Huaxi to the model application situation monitoring system

CN122533776APending Publication Date: 2026-08-07HANGZHOU HUAYAO ZHIAN TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HANGZHOU HUAYAO ZHIAN TECHNOLOGY CO LTD
Filing Date
2026-02-11
Publication Date
2026-08-07

AI Technical Summary

Technical Problem

本发明旨在解决现有大模型应用监控系统多源日志整合能力弱、态势可视化不灵活、审计与告警割裂、事件关联分析不足、适配行业有限的技术缺陷,提供华钥至安大模型应用态势监控系统,通过多模块协同工作,实现大模型应用运行态势与安全状态的全面、实时、精准监控

Benefits of technology

多源日志整合能力强,支持多种大模型安全产品与日志源设备接入,采集过滤策略可有效减少冗余数据,提升监控效率;

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122533776A_ABST
    Figure CN122533776A_ABST
Patent Text Reader

Abstract

The application relates to a HuaKey to AnDa model application situation monitoring system and belongs to the technical field of network security and large model monitoring. The system comprises eight modules of data acquisition, situation visualization, audit analysis, behavior alarm, event correlation, report generation, system configuration and platform management, can be connected with various large model security products and various log source equipment, collects logs through a Syslog protocol and is filtered and screened in multiple dimensions, realizes visual functions of self-defined dashboards, IP correlation analysis, compliance audit, real-time monitoring and the like, supports multi-industry audit templates and AI abnormal behavior alarms, completes event aggregation analysis based on correlation strategies, automatically generates multiple types of reports and supports scheduling export, realizes fine configuration through role permissions and user management, simultaneously monitors the resource state of the system itself and triggers an alarm cleaning mechanism. The application solves the defects of weak multi-source log integration, inflexible visualization, split audit and alarm in the prior art, realizes comprehensive, real-time and accurate monitoring of a large model application situation, is suitable for multi-industry scenes, and significantly improves operation and maintenance efficiency and safety guarantee capability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of network security and large model monitoring technology, specifically involving the Huayue Zhian large model application status monitoring system. It is applicable to scenarios such as monitoring the operational status of large model service agents, auditing security events, and alarming abnormal behavior. It can be connected to various large model security detection and protection products, providing users with a real-time and comprehensive solution for monitoring the security and operational status of large model applications. Background Technology

[0002] With the widespread application of large-scale model technology, the operational security and situational awareness monitoring of large-scale model service agents have become crucial requirements in the cybersecurity field. Current technologies for large-scale model-related security monitoring largely rely on independent log analysis from single products, lacking multi-source log integration capabilities, leading to fragmented situational awareness monitoring. Furthermore, existing monitoring systems suffer from shortcomings such as unintuitive situational awareness visualization, fragmented auditing and alerting functions, a lack of industry-compatible audit templates, and weak event correlation analysis capabilities. For example, traditional monitoring systems cannot simultaneously interface with logs from multiple products such as LLM application firewalls and MCP large-scale model security detection tools, and their fixed visualization displays fail to meet users' customized monitoring needs. Auditing strategies lack industry specificity, and alerts and event analysis are not linked, making it difficult for users to quickly locate security risks. In addition, existing systems have insufficient log collection and filtering capabilities, easily generating redundant data and impacting monitoring efficiency. Therefore, there is an urgent need for a large-scale model application situational awareness monitoring system with multi-source log integration, customizable visualization, multi-industry audit adaptation, and alert-audit-event linkage. Summary of the Invention

[0003] Technical problems to be solved This invention aims to address the technical shortcomings of existing large-scale application monitoring systems, such as weak multi-source log integration capabilities, inflexible situation visualization, fragmented auditing and alarm functions, insufficient event correlation analysis, and limited industry adaptability. It provides the Huayue Zhian Large-Scale Application Situation Monitoring System, which achieves comprehensive, real-time, and accurate monitoring of the operational status and security status of large-scale applications through the collaborative work of multiple modules. Technical solution

[0004] To address the above problems, this invention adopts the following technical solution: the Huayue-AnDa model application situation monitoring system, comprising the following core steps: S1: During the data acquisition phase, the data acquisition module connects to products such as LLM application firewall, MCP large model security detection tool, large model application security monitoring system, and Agentic large model risk detection system, while also receiving component logs from the large model service agent. The collector management unit supports Syslog protocol access and is compatible with log source devices such as IDS, firewalls, and auditing devices. The collection filtering strategy filters valid logs according to log level, event type, and IP address range.

[0005] S2: Situation visualization phase. The situation visualization module provides four core functions: a customizable dashboard that supports flexible addition of data components to meet users' personalized monitoring needs; IP association analysis that can query the relationship between source IPs and destination IPs within a specified time range and generate an IP association graph; compliance audit that displays the number of log source assets, the total number of logs received, storage status, and trend data; and a real-time monitoring module that displays real-time log trends within 2 minutes and supports multi-dimensional log ignore condition configuration.

[0006] S3: Audit Analysis Phase. The audit analysis module provides audit templates for multiple industries (electricity, energy, transportation, etc.). Users can customize audit strategies and adjust the execution order. Audit event management supports keyword search and precise search. The auditor module can configure audit event types and event level permissions for different accounts.

[0007] S4: Behavior Alert Phase. The behavior alert module uses AI algorithms to detect abnormal user access, vulnerability exploitation, and other abnormal behaviors. It supports adding, modifying, deleting, and enabling / disabling abnormal behavior policies. The AI ​​audit alert module displays alert information in categories and supports batch confirmation and ignore operations. Alert policies cover more than 8 scenarios, including DNS spoofing, viruses / Trojans, and scanning detection.

[0008] S5: Event Correlation Phase. The event correlation module aggregates and correlates security events based on custom correlation strategies. The raw log module supports log forwarding and advanced queries. The event feature value module can mark and manage the features of specific events.

[0009] S6: Report generation stage. The report generation module provides templates for audit reports, asset reports, etc., supports weekly scheduling of report tasks, and reports can be queried by asset type and custom time range. Data export is also supported.

[0010] S7: System configuration and platform management phase. The system configuration module enables fine-grained management of role permissions and user accounts; the platform management module monitors resource status such as system storage duration, outputs system operation alarms, and triggers data cleanup mechanisms. Beneficial effects

[0011] Compared with the prior art, the present invention has the following advantages: It has strong multi-source log integration capabilities, supports access to various large-scale security products and log source devices, and its collection and filtering strategies can effectively reduce redundant data and improve monitoring efficiency. Situational visualization is flexible and intuitive, and customizable dashboards and multi-dimensional real-time monitoring meet the personalized needs of different users. IP association and compliance auditing enable comprehensive situational awareness. Audit, alert, and event linkage are closely integrated; audit templates for multiple industries are adapted to different scenarios; AI-powered abnormal behavior detection and correlation strategy analysis improve the accuracy of risk identification. It is highly scalable and practical, supports flexible configuration of collectors, auditing policies and alarm rules, adapts to a variety of log source devices, and is suitable for monitoring scenarios of large-scale application in multiple industries. The system features refined management, hierarchical configuration of roles and user permissions, and system resource monitoring and alarms to ensure operational stability. Figure 1 is the overall system architecture diagram, which shows the entire process of the system from log source input to final system monitoring, and clarifies the connection relationship and signal flow of the eight major modules: data collection, situation visualization, audit analysis, behavior alarm, event correlation, report generation, system configuration and platform management. Figure 2 This is a data collection and filtering flowchart. The flowchart clarifies the core process of log source devices, collector access, log reception, filtering strategies, and effective log output. It marks the collection protocol (Syslog) and filtering dimensions (log level, event type, IP address range) to reflect the multi-source log filtering mechanism. Figure 3 This is an audit alarm event linkage diagram. The diagram shows the linkage logic of audit event generation, alarm condition judgment, AI anomaly detection, and correlation strategy analysis, and clarifies the triggering relationship and data flow of each link. Figure 4 This is a flowchart of situation visualization and report generation. The flowchart illustrates the four core functions of situation visualization and the entire process of report generation, marking the report template type, scheduling method and query dimension, and showing the link between visualized data and report conversion. Figure 5 This is a system configuration and platform management flowchart. The flowchart shows the closed-loop process of administrator operation, permission configuration, system resource monitoring, threshold alarm and data cleanup, and clarifies the allocation logic of roles and user permissions as well as the system's own operation and maintenance mechanism.

Claims

1. The Huayue-AnDa model application situation monitoring system, characterized in that, include: The data acquisition module is used to receive alarm logs from large-scale security detection and protection products, as well as component logs from large-scale service agents. It supports access to multiple types of log source devices and log filtering. The situation visualization module provides customizable dashboards, IP correlation analysis, compliance auditing, and real-time monitoring functions to visualize the operational status and security status of large-scale application models. The audit analysis module includes audit event management, multi-industry audit strategy templates, audit type configuration, and auditor management functions, and supports custom audit rules and dynamic adjustment of strategies. The behavior alert module uses AI-based abnormal behavior detection and alert policy configuration to achieve real-time alerts and batch processing of behaviors such as abnormal access and vulnerability exploitation. The event association module aggregates and analyzes security events based on custom association strategies, and supports raw log querying and event feature value tagging. The report generation module provides multiple types of report templates, supports report task scheduling, automatic generation, and report display by asset and time dimensions; The system configuration module is used for role-based access control and user account management, enabling fine-grained allocation of operation permissions; The platform management module is used to monitor the system's own resource status and output system operation alarm information.

2. According to claim 1 Data acquisition module, Its features are, Can Supported log source devices include IDS / IPS, firewalls / VPNs, auditing devices, isolation devices, application systems, etc. The access method adopts the Syslog protocol and can be configured with collection filtering policies, which can filter logs by log level, event type, and IP address range.

3. According to claim 1 Situation visualization module, Its features are, can The custom dashboard supports flexible addition of data components, and the real-time monitoring module can set log ignore conditions (multiple conditions are ORed), covering dimensions such as source IP, destination IP, source port, and destination port, and supports real-time log trend display within 2 minutes.

4. According to claim 1 Audit analysis module, Its features are, Can It supports operations such as moving up, moving down, modifying, and deleting. The system has built-in basic auditing strategies for network attacks, malicious programs, virus infections, flood attacks, etc.

5. According to claim 1 Behavior alarm module, Its features are, use AI-powered abnormal behavior detection can cover scenarios such as abnormal user access, remote buffer overflow vulnerabilities, and path deserialization vulnerabilities. The alarm policy supports enabling / disabling the status and allows setting the time range for event monitoring.

6. According to claim 1 Event association module, Its features are, It supports custom configuration of association policies, and can aggregate security events by event type, event level, source IP, and other dimensions. Raw log queries support keyword queries, precise queries, and advanced queries. Event feature values ​​can be added, modified, and deleted.

7. According to claim 1 Report generation module Its features are, It supports weekly scheduling and execution, including types of audit reports and asset reports. The report display supports filtering by asset type, the query time range can be customized, and the report export function is supported.

8. According to claim 1 System configuration module / platform management module Its features are, It includes a collector management unit for monitoring and managing the collector's name, collection address, access method, proxy server, and operating status. It supports log import, addition, batch operations, and enable / disable control. It also includes the system's own management and security configurations.