Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

240 results about "Active Defense" patented technology

Active defense. The employment of limited offensive action and counterattacks to deny a contested area or position to the enemy. See also passive defense.

Active defense method and system based on large model

The invention discloses an active defense method and system based on a large model, and relates to the technical field of security protection, and the method comprises the steps: intercepting a malicious request of an external attacker, cleaning sensitive information and adversarial samples in the malicious request, and outputting standardized data; injecting the standardized data as training data into a training confrontation sample to optimize a protection model, and ensuring the leakage traceability of the protection model by embedding a digital watermark; and trapping an attacker by deploying a honey spot interface and triggering a countering strategy, generating a dynamic defense rule by using the protection model, and updating the training confrontation sample in real time for continuous optimization of the protection model. Active attack sensing and advanced attack blocking are achieved through malicious request interception cleaning and honey spot trapping countering, dynamic defense rule generation and protection model continuous optimization are combined to adapt to attack iteration, a digital watermark tracing mechanism is matched, an'interception-protection-optimization 'closed-loop full link is constructed, and the security defense capability of the protection model is improved.
Owner:SHANDONG INSPUR NEW CENTURY TECH CO LTD

Watermark-based method for actively defending deep counterfeiting

The invention relates to a deep forgery active defense method based on watermarking, which belongs to the technical field of information security, firstly provides a semantic self-adaptive watermark embedding method based on Transform, and dynamically distributes watermark weights according to the semantic importance of a human face area by using a cross attention mechanism so as to enhance the defense effect on deep forgery attack; secondly, a separable decoder watermark architecture is constructed, the separable decoder watermark architecture comprises a robust decoder and a semi-robust decoder, a random image processing module (RIPM) is introduced during training, the separable decoder is trained by simulating images of conventional distortion and deep forgery attack, and stable traceability of user identity information and recognition of deep forgery behaviors are achieved; meanwhile, local watermark concentration difference caused by deep counterfeiting is analyzed, a thermodynamic diagram of a counterfeiting region is generated in combination with supervised learning, and positioning of the deep counterfeiting region is realized.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Transformer substation safety distance monitoring system based on multi-modal data fusion

The invention discloses a substation safety distance monitoring system based on multi-modal data fusion, and relates to the technical field of substation safety distance monitoring. Comprising a laser point cloud data acquisition module, a visible light image data acquisition module, a data fusion module, a model construction module, a target identification module, a target sensing module, a safe distance calculation module, a danger alarm module, an intrusion area identification module, an alarm grading module, a sound-light alarm module, a broadcast alarm module and an unmanned aerial vehicle expelling module. According to the transformer substation safety distance monitoring system based on multi-modal data fusion, security and protection are upgraded from static alarm to dynamic active intervention through the unmanned aerial vehicle expelling module, an unmanned aerial vehicle can quickly arrive at a site and track, warn and expel from an optimal perspective, the problem that security personnel arrive at the site slowly is solved, and the security and protection efficiency is improved. And the active defense capability and the emergency disposal efficiency of the system are greatly improved.
Owner:SUPER HIGH VOLTAGE BRANCH OF STATE GRID JIANGXI ELECTRIC POWER CO LTD

Endogenous security OS construction method and device based on intelligent agent and control calculation

The invention belongs to the technical field of information security, and relates to an endogenous security OS construction method and device based on intelligent agent and control computing, and the method comprises the steps: constructing an underlying security base based on a hardware trusted root and a microkernel; based on the bottom-layer security base, defining and deploying a hierarchical multi-intelligent agent with a specific function; establishing a multi-agent communication and interaction protocol stack for the multi-intelligent agent; based on a multi-agent communication and interaction protocol stack, an intelligent collaborative scheduling algorithm oriented to multi-objective optimization is developed; an endogenous security mechanism integrating active defense and passive response; and carrying out full-life-cycle security situation assessment on the endogenous security operation system. Dynamic intrusion detection can be carried out, an intrusion detection system (IDS) based on machine learning is deployed, a normal behavior mode of an intelligent agent is learned, and abnormal tampering behaviors, DoS attacks, communication anomalies and the like are identified.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Mooring type low-altitude monitoring countering unmanned system based on deep learning target recognition

The invention discloses a mooring type low-altitude monitoring countering unmanned system based on deep learning target recognition. The mooring type low-altitude monitoring countering unmanned system comprises a mooring unmanned aerial vehicle platform module, a multi-source sensing and data fusion module, a deep learning target recognition and classification module, a self-adaptive countering decision and execution module, a dynamic tracking and collaborative aiming module and a ground command and control module. The mooring unmanned aerial vehicle platform module forms a stable air monitoring and countering base point; the multi-source sensing and data fusion module provides high-quality input for system identification; the deep learning target recognition and classification module recognizes and predicts a target behavior through deep learning; the self-adaptive countering decision and execution module realizes precise countering; the dynamic tracking and collaborative aiming module applies counter energy to a dynamic target; the ground command and control module provides a human-computer interaction interface and displays global information. The low-altitude active defense system has the advantages that technologies such as multi-source fusion perception, deep learning AI recognition and self-adaptive precise countering are deeply fused, and the low-altitude active defense system is formed.
Owner:SHANGHAI YIBO TECH CO LTD

Anti-leakage encryption system and method based on power grid data

The invention discloses an anti-leakage encryption system and method based on power grid data, and relates to the technical field of power grid data security encryption, and the method comprises the steps: dividing encryption levels according to power grid data sensitivity levels, and matching algorithms; during service operation, generating a dynamic key seed based on a real-time scene, and binding the dynamic key seed with data transfer node information to generate an initial dynamic key; user permission change is monitored, and the secret key is automatically updated according to the newest role and node information when conditions are met; encrypting each level of data by adopting a corresponding algorithm and a dynamic key to form a ciphertext; and performing permission verification during access, and decrypting the ciphertext by using the corresponding key and algorithm according to the authorized decryption hierarchy. According to the method, the real-time linkage of encryption protection, the data flow state and the user permission change is realized, so that a security mechanism can dynamically adapt to the service scene change, and the active defense capability of power grid data leakage prevention and the immediate effectiveness of permission control are enhanced.
Owner:INFORMATION & COMMNUNICATION BRANCH STATE GRID JIANGXI ELECTRIC POWER CO

Data transmission path analysis and security protection method based on AI

The invention provides an AI-based data transmission path analysis and security protection method, which comprises the following steps: evaluating the security exposure degree of path topological symmetry according to the bidirectional structure detectability of a symmetric topological path, and identifying the attacker path deduction convenience according to the security exposure degree; adjusting network redundancy processing of the uplink path according to the attacker path deduction convenience to obtain an adjusted uplink path node distribution pattern; according to the alarm signal and the adjusted uplink path node distribution form, combining downlink path node distribution data to identify a potential attack path, performing path planning optimization processing on the potential attack path to extract an attack node invasion sequence, and determining a target node deployed by active defense according to the attack node invasion sequence; and performing real-time reconstruction processing on the data transmission path according to the topological differentiation protection intensity to obtain a reconstructed transmission path topological structure, and evaluating the security protection satisfaction degree of the reconstructed path according to the reconstructed transmission path topological structure.
Owner:SHENZHEN MINGHUI INTELLIGENT TECH CO LTD

Network threat systematic protection method

PendingCN121966996ASecuring communicationSecurity operations centerData aggregator
The invention discloses a network threat systematic protection method, and belongs to the technical field of network security. According to the method, a unified policy center is constructed, and three layers of security policies of an overlay network, a terminal and an application are defined and issued in a unified manner; network admission control, terminal security management and API risk monitoring systems are deployed to execute strategies respectively; an intelligent linkage mechanism is established, and cross-system automatic co-processing is realized; centralized monitoring, data aggregation and visual analysis are carried out through the unified safety operation center, and support is provided for optimization; and continuously optimizing the strategy and the rule based on the operation data. According to the invention, the problems of isolation, strategy splitting and response lag of a protection system in the prior art are solved, and an active defense system with cooperative linkage and continuous evolution is constructed.
Owner:GUANGZHOU CHANGBENHENG NETWORK TECHNOLOGY CO LTD +1

Power grid ferromagnetic resonance risk prediction and cooperative defense system and method

The invention provides a risk prediction and cooperative defense system and method for ferromagnetic resonance of a power grid. The data acquisition module is used for acquiring electrical quantity data and switch state data of a plurality of nodes of the whole network in real time; the data analysis module is used for analyzing the electrical quantity data through a preset first prediction model to calculate a first risk characteristic value, and analyzing the switch state data through a preset second prediction model to calculate a second risk characteristic value; the feature fusion module is used for calculating the risk probability and grade of the magnetic resonance of the starting iron by fusing the first risk feature value and the second risk feature value; and the early warning and execution module is used for generating early warning information and a self-adaptive regulation and control strategy according to the calculated risk probability and grade of the ferromagnetic resonance, and sending out a corresponding alarm according to the generated early warning information and the self-adaptive regulation and control strategy. Through multi-source data fusion analysis, advanced prediction of the ferromagnetic resonance risk is realized, and passive response is changed into active defense.
Owner:STATE GRID FUYANG POWER SUPPLY COMPANY +2

Active defense security control method for hidden false data injection attack

The invention discloses an active defense security control method for a hidden false data injection attack, and relates to the field of information physical system security control, in particular to an active defense security control method. The invention aims to solve the problem that the existing detection method can encrypt a transmitted signal, but is limited to detection of a specific type of attack, or dynamic coupling changing the configuration of a control system can increase the burden of a state estimator, and even causes the performance reduction of the system. The method comprises the following steps of: 1, acquiring output feedback gains of the information physical system under different switching signals; and 2, based on the output feedback control gain obtained in the step 1, performing active attack detection and positioning on the FDI attack, and when the attack is detected and positioned, performing active switching by a controller of the information physical system so as to construct an active security controller aiming at the FDI attack.
Owner:HARBIN INST OF TECH

Security situation awareness and self-adaptive defense system for power plant machine room

The invention discloses a power plant room-oriented security situation awareness and adaptive defense system, which adopts a layered architecture and comprises a data acquisition layer, a situation analysis layer, a decision response layer and a man-machine interaction layer. The data acquisition layer is used for acquiring multi-source heterogeneous data such as network traffic, host behaviors and physical operation parameters; the situation analysis layer performs fusion analysis on the data through a dynamic trust evaluation module, a threat evaluation module, a situation understanding module and a situation prediction module, generates a global security situation quantitative index and predicts an attack path; and the decision response layer generates a self-adaptive defense control instruction based on a predefined strategy library and a self-adaptive defense strategy engine, and drives a network security device or a process control system to execute operations such as dynamic micro-isolation and security mode switching through a response actuator. According to the method, an intelligent closed loop of perception-analysis-decision-execution is formed, and the active defense capability and the safety operation and maintenance efficiency of the power plant machine room facing complex network attacks are effectively improved.
Owner:GUODIAN ZHENENG NINGDONG POWER GENERATION CO LTD

Network security risk prediction and prevention method and system based on big data

PendingCN121396539ABiological modelsSecuring communicationCritical information infrastructureInternet traffic
The invention relates to the technical field of information, and discloses a network security risk prediction and prevention method and system based on big data, and the method and system comprise a data collection module, a data processing module, a risk prediction module, a strategy generation module, a response execution module, and an optimization feedback module. Network traffic, system logs, user behaviors and threat intelligence data are converged in real time through a distributed acquisition module, a high-dimensional feature vector is generated by fusing time sequence, statistics and semantic features through feature engineering, automatic responses such as traffic filtering and access control are executed, and an incremental learning mechanism dynamic optimization model is constructed; according to the method, multi-source data fusion analysis is realized, the attack detection coverage rate and response timeliness are improved, real-time risk prediction and dynamic defense are supported, the high-risk attack interception efficiency is improved, continuous evolution of the model is realized through incremental learning, and the novel attack detection rate and the resource efficiency are improved in a breakthrough manner; and an efficient active defense capability is provided for the key information infrastructure.
Owner:YANGJIANG YUEFENG TECHNOLOGY CO LTD

Cloud honey point dynamic arrangement method and system based on software-defined spoofing defense

The invention provides a cloud honey point dynamic arrangement method and system based on software-defined spoofing defense, and the system comprises a base construction control layer and an execution layer based on software-defined spoofing defense, the control layer comprises a threat sensing unit, a game decision unit and an arrangement control unit, the execution layer comprises a cloud native arrangement unit and a defense resource library; the threat sensing unit collects threat intelligence and generates a structured intelligence object; the game decision-making unit is used for game solving of an optimal response strategy; the arrangement control unit reads the defense strategy state data, generates a strategy configuration instruction according to the optimal response strategy, and issues the strategy configuration instruction to the cloud native arrangement unit; the cloud native arrangement unit responds to the instruction and dispatches a defense resource library to instantiate a Pod comprising a honey point container and a distributed feedback component; the defense resource library is used for maintaining honey point configuration files for generating honey point instances. By applying the system, self-adaptive closed-loop active defense can be realized.
Owner:GUANGZHOU UNIVERSITY +1

Computer running state intelligent management method and system

The invention discloses a computer running state intelligent management method and system, and belongs to the technical field of computer supervision. According to the method, multi-source data are collected and fused in real time, and a structured state data set is constructed; establishing a dynamic operation state portrait based on the data set and the system knowledge graph, and pre-judging the operation state of the next monitoring interval through a mixed time sequence prediction model; an unsupervised deep contrast learning two-way detection mechanism is adopted to identify abnormity, and a potential security attack event is identified in combination with an attack chain knowledge base and a causal inference engine; calculating a comprehensive priority according to the prediction state, the abnormity and the attack event, and dynamically executing linkage adjustment of computing resource allocation and network security protection; and monitoring a linkage adjustment effect and feeding back a deviation value between the linkage adjustment effect and a preset target to each model to realize full-process adaptive optimization. According to the method, resource dynamic accurate allocation and security threat active defense are realized, the system operation efficiency and protection effectiveness are improved, and the method adapts to the dynamic change of the computer operation state and threat.
Owner:YANTAI VOCATIONAL COLLEGE

Firewall dynamic policy adaptation method and system based on big data

The invention discloses a firewall dynamic policy adaptation method and system based on big data, and the method comprises the steps: collecting multi-source heterogeneous data in a network, and constructing a dynamic network entity map in real time; processing the time sequence of the atlas by using a preset time sequence diagram attention network model to obtain a behavior fingerprint vector representing the behavior state of the entity, and calculating the risk score of the entity; when the risk score exceeds a risk threshold value, automatically generating a temporary security policy for managing and controlling the access behavior of the entity; and managing the life cycle of the temporary security policy, and automatically updating, renewing or cancelling according to the entity risk state change. According to the method, the network entity behavior baseline is constructed and the risk prediction is carried out, so that the conversion from passive defense to active defense is realized, the security policy can be automatically and accurately generated and managed, advanced persistent threats and zero-day attacks can be effectively coped with, and the self-adaptability and the intelligent level of network defense are improved.
Owner:HANGZHOU TAICHENG NETWORK TECH CO LTD

Dynamic trapping network deployment method and system fusing attack behavior preference

The invention discloses a dynamic trapping network deployment method and system fusing attack behavior preferences, and relates to the technical field of network security. The method comprises the following steps: modeling a network topology into a directed acyclic graph, and constructing a dynamic trapping network topology structure fused with attack behavior preference based on attacker behavior preference analysis in combination with situation awareness; modeling an attack and defense confrontation process as a Markov multi-stage dynamic game process, and solving Nash equilibrium to obtain an optimal strategy of each stage; the behavior preference of an attacker is updated in real time by using Bayesian learning and a sliding window mechanism, and the adaptability of a dynamic trapping network to attack and defense situations is enhanced. According to the method, the problems of configuration stiffness and poor attack and defense situation change adaptability in dynamic trap network deployment are solved, the active defense capability aiming at attacker behaviors can be improved, and an effective solution is provided for dynamic deployment of a trap network in a dynamic network environment.
Owner:NANJING UNIV OF SCI & TECH

Information security comprehensive protection system of production enterprise

The invention discloses a production enterprise-oriented information security comprehensive protection system, which comprises a unified security management center, a region boundary protection module, a security computing environment module, a data full life cycle protection module, an authority management module, a threat active defense module and a network security situation awareness module, original dispersed and isolated safety capabilities are integrated into a linkage system through an integrated architecture of a unified safety management center and six functional modules through a unified interface / event bus, so that instant isolation and authentication of a transverse production control area, a management information area and a longitudinal remote operation and maintenance channel are realized, and the transverse penetration blocking rate is remarkably improved; role isolation and dynamic authorization are realized through the authority management module, the attack surface of a supply chain is greatly narrowed, the manual operation and maintenance workload is reduced by about six percent, and the overall safety toughness and operation efficiency of an enterprise are remarkably improved.
Owner:HENGTONG PRECISION COPPER FOIL TECHNOLOGY (DEYANG) CO LTD

Power distribution network pre-disaster active defense method considering network reconstruction

The invention provides a power distribution network pre-disaster active defense method considering network reconstruction. The method comprises the following steps: 1) establishing a power distribution network operation state model and defining system elements; 2) acquiring meteorological prediction data in a future preset time window, predicting the icing thickness of the distribution line at each moment, calculating the line failure probability according to the icing thickness, and judging the line with the failure probability exceeding a threshold value as a high-risk line; 3) constructing a pre-disaster active defense optimization model of the power distribution network; 4) introducing a second-order cone relaxation method to convert the non-convex power flow constraint in the pre-disaster active defense optimization model of the power distribution network into a convex constraint form; (5) carrying out iterative solution on the converted active defense model by adopting a Benders decomposition method to generate an optimal network reconstruction scheme, a power flow operation state and a distributed power supply output scheme, and (6) monitoring a line icing state in real time to realize dynamic updating of an active defense strategy.
Owner:SUQIAN WANDA POWER IND CO LTD +1

Multi-mode security threat detection and active defense method and system for new energy station

The invention discloses a new energy station multi-mode security threat detection and active defense method and system, and relates to the technical field of new energy station security monitoring and intelligent protection, and the method comprises the following steps: constructing a brightness and texture cross-time scale joint observation baseline, extracting a hot spot track and boundary definition curve, and obtaining a new energy station multi-mode security threat detection and active defense model; generating a time anchor point set reflecting the illumination change rate; and performing frame-by-frame optical decomposition based on the time anchor point set, separating a specular reflection component from a diffuse reflection component, extracting a brightness mutation position, calibrating a pseudo peak seed region, and constructing an illumination behavior template. According to the invention, through constructing a time anchor point and an illumination behavior template, accurate identification of illumination disturbance is realized, a false alarm window is compressed in combination with multi-modal verification, a sampling rhythm is reconstructed, pseudo peak energy is adaptively suppressed, the credibility of a target signal is enhanced, and a closed-loop control flow from identification to response is formed. And safe and stable operation of the new energy station in a dynamic environment is effectively ensured.
Owner:STATE GRID JIBEI ELECTRIC POWER CO LTD TANGSHAN POWER SUPPLY CO

Active defense method for adversarial denial of service attack in micro-service scenario

ActiveCN121333708BQuality of serviceAttack
The application discloses an active defense method against adversarial denial of service attacks in a microservice scenario. First, multi-source index collection probes are deployed in the microservice system and combined with centralized aggregation processing. Then, the system attack and defense process is modeled as a zero-sum game problem of double reinforcement learning agents. The defense strategy is optimized in the alternating update using the adversarial training mechanism, allowing the defender to gradually converge to a robust optimal strategy. On this basis, a multi-dimensional discrete deep Q network is introduced. Through shared feature extraction and multi-head independent output, efficient generation of multi-dimensional expansion and contraction defense decisions is achieved. A loss balancing mechanism is used to accelerate convergence. Finally, a closed-loop optimization mechanism is combined to trigger lightweight incremental training when new attack patterns are detected or defense effectiveness decreases, dynamically updating part of the network weights to maintain the adaptability of the strategy. This scheme can achieve intelligent, automated and efficient defense of microservice systems in adversarial attack environments, significantly improving system security and service quality.
Owner:SOUTHEAST UNIV

Camera with active defense function

The utility model discloses a camera with active defense function relates to camera technical field, including protective shell, fixed buckle, bearing handle, lamp holder and drive connecting rod, be equipped with fixed buckle and bearing handle above protective shell, protective shell left side is equipped with lamp holder, lamp holder right side is equipped with connecting pipe and locking block, the drive connecting rod is equipped with the fixed buckle, bearing handle, lamp holder right side is equipped with the connecting pipe and locking block. A locking block is installed on the left side of the base, a limiting ring is installed on the left side of the locking block, a fixing pin, a motor and an adjusting screw rod are installed on the right side of the locking block, and an adjusting screw sleeve, a guide groove and a driving connecting rod are installed on the right side of the adjusting screw rod. And the fixing pin and the protective shell are firmly buckled, so that the equipment is prevented from being opened by personnel, and the safety and the protection level of the equipment are improved.
Owner:JIANGSU WANGREN INTELLIGENT TECHNOLOGY CO LTD

A large model-based active defense method and system

This application discloses a proactive defense method and system based on a large model, relating to the field of security protection technology. The method includes: intercepting malicious requests from external attackers and cleaning sensitive information and adversarial samples from the malicious requests to output standardized data; injecting the standardized data as training data into training adversarial samples to optimize the protection model and ensuring the traceability of the protection model by embedding digital watermarks; deploying honeypot interfaces to lure attackers and trigger countermeasures; generating dynamic defense rules using the protection model; and updating the training adversarial samples in real time for continuous optimization of the protection model. By intercepting and cleaning malicious requests and using honeypot luring and countermeasures, proactive attack detection and early blocking are achieved. Combined with dynamic defense rule generation and continuous optimization of the protection model to adapt to attack iterations, along with a digital watermark traceability mechanism, a closed-loop full-link of "interception-protection-optimization" is constructed, improving the security defense capability of the protection model.
Owner:SHANDONG INSPUR NEW CENTURY TECH CO LTD

Railway signal system based on trusted computing security computing protection technology

The application discloses a kind of railway signal system security computing protection technology and system based on trusted computing.The application takes hardware trusted module as trust root, constructs the end-to-end trusted verification chain covering operation and maintenance terminal, communication link and destination device;Through the trusted management platform of center, the trust measurement and white list management of operation and maintenance tool are realized;Deeply integrate railway "window time" and standard operation process, construct device dynamic trusted benchmark model, and generate operation and maintenance personnel behavior trusted model based on historical behavior data;Deploy lightweight trusted agent to monitor operation and maintenance behavior in real time, and implement hierarchical response and authority control to behaviors deviating from the two models.The application realizes dynamic trusted protection in the whole operation and maintenance process, effectively improves the active defense capability against internal and external threats, balances safety strength and operation and maintenance efficiency, and provides business-aware security protection for railway signal system and key infrastructure.
Owner:CHINA STATE RAILWAY GRP CO LTD +1

Primary equipment network security reinforcement method, computer equipment and storage medium

The invention relates to the technical field of network security, and discloses a primary equipment network security reinforcement method, computer equipment and a storage medium, by setting a dynamic threshold judgment and hierarchical response mechanism in an instruction receiving link, abnormal high-frequency operation for primary equipment can be effectively identified and blocked, and the security of the primary equipment is enhanced. The equipment operation risk caused by a malicious instruction is obviously reduced; meanwhile, in combination with double judgment of an upper limit of operation times and a preset multiple, accurate grading alarm from suspected attacks to confidential attacks is realized, the accuracy of threat identification is greatly improved, and false alarms are reduced; by intelligently agenting the confidential attack traffic to the electric power honeypot, the security of real equipment is protected, an effective environment is provided for analysis and tracking of attack behaviors, and the active defense capability of the system in an industrial network environment in which a feature library cannot be updated in real time is enhanced.
Owner:YISHITE ENERGY STORAGE TECH CO LTD

Energy router cascading failure defense and recovery method

The application discloses a kind of energy router cascade failure defense and recovery method, comprising: obtaining the operating state data of multiple ports of energy router, wherein current control mode of each port is contained;Based on operating state data, by constructing a dynamic coupling matrix dependent on real-time control mode, to assess the cascade failure risk of system level, obtain system cascade failure risk index;In response to risk index over-limit or actual failure occurs, by solving an optimization problem with control mode as the core decision variable, generate and execute control instructions for suppressing cascade failure propagation;In response to fault clearance, execute risk-aware ordered recovery process, and perform closed-loop safety review after each step of the recovery sequence to ensure the stability of the recovery process.The application can improve the accuracy of cascade failure risk prediction, the effectiveness of active failure defense and the safety of system failure recovery.
Owner:WUHAN RUICHUANG YOUNENG TECHNOLOGY CO LTD

Chip Trojan horse detection and shielding system and method based on multiple confusion links

PendingCN121435290AInternal/peripheral component protectionPathPingHardware Trojan
The invention discloses a chip Trojan horse detection and shielding system and method based on multiple confusion links, and relates to the technical field of integrated circuit safety. According to the method, a plurality of confusion links which are large in structural difference, identical in function and similar in time delay are designed for sensitive critical paths in a chip. A write-only unreadable register is adopted to store link selection information, so that an attacker is prevented from stealing or tampering a currently activated path by means of scanning a chain, debugging an interface and the like; a dual-stage operation mechanism is adopted, a test stage is combined with high-precision delay measurement and anomaly analysis to accurately identify a path in which Trojan is implanted, and a formal stage is dynamically switched to a Trojan-free path based on safety link information stored in a register, so that a chip is ensured to automatically avoid malicious logic during operation, and active defense instead of passive detection is realized. The method is superior to a traditional hardware Trojan horse protection scheme in detection precision, operation safety and implementation cost, and an efficient, reliable and easy-to-integrate solution is provided for chip safety.
Owner:THE 54TH RESEARCH INSTITUTE OF CHINA ELECTRONICS TECHNOLOGY GROUP CORPORATION +1

A method and device for identifying and dynamically blocking illegal access of a Bluetooth device

ActiveCN121751176BAchieve multi-dimensional perceptionBreaking through the limitations of insufficient discrimination of subtle defectsBiological modelsSecurity arrangementAlgorithmRadio frequency
The application discloses a kind of illegal access hardware identification and dynamic blocking method and device of bluetooth device, it is related to artificial intelligence technical field, the method includes the steady-state current response waveform and radio frequency IQ baseband signal of synchronous acquisition bluetooth device;Signal is preprocessed and respectively extracts cyclic stationary feature and joint time-frequency-cyclic feature;Adaptive multi-source feature fusion network of fusion channel and spatial attention is constructed, and classification is carried out in combination with double-branch convolution, protocol perception feature modulator and multi-scale hollow convolution pyramid.The application realizes multidimensional perception and cross-domain feature fusion of hardware fingerprint, enhances abnormal discrimination by protocol perception modulation, realizes the feature normalization of different working modes of same hardware and illegal equipment feature abnormal amplification, forms end-to-end active defense system from feature extraction to dynamic blocking.
Owner:深圳市乾海芯联科技有限公司 +1

A power industrial control security protection system and method based on microkernel active defense

PendingCN122179216ASecuring communicationScheduling (computing)Trusted computing base
The application discloses a power industrial control safety protection system and method based on a microkernel active defense, wherein the system takes a microkernel isolation base as a minimum trusted computing base, allocates revocable communication endpoints and controlled mapping permissions to each protection domain, and provides base support for the isolation domain boundary and permission recovery in the active defense; in the method, the system is uniformly formatted by an input module to process field data and service requests and generate a request identifier, a request distribution service distributes the same request to an odd number of online executors for parallel processing, a single decision output available externally is generated, an executor scheduling service selects a candidate executor from a candidate protection domain pool and reconstructs an online user mode service cluster according to a feedback index by adopting a periodic rotation and event triggering strategy, and if the request distribution service, the consistency arbitration service or the executor scheduling service fails, a minimum bottom-up cleaning is performed by an active defense kernel state support module and a reestablishable state is entered.
Owner:NARI INFORMATION & COMM TECH

Signal backdoor attack method and system based on gradient clipping optimization

The application discloses a signal backdoor attack method and system based on gradient clipping optimization, comprising constructing a backdoor training set containing a directional attack label and a clean training set, adopting an alternating mixed training strategy, and synchronously processing clean samples and backdoor samples in each training batch. By calculating the clean sample loss and the backdoor sample loss, a weighted combined loss is constructed and the model parameters are updated, and at the same time, the gradient clipping technology is used to constrain the update amplitude of the backdoor trigger, so that the trigger disturbance is strictly controlled within a predetermined range. The final backdoor model can output the preset attack category to the input embedded trigger while maintaining normal classification performance, effectively counteracting the stolen model. The method is significantly superior to the prior art in terms of attack success rate, concealment and model performance retention, and provides a reliable solution for active defense against model theft.
Owner:XIDIAN UNIV

Risk area active defense control method based on vehicle cabin control

The application discloses a risk area active defense control method based on vehicle cabin control, and the main design concept of the application is that, on one hand, risk area information can be continuously acquired during driving, and on the other hand, based on vehicle positioning information, whether the vehicle is close to or has driven into the risk area can be detected, and when the vehicle is close to or drives into the risk area, prompt information can be output and the cabin can be triggered to enter an active defense mode. The application can make the vehicle automatically enter a defense state according to the positions of the positioning and the risk area during driving, actively cope with the risks brought by the external environment in a preparedness mode, can significantly reduce the influence of the external environment on the driver and the passenger, and further guarantee the health and safety of the driver and the passenger.
Owner:ANHUI JIANGHUAI AUTOMOBILE GRP CORP LTD