possible manner, the business risk detection of the first task request according to the correspondence between the first task request and the at least one business model comprises: judging, by the traffic access engine, whether the business model corresponding to the first task request is a preset business model based on business model configuration information; and performing, by the traffic analysis proxy, content analysis on the first task request to obtain fourth analysis content in a case where the business model corresponding to the first task request is the preset business model, and calling the large model engine to perform business risk detection on the fourth analysis content.

[0054] For example, as shown in Figure 2 The traffic access engine can determine whether the service model corresponding to the task request is a preset service model based on the service model configuration information issued by the data processing engine. If it is determined that the service model corresponding to the task request is a preset service model, the task request is issued to the traffic analysis agent, and then the content of the task request is parsed through the traffic analysis agent, so that subsequent large model engine can perform service risk detection and service risk analysis based on structured data, thereby enabling the service risk detection of the task request for different service models on demand, improving the flexibility and efficiency of service risk detection, and reducing resource waste for subsequent large model analysis data.

[0055] In a possible manner, the service risk detection on the first parsed content includes: in a case where the first parsed content meets a preset detection rule corresponding to the preset service model, performing service risk detection on the first parsed content; wherein the preset detection rule represents a content matching rule for determining whether service risk detection is needed.

[0056] For example, according to the preset detection rule and the first parsed content, it is further determined whether the service risk detection on the first task request is needed. For example, the preset detection rule includes "risk detection on traffic of request API interface XX", and if the first parsed content includes API interface "XX", it is determined that the service risk detection on the first task request is needed. Thus, the service risk detection on the task request with different content on demand can improve the flexibility and efficiency of service risk detection, and reduce resource waste for subsequent large model analysis data.

[0057] In a possible manner, the large model engine is called to perform service risk detection on the fourth parsed content, including: the traffic analysis agent performs content matching between the fourth parsed content and a preset detection rule corresponding to the preset service model; in a case where the result of the content matching indicates that the fourth parsed content meets the preset detection rule, the large model engine is called to perform service risk detection on the fourth parsed content.

[0058] For example, as shown in Figure 2 The traffic analysis agent can further determine whether the service risk detection on the task request is needed according to the detection rule configuration information issued by the data processing engine, and in a case where the parsed content of the task request meets the preset detection rule, the large model engine is called to perform service risk detection on the fourth parsed content. Thus, the service risk detection on the task request with different content on demand can improve the flexibility and efficiency of service risk detection, and reduce resource waste for subsequent large model analysis data.

[0059] It should be noted that the preset detection rule can include a specific rule for the business model corresponding to the first task request, or a general rule for all preset business models, and the present disclosure does not limit this.

[0060] In a possible manner, the business risk detection on the first task request according to the correspondence between the first task request and the at least one business model comprises: obtaining a first business risk detection strategy of the business model corresponding to the first task request; wherein different business models correspond to different business risk detection strategies; and performing business risk detection on the first task request according to the first business risk detection strategy.

[0061] For example, different business risk detection strategies can be set for different business models in advance due to different business logics of different business models, and of course, a general business risk detection strategy can also be set, which can be set according to requirements, and the present disclosure does not limit this.

[0062] Further, the business risk detection on the task request can be performed based on the business risk detection strategy of the business model corresponding to the task request, so as to perform targeted business risk detection on the task request for different business models.

[0063] In a possible manner, the business risk detection on the first task request comprises: performing content analysis on second analysis content corresponding to the first task request, determining a first large model for detecting the second analysis content from at least one large model, and the at least one large model is used to perform business risk detection on the task request according to a preconfigured business risk detection strategy; and performing business risk detection on the second analysis content by the first large model.

[0064] In the present embodiment, as shown in Figure 2 The security management platform provides a micro-service mode and an SDK (Software Development Kit) access mode, the micro-service mode is a non-invasive mode, and business risk detection is performed by calling a business risk detection model provided by the security management platform. The SDK access mode refers to a business model that provides a business risk detection service, and business risk detection can also be performed by directly using the business risk detection service provided by the business model by calling the corresponding SDK, and the present disclosure does not limit this according to requirements.

[0065] For example, as shown in Figure 2As shown, by invoking a large model engine, the corresponding model is invoked to perform business risk detection based on the parsed content corresponding to the first task request. This includes content security, data security, algorithm attacks, and model illusions. For example, a large analysis model can be used to analyze the parsed content first to determine which large model can be used for business risk detection. If the parsed content involves data security, a large model for analyzing data security can be invoked to further analyze the parsed content to determine the existing business risks, such as unauthorized access or data tampering. The specific settings can be configured according to requirements, and this disclosure does not impose any restrictions on this.

[0066] For example, business risk detection can also be performed on the parsed content using each large model for business risk detection to identify existing business risks. The specific settings can be customized according to requirements, and this disclosure does not impose any limitations on this. This allows for targeted model analysis to obtain detection results for different business risks, or the analysis results from all large models can be aggregated to obtain the detection results, thereby improving the efficiency and accuracy of the detection results.

[0067] In some possible approaches, the method further includes: obtaining a pre-configured business risk detection strategy from a third database via a large model engine, the pre-configured business risk detection strategy being determined in response to a second configuration operation by the user in the configuration platform. Calling the large model engine to perform business risk detection on the fourth parsed content includes: determining a second large model for detecting the fourth parsed content from at least one large model based on the fourth parsed content using the large model engine, and calling the second large model to perform business risk detection on the fourth parsed content based on the business risk detection strategy, wherein at least one large model is used to perform risk detection on the task request according to the pre-configured business risk detection strategy.

[0068] For example, such as Figure 2 As shown, administrators can set different business risk detection strategies for different business models on the management platform. Of course, they can also set general business risk detection strategies and then store them in the corresponding database.

[0069] For example, the large model engine can obtain the set business risk detection strategy from the database, and then train and fine-tune the large model for business risk detection based on the business risk detection strategy, so that the large model has the ability to perform business risk detection on task requests based on the business risk detection strategy. The business risk detection strategy can also be used as part of the prompt words so that the large model can perform business risk detection based on the business risk detection strategy when the model is inferring. This disclosure does not limit this.

[0070] It should be noted that the large model can perform model inference based on the business risk detection strategy configured by the user on the management platform and the related knowledge base content, in addition, tools or plug-ins can be called for processing during model inference, which can be set according to requirements, and the present disclosure does not limit this.

[0071] In a possible manner, the first task request is processed according to the detection result, including: determining a first processing strategy for the first task request according to the detection result; and processing the first task request based on the first processing strategy.

[0072] For example, as shown in Figure 2 According to the traffic analysis agent, the processing strategy for the first task request can be determined according to the traffic detection result, such as blocking the first task request from being forwarded to the backend server and feeding back a prompt information of request failure to the client, replacing the request content of the first task request, returning the reply content corresponding to the first task request to the client, continuing to forward the first task request without business risk to the backend server, etc., which can be set according to requirements, and the present disclosure does not limit this.

[0073] Thus, the different business risks can be processed specifically, and the accuracy and flexibility of business risk processing are provided.

[0074] In addition, the traffic analysis agent can also record the result log for further analysis in the future.

[0075] In a possible manner, the first task request is processed according to the detection result, including: determining a second processing strategy for the first task request according to the detection result and the processing strategy configuration information through the traffic analysis agent; and processing the first task request according to the second processing strategy.

[0076] For example, as shown in Figure 2 The traffic analysis agent can determine the processing strategy for the task request according to the processing strategy configuration information and the detection result issued by the data processing engine, so that the different business risks can be processed specifically, and the accuracy and flexibility of business risk processing are provided.

[0077] In a possible manner, the method further includes: storing the first task request and the detection result corresponding to the first task request in a first database, the first database being used to store historical task requests and detection results corresponding to the historical task requests, the historical task requests and the detection results corresponding to the historical task requests being used to construct training samples and / or generate analysis reports, the training samples being used to optimize at least one large model, and the at least one large model being used to detect business risks of task requests according to a preconfigured business risk detection strategy.

[0078] For example, as shown in Figure 2As shown, task requests and their corresponding detection results can be stored in a task request database. Historical task requests and their corresponding detection results in the task request database can be used to build training samples and generate analysis reports.

[0079] For example, training samples can be constructed based on historical task requests and their corresponding detection results, or a portion of historical task requests and their corresponding detection results can be sampled to construct training samples. Figure 2 As shown, historical task requests and their corresponding detection results are used as initial samples to construct training samples. After data cleaning and filtering by the sample agent, training samples are obtained. These training samples are then used to train or fine-tune a large model for business risk detection. Furthermore, training samples can be periodically constructed based on new task requests and their corresponding detection results to optimize the large model. This allows for continuous optimization of the large model based on actual task requests, improving its analytical accuracy.

[0080] For example, such as Figure 2 As shown, the reporting agent can also summarize and analyze historical task requests and their corresponding detection results over a period of time to generate analysis reports, such as weekly or monthly reports. This allows for the summarization and analysis of business risks based on requirements, enabling users to intuitively understand the model's security status and adjust business risk detection strategies accordingly.

[0081] In some possible approaches, the method further includes: storing the first task request and the corresponding detection results of the first task request into a fourth database through a data processing engine, the fourth database being used to store historical task requests and the corresponding detection results of historical task requests; constructing training samples and / or generating analysis reports based on historical task requests and the corresponding detection results of historical task requests through a large model engine, the training samples being used to optimize at least one large model, and at least one large model being used to perform business risk detection on the task request according to a pre-configured business risk detection strategy.

[0082] For example, such as Figure 2 As shown, it is generally necessary to summarize and analyze all task requests obtained by the traffic analysis agent, and then use a portion of these task requests as training samples. Therefore, the data processing engine can sample all task requests from the traffic analysis agent through a sampling channel and store them in the task request database. Then, the engine surface can retrieve task requests as needed for processing. By decoupling the engine surface and the data surface, it is convenient to sample task requests and perform rapid analysis of large models.

[0083] In a possible manner, the method further includes: performing content analysis on the first task request to obtain third analysis content, the third analysis content including resource information accessed by the first task request; in a case where the resource information satisfies a preset resource rule, updating the service model configuration information and / or the detection rule configuration information based on the resource information; wherein the service model configuration information is used to configure a preset service model in at least one service model that needs to perform service risk detection, and the detection rule configuration information is used to configure a preset detection rule corresponding to the preset service model, the preset detection rule representing a content matching rule for judging whether service risk detection is needed.

[0084] For example, the traffic analysis agent can analyze the task request according to the business needs, for example, convert it into structured data such as JSON format according to the predefined field format, which can be set according to the needs, and the present disclosure does not limit this. Further analysis of the structured analysis content can be performed by a preset analysis large model, or can be visually displayed on the management platform for manual analysis by management personnel, which can be set according to the needs, and the present disclosure does not limit this.

[0085] For example, assuming that the resource information accessed by the task request is a new resource or a new service that does not exist in resource management or service management, the stored resource information or service information can be automatically updated, and the business model configuration information or the detection rule configuration information can also be automatically updated according to the needs, or the business model configuration information or the detection rule configuration information can be manually updated by the user based on the new resource or the new service, which can be set according to the needs, and the present disclosure does not limit this. In order to improve the accuracy of the business model configuration information or the detection rule configuration information, the automatically updated business model configuration information or the detection rule configuration information can also be manually checked.

[0086] As Figure 2 shown, the historical task requests can also be obtained from the task request database by the data processing engine, and the analysis intelligent agent in the large model engine is called for resource analysis to decouple the data plane and the control plane. Thus, through task request collection and model analysis and identification, the asset configuration is generated, the ability to automatically discover large model assets is achieved, and the large model protection is quickly started through rule generation and simple manual checking.

[0087] The above method enables a non-intrusive large-model protection solution that places no burden on model-related business operations, allowing for on-demand development and implementation. It also delegates business risk detection to designated personnel, reducing reliance on systems and services for identifying business risks in large-model applications and facilitating collaborative development. Furthermore, it allows those responsible for business risk detection to rapidly and on a large scale implement the large-model protection solution. Additionally, it provides the ability to automatically discover large-model assets, enabling those responsible for business risk detection to manage model assets holistically. For the business, large-model technology can be rapidly deployed while automatically protecting large models, eliminating the need for time-consuming separate compliance and business risk assessments.

[0088] Based on the same inventive concept, such as Figure 4 As shown, this disclosure also provides a system 400 for identifying business risks in large-scale model applications, including a traffic access engine 401, a traffic analysis agent 402, a data processing engine 403, a large-scale model engine 404, and a management platform 405. The functions of each module of the above system have been described in the above combination. Figure 2 The method embodiments are described in detail, and will not be repeated here.

[0089] Based on the same inventive concept, this disclosure also provides an apparatus for identifying business risks in large-scale application models, the apparatus 500 for identifying business risks in large-scale application models comprising: The acquisition module 501 is used to acquire the first task request sent by the client to the large model application from the traffic proxy component; wherein the large model application is associated with at least one business model, the traffic proxy component is used to forward the client's traffic to the backend server, the backend server is used to deploy at least one business model, and different business models are used to handle different types of tasks. The detection module 502 is used to perform business risk detection on the first task request based on the correspondence between the first task request and at least one business model, and obtain the detection result. The detection result is used to characterize whether there is a business risk in the first task request. The processing module 503 is used to process the first task request based on the detection results.

[0090] Optionally, the detection module 502 is used for: If the business model corresponding to the first task request is a preset business model, the first task request is parsed to obtain the first parsed content; wherein, the preset business model is the business model that needs to be detected for business risks among the at least one business model. Perform business risk detection on the first parsed content.

[0091] Optionally, the detection module 502 is configured to: In a case where the first parsed content meets a preset detection rule corresponding to the preset business model, performing business risk detection on the first parsed content, wherein the preset detection rule represents a content matching rule for determining whether business risk detection is needed.

[0092] Optionally, the detection module 502 is configured to: Obtaining a first business risk detection strategy of a business model corresponding to the first task request, wherein different business models correspond to different business risk detection strategies; Performing business risk detection on the first task request according to the first business risk detection strategy.

[0093] Optionally, the detection module 502 is configured to: Performing content analysis on second parsed content corresponding to the first task request, determining a first large model for detecting the second parsed content from at least one large model, wherein the at least one large model is configured to perform business risk detection on a task request according to a preconfigured business risk detection strategy; Performing business risk detection on the second parsed content by using the first large model.

[0094] Optionally, the acquisition module 501 is configured to: In a first mode, intercepting the first task request from the traffic proxy component, wherein the first mode represents intercepting and processing a task request sent by the client to the large model application; The device 500 for identifying business risk of a large model application further includes a routing module, which is configured to: In a case where the detection result indicates that the first task request has business risk and the business risk can be solved, routing the first task request in which the business risk has been solved to a corresponding backend server according to address information carried by the first task request; or, In a case where any of the following conditions is met, routing the first task request to a corresponding backend server according to address information carried by the first task request: The business model corresponding to the first task request does not match a preset business model, wherein the preset business model is a business model in the at least one business model that needs to perform business risk detection; The business model corresponding to the first task request matches the preset business model, and parsed content obtained by parsing the first task request does not meet a preset detection rule corresponding to the preset business model, wherein the preset detection rule represents a content matching rule for determining whether business risk detection is needed; The detection result represents that the first task request does not have a business risk.

[0095] Optionally, the acquisition module 501 is configured to: In the second mode, the first task request is copied from the traffic proxy component, and the second mode represents that the task request sent by the client to the large model application is mirror processed.

[0096] Optionally, the processing module 503 is configured to: determine a first processing strategy for the first task request according to the detection result; process the first task request based on the first processing strategy.

[0097] Optionally, the device 500 for identifying business risks of a large model application further includes a first storage module, which is configured to: store the first task request and the detection result corresponding to the first task request in a first database, the first database being configured to store historical task requests and detection results corresponding to the historical task requests, the historical task requests and the detection results corresponding to the historical task requests being configured to construct training samples and / or generate an analysis report, the training samples being configured to optimize at least one large model, and the at least one large model being configured to detect business risks of task requests according to a preconfigured business risk detection strategy.

[0098] Optionally, the device 500 for identifying business risks of a large model application further includes an updating module, which is configured to: perform content analysis on the first task request to obtain third analysis content, the third analysis content including resource information accessed by the first task request; update business model configuration information and / or detection rule configuration information based on the resource information in a case where the resource information meets a preset resource rule, the business model configuration information being configured to configure a preset business model in the at least one business model that needs to be subjected to business risk detection, and the detection rule configuration information being configured to configure a preset detection rule corresponding to the preset business model, the preset detection rule representing a content matching rule for determining whether business risk detection is needed.

[0099] Optionally, the device 500 for identifying business risks of a large model application further includes a data processing module, which is configured to: The data processing engine stores configuration information corresponding to the first configuration operation of the user in the management platform into a second database in response to the first configuration operation; wherein the configuration information comprises at least one of business model configuration information, detection rule configuration information and processing strategy configuration information; wherein the business model configuration information is used to configure a preset business model in the at least one business model that needs to perform business risk detection, the detection rule configuration information is used to configure a preset detection rule corresponding to the preset business model, the preset detection rule represents a content matching rule for judging whether business risk detection is needed, and the processing strategy configuration information is used to configure a processing strategy for a task request that exists business risk. The data processing engine distributes the business model configuration information in the second database to a traffic access engine, and distributes the detection rule configuration information and / or the processing strategy configuration information to a traffic analysis agent.

[0100] Optionally, the detection module 502 is configured to: The traffic access engine judges whether the business model corresponding to the first task request is the preset business model based on the business model configuration information. The traffic analysis agent performs content analysis on the first task request to obtain fourth analysis content, and calls a large model engine to perform business risk detection on the fourth analysis content, in a case where the business model corresponding to the first task request is the preset business model.

[0101] Optionally, the detection module 502 is configured to: The traffic analysis agent performs content matching on the fourth analysis content and a preset detection rule corresponding to the preset business model. In a case where the result of the content matching indicates that the fourth analysis content meets the preset detection rule, the large model engine is called to perform business risk detection on the fourth analysis content.

[0102] Optionally, the device for identifying large model application business risk 500 further comprises an acquisition submodule, which is configured to: The large model engine acquires a preconfigured business risk detection strategy from a third database, wherein the preconfigured business risk detection strategy is determined in response to a second configuration operation of the user in the management platform. The detection module 502 is configured to: The large model engine determines a second large model for detecting the fourth parsed content from at least one large model based on the fourth parsed content, and calls the second large model to perform business risk detection on the fourth parsed content based on the business risk detection strategy, the at least one large model being used to perform risk detection on a task request according to the preconfigured business risk detection strategy.

[0103] Optionally, the processing module 503 is configured to: determine a second processing strategy for the first task request according to the detection result and the processing strategy configuration information through the traffic analysis agent; perform processing on the first task request according to the second processing strategy; Optionally, the device for identifying business risk of a large model 500 further comprises a second storage module, which is configured to: store the first task request and the detection result corresponding to the first task request into a fourth database through a data processing engine, the fourth database being used to store historical task requests and detection results corresponding to the historical task requests; construct a training sample and / or generate an analysis report based on the historical task requests and the detection results corresponding to the historical task requests through a large model engine, the training sample being used to optimize at least one large model, the at least one large model being used to perform business risk detection on a task request according to a preconfigured business risk detection strategy.

[0104] Embodiments of each module of the device for identifying business risk of a large model have been described in detail in the embodiments of the corresponding method, and the present disclosure will not be repeated here.

[0105] Based on the same concept, the embodiments of the present disclosure further provide a computer readable medium having a computer program stored thereon, which, when executed by a processing device, implements the steps of any of the above methods for identifying business risk of a large model.

[0106] Based on the same concept, the embodiments of the present disclosure further provide an electronic device, which can include: a storage device having a computer program stored thereon; a processing device configured to execute the computer program in the storage device to implement the steps of any of the above methods for identifying business risk of a large model.

[0107] Based on the same concept, the embodiments of the present disclosure further provide a computer program product comprising a computer program, which, when executed by a processor, implements the steps of any of the above methods for identifying business risk of a large model.

[0108] The following will be described with reference to the drawingsFigure 6 The diagram illustrates a structural schematic of an electronic device 600 suitable for implementing embodiments of the present disclosure. Terminal devices in embodiments of the present disclosure may include, but are not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 6 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments disclosed herein.

[0109] like Figure 6 As shown, electronic device 600 may include a processing device (e.g., a central processing unit, a graphics processor, etc.) 601, which can perform various appropriate actions and processes according to a program stored in read-only memory (ROM) 602 or a program loaded from storage device 608 into random access memory (RAM) 603. RAM 603 also stores various programs and data required for the operation of electronic device 600. Processing device 601, ROM 602, and RAM 603 are interconnected via bus 604. Input / output (I / O) interface 605 is also connected to bus 604.

[0110] Typically, the following devices can be connected to I / O interface 605: input devices 606 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 607 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 608 including, for example, magnetic tapes, hard disks, etc.; and communication devices 609. Communication device 609 allows electronic device 600 to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 6 An electronic device 600 with various devices is shown; however, it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed alternatively.

[0111] In particular, according to embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device 609, or installed from a storage device 608, or installed from a ROM 602. When the computer program is executed by the processing device 601, it performs the functions defined in the methods of embodiments of this disclosure.

[0112] It is noted that the aforementioned computer-readable medium of the present disclosure can be a computer-readable signal medium or a computer-readable storage medium or any combination thereof. The computer-readable storage medium can be, for example and without limitation, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the computer-readable storage medium can include, but are not limited to, an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. In the present disclosure, the computer-readable storage medium can be any tangible medium that contains or stores a program used by or in connection with an instruction execution system, apparatus, or device. In the present disclosure, the computer-readable signal medium can include a computer-readable program code transmitted by a computer-readable signal medium, in a baseband or as a part of a carrier wave. Such a transmitted computer-readable signal medium can take a variety of forms, including but not limited to, electro-magnetic, optical, or any suitable combination of the foregoing. The computer-readable signal medium can also be any computer-readable medium that is not a computer-readable storage medium and that can be used to carry or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained in the computer-readable medium can be transmitted using any suitable medium, including but not limited to, wire, cable, RF, etc., or any suitable combination of the foregoing.

[0113] In some embodiments, communication can be conducted using any currently known or future developed network protocol, such as HTTP (HyperText Transfer Protocol), and can be interconnected with digital data communication of any form or medium (e.g., a communication network). Examples of communication networks include local area networks ("LAN"), wide area networks ("WAN"), internetworks (e.g., the Internet), and end-to-end networks (e.g., ad hoc end-to-end networks), as well as any currently known or future developed networks.

[0114] The aforementioned computer-readable medium can be contained in the aforementioned electronic device; or can exist separately without being assembled into the electronic device.

[0115] The computer readable medium described above carries one or more programs, when the one or more programs are executed by the electronic device, cause the electronic device to: obtain a first task request sent by a client to a large model application from a traffic proxy component; wherein the large model application is associated with at least one business model, the traffic proxy component is used to forward traffic of the client to a backend server, and the backend server is used to deploy the at least one business model, wherein different business models are used to process different types of tasks; performing business risk detection on the first task request according to a correspondence between the first task request and the at least one business model, to obtain a detection result, the detection result being used to represent whether the first task request has business risk; and processing the first task request according to the detection result.

[0116] Computer program code for carrying out operations of the present disclosure can be written in any one or more programming languages or combinations of languages including object or visual programming languages specifically, assembly language, C, C++, Java, Visual Basic, or the like. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).

[0117] The flow diagrams and the block diagrams in the drawings are illustrations of architectures, functionalities, and operations of possible implementations of systems, methods, and computer program products according to various embodiments of present disclosure. In this regard, each block in the flow diagrams or block diagrams can represent a module, a procedure, or a portion of code, which comprises one or more executable instructions for implementing the specified logical functions. It should also be noted that in some alternative implementations, the functions noted in the blocks can occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently or in the reverse order, depending on the functionality involved. It is also noted that each block of the block diagrams and / or flow diagrams, and combinations of blocks in the block diagrams and / or flow diagrams, can be implemented by dedicated hardware-based systems that perform the specified functions or operations, or by combinations of dedicated hardware and computer instructions.

[0118] The modules involved in the embodiments of the present disclosure can be implemented in the form of software, or can be implemented in the form of hardware. In some cases, the name of the module does not constitute a limitation on the module itself.

[0119] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. For example, and without limitation, example types of hardware logic components that can be used include Field-programmable Gate Arrays (FPGAs), Application-specific Integrated Circuits (ASICs), Application-specific Standard Products (ASSPs), System-on-a-chip (SOCs), Complex Programmable Logic Devices (CPLDs), etc.

[0120] In the context of the present disclosure, a machine-readable medium can be a tangible medium that contains or stores a program for use by or in connection with an instruction execution system, apparatus, or device. The machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the machine-readable storage medium will include one or more lines of a program of a processor, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0121] The above description is merely exemplary of the present disclosure and the application of the principles thereof. It is not intended to limit the disclosed concepts to the precise forms disclosed. Rather, it is intended to cover such departures from the present disclosure as come within the scope of the concepts disclosed herein and the patentable scope of the present disclosure. For example, the features described above can be interchanged with similar features disclosed (but not limited to) in the present disclosure and the application of the principles thereof.

[0122] Furthermore, while operations are depicted in a particular, sequential order, this should not be understood as requiring or implying that the operations are performed in the order depicted and described. Many of the operations can in fact be performed in parallel, concurrently, or in any order suitable for achieving the goals of the related steps. The above description is merely exemplary of the present disclosure and the application of the principles thereof. It is not intended to limit the disclosed concepts to the precise forms disclosed. Rather, it is intended to cover such departures from the present disclosure as come within the scope of the concepts disclosed herein and the patentable scope of the present disclosure. For example, the features described above can be interchanged with similar features disclosed (but not limited to) in the present disclosure and the application of the principles thereof.

[0123] Although the subject matter has been described in language specific to structural features and / or methodological acts, it is to be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims. With respect to the devices in the above-described embodiments, in which various modules perform operations, the specific manner in which the various modules perform the operations has been described in detail in the embodiments relating to the method. Here, no detailed explanation will be given.

Claims

1. A method for identifying business risks of large model applications, characterized in that, The method comprises: obtaining a first task request sent by a client to a large model application from a traffic proxy component; wherein the large model application is associated with at least one business model, the traffic proxy component is used to forward traffic of the client to a backend server, and the backend server is used to deploy the at least one business model, wherein different business models are used to process different types of tasks; performing business risk detection on the first task request according to a correspondence between the first task request and the at least one business model, to obtain a detection result, wherein the detection result is used to represent whether the first task request has business risk; processing the first task request according to the detection result.

2. The method for identifying business risks of large model applications according to claim 1, wherein, The business risk detection on the first task request according to the correspondence between the first task request and the at least one business model comprises: in a case where the business model corresponding to the first task request is a preset business model, performing content analysis on the first task request to obtain first analysis content; wherein the preset business model is a business model in the at least one business model that needs to be subjected to business risk detection; performing business risk detection on the first analysis content.

3. The method for identifying business risks of large model applications according to claim 2, characterized in that, The business risk detection on the first analysis content comprises: in a case where the first analysis content meets a preset detection rule corresponding to the preset business model, performing business risk detection on the first analysis content; wherein the preset detection rule represents a content matching rule for judging whether business risk detection is needed.

4. The method for identifying business risks of large model applications according to claim 1, wherein, The business risk detection on the first task request according to the correspondence between the first task request and the at least one business model comprises: obtaining a first business risk detection strategy of the business model corresponding to the first task request; wherein different business models correspond to different business risk detection strategies; performing business risk detection on the first task request according to the first business risk detection strategy.

5. The method for identifying business risks of large model applications according to any one of claims 1-4, characterized in that, The business risk detection on the first task request comprises: performing content analysis on second analysis content corresponding to the first task request, to determine a first large model for detecting the second analysis content from at least one large model, wherein the at least one large model is used to perform business risk detection on a task request according to a preconfigured business risk detection strategy; performing business risk detection on the second analysis content by using the first large model.

6. The method for identifying business risks of large model applications according to any one of claims 1-4, characterized in that, The obtaining of the first task request sent by the client to the large model application from the traffic proxy component comprises: in a first mode, intercepting the first task request from the traffic proxy component, wherein the first mode represents that the task request sent by the client to the large model application is intercepted and processed; The method further comprises: in a case where the detection result represents that the first task request has business risk and the business risk can be solved, routing the first task request in which the business risk has been solved to a corresponding backend server according to address information carried by the first task request; or, In the case that any of the following conditions is met, the first task request is routed to a corresponding backend server according to address information carried by the first task request: The business model corresponding to the first task request does not match a preset business model; wherein the preset business model is a business model in the at least one business model that needs to be subjected to business risk detection; The business model corresponding to the first task request matches the preset business model and the analysis content obtained by analyzing the first task request does not satisfy a preset detection rule corresponding to the preset business model; wherein the preset detection rule represents a content matching rule for judging whether business risk detection is needed; The detection result represents that the first task request does not have business risk.

7. The method for identifying business risks of large model applications according to any one of claims 1-4, characterized in that, The method further comprises: In the second mode, the first task request is copied from the traffic proxy component, and the second mode represents mirror processing of the task request sent by the client to the large model application.

8. The method for identifying business risks of large model applications according to any one of claims 1-4, characterized in that, The method further comprises: According to the detection result, a first processing strategy for the first task request is determined; Based on the first processing strategy, the first task request is processed.

9. The method for identifying business risks of large model applications according to any one of claims 1-4, characterized in that, The method further comprises: The first task request and the detection result corresponding to the first task request are stored in a first database, the first database is used to store historical task requests and detection results corresponding to the historical task requests, the historical task requests and the detection results corresponding to the historical task requests are used to construct training samples and / or generate analysis reports, the training samples are used to optimize at least one large model, and the at least one large model is used to detect business risk of a task request according to a preconfigured business risk detection strategy.

10. The method for identifying business risks of large model applications according to any one of claims 1-4, characterized in that, The method further comprises: The first task request is subjected to content analysis to obtain third analysis content, and the third analysis content includes resource information accessed by the first task request; In the case that the resource information satisfies a preset resource rule, the business model configuration information and / or the detection rule configuration information are updated based on the resource information; wherein the business model configuration information is used to configure a preset business model in the at least one business model that needs to be subjected to business risk detection, the detection rule configuration information is used to configure a preset detection rule corresponding to the preset business model, and the preset detection rule represents a content matching rule for judging whether business risk detection is needed.

11. The method for identifying business risks of large model applications according to any one of claims 1-4, characterized in that, The method further comprises: The data processing engine stores configuration information corresponding to the first configuration operation of the user in the management platform into a second database in response to the first configuration operation; wherein the configuration information includes at least one of business model configuration information, detection rule configuration information, and processing strategy configuration information; wherein the business model configuration information is used to configure a preset business model in the at least one business model that needs to perform business risk detection, the detection rule configuration information is used to configure a preset detection rule corresponding to the preset business model, the preset detection rule represents a content matching rule for judging whether business risk detection is needed, and the processing strategy configuration information is used to configure a processing strategy for a task request that exists business risk; The data processing engine distributes the business model configuration information in the second database to a traffic access engine, and distributes the detection rule configuration information and / or the processing strategy configuration information to a traffic analysis agent.

12. The method for identifying business risks of large model applications according to claim 11, wherein, The business risk detection on the first task request according to the correspondence between the first task request and the at least one business model includes: The traffic access engine judges whether the business model corresponding to the first task request is the preset business model based on the business model configuration information; The traffic analysis agent performs content analysis on the first task request to obtain fourth analysis content in the case that the business model corresponding to the first task request is the preset business model, and calls a large model engine to perform business risk detection on the fourth analysis content.

13. The method for identifying business risks of large model applications according to claim 12, characterized in that, The calling of the large model engine to perform business risk detection on the fourth analysis content includes: The traffic analysis agent performs content matching on the fourth analysis content and a preset detection rule corresponding to the preset business model; In the case that the result of the content matching indicates that the fourth analysis content meets the preset detection rule, the large model engine is called to perform business risk detection on the fourth analysis content.

14. The method for identifying business risks of large model applications according to claim 12 or 13, characterized in that, The method further includes: The large model engine acquires a preconfigured business risk detection strategy from a third database, wherein the preconfigured business risk detection strategy is determined in response to a second configuration operation of the user in the management platform; The calling of the large model engine to perform business risk detection on the fourth analysis content includes: The large model engine determines a second large model for detecting the fourth analysis content from at least one large model based on the fourth analysis content, and calls the second large model to perform business risk detection on the fourth analysis content based on the business risk detection strategy, wherein the at least one large model is used to perform risk detection on a task request according to the preconfigured business risk detection strategy.

15. The method for identifying large model application business risks according to claim 11, wherein, The processing of the first task request according to the detection result includes: The traffic analysis agent determines a second processing strategy for the first task request according to the detection result and the processing strategy configuration information; The first task request is processed according to the second processing strategy.

16. The method for identifying business risks of large model applications of any one of claims 1-4, wherein, The method further includes; store the first task request and the detection result corresponding to the first task request into a fourth database through a data processing engine, the fourth database being used for storing historical task requests and detection results corresponding to the historical task requests; construct training samples and / or generate an analysis report based on the historical task requests and the detection results corresponding to the historical task requests through a large model engine, the training samples being used for model optimization of at least one large model, the at least one large model being used for business risk detection of a task request according to a preconfigured business risk detection strategy.

17. An apparatus for identifying business risks in large-scale model applications, characterized in that, The apparatus comprises: an acquisition module configured to acquire a first task request sent by a client to a large model application from a traffic proxy component, wherein the large model application is associated with at least one business model, the traffic proxy component is configured to forward traffic of the client to a backend server, and the backend server is configured to deploy the at least one business model, wherein different business models are used to process different types of tasks; a detection module configured to perform business risk detection on the first task request according to a correspondence between the first task request and the at least one business model to obtain a detection result, wherein the detection result is used to represent whether the first task request has business risk; a processing module configured to process the first task request according to the detection result.

18. A computer readable medium having stored thereon a computer program, characterized in that, The computer program is executed by the processing apparatus to implement the steps of the method of any one of claims 1-16.

19. An electronic device, comprising: comprise: a storage device having a computer program stored thereon; a processing device configured to execute the computer program in the storage device to implement the steps of the method of any one of claims 1-16.

20. A computer program product comprising a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the method of any one of claims 1-16.