Network range credibility evaluation method, device, equipment and medium
By combining a large language model and a simulation knowledge base, a simulation evaluation scheme for network target ranges is automatically generated, which solves the problems of low efficiency and poor accuracy of manual evaluation in existing technologies and achieves efficient and accurate credibility evaluation.
Patent Information
- Application Number
- CN202510933021.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-04
- Publication Date
- 2025-11-18
AI Technical Summary
In existing technologies, the credibility assessment of network test ranges relies on human experience, resulting in low assessment efficiency, high cost, and poor accuracy, making it difficult to achieve automation and accurate simulation scheme development.
By acquiring user demand information, utilizing large language models and simulation knowledge bases, we automatically generate target simulation evaluation schemes, conduct evaluations based on target business domains and indicators, and obtain indicator parameters to determine credibility results.
It improves the efficiency and accuracy of cyber range credibility assessment, reduces manpower and time costs, and achieves an automated and standardized assessment process.
Smart Images

Figure CN120979688A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of network range, and particularly relates to a credibility evaluation method and device of a network range, equipment and a medium. BACKGROUND
[0002] A network range is a network security training and testing platform based on virtualization and simulation technology, which simulates a real network environment and a business scenario to provide a safe and controllable experimental space for attack and defense drills, vulnerability verification, security testing and personnel training. The security analysis of the network range is mainly performed by constructing a simulation range of the original range and verifying the security of the original range on the simulation range, and therefore the credibility of the simulation range is particularly important.
[0003] In the related art, a simulation scheme conforming to the requirements is formulated according to actual simulation requirements and combined with expert experience, and then the credibility of the simulation range is evaluated, however, the manual method depends on the experience of the staff to perform, which makes the credibility evaluation process time-consuming and laborious, and different simulation schemes need to be formulated for different simulation requirements, which is difficult to realize automatic evaluation, greatly increases the difficulty and time cost of manual evaluation, and due to the experience difference of the staff, inaccurate evaluation is likely to occur, thereby the efficiency and accuracy of the network range credibility evaluation are low, and the cost is high. SUMMARY
[0004] The main purpose of the embodiments of the present disclosure is to provide a credibility evaluation method, device, equipment and medium of a network range, which can improve the efficiency and accuracy of the network range credibility evaluation.
[0005] To achieve the above purpose, a first aspect of the embodiments of the present disclosure provides a credibility evaluation method of a network range, comprising:
[0006] obtaining credibility evaluation requirement information input by a user terminal for a target network range and a simulation range, and extracting a target business field and a target simulation dimension that need to be evaluated from the credibility evaluation requirement information;
[0007] obtaining a simulation degree knowledge base constructed in advance, and querying a target business index under the target simulation dimension from the simulation degree knowledge base under the index of the target business field;
[0008] constructing a first prompt text based on the target business field and the target business index, and inputting the first prompt text into a target large language model to generate a target simulation evaluation scheme with the target business index under the target business field;
[0009] According to the target simulation evaluation scheme, the simulation target range is evaluated, and an index parameter under the target business index in the evaluation process is obtained. According to the index parameter, a credibility evaluation result between the target network target range and the simulation target range is determined.
[0010] In some embodiments, the target business field and the target simulation dimension that need to be evaluated are extracted from the credibility evaluation requirement information, including:
[0011] The credibility evaluation requirement information is subjected to natural language recognition, and domain knowledge text and dimension knowledge text that need to be subjected to credibility evaluation are extracted. The domain knowledge text is encoded to obtain domain knowledge features, and the dimension knowledge text is encoded to obtain dimension knowledge features;
[0012] Based on the domain knowledge features, cosine similarity query is performed in a plurality of preset business domain features to obtain similar target business domain features;
[0013] The target business domain features and the dimension knowledge features are spliced to obtain spliced features, and the spliced features are input into a preset target large language model for feature fine-tuning to obtain fine-tuned features;
[0014] The target business domain features are decoded to obtain a target business domain, and the fine-tuned features are decoded to obtain a target simulation dimension.
[0015] In some embodiments, the simulation degree knowledge base is obtained by the following steps, including:
[0016] A plurality of sample data are obtained, wherein the sample data include industry standard documents, technical specification files, expert experience summaries, sample simulation evaluation schemes, sample credibility evaluation reports or papers;
[0017] The corresponding data preprocessing is performed on different types of sample data respectively to obtain preprocessed sample data;
[0018] The corresponding initial business domain, initial simulation dimension and initial business index are extracted from each preprocessed sample data, and a corresponding multi-layer knowledge graph is constructed according to the order of the initial business domain, the initial simulation dimension and the initial business index;
[0019] The simulation degree knowledge base is constructed based on the multi-layer knowledge graph corresponding to each sample data;
[0020] The target business domain is one of a plurality of initial business domains.
[0021] In some embodiments, the querying, under the index of the target business field, the target business indicator under the target simulation dimension from the simulation degree knowledge base comprises:
[0022] identifying the type of the target simulation dimension to obtain a type identification result;
[0023] if the type identification result indicates that the type of the target simulation dimension is a network topology dimension, generating a network topology edge dimension, a network topology node dimension, and a network topology overall dimension;
[0024] under the index of the target business field, querying, from the simulation degree knowledge base, an edge business indicator under the network topology edge dimension, a node business indicator under the network topology node dimension, and an overall business indicator under the network topology overall dimension;
[0025] determining the target business indicator under the target simulation dimension by combining the edge business indicator, the node business indicator, and the overall business indicator.
[0026] In some embodiments, the evaluating the simulation target range according to the target simulation evaluation scheme comprises:
[0027] sending the target simulation evaluation scheme to the user end for display;
[0028] obtaining scheme modification information input by the user end for the target simulation evaluation scheme, and constructing a second prompt text based on the scheme modification information and the target simulation evaluation scheme, inputting the second prompt text into the target large language model to adjust the target simulation evaluation scheme based on the scheme modification information, and outputting an adjusted target simulation evaluation scheme after adjusting the target business indicator;
[0029] evaluating the simulation target range according to the adjusted target simulation evaluation scheme.
[0030] In some embodiments, the evaluating the simulation target range according to the target simulation evaluation scheme and obtaining the indicator parameter under the target business indicator during the evaluation process comprises:
[0031] task decomposition of the target simulation evaluation scheme to generate a plurality of to-be-executed tasks;
[0032] executing each of the to-be-executed tasks in the simulation target range in sequence, and calling a plurality of application programming interfaces through the target large language model, and obtaining the indicator parameter under the corresponding target business indicator through the application programming interface during the execution of the to-be-executed task.
[0033] In some embodiments, the task decomposition of the target simulation evaluation scheme generates a plurality of to-be-executed tasks, including:
[0034] The task scheduling tool under the corresponding field is called based on the target business field, wherein the task scheduling tools under different fields are not the same;
[0035] The target simulation evaluation scheme is input into the task scheduling tool to decompose the target simulation evaluation scheme in the target business field and generate a plurality of to-be-executed tasks.
[0036] In some embodiments, the first prompt text is constructed based on the target business field and the target business indicator, and the target simulation evaluation scheme in the target business field with the target business indicator is generated by inputting the first prompt text into the target large language model, including:
[0037] The pre-constructed template prompt text is obtained, wherein the template prompt text is used to guide the target large language model to generate a simulation evaluation scheme in the functional dimension, the performance dimension and the security dimension;
[0038] The dynamic prompt text is constructed based on the target business field and the target business indicator, and the first prompt text is synthesized based on the template prompt text and the dynamic prompt text, and the target simulation evaluation scheme in the target business field with the target business indicator is generated in the functional dimension, the performance dimension and the security dimension by inputting the first prompt text into the target large language model.
[0039] In some embodiments, before the first prompt text is input into the target large language model, the network target range credibility evaluation method further includes:
[0040] An initial large language model is obtained, and the initial large language model is fine-tuned based on the simulation degree knowledge base and a preset fine-tuning method to obtain a fine-tuned large language model;
[0041] A basic framework is built for the fine-tuned large language model, and a data processing module, a prompt word management module and an application programming interface calling module are configured for the fine-tuned large language model on the basic framework to obtain an adjusted large language model framework;
[0042] The fine-tuned large language model is integrated with an evaluation result generation tool, a simulation degree knowledge base calling tool and a task scheduling tool on the adjusted large language model framework to obtain a target large language model.
[0043] To achieve the above object, a second aspect of the embodiment of the present disclosure provides a credibility evaluation device of a network range, comprising:
[0044] A data acquisition module is configured to acquire credibility evaluation requirement information input by a user terminal for a target network range and a simulation range, and extract a target business field and a target simulation dimension that need to be evaluated from the credibility evaluation requirement information.
[0045] An index acquisition module is configured to acquire a simulation degree knowledge base constructed in advance, and query a target business index under the target simulation dimension from the simulation degree knowledge base under the index of the target business field.
[0046] A scheme generation module is configured to construct a first prompt text based on the target business field and the target business index, and input the first prompt text into a target large language model to generate a target simulation evaluation scheme under the target business field and with the target business index.
[0047] A credibility evaluation module is configured to evaluate the simulation range according to the target simulation evaluation scheme, acquire an index parameter under the target business index in the evaluation process, and determine a credibility evaluation result between the target network range and the simulation range according to the index parameter.
[0048] To achieve the above object, a third aspect of the embodiment of the present disclosure provides an electronic device, which comprises a memory and a processor, the memory stores a computer program, and the processor implements the credibility evaluation method of the network range when executing the computer program.
[0049] To achieve the above object, a fourth aspect of the embodiment of the present disclosure provides a storage medium, which is a computer readable storage medium, the storage medium stores a computer program, and the computer program is executed by a processor to implement the credibility evaluation method of the network range.
[0050] The embodiment of the present disclosure can obtain the credibility evaluation requirement information input by the user terminal for the target network range and the simulation range, extract the target business field and the target simulation dimension that need to be evaluated from the credibility evaluation requirement information, obtain the simulation degree knowledge base constructed in advance, query the target business indicators under the target simulation dimension from the simulation degree knowledge base under the index of the target business field, construct the first prompt text based on the target business field and the target business indicators, input the first prompt text into the target large language model to generate the target simulation evaluation scheme with the target business indicators under the target business field, evaluate the simulation range according to the target simulation evaluation scheme, obtain the indicator parameters under the target business indicators in the evaluation process, and determine the credibility evaluation result between the target network range and the simulation range according to the indicator parameters.
[0051] Therefore, after obtaining the credibility evaluation requirement information input by the user terminal for the target network range and the simulation range, the embodiment of the present disclosure splits the credibility evaluation requirement from the field and the dimension, extracts the target business field and the target simulation dimension that need to be evaluated, queries the target business indicators under the target simulation dimension from the simulation degree knowledge base under the index of the target business field, so that the target business indicators obtained can accurately match the current credibility evaluation requirement, then constructs the first prompt text based on the target business field and the target business indicators, inputs the first prompt text into the target large language model to generate the target simulation evaluation scheme with the target business indicators under the target business field, and evaluates the simulation range according to the target simulation evaluation scheme, obtains the indicator parameters under the target business indicators in the evaluation process, and determines the credibility evaluation result between the target network range and the simulation range according to the indicator parameters.
[0052] Compared with the manual evaluation method according to the expert experience in the related art, the embodiment of the present disclosure indexes the target business indicators matched with the current credibility evaluation requirement based on the field and the dimension related information obtained by splitting, thereby avoiding the difference in manual subjective understanding of the credibility evaluation requirement, making the extracted target business indicators more accurate and efficient, then automatically generating the target simulation evaluation scheme through the target large language model, and determining the credibility evaluation result between the target network range and the simulation range based on the indicator parameters under the target business indicators in the execution process after evaluating the credibility of the simulation range according to the target simulation evaluation scheme, finally reducing the labor cost and time cost of the network range credibility evaluation, and improving the efficiency and accuracy of the network range credibility evaluation. BRIEF DESCRIPTION OF DRAWINGS
[0053] Figure 1is a scene schematic diagram of an implementation environment of a network range credibility evaluation method provided by an embodiment of the present disclosure.
[0054] Figure 2 is a flow schematic diagram of a network range credibility evaluation method provided by an embodiment of the present disclosure.
[0055] Figure 3 is Figure 2 is a flow schematic diagram further included in step 201 in the method.
[0056] Figure 4 is a flow schematic diagram of a simulation degree knowledge base construction process provided by an embodiment of the present disclosure.
[0057] Figure 5 is Figure 2 is a flow schematic diagram further included in step 202 in the method.
[0058] Figure 6 is Figure 2 is a flow schematic diagram further included in step 204 in the method.
[0059] Figure 7 is Figure 2 is another flow schematic diagram further included in step 204 in the method.
[0060] Figure 8 is Figure 2 is a flow schematic diagram further included in step 701 in the method.
[0061] Figure 9 is Figure 2 is a flow schematic diagram further included in step 203 in the method.
[0062] Figure 10 is a flow schematic diagram of a target large language model construction process provided by an embodiment of the present disclosure.
[0063] Figure 11 is a functional module schematic diagram of a network range credibility evaluation device provided by an embodiment of the present disclosure.
[0064] Figure 12 is a hardware structure schematic diagram of an electronic device provided by an embodiment of the present disclosure. DETAILED DESCRIPTION
[0065] In order for those skilled in the art to better understand the scheme of the present disclosure, the technical solutions in the embodiments of the present disclosure will be described clearly and completely below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only part of the embodiments of the present disclosure, not all the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present disclosure.
[0066] It can be understood that, in the specific embodiments of the present disclosure, the initial timing data, the initial sample timing data and the related data are involved, and when the embodiments of the present disclosure are applied to specific products or technologies, the permission or consent of the subject needs to be obtained, and the collection, use and processing of the related data need to comply with relevant laws, regulations and standards.
[0067] In addition, when the embodiments of the present disclosure need to call the initial timing data, the initial sample timing data and the related data, the separate permission or separate consent of the initial timing data, the initial sample timing data and the related data is obtained through a pop-up window or jumping to a confirmation page, and after the separate permission or separate consent of the initial timing data, the initial sample timing data and the related data is obtained, the necessary initial timing data, the initial sample timing data and the related data for enabling the embodiments of the present disclosure to normally operate are obtained.
[0068] In the embodiments of the present disclosure, the term "module" or "unit" refers to a computer program or a part of a computer program with a predetermined function, and works together with other related parts to achieve a predetermined target, and can be implemented entirely or partially by using software, hardware (such as a processing circuit or a memory) or a combination thereof. Similarly, one processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be a part of an integral module or unit that includes the functions of the module or unit.
[0069] Before the embodiments of the present disclosure are further described in detail, the terms and phrases involved in the embodiments of the present disclosure are explained, and the terms and phrases involved in the embodiments of the present disclosure are applicable to the following explanations:
[0070] Artificial intelligence (AI): It is a new technical science of researching and developing a theory, method, technology and application system for simulating, extending and expanding human intelligence; artificial intelligence is a branch of computer science, and artificial intelligence attempts to understand the essence of intelligence and produce a new intelligent machine that can react in a similar way to human intelligence. The research in this field includes robots, language recognition, image recognition, natural language processing and expert systems. Artificial intelligence can simulate the information process of human consciousness and thinking. Artificial intelligence is also a theory, method, technology and application system for simulating, extending and expanding human intelligence by using a digital computer or a digital computer controlled machine, perceiving the environment, acquiring knowledge and using the knowledge to obtain the best results.
[0071] The basic technologies of artificial intelligence generally include technologies such as sensors, special artificial intelligence chips, cloud computing, distributed storage, big data processing technologies, operation / interaction systems, mechatronics, and the like. The software technologies of artificial intelligence mainly include computer vision technologies, robot technologies, biometric identification technologies, speech processing technologies, natural language processing technologies, and machine learning / deep learning technologies.
[0072] AI Agent, namely, an AI intelligent agent, refers to an intelligent agent capable of actively thinking and acting, capable of working in a manner similar to humans, "understanding" user requirements through a large model, actively "planning" to achieve goals, using various "tools" to complete tasks, and finally "acting" to execute these tasks.
[0073] A cyber range is a network security training and testing platform based on virtualization and simulation technology, which simulates real network environments and business scenarios to provide a safe and controllable experimental space for attack and defense exercises, vulnerability verification, security testing, and personnel training. The security analysis of the network range is mainly to build a simulation range of the original range and verify the security of the original range on the simulation range, so the credibility of the simulation range is particularly important.
[0074] In the related art, it is often necessary to manually formulate a simulation scheme according to actual simulation requirements and in combination with expert experience, and then to perform credibility evaluation on the simulation range. However, the manual method relies on the experience of the staff to perform, so that the credibility evaluation process is time-consuming and laborious, and different simulation schemes need to be formulated for different simulation requirements, which makes it difficult to realize automatic evaluation, greatly increases the difficulty and time cost of manual evaluation, and due to the experience difference of the staff, it is easy to cause inaccurate evaluation, thereby resulting in low efficiency and accuracy of the credibility evaluation of the network range, and high cost.
[0075] In order to solve the above problems, the embodiments of the present disclosure provide a network range credibility evaluation method, device, equipment and medium, which can improve the efficiency and accuracy of the network range credibility evaluation.
[0076] Please refer to Figure 1 , Figure 1 The scene schematic diagram of the network range credibility evaluation method implementation environment provided by the embodiments of the present disclosure includes a terminal 101 and a server 102.
[0077] Exemplarily, the terminal 101 can serve as a user terminal and send information to the server 102, and the terminal 101 can also receive information sent by the user terminal and forward the information to the server 102. The server 102 can obtain, from the terminal 101, the credibility evaluation requirement information input for the target network range and the simulation range, and extract, from the credibility evaluation requirement information, the target business field and the target simulation dimension that need to be evaluated. The server 102 can obtain the pre-constructed simulation degree knowledge base, and query, under the index of the target business field, the target business index under the target simulation dimension from the simulation degree knowledge base. The server 102 can construct a first prompt text based on the target business field and the target business index, and input the first prompt text into the target large language model to generate a target simulation evaluation scheme under the target business field and with the target business index. The server 102 can evaluate the simulation range according to the target simulation evaluation scheme, and obtain the index parameters under the target business index in the evaluation process, and determine the credibility evaluation result between the target network range and the simulation range according to the index parameters.
[0078] The terminal 101 can be a mobile phone, a computer, a smart voice interaction device, a smart wearable device, a smart home appliance, a vehicle-mounted terminal, and the like, but is not limited thereto. The terminal 101 can also independently execute the credibility evaluation method of the network range. The terminal 101 and the server 102 can be directly or indirectly connected through wired or wireless communication, and the present disclosure is not limited in this regard.
[0079] The server 102 can be a standalone physical server, a server cluster or a distributed system composed of multiple physical servers, a cloud server providing cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN (Content Delivery Network), and basic cloud computing services such as big data and artificial intelligence platforms. In addition, the server 102 can also be a node server in a blockchain network.
[0080] It should be noted that Figure 1 The scene schematic diagram of the credibility evaluation method of the network range shown is only an example. The scene described in the present disclosure is used to more clearly illustrate the technical solutions of the present disclosure, and does not limit the technical solutions provided by the present disclosure. It is known to those skilled in the art that, as technology evolves and new business scenarios emerge, the technical solutions provided by the present disclosure are also applicable to similar technical problems.
[0081] Please refer to Figure 2 , Figure 2is a flowchart of a network range credibility evaluation method provided by the embodiments of the present disclosure. The network range credibility evaluation method can be applied in the server in the above-mentioned embodiments, or jointly executed by the terminal and the server. The network range credibility evaluation method comprises steps 201 to 204:
[0082] In step 201, the credibility evaluation requirement information input by the user terminal for the target network range and the simulation range is acquired, and the target business field and the target simulation dimension that need to be evaluated are extracted from the credibility evaluation requirement information.
[0083] In step 202, a pre-constructed simulation degree knowledge base is acquired, and the target business indicators under the target simulation dimension are queried from the simulation degree knowledge base under the index of the target business field.
[0084] In step 203, a first prompt text is constructed based on the target business field and the target business indicators, and the first prompt text is input into the target large language model to generate a target simulation evaluation scheme with the target business indicators under the target business field.
[0085] In step 204, the simulation range is evaluated according to the target simulation evaluation scheme, and the indicator parameters under the target business indicators in the evaluation process are acquired, and the credibility evaluation result between the target network range and the simulation range is determined according to the indicator parameters.
[0086] For the above step 201, the target network range is a real network security training and testing platform based on virtualization and simulation technology, which can be used to simulate actual network environment and business scenarios, and can be used for attack and defense drills, vulnerability verification, security testing and personnel training, etc. For example, an enterprise builds a target range to simulate its own core business network environment. Various real network security experiments can be conducted on this target range to detect possible security vulnerabilities in the network system, and also to provide a practical environment for training professional network security personnel for the enterprise.
[0087] The simulation range is a simulation platform built to verify the security of the target network range, which is a simulation of the target network range. By performing related tests and evaluations on the simulation range, the credibility and security of the target network range can be inferred. For example, in order to evaluate the target network range built by the above-mentioned enterprise, a simulation range similar to it is constructed, which is consistent with the target network range in network topology, business system, data flow, etc. Then various evaluation operations are performed on the simulation range to determine whether the target network range can truly and effectively simulate the actual network environment and meet the needs of network security training and testing.
[0088] The credibility evaluation requirement information is a specific evaluation requirement proposed by a user for a target network range and a simulation range, and contains multi-dimensional information such as a business scenario, a performance index, and a security requirement. It should be noted that the embodiment of the present disclosure can set a user end input interface on a terminal, and after the user inputs the credibility evaluation requirement information through the user end, the system is instructed to perform corresponding credibility evaluation on the simulation range according to the requirement.
[0089] The target business field is a specific business category according to the user requirement, such as the fields of financial transaction, industrial control, and energy grid. The target simulation dimension is a specific simulation level that needs to be focused on for evaluation, such as the dimensions of network topology, traffic characteristics, and protocol interaction.
[0090] It should be noted that in the prior art, manual analysis of requirements is easily affected by subjective experience, leading to omission or misjudgment of indicators. The embodiment of the present disclosure realizes accurate positioning of requirements by splitting abstract requirements into structured elements of fields and dimensions. For example, when the user proposes to evaluate the transaction security of a bank data center simulation range, the target business field can be extracted as “high-frequency financial transaction”, and the target simulation dimension can be extracted as “network traffic transmission”, avoiding deviation of evaluation direction caused by differences in manual understanding.
[0091] For the above step 202, the simulation degree knowledge base is a structured database pre-constructed by the embodiment of the present disclosure, used to store key evaluation indicators and expert experience data of each business field under different simulation dimensions. Further, the simulation degree knowledge base can also store related credibility evaluation methods, which are not specifically limited by the embodiment of the present disclosure. The target business indicator is a specific evaluation parameter for a specific field and dimension, such as throughput, delay jitter, and protocol compatibility.
[0092] It should be noted that traditional manual retrieval of indicators depends on expert memory, which is low in efficiency and prone to errors. The embodiment of the present disclosure automatically matches target indicators from the knowledge base through a field index mechanism, ensuring accuracy and efficiency. For example, under the PLC protocol simulation dimension in the industrial control field, the knowledge base can directly retrieve indicators such as “Modbus protocol response time” and “TCP / IP data frame integrity”, avoiding the time-consuming process of manually consulting literature or historical data.
[0093] For the above step 203, the first prompt text is a natural language instruction constructed based on the target business field and the target business indicator, used to guide the large language model to generate an evaluation scheme. The target large language model is an AI model fine-tuned in the field, which can also be an AI Agent, having the ability to understand professional scenarios and generate structured evaluation schemes.
[0094] After constructing the first prompt text based on the extracted target business field and target business indicators, the first prompt text is input into the target large language model. The model understands and analyzes the prompt text based on its own algorithm and learning ability, thereby generating a target simulation evaluation scheme. The target simulation evaluation scheme can include detailed test steps, configuration information of required tools, and verification standards, etc., providing specific execution basis for the credibility evaluation of the simulation target range, so that the evaluation process no longer relies on subjective judgment and experience of manual operation, but operates according to a standardized and structured scheme, thereby ensuring the accuracy and reliability of the evaluation results. Moreover, through automatic generation, the time for formulating the evaluation scheme is greatly shortened, and the overall efficiency of the network target credibility evaluation is improved.
[0095] Further, the embodiments of the present disclosure can also obtain the evaluation method required by the corresponding target business indicators from the simulation degree knowledge base, thereby constructing the first prompt text together. Subsequently, after inputting the first prompt text into the target large language model, the model can output the target simulation evaluation scheme containing the evaluation method.
[0096] It should be noted that the traditional manual writing of the evaluation scheme requires several hours to several days, and the quality depends on experience. The embodiments of the present disclosure trigger the few-shot learning ability of the large model through the prompt text, and automatically generate the target simulation evaluation scheme containing test steps, verification standards, etc. For example, inputting the prompt text "financial field network traffic simulation evaluation needs to include PFC / ECN mechanism test, and the indicators are throughput and delay jitter", the model can quickly generate a scheme containing traffic generation parameters, congestion scenario simulation, and indicator collection method.
[0097] For the above step 204, the indicator parameter is the specific value measured in the evaluation process, such as the measured value of network delay, the success rate of vulnerability detection, etc. The credibility evaluation result is the credibility degree of the simulation target range quantitatively obtained based on the comparison between the indicator parameter and the expected value. For example, the credibility evaluation result can be a binary result, such as credible and not credible, or the credibility evaluation result can be a percentage, with a higher value representing a higher credibility of the simulation target range, and vice versa. Alternatively, the credibility evaluation result can be a label of the credibility degree, such as high, medium and low, etc.
[0098] It should be noted that the traditional manual evaluation relies on subjective scoring, with a high error rate. The embodiments of the present disclosure realize objective evaluation of credibility through standardized indicator parameter collection and quantitative analysis. For example, in financial traffic simulation, the measured high-priority transaction delay is 50 microseconds, compared with the target value of 40 microseconds, the credibility deviation rate can be calculated, avoiding the inaccuracy caused by manual subjective judgment.
[0099] To sum up, by performing the credibility evaluation method of the network target range in steps 201 to 204, after obtaining the credibility evaluation requirement information input by the user end for the target network target range and the simulation target range, the credibility evaluation requirement is split in terms of field and dimension, the target business field and the target simulation dimension that need to be evaluated are extracted, then the target business indicators under the target simulation dimension are queried from the simulation degree knowledge base under the index of the target business field, so that the obtained target business indicators can accurately match the current credibility evaluation requirement, then the first prompt text is constructed based on the target business field and the target business indicators, and the first prompt text is input into the target large language model to generate the target simulation evaluation scheme with the target business indicators in the target business field, so that the simulation target range can be evaluated according to the target simulation evaluation scheme, and the index parameters under the target business indicators in the evaluation process are obtained, and the credibility evaluation result between the target network target range and the simulation target range is determined according to the index parameters.
[0100] Compared with the evaluation method of manually evaluating according to expert experience in the related art, the embodiment of the present disclosure indexes the target business indicators matched with the current credibility evaluation requirement on the split field and dimension related information, thereby avoiding the difference in manual subjective understanding of the credibility evaluation requirement, making the extracted target business indicators more accurate and efficient, then the target simulation evaluation scheme is automatically generated through the target large language model, after the credibility evaluation of the simulation target range according to the target simulation evaluation scheme, the credibility evaluation result between the target network target range and the simulation target range can be determined based on the index parameters under the target business indicators in the execution process, finally the human cost and time cost of the network target range credibility evaluation can be reduced, and the efficiency and accuracy of the network target range credibility evaluation are improved.
[0101] Next, the further included contents in steps 201 to 204 in the embodiment of the present disclosure are described in detail.
[0102] Please refer to Figure 3 , Figure 3 is Figure 2 the flowchart further included in step 201. In some embodiments, the process of extracting the target business field and the target simulation dimension that need to be evaluated from the credibility evaluation requirement information can further include steps 301 to 304:
[0103] Step 301, performing natural language recognition on the credibility evaluation requirement information, extracting field knowledge text and dimension knowledge text that need to be evaluated, and encoding the field knowledge text to obtain field knowledge features and encoding the dimension knowledge text to obtain dimension knowledge features;
[0104] At step 302, the cosine similarity is queried in the preset plurality of business domain features based on the domain knowledge feature, and similar target business domain features are obtained.
[0105] At step 303, the target business domain feature is spliced with the dimension knowledge feature to obtain a spliced feature, and the spliced feature is input into a preset target large language model for feature fine-tuning to obtain a fine-tuned feature.
[0106] At step 304, the target business domain feature is decoded to obtain a target business domain, and the fine-tuned feature is decoded to obtain a target simulation dimension.
[0107] In the above steps, the disclosed embodiments can perform natural language recognition on the credibility evaluation requirement information, extract domain knowledge text and dimension knowledge text that need to be evaluated for credibility, and encode the domain knowledge text to obtain domain knowledge features and encode the dimension knowledge text to obtain dimension knowledge features. Natural language recognition refers to a technology that enables computers to understand human natural language, and can convert human input natural language text into structured information that computers can process. The domain knowledge text is text content related to the business domain in the credibility evaluation requirement information, and the dimension knowledge text is text content related to the evaluation dimension in the credibility evaluation requirement information.
[0108] It should be noted that the credibility evaluation requirement information is usually input in the form of human natural language, which cannot be directly processed by computers. By natural language recognition, the domain knowledge text and the dimension knowledge text are extracted and encoded, which can convert unstructured natural language information into structured feature data that computers can understand and process, laying a foundation for subsequent accurate extraction of the target business domain and the target simulation dimension. For example, without natural language recognition and encoding, it is difficult for a computer to accurately obtain the information of the business domain "social network" and the simulation dimension "user authentication" from the sentence "I want to evaluate the credibility of the social network target in user authentication".
[0109] Then, the embodiment of the present disclosure can perform cosine similarity query in the preset plurality of business domain features based on the domain knowledge feature, to obtain a similar target business domain feature. The preset plurality of business domain features are encoding feature vectors of different business domains stored in the system in advance, covering various common business domains, and used for comparison with the extracted domain knowledge feature. The cosine similarity query is a method provided by the embodiment of the present disclosure for measuring the similarity between two vectors. The cosine value of the angle between the two vectors is calculated to determine their similarity. The closer the cosine value is to 1, the more similar the two vectors are. For example, assuming that there are preset business domain feature vectors A (representing the financial domain), B (representing the medical domain), and C (representing the education domain), the cosine similarity of the domain knowledge feature obtained in step 301 is calculated with A, B, and C respectively. If the cosine similarity with A is the highest, then A is the similar target business domain feature.
[0110] It should be noted that, due to the large number and diversity of business domains, it is difficult to directly determine the accurate business domain corresponding to the input demand. Through cosine similarity query, the embodiment of the present disclosure can find the target business domain feature most similar to the extracted domain knowledge feature from the preset plurality of business domain features, thereby accurately determining the target business domain and avoiding the subjectivity and errors of manual judgment.
[0111] Subsequently, the embodiment of the present disclosure also splices the target business domain feature with the dimension knowledge feature to obtain a spliced feature, and inputs the spliced feature into the preset target large language model for feature fine-tuning to obtain a fine-tuned feature. The splicing is to connect two or more feature vectors together according to certain rules to form a new feature vector. In the embodiment of the present disclosure, the target business domain feature and the dimension knowledge feature are spliced into a new vector feature, referred to as a spliced feature.
[0112] Feature fine-tuning is a process in which the target large language model re-encodes and transforms the spliced feature based on its existing parameters and learning ability after receiving the spliced feature. The large language model learns and understands the business domain and simulation dimension information contained in the spliced feature, adjusts the representation form of the feature, and makes it more suitable for the needs of network target range credibility evaluation tasks. For example, for the spliced feature of the "financial" business domain feature and the "data encryption" dimension knowledge feature, the model will optimize the spliced feature based on the knowledge about finance and data encryption accumulated in a large amount of text learning, and highlight the key information related to credibility evaluation.
[0113] The fine-tuning feature is the output result of the target large language model after completing the feature fine-tuning on the spliced feature, is a feature vector after deep processing and optimization of the large language model, and more accurately reflects the correlation information of the business field and the simulation dimension in the current credibility assessment demand, as well as the specific direction and key elements in the credibility assessment task after the combination of the two, thereby providing a more targeted and valuable information basis for subsequent accurate extraction of the target simulation dimension.
[0114] It should be noted that the target business field feature and the dimension knowledge feature alone may not fully reflect the correlation and specific requirements between the two. The disclosed embodiments combine the two by splicing and fine-tune them using a target large language model, which can mine the potential relationship and specific requirement details between the business field and the simulation dimension, and obtain fine-tuning features that more accurately reflect the credibility assessment requirements, thereby providing support for accurately extracting the target simulation dimension.
[0115] Finally, the disclosed embodiments decode the target business field feature to obtain the target business field, and decode the fine-tuning feature to obtain the target simulation dimension. Decoding is the opposite of encoding, which converts the feature in the form of numerical vectors processed by the computer back to the natural language text form understandable by humans. Through decoding, the feature is converted into specific business field and simulation dimension text, realizing the conversion from computer-processed data to human-readable information.
[0116] Please refer to Figure 4 , Figure 4 is a flowchart of the simulation degree knowledge base construction process provided by the disclosed embodiments. In some embodiments, the simulation degree knowledge base is obtained through the following steps, which can further include steps 401 to 404:
[0117] Step 401, obtaining a plurality of sample data;
[0118] The sample data includes industry standard documents, technical specification files, expert experience summaries, sample simulation evaluation schemes, sample credibility evaluation reports or papers.
[0119] Step 402, respectively pre-processing the different types of sample data to obtain pre-processed sample data;
[0120] Step 403, extracting the corresponding initial business field, initial simulation dimension and initial business indicator from each pre-processed sample data, and constructing a corresponding multi-layer knowledge graph according to the order of the initial business field, the initial simulation dimension and the initial business indicator;
[0121] Step 404, constructing a simulation degree knowledge base based on the multi-layer knowledge graph corresponding to each sample data;
[0122] The target business field is one of a plurality of initial business fields.
[0123] In the above steps, the sample data refers to various types of materials obtained from different channels, containing rich network range related knowledge information, which is the original material for constructing the simulation degree knowledge base. The embodiments of the present disclosure can widely collect various sample data related to the network range, specifically covering industry standard documents, technical specification files, expert experience summaries, sample simulation evaluation schemes, sample credibility evaluation reports or papers, etc. These data sources are diverse, from official industry standards to valuable experience accumulated by experts in practice, to existing evaluation schemes and reports, all of which are within the collection range.
[0124] The reason why multiple types of sample data are obtained in the embodiments of the present disclosure is that a single type of data cannot comprehensively cover all knowledge and experience involved in network range credibility evaluation. For example, industry standard documents can provide authoritative specifications and requirements, clearly defining the requirements for the basic architecture and functional modules of the range; expert experience summaries contain tips and precautions in actual operation, such as key points for vulnerability verification in specific scenarios summarized by a senior network security expert in long-term attack and defense drills. By collecting diverse data, the embodiments of the present disclosure can provide sufficient and comprehensive information basis for subsequent construction of a comprehensive and accurate simulation degree knowledge base.
[0125] Data preprocessing is a process of performing a series of operations on original sample data to improve data quality and usability, which can make different types and formats of data standardized and unified, facilitating subsequent knowledge extraction and graph construction. Since different types of sample data differ in format, content organization, etc., different preprocessing methods need to be adopted, including removing redundancy and noise, format unification, professional term standardization, context relationship annotation, and multi-industry data collection and cleaning, etc. Therefore, the embodiments of the present disclosure can extract structured fields such as core indicators, evaluation processes, and constraint conditions from Internet crawled simulation evaluation schemes in various fields (such as structural engineering cases and autonomous driving test scenarios) through natural language technology, and perform word segmentation and entity recognition (such as identifying professional terms such as “HNSW index structure” and “NDCG indicator”) on unstructured text (such as evaluation reports and logs).
[0126] For example, different types of sample data have different data preprocessing methods. For example, for industry standard documents and technical specification files, redundant format information can be removed and key text content can be extracted; for expert experience summaries and papers, text cleaning can be performed to remove typos and repetitive sentences; for sample simulation evaluation schemes and sample credibility evaluation reports, structured data (such as information in tables and charts) can be extracted and converted to a unified format for subsequent processing.
[0127] Then, the embodiment of the disclosure extracts the corresponding initial business field, initial simulation dimension and initial business index from each pre-processed sample data, and constructs a corresponding multi-layer knowledge graph in the order of the initial business field, the initial simulation dimension and the initial business index. Among them, the initial business field is the different classification of network range related business extracted from the sample data, which is used to divide the knowledge at a macro level, and the target business field is one of the multiple initial business fields. The initial simulation dimension is a further subdivision of the simulation content under the initial business field, which helps to more specifically describe various aspects of network range simulation. The initial business index is a specific parameter for measuring the effect and credibility of network range simulation, and is a key basis in the evaluation process. The multi-layer knowledge graph is to associate and display the initial business field, the initial simulation dimension and the initial business index in a hierarchical structure, which intuitively presents the relationship between the knowledge, and is convenient for subsequent query and use.
[0128] It should be noted that constructing a multi-layer knowledge graph can structure and integrate the scattered knowledge in the sample data, making the relationship between the knowledge more clear and explicit, forming a three-layer graph relationship of field-scene-index. In this way, when querying the target business index subsequently, the target business index can be quickly located through the index of the business field and the simulation dimension, improving the efficiency of knowledge acquisition. For example, the industrial control field-equipment simulation scene-protocol restoration degree, timing error rate and other indexes can be directly found through the multi-layer knowledge graph without searching one by one in a large amount of disordered data. Further, the embodiment of the disclosure can also express the knowledge association through RDF triple (for example: <structural engineering simulation, evaluation method, finite element analysis>).
[0129] Please refer to Figure 5 , Figure 5 is Figure 2 the flowchart further included in step 202. In some embodiments, the process of querying the target business index under the target simulation dimension from the simulation degree knowledge base under the index of the target business field can further include steps 501 to 504:
[0130] Step 501, identifying the type of the target simulation dimension to obtain a type identification result;
[0131] Step 502, if the type identification result represents that the type of the target simulation dimension is a network topology dimension, generating a network topology edge dimension, a network topology node dimension and a network topology overall dimension;
[0132] Step 503, under the index of the target business field, querying the edge business index under the network topology edge dimension, the node business index under the network topology node dimension and the overall business index under the network topology overall dimension from the simulation degree knowledge base, respectively;
[0133] In step 504, the joint edge service index, node service index and overall service index are used to determine the target service index under the target simulation dimension.
[0134] In the above steps, the specific type of the extracted target simulation dimension can be analyzed and judged by the specific algorithm or program processing, and it is determined that the target simulation dimension belongs to which type of dimension. Finally, the type identification result is output, and the type identification result is used to identify the type of the target simulation dimension, which can clearly define which category the target simulation dimension belongs to, such as network topology dimension, network communication dimension, data processing dimension and many other dimension types.
[0135] It should be noted that different types of target simulation dimensions have different ways and focuses of subsequent query service indexes. Only by identifying the type first can subsequent operations be targeted to ensure that the queried service index meets the evaluation requirements. For example, if it is not clear whether the target simulation dimension is a network topology dimension or a business process dimension, subsequent blind query of service indexes may result in indexes that do not match the actual evaluation requirements.
[0136] When the type identification result shows that the target simulation dimension belongs to the network topology dimension, the network topology dimension can be further subdivided into three sub-dimensions. Among them, the network topology dimension is used to describe the layout and structure related simulation dimensions of devices, nodes and connection relationships in the network, for example, the topology structure of an enterprise internal network, which contains nodes such as servers, switches, routers and their connection edges. The simulation evaluation of such a structure involves the network topology dimension. The network topology edge dimension focuses on the relevant characteristics of the connection edges between nodes in the network, mainly studying the relevant attributes of the connection lines (edges) between nodes in the network, such as bandwidth, delay, reliability, etc. The network topology node dimension focuses on the attributes and states of each node in the network, focusing on the attributes of each node (such as servers, terminal devices, etc.) in the network, such as processing power, storage capacity, security protection configuration, etc. The network topology overall dimension considers the characteristics of the entire network topology structure from a macro perspective, such as the overall characteristics of network connectivity, redundancy, scalability, etc.
[0137] It should be noted that the network topology structure is relatively complex, and a single dimension is difficult to comprehensively evaluate its simulation credibility. The network topology dimension is divided into edge, node and overall three sub-dimensions by the embodiment of the disclosure, which can more detailedly and comprehensively analyze and evaluate the network topology structure, avoid missing key evaluation elements, and improve the accuracy and comprehensiveness of the evaluation. For example, when evaluating a large enterprise network (such as a government enterprise), only focusing on the configuration of the node and ignoring the bandwidth limit of the connection edge may lead to inaccurate evaluation of the network performance, and after subdivision, it can be more accurately evaluated.
[0138] Then, the embodiment of the present disclosure can take the target business field as the index basis, and in the pre-constructed simulation degree knowledge base, the business indicators corresponding to the network topology edge dimension, the network topology node dimension and the network topology overall dimension are searched respectively to obtain the edge business indicators under the network topology edge dimension, the node business indicators under the network topology node dimension and the overall business indicators under the network topology overall dimension. Through the target business field index and the subdivided network topology sub-dimension, the business indicators meeting the current evaluation requirements can be quickly and accurately located, the query efficiency and the index matching degree are improved, and reliable data support is provided for subsequent accurate evaluation.
[0139] Among them, the edge business indicators are specific indicators for measuring and evaluating the relevant characteristics of the network connection edge under the network topology edge dimension, such as link bandwidth utilization rate, packet loss rate, edge connectivity, edge transmission time delay, edge transmission rate, etc.; the node business indicators are indicators for evaluating the network node attributes and states under the network topology node dimension, such as CPU usage rate, memory occupancy rate, node asset information, node hardware information, etc.; and the overall business indicators are indicators for evaluating the characteristics of the entire network topology structure under the network topology overall dimension, such as network average delay, network maximum throughput, overall similarity, etc.
[0140] Finally, the embodiment of the present disclosure can integrate and comprehensively consider the edge business indicators under the network topology edge dimension, the node business indicators under the network topology node dimension and the overall business indicators under the network topology overall dimension to determine the target business indicator set finally used for the evaluation of the target simulation dimension (network topology dimension). For example, different weights can be given according to the importance of each indicator, and the final target business indicator is obtained through weighted calculation.
[0141] Based on this, the individual edge business indicators, node business indicators and overall business indicators can only reflect one aspect of the network topology structure, and the embodiment of the present disclosure can comprehensively evaluate the simulation credibility of the network topology structure from multiple angles by combining these indicators to form a complete and comprehensive evaluation system, so that the evaluation result is more scientific and reliable.
[0142] Please refer to Figure 6 , Figure 6 is Figure 2 the flowchart further included in step 204. In some embodiments, the process of evaluating the simulation target range according to the target simulation evaluation scheme described above can further include steps 601 to 603:
[0143] Step 601, the target simulation evaluation scheme is sent to the user end for display;
[0144] At step 602, the scheme modification information input by the user terminal for the target simulation evaluation scheme is acquired, and a second prompt text is constructed based on the scheme modification information and the target simulation evaluation scheme. The second prompt text is input into the target large language model to adjust the target simulation evaluation scheme based on the scheme modification information, and an adjusted target simulation evaluation scheme is output after adjusting the target business index.
[0145] At step 603, the simulation target range is evaluated according to the adjusted target simulation evaluation scheme.
[0146] In the above steps, the target simulation evaluation scheme generated by the target large language model can be sent to the user terminal for display, and presented to the user in a visual form, such as displaying the specific content of the evaluation scheme in the form of a document, a list, etc. on the interface of the user terminal, so that the user can intuitively view the target simulation evaluation scheme and understand the entire evaluation process and key points. As the main body with the most direct cognition of the evaluation requirement, only when the user clearly knows the content of the evaluation scheme, can the user judge whether the scheme meets the expected and actual requirements, thereby providing a basis for subsequent possible scheme adjustment.
[0147] Then, the scheme modification information input by the user terminal for the target simulation evaluation scheme can be acquired. After viewing the target simulation evaluation scheme, the user may find that the scheme is not perfect or does not conform to the actual situation according to the user's experience, actual requirements, etc. The user will input the corresponding modification opinions on the user terminal, and these opinions constitute the scheme modification information. Then, a second prompt text is constructed based on the scheme modification information and the target simulation evaluation scheme, that is, the modification opinions are integrated with the original scheme to form new prompt content, and then the second prompt text is input into the target large language model. The target large language model will adjust the target simulation evaluation scheme based on the scheme modification information, including re-considering and modifying the target business index, and finally output an adjusted target simulation evaluation scheme.
[0148] The scheme modification information is the modification suggestion and opinion proposed by the user for the target simulation evaluation scheme according to the user's understanding of the evaluation requirement and actual situation. For example, the user finds that the system vulnerability related index needs to be added in the original scheme, and then proposes the scheme modification information of adding the system vulnerability related index. The second prompt text is generated by combining the scheme modification information and the original target simulation evaluation scheme, and is used to convey new modification requirements and expected prompt content to the target large language model, so as to guide the target large language model to optimize and adjust the original scheme.
[0149] It should be noted that although the target simulation evaluation scheme generated by the target large language model is based on the extracted target business field and indicators, it may not fully match the actual needs and complex actual scenarios of the user. By allowing the user to review the scheme and provide modification information, and then using the target large language model to adjust the scheme, the evaluation scheme can be more accurately matched to actual needs, improving the rationality of the evaluation scheme and the accuracy of the evaluation results.
[0150] Finally, according to the target simulation evaluation scheme adjusted by the user review and the target large language model, the actual credibility evaluation operation of the simulation target range can be performed. According to the evaluation process, method and indicator specified in the adjusted scheme, the indicator parameters under the target business indicator in the evaluation process are collected, and through analysis and calculation of these indicator parameters, the credibility evaluation result of the simulation target range in the target network target range background is obtained. After the target simulation evaluation scheme is adjusted through the previous steps, the evaluation scheme is more perfect and meets the actual needs. At this time, according to the adjusted scheme, the optimized evaluation indicators and processes can be fully utilized to maximize the efficiency and accuracy of network target range credibility evaluation, so that the evaluation results can truly reflect the credibility relationship between the simulation target range and the target network target range.
[0151] Exemplarily, taking the case of government and enterprise business as an example, it is illustrated. After the user inputs "I want to evaluate the simulation scene of government and enterprise business for the network target range, focusing on network topology credibility and attack and defense behavior credibility" in the user end, the user input is segmented and entity recognized by using natural language technology, the key requirements are extracted, the structured requirement table is generated, the target business field is government and enterprise business, and the target simulation dimension is network topology credibility and attack and defense behavior credibility. Then, the initial target simulation evaluation scheme is generated according to the disclosure embodiment, including calling the simulation degree knowledge base according to the requirements, retrieving related indicators and evaluation methods, and the knowledge base retrieval result is as follows: the indicators include network topology edge credibility (edge connectivity, edge transmission time delay, edge transmission rate), network topology node credibility (node asset, node hardware information), and network topology overall similarity, and the evaluation methods include analytic hierarchy process, topology similarity algorithm, and weighted average method. Finally, the retrieved content is combined with the prompt template to generate the initial target simulation evaluation scheme. The example scheme is as follows:
[0152] (1) Evaluation target: government and enterprise business simulation credibility evaluation of network target range;
[0153] (2) Evaluation indicators: network topology edge credibility (edge connectivity, edge transmission time delay, edge transmission rate), network topology node credibility (node asset, node hardware information), and network topology overall similarity;
[0154] (3) Usage method: analytic hierarchy process, topological similarity algorithm, weighted average method;
[0155] (4) Evaluation steps:
[0156] Step 1, data collection and preprocessing: determine the data to be collected according to the evaluation index and algorithm;
[0157] Step 2, index calculation and analysis: determine the index weight, and call the corresponding algorithm to calculate the index result layer by layer;
[0158] Step 3, generate evaluation report.
[0159] Further, the embodiments of the present disclosure can also implement multi-round dialogue to optimize the target simulation evaluation scheme. Specifically, the interactive interface provided by the user end can be used to collect user's evaluation and modification opinions on the scheme, such as the user can input the information "the scheme needs to add system vulnerability related indicators" after viewing the scheme, and the embodiments of the present disclosure can retrieve the knowledge base again according to the user feedback to generate an optimized scheme. The optimized scheme adds vulnerability severity credibility, vulnerability availability credibility, etc. as new target business indicators, and can also add related algorithms, such as a ratio calculation algorithm to adapt to the newly added target business indicators.
[0160] In addition, the embodiments of the present disclosure can also perform a process of manual review and confirmation after determining the target simulation evaluation scheme. For example, the final target simulation evaluation scheme can be sent to an expert system for review, or sent to a user end, and experts can check the rationality of the optimized scheme through the expert system or the user end, check whether it meets the requirements, and then fine-tune the scheme according to the expert's suggestion to form the final version of the evaluation scheme.
[0161] Please refer to Figure 7 , Figure 7 is Figure 2 another flowchart further included in step 204. In some embodiments, the process of evaluating the simulation range according to the target simulation evaluation scheme and obtaining the index parameters under the target business indicators in the evaluation process can further include steps 701 to 702:
[0162] Step 701, task decomposition is performed on the target simulation evaluation scheme to generate a plurality of to-be-executed tasks;
[0163] Step 702, each to-be-executed task is executed in the simulation range in turn, and a plurality of application programming interfaces are called through the target large language model, and the corresponding index parameters under the target business indicators are obtained through the application programming interfaces in the process of executing the to-be-executed tasks.
[0164] In the above steps, the embodiments of the present disclosure can analyze and disassemble the target simulation evaluation scheme generated by the target large language model, and according to certain logical rules, the overall evaluation task is divided into multiple interrelated and relatively independent to-be-executed tasks. Among them, the to-be-executed task is a specific and operable task unit decomposed from the target simulation evaluation scheme, each to-be-executed task has a clear execution target and scope, and is a basic component for implementing the entire evaluation scheme.
[0165] For example, if the target simulation evaluation scheme is a credibility evaluation of an enterprise network target range, which includes evaluation of network architecture, data transmission, user permission management, etc., the evaluation of network architecture can be divided into network topology structure analysis, network device configuration check and other to-be-executed tasks; the data transmission evaluation can be divided into data encryption strength detection, data transmission integrity verification tasks; the user permission management evaluation can be divided into permission allocation rationality check, permission change record review tasks. Or, tasks can be generated including collecting sensor data, calculating allocation indicators, and analyzing the influence of environmental light conditions on evaluation results, and then using a task scheduling tool (such as Celery) to distribute and manage the steps. In this way, the complex overall evaluation scheme is converted into multiple clear and specific small tasks, which is convenient for subsequent execution and management.
[0166] It should be noted that the target simulation evaluation scheme usually involves multiple aspects and complex processes, and direct execution may cause operational confusion, difficulty in management and monitoring. By task decomposition, it can be refined into multiple to-be-executed tasks, which can make the evaluation process more organized and clear. On the one hand, it helps to clarify the specific work content and responsibility of each stage, improves the efficiency and accuracy of execution; on the other hand, it is convenient for monitoring and managing the evaluation process, and timely discovering and solving problems that occur in the execution process.
[0167] Next, the embodiments of the present disclosure can execute each to-be-executed task generated in the simulation target range environment in a certain order, and in the process of executing each to-be-executed task, the capabilities of the target large language model are used to call multiple application programming interfaces (APIs). Among them, the application programming interface is the interface for interaction between different software components, and by calling these interfaces, specific indicator parameters under the target business indicators related to the to-be-executed task can be obtained.
[0168] For example, when performing the task of "checking whether the network device configuration meets the security standards", the API of the network device management system is called through the target large language model to obtain the configuration parameters, security policy settings and other data of the device, which are the index parameters under the target business index (such as the device configuration compliance index); for example, when performing the task of "verifying the integrity of data transmission", the API of the data transmission system is called to obtain the data verification code, transmission success rate and other index parameters. In this way, while performing the to-be-executed task, the key data for evaluating the credibility of the simulation target range is accurately obtained.
[0169] It should be noted that in the evaluation process of the simulation target range, a large amount of index parameters related to the target business index need to be obtained, and these parameters are usually stored in different systems and modules. The embodiment of the disclosure uses the target large language model as an agent to collect data such as network topology information, whole network vulnerability scanning information, network topology attack path, etc. by calling external APIs, and finally uses the collected data to input the agent to automatically call related algorithms to calculate the index credibility, which can realize the automatic and efficient acquisition of these parameters, avoiding the tediousness and error-prone problems of manual data collection. At the same time, the use of API to obtain data has the characteristics of standardization and standardization, which can ensure that the obtained data is accurate and reliable, thereby providing a solid data foundation for subsequent determination of the credibility evaluation result based on the index parameters.
[0170] Exemplarily, the embodiment of the disclosure can aggregate and report the results of the index parameters, including integrating the execution results of all steps to generate a structured data table. For example, the network topology simulation credibility is 80%, the network vulnerability credibility is 90%, the attack behavior credibility is 81%, and the defense behavior credibility is 70%, etc. Then, a visual report is generated using a templating tool, including charts, text descriptions, etc., such as generating a report title of "simulation degree evaluation analysis in the field of autonomous driving", and the evaluation index and evaluation result of the evaluation industry of government business.
[0171] Please refer to Figure 8 , Figure 8 is Figure 2 further included in step 701. In some embodiments, the process of task decomposition of the target simulation evaluation scheme to generate a plurality of to-be-executed tasks can further include steps 801 to 802:
[0172] Step 801, calling a task scheduling tool under the corresponding field based on the target business field;
[0173] Wherein, the task scheduling tools under different fields are not the same;
[0174] At step 802, the target simulation evaluation scheme is input into the task scheduling tool to perform task decomposition on the target simulation evaluation scheme under the target business field, and a plurality of to-be-executed tasks are generated.
[0175] In the above steps, the embodiments of the present disclosure can further call the task scheduling tool corresponding to the target business field from the system according to the target business field that has been determined. Due to the differences in business logic, process and characteristics, different business fields such as finance, e-commerce, Internet of Things, government business, etc. require different task scheduling tools. If the target business field is finance, a task scheduling tool specially suitable for the financial business scenario is called; if the target business field is Internet of Things, a task scheduling tool designed for the business characteristics of Internet of Things device management and data transmission is called. In this way, it is ensured that the selected task scheduling tool matches the characteristics of the target business field.
[0176] The task scheduling tool is a software tool specially used for planning, allocating, managing and coordinating tasks, which can reasonably decompose and arrange the overall tasks according to the rules and requirements of different business fields. For example, in the e-commerce field, the task scheduling tool can reasonably divide and schedule related evaluation tasks according to business processes such as commodity transactions, inventory management and logistics distribution; in the industrial control field, the task scheduling tool will optimize the allocation of evaluation tasks according to business characteristics such as production equipment operation and process monitoring.
[0177] Finally, the embodiments of the present disclosure can input the target simulation evaluation scheme into the called task scheduling tool. After receiving the scheme, the task scheduling tool analyzes and decomposes the target simulation evaluation scheme in depth according to the algorithms and rules set by it for the target business field, and splits the overall evaluation task into a plurality of to-be-executed tasks that are relatively independent and related to each other according to certain logical relationships, so as to ensure that the decomposed to-be-executed tasks are more in line with the actual situation and evaluation requirements of the target business field. Compared with manual or general task decomposition, using the task scheduling tool can reduce the problem of unreasonable task decomposition caused by subjective judgment or rule mismatch, improve the accuracy and efficiency of task decomposition, and thus ensure that the network target range credibility evaluation work is carried out in an orderly and efficient manner.
[0178] Please refer to Figure 9 , Figure 9 is Figure 2 a flowchart further included in step 203. In some embodiments, the process of constructing the first prompt text based on the target business field and the target business indicator, and inputting the first prompt text into the target large language model to generate the target simulation evaluation scheme under the target business field with the target business indicator can further include steps 901 to 902:
[0179] Step 901, obtaining a pre-constructed template prompt text;
[0180] The template prompt text is used to guide the target large language model to generate simulation evaluation schemes in the functional dimension, performance dimension, and security dimension.
[0181] Step 902, constructing a dynamic prompt text based on the target business field and the target business indicators, synthesizing a first prompt text based on the template prompt text and the dynamic prompt text, and inputting the first prompt text into the target large language model to generate a target simulation evaluation scheme in the target business field with the target business indicators in the functional dimension, performance dimension, and security dimension.
[0182] In the above steps, the disclosed embodiments can obtain a pre-constructed template prompt text from the system. The template prompt text is designed and stored in advance, and its core function is to provide a basic generation framework and direction guide for the target large language model, and to clearly inform the model which dimensions (functional dimension, performance dimension, and security dimension) to generate simulation evaluation schemes. Further, the template prompt text exists in a fixed sentence form, and can be directly called every time the target large language model generates a simulation evaluation scheme, providing a standardized guide basis for the subsequent generation process. For example, when evaluating any type of network range, a template prompt text similar to "You are an AI Agent responsible for simulation degree evaluation, please generate a simulation degree evaluation scheme according to user requirements, including functional dimension, performance dimension, and security dimension" can be called, so that the target large language model clearly knows which aspects to consider for scheme conception and generation from the beginning.
[0183] It should be noted that as a network security training and testing platform, whether the network range is complete in function, stable in performance, and reliable in security is the core of evaluating its credibility. The functional dimension focuses on the ability of the range to simulate business scenarios, such as whether it can completely implement various operation processes of network systems; the performance dimension measures the efficiency of the range, including system response speed, resource utilization, etc.; and the security dimension focuses on data and system security, such as data encryption and access control. Generating schemes from these three dimensions can ensure comprehensive and complete evaluation and accurately reflect the true status of the network range.
[0184] Then, the embodiment of the present disclosure can construct a dynamic prompt text based on the target business field and the target business indicator that have been determined. The dynamic prompt text is generated according to specific evaluation requirements, combined with the characteristics of the target business field and the requirements of the target business indicator, so as to dynamically adjust according to different evaluation scenarios and requirements, supplement specific business details and evaluation points. Then, the template prompt text and the dynamic prompt text are integrated to synthesize a first prompt text, and finally the first prompt text is input into the target large language model. The target large language model is guided by the basic framework provided by the template prompt text and the specific business information provided by the dynamic prompt text, and generates a target simulation evaluation scheme that meets the characteristics of the target business field and contains the target business indicator from the functional dimension, the performance dimension and the security dimension.
[0185] For example, when the template prompt text in the embodiment of the present disclosure is "You are an AIAgent responsible for simulation degree evaluation. Please generate a simulation degree evaluation scheme according to user requirements, including functional dimension, performance dimension and security dimension", after receiving the credibility evaluation requirement information, the scene requirement analysis tool (such as deepseek model API) is used to decompose the user input requirements, and finally the structured prompt words are generated based on the target business field and the target business indicator. For example, when the credibility evaluation requirement information is "I need a simulation evaluation scheme for the industrial control field, focusing on protocol restoration degree and timing error", the generated dynamic prompt text includes "generate an industrial control field simulation evaluation scheme, including the following important indicators: protocol restoration degree, timing error rate".
[0186] In this way, although the template prompt text can provide a basic generation direction for the model, it lacks specific business scene pertinence, and the dynamic prompt text focuses on specific business requirements but lacks a unified dimension framework. The embodiment of the present disclosure combines the two to generate a first prompt text, which can ensure that the evaluation scheme generated by the model maintains integrity and standardization in core dimensions such as function, performance and security, and can closely fit the actual situation of the target business field and the requirements of the target business indicator, thereby improving the accuracy and practicality of the target simulation evaluation scheme.
[0187] Please refer to Figure 10 , Figure 10 is a flowchart of the process of constructing the target large language model provided by the embodiment of the present disclosure. In some embodiments, before the first prompt text is input into the target large language model, the credibility evaluation method of the network target range can further include steps 1001 to 1003:
[0188] Step 1001, obtaining an initial large language model, and performing fine-tuning operation on the initial large language model based on the simulation degree knowledge base and the preset fine-tuning method to obtain a fine-tuned large language model;
[0189] Step 1002, a basic framework is built for the fine-tuned large language model, and data processing modules, prompt word management modules, and application programming interface calling modules are configured for the fine-tuned large language model on the basic framework to obtain an adjusted large language model framework;
[0190] Step 1003, an evaluation result generation tool, a simulation degree knowledge base calling tool, and a task scheduling tool are integrated for the fine-tuned large language model on the adjusted large language model framework to obtain a target large language model.
[0191] In the above steps, the initial large language model refers to a general-purpose large language model that has not been trained in a specific field and has basic natural language understanding and generation capabilities but lacks professional knowledge of network target range evaluation. For example, GPT-4, before fine-tuning, can only handle general text generation tasks and cannot accurately understand the professional requirements of simulation target range credibility evaluation.
[0192] The embodiments of the present disclosure can obtain a general initial large language model, and then train the initial model based on a pre-constructed simulation degree knowledge base and a pre-set fine-tuning method. Specifically, the simulation degree knowledge base stores professional knowledge in the network target range field. By inputting these knowledge and labeled evaluation task data into the model, the model parameters are adjusted to enable the model to understand and master the professional logic of network target range credibility evaluation.
[0193] Then, after obtaining the fine-tuned large language model, a basic framework is built for it. The basic framework is the underlying architecture of the large language model, similar to the operating system of a computer, which provides the model with basic running environment, resource management, module coordination, and other functions to ensure stable operation and efficient task processing of the model. Then, three important functional modules are configured on the basic framework. Among them, the data processing module is responsible for cleaning and structuring the data involved in the evaluation process, the prompt word management module is used to manage the prompt text used to guide the model to generate evaluation schemes, supports storage, editing, and dynamic combination of prompt words, and the application programming interface (API) calling module is used to connect external systems to realize data interaction and function calling. After the integration of these modules with the basic framework, a large language model framework with complete data processing and function calling capabilities is formed.
[0194] It should be noted that although the fine-tuned large language model has professional knowledge of network target range evaluation, it lacks complete data processing and function calling capabilities required for handling actual evaluation tasks. By building a basic framework and configuring data processing modules, prompt word management modules, and API calling modules, the model can effectively process various types of data in evaluation tasks, flexibly manage and optimize prompt texts, and interact with external systems to obtain necessary data and function support, thereby improving the practicality and efficiency of the model in actual evaluation tasks.
[0195] Finally, on the basis of the adjusted large language model framework, three important tools are further integrated for the fine-tuned large language model. Among them, the evaluation result generation tool can generate reliable evaluation results according to the index parameters of the target business indicators obtained by the model during the evaluation process, according to the predetermined evaluation rules and algorithms, and present them in an intuitive and easy-to-understand form, such as generating evaluation reports, scoring results, etc.; the simulation knowledge base calling tool can quickly and accurately query and obtain the required professional knowledge and data from the simulation knowledge base during the running of the model, providing support for the analysis and decision-making of the model, for example, when the model generates an evaluation scheme, it needs to refer to the specific index standards of a certain business field, and can call related content from the knowledge base through the tool; the task scheduling tool is used to reasonably plan and schedule the evaluation task, decompose the task into multiple sub-tasks according to the evaluation scheme, and arrange the execution order and resource allocation of the sub-tasks, to ensure that the evaluation task can be executed in an orderly and efficient manner. After integrating the three tools, the target large language model is finally obtained, which has complete network target credibility evaluation capability, and the target large language model can form a complete closed loop from data processing, knowledge acquisition, task execution to result output, ensuring the automation, efficiency and accuracy of the evaluation process.
[0196] Exemplarily, the process of constructing the target large language model described above is exemplified as follows:
[0197] The embodiments of the present disclosure can determine a suitable large model, for example, using the open source deepseek or Ali Tongyi Qianwen open source model; then select a suitable fine-tuning method, which includes LoRA / QLoRA light fine-tuning, retrieval-enhanced generation (Retrieval-Augmented Generation, RAG), and Prompt-tuning, etc., and the RAG method is used for fine-tuning in the present embodiment; during the fine-tuning of the large model, the huggingface module is programmed using a python script to fine-tune the large model.
[0198] In addition, during the development of the AI agent for simulation degree process automation, an agent framework can be selected and built as a basic framework, such as a mainstream agent framework (e.g., LangChain, AutoGen, LangGraph, etc.), and the extensibility and compatibility of the framework are determined according to the requirements. Then, the Python development environment is initialized, the necessary dependencies are installed, such as Hugging Face Transformers, LangChain modules, etc., and then a modular development structure is established, including a data processing module, a prompt word management module, and an application programming interface calling module, etc. Then, external tools are integrated, and an evaluation index generation tool is called through the agent framework to access the generation tool of the evaluation index system, support dynamic acquisition of indexes, and call a simulation method library calling tool to integrate the simulation degree knowledge base, support calling different evaluation methods, and call a task scheduling tool to support distributed task scheduling, such as Celery or Ray, etc., for efficient execution of complex simulation degree evaluation tasks, and finally obtain the target large language model.
[0199] Please refer to Figure 11 The embodiments of the present disclosure also provide a network range credibility evaluation device, which can implement the network range credibility evaluation method. The network range credibility evaluation device comprises:
[0200] The data acquisition module 1101 is configured to acquire credibility evaluation requirement information input by a user terminal for a target network range and a simulation range, and extract a target business field and a target simulation dimension that need to be evaluated from the credibility evaluation requirement information.
[0201] The index acquisition module 1102 is configured to acquire a simulation degree knowledge base, and query a target business index under the target simulation dimension from the simulation degree knowledge base under the index of the target business field.
[0202] The scheme generation module 1103 is configured to construct a first prompt text based on the target business field and the target business index, and input the first prompt text into a target large language model to generate a target simulation evaluation scheme with the target business index in the target business field.
[0203] The credibility evaluation module 1104 is configured to evaluate the simulation range according to the target simulation evaluation scheme, acquire an index parameter under the target business index in the evaluation process, and determine a credibility evaluation result between the target network range and the simulation range according to the index parameter.
[0204] In summary, the credibility evaluation device of the network target range performs the credibility evaluation method of the network target range in the above embodiments. After obtaining the credibility evaluation requirement information input by the user terminal for the target network target range and the simulation target range, the credibility evaluation requirement is split in terms of field and dimension, and the target business field and the target simulation dimension that need to be evaluated are extracted. Then, the target business indicators under the target simulation dimension are queried from the simulation degree knowledge base under the index of the target business field, so that the target business indicators obtained can accurately match the current credibility evaluation requirement. Next, the first prompt text is constructed based on the target business field and the target business indicators, and the first prompt text is input into the target large language model to generate the target simulation evaluation scheme with the target business indicators in the target business field. The simulation target range can be evaluated according to the target simulation evaluation scheme, and the index parameters under the target business indicators in the evaluation process are obtained. The credibility evaluation result between the target network target range and the simulation target range is determined according to the index parameters. Compared with the manual evaluation method according to expert experience in the related art, the target business indicators matched with the current credibility evaluation requirement are indexed based on the split field and dimension related information in the embodiment of the present disclosure, so as to avoid the difference in manual subjective understanding of the credibility evaluation requirement. The target business indicators extracted are more accurate and efficient. Then, the target simulation evaluation scheme is automatically generated through the target large language model. After the credibility of the simulation target range is evaluated according to the target simulation evaluation scheme, the credibility evaluation result between the target network target range and the simulation target range can be determined based on the index parameters under the target business indicators in the execution process. Finally, the human and time costs of the credibility evaluation of the network target range can be reduced, and the efficiency and accuracy of the credibility evaluation of the network target range are improved.
[0205] The specific implementation of the credibility evaluation device of the network target range is basically the same as the specific embodiments of the above-mentioned credibility evaluation method of the network target range, and will not be repeated here. The network target range credibility evaluation device can also be provided with other functional modules to implement the network target range credibility evaluation method in the above embodiments under the premise of meeting the requirements of the embodiments of the present disclosure.
[0206] The embodiments of the present disclosure also provide an electronic device, which includes a memory and a processor. The memory stores a computer program, and the processor implements the above-mentioned credibility evaluation method of the network target range when executing the computer program. The electronic device can be any intelligent terminal including a tablet computer, a vehicle-mounted computer, etc.
[0207] Please refer to Figure 12 , Figure 12 The hardware structure of the electronic device of another embodiment is illustrated, which includes:
[0208] The processor 1201 can be implemented by a general-purpose CPU (Central Processing Unit), a microprocessor, an ASIC (Application Specific Integrated Circuit), or one or more integrated circuits, and is configured to execute related programs to implement the technical solutions provided by the embodiments of the present disclosure.
[0209] The memory 1202 can be implemented by a ROM (Read Only Memory), a static storage device, a dynamic storage device, or a RAM (Random Access Memory), etc. The memory 1202 can store operating devices and other application programs. When the technical solutions provided by the embodiments of the present disclosure are implemented by software or firmware, the related program codes are stored in the memory 1202 and are called and executed by the processor 1201 to implement the network range credibility evaluation method of the network range provided by the embodiments of the present disclosure.
[0210] The input / output interface 1203 is configured to implement information input and output.
[0211] The communication interface 1204 is configured to implement the communication interaction between the device and other devices. The communication can be implemented by a wired manner (for example, a USB, a network cable, etc.) or a wireless manner (for example, a mobile network, WIFI, Bluetooth, etc.).
[0212] The bus 1205 is configured to transmit information between various components (for example, the processor 1201, the memory 1202, the input / output interface 1203, and the communication interface 1204) of the device.
[0213] The processor 1201, the memory 1202, the input / output interface 1203, and the communication interface 1204 are connected to each other through the bus 1205 to realize the communication connection between the device.
[0214] The embodiments of the present disclosure further provide a computer readable storage medium, which stores a computer program. The computer program is executed by a processor to implement the network range credibility evaluation method.
[0215] Memory, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs and non-transitory computer-executable programs. In addition, the memory can include a high-speed random access memory and can also include a non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state memory device. In some embodiments, the memory can optionally include a memory that is remotely disposed relative to the processor, and these remote memories can be connected to the processor through a network. Examples of the above network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0216] The embodiments described in the embodiments of the present disclosure are used to more clearly illustrate the technical solutions of the embodiments of the present disclosure, and do not constitute a limitation on the technical solutions provided by the embodiments of the present disclosure. Those skilled in the art can know that, as technology evolves and new application scenarios appear, the technical solutions provided by the embodiments of the present disclosure are also applicable to similar technical problems.
[0217] Those skilled in the art can understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present disclosure, and can include more or fewer steps than those shown in the figures, or combine certain steps or different steps.
[0218] The device embodiments described above are only schematic, and units described as separate components can or can not be physically separate, i.e., can be located in one place, or can be distributed on multiple network units. Part or all of the modules can be selected according to actual needs to achieve the purpose of the embodiments.
[0219] Those skilled in the art can understand that all or some of the steps in the above disclosed method, the functions of the modules / units in the device, and the equipment can be implemented as software, firmware, hardware, and appropriate combinations thereof.
[0220] The terms "first", "second", "third", "fourth" and the like used in the description of the present disclosure and the above drawings, if any, are used to distinguish similar objects, and do not necessarily have to describe a particular order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present disclosure described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, device, product or apparatus including a series of steps or units does not have to be limited to only those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or apparatuses.
[0221] It should be understood that in the disclosure, "at least one" refers to one or more, and "multiple" refers to two or more. "And / or" is used to describe the association relationship of the associated objects, which means that there can be three relationships, for example, "A and / or B" can represent three cases of only A, only B, and A and B existing at the same time, where A and B can be singular or plural. The character " / " generally represents an "or" relationship between the associated objects before and after it. "At least one of the following" or similar expressions means any combination of these items, including any combination of single or multiple items. For example, at least one of a, b or c can represent a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.
[0222] In several embodiments provided in the disclosure, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only illustrative, for example, the division of the above units is only a logical function division, and actual implementation can have another division manner, for example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed units can be indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.
[0223] The units described above as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, that is, they can be located in one place, or they can be distributed on multiple network units. According to actual needs, some or all of the units can be selected to achieve the purpose of the embodiment scheme.
[0224] In addition, each functional unit in each embodiment of the disclosure can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.
[0225] The integrated unit, if implemented in the form of a software function unit and sold or used as an independent product, can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present disclosure, essentially or in other words, the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes multiple instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in the various embodiments of the present disclosure. The aforementioned storage medium includes various media that can store program codes, such as a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0226] The preferred embodiments of the embodiments of the present disclosure are described above with reference to the accompanying drawings, and are not intended to limit the scope of the embodiments of the present disclosure. Any modifications, equivalent replacements and improvements made by those skilled in the art without departing from the scope and essence of the embodiments of the present disclosure shall be within the scope of the embodiments of the present disclosure.
Claims
1. A method for trustworthiness evaluation of a network range, characterized in that, The method comprises the following steps: acquiring the credibility evaluation requirement information input by a user terminal for a target network range and a simulation range, and extracting the target business field and the target simulation dimension that need to be evaluated from the credibility evaluation requirement information; acquiring a simulation degree knowledge base, and querying the target business indicators under the target simulation dimension from the simulation degree knowledge base under the index of the target business field; constructing a first prompt text based on the target business field and the target business indicators, and inputting the first prompt text into a target large language model to generate a target simulation evaluation scheme under the target business field with the target business indicators; evaluating the simulation range according to the target simulation evaluation scheme, and acquiring the indicator parameters under the target business indicators in the evaluation process, and determining the credibility evaluation result between the target network range and the simulation range according to the indicator parameters.
2. The network range confidence assessment method of claim 1, wherein, The step of extracting the target business field and the target simulation dimension that need to be evaluated from the credibility evaluation requirement information comprises the following steps: performing natural language recognition on the credibility evaluation requirement information, extracting the domain knowledge text and the dimension knowledge text that need to be evaluated, and encoding the domain knowledge text to obtain domain knowledge features and encoding the dimension knowledge text to obtain dimension knowledge features; performing cosine similarity query on the domain knowledge features in a plurality of preset business field features to obtain similar target business field features; splicing the target business field features and the dimension knowledge features to obtain spliced features, and inputting the spliced features into the target large language model for feature fine-tuning to obtain fine-tuned features; decoding the target business field features to obtain the target business field, and decoding the fine-tuned features to obtain the target simulation dimension.
3. The method of claim 1, wherein, The simulation degree knowledge base is obtained through the following steps, comprising: acquiring a plurality of sample data, wherein the sample data comprises industry standard documents, technical specification files, expert experience summaries, sample simulation evaluation schemes, sample credibility evaluation reports or papers; respectively performing corresponding data preprocessing on different types of sample data to obtain preprocessed sample data; extracting the initial business field, the initial simulation dimension and the initial business indicators from each preprocessed sample data, and constructing a corresponding multi-layer knowledge graph according to the order of the initial business field, the initial simulation dimension and the initial business indicators; constructing the simulation degree knowledge base based on the multi-layer knowledge graph corresponding to each sample data; wherein the target business field is one of the initial business fields.
4. The method of claim 1, wherein, The step of querying the target business indicators under the target simulation dimension from the simulation degree knowledge base under the index of the target business field comprises: identifying the type of the target simulation dimension to obtain a type identification result; if the type identification result represents that the type of the target simulation dimension is a network topology dimension, generating a network topology edge dimension, a network topology node dimension and a network topology overall dimension; query the edge service indicators in the network topology edge dimension, the node service indicators in the network topology node dimension and the overall service indicators in the network topology overall dimension from the simulation degree knowledge base respectively under the index of the target service field; determine the target service indicators in the target simulation dimension by combining the edge service indicators, the node service indicators and the overall service indicators.
5. The networked range trustworthiness evaluation method of claim 1, wherein, The evaluation of the simulation target range according to the target simulation evaluation scheme includes: sending the target simulation evaluation scheme to the user end for display; obtaining scheme modification information input by the user end for the target simulation evaluation scheme, and constructing a second prompt text based on the scheme modification information and the target simulation evaluation scheme, inputting the second prompt text into the target large language model to adjust the target simulation evaluation scheme based on the scheme modification information, and outputting the adjusted target simulation evaluation scheme after adjusting the target service indicators; evaluating the simulation target range according to the adjusted target simulation evaluation scheme.
6. The network range confidence assessment method of claim 1, wherein, The evaluation of the simulation target range according to the target simulation evaluation scheme and the acquisition of the indicator parameters under the target service indicators in the evaluation process include: task decomposition of the target simulation evaluation scheme to generate a plurality of to-be-executed tasks; sequentially executing each of the to-be-executed tasks in the simulation target range, and calling a plurality of application programming interfaces through the target large language model, and acquiring the indicator parameters under the target service indicators through the application programming interfaces in the process of executing the to-be-executed tasks.
7. The method of claim 6, wherein, The task decomposition of the target simulation evaluation scheme to generate a plurality of to-be-executed tasks includes: calling a task scheduling tool under a corresponding field based on the target service field, wherein the task scheduling tools under different fields are not the same; inputting the target simulation evaluation scheme into the task scheduling tool to perform task decomposition on the target simulation evaluation scheme in the target service field to generate a plurality of to-be-executed tasks.
8. The method of claim 1, wherein, The construction of the first prompt text based on the target service field and the target service indicators, and the input of the first prompt text into the target large language model to generate the target simulation evaluation scheme in the target service field with the target service indicators includes: acquiring a pre-constructed template prompt text, wherein the template prompt text is used to guide the target large language model to generate a simulation evaluation scheme in the function dimension, the performance dimension and the security dimension; constructing a dynamic prompt text based on the target service field and the target service indicators, and synthesizing a first prompt text based on the template prompt text and the dynamic prompt text, and inputting the first prompt text into the target large language model to generate the target simulation evaluation scheme in the target service field with the target service indicators in the function dimension, the performance dimension and the security dimension.
9. The method of claim 1 or 8, wherein, Before the first prompt text is input into the target large language model, the network target range credibility evaluation method further includes: An initial large language model is obtained, and the initial large language model is fine-tuned based on the simulation degree knowledge base and a preset fine-tuning method to obtain a fine-tuned large language model; A basic framework is built for the fine-tuned large language model, and a data processing module, a prompt word management module, and an application programming interface calling module are configured for the fine-tuned large language model on the basic framework to obtain an adjusted large language model framework; An evaluation result generation tool, a simulation degree knowledge base calling tool, and a task scheduling tool are integrated for the fine-tuned large language model on the adjusted large language model framework to obtain a target large language model.
10. A cyber range trustworthiness evaluation apparatus, comprising: Comprise: The data acquisition module is used for acquiring the credibility evaluation requirement information input by the user terminal for the target network target field and the simulation target field, and extracting the target business field and the target simulation dimension that need to be evaluated from the credibility evaluation requirement information; The index acquisition module is used for acquiring a pre-constructed simulation degree knowledge base, and querying a target business index under the target simulation dimension from the simulation degree knowledge base under the index of the target business field; The scheme generation module is used for constructing a first prompt text based on the target business field and the target business index, and inputting the first prompt text into a target large language model to generate a target simulation evaluation scheme under the target business field with the target business index; The credibility evaluation module is used for evaluating the simulation target field according to the target simulation evaluation scheme, and acquiring an index parameter under the target business index in the evaluation process, and determining a credibility evaluation result between the target network target field and the simulation target field according to the index parameter.
11. An electronic device, comprising: The electronic device comprises a memory and a processor, the memory stores a computer program, and the processor realizes the credibility evaluation method of the network target field in any one of claims 1 to 10 when executing the computer program.
12. A computer readable storage medium, the storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to realize the credibility evaluation method of the network target field in any one of claims 1 to 10.