Method, apparatus, and device for generating control policy in information system, and medium

The method and apparatus leverage machine learning to generate control policies from natural language input, addressing the complexity of IT operations and maintenance by automating policy generation and optimization in information systems, enhancing efficiency and reducing costs.

JP2025143349APending Publication Date: 2025-10-01BEIJING VOLCANO ENGINE TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2025110183
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-10-16
Filing Date
2025-06-30
Publication Date
2025-10-01

AI Technical Summary

Technical Problem

Effective management of complex information systems requires high-quality IT operations and maintenance, which is challenging due to the need for deep understanding of IT architecture, business processes, and organizational structure, and demands continuous optimization and quick response capabilities.

Method used

A method and apparatus that utilize a machine learning model to generate control policies from natural language input, determining a control policy generation module, and adding the policy to the information system upon user confirmation, enabling efficient policy improvement and optimization without requiring deep technical knowledge.

Benefits of technology

Facilitates quick and easy addition of control policies, improving operational and maintenance efficiency and reducing costs by automating policy generation and optimization in information systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025143349000001_ABST
    Figure 2025143349000001_ABST
Patent Text Reader

Abstract

To provide a method, apparatus and device for generating a control policy, and a computer-readable storage medium.SOLUTION: A method for generating a control policy in an information system comprises: receiving first information input by a user in a natural language, the first information indicating a target rule for managing the information system; determining a first control policy generation module matched with the first information from a plurality of control policy generation modules by utilizing a first machine learning model; and presenting target configuration information generated for a target control policy. The target configuration information is generated using a first control policy generation module. The method includes: indicating a control policy for implementing a target rule; and in response to a received positive indication for the target configuration information, adding a target control policy corresponding to the target rule based on the target configuration information.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] FIELD OF THE INVENTION Exemplary embodiments of the present invention relate generally to the field of computers, and more particularly to methods, apparatus, devices, and computer-readable storage media for generating control policies in information systems. [Background technology]

[0002] With the development of information technology (IT), the development of various industries is becoming increasingly dependent on information systems. Accordingly, the demand for management platforms for information systems is also increasing. For example, in the operation and maintenance of corporate information technology and data security management, various IT tools can be used to formulate management policies, analyze operation and maintenance data, and otherwise translate a company's management system into actual IT capabilities and business support. However, in an increasingly complex network environment, many challenges arise in effective IT operation and maintenance. Therefore, an effective policy generation method is needed to realize information system management. Summary of the Invention

[0003] In a first aspect of the present invention, there is provided a method for generating a control policy in an information system, the method including: receiving first information input in natural language by a user, the first information indicating a target rule for managing the information system; using a first machine learning model to determine a first control policy generation module that matches the first information from a plurality of control policy generation modules, each of the plurality of control policy generation modules being configured to generate configuration information for a different type of control policy; submitting generated targeting configuration information for a target control policy, the targeting configuration information being generated using the first control policy generation module, the target control policy indicating a control policy that implements the target rule in the information system; and, in response to receiving a positive indication for the targeting information, adding a targeted control policy corresponding to the target rule to the information system based on the targeting information.

[0004] In a second aspect of the present invention, there is provided an apparatus for generating a control policy in an information system, the apparatus comprising: a first information receiving module configured to receive first information input in a natural language by a user, the first information indicating a target rule for managing the information system; a control policy generation module determination module configured to determine a first control policy generation module matching the first information from a plurality of control policy generation modules using a first machine learning model, the plurality of control policy generation modules being configured to generate configuration information for different types of control policies; a configuration information submission module configured to submit target configuration information generated for a target control policy, the target configuration information being generated using the first control policy generation module, and the target control policy indicating a control policy that implements the target rule in the information system; and a control policy addition module configured to add a targeted control policy corresponding to the target rule to the information system based on the target configuration information in response to receiving a positive indication for the target configuration information.

[0005] In a third aspect of the present invention, there is provided an electronic device comprising at least one processing unit and at least one memory coupled to the at least one processing unit and storing instructions for execution by the at least one processing unit, the instructions, when executed by the at least one processing unit, causing the device to perform the method of the first aspect.

[0006] In a fourth aspect of the present invention, there is provided a computer-readable storage medium having stored thereon a computer program executable by a processor to implement the method of the first aspect.

[0007] It should be understood that the contents described in the summary of the present invention are not intended to limit the main or important features of the embodiments of the present invention, nor are they intended to limit the scope of the present invention. Other features of the present invention will be readily apparent from the following description. [Brief explanation of the drawings]

[0008] The above-mentioned and other features, advantages, and aspects of the embodiments of the present invention will become more apparent from the following detailed description taken in conjunction with the drawings, in which like or similar reference numerals indicate like or similar elements, and in which:

[0009] [Figure 1] 1 shows a schematic diagram of an exemplary environment in which embodiments of the present invention may be implemented;

[0010] [Figure 2] 1 illustrates a flowchart of an exemplary process for generating control policies in an information system according to some embodiments of the present invention;

[0011] [Figure 3] 1 shows a schematic diagram of an exemplary architecture for generating control policies in an information system according to some embodiments of the present invention;

[0012] [Figure 4] 1 illustrates a flowchart of a process for generating control policies in an information system according to some embodiments of the present invention;

[0013] [Figure 5] 1 shows a block diagram of an apparatus for generating control policies in an information system according to some embodiments of the present invention;

[0014] [Figure 6] 1 shows a block diagram of a device capable of implementing several embodiments of the present invention; DETAILED DESCRIPTION OF THE INVENTION

[0015] Before using the technical solutions disclosed in each embodiment of the present invention, the type, scope and usage scenario of information related to the present invention should be notified to relevant users in an appropriate manner in accordance with relevant laws and regulations, and the consent of relevant users should be obtained.

[0016] For example, in response to receiving an unsolicited request from a user, presentation information may be sent to the relevant user to explicitly indicate to the user that the requested operation requires the acquisition and use of the user's personal information, so that the user can independently choose whether or not to provide the personal information to software or hardware, such as an electronic device, application, server, or storage medium, that performs the operation of the technical solution of the present invention, based on the presentation information.

[0017] In an optional, non-limiting implementation, the method for transmitting the presentation to the user in response to receiving the user's unsolicited request may be, for example, a method using a pop-up window in which the presentation can be displayed in text form, and the pop-up window may further include a selection control for the user to select "agree" or "disagree" to providing personal information to the electronic device.

[0018] It is understood that the notification and user authorization process described above is merely a general outline and is not intended to limit the implementation of the present invention, and that other methods that comply with relevant laws and regulations may also be applied to the implementation of the present invention.

[0019] It is understood that any data related to this technical solution (including but not limited to the data itself, the acquisition of data, or the use of data) should comply with applicable laws and regulations and related specified requirements.

[0020] Hereinafter, the embodiments of the present invention will be described in more detail with reference to the drawings. Although the drawings show specific embodiments of the present invention, it should be understood that the present invention can be realized in various forms and should not be construed as being limited to the embodiments described herein, but rather, these embodiments are provided for a more thorough and complete understanding of the present invention. It should be understood that the drawings and embodiments of the present invention are for illustrative purposes and are not used to limit the protection scope of the present invention.

[0021] It should be noted that any section / subsection headings provided herein are not limiting. Various examples are described throughout this specification, and any type of example may be included in any section / subsection. Additionally, examples described in any section / subsection may be combined in any manner with any other example described in the same section / subsection and / or different sections / subsections.

[0022] In this specification, unless explicitly stated otherwise, performing a step "in response to A" does not mean performing the step immediately after "A," but may include one or more intermediate steps.

[0023] In describing embodiments of the present invention, the term "comprising" and similar terms are intended to be open-ended inclusions, including, but not limited to, the term "based on" should be understood to mean "based at least in part on." The terms "an embodiment" or "the embodiment" should be understood to mean "at least one embodiment." The term "some embodiments" should be understood to mean "at least some embodiments." The following specification may contain explicit and implicit definitions below. Terms such as "first," "second," etc. may refer to different objects or the same object. The following specification may contain explicit and implicit definitions below.

[0024] The term "model" as used herein refers to a model that can learn the association relationship between corresponding inputs and outputs from training data and generate a corresponding output for a given input after training is completed. The generation of the model can be based on machine learning techniques. Deep learning is a type of machine learning algorithm that uses multiple layers of processing units to process inputs and provide corresponding outputs. In this specification, a "model" may be referred to as a "machine learning model," a "machine learning network," or a "network," and these terms are used interchangeably in this specification. One model may include different types of processing units or networks.

[0025] As briefly mentioned above, effective IT operations and maintenance poses many challenges in an increasingly complex network environment. For example, it requires a deep understanding of the company's overall IT architecture, including knowledge of not only technical aspects but also business processes and organizational structure. Accordingly, high-quality IT operations and maintenance requires high-quality personnel, including multidisciplinary personnel with both technical and business understanding. Furthermore, the dynamic IT environment requires continuous optimization and adjustment of operations and maintenance policies, requiring operations and maintenance personnel to have sharp insight and the ability to respond quickly.

[0026] Accordingly, embodiments of the present invention propose a solution for generating a control policy in an information system. According to various embodiments of the present invention, a first information of a target rule for managing an information system input in natural language by a user is received. A first machine learning model is used to determine a first control policy generation module that matches the first information from a plurality of control policy generation modules, each of which is configured to generate configuration information for a different type of control policy. In response, target configuration information is generated for the target control policy, the target configuration information being generated using the first control policy generation module, and the target control policy indicates a control policy that implements the target rule in the information system. Thereafter, if a positive indication is received for the target configuration information, the target control policy corresponding to the target rule is added to the information system based on the target configuration information.

[0027] In an embodiment of the present invention, control policies added by a user expressed in natural language are supported, and machine learning technology is used to convert such control policies expressed in natural language into policies that can be executed in an information system. Using this embodiment of the present invention, a user can add control policies without having a deep understanding of the information system. Furthermore, the user can add policies quickly and easily using natural language. This allows the automatic completion of policy improvement and optimization, thereby improving the operational and maintenance efficiency of the information system and reducing operational and maintenance costs.

[0028] Example Environment

[0029] FIG. 1 illustrates a schematic diagram of an exemplary environment 100 in which an embodiment of the present invention may be implemented. As shown in FIG. 1, the environment 100 may include a system management platform 110. In the exemplary environment 100, the system management platform 110 may be used to manage an information system of an organization (e.g., a business, a government agency, or other entity). Such an information system may include a collection of various hardware, software, networks, data resources, and the like. For example, the information system may include various hardware devices within the organization. Interfaces between different components within the information system and between the information system and the outside world are also part of the information system.

[0030] When information for generating a control policy input in natural language by a user 140 is received, a target model 155 is invoked to determine a control policy generation module, and the control policy can be added to the information system. In this specification, a "module" described with reference to FIGS. 1 to 4 is configured to perform one or more tasks or realize one or more functions. For example, such a module may be an encapsulated functional module that provides an external input interface and an output interface. Such a module may be referred to as a plug-in in this specification.

[0031] In some examples, the system management platform 110 may further determine a control policy by invoking a control policy generation module. The system management platform 110 then adds the control policy to the information system by invoking a control policy addition module. In some cases, the user 140 may be a user who manages control policies using a terminal device, such as an IT administrator of a company.

[0032] In some embodiments, at least some functions of the system management platform 110 may be implemented based on the target model 155. The system management platform 110 may invoke one or more target models 155, such as functions of the target model 155, during the process of adding a control policy to the information system. As used herein, the term "model" refers to a model that learns association relationships between corresponding inputs and outputs from training data and can generate corresponding outputs for a given input after training is completed. The generation of the model may be based on machine learning techniques. Deep learning is a type of machine learning algorithm that uses multiple layers of processing units to process inputs and provide corresponding outputs. A neural network model is an example of a model based on deep learning. In this specification, a "model" may also be referred to as a "machine learning model," a "learning model," a "machine learning network," or a "learning network," and these terms are used interchangeably herein.

[0033] The system management platform 110 may be deployed locally on the user's 140 terminal device and / or supported by a service-side device. For example, a system management platform client may be running on the user's 140 terminal device, and the client may support interaction between the user and the system management platform provided by the service side. When the system management platform is running locally on the user's terminal device, the user 140 may directly use the terminal device to interact with the local system management platform. When the system management platform is running on the service-side device, the service-side device may provide services to the client running on the terminal device based on a communication connection with the terminal device. Based on the user's 140 operation, the system management platform 110 may output system management-related information to the user 140 and / or receive system management-related information from the user 140 by presenting a corresponding interface 142 to the user 140.

[0034] The system management platform 110 may be executed on a suitable electronic device. The electronic device here may be any type of computing-capable device, including a terminal device or a serving device. The terminal device may be any type of mobile, fixed, or portable terminal, including a mobile cell phone, a desktop computer, a laptop computer, a notebook computer, a netbook computer, a tablet computer, a media computer, a multimedia tablet, a personal communication system (PCS) device, a personal navigation device, a personal digital assistant (PDA), an audio / video player, a digital camera / camcorder, a locator device, a television receiver, a radio receiver, an e-book device, a gaming device, or any combination thereof, including accessories, peripherals, or any combination thereof. The serving device may include, for example, a computing system / server, such as a mainframe, an edge computing node, or a computing device in a cloud environment. In some embodiments, the data management platform 110 may be implemented based on cloud services.

[0035] It should be understood that the structure and functionality of environment 100 is described for illustrative purposes only and is not intended to limit the scope of the present invention.

[0036] Some exemplary embodiments of the present invention will now be described with reference to the drawings. The exemplary embodiments will be described below primarily with reference to system management platform 110. It should be understood that the operations described with reference to system management platform 110 may be performed by a control policy generation module and a control policy addition module on system management platform 110, or may be performed by a service side (e.g., server 130) and / or a machine learning model in cooperation with the control policy generation module and the control policy addition module.

[0037] The policy generation solution of the present invention will now be described with reference to Figures 2 and 3. Figure 2 shows a flow chart of an exemplary process 200 for a control policy generation module and a control policy addition module according to some embodiments of the present invention. Figure 3 shows a schematic diagram of an exemplary architecture 300 for a control policy generation module and a control policy addition module according to some embodiments of the present invention.

[0038] In box 211, the system management platform 110 receives first information input in natural language by a user. The first information indicates target rules for managing an information system, for example, rules for managing an information technology system (IT system) input by a user (which may also be referred to as an administrator). In some examples, the system management platform 110 receives the natural language input by the user, for example, natural language corresponding to a company's security management system, IT management system, or problem scenario that the company's IT administrator wants to solve, which the user specifically needs to implement.

[0039] In some embodiments, the system management platform 110 uses a first machine learning model to determine a first control policy generation module that matches the first information from a plurality of control policy generation modules. In some embodiments, the plurality of control policy generation modules are configured to generate configuration information for different types of control policies. It will be understood that the system management platform 110 uses the first machine learning model to determine a user's intention and determines a first control policy generation module (which may also be referred to as a policy generation plug-in) from the plurality of control policy generation modules for generating different types of pre-configured control policies based on the user's intention. For example, when the system management platform 110 uses the first machine learning model to determine that the administrator's intent category is "resolve through an IT system platform policy item that can implement the configuration information," the first machine learning model can invoke a policy generation plug-in that matches the current administrator's intent category.

[0040] In some examples, an administrator can pre-configure each type of policy corresponding to each control policy generation module. For example, if a security policy needs to be generated, the system management platform 110 can call a security control policy generation module. If a network access policy needs to be generated, the system management platform 110 can call a network access control policy generation module. In some examples, a plug-in can constrain a model according to the configuration information to which the policy is converted.

[0041] In some embodiments, the system management platform 110 may further determine a first control policy generation module that matches the first information from the plurality of control policy generation modules in the following manner: As shown in FIG. 2 , in process 200, in box 212, the system management platform 110 obtains search results that match the first information by searching at least one knowledge base related to management of information systems based on the first information. In box 213, the system management platform 110 determines the first control policy generation module from the plurality of control policy generation modules based on the search results using a first machine learning model.

[0042] In some embodiments, the at least one knowledge base may include a knowledge base about the general technology of the information system, such as an information technology knowledge base. Alternatively or additionally, the at least one knowledge base may include a knowledge base about the management of the organization to which the information system belongs, such as an enterprise management system knowledge base. Alternatively or additionally, the at least one knowledge base may include a knowledge base about history management policies adopted by the information system, such as a history policy database. Alternatively or additionally, the at least one knowledge base may further include a knowledge base about how to reference policy settings, such as a knowledge base about policy setting methods.

[0043] As shown in the exemplary architecture 300, the system management platform 110 receives specific requirements for a policy that needs to be generated, input by a user (311). The system management platform 110 sends a request to the machine learning model to query a target policy based on first information input by the user (312). Based on the first information, the machine learning model searches related knowledge backgrounds through knowledge bases including an IT technology knowledge base, an enterprise management system knowledge base, historical policy data, and policy setting methods, and determines search results to improve the understanding of the IT background knowledge.

[0044] The machine learning model then analyzes and summarizes the search results to determine a first control policy generation module for generating a policy. The machine learning model sends an invocation request to the system management platform 110 for the first control policy generation module that needs to be invoked (313). After receiving the invocation request, the system management platform 110 invokes the first control policy generation module (314). Thus, the system management platform 110 receives initial targeting information for the target policy generated by the first control policy generation module (315).

[0045] Therefore, an embodiment of the present invention analyzes an enterprise's IT management system, IT technology knowledge base, and historical system platform policy data knowledge base, and based on the condition logic of time, event data, and processing means, decomposes the enterprise's IT management methods for terminals, security, etc. into configuration parameters corresponding to the system platform. Accordingly, the configuration parameters can be provided to the administrator for reference, thereby reducing the need for the enterprise administrator to understand the IT technology background and historical enterprise solution implementation experience. This method improves the work efficiency of enterprise administrators during daily IT operation and maintenance.

[0046] 2 and 3, the process by which system management platform 110 determines targeting information will now be described. It will be appreciated that the operations described with respect to system management platform 110 may be performed by a control policy generation module.

[0047] Continuing with process 200, in box 214, the system management platform 110 converts the first information into description information having a predetermined logic by the first control policy generation module invoking the second machine learning model. The system management platform 110 determines targeting information based on the description information and corresponding parameters of the information system. In some examples, the second machine learning model and the first machine learning model may be the same machine learning model, e.g., a language model, and the present invention is not limited thereto. In some examples, the first control policy generation module can utilize the second machine learning model to convert the first information entered by the user into description information with a predetermined logic, such as "when X occurs, if X data situation is encountered, perform X action." The system management platform 110 then converts the description information into configuration information based on system parameters supported by the information system.

[0048] In some embodiments, the predetermined logic may include conditional logic, and the explanatory information may include a first portion corresponding to a condition of the conditional logic and a second portion corresponding to an action of the conditional logic. For example, the first portion corresponding to the condition of the conditional logic may be expressed as "and," and the second portion corresponding to the action of the conditional logic may be expressed as "does."

[0049] In some embodiments, the system management platform 110 uses a first control policy generation module to determine prompt information for a second machine learning model, where the prompt information includes trigger condition information, and the trigger condition information indicates multiple trigger conditions of a target type policy corresponding to the first control policy generation module. The system management platform 110 then uses a second machine learning model to generate explanation information based on the prompt information and the first information. The first portion indicates a target trigger condition among the multiple trigger conditions. For example, for a rule related to office security, the second machine learning model can rewrite and optimize the rule to make the information expressed clearer. The generation of prompt information is described below with reference to Table 1, which is an example of prompt information.

[0050] [Table 1] TIFF2025143349000003.tif168170

[0051] It will be understood that the system management platform 110, via the first control policy generation module, utilizes a second machine learning model to convert the first information into explanatory information having a logical relationship. In some embodiments, the second machine learning model can convert the first information into explanatory information having a logical relationship based on prompt information. In some embodiments, the prompt information includes trigger condition information, which is used to indicate multiple trigger conditions of a control policy of a target type corresponding to the first control policy generation module. As shown in Table 1, the third row of the prompt information indicates examples of multiple trigger conditions. In some embodiments, the multiple trigger conditions may be pre-set by a user.

[0052] In some examples, the second machine learning model can select a target trigger condition from the plurality of trigger conditions based on the description information. For example, if the second machine learning model determines that information input by a user corresponds to a rule related to office security, it can determine a trigger condition from the plurality of trigger conditions that matches the rule. In some embodiments, the second machine learning model can select at least one trigger condition from the plurality of trigger conditions that matches the description information based on the description information. Thereafter, the second machine learning model further analyzes and compares the at least one trigger condition to determine a target trigger condition.

[0053] In some embodiments, the system management platform 110 retrieves search results matching the first information by searching at least one knowledge base related to management of information systems based on the first information. The system management platform 110 can then determine a plurality of trigger conditions from the search results. In some examples, the first control policy generation module can utilize a second machine learning model in combination with a knowledge base of policy configuration methods to convert information entered by a user into a logical relationship based on "when X, if X data condition is encountered, perform X action."

[0054] In some embodiments, the prompt information may further include an explanation and an example of how to convert the natural language input into a conversion task. For example, as shown in Table 1, lines 5 to 9 of the prompt information indicate Skill 1, which is used by the machine learning model. That is, the machine learning model can understand the information entered by the user and rewrite the sentence in the form of "... and...".

[0055] In some embodiments, the prompt information may further include a selection rule for selecting a trigger condition from multiple trigger conditions. For example, as shown in Table 1, lines 11 to 13 of the prompt information indicate skill 2 used by the machine learning model. That is, the machine learning model selects at least one trigger condition that best matches the first information based on the rewritten rule description. Then, in combination with the rule description, the selected at least one trigger condition is compared and analyzed, and the most appropriate trigger condition is selected as the target trigger condition.

[0056] In some embodiments, the prompt information may further include constraints for the conversion task. For example, as shown in Table 1, lines 15 to 17 of the prompt information indicate constraint information used to constrain the machine learning model. That is, the machine learning model is constrained to select a recommended trigger setting from multiple trigger conditions provided by the user, and must not generate non-existent trigger conditions based on the text.

[0057] In some embodiments, the prompt information includes action information, the action information including a plurality of control actions of a target-type control policy, and the second part indicates a target management action among the plurality of management actions. In some examples, the prompt information may interpret the first information entered by a user and rewrite the sentence expression format into the form of "... and...". For example, in the example "If a non-company device accesses the network, its network privileges are downgraded", the rewritten result may be "If the device is not a company device, its network privileges are downgraded". It will be understood that the generation process of the target management action can refer to the generation process of the target trigger condition, and the present invention will not be repeated here.

[0058] In some embodiments, the system management platform 110 submits targeting information generated for the target control policy. The targeting information is generated using a first control policy generation module, and the target control policy indicates a control policy that implements the target rule in the information system. In some examples, the system management platform 110 can submit the configuration information for the target control policy generated via the first control policy generation module. It will be appreciated that the system management platform 110 can implement the control policy of the target rule in the information system.

[0059] In some embodiments, if the system management platform 110 receives a positive indication for the targeting information, it adds a target control policy corresponding to the target rule based on the targeting information. Continuing with process 200, in box 215, after receiving the targeting information output by the machine learning model, the system management platform 110 submits the targeting information and determines whether the targeting information meets the user's expectations. In box 216, if the system management platform 110 receives a user's decision for the targeting information, it invokes a policy addition plug-in. In box 217, the system management platform 110 invokes a policy addition plug-in to add a control policy corresponding to the target rule.

[0060] In some embodiments, the system management platform 110 can add a targeted control policy corresponding to a targeted rule to an information system in the following manner: When the system management platform 110 receives a positive instruction from a user, it extracts configuration parameters from the targeted configuration information. The system management platform 110 uses a control policy addition module to convert the configuration parameters into interface parameters of a targeted interface in the information system. The system management platform 110 then uses the control policy addition module to add the interface parameters to the targeted interface as a targeted control policy.

[0061] In some examples, if the system management platform 110 receives a positive indication, it calls a control policy addition module to add the target control policy. The control policy addition module (which may also be referred to as a control policy addition plug-in) can convert the configuration parameters in the target configuration information into interface parameters of a target interface included in the information system (e.g., a POST request) and then call the target interface in the information system. The control policy addition module can then add the target control policy to the information system based on the interface parameters of the target interface and return the addition result to the system management platform 110.

[0062] 3 , the system management platform 110 sends initial targeting information for the targeting rules generated via the targeting rule generation module to the machine learning model (316). It will be appreciated that the first control policy generation module converts the initial targeting information into explanatory information having logical relationships using the machine learning model. The machine learning model then sends the explanatory information (i.e., policy content) having logical relationships to the system management platform 110 (317).

[0063] The system management platform 110 presents (318) targeting information corresponding to the explanatory information having the logical relationship to a client device corresponding to the user. When the system management platform 110 receives (319) a confirmation addition instruction from the user client device, it sends (320) the confirmation instruction to the machine learning model. The system management platform 110 then receives (321) a request sent by the machine learning model to invoke a control policy addition module and extracts parameters. In some examples, the control policy addition module can be used to add a control policy to an information system.

[0064] The system management platform 110 invokes the policy addition module based on the request and parameters for invoking the control policy addition module (322). In response, the system management platform 110 receives the result returned by the control policy addition module (323). The system management platform 110 sends the result returned by the control policy addition module to the machine learning model (324). The system management platform 110 receives the text returned by the machine learning model (325) and sends the text to the client device corresponding to the user (326). The text is used to notify the user of the result of the control policy addition, such as whether the control policy addition was successful or failed.

[0065] In summary, the present invention can improve business response efficiency by combining policy analysis and transformation with a control policy generation module. Furthermore, as more control policy generation modules for different information systems are built and more historical control policy data knowledge bases are built and accumulated, the system can complete information system management solutions more intelligently and accurately.

[0066] Example Process

[0067] 4 shows a flowchart of a process 400 for generating control policies in an information system according to some embodiments of the present invention. Process 400 may be implemented in system management platform 110. Process 400 is described below with reference to FIG. 1.

[0068] In box 410, the system management platform 110 receives first information entered by a user in natural language, the first information indicating target rules for managing the information system.

[0069] In box 420, the system management platform 110 uses a first machine learning model to determine a first control policy generation module that matches the first information from a plurality of control policy generation modules, each of the plurality of control policy generation modules being configured to generate configuration information for a different type of control policy.

[0070] In box 430, the system management platform 110 submits targeting information generated for the target control policy, where the targeting information is generated using a first control policy generation module, and the target control policy indicates a control policy that implements the target rule in the information system.

[0071] At box 440, in response to receiving a positive indication for the targeting information, the system management platform 110 adds a targeted control policy to the information system that corresponds to the targeted rule based on the targeting information.

[0072] In some embodiments, determining a first control policy generation module from the plurality of control policy generation modules that matches the first information includes: searching at least one knowledge base related to management of information systems based on the first information to obtain search results that match the first information; and determining the first control policy generation module from the plurality of control policy generation modules based on the search results using a first machine learning model.

[0073] In some embodiments, the at least one knowledge base includes at least one of a knowledge base regarding the general technology of the information system, a knowledge base regarding the management of the organization to which the information system belongs, a knowledge base regarding history management policies adopted by the information system, and a knowledge base regarding how to reference policy settings.

[0074] In some embodiments, the targeting information is generated by the first control policy generation module invoking a second machine learning model to convert the first information into explanatory information having a predetermined logic, and determining the targeting information based on the explanatory information and corresponding parameters of the information system.

[0075] In some embodiments, the predetermined logic includes conditional logic, and the explanatory information includes a first portion corresponding to a condition of the conditional logic and a second portion corresponding to an operation of the conditional logic, and converting the first information into explanatory information having the predetermined logic includes: determining prompt information for the second machine learning model using a first control policy generation module, wherein the prompt information includes trigger condition information, and the trigger condition information indicates a plurality of trigger conditions of a control policy of a target type corresponding to the first control policy generation module; and generating explanatory information using the second machine learning model based on the prompt information and the first information, wherein the first portion indicates a target trigger condition among the plurality of trigger conditions.

[0076] In some embodiments, the prompt information further includes one of an explanation and example of converting the natural language input to a conversion task of the explanation information, a selection rule for selecting a trigger condition from a plurality of trigger conditions, and a constraint of the conversion task.

[0077] In some embodiments, the plurality of trigger conditions are determined by searching at least one knowledge base related to management of information systems based on the first information to obtain search results that match the first information, and determining the plurality of trigger conditions from the search results.

[0078] In some embodiments, the prompt information includes action information, the action information indicating a plurality of control actions of a policy of a target type, and the second portion indicating a target management action of the plurality of control actions.

[0079] In some embodiments, adding a targeted control policy corresponding to the target rule to the information system based on the target configuration information includes, in response to an affirmative indication, extracting configuration parameters from the target configuration information, converting the configuration parameters into interface parameters of the target interface in the information system using a control policy addition module, and adding the interface parameters to the target interface as a targeted control policy using the control policy addition module.

[0080] Exemplary Apparatus and Devices

[0081] 5 shows a schematic configuration block diagram of an apparatus 500 for generating control policies in an information system according to a specific embodiment of the present invention. The apparatus 500 may be implemented as or included in the system management platform 110. Each module / component in the apparatus 500 may be implemented by hardware, software, firmware, or any combination thereof.

[0082] As shown in the figure, the apparatus 500 includes an information receiving module 510 configured to receive first information input in natural language by a user, the first information indicating a target rule for managing an information system. The apparatus 500 further includes a control policy generation module determination module 520 configured to determine a first control policy generation module matching the first information from a plurality of control policy generation modules using a first machine learning model, the plurality of control policy generation modules being configured to generate configuration information for different types of control policies. The apparatus 500 further includes a configuration information submission module 530 configured to submit target configuration information generated for a target control policy, the target configuration information being generated using the first control policy generation module, the target control policy indicating a control policy for implementing the target rule in the information system. The apparatus 500 further includes a control policy addition module 540 configured to add a target control policy corresponding to the target rule to the information system based on the target configuration information in response to receiving a positive indication for the target configuration information.

[0083] In some embodiments, the control policy generation module determination module 520 is further configured to: search at least one knowledge base related to management of information systems based on the first information to obtain search results matching the first information; and determine a first control policy generation module from the plurality of control policy generation modules based on the search results using a first machine learning model.

[0084] In some embodiments, the at least one knowledge base includes at least one of a knowledge base regarding the general technology of the information system, a knowledge base regarding the management of the organization to which the information system belongs, a knowledge base regarding history management policies adopted by the information system, and a knowledge base regarding how to reference policy settings.

[0085] In some embodiments, the targeting information is generated by the first control policy generation module invoking a second machine learning model to convert the first information into explanatory information having a predetermined logic, and determining the targeting information based on the explanatory information and corresponding parameters of the information system.

[0086] In some embodiments, the predetermined logic includes conditional logic, and the explanatory information includes a first portion corresponding to a condition of the conditional logic and a second portion corresponding to an operation of the conditional logic; and the apparatus 500 further includes an explanatory information determination module configured to: determine prompt information for the second machine learning model using the first control policy generation module, the prompt information including trigger condition information, the trigger condition information indicating a plurality of trigger conditions of a control policy of a target type corresponding to the first control policy generation module; and generate the explanatory information using the second machine learning model based on the prompt information and the first information, the first portion indicating a target trigger condition of the plurality of trigger conditions.

[0087] In some embodiments, the prompt information further includes one of an explanation and example of converting the natural language input to a conversion task of the explanation information, a selection rule for selecting a trigger condition from a plurality of trigger conditions, and a constraint of the conversion task.

[0088] In some embodiments, the plurality of trigger conditions are determined by searching at least one knowledge base related to management of information systems based on the first information to obtain search results that match the first information, and determining the plurality of trigger conditions from the search results.

[0089] In some embodiments, the prompt information includes action information, the action information indicating a plurality of control actions of a policy of a target type, and the second portion indicating a target management action of the plurality of control actions.

[0090] In some embodiments, the control policy addition module 540 is further configured to, in response to the affirmative indication, extract configuration parameters from the target configuration information, convert the configuration parameters using the control policy addition module into interface parameters of the target interface in the information system, and add the interface parameters to the target interface as a target control policy using the control policy addition module.

[0091] 6 illustrates a block diagram of an electronic device 600 capable of implementing one or more embodiments of the present invention. It should be understood that the electronic device 600 illustrated in FIG. 6 is exemplary only and should not be construed as limiting the functionality and scope of the embodiments described herein. The electronic device 600 illustrated in FIG. 6 may be used to implement the system management platform 110 of FIG. 1.

[0092] 6, electronic device 600 is a form of general-purpose electronic device. Components of electronic device 600 may include, but are not limited to, one or more processors or processing units 610, memory 620, storage device 630, one or more communication units 640, one or more input devices 650, and one or more output devices 660. Processing unit 610 may be a real or virtual processor and may perform various processes based on programs stored in memory 620. In a multiprocessor system, multiple processing units execute computer-executable instructions in parallel, thereby increasing the parallel processing capabilities of electronic device 600.

[0093] The electronic device 600 typically includes a plurality of computer storage media. Such media may be any obtainable media accessible by the electronic device 600, including, but not limited to, volatile and nonvolatile media, removable and non-removable media. The memory 620 may be volatile memory (e.g., registers, high-speed cache, random access memory (RAM)), non-volatile memory (e.g., read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory), or some combination thereof. The storage device 630 may be removable or non-removable media and may include machine-readable media, such as a flash memory drive, a magnetic disk, or any other medium that may be used to store information and / or data and that may be accessible within the electronic device 600.

[0094] The electronic device 600 may further include other removable / non-removable, volatile / non-volatile storage media. Although not shown in FIG. 6, a magnetic disk drive for reading from or writing to a removable, non-volatile magnetic disk (e.g., a "floppy disk") and an optical disk drive for reading from or writing to a removable, non-volatile optical disk may be provided. In these cases, each drive may be connected to a path (not shown) by one or more data medium interfaces. The memory 620 may include a computer program product 625 having one or more program modules configured to perform various methods or operations of various embodiments of the present invention.

[0095] The communication unit 640 facilitates communication with other computing devices over a communication medium. Additionally, the functionality of the components of the electronic device 600 may be implemented as a single computing cluster or multiple computing machines, which can communicate over a communication connection. Thus, the electronic device 600 can operate in a networked environment using logical connections to one or more other servers, network personal computers (PCs), or other network nodes.

[0096] The input device(s) 650 may be one or more input devices such as a mouse, keyboard, trackball, etc. The output device(s) 660 may be one or more output devices such as a display, speakers, printer, etc. The electronic device 600 may further communicate with one or more external devices (not shown) such as a storage device, a display device, etc. via the communication unit 640, as needed, to communicate with one or more devices that allow a user to interact with the electronic device 600, or any device (e.g., a netbook card, a modem, etc.) that allows the electronic device 600 to communicate with one or more other computing devices. Such communication may be performed via an input / output (I / O) interface (not shown).

[0097] An exemplary implementation according to the present invention provides a computer-readable storage medium having computer-executable instructions stored thereon, which are executed by a processor to implement the above-described method.An exemplary implementation according to the present invention further provides a computer program product, the computer program product including computer-executable instructions tangibly stored on a non-transitory computer-readable medium, which are executed by a processor to implement the above-described method.

[0098] Aspects of the present invention are described herein with reference to flowchart and / or block diagrams of methods, apparatus, devices and computer program products implemented by the present invention. It will be understood that each box in the flowchart and / or block diagrams, and combinations of boxes in the flowchart and / or block diagrams, may be implemented by computer-readable program instructions.

[0099] These computer-readable program instructions may be provided to a processing unit of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus to generate a machine that, when executed by the processing unit of the computer or other programmable data processing apparatus, generates an apparatus for implementing the functions / acts specified in one or more boxes in the flowcharts and / or block diagrams. These computer-readable program instructions may be stored on a computer-readable storage medium such that the instructions cause the computer, programmable data processing apparatus, and / or other device to operate in a particular manner such that the computer-readable medium on which the instructions are stored configures an article of manufacture containing instructions that implement each aspect of the functions / acts specified in one or more boxes in the flowcharts and / or block diagrams.

[0100] The computer-readable program instructions, when loaded into a computer, other programmable data processing apparatus, or other device, cause the computer, other programmable data processing apparatus, or other device to perform a series of operational steps to produce a computer-implemented process, such that the instructions executing on the computer, other programmable data processing apparatus, or other device implement the functions / acts specified in one or more boxes in the flowcharts and / or block diagrams.

[0101] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to the present invention. In this regard, each box in a flowchart or block diagram may represent a module, program segment, or portion of instructions, which includes one or more executable instructions for implementing the specified logical function(s). In some alternative implementations, the functions depicted in the boxes may occur in a different order than depicted in the figures. For example, two consecutive boxes may actually be executed substantially in parallel, or may be executed in the reverse order, depending on the functionality involved. It should also be noted that each box in the block diagrams and / or flowcharts, and combinations of boxes in the block diagrams and / or flowcharts, may be implemented by a special-purpose hardware-based system that performs the specified functions or operations, or by a combination of special-purpose hardware and computer instructions.

[0102] Although various implementations of the present invention have been described above, the above descriptions are illustrative and not exhaustive, and are not limited to the various implementations disclosed. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the various implementations described. The terminology used herein is intended to best interpret the principles, practical applications, or improvements to commercially available technologies of the various implementations, or to enable those skilled in the art to understand the various implementations disclosed herein.

Claims

1. 1. A method for generating a control policy in an information system, comprising: receiving first information input in natural language by a user, the first information indicating a target rule for managing an information system; Using a first machine learning model, determine a first control policy generation module that matches the first information from a plurality of control policy generation modules, wherein each of the plurality of control policy generation modules is configured to generate configuration information for a different type of control policy; submitting generated targeting information for a targeted control policy, the targeting information being generated using the first control policy generation module, the targeted control policy indicating a control policy that implements the targeted rule in the information system; and in response to receiving a positive indication for the targeting information, adding the targeting control policy corresponding to the targeting rule to the information system based on the targeting information. method.

2. Determining a first control policy generation module that matches the first information from a plurality of control policy generation modules includes: searching at least one knowledge base related to management of the information system based on the first information to obtain search results matching the first information; determining the first control policy generation module from the plurality of control policy generation modules based on the search results using the first machine learning model; The method of claim 1.

3. The at least one knowledge base a knowledge base regarding the general purpose technology of said information system; a knowledge base relating to the management of the organization to which said information system belongs; a knowledge base regarding the history management policies employed by said information system; and Knowledge base on how to view policy settings, at least one of: The method of claim 2.

4. The targeting information includes: The first control policy generation module converts the first information into explanatory information having a predetermined logic by calling a second machine learning model; determining the targeting information based on the description information and corresponding parameters of the information system; The method of claim 1.

5. the predetermined logic includes conditional logic, and the description information includes a first portion corresponding to a condition of the conditional logic and a second portion corresponding to an operation of the conditional logic; converting the first information into explanatory information having a predetermined logic, determining prompt information for the second machine learning model using the first control policy generation module, the prompt information including trigger condition information, the trigger condition information indicating a plurality of trigger conditions for a control policy of a target type corresponding to the first control policy generation module; generating the explanation information using the second machine learning model based on the prompt information and the first information, wherein the first portion indicates a target trigger condition among the plurality of trigger conditions; The method of claim 4.

6. The prompt information comprises: A description and example of how to convert a natural language input into the description information; a selection rule for selecting a trigger condition from the plurality of trigger conditions; and Constraints of the transformation task; further comprising one of: The method of claim 5.

7. The plurality of trigger conditions include: searching at least one knowledge base related to management of the information system based on the first information to obtain search results matching the first information; determining the plurality of trigger conditions from the search results. The method of claim 5.

8. the prompt information includes operation information, the operation information indicating a plurality of control actions of a control policy of the target type, and the second part indicating a target management action among a plurality of management actions; The method of claim 5.

9. adding the target control policy corresponding to the target rule to the information system based on the target setting information, extracting configuration parameters from the target configuration information in response to the affirmative indication; Utilizing a control policy addition module to convert the configuration parameters into interface parameters of a target interface in the information system; and adding the interface parameters to the target interface as the target control policy using the control policy addition module. The method of claim 1.

10. a first information receiving module configured to receive first information input by a user in a natural language, the first information indicating a target rule for managing an information system; and a control policy generation module determination module configured to determine a first control policy generation module that matches the first information from a plurality of control policy generation modules using a first machine learning model, the plurality of control policy generation modules being configured to generate configuration information for different types of control policies; and a configuration information submission module configured to submit target configuration information generated for a target control policy, the target configuration information being generated using the first control policy generation module, and the target control policy being a control policy capable of implementing the target rule in the information system; and a control policy addition module configured to, in response to receiving a positive indication for the targeting information, add the targeted control policy corresponding to the targeting rule to the information system based on the targeting information. A device for policy generation.

11. at least one processing unit; at least one memory coupled to the at least one processing unit and configured to store instructions executed by the at least one processing unit, The instructions, when executed by the at least one processing unit, cause the electronic device to perform the method of any one of claims 1 to 9. electronic equipment.

12. A computer program executable by a processor to implement the method according to any one of claims 1 to 9 is stored on the device. A computer-readable storage medium.

Citation Information

Patent Citations

  • Workflow circulation control method and device and electronic equipment

    CN114968334A

  • Method, device, medium and program product for information interaction

    CN118568343A

  • Strategy recommendation method, device and system, electronic equipment and readable medium

    CN118760543A

  • Authoring context aware policies with intelligent suggestions

    US20240069700A1