iT邦幫忙

2026 iThome 鐵人賽

DAY 17
0
AI Security

30 天打造 AI 輔助 SOC 資安事件分析平台系列 第 17 篇

Day 17|Prompt Engineering:讓 AI 從聊天機器人變成 SOC Analyst Assistant

  • 分享至 

  • xImage
  •  

Prompt Engineering:

我使用同一筆 Network Scan 測試事件,逐步改變 Prompt 的內容,觀察 AI 回答的差異。
建立新檔案:nano prompt_test.py
https://ithelp.ithome.com.tw/upload/images/20261001/201777549YixpJuv6g.png

Prompt 1:最簡單的 Prompt

在nano prompt_test.py底下加入

prompt1 = f"""
Analyze this security event:

{event}
"""

response1 = client.models.generate_content(
    model="gemini-flash-lite-latest",
    contents=prompt1
)

print("===== Prompt 1 =====")
print(response1.text)

第一次測試只給 AI 一個非常簡單的指令「Analyze this security event」,沒有指定 AI 的角色、Severity 定義或回答格式。藉此觀察 LLM 在缺乏明確指示時會如何解讀事件。
https://ithelp.ithome.com.tw/upload/images/20261001/20177754b98LyKtxSY.png
第一個 Prompt 並沒有提供其他背景資訊。這種方式雖然可以取得分析結果,但 AI 必須自行判斷回答的深度、對象與分析方式。

Prompt 2:告訴 AI「你是誰」

第二次測試則加入「You are a SOC Analyst Assistant」的角色設定,並說明回答對象是資安初學者,希望 AI 使用較容易理解的方式說明事件。
把 prompt1 以下改成:

prompt2 = f"""
You are a SOC Analyst Assistant.

Your job is to help a cybersecurity student understand
security events.

Please analyze the following event in simple language.

{event}
"""

response2 = client.models.generate_content(
    model="gemini-flash-lite-latest",
    contents=prompt2
)

print("===== Prompt 2 =====")
print(response2.text)

https://ithelp.ithome.com.tw/upload/images/20261001/201777546DIhEvwJSS.png

Prompt 3:設計 SOC Prompt

第三次測試進一步加入本系統的 Severity 定義,例如 1 代表 High、2 代表 Medium、3 代表 Low,同時明確要求 AI 說明事件內容、風險程度、可能的安全風險,以及 SOC 人員下一步可以檢查的項目。
把 Prompt 改成:

prompt3 = f"""
You are a SOC Analyst Assistant.

Your task is to help a cybersecurity student understand
security events. Do not make the final blocking decision.

Severity definition:
1 = High
2 = Medium
3 = Low

Please analyze the following security event:

{event}

Please explain:

1. What happened?
2. What does the severity mean?
3. What is the possible security risk?
4. What should a SOC analyst check next?

Use simple and concise language.
"""

response3 = client.models.generate_content(
    model="gemini-flash-lite-latest",
    contents=prompt3
)

print("===== Prompt 3 =====")
print(response3.text)

https://ithelp.ithome.com.tw/upload/images/20261001/20177754JqhmEdgElP.png
Do not make the final blocking decision.AI 提供分析輔助,而不是替 SOC 人員直接做最終處置決策。
Prompt Engineering 並不只是把問題寫得更長,而是提供 LLM 執行任務所需要的角色、背景、規則與輸出要求。尤其像 Severity 數值這類屬於系統內部定義的資訊,如果沒有明確告訴模型,就不應假設 AI 一定能正確理解。


上一篇
Day 16|串接 LLM API : SOC Dashboard 加入 AI
系列文
30 天打造 AI 輔助 SOC 資安事件分析平台 共 17 篇
圖片
  熱門推薦
圖片
{{ item.channelVendor }} | {{ item.webinarstarted }} |
{{ formatDate(item.duration) }}
直播中

尚未有邦友留言

立即登入留言