Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

450 results about "Active Defense" patented technology

Active defense. The employment of limited offensive action and counterattacks to deny a contested area or position to the enemy. See also passive defense.

Network mapping behavior anomaly detection method and system based on machine learning

A network mapping behavior anomaly detection method and system based on machine learning is provided. The method includes: collecting dual-source traffic data, generating a structured log data set through dual-source log fusion engine; performing subgraph matching calculation to obtain a mapping behavior deviation degree; generating communication data containing a watermark identifier in a session corresponding communication path; verifying whether attack events carry the watermark identifier; generating a network mapping behavior anomaly detection report. According to the disclosure, an adaptive attack behavior model is constructed through a multi-modal feature vector based on structured logs and a graph protocol mapping rule base, so that the cognitive robustness to protocol camouflage and path drift is fundamentally enhanced, a real-time verification chain of detection results is built, and traditional passive detection is transformed into self-proof active defense through cross verification of watermark carrying state and behavior trajectory.
Owner:HUANENG INFORMATION TECH CO LTD

Method and system for detecting and defending cross-domain threats of power system

The invention provides a method and a system for detecting and defending cross-domain threats of a power system. The method comprises the following steps: after carrying out anomaly identification on operation monitoring data of a physical domain node in a target power grid region to obtain an anomaly identification result and carrying out denial of service attack identification according to network flow data of an information domain node to obtain an attack identification result, carrying out abnormal event association analysis on the anomaly identification result and the attack identification result to obtain an attack cross-domain anomaly identification result; according to key nodes and key risk propagation paths in a cross-domain attack chain generated based on a graph theory algorithm, generating an attack tracing atlas, and according to vulnerability information of the key nodes in the atlas, obtaining a corresponding power system topological graph and a corresponding communication network topological graph; and iteratively generating an active defense rule based on a game theory algorithm and a reinforcement learning algorithm, and issuing the active defense rule to the node. According to the method, the cross-domain attack risk is accurately perceived in real time and adaptive security defense is executed through cross-domain abnormal event association analysis, so that the comprehensiveness and reliability of security protection of the power system are improved.
Owner:LISHUI POWER SUPPLY COMPANY OF STATE GRID ZHEJIANG ELECTRIC POWER

Electrolytic aluminum short circuit port operation safety early warning system based on multi-parameter collaborative awareness and intelligent diagnosis

The invention relates to the technical field of industrial safety, and discloses an electrolytic aluminum short circuit port operation safety early warning system based on multi-parameter collaborative awareness and intelligent diagnosis, and the system comprises a parameter collaborative awareness module, a dynamic diagnosis module, an early warning decision module, and an execution feedback module. By constructing a multi-dimensional parameter collaborative sensing mechanism, fusing temperature field distribution, current balance degree and insulation state multi-source data in real time and dynamically capturing early abnormal symptoms of a short circuit port, the hysteresis problem of traditional single-parameter threshold monitoring is solved, conversion from passive response to active defense is achieved, and the comprehensiveness and timeliness of operation state monitoring are improved; and meanwhile, based on a historical fault database and a real-time evolution model, a health index is generated and a fault path is predicted, so that maintenance personnel can pre-judge a development trend and a time window of potential risks in advance, and sudden equipment accidents are avoided.
Owner:上海品蓝信息科技有限公司

Network intrusion intelligent monitoring method and system based on deep learning

The invention provides a network intrusion intelligent monitoring method and system based on deep learning, relates to the field of network security, and solves the technical problem of response lag of an existing defense method. The method comprises the following steps: collecting multi-source data; preprocessing the multi-source data to generate a spatial-temporal feature map; inputting the spatial-temporal feature map into a first model and a second model constructed based on a deep learning algorithm for anomaly detection to obtain a detection result; wherein the first model is used for detecting a known attack mode, and the second model is used for detecting an unknown attack mode; and carrying out hierarchical risk level division on the detection result, and carrying out active defense according to the defense strategy of each risk level. The method is used in the network intrusion monitoring and defense process, intelligent monitoring and active defense of network intrusion are realized through multi-source data acquisition, spatial-temporal feature map generation, dual-model cooperative detection and layered defense strategy implementation, and the real-time performance and initiative of network security protection are improved.
Owner:常德学院

Intelligent tracking and blocking method and system for network attack chain

The invention provides an intelligent tracking and blocking method and system for a network attack chain, and relates to the technical field of network security, and the method comprises the steps: collecting network flow data, building an attack chain propagation path, setting a detection breakpoint, obtaining a data sample, carrying out the causal correlation analysis, extracting a data transmission feature, and converting the data transmission feature into a behavior sequence feature; predicting an attack chain evolution path by adopting a bidirectional feature matching mechanism; a honeypot service and a flow probe are deployed to generate an attacker portrait; and formulating a defense strategy according to the attack intention to realize attack chain blocking. According to the invention, accurate identification, effective tracking and active defense of network attacks can be realized, and the network security protection capability is improved.
Owner:BEIJING YUHONG XINAN TECHNOLOGY CO LTD

Network attack active trapping method based on intelligent scheduling

The invention discloses a network attack active trapping method based on intelligent scheduling, and the method comprises the steps: constructing a dynamic honeypot environment according to a real business system mirror image, simulating the interaction logic and data characteristics of a real business system, and generating a honeypot system; analyzing a network equipment log of an access source according to the security situation awareness platform, and capturing multi-dimensional features to identify attack traffic; dynamically generating a drainage strategy according to an identification result of the security situation awareness platform, and seamlessly switching attack traffic to a honeypot system through load balancing equipment; and recording an attack behavior chain in the honeypot system, extracting an attack tool fingerprint and tracking an attacker identity. Through dynamic simulation environment construction, intelligent traffic scheduling, full-chain traceability and intelligent resource management, high-simulation trapping, accurate attack shunting, credible electronic evidence chain generation and efficient resource utilization are realized, and the active defense efficiency is remarkably improved.
Owner:BANK OF HANGZHOU CO LTD

Power monitoring system distribution network security management active defense system

The invention relates to the technical field of network security management, in particular to an active defense system for power monitoring system distribution network security management. The safety monitoring unit is used for collecting and analyzing network data in real time; the intrusion detection unit is used for identifying suspicious activities and attack signs; the risk assessment unit further analyzes the suspicious activities and the attack signs and assesses the influence degree of the suspicious activities and the attack signs on the power grid security; and the decision support response unit provides coping strategy suggestions according to the result of the risk assessment and executes the provided countermeasures. By integrating the safety monitoring unit, the intrusion detection unit, the risk assessment unit and the decision support response unit, real-time collection, analysis and processing of network data are realized. Particularly, the intrusion detection unit adopts an advanced network flow behavior recognition model and a system log behavior recognition model, so that behaviors which are not consistent with a normal communication mode and abnormal operation records in a system log can be effectively recognized.
Owner:STATE GRID SHANDONG ELECTRIC POWER CO

Defense method and system for big language model cue word attack, terminal and medium

The invention belongs to the technical field of big language model security, and particularly discloses a defense method and system for big language model cue word attack, a terminal and a medium. Comprising the steps of receiving information content input by a user, and generating a plurality of detection input copies based on a preset rule; inputting the copies into mutually independent detection processes in parallel to obtain a plurality of risk scores; constructing a comprehensive risk score based on the risk score, and determining a risk level of the input content according to the comprehensive risk score; when the risk level falls into a defense triggering interval, executing an active defense strategy, and implementing instruction confusion, semantic dilution and structural isolation processing to generate first output content; when the risk level is below a pass threshold, second output content is generated based on the user original input. According to the method, on the premise that normal interaction experience is not affected, fine-grained, controllable and dynamic safety protection can be carried out on multi-type cue word attacks, and the overall safety and usability of a large language model are improved.
Owner:浪潮智慧科技有限公司 +2

Multi-class network security threat perception and active and passive cooperative response processing system and method

The invention discloses a multi-class network security threat perception and active and passive cooperative response processing system and method, and the system comprises a multi-class threat perception module which is used for perceiving a plurality of security threats existing in a network environment, and transmitting an obtained security event to a threat information association module; the threat information association module is used for analyzing and integrating various security events and extracting threat information from the security events; the attack graph-based threat path analysis module is used for mining vulnerability information in a network system, describing a network topology structure and an operation state, constructing an attack graph and obtaining active defense nodes in combination with a currently occurring security event and an analysis result of the attack graph; and the strategy generation module generates a corresponding response processing strategy according to the threat information and the property and the emergency degree of the security event, and generates an active defense strategy in combination with the active defense node, thereby realizing active defense and advanced deployment and control of potential threats. According to the invention, network security threats can be timely and effectively found and coped with.
Owner:CHINA ELECTRONICS TECH CYBER SECURITY CO LTD +2

Wireless communication anti-interference method and system based on data analysis

The invention discloses a wireless communication anti-interference method and system based on data analysis, and belongs to the technical field of communication anti-interference, in the wireless communication anti-interference method and system based on data analysis, the active defense capability of the system to unknown interference is improved through virtual interference generation and physical suppression by linkage cooperation of a generative adversarial network and an adaptive beam forming algorithm. The generator continuously simulates a novel interference signal injection training environment, so that a beam forming algorithm learns in advance to form accurate null in an interference direction, and the response time when actual interference occurs is greatly shortened. Meanwhile, interference space features detected by the beam forming module in an actual scene reversely optimize a signal construction rule of the generator, and the matching degree of a generated sample and a real electromagnetic environment is enhanced. The dynamic mutual promotion mechanism not only enhances the timeliness of interference suppression, but also reduces the problems of signal quality fluctuation and excessive consumption of hardware resources caused by passive response in the traditional scheme.
Owner:WUHU ZHIXING INTELLIGENT TECHNOLOGY CO LTD

Short video active defense encryption system based on device fingerprint and dynamic confusion field

The invention relates to the technical field of short video encryption, and discloses a short video active defense encryption system based on a device fingerprint and a dynamic confusion field, and the key point of the technical scheme is that the system comprises a device fingerprint generation module, a mother video encryption module, a slice encryption module, a behavior recognition and defense module and an encryption logic update regulation and control module. The system generates a unique device fingerprint hash value through a multi-modal feature, generates a dynamic confusion field in combination with a chaotic system and a quantum random number, realizes differential encryption of a mother video and slices, and is embedded with zero-knowledge consanguinity proof to support traceability verification. The behavior recognition and defense module monitors user behaviors in real time and dynamically adjusts a confusion strategy or triggers an active defense mechanism, and the encryption logic updating regulation and control module optimizes the updating frequency according to playing data and reduces the batch crawling risk. According to the invention, the security and anti-attack capability of the short video content can be effectively improved.
Owner:HANGZHOU POPCORN EAGLE EYE TECH CO LTD

Cloud environment active defense system based on dynamic honey points

The invention provides a cloud environment active defense system based on dynamic honey spots. The system comprises a honey spot deployment and management module which generates and deploys honey spots, manages honey spot layout and provides honey spot information; the dynamic defense control module monitors network flow, perceives an attack path, analyzes attack behavior characteristics, adjusts honey point layout, generates an adjustment instruction and generates alarm information according to the attack behavior characteristics; the attack chain tracking and analyzing module is used for acquiring attack event data for attack behavior tracking, constructing an attack graph for attack path analysis and attack intention prediction and generating a threat intelligence report; and the system integration and management module monitors the running state and the resource use condition of each module, dynamically distributes system computing resources, and sets an interaction unit to provide interaction. According to the system, a complete deception defense mechanism is constructed, a deception environment is constructed by utilizing honey points, the honey points are dynamically adjusted according to attacks, and quick response and accurate countering are ensured through a flexible defense strategy and multi-layer cooperation.
Owner:GUANGZHOU UNIVERSITY +1

Method and device for constructing network attack behavior chain and active defense, and computer equipment

The invention belongs to the technical field of network security, and relates to a network attack behavior chain construction and active defense method and device and computer equipment, and the method comprises the steps: collecting full-flow data and a multi-source log from a network environment, and carrying out the preprocessing of the full-flow data and the multi-source log; storing the preprocessed full-flow data and multi-source logs, and establishing an associated index; through a deep learning algorithm and an unsupervised model, abnormal traffic and attack behaviors are identified from the full-traffic data and the multi-source logs; reconstructing the fragmented attack events into a complete behavior chain through a graph neural network and a visualization mode; based on the AI model, a dynamic defense strategy is generated, and a response action is automatically executed; through time sequence prediction and a deep learning model, a future attack trend is predicted, and active defense is realized. The method improves the unknown attack detection capability, optimizes the traceability efficiency, enhances the defense initiative, guarantees the real-time performance and accuracy of network attack prediction, and has compliance adaptability.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Active defense system and method for unknown threat

Provided are an active defense system and method for an unknown threat. The system includes an intelligent threat early-warning module (10), an unknown threat detection module (20) and a self-adaption defense processing module (30). The intelligent threat early-warning module (10) is configured to perform threat prediction on a power grid situation data set collected from a power information network in real time to obtain threat early-warning information and send the information to the unknown threat detection module (20). The unknown threat detection module (20) is configured to perform threat detection and analysis on collected unknown threat network data when receiving the threat early-warning information to generate a threat analysis report and send the report to the self-adaption defense processing module (30). The self-adaption defense processing module (30) is configured to trigger a defense processing operation corresponding to a preset threat defense strategy according to the threat analysis report.
Owner:INFORMATION & COMM BRANCH OF STATE GRID JIANGSU ELECTRIC POWER +3

Active defense system and method based on multi-protocol dynamic simulation and distributed trapping

The invention provides an active defense system and method based on multi-protocol dynamic simulation and distributed trapping. The active defense method based on multi-protocol dynamic simulation and distributed trapping comprises the following sub-steps: S1, constructing a multi-protocol dynamic simulation environment; s2, deploying distributed trapping nodes; s3, deep trapping of attack behaviors; s4, attack chain reconstruction and behavior analysis; s5, performing adaptive confusion and adversarial enhancement; s6, automatic threat intelligence production and feedback; by loading the protocol template library and initializing the state machine, the response can be dynamically generated according to the real-time session context, and dynamic simulation of various service protocols is adopted, so that the detection capability on network attacks is improved, potential threats can be captured more quickly, and the risks of missing report and false report are reduced; and through an automatic threat intelligence generation and feedback mechanism, in combination with IOC index identification, structured output and real-time response, a defense strategy can be quickly responded and adjusted.
Owner:CHINA LIFE INSURANCE CO LTD

PLC high-interaction honeypot system based on multi-agent task splitting and RAG enhancement

The invention relates to the crossing field of industrial control system (ICS) safety and artificial intelligence, and particularly discloses a PLC high-interaction honeypot system based on multi-agent task splitting and RAG enhancement, which adopts a localized multi-agent collaborative architecture based on edge computing and is composed of a high-simulation equipment layer and an intelligent decision-making layer. The high-simulation equipment layer comprises a PLC dynamic mirror image, an HMI interface and a sensor data generator, and an active trapping environment is constructed through protocol fingerprint confusion and virtual and real data fusion technologies. The decision-making layer deploys a multi-agent task scheduling engine, integrates four kinds of agents including protocol analysis, behavior analysis, threat assessment and response generation, and realizes attack context perception and strategy dynamic generation based on a local RAG knowledge base. The load balancing agent dynamically allocates tasks according to equipment resources, and cooperates with offline knowledge update (USB flash disk encryption synchronization threat features) to form a closed-loop defense system, thereby ensuring physical isolation of an industrial network and realizing high-fidelity active defense.
Owner:GUANGZHOU UNIVERSITY

Artificial intelligence early warning and management method for smart ocean

The invention provides an artificial intelligence early warning and management method for a smart ocean, and is applied to the field of data processing application. Aiming at the problems that intelligent ocean data is large in scale and complex in multiple sources, threat identification is single in the prior art, an early warning model lacks self-adaptive adjustment and is prone to false alarm and missing alarm, and data security is difficult to guarantee, the method is based on intelligent ocean multi-source data and a preset data set containing data types, security levels and other labels; after preprocessing, a deep learning framework is used to train a threat identification and early warning model. The model detects four types of features such as sensitive information in real-time data, extracts parameters, matches threat features to determine risk levels, and establishes mapping relationships between data types and threat and abnormal modes. Through abnormal threshold evaluation, false alarms are removed to generate initial early warning parameters, a machine learning iterative optimization model is combined, risk data are finally sorted, a response strategy is constructed and the like, a safety management scheme is formulated to generate a result, and intelligent upgrading from passive response to active defense is realized.
Owner:QUANZHOU INST OF INFORMATION ENG

Network attack active defense strategy optimization method based on deep reinforcement learning

The invention discloses a network attack active defense strategy optimization method based on deep reinforcement learning, and the method comprises the following steps: collecting multi-source data of a network environment, and carrying out the feature clipping and white list feature reservation; performing normalization and coding processing to generate a security situation vector; constructing a multi-index reward function, and generating an instant reward value and an event-level reward value; executing a double-closed-loop mechanism through an improved PPO model, and respectively outputting an instant strategy instruction and a long-term strategy parameter; performing multi-source evidence commissioning on the instant strategy instruction and the security situation vector, and judging a key evidence loss condition to obtain an execution token; inputting a risk budget pool to carry out resource quota checking, and executing anti-jitter and cooling control; and optimizing parameters of the multi-index reward function through a causal account book. According to the method, rapid response and continuous optimization of various attack behaviors can be realized, the defense effect and the resource utilization rate are considered, the false report and missing report rate is reduced, and the self-adaptability and stability of a network defense system are improved.
Owner:QIAN XINGCHENG NETWORK SECURITY TECH (HUNAN) CO LTD

Active defense method and system based on large model

The invention discloses an active defense method and system based on a large model, and relates to the technical field of security protection, and the method comprises the steps: intercepting a malicious request of an external attacker, cleaning sensitive information and adversarial samples in the malicious request, and outputting standardized data; injecting the standardized data as training data into a training confrontation sample to optimize a protection model, and ensuring the leakage traceability of the protection model by embedding a digital watermark; and trapping an attacker by deploying a honey spot interface and triggering a countering strategy, generating a dynamic defense rule by using the protection model, and updating the training confrontation sample in real time for continuous optimization of the protection model. Active attack sensing and advanced attack blocking are achieved through malicious request interception cleaning and honey spot trapping countering, dynamic defense rule generation and protection model continuous optimization are combined to adapt to attack iteration, a digital watermark tracing mechanism is matched, an'interception-protection-optimization 'closed-loop full link is constructed, and the security defense capability of the protection model is improved.
Owner:SHANDONG INSPUR NEW CENTURY TECH CO LTD

Distributed energy storage equipment group intelligent cooperative control optimization method and system

The invention provides a distributed energy storage device group intelligent cooperative control optimization method and system, and relates to the technical field of group intelligence, and the method comprises the steps: obtaining source load fluctuation data, constructing a dynamic defense topological graph with energy storage devices as nodes and electrical coupling relations as edges, recognizing a disturbance propagation path and a node disturbance arrival time sequence through graph convolution operation, and obtaining a distributed energy storage device group intelligent cooperative control optimization model. Obtaining a node disturbance sensitivity quantized value; dividing the energy storage equipment group into a front defense domain and a back-up defense domain based on the quantized value and a preset layering threshold value; reversely deducing a power regulation sequence aiming at the front defense domain to generate an active defense instruction, and generating a following type scheduling instruction aiming at the back-up defense domain; issuing and executing the instruction, collecting topological response data, and jointly updating the edge weight and the propagation coefficient based on the deviation. According to the method, disturbance pre-compensation control is realized through dynamic topology modeling and a layered defense strategy, and the cooperative response efficiency of the energy storage equipment group and the system stability are improved.
Owner:BEIJING TRUTH WISDOM POWER TECH CO LTD

Face forgery active defense image generation method and system, and medium

The invention discloses a face forgery active defense image generation method and system and a medium, and belongs to the technical field of image processing. The method comprises the following steps: acquiring a to-be-protected face image; projecting a to-be-protected face image to the parameterized two-dimensional coordinate system to obtain a parameterized face texture image; extracting a frequency component of the parameterized facial texture image, inputting the frequency component into a pre-constructed active defense image generation model, and outputting a frequency confrontation component; performing feature fusion on the frequency adversarial components to obtain adversarial features; and projecting the adversarial features to a normalized equipment coordinate system to obtain a face forgery active defense image. According to the method, effective hidden attacks can be added to the face images in different poses while the face airspace visualization effect can be guaranteed, the method adapts to different input samples or attack stages, and the good defense effect is achieved.
Owner:NANJING UNIV OF POSTS & TELECOMM

Power grid topology toughness enhancement method based on pre-disaster prediction of graph neural network

The invention discloses a power grid topology toughness enhancement method based on pre-disaster prediction of a graph neural network. The method comprises the following steps: constructing a power grid graph structure taking power grid equipment as nodes; predicting a node damage probability through a graph attention network, and defining a high-risk node set; according to the high-risk nodes and the propagation paths thereof, a mixed integer programming model is constructed and solved, and a pre-disaster optimal power grid structure adjustment strategy is generated; in combination with the strategy, a resource scheduling scheme is generated by using a deep reinforcement learning algorithm; calculating a power grid toughness core index after simulation operation, and if the index is lower than a preset threshold value, optimizing a structure adjustment strategy; and uploading the optimized strategy and scheduling scheme to a scheduling platform to complete pre-disaster active defense deployment. According to the method, collaborative linkage of pre-disaster risk prediction, topology reconstruction and resource deployment is realized, a differentiated pre-disaster defense scheme is automatically generated, post-disaster first-aid repair is converted into pre-disaster deployment, and the pre-disaster prevention and control response efficiency is remarkably improved.
Owner:STATE GRID JIANGXI ELECTRIC POWER CO LTD RES INST

Data mapping and structured integration method based on heterogeneous threat intelligence

The invention discloses a data mapping and structured integration method based on heterogeneous threat intelligence. The method comprises the following steps: S1, constructing an initial heterogeneous graph based on threat intelligence types, sources and association strength; s2, constructing a local Transform semantic aggregation sub-graph, and realizing local semantic enhancement; s3, optimizing the fused semantic features by using a flying fox optimization algorithm, and determining fusion parameters; s4, a cross-subgraph Transform network is constructed based on parameter combination, and node and edge feature fusion is realized; s5, mapping data by adopting a dynamic semantic propagation fusion strategy to generate a heterogeneous threat knowledge graph; s6, identifying a high-risk node by using a Transform adaptive threshold mechanism; and S7, dynamically correcting a graph node state to form a structured threat data set. According to the method, the fusion efficiency and response accuracy of threat intelligence are improved, and the real-time monitoring and active defense capabilities of the security situation are enhanced.
Owner:GUANGXI POWER GRID CORP

Active defense method and system for oil-immersed transformer based on pulse current characteristics

The invention discloses an oil-immersed transformer active defense method and system based on pulse current characteristics. The acquisition device is used for acquiring output signals of high-frequency pulse current sensors mounted at a high-voltage bushing end screen grounding position, a high-voltage bushing position and an iron core grounding position to obtain digital pulse current signals; whether active defense is started or not is judged according to whether the instantaneous value of the pulse current signal at the iron core grounding position reaches a protection starting threshold or not; judging whether the current pulse cluster is a discharge pulse cluster with abnormal internal discharge or not based on the three groups of pulse current signal characteristics; and judging whether protection acts or not according to the number of abnormal discharge pulse clusters in a set period. According to the method, serious partial discharge in the large oil-immersed transformer can be identified, protection measures are actively taken, and the situation that serious discharge defects are further developed into arc breakdown faults is effectively avoided.
Owner:NARI NANJING CONTROL SYSTEM CO LTD

APT attack active defense method based on four-honey system

The invention provides an APT (Advanced Persistent Threat) attack active defense method based on a four-honey system. The APT attack active defense method comprises the following steps: collecting events fed back by a defense component in the four-honey system and external threat intelligence to obtain safety observation data, and generating an alignment sub-graph representing a relationship between anchored tactical behaviors; performing explicit relation reasoning and implicit relation reasoning by combining the aligned sub-graph and the APT knowledge graph to realize attack intention prediction so as to generate a candidate attack intention set and confidence distribution thereof; generating an optimal deployment strategy under the constraint of a system resource state, and packaging the optimal deployment strategy into an executable work order; calling resources for deployment and generating a deployment state receipt to complete construction of a new trapping environment; and collecting attacker behavior data, evaluating strategy validity according to the attacker behavior data and the deployment strategy, and updating the strategy deployment priority. The method can be applied to real-time strategy adaptation and automatic resource scheduling of attack behavior evolution, and the flexibility and continuous interference capability in a complex attack and defense environment are remarkably improved.
Owner:GUANGZHOU UNIVERSITY

Watermark-based method for actively defending deep counterfeiting

The invention relates to a deep forgery active defense method based on watermarking, which belongs to the technical field of information security, firstly provides a semantic self-adaptive watermark embedding method based on Transform, and dynamically distributes watermark weights according to the semantic importance of a human face area by using a cross attention mechanism so as to enhance the defense effect on deep forgery attack; secondly, a separable decoder watermark architecture is constructed, the separable decoder watermark architecture comprises a robust decoder and a semi-robust decoder, a random image processing module (RIPM) is introduced during training, the separable decoder is trained by simulating images of conventional distortion and deep forgery attack, and stable traceability of user identity information and recognition of deep forgery behaviors are achieved; meanwhile, local watermark concentration difference caused by deep counterfeiting is analyzed, a thermodynamic diagram of a counterfeiting region is generated in combination with supervised learning, and positioning of the deep counterfeiting region is realized.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Transformer substation safety distance monitoring system based on multi-modal data fusion

The invention discloses a substation safety distance monitoring system based on multi-modal data fusion, and relates to the technical field of substation safety distance monitoring. Comprising a laser point cloud data acquisition module, a visible light image data acquisition module, a data fusion module, a model construction module, a target identification module, a target sensing module, a safe distance calculation module, a danger alarm module, an intrusion area identification module, an alarm grading module, a sound-light alarm module, a broadcast alarm module and an unmanned aerial vehicle expelling module. According to the transformer substation safety distance monitoring system based on multi-modal data fusion, security and protection are upgraded from static alarm to dynamic active intervention through the unmanned aerial vehicle expelling module, an unmanned aerial vehicle can quickly arrive at a site and track, warn and expel from an optimal perspective, the problem that security personnel arrive at the site slowly is solved, and the security and protection efficiency is improved. And the active defense capability and the emergency disposal efficiency of the system are greatly improved.
Owner:SUPER HIGH VOLTAGE BRANCH OF STATE GRID JIANGXI ELECTRIC POWER CO LTD

Endogenous security OS construction method and device based on intelligent agent and control calculation

The invention belongs to the technical field of information security, and relates to an endogenous security OS construction method and device based on intelligent agent and control computing, and the method comprises the steps: constructing an underlying security base based on a hardware trusted root and a microkernel; based on the bottom-layer security base, defining and deploying a hierarchical multi-intelligent agent with a specific function; establishing a multi-agent communication and interaction protocol stack for the multi-intelligent agent; based on a multi-agent communication and interaction protocol stack, an intelligent collaborative scheduling algorithm oriented to multi-objective optimization is developed; an endogenous security mechanism integrating active defense and passive response; and carrying out full-life-cycle security situation assessment on the endogenous security operation system. Dynamic intrusion detection can be carried out, an intrusion detection system (IDS) based on machine learning is deployed, a normal behavior mode of an intelligent agent is learned, and abnormal tampering behaviors, DoS attacks, communication anomalies and the like are identified.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Virtual-real fusion attack and defense drilling system and method for oil and gas production system, medium and equipment

The invention provides an oil and gas production system virtual-real fusion attack and defense drilling system and method, a medium and equipment, and the system comprises a virtual-real simulation module which is used for simulating a field operation environment of an oil and gas production system, and maintaining a communication control relation between a regulation and control center and station equipment; receiving an attack instruction, and simulating the physical influence of the station yard equipment of the oil and gas production system under the attack condition; the local attack module is used for monitoring a network risk area of the oil and gas production system and calling an attack strategy instruction to initiate an attack instruction to a communication link or a control node in the network risk area; and the safety protection module is used for detecting the system abnormity of the station yard equipment in the simulation module, calling a protection strategy matched with the system abnormity to perform linkage protection and generating an attack and defense drill report. According to the invention, a high-fidelity experiment environment can be provided for attack penetration, active defense and emergency response faced by the oil and gas production system in a real scene, and the safety protection capability of the oil and gas production system is effectively guaranteed.
Owner:CHINA UNIV OF PETROLEUM (BEIJING)

Cloud native application security protection and monitoring method and system oriented to financial science and technology

The invention provides a cloud native application security protection and monitoring method and system for financial science and technology, and relates to the technical field of financial science and technology network security, and the method comprises the steps: obtaining multi-dimensional monitoring data, building a security threat knowledge graph, recognizing a high-risk attack path through a graph convolution network, generating a potential threat prediction result, and recognizing an abnormal behavior. And configuring a dynamic honeypot environment, recording behavior tracks of attackers, analyzing attack intentions and technical characteristics, and generating and deploying protection rules in real time. According to the invention, the safety protection capability of the financial cloud environment is improved, and intelligent threat prediction and active defense are realized.
Owner:JIANGSU YAOER LINGJIU TECHNOLOGY SERVICE CO LTD