Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

14 results about "Advanced persistent threat" patented technology

An Advanced Persistent Threat (APT) is a stealthy computer network threat actor, typically a nation state or state-sponsored group, which gains unauthorized access to a computer network and remains undetected for an extended period . In recent times, the term may also refer to non-state sponsored groups conducting large-scale targeted intrusions for specific goals.

Attack profiling system and method based on graph association

The application discloses an attack portrait system and method based on atlas association, relates to the technical field of network security, and aims to solve the problems of scattered threat IP behavior information, difficulty in dynamically displaying and tracing attack chains, and lack of intelligent identification of attack group coordination. The system comprises a data access and standardization module, a threat IP coordination body management module, a multi-dimensional portrait analysis module, an atlasized coordination body analysis module, and a closed-loop research and disposal module. By constructing a unified graph calculation data model, a coordination body object, multi-dimensional portrait factors, and a four-layer attack association atlas, and combining a SOAR automatic disposal mechanism, a full-process closed loop is realized from multi-source data fusion, coordinated attack gang identification to risk assessment and automatic blocking. The application significantly improves the identification, analysis and response capability of advanced persistent threats and complex coordinated attacks.
Owner:SICHUAN YILAN SITUATION TECH CO LTD

Digital mine network security situation awareness method and system

The invention belongs to the technical field of industrial internet security, and particularly relates to a digital mine network security situation awareness method and system, and the method comprises the following steps: S1, accessing the network flow of a mine industrial switch, deconstructing a data packet into an instruction domain, an address domain and a load domain through protocol analysis, and extracting a timestamp and the binary content of each domain; s2, calculating the Shannon entropy of the protocol field in the current time window, and calculating the abnormal entropy increase index of the protocol field according to the average entropy value and the standard deviation under the historical normal working condition, thereby evaluating the hidden channel risk; and S3, extracting physical values in the continuous data packets, and calculating a physical inertia conflict coefficient according to the maximum change rate allowed by the physical parameters of the equipment. According to the method, the physical law is introduced as a safety criterion, so that the false alarm rate is effectively reduced, and precise perception of advanced persistent threats is realized.
Owner:CHINA ELECTRIC CLOUD INFORMATION TECH CO LTD

Autonomous generative pre-trained ai driven purple teaming solution for simulating advanced persistent threats and generating tailored risk remediation

PendingUS20260156138A1Securing communicationSelf adaptiveAdvanced persistent threat
Devices, systems, and methods for AI-driven security exercises emulate evolving threats across varied environments to proactively assess and strengthen resilience. AI models fuse external knowledge and best practices to design safe, multi-step simulations orchestrated by lightweight agents that elicit realistic, non-disruptive defensive behavior. The platform ingests operational signals and environment descriptions to adapt scenarios in a vendor-agnostic, environment-aware way. Iterative campaigns expand coverage and translate outcomes into qualitative likelihood and impact indicators for comparative risk views by asset and service. The system outputs machine-readable guidance summarizing effective and ineffective defenses, mapping findings to simulated paths, and recommending prioritized improvements across key control domains, aligned to governance and assurance expectations. By uniting adaptive simulation, continuous context, and outcome-driven guidance, the invention exposes material risk, focuses remediation on highest-value areas, and demonstrates measurable improvement over time.
Owner:PLURILOCK SECURITY SOLUTIONS INC

A data leakage detection system and method based on time series data anomaly detection

The application discloses a data leakage detection system and method based on time series data anomaly detection, relates to the technical field of data leakage detection, and solves the problems of a traditional data leakage detection method based on rule matching or static threshold detection, high false positive rate, high false negative rate, poor adaptability and early warning lag when facing zero-day vulnerabilities, malicious theft by internal personnel and advanced persistent threats. The application comprises a data acquisition and analysis module, a user entity behavior portrait construction module, a core detection engine, a model management and optimization module and an alarm aggregation and response arrangement module; the data acquisition and analysis module is used for collecting original security logs and network metadata from heterogeneous data sources in real time and performing standardized analysis. The application can more accurately identify various leakage scenarios from single-point anomalies to coordinated attacks by capturing complex time patterns through "multimodal time series coding" and revealing associated threats through "graph context analysis".
Owner:SAIER DIGITAL (BEIJING) TECH CO LTD

Advanced persistent threat (apt) attack behavior detection method, device and equipment

ActiveCN115603992BDomain nameData pack
This invention discloses a method, apparatus, and device for detecting Advanced Persistent Threat (APT) attacks. The method acquires the spatiotemporal interaction graph and corresponding first label information of any sample from a pre-saved sample set at the endpoint. It then trains a detection model using the original neural network model. Based on all data packets collected within a preset time range from the network equipment of the network operator at the network side, it parses out each IP address and determines the domain name and location of each IP address. Entities corresponding to the domain name, IP address, and location are created in the spatiotemporal interaction graph. If a connection is established or data packets are exchanged between any two entities, the two entities are connected, and the connection characteristics corresponding to the two entities are determined. The spatiotemporal interaction graph, acquired through endpoint-network fusion and detected based on the detection model, more fundamentally displays the temporal characteristics of APT attacks, thereby enabling the detection of all types of APT attacks.
Owner:CHINA TELECOM NETWORK SECURITY TECH CO LTD

A terminal security protection method based on terminal operation self-explaining constraint verification

The application provides a terminal security protection method based on terminal running self-explanation constraint verification, first constructs a terminal running constraint model, defines a legal running state and a state change path, and collects system state information of the terminal in real time. Whenever the terminal state changes, the system generates a self-explanation proof and performs consistency checking with the pre-defined model. When it is detected that the state change does not conform to the safety constraint, the system automatically triggers a security protection strategy, such as isolating a risk process, limiting operation or rolling back to a safe state, etc. The method can effectively prevent memory resident attacks, malicious code injection and advanced persistent threats (APT), and provide more accurate and real-time terminal security protection. The innovation of the application lies in that, through terminal self-explanation and state evolution consistency verification, the limitation of traditional detection methods is broken through, the defense capability against hidden attacks is enhanced, and the application has strong innovation and practical application value.
Owner:ZHANGZHOU POWER SUPPLY COMPANY STATE GRID FUJIANELECTRIC POWER +1

An intelligent detection method, device and equipment for document type advanced persistent threats and a medium

PendingCN122333450AAchieve depth perceptionimprove accuracyEngineeringComputers technology
This application discloses an intelligent detection method, apparatus, device, and medium for document-based advanced persistent threats (APTs), relating to the field of computer technology. It includes: static preprocessing of the target document to extract its document structure features and metadata, and establishing a document object relationship graph based on these features and metadata; constructing an isolation sandbox using virtualization technology, and performing dynamic behavior analysis on the target document based on the sandbox and the document object relationship graph to generate corresponding dynamic analysis results; using a neural network architecture configured with bidirectional gated recurrent units to perform deep modeling of the dynamic analysis results and analyze the semantic features of the resulting behavioral sequences to output threat assessment results; the behavioral sequences include user operation logs, device interaction records, and text behavior trajectories. This improves the accuracy and efficiency of document-based APT detection and reduces the false positive rate.
Owner:HANGZHOU DBAPPSECURITY CO LTD +1

A dynamic detection method and system of malicious code based on double space embedding

The application discloses a kind of dynamic detection method and system of malicious code based on double space embedding, applied to network security field, including obtaining and analyzing program running behavior event, extraction program interface identification and calling parameter;Interface identification is mapped to Euclidean space to obtain the first characteristic vector, calling parameter is mapped to hyperbolic space to obtain the second characteristic vector, and the comprehensive characteristic vector of behavior event is formed by fusion;According to the similarity degree of adjacent behavior event comprehensive characteristic vector, dynamically filter out multiple target behavior event sets associated with potential attack behavior;Based on each event set, the corresponding dynamic topology sequence is constructed, and the sequence is analyzed and processed, and the stage characteristic representation of each component element is extracted;According to stage characteristic representation, maliciousness determination and result output are completed.The dynamic detection method of malicious code based on double space embedding provided by the application can accurately detect multi-stage, high-concealment malicious code such as advanced persistent threat.
Owner:STATE GRID ZHEJIANG ELECTRIC POWER CO LTD

A multi-network environment simulation game server test system

The application discloses a kind of multi-network environment simulation game server test system, it is related to information security technical field, including constructing a multi-node simulation test environment;According to the preset advanced persistent threat attack script, send the simulation service traffic that has the characteristics of covert attack fusion to target system;Dynamically trigger controllable fault injection operation to at least one security component in target system;Monitoring and recording the system behavior and security state evolution data of target system under the synergistic effect of simulation service traffic that has the characteristics of covert attack fusion and internal fault injection operation;Based on system behavior and security state evolution data, generate the evaluation result of target system security resilience.The application realizes high-fidelity, quantifiable evaluation of the security resilience of game server in complex disaster scenario;It can not only find the deep interweaving vulnerabilities of cross-business logic and security components that traditional testing cannot reach, continuously improve testing depth and efficiency.
Owner:GUANGZHOU LETENG SOFTWARE TECHNOLOGY CO LTD

A knowledge graph-based network abnormal traffic information construction method and device

PendingCN122419926AEngineeringOutlier
The application provides a network abnormal flow intelligence construction method and device based on a knowledge graph, which comprises the following steps: constructing an initial knowledge graph based on static information, dividing features based on dynamic information to obtain statistical features and structured features; performing clustering analysis on the statistical features based on density-guided bisection splitting clustering to obtain statistical clusters, and performing clustering analysis on the structured features based on quality density projection clustering to obtain structured clusters and outliers; performing consensus fusion based on the statistical clusters, the structured clusters and the outliers to obtain feature consensus results, mapping entities corresponding to the dynamic information to the initial knowledge graph based on the feature consensus results to perform dynamic completion, and obtaining a completed knowledge graph; and converting context subgraphs retrieved in the completed knowledge graph with abnormal behavior events as the center into context information and inputting the context information into an AI model to obtain abnormal flow intelligence. The application improves the attack tracing efficiency and decision accuracy for advanced persistent threats.
Owner:GUANGZHOU ANHAI INFORMATION SECURITY TECH CO LTD

An IPv6 encrypted traffic advanced persistent threat attack identification method and system

PendingCN122457381AFeature vectorAttack
The application relates to the technical field of network security, in particular to an IPv6 encrypted traffic advanced persistent threat attack identification method and system; the method comprises the following steps: extracting a cipher suite arrangement sequence, an extended field type set and a cipher library version identifier; performing sequence comparison and tolerance determination with a preset legal client variant fingerprint library to determine a suite arrangement coincidence level; screening out to-be-identified messages with a coincidence level lower than a preset legal threshold to generate a to-be-identified object set; and performing clustering analysis based on the arrangement feature vectors of the to-be-identified object set to identify a homologous concealed imitated traffic subset. In this way, the technical problem that the identification precision of a handshake fingerprint template and the overall identification accuracy are difficult to be considered in the prior art when dealing with the realistic scene of diversified client fingerprints in a signal creation environment is solved, and the accuracy and reliability of encrypted threat identification are improved.
Owner:LISHUI POWER SUPPLY COMPANY OF STATE GRID ZHEJIANG ELECTRIC POWER

An advanced persistent threat encrypted traffic detection method, device and electronic equipment

The application provides an APT encrypted traffic detection method and device and electronic equipment, which can use an APT identification model trained according to the double-entity multi-session characteristics of APT encrypted traffic to detect whether the obtained network traffic is APT encrypted traffic, so that APT malicious traffic can be detected as comprehensively and accurately as possible.
Owner:CHINA INFORMATION TECH SECURITY EVALUATION CENT

Adaptive deception defense method and system based on reinforcement learning

The application relates to a kind of adaptive deception defense method and system based on reinforcement learning, the method includes the following steps: real-time acquisition of the multidimensional data of protected host, and it is integrated as environment state vector, the multidimensional data includes network traffic state, system vulnerability information and attacker behavior mode;Create the defense agent driven by the deep reinforcement learning kernel, enable it to dynamically select and execute deception defense action according to environment state vector, deception defense action includes real-time generation and attacker detection intention matching false service image, modification network topology to redirect malicious traffic, and fake system response data;Wherein, the defense process is modeled as Markov decision process, so that the system can predict its subsequent attack intention in real time according to each operation of attacker in deception environment, and dynamically adjust subsequent deception defense action.The application can realize the efficient trapping and defense of advanced persistent threat and automated attack.
Owner:CHINA STATE CONSTR OVERSEAS DEV CO LTD