Information display method and device, equipment, storage medium and program product
By using a visual style that represents hierarchical relationships to display risk detection results in cybersecurity risk detection, the problem of information fragmentation in existing technologies is solved, and the efficiency of information acquisition is improved.
Patent Information
- Application Number
- CN202511232539.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-29
- Publication Date
- 2025-11-11
AI Technical Summary
In existing technologies, the presentation of cybersecurity risk detection results is mainly a flat display, which makes it difficult for relevant personnel to quickly find the risk-related information they need, thus reducing the efficiency of information acquisition.
The risk detection results are displayed using a visualization style that represents hierarchical relationships, including attack status, hit probability, attack percentage, risk level identifier, and risk impact information at the attack method level. The relationships between various attack methods are shown through visualizations such as tree diagrams and sunburst diagrams.
It enables rapid understanding of cybersecurity attack methods and their relationships, improving the efficiency of relevant personnel in finding risk-related information.
Smart Images

Figure CN120934880A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of network security technology, and in particular to an information display method, apparatus, device, storage medium, and program product. Background Technology
[0002] With the development of internet technology, the number of network-related resources is increasing, and the possibility of these resources being attacked by cyberattacks is also increasing. To improve resource security, network security risk detection of resources can be carried out according to certain strategies (such as regular monitoring) to obtain the risk detection results for the resources.
[0003] Currently, the presentation of risk assessment results for resources is mainly done in a flat, content-layout manner, where various risk assessment results are directly displayed on the relevant interface for viewing by relevant personnel. However, this presentation method makes it difficult for relevant personnel to find the risk-related information they need, resulting in low information retrieval efficiency. Summary of the Invention
[0004] To address the aforementioned technical problems, this disclosure provides an information display method, apparatus, device, storage medium, and program product.
[0005] In a first aspect, embodiments of this disclosure provide an information display method, the method comprising:
[0006] Displays the risk detection interface corresponding to the target resource;
[0007] In the risk detection interface, the risk detection results of the target resource across multiple attack method dimensions are displayed in a first visualization style that represents hierarchical relationships; wherein, the risk detection results include at least one of the following: attack status, hit probability, attack percentage, risk level identifier, and risk impact information corresponding to the attack method dimension.
[0008] Secondly, embodiments of this disclosure also provide an information display device, the device comprising:
[0009] The risk detection interface display module is used to display the risk detection interface corresponding to the target resource;
[0010] The risk detection result display module is used to display the risk detection results of the target resource in multiple attack method dimensions in the risk detection interface in a first visualization style that represents the hierarchical relationship; wherein, the risk detection results include at least one of the attack status, hit probability, attack ratio, risk level identifier and risk impact information corresponding to the attack method dimension.
[0011] Thirdly, embodiments of this disclosure also provide an electronic device, the electronic device comprising:
[0012] processor;
[0013] Memory, used to store executable instructions;
[0014] The processor is configured to read executable instructions from memory and execute the executable instructions to implement the information display method described in any embodiment of this disclosure.
[0015] Fourthly, embodiments of this disclosure also provide a computer-readable storage medium storing a computer program that, when executed by a processor, causes the processor to implement the information display method described in any embodiment of this disclosure.
[0016] Fifthly, embodiments of this disclosure also provide a computer program product for executing the information display method described in any embodiment of this disclosure.
[0017] The information display method, apparatus, device, storage medium, and program product of this disclosure can display the risk detection results of the target resource in multiple attack method dimensions in a first visualization style representing hierarchical relationships within the risk detection interface corresponding to the target resource. The risk detection results include at least one of the following: attack status, hit probability, attack percentage, risk level identifier, and risk impact information corresponding to the attack method dimension. This achieves the presentation of the risk detection results of the target resource from the attack method dimension and displays them in a hierarchical visualization, enabling relevant personnel to quickly understand the attack methods of the network security attacks suffered by the target resource, the correlation between each attack method, and the risk situation corresponding to each attack method, thereby improving the efficiency of relevant personnel in finding the risk-related information they need.
[0018] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in the embodiments of this disclosure are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation entry points are provided for users to choose to authorize or refuse. Attached Figure Description
[0019] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and elements are not necessarily drawn to scale.
[0020] Figure 1This is a schematic diagram illustrating the display effect of risk detection results in related technologies;
[0021] Figure 2 A flowchart illustrating an information display method provided in an embodiment of this disclosure;
[0022] Figure 3 A schematic diagram illustrating the display effect of risk detection results in a first visualization style, provided as an embodiment of this disclosure;
[0023] Figure 4 A schematic diagram illustrating another display effect of risk detection results in a first visualization style provided in this embodiment of the disclosure;
[0024] Figure 5 A schematic diagram illustrating the display effect of a risk detection interface provided in an embodiment of this disclosure;
[0025] Figure 6 A schematic diagram illustrating the display effect of a prompt word optimization interface provided in an embodiment of this disclosure;
[0026] Figure 7 This is a schematic diagram of the structure of an information display device provided in an embodiment of the present disclosure;
[0027] Figure 8 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this disclosure. Detailed Implementation
[0028] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.
[0029] It should be understood that the steps described in the method embodiments of this disclosure may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this disclosure is not limited in this respect.
[0030] The term "comprising" and its variations as used herein are open-ended inclusions, meaning "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Definitions of other terms will be given in the description below.
[0031] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.
[0032] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".
[0033] The names of messages or information exchanged between multiple devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of such messages or information.
[0034] In related technologies, after conducting network security risk detection on a specific resource, the risk detection results can be classified and summarized according to certain dimensions (such as time dimension, attack event dimension, etc., referred to as risk dimensions), and the classified and summarized results can be displayed in a flat manner. For example... Figure 1 As shown, the system can display the overall risk detection score, number of attack hits, total number of detected attacks, each risk dimension and its corresponding hit probability, etc. However, this information display method results in fragmented information, failing to present the relationships between different risk dimensions. Consequently, it fails to effectively highlight attacks / threats affecting network security, making it difficult for relevant personnel to accurately and quickly identify security threats, thus reducing information acquisition efficiency.
[0035] Based on the above, this disclosure provides an information display technical solution that presents risk detection results according to various attack methods, in order to display the detected security risks in a more professional and comprehensive manner. Furthermore, by displaying the risk detection results in a visual style that represents hierarchical relationships, the relationship between various attack dimensions can be more clearly shown, thereby establishing the relationship between various risk detection results. This allows relevant personnel to more quickly identify cybersecurity issues that require attention and improves the efficiency of information acquisition from risk detection results.
[0036] The information display method provided in this disclosure is applicable to scenarios where network security detection results of network-related resources are displayed. This method can be executed by an information display device, which can be implemented in software and / or hardware and can be integrated into an electronic device with display functionality. This electronic device may include, but is not limited to, smartphones, personal digital assistants (PDAs), tablet computers (Tablet PCs), laptops, desktop computers, mobile workstations, or servers.
[0037] Figure 2 A flowchart illustrating an information display method provided in an embodiment of this disclosure is shown. Figure 2 As shown, the information display method may include the following steps:
[0038] S210, Display the risk detection interface corresponding to the target resource.
[0039] The target resource is a network-related resource, which can be hardware devices, containers, clusters, or generative model-based software / hardware products within the network. For example, the target resource includes generative model-based products, which can be entities capable of autonomously perceiving their environment, making decisions, and executing actions. Specifically, the target resource can be software programs (such as chatbots, autonomous driving systems, etc.) and / or hardware devices (such as intelligent robots) that rely on generative models. Subsequent embodiments of this disclosure may use the example of a generative model-based product as the target resource for illustration.
[0040] Specifically, network security testing products can conduct network security risk detection on target resources according to certain strategies (such as periodicity) and obtain corresponding detection results. These results can include at least some information from initial attack details, such as the timestamp of the attack on the target resource, the attacker, the attack method, the number of attacks, whether the attack was successful, the severity of the attack, and the risk impact caused by the attack. The results can also include relevant information obtained through comprehensive analysis of each attack detail, such as the number of attacks corresponding to each risk level, categorized by attack / risk severity (i.e., risk level); the overall risk level of the target resource determined by a comprehensive assessment of the risk levels of each attack detail (i.e., comprehensive risk level); the specific score value obtained by a comprehensive assessment of each attack detail according to pre-set scoring rules (i.e., comprehensive risk score); and the score value of the target resource on each core dimension (also known as the risk impact dimension) of the risk assessment, obtained by analyzing each attack detail according to a risk assessment model in relevant technologies (i.e., risk impact value).
[0041] The risk detection information mentioned above can be presented to relevant personnel from a resource perspective. For example, electronic devices can display a list of resource information items that have undergone risk detection, including the information item corresponding to the target resource; or, electronic devices can push the risk detection information of the target resource to relevant personnel in some way. Then, relevant personnel can trigger the target resource according to the above information presentation method. For example, relevant personnel can trigger the information item corresponding to the target resource in the list, or trigger the relevant link in the pushed information. In this way, the electronic device can respond to the triggering operation and display the interface where the risk detection results of the target resource are located (i.e., the risk detection interface). This risk detection interface can be a separate page, or a display panel occupying a part of the page, etc. The risk detection interface can display basic information of the target resource, such as the target resource's identifier (e.g., name, number, etc.), the platform identifier of the platform it is on, a brief description of the target resource's functions, the time and time timestamps of the risk detection, etc. At the same time, the risk detection interface can also display various risk detection information described above.
[0042] S220. In the risk detection interface, the risk detection results of the target resource in multiple attack method dimensions are displayed in the first visualization style representing the hierarchical relationship. The risk detection results include at least one of the following: attack status, hit probability, attack ratio, risk level identifier, and risk impact information corresponding to the attack method dimension.
[0043] The first visualization style represents hierarchical relationships. It uses visual nesting to simulate logical nesting, such as tree diagrams, sunburst diagrams, indented lists, and other visualizations with hierarchical nesting logic. It helps relevant personnel quickly understand the relationships (e.g., parallel relationships, inclusion relationships) between different attack methods. Attack status refers to the existence of a cybersecurity attack in a certain dimension, and if so, whether that attack has been detected. Hit probability is the likelihood that an attack method will hit / act on a target (e.g., a system or vulnerability). It focuses on the coverage of the attack target and can be a value less than 1 or a fractional value. Attack percentage refers to the proportion of a certain attack method in the total number of attacks detected in a risk assessment, quantitatively reflecting the size / proportion of that attack method in the overall attack. Risk level labels represent the risk level. These can be text labels indicating the severity of the attack risk, such as "Severe," "High Risk," "Medium Risk," or "Low Risk," or corresponding icons. Risk impact information refers to the assessment information on the risks or impacts that a cyberattack poses to the cybersecurity of a target resource. This may include risk impact dimensions, risk impact values, and trends in risk impact.
[0044] Specifically, to improve the efficiency of information retrieval from risk detection results and enhance the convenience for relevant personnel to view the results, electronic devices can extract and organize information from the attack method dimension of the detection results, and render the results according to a first visualization style representing hierarchical relationships, displaying them on the risk detection interface. The content displayed by the nodes at each level in the first visualization style can be in the form of text, graphics, or a combination of text and graphics, etc.
[0045] The attack method dimensions mentioned above correspond to attack methods adapted to specific business scenarios. Attack methods can be determined based on prior attack methods relevant to the business scenario. For example, for a particular business scenario, relevant professionals can compile a knowledge base of potential cybersecurity attacks / threats that the industry may suffer, based on industry development trends. This knowledge base can include various attack methods corresponding to that industry. Attack methods can also be obtained by summarizing attack methods against security threats suffered by products similar to the target resource within a historical timeframe. In this way, displaying detection results through the attack method dimension allows relevant personnel to more directly understand the cyberattack situation suffered by the target resource.
[0046] In some embodiments, when the target resource includes a product based on a generative model, the attack method dimension includes subdivided attack methods of the target attack category. The target attack category can be determined using relevant industry knowledge bases based on generative models. For example, based on the entire lifecycle of the product based on the generative model, the target attack category can be determined according to different stages of the lifecycle. In this disclosure embodiment, the target attack category may include at least one of prompt-based attack categories, database-based attack categories, upstream / downstream access-based attack categories, and generative model-based attack categories. Specifically, prompt-based attack categories involve adding special instructions to the prompts in the input model to manipulate the product's output to conform to the attack intent, constituting a cybersecurity attack category. Database-based attack categories involve pre-injecting malicious or misleading data into a relevant database, causing the product to perform malicious operations when accessing the database during operation, constituting a cybersecurity attack category. Upstream / downstream access-based attack categories involve introducing special instructions into the product's upstream / downstream access requests, causing the product to perform malicious operations when processing access requests, constituting a cybersecurity attack category. Generative model-based attacks are a type of cybersecurity attack in which specific instructions are pre-embedded in the model upon which the product depends, causing the product to execute malicious operations when those instructions are triggered during operation.
[0047] The target attack category is a broad category, which is insufficient to help relevant personnel understand the cybersecurity threats suffered by the target resource. Therefore, in this embodiment, the attack method dimension can be set as a sub-category of attack methods under the target attack category. For example, if the target attack category is a prompt-based attack category, then the attack method dimension may include: direct command dimension, coded interaction dimension, context overload dimension, social attack dimension, dedicated token dimension, and hybrid technology dimension, etc.
[0048] In some embodiments, the content displayed by nodes at each level in the first visualization style may be in the form of text representing risk detection results. See also Figure 3 Taking the first visualization style as a tree diagram as an example, the root node represents the target resource, the first-level branches can represent the target attack category, the second-level branches can represent the subdivided attack methods of the target attack category, and the leaf nodes can represent the specific risk detection results corresponding to the subdivided attack methods, such as the hit probability, attack ratio, risk level label, risk impact dimension and its changing trend corresponding to a certain subdivided attack method. Figure 3 The upward arrow (indicating a situation where the risk impact is continuously expanding) illustrates this. If a second-level branch includes leaf nodes, it means that the attack status of the corresponding attack sub-method is that a cybersecurity attack of that attack sub-method exists and has been detected. Conversely, if a second-level branch does not contain leaf nodes, it means that the attack status of the corresponding attack sub-method is that a cybersecurity attack of that attack sub-method does not exist.
[0049] It should be noted that, Figure 3 This is just an example of a first-order visualization style, and the specific data in it is also for illustrative purposes.
[0050] In other embodiments, the content displayed by nodes at each level in the first visualization style can be a combination of text and graphics representing the risk detection results. Thus, displaying the risk detection results of the target resource across multiple attack method dimensions using the first visualization style that represents the hierarchical relationship includes: displaying the dimension identifiers of each attack method dimension corresponding to the target resource in the first visualization style; and displaying the risk detection results of the target resource across the corresponding attack method dimension in the display area where the dimension identifiers are located, using the second visualization style.
[0051] The dimension identifier is the identifying information of the attack method dimension, such as the name, abbreviation, or number of the attack method. For example, the dimension identifier is in natural language that relevant personnel can understand. The second visualization style is another visualization style, mainly implemented in a graphic and text format. Therefore, the second visualization style includes at least one of the following: a fourth text style, an icon, a region fill area, and a region fill color. The region fill color can be the color that fills the entire display area, or it can be the color that fills a local display area corresponding to the relevant indicators in the risk detection results. For example, the fourth text style can be used to express the risk detection results, combined with an icon and / or region fill color to indicate the attack status; the fourth text style can be used to express indicators such as hit probability, attack percentage, and ASR, while overlaying the region fill area corresponding to the indicator to more intuitively convey these indicators; the fourth text style can be used to express the risk level identifier, while overlaying the region fill area's region fill color to more intuitively represent the risk level; the fourth text style can be used to express risk impact information, while overlaying icons representing development trends (such as arrows or broken lines) to more intuitively represent the risk impact, etc.
[0052] Specifically, in this embodiment, the electronic device uses dimensional identifiers for each attack method dimension in a first visualization style to present the hierarchical relationship between the attack method dimensions. Then, the risk detection result corresponding to each attack method dimension is displayed in the display area where the corresponding attack method dimension identifier is located in a second visualization style. In this way, the attack methods and risk detection results in the first visualization style can be distinguished, allowing relevant personnel to more quickly understand the various network security attacks suffered by the target resource and the relationships between them through the hierarchical relationship; and the attack situation of each attack method can be better understood through the graphic and textual risk detection results in each display area; without the need for relevant personnel to interpret hierarchical information layer by layer, further improving the intuitiveness of the risk detection results and the efficiency of information acquisition.
[0053] In some embodiments, the first visualization style described above can be implemented as follows: Figure 4 The tree diagram shown uses the root node to represent the risk visualization as an "attack matrix" of attack methods. First-level branches subdivide attack methods, second-level branches further subdivide them, and leaf nodes represent even further subdivisions. Each node displays the name of the attack method dimension.
[0054] See Figure 4Taking the target attack category as a prompt-based attack category as an example, the first-level branch includes six attack methods: Direct Instruction refers to directly inputting malicious instructions or misleading prompts, triggering the product based on the generative model to output results consistent with the attack intent; Encoded Interaction refers to using specific encoding, style, syntax, and typography to trigger the product based on the generative model to respond with results consistent with the attack intent; Context Overload refers to injecting excessively long or complex context (such as irrelevant text, repetitive prompts, etc.) into the model, breaking the model's context window constraints, causing it to ignore security constraints or produce logical confusion, thereby outputting results consistent with the attack intent. Social Attacks refer to attackers using the model's anthropomorphic characteristics, learning ability, and context dependence, employing psychological techniques (such as authority inducement, urgency cues, or trust deception) to design prompts, causing the model to ignore security policies or perform unexpected operations, producing results consistent with the attack intent. Dedicated Tokens utilize the model's sensitive response to specific tokens (such as special marks or characters during model training) to trigger the model to hide behavior or bypass filtering rules, thereby producing results consistent with the attack intent. Hybrid Techniques refer to combining multiple attack methods mentioned above to produce results consistent with the attack intent. The attack methods in the second-level branches, such as output encoding, payload splitting, spelling errors, and scarce resources, are further refinements of the attack methods targeting encoding interactions. Alternative modal encoding and forced style encoding in leaf nodes represent even more refined attacks targeting output encoding. Rare dialects and informal expressions in leaf nodes represent even more refined attacks targeting scarce resources.
[0055] Based on the above embodiments, if the risk detection result includes the attack status, hit probability and attack ratio corresponding to the attack method dimension, then in the display area where the dimension identifier is located, the risk detection result of the target resource in the corresponding attack method dimension is displayed in the second visualization style, including: in the display area where the dimension identifier is located, the attack status is represented by an icon, and the hit probability and attack ratio are represented by a fourth text style, area filling area and area filling color.
[0056] There is a correspondence between the area fill color and the icon; that is, the area fill color matches the visual semantics of the icon. For example, if the visual semantics of the icon are warning or danger, then the area fill color can be red; if the visual semantics of the icon are safe or harmless, then the area fill color can be green, and so on.
[0057] Specifically, see [link to relevant documentation] Figure 4In the display area of the dimension identifier for each attack method dimension, electronic devices can use icons to represent the attack status of that attack method in this risk detection. For example, the first icon 401, with a shield and an exclamation mark, indicates that an attack method exists against the product and has been detected in this risk detection; the second icon 402, with a shield and a checkmark, indicates that an attack method exists against the product but has not been detected in this risk detection; and the third icon 403, with a cross, indicates that an attack method does not exist against the product.
[0058] For the hit probability and attack percentage, this embodiment can display the corresponding values using a fourth text style (such as color, font, font size, layout, etc.). Based on this, the area to be filled in the display area of the dimension identifier can be determined according to the hit probability or attack percentage values. Then, the area to be filled in the color corresponding to the aforementioned icon or its meaning. For example, for the direct command attack method dimension, if the hit probability is 4 / 10 and the attack percentage is 40%, then the corresponding value can be displayed in its display area, and the 40% area of the display area can be filled with a dark color or red / orange color scheme that represents visual semantics such as warning and danger; for the social attack attack method dimension, which has not been detected, the entire display area can be filled with a light color or blue / green color scheme that represents visual semantics such as safety and harmlessness; for the rare dialect attack method dimension, which does not exist in the product, then no color / pattern filling is required for its display area.
[0059] By setting the second visualization style with the above-mentioned icons, fourth text style, area fill area, and area fill color, the more important risk detection results in the business can be displayed more intuitively and clearly, thereby further improving the efficiency of information acquisition from the detection results.
[0060] In some embodiments, after displaying the risk detection results of the target resource in the corresponding attack method dimension in a second visualization style, the method further includes: in response to a first triggering operation on the display area, displaying first detailed information of the attack method dimension corresponding to the triggered display area in a third visualization style with information structured information in the surrounding area of the display area.
[0061] The first triggering operation is a relatively lightweight interaction method, such as a mouse hover operation or a click operation. The third visualization style is a visualization style that aggregates and displays various information in a structured form. For example, the third visualization style can be information-carrying components such as cards, lists, and pop-ups, and the content therein presents a structured layout. The first detailed information is more detailed risk detection-related information than the risk detection results. In this embodiment of the disclosure, the first detailed information includes at least one of the following: attack method description, attack success rate, risk level identifier, and risk impact information. The attack method description is information introducing the attack method. The attack success rate (ASR) is the probability that a network security attack successfully hits the target (such as triggering a system vulnerability, bypassing a set defense, etc.).
[0062] Specifically, the risk detection results displayed in the first visualization style are relatively brief key information. In order to convey more detailed risk detection results and improve the convenience of relevant personnel to obtain information, this embodiment of the disclosure can provide interactive operation functions on the basis of the first visualization style, so that relevant personnel can view more detailed risk detection results of the corresponding attack method dimension by interacting with the display area corresponding to any attack method dimension.
[0063] See also Figure 4 If the electronic device detects the user's first trigger operation (e.g., a click) on the display area of the "direct command", then it can display a visualization component 404 of aggregated information such as pop-ups or cards in the surrounding area of the display area, and display the first detailed information corresponding to the "direct command" in a third visualization style (such as a list style). Figure 4 The example describes the attack method of "direct command," its success rate and risk level in this detection, as well as the risk impact dimensions and their changing trends involved in "direct command" in this detection.
[0064] In some embodiments, after displaying the risk detection results of the target resource in the corresponding attack method dimension in a second visualization style, the method further includes: in response to a second triggering operation on the display area, displaying a risk details interface, and displaying second details information of the attack method dimension corresponding to the triggered display area in the risk details interface.
[0065] The second triggering operation is a relatively deep interaction method. The second triggering operation is more complex than the first triggering operation. For example, if the first triggering operation is a hover operation, the second triggering operation can be a single click; if the first triggering operation is a single click, the second triggering operation can be a double click, etc. The risk details interface is used to display more detailed risk detection information (i.e., the second details information). It can be a new page or a new display panel within an existing page. In this embodiment, the second details information includes the first details information and / or at least one attack detail of the target resource in the attack method dimension.
[0066] Specifically, if relevant personnel wish to view more detailed detection results, they can execute a second trigger operation on the display area for any attack method dimension. See also... Figure 4 Upon double-clicking the "direct command," the electronic device displays the risk details interface 405. The device can filter all initial attack details detected in this risk assessment using the attack method dimension of the "direct command," obtaining the attack details corresponding to each attack method dimension, and presenting these attack details in a list format on the risk details interface 405. This allows relevant personnel to drill down to view more detailed attack details for the corresponding dimension through the risk detection results presented in the first visual style, further improving the convenience and efficiency of viewing the detection results.
[0067] The information display method provided in this disclosure can display the risk detection results of the target resource in multiple attack method dimensions in a first visualization style representing hierarchical relationships on the risk detection interface corresponding to the target resource. The risk detection results include at least one of the following: attack status, hit probability, attack ratio, risk level identifier, and risk impact information corresponding to the attack method dimension. This realizes the presentation of the risk detection results of the target resource from the attack method dimension and displays them in a hierarchical visualization manner, enabling relevant personnel to quickly understand the attack methods of the network security attacks suffered by the target resource, the correlation between the attack methods, and the risk situation corresponding to each attack method, thereby improving the efficiency of relevant personnel in finding the risk-related information they need.
[0068] In some embodiments, after displaying the risk detection interface corresponding to the target resource, the method further includes: displaying the comprehensive risk score of the target resource in the risk detection interface using a fourth visualization style that represents the numerical range, and displaying the comprehensive risk level of the target resource, each risk level dimension, and the number of attacks corresponding to the risk level dimension using a fifth visualization style that is information-structured.
[0069] The fourth visualization style presents the numerical range and current value of a certain indicator in a combination of text and graphics. For example, the fourth visualization style could be a dashboard chart, progress bars of various shapes, a thermometer-style graph, etc. The comprehensive risk score integrates multi-dimensional and multi-type cybersecurity attack factors into a unified indicator value to intuitively reflect the overall risk level of the target resource. The fifth visualization style is another way to structure and display multiple pieces of information, such as a list format. The comprehensive risk level represents the overall risk level of the target resource.
[0070] Specifically, see Figure 5 The electronic device displays basic information 510 of the target resource in the top area of the risk detection interface, and a risk view module, primarily presented in a graphical format, can be displayed in the remaining area. In the risk view module, a first visualization style (example shown) can be used as described in the foregoing embodiments. Figure 4 The tree diagram shown displays the risk detection results 520 for the target resource across various attack dimensions. This risk detection result 520 has a zoom function, allowing relevant personnel to scale the tree diagram by performing corresponding operations on the zoom component. In addition, the electronic device can also display the comprehensive assessment result 530 of the target resource in this risk detection within the risk view module. This comprehensive assessment result 530 can display the comprehensive risk score of the target resource in a fourth visualization style (example: dashboard).
[0071] Electronic devices can determine the proportion of each risk level dimension based on the number of attacks detected in the target resource across different risk level dimensions during the current detection. This proportion is then used to divide the dashboard into arc-shaped scales, and each resulting local scale is filled with a color / pattern that matches the wind direction level dimension. For example, Figure 5 The system divides the target resource into scales based on the number of attacks across risk levels: "Low Risk," "Medium Risk," "High Risk," and "Severe Risk," filling each scale with light gray, medium gray, dark gray, and black, respectively. Based on this, electronic devices can display the target resource's overall risk score of "94" in the central area of the dashboard, and adjust the instrument pointer (…). Figure 5 (Example: Black circle) Position the cursor to the scale corresponding to the score. This allows relevant personnel to more intuitively understand the overall risk level of the target resource in this inspection through the dashboard chart.
[0072] To further quantify the detection results, the electronic device can display each risk level dimension and its corresponding attack count in a fifth visualization style (example: data table) below the dashboard chart. It also displays the overall risk level of the target resource (i.e., the comprehensive risk level) by summarizing each risk level dimension and its attack count.
[0073] In some embodiments, after displaying the risk detection interface corresponding to the target resource, the method further includes: displaying the comprehensive impact value of the target resource on each risk impact dimension in the risk detection interface using a sixth visualization style that characterizes the multi-dimensional data distribution.
[0074] The sixth visualization style is a graphical display style used to represent the distribution of data in multiple dimensions, such as radar charts, sunburst charts, box plots, etc.
[0075] Specifically, see [link to relevant documentation] Figure 5 In addition to displaying the risk detection results 520 for each attack method dimension and the overall comprehensive assessment result 530, the electronic device can also display the risk impact of each detected cybersecurity attack on the target resource from the risk impact / assessment dimension. The electronic device can calculate the comprehensive risk impact value (referred to as the comprehensive impact value) of the target resource in each risk impact dimension based on the risk impact dimensions involved in each attack detail of the target resource and their corresponding risk impact values. Then, using... Figure 5 Taking the example radar chart 540, the electronic device can use each risk impact dimension as an outward radiating indicator axis, and determine the data points on the corresponding indicator axis based on the comprehensive impact values obtained above. These data points constitute a polygon representing the risk impact of the target resource. In this way, the comprehensive situation of the target resource across multiple risk impact dimensions can be displayed more intuitively through the shape and area of the polygon.
[0076] In some embodiments, after displaying the comprehensive impact value of the target resource on each risk impact dimension in a sixth visualization style representing the multidimensional data distribution, the method further includes: in response to a third triggering operation on the risk impact dimension, displaying the changing trend information of the target resource on the corresponding risk impact dimension in the surrounding area of the triggered risk impact dimension.
[0077] Specifically, in the process of calculating the comprehensive impact value, for each risk impact dimension, the electronic device can sort the risk impact values corresponding to that dimension by timestamp to obtain the trend information of risk impact changes on each risk impact dimension. Then, the trend of risk impact changes is linked to the response risk impact dimension in the sixth visualization style mentioned above, and interactive operations are provided for it. In this way, when relevant personnel... Figure 5After the third trigger operation is performed on any risk impact dimension in the radar chart shown, the electronic device can display the corresponding trend information of the risk impact dimension in its surrounding area. This trend information can be represented, for example, as a line graph of the trend corresponding to the triggered risk impact dimension, as an arrow indicating overall enhancement or weakening of the triggered risk impact dimension, or as a radar chart that dynamically changes according to timestamps, etc. It is understandable that, if a dynamically changing radar chart is displayed, to highlight the change in the risk impact value of the triggered risk impact dimension, the risk impact values of other risk impact dimensions can be set to a composite impact value and kept constant, while the risk impact value of the triggered risk impact dimension changes. In this way, through interactive operations on the risk impact results presented in the sixth visualization style, relevant personnel can more quickly obtain information about the risk impact faced by the target resource.
[0078] In some embodiments, for an example where the target attack category is a prompt-based attack category, after displaying the risk detection results of the target resource across multiple attack method dimensions, the method further includes: displaying a prompt optimization interface in response to an optimization operation on the prompt corresponding to the target resource; in the prompt optimization interface, displaying the initial prompt in a first text style, displaying the content to be deleted in the initial prompt in a second text style, and displaying the content to be added in the initial prompt in a third text style.
[0079] The prompt optimization interface displays information related to optimizing or strengthening prompts. The first, second, and third text styles are all pre-defined text display styles. The first text style is the default text display style for prompts. The second and third text styles offer significantly better display effects compared to the first text style, such as visual differences in font style and layout. The initial prompt is the prompt before optimization. Content to be deleted is content suggested to be removed from the prompt. Content to be added is content suggested to be added to the prompt.
[0080] Specifically, for cue-based attacks, the attacks on target resources primarily originate from the cue words input into the model. Therefore, electronic devices can provide cue word optimization features to minimize vulnerabilities in the cue words, thereby enhancing the model's defense capabilities. For example, if an electronic device displays risk detection information entries for the target resource in a list format, then interactive components for cue word optimization can be provided within those entries. See also... Figure 5 The electronic device can provide an interactive component 550 with optimized prompts within the risk detection interface. If it detects that a relevant person has triggered the aforementioned interactive component, the electronic device can display the optimized prompt interface, such as... Figure 6As shown. See also Figure 6 In the suggestion optimization interface, the initial suggestion is displayed using the default first text style. Based on this, the content to be deleted from the initial suggestion is displayed using a second text style (double strikethrough in the example), and the content to be added to the initial suggestion is displayed using a third text style (underline in the example). This allows relevant personnel to more intuitively understand the specific locations in the initial suggestion that need optimization, as well as the specific optimization methods, thereby improving the efficiency and accuracy of suggestion optimization.
[0081] Understandably, relevant personnel can refer to the content to be deleted and the content to be optimized in the prompt word optimization interface and manually modify the corresponding positions in the initial prompt words.
[0082] In some embodiments, after displaying the initial prompt in a first text style, the content to be deleted in the initial prompt in a second text style, and the content to be added in the initial prompt in a third text style in the prompt optimization interface, the method further includes: in response to a triggering operation on the optimized content, displaying the optimization basis and the impact of rejecting optimization in the surrounding area of the optimized content.
[0083] The optimization content includes content to be deleted or added. The basis for optimization is the reason for deleting or adding the corresponding content. The impact of refusing optimization refers to the risk / harm that will occur if the prompt words are not optimized according to the optimization content. The above-mentioned optimization basis and the impact of refusing optimization can be comprehensively determined based on relevant network security regulations, the detection results of this risk detection, and business needs.
[0084] Specifically, see [link to relevant documentation] Figure 6 For each piece of content to be deleted or added, the electronic device provides a drill-down interactive function. Therefore, in response to the triggering operation of content to be deleted or added, the electronic device can display information display components 610 such as cards or pop-ups in its surrounding area, showing the optimization basis and the impact of rejecting optimization for the triggered content. This localized optimization interaction method ensures both the simplicity of the prompt optimization interface and allows relevant personnel to clearly and conveniently understand the basis and consequences of each optimization, thereby further improving the efficiency of prompt optimization.
[0085] In some embodiments, after displaying the initial prompt in a first text style, the content to be deleted in the initial prompt in a second text style, and the content to be added in the initial prompt in a third text style in the prompt optimization interface, the method further includes: displaying a partial copy component in the surrounding area of the content to be added; and performing a copy operation on the content to be added in response to a trigger operation on the partial copy component, so as to modify the initial prompt using the copy result.
[0086] Specifically, see [link to relevant documentation] Figure 6 For each piece of content to be added, the electronic device provides an interactive component (i.e., a partial copy component 620) for the partial copy function. When a user triggers a partial copy component 620, the electronic device responds to the trigger operation by copying the corresponding content to be added. The user can then paste the copied content to a suitable location, such as the corresponding position in the initial prompt, to modify the initial prompt at that location. This allows users to manually modify the initial prompt more efficiently, and also enables them to further modify and optimize the content based on the optimized content provided by the electronic device, thereby further improving the accuracy of the prompts.
[0087] In other embodiments, after displaying the initial prompt in a first text style, the content to be deleted in the initial prompt in a second text style, and the content to be added in the initial prompt in a third text style in the prompt optimization interface, the method further includes: displaying a global copy component in the prompt optimization interface; and performing a copy operation on the content to be added and the content in the initial prompt except for the content to be deleted in response to a trigger operation on the global copy component, so as to replace the initial prompt with the copy result.
[0088] Specifically, see [link to relevant documentation] Figure 6 The electronic device can also provide an interactive component (i.e., a global copy component 630) that allows copying all content in the prompt word optimization interface. When a user triggers the global copy component 630, the electronic device can respond to this trigger by copying the optimized initial prompt word. This optimized initial prompt word is obtained by deleting the corresponding content to be deleted according to its position and adding the corresponding content to be added according to its position. Then, the user can directly replace the initial prompt word with this new complete prompt word. This interactive setup allows for more efficient optimization of the initial prompt word.
[0089] The following are embodiments of the information display device provided in this disclosure. This device and the information display methods of the above embodiments belong to the same inventive concept. For details not described in detail in the embodiments of the information display device, please refer to the embodiments of the above information display methods.
[0090] Figure 7 A schematic diagram of the structure of an information display device provided in an embodiment of this disclosure is shown. Figure 7 As shown, the information display device 700 may include:
[0091] The risk detection interface display module 710 is used to display the risk detection interface corresponding to the target resource.
[0092] The risk detection result display module 720 is used to display the risk detection results of the target resource in multiple attack method dimensions in the risk detection interface in a first visualization style that represents the hierarchical relationship; wherein, the risk detection results include at least one of the attack status, hit probability, attack ratio, risk level identifier and risk impact information corresponding to the attack method dimension.
[0093] The information display device provided in this embodiment can display the risk detection results of the target resource in multiple attack method dimensions in a first visualization style representing hierarchical relationships on the risk detection interface corresponding to the target resource. The risk detection results include at least one of the attack status, hit probability, attack ratio, risk level identifier, and risk impact information corresponding to the attack method dimension. This realizes the presentation of the risk detection results of the target resource from the attack method dimension and displays them in a hierarchical visualization manner, enabling relevant personnel to quickly understand the attack methods of the network security attacks suffered by the target resource, the correlation between the attack methods, and the risk situation corresponding to each attack method, thereby improving the efficiency of relevant personnel in finding the risk-related information they need.
[0094] In some embodiments, the target resource includes products based on generative models;
[0095] The attack method dimension includes subdivided attack methods for target attack categories; among which, target attack categories include at least one of the following: prompt-based attack categories, database-based attack categories, upstream and downstream access-based attack categories, and generative model-based attack categories.
[0096] In some embodiments, the information display device 700 further includes a prompt word optimization module, used for:
[0097] In the risk detection interface, the risk detection results of the target resource in multiple attack method dimensions are displayed in the first visualization style representing the hierarchical relationship. In response to the optimization operation of the prompt words corresponding to the target resource, the prompt word optimization interface is displayed.
[0098] In the prompt word optimization interface, the initial prompt word is displayed in the first text style, the content to be deleted in the initial prompt word is displayed in the second text style, and the content to be added in the initial prompt word is displayed in the third text style.
[0099] In some embodiments, the risk detection result display module 720 includes:
[0100] The dimension identifier display submodule is used to display the dimension identifiers of each attack method dimension corresponding to the target resource in a first visualization style;
[0101] The risk detection result display submodule is used to display the risk detection results of the target resource in the corresponding attack method dimension in the display area where the dimension identifier is located, using a second visualization style; wherein, the second visualization style includes at least one of the fourth text style, icon, area fill area and area fill color.
[0102] Furthermore, the first visualization style includes a tree diagram style;
[0103] Accordingly, the risk detection results show that the submodule is specifically used for:
[0104] If the risk detection results include the attack status, hit probability, and attack percentage corresponding to the attack method dimension, then in the display area where the dimension identifier is located, the attack status is represented by an icon, and the hit probability and attack percentage are represented by the fourth text style, the area fill area, and the area fill color; among them, there is a corresponding relationship between the area fill color and the icon.
[0105] In some embodiments, the risk detection result display module 720 further includes a first details information display submodule, used for:
[0106] In the display area where the dimension identifier is located, after displaying the risk detection results of the target resource in the corresponding attack method dimension in the second visualization style, in response to the first trigger operation on the display area, in the surrounding area of the display area, the first detailed information of the attack method dimension corresponding to the triggered display area is displayed in the third visualization style with information structure; wherein, the first detailed information includes at least one of the attack method description, attack success rate, risk level identifier and risk impact information.
[0107] In other embodiments, the risk detection result display module 720 further includes a second details information display submodule, used for:
[0108] In the display area where the dimension identifier is located, after displaying the risk detection results of the target resource in the corresponding attack method dimension in the second visualization style, in response to the second trigger operation on the display area, the risk details interface is displayed, and the second details information of the attack method dimension corresponding to the triggered display area is displayed in the risk details interface; wherein, the second details information includes the first details information and / or at least one attack detail of the target resource in the attack method dimension.
[0109] In some embodiments, the information display device 700 further includes a comprehensive risk information display module, used for:
[0110] After displaying the risk detection interface corresponding to the target resource, the risk detection interface displays the comprehensive risk score of the target resource in the fourth visualization style, which represents the numerical range, and displays the comprehensive risk level of the target resource, each risk level dimension, and the number of attacks corresponding to each risk level dimension in the fifth visualization style, which is information-structured.
[0111] In some embodiments, the information display device 700 further includes an integrated impact information display module, used for:
[0112] After displaying the risk detection interface corresponding to the target resource, the risk detection interface displays the comprehensive impact value of the target resource in each risk impact dimension using a sixth visualization style that represents the multi-dimensional data distribution.
[0113] Furthermore, the comprehensive impact information display module is also used for:
[0114] After displaying the comprehensive impact value of the target resource on each risk impact dimension in the sixth visualization style that represents the multi-dimensional data distribution, in response to the third trigger operation on the risk impact dimension, the changing trend information of the target resource on the corresponding risk impact dimension is displayed in the surrounding area of the triggered risk impact dimension.
[0115] In some embodiments, the information display device 700 further includes an optimization-based display module, used for:
[0116] In the prompt word optimization interface, the initial prompt word is displayed in the first text style, the content to be deleted in the initial prompt word is displayed in the second text style, and the content to be added in the initial prompt word is displayed in the third text style. In response to the trigger operation on the optimized content, the optimization basis and the impact of rejecting optimization are displayed in the area around the optimized content. The optimized content includes the content to be deleted or the content to be added.
[0117] In some embodiments, the information display device 700 further includes an optimized content copying module, used for:
[0118] In the prompt word optimization interface, the initial prompt word is displayed in the first text style, the content to be deleted in the initial prompt word is displayed in the second text style, and the content to be added in the initial prompt word is displayed in the third text style. Then, a partial copy component is displayed in the area around the content to be added.
[0119] In response to a triggering operation on the partial copy component, a copy operation is performed on the content to be added, so as to modify the initial prompt word using the copy result.
[0120] In other embodiments, the optimized content copying module is also used for:
[0121] In the prompt word optimization interface, the initial prompt word is displayed in the first text style, the content to be deleted in the initial prompt word is displayed in the second text style, and the content to be added in the initial prompt word is displayed in the third text style. Then, the global copy component is displayed in the prompt word optimization interface.
[0122] In response to a triggering operation on the global copy component, a copy operation is performed on the content to be added and the content in the initial prompt (excluding the content to be deleted), so as to replace the initial prompt with the copy result.
[0123] The information display device provided in this disclosure can execute the information display method provided in any embodiment of this disclosure, and has the corresponding functional modules and beneficial effects of executing the method.
[0124] It is worth noting that in the embodiments of the above information display device, the various modules and sub-modules are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be realized; in addition, the specific names of each functional module / sub-module are only for easy differentiation and are not used to limit the protection scope of this disclosure.
[0125] This disclosure also provides an electronic device that may include a processor and a memory, the memory being used to store executable instructions. The processor can be used to read the executable instructions from the memory and execute them to implement the information display method described above.
[0126] Figure 8 A schematic diagram of the structure of an electronic device provided in an embodiment of this disclosure is shown.
[0127] like Figure 8 As shown, the electronic device 800 may include a processing unit 801 (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 802 or a program loaded from a storage device 808 into a random access memory (RAM) 803. The RAM 803 also stores various programs and data required for the operation of the electronic device 800. The processing unit 801, ROM 802, and RAM 803 are interconnected via a bus 804. An input / output interface (I / O interface) 805 is also connected to the bus 804.
[0128] Typically, the following devices can be connected to I / O interface 805: input devices 806 including, for example, touch screens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 807 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 808 including, for example, magnetic tapes, hard disks, etc.; and communication devices 809. Communication device 809 allows electronic device 800 to communicate wirelessly or wiredly with other devices to exchange data.
[0129] It should be noted that, Figure 8 The illustrated electronic device 800 is merely an example and should not be construed as limiting the functionality and scope of the embodiments disclosed herein. That is, although... Figure 8 An electronic device 800 with various devices is shown; however, it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed alternatively.
[0130] In particular, according to embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device 809, or installed from a storage device 808, or installed from a ROM 802. When the computer program is executed by a processing device 801, it performs the functions defined in the network isolation policy management method of any embodiment of this disclosure.
[0131] This disclosure also provides a computer-readable storage medium storing a computer program that, when executed by a processor, enables the processor to implement the network isolation policy management method in any embodiment of this disclosure.
[0132] It should be noted that the computer-readable medium described above in this disclosure can be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. Computer-readable storage media can be, for example, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), flash memory, optical fiber, portable compact disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this disclosure, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this disclosure, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. The transmitted data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. The computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, radio frequency (RF), etc., or any suitable combination thereof.
[0133] In some implementations, clients and servers can communicate using any currently known or future-developed network protocol, such as Hypertext Transfer Protocol (HTTP), and can interconnect with digital data communication (e.g., communication networks) of any form or medium. Examples of communication networks include Local Area Networks (LANs), Wide Area Networks (WANs), the Internet (e.g., the Internet), and peer-to-peer networks (e.g., ad hoc peer-to-peer networks), as well as any currently known or future-developed networks.
[0134] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device.
[0135] The aforementioned computer-readable medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to perform the network isolation policy management method described in any embodiment of this disclosure.
[0136] In embodiments of this disclosure, computer program code for performing the operations of this disclosure can be written in one or more programming languages or a combination thereof. These programming languages include, but are not limited to, object-oriented programming languages such as Java, Smalltalk, and C++, as well as conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0137] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of devices, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0138] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: Field Programmable Gate Array (FPGA), Application Specific Integrated Circuit (ASIC), Application Specific Standard Parts (ASSP), System on Chip (SOC), Complex Programmable Logic Device (CPLD), and so on.
[0139] The above description is merely a preferred embodiment of this disclosure and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features disclosed in this disclosure that have similar functions.
[0140] Furthermore, while the operations are described in a specific order, this should not be construed as requiring these operations to be performed in the specific order shown or in a sequential order. In certain environments, multitasking and parallel processing may be advantageous. Similarly, while several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of this disclosure. Certain features described in the context of individual embodiments may also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments.
[0141] Although the subject matter has been described using language specific to structural features and / or methodological logic, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are merely illustrative examples of implementing the claims.
Claims
1. An information display method, characterized in that, include: Displays the risk detection interface corresponding to the target resource; In the risk detection interface, the risk detection results of the target resource across multiple attack method dimensions are displayed in a first visualization style that represents hierarchical relationships; wherein, the risk detection results include at least one of the following: attack status, hit probability, attack percentage, risk level identifier, and risk impact information corresponding to the attack method dimension.
2. The method according to claim 1, characterized in that, The target resources include products based on generative models; The attack method dimension includes subdivided attack methods of target attack categories; wherein, the target attack categories include at least one of the following: attack categories based on prompt words, attack categories based on databases, attack categories based on upstream and downstream access, and attack categories based on generative models.
3. The method according to claim 2, characterized in that, After displaying the risk detection results of the target resource across multiple attack method dimensions in a first visualization style representing hierarchical relationships on the risk detection interface, the method further includes: In response to the optimization operation of the prompt words corresponding to the target resource, the prompt word optimization interface is displayed; In the prompt word optimization interface, the initial prompt word is displayed in a first text style, the content to be deleted in the initial prompt word is displayed in a second text style, and the content to be added in the initial prompt word is displayed in a third text style.
4. The method according to claim 1, characterized in that, The first visualization style, representing hierarchical relationships, displays the risk detection results of the target resource across multiple attack method dimensions, including: The dimension identifiers of each attack method dimension corresponding to the target resource are displayed in the first visualization style; In the display area where the dimension identifier is located, the risk detection result of the target resource in the corresponding attack method dimension is displayed in a second visualization style; wherein, the second visualization style includes at least one of a fourth text style, an icon, an area fill area, and an area fill color.
5. The method according to claim 4, characterized in that, The first visualization style includes a tree diagram style; If the risk detection result includes the attack status, hit probability, and attack percentage corresponding to the attack method dimension, then in the display area where the dimension identifier is located, the risk detection result of the target resource on the corresponding attack method dimension is displayed in a second visualization style, including: In the display area where the dimension identifier is located, the icon represents the attack state, and the fourth text style, the area filling area, and the area filling color represent the hit probability and the attack ratio; wherein, there is a corresponding relationship between the area filling color and the icon.
6. The method according to claim 4 or 5, characterized in that, After displaying the risk detection results of the target resource on the corresponding attack method dimension in the display area where the dimension identifier is located, using a second visualization style, the method further includes: In response to a first triggering operation on the display area, in the surrounding area of the display area, first detailed information of the attack method dimension corresponding to the triggered display area is displayed in a third visualization style with information structure; wherein, the first detailed information includes at least one of the attack method description, attack success rate, risk level identifier and risk impact information.
7. The method according to claim 4 or 5, characterized in that, After displaying the risk detection results of the target resource on the corresponding attack method dimension in the display area where the dimension identifier is located, using a second visualization style, the method further includes: In response to a second triggering operation on the display area, a risk details interface is displayed, and the risk details interface displays second details information corresponding to the attack method dimension of the triggered display area; wherein, the second details information includes first details information and / or at least one attack detail of the target resource in the attack method dimension.
8. The method according to claim 1, characterized in that, After displaying the risk detection interface corresponding to the target resource, the method further includes: In the risk detection interface, the comprehensive risk score of the target resource is displayed in a fourth visualization style that represents the numerical range, and the comprehensive risk level of the target resource, each risk level dimension, and the number of attacks corresponding to the risk level dimension are displayed in a fifth visualization style that is information-structured.
9. The method according to claim 1 or 8, characterized in that, After displaying the risk detection interface corresponding to the target resource, the method further includes: In the risk detection interface, the sixth visualization style, which represents the multi-dimensional data distribution, displays the comprehensive impact value of the target resource on each risk impact dimension.
10. The method according to claim 9, characterized in that, After displaying the comprehensive impact value of the target resource across each risk impact dimension in the sixth visualization style representing the multi-dimensional data distribution, the method further includes: In response to the third trigger operation on the risk impact dimension, the change trend information of the target resource on the corresponding risk impact dimension is displayed in the surrounding area of the triggered risk impact dimension.
11. The method according to claim 3, characterized in that, After displaying the initial prompt in a first text style, the content to be deleted in the initial prompt in a second text style, and the content to be added in the initial prompt in a third text style in the prompt optimization interface, the method further includes: In response to a trigger operation on the optimized content, the optimization criteria and the impact of rejecting optimization are displayed in the area surrounding the optimized content; wherein, the optimized content includes the content to be deleted or the content to be added.
12. The method according to claim 3, characterized in that, After displaying the initial prompt in a first text style, the content to be deleted in the initial prompt in a second text style, and the content to be added in the initial prompt in a third text style in the prompt optimization interface, the method further includes: A partial copy component is displayed in the area surrounding the content to be added; In response to a trigger operation on the local copy component, a copy operation is performed on the content to be added, so as to modify the initial prompt word using the copy result; Alternatively, the method may further include: The global copy component is displayed in the prompt word optimization interface; In response to a trigger operation on the global copy component, a copy operation is performed on the content to be added and the content in the initial prompt word, excluding the content to be deleted, so as to replace the initial prompt word with the copy result.
13. An information display device, characterized in that, include: The risk detection interface display module is used to display the risk detection interface corresponding to the target resource; The risk detection result display module is used to display the risk detection results of the target resource in multiple attack method dimensions in the risk detection interface in a first visualization style that represents the hierarchical relationship; wherein, the risk detection results include at least one of the attack status, hit probability, attack ratio, risk level identifier and risk impact information corresponding to the attack method dimension.
14. An electronic device, characterized in that, include: processor; Memory, used to store executable instructions; The processor is configured to read the executable instructions from the memory and execute the executable instructions to implement the information display method according to any one of claims 1-12.
15. A computer-readable storage medium, characterized in that, The storage medium stores a computer program, which, when executed by a processor, causes the processor to implement the information display method according to any one of claims 1-12.
16. A computer program product, characterized in that, The computer program product is used to implement the information display method according to any one of claims 1-12.
Citation Information
Patent Citations
Prompt word attack detection method and device for large language model
CN118445815A
Method and device for generating adversarial attack sample, storage medium and electronic equipment
CN119358605A
Network security data association analysis method and device, electronic equipment and storage medium
CN119788341A
Alarm information display method and device, equipment, storage medium and program product
CN120301756A