The invention relates to the technical field of
network security, in particular to a
network security situation awareness method and
system based on a
large model and
threat assessment. The method comprises the following steps: firstly, acquiring and standardizing multi-
modal security data in a cloud service environment in real time, distributing a behavior
modal cluster for security event
metadata through clustering analysis, and generating a security
feature vector containing business
semantics and behavior dynamic features based on a cluster center
relocation technology; then constructing a local situation map reflecting asset topology and an access link by using a cloud
security association model; semantic reasoning is performed on the atlas through a large
language model, an
attack intention is recognized, and an
attack path is predicted; and finally, combining the path probability, the asset value and the
vulnerability feature to quantitatively calculate a
risk index, and automatically generating a
response strategy. Semantic compression of massive logs is realized through
modal clustering, and the calculation
bottleneck of
processing original data by a
large model is overcome; and in combination with graph correlation and
large model reasoning, the crossing from passive warning to active intention prediction is realized.