一种大模型智能体网络行为监测识别方法、装置、设备及介质

By capturing network traffic, reconstructing sessions, and extracting features, and combining clustering algorithms to reconstruct the task chain, the problem of monitoring the network behavior of large-scale intelligent agents in encrypted communication scenarios is solved, achieving efficient and accurate identification and tracking, and meeting the needs of network security management.

CN122069118BActive Publication Date: 2026-07-17EVERSEC BEIJING TECH
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-04-21
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Existing technologies cannot effectively monitor the behavior of large-scale intelligent agents in encrypted communication scenarios, resulting in high operational complexity, high computational consumption, and easy leakage of user communication privacy, making it difficult to meet the needs of network security management.

Method used

By capturing network traffic, reconstructing network sessions, extracting protocol semantic fingerprints, flow-level dynamic rhythm features, and intent-driven behavior graphs, and using clustering algorithms to reconstruct the entire task execution chain, we can achieve accurate identification and tracking of network behavior of large-scale intelligent agents and avoid decryption operations.

Benefits of technology

It improves the accuracy and completeness of network behavior monitoring of large-scale intelligent agents without decrypting network communication content, adapts to monitoring needs in encrypted communication scenarios, avoids privacy leaks, and provides clear monitoring and identification results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122069118B_ABST
    Figure CN122069118B_ABST
Patent Text Reader

Abstract

本申请提供了一种大模型智能体网络行为监测识别方法、装置、设备及介质,在不解密网络通信内容的条件下,捕获网络流量重建网络会话;针对每个网络会话,提取协议语义指纹、流级动态节奏特征以及意图驱动行为图输入至模型中,识别该会话是否由大模型智能体产生;若是则解析其使用的协议类型及调用的工具;根据解析得到的协议类型与工具信息确定对应的行为类型,生成带标注会话数据;基于带标注会话数据,采用聚类算法将属于同一智能体任务的多条网络流进行关联,重构任务执行全链条;输出重构后的任务执行全链条信息作为智能体网络行为的监测识别结果。采用上述方法,能够提升大模型智能体网络行为监测识别的准确性、完整性和高效性。
Need to check novelty before this filing date? Find Prior Art

Citation Information

Patent Citations

  • Encrypted traffic application activity identification method based on wavelet transform

    CN111626322A

  • Time sequence graph construction method and device, equipment and medium

    CN114547491A