The application relates to the technical field of network operation and maintenance, in particular to an automatic operation and maintenance method and
system based on
artificial intelligence. The method collects detailed log information containing security events in real time through a
security information and
event management system configured at a target endpoint, then uses an agent
artificial intelligence system to clean,
label and structure process the
log data, generates standardized
metadata, maps the
metadata with an MITRE ATT&CK
knowledge base, identifies the technical features and behavior patterns of attacks, compares the enriched
log data with external
threat intelligence sources, analyzes the TTP of known
attack groups, generates a
threat intelligence correlation report, uses a large
language model to generate a targeted response plan, generates an
executable command sequence according to the response plan, connects the agent executor with the
server through a
WebSocket protocol, executes the command in a
POSIX shell environment, captures and returns the execution result, verifies the execution result, performs necessary command optimization, records the optimized response to a vector
database, automatically matches historical events through a vector retrieval mechanism, triggers a predefined
response process, and realizes continuous
threat monitoring and
adaptive response. The application can solve the problem that the existing security operation and maintenance cannot form a
closed loop of terminal executor,
data enrichment and historical event recall.