Alarm studying and judging system and method based on multi-agent cooperation
The alarm analysis system, which is based on multi-agent collaboration, realizes a complete automated process from alarm to analysis, solves the problems of low efficiency and insufficient accuracy in the existing SIEM system, improves the efficiency and accuracy of alarm processing, and enables the analysis results to be directly applied to existing security business processes.
Patent Information
- Application Number
- CN202511984703.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-25
- Publication Date
- 2026-03-10
AI Technical Summary
Existing SIEM systems lack a complete automated process and multi-toolchain collaboration in alarm analysis, resulting in low efficiency, insufficient accuracy, and low integration with existing security business processes.
An alarm analysis and judgment system based on multi-agent collaboration is adopted, including an alarm access module, a multi-agent collaborative analysis and judgment engine, and a result output module. Through the collaborative work of entity extraction, problem generation, tool invocation, and analysis and decision-making agents, an end-to-end automated process is achieved.
It improves the efficiency, accuracy, and feasibility of alarm handling, ensures the depth of analysis and the practicality of results, and can directly empower existing security business processes.
Smart Images

Figure CN121644308A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data processing technology, and in particular to an alarm analysis system and method based on multi-agent collaboration. Background Technology
[0002] Security Information and Event Management (SIEM) systems are central to enterprise security operations, used to centrally collect, standardize, and correlate massive amounts of security logs generated by various devices and systems, and generate security alerts. Faced with the ever-increasing number of alerts and complex attack methods, traditional security operations heavily rely on analysts manually analyzing each alert. In recent years, large language models have demonstrated powerful natural language understanding and reasoning capabilities, providing a new technical path for automated analysis of security log text. However, when directly applied to alert analysis scenarios, they have inherent limitations in task decomposition, tool invocation, and integration with existing systems.
[0003] Existing solutions primarily rely on single models or rule scripts to process alarms, leading to a break in the automation process and an inability to complete end-to-end analysis from alarm parsing and information retrieval to comprehensive judgment. Furthermore, due to the lack of division of labor and collaboration mechanisms among multi-role intelligent agents, and the inability to automatically access external toolchains such as asset and intelligence data for in-depth information, their analytical capabilities are limited. In addition, these solutions have low integration with actual SIEM operation platforms, making it difficult to integrate the judgment process and results into existing security business processes, resulting in serious deficiencies in practicality and feasibility. Summary of the Invention
[0004] Based on this, the present invention provides an alarm analysis system and method based on multi-agent collaboration to solve the problems of low efficiency and insufficient accuracy in existing SIEM alarm analysis caused by the lack of a complete automated process and multi-toolchain collaboration.
[0005] In a first aspect, embodiments of the present invention provide an alarm analysis system based on multi-agent collaboration, comprising: an alarm access module, a multi-agent collaborative analysis engine, and a result output module;
[0006] The alarm access module is used to obtain raw alarm data from the security information and event management platform, perform data preprocessing on the raw alarm data to generate structured alarm objects, and transmit the structured alarm objects to the entity extraction module in the multi-agent collaborative engine.
[0007] The multi-agent collaborative judgment engine includes multiple dedicated agents and a task orchestrator; the multiple dedicated agents include: an entity extraction agent, a problem generation agent, a tool invocation agent, and a judgment decision agent; the task orchestrator is configured to drive the entity extraction agent, the problem generation agent, the tool invocation agent, and the judgment decision agent to execute in sequence according to a preset judgment logic order, forming an end-to-end automated judgment process;
[0008] The entity extraction agent is configured to perform semantic understanding and rule matching on the structured alarm object to extract and label an entity list containing entity type, entity value and importance score;
[0009] The problem-generating agent is configured to generate a priority-sorted list of assessment problems based on the entity list by matching problem templates, filling in entity values, and referencing importance scores.
[0010] The tool invokes an intelligent agent, configured to analyze the semantics of each judgment question in the judgment question list, and routes calls to multiple external security tools for parallel queries in order to obtain and integrate the query results;
[0011] The judgment and decision-making intelligent agent is configured to construct an evidence chain based on the query results, and integrate rule reasoning and large language model reasoning to generate a judgment result containing judgment labels, confidence levels and judgment basis;
[0012] The result output module is used to associate the judgment result with the original alarm data and write it back to the security information and event management platform.
[0013] Secondly, embodiments of the present invention also provide an alarm judgment method based on multi-agent collaboration, including:
[0014] The system obtains raw alarm data from the security information and event management platform, performs data preprocessing on the raw alarm data to generate structured alarm objects, and transmits the structured alarm objects to the entity extraction module in the multi-agent collaborative engine.
[0015] By using an entity extraction agent, semantic understanding and rule matching are performed on the structured alarm object to extract and label an entity list containing entity type, entity value and importance score;
[0016] The question-generating agent generates a priority-sorted list of assessment questions based on the entity list by matching question templates, filling in entity values, and referencing importance scores.
[0017] The tool invokes an intelligent agent to analyze the semantics of each judgment question in the judgment question list, and routes calls to multiple external security tools to perform parallel queries in order to obtain and integrate the query results;
[0018] By analyzing the decision-making agent, an evidence chain is constructed based on the query results, and rule-based reasoning and large language model reasoning are integrated to generate an analysis result containing analysis labels, confidence levels, and analysis criteria.
[0019] The analysis results are correlated with the original alarm data and written back to the security information and event management platform.
[0020] This invention, through a multi-agent collaborative architecture driven by a task orchestrator, achieves a complete automated process from alarm to analysis. Each agent has a specialized role and collaborates sequentially, solving the problem of insufficient capabilities of a single model. The tools calling the agents can query multiple external tools in parallel, ensuring in-depth analysis. Simultaneously, the system is deeply integrated with existing SIEM platforms through standardized interfaces, enabling automated analysis conclusions to directly empower actual operations, thereby significantly improving the efficiency, accuracy, and implementability of alarm processing.
[0021] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0022] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0023] Figure 1 This is a schematic diagram of the internal structure of an alarm analysis system based on multi-agent collaboration according to Embodiment 1 of the present invention;
[0024] Figure 2 This is a flowchart of an alarm analysis method based on multi-agent collaboration provided in Embodiment 2 of the present invention. Detailed Implementation
[0025] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0026] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0027] Example 1
[0028] Figure 1 This is a schematic diagram of the internal structure of an alarm analysis system based on multi-agent collaboration provided in Embodiment 1 of the present invention. The system includes: an alarm access module (S1), a multi-agent collaborative analysis engine (S2), and a result output module (S3).
[0029] The alarm access module (S1) is used to obtain raw alarm data from the security information and event management platform, perform data preprocessing on the raw alarm data to generate structured alarm objects, and transmit the structured alarm objects to the entity extraction module in the multi-agent collaborative engine (S2).
[0030] The multi-agent collaborative judgment engine (S2) includes multiple dedicated agents and a task orchestrator (S21); the multiple dedicated agents include: an entity extraction agent (S22), a problem generation agent (S23), a tool invocation agent (S24), and a judgment decision agent (S25); the task orchestrator (S21) is configured to drive the entity extraction agent, the problem generation agent, the tool invocation agent, and the judgment decision agent to execute in sequence according to a preset judgment logic order, forming an end-to-end automated judgment process;
[0031] The entity extraction agent (S22) is configured to perform semantic understanding and rule matching on the structured alarm object to extract and label an entity list containing entity type, entity value and importance score;
[0032] The problem generation agent (S23) is configured to generate a priority-sorted list of judgment problems based on the entity list by matching problem templates, filling in entity values, and referring to importance scores.
[0033] The tool invokes an intelligent agent (S24) configured to analyze the semantics of each judgment question in the judgment question list and route calls to multiple external security tools for parallel queries in order to obtain and integrate the query results;
[0034] The judgment and decision-making intelligent agent (S25) is configured to construct an evidence chain based on the query results, and integrate rule reasoning and large language model reasoning to generate a judgment result containing judgment labels, confidence levels and judgment basis;
[0035] The result output module (S3) is used to associate the judgment result with the original alarm data and write it back to the security information and event management platform.
[0036] This system aims to automate and intelligently analyze alarms from the Security Information and Event Management (SIEM) platform. For example... Figure 1 As shown, the alarm analysis system mainly consists of three modules in sequence: an alarm access module (S1), a multi-agent collaborative analysis engine (S2), and a result output module (S3). Its core workflow is as follows: the alarm access module (S1) obtains the original alarms from the Security Information and Event Management (SIEM) platform and processes them into a standardized format; subsequently, multiple dedicated agents in the multi-agent collaborative analysis engine (S2), under the scheduling of the task orchestrator (S21), sequentially perform in-depth analysis of the alarms and generate analysis conclusions; finally, the result output module writes the conclusions back to the SIEM platform, completing the closed loop.
[0037] The alarm access module (S1) serves as the interface between the system and the external SIEM platform. It is responsible for data input and initial processing. Its functions are specifically implemented by calling the platform's application programming interface (API) to either periodically poll or receive streaming data in real time. The resulting structured alarm object is an internal data object with predetermined fields and formats, providing a unified and standardized input for all subsequent analysis steps.
[0038] The task orchestrator (S21) is the scheduling center of the multi-agent collaborative judgment engine. Its "driving according to a preset judgment logic sequence" is specifically manifested as a fixed, data-driven execution sequence: entity extraction → problem generation → tool invocation → judgment decision. The orchestrator monitors the execution status of each agent, and only automatically triggers the start of the next agent after an agent successfully completes its task and outputs the specified data result (such as the entity extraction agent outputting an entity list), thereby ensuring the continuity and automation of the process.
[0039] The entity extraction agent (S22) is responsible for identifying key information from unstructured text. Its "semantic understanding and rule matching" process combines two technologies: ① It utilizes a Large Language Model (LLM) to perform deep analysis on text fields such as event descriptions in structured alert objects, understanding the context and extracting implicit, non-fixed-format security entities such as attack methods and malware families. ② It applies a set of predefined regular expressions or pattern rules to quickly scan structured fields, accurately extracting entities with fixed formats such as IP addresses, domain names, file hashes, and user accounts. The results extracted by these two methods are then fused, deduplicated, and combined with a security knowledge graph to label each entity with its type, assigning it an importance score based on predefined rules or models. The final output entity list is a structured data set containing entity type, entity value, and importance score.
[0040] The problem-generating agent (S23) transforms entities into actionable guidelines for investigation. Its work is specified in three steps: ① Based on the type of each entity in the entity list, select the corresponding template from a pre-built security analysis question template library (e.g., for the "IP address" type, match the "Is this IP a malicious IP?" template); ② Fill the specific "value" of the entity into the placeholders of the selected template to generate specific judgment questions (e.g., "Is IP address '192.168.1.100' a malicious IP?"); (3) Based on the importance score of the entity, prioritize all generated questions to form a priority-ordered judgment question list to guide subsequent resources to prioritize high-risk questions.
[0041] The tool invocation agent (S24) is responsible for collecting external information. Its work includes: ① analyzing the intent of each assessment question and determining the type of external security tool to be queried; ② sending the query requests corresponding to different questions concurrently to their respective target tool interfaces, rather than executing them sequentially, thereby significantly shortening the overall query time; ③ receiving the raw data returned by each tool, cleaning and standardizing the format, and associating it with the corresponding questions to form a unified query result set.
[0042] The decision-making agent employs a hybrid reasoning model: ① Constructing an evidence chain: Based on the entity list, question list, and query results, a logically connected evidence chain is constructed, clearly presenting the deductive relationship from alarms to various types of evidence; ② Integrating rule-based reasoning and large language model reasoning: First, the evidence chain is matched with a pre-set expert rule base, performing deterministic logical judgment (rule-based reasoning). Then, the evidence chain and rule matching results are input into a large language model for deep contextual semantic synthesis and uncertain reasoning (large language model reasoning); ③ Generating a judgment result: Finally, a structured judgment result is output, which includes: judgment labels, confidence levels, and textual judgment basis derived from the evidence chain.
[0043] The results output module (S3) is responsible for applying the conclusions of intelligent analysis to actual operations. Its specific functions are: ① using the unique identifier of the original alarm to bind the generated analysis result with the alarm record; ② by calling the API of the SIEM platform, writing the key information in the analysis result into the custom fields of the alarm record, so that the analysis conclusion can be directly displayed in the SIEM console and can be directly used by subsequent work orders and automated response processes.
[0044] This invention, through a multi-agent collaborative architecture driven by a task orchestrator, achieves a complete automated process from alarm to analysis. Each agent has a specialized role and collaborates sequentially, solving the problem of insufficient capabilities of a single model. The tools calling the agents can query multiple external tools in parallel, ensuring in-depth analysis. Simultaneously, the system is deeply integrated with existing SIEM platforms through standardized interfaces, enabling automated analysis conclusions to directly empower actual operations, thereby significantly improving the efficiency, accuracy, and implementability of alarm processing.
[0045] Optionally, the alarm access module (S1) may further include: a data acquisition unit (S11), a format standardization unit (S12), and a data cleaning unit (S13).
[0046] The data acquisition unit (S11) is used to periodically poll or receive raw alarm data in real time through the API interface provided by the security information and event management platform.
[0047] The format standardization unit (S12) is used to parse the original alarm data and convert it into a unified JSON format object within the system to obtain standard alarm data.
[0048] The data cleaning unit (S13) is used to remove redundant fields, complete key information, and filter noisy data from the standard alarm data to generate structured alarm objects.
[0049] The data acquisition unit (S11) serves as the data channel between the system and the external SIEM platform. Periodic polling refers to the system actively calling the SIEM platform's query API at fixed time intervals to retrieve newly generated alarm data. This method is suitable for scenarios that do not support proactive push or require controlled retrieval rhythm. Real-time reception refers to the system registering as an event listening endpoint on the SIEM platform. When the platform generates a new alarm, it transmits the data to this system in real time through push mechanisms such as Webhook and message queues (e.g., Kafka). This method achieves the lowest possible analysis latency. The format standardization unit (S12) is responsible for resolving the unification issue of multi-source heterogeneous data. Since the original alarm formats output by different devices and SIEM products vary greatly, direct processing is extremely difficult. Its "parsing" operation refers to identifying the format of the original data and extracting discrete fields based on predefined rules or a parser. JSON was chosen as the internal standard exchange format due to its flexible structure and strong universality. The format standardization unit (S12) maps parsed fields to corresponding key-value pairs according to a predefined, fixed JSON schema, generating a standard alarm data object that all subsequent modules can understand unambiguously. This is the primary prerequisite for achieving an automated pipeline. The data cleaning unit (S13) performs in-depth processing of the standard alarm data object: ① Removes fields that do not contribute substantially to security analysis, reducing data noise and processing overhead; ② Completes missing but critical information based on rules or lookup tables. For example, when an alarm only contains the hostname but not the IP address, its IP information can be completed by querying the internal CMDB (Configuration Management Database); ③ Filters out known, explicit, and meaningless alarms using simple rules. The output obtained after the above cleaning is a structured alarm object that can be directly used by the entity extraction agent.
[0050] Furthermore, the entity extraction agent (S22) may also include: a semantic parsing unit (S221), a rule matching unit (S222), and an entity annotation unit (S223);
[0051] The semantic parsing unit (S221) is used to perform deep semantic analysis on the text description in the structured alarm object using a large language model to identify the initial set of entities associated with the context.
[0052] The rule matching unit (S222) is used to scan and match the structured alarm object using a predefined set of regular expression patterns to obtain a set of rule-based structured entities.
[0053] The entity annotation unit (S223) is used to receive and merge the initial entity set and the structured entity set, perform deduplication and normalization processing on the merged entities, assign an importance score to each entity based on the security domain knowledge graph, and finally generate an entity list containing entity type, entity value and importance score.
[0054] The semantic parsing unit (S221) employs a deep semantic analysis of the text description using a large language model. The input is unstructured or semi-structured text fields from structured alert objects, typically "event description" or "message" fields, which contain natural language descriptions of the security event. The core operation involves calling the large language model and leveraging its powerful contextual understanding and named entity recognition capabilities to identify security-related elements from the text. This includes, but is not limited to, attack methods, malware names, attack phase descriptions, and context-related entities not explicitly listed in fixed fields. Its output is an initial entity set, focusing on identifying implicit, semantically related entities. The rule matching unit (S222) uses a predefined set of regular expression patterns for scanning and matching. The input is also a structured alert object, but it focuses on processing field values with fixed formats. The core operation involves using a pre-compiled set of regular expression patterns for various security entities. The system uses regular expressions to perform high-speed and accurate scanning of all fields. This method can reliably extract structured entities such as IP addresses, port numbers, and file hashes. Its output is a rule-based set of structured entities, focusing on identifying clearly defined, fixed-format entities. The entity annotation unit (S223) is the fusion and decision layer, responsible for integrating the outputs of the two technical paths into the final output. First, it receives two entity sets as input from semantic parsing and rule matching. Second, it merges the entities in the two sets and deduplicates entities pointing to the same real-world object (e.g., merging the IP address matched by the rule with the same IP address mentioned in the semantic analysis) and normalizes their representations (e.g., associating "Host A" and "WEB-SRV-01" as the same entity). Finally, the system queries a security domain knowledge graph. Based on this graph, it determines a more precise entity type for each entity and calculates its importance score. The scoring rules can be based on the entity's attributes in the knowledge graph and its contextual role in the current alert.
[0055] Optionally, the question generating agent (S23) further includes: a template matching unit (S231), a question generating unit (S232), and a sorting unit (S233);
[0056] The template matching unit (S231) is used to select a corresponding problem template from a preset security analysis problem template library according to the entity type of each entity in the entity list.
[0057] The question generation unit (S232) is used to combine the matched question template with the entity value of the corresponding entity to generate a specific judgment question;
[0058] The sorting unit (S233) is used to prioritize the generated assessment questions based on the importance score of each entity, forming a list of assessment questions.
[0059] The core technology of the template matching unit (S231) lies in a "preset security analysis question template library." The matching criterion is the entity type of each entity in the entity list, a deterministic mapping process. For example, when the entity type is "IP address," a pre-defined template associated with that type in the template library will be selected. This security analysis question template library is a carrier of domain knowledge, pre-defined by security experts to ensure that the generated questions conform to a professional analysis framework, covering different analysis dimensions such as assets, vulnerabilities, threats, and behaviors. The question generation unit (S232) performs simple string combination or formatted replacement with the placeholder question templates obtained from the template matching unit and the currently processed specific "entity values." The result is a specific, actionable assessment question. This process transforms abstract entities and templates into specific investigation instructions for the current alarm context. The sorting unit (S233) sorts based directly on the importance score calculated for each entity during the entity extraction phase. Entities with higher scores are considered to pose a greater risk or be more critical in the current alert (for example, a destination IP labeled "database server" typically has a higher importance score than a regular office terminal IP). The system sorts a series of issues generated by the issue generation unit in descending order based on this score. The final output list of issues for assessment is a priority-sorted queue. This ensures that in subsequent tool calls, the system prioritizes concurrent queries for issues related to high-importance entities, allowing the most critical security investigations to yield results first, thus optimizing the timeliness and risk focus of the overall assessment process.
[0060] Furthermore, the tool invokes an intelligent agent (S24), which includes: a semantic routing unit (S241), a parameter adaptation unit (S242), a parallel invocation unit (S243), and a result integration unit (S244).
[0061] The semantic routing unit (S241) is used to receive a list of assessment questions sorted by priority, analyze the semantic intent of each assessment question, determine at least one target external security tool to be invoked for each assessment question based on the semantic intent, and record the target external security tool as a data source corresponding to the assessment question.
[0062] The parameter adaptation unit (S242) is used to receive the data source and the judgment question from the semantic routing unit, and convert each judgment question into a corresponding query request according to the interface specifications of each data source.
[0063] The parallel invocation unit (S243) is used to uniformly schedule all query requests, concurrently send query requests to all target external security tools involved, and receive the original response returned by each target external security tool.
[0064] The result integration unit (S244) is used to obtain all the original responses of each judgment question from the parallel calling unit, standardize and clean the original responses and unify their format, and then merge them to generate query results for the current judgment question. The query results corresponding to each judgment question and the data source are associated and encapsulated to generate a structured query result set.
[0065] The semantic routing unit (S241) takes as input a sorted list of assessment questions generated upstream. Analyzing semantic intent involves parsing the literal meaning of the questions using rules or lightweight models to determine their query type. For example, the intent of the question "Is IP address X malicious?" is "Threat intelligence query". Based on the intent, one or more of the most suitable tools are selected from the system-configured set of target external security tools (i.e., APIs of various SIEM subsystems or third-party services, such as VirusTotal, Asset CMDB, and vulnerability scanners) as the targets for this query. Simultaneously, the identifiers of the selected tools are recorded as data sources, providing key metadata for subsequent result tracing and evidence chain construction. The parameter adaptation unit (S242) takes as input from the semantic routing unit, i.e., the assessment questions and their corresponding data sources. Its core operation is querying a pre-defined interface specification configuration library, which defines the authentication methods, API endpoints, and parameter formats required for each external tool. According to the specifications, common assessment questions are converted into query requests that conform to the API requirements of specific tools. For example, the entity value "192.168.1.100" from the question is filled into the indicator parameter required by the target intelligence platform API. The parallel invocation unit (S243) aims to minimize the overall latency caused by external I / O. Its operation of "unified scheduling" and "concurrent sending" means that this unit does not execute query requests sequentially, but collects all query requests generated within the current analysis period (for a single alarm), and uses asynchronous I / O or thread pools to simultaneously initiate network calls to multiple different external tool interfaces. The data returned by each tool, maintaining its original format, is called the raw response. The result integration unit (S244) is responsible for transforming the raw data into usable intelligence. The input is the messy and loosely related raw responses collected by the parallel invocation unit. First, according to the tool type corresponding to each response, the corresponding parser is invoked for standardization, cleaning, and format unification. Then, multiple tool responses that may correspond to the same analysis question (such as an IP querying both intelligence A and intelligence B) are "fused" to generate a unified query result for that question. Finally, the query results, the original question text, and its data source for each question are bound together and encapsulated into a structured information unit. The collection of all information units for each question constitutes the structured query result set output downstream.
[0066] The tool invocation agent achieves intelligent and flexible integration of external tools through semantic routing and parameter adaptation, rather than hard-coded invocation. The parallel invocation mechanism greatly improves performance in scenarios with massive external queries. The result integration unit ensures the availability and traceability of heterogeneous data, enabling threat data from different vendors and in different formats to be processed and applied uniformly, forming the core support for the system's deep analysis capabilities.
[0067] Optionally, the judgment and decision-making intelligent agent (S25) further includes: an evidence chain construction unit (S251), a rule reasoning unit (S252), and a fusion reasoning unit (S253);
[0068] The evidence chain construction unit (S251) is used to receive the query result set and, based on the entity list, logically associate and chronologically organize each entity with its corresponding judgment question, query result and data source to construct a structured evidence chain with the entity as the core.
[0069] The rule reasoning unit (S252) is used to receive the structured evidence chain and sequentially call each logical rule in the expert rule base. Based on the target condition carried by the current logical rule, it searches for the corresponding target entity in the structured evidence chain and compares the query result associated with the target entity with the target condition. If the comparison is successful, it records the target logical rule to which the target condition belongs as the target triggering rule. By summarizing all target triggering rules, it generates a rule reasoning result for the structured evidence chain.
[0070] The fusion reasoning unit (S253) is used to receive the structured evidence chain and the rule reasoning result, and input both into the large language model. Utilizing the comprehensive analysis capability of the large language model, it outputs a judgment result that includes judgment labels, confidence levels, and judgment criteria.
[0071] The evidence chain construction unit (S251) receives the query result set and entity list generated upstream as input. Logical association and temporal organization refer to the fact that the evidence chain construction unit (S251), using each entity as an anchor point, automatically associates "What is this entity?" (from the entity list), "What question was asked about it?" (question analysis), "What answer was found?" (query result), and "Where did the answer come from?" (data source) according to the logical sequence of question generation and tool invocation. These associations are organized into a clear, entity-centric structured evidence chain. The rule reasoning unit (S252) executes based on a pre-set expert rule base, where each logical rule defines a specific target condition. The rule reasoning unit (S252) traverses each rule, locates the target entity specified by the rule condition from the structured evidence chain, and extracts the query result data associated with that entity. Then, the data is compared item by item with the rule conditions. If all conditions of a rule are met, the rule is marked as a target triggering rule. The set of all triggered rules constitutes the rule-based reasoning result, representing a reproducible, deterministic judgment based on explicit expert knowledge. The input to the fusion reasoning unit (S253) integrates the structured chain of evidence representing facts and connections with the rule-based reasoning result representing deterministic logical judgments. The core operation is to input both as a holistic context into the large language model. Through a carefully designed prompting process, leveraging the comprehensive analytical capabilities of the large language model, the LLM is guided to perform the following comprehensive tasks: ① Evaluation and Judgment: Based on all input information, the alarm event is qualitatively assessed, generating a judgment label; ② Quantified Confidence: The degree of confidence in its own judgment is self-assessed, generating a quantified confidence level; ③ Inductive Basis: From the input chain of evidence and triggered rules, key factual chains and logical points supporting the above judgments are extracted, generating a natural language description of the judgment basis. The final output contains the above three elements and can be directly used to guide the response.
[0072] In this embodiment, the three-stage architecture of "evidence chain construction + rule-based reasoning + large language model fusion reasoning" is the core of the system's intelligent decision-making. It combines the efficiency and determinism of a rule-based system with the powerful ability of a large language model to handle complex, fuzzy, and unstructured reasoning. The evidence chain ensures the traceability and explainability of the entire process; the rule engine provides rapid risk modeling and expert knowledge application; and the final large language model fusion integrates all information and intermediate conclusions to generate a convincing natural language report. This effectively solves the shortcomings of rigid single rule systems or the "black box" and uncontrollable nature of single models.
[0073] Furthermore, the result output module (S3) also includes: a tag writing unit (S31) and a result storage unit (S32);
[0074] The tag writing unit (S31) is used to receive the judgment result and write the judgment tag in the judgment result into the custom field of the alarm record corresponding to the original alarm data through the API interface provided by the security information and event management platform;
[0075] The result storage unit (S32) is used to associate and store the judgment basis and confidence level in the judgment result with the original alarm data, so that the front-end interface of the security information and event management platform can call and display it.
[0076] The tag writing unit (S31) uses a standard API interface provided by the SIEM platform. Specifically, it locates the corresponding alarm record in the SIEM platform using a unique identifier carried in the original alarm data. Then, it writes the assessment tag into a predefined custom field of that record via the API. This custom field is a storage space that the SIEM platform allows users to expand themselves. This operation enables the conclusions of automated assessments to be directly displayed on the native interface of the SIEM console, such as the alarm list and dashboard. Security analysts can quickly identify high-risk alarms without switching systems and can use this tag for filtering, triage, or triggering automated response processes. The result storage unit (S32) is responsible for the complete recording and long-term management of the assessment process, supporting in-depth review and auditing. Its operation objects are the assessment basis containing detailed reasoning processes and the confidence level indicating the degree of certainty. The result storage unit (S32) stores the complete assessment basis and confidence level in the form of structured documents or database records in a dedicated system storage area. During storage, it strongly associates the result with the original alarm data using the same unique identifier. The ultimate goal is to provide this information for the front-end interface to access and display. For example, when a security analyst clicks "View Details" on a pre-assessed alert on the SIEM platform frontend, the frontend interface can send a request to the system or associated storage service via the alert ID to retrieve and display the complete assessment basis and confidence level. This provides analysts with a transparent explanation of their decisions, supporting conclusion review, incident tracing, and experience accumulation.
[0077] By splitting the output strategy into real-time tag writing and result-based associated storage, this embodiment achieves an optimal balance between performance and functionality. Tag writing ensures the real-time nature and operational integration of the assessment conclusions, making the automation effects immediately visible and usable; result storage guarantees the interpretability and auditability of the analysis process, forming a complete digital evidence archive. The two are closely linked through a unified identifier, together forming the final link in the closed-loop automation of security operations, making the intelligent assessment system not only an analysis tool but also an "intelligent enhancement component" that can enhance and empower existing SOC workflows.
[0078] Optionally, the task orchestrator (S21) further includes: a task scheduling unit (S211) and a status monitoring unit (S212);
[0079] The task scheduling unit (S211) has a pre-set task execution sequence corresponding to the judgment logic order, which is used to send task start instructions to the entity extraction agent, the problem generation agent, the tool calling agent and the judgment decision agent in sequence.
[0080] The status monitoring unit (S212) is used to monitor the task execution status of the corresponding intelligent agent in real time after the task scheduling module sends the instruction; when it detects that the current intelligent agent outputs the corresponding structured data result, it sends a completion signal to the task scheduling module, and the task scheduling module sends a task start instruction to the next intelligent agent according to the task execution sequence, thereby driving each intelligent agent to execute in sequence and form the end-to-end automated judgment process.
[0081] The core of the task scheduling unit (S211) is a built-in, fixed task execution sequence. This sequence clearly defines the startup order of four dedicated intelligent agents: entity extraction → problem generation → tool invocation → analysis and decision-making. This sequence is an abstraction and solidification of best practices in security analysis, ensuring the correctness of the analysis logic. Sending task startup commands sequentially is a proactive command behavior; it marks the initiation of the analysis process for a specific alarm and sequentially issues commands to each intelligent agent to begin work. The status monitoring unit (S212) is responsible for ensuring the continuity of the process and data-driven collaboration. Real-time monitoring of task execution status establishes a status communication mechanism between the status monitoring unit (S212) and each intelligent agent. It does not monitor all internal computational processes of the intelligent agent but focuses on milestone events related to task completion. The key triggering condition is the detection of the structured data result output by the current intelligent agent; this is the core mechanism for achieving data-driven collaboration in this embodiment. Specifically: when the entity extraction intelligent agent completes its work and successfully outputs the entity list, the status monitoring unit captures this event and then sends a completion signal to the task scheduling unit. The task scheduling unit will only send a start command to the next agent after receiving a completion signal from the preceding agent, based on its built-in task execution sequence. For example, it will only instruct the problem-generating agent to start after confirming receipt of the entity list.
[0082] The task scheduling unit and the status monitoring unit form a closed-loop control circuit of "issuing a command - waiting for feedback - issuing the next command". This design ensures that the activation of downstream agents strictly depends on the high-quality output of upstream agents, rather than simple timed or blind sequential invocation. It effectively prevents process chaos or idle running due to the failure or timeout of a certain agent, greatly improving the robustness and reliability of the entire automated pipeline.
[0083] Example 2
[0084] Figure 2 This is a flowchart of an alarm analysis method based on multi-agent collaboration provided in Embodiment 2 of the present invention. This embodiment is applicable to the automated and intelligent analysis of alarms generated by a Security Information and Event Management (SIEM) platform. This method can be executed by an alarm analysis system based on multi-agent collaboration, which can be configured in an independent server or computing device linked to the SIEM platform. Figure 2 As shown, the system includes:
[0085] S210. Obtain raw alarm data from the security information and event management platform, perform data preprocessing on the raw alarm data to generate structured alarm objects, and transmit the structured alarm objects to the entity extraction module in the multi-agent collaborative engine.
[0086] Raw alarm data is obtained from the security information and event management platform. This can be achieved by calling the platform's standard API in two modes: periodic polling (actively pulling data periodically) or real-time reception (listening to the event stream), ensuring reliable alarm data access. Preprocessing the raw alarm data to generate structured alarm objects is a deterministic process. This includes parsing the acquired raw data, which varies in format, and extracting key fields; performing standardization, such as unifying timestamp formats and IP address representations; and performing basic cleaning to filter invalid entries. The output is an internally unified structured alarm object, which is directly transmitted to the entry point of the multi-agent collaborative engine, i.e., the entity extraction agent.
[0087] S220. Using an entity extraction agent, perform semantic understanding and rule matching on the structured alarm object to extract and label an entity list containing entity type, entity value, and importance score.
[0088] This embodiment serves as the starting point for information extraction and standardization, while "semantic understanding and rule matching" represent the collaborative application of these two techniques. Semantic understanding specifically refers to invoking a large language model to perform deep contextual analysis on unstructured text fields (such as event descriptions) within the structured alert object, identifying and extracting implicit, non-fixed-pattern security-related concepts and objects to form an initial entity set. Rule matching specifically refers to simultaneously applying a set of pre-compiled regular expression patterns to perform high-speed scanning of structured fields in the alert object, accurately matching and extracting entities with fixed formats to form a structured entity set. Based on a security domain knowledge graph, each entity is assigned a standardized entity type and its importance score is calculated. The final generated entity list is a structured data set rich in semantic information and priority weights.
[0089] S230. Generate an intelligent agent by generating a list of judgment questions sorted by priority based on the entity list by matching question templates, filling in entity values, and referring to importance scores.
[0090] The matching question template solidifies expert analysis experience, ensuring the professionalism and comprehensiveness of the generated questions and avoiding the uncertainty of freely generated ones. Filling entity values instantiates the general template into a specific query task for the current alarm. The key design of this embodiment is generating a priority-sorted list based on importance scores. This is not a simple sorting but introduces a risk-based dynamic scheduling concept. This allows subsequent resources to prioritize issues corresponding to high-risk entities, optimizing the timeliness of the overall analysis process and mimicking the decision-making process of a senior analyst focusing on the main issues.
[0091] S240. By calling the intelligent agent through the tool, the semantics of each judgment question in the judgment question list are analyzed, and multiple external security tools are routed to perform parallel queries in order to obtain and integrate the query results.
[0092] Analyzing semantic intent and routing solves the "which tool to query" problem, demonstrating intelligent scheduling capabilities and accurately mapping analytical needs to different external tools such as assets, vulnerabilities, and intelligence. Parallel queries directly target I / O latency bottlenecks when multiple external interface calls are made, compressing the total time to the level of the slowest single request through concurrent requests, which is a key technical means to improve end-to-end process efficiency. Acquiring and integrating query results standardizes and correlates the diverse original responses, forming a structured query result set, providing unified and reliable factual input for the final decision.
[0093] S250. Through the analysis and decision-making intelligent agent, an evidence chain is constructed based on the query results, and rule reasoning and large language model reasoning are integrated to generate an analysis result containing analysis labels, confidence levels and analysis basis.
[0094] The advanced nature of the decision-making agent lies in its "layered-fusion" reasoning architecture. Constructing an evidence chain based on query results first organizes scattered factual points into a logically connected structured narrative, solving the problem of information fragmentation and laying the foundation for interpretability. The core innovation of the decision-making mechanism is the fusion of rule-based reasoning and large language model reasoning. Rule-based reasoning provides efficient processing of clear and deterministic logic, offering speed and clear results; large language model reasoning, based on rules, handles complex and uncertain contextual relationships and intent inferences within the evidence chain. The fusion of these two approaches overcomes the rigidity of rule-based systems while avoiding the uncontrollability and factual illusion risks associated with large models acting as "black boxes," ultimately robustly generating complete conclusions containing judgment labels, confidence levels, and traceable judgment evidence.
[0095] S260. Associate the judgment result with the original alarm data and write it back to the security information and event management platform.
[0096] Linking the analysis results with the original alarm data ensures a precise link between the analytical conclusions and the source event. Writing back to the security information and incident management platform uses a standard API to directly update the analysis conclusions (especially the analysis tags) to the SIEM alarm logs. This design allows the output of intelligent analysis to be seamlessly embedded into existing security operations workflows, presented directly on the analyst's console, and can drive subsequent work orders, reports, or automated response scripts, completing a closed loop from intelligent analysis to operational action.
[0097] This invention defines a complete technical solution from standardized data input to intelligent agent-based processing, efficient integration of external tools, hybrid reasoning decision-making, and finally closed-loop operational empowerment. Each step is tightly linked through structured data output; the output of each preceding step is a necessary condition and input for the high-quality execution of subsequent steps. Together, they constitute an integrated method for addressing the needs of automated, intelligent, and implementable alarm analysis in scenarios with massive alarm volumes, significantly improving the efficiency, accuracy, and implementability of alarm analysis overall.
[0098] Optionally, after associating the assessment results with the original alarm data and writing them back to the security information and event management platform, the process may further include:
[0099] The security information and event management platform calls the previously written-back assessment results, and through the front-end visualization engine, renders the assessment tags and confidence levels in the custom field area of the alarm list interface, and generates interactive visualization charts to display the assessment basis in the assessment details interface.
[0100] This embodiment also describes how the generated assessment results, after being written back to the SIEM platform, are ultimately consumed and applied. Specifically, this is executed by the SIEM platform, which utilizes its standard capabilities to display the assessment results, which have been written back and stored in the SIEM platform database through the aforementioned steps and are bound to a specific alarm record. In the SIEM platform's unified alarm management list view, the platform's front-end service automatically extracts the assessment tag and confidence level fields from the storage location associated with the alarm record. Subsequently, according to the predetermined display configuration, the values of these two fields are dynamically rendered to the custom field display area corresponding to the alarm record in the list, thereby achieving rapid risk classification and filtering of alarms. When security operations personnel navigate to the detailed analysis page of a specific alarm through the platform interface, the platform will call its front-end visualization engine to parse and transform the more complex assessment basis parts in the assessment results, automatically converting the structured relational information contained within the assessment basis into one or more interactive visual charts.
[0101] By transforming the structured analytical data generated by machine reasoning into intuitive visual charts, the originally complex and internal analysis process becomes externalized, transparent, and easily traceable. This effectively addresses the "black box" concerns in artificial intelligence applications and enhances security personnel's trust in and willingness to adopt automated analytical results. Based on the standard front-end capabilities of the SIEM platform, the analytical results of this invention can be embedded into analysts' existing work environments at zero cost and without intrusion. The analytical conclusions are directly presented on their core operating interfaces used daily, eliminating the costs of system switching and data transfer. This achieves efficient integration from automated intelligent analysis to human decision-making intervention, directly demonstrating the high practicality and feasibility of this invention.
[0102] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.
[0103] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.
Claims
1. An alarm research and judgment system based on multi-agent cooperation, characterized in that, The application relates to an alarm processing method and device. The alarm processing method comprises the following steps: An alarm access module, a multi-agent collaborative research and judgment engine, and a result output module are provided. The alarm access module is used for obtaining original alarm data from a security information and event management platform, performing data preprocessing on the original alarm data to generate a structured alarm object, and transmitting the structured alarm object to an entity extraction module in the multi-agent collaborative engine. The multi-agent collaborative research and judgment engine comprises a plurality of special agents and a task arranger. The plurality of special agents comprise an entity extraction agent, a question generation agent, a tool calling agent, and a research and judgment decision-making agent. The task arranger is configured to drive the entity extraction agent, the question generation agent, the tool calling agent, and the research and judgment decision-making agent to sequentially collaborate and execute according to a preset research and judgment logic sequence, so as to form an end-to-end automatic research and judgment process. The entity extraction agent is configured to perform semantic understanding and rule matching on the structured alarm object to extract and label an entity list comprising an entity type, an entity value, and an importance score. The question generation agent is configured to generate a research and judgment question list sorted according to priorities by matching a question template, filling in entity values, and referring to importance scores according to the entity list. The tool calling agent is configured to analyze the semantics of each research and judgment question in the research and judgment question list, and route and call a plurality of external security tools for parallel query to obtain and integrate query results.
2. The system of claim 1, wherein, The research and judgment decision-making agent is configured to construct an evidence chain based on the query results, and generate a research and judgment result comprising a research and judgment label, a confidence score, and research and judgment basis by fusing rule reasoning and large language model reasoning. The result output module is used for associating the research and judgment result with the original alarm data and writing back to the security information and event management platform. The alarm access module further comprises a data acquisition unit, a format standardization unit, and a data cleaning unit. The data acquisition unit is used for regularly polling or real-timely receiving original alarm data through an API interface provided by the security information and event management platform.
3. The system of claim 1, wherein, The format standardization unit is used for parsing the original alarm data, converting the original alarm data into a JSON format object unified in the system, and obtaining standard alarm data. The data cleaning unit is used for performing redundant field elimination, key information completion, and noise data filtering on the standard alarm data to generate a structured alarm object. The entity extraction agent further comprises a semantic analysis unit, a rule matching unit, and an entity labeling unit. The semantic analysis unit is used for performing deep semantic analysis on a text description in the structured alarm object by using a large language model to identify an initial entity set associated with context. The rule matching unit is used for scanning and matching the structured alarm object by using a predefined regular expression pattern set to obtain a rule-based structured entity set. The question generation agent is configured to generate a research and judgment question list sorted according to priorities by matching a question template, filling in entity values, and referring to importance scores according to the entity list. The tool calling agent is configured to analyze the semantics of each research and judgment question in the research and judgment question list, and route and call a plurality of external security tools for parallel query to obtain and integrate query results. The research and judgment decision-making agent is configured to construct an evidence chain based on the query results, and generate a research and judgment result comprising a research and judgment label, a confidence score, and research and judgment basis by fusing rule reasoning and large language model reasoning. The result output module is used for associating the research and judgment result with the original alarm data and writing back to the security information and event management platform. The alarm access module further comprises a data acquisition unit, a format standardization unit, and a data cleaning unit. The data acquisition unit is used for regularly polling or real-timely receiving original alarm data through an API interface provided by the security information and event management platform. The format standardization unit is used for parsing the original alarm data, converting the original alarm data into a JSON format object unified in the system, and obtaining standard alarm data. The data cleaning unit is used for performing redundant field elimination, key information completion, and noise data filtering on the standard alarm data to generate a structured alarm object. The entity extraction agent further comprises a semantic analysis unit, a rule matching unit, and an entity labeling unit. The semantic analysis unit is used for performing deep semantic analysis on a text description in the structured alarm object by using a large language model to identify an initial entity set associated with context. The rule matching unit is used for scanning and matching the structured alarm object by using a predefined regular expression pattern set to obtain a rule-based structured entity set. The entity labeling unit is configured to receive and fuse the initial entity set and the structured entity set, perform deduplication and normalization processing on the fused entities, assign an importance score to each entity based on a security domain knowledge graph, and finally generate an entity list containing an entity type, an entity value, and an importance score.
4. The system of claim 1, wherein, The question generation agent further includes a template matching unit, a question generation unit, and a sorting unit. The template matching unit is configured to select a corresponding question template from a preset security analysis question template library according to an entity type of each entity in the entity list. The question generation unit is configured to combine the matched question template and the entity value of the corresponding entity to generate a specific research question. The sorting unit is configured to sort the generated research questions according to the importance score of each entity to form a research question list.
5. The system of claim 1, wherein, The tool calling agent includes a semantic routing unit, a parameter adaptation unit, a parallel calling unit, and a result integration unit. The semantic routing unit is configured to receive the research question list sorted by priority, analyze the semantic intent of each research question, determine at least one target external security tool to be called for each research question according to the semantic intent, and record the target external security tool as a data source corresponding to the research question. The parameter adaptation unit is configured to receive the data source and research question from the semantic routing unit, and convert each research question into a corresponding query request according to the interface specification of each data source. The parallel calling unit is configured to uniformly schedule all query requests, concurrently send the query requests to all target external security tools involved, and receive the original responses returned by each target external security tool. The result integration unit is configured to obtain all original responses of each research question from the parallel calling unit, fuse the original responses after standardization cleaning and format unification to generate a query result for the current research question, and associate and encapsulate the query result corresponding to each research question and the data source to generate a structured query result set.
6. The system of claim 5, wherein, The research and judgment decision agent further includes an evidence chain construction unit, a rule reasoning unit, and a fusion reasoning unit. The evidence chain construction unit is configured to receive the query result set and logically associate and time-organize each entity with its corresponding research question, query result, and data source based on the entity list to construct a structured evidence chain with the entity as the core. The rule reasoning unit is configured to receive the structured evidence chain, sequentially call each logical rule in the expert rule library, find the corresponding target entity from the structured evidence chain according to the target condition carried by the current logical rule, and compare the query result associated with the target entity with the target condition. If the comparison is successful, the target logical rule to which the target condition belongs is recorded as a target trigger rule. By aggregating all target trigger rules, a rule reasoning result for the structured evidence chain is generated. The fusion reasoning unit is configured to receive the structured evidence chain and the rule reasoning result, input both into a large language model, and output a judgment result including a judgment label, a confidence level, and a judgment basis by using comprehensive analysis capability of the large language model.
7. The system of claim 4, wherein, The result output module further includes a label writing unit and a result storage unit. The label writing unit is configured to receive the judgment result, write the judgment label in the judgment result into a custom field of an alarm record corresponding to the original alarm data through an API interface provided by the security information and event management platform, and store the judgment result in the custom field. The result storage unit is configured to store the judgment basis and the confidence level in the judgment result in association with the original alarm data, so as to be called and displayed by a front-end interface of the security information and event management platform.
8. The system of claim 1, wherein, The task arranger further includes a task scheduling unit and a state monitoring unit. The task scheduling unit is preconfigured with a task execution sequence corresponding to the judgment logic sequence, and is configured to sequentially send a task start instruction to the entity extraction agent, the question generation agent, the tool calling agent, and the judgment and decision-making agent. The state monitoring unit is configured to listen to a task execution state of a corresponding agent in real time after the task scheduling module sends an instruction, and send a completion signal to the task scheduling module when the corresponding structured data result is output by the current agent, so that the task scheduling module sends a task start instruction to a next agent according to the task execution sequence, to drive the agents to execute in sequence and form the end-to-end automatic judgment process.
9. An alarm research and judgment method based on multi-agent cooperation, characterized in that, An alarm judgment system based on multi-agent collaboration is executed, including: Obtaining original alarm data from a security information and event management platform, performing data preprocessing on the original alarm data to generate a structured alarm object, and transmitting the structured alarm object to an entity extraction module in the multi-agent collaboration engine; Performing semantic understanding and rule matching on the structured alarm object by an entity extraction agent to extract and label an entity list including entity types, entity values, and importance scores; Generating a priority-ordered judgment question list by matching a question template, filling in entity values, and referring to importance scores by a question generation agent according to the entity list; Analyzing the semantics of each judgment question in the judgment question list by a tool calling agent, and routing and calling multiple external security tools for parallel query to obtain and integrate query results; Constructing an evidence chain based on the query results by a judgment and decision-making agent, and generating a judgment result including a judgment label, a confidence level, and a judgment basis by fusing rule reasoning and large language model reasoning; Associating the judgment result with the original alarm data and writing back to the security information and event management platform.
10. The method of claim 9, wherein, After the judgment result is associated with the original alarm data and written back to the security information and event management platform, further including: The security information and event management platform calls the written back analysis result, renders the analysis label and confidence in the custom field area of the alarm list interface through the front-end visualization engine, and generates an interactive visualization chart in the analysis details interface to display the analysis basis.
Citation Information
Cited By
A Network Alarm Analysis Method and System Based on Multi-Agent Large Model Dynamic RAG
CN122226509B