我使用同一筆 Network Scan 測試事件,逐步改變 Prompt 的內容,觀察 AI 回答的差異。
建立新檔案:nano prompt_test.py
在nano prompt_test.py底下加入
prompt1 = f"""
Analyze this security event:
{event}
"""
response1 = client.models.generate_content(
model="gemini-flash-lite-latest",
contents=prompt1
)
print("===== Prompt 1 =====")
print(response1.text)
第一次測試只給 AI 一個非常簡單的指令「Analyze this security event」,沒有指定 AI 的角色、Severity 定義或回答格式。藉此觀察 LLM 在缺乏明確指示時會如何解讀事件。
第一個 Prompt 並沒有提供其他背景資訊。這種方式雖然可以取得分析結果,但 AI 必須自行判斷回答的深度、對象與分析方式。
第二次測試則加入「You are a SOC Analyst Assistant」的角色設定,並說明回答對象是資安初學者,希望 AI 使用較容易理解的方式說明事件。
把 prompt1 以下改成:
prompt2 = f"""
You are a SOC Analyst Assistant.
Your job is to help a cybersecurity student understand
security events.
Please analyze the following event in simple language.
{event}
"""
response2 = client.models.generate_content(
model="gemini-flash-lite-latest",
contents=prompt2
)
print("===== Prompt 2 =====")
print(response2.text)

第三次測試進一步加入本系統的 Severity 定義,例如 1 代表 High、2 代表 Medium、3 代表 Low,同時明確要求 AI 說明事件內容、風險程度、可能的安全風險,以及 SOC 人員下一步可以檢查的項目。
把 Prompt 改成:
prompt3 = f"""
You are a SOC Analyst Assistant.
Your task is to help a cybersecurity student understand
security events. Do not make the final blocking decision.
Severity definition:
1 = High
2 = Medium
3 = Low
Please analyze the following security event:
{event}
Please explain:
1. What happened?
2. What does the severity mean?
3. What is the possible security risk?
4. What should a SOC analyst check next?
Use simple and concise language.
"""
response3 = client.models.generate_content(
model="gemini-flash-lite-latest",
contents=prompt3
)
print("===== Prompt 3 =====")
print(response3.text)

Do not make the final blocking decision.AI 提供分析輔助,而不是替 SOC 人員直接做最終處置決策。
Prompt Engineering 並不只是把問題寫得更長,而是提供 LLM 執行任務所需要的角色、背景、規則與輸出要求。尤其像 Severity 數值這類屬於系統內部定義的資訊,如果沒有明確告訴模型,就不應假設 AI 一定能正確理解。