Alarm handling method, device, apparatus, medium, and computer program

The alarm handling method automates the analysis process using language models to enhance efficiency and accuracy of cloud security guard products by dividing the analysis into steps and utilizing data query tools, addressing the inefficiencies of human-dependent methods.

JP2025186445APending Publication Date: 2025-12-23BEIJING VOLCANO ENGINE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025156804
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-10-21
Filing Date
2025-09-22
Publication Date
2025-12-23

AI Technical Summary

Technical Problem

Existing cloud security guard products rely heavily on human resources for alarm analysis, leading to reduced efficiency, accuracy, and appropriateness of alarm responses due to the difficulty in obtaining comprehensive alarm analysis results.

Method used

An alarm handling method that divides the analysis process into multiple steps, utilizing a first and a second language model to extract key alarm data, determine query parameters, and automate the analysis process by invoking data query tools, thereby generating multifaceted and accurate results.

Benefits of technology

The method enhances the efficiency and accuracy of alarm analysis by automating the process, improving the security protection capabilities of cloud security products like CWPPs and CSPs through comprehensive and appropriate alarm handling.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025186445000001_ABST
    Figure 2025186445000001_ABST
Patent Text Reader

Abstract

To provide an alarm handling method, a device, an electronic apparatus, a computer-readable storage medium, and a computer program product that improve efficiency of alarm analysis and realize accurate and appropriate alarm handling.SOLUTION: An alarm handling method comprises the steps of: acquiring a first alarm event; determining at least one analysis step of the first alarm event and a data query tool to extract key alarm data; transmitting, for each analysis step, the key alarm data and description information of the data query tool to a first language model, transmitting the first alarm event and related data acquired in each analysis step to the first language model, and receiving an alarm analysis result output by the first language model; and handling, on the basis of the alarm analysis result, the first alarm event.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present application relates to the field of computer technology, and in particular to an alarm handling method, device, electronic device, computer-readable storage medium and computer program. [Background technology]

[0002] With the continuous development of cloud computing technology, cloud security guard products have emerged to perform cloud security detection, which may include products that guard workloads (e.g., virtual machines, containers) in cloud environments, such as cloud security centers and cloud workload protection platforms (CWPPs).

[0003] The cloud security guard product can detect alarm information and generate an alarm event, and the security operator needs to analyze the alarm event and further take alarm action based on the analysis result. Generally, in the process of analyzing the alarm event, the security operator can analyze the alarm data of the alarm information to obtain an alarm analysis result, for example, to identify the cause of the alarm event and determine the scope of the impact of the alarm event, and then take alarm action.

[0004] However, the above method relies heavily on human resources and reduces the efficiency of alarm analysis. At the same time, the method of analyzing alarm data from alarm information makes it difficult to obtain comprehensive alarm analysis results, which reduces the accuracy and appropriateness of alarm responses. Summary of the Invention

[0005] The present application provides an alarm handling method, which can improve the efficiency of alarm analysis and achieve accurate and appropriate alarm handling. The present application also provides an apparatus, an electronic device, a computer-readable storage medium, and a computer program product corresponding to the above method.

[0006] According to a first aspect, the present application provides: Obtaining a first alarm incident; determining at least one analysis step of the first alarm event and a data query tool corresponding to the at least one analysis step to extract key alarm data from the first alarm event; For each analysis step, executing the steps of: sending the key alarm data and description information of a data query tool corresponding to the analysis step to a first language model, and receiving query parameters output by the first language model; and calling the data query tool corresponding to the analysis step based on the query parameters to obtain related data; sending the first alarm event and associated data acquired in each of the analysis steps to the first language model, and receiving an alarm analysis result output by the first language model; and handling the first alarm event based on the alarm analysis result.

[0007] According to a second aspect, the present application provides: an acquisition module for acquiring a first alarm incident; a determination module for determining at least one analysis step of the first alarm event and a data query tool corresponding to the at least one analysis step, and extracting key alarm data from the first alarm event; an analysis module for executing, for each analysis step, the steps of sending the key alarm data and description information of a data query tool corresponding to the analysis step to a first language model and receiving query parameters output by the first language model; and calling the data query tool corresponding to the analysis step based on the query parameters to obtain related data; a communication module for transmitting the first alarm event and related data acquired in each of the analysis steps to the first language model and receiving alarm analysis results output by the first language model; A handling module for handling the first alarm event based on the alarm analysis result is provided, and an alarm handling device having the same is provided.

[0008] According to a third aspect, the present application provides an electronic device comprising a processor and a memory, the processor and the memory being in communication with each other, the processor executing instructions stored in the memory to cause the electronic device to perform the alarm handling method of the first aspect or any embodiment of the first aspect.

[0009] According to a fourth aspect, the present application provides a computer-readable storage medium having stored thereon instructions for causing an electronic device to execute the alarm handling method according to the first aspect or any embodiment of the first aspect above.

[0010] According to a fifth aspect, the present application provides a computer program product comprising instructions which, when executed on an electronic device, cause the electronic device to perform the alarm handling method described in the first aspect or any embodiment of the first aspect above.

[0011] The present application can provide more embodiments by further combining the embodiments according to the above aspects.

[0012] As can be seen from the above technical solutions, the present application has the following advantages:

[0013] The present application provides an alarm handling method, which includes: first obtaining a first alarm event; determining at least one analysis step of the first alarm event and a data query tool corresponding to the at least one analysis step; extracting key alarm data from the first alarm event; in each analysis step, sending the key alarm data and description information of the data query tool corresponding to the analysis step to a first language model; receiving query parameters output by the first language model; and calling the data query tool corresponding to the analysis step based on the query parameters to obtain related data; then sending the first alarm event and the related data obtained in each analysis step to the first language model; receiving alarm analysis results output by the first language model; and handling the first alarm event based on the alarm analysis results.

[0014] The method divides the analysis process for an alarm event into multiple analysis steps, and in each analysis step, key alarm data of the alarm event is used to obtain relevant data related to the alarm event, and the relevant data from each analysis step is used to analyze the alarm event together. The resulting alarm analysis results are more multifaceted and comprehensive, thereby enabling accurate and appropriate alarm handling. Furthermore, the natural language processing capabilities of the language model are utilized to determine query parameters for invoking a data query tool and generate alarm analysis results, thereby automating the analysis process for alarm events, improving the efficiency of alarm analysis, and further enhancing the security protection capabilities of cloud security products such as cloud workload protection platforms (CWPPs), cloud security centers, and container security protection platforms. [Brief explanation of the drawings]

[0015] In order to more clearly describe the technical methods of the embodiments of the present application, the following briefly describes the accompanying drawings necessary for the embodiments.

[0016] [Figure 1]1 is a schematic diagram showing the flow of an alarm handling method according to an embodiment of the present application; [Figure 2] 1 is a schematic diagram showing the flow of an alarm handling method according to an embodiment of the present application; [Figure 3] FIG. 2 is a schematic diagram showing a flow of constructing an alarm database according to an embodiment of the present application. [Figure 4] 1 is a schematic diagram of the structure of an alarm handling device according to an embodiment of the present application; [Figure 5] 1 is a schematic diagram of the structure of an electronic device according to an embodiment of the present application; DETAILED DESCRIPTION OF THE INVENTION

[0017] The terms "first" and "second" in the examples of this application are used for descriptive purposes only and are not to be understood as expressing or implying relative importance or the number of technical features they refer to, whereby a feature qualified by "first" or "second" may explicitly or implicitly include one or more of the feature.

[0018] First, some technical terms and application scenarios related to the embodiments of the present application will be explained.

[0019] With the continuous development of cloud computing technology, cloud security guard products for detecting cloud security have emerged. Cloud security guard products perform multifaceted security detection for various operating scenarios. For example, a cloud security guard product may be a cloud workload protection platform (CWPP), which can detect host machine security and network security. Alternatively, a cloud security guard product may be a host-based intrusion detection system (HIDS), which can detect the security of computer system behavior and status. Alternatively, a cloud security guard product may be an endpoint detection and response (EDR), which can perform security detection for endpoint system-level behavior. Alternatively, a cloud security guard product may be a container security platform (CSP), which can provide multifaceted security detection for containers.

[0020] In specific implementation, the cloud security guard product can detect alarm information and generate an alarm event, after which the security operator can analyze the alarm event and combine the alarm analysis results to handle the alarm.

[0021] In the related art, a security operator analyzes an alarm event using a standard operating procedure (SOP) document. Specifically, the SOP document records historical analysis processes for different alarm events, and the security operator selects a historical analysis process similar to the current alarm event from the SOP document, analyzes the current alarm event according to the historical analysis process, and obtains an alarm analysis result.

[0022] Generally, the alarm analysis of the security operator can be realized by analyzing the alarm data of the alarm information, for example, analyzing the alarm data of the alarm information, identifying the cause of the alarm incident, and determining the scope of the impact of the alarm incident.

[0023] However, the above method relies heavily on human resources and reduces the efficiency of alarm analysis. At the same time, the method of analyzing alarm data from alarm information makes it difficult to obtain comprehensive alarm analysis results, which reduces the accuracy and appropriateness of alarm responses.

[0024] In view of this, the present application provides an alarm handling method, which includes: firstly obtaining a first alarm event; identifying at least one analysis step of the first alarm event and a data query tool corresponding to the at least one analysis step; extracting key alarm data from the first alarm event; for each analysis step, sending the key alarm data and description information of the data query tool corresponding to the analysis step to a first language model; receiving query parameters output by the first language model; and calling the data query tool corresponding to the analysis step based on the query parameters to obtain related data; then sending the first alarm event and the related data obtained in each analysis step to the first language model; receiving the alarm analysis result output by the first language model; and handling the first alarm event based on the alarm analysis result.

[0025] In this method, the analysis process for an alarm event is divided into multiple analysis steps, and in each analysis step, key alarm data of the alarm event is used to obtain relevant data related to the alarm event, and the relevant data in each analysis step is used to analyze the alarm event together. In this way, the obtained alarm analysis results are more multifaceted and rich, and realize accurate and appropriate alarm handling. Furthermore, the natural cause processing ability of the language model is used to determine query parameters for invoking a data query tool and generate alarm analysis results, thereby automating the execution of the analysis process for the alarm event and improving the efficiency of alarm analysis.

[0026] To facilitate understanding of the technical solutions in the embodiments of the present application, the following description will be made with reference to the accompanying drawings.

[0027] Referring to the flow diagram of the alarm handling method according to the embodiment of the present application shown in FIG. 1, the method specifically includes the following steps: S101: Acquire the first alarm event.

[0028] In the embodiments of the present application, the first alarm event can be understood as any alarm event generated by the cloud security guard product. In other words, a user can use the cloud security guard product to detect a computing device or virtual operating environment, and when an abnormality occurs in the computing device or virtual operating environment, the cloud security guard product can generate a first alarm event.

[0029] Generally, the first alarm event may be associated with at least one alarm information, where alarm information may be understood as information related to an anomaly occurring in the computing device or virtual operating environment, such as information related to malware, intrusion, bug, etc.

[0030] In a specific implementation, the first alarm event can be generated based on an alarm rule. Here, the alarm rule can be understood as a rule that generates an alarm event based on alarm information. The cloud security guard product continuously acquires alarm information, and generates a first alarm event when at least one piece of alarm information matches a specific alarm rule.

[0031] In some embodiments, the cloud security guard product may be a software system, for example, the cloud security guard product may be a software system deployed locally or in the cloud, in which case the server for performing alarm handling in accordance with embodiments of the present application may access the cloud security guard product in the form of a plug-in, cloud service, or the like.

[0032] S102: Identify at least one analysis step of the first alarm event and a data query tool corresponding to the at least one analysis step, and extract key alarm data from the first alarm event.

[0033] In the embodiment of the present application, the analysis step may be a step of analyzing the first alarm event. It should be understood that alarm analysis usually has a certain standard process, that is, alarm analysis can be performed according to a certain logical order, and the analysis step may be understood as a step included in the standard process or a step consisting of the logical order.

[0034] The data query tool may be understood as a tool for querying data, for example, software, components, cloud services, etc. In an embodiment of the present application, the data query tool may be used to query relevant data related to the first alarm incident, i.e., the data query tool may be relevant data software, components, cloud services, etc. for querying a computing device or virtual operating environment.

[0035] In the embodiment of the present application, one analysis step may correspond to one data query tool. In other words, in any of the analysis steps, the corresponding data query tool can be used to perform a data query to further obtain related data. Thus, if at least one analysis step of the first alarm event analyzes different dimensions, the corresponding data query tool can be used to obtain related data of different dimensions and different types.

[0036] Generally, alarm events of the same alarm type correspond to the same alarm analysis process. In other words, alarm events of the same alarm type have the same analysis steps and the same data query tools corresponding to each analysis step. Specifically, a target alarm type of a first alarm event is identified, an alarm analysis script corresponding to the target alarm type is executed, and at least one analysis step of the first alarm event and a data query tool corresponding to the at least one analysis step are identified.

[0037] The target alarm type may be understood as the alarm type of the first alarm event, and the alarm analysis script may be understood as a script including at least one analysis step of the alarm event and a data query tool corresponding to the at least one analysis step.

[0038] Here, the term "script" refers to a set of instructions that can be read and executed by a computing device and control the operation of the computing device. That is, the alarm analysis script in the embodiment of the present application includes a set of instructions for dividing the alarm analysis of a target alarm type into different analysis steps and determining data query tools corresponding to the analysis steps, thereby providing an alarm analysis script. By executing the alarm analysis script, at least one analysis step of a first alarm event and a data query tool corresponding to the at least one analysis step can be automatically generated, thereby improving the efficiency and intelligence of alarm analysis.

[0039] In some possible embodiments, the alarm analysis script is obtained by converting a standard operating procedure (SOP) document, where the SOP document is typically written in natural language and records the steps a security operator takes to perform alarm analysis. In other words, the SOP document includes alarm analysis records related to the alarm analysis process.

[0040] In a specific implementation, by obtaining an SOP document and sending the SOP document to a second language model, the second language model identifies an alarm type from the SOP document, extracts analysis steps and determines a data query tool, generates an alarm analysis script, and then receives the alarm analysis script corresponding to the alarm type output by the second language model.

[0041] Here, the second language model has natural language processing capabilities, can understand the meaning of natural language, and can process different types of natural language tasks. For example, the second target model may be a deep learning model trained using text data. In the embodiment of the present application, since the SOP document is expressed in natural language, the natural language processing capabilities of the language model are used to identify and analyze the SOP document, thereby converting the SOP document expressed in natural language into an alarm analysis script that can be read and executed by a computing device.

[0042] The second language model can generate alarm analysis scripts through a prompt learning approach, where prompts can be used to guide the language model to perform specific outputs in generative tasks (e.g., text generation, question answering, and dialogue tasks), and by configuring prompts to help the language model understand the context and needs of the task, the language model can handle different types of natural language processing tasks without retraining the language model, thereby improving the scalability and flexibility of the language model.

[0043] In an embodiment of the present application, the prompt may include instructing the second language model to extract content for extracting analysis steps from the SOP document, for example, the prompt may include instructing the second language model to extract information such as a timestamp, an executing user, an executing operation, platform information, and an operation resource object from the SOP document, and can determine the content of at least one analysis step based on the extracted information. Thus, through the prompt function of the prompt, the second language model can convert the alarm analysis record in the SOP document into at least one analysis step.

[0044] Furthermore, the prompt may further include description information of different data query tools and content instructing the second language model to determine a data query tool corresponding to each analysis step, where the description information of the data query tool may be understood as information describing the function, in parameters, out parameters, etc. for the data query tool. Thus, through the prompt function of the prompt, the second language model can determine a data query tool corresponding to at least one analysis step based on the alarm analysis record in the SOP document, and further obtain an alarm analysis script.

[0045] In some embodiments, the SOP documents are pre-classified based on alarm types. The second language model can identify and analyze SOP documents of different alarm types to generate alarm analysis scripts corresponding to the different alarm types. For example, the SOP documents include SOP document A for alarm type A and SOP document B for alarm type B. The second language model identifies and analyzes SOP document A for alarm type A to generate an alarm analysis script corresponding to alarm type A, and the second language model identifies and analyzes SOP document B for alarm type B to generate an alarm analysis script corresponding to alarm type B.

[0046] In some other embodiments, the SOP document is not pre-classified, i.e., the SOP document includes alarm analysis records for different alarm types. The second language model is used to identify and analyze the SOP document to generate alarm analysis scripts, and then the second language model is used to classify the alarm analysis scripts to obtain alarm analysis scripts corresponding to different alarm types. For example, SOP document A includes alarm analysis records for alarm events of alarm type A and alarm analysis records for alarm events of alarm type B. The second language model is used to identify and analyze SOP document A to generate alarm analysis scripts, and then the second language model is used to classify the alarm analysis scripts according to alarm types to obtain alarm analysis scripts corresponding to alarm type A and alarm analysis scripts corresponding to alarm type B.

[0047] The key alarm data of the first alarm event may be alarm data of at least one piece of alarm information related to the first alarm event. In an embodiment of the present application, the key alarm data may be data corresponding to a key field of the at least one piece of alarm information related to the first alarm event. For example, the key fields may include a detection time field, an operation status field, an impact range field, a detection source field, an account ID field, a security credential name field, a security credential access key (AK) field, a service name field, a service area field, a call interface field, a call interface version field, a requested internet protocol (IP) address field, etc.

[0048] S103: For each analysis step, the following steps are executed: sending key alarm data and description information of a data query tool corresponding to the analysis step to a first language model, and receiving query parameters output by the first language model; and calling the data query tool corresponding to the analysis step based on the query parameters, and obtaining related data.

[0049] After determining at least one analysis step for the first alarm event, each analysis step is automatically executed according to an execution order, and relevant data is obtained in each analysis step.

[0050] In an embodiment of the present application, each analysis step utilizes a first language model to determine query parameters, where the query parameters can be understood as parameter values ​​required to invoke a data query tool. In an embodiment of the present application, the query parameters can be extracted from key alarm data of the first alarm event.

[0051] Here, similar to the second language model, the first language model has natural language processing capabilities, understands the meaning of natural language, and can process different types of natural language tasks. For example, the first target model may be a deep learning model trained using text data.

[0052] Similarly, the first language model can determine the query parameters by a prompting learning method, where the prompt words may include content instructing the first language model to determine the query parameters from the alarm key data in combination with the description information of the data query tool. Thus, through the prompt function of the prompt, the first language model can determine the parameter fields required to invoke the data query tool from the description information of the data query tool and extract query parameters matching the parameter fields from the alarm key data.

[0053] After the first language model outputs the query parameters, the query parameters can be used to invoke a data query tool to obtain relevant data related to the first alarm event. In some embodiments, the first alarm event is related to at least one of a target device, a target account, or a target business. For example, the first alarm event may be an alarm event caused by an abnormality in at least one of the target device, the target account, or the target business. In this case, the relevant data may include at least one of a process log of the target device, an access behavior log of the target account, and business data of the target business.

[0054] That is, the associated data may include data related to the device, account, or business associated with the first alarm incident. The following describes different data query tools. If the data query tool is a tool that queries for security credentials AK using an account name, the query parameters may be the account name and a timestamp. If the data query tool is a tool that queries for security credentials AK using an AK, the query parameters may be the AK and a timestamp. If the data query tool is a tool that queries for security credentials AK using an account ID, the query parameters may be the account ID and a timestamp. If the data query tool is a tool that queries for security credentials AK using an IP address, the query parameters may be the IP address and a timestamp. If the data query tool is a tool that queries for operation logs from a multi-cloud system, the query parameters may be the account ID and a timestamp. If the data query tool is a tool that queries for process logs, the query parameters may be the IP address, the host ID, and a timestamp. If the data query tool is a tool that queries for access behavior logs, the query parameters may be the host ID, the account ID, and a timestamp. If the data query tool is a tool that queries for business data, the query parameters may be the security credentials AK, a business identifier, and a timestamp.

[0055] In this way, different dimensions and types of relevant data can be obtained through different data query tools corresponding to different analysis steps, and by finding more data related to the first alarm incident, the relevant data can then be combined to more accurately identify the cause of the first alarm incident and implement targeted alarm responses.

[0056] S104: Send the first alarm event and related data acquired in each analysis step to a first language model, and receive the alarm analysis result output by the first language model.

[0057] In the embodiment of the present application, after obtaining the related data in each analysis step, the first language model is used to analyze the first alarm event in combination with the related data obtained in each analysis step, and an alarm analysis result is obtained.

[0058] Similarly, the first language model can generate an alarm analysis result by a learning prompting method, where the prompting words may include content instructing the first language model to analyze the first alarm event together with the related data acquired in each analysis step. Thus, through the prompting function of the prompt, the first language model can analyze the related data and at least one alarm information related to the first alarm event together, identify the alarm root cause, determine the root cause of the problem, analyze the alarm trend, and identify noteworthy content to generate an alarm analysis result.

[0059] S105: Handle the first alarm event based on the alarm analysis result.

[0060] By analyzing the first alarm event, an alarm analysis result of the first alarm event can be obtained, and the first alarm event can be dealt with appropriately based on the content of the alarm analysis result.

[0061] In some embodiments, the alarm analysis result may include information for handling the first alarm event, specifically, determining at least one response tool and response parameters corresponding to the at least one response tool based on the alarm analysis result, and then invoking the at least one response tool based on the response parameters to handle the first alarm event.

[0062] That is, the alarm analysis result output by the first language model includes a recommended response method for the first alarm event, specifically providing the response tool required to handle the first alarm event and the response parameters for invoking the response tool. Thus, the response tool invoking the response parameters is used to realize automatic response to the first alarm event, improving the efficiency of alarm response. At the same time, because the alarm analysis result is generated by combining abundant multi-dimensional related data, the alarm response is more accurate.

[0063] In this method, the analysis process for an alarm event is divided into multiple analysis steps, and in each analysis step, key alarm data in the alarm event is used to obtain relevant data related to the alarm event, and the relevant data in each analysis step is used to analyze the alarm event together. Thus, the obtained alarm analysis results are more multifaceted and rich, and realize accurate and appropriate alarm handling. Furthermore, the natural cause processing ability of the language model is used to determine query parameters for invoking a data query tool and generate alarm analysis results, thereby automating the execution of the analysis process for the alarm event, improving the efficiency of alarm analysis, and further improving the security protection capabilities of cloud security products such as cloud workload protection platforms (CWPPs), cloud security centers, and container security protection platforms.

[0064] The alarm handling method according to the embodiment of the present application has been described, and the following description will be given in conjunction with specific scenarios.

[0065] Referring to the schematic diagram showing the flow of the alarm handling method shown in Figure 2, the server for implementing the alarm handling in the embodiment of the present application may include an alarm analyzer and an alarm handler, where the alarm analyzer is used to automatically analyze the alarm event, and the alarm handler is used to automatically handle the alarm event.

[0066] Specifically, the second language model converts the SOP document transformation written in natural language into an alarm analysis script that can be read and executed by a computing device based on the description information of the data query tool, and when a raw first alarm event occurs, the alarm analyzer executes the alarm analysis script corresponding to the target alarm type of the first alarm event and determines at least one analysis step (e.g., analysis step 1, analysis step 2, ...) and a data query tool corresponding to each analysis step.

[0067] For each analysis step, the alarm analyzer calls the first language model, which determines query parameters based on the key alarm data and the description information of the data query tool corresponding to the analysis step, and the alarm analyzer calls the data query tool based on the query parameters to obtain related data. After obtaining the related data of each analysis step, the alarm analyzer calls the first language model, which analyzes the first alarm event based on the related data of each analysis step to generate an alarm analysis result, which may include a response tool and response parameters corresponding to the response tool.

[0068] The alarm analyzer sends the alarm analysis result to the alarm handler, and the alarm handler invokes the corresponding handling tool based on the handling parameters to handle the first alarm event and complete the alarm handling process.

[0069] In some embodiments, the alarm analyzer may also perform alarm analysis by combining historical alarm data, as shown in Figure 2. Specifically, historical alarm data is obtained from an alarm database, where the historical alarm data includes alarm data of alarm events that belong to the same alarm type as the first alarm event and / or alarm data that is similar to key alarm data of the first alarm event.

[0070] Here, the alarm database can be understood as a database containing multiple alarm data in a historical time period. Generally, the alarm data in the alarm database is the alarm for which an alarm response has been performed. In other words, the alarm database may also contain response information for multiple alarm data in a historical time period, and the alarm data in the alarm database can be stored in association with the corresponding response information.

[0071] In the embodiment of the present application, alarm data similar to the first alarm event is selected from the alarm database, such as alarm data of alarm events of the same alarm type or alarm data similar to the key alarm data of the first alarm event. Since the historical alarm data is similar to the first alarm event and alarm handling has been carried out, in the process of performing alarm analysis of the first alarm event, the historical alarm data can also be combined to perform alarm analysis, further enriching the data types and data dimensions.

[0072] In a specific implementation, the first alarm event, the associated data acquired in each analysis step, and the historical alarm data are sent to the first language model, and the alarm analysis result output by the first language model is received. In this case, the prompt may include content instructing the first language model to analyze the first alarm event by combining the associated data acquired in each analysis step and the historical alarm data. Thus, through the prompt function of the prompt, the first language model can analyze the associated data, the historical alarm data, and at least one alarm information related to the first alarm event together to generate an alarm analysis result, thereby improving the accuracy of the alarm analysis.

[0073] The following describes the process of constructing an alarm database. Referring to the schematic diagram of the process of constructing an alarm database shown in Figure 3, first, multiple alarm data are obtained, the multiple alarm data are vectorized, vector expressions corresponding to the multiple alarm data are determined, and an alarm database is constructed based on the vector expressions corresponding to the multiple alarm data.

[0074] Here, vectorization (embedding) can be understood as a process of converting information in a text representation into information in a vector representation. For example, the vectorization can include dividing the text of alarm data, generating alarm data blocks, embedding the alarm data blocks using a vector model, generating vector representations of the alarm data blocks, and storing the vector representations of the alarm data blocks in an alarm database.

[0075] In the embodiment of the present application, alarm data is stored in the alarm database in the form of a vector representation, and when the alarm analyzer searches for historical alarm data from the alarm database, it can realize efficient searching, improve the efficiency of obtaining historical alarm data, and further improve the efficiency of alarm analysis.

[0076] Continuing to refer to FIG. 2, the alarm analyzer can perform alarm analysis of multiple alarm events, and the multiple alarm events can be arranged in the form of an alarm queue, where the alarm queue may include alarm events to be processed in a current alarm handling process, and the current alarm handling process can be understood as an alarm handling process triggered by a first alarm event.

[0077] In a specific implementation, in response to the relevant data hit alarm rule obtained in the at least one analysis step, a second alarm event is generated and the second alarm event is added to the alarm queue.

[0078] That is, in the embodiment of the present application, after the first alarm event occurs, related data can be obtained in any of the analysis steps for analyzing the first alarm event, and the related data obtained in each analysis step can be a new alarm event, and the alarm event generated by the related data can belong to the alarm handling process together with the first alarm event.

[0079] In other words, the alarm queue may include, in addition to the first alarm event, a second alarm event generated by the associated data acquired in each analysis step of the first alarm event, so that the associated data can assist in alarm analysis and automatically detect other alarm events related to the first alarm event, thereby accelerating the operation efficiency of the cloud security guard product and ensuring the safety of the computing device or virtual operating environment.

[0080] Considering that the analysis process for the first alarm event includes a relatively large number of analysis steps, and each analysis step may acquire a relatively large amount of related data, the embodiment of the present application may add a check operation to each analysis step, specifically, refusing to execute the operation of calling the data query tool corresponding to the second analysis step in response to the existence of the data query tool corresponding to the first analysis step being the same as the data query tool corresponding to the second analysis step and the query parameters in the first analysis step being the same as the query parameters in the second analysis step.

[0081] Here, the first analysis step and the second analysis step are any two analysis steps in the current alarm handling process, and the second analysis step is a step after the first analysis step. That is, after the first language model outputs the query parameters, the alarm analyzer determines whether the data query tool and query parameters in the analysis step match those in the analysis step executed in the current alarm handling process. If they match, it means that the related data acquired in the analysis step matches the related data acquired in the analysis step executed in the current alarm handling process, and refuses to invoke the data query tool in the analysis step to acquire the related data, thereby saving computing resources and avoiding repeated acquisition of the related data.

[0082] For example, the analysis of a first alarm event includes analysis step 1 and analysis step 2, where analysis step 1 corresponds to data query tool A, and in analysis step 1, the first language model outputs query parameter A, and the alarm analyzer invokes data query tool A based on the query parameter A to obtain related data A. Analysis step 2 corresponds to data query tool A, and in analysis step 2, the first language model outputs query parameter A, and the alarm analyzer determines that the data query tool corresponding to analysis step 2 is the same as the data query tool corresponding to analysis step 1, and that the query parameters in analysis step 2 are also the same as the query parameters in analysis step 1, so the alarm analyzer does not perform the operation of invoking the data query tool in analysis step 2.

[0083] In some other embodiments, the alarm queue also includes a second alarm event, and after the analysis process of the first alarm event is completed, the alarm analyzer can analyze the second alarm event. The analysis of the second alarm event includes an analysis step 3, where the analysis step 3 corresponds to a data query tool A, and in the analysis step 3, the first language model outputs a query parameter A. Since the alarm analyzer determines that the data query tool corresponding to the analysis step 3 is the same as the data query tool corresponding to the analysis step 1, and that the query parameter in the analysis step 2 is also the same as the query parameter in the analysis step 1, the alarm analyzer does not perform an operation of calling the data query tool in the analysis step 3.

[0084] Furthermore, considering that the same related data can be obtained using different query parameters or different data query tools, the embodiment of the present application can also add a data judgment operation to each analysis step, specifically, discarding the related data obtained in the fourth analysis step in response to the existence of the same related data obtained in the third analysis step and the related data obtained in the fourth analysis step.

[0085] Here, the third analysis step and the fourth analysis step are any two analysis steps in the current alarm handling process, and the fourth analysis step is a step after the third analysis step. That is, after the alarm analyzer invokes a data query tool corresponding to a specific analysis step and obtains the related data of the analysis step, the alarm analyzer determines whether the related data obtained in the analysis step matches the related data obtained in the analysis step executed in the current alarm handling process. If they match, the alarm analyzer discards the related data obtained in the analysis step, that is, it ignores the operation of invoking the data query tool in the analysis step, and can avoid using the same related data to analyze alarm events, and can avoid the same related data from generating the same alarm events, and can prevent the same alarm events from being added to the alarm queue.

[0086] For example, the analysis of a first alarm event includes analysis step 1 and analysis step 2, where analysis step 1 corresponds to data query tool A, in analysis step 1 the first language model outputs query parameter A, and the alarm analyzer invokes data query tool A based on query parameter A to obtain related data A. Analysis step 2 corresponds to data query tool B, in analysis step 2 the first language model outputs query parameter B, and the alarm analyzer invokes data query tool B based on query parameter B to obtain related data A. Since the related data obtained in analysis step 2 is the same as the related data obtained in analysis step 1, the alarm analyzer discards the related data obtained in analysis step 2.

[0087] In some other embodiments, the alarm queue also includes a second alarm event, and after the analysis process of the first alarm event is completed, the alarm analyzer can analyze the second alarm event. The analysis for the second alarm event includes an analysis step 3, where the analysis step 3 corresponds to a data query tool C, in which the first language model outputs query parameters C, the alarm analyzer invokes the data query tool C based on the query parameters C to obtain related data A, and the alarm analyzer determines that the related data obtained in the analysis step 3 is the same as the related data obtained in the analysis step 1, so the alarm analyzer discards the related data obtained in the analysis step 3.

[0088] The alarm handling method according to the embodiment of the present application has been described in detail above with reference to FIGS. 1 to 3. Hereinafter, the apparatus and device according to the embodiment of the present application will be described with reference to the accompanying drawings.

[0089] Referring to the schematic diagram of the structure of the alarm handling device shown in FIG. 4, the device 40 comprises: an acquisition module 401 for acquiring a first alarm event; a determination module 402 for determining at least one analysis step of the first alarm event and a data query tool corresponding to the at least one analysis step, and extracting key alarm data from the first alarm event; an analysis module 403 for performing, for each analysis step, the steps of sending the key alarm data and description information of a data query tool corresponding to the analysis step to a first language model and receiving query parameters output by the first language model; and calling the data query tool corresponding to the analysis step based on the query parameters to obtain related data; a communication module 404 for transmitting the first alarm event and related data acquired in each of the analysis steps to the first language model and receiving alarm analysis results output by the first language model; and a handling module 405 for handling the first alarm event based on the alarm analysis result.

[0090] In some possible embodiments, the determination module 402 may specifically: identifying a target alarm type of the first alarm event; Executing an alarm analysis script corresponding to the target alarm type, and determining at least one analysis step for the first alarm event and a data query tool corresponding to the at least one analysis step.

[0091] In some possible embodiments, the alarm analysis script: Obtaining a standard operating procedure (SOP) document containing an alarm analysis record expressed in natural language; Sending the SOP document to a second language model, causing the second language model to identify alarm types from the SOP document, extract analysis steps, determine data query tools, and generate alarm analysis scripts; receiving an alarm analysis script output by the second language model that corresponds to the alarm type.

[0092] In some possible embodiments, the first alarm event is associated with at least one of a target device, a target account, or a target transaction; The related data includes at least one of a process log of the target device, an access behavior log of the target account, or business data of the target business.

[0093] In some possible embodiments, the device 40 further comprises a generating module, the generating module being generating a second alarm event in response to at least one associated data hit alarm rule obtained in said analyzing step; and adding the second alarm event to an alarm queue containing alarm events to be processed in the current alarm handling process.

[0094] In some possible embodiments, the device 40 further comprises an execution module, the execution module being: This is used to refuse to execute an operation to call a data query tool corresponding to a second analysis step in response to the existence of a data query tool corresponding to a first analysis step being the same as a data query tool corresponding to a second analysis step, and a query parameter in the first analysis step being the same as a query parameter in the second analysis step, where the first analysis step and the second analysis step are any two analysis steps in the current alarm handling process, and the second analysis step is a step subsequent to the first analysis step.

[0095] In some possible embodiments, the execution module further comprises: This is used to discard the related data acquired in the fourth analysis step in response to the existence of the same related data acquired in the third analysis step, where the third analysis step and the fourth analysis step are any two analysis steps in the current alarm handling process, and the fourth analysis step is a step subsequent to the third analysis step.

[0096] In some possible embodiments, the acquisition module 401 further comprises: retrieves, from an alarm database, historical alarm data including alarm data of alarm events that belong to the same alarm type as the first alarm event and / or alarm data that is similar to key alarm data of the first alarm event; Specifically, the communication module 404 includes: It is used to send the first alarm event, the associated data acquired in each of the analysis steps, and the historical alarm data to the first language model, and to receive the alarm analysis result output by the first language model.

[0097] In some possible embodiments, the alarm database comprises: acquiring a plurality of alarm data; performing a vectorization process on the plurality of alarm data to determine a vector representation corresponding to the plurality of alarm data; The method includes constructing an alarm database based on a vector representation corresponding to the plurality of alarm data.

[0098] In some possible embodiments, the remediation module 405 specifically: determining at least one response tool and a response parameter corresponding to the at least one response tool based on the alarm analysis result; and invoking the at least one response tool to handle the first alarm event based on the response parameters.

[0099] The alarm handling device 40 according to the embodiments of the present application may be adapted to execute the methods described in the embodiments of the present application, and each of the above and other operations and / or functions of each module / unit of the alarm handling device 40 is intended to realize the corresponding process of each method in the embodiments shown in Figures 1 to 3, and for the sake of brevity, redundant explanations will not be repeated in this specification.

[0100] The embodiment of the present application further provides an electronic device, which is specifically used to realize the function of the alarm handling device 40 in the embodiment shown in FIG.

[0101] 5 is a schematic diagram of the structure of an electronic device 500. As shown in FIG. 5, the electronic device 500 includes a bus 501, a processor 502, a communication interface 503, and a memory 504. The processor 502, the memory 504, and the communication interface 503 communicate with each other via the bus 501.

[0102] Bus 501 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. Buses can be classified into address buses, data buses, control buses, etc. For ease of representation, FIG. 5 shows only one bold line, but this does not indicate that there is only one bus or only one type of bus.

[0103] The processor 502 may be any one or more of a processor such as a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).

[0104] The communication interface 503 is used for communicating with the outside world. For example, the communication interface 503 can be used for communicating with a terminal.

[0105] The memory 504 may include volatile memory such as random access memory (RAM), and may further include non-volatile memory such as read-only memory (ROM), flash memory, a hard disk drive (HDD), or a solid state drive (SSD).

[0106] Executable code is stored in memory 504 and executed by processor 502 to implement the alarm handling methods described above.

[0107] Specifically, when the embodiment shown in Fig. 4 is implemented and each module or unit of alarm handling device 40 described in the embodiment shown in Fig. 4 is realized by software, the software or program code necessary for the function of each module / unit in Fig. 4, some or all of which can be stored in memory 504, is executed. Processor 502 executes the program code corresponding to each unit stored in memory 504, and performs the alarm handling method described above.

[0108] An embodiment of the present application also provides a computer-readable storage medium. The computer-readable storage medium may be any available medium on which a computing device can store data, or may be a data storage device, such as a data center, that includes one or more available media. The available medium may be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive). The computer-readable storage medium includes instructions for instructing a computing device to perform an alarm handling method that is applied to the alarm handling apparatus 40 described above.

[0109] An embodiment of the present application further provides a computer program product including one or more computer instructions that, when loaded into a computing device and executed, produce, in whole or in part, the processes or functions described in the embodiment of the present application.

[0110] The computer instructions may be stored on a computer-readable storage medium or transmitted from one computer-readable storage medium to another, for example, the computer instructions may be transmitted from one website, computer, or data center to another website, computer, or data center via wire (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, radio, microwave, etc.).

[0111] When the computer program product is executed by a computer, the computer performs any of the above-mentioned alarm handling methods. The computer program product may be a software installation package, and when it is necessary to use any of the above-mentioned alarm handling methods, the computer program product can be loaded and executed on the computer.

[0112] The flowcharts and blocks in the accompanying drawings illustrate possible architectures, functions, and operations of systems, methods, and computer program products according to embodiments of the present application. In this regard, each block in the flowcharts or blocks may represent a module, program segment, or portion of code, which includes executable instructions for implementing one or more predetermined logical functions. It should also be noted that in alternative implementations, the functions shown in the blocks may occur in a different order than that shown in the accompanying drawings. For example, two blocks shown in succession may in fact be executed substantially in parallel, but may also be executed in the reverse order, depending on the functionality involved. It should also be noted that each block in the blocks and / or flowcharts, and combinations of blocks in the blocks and / or flowcharts, may be implemented by a system of dedicated hardware for performing a predetermined function or operation, or by a combination of dedicated hardware and computer instructions.

[0113] The units according to the embodiments of the present application may be implemented in software or hardware, and the names of the units / modules, if any, do not constitute limitations on the units themselves.

[0114] As used herein, the functions described above may be performed at least in part by one or more hardware logic components, for example, illustratively representative types of hardware logic components that may be used include field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), complex programmable logic devices (CPLDs), etc.

[0115] In the context of the embodiments of the present application, a machine-readable medium includes an instruction execution system, apparatus, or device, or a program for use therewith. The machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. The machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the above. More specific examples of machine-readable storage media include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0116] In addition, each embodiment in this specification is described in a step-by-step manner, and each embodiment is described by focusing on the differences from other embodiments, and the same and similar parts of each embodiment can be mutually referenced. The system or apparatus disclosed in the embodiment corresponds to the method disclosed in the embodiment, so the description is relatively simple, and the relevant points can be referenced to the method part.

[0117] It should be understood that, in this application, "at least one" means one or more, and "plurality" means two or more. "And / or" is used to describe an associative relationship between related objects and indicates that three types of relationships may exist; for example, "A and / or B" may indicate that only A is present, only B is present, or both A and B are present, where A and B may be singular or plural. The symbol " / " generally indicates an "or" relationship between related objects. The phrase "at least one of" or similar phrases refers to any combination of these items, such as any combination of singular or plural items. For example, at least one of a, b, and c may refer to a, b, c, "a and b," "a and c," "b and c," or "a, b, and c," where a, b, and c may be singular or plural.

[0118] It should be noted that, in this specification, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another and do not necessarily require or imply the existence of any actual relationship or order between those entities or operations. Furthermore, the terms "comprise," "include," and other variations thereof are intended to cover a non-exclusive inclusion, such that a process, method, article, or device consisting of a set of elements includes not only those elements but also other elements not expressly listed or elements inherent in such process, method, article, or device. Unless further limited, an element limited by the phrase "comprising a..." does not exclude the presence of other identical elements in a process, method, article, or device that includes that element.

[0119] The steps of a method or algorithm described in connection with the embodiments disclosed herein may be implemented using hardware, software modules executed by a processor, or a combination of both. The software modules may be located in random memory (RAM), memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, portable disk, CD-ROM, or any other form of storage medium known in the art.

[0120] Based on the above description of the disclosed embodiments, those skilled in the art will be able to understand or practice the present disclosure. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. Thus, the present application is not intended to be limited to the embodiments described herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. obtaining a first alarm incident; determining at least one analysis step of the first alarm event and a data query tool corresponding to the at least one analysis step to extract key alarm data from the first alarm event; For each analysis step, executing the steps of: sending the key alarm data and description information of a data query tool corresponding to the analysis step to a first language model, and receiving query parameters output by the first language model; and calling the data query tool corresponding to the analysis step based on the query parameters to obtain related data; sending the first alarm event and associated data acquired in each of the analysis steps to the first language model, and receiving an alarm analysis result output by the first language model; and handling the first alarm event based on the alarm analysis result. An alarm handling method characterized by:

2. Determining at least one analysis step of the first alarm event and a data query tool corresponding to the at least one analysis step includes: identifying a target alarm type for the first alarm event; executing an alarm analysis script corresponding to the target alarm type to determine at least one analysis step for the first alarm incident and a data query tool corresponding to the at least one analysis step; 2. The method of claim 1 .

3. The alarm analysis script Obtaining a standard operating procedure (SOP) document containing an alarm analysis record expressed in natural language; sending the SOP document to a second language model, causing the second language model to identify alarm types from the SOP document, extract analysis steps, determine data query tools, and generate alarm analysis scripts; receiving an alarm analysis script output by the second language model that corresponds to the alarm type; 3. The method of claim 2.

4. the first alarm event is associated with at least one of a target device, a target account, or a target transaction; The related data includes at least one of a process log of the target device, an access behavior log of the target account, or business data of the target business; 2. The method of claim 1 .

5. generating a second alarm event in response to at least one associated data hit alarm rule obtained in said analyzing step; adding the second alarm event to an alarm queue containing alarm events to be processed in the current alarm handling process; 5. The method according to claim 1, wherein the first and second electrodes are connected to a first electrode.

6. and further comprising: refusing to execute an operation to invoke the data query tool corresponding to the second analysis step in response to the existence of a data query tool corresponding to the first analysis step being the same as a data query tool corresponding to the second analysis step and a query parameter in the first analysis step being the same as a query parameter in the second analysis step; The first analysis step and the second analysis step are any two analysis steps in the current alarm handling process, and the second analysis step is a step subsequent to the first analysis step.

6. The method of claim 5.

7. further comprising discarding the associated data acquired in the fourth analysis step in response to the associated data acquired in the third analysis step being the same as the associated data acquired in the fourth analysis step; The third analysis step and the fourth analysis step are any two analysis steps in the current alarm handling process, and the fourth analysis step is a step subsequent to the third analysis step.

6. The method of claim 5.

8. The method further includes obtaining historical alarm data from an alarm database, the historical alarm data including alarm data of alarm events that belong to the same alarm type as the first alarm event and / or alarm data that is similar to key alarm data of the first alarm event; transmitting the first alarm event and related data acquired in each of the analysis steps to the first language model and receiving an alarm analysis result output by the first language model; transmitting the first alarm event, the associated data acquired in each of the analyzing steps, and the historical alarm data to the first language model; and receiving an alarm analysis result output by the first language model.

5. The method according to claim 1, wherein the first and second electrodes are connected to a first electrode.

9. The alarm database includes: acquiring a plurality of alarm data; performing a vectorization process on the plurality of alarm data to determine a vector representation corresponding to the plurality of alarm data; constructing an alarm database based on a vector representation corresponding to the plurality of alarm data; 9. The method of claim 8.

10. Handling the first alarm event based on the alarm analysis result includes: determining at least one response tool and a response parameter corresponding to the at least one response tool based on the alarm analysis result; and invoking the at least one response tool to handle the first alarm event based on the response parameters.

5. The method according to claim 1, wherein the first and second electrodes are connected to a first electrode.

11. an acquisition module for acquiring a first alarm event; a determination module for determining at least one analysis step of the first alarm event and a data query tool corresponding to the at least one analysis step, and extracting key alarm data from the first alarm event; an analysis module for executing, for each of the analysis steps, the steps of sending the key alarm data and description information of a data query tool corresponding to the analysis step to a first language model and receiving query parameters output by the first language model; and, based on the query parameters, calling the data query tool corresponding to the analysis step to obtain related data; a communication module for transmitting the first alarm event and related data acquired in each of the analysis steps to the first language model and receiving alarm analysis results output by the first language model; a response module for handling the first alarm event based on the alarm analysis result. An alarm handling device characterized by:

12. An electronic device, A processor and a memory, The processor is adapted to execute instructions stored in the memory to cause the electronic device to perform the method of any one of claims 1 to 10. An electronic device characterized by:

13. comprising instructions for causing an electronic device to carry out the method of any one of claims 1 to 10, A computer-readable storage medium comprising:

14. Comprising computer readable instructions for implementing the method of any one of claims 1 to 10, 1. A computer program product comprising: