Alert analysis method, server, and storage medium
Through the security model, the security alarms in cloud computing scenarios are automatically analyzed, and combined with real-time and private knowledge bases, the problem of poor accuracy of manual analysis is solved, and the accuracy and efficiency of security alarm analysis is improved.
Patent Information
- Application Number
- PCT/CN2024/115444
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-27
- Filing Date
- 2024-08-29
- Publication Date
- 2025-07-03
AI Technical Summary
In the prior art, security alarm analysis relies on manual analysis, and has poor accuracy and is difficult to effectively deal with potential security threats in cloud computing scenarios.
The security model is used to plan the target security alarm, call relevant tools to perform alarm information processing operations, and analyze it in combination with real-time knowledge base and private knowledge base to generate accurate alarm analysis results.
It realizes automatic reply to security alarm-related questions, reduces manual dependence, improves the accuracy and efficiency of security alarm analysis, and is suitable for cloud computing security protection systems.
Smart Images

Figure CN2024115444_03072025_PF_FP_ABST
Abstract
Description
Alarm analysis method, server and storage medium
[0001] This disclosure claims priority to the Chinese patent application filed with the China Patent Office on December 27, 2023, with application number 202311836157.3 and application name “Alarm Analysis Method, Server and Storage Medium,” the entire contents of which are incorporated by reference in this disclosure. Technical Field
[0002] The present disclosure relates to the field of computer technology, and in particular to an alarm analysis method, a server, and a storage medium. Background Art
[0003] Security alerts (also known as threat alerts) are common warnings or notifications in information security scenarios. Typically, security alerts are generated by security systems or tools after they detect potential security threats or unusual activity. For example, in cloud computing scenarios, many cloud security products can generate security alerts based on security checks on cloud resources. Security operations analysts can use these alerts to identify malicious intrusions and take appropriate countermeasures.
[0004] In some traditional solutions, security alert data, such as indicators of compromise (IOCs), vulnerabilities, logs, and behaviors, is manually analyzed. Based on the analysis results, the system determines whether a host has been attacked and analyzes the cause of the attack. This manual approach to alert analysis suffers from low accuracy, leading to the need for a new solution.
[0005] Summary of the Invention
[0006] Various aspects of the present disclosure provide an alarm analysis method, a server, and a storage medium for automatically responding to security alarm issues and improving the accuracy of alarm analysis results corresponding to target issues.
[0007] An embodiment of the present disclosure provides an alarm analysis method, comprising: obtaining a target problem, wherein the target problem is associated with a target security alarm of a user resource; inputting the target problem into a security model so that the security model performs an action plan for the target problem and obtains action planning information for the target problem; the action planning information is used to describe the action required to solve the target problem; if the action planning information includes at least one tool calling information, then, based on the at least one tool calling information, calling at least one target alarm processing tool to perform an alarm information processing operation associated with the target problem and obtain at least one alarm information processing result; inputting the at least one alarm information processing result into the security model so that the security model outputs an alarm analysis result corresponding to the target problem based on the at least one alarm information processing result.
[0008] Optionally, before inputting the target question into the security model, it also includes: obtaining multiple groups of training samples of alarm analysis scenarios, any group of training samples includes: prompt word samples and reply samples; wherein the prompt word samples include: a preset candidate alarm processing tool, the input parameter format information of the preset candidate alarm processing tool and a question sample; the reply sample includes: a target alarm analysis tool sample selected from the preset candidate alarm processing tool, an interface input data sample matching the input parameter format information of the target alarm analysis tool sample, an alarm information processing result sample returned by the target alarm analysis tool sample, and an alarm analysis result sample obtained based on the alarm information processing result sample; based on the multiple groups of training samples, the security model is trained so that the security model learns action planning knowledge based on the multiple groups of training samples.
[0009] Optionally, the target problem is input into the security model so that the security model performs action planning on the target problem and obtains action planning information for the target problem, including: in the security model, based on the action planning knowledge learned in advance from the sample data, determining at least one target alarm analysis tool for processing the target problem from the preset candidate alarm processing tools, and determining the interface input data corresponding to each of the at least one target alarm analysis tools based on the target problem and the input parameter format information of the at least one target alarm analysis tool; and outputting the action planning information containing the at least one tool call information based on the respective interface identifiers and interface input data of the at least one target alarm analysis tool.
[0010] Optionally, according to the at least one tool calling information, at least one target alarm processing tool is called to execute the alarm information processing operation associated with the target problem to obtain at least one alarm information processing result, including: if the at least one tool calling information includes a first interface identifier corresponding to a script calculation tool and first interface input data corresponding to the script calculation tool, then the script calculation tool is called according to the first interface identifier, and the first interface input data is provided to the script calculation tool so that the script calculation tool executes the calculation operation of the first interface input data to obtain the calculation result as the alarm information processing result; the script calculation tool includes: at least one of a vector processing tool, an encoding tool, a decoding tool, an encryption tool and a decryption tool; and / or, if the at least one tool calling information includes The search tool is called according to the second interface identifier and the second interface input data corresponding to the search tool, and the second interface input data is provided to the search tool, so that the search tool performs the search operation of the second interface input data and obtains the search result as the alarm information processing result; and / or, if the at least one tool call information includes the third interface identifier corresponding to the threat intelligence call tool and the third interface input data corresponding to the search tool, the threat intelligence call tool is called according to the third interface identifier, and the third interface input data is provided to the threat intelligence call tool, so that the threat intelligence call tool performs the threat intelligence call operation of the third interface input data and obtains the threat intelligence call result as the alarm information processing result.
[0011] Optionally, based on the at least one tool calling information, at least one target alarm processing tool is called to perform the alarm information processing operation associated with the target problem to obtain at least one alarm information processing result, including: if the at least one tool calling information includes a fourth interface identifier corresponding to the target knowledge base tool and fourth interface input data corresponding to the target knowledge base tool, then the target knowledge base is called according to the fourth interface identifier, and the fourth interface input data is provided to the target knowledge base, so that the target knowledge base performs knowledge matching according to the fourth interface input data, and obtains a knowledge matching result as the alarm information processing result.
[0012] Optionally, the target knowledge base includes: a private knowledge base; the method also includes: obtaining log data and host behavior data corresponding to historical security alerts; extracting entities and relationships between entities from the log data and behavior data; and constructing a graph-based private knowledge base based on the entities and relationships between entities.
[0013] Optionally, the target knowledge base includes: a real-time knowledge vector library; determining the interface input data corresponding to each of the at least one target alarm analysis tools based on the target problem and the input parameter format information of the at least one target alarm analysis tool, including: performing vectorization processing on the target problem according to the input parameter format information of the real-time knowledge vector library to obtain the problem vector of the target problem as the interface input data corresponding to the real-time knowledge vector library; calling the target knowledge base according to the fourth interface identifier, and providing the fourth interface input data to the target knowledge base, so that the target knowledge base performs knowledge matching according to the fourth interface input data, and obtains a knowledge matching result as an alarm information processing result, including: calling the real-time knowledge vector library according to the fourth interface identifier, and providing the problem vector to the real-time knowledge vector library to retrieve at least one knowledge vector matching the problem vector in the real-time knowledge vector library as the alarm information processing result.
[0014] Optionally, it also includes: obtaining real-time updated security knowledge from a real-time security knowledge base according to a set period; vectorizing the real-time updated security knowledge to obtain a real-time updated security knowledge vector; and storing the real-time updated security knowledge vector in the real-time knowledge vector base.
[0015] Optionally, the method further includes: if the action plan information does not include any tool calling information, obtaining the target task type corresponding to the target problem; determining the target alarm processing tool corresponding to the target task type based on the predefined correspondence between different task types and different alarm processing tools; calling the target alarm processing tool, executing the alarm information processing operation associated with the target problem, and obtaining the alarm information processing result; inputting the alarm information processing result into the security model, so that the security model outputs the alarm analysis result corresponding to the target problem according to the alarm information processing result.
[0016] Optionally, obtaining the target question includes: obtaining, through an input interface provided to the user, a question associated with the target security alert of the user resource, input by the user as the target question; or, generating at least one recommended question based on the security status data of the user resource, and obtaining the target question based on the user's selection operation of the at least one recommended question; or, providing the user with a prompt word script corresponding to the target security alert, and determining the target question based on the selected prompt word based on the user's selection operation of at least one question in the prompt word script.
[0017] Optionally, after inputting the at least one alarm information processing result into the security model so that the security model outputs the alarm analysis result corresponding to the target problem based on the at least one alarm information processing result, it also includes: obtaining feedback information from the user on the alarm analysis result; and updating the prompt word script corresponding to the target security alarm based on the feedback information.
[0018] Optionally, after obtaining the action planning information of the target problem, it also includes: recording the correspondence between the target problem and the action planning information, so that when the target problem is received next time, according to the action planning information, calling at least one target alarm processing tool to perform the alarm information processing operation associated with the target problem.
[0019] Optionally, the method further includes: if the action plan information includes direct reply instruction information, using the security model to generate answer information corresponding to the target question.
[0020] Optionally, the security model includes: a large security domain model obtained by fine-tuning instructions on a large generative language model whose parameter quantity is greater than a set threshold.
[0021] An embodiment of the present disclosure further provides a server, comprising: a memory and a processor; the memory is used to store one or more computer instructions; the processor is used to execute the one or more computer instructions to: execute the steps in the method provided by the embodiment of the present disclosure.
[0022] The embodiments of the present disclosure further provide a computer-readable storage medium storing a computer program, which, when executed by a processor, can implement the steps of the method provided in the embodiments of the present disclosure.
[0023] The embodiments of the present disclosure further provide a computer program, which, when executed by a processor, implements the steps in the method provided by the embodiments of the present disclosure.
[0024] In the alarm analysis method provided by the embodiment of the present disclosure, after obtaining the target problem associated with the target security alarm of the user resource, the security model is used to perform action planning on the target problem to obtain action planning information. When the action planning information includes at least one tool call information, at least one target alarm processing tool can be called according to the at least one tool call information to perform the alarm information processing operation associated with the target problem to obtain at least one alarm information processing result. The security model can output the alarm analysis result corresponding to the target problem based on the at least one alarm information processing result. In this embodiment, on the one hand, the security knowledge capability of the security model is utilized to realize automatic reply to security alarm-related issues, reduce dependence on manual labor, thereby lowering the technical threshold of security alarm analysis and effectively improving the efficiency of security alarm analysis; on the other hand, the action planning capability of the security model is utilized to call the alarm processing tool to process the alarm information associated with the target problem, thereby facilitating the full use of security knowledge outside the security model, thereby effectively improving the accuracy of the alarm analysis results corresponding to the target problem. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] The drawings described herein are used to provide a further understanding of the present disclosure and constitute a part of the present disclosure. The exemplary embodiments of the present disclosure and their descriptions are used to explain the present disclosure and do not constitute an improper limitation of the present disclosure. In the drawings:
[0026] FIG1 is a flow chart of an alarm analysis method provided by an exemplary embodiment of the present disclosure;
[0027] FIG2 is a schematic diagram of an alarm analysis interface provided by an exemplary embodiment of the present disclosure;
[0028] FIG3 is a schematic diagram of a process and framework of an alarm analysis method provided by an exemplary embodiment of the present disclosure;
[0029] FIG4 is a schematic diagram of the structure of a server provided by an exemplary embodiment of the present disclosure. DETAILED DESCRIPTION
[0030] To make the objectives, technical solutions, and advantages of the present disclosure more clear, the technical solutions of the present disclosure will be clearly and completely described below in conjunction with the specific embodiments of the present disclosure and the corresponding drawings. Obviously, the described embodiments are only part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments of the present disclosure, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present disclosure.
[0031] The terms used in the embodiments of the present invention are for the purpose of describing specific embodiments only and are not intended to limit the present invention. As used in the embodiments of the present invention and the appended claims, the singular forms "a," "an," "the," and "the" are intended to include the plural forms. Unless the context clearly indicates otherwise, "a plurality" generally includes at least two, but does not exclude the inclusion of at least one.
[0032] It should be understood that the term "and / or" as used herein is merely a description of the relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A exists alone, A and B exist simultaneously, or B exists alone. Furthermore, the character " / " in this document generally indicates that the associated objects are in an "or" relationship.
[0033] It should also be noted that the terms "include," "comprises," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a product or system comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such product or system. In the absence of further limitations, an element defined by the phrase "comprises a..." does not exclude the presence of other identical elements in the product or system comprising the element.
[0034] When analyzing target security alerts, there are at least the following analysis methods:
[0035] 1. Analyze the IOCs related to the target security alert. Extract indicators of compromise (IOCs) on the host through the target security alert, and analyze whether the host is under real attack and the specific mode and method of the attack based on the extracted IOCs. Among them, the IOCs may include: file samples extracted from the host, host access URL (uniform resource locator, uniform resource locator), host access domain name, host access IP (Internet Protocol Address, Internet Protocol) address, etc. For example, after extracting file samples related to the target security alert, you can use reverse methods (such as using the message digest algorithm (MD5) to calculate the MD5 value of the file sample) or sandbox related technologies to analyze the sample behavior.
[0036] 2. Analyze the vulnerabilities associated with the target security alert. Typically, vulnerability analysis can be combined with vulnerability intelligence data to determine the initial entry point for the attack.
[0037] 3. Analyze logs and behaviors related to target security alerts. Typically, log data generated by systems, networks, applications, and devices can be analyzed to detect unusual activity, potential attacks, and security incidents. By analyzing user and entity behavior, unusual patterns, trends, and activities can be detected to identify potential insider threats or unauthorized behavior. Log and behavior-based analysis can determine the attacker's actions after gaining access to a host.
[0038] Some manual alarm analysis methods require analysts to possess specialized security knowledge and have a high technical threshold. Computer-based alarm analysis methods utilize data mining and machine learning techniques to analyze and model large amounts of security data, uncovering hidden behavioral patterns, anomalies, and their correlations on hosts. However, these data mining and machine learning methods only cover a limited amount of security data and have limited universal applicability.
[0039] In response to the above technical problems, a solution is provided in some embodiments of the present disclosure. The technical solutions provided by the embodiments of the present disclosure are described in detail below with reference to the accompanying drawings.
[0040] FIG1 is a flow chart of an alarm analysis method provided by an exemplary embodiment of the present disclosure. The method may include the steps shown in FIG1 :
[0041] Step 101: Obtain a target problem, where the target problem is associated with a target security alert of a user resource.
[0042] Step 102: Input the target problem into the security model so that the security model performs action planning on the target problem and obtains action planning information for the target problem.
[0043] Step 103: If the action plan information includes at least one tool calling information, at least one target alarm processing tool is called according to the at least one tool calling information to execute an alarm information processing operation associated with the target problem, and obtain at least one alarm information processing result.
[0044] Step 104: Input the at least one alarm information processing result into the security model, so that the security model outputs an alarm analysis result corresponding to the target problem according to the at least one alarm information processing result.
[0045] This embodiment is used to utilize security models and alarm analysis tools to realize automatic analysis operations of target security alarms. Among them, target security alarms refer to alarms or notifications generated after a security system or security tool detects a potential security threat or abnormal activity. For example, target security alarms may include but are not limited to: any one of: web page anti-tampering alarms, process abnormality alarms, website backdoor alarms, abnormal login alarms, and malicious process alarms. Target security alarms are an important security incident response mechanism in information security and can be applied to a variety of cloud computing security protection systems, such as cloud security centers, Web (network) application firewalls, cloud firewalls, DDoS (Distributed Denial of Service) protection systems, etc. The above-mentioned cloud computing security protection system (hereinafter referred to as the security protection system) can be used to provide security protection for user resources on the cloud (such as cloud servers rented by users on the cloud computing platform, systems deployed on the cloud computing platform, etc.).
[0046] The security model's analysis of the target security alert includes, but is not limited to, at least one of the following: analyzing IOCs related to the target security alert, analyzing vulnerabilities related to the target security alert, and analyzing logs and behaviors related to the target security alert. The security model includes a security domain large model obtained by fine-tuning a generative large language model whose parameters exceed a set threshold. Fine-tuning the model refers to retraining a pre-trained model for a specific task using a small amount of instruction data from the target domain to optimize the pre-trained model's performance on a specific task in the target domain. The large language model is a neural network-based, unsupervised pre-trained model that can be trained on large amounts of unlabeled text data to learn the knowledge and skills required for natural language processing tasks, such as understanding grammar, semantics, context, logical reasoning, and security knowledge. The network parameters of a generative pre-trained large model typically exceed one billion, or even hundreds of billions. Fine-tuning the pre-trained large language model using a set of security domain instructions yields a security model. Among them, in the large language model, instructions generally refer to a set of rules or guidance used to guide the model to generate specific outputs or complete specific tasks. Instructions can include text, code, labels or other forms of guidance to indicate how the model should generate, adjust or optimize its output. In this embodiment, the knowledge question-answering ability of the generative pre-trained large model in the security field after instruction fine-tuning can be used to achieve automatic analysis of target security alerts. After the pre-training stage and the instruction fine-tuning stage, the security model can better analyze file samples, malicious scripts, IOCs and vulnerability-related data by compressing knowledge, thereby alleviating the problem of high security analysis threshold to a large extent.
[0047] In some embodiments, the security model can be applied to service components within the security protection system, such as intelligent customer service or intelligent question-and-answer robots. When the security protection system detects a targeted security alert, it can issue an alert notification to the user. Using the Q&A capabilities provided by the security model, the user can automatically answer questions related to the targeted security alert. Based on one or more rounds of Q&A, the user can obtain alert analysis results for the targeted security alert. In this embodiment, the security model can collaborate with other alert processing tools to perform targeted security alert analysis.
[0048] Target issues related to the target security alert may include but are not limited to: security knowledge issues related to the target security alert, threat intelligence issues related to the target security alert, entities and entity relationships related to the target security alert, host behavior issues related to the target security alert, etc.
[0049] In some optional implementations, the target question input by the user is obtained through an input interface provided to the user. That is, the target question can be input by the user based on actual needs. In this embodiment, the user primarily includes the security operations personnel of user resources. Security operations personnel can freely input security-related questions to the intelligent robot in the security protection system, such as questions related to threat alerts, security operations, security knowledge, logs, and host behavior.
[0050] In other optional implementations, at least one recommended question can be generated based on the security status data of the user's resources, and a target question can be obtained based on the user's selection of the at least one recommended question. In such implementations, the security model can generate a list of questions related to the target security alerts for the user based on security status data such as the user's resources' current threat alerts, the user's resources' current security status, and the user's resources' logs and host behavior, allowing the user to better analyze and understand the security level and status of the user's resources.
[0051] In some other optional implementations, a prompt word script (PromptBook) corresponding to the target security alert can be provided to the user, and according to the user's selection operation of at least one question in the prompt word script, the target question is determined according to the selected prompt word. That is, the target question related to the target security alert is triggered by the historical prompt word script. Among them, the historical prompt word script is formed by a series of process-based questions generated in the process of analyzing security threat alerts at historical moments. The security model can automatically analyze and judge security threat alerts by answering a series of process-based questions. Figure 2 illustrates an alert issued by the security protection system when it detects suspicious downloading behavior. As shown in Figure 2, when displaying the alert, the prompt word script corresponding to the alert can be displayed. The prompt word script includes multiple selectable questions, and the user can choose any of them to ask questions. Based on the prompt word script, the efficiency of users' questions can be greatly improved.
[0052] After obtaining the target problem based on the above implementation, the target problem can be input into the security model, which can then perform action planning for the target problem. Action planning refers to planning executable actions to solve the target problem. During the instruction fine-tuning phase, the security model learned how to perform action planning based on the input target problem. Based on this knowledge, the security model can plan analysis actions for the target problem based on this pre-learned knowledge, generating action planning information for the target problem. This action planning information describes the actions required to solve the target problem.
[0053] In some optional embodiments, the security model's action planning for the target question may include providing a direct response or invoking other alarm processing tools to provide a response. If a direct response is provided, the security model may generate a response corresponding to the target question based on the security knowledge learned during the pre-training and instruction fine-tuning phases. Accordingly, if the action planning results in a direct response, the action planning information output by the security model may include direct response instructions. If the action planning information includes direct response instructions, the security model may be used to generate the answer information corresponding to the target question.
[0054] If the action plan results in the invocation of another alarm processing tool to provide a response, the action plan information output by the security model may include at least one tool invocation message. Based on this at least one tool invocation message, at least one target alarm processing tool may be invoked to perform an alarm processing operation associated with the target issue, thereby obtaining at least one alarm processing result. Each tool invocation message may be used to invoke a target alarm processing tool, and each target alarm processing tool may generate an alarm processing result. This at least one alarm processing result may be input into the security model, which then analyzes it to obtain an alarm analysis result corresponding to the target issue.
[0055] The security model can call upon multiple types of alarm processing tools, each of which performs different alarm information processing operations. For example, it can include knowledge base-type alarm processing tools and tool-type alarm processing tools. Knowledge base-type alarm processing tools are used to perform knowledge matching and return matched knowledge content. Knowledge base-type alarm processing tools may include real-time knowledge bases and / or private knowledge bases. The real-time knowledge base is used to store real-time acquired knowledge, including security knowledge that is updated in real time as the security system operates. The data in the real-time knowledge base is updated quickly and can provide knowledge that is not covered during the security model pre-training and instruction fine-tuning phases, thereby supplementing the real-time knowledge of the security model. The private knowledge base is a database that stores private knowledge accumulated by users (including individual users and enterprise users) on the cloud computing platform. The knowledge in the private knowledge base is generally not used during the security model pre-training and instruction fine-tuning phases. The real-time knowledge base can provide private knowledge that is not covered by the security model, thereby facilitating the effective answering of questions that match the knowledge in the private knowledge base.
[0056] Among them, the tool-type alarm processing tool is used to provide non-natural language processing operations such as search and calculation. Among them, the tool-type alarm processing tool may include: at least one of a search tool, a threat intelligence calling tool and a scripting tool. Among them, the search tool can be used to search for security knowledge on a specified website. The threat intelligence calling tool is used to call a local or third-party threat intelligence analysis service to obtain network threat intelligence. Among them, network threat intelligence is a kind of evidence-based knowledge, including context, mechanism, indicator, implicit and practical suggestions. Threat intelligence describes existing or imminent threats or dangers to network assets, and can be used to notify the subject to take some response to the relevant threats or dangers. Among them, the scripting tool may include: at least one of a vector processing tool, encoding tool, decoding tool, encryption tool and decryption tool written in the form of a script. For example, the scripting tool may include: Base64 (a coding method for transmitting 8-bit bytecode) encryption and decryption tool, URL encoding and decoding tool, etc.
[0057] Based on the above-mentioned alarm processing tools, the security model can, to a certain extent, solve the technical problems of narrow knowledge coverage or lack of processing capabilities for non-natural language data.
[0058] The following will exemplify optional implementation methods for the security model to perform action planning on a target problem and obtain action planning information.
[0059] In some exemplary embodiments A, the correspondence between different types of target problems and different types of alarm processing tools may be predefined in the security model, so that the security model calls different types of alarm processing tools according to the correspondence.
[0060] For example, the alert handling tool for vulnerability-related issues and product documentation-related issues corresponding to user resources is a real-time knowledge base. For example, the alert handling tool for internal user knowledge-related issues is a private knowledge base. For example, the alert handling tool for threat intelligence-related issues is a threat intelligence invocation tool. Another example is a codec-related alert handling tool for codec-related issues.
[0061] Optionally, in this embodiment, the target task type corresponding to the target problem can be determined, and the target alarm processing tool corresponding to the target task type can be determined based on the predefined correspondence between different task types and different alarm processing tools. Optionally, if the target task type is a calculation type, the target alarm processing tool can be determined to be a script calculation tool based on the predefined correspondence; the script calculation tool includes at least one of a vector processing tool, an encoding tool, a decoding tool, an encryption tool, and a decryption tool. If the target task type is a search type, the target alarm processing tool can be determined to be a search tool based on the predefined correspondence. If the target task type is a threat intelligence acquisition type, the target alarm processing tool can be determined to be a threat intelligence call tool based on the learned correspondence between different task types and different alarm processing tools. If the target task type is a knowledge call type, the target alarm processing tool can be determined to be a target knowledge base based on the predefined correspondence; the target knowledge base includes a private knowledge base and / or a real-time knowledge base.
[0062] After determining at least one target alarm processing tool based on the above implementation, the security model can determine the interface input data of the at least one target alarm processing tool according to the target problem and the input parameter format information of the at least one target alarm processing tool. The security model can output action plan information containing at least one tool call information based on the interface identifier and interface input data of the at least one target alarm processing tool. Among them, one tool call information includes the interface identifier of a target alarm processing tool and its interface input data. Based on this implementation, by pre-defining the correspondence between the problem and the alarm processing tool, the target alarm processing tool corresponding to the target problem can be quickly determined, thereby improving the efficiency of alarm analysis.
[0063] In other exemplary embodiments B, the security model may perform action planning on the target problem based on action planning knowledge previously learned from sample data to obtain action planning information.
[0064] In some exemplary embodiments, before inputting the target question into the security model, the security model may be fine-tuned using training samples so that the security model learns action planning knowledge. An exemplary explanation is provided below.
[0065] Optionally, multiple sets of training samples can be obtained, and any set of training samples includes: prompt word samples and response samples. For example, a set of training samples can be implemented as:
[0066] {
[0067] "Prompt word": "Please answer the following questions to the best of your ability. You can use the following tools: Tool C1, which can be called using interface C2. The function of interface C2 is xxx; the input format of interface C2 is xxx. Tool D1, which can be called using interface D2. The function of interface D2 is xxx; the input format of interface D2 is xxx. Tool E1, which can be called using interface E2. The function of interface E2 is xxx; the input format of interface E2 is xxx. Please follow the following format:
[0068] \n\nQuestion: The input question you must answer;\nThought: You should always think about what to do;\nAction: The action to be taken, which should be one of [Tool C1, Tool D1, Tool E1];\nAction Input: The input of the action;\nObservation: The result of the action;\n... (The above Thought / Action / Action Input / Observation can be repeated 0 or more times);\nThought: I now know the final answer;\nFinal Answer: The final answer to the original input question;\n\nBegin!\n\nQuestion: What alarms exist on this host?
[0069] "Reply": "You need to use interface C2 to search for alarm information on the host.\nAction: Tool C1;\nAction Input: {\"Host IP\": \"xxx\", \"Search object\": \"Alarm\"};\nObservation: {\"Alarm type\": \"xxx\", \"Alarm time\": \"xxx"};\nThought: From the returned results, you can see that the alarms on the host include the process abnormality alarm at time t1, the abnormal login alarm at time t2, and the malicious process alarm at time t3;\nFinal Answer: There are three alarms on this host: the process abnormality alarm at time t1, the abnormal login alarm at time t2, and the malicious process alarm at time t3."
[0070] }
[0071] Taking the training samples above as an example, the prompt word samples in the training samples may include at least: a preset candidate alarm processing tool, the input format information of the preset candidate alarm processing tool, and a question sample; the response samples in the training samples may include at least: a target alarm analysis tool sample selected from the preset candidate alarm processing tools, an interface input data sample matching the input format information of the target alarm analysis tool sample, an alarm information processing result sample returned by the target alarm analysis tool sample, and an alarm analysis result sample obtained based on the alarm information processing result sample. The security model is trained based on these multiple sets of training samples, so that the security model learns action planning knowledge based on these multiple sets of training samples. During the training process, the security model learns relevant knowledge about selecting a target alarm analysis tool from the preset candidate alarm processing tools when a problem is known; and, when a problem is known, learns relevant knowledge about converting a problem into interface input data based on the input format information of the target alarm analysis tool. Furthermore, after multiple rounds of training, when the security model converges, the security model can automatically perform action planning for the input security-related problem based on the learned action planning knowledge and output relatively accurate action planning information.
[0072] Optionally, in this embodiment, in the security model, based on the action planning knowledge learned in advance from the sample data, at least one target alarm analysis tool for processing the target problem can be determined from the preset candidate alarm processing tools, and based on the target problem and the input parameter format information of the at least one target alarm analysis tool, the interface input data corresponding to each of the at least one target alarm analysis tools can be determined. Among them, the input parameter format information of any target alarm analysis tool is used to describe the format of the input parameters of the target alarm analysis tool. The security model can output a tool call information based on the interface identifier and interface input data of any target alarm analysis tool. Among them, the security model's calling operation on other alarm processing tools can be implemented through the security model agent component (SecAgent), as shown in Figure 3. As shown in Figure 3, the action planning information output by the security model can be displayed as an action list, and one action in the action list can correspond to a tool call operation.
[0073] It is worth noting that in some exemplary embodiments, after obtaining the action plan information for a target issue, the corresponding relationship between the target issue and the action plan information can be recorded. This allows the target alarm processing tool to be invoked based on the action plan information the next time the target issue is received. This, in turn, reduces the computational complexity of the security model.
[0074] The following will illustrate different alarm processing tools.
[0075] In some optional embodiments B1, the at least one target alarm processing tool includes a script calculation tool. Accordingly, the action planning information output by the security model includes script calculation tool call information, and the script tool call information includes an interface identifier corresponding to the script calculation tool (hereinafter referred to as the first interface identifier), and interface input data (hereinafter referred to as the first interface input data) determined based on the target problem and input parameter format information corresponding to the script calculation tool.
[0076] If the action plan information includes a first interface identifier and first interface input data corresponding to a script calculation tool, the security model agent may invoke the script calculation tool based on the first interface identifier and provide the first interface input data to the script calculation tool, causing the script calculation tool to perform a calculation operation on the first interface input data and obtain a calculation result as the alarm information processing result. Optionally, the script calculation tool includes at least one of a vector processing tool, an encoding tool, a decoding tool, an encryption tool, and a decryption tool.
[0077] In some optional embodiments B2, the at least one target alarm processing tool includes a search tool. As shown in FIG3 , the search tool is located in the execution tool library. Accordingly, the action plan information output by the security model includes search tool call information, which includes an interface identifier corresponding to the search tool (hereinafter referred to as the second interface identifier) and interface input data determined based on the target problem and input parameter format information corresponding to the search tool (hereinafter referred to as the second interface input data).
[0078] If the action plan information includes a second interface identifier and second interface input data corresponding to the search tool, the search tool is called according to the second interface identifier, and the second interface input data is provided to the search tool so that the search tool performs a search operation on the second interface input data and obtains the search results as the alarm information processing result.
[0079] In some optional embodiments B3, the at least one target alarm processing tool includes: a threat intelligence calling tool. As shown in Figure 3, the threat intelligence calling tool is located in the execution tool library. Accordingly, the action plan information output by the security model includes threat intelligence calling tool calling information, and the threat intelligence calling tool calling information includes: an interface identifier corresponding to the threat intelligence calling tool (hereinafter referred to as the third interface identifier), and interface input data (hereinafter referred to as the third interface input data) determined based on the target problem and the input parameter format information corresponding to the threat intelligence calling tool.
[0080] If the action plan information includes a third interface identifier and third interface input data corresponding to the threat intelligence calling tool, the threat intelligence calling tool is called according to the third interface identifier, and the third interface input data is provided to the threat intelligence calling tool, so that the threat intelligence calling tool executes the threat intelligence calling operation of the third interface input data, and obtains the threat intelligence calling result as the alarm information processing result.
[0081] In some optional embodiments B4, the target problem target alarm processing tool includes a target knowledge base tool. Accordingly, the action plan information output by the security model includes target knowledge base tool call information, and the target knowledge base call information includes an interface identifier corresponding to the target knowledge base tool (hereinafter referred to as a fourth interface identifier), and interface input data (hereinafter referred to as fourth interface input data) determined based on the target problem and input parameter format information corresponding to the target knowledge base tool.
[0082] Optionally, if the action planning information includes a fourth interface identifier and fourth interface input data corresponding to the target knowledge base, the target knowledge base is called according to the fourth interface identifier, and the fourth interface input data is provided to the target knowledge base, so that the target knowledge base performs knowledge matching according to the fourth interface input data, and obtains a knowledge matching result as the alarm information processing result.
[0083] Optionally, the target knowledge base may include a private knowledge base. The private knowledge base may include a log-based private knowledge base and / or a graph-based private knowledge base. The log-based private knowledge base may be called via a log-based private knowledge base interface, and the graph-based private knowledge base may be called via a graph-based private knowledge base interface, as shown in FIG3 . Specifically, when calling the above-mentioned different types of private knowledge bases, the fourth interface identifier may be implemented as the interface corresponding to each different type of private knowledge base.
[0084] In some optional embodiments, a log-based private knowledge base can be established based on the log data of user resources. In this embodiment, the log data can be converted into text form and stored in a log storage and retrieval platform to form a log-based private knowledge base. When using the log-based private knowledge base, the text-based log data can be retrieved from the knowledge base based on text matching.
[0085] In other embodiments, a private knowledge base based on a graph can be established based on the log data and host behavior data corresponding to historical security alerts for query and analysis. Optionally, the log data and host behavior data corresponding to historical security alerts can be obtained, and entities and the relationships between entities can be extracted from the log data and behavior data. The extracted entities may include at least one of: hosts, processes, files, domain names, IP addresses, URLs, alerts, and vulnerabilities. The relationships between entities are used to describe the access, call, storage, and resolution relationships between the above entities. For example, the relationships between entities may include: processes running on the host, files stored on the host, domain name resolution IP addresses, etc. A private knowledge base based on a graph is constructed based on the acquired entities and the relationships between entities.
[0086] Optionally, the target knowledge base may include a real-time knowledge vector base corresponding to the real-time knowledge base, and the real-time knowledge vector base is obtained by vectorizing the knowledge in the real-time knowledge base. The real-time knowledge base is continuously updated as the systems on the cloud platform operate. Based on this, in some optional embodiments, real-time updated security knowledge can be obtained from the real-time security knowledge base according to a set period, and the real-time updated security knowledge can be vectorized to obtain a real-time updated security knowledge vector. The real-time updated security knowledge vector is stored in the security knowledge vector base. As shown in Figure 3, real-time updated knowledge slices can be obtained from the real-time security knowledge base, and the knowledge slices can be vectorized using a vector embedding module to obtain knowledge vectors, and the knowledge vectors are stored in the security knowledge vector base.
[0087] When determining the interface input data corresponding to the real-time knowledge vector library based on the target problem and the input parameter format information of the real-time knowledge vector library tool, the target problem can be vectorized according to the input parameter format information of the real-time knowledge vector library to obtain the problem vector of the target problem as the interface input data corresponding to the real-time knowledge vector library. As shown in Figure 3, the target problem can be sent to the vector embedding module, and the vector embedding module vectorizes the target problem to obtain the problem vector. When the real-time knowledge vector library is called according to the fourth interface identifier, the problem vector can be provided to the real-time knowledge vector library to retrieve at least one knowledge vector that matches the problem vector in the real-time knowledge vector library as the alarm information processing result. The at least one knowledge vector can be one or more knowledge vectors in the real-time knowledge vector library whose matching pair with the problem vector is greater than the set matching degree threshold.
[0088] Among them, the above-mentioned implementation mode B1, implementation mode B2, implementation mode B3 and implementation mode B4 can be executed separately or in combination, depending on the action planning information output by the security model, and will not be described in detail one by one.
[0089] After obtaining at least one alarm information processing result of the at least one target alarm processing tool for the target problem based on the above-mentioned implementation method, the at least one alarm information processing result can be input into the security model so that the security model summarizes the at least one alarm information processing result and outputs the summarized information as the alarm analysis result corresponding to the target problem.
[0090] In the above implementation, on the one hand, the security knowledge capability of the security model is utilized to realize automatic responses to security alarm-related questions, reduce dependence on manual work, thereby lowering the technical threshold for security alarm analysis and effectively improving the efficiency of security alarm analysis; on the other hand, the action planning capability of the security model is utilized to call the alarm processing tool to process the alarm information associated with the target problem, which can facilitate the full utilization of security knowledge outside the security model, thereby effectively improving the accuracy of the alarm analysis results corresponding to the target problem.
[0091] In some exemplary embodiments, after outputting the alarm analysis result corresponding to the target problem, user feedback information on the alarm analysis result can be obtained. For example, when outputting the alarm analysis result, evaluation prompt information of the alarm analysis result can be output for the user to evaluate the alarm analysis result. The evaluation prompt information can be: "Did this answer solve your problem? If it does, please click the first control (such as the like control); if it does not, please click the second control (such as the thumbs-up control)". The evaluation prompt information and the feedback controls corresponding to "yes" and "no" are shown in Figure 2. Among them, the feedback information is used to describe the contribution of the alarm analysis result corresponding to the target problem to the process of solving the target security alarm. Based on the feedback information, the prompt word script corresponding to the target security alarm can be updated.
[0092] Optionally, if the feedback information is positive feedback information, the alarm analysis result can be considered to be valid for the analysis process of the threat alarm, and the prompt word script corresponding to the target security alarm is updated based on the target question and at least one context question associated with the target question. Among them, the at least one context question associated with the target question may include: after the target security alarm is generated, the user raises a series of questions about the target security alarm, and this series of questions makes a positive contribution to solving the analysis of the security alarm. Conversely, if the feedback information is negative feedback information, the alarm analysis result can be considered to be invalid for the analysis process of the threat alarm. If the target question is in the prompt word script of the target security alarm, the target question can be removed from the prompt word script to update the prompt word script of the target security alarm. When different users give different feedback on the alarm analysis results of a set of context questions, different prompt word scripts can be formed for different users.
[0093] Based on this implementation method, the prompt word script of the target security alarm prompt information can be flexibly updated according to the user's feedback information on the alarm analysis results of the target problem, so that the prompt word script can gradually approach the actual alarm analysis needs and enhance the beneficial contribution of the problems in the prompt word script to solving the alarm problem.
[0094] It should be noted that the execution entity of each step of the method provided in the above embodiment can be the same device, or the method can be executed by different devices. For example, the execution entity of steps 101 to 104 can be device A; for another example, the execution entity of steps 101 and 102 can be device A, and the execution entity of step 103 can be device B; and so on.
[0095] In addition, some of the processes described in the above embodiments and the accompanying drawings include multiple operations that appear in a specific order, but it should be clearly understood that these operations may not be executed in the order in which they appear in this article or may be executed in parallel. The serial numbers of the operations, such as 101, 102, etc., are only used to distinguish between different operations, and the serial numbers themselves do not represent any order of execution. In addition, these processes may include more or fewer operations, and these operations may be executed in sequence or in parallel. It should be noted that the descriptions of "first", "second", etc. in this article are used to distinguish different messages, devices, modules, etc., and do not represent a sequential order, nor do they limit "first" and "second" to different types.
[0096] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this disclosure are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0097] FIG4 is a schematic diagram illustrating the structure of a server provided by an exemplary embodiment of the present disclosure, which is applicable to the alarm analysis method provided by the aforementioned embodiment. As shown in FIG4 , the server includes: a memory 401 , a processor 402 , and a communication component 403 .
[0098] The memory 401 is used to store computer programs and can be configured to store various other data to support operations on the server, such as instructions for any application or method used to operate on the server.
[0099] The processor 402 is coupled to the memory 401 and is used to execute the computer program in the memory 401, so as to: obtain a target problem, where the target problem is associated with a target security alarm of a user resource; input the target problem into a security model so that the security model performs an action plan for the target problem and obtains action planning information for the target problem; the action planning information is used to describe the actions required to solve the target problem; if the action planning information includes at least one tool calling information, then according to the at least one tool calling information, at least one target alarm processing tool is called to perform an alarm information processing operation associated with the target problem and obtain at least one alarm information processing result; and the at least one alarm information processing result is input into the security model so that the security model outputs an alarm analysis result corresponding to the target problem according to the at least one alarm information processing result.
[0100] Optionally, before inputting the target question into the security model, the processor 402 is further used to: obtain multiple groups of training samples of alarm analysis scenarios, any group of training samples including: prompt word samples and reply samples; wherein the prompt word samples include: a preset candidate alarm processing tool, the input parameter format information of the preset candidate alarm processing tool, and a question sample; the reply sample includes: a target alarm analysis tool sample selected from the preset candidate alarm processing tool, an interface input data sample matching the input parameter format information of the target alarm analysis tool sample, an alarm information processing result sample returned by the target alarm analysis tool sample, and an alarm analysis result sample obtained based on the alarm information processing result sample; and train the security model based on the multiple groups of training samples so that the security model learns action planning knowledge based on the multiple groups of training samples.
[0101] Optionally, when the processor 402 inputs the target problem into the security model so that the security model performs action planning on the target problem and obtains action planning information for the target problem, it is specifically used to: in the security model, based on the action planning knowledge learned in advance from the sample data, determine at least one target alarm analysis tool for processing the target problem from the preset candidate alarm processing tools, and determine the interface input data corresponding to each of the at least one target alarm analysis tools based on the target problem and the input parameter format information of the at least one target alarm analysis tool; and output the action planning information containing the at least one tool call information based on the respective interface identifiers and interface input data of the at least one target alarm analysis tool.
[0102] Optionally, when the processor 402 calls at least one target alarm processing tool to execute the alarm information processing operation associated with the target problem and obtains at least one alarm information processing result according to the at least one tool calling information, it is specifically used to: if the at least one tool calling information includes a first interface identifier corresponding to a script calculation tool and first interface input data corresponding to the script calculation tool, then call the script calculation tool according to the first interface identifier, and provide the first interface input data to the script calculation tool so that the script calculation tool executes the calculation operation of the first interface input data and obtains the calculation result as the alarm information processing result; the script calculation tool includes: at least one of: a vector processing tool, an encoding tool, a decoding tool, an encryption tool and a decryption tool; and / or ... If the information includes a second interface identifier corresponding to the search tool and the second interface input data corresponding to the search tool, the search tool is called according to the second interface identifier, and the second interface input data is provided to the search tool, so that the search tool performs the search operation of the second interface input data, and obtains the search result as the alarm information processing result; and / or, if the at least one tool call information includes a third interface identifier corresponding to the threat intelligence call tool and the third interface input data corresponding to the search tool, the threat intelligence call tool is called according to the third interface identifier, and the third interface input data is provided to the threat intelligence call tool, so that the threat intelligence call tool performs the threat intelligence call operation of the third interface input data, and obtains the threat intelligence call result as the alarm information processing result.
[0103] Optionally, when the processor 402 calls at least one target alarm processing tool to perform the alarm information processing operation associated with the target problem according to the at least one tool calling information and obtains at least one alarm information processing result, it is specifically used to: if the at least one tool calling information includes a fourth interface identifier corresponding to the target knowledge base tool and fourth interface input data corresponding to the target knowledge base tool, then call the target knowledge base according to the fourth interface identifier, and provide the fourth interface input data to the target knowledge base, so that the target knowledge base performs knowledge matching according to the fourth interface input data, and obtains a knowledge matching result as the alarm information processing result.
[0104] Optionally, the target knowledge base includes: a private knowledge base; the processor 402 is also used to: obtain log data and host behavior data corresponding to historical security alerts; extract entities and relationships between entities from the log data and behavior data; and construct a graph-based private knowledge base based on the entities and relationships between entities.
[0105] Optionally, the target knowledge base includes: a real-time knowledge vector library; when the processor 402 determines the interface input data corresponding to each of the at least one target alarm analysis tools based on the target problem and the input parameter format information of the at least one target alarm analysis tool, it is specifically used to: vectorize the target problem according to the input parameter format information of the real-time knowledge vector library to obtain the problem vector of the target problem as the interface input data corresponding to the real-time knowledge vector library; call the target knowledge base according to the fourth interface identifier, and provide the fourth interface input data to the target knowledge base, so that the target knowledge base performs knowledge matching according to the fourth interface input data, and obtains a knowledge matching result as an alarm information processing result, including: calling the real-time knowledge vector library according to the fourth interface identifier, and providing the problem vector to the real-time knowledge vector library to retrieve at least one knowledge vector matching the problem vector in the real-time knowledge vector library as the alarm information processing result.
[0106] Optionally, the processor 402 is also used to: obtain real-time updated security knowledge from the real-time security knowledge base according to a set period; vectorize the real-time updated security knowledge to obtain a real-time updated security knowledge vector; and store the real-time updated security knowledge vector in the real-time knowledge vector base.
[0107] Optionally, the processor 402 is also used to: if the action plan information does not include any tool calling information, obtain the target task type corresponding to the target problem; determine the target alarm processing tool corresponding to the target task type according to the predefined correspondence between different task types and different alarm processing tools; call the target alarm processing tool, execute the alarm information processing operation associated with the target problem, and obtain the alarm information processing result; input the alarm information processing result into the security model, so that the security model outputs the alarm analysis result corresponding to the target problem according to the alarm information processing result.
[0108] Optionally, when obtaining the target question, the processor 402 is specifically used to: obtain the question associated with the target security alert of the user resource input by the user as the target question through an input interface provided to the user; or, generate at least one recommended question based on the security status data of the user resource, and obtain the target question based on the user's selection operation of the at least one recommended question; or, provide the user with a prompt word script corresponding to the target security alert, and determine the target question based on the selected prompt word based on the user's selection operation of at least one question in the prompt word script.
[0109] Optionally, after inputting the at least one alarm information processing result into the security model so that the security model outputs the alarm analysis result corresponding to the target problem based on the at least one alarm information processing result, the processor 402 is also used to: obtain feedback information from the user on the alarm analysis result; and update the prompt word script corresponding to the target security alarm based on the feedback information.
[0110] Optionally, after obtaining the action planning information of the target problem, the processor 402 is also used to: record the correspondence between the target problem and the action planning information, so that when the target problem is received next time, the at least one target alarm processing tool is called according to the action planning information to perform the alarm information processing operation associated with the target problem.
[0111] Optionally, the processor 402 is further configured to: if the action plan information includes direct reply instruction information, generate answer information corresponding to the target question using the security model.
[0112] Optionally, the security model includes: a large security domain model obtained by fine-tuning instructions on a large generative language model whose parameter quantity is greater than a set threshold.
[0113] Furthermore, as shown in Figure 4 , the server also includes other components such as a power supply component 404. Figure 4 only schematically illustrates some components, which does not mean that the server only includes the components shown in Figure 4 .
[0114] Among them, the memory 401 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random-access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk.
[0115] The communication component 403 is configured to facilitate wired or wireless communication between the device where the communication component is located and other devices. The device where the communication component is located can access a wireless network based on a communication standard, such as Wi-Fi (wireless network communication technology), 2G (such as Global System for Mobile Communications (GSM)), 3G (such as Wideband Code Division Multiple Access (WCDMA), 4G (such as Long Term Evolution (LTE)), 4G+ (such as upgraded Long Term Evolution (LTE-Advanced, LTE-A)), or 5G (5th Generation Mobile Communication Technology), or a combination thereof. In an exemplary embodiment, the communication component receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component can be implemented based on Near Field Communication (NFC) technology, Radio Frequency Identification (RFID) technology, Infrared Data Association (IrDA) technology, Ultra Wide Band (UWB) technology, Bluetooth (BT) technology, and other technologies.
[0116] The power supply component 404 is used to provide power to various components of the device where the power supply component is located. The power supply component may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to the device where the power supply component is located.
[0117] In this embodiment, after obtaining the target problem associated with the target security alarm of the user resource, the security model is used to perform action planning on the target problem to obtain action planning information. According to the tool call information in the action planning information, the target alarm processing tool is called to perform the alarm information processing operation associated with the target problem to obtain the alarm information processing result. The security model can output the alarm analysis result corresponding to the target problem based on the alarm information processing result. On the one hand, by utilizing the security knowledge capability of the security model, automatic responses to security alarm-related issues are achieved, reducing dependence on manual labor, thereby lowering the technical threshold for security alarm analysis and effectively improving the efficiency of security alarm analysis; on the other hand, by utilizing the action planning capability of the security model, the alarm processing tool is called to process the alarm information associated with the target problem, which can facilitate the full use of security knowledge outside the security model, thereby effectively improving the accuracy of the alarm analysis results corresponding to the target problem.
[0118] Accordingly, an embodiment of the present disclosure further provides a computer-readable storage medium storing a computer program, which, when executed, can implement the steps that can be executed by the server in the above method embodiment.
[0119] Accordingly, an embodiment of the present disclosure further provides a computer program, which, when executed by a processor, implements the steps that can be executed by the server in the method embodiment.
[0120] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM (Compact Disc Read-Only Memory), optical storage, etc.) containing computer-usable program code.
[0121] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as combinations of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable alarm information processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable alarm information processing device produce a device for implementing the functions specified in one or more processes in the flowchart and / or one or more blocks in the block diagram.
[0122] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable alarm information processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0123] These computer program instructions can also be loaded onto a computer or other programmable alarm information processing device, so that a series of operating steps are executed on the computer or other programmable device to produce computer-implemented processing, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0124] In a typical configuration, a computing device includes one or more processors (Central Processing Unit, CPU), input / output interfaces, network interfaces, and memory.
[0125] Memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.
[0126] Computer-readable media include permanent and non-permanent, removable and non-removable media that can be used to store information using any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, Parallel Random Access Machine (PRAM), Static Random Access Memory (SRAM), Dynamic Random Access Memory (DRAM), other types of random access memory (RAM), Read-Only Memory (ROM), Electrically Erasable Programmable Read-Only Memory (EEPROM), flash memory or other memory technology, Compact Disc Read-Only Memory (CD-ROM), Digital Versatile Disc (DVD) or other optical storage, magnetic cassettes, magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media such as modulated data signals and carrier waves.
[0127] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.
[0128] The foregoing is merely an embodiment of the present disclosure and is not intended to limit the present disclosure. Various modifications and variations are possible for those skilled in the art. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present disclosure are intended to be included within the scope of the claims of the present disclosure.
Claims
1. An alarm analysis method, comprising: Obtaining a target problem, where the target problem is associated with a target security alarm of user resources; Inputting the target problem into a security model so that the security model performs action planning on the target problem to obtain action planning information for the target problem; The action planning information is used to describe the actions to be taken to solve the target problem; If the action planning information includes at least one tool call information, then according to the at least one tool call information, at least one target alarm processing tool is called to execute the alarm information processing operation associated with the target problem, and at least one alarm information processing result is obtained; Inputting the at least one alarm information processing result into the security model so that the security model outputs an alarm analysis result corresponding to the target problem according to the at least one alarm information processing result.
2. The method according to claim 1, before inputting the target problem into the security model, further comprising: Obtaining multiple groups of training samples for the alarm analysis scenario, and any group of training samples includes: a prompt word sample and a reply sample; wherein, the prompt word sample includes: a preset candidate alarm processing tool, parameter input format information of the preset candidate alarm processing tool, and a problem sample; the reply sample includes: a target alarm analysis tool sample selected from the preset candidate alarm processing tools, an interface input data sample matching the parameter input format information of the target alarm analysis tool sample, an alarm information processing result sample returned by the target alarm analysis tool sample, and an alarm analysis result sample obtained according to the alarm information processing result sample; Training the security model according to the multiple groups of training samples so that the security model learns action planning knowledge according to the multiple groups of training samples.
3. The method according to claim 1 or 2, inputting the target problem into the security model so that the security model performs action planning on the target problem to obtain action planning information for the target problem, including: In the security model, according to the action planning knowledge learned in advance from sample data, at least one target alarm analysis tool for processing the target problem is determined from the preset candidate alarm processing tools, and according to the target problem and the parameter input format information of the at least one target alarm analysis tool, the interface input data corresponding to each of the at least one target alarm analysis tool is determined; According to the interface identifiers and interface input data of the at least one target alarm analysis tool, the action planning information including the at least one tool call information is output.
4. The method according to claim 3, according to the at least one tool call information, calling at least one target alarm processing tool to execute the alarm information processing operation associated with the target problem, and obtaining at least one alarm information processing result, including: If the at least one tool call information includes a first interface identifier corresponding to a script calculation tool and first interface input data corresponding to the script calculation tool, then call the script calculation tool according to the first interface identifier, and provide the first interface input data to the script calculation tool, so that the script calculation tool performs a calculation operation on the first interface input data to obtain a calculation result as an alarm information processing result; The script calculation tool includes at least one of: a vector processing tool, an encoding tool, a decoding tool, an encryption tool, and a decryption tool; and / or, If the at least one tool call information includes a second interface identifier corresponding to a search tool and second interface input data corresponding to the search tool, then call the search tool according to the second interface identifier, and provide the second interface input data to the search tool, so that the search tool performs a search operation on the second interface input data to obtain a search result as an alarm information processing result; and / or, If the at least one tool call information includes a third interface identifier corresponding to a threat intelligence call tool and the search tool corresponding to the third interface input data, then call the threat intelligence call tool according to the third interface identifier, and provide the third interface input data to the threat intelligence call tool, so that the threat intelligence call tool performs a threat intelligence call operation on the third interface input data to obtain a threat intelligence call result as an alarm information processing result.
5. The method according to claim 3, calling at least one target alarm processing tool to perform an alarm information processing operation associated with the target problem according to the at least one tool call information, and obtaining at least one alarm information processing result, including: If the at least one tool call information includes a fourth interface identifier corresponding to a target knowledge base tool and fourth interface input data corresponding to the target knowledge base tool, then call the target knowledge base according to the fourth interface identifier, and provide the fourth interface input data to the target knowledge base, so that the target knowledge base performs knowledge matching according to the fourth interface input data to obtain a knowledge matching result as an alarm information processing result.
6. The method according to claim 5, wherein the target knowledge base includes: Private knowledge base; The method further includes: Obtain log data and host behavior data corresponding to historical security alarms; Extract entities and relationships between entities from the log data and behavior data; Construct a private knowledge base based on a graph according to the entities and relationships between entities.
7. The method according to claim 5, wherein the target knowledge base includes: Real-time knowledge vector library; Determine the interface input data corresponding to each of the at least one target alarm analysis tool according to the target problem and the parameter input format information of the at least one target alarm analysis tool, including: performing vectorization processing on the target problem according to the parameter input format information of the real-time knowledge vector library to obtain a problem vector of the target problem as the interface input data corresponding to the real-time knowledge vector library; Invoke the target knowledge base according to the fourth interface identifier, and provide the fourth interface input data to the target knowledge base, so that the target knowledge base performs knowledge matching according to the fourth interface input data, and obtains a knowledge matching result as an alarm information processing result, including: Invoke the real-time knowledge vector library according to the fourth interface identifier, and provide the problem vector to the real-time knowledge vector library to retrieve at least one knowledge vector matching the problem vector in the real-time knowledge vector library as an alarm information processing result.
8. The method according to claim 7, further comprising: Obtain real-time updated security knowledge from the real-time security knowledge base at a set period; Perform vectorization processing on the real-time updated security knowledge to obtain real-time updated security knowledge vectors; Store the real-time updated security knowledge vectors in the real-time knowledge vector library.
9. The method according to any one of claims 1-8, further comprising: If the action planning information does not include any tool call information, obtain the target task type corresponding to the target problem; Determine the target alarm processing tool corresponding to the target task type according to the corresponding relationship between different predefined task types and different alarm processing tools; Invoke the target alarm processing tool to execute the alarm information processing operation associated with the target problem, and obtain an alarm information processing result; Input the alarm information processing result into the security model, so that the security model outputs an alarm analysis result corresponding to the target problem according to the alarm information processing result.
10. The method according to any one of claims 1-9, for obtaining a target problem, including: Obtain, through an input interface provided to the user, a problem associated with the target security alarm of the user resource input by the user as the target problem; Or, Generate at least one recommended problem according to the security status data of the user resource, and obtain the target problem according to the user's selection operation on the At least one recommended problem; or Provide the user with a prompt word script corresponding to the target security alarm, and determine the target problem according to the selected prompt word according to the user's selection operation on at least one problem in the prompt word script.
11. After inputting the at least one alarm information processing result into the security model according to the method of claim 10, so that the security model outputs an alarm analysis result corresponding to the target problem according to the at least one alarm information processing result, further comprising: Obtain the feedback information of the user on the alarm analysis result; Update the prompt word script corresponding to the target security alarm according to the feedback information.
12. After obtaining the action planning information of the target problem according to the method according to any one of claims 1-11, further comprising: Record the correspondence between the target problem and the action planning information, so that when the target problem is received next time, according to the action planning information, invoke the at least one target alarm processing tool to execute the alarm information processing operation associated with the target problem.
13. The method according to any one of claims 1-12 further comprises: If the action planning information includes indication information for direct reply, generating answer information corresponding to the target question by using the security model.
14. The method according to any one of claims 1-13, wherein the security model comprises: A large model in the security field obtained by fine-tuning the instructions of a generative large language model with the number of parameters greater than a set threshold.
15. A server, comprising: A memory and a processor; The memory is used to store one or more computer instructions; The processor is used to execute the one or more computer instructions for: executing the steps in the method according to any one of claims 1-14.
16. A computer-readable storage medium storing a computer program, wherein when the computer program is executed by a processor, it can implement the alarm analysis method according to any one of claims 1-14.
17. A computer program, wherein when the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1-14.
Citation Information
Patent Citations
Interactive intelligent response system
CN110232573A
IT knowledge intelligent operation management system
CN111221799A
Problem diagnosis system and method based on AI
CN116932148A
Construction method of data analysis tool for information security and electronic equipment
CN117155712A
Automatic Detection of Required Tools for a Task Described in Natural Language Content
US20180157641A1
Cited By
Network attack and defense strategy generation method and device, equipment and storage medium
CN120750603A
Autonomous mobile robot passage control method and device, medium and equipment
CN121165720A
Risk mining and replying method and device for content security, medium and product
CN121501964A
Security event studying and judging method and device, electronic equipment and storage medium
CN121690695A