Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

377 results about "Active Defense" patented technology

Active defense. The employment of limited offensive action and counterattacks to deny a contested area or position to the enemy. See also passive defense.

Network mapping behavior anomaly detection method and system based on machine learning

A network mapping behavior anomaly detection method and system based on machine learning is provided. The method includes: collecting dual-source traffic data, generating a structured log data set through dual-source log fusion engine; performing subgraph matching calculation to obtain a mapping behavior deviation degree; generating communication data containing a watermark identifier in a session corresponding communication path; verifying whether attack events carry the watermark identifier; generating a network mapping behavior anomaly detection report. According to the disclosure, an adaptive attack behavior model is constructed through a multi-modal feature vector based on structured logs and a graph protocol mapping rule base, so that the cognitive robustness to protocol camouflage and path drift is fundamentally enhanced, a real-time verification chain of detection results is built, and traditional passive detection is transformed into self-proof active defense through cross verification of watermark carrying state and behavior trajectory.
Owner:HUANENG INFORMATION TECH CO LTD

Electrolytic aluminum short circuit port operation safety early warning system based on multi-parameter collaborative awareness and intelligent diagnosis

The invention relates to the technical field of industrial safety, and discloses an electrolytic aluminum short circuit port operation safety early warning system based on multi-parameter collaborative awareness and intelligent diagnosis, and the system comprises a parameter collaborative awareness module, a dynamic diagnosis module, an early warning decision module, and an execution feedback module. By constructing a multi-dimensional parameter collaborative sensing mechanism, fusing temperature field distribution, current balance degree and insulation state multi-source data in real time and dynamically capturing early abnormal symptoms of a short circuit port, the hysteresis problem of traditional single-parameter threshold monitoring is solved, conversion from passive response to active defense is achieved, and the comprehensiveness and timeliness of operation state monitoring are improved; and meanwhile, based on a historical fault database and a real-time evolution model, a health index is generated and a fault path is predicted, so that maintenance personnel can pre-judge a development trend and a time window of potential risks in advance, and sudden equipment accidents are avoided.
Owner:上海品蓝信息科技有限公司

Network intrusion intelligent monitoring method and system based on deep learning

The invention provides a network intrusion intelligent monitoring method and system based on deep learning, relates to the field of network security, and solves the technical problem of response lag of an existing defense method. The method comprises the following steps: collecting multi-source data; preprocessing the multi-source data to generate a spatial-temporal feature map; inputting the spatial-temporal feature map into a first model and a second model constructed based on a deep learning algorithm for anomaly detection to obtain a detection result; wherein the first model is used for detecting a known attack mode, and the second model is used for detecting an unknown attack mode; and carrying out hierarchical risk level division on the detection result, and carrying out active defense according to the defense strategy of each risk level. The method is used in the network intrusion monitoring and defense process, intelligent monitoring and active defense of network intrusion are realized through multi-source data acquisition, spatial-temporal feature map generation, dual-model cooperative detection and layered defense strategy implementation, and the real-time performance and initiative of network security protection are improved.
Owner:常德学院

Defense method and system for big language model cue word attack, terminal and medium

The invention belongs to the technical field of big language model security, and particularly discloses a defense method and system for big language model cue word attack, a terminal and a medium. Comprising the steps of receiving information content input by a user, and generating a plurality of detection input copies based on a preset rule; inputting the copies into mutually independent detection processes in parallel to obtain a plurality of risk scores; constructing a comprehensive risk score based on the risk score, and determining a risk level of the input content according to the comprehensive risk score; when the risk level falls into a defense triggering interval, executing an active defense strategy, and implementing instruction confusion, semantic dilution and structural isolation processing to generate first output content; when the risk level is below a pass threshold, second output content is generated based on the user original input. According to the method, on the premise that normal interaction experience is not affected, fine-grained, controllable and dynamic safety protection can be carried out on multi-type cue word attacks, and the overall safety and usability of a large language model are improved.
Owner:浪潮智慧科技有限公司 +2

Cloud environment active defense system based on dynamic honey points

The invention provides a cloud environment active defense system based on dynamic honey spots. The system comprises a honey spot deployment and management module which generates and deploys honey spots, manages honey spot layout and provides honey spot information; the dynamic defense control module monitors network flow, perceives an attack path, analyzes attack behavior characteristics, adjusts honey point layout, generates an adjustment instruction and generates alarm information according to the attack behavior characteristics; the attack chain tracking and analyzing module is used for acquiring attack event data for attack behavior tracking, constructing an attack graph for attack path analysis and attack intention prediction and generating a threat intelligence report; and the system integration and management module monitors the running state and the resource use condition of each module, dynamically distributes system computing resources, and sets an interaction unit to provide interaction. According to the system, a complete deception defense mechanism is constructed, a deception environment is constructed by utilizing honey points, the honey points are dynamically adjusted according to attacks, and quick response and accurate countering are ensured through a flexible defense strategy and multi-layer cooperation.
Owner:GUANGZHOU UNIVERSITY +1

Method and device for constructing network attack behavior chain and active defense, and computer equipment

The invention belongs to the technical field of network security, and relates to a network attack behavior chain construction and active defense method and device and computer equipment, and the method comprises the steps: collecting full-flow data and a multi-source log from a network environment, and carrying out the preprocessing of the full-flow data and the multi-source log; storing the preprocessed full-flow data and multi-source logs, and establishing an associated index; through a deep learning algorithm and an unsupervised model, abnormal traffic and attack behaviors are identified from the full-traffic data and the multi-source logs; reconstructing the fragmented attack events into a complete behavior chain through a graph neural network and a visualization mode; based on the AI model, a dynamic defense strategy is generated, and a response action is automatically executed; through time sequence prediction and a deep learning model, a future attack trend is predicted, and active defense is realized. The method improves the unknown attack detection capability, optimizes the traceability efficiency, enhances the defense initiative, guarantees the real-time performance and accuracy of network attack prediction, and has compliance adaptability.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Active defense system and method based on multi-protocol dynamic simulation and distributed trapping

The invention provides an active defense system and method based on multi-protocol dynamic simulation and distributed trapping. The active defense method based on multi-protocol dynamic simulation and distributed trapping comprises the following sub-steps: S1, constructing a multi-protocol dynamic simulation environment; s2, deploying distributed trapping nodes; s3, deep trapping of attack behaviors; s4, attack chain reconstruction and behavior analysis; s5, performing adaptive confusion and adversarial enhancement; s6, automatic threat intelligence production and feedback; by loading the protocol template library and initializing the state machine, the response can be dynamically generated according to the real-time session context, and dynamic simulation of various service protocols is adopted, so that the detection capability on network attacks is improved, potential threats can be captured more quickly, and the risks of missing report and false report are reduced; and through an automatic threat intelligence generation and feedback mechanism, in combination with IOC index identification, structured output and real-time response, a defense strategy can be quickly responded and adjusted.
Owner:CHINA LIFE INSURANCE CO LTD

Artificial intelligence early warning and management method for smart ocean

The invention provides an artificial intelligence early warning and management method for a smart ocean, and is applied to the field of data processing application. Aiming at the problems that intelligent ocean data is large in scale and complex in multiple sources, threat identification is single in the prior art, an early warning model lacks self-adaptive adjustment and is prone to false alarm and missing alarm, and data security is difficult to guarantee, the method is based on intelligent ocean multi-source data and a preset data set containing data types, security levels and other labels; after preprocessing, a deep learning framework is used to train a threat identification and early warning model. The model detects four types of features such as sensitive information in real-time data, extracts parameters, matches threat features to determine risk levels, and establishes mapping relationships between data types and threat and abnormal modes. Through abnormal threshold evaluation, false alarms are removed to generate initial early warning parameters, a machine learning iterative optimization model is combined, risk data are finally sorted, a response strategy is constructed and the like, a safety management scheme is formulated to generate a result, and intelligent upgrading from passive response to active defense is realized.
Owner:QUANZHOU INST OF INFORMATION ENG

Network attack active defense strategy optimization method based on deep reinforcement learning

The invention discloses a network attack active defense strategy optimization method based on deep reinforcement learning, and the method comprises the following steps: collecting multi-source data of a network environment, and carrying out the feature clipping and white list feature reservation; performing normalization and coding processing to generate a security situation vector; constructing a multi-index reward function, and generating an instant reward value and an event-level reward value; executing a double-closed-loop mechanism through an improved PPO model, and respectively outputting an instant strategy instruction and a long-term strategy parameter; performing multi-source evidence commissioning on the instant strategy instruction and the security situation vector, and judging a key evidence loss condition to obtain an execution token; inputting a risk budget pool to carry out resource quota checking, and executing anti-jitter and cooling control; and optimizing parameters of the multi-index reward function through a causal account book. According to the method, rapid response and continuous optimization of various attack behaviors can be realized, the defense effect and the resource utilization rate are considered, the false report and missing report rate is reduced, and the self-adaptability and stability of a network defense system are improved.
Owner:QIAN XINGCHENG NETWORK SECURITY TECH (HUNAN) CO LTD

Active defense method and system based on large model

The invention discloses an active defense method and system based on a large model, and relates to the technical field of security protection, and the method comprises the steps: intercepting a malicious request of an external attacker, cleaning sensitive information and adversarial samples in the malicious request, and outputting standardized data; injecting the standardized data as training data into a training confrontation sample to optimize a protection model, and ensuring the leakage traceability of the protection model by embedding a digital watermark; and trapping an attacker by deploying a honey spot interface and triggering a countering strategy, generating a dynamic defense rule by using the protection model, and updating the training confrontation sample in real time for continuous optimization of the protection model. Active attack sensing and advanced attack blocking are achieved through malicious request interception cleaning and honey spot trapping countering, dynamic defense rule generation and protection model continuous optimization are combined to adapt to attack iteration, a digital watermark tracing mechanism is matched, an'interception-protection-optimization 'closed-loop full link is constructed, and the security defense capability of the protection model is improved.
Owner:SHANDONG INSPUR NEW CENTURY TECH CO LTD

Distributed energy storage equipment group intelligent cooperative control optimization method and system

The invention provides a distributed energy storage device group intelligent cooperative control optimization method and system, and relates to the technical field of group intelligence, and the method comprises the steps: obtaining source load fluctuation data, constructing a dynamic defense topological graph with energy storage devices as nodes and electrical coupling relations as edges, recognizing a disturbance propagation path and a node disturbance arrival time sequence through graph convolution operation, and obtaining a distributed energy storage device group intelligent cooperative control optimization model. Obtaining a node disturbance sensitivity quantized value; dividing the energy storage equipment group into a front defense domain and a back-up defense domain based on the quantized value and a preset layering threshold value; reversely deducing a power regulation sequence aiming at the front defense domain to generate an active defense instruction, and generating a following type scheduling instruction aiming at the back-up defense domain; issuing and executing the instruction, collecting topological response data, and jointly updating the edge weight and the propagation coefficient based on the deviation. According to the method, disturbance pre-compensation control is realized through dynamic topology modeling and a layered defense strategy, and the cooperative response efficiency of the energy storage equipment group and the system stability are improved.
Owner:BEIJING TRUTH WISDOM POWER TECH CO LTD

Power grid topology toughness enhancement method based on pre-disaster prediction of graph neural network

The invention discloses a power grid topology toughness enhancement method based on pre-disaster prediction of a graph neural network. The method comprises the following steps: constructing a power grid graph structure taking power grid equipment as nodes; predicting a node damage probability through a graph attention network, and defining a high-risk node set; according to the high-risk nodes and the propagation paths thereof, a mixed integer programming model is constructed and solved, and a pre-disaster optimal power grid structure adjustment strategy is generated; in combination with the strategy, a resource scheduling scheme is generated by using a deep reinforcement learning algorithm; calculating a power grid toughness core index after simulation operation, and if the index is lower than a preset threshold value, optimizing a structure adjustment strategy; and uploading the optimized strategy and scheduling scheme to a scheduling platform to complete pre-disaster active defense deployment. According to the method, collaborative linkage of pre-disaster risk prediction, topology reconstruction and resource deployment is realized, a differentiated pre-disaster defense scheme is automatically generated, post-disaster first-aid repair is converted into pre-disaster deployment, and the pre-disaster prevention and control response efficiency is remarkably improved.
Owner:STATE GRID JIANGXI ELECTRIC POWER CO LTD RES INST

Data mapping and structured integration method based on heterogeneous threat intelligence

The invention discloses a data mapping and structured integration method based on heterogeneous threat intelligence. The method comprises the following steps: S1, constructing an initial heterogeneous graph based on threat intelligence types, sources and association strength; s2, constructing a local Transform semantic aggregation sub-graph, and realizing local semantic enhancement; s3, optimizing the fused semantic features by using a flying fox optimization algorithm, and determining fusion parameters; s4, a cross-subgraph Transform network is constructed based on parameter combination, and node and edge feature fusion is realized; s5, mapping data by adopting a dynamic semantic propagation fusion strategy to generate a heterogeneous threat knowledge graph; s6, identifying a high-risk node by using a Transform adaptive threshold mechanism; and S7, dynamically correcting a graph node state to form a structured threat data set. According to the method, the fusion efficiency and response accuracy of threat intelligence are improved, and the real-time monitoring and active defense capabilities of the security situation are enhanced.
Owner:GUANGXI POWER GRID CORP

APT attack active defense method based on four-honey system

The invention provides an APT (Advanced Persistent Threat) attack active defense method based on a four-honey system. The APT attack active defense method comprises the following steps: collecting events fed back by a defense component in the four-honey system and external threat intelligence to obtain safety observation data, and generating an alignment sub-graph representing a relationship between anchored tactical behaviors; performing explicit relation reasoning and implicit relation reasoning by combining the aligned sub-graph and the APT knowledge graph to realize attack intention prediction so as to generate a candidate attack intention set and confidence distribution thereof; generating an optimal deployment strategy under the constraint of a system resource state, and packaging the optimal deployment strategy into an executable work order; calling resources for deployment and generating a deployment state receipt to complete construction of a new trapping environment; and collecting attacker behavior data, evaluating strategy validity according to the attacker behavior data and the deployment strategy, and updating the strategy deployment priority. The method can be applied to real-time strategy adaptation and automatic resource scheduling of attack behavior evolution, and the flexibility and continuous interference capability in a complex attack and defense environment are remarkably improved.
Owner:GUANGZHOU UNIVERSITY

Watermark-based method for actively defending deep counterfeiting

The invention relates to a deep forgery active defense method based on watermarking, which belongs to the technical field of information security, firstly provides a semantic self-adaptive watermark embedding method based on Transform, and dynamically distributes watermark weights according to the semantic importance of a human face area by using a cross attention mechanism so as to enhance the defense effect on deep forgery attack; secondly, a separable decoder watermark architecture is constructed, the separable decoder watermark architecture comprises a robust decoder and a semi-robust decoder, a random image processing module (RIPM) is introduced during training, the separable decoder is trained by simulating images of conventional distortion and deep forgery attack, and stable traceability of user identity information and recognition of deep forgery behaviors are achieved; meanwhile, local watermark concentration difference caused by deep counterfeiting is analyzed, a thermodynamic diagram of a counterfeiting region is generated in combination with supervised learning, and positioning of the deep counterfeiting region is realized.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Transformer substation safety distance monitoring system based on multi-modal data fusion

The invention discloses a substation safety distance monitoring system based on multi-modal data fusion, and relates to the technical field of substation safety distance monitoring. Comprising a laser point cloud data acquisition module, a visible light image data acquisition module, a data fusion module, a model construction module, a target identification module, a target sensing module, a safe distance calculation module, a danger alarm module, an intrusion area identification module, an alarm grading module, a sound-light alarm module, a broadcast alarm module and an unmanned aerial vehicle expelling module. According to the transformer substation safety distance monitoring system based on multi-modal data fusion, security and protection are upgraded from static alarm to dynamic active intervention through the unmanned aerial vehicle expelling module, an unmanned aerial vehicle can quickly arrive at a site and track, warn and expel from an optimal perspective, the problem that security personnel arrive at the site slowly is solved, and the security and protection efficiency is improved. And the active defense capability and the emergency disposal efficiency of the system are greatly improved.
Owner:SUPER HIGH VOLTAGE BRANCH OF STATE GRID JIANGXI ELECTRIC POWER CO LTD

Endogenous security OS construction method and device based on intelligent agent and control calculation

The invention belongs to the technical field of information security, and relates to an endogenous security OS construction method and device based on intelligent agent and control computing, and the method comprises the steps: constructing an underlying security base based on a hardware trusted root and a microkernel; based on the bottom-layer security base, defining and deploying a hierarchical multi-intelligent agent with a specific function; establishing a multi-agent communication and interaction protocol stack for the multi-intelligent agent; based on a multi-agent communication and interaction protocol stack, an intelligent collaborative scheduling algorithm oriented to multi-objective optimization is developed; an endogenous security mechanism integrating active defense and passive response; and carrying out full-life-cycle security situation assessment on the endogenous security operation system. Dynamic intrusion detection can be carried out, an intrusion detection system (IDS) based on machine learning is deployed, a normal behavior mode of an intelligent agent is learned, and abnormal tampering behaviors, DoS attacks, communication anomalies and the like are identified.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Virtual-real fusion attack and defense drilling system and method for oil and gas production system, medium and equipment

The invention provides an oil and gas production system virtual-real fusion attack and defense drilling system and method, a medium and equipment, and the system comprises a virtual-real simulation module which is used for simulating a field operation environment of an oil and gas production system, and maintaining a communication control relation between a regulation and control center and station equipment; receiving an attack instruction, and simulating the physical influence of the station yard equipment of the oil and gas production system under the attack condition; the local attack module is used for monitoring a network risk area of the oil and gas production system and calling an attack strategy instruction to initiate an attack instruction to a communication link or a control node in the network risk area; and the safety protection module is used for detecting the system abnormity of the station yard equipment in the simulation module, calling a protection strategy matched with the system abnormity to perform linkage protection and generating an attack and defense drill report. According to the invention, a high-fidelity experiment environment can be provided for attack penetration, active defense and emergency response faced by the oil and gas production system in a real scene, and the safety protection capability of the oil and gas production system is effectively guaranteed.
Owner:CHINA UNIV OF PETROLEUM (BEIJING)

Cloud native application security protection and monitoring method and system oriented to financial science and technology

The invention provides a cloud native application security protection and monitoring method and system for financial science and technology, and relates to the technical field of financial science and technology network security, and the method comprises the steps: obtaining multi-dimensional monitoring data, building a security threat knowledge graph, recognizing a high-risk attack path through a graph convolution network, generating a potential threat prediction result, and recognizing an abnormal behavior. And configuring a dynamic honeypot environment, recording behavior tracks of attackers, analyzing attack intentions and technical characteristics, and generating and deploying protection rules in real time. According to the invention, the safety protection capability of the financial cloud environment is improved, and intelligent threat prediction and active defense are realized.
Owner:JIANGSU YAOER LINGJIU TECHNOLOGY SERVICE CO LTD

Multi-frequency omnidirectional unmanned aerial vehicle active defense system and method

ActiveCN120896667ARadio transmissionCommunication jammingCarrier signalResonance analysis
The invention discloses a multi-frequency omnidirectional unmanned aerial vehicle active defense system and method, and the method comprises the steps: obtaining defense region parameters, and constructing a navigation signal generation task library based on the coverage requirements of GPSL1 and Beidou B1 / B2 / B3 frequency bands; resonance interference points are determined through carrier locking resonance analysis, Doppler frequency shift traps are designed, frequency shift fragility features are extracted in combination with C / A code recombination processing, and a targeted interference enhancement domain is constructed; the method comprises the following steps: respectively carrying out constellation topology reconstruction on a GPS (Global Positioning System) and a Beidou system, generating false orbit parameters through ephemeris data tampering, and forming a mixed defense signal domain by utilizing carrier phase interleaving processing; analyzing signal power to determine strong and weak interference areas, and setting graded attenuation parameters to construct a graded signal attenuation field; the attenuation field and the interference enhancement domain are fused to generate dynamic simulation parameters, false orbit parameters are adjusted in real time to generate a coordinate input mode, a high-dynamic navigation signal is reconstructed, a satellite working mode is selected, an L1 / B1 / B2 / B3 multi-band radio frequency output instruction is finally generated, and all-dimensional intelligent deception jamming of the unmanned aerial vehicle navigation system is achieved.
Owner:CCCC REMOTE SENSING TIANYU TECH JIANGSU CO LTD

Heterogeneous network security defense system and method based on artificial intelligence

The invention relates to the technical field of network security, and particularly discloses a heterogeneous network security defense system and method based on artificial intelligence, and the system comprises a full-dimensional perception layer which is used for obtaining original data of heterogeneous network security through a hardware-level data collection and protocol self-adaption technology; the cognitive enhancement layer is used for undertaking the output of the full-dimensional perception layer and optimizing the threat identification precision through four-dimensional spatial-temporal feature fusion and antagonism feature purification; the intelligent decision-making layer is used for accurately depicting a complex attack mode through hypergraph modeling and causal reasoning based on output of the cognitive enhancement layer; according to the method, through integration of four-dimensional spatial-temporal feature fusion and antagonistic feature purification technologies, the identification precision of complex and variable threats in a heterogeneous network is remarkably improved, especially for unknown or variable attack means; by means of hypergraph modeling and causal reasoning technologies, a complex attack mode is accurately described, an optimal defense action sequence is automatically generated, and conversion from passive defense to active defense is achieved.
Owner:ZHONGTONG SERVICE WANGYING TECH CO LTD

Electric power protocol honeypot trapping and abnormity identification method based on GAN

The invention discloses a GAN-based electric power protocol honeypot trapping and anomaly identification method, which comprises the following steps: constructing a data set by collecting real traffic of an electric power protocol, generating diversified attack samples conforming to protocol grammar by using a GAN of a Transform architecture, and improving robustness by combining data enhancement technologies such as random truncation and noise injection. Virtual honeypot equipment is deployed to simulate power equipment behaviors, attack logs and traffic features are fused in real time, a graph neural network is adopted to model a cross-message interaction relation, and self-supervised learning is introduced to detect semantic anomaly. Experiments show that the method realizes 98.2% of detection accuracy on data sets such as IEEE 123-Bus and the like, supports dynamic adaptation of protocol versions, realizes accurate tracing of attack source IP and intention through honeypot log association analysis, and effectively improves the active defense capability of a power system to novel attacks.
Owner:INFORMATION & COMM CO OF STATE GRID JILIN ELECTRIC POWER CO LTD

Mooring type low-altitude monitoring countering unmanned system based on deep learning target recognition

The invention discloses a mooring type low-altitude monitoring countering unmanned system based on deep learning target recognition. The mooring type low-altitude monitoring countering unmanned system comprises a mooring unmanned aerial vehicle platform module, a multi-source sensing and data fusion module, a deep learning target recognition and classification module, a self-adaptive countering decision and execution module, a dynamic tracking and collaborative aiming module and a ground command and control module. The mooring unmanned aerial vehicle platform module forms a stable air monitoring and countering base point; the multi-source sensing and data fusion module provides high-quality input for system identification; the deep learning target recognition and classification module recognizes and predicts a target behavior through deep learning; the self-adaptive countering decision and execution module realizes precise countering; the dynamic tracking and collaborative aiming module applies counter energy to a dynamic target; the ground command and control module provides a human-computer interaction interface and displays global information. The low-altitude active defense system has the advantages that technologies such as multi-source fusion perception, deep learning AI recognition and self-adaptive precise countering are deeply fused, and the low-altitude active defense system is formed.
Owner:SHANGHAI YIBO TECH CO LTD

Distributed unmanned aerial vehicle active defense system

The invention belongs to the technical field of radio countermeasure, and particularly relates to a distributed unmanned aerial vehicle active defense system which comprises an intelligent stationing dynamic optimization module, a multi-mode cognitive interference module, a high-precision three-level clock synchronization module and an elastic ad hoc network communication module which are used for supporting the overall function of the system. The distributed hardware equipment and the edge intelligent decision-making terminal are used for implementing a detection countering function at distributed layout positions; during specific operation and use, a distributed unmanned aerial vehicle active defense system can be provided for an important target with a large area and multiple important parts; the application problems that the arrangement position cannot be accurately selected, a large coverage blind area exists, the synchronous time service precision is low, communication networking is unreliable, serious self-interference is generated on electromagnetic and time service equipment of a partner, and the unmanned aerial vehicle countering effect is poor can be solved. And rapid and automatic passive detection and accurate interference of important targets with a large area and multiple important parts on the low-slow-small unmanned aerial vehicle are realized.
Owner:INST OF ENG PROTECTION NAT DEFENSE ENG RES INST ACAD OF MILITARY SCI CHINESE PEOPLES LIBERATION ARMY

Anti-leakage encryption system and method based on power grid data

The invention discloses an anti-leakage encryption system and method based on power grid data, and relates to the technical field of power grid data security encryption, and the method comprises the steps: dividing encryption levels according to power grid data sensitivity levels, and matching algorithms; during service operation, generating a dynamic key seed based on a real-time scene, and binding the dynamic key seed with data transfer node information to generate an initial dynamic key; user permission change is monitored, and the secret key is automatically updated according to the newest role and node information when conditions are met; encrypting each level of data by adopting a corresponding algorithm and a dynamic key to form a ciphertext; and performing permission verification during access, and decrypting the ciphertext by using the corresponding key and algorithm according to the authorized decryption hierarchy. According to the method, the real-time linkage of encryption protection, the data flow state and the user permission change is realized, so that a security mechanism can dynamically adapt to the service scene change, and the active defense capability of power grid data leakage prevention and the immediate effectiveness of permission control are enhanced.
Owner:INFORMATION & COMMNUNICATION BRANCH STATE GRID JIANGXI ELECTRIC POWER CO

Security code automatic generation system based on artificial intelligence

The invention relates to the technical field of artificial intelligence, in particular to an automatic security code generation system based on artificial intelligence, which comprises a demand understanding and security analysis unit, a code generation and optimization unit, a security verification and vulnerability detection unit and a feedback learning and knowledge updating unit. Through scene-based security level dynamic adaptation, reinforcement learning-driven security-performance balance and modular security component integration, it can be ensured that the generated code meets the service scene security requirement, redundant logic can be eliminated, the execution efficiency is considered, the problem that security and performance are difficult to cooperate in traditional code generation is solved, and the code generation efficiency is improved. Sustainable evolution and prospective defense of system security capability are realized, code generation is upgraded from passive compliance to active defense iteration, and the security, efficiency and adaptability of code generation are remarkably improved.
Owner:SHANGHAI RUNXUNDA DIGITAL TECH CO LTD

Dynamic adaptive network security protection method and device, equipment and storage medium

The invention discloses a dynamic self-adaptive network security protection method and device, equipment and a storage medium, relates to the technical field of network security, and aims to solve the problem that traditional network security protection is poor in initiative and adaptability. The method comprises the following steps: extracting microscopic behavior characteristics of real-time network traffic, constructing an attacker behavior fingerprint database in combination with an online learning model, and outputting an attack type classification result; in response to an attack type classification result, dynamically rotating the encryption key and associated elliptic curve mathematical parameters, and generating an encryption strategy; according to the network load state and the encryption strategy, dynamically switching communication ports and outputting a port state log; under the condition that the directional scanning attack is recognized, active defense operation is executed, and the active defense operation comprises the steps of closing unnecessary ports, injecting noise data, constructing a bait network and outputting attack traceability data.
Owner:SHANXI XINDINGCHEN TECH CO LTD

Charging pile terminal security situation awareness system

The invention discloses a charging pile terminal security situation awareness system, belongs to the field of charging technology facilities, and aims to solve the problems that an existing charging pile is passive in security protection, single in awareness dimension and incapable of intelligently adapting to compound attacks. The core of the method is to construct an end-side active defense system from real-time perception of behavior and physical double-layer characteristics to closed-loop adaptive execution of a security policy. According to the method, through an innovative nonlinear risk fusion model, behavior deviation analysis based on a charging gene map and physical layer authentication based on equipment pulse imprint are deeply coupled, on the premise that a normal charging process is not affected, software and hardware compound attacks which are difficult to discover by a traditional method are accurately identified and quantified, and the risk fusion efficiency is improved. Therefore, the endogenous safety and the autonomous response capability of the charging facility are greatly improved, and the method is particularly suitable for unattended operation, vehicle network interaction and other scenes with high safety requirements.
Owner:GUANGDONG WEIPENG CENTURY NEW ENERGY TECHNOLOGY CO LTD

Power grid vulnerability micropatch generation method, system and device based on call chain backtracking and medium

The invention discloses a power grid vulnerability micropatch generation method, system and device based on call chain backtracking and a medium, and belongs to the technical field of network security, and the method comprises the following steps: based on a dynamic probe, realizing kernel layer protocol analysis, lock-free acquisition of system call and user state call chain reconstruction; key path marking is realized through LLVM-IR semantic analysis and power business feature matching; generating a security micropatch based on the metadata and realizing isolated hot loading; and the patch compatibility is ensured by adopting digital simulation verification and a layered release mechanism. The method has the advantages that a five-dimensional cooperative power grid active defense system of observation-modeling-reasoning-evaluation-arrangement is constructed, millisecond observation is achieved through eBPF collection synchronized with PTP, a multi-domain ontology atlas supports cross-domain reasoning, a GNN-RL model predicts an attack path, protection logic is verified through double-target-range simulation, and the method is high in reliability and high in reliability. The intention-driven mechanism realizes second-level response, and a complete closed loop from threat perception to adaptive protection is formed.
Owner:GUIZHOU POWER GRID CO LTD

Data transmission path analysis and security protection method based on AI

The invention provides an AI-based data transmission path analysis and security protection method, which comprises the following steps: evaluating the security exposure degree of path topological symmetry according to the bidirectional structure detectability of a symmetric topological path, and identifying the attacker path deduction convenience according to the security exposure degree; adjusting network redundancy processing of the uplink path according to the attacker path deduction convenience to obtain an adjusted uplink path node distribution pattern; according to the alarm signal and the adjusted uplink path node distribution form, combining downlink path node distribution data to identify a potential attack path, performing path planning optimization processing on the potential attack path to extract an attack node invasion sequence, and determining a target node deployed by active defense according to the attack node invasion sequence; and performing real-time reconstruction processing on the data transmission path according to the topological differentiation protection intensity to obtain a reconstructed transmission path topological structure, and evaluating the security protection satisfaction degree of the reconstructed path according to the reconstructed transmission path topological structure.
Owner:SHENZHEN MINGHUI INTELLIGENT TECH CO LTD