The invention relates to the technical field of
network security, in particular to a multi-dimensional
threat traffic detection method based on a large
language model and a security
protection system, which are used for solving the problem that when an existing network
threat detection and
protection system processes multi-source heterogeneous
threat traffic from each layer of a network, the threat traffic cannot be detected. The problems of technical bottlenecks such as multi-dimensional flow semantic segmentation,
attack behavior modeling shallow stratification, static
lag of detection rules and lack of
interpretability of response strategies generally exist; according to the method, space-time joint reasoning of
attack behaviors is realized by fusing a graph structure and
time evolution characteristics through a large
language model: modeling is performed in combination with a graph neural network and a
time sequence, node representation fusing
semantics, a structure and the
time sequence is generated, Q-learning path deduction is introduced, a high-value target is accurately identified, and an
attack path is restored; and finally, a structured intention containing a target, a condition, a path and a strategy and a behavior chain graph with a
time sequence tag are output, so that the accuracy, the
interpretability and the perspectiveness of attack intention recognition are remarkably improved.