Large model-based data security risk automatic research and judgment processing system and method
By combining deep learning and large-scale language models, the automated data security risk assessment and handling system solves the problems of inaccurate assessment and low handling efficiency of massive alarms, and achieves efficient and reliable data security protection, adapting to complex environments and avoiding business interruption.
Patent Information
- Application Number
- CN202511682942.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-17
- Publication Date
- 2026-02-13
AI Technical Summary
Existing data security protection systems face problems such as inaccurate analysis of massive alarms, low handling efficiency, conflicts between security and business, and difficulty in knowledge reuse. Especially in the complex power business environment, traditional methods are difficult to deal with complex and unknown threats, and automated handling is prone to causing business interruption.
An automated data security risk assessment and handling system based on a large model is adopted. It combines deep learning models and large language models, conducts comprehensive assessment through a fusion assessment module, evaluates business impact through a business process decomposition and analysis module, and uses a distributed architecture of AI agents for automated handling to achieve a multi-level progressive response strategy.
It improves the accuracy of alarm analysis, reduces false alarms and missed alarms, achieves "business-aware" security response, avoids the impact of rough handling on core business, and has the ability to learn and evolve autonomously, adapting to complex and dynamically changing environments.
Smart Images

Figure CN121524844A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data security and artificial intelligence, in particular to a data security risk automatic research and judgment and disposal system and method based on a large model. BACKGROUND
[0002] With the deepening of global digital transformation, data has become a key production factor, and its security risks have become increasingly prominent. In particular, in the fields of power, finance and other critical infrastructure, data security is directly related to national security and economic lifelines. However, the current data security protection system is facing severe challenges.
[0003] First, the complexity and concealment of security threats are increasing. Advanced persistent threats (APT), supply chain attacks, zero-day vulnerability exploitation and other means are emerging in an endless stream. Traditional security protection methods based on rules and signatures have been difficult to cope with these unknown and rapidly changing threats, resulting in a large number of alarms from security devices, among which there are a large number of false positives and low-value information.
[0004] Second, the efficiency of security operations (SecOps) is low, and the "alarm fatigue" problem is prominent. Security analysts (SOC analysts) must manually distinguish real threats from a large number of alarms, which is time-consuming and labor-intensive, and highly dependent on expert experience. According to statistics, security teams often cannot handle all alarms in a timely manner, resulting in important security risks being submerged. There is a significant time gap between detecting threats and implementing protection, i.e. the "security gap", which provides attackers with ample opportunities.
[0005] Third, the conflict between security disposal and business continuity. Currently, the disposal of most security risks still highly depends on manual operation, not only low efficiency, but also prone to inconsistent response or wrong operation due to human factors. Traditional automated disposal (such as SOAR) technology introduced to improve efficiency often adopts a "one-size-fits-all" blocking strategy, such as directly isolating servers or blocking IP. In a complex power business environment, this rough disposal method is extremely likely to cause the interruption of core business (such as power trading, power grid scheduling), and the loss caused may even exceed the security event itself.
[0006] Finally, the mechanism of security knowledge sedimentation and reuse is not perfect. Data security protection is a continuous confrontation and learning process that needs to constantly learn from historical security incidents. However, valuable security experience is often scattered in the brains of different experts or in scattered documents, making it difficult to form a systematic and structured knowledge base, resulting in security teams having to face similar security challenges repeatedly.
[0007] In recent years, the development of artificial intelligence (AI) technology, especially large language models (LLM), has provided new possibilities for solving the above challenges. However, how to deeply integrate AI technology with complex security scenarios to build a truly intelligent, efficient, explainable, and business continuity-oriented automated protection system remains a technical challenge that the industry urgently needs to solve. Summary of the Invention
[0008] To address the problems of inaccurate analysis of massive alerts, low handling efficiency, conflicts between security and business operations, and difficulties in knowledge reuse, this invention proposes an automated data security risk analysis and handling system based on a large-scale model, including: The integrated analysis module, based on security data and combining deep learning models and large-scale language models, comprehensively assesses the risk level, attack intent, and potential impact of security incidents, and transmits the assessment conclusions to the automated handling module. The business process decomposition and analysis module, based on security data and through process mining and traffic analysis, automatically discovers, models, and perceives in real time the business processes and dependency graphs associated with security incidents, and assesses the potential impact of different handling measures on business continuity, transmitting the business impact assessment to the automated handling module. The automated handling module, using a distributed architecture of AI agents, selects and executes the optimal risk handling strategy from the security policy library based on the assessment conclusions and the business impact assessment.
[0009] Optionally, the fusion analysis module includes: The ultra-long sequence processing unit is used to analyze secure data by employing a text representation method based on a balanced tree data structure, combined with a local-global sparse attention mechanism, to understand the global context and obtain text understanding results; The pattern analysis unit is used to perform time-series anomaly detection and correlation pattern analysis on numerical data in security data using a deep learning model, and to obtain pattern analysis results. The fusion unit is used to combine the text understanding results with the pattern analysis results to obtain a judgment on the risk level, attack intent, and potential impact of the security incident.
[0010] Optionally, the business process decomposition and analysis module is specifically used for: When a security incident occurs, construct a system dependency graph of the key business processes related to the security incident; Based on the system dependency graph, different actions are simulated and executed to assess the potential impact of different actions and obtain a business impact assessment.
[0011] Optionally, the automated processing module includes: The monitoring agent is deployed on edge nodes for real-time environmental perception and anomaly detection, and reports the raw anomaly data to the analysis agent. The analytical agent is used to perform in-depth analysis and risk assessment of abnormal data, generate trigger signals, and transmit the trigger signals to the fusion analysis module and the business process decomposition analysis module. The decision-making agent is used to receive and integrate the judgment conclusions and business impact assessments, formulate a disposal plan based on the built-in security policy library, and distribute the disposal plan to the coordinating agent; The coordinating agent is used to break down the disposal plan into specific execution tasks, distribute the specific execution tasks to the disposal agents, and manage communication, task allocation and conflict resolution between the agents. Intelligent agents are deployed in critical business systems or network devices to perform specific security response operations based on specific tasks.
[0012] Optionally, the analytical agent, the decision-making agent, and the coordinating agent all employ a large language model as their core cognitive engine.
[0013] Optionally, it also includes: a data acquisition and preprocessing module, used to acquire security data from multi-source heterogeneous systems, perform unified cleaning, standardization and feature extraction, and transmit the processed data to the fusion and analysis module.
[0014] Optionally, it also includes: a report generation platform; The report generation platform is used to receive the judgment conclusions obtained by the fusion judgment module, the business impact assessment obtained by the business process decomposition and analysis module, and the handling logs obtained by the automated handling module using the optimal risk handling strategy, and automatically generate an analysis report based on the judgment conclusions, business impact assessments and handling logs.
[0015] Furthermore, this invention also provides an automated data security risk assessment and handling method based on large models, including: Based on security data, combined with deep learning models and large-scale language models, a comprehensive assessment of the risk level, attack intent, and potential impact of security incidents is conducted to arrive at a conclusion. Based on security data, through process mining and traffic analysis, business processes and dependency graphs associated with security incidents are automatically discovered, modeled, and perceived in real time, and the potential impact of different handling measures on business continuity is evaluated to obtain a business impact assessment. Using a distributed architecture of AI agents, the optimal risk handling strategy is selected and executed from the security policy library based on the assessment conclusions and the business impact assessment.
[0016] Optionally, based on security data, and combining deep learning models with large-scale language models, a comprehensive assessment of the risk level, attack intent, and potential impact of security incidents is conducted to arrive at an assessment conclusion, including: A text representation method based on a balanced tree data structure is adopted, combined with a local-global sparse attention mechanism to analyze security data, understand the global context, and obtain text understanding results; Deep learning models are used to perform time-series anomaly detection and correlation pattern analysis on numerical data in security data to obtain pattern analysis results. By integrating the results of text understanding with those of pattern analysis, conclusions can be drawn regarding the risk level, attack intent, and potential impact of security incidents.
[0017] Optionally, based on security data, through process mining and traffic analysis, the system automatically discovers, models, and perceives in real time the business processes and dependency graphs associated with security incidents, and assesses the potential impact of different handling measures on business continuity, resulting in a business impact assessment, including: When a security incident occurs, construct a system dependency graph of the key business processes related to the security incident; Based on the system dependency graph, different actions are simulated and executed to assess the potential impact of different actions and obtain a business impact assessment.
[0018] Optionally, an AI agent-based distributed architecture is employed to select and execute the optimal risk management strategy from a security policy library based on the assessment conclusions and the business impact evaluation, including: Real-time environmental perception and anomaly detection are performed by monitoring agents deployed at edge nodes, and raw anomaly data is reported to the analysis agent. By analyzing the intelligent agent to perform in-depth analysis and risk assessment of abnormal data, trigger signals are generated and transmitted to the fusion analysis module and the business process decomposition analysis module. The decision-making agent receives and integrates the judgment conclusions and business impact assessments, formulates a response plan based on the built-in security policy library, and distributes the response plan to the coordinating agent. The coordination agent breaks down the disposal plan into specific execution tasks, distributes the specific execution tasks to the disposal agent, and manages the communication, task allocation and conflict resolution between the agent and the disposal agent. The intelligent agents deployed on critical business systems or network devices perform specific security response operations based on specific tasks.
[0019] Optionally, before drawing conclusions by comprehensively assessing the risk level, attack intent, and potential impact of security incidents based on security data and combining deep learning models with large-scale language models, the following steps are also included: Security data is obtained from multi-source heterogeneous systems and then subjected to unified cleaning, standardization, and feature extraction to obtain processed security data.
[0020] Optionally, after the distributed architecture employing AI agents selects and executes the optimal risk management strategy from the security strategy library based on the assessment conclusions and the business impact evaluation, the method further includes: Analysis reports are automatically generated from the handling logs obtained based on the assessment conclusions, business impact evaluation, and optimal risk handling strategies.
[0021] In another aspect, this application also provides an electronic device, comprising: at least one processor and a memory; the memory and the processor are connected via a bus; The memory is used to store one or more programs; When the one or more programs are executed by the at least one processor, the automated data security risk assessment and handling method based on the large model described above is implemented.
[0022] Furthermore, this application also provides a readable storage medium on which an executable program is stored, which, when executed, implements the automated data security risk assessment and handling method based on a large model as described above.
[0023] Compared with the prior art, the beneficial effects of the present invention are as follows: This invention provides an automated data security risk assessment and handling system and method based on a large model, comprising: a fusion assessment module, used to comprehensively assess the risk level, attack intent, and potential impact of security events based on security data, combined with deep learning models and large language models, and transmit the assessment conclusions to an automated handling module; a business process decomposition and analysis module, used to automatically discover, model, and perceive business processes and dependency graphs associated with security events in real time based on security data through process mining and traffic analysis, and assess the potential impact of different handling measures on business continuity, and transmit the business impact assessment to the automated handling module; and an automated handling module, used to select and execute the optimal risk handling strategy from a security policy library based on the assessment conclusions and the business impact assessment using a distributed architecture of AI agents. The integrated analysis module, combining deep learning and a large language model, achieves a comprehensive understanding of numerical patterns and semantic context, significantly improving the accuracy of alarm analysis, effectively reducing false alarms and missed alarms, and alleviating "alarm fatigue." The automated handling module adopts a multi-level progressive response strategy, using business process analysis as a prerequisite for automated handling, achieving "business-aware" security response. Through progressive and precise handling, it avoids the impact of brute-force handling on core businesses, resolving the long-term conflict between security and business. The automated handling module adopts a distributed architecture of AI agents, which has high elasticity, high fault tolerance, and strong collaborative capabilities. With LLM as the cognitive core, it has the potential for autonomous learning and evolution, making it easy to adapt to complex and dynamically changing environments. Attached Figure Description
[0024] Figure 1 This is a schematic diagram of the automated data security risk assessment and handling system based on a large model according to the present invention; Figure 2 This is a flowchart of the automated data security risk assessment and handling method based on a large model according to the present invention; Figure 3 This is a schematic diagram of an electronic device structure according to the present invention. Detailed Implementation
[0025] This invention relates to a system and method for intelligently assessing data security alerts using large language models (LLM) and deep learning technology, and for automatically handling risks by combining business process awareness.
[0026] This invention discloses an automated data security risk assessment and handling system and method based on a large-scale model, belonging to the fields of data security and artificial intelligence technology. This invention aims to address the problems in existing security protection systems, such as "alarm fatigue," inaccurate assessment, and delayed response when facing massive amounts of alarms, particularly the potential for automated handling measures to cause business interruptions. The system includes: a data acquisition and preprocessing module, a fusion assessment module, a business process decomposition and analysis module, and an automated handling module. The fusion assessment module innovatively combines deep learning models and large-scale language models; the former processes high-dimensional numerical and temporal features, while the latter utilizes ultra-long sequence processing technology to deeply understand unstructured text such as security logs and attack payloads, achieving accurate assessment of complex attacks. The business process decomposition and analysis module automatically discovers and constructs business dependency graphs through process mining and other technologies, providing a basis for business impact assessment for handling decisions. Based on the assessment results and business impact assessment, the automated handling module adopts a distributed AI intelligent agent architecture to execute multi-level progressive response strategies, including enhanced monitoring, access restrictions, and precise blocking, effectively controlling risks while maximizing business continuity. This invention significantly improves the intelligence, automation, and accuracy of security risk handling, resolves the conflict between security response and business operations, and achieves efficient and reliable data security protection.
[0027] To better understand the present invention, the following description, in conjunction with the accompanying drawings and embodiments, will further illustrate the content of the present invention.
[0028] Example 1: An automated data security risk assessment and handling system based on a large model includes: The integrated analysis module, based on security data and combining deep learning models and large-scale language models, comprehensively assesses the risk level, attack intent, and potential impact of security incidents, and transmits the assessment conclusions to the automated handling module. The business process decomposition and analysis module, based on security data and through process mining and traffic analysis, automatically discovers, models, and perceives in real time the business processes and dependency graphs associated with security incidents, and assesses the potential impact of different handling measures on business continuity, transmitting the business impact assessment to the automated handling module. The automated handling module, using a distributed architecture of AI agents, selects and executes the optimal risk handling strategy from the security policy library based on the assessment conclusions and the business impact assessment.
[0029] The various modules in this invention will be further described below: An automated data security risk assessment and handling system based on a large model, such as Figure 1 As shown, it includes: The integrated analysis module is used to comprehensively analyze the risk level, attack intent, and potential impact of security incidents based on security data, deep learning models, and large-scale language models, and output the analysis conclusions. The business process decomposition and analysis module is used to automatically discover, model, and perceive business processes and their dependency graphs associated with security incidents in real time through process mining and traffic analysis, assess the potential impact of different handling measures on business continuity, and output a business impact assessment. The automated handling module is used to automatically select and execute the optimal risk handling strategy based on the judgment conclusions output by the fusion judgment module and the business impact assessment output by the business process decomposition and analysis module.
[0030] The automated data security risk assessment and handling system based on a large model provided by this invention also includes a data acquisition and preprocessing module. Before the fusion assessment module performs fusion assessment, the data acquisition and preprocessing module is used to acquire security data from multi-source heterogeneous systems, and perform unified cleaning, standardization and feature extraction to obtain processed security data. The processed security data is then transmitted to the fusion assessment module, which makes the fusion assessment results more accurate.
[0031] Furthermore, the integrated analysis module includes: The ultra-long sequence processing unit is used to analyze secure data by employing a text representation method based on a balanced tree data structure, combined with a local-global sparse attention mechanism, to understand the global context and obtain text understanding results; The pattern analysis unit is used to perform time-series anomaly detection and correlation pattern analysis on numerical data in security data using a deep learning model, and to obtain pattern analysis results. The fusion unit is used to combine the text understanding results with the pattern analysis results to obtain a judgment on the risk level, attack intent, and potential impact of the security incident.
[0032] Furthermore, the ultra-long sequence processing unit adopts a text representation method based on a balanced tree data structure, combined with a local-global sparse attention mechanism, enabling the large language model to process security log or configuration file sequences containing hundreds of thousands of lines that exceed the standard context length limit, in order to achieve the analysis of long-term, covert attack chains.
[0033] Furthermore, the automated handling module is implemented as a distributed AI agent network. This network, through the collaborative cooperation among the agents, achieves the overall function of "automatically selecting and executing the optimal risk handling strategy." The network includes at least: a monitoring agent deployed at edge nodes for real-time environmental awareness and anomaly detection, and reporting raw anomaly data to an analysis agent; the analysis agent, used for in-depth analysis and risk assessment of the anomaly data, and as a trigger signal to activate the fusion judgment module and the business process decomposition and analysis module; a decision-making agent, whose core function is to receive and synthesize the judgment conclusions and business impact assessments, and formulate a handling plan based on a built-in security policy library; a coordinating agent, used to receive the handling plan, decompose it into specific execution tasks, and manage communication, task allocation, and conflict resolution among the handling agents; and a handling agent deployed on critical business systems or network devices to receive and execute the specific security response operations.
[0034] As shown above, the data flow and collaboration process for achieving "automatic selection and execution of the optimal risk management strategy" are as follows: Trigger: The monitoring agent reports raw abnormal data to the analysis agent.
[0035] Analysis: This includes the analysis of the intelligent agent trigger fusion judgment module and the business process decomposition and analysis module.
[0036] Decision-making: The decision-making agent receives the judgment conclusions and business impact assessments output by the two main modules, and formulates a response plan.
[0037] Execution: The coordinating agent receives the disposal plan, breaks it down into execution tasks, and distributes them to the disposal agents.
[0038] Implementation: The intelligent agent executes specific security response operations.
[0039] This closed-loop process clearly demonstrates how each agent integrates the analysis results from external modules and works together to achieve the final policy execution.
[0040] Furthermore, to achieve complex autonomous decision-making and collaboration, the analytical agent, decision-making agent, and coordinating agent utilize large-scale language models as their core cognitive engines. Specifically, the large-scale language model in the analytical agent is used to deeply understand the semantics of raw anomaly data and assess threat credibility; the large-scale language model in the decision-making agent is used to perform complex reasoning on judgment conclusions and business impact assessments, autonomously generating optimal response plans; and the large-scale language model in the coordinating agent is used to autonomously decompose high-level, intent-based response plans (e.g., "contain the threat without interrupting business A") into executable sequences of specific tasks for different devices.
[0041] Furthermore, the risk management strategy executed by the automated handling module is a multi-level, progressive strategy dynamically formulated and selected by the decision-making agent based on the assessment conclusions (especially the risk level) and the business impact assessment. This strategy automatically selects the optimal response level based on the balance between risk and business impact, and includes at least: enhanced monitoring or access auditing strategies implemented based on low-risk assessment results; fine-grained access restrictions or traffic adjustment strategies implemented based on medium-risk assessment results, incorporating business process awareness; and precise blocking strategies for specific process nodes or services implemented based on high-risk assessment results and business impact assessment.
[0042] This invention provides an automated data security risk assessment and handling system, which includes at least a data acquisition and preprocessing module, a fusion assessment module, a business process decomposition and analysis module, and an automated handling module.
[0043] A core innovation of this invention lies in its fusion analysis module, designed to address the challenge of traditional methods dealing with complex and unknown threats. It innovatively employs a hybrid architecture combining deep learning (DL) and large language models (LLM). Deep learning models (such as CNN, LSTM, and GNN) handle their strengths in processing high-dimensional numerical features, network traffic, and temporal patterns, automatically learning the deep features of security data. Meanwhile, the large language model (LLM) is responsible for deeply understanding unstructured textual data, such as log descriptions, error messages, attack scripts, and threat intelligence reports. Through feature interaction and collaboration with the fusion layer, the two enable the system not only to "understand" data patterns but also to "comprehend" the semantics of security events and the attacker's intent, significantly improving the accuracy of assessing complex and unknown threats.
[0044] Another core innovation of this invention lies in the aforementioned business process decomposition and analysis module. This module is the core of this invention's "business-aware" security, aiming to resolve the conflict between security measures and business continuity. When a security incident occurs, this module does not immediately execute measures; instead, it first automatically discovers and models the business processes related to the incident. For example, through passive traffic analysis, log mining, and process mining techniques, it automatically constructs system dependency graphs for key business processes such as "electricity billing," "electricity trading," and "dispatch instruction issuance." Before taking action, the system uses this model to assess the potential impact of different measures (such as isolation, rate limiting, and degradation) on each business process.
[0045] Based on the above assessment and analysis, the automated response module is responsible for making the optimal decision. This invention employs a multi-level, progressive response strategy, replacing the traditional "one-size-fits-all" blocking. For example, for low-risk events, only "enhanced monitoring" may be implemented; for medium-risk events, "restricting non-core functions" may be adopted; only when the risk is high and the assessment shows that the impact on core business is controllable will "precise blocking" be executed. This business-aware approach achieves a fine balance between security effectiveness and business continuity.
[0046] In a preferred embodiment, the automated handling module of the present invention is implemented using a distributed AI agent architecture. This architecture features high scalability, strong adaptability, and high fault tolerance. Various specialized agents (such as monitoring, analysis, decision-making, execution, and coordination agents) are deployed in the network. Furthermore, key agents (especially analysis and decision-making agents) integrate large-scale language models as their "cognitive core" or "brain," enabling them to autonomously understand the context, perform complex reasoning, and collaboratively complete handling tasks, achieving a higher level of automation and intelligence.
[0047] In another preferred embodiment, to address the context length limitation faced by large language models when processing massive amounts of security logs, the fusion analysis module of this invention integrates an ultra-long sequence processing technique (e.g., a technique based on Longrope encoding extension). This technique constructs long text sequences (such as millions of log lines) into a balanced tree data structure and combines it with a local-global sparse attention mechanism, enabling the model to handle inputs of up to millions of tokens while maintaining awareness of the global context. This allows LLM to analyze complete logs spanning hours or even days at once, discovering hidden attack chains that span long periods and cannot be identified by traditional methods.
[0048] The present invention also provides a corresponding method, the steps of which correspond to the functions of the above-mentioned system, including data acquisition and processing, fusion analysis, business process impact assessment, and automated handling of business perception.
[0049] Compared with the prior art, the beneficial effects of the present invention are as follows: 1. High accuracy of analysis: Through the integration architecture of DL and LLM, a comprehensive understanding of numerical patterns and semantic context is achieved, which greatly improves the accuracy of alarm analysis, effectively reduces false alarms and false negatives, and alleviates "alarm fatigue".
[0050] 2. Intelligent and business-friendly handling: For the first time, business process analysis is used as a prerequisite for automated handling, realizing a "business-aware" security response. Through gradual and precise handling, the impact of rough handling on core business is avoided, and the long-term conflict between security and business is resolved.
[0051] 3. Advanced and scalable architecture: Based on the distributed architecture of AI agents, it has high elasticity, high fault tolerance and strong collaborative capabilities. With LLM as the cognitive core, it has the potential for autonomous learning and evolution, and is easy to adapt to complex and dynamically changing environments.
[0052] 4. Strong data processing capabilities: It breaks through the context length limitation of LLM, enabling it to process ultra-long secure data sequences, greatly enhancing the ability to analyze complex, long-term, and covert attacks, which is difficult to achieve with traditional methods.
[0053] 5. Knowledge can be accumulated: The experience and knowledge gained during the assessment and handling process are continuously learned and absorbed by the AI agent and large language model, forming a reusable and evolving structured knowledge base, which solves the problem of the difficulty in passing on security experience.
[0054] Example 2 To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below in conjunction with specific embodiments. Obviously, the described embodiments are merely some embodiments of this invention, and not all embodiments. Based on the embodiments of this invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this invention.
[0055] This invention provides an automated data security risk assessment and handling system based on a large model, which can be deployed in the Security Operations Center (SOC) or data center of an enterprise (such as the State Grid Corporation of China).
[0056] (I) System Overall Architecture and Data Flow The system is logically divided into five layers: infrastructure layer, data and integration layer, core capability layer, intelligent agent and process layer, and application layer.
[0057] The data flow is as follows: First, the data and integration layer is used to collect massive amounts of heterogeneous data in real time from the power system's firewalls, IDS / IPS, DLP, host logs, network devices, and key business systems (such as power trading systems and SCADA systems) through multi-source data access adapters. It then performs unified cleaning, standardization, and feature extraction on the massive heterogeneous data and transmits the processed data to the core capability layer.
[0058] Data enters the core capability layer, which consists of a fusion analysis module and a business process decomposition and analysis module. The fusion analysis module is one of the core components of this invention. For logs, alarm texts, etc., the system calls the AI large model service (an LLM pre-trained and fine-tuned in the security domain) for deep semantic understanding. If the input log is too long (e.g., a 500MB log file containing all relevant activities in the past 24 hours), the system will activate the Longrope algorithm. This algorithm does not use simple truncation or sliding windows, but instead segments the log according to semantics (such as session, timestamp, source IP) and constructs a balanced tree. The LLM uses a sparse attention mechanism to prioritize accessing the high-level summary nodes of the tree and the leaf nodes marked as high risk, efficiently understanding the global context without exceeding computational limitations. Meanwhile, for numerical data such as network traffic and user behavior statistics, the system uses deep learning models (such as LSTM and GNN) for time-series anomaly detection and correlation pattern analysis. Finally, the LLM merges its own text understanding results (such as "identifying a specific string suspected of SQL injection") with the pattern analysis results of the DL model (such as "detecting an abnormal timing of the user's behavior") to output a comprehensive assessment of the security incident (such as "a highly credible data theft attempt, suspected of exploiting the CVE-2023-XXXX vulnerability").
[0059] While the analysis is underway, the business process breakdown and analysis module begins its work. Based on the assets involved in the analysis (such as IP addresses and database tables), it retrieves the business process graphs pre-constructed through process mining and traffic analysis from their knowledge base. For example, it discovers that the affected asset (DB_Server_01) belongs to a critical node in the "electricity bill settlement" process. This module simulates different actions (such as "isolate the host" and "block port 1521") and assesses their collateral impact on the "electricity bill settlement" process (such as "process interruption, probability 95%" and "process delay of 30 minutes, probability 80%)).
[0060] Subsequently, the core capability layer sends the assessment conclusions and business impact assessments to the agent and process layer, which is composed of an automated handling module. In a preferred embodiment, this automated handling module is implemented by the agent and process layer. A decision-making agent receives the task (the received assessment conclusions and business impact assessments), queries the security policy database based on the risk level (high) in the assessment conclusions and the business impact (high risk of disruption) in the business impact assessment, and decides to take a "business-aware, precise blocking" measure, rather than complete isolation.
[0061] The security policy library is pre-built, a structured knowledge base primarily based on the organization's security compliance and business continuity requirements. The data stored in this library is mapped to a "business-aware, precise blocking" strategy if: the assessment conclusion is "high risk" AND the business impact assessment is "interruption of core transactions." The coordinating agent, by querying these pre-defined libraries in the security policy library, can automatically match and execute the optimal action based on real-time assessment results.
[0062] The coordinating agent breaks down tasks and distributes them to distributed processing agents. For example, a processing agent deployed on a database firewall is activated. Instead of blocking the entire host, it performs fine-grained blocking based on recommendations from the business analysis module, targeting only SQL queries (non-normal queries from electricity billing services) originating from specific malicious IPs that access specific sensitive data tables.
[0063] Finally, all assessment, decision-making, and handling logs are aggregated at the application layer, triggering the report generation platform. This application layer is built upon the report generation platform, which invokes an intelligent report generation engine to automatically generate multiple reports for different audiences: one is a detailed event analysis report for technical personnel (containing a complete chain of evidence and handling steps), and the other is a summary report for management (explaining the nature of the event, that its business impact has been controlled, and that the risks have been eliminated).
[0064] The integrated analysis module, combining deep learning and large language models, and the fusion architecture of DL and LLM, achieves a comprehensive understanding of numerical patterns and semantic context, significantly improving the accuracy of alarm analysis, effectively reducing false alarms and false negatives, and alleviating "alarm fatigue". The automated handling module adopts a multi-level progressive response strategy, taking business process analysis as a prerequisite for automated handling, realizing a "business-aware" security response. Through progressive and precise handling, it avoids the impact of rough handling on core business and resolves the long-term conflict between security and business. The automated processing module adopts a distributed architecture based on AI agents, which has high elasticity, high fault tolerance and strong collaborative capabilities. With LLM as the cognitive core, it has the potential for autonomous learning and evolution, and is easy to adapt to complex and dynamically changing environments. It breaks through the context length limitation of LLM, enabling it to handle extremely long secure data sequences, greatly enhancing its ability to analyze complex, long-term, and covert attacks—a feat difficult to achieve with traditional methods. The experience and knowledge gained during the assessment and handling process are continuously learned and absorbed by the AI agent and large-scale language model, forming a reusable and evolvable structured knowledge base, which solves the problem of the difficulty in passing on security experience.
[0065] (II) Example: Handling Abnormal Data Access in Power Trading Center This embodiment details how the system performs business awareness and progressive handling in critical business scenarios.
[0066] Scenario: The system detected abnormal access to the power trading center database (DB_Trade_01) of a provincial power company.
[0067] Step 1: Assessment and Business Impact Analysis.
[0068] The monitoring agent reported an anomaly. The analysis agent initiated the fusion analysis module. LLM analysis revealed that the source IP (10.1.1.1) was attempting to enumerate the "historical electricity price" table using a non-standard SQL query, which was highly suspicious, but the account (User_A) it was using had normal permissions.
[0069] Meanwhile, the business process breakdown and analysis module was activated, confirming that the DB_Trade_01 server carries two major business processes: "real-time trading" (core business) and "historical query" (auxiliary business). It analyzed that account User_A belongs to the "Data Analysis Department," and its normal business only involves the "historical query" process; while the "real-time trading" process uses the service account (Svc_Trade).
[0070] Step 2: Decision-making and authorization verification.
[0071] The decision-making agent receives the assessment conclusion (medium risk) and the business impact assessment (if the server is isolated, "real-time transactions" will be interrupted; if only User_A is blocked, "real-time transactions" will not be affected).
[0072] The system queries the security policy database and decides to adopt a "progressive handling" strategy. In the first phase, instead of issuing a blocking command, it issues "enhanced monitoring" and "access restriction" commands. The coordinating agent verifies the authorization for the handling, confirming that the operation is within the pre-authorized scope. Before issuing the task, the coordinating agent checks whether the operation to be executed (e.g., "enhanced monitoring" or "access restriction") complies with the predefined security policy and permission scope.
[0073] Step 3: Gradual Implementation (Phase 1).
[0074] Coordinate agent task allocation. The processing agent deployed on the Database Firewall (DBFW) is activated and performs the following actions: a) Initiate full traffic auditing for all operations of User_A; b) Temporarily prohibit User_A account from accessing other sensitive tables (such as the "Customer Accounts" table) except for the "Historical Electricity Price" table.
[0075] Step 4: Risk Escalation and Precise Intervention (Phase 2).
[0076] After setting the duration (in this example, the duration is set to 10 minutes, i.e., after 10 minutes), the LLM of the analysis agent analyzed the full traffic log of the enhanced monitoring (a very long sequence of data). Using Longrope technology for global correlation, it was found that the query pattern of User_A matched the "data sniffing" pattern of a known APT attack tool with a 95% match rate. Furthermore, this IP (10.1.1.1) had a failed login attempt from a different account 3 hours ago.
[0077] The decision-making agent immediately raised the risk level to "extremely high, intrusion confirmed." The business process analysis module further confirmed that User_A had no connection to the "real-time transaction" process. The system decided to execute "precise blocking."
[0078] The coordinating agent issues a "precise blocking" command. Multiple handling agents deployed on the network firewall, identity authentication system, and DBFW work together to execute: a) immediately block all access from IP 10.1.1.1 on the network firewall; b) immediately lock the User_A account on the identity authentication system; c) clear all active sessions of User_A on the DBFW.
[0079] Step 5: Performance monitoring and report generation.
[0080] The monitoring agent continuously monitors the SLA metrics (such as transaction latency and TPS) of the "real-time trading" business process to ensure that it is not affected in any way. The system automatically generates closed-loop event reports and regulatory compliance reports.
[0081] In this embodiment, the system of the present invention successfully restricted the attacker in the early stage of the intrusion through a business-aware, progressive approach, and collected conclusive evidence through enhanced monitoring. Ultimately, the threat was precisely eliminated without affecting the core power trading business, perfectly resolving the conflict between security and business.
[0082] Example 3 Based on the same inventive concept, this invention also provides an automated data security risk assessment and handling method based on a large model, such as... Figure 2 As shown, it includes: Step 1: Based on security data, combined with deep learning models and large-scale language models, a comprehensive assessment of the risk level, attack intent, and potential impact of security incidents is conducted to obtain an assessment conclusion. Step 2: Based on security data, through process mining and traffic analysis, business processes and dependency graphs associated with security incidents are automatically discovered, modeled, and perceived in real time, and the potential impact of different handling measures on business continuity is evaluated to obtain a business impact assessment. Step 3: Using a distributed architecture of AI agents, the optimal risk handling strategy is selected and executed from the security policy library based on the assessment conclusions and the business impact assessment.
[0083] Optionally, step 1: Based on security data, and combining deep learning models and large-scale language models, a comprehensive assessment of the risk level, attack intent, and potential impact of the security incident is conducted to obtain an assessment conclusion, including: A text representation method based on a balanced tree data structure is adopted, combined with a local-global sparse attention mechanism to analyze security data, understand the global context, and obtain text understanding results; Deep learning models are used to perform time-series anomaly detection and correlation pattern analysis on numerical data in security data to obtain pattern analysis results. By integrating the results of text understanding with those of pattern analysis, conclusions can be drawn regarding the risk level, attack intent, and potential impact of security incidents.
[0084] Optionally, step 2: Based on security data, through process mining and traffic analysis, automatically discover, model, and perceive in real time the business processes and dependency graphs associated with security incidents, and assess the potential impact of different handling measures on business continuity to obtain a business impact assessment, including: When a security incident occurs, construct a system dependency graph of the key business processes related to the security incident; Based on the system dependency graph, different actions are simulated and executed to assess the potential impact of different actions and obtain a business impact assessment.
[0085] Optionally, step 3: Using a distributed architecture of AI agents, based on the assessment conclusions and the business impact evaluation, select and execute the optimal risk management strategy from the security strategy library, including: Real-time environmental perception and anomaly detection are performed by monitoring agents deployed at edge nodes, and raw anomaly data is reported to the analysis agent. By analyzing the intelligent agent to perform in-depth analysis and risk assessment of abnormal data, trigger signals are generated and transmitted to the fusion analysis module and the business process decomposition analysis module. The decision-making agent receives and integrates the judgment conclusions and business impact assessments, formulates a response plan based on the built-in security policy library, and distributes the response plan to the coordinating agent. The coordination agent breaks down the disposal plan into specific execution tasks, distributes the specific execution tasks to the disposal agent, and manages the communication, task allocation and conflict resolution between the agent and the disposal agent. The intelligent agents deployed on critical business systems or network devices perform specific security response operations based on specific tasks.
[0086] Optionally, before drawing conclusions by comprehensively assessing the risk level, attack intent, and potential impact of security incidents based on security data and combining deep learning models with large-scale language models, the following steps are also included: Security data is obtained from multi-source heterogeneous systems and then subjected to unified cleaning, standardization, and feature extraction to obtain processed security data.
[0087] Optionally, after the distributed architecture employing AI agents selects and executes the optimal risk management strategy from the security strategy library based on the assessment conclusions and the business impact evaluation, the method further includes: Analysis reports are automatically generated from the handling logs obtained based on the assessment conclusions, business impact evaluation, and optimal risk handling strategies.
[0088] This invention provides an automated data security risk assessment and handling method based on a large model, comprising the following steps: collecting and preprocessing multi-source security data; analyzing the data using a fusion assessment model, which combines a deep learning model for processing time-series and numerical features with a large language model for understanding text and log semantics; simultaneously, automatically analyzing the business processes associated with the security incident using techniques such as process mining, and assessing the potential impact of different handling measures on the business processes; and selecting and automatically executing an optimal risk handling measure based on the assessed risk level and the business impact assessment, wherein the measure achieves a balance between controlling security risks and ensuring business continuity.
[0089] Furthermore, in the step of analyzing using the fusion judgment model, when processing ultra-long security logs that the large language model cannot directly load, the following steps are included: segmenting the ultra-long log sequence into multiple text segments based on semantic boundaries (such as log entries, session identifiers); organizing the text segments into a balanced tree data structure and recursively generating content summary information for the internal nodes of the tree; and employing a local-global sparse attention mechanism to enable the large language model to efficiently access global summary information while processing local text segments, thereby achieving context awareness and key information extraction for ultra-long sequences.
[0090] Furthermore, the step of automatically executing risk mitigation measures is performed by a distributed AI agent network, including: after receiving a mitigation decision, the coordinating agent decomposes the task into sub-tasks; assigns the sub-tasks to the most suitable mitigation agent and performs authorization verification and pre-environment checks for the mitigation operation; the mitigation agent performs business process-aware blocking operations; during and after execution, the monitoring agent evaluates the mitigation effect and business impact in real time and feeds the results back to the decision-making agent for dynamic adjustment or confirmation.
[0091] Example 4 like Figure 3 As shown, the present invention also provides an electronic device, which may be a computer device, a microcontroller device, a smart mobile device, etc. The electronic device in this embodiment may include a processor, a memory, a transceiver component, etc. The memory, processor, and transceiver component are connected via a bus; the memory can be used to store executable programs, and an exemplary executable program may include instructions; the processor is used to execute the instructions stored in the memory. The memory can also be used to store data, which can be accessed and / or modified when instructions are executed.
[0092] The processor may be a Central Processing Unit (CPU), or it may be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. It is the computing core and control core of the terminal, and it is suitable for implementing one or more instructions. Specifically, it is suitable for loading and executing one or more instructions in the storage medium to realize the corresponding method flow or corresponding function, so as to realize the steps of the automated data security risk assessment and handling method based on the large model in the above embodiments.
[0093] Example 5 Based on the same inventive concept, this invention also provides a readable storage medium, specifically an electronic device readable storage medium (Memory). This readable storage medium is a memory device within an electronic device used to store programs and data. It is understood that the storage medium here can include both built-in storage media within the electronic device and extended storage media supported by the electronic device. The storage medium provides storage space, which stores the terminal's operating system. Furthermore, this storage space also stores one or more instructions suitable for loading and execution by a processor. These instructions can be one or more executable programs (including program code). It should be noted that the storage medium here can be high-speed RAM or non-volatile memory, such as at least one disk storage device. Loading and executing one or more instructions stored in the storage medium by the processor enables the implementation of the steps in the automated data security risk assessment and handling method based on a large model as described in the above embodiments.
[0094] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0095] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0096] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1The function specified in one or more boxes.
[0097] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0098] The above are merely embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention are included within the scope of the claims of the present invention pending approval.
Claims
1. An automated data security risk assessment and handling system based on a large model, characterized in that, include: The integrated analysis module is used to comprehensively analyze the risk level, attack intent, and potential impact of security incidents based on security data, combined with deep learning models and large-scale language models, and transmit the analysis results to the automated handling module. The business process decomposition and analysis module is used to automatically discover, model, and perceive the business processes and dependency graphs associated with security incidents in real time through process mining and traffic analysis based on security data, and to assess the potential impact of different handling measures on business continuity, and transmit the business impact assessment to the automated handling module. An automated handling module is used to select and execute the optimal risk handling strategy from a security strategy library based on the judgment conclusions and the business impact assessment using a distributed architecture of AI agents.
2. The method as described in claim 1, characterized in that, The fusion analysis module includes: The ultra-long sequence processing unit is used to analyze secure data by employing a text representation method based on a balanced tree data structure, combined with a local-global sparse attention mechanism, to understand the global context and obtain text understanding results; The pattern analysis unit is used to perform time-series anomaly detection and correlation pattern analysis on numerical data in security data using a deep learning model, and to obtain pattern analysis results. The fusion unit is used to combine the text understanding results with the pattern analysis results to obtain a judgment on the risk level, attack intent, and potential impact of the security incident.
3. The method as described in claim 1, characterized in that, The business process decomposition and analysis module is specifically used for: When a security incident occurs, construct a system dependency graph of the key business processes related to the security incident; Based on the system dependency graph, different actions are simulated and executed to assess the potential impact of different actions and obtain a business impact assessment.
4. The method as described in claim 1, characterized in that, The automated processing module includes: The monitoring agent is deployed on edge nodes for real-time environmental perception and anomaly detection, and reports the raw anomaly data to the analysis agent. The analytical agent is used to perform in-depth analysis and risk assessment of abnormal data, generate trigger signals, and transmit the trigger signals to the fusion analysis module and the business process decomposition analysis module. The decision-making agent is used to receive and integrate the judgment conclusions and business impact assessments, formulate a disposal plan based on the built-in security policy library, and distribute the disposal plan to the coordinating agent; The coordinating agent is used to break down the disposal plan into specific execution tasks, distribute the specific execution tasks to the disposal agents, and manage communication, task allocation and conflict resolution between the agents. Intelligent agents are deployed in critical business systems or network devices to perform specific security response operations based on specific tasks.
5. The method as described in claim 4, characterized in that, The analytical agent, decision-making agent, and coordination agent all employ a large-scale language model as their core cognitive engine.
6. The method as described in claim 1, characterized in that, Also includes: The data acquisition and preprocessing module is used to acquire security data from multi-source heterogeneous systems, perform unified cleaning, standardization and feature extraction, and transmit the processed data to the fusion and analysis module.
7. The method as described in claim 1, characterized in that, Also includes: Report generation platform; The report generation platform is used to receive the judgment conclusions obtained by the fusion judgment module, the business impact assessment obtained by the business process decomposition and analysis module, and the handling logs obtained by the automated handling module using the optimal risk handling strategy, and automatically generate an analysis report based on the judgment conclusions, business impact assessments and handling logs.
8. An automated data security risk assessment and handling method based on a large model, characterized in that, include: Based on security data, combined with deep learning models and large-scale language models, a comprehensive assessment of the risk level, attack intent, and potential impact of security incidents is conducted to arrive at an assessment conclusion. Based on security data, through process mining and traffic analysis, the system automatically discovers, models, and perceives in real time the business processes and dependency graphs associated with security incidents, and assesses the potential impact of different handling measures on business continuity to obtain a business impact assessment. Using a distributed architecture of AI agents, the system selects and executes the optimal risk handling strategy from the security policy library based on the assessment conclusions and the business impact assessment.
9. An electronic device, characterized in that, include: At least one processor and memory; The memory and processor are connected via a bus; The memory is used to store one or more programs; When the one or more programs are executed by the at least one processor, the method for automated assessment and handling of data security risks based on a large model as described in any one of claims 8 is implemented.
10. A readable storage medium, characterized in that, It contains an execution program, which, when executed, implements the automated data security risk assessment and handling method based on a large model as described in any one of claims 9.
Citation Information
Cited By
Intelligent safe operation method and device based on C4ISR and electronic equipment
CN122179228A
Method, device and system for risk identification and processing of network protocol addresses
CN122394966A