Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

17764results about "Platform integrity maintainance" patented technology

Context-aware privileged access control system for dynamic risk-based authorization

A context-dependent, privileged access control system for dynamic, risk-based authorization, consisting of: a context acquisition subsystem configured to ingest and normalize multimodal contextual data streams from a variety of sources, including endpoint telemetry, geolocation sensors, user authentication metadata, device status metrics, and network traffic descriptors; a behavior profiling processing unit communicatively coupled to the context detection subsystem, the engine configured to maintain per-user behavior baselines using unsupervised learning models and to compute behavioral deviation vectors in real time for each privileged access request; a dynamic risk assessment module operatively connected to the behavioral profile processing unit, the module configured to calculate a multidimensional risk score for each session by applying a weighted aggregate function to behavioral deviation vectors, device risk posture, threat intelligence indicators, and environmental context volatility; a policy decision engine configured to apply programmable access control policies to the calculated risk score using a context-sensitive policy scoring language, wherein the engine is further configured to dynamically determine whether to authorize, deny, elevate, or revoke privileged access according to the current trust thresholds and permission boundaries; A permission enforcement controller unit communicatively connected to one or more endpoints, cloud services, and virtual infrastructure resources. The framework is configured to implement policy decisions by generating ephemeral access tokens, providing just-in-time (JIT) permissions, and initiating permission revocation workflows upon contextual anomalies. a secure hardware appliance consisting of a plurality of tamper-evident modules configured to host the behavioral profile processing unit, the risk assessment module, and the policy decision control unit in a trusted execution environment isolated from general computing resources.
Owner:KOTAPATI RAVI KUMAR FRISCO

Dynamic sensitive data outbound risk assessment method and system based on multi-source risk information

The invention discloses a dynamic sensitive data outbound risk assessment method and system based on multi-source risk information in the technical field of data cross-border. The system is mainly composed of a multi-source risk information acquisition module, a dynamic security identifier generation module, a risk collaborative assessment engine, a dynamic weight adjustment module, a disposal range dynamic calculation module and a flexible emergency disposal module, and an acquisition-identifier-assessment-calculation-disposal full-process closed-loop architecture is formed. A full-process closed-loop processing framework of collection-identification-evaluation-calculation-disposal is innovatively proposed, and by combining a dynamic risk evaluation model, a reinforcement learning intelligent technology and a block chain evidence storage technology, the problems of insufficient dynamic nature, lack of collaboration and lack of closed-loop capability in the prior art are systematically solved; and high-precision evaluation, real-time response and traceable management and control of the cross-border data flow risk are realized.
Owner:积至(海南)信息技术有限公司

Vulnerability management method and system based on adaptive security platform

The invention relates to the technical field of vulnerability management, and discloses a vulnerability management method and system based on an adaptive security platform. The method comprises the following steps: constructing an asset information database based on all IT assets in an organization network environment, and calculating a time sensitivity parameter set; based on the asset information database and the time sensitivity parameter set, executing aperiodic time stratification vulnerability data collection and dynamic self-shaping processing to obtain a standardized structure vulnerability data set; performing vulnerability utilization chain topology analysis through the bidirectional adversarial neural network model to generate a vulnerability risk score and a vulnerability association relationship graph; and generating vulnerability risk decision information according to the vulnerability risk score and the vulnerability association relationship graph, and performing constraint perception adaptive repair arrangement based on the vulnerability risk decision information to generate an optimal vulnerability repair scheme. The vulnerability discovery process is more efficient and accurate, the repair success rate is improved, the service interruption time is shortened, and continuous optimization of the repair process is achieved.
Owner:SHAOGUAN COLLEGE

Guiding query creation for a generative artificial intelligence (AI)-enabled assistant

Guiding query creation for a generative artificial intelligence (AI)-enabled assistant, including: receiving, via a natural language interface for a security framework monitoring a cloud deployment, a natural language input comprising one or more entity identifiers; gathering information based on the one or more entity identifiers; providing, to a generative artificial intelligence (AI) model, a prompt based on the natural language input and comprising the gathered information; and receiving, from the generative AI model, a response to the prompt.
Owner:FORTINET INC

Systems and Methods for Protecting Machine Learning (ML) Units, Artificial Intelligence (AI) Units, Large Language Model (LLM) Units, Deep Learning (DL) Units, and Reinforcement Learning (RL) Units

Systems and methods for protecting and fortifying machine learning engines, artificial intelligence (AI) engines, large language models, deep learning engines, reinforcement learning engines, and AI-based agentic units. An Offline Protection Unit analyzes characteristics of a Protected Engine, and performs offline fortification of the Protected Engine against attacks; by changing operational properties or operational parameters of the Protected Engine to reduce its vulnerability to attacks. An Online Protection Unit performs analysis of at least one of: (i) inputs that are intended to be inputs of the Protected Engine, (ii) outputs that are generated by the Protected Engine; and based on the analysis, dynamically performs online fortification of the Protected Engine against attacks; by dynamically changing operational properties or operational parameters of the Protected Engine to reduce its vulnerability to attacks.
Owner:DEEPKEEP LTD

Secure Systems of Guardrails for Securing the Use of Large Language Models (LLMS)

The present disclosure includes computer-implemented methods of guardrails for securely using large language models (LLMs). The method comprises monitoring user data flow using an application programming interface (API) and receiving an administrative policy from an administration communication interface. The method involves dynamically applying a plurality of LLM input inspectors to LLM input data. The application of the plurality of LLM input inspectors is based on the administration policy. The dynamic application of the plurality of LLM input inspectors is in sequence for latency optimization. The plurality of LLM input inspectors serve as LLM input guardrails for a plurality of secure deployed large language models (LLMs). The plurality of LLM input inspectors are configured by the administrative policy and validate the LLM input data to validated LLM input data based on the administration policy. Additionally, the method comprises dynamically applying a plurality of LLM output inspectors to LLM output data.
Owner:WITNESSAI INC

System and method for ai safety red-teaming with policy fuzzing and adversarial prompting

The present invention discloses a system and method for performing artificial intelligence (AI) safety red-teaming with integrated policy fuzzing and adversarial prompting to systematically identify, characterize, and mitigate unsafe or non-compliant behaviors in AI models. The disclosed invention automates the process of generating, executing, and analyzing adversarial test cases through coordinated functional units comprising a policy fuzzing unit, an adversarial prompting unit, an execution sandbox, a telemetry processing unit, a scoring and triage processor, and a cryptographic provenance processor. The system applies grammar-driven and reinforcement-based fuzzing techniques to vary policy descriptors, model configuration parameters, and instruction hierarchies, while a learned adversarial prompt generator synthesizes contextually coherent adversarial prompts optimized for maximum policy violation likelihood. The generated prompts and policy vectors are executed in an isolated, instrumented sandbox that records input-output interactions, timing characteristics, and intermediate representations.
Owner:MOGALI SUNEEL KUMAR +3

Method and system for analyzing embedded systems

Method and system for analyzing software or firmware of computing systems to assess security properties includes loading predicate device input data including characteristics about predicate devices; translating predicate device input data into predicate device model data describing characteristics or dependencies of the predicate device input data relevant to the analysis; determining digital twin configuration data used to configure digital twin; loading the digital twin configuration data onto the digital twin; storing configuration data in the memory; instructing the digital twin to configure itself to implement the loaded digital twin configuration data; determining security analysis to be carried out on the digital twin; simulating the predicate device; executing security analysis on the digital twin; generating output data describing the result of execution of the security analysis; storing output data pertaining to the result; and determining if the result satisfies a predetermined condition, and if so, executing action corresponding to the result.
Owner:OBJECTSECURITY LLC

Activity monitoring of a cloud compute environment based on container orchestration data

Activity monitoring of a cloud compute environment based on container orchestration data may be performed by a data platform. For example, the data platform may obtain audit log data generated by a container orchestrator within a cloud compute environment, generate a data model based on the audit log data, and use the data model to monitor the activity for a security issue. The data model may be indicative of activity occurring with respect to one or more containerized applications executing within the cloud compute environment and the monitored activity may be activity with respect to the one or more containerized applications. Corresponding methods, systems, and products are also disclosed.
Owner:FORTINET INC

Attack path risk mitigation by a data platform

An illustrative method includes scanning a compute environment associated with an entity and identifying one or more attack paths from a network to one or more datasets associated with the entity. The one or more attack paths each include a series of risk artifacts within the compute environment that can be exploited by an attacker to access the one or more datasets. The method further includes generating one or more attack path risk scores associated with the one or more attack paths and indicative of one or more levels of risk that the one or more attack paths could be exploited to access the one or more datasets. A risk mitigation operation associated with the one or more attack paths is performed based on the one or more attack path risk scores.
Owner:FORTINET INC

Dynamic authority management system and method based on multi-source salary data integration

The invention discloses a dynamic authority management system and method based on multi-source salary data integration, and relates to the technical field of salary data management, and the method comprises the following steps: collecting role names, authority boundaries and operation granularity information from a plurality of business systems, and generating structured role semantic ontology entries based on a field-level semantic annotation mode; and disassembling the to-be-mapped role according to the authority dimension, calculating a semantic similarity index between the to-be-mapped role and the standard role based on the role semantic ontology library, and outputting a role consistency scoring matrix. According to the method, the authority difference is identified through the role semantic ontology and the similarity score, the minimum authorization judgment is realized in combination with the rule engine and reinforcement learning, the audit traceability and anomaly detection are guaranteed by using the block chain and the dynamic graph, and finally a strategy self-evolution closed loop is constructed. And the problems of permission mismatching and data leakage caused by role semantic inconsistency are effectively solved.
Owner:HUNAN BAIFEITE INFORMATION TECH CO LTD

CAPEC vulnerability management system based on large language model

The invention discloses a CAPEC vulnerability management system based on a large language model, and belongs to the technical field of network security. The system comprises three modules: a vulnerability-CAPEC dynamic mapping module jointly encodes vulnerability description and code context through a bimodal large language model, accurately associates vulnerability logic with a CAPEC attack mode in combination with comparative learning and knowledge graph construction, and breaks through semantic limitation of traditional rule matching; the adversarial repair code generation module is used for generating high-robustness repair codes through adversarial training and syntax tree verification by fusing CAPEC relieving suggestions and code features on the basis of the association result, so that the secondary vulnerability risk is remarkably reduced; and the full-process automatic verification and DevOps integration module performs multi-dimensional security verification such as symbolic execution, fuzzy testing and the like on the generated repair code, and deeply integrates a development tool chain to realize real-time pushing and closed-loop management of a repair scheme.
Owner:BEIJING SHIXING TECH CO LTD

Autonomous agent observation and control

Systems, methods, and devices that relate to monitoring and managing autonomous agents are disclosed. In one example aspect, the method includes receiving activity data from autonomous agents in an operational environment, deploying static and dynamic observing agents to monitor expected behavior and deviations, detecting a deviation by an autonomous agent, determining the cause through analysis, performing a mitigative action based on the cause, and executing a preventative action to block similar future deviations. The method may also involve configuring observing agents with different observation modalities, periodically modifying observation parameters unpredictably, facilitating direct communication between observing agents, resolving conflicts in observations, and updating observation policies. Mitigative actions can include disabling credentials, rerouting communications, and logging actions. Preventative measures may involve updating behavioral policies and adjusting agent parameters to disincentivize problematic behaviors.
Owner:CITIBANK N A

Dynamic digital watermarking system for real-time user activity fingerprinting and unauthorized access tracking

A method is provided for dynamically generating a digital watermark for a data file. The method includes receiving a request to access the data file from a user; dynamically generating an encryption key based on at least one parameter selected from the group consisting of the identity of the user, the time of access, and the mode of access; embedding a digital watermark into the data file using the dynamically generated encryption key, wherein the digital watermark is unique to the request; providing access to the data file with the embedded digital watermark to the user; and storing information related to the encryption key and the parameters used for its generation in a secure database.
Owner:LEPTUDE INC

Cybersecurity threat detection and mitigation classification system

In some implementations, a cybersecurity threat detection and mitigation system is provided. The system refines an artificial intelligence (AI) model with a corpus of historical data that represents security events that occurred, queries that were submitted by security analysts in response to the security events, and actions that were performed for mitigating the security events. Telemetry data that corresponds to behavior and performance of a computer network is collected and provided to the AI model. Based on the telemetry data, the AI model predicts a potential security threat to the computer network and performs an assessment of risk to the computer network. When the assessment of risk to the computer network indicates that the potential security threat is an actual security threat, a security alert that corresponds to the actual security threat is triggered. Other embodiments are described and claimed.
Owner:ARCTIC WOLF NETWORKS INC

Cloud compliance monitoring for a cloud compute environment managed by a container orchestrator

Cloud compliance monitoring for a cloud compute environment managed by a container orchestrator may be performed by a data platform. For example, the data platform may obtain cluster configuration data from a control plane of a cluster that is managed by a container orchestrator within a cloud compute environment, obtain node configuration data from one or more compute nodes associated with a data plane of the cluster that is managed by the container orchestrator, and generate a compliance statement based on the cluster configuration data and node configuration data. The compliance statement may indicate a configuration posture of the cloud compute environment according to a compliance benchmark. Corresponding methods, systems, and products are also disclosed.
Owner:FORTINET INC

Container vulnerability management by a data platform

An illustrative method includes accessing, by a data platform, an alert generation policy associated with an entity that deploys containers in a cloud environment, the alert generation policy modifiable by the entity and specifying criteria for providing alerts associated with one or more vulnerabilities associated with the containers; detecting, by the data platform based on a scan of a container included in the containers, a vulnerability associated with the container; determining, by the data platform, an attribute of the vulnerability; and generating, by the data platform when the attribute meets the criteria specified in the alert generation policy, an alert associated with the vulnerability.
Owner:FORTINET INC

System and Method for Network Weight Compression and Intrusion Detection

A system and method for neural network weight compression with intrusion detection capabilities that optimizes model storage and transmission while providing security. The system analyzes weight characteristics to identify statistical properties within different neural network layers, generates optimized encoding schemes based on the analysis, and creates reference distributions for security verification. The compression process employs a multi-resolution approach that produces a progressive representation with base and enhancement layers, enabling flexible deployment across diverse computing environments. Security markers and statistical fingerprints can be embedded throughout the encoded representation, allowing for detection of unauthorized modifications during transmission or deployment. The system monitors encoded weight streams, measures distribution divergence against reference baselines, and generates alerts when statistical anomalies indicate potential tampering. This approach achieves superior compression ratios while maintaining model performance and providing robust protection against increasingly sophisticated attacks targeting neural network weights.
Owner:ATOMBEAM TECH INC

Container mirror image security management method and system

The invention relates to the technical field of data access security, and discloses a container mirror image security management method and system, and the method comprises the steps: constructing a container mirror image, generating a differential encryption key through a strategy center, carrying out the encryption strategy of a kernel dependence layer, a runtime environment layer, an application code layer and a sensitive configuration layer, and forming a hierarchical protection basis. If an access request is triggered, firstly collecting equipment fingerprints and geofence information and evaluating an environmental risk score, verifying access authority and an access scene matching degree through attribute-based encryption, analyzing operation track characteristics in real time, identifying an abnormal mode, and if the three-layer verification is passed, generating a temporary access token; according to the method, access request authority is verified, a temporary access token is matched, key fragments are synthesized, a master key is only temporarily generated in a memory and encrypted and stored, and through combination of a double-layer encryption channel and inner-layer and outer-layer defense, the anti-attack ability of container mirror image transmission is improved, and man-in-the-middle attack and data tampering are effectively coped with.
Owner:NANJING TORTOISE & HARE RACE SOFTWARE RES INST CO LTD

Failure chain quantitative analysis and risk assessment method and system based on multi-level security model

The invention discloses a failure chain quantitative analysis and risk assessment method and system based on a multi-level security model, and aims to solve the defects that accident cause analysis of a complex social technology system is inaccurate, and a risk assessment result is lack of effective verification. According to the method, a multi-level causal model is systematically constructed, a multi-dimensional failure chain (MDFC) is extracted, multi-dimensional risk quantification is performed on the MDFC, a directed weighted failure propagation network is constructed based on the multi-dimensional risk quantification, and structural features of the directed weighted failure propagation network are analyzed to identify key risk factors. The core innovation of the method is that reverse accident reason tracing and forward risk propagation path analysis based on the weighted network are fused, mutual verification and iterative optimization are realized by comparing analysis results of the two paths, so that the understanding of an accident evolution mechanism is deepened, and the reliability of evaluation is improved. The system vulnerability can be revealed more comprehensively, powerful support is provided for formulating accurate risk control measures, and the overall safety level of a complex system is improved.
Owner:CHINA UNIV OF PETROLEUM (EAST CHINA)

Compute resource risk mitigation by a data platform

An illustrative method includes identifying, based on a scan of a compute environment associated with an entity, a plurality of attack paths from one or more networks to one or more datasets associated with the entity and determining a set of one or more attack paths included in the plurality of attack paths that include a particular risk artifact. Based on one or more characteristics of the set of one or more attack paths, a risk score specific to the particular risk artifact may be determined and a risk mitigation operation associated with the particular risk artifact may be performed.
Owner:FORTINET INC

Detecting and mitigating prompt injection attacks on large language models

Systems and methods for detecting and mitigating prompt injection attacks on a generative LLM are disclosed. A deployment scenario is considered, in which the generative LLM supports a task automation function. Prompts are received and interpreted by the generative LLM, and outputs from the generative LLM are used to trigger automation actions. The prompts are constructed based on a combination of user input and external data and are, therefore, vulnerable to prompt injection attacks though manipulation of the external data. To mitigate this risk, a separate discriminative classification, decoupled from the generative LLM, engine is configured to identify malicious prompts, and filter out any malicious prompts before they reach the generative LLM.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Smart recognition and consumer-centric activity recognition based system for battery management in mobile device

PendingUS20260006557A1Power managementPlatform integrity maintainanceActivity classificationElectrical battery
The present invention relates to an intelligent, context-aware battery management system embedded within a mobile device that dynamically allocates power resources based on real-time user behavior, system state, and environmental context. It incorporates a smart recognition engine that analyzes sensor-derived telemetry data to compute behavioral deviation scores, enabling the system to anticipate abnormal or emergency-prone conditions. A continuous activity classification module contextualizes user motion and geolocation to inform power policy decisions. Upon detecting significant behavioral anomalies or critically low battery conditions, an emergency mode subsystem is triggered, restricting device operations to essential functionalities while preserving energy for critical communication and navigation tasks. The system also establishes a secure, lightweight emergency communication tunnel for relaying essential metadata, including GPS and behavioral indicators, to predefined response servers.
Owner:ALMALKI SULTAN AHMED +3

Community-based generation of policies for a data platform

A disclosed data platform may be configured to access a custom policy developed by a particular client entity that uses the data platform. The custom policy may invoke a query that targets a target dataset ingested from a cloud environment and stored in a data store. The data platform may determine that the custom policy is likely to be of value to one or more other client entities, besides the particular client entity, that also use the data platform. In response to the determining that the custom policy is likely to be of value to the one or more other client entities, the data platform may generate a community policy based on the custom policy. The community policy may be available for use by the one or more other client entities. Corresponding methods, systems, and products are also disclosed.
Owner:FORTINET INC

Power generation side industrial control system network security target building method based on virtual-real combination

The invention discloses a virtual-real combination-based power generation side industrial control system network security target construction method. The method comprises the following steps of: constructing a virtual-real combination target environment consisting of a physical equipment layer and a virtual model layer; the heterogeneous industrial control protocol between the physical equipment layer and the virtual model layer is analyzed, protocol semantic information is extracted, and a bidirectional dynamic mapping rule of a physical equipment state and a virtual model state is generated based on the protocol semantic information; based on a state change event of the physical equipment layer, according to a bidirectional dynamic mapping rule, synchronizing changed equipment state data to the virtual model layer in real time, and simulating protocol behavior logic corresponding to the equipment state data in the virtual model layer according to a security test requirement; and based on the attack instruction or the abnormal state signal generated by the virtual model layer, according to the protocol specification format of the target physical equipment, converting the instruction or the signal into an executable control command, and driving the physical equipment layer to execute an operation corresponding to the control command.
Owner:HUANENG POWER INT INC +1

Intelligent risk identification and self-adaptive repair method, system and equipment for software supply chain and medium

The invention discloses an intelligent risk identification and self-adaptive repair method, system and device for a software supply chain and a medium, belongs to the field of network security and automatic software engineering, and aims to solve the technical problem of how to accurately and comprehensively identify software code supply chain risks including code snippets. A reliable and efficient automatic closed-loop repair scheme is provided, and the technical defects that in the prior art, the software code supply chain recognition range is limited, the repair process is rigid and the reliability is low are overcome. Analyzing the declarative dependency; meanwhile, semantic traceability based on artificial intelligence is carried out on the code snippets, and a global software material list is generated; and performing intelligent mapping on the software components in the global software bill of materials and the vulnerability database to identify risks.
Owner:SHANDONG ZHENBAI INFORMATION TECHNOLOGY CO LTD

Federated distributed computational graph architecture for biological system engineering and analysis

A federated distributed computational system enables secure collaboration across institutions for unified biological and multiomics data analysis. It comprises interconnected computational nodes managed by a central federation manager. Each node includes specialized components: a local computational engine for biological data processing, a privacy-preservation system, a knowledge integration component leveraging dynamic knowledge graphs, and a secure communication interface. The federation manager coordinates computational activities while ensuring security, privacy, legality, and contractual adherence. This architecture allows institutions, citizen scientists, and patients to collaborate on complex biological analyses without compromising sensitive data. By enabling shared computational resources and expertise, the system facilitates breakthrough discoveries while maintaining confidentiality. Additionally, it supports pro-rata or contractually defined participation in resultant benefits or knowledge, ensuring equitable collaboration.
Owner:QOMPLX INC

Artificial intelligence security vulnerability detection platform based on deep learning

The invention discloses a deep learning artificial intelligence security vulnerability detection platform, and relates to the technical field of intelligent detection, and the platform comprises an information processing module which collects heterogeneous data in real time, carries out the labeling, format unification and modal aggregation processing of the data, and generates a sample set; the feature learning module is used for performing feature unwrapping on the sample set by using a variational auto-encoder, extracting modal data features and potential space representation learning, and outputting a potential space vector; the response generation module is used for generating a vulnerability response strategy through a modal consistency verification and response template matching mechanism based on the vulnerability risk level vector in combination with a response generation engine; and the repair feedback module is used for executing automatic vulnerability repair operation in combination with federal reinforcement learning and Bayesian optimization, performing feedback optimization according to an execution result, and outputting the vulnerability repair operation and a feedback result. According to the method, the response strategy is combined with intelligent matching of the real-time risk level, so that the accuracy and adaptability of vulnerability repair are improved.
Owner:HEFEI TANOVO INFORMATION SECURITY TECH CO LTD

Jailbreak detection for language models in conversational ai systems and applications

In various examples, systems and methods are disclosed relating to language model jailbreak detection using length-perplexity metrics. A system can identify a prompt for a language model—such as an LLM, VLM, etc.—and generate a perplexity score for the prompt. The system can determine, based at least on the perplexity score and a length of the prompt, that the prompt is indicative of a jailbreak attempt for the large language model. The system can restrict the prompt from input to the large language model—or block an output generated based on the prompt from being shared—responsive to determining that the prompt is indicative of the jailbreak attempt.
Owner:NVIDIA CORP

Capturing and using application-level data to monitor a compute environment

An illustrative method includes receiving, by a data platform configured to monitor the compute environment, runtime workload data collected by an agent deployed to the compute environment, wherein the runtime workload data comprises user space data collected from a user space of the compute environment and kernel space data collected from a kernel space of the compute environment. The method further includes performing, by the data platform, a monitoring operation based on the user space data and the kernel space data of the runtime workload data.
Owner:FORTINET INC