Big model-based network security alarm intelligent research and judgment and disposal method and system
Patent Information
- Application Number
- CN202610900746.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-22
- Publication Date
- 2026-09-29
AI Technical Summary
然而,现有技术存在以下不足:首先,告警研判过度依赖预定义规则和人工经验,仅能实现基于已知特征的浅层关联,缺乏对告警内容的深度语义理解与生成式推理能力,无法自动还原跨阶段、跨平台的复杂攻击链条,尤其对新型攻击和零日漏洞束手无策
[0015]本发明的有益效果:通过将生成式大模型及其思维链推理引擎嵌入网络安全告警研判与处置全流程,并对多源异构数据进行统一语义化与知识检索增强,从而实现了对复杂攻击链的自动还原与可解释性研判,进而大幅降低了告警误报率和漏报率;通过基于置信度与风险等级的分级自动处置机制,从而兼顾了处置效率与操作安全,进而实现了从告警接入到闭环处置的端到端智能化;通过反馈学习与持续进化机制,从而使系统具备自适应新型威胁的能力,显著提升了网络安全运营的整体效能。
Smart Images

Figure CN122845185A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to a method and system for intelligent analysis and handling of network security alarms based on large models. Background Technology
[0002] Current cybersecurity operations systems primarily rely on Security Information and Event Management (SIEM) and Security Orchestration and Automated Response (SOAR) systems for alert aggregation and incident handling. However, existing technologies have the following shortcomings: First, alert analysis relies excessively on predefined rules and human experience, achieving only shallow correlations based on known features. They lack deep semantic understanding and generative reasoning capabilities for alert content, and cannot automatically reconstruct complex attack chains across stages and platforms, especially in the face of novel attacks and zero-day vulnerabilities. Second, large-scale network environments generate massive amounts of alerts daily, with over 90% being invalid or low-risk. Existing systems lack intelligent noise reduction and prioritization, leading to "alert fatigue" among security operations personnel, and genuine high-risk attacks are easily overlooked. Furthermore, data from diverse and heterogeneous security devices exhibits varying formats and semantic inconsistencies, creating knowledge silos. Traditional SOAR can only execute fixed processes and cannot understand and integrate unstructured information such as threat reports and ticket content, resulting in low levels of automation and requiring manual intervention for critical operations.
[0003] Therefore, there is an urgent need for an intelligent network security alarm processing solution that can integrate multi-source heterogeneous data, possess deep semantic understanding and logical reasoning capabilities, and achieve dynamic adaptive automated processing. Summary of the Invention
[0004] To address the aforementioned technical problems in related technologies, this invention proposes a method and system for intelligent analysis and handling of network security alarms based on a large model, which can overcome the above-mentioned shortcomings of existing technologies.
[0005] To achieve the above-mentioned technical objectives, the technical solution of the present invention is implemented as follows: A method for intelligent analysis and handling of network security alerts based on large models; This intelligent analysis and handling method for network security alerts based on a large model includes the following steps: Step S1: Obtain raw alarm data, preprocess the raw alarm data to generate standardized events, and convert the standardized events into textual descriptions in natural language form; Step S2: The textual description and the related knowledge obtained through knowledge retrieval are used as context input and provided to the generative large model trained on the security domain corpus. Step S3: The generative large model, based on its built-in thought chain reasoning engine, performs multi-step logical reasoning on the input context to generate structured judgment results; the judgment results include: threat level assessment, attack chain description, handling suggestions, model confidence score, and evidence citations supporting the reasoning conclusions; Step S4: Based on the model confidence score in the assessment results and the action risk level corresponding to the proposed action, implement tiered action; the tiered action includes automatic execution, semi-automatic execution, or triggering manual approval; Step S5: Collect and record feedback data from human observers on the assessment results and the effectiveness of the measures taken. Use the feedback data to incrementally fine-tune the generative large model and update the knowledge base used for knowledge retrieval.
[0006] Furthermore, the preprocessing in step S1 includes: unified timestamp calibration, field mapping normalization, deduplication, aggregation, and rule-based intelligent filling of missing fields; the knowledge retrieval includes vector retrieval and graph database query; the vector retrieval is used to obtain historical judgment cases or threat intelligence that are semantically similar to the current alarm from the vector database; the graph database query is used to obtain the relationship path associated with the entity involved in the current alarm from the security knowledge graph.
[0007] Furthermore, the generative large model is obtained in the following way: based on a general large model base with a Decoder-Only architecture, incremental pre-training is performed using multi-source security domain corpus containing historical alarm judgment cases, attack pattern library, threat intelligence, and handling strategies, and instruction fine-tuning is performed using an alarm judgment dataset labeled with thought chains.
[0008] Further, in step S4, a final decision score is calculated to implement tiered treatment. The final decision score is obtained according to the formula final_score=α×model_confidence+β×rule_score+γ×historical_score. Wherein, model_confidence is the model confidence score, rule_score is the score based on preset safety rules, historical_score is the statistical score based on historical similar events, and α, β, and γ are configurable weight coefficients with α+β+γ=1.
[0009] Furthermore, the tiered treatment specifically includes: When the final decision score is greater than or equal to the first threshold, and the action risk level corresponding to the disposal suggestion is low risk, the system will automatically execute the disposal instruction. When the final decision score is greater than or equal to the second threshold and less than the first threshold, the system automatically generates a handling work order and pushes it to the security analyst, waiting for one-click confirmation before execution; When the final decision score is less than the second threshold, the current alarm is added to the manual analysis queue and awaits review by a security analyst.
[0010] Furthermore, after step S4, there is also a step to verify the effect of the treatment: after the executor issues the treatment instruction, it monitors the execution result. If the execution fails or a preset abnormal condition is triggered, the predefined emergency rollback script is automatically invoked.
[0011] According to another aspect of the present invention, a network security alarm intelligent analysis and handling system based on a large model is provided; This intelligent network security alert analysis and handling system based on a large model includes: The data acquisition and preprocessing module is used to acquire and preprocess raw alarm data, and generate standardized events and textual descriptions; The security knowledge base module stores and provides historical analysis cases, threat intelligence, and entity relationship knowledge, including graph databases and vector databases; The generative large model judgment module integrates a thought chain reasoning engine, which is used to generate structured judgment results based on the input textual description and the related knowledge retrieved from the security knowledge base module. The intelligent decision-making and response execution module is used to execute graded responses based on the confidence score and action risk level in the assessment results, and to monitor the response effectiveness. The feedback learning module is used to collect human feedback data and to incrementally fine-tune and update the security knowledge base module for the generative large model judgment module.
[0012] Furthermore, the generative large model judgment module adopts a retrieval-enhanced generative architecture. When performing inference, it first retrieves relevant knowledge from the security knowledge base module based on the input content, and then concatenates the original input with the retrieved knowledge before inputting it into the generative large model for inference.
[0013] Furthermore, the intelligent decision-making and response execution module includes a standardized connector plug-in framework for interacting with heterogeneous security products via API, converting response suggestions into executable instructions for the linked layer security products.
[0014] Furthermore, before executing automated disposal instructions, the intelligent decision-making and disposal execution module performs preset security policy verification, business asset impact assessment, and compliance checks in sequence. Only instructions that pass all verifications are allowed to be executed automatically.
[0015] The beneficial effects of this invention are as follows: By embedding a generative large model and its thought chain reasoning engine into the entire process of network security alarm analysis and handling, and by performing unified semanticization and knowledge retrieval enhancement on multi-source heterogeneous data, the invention achieves automatic reconstruction and interpretability analysis of complex attack chains, thereby significantly reducing the false alarm rate and false negative rate; through a graded automatic handling mechanism based on confidence level and risk level, the invention balances handling efficiency and operational security, thereby achieving end-to-end intelligence from alarm access to closed-loop handling; and through a feedback learning and continuous evolution mechanism, the system is equipped with the ability to adapt to new threats, significantly improving the overall efficiency of network security operations. Attached Figure Description
[0016] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0017] Figure 1 This is an overall architecture diagram of the network security alarm intelligent analysis and handling system based on a large model as described in this invention; Figure 2 This is a flowchart illustrating the intelligent analysis and handling method for network security alarms based on a large model as described in this invention. Figure 3 This is a decision-making flowchart for the intelligent judgment and handling method for network security alarms based on a large model, as described in this invention. Detailed Implementation
[0018] The technical solution of the present invention will be clearly and completely described below with reference to the embodiments. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0019] In the description of this invention, it should be understood that the terms "center," "longitudinal," "lateral," "length," "width," "thickness," "upper," "lower," "front," "rear," "left," "right," "vertical," "horizontal," "top," "bottom," "inner," "outer," "clockwise," and "counterclockwise," etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are used only for the convenience of describing this invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limiting this invention.
[0020] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the stated features. In the description of this invention, "a plurality of" means two or more, unless otherwise explicitly specified. Furthermore, the terms "installed," "connected," and "linked" should be interpreted broadly; for example, they may refer to a fixed connection, a detachable connection, or an integral connection; they may refer to a mechanical connection or an electrical connection; they may refer to a direct connection or an indirect connection through an intermediate medium; and they may refer to the internal connection of two components. Those skilled in the art can understand the specific meaning of the above terms in this invention based on the specific circumstances.
[0021] like Figure 2 and Figure 3 As shown in the embodiment of the present invention, the intelligent judgment and handling method for network security alarms based on a large model includes the following steps: Step S1: Obtain raw alarm data, preprocess the raw alarm data to generate standardized events, and convert the standardized events into textual descriptions in natural language form; Step S2: The textual description and the related knowledge obtained through knowledge retrieval are used as context input and provided to the generative large model trained on the security domain corpus. Step S3: The generative large model, based on its built-in thought chain reasoning engine, performs multi-step logical reasoning on the input context to generate structured judgment results; the judgment results include: threat level assessment, attack chain description, handling suggestions, model confidence score, and evidence citations supporting the reasoning conclusions; Step S4: Based on the model confidence score in the assessment results and the action risk level corresponding to the proposed action, implement tiered action; the tiered action includes automatic execution, semi-automatic execution, or triggering manual approval; Step S5: Collect and record feedback data from human observers on the assessment results and the effectiveness of the measures taken. Use the feedback data to incrementally fine-tune the generative large model and update the knowledge base used for knowledge retrieval.
[0022] According to an embodiment of the present invention, the intelligent analysis and handling method for network security alarms based on a large model, in a specific implementation, the preprocessing in step S1 includes: unified timestamp calibration, field mapping normalization, deduplication, aggregation, and rule-based intelligent filling of missing fields; the knowledge retrieval includes vector retrieval and graph database query; the vector retrieval is used to obtain historical analysis cases or threat intelligence that are semantically similar to the current alarm from the vector database; the graph database query is used to obtain the relationship paths associated with the entities involved in the current alarm from the security knowledge graph.
[0023] According to an embodiment of the present invention, the intelligent judgment and handling method for network security alarms based on a large model is obtained in a specific implementation by obtaining the generative large model in the following way: based on a general large model base with a Decoder-Only architecture, incremental pre-training is performed using multi-source security domain corpus containing historical alarm judgment cases, attack pattern library, threat intelligence, and handling strategies, and fine-tuning of instructions is performed using an alarm judgment dataset labeled with thought chains.
[0024] According to an embodiment of the present invention, in a specific implementation of the intelligent judgment and handling method for network security alarms based on a large model, in step S4, a final decision score is calculated to execute tiered handling. The final decision score is calculated according to the formula final_score=α×model_confidence+β×rule_score+γ×historical_score. Wherein, model_confidence is the model confidence score, rule_score is the score based on preset safety rules, historical_score is the statistical score based on historical similar events, and α, β, and γ are configurable weight coefficients with α+β+γ=1.
[0025] According to an embodiment of the present invention, the intelligent analysis and handling method for network security alarms based on a large model, in a specific implementation, the graded handling specifically includes: When the final decision score is greater than or equal to the first threshold, and the action risk level corresponding to the disposal suggestion is low risk, the system will automatically execute the disposal instruction. When the final decision score is greater than or equal to the second threshold and less than the first threshold, the system automatically generates a handling work order and pushes it to the security analyst, waiting for one-click confirmation before execution; When the final decision score is less than the second threshold, the current alarm is added to the manual analysis queue and awaits review by a security analyst.
[0026] According to an embodiment of the present invention, the intelligent judgment and handling method for network security alarms based on a large model, in a specific implementation, after step S4, a handling effect verification step is also included: after the executor issues the handling instruction, the execution result is monitored. If the execution fails or a preset abnormal condition is triggered, a predefined emergency rollback script is automatically invoked.
[0027] Secondly, such as Figure 1 As shown in the embodiment of the present invention, the intelligent network security alarm analysis and handling system based on a large model includes: The data acquisition and preprocessing module is used to acquire and preprocess raw alarm data, and generate standardized events and textual descriptions; The security knowledge base module stores and provides historical analysis cases, threat intelligence, and entity relationship knowledge, including graph databases and vector databases; The generative large model judgment module integrates a thought chain reasoning engine, which is used to generate structured judgment results based on the input textual description and the related knowledge retrieved from the security knowledge base module. The intelligent decision-making and response execution module is used to execute graded responses based on the confidence score and action risk level in the assessment results, and to monitor the response effectiveness. The feedback learning module is used to collect human feedback data and to incrementally fine-tune and update the security knowledge base module for the generative large model judgment module.
[0028] According to an embodiment of the present invention, the intelligent judgment and handling system for network security alarms based on a large model, in a specific implementation, the generative large model judgment module adopts a retrieval-enhanced generative architecture. When performing reasoning, it first retrieves relevant knowledge from the security knowledge base module based on the input content, and then concatenates the original input with the retrieved knowledge and inputs it into the generative large model for reasoning.
[0029] According to an embodiment of the present invention, the intelligent decision-making and handling system for network security alarms based on a large model, in a specific implementation, includes a standardized connector plug-in framework for interacting with heterogeneous security products via API, and converting handling suggestions into executable instructions of the linked layer security products.
[0030] According to an embodiment of the present invention, in a specific implementation of the intelligent network security alarm analysis and handling system based on a large model, the intelligent decision-making and handling execution module performs preset security policy verification, business asset impact assessment and compliance check in sequence before executing the automated handling instruction. Only instructions that pass all verifications are allowed to be executed automatically.
[0031] To facilitate understanding of the above technical solutions of the present invention, the following detailed description of the above technical solutions of the present invention is provided through specific embodiments and working principles.
[0032] Example 1: System Deployment and Data Access This embodiment deploys the system of the present invention in a medium-sized enterprise Security Operations Center (SOC) environment. The system includes a multi-source alarm data acquisition and access module, a preprocessing and structuring module, a feature extraction and semantic vectorization module, a security knowledge graph and retrieval knowledge base module, a generative large model alarm intelligent judgment core module, an intelligent decision-making and automated handling execution module, a judgment result visualization and interpretability module, and a feedback learning and continuous evolution module.
[0033] First, raw alert logs generated by firewalls, intrusion detection systems (IDS), endpoint detection and response systems (EDR), and web application firewalls (WAF) are collected in real time via the Syslog protocol. Simultaneously, intelligence data is periodically retrieved from the threat intelligence platform (TIP) via a REST API, and unstructured text is read from the historical ticket system. The data acquisition module converts data from different sources into a unified internal message format and assigns a unique event ID and timestamp. This design solves the problem of accessing multi-source heterogeneous data, laying the foundation for subsequent unified processing.
[0034] Example 2: Alarm Preprocessing and Text Conversion Following Example 1, the preprocessing module cleans, deduplicates, synchronizes time, and normalizes fields in the raw alarm data. For example, it maps the "source IP" field from devices from different vendors to "src_ip". Then, the module automatically concatenates structured fields with unstructured message content into natural language sentences, forming a "textual description". For example, a raw alarm is transformed into: "At 10:23:15 on June 12, 2026, host01 (IP: 192.168.1.100) received an SSH login request from external IP 203.0.113.45, which failed 8 times consecutively for a duration of 120 seconds." This textual description allows the generative large model to directly understand the alarm semantics without additional parsing of structured fields, effectively utilizing the natural language understanding capabilities of the pre-trained language model.
[0035] Example 3: Knowledge Retrieval and Context Enhancement The feature extraction module converts the aforementioned textual descriptions into semantic vectors using a tokenizer and embedding model, and calculates the cosine similarity with historical events in the vector database (Milvus), recalling the top-5 most similar handled alert cases and their analysis conclusions. Simultaneously, using the source IP, destination IP, and hostname in the alert as entities, it queries the security knowledge graph in the graph database (Neo4j) to obtain the association paths between entities, such as "203.0.113.45 → malicious domain xyz.com → associated host host02 → previously marked as a C2 server". The retrieved fragments are accompanied by source tags (such as "historical case library" and "threat intelligence"). This Retrieval Enhancement Generation (RAG) mechanism provides rich background knowledge for the large model, compensating for the shortcomings of general models in vertical domain corpora, and significantly improving the accuracy and interpretability of inference.
[0036] Example 4: Large-Scale Model Thinking Chain Reasoning and Structured Input The system commands, the textual description of the current alarm, the retrieved Top-5 historical cases, and the graph relationship paths are concatenated according to a preset Prompt template and then input into a generative large-scale model (based on a Decoder-Only architecture) that has undergone incremental pre-training in the security domain and fine-tuning of the thought chain. The model is required to reason step by step according to the thought chain steps of "attack type identification → attack stage determination → attack chain reconstruction → risk assessment → handling suggestion generation". For example, the model outputs the following structured JSON: { "threat_assessment":{"score":0.94,"label":"critical"}, “attack_chain”:[ {“step”:1,“description”:“External IP 203.0.113.45 performs SSH brute-force attack on host01”,“evidence_ref”:“log_id_12345”}, {“step”:2,“description”:“After a successful brute-force attack, the IP attempted to log in to other hosts on the intranet”,“evidence_ref”:“graph_relation_c2”} ], “recommended_actions”:[ {"action":"block_ip","target":"203.0.113.45","risk":"low","priority":1}, {"action":"isolate_host","target":"host01","risk":"medium","priority":2} ], “model_confidence”:0.92, “explanation”: “This IP has been marked as a known malicious C2 server in historical intelligence, and its behavior is consistent with the attack pattern of lateral movement after brute-force attack, which is highly confident.” } Each conclusion output by the model is accompanied by an evidence citation ID to ensure traceability. This thought chain reasoning mechanism simulates the thought process of a senior security analyst, solving the problem that traditional models cannot perform multi-step causal reasoning.
[0037] Example 5: Hierarchical Automated Processing and Effect Verification The intelligent decision-making module receives the above assessment results and calculates the final decision score: final_score = 0.6 × 0.92 + 0.3 × 0.9 (rule score: the IP has been blacklisted, so it gets 0.9) + 0.1 × 0.95 (95% malicious proportion of similar historical events) = 0.917. This score is greater than the preset first threshold of 0.9, and the recommended "block IP" action has a low risk level, so automatic execution is triggered. The executor sends a blocking command to the firewall via a standardized API and a host isolation command to the EDR. Monitoring results after execution: the firewall returns success, and the EDR returns isolation completed. If execution fails (e.g., API timeout), the system automatically calls the rollback script, restores the firewall policy, and generates an alarm to notify the operations and maintenance personnel. This hierarchical mechanism ensures rapid handling of high-risk threats while avoiding the risk of mishandling through thresholds and approval processes.
[0038] Example 6: Feedback Learning and Model Evolution After the action is completed, security analysts can annotate the assessment on a visual interface: confirming a true positive and indicating a good handling effect. The annotation results, original alerts, model outputs, and execution logs are automatically collected and stored in the training data pool. The system triggers incremental fine-tuning weekly, using newly accumulated annotated data to fine-tune the model using LoRA; simultaneously, the handling case is vectorized and inserted into the vector database, and the entity relationships in the knowledge graph are updated. Before the update, the system undergoes A / B testing in a shadow environment, and only goes live if the new model performs no worse than the old one. This closed-loop self-learning mechanism enables the system to continuously adapt to new attack methods without requiring frequent manual updates to the rule base.
[0039] Example 7: Dialogue-based Assisted Analysis When reviewing semi-automated alert handling, security analysts can input natural language questions through the interactive interface, such as "Why was this alert marked as high-risk?". The generative big data model, based on the context of the current alert and the evidence chain preserved during the reasoning process, returns a readable explanation: "Because the source IP 203.0.113.45 has been marked as an Emotet botnet control node by three different intelligence sources within the past week, and its behavior matches the TA0008 lateral movement technique in the ATT&CK framework." This feature significantly lowers the barrier to manual analysis and improves review efficiency.
[0040] Example 8: Explanation of Alternative Solutions In terms of model architecture, besides the Decoder-Only architecture, an Encoder-Decoder architecture (such as T5) can also be used to achieve the same semantic understanding and generation functions. Regarding the inference mechanism, in addition to the thought chain, a Program-Assisted Language Model (PoT) method can be used, allowing the model to generate pseudocode before performing security analysis. For deployment, model distillation technology can be used to compress large models into lightweight versions and deploy them on edge nodes, enabling collaborative processing between the edge and the cloud to meet the needs of low-latency scenarios. These alternative solutions all fall within the scope of protection of this invention.
[0041] In summary, by employing the technical solutions described above in this invention, and by embedding the generative large model and its thought chain reasoning engine into the entire process of network security alarm analysis and handling, and by unifying semantics and enhancing knowledge retrieval of multi-source heterogeneous data, the system achieves automatic reconstruction and interpretability analysis of complex attack chains, thereby significantly reducing the false alarm rate and false negative rate. Furthermore, through a graded automatic handling mechanism based on confidence level and risk level, both handling efficiency and operational security are balanced, achieving end-to-end intelligence from alarm access to closed-loop handling. Finally, through feedback learning and continuous evolution mechanisms, the system acquires the ability to adapt to new threats, significantly improving the overall efficiency of network security operations.
[0042] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for intelligent analysis and handling of network security alarms based on a large model, characterized in that, Includes the following steps: Step S1: Obtain raw alarm data, preprocess the raw alarm data to generate standardized events, and convert the standardized events into textual descriptions in natural language form; Step S2: The textual description and the related knowledge obtained through knowledge retrieval are used as context input and provided to the generative large model trained on the security domain corpus. Step S3: The generative large model, based on its built-in thought chain reasoning engine, performs multi-step logical reasoning on the input context to generate structured judgment results. The assessment results include: threat level assessment, attack chain description, handling recommendations, model confidence score, and evidence citations supporting the reasoning conclusions; Step S4: Based on the model confidence score in the assessment results and the action risk level corresponding to the proposed action, implement tiered action; the tiered action includes automatic execution, semi-automatic execution, or triggering manual approval; Step S5: Collect and record feedback data from human observers on the assessment results and the effectiveness of the measures taken. Use the feedback data to incrementally fine-tune the generative large model and update the knowledge base used for knowledge retrieval.
2. The method for intelligent analysis and handling of network security alarms based on a large model according to claim 1, characterized in that, The preprocessing in step S1 includes: unified timestamp calibration, field mapping normalization, deduplication, aggregation, and rule-based intelligent filling of missing fields; the knowledge retrieval includes vector retrieval and graph database query; the vector retrieval is used to obtain historical judgment cases or threat intelligence that are semantically similar to the current alarm from the vector database; the graph database query is used to obtain the relationship path associated with the entity involved in the current alarm from the security knowledge graph.
3. The method for intelligent analysis and handling of network security alarms based on a large model as described in claim 1, characterized in that, The generative large model is obtained in the following way: based on a general large model base with a Decoder-Only architecture, incremental pre-training is performed using multi-source security domain corpus containing historical alarm judgment cases, attack pattern library, threat intelligence, and handling strategies, and instruction fine-tuning is performed using an alarm judgment dataset labeled with thought chains.
4. The method for intelligent analysis and handling of network security alarms based on a large model according to claim 1, characterized in that, In step S4, a final decision score is calculated to implement tiered treatment. The final decision score is obtained according to the formula final_score=α×model_confidence+β×rule_score+γ×historical_score. Wherein, model_confidence is the model confidence score, rule_score is the score based on preset safety rules, historical_score is the statistical score based on historical similar events, and α, β, and γ are configurable weight coefficients with α+β+γ=1.
5. The method for intelligent analysis and handling of network security alarms based on a large model according to claim 4, characterized in that, The tiered treatment specifically includes: When the final decision score is greater than or equal to the first threshold, and the action risk level corresponding to the disposal suggestion is low risk, the system will automatically execute the disposal instruction. When the final decision score is greater than or equal to the second threshold and less than the first threshold, the system automatically generates a handling work order and pushes it to the security analyst, waiting for one-click confirmation before execution; When the final decision score is less than the second threshold, the current alarm is added to the manual analysis queue and awaits review by a security analyst.
6. The method for intelligent analysis and handling of network security alarms based on a large model according to claim 1, characterized in that, After step S4, there is also a step to verify the effect of the treatment: after the executor issues the treatment instruction, it monitors the execution result. If the execution fails or a preset abnormal condition is triggered, the predefined emergency rollback script is automatically invoked.
7. A network security alarm intelligent analysis and automated handling system based on generative large models, used to execute the method of any one of claims 1 to 6, characterized in that, include: The data acquisition and preprocessing module is used to acquire and preprocess raw alarm data, and generate standardized events and textual descriptions; The security knowledge base module stores and provides historical analysis cases, threat intelligence, and entity relationship knowledge, including graph databases and vector databases; The generative large model judgment module integrates a thought chain reasoning engine, which is used to generate structured judgment results based on the input textual description and the related knowledge retrieved from the security knowledge base module. The intelligent decision-making and response execution module is used to execute graded responses based on the confidence score and action risk level in the assessment results, and to monitor the response effectiveness. The feedback learning module is used to collect human feedback data and to incrementally fine-tune and update the security knowledge base module for the generative large model judgment module.
8. The intelligent analysis and automated handling system for network security alarms based on generative large models according to claim 7, characterized in that, The generative large model judgment module adopts a retrieval-enhanced generative architecture. When performing inference, it first retrieves relevant knowledge from the security knowledge base module based on the input content, and then concatenates the original input with the retrieved knowledge and inputs it into the generative large model for inference.
9. The intelligent analysis and automated handling system for network security alarms based on generative large models according to claim 7, characterized in that, The intelligent decision-making and response execution module includes a standardized connector plug-in framework, which is used to interact with heterogeneous security products via API and convert response suggestions into executable instructions of the linkage layer security products.
10. The intelligent analysis and automated handling system for network security alarms based on generative large models according to claim 7, characterized in that, Before executing automated disposal instructions, the intelligent decision-making and disposal execution module performs preset security policy verification, business asset impact assessment, and compliance checks in sequence. Only instructions that pass all verifications are allowed to be executed automatically.