Network security defense scene generation method and system based on AI large model

By constructing a network security defense scenario generation method based on multi-source data preprocessing and a dedicated AI large model, the problems of insufficient multi-source data fusion and poor model adaptability in existing technologies are solved. This enables accurate positioning of network security defense scenarios and efficient generation of strategies, improves threat assessment efficiency and defense response speed, and meets the needs of efficient security protection in complex network environments.

CN121841671APending Publication Date: 2026-04-10SANMEN NUCLEAR POWER CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-05
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

Existing methods and systems for generating cybersecurity defense scenarios based on AI large models suffer from insufficient multi-source data fusion, poor model adaptability, difficulty in accurately identifying false alarms and real attacks, lack of dynamic defense scenario generation capabilities, resulting in rigid defense strategies, inability to quickly respond to new threats, and reliance on manual analysis leading to high delays in alarm handling, numerous false alarms and missed alarms, making it difficult to meet the needs of efficient security protection in complex network environments.

Method used

By acquiring multi-source cybersecurity data, preprocessing it, and then training a basic AI model, a defense scenario generation model is constructed that integrates attack threat qualitative rules and thought chain reasoning mechanisms. Combined with the semantic understanding and analysis capabilities of a dedicated AI model, cybersecurity defense scenarios and corresponding defense strategies are generated. The model is then dynamically optimized through real-time data to achieve accurate positioning of defense scenarios and efficient generation of strategies.

Benefits of technology

It achieves efficient fusion and cleaning of multi-source data, improves the adaptability of the model and the accuracy of threat assessment, dynamically adjusts defense strategies, reduces manual operation and maintenance costs, and meets the needs of efficient 24/7 security protection in complex network environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121841671A_ABST
    Figure CN121841671A_ABST
Patent Text Reader

Abstract

The invention discloses a network security defense scene generation method and system based on an AI large model, and relates to the technical field of network security. The method comprises the following steps: firstly, acquiring multi-source data such as network equipment logs, attack traffic and threat intelligence, preprocessing the multi-source data, and training a basic AI large model to obtain a special AI large model adaptive to a network security scene; constructing a defense scene generation model integrating an attack threat qualitative rule and a thinking chain reasoning mechanism, and establishing a multi-type defense scene classification system and a corresponding strategy template; the method comprises the following steps: acquiring real-time network operation data, inputting double models to generate a targeted defense scene and strategy, performing defense operation, collecting feedback data, dynamically optimizing the models, and generating an alarm analysis report in real time. The system comprises an acquisition module, a model training module, a scene generation module, a defense disposal module and a display module. According to the method, the network security threat research and judgment efficiency and the defense accuracy are improved, the labor cost is reduced, and the complex network security protection requirements are met.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, in particular to a network security defense scene generation method and system based on an AI large model. BACKGROUND

[0002] With the rapid evolution of network attack and defense technologies, new advanced threats such as variant viruses and zero-day vulnerability attacks are emerging, and network architectures are becoming increasingly complex due to the Internet of Things and microservices. Daily, a large amount of security logs and attack traffic are generated. As a key infrastructure operator, it is necessary to respond to national risk resistance and 7*24-hour security monitoring requirements, and to build an intelligent defense system to improve threat judgment and disposal efficiency and ensure network security, which has become a core requirement in the field of network security.

[0003] The existing network security defense scene generation method and system based on an AI large model have the problems of insufficient multi-source data fusion, poor model adaptability, difficulty in accurately identifying business false positives and real attacks, lack of dynamic defense scene generation capability, fixed defense strategies, inability to quickly respond to new threats, and high alarm disposal delay and many false positives and false negatives due to reliance on manual analysis, which cannot meet the efficient and secure protection requirements in complex network environments. Therefore, a network security defense scene generation method and system based on an AI large model are needed to solve the above problems. SUMMARY

[0004] Therefore, the present application provides a network security defense scene generation method and system based on an AI large model, which solves the problems of insufficient multi-source data fusion, poor model adaptability, difficulty in accurately identifying business false positives and real attacks, lack of dynamic defense scene generation capability, fixed defense strategies, inability to quickly respond to new threats, high alarm disposal delay, and many false positives and false negatives due to reliance on manual analysis in the existing network security defense scene generation method and system based on an AI large model, which cannot meet the efficient and secure protection requirements in complex network environments.

[0005] The first aspect of the present application provides a network security defense scene generation method based on an AI large model, which comprises: S1. Obtain network security multi-source data, wherein the network security multi-source data comprises network device log data, security device operation data, Internet of Things device state data, network attack traffic data, external threat intelligence data, and historical security event disposal data; S2. Preprocess the network security multi-source data, train a basic AI large model based on the preprocessed data, and obtain a special AI large model adapted to the network security scene; S3. Construct a network security defense scenario generation model. The defense scenario generation model integrates attack threat qualitative rules and thought chain reasoning mechanism, and combines the semantic understanding and analysis capabilities of a dedicated AI big model to establish a defense scenario classification system. S4. Collect real-time network operation data, input the real-time network operation data into a dedicated AI big model and a defense scenario generation model, and generate corresponding network security defense scenarios and adapted defense strategies; S5. Based on the generated defense scenarios and defense strategies, execute network security defense operations, collect defense effect feedback data, and dynamically optimize the defense scenario generation model.

[0006] In one specific embodiment of the present invention, step S1 includes: S1.1. Obtain network device log data, security device operation data, and IoT device status data through network security device interfaces and log collection systems. The data includes device operation status, access behavior records, vulnerability information, and weak password detection results. S1.2. Collect network attack traffic data through network traffic monitoring nodes. The attack traffic data includes attack IP address, attack behavior characteristics, attack initiation time, and attack target port. S1.3. Obtain external threat intelligence data from legitimate third-party threat intelligence platforms, including new attack methods, vulnerability exploitation trends, and characteristics of black and gray market attacks; S1.4. Collect historical security incident handling data, which includes alarm type, handling process, blocking result and feedback information.

[0007] In one specific embodiment of the present invention, step S2 specifically includes: S2.1. Clean, deduplicate, standardize the format, and de-identify sensitive information from multi-source network security data to obtain an optimized training dataset; S2.2. Incremental pre-training of the basic AI model is performed based on the training dataset. The pre-training process of the basic AI model integrates cybersecurity industry knowledge and best practice procedures. S2.3. Fine-tune the pre-trained model using supervised learning, inputting network security-related question-and-answer samples, alarm interpretation samples, and event handling samples to optimize the model's scenario adaptability; S2.4. Employ the thinking chain adjustment technology to optimize the model's reasoning logic, enabling the model to possess an event analysis and thinking process similar to that of a security expert, resulting in a dedicated large-scale AI model adapted to cybersecurity scenarios.

[0008] In one specific embodiment of the present invention, step S3 specifically includes: S3.1. Establish an attack threat qualitative rule base, which includes judgment criteria for four types of alarms: false alarms, automated scanning, black and gray market virus attacks, and manual attacks. S3.2. Link the attack threat qualitative rule base with the dedicated AI big model to build a thinking chain reasoning mechanism, so that the model can automatically match the alarm type based on the input data and generate attack behavior analysis conclusions; S3.3. Establish a defense scenario classification system, wherein the defense scenarios include near-source attack defense scenarios, spoofing attack defense scenarios, unauthorized external connection defense scenarios, zero-day vulnerability attack defense scenarios, and Internet of Things device attack defense scenarios; S3.4. Configure a corresponding defense strategy template for each defense scenario. The template includes IP blocking rules, traffic blocking strategies, vulnerability remediation suggestions, and security baseline adjustment schemes to form a complete network security defense scenario generation model.

[0009] In one specific embodiment of the present invention, step S4 specifically includes: S4.1. Obtain real-time network operation data through real-time acquisition nodes, wherein the real-time operation data includes real-time log data, real-time attack traffic data, IoT device access status and network access behavior data; S4.2. Input real-time network operation data into a dedicated AI model to perform semantic analysis, attack behavior identification, and threat level assessment, and output preliminary judgment results; S4.3. Input the preliminary assessment results into the defense scenario generation model, match the alarm type through the attack threat qualitative rule base, and determine the corresponding defense scenario by combining the thinking chain reasoning mechanism; S4.4. Based on the determined defense scenario, the corresponding defense strategy template is invoked, and the defense strategy is dynamically adjusted in combination with the real-time network status to generate a targeted network security defense strategy. The defense strategy includes attack IP blocking instructions, abnormal traffic filtering rules, and device security configuration adjustment parameters.

[0010] In one specific embodiment of the present invention, step S5 specifically includes: S5.1. Execute the generated network security defense policy to block attack traffic, isolate unauthorized access devices, and issue early warnings for security vulnerabilities; S5.2. Collect defense effectiveness feedback data, including attack blocking success rate, alarm false alarm rate, defense strategy execution delay time and business impact assessment data; S5.3. When the defense effect feedback data meets the preset optimization conditions, the rule base and strategy template of the defense scenario generation model are updated based on the feedback data, and the feedback data is used as incremental training data to iteratively optimize the dedicated AI large model. S5.4. Generate network security alarm analysis reports in real time, which include details of attack events, implementation status of defense measures, and risk trend predictions.

[0011] A second aspect of the present invention provides a network security defense scenario generation system based on an AI large-scale model. This system is used to implement a network security defense scenario generation method based on an AI large-scale model as described in any of the preceding claims, comprising: The data acquisition module is used to acquire multi-source network security data and real-time network operation data. The multi-source network security data includes network device log data, security device operation data, IoT device status data, network attack traffic data, external threat intelligence data, and historical security incident handling data. The model training module is used to preprocess the data acquired by the acquisition module, and train the basic AI large model based on the preprocessed data to obtain a special AI large model adapted to network security scenarios. The scenario generation module is used to construct a network security defense scenario generation model. It inputs real-time network operation data into a dedicated AI big model and a defense scenario generation model to generate corresponding network security defense scenarios and adapted defense strategies. The defense and response module is used to perform network security defense operations based on the generated defense scenario and defense strategy, collect defense effect feedback data, and dynamically optimize the defense scenario generation model. The display module is used to display the acquisition process and results of the acquisition module, the training process and results of the model training module, the scene generation process and results of the scene generation module, and the defense execution process, feedback data and alarm analysis reports of the defense and handling module.

[0012] In one specific embodiment of the present invention, the acquisition module includes: A multi-source data acquisition unit is used to acquire network device log data, security device operation data, IoT device status data, network attack traffic data, external threat intelligence data, and historical security incident handling data. The real-time data acquisition unit is used to acquire real-time network operation data through real-time acquisition nodes. The real-time operation data includes real-time log data, real-time attack traffic data, IoT device access status, and network access behavior data.

[0013] In one specific embodiment of the present invention, the scene generation module includes: The rule base construction unit is used to establish a qualitative rule base for attack threats. The rule base includes judgment criteria for four types of alarms: false alarms, automated scanning, black and gray market virus attacks, and manual attacks. The scenario construction unit is used to establish a defense scenario classification system, configure a corresponding defense strategy template for each defense scenario, and construct a defense scenario generation model that integrates attack threat qualitative rules and thought chain reasoning mechanism. The strategy generation unit is used to input real-time network operation data into a dedicated AI big model and a defense scenario generation model to generate targeted network security defense strategies.

[0014] In one specific embodiment of the present invention, the defense handling module includes: A defense execution unit is used to execute the generated network security defense strategy, including attack traffic blocking, isolation of unauthorized devices, and vulnerability warning; A feedback optimization unit is used to collect defense effect feedback data and dynamically optimize the defense scenario generation model and the dedicated AI large model based on the feedback data. The report generation unit is used to generate network security alarm analysis reports in real time.

[0015] The beneficial effects of this invention's technical solution are as follows: It constructs a multi-source data collection system covering dimensions such as device logs, attack traffic, and threat intelligence. Combined with preprocessing techniques including cleaning, deduplication, standardization, and anonymization, it ensures data integrity to support model training while mitigating the risk of sensitive information leakage, laying a high-quality data foundation for subsequent defense processes. Through incremental pre-training integrating cybersecurity knowledge, fine-tuning instructions to optimize scenario adaptability, and adjusting the thought process chain to endow it with expert-like reasoning capabilities, it creates a dedicated large-scale AI model. Simultaneously, it links with an attack threat qualitative rule base, balancing model flexibility with rule certainty, solving the "black box reasoning" problem of traditional models, and improving the accuracy and interpretability of threat assessment. It establishes a defense scenario classification system covering new threats such as near-source attacks and IoT attacks, configuring strategy templates for each scenario and dynamically adjusting strategies based on real-time network conditions. This fills the gaps in traditional defense coverage of new threats while avoiding the problem of fixed strategies being out of touch with the actual environment, achieving precise scenario positioning and efficient strategy generation. A dynamic optimization closed loop of "strategy execution - effect feedback - model and strategy update" is formed. Based on feedback data such as attack blocking success rate and false alarm rate, the defense scenario generation model and dedicated AI big model are iteratively optimized to continuously improve the adaptability of the defense system to new threats, while reducing manual operation and maintenance costs and meeting the needs of efficient security protection 24 / 7 in complex network environments. Attached Figure Description

[0016] Figure 1 The diagram shown is a flowchart illustrating a method for generating network security defense scenarios based on a large AI model, according to an embodiment of the present invention.

[0017] Figure 2 The diagram shown is a flowchart of a dedicated AI large model acquisition method provided by an embodiment of the present invention.

[0018] Figure 3 The diagram shown is a flowchart of the construction process of a network security defense scenario generation model provided by an embodiment of the present invention.

[0019] Figure 4 The diagram shown is a framework diagram of a network security defense scenario generation system based on an AI large model provided by an embodiment of the present invention. Detailed Implementation

[0020] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0021] At least one embodiment of the present invention provides a method for generating network security defense scenarios based on AI large-scale models. The executing entity of this method can be a processor or a server, etc. (See reference...) Figure 1 A method for generating cybersecurity defense scenarios based on AI large models includes: S1. Obtain multi-source network security data, including network device log data, security device operation data, IoT device status data, network attack traffic data, external threat intelligence data, and historical security incident handling data; S2. Preprocess the multi-source data for network security, and train the basic AI model based on the preprocessed data to obtain a dedicated AI model adapted to network security scenarios; S3. Construct a network security defense scenario generation model. The defense scenario generation model integrates attack threat qualitative rules and thought chain reasoning mechanism, and combines the semantic understanding and analysis capabilities of a dedicated AI big model to establish a defense scenario classification system. S4. Collect real-time network operation data, input the real-time network operation data into a dedicated AI big model and defense scenario generation model, and generate corresponding network security defense scenarios and adapted defense strategies. S5. Based on the generated defense scenarios and defense strategies, execute network security defense operations, collect defense effect feedback data, and dynamically optimize the defense scenario generation model.

[0022] In at least one embodiment of the present invention, step S1 specifically includes: S1.1. Obtain network device log data, security device operation data, and IoT device status data through network security device interfaces and log collection systems. The data includes device operation status, access behavior records, vulnerability information, and weak password detection results. S1.2. Collect network attack traffic data through network traffic monitoring nodes. The attack traffic data includes attack IP address, attack behavior characteristics, attack initiation time, and attack target port. S1.3. Obtain external threat intelligence data from legitimate third-party threat intelligence platforms. Threat intelligence data includes new attack methods, vulnerability exploitation trends, and characteristics of black and gray market attacks. S1.4. Collect historical security incident handling data, including alarm types, handling procedures, blocking results, and feedback information.

[0023] Specifically, for step S1.1, a standardized API interface is used to connect to network security devices such as firewalls and intrusion detection systems. Simultaneously, a distributed log collection agent is deployed to build a log collection system, which captures network device operation logs, security device detection records, and the online status and configuration parameters of IoT devices (such as cameras and monitoring terminals) in real time. Device operating status and access behavior records are extracted from these data. Vulnerability information is obtained by periodically checking the results of vulnerability scanning tools. Weak password detection results are generated through weak password brute-force simulation and compliance checking tools. In step S1.2, traffic probes deployed at key nodes such as core switches and internet egress points serve as network traffic monitoring nodes. Based on deep packet inspection (DPI) technology, network data packets are parsed to extract attack IP addresses and attack behavior characteristics (such as port scanning and SQL injection commands). The attack initiation timestamp and target port number are recorded simultaneously to form a structured attack traffic dataset. S1.3 Establishes a data exchange channel with legitimate third-party threat intelligence platforms (such as Qi An Xin Threat Intelligence Center and Microstep Online Threat Intelligence Platform) via HTTPS protocol. This channel is used to periodically retrieve or receive push notifications of new attack methods (such as fileless attack techniques), vulnerability exploitation trends (such as the exploitation methods of recently prevalent vulnerabilities), and black market attack characteristics (such as commonly used IP ranges and attack tool fingerprints) through subscription services. S1.4 By connecting to the incident handling record system of the enterprise's Security Operations Center (SOC), it extracts alarm classification tags, manual or automated handling process documents, and attack blocking execution result logs from historical security incidents. Simultaneously, it collects feedback records from operations and maintenance personnel regarding the handling effectiveness, forming a structured historical security incident handling dataset.

[0024] In at least one embodiment of the present invention, reference is made to Figure 2 Step S2 specifically includes: S2.1. Clean, deduplicate, standardize the format, and de-identify sensitive information from multi-source network security data to obtain an optimized training dataset; S2.2. Incremental pre-training of the basic AI model is performed based on the training dataset. The pre-training process of the basic AI model integrates cybersecurity industry knowledge and best practice procedures. S2.3. Fine-tune the pre-trained model using supervised learning, inputting network security-related question-and-answer samples, alarm interpretation samples, and event handling samples to optimize the model's scenario adaptability; S2.4. Employ the thinking chain adjustment technology to optimize the model's reasoning logic, enabling the model to possess an event analysis and thinking process similar to that of a security expert, resulting in a dedicated large-scale AI model adapted to cybersecurity scenarios.

[0025] Specifically, S2.1 employs data processing tools such as Python Pandas and Spark to first clean the data through null value imputation and outlier removal (based on the 3σ principle or box plot method); then, it removes duplicate records based on unique data identifiers (such as log IDs and attack traffic hash values); subsequently, it standardizes field formats and data types by referring to network security data standards (such as MITREATT&CK format); finally, it processes sensitive information using methods such as data replacement (replacing sensitive IPs with masks) and field desensitization (encrypting device accounts) to generate a preferred training dataset. S2.2 selects a large-scale basic AI model (such as LLaMA or ChatGLM) with ≥10 billion parameters, and divides the preferred training dataset into training and validation sets in an 8:2 ratio. Incremental pre-training is performed using mini-batch gradient descent, incorporating network security industry knowledge (such as attack chain principles and vulnerability classification standards) and best practice procedures (such as security incident handling SOPs) during pre-training. Parameters such as the learning rate and number of iterations are adjusted through cross-validation to ensure model convergence. S2.3 Construct a supervised training set containing 5000+ cybersecurity Q&A samples (e.g., "How to identify SQL injection attacks"), 3000+ alarm interpretation samples (e.g., the criteria for judging different types of alarms), and 2000+ incident handling samples (e.g., ransomware handling steps). Label smoothing technology is used to optimize label distribution. The pre-trained model is fine-tuned using the Adam optimizer. After each round of fine-tuning, the model's accuracy on the validation set is calculated. Fine-tuning stops when the accuracy shows no improvement for three consecutive rounds. S2.4 Based on cybersecurity incident analysis logic (e.g., "alarm type identification → threat level assessment → handling plan matching"), a thought chain prompt template is designed. Complex analysis tasks are broken down into multi-step reasoning sub-tasks, which are input into the model for thought chain adjustment. The model's reasoning path is optimized using a small number of reasoning samples labeled by security experts. A reinforcement learning (RLHF) mechanism is used, with expert feedback as a reward signal, to iteratively optimize the model's reasoning logic, ultimately resulting in a dedicated large-scale AI model.

[0026] Understandably, the data preprocessing stage ensures the quality of training data. Cleaning and deduplication reduce noise interference, format standardization lowers the cost of model data adaptation, and sensitive information desensitization avoids the risk of data leakage, laying a high-quality data foundation for model training. Incremental pre-training, combined with industry knowledge, retains the general capabilities of the basic model while enabling the model to quickly master core knowledge in the cybersecurity field, avoiding the waste of resources and inefficiency caused by training from scratch. Supervised fine-tuning optimizes the model's ability to adapt to specific scenarios, allowing the model to accurately match actual business needs such as cybersecurity Q&A and alarm interpretation. The thinking chain adjustment technology endows the model with the reasoning ability of an expert, solving the "black box reasoning" problem of traditional models, improving the interpretability of the model's judgment process and the accuracy of the results, and meeting the needs of refined handling of cybersecurity incidents.

[0027] In at least one embodiment of the present invention, reference is made to Figure 3 Step S3 specifically includes: S3.1. Establish a rule base for qualitative analysis of attack threats. The rule base includes judgment criteria for four types of alarms: false alarms, automated scanning, black and gray market virus attacks, and manual attacks. S3.2. Link the attack threat qualitative rule base with the dedicated AI big model to build a thinking chain reasoning mechanism, so that the model can automatically match the alarm type based on the input data and generate attack behavior analysis conclusions; S3.3. Establish a defense scenario classification system, which includes near-source attack defense scenarios, spoofing attack defense scenarios, unauthorized external connection defense scenarios, zero-day vulnerability attack defense scenarios, and IoT device attack defense scenarios; S3.4. Configure a corresponding defense strategy template for each defense scenario. The template includes IP blocking rules, traffic blocking strategies, vulnerability remediation suggestions, and security baseline adjustment plans to form a complete network security defense scenario generation model.

[0028] Specifically, S3.1 extracts four judgment dimensions for alarm types by sorting out historical security incident data and industry attack and defense cases: business false alarms are based on the core criteria of "initiated by normal business IP, without attack characteristic commands, and consistent with business operation time periods"; automated scanning is based on "high frequency, fixed interval, and multi-target port detection"; black and gray market virus attacks are identified by "associated with black market IP database, containing malicious code characteristics, and exhibiting lateral spread behavior"; and manual attacks are distinguished by "low frequency, targeted targets, and custom attack commands". These criteria are transformed into structured rules and stored in the rule base, supporting dynamic addition, deletion, and parameter adjustment of rules. S3.2 embeds the rule base call interface into the dedicated AI large model inference process, constructing a thinking chain inference mechanism of "data input → rule initial judgment → model deep verification → conclusion output": first, real-time data is matched with the rule base for preliminary alarm characterization, then the preliminary judgment result and data characteristics are input into the model, and the model combines semantic understanding and attack behavior correlation analysis to verify the accuracy of the preliminary judgment, and finally generates an attack behavior analysis conclusion that includes alarm type, confidence level, and key features. S3.3 Based on the network security risk scenario classification framework, and combined with the characteristics of emerging threats such as IoT device attacks and zero-day vulnerabilities, S3.3 clarifies the boundaries and core features of five types of defense scenarios: near-source attacks focus on physical contact or short-distance access scenarios; spoofing attacks are centered on "forging identity authentication information"; unauthorized external connections target unauthorized network access; zero-day vulnerability attacks highlight the characteristics of "no known patches and new exploitation methods"; and IoT device attacks revolve around risks such as weak device passwords and firmware vulnerabilities, forming a clearly hierarchical defense scenario classification system. S3.4 For each type of defense scenario, defense strategy templates are designed based on best practices for attack and defense: IP blocking rules clearly define the execution logic of "real-time blacklisting of attacking IPs and restriction of access to associated IP ranges"; traffic blocking policies include parameters such as "data packet filtering based on attack characteristics and bandwidth restriction for abnormal traffic"; vulnerability remediation suggestions provide "patch installation steps and temporary protection solutions"; and security baseline adjustment schemes cover key points such as "device configuration optimization and upgraded access control." These templates are bound to the scenario classification system to form a directly callable defense scenario generation model.

[0029] Understandably, the attack threat qualitative rule base enables precise alarm filtering. By clearly defining four alarm judgment criteria, it effectively distinguishes between low-value false alarms and high-risk attacks, reduces invalid model calculations, and improves alarm analysis efficiency. Secondly, the thought chain reasoning mechanism integrates the determinism of the rule base with the flexibility of the AI ​​model, avoiding the limitations of pure rules in dealing with new threats and solving the risk of misjudgment by pure models, thus improving the accuracy and credibility of attack behavior analysis conclusions. Thirdly, the defense scenario classification system covers new threat scenarios, filling the gaps in the traditional classification for IoT and zero-day vulnerability attacks, and meeting the scenario identification needs in complex network environments. Fourthly, the design of binding scenario and policy templates enables rapid matching and generation of defense policies, avoiding the problem of "scenario and policy disconnect and repeated manual adaptation" in traditional defense, and improving the response speed of network security incidents.

[0030] In at least one embodiment of the present invention, step S4 specifically includes: S4.1. Obtain real-time network operation data through real-time acquisition nodes. The real-time operation data includes real-time log data, real-time attack traffic data, IoT device access status and network access behavior data. S4.2. Input real-time network operation data into a dedicated AI model to perform semantic analysis, attack behavior identification, and threat level assessment, and output preliminary judgment results; S4.3. Input the preliminary assessment results into the defense scenario generation model, match the alarm type through the attack threat qualitative rule base, and determine the corresponding defense scenario by combining the thinking chain reasoning mechanism; S4.4. Based on the determined defense scenario, the corresponding defense strategy template is invoked, and the defense strategy is dynamically adjusted in combination with the real-time network status to generate a targeted network security defense strategy. The defense strategy includes attack IP blocking instructions, abnormal traffic filtering rules, and device security configuration adjustment parameters.

[0031] Specifically, for S4.1, lightweight real-time acquisition nodes are deployed at key locations such as core network switching nodes, IoT device aggregation gateways, and internet egress points, employing edge computing technology to reduce data transmission latency. Real-time log data from network and security devices is captured via the Syslog protocol, real-time attack traffic data is collected based on NetFlow technology, and access information such as IoT device online status and access duration is obtained using the MQTT protocol. Behavioral auditing tools record network access behavior data such as user logins and resource access. All data is transmitted to the data processing center in a unified format in real time. S4.2 inputs the real-time operational data into a dedicated AI model categorized by "log text, traffic characteristics, and device status." The model uses natural language processing technology to semantically analyze the log text, extracting key operation commands and anomaly markers; it identifies attack patterns in the traffic (such as port scanning and injection attacks) based on an attack behavior feature library; and it combines device vulnerability scores and the scope of attack impact with a weighted scoring method to assess the threat level (high, medium, and low), ultimately outputting preliminary judgment results including threat type, level, and related data. S4.3 The preliminary assessment results are imported into the defense scenario generation model. The model first calls the attack threat qualitative rule base, compares the alarm features in the results with the rule base standards, and initially matches possible alarm types. Then, the thought chain reasoning mechanism is activated, combining information such as the attack IP attribution and behavior continuity in real-time data to verify the accuracy of alarm type matching. At the same time, it associates the scenario features of the defense scenario classification system to determine the defense scenario corresponding to the current threat (such as the IoT device attack defense scenario) and outputs the scenario matching confidence. S4.4 Based on the determined defense scenario, the corresponding policy template is automatically called. At the same time, data such as real-time bandwidth utilization, device load, and business operation status are obtained through network status monitoring tools. If it is found that the IP blocking rules in the template may affect normal business IPs, the blocking scope is dynamically adjusted. If the abnormal traffic filtering rules conflict with the current bandwidth load, the filtering priority and bandwidth allocation ratio are optimized. Finally, a targeted defense strategy is generated, which includes attack IP blocking instructions (such as blacklisting IPs), abnormal traffic filtering rules (such as signature matching conditions), and device security configuration adjustment parameters (such as firewall policy update values).

[0032] In at least one embodiment of the present invention, step S5 specifically includes: S5.1. Execute the generated network security defense policy to block attack traffic, isolate unauthorized access devices, and issue early warnings for security vulnerabilities; S5.2. Collect defense effectiveness feedback data, including attack blocking success rate, false alarm rate, defense strategy execution delay time and business impact assessment data; S5.3. When the defense effect feedback data meets the preset optimization conditions, the rule base and strategy template of the defense scenario generation model are updated based on the feedback data, and the feedback data is used as incremental training data to iteratively optimize the dedicated AI large model. S5.4. Generates network security alert analysis reports in real time, including details of attack events, implementation status of defense measures, and risk trend predictions.

[0033] Specifically, S5.1 establishes a command interaction channel with network security devices (firewalls, intrusion prevention systems, and IoT access controllers) through the defense and handling module, automatically issuing defense policies: For attack traffic, it sends attack signature codes and IP blacklists to the firewall, triggering packet filtering and traffic blocking; for devices that access the network without authorization, it issues port disabling or network isolation commands through the IoT access controller, cutting off their connection to the core network; for security vulnerabilities, it pushes early warning information to the vulnerability management platform and simultaneously sends alarm notifications containing vulnerability location and risk level to operations and maintenance personnel. S5.2 builds a defense effectiveness monitoring system, using traffic analysis tools to statistically analyze the change ratio of attack traffic before and after blocking, and calculate the attack blocking success rate; it compares the AI ​​model's judgment results with the conclusions of manual review to statistically analyze the false alarm rate; it records the time difference from policy generation to device execution to obtain the defense policy execution delay time; and it evaluates the impact of defense operations on business through business system performance monitoring tools (such as CPU utilization and response latency) and user feedback collection, forming a structured feedback dataset. S5.3 Presets optimization conditions (such as attack blocking success rate below 80%, false alarm rate above 15%, execution delay exceeding 3 minutes), and determines whether the feedback data triggers the conditions through data comparison. If triggered, it supplements the rule base of the defense scenario generation model with judgment rules corresponding to new attack features, and updates parameters in the strategy template that conflict with actual business. At the same time, it marks the feedback data as incremental training samples and inputs them into a dedicated AI large model for a new round of fine-tuning, optimizing the model's judgment logic and scenario adaptability. S5.4 Based on the report generation template, it automatically extracts details such as the time, IP, and behavioral characteristics of attack events from event logs, summarizes the execution status and results of measures from defense execution records, and performs trend analysis on historical attack data and real-time threat intelligence through a dedicated AI large model to predict high-risk attack types and potentially affected business nodes in the next 72 hours. Finally, it generates a network security alarm analysis report containing text descriptions and data charts, which can be automatically pushed to the operation and maintenance personnel's terminals or security operation platform.

[0034] This solution proposes a method for generating cybersecurity defense scenarios based on AI large models. By constructing a multi-source data collection system for cybersecurity covering multiple dimensions such as device logs, attack traffic, and threat intelligence, and combining data preprocessing processes such as cleaning, deduplication, standardization, and desensitization, it achieves the systematic aggregation of high-quality training data, providing comprehensive, compliant, and accurate data support for training dedicated AI large models, and ensuring the model's adaptability and accuracy in judging cybersecurity scenarios. This solution proposes a method for generating network security defense scenarios based on an AI big model. By linking an attack threat qualitative rule base with a dedicated AI big model, a thought chain reasoning mechanism is constructed, and a multi-type defense scenario classification system and corresponding strategy templates are established. This achieves full-process automation from accurate alarm qualitative analysis to rapid matching of defense scenarios and dynamic generation of strategies, which greatly improves the efficiency of network security threat assessment and defense response speed, and effectively distinguishes between low-value false alarms and high-risk attacks. This solution proposes a network security defense scenario generation method based on an AI large model. By collecting multi-dimensional feedback data such as attack blocking success rate and false alarm rate after executing the defense strategy, the rule base, policy template and dedicated AI large model of the defense scenario generation model are dynamically iteratively optimized. This enables the defense system to adaptively adjust to new attack methods and changes in the network environment, continuously reduce false alarm and missed alarm rates and manual operation and maintenance costs, and meet the long-term and efficient security protection needs in complex network environments.

[0035] At least one embodiment of the present invention also provides a network security defense scenario generation system based on an AI large-scale model, used to implement the network security defense scenario generation method based on an AI large-scale model as described in any of the above embodiments. (Reference) Figure 4 The AI-based large-scale network security defense scenario generation system includes a data acquisition module, a model training module, a scenario generation module, a defense and response module, and a display module.

[0036] The data acquisition module is used to acquire multi-source network security data and real-time network operation data. The multi-source network security data includes network device log data, security device operation data, IoT device status data, network attack traffic data, external threat intelligence data, and historical security incident handling data.

[0037] The model training module is used to preprocess the data acquired by the acquisition module, and train the basic AI large model based on the preprocessed data to obtain a special AI large model adapted to network security scenarios.

[0038] The scenario generation module is used to construct a network security defense scenario generation model. It inputs real-time network operation data into a dedicated AI big model and a defense scenario generation model to generate corresponding network security defense scenarios and adapted defense strategies.

[0039] The defense and response module is used to perform network security defense operations based on the generated defense scenario and defense strategy, collect defense effect feedback data, and dynamically optimize the defense scenario generation model.

[0040] The display module is used to display the acquisition process and results of the acquisition module, the training process and results of the model training module, the scene generation process and results of the scene generation module, and the defense execution process, feedback data and alarm analysis reports of the defense and handling module.

[0041] In an optional embodiment, the acquisition module includes: A multi-source data acquisition unit is used to acquire network device log data, security device operation data, IoT device status data, network attack traffic data, external threat intelligence data, and historical security incident handling data. The real-time data acquisition unit is used to acquire real-time network operation data through real-time acquisition nodes. The real-time operation data includes real-time log data, real-time attack traffic data, IoT device access status, and network access behavior data.

[0042] In an optional embodiment, the scene generation module includes: The rule base construction unit is used to establish a qualitative rule base for attack threats. The rule base includes judgment criteria for four types of alarms: false alarms, automated scanning, black and gray market virus attacks, and manual attacks. The scenario construction unit is used to establish a defense scenario classification system, configure a corresponding defense strategy template for each defense scenario, and construct a defense scenario generation model that integrates attack threat qualitative rules and thought chain reasoning mechanism. The strategy generation unit is used to input real-time network operation data into a dedicated AI big model and a defense scenario generation model to generate targeted network security defense strategies.

[0043] In an optional embodiment, the defense handling module includes: A defense execution unit is used to execute the generated network security defense strategy, including attack traffic blocking, isolation of unauthorized devices, and vulnerability warning; A feedback optimization unit is used to collect defense effect feedback data and dynamically optimize the defense scenario generation model and the dedicated AI large model based on the feedback data. The report generation unit is used to generate network security alarm analysis reports in real time.

[0044] The AI-based large-scale network security defense scenario generation system is a system embodiment of the above-described method embodiment, which includes all the technical features of the above-described method embodiment and can achieve the corresponding technical effects, which will not be elaborated here.

[0045] It should be noted that the combination of the technical features in the embodiments of the present invention is not limited to the combination methods described in the embodiments of the present invention or the combination methods described in the specific embodiments. All technical features described in the present invention can be freely combined or combined in any way, unless there is a contradiction between them.

[0046] As indicated in this invention and the claims, unless the context clearly indicates otherwise, the words "a," "an," and / or "the" do not specifically refer to the singular and may also include the plural. Generally speaking, the term "comprising" only indicates that it includes the explicitly identified steps and elements, which do not constitute an exclusive list, and the method or apparatus may also include other steps or elements.

[0047] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A method for generating network security defense scenarios based on AI large-scale models, characterized in that, include: S1. Obtain multi-source network security data, including network device log data, security device operation data, IoT device status data, network attack traffic data, external threat intelligence data, and historical security incident handling data; S2. Preprocess the multi-source data of network security, and train the basic AI model based on the preprocessed data to obtain a special AI model adapted to network security scenarios; S3. Construct a network security defense scenario generation model. The defense scenario generation model integrates attack threat qualitative rules and thought chain reasoning mechanism, and combines the semantic understanding and analysis capabilities of a dedicated AI big model to establish a defense scenario classification system. S4. Collect real-time network operation data, input the real-time network operation data into a dedicated AI big model and a defense scenario generation model, and generate corresponding network security defense scenarios and adapted defense strategies; S5. Based on the generated defense scenarios and defense strategies, execute network security defense operations, collect defense effect feedback data, and dynamically optimize the defense scenario generation model.

2. The method for generating network security defense scenarios based on AI large models according to claim 1, characterized in that, Step S1 includes: S1.

1. Obtain network device log data, security device operation data, and IoT device status data through network security device interfaces and log collection systems. The data includes device operation status, access behavior records, vulnerability information, and weak password detection results. S1.

2. Collect network attack traffic data through network traffic monitoring nodes. The attack traffic data includes attack IP address, attack behavior characteristics, attack initiation time, and attack target port. S1.

3. Obtain external threat intelligence data from legitimate third-party threat intelligence platforms, including new attack methods, vulnerability exploitation trends, and characteristics of black and gray market attacks; S1.

4. Collect historical security incident handling data, which includes alarm type, handling process, blocking result and feedback information.

3. The method for generating network security defense scenarios based on AI large models according to claim 1, characterized in that, Step S2 includes: S2.

1. Clean, deduplicate, standardize the format, and de-identify sensitive information from multi-source network security data to obtain an optimized training dataset; S2.

2. Incremental pre-training of the basic AI model is performed based on the training dataset. The pre-training process of the basic AI model integrates cybersecurity industry knowledge and best practice procedures. S2.

3. Fine-tune the pre-trained model using supervised learning, inputting network security-related question-and-answer samples, alarm interpretation samples, and event handling samples to optimize the model's scenario adaptability; S2.

4. Employ the thinking chain adjustment technology to optimize the model's reasoning logic, enabling the model to possess an event analysis and thinking process similar to that of a security expert, resulting in a dedicated large-scale AI model adapted to cybersecurity scenarios.

4. The method for generating network security defense scenarios based on AI large models according to claim 1, characterized in that, Step S3 includes: S3.

1. Establish an attack threat qualitative rule base, which includes judgment criteria for four types of alarms: false alarms, automated scanning, black and gray market virus attacks, and manual attacks. S3.

2. Link the attack threat qualitative rule base with the dedicated AI big model to build a thinking chain reasoning mechanism, so that the model can automatically match the alarm type based on the input data and generate attack behavior analysis conclusions; S3.

3. Establish a defense scenario classification system, wherein the defense scenarios include near-source attack defense scenarios, spoofing attack defense scenarios, unauthorized external connection defense scenarios, zero-day vulnerability attack defense scenarios, and Internet of Things device attack defense scenarios; S3.

4. Configure a corresponding defense strategy template for each defense scenario. The template includes IP blocking rules, traffic blocking strategies, vulnerability remediation suggestions, and security baseline adjustment schemes to form a complete network security defense scenario generation model.

5. The method for generating network security defense scenarios based on AI large models according to claim 1, characterized in that, Step S4 includes: S4.

1. Obtain real-time network operation data through real-time acquisition nodes, wherein the real-time operation data includes real-time log data, real-time attack traffic data, IoT device access status and network access behavior data; S4.

2. Input real-time network operation data into a dedicated AI model to perform semantic analysis, attack behavior identification, and threat level assessment, and output preliminary judgment results; S4.

3. Input the preliminary assessment results into the defense scenario generation model, match the alarm type through the attack threat qualitative rule base, and determine the corresponding defense scenario by combining the thinking chain reasoning mechanism; S4.

4. Based on the determined defense scenario, the corresponding defense strategy template is invoked, and the defense strategy is dynamically adjusted in combination with the real-time network status to generate a targeted network security defense strategy. The defense strategy includes attack IP blocking instructions, abnormal traffic filtering rules, and device security configuration adjustment parameters.

6. A method for generating network security defense scenarios based on AI large models according to any one of claims 1 to 5, characterized in that, Step S5 includes: S5.

1. Execute the generated network security defense policy to block attack traffic, isolate unauthorized access devices, and issue early warnings for security vulnerabilities; S5.

2. Collect defense effectiveness feedback data, including attack blocking success rate, alarm false alarm rate, defense strategy execution delay time and business impact assessment data; S5.

3. When the defense effect feedback data meets the preset optimization conditions, the rule base and strategy template of the defense scenario generation model are updated based on the feedback data, and the feedback data is used as incremental training data to iteratively optimize the dedicated AI large model. S5.

4. Generate network security alarm analysis reports in real time, which include details of attack events, implementation status of defense measures, and risk trend predictions.

7. A network security defense scenario generation system based on AI large-scale models, characterized in that, A method for generating network security defense scenarios based on an AI large model as described in any one of claims 1-6, wherein the network security defense scenario generation system based on an AI large model comprises: The data acquisition module is used to acquire multi-source network security data and real-time network operation data. The multi-source network security data includes network device log data, security device operation data, IoT device status data, network attack traffic data, external threat intelligence data, and historical security incident handling data. The model training module is used to preprocess the data acquired by the acquisition module, and train the basic AI large model based on the preprocessed data to obtain a special AI large model adapted to network security scenarios. The scenario generation module is used to construct a network security defense scenario generation model. It inputs real-time network operation data into a dedicated AI big model and a defense scenario generation model to generate corresponding network security defense scenarios and adapted defense strategies. The defense and response module is used to perform network security defense operations based on the generated defense scenario and defense strategy, collect defense effect feedback data, and dynamically optimize the defense scenario generation model. The display module is used to display the acquisition process and results of the acquisition module, the training process and results of the model training module, the scene generation process and results of the scene generation module, and the defense execution process, feedback data and alarm analysis reports of the defense and handling module.

8. The network security defense scenario generation system based on an AI large model according to claim 7, characterized in that, The acquisition module includes: A multi-source data acquisition unit is used to acquire network device log data, security device operation data, IoT device status data, network attack traffic data, external threat intelligence data, and historical security incident handling data. The real-time data acquisition unit is used to acquire real-time network operation data through real-time acquisition nodes. The real-time operation data includes real-time log data, real-time attack traffic data, IoT device access status, and network access behavior data.

9. A network security defense scenario generation system based on an AI large model according to claim 7, characterized in that, The scene generation module includes: The rule base construction unit is used to establish a qualitative rule base for attack threats. The rule base includes judgment criteria for four types of alarms: false alarms, automated scanning, black and gray market virus attacks, and manual attacks. The scenario construction unit is used to establish a defense scenario classification system, configure a corresponding defense strategy template for each defense scenario, and construct a defense scenario generation model that integrates attack threat qualitative rules and thought chain reasoning mechanism. The strategy generation unit is used to input real-time network operation data into a dedicated AI big model and a defense scenario generation model to generate targeted network security defense strategies.

10. A network security defense scenario generation system based on an AI large model according to claim 7, characterized in that, The defense response module includes: A defense execution unit is used to execute the generated network security defense strategy, including attack traffic blocking, isolation of unauthorized devices, and vulnerability warning; A feedback optimization unit is used to collect defense effect feedback data and dynamically optimize the defense scenario generation model and the dedicated AI large model based on the feedback data. The report generation unit is used to generate network security alarm analysis reports in real time.