A shell command detection method and device based on a large model, a storage medium and electronic equipment

CN122802171APending Publication Date: 2026-09-22BEIJING 360 INTELLIGENT TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510337732.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-20
Publication Date
2026-09-22

AI Technical Summary

Benefits of technology

[0061]In one or more embodiments of this specification, the electronic device extracts domain name address information from the target shell command, determines associated asset information data and associated threat intelligence information based on the domain name address information, and performs command security detection processing on the target shell command using a large-scale security detection model based on the domain name address information, associated asset information data, and associated intelligence information data to obtain the shell command security detection result. By effectively coordinating abnormal command monitoring, asset and threat intelligence query, and the large-scale security detection model, accurate extraction, intelligent filtering, and risk assessment of abnormal shell commands are achieved, which not only significantly reduces the false alarm rate but also improves the ability to identify unknown attacks. At the same time, by combining digital asset information and threat intelligence, comprehensive data support is provided for security detection, thereby greatly enhancing the timeliness and accuracy of overall network security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122802171A_ABST
    Figure CN122802171A_ABST
Patent Text Reader

Abstract

This specification discloses a shell command detection method, apparatus, storage medium, and electronic device based on a large-scale security detection model. The method includes: determining the target shell command to be detected; extracting domain name address information from the target shell command; determining associated asset information data and associated threat intelligence information based on the domain name address information; and performing command security detection processing on the target shell command using a large-scale security detection model based on the domain name address information, associated asset information data, and associated threat intelligence information data to obtain the shell command security detection result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification relates to the field of computer technology, and in particular to a method, apparatus, storage medium, and electronic device for detecting shell commands based on a large model. Background Technology

[0002] In the field of cybersecurity, system security is constantly threatened by various malicious attacks. Among these threats, monitoring and analyzing the shell commands executed by users in the operating system is a critical task, aiming to promptly detect and block potential attacks. Shell commands, as an important means of interaction between users and the operating system, play a vital role not only in system management and automated operations and maintenance, but can also become a vehicle for attackers to commit intrusions, lateral movement, or download malicious programs. Summary of the Invention

[0003] This specification provides a method, apparatus, storage medium, and electronic device for detecting shell commands based on a large model. The technical solution is as follows:

[0004] Firstly, embodiments of this specification provide a shell command detection method based on a large model, the method comprising:

[0005] Determine the target shell command to be detected, and extract the domain name address information from the target shell command;

[0006] Based on the domain name address information, related asset information data and related threat intelligence information are determined;

[0007] Based on the domain name address information, the associated asset information data, and the associated intelligence information data, a large-scale security detection model is used to perform command security detection processing on the target shell command to obtain the shell command security detection result.

[0008] In one feasible implementation, determining the associated asset information data and associated threat intelligence information based on the domain name address information includes:

[0009] The domain name address information is matched with digital assets in the digital asset information database to obtain associated asset information data.

[0010] Based on the associated asset information data, the target shell command is verified to obtain the whitelist verification result;

[0011] Based on the whitelist verification results, the domain name address information is queried and processed through the threat intelligence platform to obtain associated threat intelligence information.

[0012] In one feasible implementation, the step of querying and processing the domain name address information through a threat intelligence platform based on the whitelist verification result to obtain associated threat intelligence information includes:

[0013] If the whitelist verification result is of the whitelist record type, then the first shell command security detection result of the command security type is generated;

[0014] If the whitelist verification result is that the whitelist does not record a certain type, then the related threat intelligence information is obtained by querying and processing the domain name address information through the threat intelligence platform.

[0015] In one feasible implementation, the step of performing command security detection processing on the target shell command using a security detection big data model based on the domain name address information, the associated asset information data, and the associated intelligence information data, to obtain the shell command security detection result, includes:

[0016] Based on the target shell command and the domain name address information, a large-scale security detection model is used to identify potential attack command scenarios;

[0017] Based on the potential attack command scenario, obtain the target scenario security prompt words. Based on the target scenario security prompt words, use the domain name address information, the associated asset information data, and the associated intelligence information data to control the security detection big model to perform security detection processing and obtain the shell command security detection result.

[0018] In one feasible implementation, the step of using the domain name address information, the associated asset information data, and the associated intelligence information data to control a large-scale security detection model based on the target scenario security prompt words to perform security detection processing and obtain the shell command security detection result includes:

[0019] Based on the security prompt words of the target scenario, the domain name address information, the associated asset information data and the associated intelligence information data are used to control the security detection big model to parse the target scenario detection link. The target scenario detection link includes multiple link detection thought steps.

[0020] The security detection model is used to perform step-by-step security detection on the target shell command based on the target scenario detection link and following the detection steps of each link to obtain the shell command security detection result.

[0021] In one feasible implementation, the potential attack command scenarios include download execution attack scenarios.

[0022] The process of performing step-by-step security detection on the target shell command using the security detection model based on the target scenario detection link and following the detection steps of each link to obtain the shell command security detection result includes:

[0023] The security detection model extracts abnormal shell commands based on the abnormal command extraction steps of the target scene detection link, obtains download execution instructions according to the download instruction extraction steps, and performs abnormal parsing processing on the abnormal shell commands and the download execution instructions according to the abnormal parsing steps to obtain the shell command security detection result.

[0024] In one feasible implementation, after extracting the domain name address information from the target shell command, the method further includes:

[0025] Obtain the command context information of the target shell command;

[0026] Based on the command context information, the domain name address information is subjected to domain name address compliance verification processing through a large security detection model to obtain a compliance verification result.

[0027] If the compliance verification result is a real domain name address type, then the step of determining the associated asset information data and associated threat intelligence information based on the domain name address information is executed;

[0028] If the compliance verification result is a similar domain name address type, then the target shell command will be ignored.

[0029] In one feasible implementation, the step of determining the target shell command to be detected includes:

[0030] The system monitors user-executed commands using an abnormal command monitoring system to obtain the target shell commands to be detected.

[0031] Secondly, embodiments of this specification provide a shell command detection device based on a large model, the device comprising:

[0032] The extraction module is used to determine the target shell command to be detected and extract domain name address information from the target shell command;

[0033] The determination module is used to determine associated asset information data and associated threat intelligence information based on the domain name address information;

[0034] The detection module is used to perform command security detection processing on the target shell command based on the domain name address information, the associated asset information data and the associated intelligence information data using a security detection big model, and obtain the shell command security detection result.

[0035] In one feasible implementation, determining the associated asset information data and associated threat intelligence information based on the domain name address information includes:

[0036] The domain name address information is matched with digital assets in the digital asset information database to obtain associated asset information data.

[0037] Based on the associated asset information data, the target shell command is verified to obtain the whitelist verification result;

[0038] Based on the whitelist verification results, the domain name address information is queried and processed through the threat intelligence platform to obtain associated threat intelligence information.

[0039] In one feasible implementation, the step of querying and processing the domain name address information through a threat intelligence platform based on the whitelist verification result to obtain associated threat intelligence information includes:

[0040] If the whitelist verification result is of the whitelist record type, then the first shell command security detection result of the command security type is generated;

[0041] If the whitelist verification result is that the whitelist does not record a certain type, then the related threat intelligence information is obtained by querying and processing the domain name address information through the threat intelligence platform.

[0042] In one feasible implementation, the step of performing command security detection processing on the target shell command using a security detection big data model based on the domain name address information, the associated asset information data, and the associated intelligence information data, to obtain the shell command security detection result, includes:

[0043] Based on the target shell command and the domain name address information, a large-scale security detection model is used to identify potential attack command scenarios;

[0044] Based on the potential attack command scenario, obtain the target scenario security prompt words. Based on the target scenario security prompt words, use the domain name address information, the associated asset information data, and the associated intelligence information data to control the security detection big model to perform security detection processing and obtain the shell command security detection result.

[0045] In one feasible implementation, the step of using the domain name address information, the associated asset information data, and the associated intelligence information data to control a large-scale security detection model based on the target scenario security prompt words to perform security detection processing and obtain the shell command security detection result includes:

[0046] Based on the security prompt words of the target scenario, the domain name address information, the associated asset information data and the associated intelligence information data are used to control the security detection big model to parse the target scenario detection link. The target scenario detection link includes multiple link detection thought steps.

[0047] The security detection model is used to perform step-by-step security detection on the target shell command based on the target scenario detection link and following the detection steps of each link to obtain the shell command security detection result.

[0048] In one feasible implementation, the potential attack command scenarios include download execution attack scenarios.

[0049] The process of performing step-by-step security detection on the target shell command using the security detection model based on the target scenario detection link and following the detection steps of each link to obtain the shell command security detection result includes:

[0050] The security detection model extracts abnormal shell commands based on the abnormal command extraction steps of the target scene detection link, obtains download execution instructions according to the download instruction extraction steps, and performs abnormal parsing processing on the abnormal shell commands and the download execution instructions according to the abnormal parsing steps to obtain the shell command security detection result.

[0051] In one feasible implementation, after extracting the domain name address information from the target shell command, the method further includes:

[0052] Obtain the command context information of the target shell command;

[0053] Based on the command context information, the domain name address information is subjected to domain name address compliance verification processing through a large security detection model to obtain a compliance verification result.

[0054] If the compliance verification result is a real domain name address type, then the step of determining the associated asset information data and associated threat intelligence information based on the domain name address information is executed;

[0055] If the compliance verification result is a similar domain name address type, then the target shell command will be ignored.

[0056] In one feasible implementation, the step of determining the target shell command to be detected includes:

[0057] The system monitors user-executed commands using an abnormal command monitoring system to obtain the target shell commands to be detected.

[0058] Thirdly, embodiments of this specification provide a computer storage medium storing a plurality of instructions adapted for loading by a processor and executing the above-described method steps.

[0059] Fourthly, embodiments of this specification provide an electronic device that may include: a processor and a memory; wherein the memory stores a computer program adapted to be loaded by the processor and to execute the above-described method steps.

[0060] The beneficial effects of the technical solutions provided in some embodiments of this specification include at least the following:

[0061] In one or more embodiments of this specification, the electronic device extracts domain name address information from the target shell command, determines associated asset information data and associated threat intelligence information based on the domain name address information, and performs command security detection processing on the target shell command using a large-scale security detection model based on the domain name address information, associated asset information data, and associated intelligence information data to obtain the shell command security detection result. By effectively coordinating abnormal command monitoring, asset and threat intelligence query, and the large-scale security detection model, accurate extraction, intelligent filtering, and risk assessment of abnormal shell commands are achieved, which not only significantly reduces the false alarm rate but also improves the ability to identify unknown attacks. At the same time, by combining digital asset information and threat intelligence, comprehensive data support is provided for security detection, thereby greatly enhancing the timeliness and accuracy of overall network security protection. Attached Figure Description

[0062] To more clearly illustrate the technical solutions in the embodiments or prior art of this specification, the drawings used in the description of the embodiments or prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0063] Figure 1 This is a flowchart illustrating a shell command detection method based on a large model provided in the embodiments of this specification;

[0064] Figure 2 This is a schematic diagram of a set of abnormal target shell commands provided in the embodiments of this specification;

[0065] Figure 3 This is a schematic diagram of a shell command security detection result provided in an embodiment of this specification;

[0066] Figure 4 This is a schematic diagram of an information determination process provided in the embodiments of this specification;

[0067] Figure 5 This is a schematic diagram of a command security detection process provided in the embodiments of this specification;

[0068] Figure 6 This is a schematic diagram of a security detection process based on relevant information provided in the embodiments of this specification;

[0069] Figure 7 This is a schematic diagram of a compliance inspection process provided in the embodiments of this specification;

[0070] Figure 8 This is a schematic diagram of the shell command detection device based on a large model provided in the embodiments of this specification;

[0071] Figure 9 This is a schematic diagram of the structure of an electronic device provided in the embodiments of this specification;

[0072] Figure 10 This is a schematic diagram of the operating system and user space structure provided in the embodiments of this specification;

[0073] Figure 11 yes Figure 10 Architecture diagram of the Android operating system in China;

[0074] Figure 12 yes Figure 10 Architecture diagram of the iOS operating system. Detailed Implementation

[0075] The technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this specification, and not all embodiments. Based on the embodiments in this specification, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this specification.

[0076] In the description of this specification, it should be understood that the terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance. In the description of this specification, it should be noted that, unless otherwise expressly specified and limited, "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to these processes, methods, products, or devices. Those skilled in the art can understand the specific meaning of the above terms in this specification based on the specific circumstances. Furthermore, in the description of this specification, unless otherwise stated, "multiple" means two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, and B alone. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship.

[0077] In related technologies, to accurately determine the security of user-executed commands and effectively prevent potential malicious behavior, a blacklist or whitelist based on high-risk commands is employed. This method matches user-executed commands against a predefined list of high-risk commands to determine their security. However, because this method cannot understand the context and intent of the commands, many normal operations are incorrectly flagged as security threats, resulting in a large number of false alarms.

[0078] It is evident that shell command detection methods in related technologies have numerous problems in practical use, including high false alarm rates and insufficient ability to identify unknown attacks. Therefore, improvements are necessary to enhance the accuracy and efficiency of monitoring systems, reduce false alarms, strengthen the ability to identify unknown attacks, and provide clearer decision explanations.

[0079] The present specification will now be described in detail with reference to specific embodiments.

[0080] In one embodiment, such as Figure 1 As shown, a shell command detection method based on a large model is proposed. This method can be implemented using a computer program and can run on a shell command detection device based on a von Neumann architecture. This computer program can be integrated into applications or run as a standalone utility application. The shell command detection device based on the large model can be an electronic device, including but not limited to: personal computers, tablets, handheld devices, vehicle-mounted devices, server devices, computing devices, or other processing devices connected to a wireless modem. Terminal devices can have different names in different networks, such as: user equipment, access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent or user equipment, cellular phone, cordless phone, device in 5G network or future evolved network, etc.

[0081] Specifically, this shell command detection method based on a large model includes:

[0082] S102: Determine the target shell command to be detected, and extract the domain name address information from the target shell command;

[0083] Target shell commands: These are shell commands that require security checks. They are usually a group of commands that are considered abnormal or have security risks and are selected by the security monitoring system. Target shell commands need to undergo further shell command checks.

[0084] Domain name address information: This includes network address information appearing in shell commands, including but not limited to domain names (such as "example.com", "sub.domain.net") and IP addresses (such as "192.168.1.1").

[0085] As an example, the target shell commands to be detected are collected from logs, monitoring systems, or other data sources. The command text of the collected target shell commands is parsed, and regular expressions or string matching methods are used to identify possible domain names and / or IP addresses. Strings that conform to the domain name and / or IP address format are extracted as key domain name address information for subsequent risk assessment.

[0086] In one feasible implementation, the step of determining the target shell command to be detected includes:

[0087] The system monitors user-executed commands using an abnormal command monitoring system to obtain the target shell commands to be detected.

[0088] Anomaly command monitoring system: This is a security system specifically designed for real-time monitoring of shell commands executed by users in the operating system. Through preset rules, behavioral pattern analysis, and anomaly detection algorithms, this system identifies shell commands that deviate from normal usage patterns. Typically, this system can only detect anomalies that may result in false alarms; further implementation of the large-model-based shell command detection method described in this specification is required.

[0089] User command execution monitoring and processing: This refers to the process by which the abnormal command monitoring system captures, records, and performs preliminary analysis on all commands entered by the user, with the aim of promptly identifying potentially abnormal or malicious command behaviors.

[0090] Optionally, the abnormal command monitoring system can be deployed on critical network nodes or servers to continuously monitor all commands executed by users in the shell environment. For example, when a user executes a command through a terminal or remote connection, the system captures the command text and related execution context (such as execution time, user identity, terminal information, etc.) in real time. The system has a built-in predefined rule base and anomaly detection algorithm to analyze the execution patterns of user commands. The abnormal command monitoring system can determine whether a command is executed during an unusual time period or whether the command contains suspicious operations such as potentially downloading or executing external code. When the behavior of a command deviates significantly from the regular security policy, the system will mark the command as abnormal; commands with detected abnormal characteristics will be filtered by the abnormal command monitoring system as target shell commands to be detected.

[0091] For example, such as Figure 2 As shown, Figure 2 This is a scenario diagram illustrating a set of abnormal target shell commands. Figure 2 In the target shell commands shown, curl is a download command that attempts to download and execute a script from titup-mirrors.pingcap.com. In this specification, the abnormal command monitoring system continuously listens for all commands executed by the user in the shell environment and detects... Figure 2 The abnormal target shell command shown uses a preset regular expression to extract domain name address information. The domain name address information extracted by the system is: topology.yaml and tiup-mirrors.pingcap.com;

[0092] S104: Determine associated asset information data and associated threat intelligence information based on the domain name address information;

[0093] Associated asset information data: refers to digital asset data corresponding to domain names or IP addresses. This data usually comes from the organization's (such as enterprises, schools, etc.) internal asset management system and records the organization's legitimate and trusted network assets, such as internal servers, databases, domain names, etc.

[0094] Related threat intelligence information: This refers to security threat information related to a domain name / IP obtained through security intelligence platforms, third-party services, or internal databases. This information may include malicious behavior records, historical security incidents, risk scores, etc.

[0095] As an illustration, the domain name address information extracted in step S102 is used to query the enterprise's or organization's digital asset database to obtain related asset information data, thereby determining whether the address or domain name is a legitimate, known internal or cooperative network asset. For addresses or domain names not in the asset database, or even if they are in the asset database but their security still needs to be verified, related threat intelligence information is obtained by calling the API or data interface of the threat intelligence platform to obtain risk and threat information related to the domain name address information.

[0096] S106: Based on the domain name address information, the associated asset information data, and the associated intelligence information data, a large security detection model is used to perform command security detection processing on the target shell command to obtain the shell command security detection result.

[0097] Large-scale security detection model: Security detection tools trained using large-scale pre-trained models (such as large language models) adapted to security detection scenarios can comprehensively analyze command text, context, and additional data to determine whether shell commands have security risks.

[0098] Related asset information data and related intelligence information data: The digital asset and threat intelligence data obtained in the previous steps serve as auxiliary inputs, providing multi-dimensional information background for the model.

[0099] In a schematic representation, domain name address information, associated asset information data, and associated intelligence information data are input as auxiliary information along with the original target shell command into the security detection model. The security detection model utilizes its semantic understanding and contextual reasoning capabilities to comprehensively analyze the multi-dimensional input information. During this comprehensive analysis, the model focuses on keywords in the command (e.g., download tools like "curl" and "wget"), the command execution order, and its interaction characteristics with external networks to obtain a comprehensive analysis result. Based on the comprehensive analysis result, the model calculates a risk score and classification result, and determines whether the command involves malicious behavior, such as illegal downloads, unauthorized data transmission, or potential lateral movement. The security detection model outputs the final shell command security detection result, which may include a classification type, risk level score, and some risk explanation to help security personnel take further action.

[0100] For example, such as Figure 3 As shown, Figure 3 This is a schematic diagram of the security detection results of a shell command. Figure 3 In the process, the security detection model was used to obtain the security detection results of the shell command as shown in the figure. It was determined which are the real domain names and addresses. The security detection results of the shell command indicate that titup-mirrors.pingcap.com is a valid domain name that conforms to the domain name format specification, while topology.yaml is a file name rather than a valid domain name or address.

[0101] In one or more embodiments of this specification, the electronic device extracts domain name address information from the target shell command, determines associated asset information data and associated threat intelligence information based on the domain name address information, and performs command security detection processing on the target shell command using a large-scale security detection model based on the domain name address information, associated asset information data, and associated intelligence information data to obtain the shell command security detection result. By effectively combining and coordinating abnormal command monitoring, asset and threat intelligence query, and the large-scale security detection model, accurate extraction, intelligent filtering, and risk assessment of abnormal shell commands are achieved, which not only significantly reduces the false alarm rate but also improves the ability to identify unknown attacks. At the same time, by combining digital asset information and threat intelligence, comprehensive data support is provided for security detection, thereby greatly enhancing the timeliness and accuracy of overall network security protection.

[0102] Please see Figure 4 , Figure 4 This is a flowchart illustrating an information determination process proposed in this specification. Specifically, the following implementation method can be used to determine the associated asset information data and associated threat intelligence information based on the domain name address information:

[0103] S202: Perform digital asset matching processing on the domain name address information in the digital asset information database to obtain associated asset information data;

[0104] Digital asset matching process: The extracted domain name address information is compared with the records in the digital asset information database to determine whether the address belongs to a known and trusted asset within the enterprise or organization.

[0105] In a schematic way, the domain name address information extracted in S102 is used as input. Through predefined matching rules or algorithms, the input domain name address is matched with the records in the digital asset information database, and the associated asset information data is output. If the match is successful, the corresponding digital asset information is output as "associated asset information data". The associated asset information data reflects the legality and related information of the domain name / IP in the asset database.

[0106] For example, if the extracted domain name is "internal.company.com", and the system finds in the digital asset information database that the domain name may belong to an internal server, then it returns the relevant digital asset data (such as server type, department, IP address, etc.).

[0107] S204: Based on the associated asset information data, the target shell command is verified to obtain a whitelist verification result;

[0108] By comparing the associated asset information data, it is determined whether the domain name / IP involved in the target shell command is a known trusted asset, thereby deciding whether to include the command in the whitelist without conducting further risk assessment.

[0109] As an illustration, using the associated asset information data obtained in S202, according to the preset whitelist policy, it checks whether the domain name / IP extracted from the target shell command appears in the trusted digital asset list. If a trusted asset is matched, a whitelist verification result is generated, and the command is marked as a command within the whitelist, which can usually ignore subsequent security threat queries; otherwise, it is marked as a non-whitelist command and enters the subsequent risk assessment process.

[0110] For example, if the target shell command contains "internal.company.com", and this domain name has been confirmed as a legitimate internal asset in the digital asset information database, the whitelist verification result will be marked as "legitimate / whitelisted", and no further threat queries will be performed on the network address of the command.

[0111] S206: Based on the whitelist verification result, the domain name address information is queried and processed through the threat intelligence platform to obtain associated threat intelligence information.

[0112] Threat intelligence platform: A service platform or system specifically designed to collect, organize, and analyze cybersecurity threat information, providing information such as malicious activity records and risk scores related to domain names, IP addresses, etc.

[0113] Related threat intelligence information: Information obtained by querying non-whitelisted objects regarding potential malicious records, historical attack behaviors, or risk warnings for the domain / IP.

[0114] As an example, based on the whitelist verification results, for domains / IPs not marked as whitelisted, subsequent threat intelligence queries are performed. Using the API or data interface of the threat intelligence platform, the target domain address information is passed in for real-time query. The threat intelligence platform returns threat information related to the domain / IP, such as whether it has been reported for malicious attacks, risk scores, historical security incidents, etc. The threat intelligence information obtained from the query is integrated into "related threat intelligence information" as an important basis for subsequent security detection model judgment.

[0115] This specification utilizes a digital asset database comparison to determine whether a domain name / IP address belongs to a known trusted asset. It verifies the target shell commands using associated asset information data, filtering out legitimate commands from the whitelist to reduce invalid risk detection. Threat intelligence queries are performed on non-whitelisted objects to provide the latest and most comprehensive risk background information for subsequent security testing. This ensures that the security assessment of domain names in target shell commands relies on both internal trusted asset data and external threat intelligence data, achieving more accurate and efficient security detection.

[0116] In one feasible implementation, the step of obtaining associated threat intelligence information by querying the domain name address information through a threat intelligence platform based on the whitelist verification result can be carried out in the following manner:

[0117] If the whitelist verification result is a whitelist record type, then a first shell command security detection result of command security type is generated; if the whitelist verification result is a whitelist unrecorded type, then the domain name address information is queried and processed through the threat intelligence platform to obtain associated threat intelligence information.

[0118] For example, by comparing the domain name address information extracted from the target shell command with the digital asset information database, a whitelist verification result was obtained. This result can be divided into two types:

[0119] Whitelist record type: indicates that the domain name address is recorded in the internal digital asset information database and belongs to a legitimate and trustworthy asset.

[0120] Unrecorded in whitelist: This means that the domain name address was not found in the digital asset information database and its security needs to be further assessed.

[0121] Furthermore, when the whitelist verification result indicates that the domain address belongs to a whitelist record type, the system considers the domain to correspond to a trusted asset and that there is no obvious security threat. It then directly generates a "first-shell command security detection result for command security type" as the output of the security detection. When the whitelist verification result indicates a whitelist-unrecorded type, it means that no corresponding record was found in the internal asset database for the domain address, and its security is currently unclear. Further investigation can be conducted by calling the threat intelligence platform to query and process the domain address information. Through this query, threat intelligence information related to the domain can be obtained, such as whether there are records of malicious activity, historical attack behaviors, or risk scores.

[0122] In the embodiments of this specification, for known and trusted domain names, security is directly determined through whitelist verification, avoiding unnecessary additional queries and false alarms, and achieving accurate filtering; for domain names not in the whitelist, the latest risk information is obtained using a threat intelligence platform, thereby ensuring comprehensive detection of unknown or potential threats; different processing paths are selected according to different whitelist verification results, which can save query resources and ensure the accuracy and real-time nature of the detection results.

[0123] Optional, please refer to Figure 5 , Figure 5 This is a flowchart illustrating a command security detection process. Specifically, it involves using a large-scale security detection model based on the domain name address information, associated asset information data, and associated intelligence information data to perform command security detection on the target shell command, obtaining the shell command security detection result. The following methods can be used as a reference:

[0124] S3002: Based on the target shell command and the domain name address information, a large-scale security detection model is used to identify potential attack command scenarios;

[0125] Potential attack command scenarios: These refer to the attack types or behavioral scenarios that the target shell command may involve, as determined through large-scale model analysis. Examples include "download attack scenario," "privilege escalation attack scenario," "lateral movement attack scenario," and "no attack command scenario." This classification helps to conduct more refined risk detection using corresponding scenario-based prompts.

[0126] In a schematic representation, the target shell command and its extracted domain name address information are integrated into the input data. After receiving the input, the security detection model uses its built-in semantic understanding capabilities to analyze the keywords, operational logic, and domain name information in the command. The model focuses on the command execution flow (e.g., downloading before execution), operation combinations, and special characters or syntax to capture typical command-line patterns. Based on the analysis results, the model identifies potential attack command scenarios that the command may correspond to; for example, if a download command is detected to be closely linked to subsequent execution operations, the model will classify it as a "download attack scenario"; if unreasonable permission operations are detected in the command, it may be classified as a "privilege escalation attack scenario".

[0127] S3004: Based on the potential attack command scenario, obtain the target scenario security prompt word, and based on the target scenario security prompt word, use the domain name address information, the associated asset information data and the associated intelligence information data to control the security detection big model to perform security detection processing to obtain the shell command security detection result.

[0128] Security prompts for specific attack scenarios are pre-designed key prompts or instruction templates used to guide the security detection model to focus on the key characteristics of that scenario and perform security checks according to the corresponding scenario's security detection process. For example, for a "download attack scenario," prompts might include "Please check the legality of the download operation in the command," "Verify whether the target domain name is trustworthy," and "Check whether the downloaded data is executed directly."

[0129] Related asset information data: refers to digital asset information related to the domain name address in the target shell command. This data usually comes from the company's internal asset database and records legitimate internal servers, domain names, IP addresses, etc.

[0130] Related intelligence information data: refers to security intelligence data about domain names or IP addresses obtained through threat intelligence platforms, including malicious records, risk scores, historical attack events, etc., which are used to supplement the judgment of the risk level of the domain name.

[0131] Shell command security detection result: refers to the security status judgment result output by the security detection big model after comprehensive analysis of the target shell command. It can be a classification result (such as "normal", "suspicious", "malicious") or a risk score, with relevant explanations.

[0132] In a schematic manner, after identifying potential attack command scenarios based on the target shell command and the domain name address information using a large-scale security detection model, the model acquires the target scenario security prompt words corresponding to the potential attack command scenarios. This involves pre-storing a mapping relationship between several baseline potential attack command scenarios and their corresponding scenario security prompt words. Based on this mapping relationship, the current target scenario security prompt word can be determined. Then, the large-scale security detection model is controlled using domain name address information, associated asset information data, and associated intelligence information data to perform security detection processing. Guided by the target scenario security prompt words, the model performs detailed analysis in conjunction with the aforementioned multi-dimensional input data. The model not only analyzes the semantics of the commands but also cross-references asset database information and threat intelligence data to confirm the legitimacy and risk of the domain name. This process helps eliminate false alarms that may occur due to simple semantic analysis, such as misjudging legitimate operations as attacks. Based on the comprehensive analysis results, the model outputs the final shell command security detection result. The result can be a direct security status judgment (e.g., "Download attack, high risk") or a detailed explanation with a risk score and recommended measures. Security detection results for shell commands might look like this: "Download attack detected, high risk level. Reason: The downloaded file in the command comes from an unauthorized external domain, and this domain has multiple malicious records in threat intelligence."

[0133] This specification utilizes a large-scale security detection model to perform semantic analysis on target shell commands and domain name address information, automatically identifying potential attack scenarios (such as download attacks and privilege escalation attacks), providing direction for subsequent customized detection and achieving accurate scenario identification. Based on the identified attack scenarios, specially designed target scenario security prompts are used to guide the large-scale model to perform refined detection by combining domain name, asset, and intelligence multi-dimensional information. This method effectively reduces the false positive rate because the large-scale model, under specific scenario prompts, pays more attention to key information and risk characteristics, ensuring that the output detection results are both accurate and highly interpretable. The organic integration of domain name address information, associated asset information, and threat intelligence data provides the large-scale model with comprehensive contextual background, improving the robustness and accuracy of detection. This hierarchical, multi-dimensional security detection process enables the system to quickly and accurately determine whether a command poses a security threat and output clear detection results based on different attack scenarios, helping security personnel make timely response decisions.

[0134] Optional, please see Figure 6 , Figure 6This is a flowchart illustrating a security detection process based on relevant information. Specifically, the process involves using the domain name address information, associated asset information data, and associated intelligence information data, based on the security prompt words of the target scenario, to control a large-scale security detection model to perform security detection and obtain the shell command security detection result. The following methods can be used as a reference:

[0135] S4002: Based on the security prompt words of the target scenario, the domain name address information, the associated asset information data and the associated intelligence information data are used to control the security detection big model to parse the target scenario detection link. The target scenario detection link includes multiple link detection thought steps.

[0136] Target scenario detection chain: refers to a series of logical steps or thought processes constructed to achieve comprehensive security detection under a specific attack scenario. Each "chain detection thought process step" is a detailed analysis of a certain link in the command, thereby gradually deducing the overall security status.

[0137] The link detection thought process consists of each independent detection unit or logical judgment stage in the target scenario detection link. Each step performs a risk assessment on a specific aspect of the command, such as URL validity verification, command combination logic verification, and execution order rationality judgment.

[0138] The system takes multi-dimensional data, including target shell commands, domain name addresses, associated asset information, and associated intelligence information, as input. Simultaneously, based on the identified attack scenario (e.g., a "download attack scenario"), the system invokes preset target scenario security prompts. Guided by these prompts, the security detection model constructs a "target scenario detection chain." This chain comprises multiple detection steps, each responsible for parsing one dimension of the command. For example, in a download attack scenario:

[0139] Step 1: URL inspection: Verify whether the domain name comes from a trusted source or whether there are any anomalies.

[0140] Step 2: Command combination analysis: Check if there is a combination of download and immediate execution in the command.

[0141] Step 3: Context verification: Compare the associated asset information with threat intelligence data to determine whether the command conforms to a known attack pattern.

[0142] Finally, a target scenario detection chain is formed: the security detection big model constructs a complete target scenario detection chain based on the detection thinking steps of each chain, laying a logical foundation for subsequent step-by-step detection. This chain describes how to judge the risk of commands from multiple angles and provides specific detection ideas for each step.

[0143] S4004: Based on the target scenario detection link, the target shell command is subjected to step-by-step security detection processing according to the detection thinking steps of each link through the security detection big model to obtain the shell command security detection result.

[0144] Stepwise security detection and processing: This refers to analyzing and evaluating the target shell commands in detail in stages and sequentially according to the detection steps of each link in the target scenario detection chain, so as to obtain the final security detection result.

[0145] As an illustration, the large-scale security detection model analyzes the target shell command step by step according to the constructed target scenario detection chain, starting from the first step. Each step in the chain will handle one detection dimension separately and output the judgment result for that stage. After each step is completed, the model will integrate the detection results of each step. For example, in a download attack scenario:

[0146] Step 1: Confirm if the domain name is abnormal;

[0147] Step 2: Verify whether there are any risks associated with the command combination;

[0148] Step 3: Compare threat intelligence to confirm the malicious nature of the command commands.

[0149] Furthermore, the results of each step provide a reference for subsequent steps, and the judgment of the entire detection chain is comprehensively evaluated in the final stage.

[0150] Finally, after completing all the link detection steps, the large model outputs the final shell command security detection result based on the comprehensive results of each stage. The result not only indicates the security status of the command, but may also include the risk level, possible attack scenarios, and suggested defense measures.

[0151] Optionally, the potential attack command scenarios include download and execution attack scenarios. The security detection result of the shell command is obtained by performing step-by-step security detection processing on the target shell command through the security detection model based on the target scenario detection link and following the detection thought process of each link. This can be achieved by referring to the following methods:

[0152] The security detection model extracts abnormal shell commands based on the abnormal command extraction steps of the target scene detection link, obtains download execution instructions according to the download instruction extraction steps, and performs abnormal parsing processing on the abnormal shell commands and the download execution instructions according to the abnormal parsing steps to obtain the shell command security detection result.

[0153] Abnormal shell commands: These refer to parts of the target shell command that exhibit unusual or suspicious behavior compared to normal legitimate operations. This typically manifests as command combinations, parameters, or syntax that deviate from normal usage habits. In download execution attack scenarios, this might manifest as download commands being tightly integrated with execution commands, or the appearance of unusual URLs.

[0154] Abnormal command extraction steps: Use a large model to extract command fragments with abnormal features from the target shell commands to be detected, namely the so-called abnormal shell commands.

[0155] Download instruction extraction steps: In the extracted abnormal shell commands, further identify and extract the instruction part that specifically performs the download operation, which is called the download execution instruction.

[0156] Anomaly analysis steps: This refers to the process of using a large-scale security detection model to conduct a detailed analysis of the extracted abnormal shell commands and download execution instructions to determine whether they constitute malicious behavior and the degree of risk.

[0157] For example, the anomaly analysis step is performed first: the target shell command to be detected is taken as input, along with extracted domain name address information and other relevant data. Guided by the target scenario detection chain, the security detection model performs semantic analysis on the entire command, identifying abnormal parts that do not conform to normal operation. Through keywords, syntax patterns, and contextual information, the model marks potentially risky abnormal command fragments, and then focuses on the identified abnormal parts for subsequent targeted analysis. Next, the download instruction extraction step is performed: in the abnormal command, keywords (such as "curl", "wget", etc.) are used to locate the starting position of the download operation. The complete instruction containing the download operation is extracted from the target shell command, including the tool name, parameters, and target URL. The download instruction is treated as an independent analysis object, facilitating comparison with the overall command and subsequent risk analysis. Finally, following the anomaly analysis step, the abnormal shell command and download execution instruction are integrated with other auxiliary data (such as domain name address information, associated asset information, threat intelligence data, etc.) to provide comprehensive context for the large model. Following the detection thought process steps in the target scenario detection chain, the analysis is performed in stages. By combining the analysis results of each stage, the model outputs an overall risk judgment to obtain the shell command security detection result.

[0158] This manual first utilizes security prompts for the target scenario to guide the security detection model in constructing a detection chain for the target scenario. This chain encompasses multiple detection steps, providing multi-dimensional analysis of the target shell command. Then, following the constructed detection chain, each detection step is executed progressively, screening for risks layer by layer. Dedicated prompts and step-by-step detection logic are employed for different attack scenarios to ensure the large model can focus on key information, make accurate judgments based on multi-dimensional data, and significantly reduce the probability of false positives. Finally, the system generates a shell command security detection result, indicating not only the risk level but also providing detailed explanations and suggestions to help security personnel take timely countermeasures. This multi-chain, step-by-step detection strategy fully leverages the semantic understanding and contextual reasoning capabilities of the security detection model, achieving refined detection of complex attack commands and providing strong technical support for network security protection.

[0159] Optional, please refer to Figure 7 , Figure 7 This is a flowchart illustrating a compliance verification process. After extracting the domain name address information from the target shell command, the following methods can also be referenced:

[0160] S5002: Obtain the command context information of the target shell command;

[0161] Command context information refers to the environment and context data of the target shell command, including but not limited to the execution time, user identity, previous and subsequent command records, execution environment (e.g., system, terminal information), and its relationship with other commands. This information helps determine whether the domain name is indeed a network address, rather than some other similar string that has been mistakenly identified.

[0162] As an example, contextual information related to the target shell command is extracted from logs, monitoring systems, or command history. This information is then integrated with execution records before and after the command, environment variables, execution time, user information, etc., to form a complete context data packet. This contextual information serves as input for the security detection model to refer to, helping the model accurately determine whether the extracted domain name address is real and valid.

[0163] S5004: Based on the command context information, the domain name address information is processed for domain name address compliance verification using a large security detection model to obtain a compliance verification result;

[0164] Domain name address information: refers to the network address extracted from the target shell command, such as the domain name in the URL or the direct IP address.

[0165] Domain name address compliance verification processing: This refers to using a large security detection model, combined with contextual information, to perform semantic and format verification on the extracted domain name address to determine whether it is a "real domain name address" or merely similar to the domain name format (such as version number, file name, or other non-network address strings).

[0166] Compliance verification results: The output of the verification generally falls into two categories:

[0167] Real Domain Address Type: Indicates that, after context verification, the string does indeed represent a legitimate domain name or IP address used for network communication.

[0168] Similar domain address type: This indicates that although the string conforms to the domain name format, in the context it may be a version number, file name or other content unrelated to the network address.

[0169] As an illustration, the context information of the target shell command and the extracted domain name address information are input into the security detection model. The security detection model uses its semantic understanding capabilities to check the context and purpose of the string in the command, determine whether there is an actual network interaction intention, and output a compliance verification result based on the analysis, indicating whether the domain name address is "real" or "similar", providing a clear basis for subsequent processing.

[0170] S5006: If the compliance verification result is a real domain name address type, then execute the step of determining the associated asset information data and associated threat intelligence information based on the domain name address information;

[0171] S5008: If the compliance verification result is a similar domain name address type, then the target shell command is ignored.

[0172] Similar domain address type: This indicates that although the string format is similar to the domain name, it may not be used for network communication. For example, it may be a version number, log identifier or other content that does not pose a security risk.

[0173] Ignore detection processing: This refers to directly ignoring subsequent risk assessment and detection for target shell commands that do not have real network addresses in the security detection process, thereby reducing the false alarm rate and avoiding the consumption of unnecessary detection resources.

[0174] As an illustration, based on the S5004 compliance verification results, if the domain name address is determined to be similar, the process enters the ignore handling branch. This can be understood as directly marking the target shell command as requiring no further detection or recording it as low-risk, thus avoiding queries for related assets and threat intelligence. It can also output an ignore result, recording that the command will not be analyzed in this detection, thereby improving overall detection efficiency.

[0175] This specification utilizes command context information to provide rich contextual data for domain name address compliance verification, helping to accurately distinguish between genuine domain names and similar characters. By employing a large-scale security detection model and contextual information, compliance verification of domain names is performed, outputting either "genuine" or "similar" verification results. This ensures that only addresses truly used for network communication proceed to subsequent detection processes. Only genuine domain name addresses are further queried for associated assets and threat intelligence, reducing unnecessary detection steps. S5008 ignores commands with similar domain name address types, effectively reducing false positives and conserving detection resources. This multi-step verification method accurately identifies truly risky network addresses, providing accurate data for subsequent security detection and response, while avoiding unnecessary interference due to format similarity.

[0176] The following will combine Figure 8 This specification provides a detailed description of the shell command detection device based on a large model, as provided in the embodiments. It should be noted that... Figure 8 The shell command detection device based on a large model shown is used to execute the instructions in this specification. Figures 1 to 7 The methods shown in the embodiments are illustrated for ease of explanation, showing only the parts related to the embodiments of this specification. For specific technical details not disclosed, please refer to this specification. Figures 1 to 7 The example shown.

[0177] Please see Figure 8 This diagram illustrates the structure of a shell command detection device based on a large model, as described in an embodiment of this specification. This shell command detection device 1 based on a large model can be implemented as all or part of a user terminal through software, hardware, or a combination of both. According to some embodiments, the shell command detection device 1 based on a large model includes an extraction module 11, a determination module 12, and a detection module 13, specifically used for:

[0178] Extraction module 11 is used to determine the target shell command to be detected and extract domain name address information from the target shell command;

[0179] The determination module 12 is used to determine associated asset information data and associated threat intelligence information based on the domain name address information;

[0180] The detection module 13 is used to perform command security detection processing on the target shell command based on the domain name address information, the associated asset information data and the associated intelligence information data using a security detection big model, and to obtain the shell command security detection result.

[0181] In one feasible implementation, determining the associated asset information data and associated threat intelligence information based on the domain name address information includes:

[0182] The domain name address information is matched with digital assets in the digital asset information database to obtain associated asset information data.

[0183] Based on the associated asset information data, the target shell command is verified to obtain the whitelist verification result;

[0184] Based on the whitelist verification results, the domain name address information is queried and processed through the threat intelligence platform to obtain associated threat intelligence information.

[0185] In one feasible implementation, the step of querying and processing the domain name address information through a threat intelligence platform based on the whitelist verification result to obtain associated threat intelligence information includes:

[0186] If the whitelist verification result is of the whitelist record type, then the first shell command security detection result of the command security type is generated;

[0187] If the whitelist verification result is that the whitelist does not record a certain type, then the related threat intelligence information is obtained by querying and processing the domain name address information through the threat intelligence platform.

[0188] In one feasible implementation, the step of performing command security detection processing on the target shell command using a security detection big data model based on the domain name address information, the associated asset information data, and the associated intelligence information data, to obtain the shell command security detection result, includes:

[0189] Based on the target shell command and the domain name address information, a large-scale security detection model is used to identify potential attack command scenarios;

[0190] Based on the potential attack command scenario, obtain the target scenario security prompt words. Based on the target scenario security prompt words, use the domain name address information, the associated asset information data, and the associated intelligence information data to control the security detection big model to perform security detection processing and obtain the shell command security detection result.

[0191] In one feasible implementation, the step of using the domain name address information, the associated asset information data, and the associated intelligence information data to control a large-scale security detection model based on the target scenario security prompt words to perform security detection processing and obtain the shell command security detection result includes:

[0192] Based on the security prompt words of the target scenario, the domain name address information, the associated asset information data and the associated intelligence information data are used to control the security detection big model to parse the target scenario detection link. The target scenario detection link includes multiple link detection thought steps.

[0193] The security detection model is used to perform step-by-step security detection on the target shell command based on the target scenario detection link and following the detection steps of each link to obtain the shell command security detection result.

[0194] In one feasible implementation, the potential attack command scenarios include download execution attack scenarios.

[0195] The process of performing step-by-step security detection on the target shell command using the security detection model based on the target scenario detection link and following the detection steps of each link to obtain the shell command security detection result includes:

[0196] The security detection model extracts abnormal shell commands based on the abnormal command extraction steps of the target scene detection link, obtains download execution instructions according to the download instruction extraction steps, and performs abnormal parsing processing on the abnormal shell commands and the download execution instructions according to the abnormal parsing steps to obtain the shell command security detection result.

[0197] In one feasible implementation, after extracting the domain name address information from the target shell command, the method further includes:

[0198] Obtain the command context information of the target shell command;

[0199] Based on the command context information, the domain name address information is subjected to domain name address compliance verification processing through a large security detection model to obtain a compliance verification result.

[0200] If the compliance verification result is a real domain name address type, then the step of determining the associated asset information data and associated threat intelligence information based on the domain name address information is executed;

[0201] If the compliance verification result is a similar domain name address type, then the target shell command will be ignored.

[0202] In one feasible implementation, the step of determining the target shell command to be detected includes:

[0203] The system monitors user-executed commands using an abnormal command monitoring system to obtain the target shell commands to be detected.

[0204] It should be noted that the shell command detection device based on a large model provided in the above embodiments is only illustrated by the division of the above functional modules when executing the shell command detection method based on a large model. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the shell command detection device based on a large model and the shell command detection method embodiment provided in the above embodiments belong to the same concept, and the implementation process is detailed in the method embodiment, which will not be repeated here.

[0205] The example numbers in this specification are for descriptive purposes only and do not represent the superiority or inferiority of the examples.

[0206] This specification also provides a computer storage medium that can store multiple instructions adapted to be loaded and executed by a processor as described above. Figures 1 to 7 The shell command detection method based on a large model described in the illustrated embodiment can be found in the following documentation for its specific execution process. Figures 1 to 7 The specific details of the illustrated embodiments will not be elaborated here.

[0207] This specification also provides a computer program product that stores at least one instruction, said at least one instruction being loaded and executed by the processor as described above. Figures 1 to 7 The shell command detection method based on a large model described in the illustrated embodiment can be found in the following documentation for its specific execution process. Figures 1 to 7 The specific details of the illustrated embodiments will not be elaborated here.

[0208] Please refer to Figure 9 This diagram illustrates a structural block diagram of an electronic device provided in an exemplary embodiment of this specification. The electronic device in this specification may include one or more components such as a processor 110, a memory 120, an input device 130, an output device 140, and a bus 150. The processor 110, memory 120, input device 130, and output device 140 may be connected via the bus 150.

[0209] Processor 110 may include one or more processing cores. Processor 110 connects to various parts of the electronic device using various interfaces and lines, and performs various functions and processes data by running or executing instructions, programs, code sets, or instruction sets stored in memory 120, and by calling data stored in memory 120. Optionally, processor 110 may be implemented using at least one hardware form of digital signal processing (DSP), field-programmable gate array (FPGA), or programmable logic array (PLA). Processor 110 may integrate one or more of the following: central processing unit (CPU), graphics processing unit (GPU), and modem. The CPU primarily handles the operating system, user interface, and applications; the GPU is responsible for rendering and drawing the displayed content; and the modem handles wireless communication. It is understood that the modem may also not be integrated into processor 110 and may be implemented separately using a communication chip.

[0210] The memory 120 may include random access memory (RAM) or read-only memory (ROM). Optionally, the memory 120 may include a non-transitory computer-readable storage medium. The memory 120 may be used to store instructions, programs, code, code sets, or instruction sets. The memory 120 may include a program storage area and a data storage area. The program storage area may store instructions for implementing an operating system, instructions for implementing at least one function (such as touch functionality, sound playback functionality, image playback functionality, etc.), instructions for implementing the various method embodiments described below, etc. The operating system may be the Android system, including systems deeply developed based on the Android system, the iOS system developed by Apple Inc., including systems deeply developed based on the iOS system, or other systems. The data storage area may also store data created by the electronic device during use, such as phonebook data, audio and video data, chat log data, etc.

[0211] See Figure 10As shown, the memory 120 can be divided into operating system space and user space. The operating system runs in the operating system space, while native and third-party applications run in the user space. To ensure that different third-party applications can achieve good running performance, the operating system allocates corresponding system resources for each application. However, different application scenarios within the same third-party application have different requirements for system resources. For example, in local resource loading scenarios, third-party applications have high requirements for disk read speed; in animation rendering scenarios, third-party applications have high requirements for GPU performance. Since the operating system and third-party applications are independent of each other, the operating system often cannot promptly perceive the current application scenario of a third-party application, resulting in the operating system's inability to adapt system resources accordingly to the specific application scenario of the third-party application.

[0212] In order for the operating system to distinguish the specific application scenarios of third-party applications, it is necessary to establish data communication between the third-party applications and the operating system. This would allow the operating system to obtain the current scenario information of the third-party applications at any time, and then perform targeted system resource adaptation based on the current scenario.

[0213] Taking the Android operating system as an example, the programs and data stored in memory 120 are as follows: Figure 11As shown, the memory 120 can store the Linux kernel layer 320, the system runtime library layer 340, the application framework layer 360, and the application layer 380. The Linux kernel layer 320, system runtime library layer 340, and application framework layer 360 belong to the operating system space, while the application layer 380 belongs to the user space. The Linux kernel layer 320 provides low-level drivers for various hardware components of the electronic device, such as display drivers, audio drivers, camera drivers, Bluetooth drivers, Wi-Fi drivers, and power management. The system runtime library layer 340 provides support for key features of the Android system through several C / C++ libraries. For example, the SQLite library provides database support, the OpenGL / ES library provides 3D graphics support, and the Webkit library provides browser kernel support. The system runtime library layer 340 also provides the Android runtime library, which mainly provides core libraries that allow developers to write Android applications using the Java language. The Application Framework Layer 360 provides various APIs that may be used when building applications. Developers can also use these APIs to build their own applications, such as activity management, window management, view management, notification management, content provider, package management, call management, resource management, and location management. At least one application runs in the Application Layer 380. These applications can be native applications that come with the operating system, such as contacts, SMS, clock, and camera apps; or third-party applications developed by third-party developers, such as games, instant messaging, and photo editing apps.

[0214] Taking the operating system as an example (iOS), the programs and data stored in memory 120 are as follows: Figure 9As shown, the iOS system includes: Core OS layer 420, Core Services layer 440, Media layer 460, and Cocoa Touch layer 480. Core OS layer 420 includes the operating system kernel, drivers, and low-level program frameworks. These low-level program frameworks provide hardware-level functionality for use by the program frameworks located in Core Services layer 440. Core Services layer 440 provides system services and / or program frameworks required by applications, such as Foundation framework, account framework, advertising framework, data storage framework, network connectivity framework, geolocation framework, motion framework, etc. Media layer 460 provides applications with audiovisual interfaces, such as interfaces related to graphics and images, audio technology, video technology, and AirPlay (wireless playback of audio and video transmission technologies). Cocoa Touch layer 480 provides various commonly used interface-related frameworks for application development and is responsible for user touch interaction on electronic devices. Examples include local notification services, remote push services, advertising frameworks, game tool frameworks, message user interface (UI) frameworks, UIKit frameworks, map frameworks, and so on.

[0215] exist Figure 12 The framework shown includes, but is not limited to, the base framework in the core service layer 440 and the UIKit framework in the touchable layer 480. The base framework provides many basic object classes and data types, offering the most basic system services to all applications, and is independent of the UI. The UIKit framework, on the other hand, provides a basic UI class library for creating touch-based user interfaces. iOS applications can use the UIKit framework to provide their UI, thus providing the application's infrastructure for building user interfaces, drawing, handling user interaction events, responding to gestures, and so on.

[0216] The methods and principles for implementing data communication between third-party applications and the operating system in the iOS system can be found in the Android system, and will not be repeated here.

[0217] The input device 130 is used to receive input instructions or data, and includes, but is not limited to, a keyboard, mouse, camera, microphone, or touch device. The output device 140 is used to output instructions or data, and includes, but is not limited to, a display device and a speaker. In one example, the input device 130 and the output device 140 can be combined into a touch screen, which is used to receive touch operations from the user using a finger, stylus, or any suitable object on or near it, and to display the user interface of various applications. The touch screen is usually located on the front panel of the electronic device. The touch screen can be designed as a full-screen, curved screen, or irregularly shaped screen. The touch screen can also be designed as a combination of a full-screen and a curved screen, or a combination of an irregularly shaped screen and a curved screen; this specification does not limit this aspect.

[0218] In addition, those skilled in the art will understand that the structure of the electronic device shown in the above figures does not constitute a limitation on the electronic device. The electronic device may include more or fewer components than shown, or combine certain components, or have different component arrangements. For example, the electronic device may also include radio frequency circuits, input units, sensors, audio circuits, wireless fidelity (WiFi) modules, power supplies, Bluetooth modules, etc., which will not be described in detail here.

[0219] In the embodiments of this specification, the executing entity for each step can be the electronic device described above. Optionally, the executing entity for each step can be the operating system of the electronic device. The operating system can be Android, iOS, or other operating systems; this specification does not limit this.

[0220] The electronic device described in this specification can also be equipped with a display device. This display device can be any device capable of displaying information, such as a cathode ray tube display (CR), a light-emitting diode display (LED), an e-ink screen, a liquid crystal display (LCD), or a plasma display panel (PDP). Users can use the display device on the electronic device to view displayed text, images, videos, and other information. The electronic device can be a smartphone, tablet computer, gaming device, AR (Augmented Reality) device, automobile, data storage device, audio playback device, video playback device, laptop, desktop computing device, or wearable device such as a smartwatch, smart glasses, smart helmet, smart bracelet, smart necklace, or smart clothing.

[0221] exist Figure 9 In the illustrated electronic device, the processor 110 can be used to call the application program stored in the memory 120 and specifically perform the following operations:

[0222] Determine the target shell command to be detected, and extract the domain name address information from the target shell command;

[0223] Based on the domain name address information, related asset information data and related threat intelligence information are determined;

[0224] Based on the domain name address information, the associated asset information data, and the associated intelligence information data, a large-scale security detection model is used to perform command security detection processing on the target shell command to obtain the shell command security detection result.

[0225] In one feasible implementation, determining the associated asset information data and associated threat intelligence information based on the domain name address information includes:

[0226] The domain name address information is matched with digital assets in the digital asset information database to obtain associated asset information data.

[0227] Based on the associated asset information data, the target shell command is verified to obtain the whitelist verification result;

[0228] Based on the whitelist verification results, the domain name address information is queried and processed through the threat intelligence platform to obtain associated threat intelligence information.

[0229] In one feasible implementation, the step of querying and processing the domain name address information through a threat intelligence platform based on the whitelist verification result to obtain associated threat intelligence information includes:

[0230] If the whitelist verification result is of the whitelist record type, then the first shell command security detection result of the command security type is generated;

[0231] If the whitelist verification result is that the whitelist does not record a certain type, then the related threat intelligence information is obtained by querying and processing the domain name address information through the threat intelligence platform.

[0232] In one feasible implementation, the step of performing command security detection processing on the target shell command using a security detection big data model based on the domain name address information, the associated asset information data, and the associated intelligence information data, to obtain the shell command security detection result, includes:

[0233] Based on the target shell command and the domain name address information, a large-scale security detection model is used to identify potential attack command scenarios;

[0234] Based on the potential attack command scenario, obtain the target scenario security prompt words. Based on the target scenario security prompt words, use the domain name address information, the associated asset information data, and the associated intelligence information data to control the security detection big model to perform security detection processing and obtain the shell command security detection result.

[0235] In one feasible implementation, the step of using the domain name address information, the associated asset information data, and the associated intelligence information data to control a large-scale security detection model based on the target scenario security prompt words to perform security detection processing and obtain the shell command security detection result includes:

[0236] Based on the security prompt words of the target scenario, the domain name address information, the associated asset information data and the associated intelligence information data are used to control the security detection big model to parse the target scenario detection link. The target scenario detection link includes multiple link detection thought steps.

[0237] The security detection model is used to perform step-by-step security detection on the target shell command based on the target scenario detection link and following the detection steps of each link to obtain the shell command security detection result.

[0238] In one feasible implementation, the potential attack command scenarios include download execution attack scenarios.

[0239] The process of performing step-by-step security detection on the target shell command using the security detection model based on the target scenario detection link and following the detection steps of each link to obtain the shell command security detection result includes:

[0240] The security detection model extracts abnormal shell commands based on the abnormal command extraction steps of the target scene detection link, obtains download execution instructions according to the download instruction extraction steps, and performs abnormal parsing processing on the abnormal shell commands and the download execution instructions according to the abnormal parsing steps to obtain the shell command security detection result.

[0241] In one feasible implementation, after extracting the domain name address information from the target shell command, the method further includes:

[0242] Obtain the command context information of the target shell command;

[0243] Based on the command context information, the domain name address information is subjected to domain name address compliance verification processing through a large security detection model to obtain a compliance verification result.

[0244] If the compliance verification result is a real domain name address type, then the step of determining the associated asset information data and associated threat intelligence information based on the domain name address information is executed;

[0245] If the compliance verification result is a similar domain name address type, then the target shell command will be ignored.

[0246] In one feasible implementation, the step of determining the target shell command to be detected includes:

[0247] The system monitors user-executed commands using an abnormal command monitoring system to obtain the target shell commands to be detected.

[0248] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. The storage medium can be a magnetic disk, optical disk, read-only memory, or random access memory, etc.

[0249] The above-disclosed embodiments are merely preferred embodiments of this specification and should not be construed as limiting the scope of this specification. Therefore, any equivalent variations made in accordance with the claims of this specification shall still fall within the scope of this specification.

Claims

1. A shell command detection method based on a large model, characterized in that, The method includes: Determine the target shell command to be detected, and extract the domain name address information from the target shell command; Based on the domain name address information, related asset information data and related threat intelligence information are determined; Based on the domain name address information, the associated asset information data, and the associated intelligence information data, a large-scale security detection model is used to perform command security detection processing on the target shell command to obtain the shell command security detection result.

2. The method according to claim 1, characterized in that, The determination of associated asset information data and associated threat intelligence information based on the domain name address information includes: The domain name address information is matched with digital assets in the digital asset information database to obtain associated asset information data. Based on the associated asset information data, the target shell command is verified to obtain the whitelist verification result; Based on the whitelist verification results, the domain name address information is queried and processed through the threat intelligence platform to obtain associated threat intelligence information.

3. The method according to claim 2, characterized in that, The process of querying and processing the domain name address information through a threat intelligence platform based on the whitelist verification result to obtain associated threat intelligence information includes: If the whitelist verification result is of the whitelist record type, then the first shell command security detection result of the command security type is generated; If the whitelist verification result is that the whitelist does not record a certain type, then the related threat intelligence information is obtained by querying and processing the domain name address information through the threat intelligence platform.

4. The method according to claim 1, characterized in that, The security detection model is used to perform command security detection processing on the target shell command based on the domain name address information, the associated asset information data, and the associated intelligence information data, to obtain the shell command security detection result, including: Based on the target shell command and the domain name address information, a large-scale security detection model is used to identify potential attack command scenarios; Based on the potential attack command scenario, obtain the target scenario security prompt words. Based on the target scenario security prompt words, use the domain name address information, associated asset information data, and associated intelligence information data to control the security detection big model to perform security detection processing and obtain the shell command security detection result.

5. The method according to claim 4, characterized in that, The security detection result of the shell command is obtained by using the domain name address information, the associated asset information data, and the associated intelligence information data to control the security prompt words based on the target scenario and performing security detection processing on the large security detection model, including: Based on the security prompt words of the target scenario, the domain name address information, the associated asset information data and the associated intelligence information data are used to control the security detection big model to parse the target scenario detection link. The target scenario detection link includes multiple link detection thought steps. The security detection model is used to perform step-by-step security detection on the target shell command based on the target scenario detection link and following the detection steps of each link to obtain the shell command security detection result.

6. The method according to claim 5, characterized in that, The potential attack command scenarios include download and execution attack scenarios. The process of performing step-by-step security detection on the target shell command using the security detection model based on the target scenario detection link and following the detection steps of each link to obtain the shell command security detection result includes: The security detection model extracts abnormal shell commands based on the abnormal command extraction steps of the target scene detection link, obtains download execution instructions according to the download instruction extraction steps, and performs abnormal parsing processing on the abnormal shell commands and the download execution instructions according to the abnormal parsing steps to obtain the shell command security detection result.

7. The method according to claim 5, characterized in that, After extracting the domain name address information from the target shell command, the process further includes: Obtain the command context information of the target shell command; Based on the command context information, the domain name address information is subjected to domain name address compliance verification processing through a large security detection model to obtain a compliance verification result. If the compliance verification result is a real domain name address type, then the step of determining the associated asset information data and associated threat intelligence information based on the domain name address information is executed; If the compliance verification result is a similar domain name address type, then the target shell command will be ignored.

8. The method according to claim 1, characterized in that, The command to determine the target shell to be detected includes: The system monitors user-executed commands using an abnormal command monitoring system to obtain the target shell commands to be detected.

9. A shell command detection device based on a large model, characterized in that, The device includes: The extraction module is used to determine the target shell command to be detected and extract domain name address information from the target shell command; The determination module is used to determine associated asset information data and associated threat intelligence information based on the domain name address information; The detection module is used to perform command security detection processing on the target shell command based on the domain name address information, the associated asset information data and the associated intelligence information data using a security detection big model, and obtain the shell command security detection result.

10. An electronic device, characterized in that, include: A processor and a memory; wherein the memory stores a computer program adapted to be loaded by the processor and executed the method steps as claimed in any one of claims 1 to 8.