The invention relates to the technical field of network operation and maintenance, in particular to an automatic operation and maintenance method and
system based on
artificial intelligence, and the method comprises the steps: collecting detailed log information containing a security event in real time through a
security information and
event management system configured at a target endpoint; performing cleaning, labeling and structured
processing on the
log data by utilizing a proxy
artificial intelligence system to generate standardized
metadata, and performing MITRE ATTamp with the standardized
metadata; mapping the CK
knowledge base, identifying technical features and behavior patterns of attacks, comparing enriched
log data with an external
threat intelligence source, analyzing TTP of a known
attack group, generating a
threat intelligence association report, generating a targeted response plan by using a large
language model, generating an
executable command sequence according to the response plan, and generating a
threat intelligence association report; the proxy executor is connected with the
server through a
WebSocket protocol, executes a command in a
POSIX shell environment, captures and returns an execution result, verifies the execution result, carries out necessary command optimization, records an optimized response to a vector
database, and automatically matches a historical event and triggers a predefined
response process through a vector retrieval mechanism. And continuous threat monitoring and
adaptive response are realized. According to the method, the problem that a
closed loop aiming at a terminal executor,
data enrichment and historical event recall cannot be formed by security operation and maintenance in the prior art can be solved.