Defense verification method and device, equipment, medium and program product

By retrieving security data from multiple data sources and combining it with large language models and response analysis models, attack verification requests are generated, solving the problems of lagging and incompleteness in traditional defense verification methods, and enabling timely and accurate assessment of the defense performance of the target object.

CN121887448APending Publication Date: 2026-04-17CHINA UNIONPAY
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINA UNIONPAY
Filing Date
2025-12-15
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

In existing technologies, traditional defense verification methods rely on manual attack request databases that are outdated and incomplete, making it impossible to respond promptly to new vulnerabilities or attack patterns. A single attack verification cannot cover network connectivity and the effectiveness of basic defense rules, resulting in biased verification results.

Method used

Security data is retrieved from multiple data sources based on the target vulnerability identifier, an attack verification request is generated, and the target description text is combined with a large language model and response analysis model to evaluate the defense performance of the target object, ensuring the timeliness and comprehensiveness of the verification.

Benefits of technology

It enables timely and comprehensive risk verification, accurately assesses the defense performance of the target, avoids assessment bias caused by data lag and incomplete verification, and improves the accuracy of attack verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121887448A_ABST
    Figure CN121887448A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a defense verification method and device, equipment, a medium and a program product. The method is applied to a defense verification device, and comprises the following steps: based on an identifier of a target vulnerability, performing retrieval from a plurality of data sources to obtain security data corresponding to the target vulnerability; based on the security data and a verification target description text, generating an attack verification request; sending the attack verification request to a target object; receiving a first defense response from the target object; and determining defensive performance of the target object based on the first defensive response. The method is used for improving the accuracy of attack verification.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cybersecurity, and in particular to a defense verification method, apparatus, device, medium, and program product. Background Technology

[0002] As internet attack methods become more complex and the frequency of attacks continues to rise, the real-time performance, accuracy, and comprehensiveness of enterprise network security defense systems have become core requirements for ensuring business continuity.

[0003] Currently, traditional defense effectiveness verification methods have significant limitations: on the one hand, attack verification relies on manually pre-set attack databases and cannot respond in a timely manner to publicly available intelligence on new vulnerabilities or attack patterns; on the other hand, a single attack verification cannot cover prerequisites such as network connectivity and the effectiveness of basic defense rules, leading to deviations in verification results.

[0004] Therefore, improving the accuracy of attack verification is an urgent problem to be solved. Summary of the Invention

[0005] This application provides a defense verification method, apparatus, device, medium, and program product to improve the accuracy of attack verification.

[0006] In a first aspect, embodiments of this application provide a defense verification method, the method being applied to a defense verification device, the method comprising:

[0007] Based on the identifier of the target vulnerability, security data corresponding to the target vulnerability is obtained by retrieving from multiple data sources;

[0008] Based on the security data and the target description text, an attack verification request is generated;

[0009] Send the attack verification request to the target object;

[0010] Receive a first defense response from the target object;

[0011] Based on the first defense response, the defense performance of the target object is determined.

[0012] In one possible implementation, generating an attack verification request based on the security data and the verified target description text includes:

[0013] Based on the security data and the verification target description text, a first prompt word is constructed; the first prompt word is used to indicate, with reference to the security data, the generation of an attack verification request that satisfies the verification target;

[0014] The first prompt word is input into the request generation model to obtain the attack verification request.

[0015] In one possible implementation, the request generation model is a trained large language model, and the large language model is trained using a low-rank adaptation fine-tuning QLoRA training method.

[0016] In one possible implementation, before sending the attack verification request to the target object, the method further includes:

[0017] The network connectivity verification between the defense verification device and the target object is performed to obtain the network connectivity verification result;

[0018] If the network connectivity verification result indicates that there is no anomaly between the defense verification device and the target object, the attack verification request is sent to the target object.

[0019] In one possible implementation, sending the attack verification request to the target object when the network connectivity verification result indicates that there is no anomaly between the defense verification device and the target object includes:

[0020] If the network connectivity verification result indicates that there is no anomaly between the defense verification device and the target object, a preset attack request is sent to the target object;

[0021] Receive a second defense response from the target object;

[0022] Based on the second defense response, it is determined whether the target object has a defense anomaly;

[0023] If the target object does not have any defense anomalies, the attack verification request is sent to the target object.

[0024] In one possible implementation, determining the defense performance of the target object based on the first defense response includes:

[0025] Based on the first defense response, a second prompt word is constructed, which is used to indicate the analysis of the defense performance of the target object based on the first defense response;

[0026] Input the second prompt word into the response analysis model to obtain the first analysis result of the defense performance of the target object;

[0027] Based on the first analysis result, the target analysis result is obtained; the target analysis result is used to characterize the defensive performance of the target object.

[0028] In one possible implementation, the response analysis model is a large language model based on the Hierarchical Classification Reasoning Framework (RHC).

[0029] In one possible implementation, constructing the second prompt word based on the first defense response includes:

[0030] Based on the first defense response and other defense responses, a second prompt word is constructed; the second prompt word is specifically used to indicate: to analyze the defense performance of the target object in combination with the first defense response and the other defense responses; the other defense responses are: the defense responses made by the target object to verification requests other than the attack verification request.

[0031] In one possible implementation, constructing the second prompt word based on the first defense response and other defense responses includes:

[0032] Based on the first defense response, the other defense responses, and the historical defense performance verification results of the target object, a second prompt word is constructed; the second prompt word is specifically used to indicate that the defense performance of the target object is analyzed in combination with the first defense response, the other defense responses, and the historical defense performance verification results.

[0033] In one possible implementation, the first defense response includes: dynamic content and non-dynamic content; the dynamic content includes: a timestamp of the first defense response and at least one of a unique identifier; the non-dynamic content includes: a Hypertext Transfer Protocol (HTTP) response header feature, a status code, and at least one of the response content; before obtaining the target analysis result based on the first analysis result, the method further includes:

[0034] Delete the dynamic content of the first defense response;

[0035] The non-dynamic content is matched with the interception response features of various defense devices in the defense device feature library using regular expressions to determine the second analysis result; the second analysis result is used to characterize whether the defense performance of the target object is within the protection range of the various defense devices.

[0036] The step of obtaining the target analysis result based on the first analysis result includes:

[0037] Based on the first analysis result and the second analysis result, the target analysis result is obtained.

[0038] In one possible implementation, the target object is a webpage to be defended and verified, and the first defense response is a defense response page.

[0039] In one possible implementation, the target object is deployed with multiple defense systems, and the first defense response includes: sub-defense responses from the multiple defense systems to the attack verification request; determining the defense performance of the target object based on the first defense response includes:

[0040] In response to a plurality of sub-defense responses, if the number of sub-defense responses of the target type is greater than or equal to a preset number, a new attack verification request is generated based on the sub-defense responses of the target type, the security data, and the verification target description text; the sub-defense responses of the target type are used to indicate that the attack verification request has been successfully defended.

[0041] Send the new attack verification request to the target object;

[0042] Receive a third defense response from the target object;

[0043] Based on the third defense response, the defense performance of the target object is determined.

[0044] In one possible implementation, before retrieving security data corresponding to the target vulnerability from multiple data sources based on the target vulnerability's identifier, the method further includes:

[0045] Periodically send defense performance update confirmation requests to the target object;

[0046] Receive feedback information from the target object;

[0047] When the feedback information indicates that the defense performance of the target object has been updated, security data corresponding to the target vulnerability is obtained by retrieving from multiple data sources based on the identifier of the target vulnerability.

[0048] Secondly, embodiments of this application provide a defense verification device, the device comprising:

[0049] The processing module is used to retrieve security data corresponding to the target vulnerability from multiple data sources based on the identifier of the target vulnerability;

[0050] The generation module is used to generate an attack verification request based on the security data and the target description text.

[0051] The sending module is used to send the attack verification request to the target object;

[0052] A receiving module is used to receive a first defense response from the target object;

[0053] The determination module is used to determine the defense performance of the target object based on the first defense response.

[0054] Thirdly, embodiments of this application provide an electronic device, including: a memory and a processor;

[0055] The memory stores computer-executed instructions;

[0056] The processor executes computer execution instructions stored in the memory, causing the processor to perform the method described in any of the first aspects above.

[0057] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the method described in any of the first aspects above.

[0058] Fifthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the method described in any of the first aspects above.

[0059] This application provides a defense verification method, apparatus, device, medium, and program product. Based on a target vulnerability identifier, it retrieves corresponding security data from multiple data sources, then combines this data with a verification target description text to generate an attack verification request and sends it to the target object. After receiving a first defense response, it determines the target's defense performance. Compared to existing technologies that rely on manual attack request databases, which are slow and incomplete, this method can automatically acquire multi-source security data to generate requests. It can conduct timely and comprehensive risk verification, accurately assess the target object's defense performance, and avoid evaluation biases caused by data lag and incomplete verification in traditional methods, thus improving the accuracy of attack verification. Attached Figure Description

[0060] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0061] Figure 1 This application provides a schematic diagram of a defense verification process.

[0062] Figure 2 A flowchart illustrating the process of determining the defensive capabilities of a target object, provided as an embodiment of this application;

[0063] Figure 3 A schematic diagram of an automatic verification device for security equipment provided in an embodiment of this application;

[0064] Figure 4 A flowchart illustrating a specific defense verification method provided in this application embodiment;

[0065] Figure 5A schematic diagram of a defense verification device provided in this application;

[0066] Figure 6 This is a schematic diagram of the structure of an electronic device provided in this application.

[0067] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0068] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application.

[0069] In this application, the term "comprising" and its variations can refer to non-limiting inclusion; the term "or" and its variations can refer to "and / or". The terms "first", "second", etc., in this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. In this application, "multiple" refers to two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. The character " / " generally indicates that the preceding and following related objects have an "or" relationship.

[0070] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of the relevant data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation entry points are provided for users to choose to authorize or refuse.

[0071] With the increasing sophistication of internet attack methods and the continuous rise in attack frequency, the real-time performance, accuracy, and comprehensiveness of enterprise network security defense systems have become core requirements for ensuring business continuity. Breach and Attack Simulation (BAS) is an emerging security defense effectiveness verification and evaluation technology that tests an organization's defense capabilities by simulating real-world attack scenarios.

[0072] Current mainstream defense verification schemes typically employ a method of sending a single, specific attack based on an existing publicly available proof-of-concept (POC) attack library on the Internet, and verifying the attack by accessing security device logs or Hypertext Transfer Protocol (HTTP) response codes.

[0073] However, existing defense effectiveness verification schemes have significant limitations. First, attack verification relies on manually prepared attack request databases, which results in a significant lag compared to publicly available intelligence on the internet, making it impossible to respond promptly to publicly available intelligence on new vulnerabilities or attack patterns.

[0074] Secondly, because a single attack verification cannot cover prerequisites such as network connectivity and the effectiveness of basic defense rules, the verification results may be biased. Thirdly, traditional attack result judgment relies on simple checks of defense device alarm logs or HTTP response codes. If alarm logs are used, there is a security risk of log leakage. If alarm logs are not used and simple judgment is made based on HTTP response codes, there is a high probability of false positives, especially when the boundary between blocked pages and normal error pages is blurred, such as custom 404 pages and blocked pages, business logic errors and security blocks.

[0075] Furthermore, the current mainstream approach in the industry is to adopt defense in depth, where network boundaries are typically reinforced with two or more different security devices using heterogeneous methods. In this case, the traditional approach can only identify one security device and cannot accurately assess the overall defense situation.

[0076] Therefore, this application embodiment retrieves corresponding security data from multiple data sources based on the target vulnerability identifier, then combines this with the target description text to generate an attack verification request and sends it to the target object. After receiving the first defense response, its defense performance is determined. Compared to the prior art that relies on a manual attack request database, which is lagging and incomplete, this method can automatically obtain multi-source security data to generate requests, enabling timely and comprehensive risk verification, accurately assessing the target object's defense performance, avoiding the assessment bias caused by data lag and incomplete verification in traditional methods, and improving the accuracy of attack verification.

[0077] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will be described below with reference to the accompanying drawings.

[0078] It should be noted that the method of this application can be applied to a defense verification device, which can be a physical device or a software device. The executing entity of this application can be any electronic device with processing capabilities, such as a user terminal or server, which deploys the defense verification device, for example, a computer.

[0079] Figure 1 This is a schematic diagram of a defense verification process provided in an embodiment of this application. Figure 1 As shown, the method includes:

[0080] S101. Based on the identifier of the target vulnerability, retrieve the security data corresponding to the target vulnerability from multiple data sources.

[0081] Optionally, the identifier of the target vulnerability can be any one or more of the following information: a unique symbol, code, name, etc., which clearly indicates the specific content of the vulnerability that needs attention and handling. The data source can be any one or more publicly available intelligence from the internet, such as security bulletins, technical blogs, code repositories, and threat platforms. The security data corresponding to the target vulnerability can be data information related to the target vulnerability that reflects its characteristics, scope of impact, exploitation methods, and remediation recommendations.

[0082] Alternatively, electronic devices can use the Retrieval-Augmented Generation (RAG) method to search and filter security data that matches the target vulnerability identifier from multiple data sources, with the aim of obtaining detailed information about the target vulnerability.

[0083] S102. Based on security data and the target description text, generate an attack verification request.

[0084] Optionally, the verification target description text can be text content that describes in detail the verification purpose to be achieved. It can specify the direction of verification, such as verifying the target object's ability to resist a certain type of vulnerability attack, or verifying whether the target object's security protection mechanism is effective in a specific network environment, or any one or more of these.

[0085] An attack verification request can be used to launch a simulated attack on a target object to verify the target object's defense capabilities against a specific vulnerability. It can include one or more key elements such as the attack method and parameters.

[0086] Optionally, the electronic device can create an attack verification request based on security data and verification target description text, using certain rules, algorithms, or logic, and transform the security data and verification target into specific attack verification instructions.

[0087] In one implementation, the electronic device may first construct a first prompt word based on security data and a verification target description text. This first prompt word can be used to instruct reference security data to generate an attack verification request that satisfies the verification target. Optionally, the electronic device may integrate key information from the security data and the requirements of the verification target to construct the first prompt word.

[0088] Secondly, the electronic device can input the first prompt word into the request generation model to obtain an attack verification request. Optionally, the request generation model can be an artificial intelligence model, capable of generating corresponding requests based on the input first prompt word. By learning from a large amount of data and patterns, it can understand the intent in the prompt word and combine its learned knowledge to generate a qualified attack verification request; for example, it could be a text generation model based on natural language processing technology.

[0089] Optionally, the electronic device can input the first prompt word into the request generation model through a call interface. The request generation model then processes and calculates the request internally to obtain the attack verification request and output it.

[0090] This application embodiment constructs a request generation model guided by a first prompt word, which can accurately generate requests that meet the verification target, improve the targeting and effectiveness of attack verification, and make the verification results more reflective of the target object's defense capabilities in actual attack scenarios.

[0091] In one implementation, the request generation model can be a trained large language model, which is trained using the Quantized Low-Rank Adaptation (QLoRA) training method.

[0092] Alternatively, QLoRA can be a model fine-tuning method that adapts model parameters using a low-rank matrix to improve training efficiency. For example, QLoRA can be used to fine-tune a large language model to meet the generation requirements of attack verification requests for target vulnerabilities.

[0093] This application's embodiments demonstrate that the QLoRA training method enables efficient fine-tuning of large language models with limited resources, allowing the model to quickly adapt to defense verification scenarios, accurately generate attack verification requests, reduce training costs, and improve the model's performance and practicality in the field of defense verification.

[0094] S103. Send an attack verification request to the target object.

[0095] Optionally, the target object can be any one or more of the following: a system, device, website, or application that requires defense performance verification. Optionally, the electronic device can send the attack verification request generated in S102 to the target object via a network connection or other communication method.

[0096] S104, Receive the first defense response from the target object.

[0097] Optionally, the first defense response may be the first reaction or feedback information generated by the target object in response to the attack after receiving the attack verification request, based on its own defense mechanism and strategy. It may include any one or more of the following: blocking the attack, recording attack information, and issuing an alarm.

[0098] Alternatively, electronic devices can obtain the first defense response from the target object through communication interfaces or network monitoring.

[0099] S105. Based on the first defense response, determine the defense performance of the target object.

[0100] Optionally, the defensive performance of a target object can be the level of its ability to effectively resist attacks and protect its own security when facing attacks. It can be determined by evaluating one or more of the following: the target object's response to attacks and whether it successfully prevents attacks.

[0101] In one implementation, the target object is the webpage to be defended and verified, and the first defense response is a defense response page. Optionally, the defense response page may be a page displayed to the attacker by the electronic device after detecting a potential attack, in order to prevent the attack from proceeding further and to protect the security of the webpage data. It may also be a page that informs normal users that the current webpage has security risks or is undergoing security maintenance.

[0102] This application's embodiments clearly define the target object and the specific form of the first defense response, making the defense verification method more targeted and operable. Defense verification targeting web pages can accurately identify security vulnerabilities and weak points in the defense of web pages. By analyzing the defense response page, the web page's defense capabilities against various attacks can be accurately assessed, ensuring web page security.

[0103] This application embodiment retrieves corresponding security data from multiple data sources based on the target vulnerability identifier, then combines this data with the target description text to generate an attack verification request and send it to the target object. After receiving the first defense response, its defense performance is determined. Compared to existing technologies that rely on manual attack request databases, which are lagging and incomplete, this method can automatically acquire multi-source security data to generate requests, enabling timely and comprehensive risk verification, accurately assessing the target object's defense performance, avoiding evaluation biases caused by data lag and incomplete verification in traditional methods, and improving the accuracy of attack verification.

[0104] Before sending an attack verification request to the target, the electronic device can perform network connectivity verification between the defense verification device and the target, obtaining a network connectivity verification result. Then, if the network connectivity verification result indicates that there are no anomalies between the defense verification device and the target, the attack verification request is sent to the target.

[0105] Optionally, network connectivity verification can be used to verify whether the network connection between the defense verification device and the target object is normal, and whether there are any abnormalities such as network interruption, excessive network latency, or restricted network access. The network connectivity verification result can be the result obtained by the electronic device after detecting and evaluating the network connection status between the defense verification device and the target object. The network connectivity verification result can be presented in the form of specific indicators or statuses, such as any one of "connection successful," "connection failed," or "latency time."

[0106] Optionally, the electronic device can use existing technical means, such as script commands, port scanning, network protocol detection, or any one or more methods, to detect and confirm the network connection between the defense verification device and the target object, and determine whether the two can communicate normally and whether there is a network failure or abnormality.

[0107] If the network connectivity verification result indicates that there are no anomalies between the defense verification device and the target object, an attack verification request is sent to the target object. This sending process is similar to S103 above and will not be described again here.

[0108] Before sending an attack verification request to the target object, this embodiment of the application performs network connectivity verification between the defense verification device and the target object to eliminate network interference and ensure that the attack verification request can be sent in a normal network environment, thereby improving the reliability and accuracy of the verification results.

[0109] In one implementation, when the network connectivity verification result is used to characterize that there is no anomaly between the defense verification device and the target object, the electronic device can first send a preset attack request to the target object, receive a second defense response from the target object, and determine whether there is a defense anomaly in the target object based on the second defense response.

[0110] Optionally, the preset attack request can be pre-defined request information used to simulate attacks on the target object. These requests contain characteristics of common attack types, such as one or more of the following: Structured Query Language (SQL) injection, Cross-Site Scripting (XSS), and command injection. The second defense response can be the reaction information generated by the target object after receiving the preset attack request, based on its own defense mechanisms and strategies. It may include operation records of blocking the attack, issuing security alerts, and logging attack information, reflecting the target object's defense status and handling results against the preset attack (common threat).

[0111] Optionally, if the network connectivity verification result indicates that there are no network anomalies between the defense verification device and the target object, the electronic device can transmit a pre-set attack request to the target object via the network. The purpose is to trigger the target object's defense mechanism and initiate a preliminary test of its defense performance. Correspondingly, the electronic device can also receive a second defense response from the target object via the network.

[0112] Optionally, the electronic device can perform detailed analysis and judgment on the received second defense response, and check whether the target object's defense mechanism is operating normally according to the preset defense performance evaluation standards, and whether there are any abnormal situations such as failure to effectively resist attacks or response errors, thereby concluding whether the target object has any defense anomalies.

[0113] Secondly, if the target object does not exhibit any defensive anomalies, the electronic device can send an attack verification request to the target object. This attack verification request is more targeted and complex, and can further verify the target object's defense capabilities, ensuring that its defense mechanism can operate effectively under various circumstances.

[0114] In this embodiment, when network connectivity is normal, a preset attack request is first sent. After receiving a second defense response confirming no defense anomalies, an attack verification request is then sent. By first sending a preset attack request to check for defense anomalies, verification deviations caused by problems with the target object itself can be avoided, ensuring that subsequent attack verification requests are performed when the target object's defense status is normal, thus improving the effectiveness of the verification results.

[0115] The following section provides a detailed explanation of how electronic devices determine the defensive capabilities of a target based on the first defensive response.

[0116] Figure 2 This application provides a flowchart illustrating a process for determining the defensive capabilities of a target object, as illustrated in the embodiments of this application. Figure 2 As shown, the above S105 may include:

[0117] S201. Based on the first defense response, construct a second prompt word. The second prompt word is used to indicate that the defense performance of the target object is analyzed based on the first defense response.

[0118] Optionally, the electronic device can analyze the first defense response, for example, extracting keywords and key parameters of the first defense response to construct a second prompt word.

[0119] S202. Input the second prompt word into the response analysis model to obtain the first analysis result of the target object's defense performance.

[0120] Optionally, the response analysis model can be a trained artificial intelligence model with the ability to analyze and process input information. It can understand the task requirements conveyed by the second prompt word and, combined with its own algorithms and knowledge, conduct an in-depth analysis of the first defense response to obtain the first analysis result on the defense performance of the target object.

[0121] Optionally, the first analysis result may be a preliminary analytical conclusion about the target's defensive capabilities output by the response analysis model after receiving the second cue word and processing the task it indicates. This first analysis result may be a preliminary assessment of the target's defensive capabilities.

[0122] In one implementation, the response analysis model can be a large language model based on the Hierarchical Classification Reasoning Framework (RHC). This module can construct a hierarchical reasoning system that decomposes complex problems or tasks into multiple levels, each containing classification and reasoning steps of different granularities.

[0123] For example, upon receiving the second cue word, the large language model based on RHC first understands the task requirement conveyed by the cue word, clarifying that it is to analyze the defensive performance of the target object. Then, the model finds the corresponding analysis level and starting point in the hierarchical classification reasoning framework according to the task requirements. For instance, if the second cue word requires analyzing the defensive performance of the target object against a specific type of attack, the model will locate the level and category related to that attack type in the framework, such as first locating the "defense strategy effectiveness" level, and then further locating the "defense effect against specific attack types" subcategory. By combining the analysis results of each level and category, the model arrives at the first analysis result regarding the defensive performance of the target object.

[0124] The embodiments of this application are based on a large language model of the RHC framework that follows a structured reasoning path. The analysis process is explicit, externalized, transparent and traceable, which can help security operations personnel to backtrack and analyze, and more accurately judge the defense performance of the target object.

[0125] S203. Based on the first analysis result, the target analysis result is obtained; the target analysis result is used to characterize the defensive performance of the target object.

[0126] Optionally, the electronic equipment can further process, integrate, or refine the initial analysis results to obtain the final results used to accurately characterize the target's defensive capabilities. The target analysis results are more comprehensive, accurate, and targeted, clearly reflecting the target's actual defensive situation and providing a reliable basis for subsequent decision-making or improvement measures.

[0127] This application embodiment constructs a second prompt word-guided response analysis model, which can accurately analyze the defense situation, avoid security risks and false alarms from log outgoing, and accurately assess the defense performance of the target object.

[0128] During the process of constructing the second prompt word based on the first defense response, the electronic device can construct the second prompt word based on the first defense response and other defense responses. These other defense responses can be defense responses made by the target object to verification requests other than attack verification requests. For example, other defense responses can be defense responses made by the target object to any one or more requests such as normal requests, general attack requests, and verification requests. Other defense responses can reflect the target object's defense capabilities and performance in different types of verification scenarios, providing more dimensions of information for a comprehensive evaluation of the target object's defense performance.

[0129] Optionally, the second prompt word can be specifically used to instruct the analysis of the target's defense performance by combining the first defense response with other defense responses. For example, the second prompt word could be "comprehensive analysis of the first defense response and other defense responses to evaluate the overall defense performance of the target."

[0130] This application embodiment, combined with other defense responses, can obtain richer defense information, evaluate the defense performance of the target object from multiple perspectives, and make the analysis results more accurate, comprehensive, and more realistically reflect the defense capabilities of the target object in the actual scenario.

[0131] In one implementation, the electronic device can construct a second prompt word based on a first defense response, other defense responses, and the historical defense performance verification results of the target object. This second prompt word can be specifically used to instruct the target object to analyze its defense performance by combining the first defense response, other defense responses, and historical defense performance verification results.

[0132] Optionally, the historical defense performance verification results of the target object can be a series of data and conclusions about its defense performance obtained by collecting, organizing and analyzing the defense responses made by the target object to various verification requests (including attack verification requests and regular verification requests) over a period of time.

[0133] For example, electronic devices can combine cross-request hierarchical reasoning (establishing a baseline for normal business behavior --> confirming the characteristics of the basic defense layer --> analyzing specific attack requests), single-response deep comparative analysis (comparing the elements of a specific attack response with the elements of a normal request response), and historical behavior reasoning (comparing the current verification situation with historical verification situations) to construct a second prompt word. Based on this second prompt word, the electronic device can analyze the defense performance of the target object. For example, through thinking chain technology and reinforcement learning optimization, it can accurately determine whether the target has been blocked by the defense device and the possible security defense strategies, such as temporary prohibition of high-frequency access or Internet Protocol (IP) blocking, and output the reasoning process and judgment results.

[0134] The embodiments of this application combine historical data to understand the changing trend of the target object's defense performance, and evaluate the current defense performance from a dynamic perspective, making the analysis results more forward-looking and valuable for reference, and helping to discover potential defense problems in a timely manner.

[0135] Based on the above embodiments, the first defense response may include: dynamic content and non-dynamic content. The dynamic content may include a timestamp of the first defense response, and any one or more of a unique identifier. The non-dynamic content may include any one or more of Hypertext Transfer Protocol (HTTP) response header features, status codes, and response content.

[0136] Optionally, dynamic content can be the information portion of the first defense response that has dynamic changing characteristics, and its content changes with each defense response. The timestamp of the first defense response can record the specific time information when the first defense response occurs, and the timestamp can clearly indicate the time sequence and occurrence time of the defense responses. The unique identifier of the first defense response can be a code or string used to uniquely identify a single first defense response, which can ensure that each defense response can be accurately distinguished and identified, avoiding confusion and duplication.

[0137] Optionally, non-dynamic content can be a relatively stable part of the first defense response that does not change frequently with each response. The HTTP response header is a series of information attached by the target object when returning the first defense response, used to convey metadata about the first defense response, such as server type, content type, cache control, etc., or any one or more of these. The HTTP status code can be a three-digit code returned by the server, used to indicate the server's processing result for the request. The response content can be the actual data content returned by the target object in the first defense response request, such as images, files, etc., or any one or more of these.

[0138] Before the electronic device obtains the target analysis result based on the first analysis result, it can first delete the dynamic content of the first defense response. The non-dynamic content is then matched with the interception response characteristics of various defense devices in the defense device feature library using regular expressions to determine the second analysis result. This second analysis result is used to characterize whether the target object's defense performance is within the protection range of the various defense devices.

[0139] Optionally, the defense device signature database can store a database of interception and response characteristics of various defense devices. These characteristics are typical patterns and rules accumulated by various defense devices during long-term operation and attack response. By comparing non-dynamic content with these characteristics, it can be determined whether the defense performance of the target object matches the known defense devices.

[0140] Optionally, the second analysis result can be used to characterize whether the defense performance of the target object is within the protection range of multiple defense devices, that is, to determine whether the defense method, characteristics, etc. of the target object are similar to or consistent with known effective defense devices, and whether they can achieve similar protection effects.

[0141] Optionally, the electronic device can remove dynamic content from the overall data in the first defense response to eliminate interference from dynamic content in the analysis results, allowing the analysis to focus more on non-dynamic content that is more relevant to the assessment of defense performance. The electronic device can use a regular expression text matching tool to compare the non-dynamic content of the first defense response with the interception response features of various defense devices in the defense device feature library, identify the parts of the non-dynamic content that match the defense device features, and thus determine the correlation between the defense performance of the target object and the defense device.

[0142] Secondly, based on the results of the first analysis and the second analysis, the target analysis results are obtained.

[0143] Optionally, the electronic device can assign different weights to the first analysis result and the second analysis result to synthesize the first analysis result and the second analysis result to obtain the target analysis result. Optionally, if the first analysis result and the second analysis result are presented in the form of scores, the electronic device can also select the analysis result with the highest score to obtain the target analysis result, or it can select the average of the two as the target analysis result.

[0144] This application embodiment deletes dynamic content and matches non-dynamic content with the feature library, which can accurately determine whether the target object is within the protection range of multiple defense devices. Combined with the first analysis result, it can comprehensively and accurately evaluate the defense performance and avoid analysis bias caused by dynamic content.

[0145] In one implementation, the target object is equipped with multiple defense systems, which can be systems for detecting, preventing, and responding to various attack behaviors, and can respond to attack verification requests. A first defense response may include sub-defense responses from multiple defense systems to the attack verification request. Each sub-defense response can be a specific response made by each of the multiple defense systems to the attack verification request.

[0146] In this scenario, the electronic device can initially respond to multiple sub-defense responses, with the number of target-type sub-defense responses being greater than or equal to a preset number. Based on the target-type sub-defense responses, security data, and the verification target description text, a new attack verification request is generated. The target-type sub-defense responses are used to indicate successful defense against the attack verification request.

[0147] Optionally, the preset quantity can be stored in the electronic device.

[0148] For example, a target-type sub-defense response could be a response from a sub-defense system that successfully provides defense feedback to a specific attack verification request (the requested attack is relatively weak and falls within the range that most defense systems can effectively handle).

[0149] Optionally, the electronic device can generate a new attack verification request based on the target type's sub-defense response, security data, and the verification target description text, similar to the above, and will not be repeated here.

[0150] Secondly, the electronic device can generate a new attack verification request based on the above, send the new attack verification request to the target object, and receive a third-party defense response from the target object. Finally, based on the third-party defense response, the defense performance of the target object is determined. This process is similar to the above and will not be repeated here.

[0151] This application embodiment can generate a new attack verification request when the number of sub-defense responses for a target type is greater than or equal to a preset number. Since a preset number of sub-defense responses for a target type indicates that the current attack verification request is weak and most defense systems can successfully defend against it, generating a new attack verification request can simulate more challenging attack scenarios and further test the target's defense performance.

[0152] Based on the above embodiments, this application embodiment can also periodically send defense performance update confirmation requests to the target object and receive feedback information from the target object before retrieving security data corresponding to the target vulnerability from multiple data sources based on the target vulnerability identifier.

[0153] Optionally, the defense performance update confirmation request can be a request to confirm whether the defense performance of the target object has been updated, and the feedback information can be information returned by the target object in response to the defense performance update confirmation request, which describes the status of its own defense performance. For example, it may include any one or more of the following: whether it has been updated, and the content of the update. Electronic devices can periodically send defense performance update confirmation requests and receive feedback information to monitor changes in the defense status of the target object in real time.

[0154] Optionally, the electronic device can send a defense performance update confirmation request to the target object via a network connection or other communication methods. The electronic device can also receive feedback information from the target object via a communication interface or network monitoring.

[0155] In this embodiment, before retrieving security data based on the target vulnerability identifier, a defense performance update confirmation request is periodically sent to the target object and feedback information is received. If the feedback information indicates that the target object's defense performance has been updated, the retrieval operation is then performed. By confirming the defense performance update status before retrieving, unnecessary retrieval operations can be avoided, effectively reducing data processing volume and improving the overall method execution efficiency.

[0156] In conclusion, Figure 3 This is a schematic diagram of an automatic verification device for security equipment provided in an embodiment of this application, as shown below. Figure 3 As shown, the automatic verification device for security equipment is the aforementioned defense verification device, and the verification target is the aforementioned target object. The automatic verification device for security equipment in this application embodiment can be divided into two parts: an attack engine and a verification engine.

[0157] The attack engine can be used to send various requests (including attack requests) to the target object. Its main components include:

[0158] (1) A proof of concept (POC) generation device is used to automatically construct relevant proof of concept based on various security intelligence.

[0159] (2) Attack orchestration device, used to determine the verification target and orchestrate attack requests.

[0160] (3) Attack sending device, used to send attack requests to the verification target.

[0161] The verification engine can be used to receive and analyze the response content of the verification target. Its main components include:

[0162] (1) A receiving and parsing device for receiving and parsing the response content of the verification target.

[0163] (2) Defense equipment identification library, used to store the interception response characteristics of various defense equipment.

[0164] (3) Response analysis device, used to carry out dynamic and static dual analysis based on device fingerprint recognition and large model response analysis.

[0165] Figure 4 A flowchart illustrating a specific defense verification method provided in this application embodiment is shown below. Figure 4 As shown, the process includes:

[0166] Attack Engine:

[0167] 1. Input the verification target and the verification vulnerability.

[0168] 2. The verification request generation device generates a verification request containing relevant characteristics based on the relevant vulnerability name. Optionally, enhanced hints are constructed using Search Enhancement Generation (RAG), and the QloRA parameter is fine-tuned to generate a large model for the verification request.

[0169] 3. Arrange the attack chain.

[0170] 4. Send normal requests to verify network connectivity and record responses. By sending multiple normal, non-aggressive data packets, confirm whether the target response is stable and reachable to ensure the basic reachability of the target system, thus ruling out physical and network-level blockages. Record connection success, response latency, and reset behavior to detect potential network layer protection or traffic management policies. Determine if the network is connected. If yes, proceed to step 5; otherwise, proceed to step 1.

[0171] 6. Send common attack requests (such as SQL injection, XSS, command injection, etc.) and record the response. Observe the target system's response to collect data on its reaction to common threats.

[0172] 7. Send a normal request to verify network connectivity. Determine if the network is connected. If yes, proceed to step 8; otherwise, proceed to step 1.

[0173] 8. Send verification requests for specific attack features to the target and observe the response status to collect feedback on the verification requests. The verification request for a specific attack feature can be represented by Ai, where i ≤ N. That is, i can represent the verification request for the i-th specific attack feature, and N can represent the total number of verification requests for N specific attack features.

[0174] Verification engine:

[0175] 1. Parse the received response content, observe the response status, and record whether the connection is successful, the response delay, and the reset behavior to ensure the basic reachability of the target system, in order to eliminate physical and network layer blockages and detect potential network layer protection or traffic management strategies.

[0176] 2. Based on the fingerprinting of defense devices, relying on the known database of defense device features (including HTTP response header features, status codes, response content, etc.), the presence and type of defense devices can be quickly identified by comparing the attack response with the features in the signature database.

[0177] 3. Based on the RHC (Reasoning for Hierarchical Classification) framework, the large-scale model response analysis compares the response pages of normal requests, general attack requests, and verification requests using the aforementioned large-scale model. The relevant reasoning process combines cross-request hierarchical reasoning (establishing a baseline for normal business behavior --> confirming the characteristics of the basic defense layer --> analyzing specific attack requests), single-response in-depth comparative analysis (elements of specific attack responses VS elements of normal request responses +), and historical behavior reasoning (current verification situation VS historical verification situation). Through the optimization of thinking chain technology and reinforcement learning, it accurately determines whether it has been blocked by defense devices and the possible security defense strategies (temporary ban on high-frequency access, IP blocking), and outputs the reasoning process and judgment results.

[0178] 4. Assess the overall defense situation.

[0179] It should be noted that steps 2 and 3 above can be performed in parallel.

[0180] Therefore, the solutions in this application embodiment include:

[0181] 1. An intelligent verification request generation device based on the RAG+QLoRA hybrid scheme was constructed.

[0182] This device overcomes the limitations of traditional methods that rely on security experts manually writing attack code. Based on a hybrid RAG+QLoRA scheme, it intelligently generates verification requests using a large model. It can deeply analyze publicly available information from the global security community, vulnerability databases, code repositories, and threat intelligence platforms using a Retrieval Enhanced Generation (RAG) scheme, based on the input vulnerability name. It then sends the latest intelligence and enhanced hints to a large model meticulously trained using a Low-Rank Adaptive Fine-Tuning Model (QLoRA) scheme. This enables the model to automatically extract and understand the vulnerability's attack principles, key characteristics, and exploitation conditions, ultimately generating a verification request containing precise attack characteristics.

[0183] 2. Designed and implemented a complete and logically rigorous systematic attack verification chain.

[0184] This process is not a simple single attack test, but rather a progressive, multi-level verification system consisting of "connectivity verification → baseline defense verification → specific attack verification." Its innovation lies in proactively establishing a clear state baseline and diagnostic path for the target under test through this structured attack orchestration. First, connectivity verification ensures the normality of the network infrastructure, eliminating interference caused by non-security factors such as network policies. Next, baseline defense verification confirms that the basic functions of the defense equipment and the general rule base are active and effective, identifying defense blind spots caused by configuration errors or outdated signature databases. Finally, after confirming the first two levels of verification are passed, targeted specific attack verification is performed, thereby accurately assessing the defense system's true detection and interception capabilities against advanced or unknown threats. This complete orchestration effectively avoids data distortion or misjudgment due to failure in the preceding stages, ensuring the completeness of the collected data and the accuracy of the conclusions.

[0185] 3. Large Model Response Analysis Based on the Classification Reasoning Framework (RHC)

[0186] After obtaining the response content of the relevant request, dynamic content (such as timestamps or unique identifiers) is removed, while HTTP response header features, status codes, and response content are retained. These are then used as the basis for detection and regular expression matching against the feature library of the defense device to determine whether the request falls within the protection scope of the known security protection product. Simultaneously, the entire verification process, including normal requests, general attack requests, verification requests, and defense fingerprint identification results, is analyzed and judged using the large model of the RHC (Reasoning for Hierarchical Classification) framework. The simple task of classifying whether a special attack request response page is abnormal is reconstructed into a multi-step reasoning process within the large model. Compared to the "deep thinking" of ordinary large models that rely on their powerful internal knowledge base for association and divergence, the "reasoning" of the RHC framework is designed to strictly follow a structured reasoning path (e.g., first judge A, then judge B based on A, and finally arrive at C). The entire reasoning process is explicit, externalized, completely transparent, and traceable, which can fully assist security operations personnel in backtracking and analysis.

[0187] The technical effects of the embodiments of this application are as follows:

[0188] 1. Based on a specified vulnerability name, it can automatically integrate publicly available intelligence from multiple dimensions of the internet, including security bulletins, technical blogs, code repositories, and threat platforms, and dynamically generate a high-fidelity verification Proof-of-Concept (POC) containing complete attack characteristics (such as specific attack payloads, malicious request sequences, and key exploit parameters). This fundamentally solves the efficiency bottlenecks and knowledge blind spots of traditional methods, ensuring the timeliness, accuracy, and comprehensiveness of attack verification, and providing a solid and reliable attack simulation foundation for subsequent defense effectiveness assessments.

[0189] 2. It possesses a complete chain of attack verification (connectivity verification, baseline defense verification, and specific attack verification). This orchestrated attack process effectively avoids interference with the final verification results due to preliminary issues such as network reachability and missing basic defense features, ensuring the completeness of the collected data and the accuracy of the conclusions, and providing irrefutable data support for accurately locating the weaknesses of the defense system.

[0190] 3. The system employs a dual analysis approach, combining static device fingerprinting with dynamic and static analysis based on the large model response analysis using the RHC (Reasoning for Hierarchical Classification) framework. By leveraging the RHC framework through thought chain technology and reinforcement learning optimization, it achieves progressive analysis from static fingerprinting and basic page feature recognition to comprehensive judgment. This allows for accurate analysis of defense status and capabilities without needing to access defense device logs, thus avoiding security risks associated with log outages.

[0191] The above are the method embodiments provided in this application. The apparatus provided in this application will be described below.

[0192] Figure 5 A schematic diagram of a defense verification device provided in this application is shown below. Figure 5 As shown, the defense verification device 400 provided in this embodiment includes:

[0193] The processing module 401 is used to retrieve security data corresponding to the target vulnerability from multiple data sources based on the identifier of the target vulnerability.

[0194] The generation module 402 is used to generate an attack verification request based on security data and the target description text.

[0195] The sending module 403 is used to send an attack verification request to the target object.

[0196] The receiving module 404 is used to receive the first defense response from the target object.

[0197] The determination module 405 is used to determine the defense performance of the target object based on the first defense response.

[0198] Optionally, the generation module 402 is specifically used to construct a first prompt word based on security data and verification target description text; the first prompt word is used to indicate the reference security data and generate an attack verification request that satisfies the verification target. The first prompt word is input into the request generation model to obtain the attack verification request.

[0199] For example, the request generates a large language model after training, and the large language model is trained using the low-rank adaptation fine-tuning QLoRA training method.

[0200] Optionally, before the sending module 403 sends the attack verification request to the target object, the processing module 401 further performs network connectivity verification between the defense verification device and the target object to obtain a network connectivity verification result. If the network connectivity verification result indicates that there are no anomalies between the defense verification device and the target object, the attack verification request is sent to the target object.

[0201] For example, when the network connectivity verification result indicates that there is no anomaly between the defense verification device and the target object, the sending module 403 is specifically used to send a preset attack request to the target object. It receives a second defense response from the target object. Based on the second defense response, it determines whether there is a defense anomaly in the target object. If there is no defense anomaly in the target object, it sends an attack verification request to the target object.

[0202] Optionally, the determining module 405 is specifically used to construct a second prompt word based on the first defense response. The second prompt word is used to indicate the analysis of the defense performance of the target object based on the first defense response. The second prompt word is input into the response analysis model to obtain a first analysis result of the defense performance of the target object. Based on the first analysis result, a target analysis result is obtained; the target analysis result is used to characterize the defense performance of the target object.

[0203] For example, the response analysis model is a large language model based on the Hierarchical Classification Reasoning Framework (RHC).

[0204] Optionally, the determining module 405 is specifically used to construct a second prompt word based on the first defense response and other defense responses. The second prompt word is specifically used to indicate: the defense performance of the target object is analyzed by combining the first defense response with other defense responses; the other defense responses are: the defense responses made by the target object to verification requests other than attack verification requests.

[0205] For example, the determining module 405 is specifically used to construct a second prompt word based on the first defense response, other defense responses, and the historical defense performance verification results of the target object. The second prompt word is specifically used to indicate that the defense performance of the target object is analyzed by combining the first defense response, other defense responses, and historical defense performance verification results.

[0206] Optionally, the first defense response includes: dynamic content and non-dynamic content; the dynamic content includes: a timestamp of the first defense response and at least one of a unique identifier; the non-dynamic content includes: a Hypertext Transfer Protocol (HTTP) response header feature, a status code, and at least one of the response content. Before the determining module 405 specifically obtains the target analysis result based on the first analysis result, the processing module is further used to delete the dynamic content of the first defense response. The non-dynamic content is matched with the interception response features of various defense devices in the defense device feature library using regular expressions to determine the second analysis result; the second analysis result is used to characterize whether the defense performance of the target object is within the protection range of various defense devices. The determining module 405 is specifically used to obtain the target analysis result based on the first analysis result and the second analysis result.

[0207] The defense verification device provided in this embodiment can execute the methods provided in any of the above method embodiments. Its implementation principle and technical effect are similar, and will not be described in detail here.

[0208] Figure 6 This is a schematic diagram of the structure of an electronic device provided in this application. Figure 6As shown, the electronic device 500 provided in this embodiment includes at least one processor 501 and a memory 502. Optionally, the device 500 further includes a communication component 503. The processor 501, memory 502, and communication component 503 are connected via a bus 504.

[0209] In a specific implementation, at least one processor 501 executes computer execution instructions stored in memory 502, causing at least one processor 501 to perform the above-described method.

[0210] The specific implementation process of processor 501 can be found in the above method embodiments, and its implementation principle and technical effect are similar. It will not be repeated here.

[0211] In the above embodiments, it should be understood that the processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor.

[0212] The memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage device.

[0213] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.

[0214] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described method.

[0215] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the above-described method.

[0216] The aforementioned readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium can be any available medium accessible to a general-purpose or special-purpose computer.

[0217] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can reside in an Application Specific Integrated Circuit (ASIC). Alternatively, the processor and the readable storage medium can exist as discrete components in the device.

[0218] The division of units is merely a logical functional division; in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or units, and may be electrical, mechanical, or other forms.

[0219] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0220] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0221] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0222] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.

[0223] Finally, it should be noted that other embodiments of the invention will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This invention is intended to cover any variations, uses, or adaptations of the invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein, and is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope.

Claims

1. A defense verification method, characterized in that, The method is applied to a defense verification device, and the method includes: Based on the identifier of the target vulnerability, security data corresponding to the target vulnerability is obtained by retrieving from multiple data sources; Based on the security data and the target description text, an attack verification request is generated; Send the attack verification request to the target object; Receive a first defense response from the target object; Based on the first defense response, the defense performance of the target object is determined.

2. The method according to claim 1, characterized in that, The step of generating an attack verification request based on the security data and the target description text includes: Based on the security data and the verification target description text, a first prompt word is constructed; the first prompt word is used to indicate, with reference to the security data, the generation of an attack verification request that satisfies the verification target; The first prompt word is input into the request generation model to obtain the attack verification request.

3. The method according to claim 2, characterized in that, The request generation model is a trained large language model, and the large language model is trained using the low-rank adaptation fine-tuning QLoRA training method.

4. The method according to any one of claims 1-3, characterized in that, Before sending the attack verification request to the target object, the method further includes: The network connectivity verification between the defense verification device and the target object is performed to obtain the network connectivity verification result; If the network connectivity verification result indicates that there is no anomaly between the defense verification device and the target object, the attack verification request is sent to the target object.

5. The method according to claim 4, characterized in that, When the network connectivity verification result indicates that there is no anomaly between the defense verification device and the target object, sending the attack verification request to the target object includes: If the network connectivity verification result indicates that there is no anomaly between the defense verification device and the target object, a preset attack request is sent to the target object; Receive a second defense response from the target object; Based on the second defense response, it is determined whether the target object has a defense anomaly; If the target object does not have any defense anomalies, the attack verification request is sent to the target object.

6. The method according to any one of claims 1-3, characterized in that, Based on the first defense response, the defense performance of the target object is determined, including: Based on the first defense response, a second prompt word is constructed, which is used to indicate the analysis of the defense performance of the target object based on the first defense response; Input the second prompt word into the response analysis model to obtain the first analysis result of the defense performance of the target object; Based on the first analysis result, the target analysis result is obtained; the target analysis result is used to characterize the defensive performance of the target object.

7. The method according to claim 6, characterized in that, The response analysis model is a large language model based on the Hierarchical Classification Reasoning Framework (RHC).

8. The method according to claim 6, characterized in that, The construction of the second prompt word based on the first defense response includes: Based on the first defense response and other defense responses, a second prompt word is constructed; the second prompt word is specifically used to indicate: to analyze the defense performance of the target object in combination with the first defense response and the other defense responses; the other defense responses are: the defense responses made by the target object to verification requests other than the attack verification request.

9. The method according to claim 8, characterized in that, The construction of the second prompt word based on the first defense response and other defense responses includes: Based on the first defense response, the other defense responses, and the historical defense performance verification results of the target object, a second prompt word is constructed; the second prompt word is specifically used to indicate that the defense performance of the target object is analyzed in combination with the first defense response, the other defense responses, and the historical defense performance verification results.

10. The method according to claim 6, characterized in that, The first defense response includes: dynamic content and non-dynamic content; the dynamic content includes: at least one of the timestamp of the first defense response and a unique identifier; the non-dynamic content includes: at least one of the HTTP response header features, a status code, and response content; before obtaining the target analysis result based on the first analysis result, the method further includes: Delete the dynamic content of the first defense response; The non-dynamic content is matched with the interception response features of various defense devices in the defense device feature library using regular expressions to determine the second analysis result; the second analysis result is used to characterize whether the defense performance of the target object is within the protection range of the various defense devices. The step of obtaining the target analysis result based on the first analysis result includes: Based on the first analysis result and the second analysis result, the target analysis result is obtained.

11. The method according to any one of claims 1-3, characterized in that, The target object is the webpage to be defended and verified, and the first defense response is the defense response page.

12. The method according to any one of claims 1-3, characterized in that, The target object is deployed with multiple defense systems. The first defense response includes: sub-defense responses from the multiple defense systems to the attack verification request. Determining the defense performance of the target object based on the first defense response includes: In response to a plurality of sub-defense responses, if the number of sub-defense responses of the target type is greater than or equal to a preset number, a new attack verification request is generated based on the sub-defense responses of the target type, the security data, and the verification target description text; the sub-defense responses of the target type are used to indicate that the attack verification request has been successfully defended. Send the new attack verification request to the target object; Receive a third defense response from the target object; Based on the third defense response, the defense performance of the target object is determined.

13. The method according to any one of claims 1-3, characterized in that, Before retrieving security data corresponding to the target vulnerability from multiple data sources based on the target vulnerability's identifier, the method further includes: Periodically send defense performance update confirmation requests to the target object; Receive feedback information from the target object; When the feedback information indicates that the defense performance of the target object has been updated, security data corresponding to the target vulnerability is obtained by retrieving from multiple data sources based on the identifier of the target vulnerability.

14. A defense verification device, characterized in that, The device includes: The processing module is used to retrieve security data corresponding to the target vulnerability from multiple data sources based on the identifier of the target vulnerability; The generation module is used to generate an attack verification request based on the security data and the target description text. The sending module is used to send the attack verification request to the target object; A receiving module is used to receive a first defense response from the target object; The determination module is used to determine the defense performance of the target object based on the first defense response.

15. An electronic device, characterized in that, include: Memory, processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory, causing the processor to perform the method as described in any one of claims 1-13.

16. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1-13.

17. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method described in any one of claims 1-13.