Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

102 results about "Advanced persistent threat" patented technology

An Advanced Persistent Threat (APT) is a stealthy computer network threat actor, typically a nation state or state-sponsored group, which gains unauthorized access to a computer network and remains undetected for an extended period . In recent times, the term may also refer to non-state sponsored groups conducting large-scale targeted intrusions for specific goals.

Intelligent network intrusion detection system based on 5G network

The invention discloses a network intrusion intelligent detection system based on a 5G network, and relates to the technical field of network security. Comprising a traffic anomaly detection and analysis module, a data encryption tampering detection module, an anomaly analysis and evaluation module, an attack prediction and prevention module, a dynamic isolation and protection module, a reverse tracking and tracing module and a redirection and isolation protection module. According to the system, more efficient and more accurate intrusion detection and threat defense can be realized in a 5G network environment by integrating a plurality of advanced technologies and intelligent modules. Compared with a traditional rule-based detection method, the system can adaptively learn and identify a new attack mode, and the detection capability for zero-day attacks, variant attacks and advanced persistent threats (APT) is enhanced. Besides, by combining deep learning and reinforcement learning algorithms, the system can predict potential attacks in a dynamically changing network environment and automatically optimize a defense strategy, and the response speed and accuracy of the defense system are improved.
Owner:SHANDONG YUNZHIHUI INFORMATION TECHNOLOGY SERVICE CO LTD

Communication data intelligent safety supervision system based on big data

The invention relates to the technical field of big data security analysis and network information security, in particular to a communication data intelligent security supervision system based on big data, which comprises a data acquisition module used for extracting standardized entity behavior feature vectors from multi-source heterogeneous communication data; the baseline modeling module is used for dynamically generating a multi-dimensional behavior baseline portrait based on the historical sequence of the entity behavior feature vectors; the anomaly detection module is used for comparing the real-time entity behavior feature vector with the multi-dimensional behavior baseline portrait so as to calculate a micro anomaly score; the atlas construction module is used for screening the micro-anomaly events according to whether the micro-anomaly score exceeds a preset threshold value or not, and quantifying association confidence among the screened events so as to construct an attack chain atlas; the risk quantification module is used for aggregating the characteristics of the attack chain atlas to determine a systematic risk score; according to the method, the discovery capability and response efficiency of complex attacks such as advanced persistent threats and the like are greatly improved.
Owner:STATE GRID JIBEI ELECTRIC POWER COMPANY LIMITED CHENGDE POWER SUPPLY +1

APT attack active defense method based on four-honey system

The invention provides an APT (Advanced Persistent Threat) attack active defense method based on a four-honey system. The APT attack active defense method comprises the following steps: collecting events fed back by a defense component in the four-honey system and external threat intelligence to obtain safety observation data, and generating an alignment sub-graph representing a relationship between anchored tactical behaviors; performing explicit relation reasoning and implicit relation reasoning by combining the aligned sub-graph and the APT knowledge graph to realize attack intention prediction so as to generate a candidate attack intention set and confidence distribution thereof; generating an optimal deployment strategy under the constraint of a system resource state, and packaging the optimal deployment strategy into an executable work order; calling resources for deployment and generating a deployment state receipt to complete construction of a new trapping environment; and collecting attacker behavior data, evaluating strategy validity according to the attacker behavior data and the deployment strategy, and updating the strategy deployment priority. The method can be applied to real-time strategy adaptation and automatic resource scheduling of attack behavior evolution, and the flexibility and continuous interference capability in a complex attack and defense environment are remarkably improved.
Owner:GUANGZHOU UNIVERSITY

APT attack detection method, device and equipment

ActiveCN120979783ABiological modelsSecuring communicationNode compromiseAttack
The invention discloses an APT (Advanced Persistent Threat) attack detection method, device and equipment. The method comprises the following steps: constructing and updating a space-time diagram based on multi-source security data; calculating only aiming at the change sub-graph influenced by the change node to obtain a node threat score so as to determine a high-risk node; extracting an operation behavior of the high-risk node, determining a tactical stage to which the operation behavior belongs by using a preset attack tactical system, and forming a security event comprising a timestamp, a behavior description vector and a tactical stage label; determining the causal degree by analyzing the time interval, tactical intention consistency and tactical stage coherence between any two security events; mapping the security events and the causality degree into nodes and edges of an event directed graph; and determining an attack path from candidate attack paths with relatively high accumulated edge weights in the event directed graph. According to the method and the device, real-time and accurate detection and automatic attack chain reconstruction of the APT attack are realized.
Owner:CHINA TELECOM NETWORK SECURITY TECH CO LTD

API monitoring security audit model based on government affair system

The invention discloses an API (Application Program Interface) monitoring security audit model based on a government affair system, which relates to the technical field of network security, and comprises the following steps: collecting and converging network traffic of each collection point; analyzing the distribution condition of APIs in the collected flow, identifying and displaying key information, meanwhile, realizing data real-time processing, data stream splitting, data reading and writing and offline data analysis, and detecting risk behaviors by utilizing a rule strategy library; aPI asset weaknesses are identified and marked, state management is supported, and an attacker portrait, security study and judgment and attack traceability model is constructed; and pushing and displaying risk model early warning, realizing multi-dimensional data source real-time association analysis based on a big data framework, automatically converging alarms to form an event file, and linking with automatic arrangement to complete event response and report generation. According to the method, the problem of insufficient security and stability of the government affair system is solved, and complex attacks and advanced persistent threats can be identified more accurately.
Owner:上海市大数据中心

File-free attack detection method, system and equipment based on multi-view behavior modeling and frequency domain enhanced contrast learning, and medium

The invention discloses a non-file attack detection method, system and device based on multi-view behavior modeling and frequency domain enhancement contrast learning and a medium, and belongs to the technical field of network security, and the method comprises the steps: collecting and coding multi-source behavior data of a target system during operation, and carrying out the unified coding; performing time sequence division on the multi-source behavior data, and constructing a corresponding behavior graph; inputting the divided time sequence into a self-attention mechanism neural network, extracting time domain representation of behaviors, inputting the constructed behavior graph into a graph structure neural network, and extracting structure representation; respectively performing fast Fourier transform on the time domain representation and the structure representation to generate frequency domain representation; constructing a joint contrast learning loss function, and training a consistency detection model; and judging whether the behavior is a file-free attack behavior based on the consistency deviation in combination with an anomaly detection judgment mechanism. According to the method, the non-file-attack characteristic behaviors are accurately identified, and the capability of detecting the non-file-attack in the advanced persistent threats is effectively improved.
Owner:GUANGXI POWER GRID CORP

Security decision execution method and system based on adaptive feedback

PendingCN120498748ASecuring communicationKnowledge based modelsAttackInternet of things cloud computing
The invention belongs to the technical field of network security defense, and particularly discloses a multi-stage network security threat defense method and system based on adaptive feedback. A defense strategy is dynamically generated and optimized by performing multi-dimensional analysis on feature differences of historical security events and events to be processed and combining an adaptive feedback mechanism and an attack detection model for iterative training; when deviation or novel threats are detected, rollback and incremental training can be automatically triggered, and multi-round iterative closed-loop defense is formed. The method effectively deals with advanced persistent threats, zero-day vulnerabilities and multi-stage attacks, significantly improves threat detection accuracy and strategy response efficiency, reduces redundant feature interference, enhances expandability and adaptivity of the system, can be widely applied to environments such as the Internet of Things, cloud computing and enterprise intranets, and has wide application prospects. And the intelligence and flexibility of network protection are obviously improved.
Owner:NAT UNIV OF DEFENSE TECH

Attack detection method and device of power monitoring system, electronic equipment, medium and product

The invention discloses an attack detection method and device for a power monitoring system, electronic equipment, a medium and a product, and relates to the technical field of information security, and the method comprises the steps: obtaining network flow data of the power monitoring system through a distributed network flow collection unit, and converting the network flow data into a feature matrix to obtain a basic feature matrix; inputting the basic feature matrix into a preset attack detection model to obtain an attack detection result; and if the attack detection result represents that the power monitoring system suffers from the advanced persistent threat, generating warning information based on the attack detection result and outputting the warning information. According to the application, the detection accuracy of the APT attack detection method can be improved, the security of the power monitoring system is improved, and reliable guarantee is provided for stable operation of the power monitoring system.
Owner:GUO JIA DIAN WANG YOU XIAN GONG SI XI NAN FEN BU +1

Attack behavior analysis engine construction method based on deep learning

The invention discloses an attack behavior analysis engine construction method and system based on deep learning, and belongs to the technical field of power system network security. The method comprises the following steps of: firstly, performing deep syntax tree analysis on an electric power industrial control protocol by constructing a multilayer feature extraction module for business semantic decoupling, and realizing semantic mapping from a network message to a business operation intention and generating a three-dimensional feature tensor in combination with a pre-constructed electric power business knowledge graph; secondly, designing a dynamic adversarial training mechanism, synthesizing a high-simulation adversarial sample by adopting a Wasserstein generative adversarial network obeying power business logic constraints, and continuously optimizing the robustness of the detection model; and finally, establishing a topology-aware graph neural network attack detection model, converting an equipment connection relationship of physical scenes such as a transformer substation into a graph structure, and analyzing a cross-node attack propagation chain by using a graph convolutional network. According to the method, the detection precision and the response speed of complex attacks such as advanced persistent threats are remarkably improved.
Owner:GUANGXI POWER GRID CORP

Safety protection method and device based on multi-level multi-player safety master-slave game

The embodiment of the invention provides a security protection method and device based on a multi-level multi-player security master-slave game, and the method comprises the steps: constructing a multi-level multi-player security master-slave game decision model corresponding to a security protection system according to a large complex attack and defense scene facing the security protection system; analyzing Stackelberg equilibrium and Nash equilibrium of the model so as to solve a Stackelberg equilibrium strategy and a Nash equilibrium strategy; determining the consistency condition of the Stackelberg equilibrium strategy and the Nash equilibrium strategy of the model according to the disturbance of the model in practical application and the threat of uncertainty factors to the Stackelberg equilibrium reliability of the model; and setting the model according to the consistency condition, and applying the set model to an advanced continuous threat attack and defense scene which is actually faced by a security protection system for security protection. In this way, the security protection effect can be improved based on the multi-level multi-player security master-slave game decision model.
Owner:TONGJI UNIV

APT network attack identification method and system

The embodiment of the invention discloses an APT (Advanced Persistent Threat) network attack identification method, which comprises the following steps: collecting multi-source data from a plurality of data sources, and filtering current attack behavior data from the multi-source data; performing multi-dimensional similarity calculation on the current attack behavior data and the APT organization intelligence in the multi-modal threat knowledge graph to obtain a comprehensive similarity, the multi-modal threat knowledge graph being obtained by modeling after the multi-dimensional attack data and the threat intelligence are fused; nodes in the multi-modal threat knowledge graph are used for representing APT organizations, TTP, used tools and attack targets, and edges connected with the nodes are used for representing relationships among entities represented by the nodes; and based on the comprehensive similarity and the multi-modal threat knowledge graph, performing attribution reasoning on the APT organization of the current attack behavior data to obtain the identity information of the attacker. According to the method, unknown threats can be identified, the identity information of an attacker can be obtained through accurate reasoning, and the utilization rate of intelligence is improved.
Owner:QI AN XIN TECHNOLOGY GROUP INC

Communication data analysis system and method for network security

The invention discloses a communication data analysis system and method for network security, and relates to the technical field of computer internet. Time sequence features, protocol semantic features and interactive topology features of communication session historical data are extracted based on network flow data; the method comprises the following steps of: acquiring a time sequence feature, a protocol semantic feature and an interactive topology feature, fusing the time sequence feature, the protocol semantic feature and the interactive topology feature into a unified high-dimensional feature vector, acquiring a communication behavior record and a communication behavior dynamic feature vector of network equipment in a communication network, calculating a digital feature of a coupling relationship evaluation value, and when a certain communication session occurs, judging whether the communication session occurs or not. The method comprises the following steps of: calculating real-time coupling relationship evaluation values among network equipment, quantifying the difference degree of the real-time coupling relationship evaluation values through digital characteristics, accumulating the coupling relationship evaluation values in the process of performing a certain communication session, calculating the total anomaly degree of the communication session, and calculating the abnormal degree of the communication session. The method aims at solving the problems that advanced persistent threats are difficult to effectively recognize, feature expression is insufficient and the perceptual ability is weak in the prior art.
Owner:YANCHENG HUAFEI DATA TECHNOLOGY CO LTD

Firewall dynamic policy adaptation method and system based on big data

The invention discloses a firewall dynamic policy adaptation method and system based on big data, and the method comprises the steps: collecting multi-source heterogeneous data in a network, and constructing a dynamic network entity map in real time; processing the time sequence of the atlas by using a preset time sequence diagram attention network model to obtain a behavior fingerprint vector representing the behavior state of the entity, and calculating the risk score of the entity; when the risk score exceeds a risk threshold value, automatically generating a temporary security policy for managing and controlling the access behavior of the entity; and managing the life cycle of the temporary security policy, and automatically updating, renewing or cancelling according to the entity risk state change. According to the method, the network entity behavior baseline is constructed and the risk prediction is carried out, so that the conversion from passive defense to active defense is realized, the security policy can be automatically and accurately generated and managed, advanced persistent threats and zero-day attacks can be effectively coped with, and the self-adaptability and the intelligent level of network defense are improved.
Owner:HANGZHOU TAICHENG NETWORK TECH CO LTD

Multivariate attack feature recognition method and system based on persistent threat attack

The invention is suitable for the technical field of network security, and provides a multivariate attack feature recognition method and system based on persistent threat attacks, and the method comprises the steps: obtaining a real-time traffic data sequence in a target network environment; performing primary anomaly sensing processing on the real-time traffic data sequence to obtain a suspicious traffic fragment set; executing thinking chain reasoning analysis on the suspicious traffic fragment set, and generating an attack behavior reasoning path comprising multi-stage reasoning steps; performing matching verification on the attack behavior reasoning path and a pre-constructed threat intelligence knowledge base, and determining an attack stage and an attack intention of the persistent threat attack; and generating a multivariate attack feature recognition result according to a matching verification result. According to the method, analysis of advanced persistent threat attack multi-stage features is realized through a thinking chain reasoning mode, and the timeliness and reliability of detection are improved, so that the active protection capability of network security is improved.
Owner:CHINA DATANG CORPORATION SCIENCE AND TECHNOLOGY GENERAL RESEARCH INSTITUTE +1

Model device for data flow monitoring based on government affair system

The invention belongs to the technical field of data flow, and discloses a data flow monitoring model device based on a government affair system. By solving the problem that government affair public data generally lacks security monitoring blind spots of overall government affair public data flow monitoring, the depth and breadth of security monitoring are effectively improved, so that the problem that a traditional security protection means is difficult to deal with advanced persistent threats, large-scale sensitive data leakage and novel threats of complex network attacks is solved. Through safety supervision and safety panoramic analysis of government affair public data flow monitoring, a result after safety data analysis is analyzed according to research and judgment analysis, authorization analysis and flow supervision process analysis of flow data safety monitoring and supervision design, and cross-platform, cross-department and cross-level unified data safety situation presentation and centralized management are realized.
Owner:上海市大数据中心

Implementation method and system of dual access control mechanism based on block chain and encryption machine

The invention relates to the technical field of data security and access control, in particular to an implementation method and system of a dual access control mechanism based on a block chain and an encryption machine, and the implementation method comprises the steps of authority management based on a smart contract, encryption machine dynamic key generation, dual access control, and exception handling and auditing. The method has the beneficial effects that the non-tampering property of authority distribution and operation records is ensured through a distributed account book technology of the block chain, and a double-layer security barrier of logic credibility and physical isolation is formed in combination with hardware-level key protection (such as a security chip HSM) of an encryption machine. And the anti-attack capability is improved, the block chain resists data tampering and insider disintegration, the encryption machine prevents key side channel attacks, and the double mechanisms can cope with complex attack modes such as man-in-the-middle attacks, replay attacks and advanced persistent threats (APT).
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

Semi-supervised classification method of relation graph aggregation model for APT attack identification

The invention discloses a semi-supervised classification method of a relation graph aggregation model for APT attack recognition, relates to the technical field of graph neural networks, and solves the problems of massive graph data, complex relation modeling, label scarcity and the like in existing advanced persistent threat attacks. And the GraphSAGE layer flexibly processes large-scale graph data through sampling and aggregation of neighbor nodes. And meanwhile, a small amount of marked data and a large amount of unmarked data can be effectively utilized by adopting a semi-supervised learning strategy, so that the pressure of data marking is relieved. Experimental results show that compared with other methods, the AARGS model has certain advantages in the aspects of classification accuracy and generalization ability. Meanwhile, the semi-supervised learning method effectively reduces the dependence on high-quality annotation data, so that the cost and workload of data annotation are reduced.
Owner:CHANGCHUN UNIV OF SCI & TECH

Behavior extraction and analysis device based on host operation log

The invention discloses a behavior extraction and analysis device based on a host operation log, and the device comprises a clustering and slicing processing module which is used for processing input clustering data, extracting the single operation behavior description of each cluster, processing the clusters based on the single operation behavior description, fusing the clusters with behavior continuity, and obtaining a fusion result; clustering fragments are obtained; the intention analysis model is used for analyzing the clustering slices on the basis of single operation behavior description, and analyzing the behavior pattern of the user from the whole behavior so as to obtain the intention of the user; and the intention analysis result processing module identifies the intention analysis result output by the intention analysis model, and gives an alarm if the intention analysis result is abnormal. According to the behavior extraction and analysis device based on the host operation log, the relationship and trend between the data can be analyzed, so that possible attack modes or abnormal behaviors for host operation are revealed, and complex attacks and advanced persistent threats can be recognized more accurately.
Owner:上海市大数据中心

An important activity network security attack early warning method

The application provides a kind of important activity network security attack early warning method before including: according to the system features of heavy protection system, construct deception system, deception system includes Web real-time communication module and multiple simulation interaction module, design false login function, the deception system is deployed in cloud server;Attack record of deception system and attack record of heavy protection system are de-duplication processing and obtain attack record set;Analysis of the access behavior information of attacker determines the type of attacker, design targeted defense measures;Generate early warning report and send early warning report and targeted defense measures to heavy protection system.The application of the method can collect data through the deception system, dynamically generate a security warning report and assess the risk of the attacker.Based on the early warning results, the heavy protection system can be guided to take defensive measures to improve the defense capabilities.The deception capability and dynamic defense level of the heavy protection system can be effectively enhanced, and the ability to deal with advanced persistent threats is improved.
Owner:GUANGZHOU UNIVERSITY

Network elasticity capability assessment method, device, equipment and medium

The invention relates to the technical field of computers, and discloses a network elasticity capability evaluation method and device, equipment and a medium, and the method comprises the steps: determining a network elasticity capability measurement index set matched with a submitted object; scoring each network elasticity capability measurement index in the network elasticity capability measurement index set to obtain a scoring set of the network elasticity capability measurement index set in different dimensions; summarizing the obtained score sets on different dimensions to obtain a target score corresponding to each network elasticity capability measurement index; and summarizing the target scores layer by layer according to a hierarchical structure of a preset network elasticity evaluation index system to obtain a network elasticity capability score of the submitted object, and determining a network elasticity capability evaluation result of the submitted object according to the network elasticity capability score. According to the technical scheme provided by the invention, the evaluation accuracy of the recovery capability of the network security system in the face of advanced persistent threats can be improved.
Owner:PURPLE MOUNTAIN LAB

Application security monitoring system and method based on behavior portrait data

The invention discloses an application security monitoring system and method based on behavior portrait data, and relates to the technical field of network security, and the system comprises a flow collection and preprocessing module, a behavior portrait module, a security analysis module and a strategy execution module. The flow acquisition and preprocessing module is deployed in a network access layer and comprises a network probe and a data cleaning unit, the behavior portrait module is connected with a log output end of the flow acquisition terminal, the security analysis module is connected with an output end of the behavior portrait module, and the strategy execution module is connected with an alarm output end of the security analysis module. According to the method, the function of high risk detection rate is realized by establishing the multi-dimensional static behavior model, the behavior baseline is constructed and is quantitatively compared with the real-time behavior, the abnormal behavior which cannot be recognized by a traditional rule base can be found, the false alarm rate is remarkably reduced, and the detection rate of internal threats and advanced persistent threats is improved.
Owner:GUANGDONG POWER GRID CO LTD +1

Network security situation awareness method and system based on artificial intelligence

The invention relates to the technical field of network security, in particular to a network security situation awareness method and system based on artificial intelligence, and the method comprises the following steps: 1, data collection: collecting multi-source data such as network traffic, system logs and threat intelligence, and providing basic materials for subsequent analysis; 2, data preprocessing, cleaning, normalization and feature extraction are carried out, so that the data are more regular and effective, and subsequent artificial intelligence model processing is facilitated; the network security situation awareness system based on artificial intelligence can perform deep analysis and mining on massive network security data by utilizing machine learning and deep learning algorithms, and can automatically learn and identify unknown attack modes and abnormal behaviors compared with a traditional detection method based on rules, so that the network security situation awareness system based on artificial intelligence can be applied to the field of network security situation awareness. And the detection capability on novel threats and advanced continuous threats is greatly improved.
Owner:LIAONING ZHONGFEI NETWORK TECHNOLOGY CO LTD

A method and system for predicting cybersecurity situation based on artificial intelligence

This invention relates to the field of network security technology and discloses a network security situation prediction method and system based on artificial intelligence, comprising the following steps: embedding controllable Trojan data into user-facing software by uploading network data; collecting hardware information data of the software and software status data of the user-facing software based on a data acquisition module; extracting feature vectors from the hardware information data and software status data; and then having a third party evaluate the security coefficient of the controllable Trojan data. This invention, by proactively embedding a controllable, fingerprint-hidden authorized Trojan in a real software environment for attack and defense drills, overturns the passive mode of traditional security detection that relies on historical attack characteristics or static rule bases. This enables proactive perception and discovery of attack clues for unknown threats and advanced persistent threats, greatly improving the system's predictability of potential risks.
Owner:SHANDONG DINGXIA INTELLIGENT TECH CO LTD +1

Malicious domain name identification system and method based on DNS collision

The invention aims to provide a malicious domain name identification system and method based on DNS collision. The system comprises a data acquisition module, an active domain name resolution module, a data cleaning and sorting module, a preliminary matching and screening module, an AI research and judgment module and a storage module. According to the system and the method, active detection and high-confidence verification are organically combined, a brand-new malicious domain name recognition and tracing normal form is constructed, advanced persistent threats which are most hidden and most cunning can be effectively found and traced, and the important blank of a system in the prior art is filled.
Owner:NAT COMPUTER NETWORK & INFORMATION SECURITY MANAGEMENT CENT GUANGXI BRANCH

APT attack detection method and system based on mask strategy and graph auto-encoder

The invention discloses an APT (Advanced Persistent Threat) attack detection method based on a mask strategy and a graph auto-encoder. The method comprises the following steps: 1, constructing a log traceability graph, and carrying out noise reduction on the log traceability graph; 2, nodes needing to be masked in the log traceability graph are masked through a mask node selector; step 3, training a mask graph auto-encoder, and representing features through a corresponding benign graph obtained by the graph auto-encoder; 4, constructing a corresponding to-be-detected log traceability graph, and performing noise reduction on the log traceability graph; establishing a mapping relation between the traceability graph node and the system log entity; 5, obtaining graph representation features of the nodes to be detected; 6, calculating an abnormal score, and judging whether a node corresponding to the graph representation feature is abnormal or not according to whether the score exceeds an abnormal threshold or not; and step 7, obtaining abnormal entity entries which are entity entries detected by the method and related to the APT attack. And a better APT attack detection effect is obtained.
Owner:HANGZHOU ADAPTIVE TECH CO LTD

Network attack attribution analysis and responsibility determination method based on causal reasoning

The invention discloses a network attack attribution analysis and responsibility determination method based on causal reasoning, and belongs to the technical field of network security. According to the method, multi-source heterogeneous data are integrated through data acquisition and preprocessing, a causal graph is constructed to mine a potential causal relationship, a causal path of an attack behavior is defined and dynamically updated, attribution analysis is performed by using a causal reasoning algorithm, the intention and ability of an attacker are clarified, the responsibility proportion is evaluated in combination with laws and regulations, and a report is output. And meanwhile, an analysis result is displayed through a visual tool, and the model is optimized based on user feedback. The method is suitable for the fields of enterprise network security protection, cloud service provider security operation, national network security supervision and the like, advanced persistent threats can be effectively dealt with, the interpretability and legal applicability of analysis results are improved, and scientific basis and technical support are provided for responsibility confirmation and risk control of network security events.
Owner:INFORMATION & COMM CO OF STATE GRID SHAANXI ELECTRIC POWER CO LTD

A network threat detection and blocking system based on multi-dimensional behavioral analysis

This invention relates to the field of network threat detection technology and discloses a network threat detection and blocking system based on multi-dimensional behavioral analysis. The system includes: constructing a service-independent behavioral profile container with baseline maturity self-checking capabilities; identifying attack intent based on heuristic rules; adaptively focusing analysis weights on specific behavioral dimensions corresponding to the intent for scoring; and ultimately achieving bypass blocking of malicious sessions. This invention avoids the fragmented understanding and excessive alerts caused by traditional methods that chase scattered attack features by deducing from behavioral appearances and focusing on the attacker's core intent. It can proactively construct logically coherent attack chains from massive amounts of data, achieving accurate perception and response to advanced persistent threats.
Owner:HANGZHOU RONGZHIXING TECH CO LTD

Industrial internet security threat discovery method and system based on large model

The invention discloses an industrial internet security threat discovery method and system based on a large model, and relates to the technical field of industrial internet security. The method comprises the following steps: collecting and preprocessing multi-source heterogeneous security data in the industrial internet; converting the processed multi-modal data into a unified joint feature vector; performing context-aware reasoning on the feature vector by using a large language model subjected to instruction fine tuning, and outputting a threat degree evaluation result; constructing a dynamic threat graph based on an evaluation result, and performing association analysis on a multi-step attack chain; and continuously optimizing the model according to the feedback information. The system comprises corresponding modules. According to the method, the problems of detection lag, single analysis dimension and incapability of deeply perceiving complex threats in a traditional method are effectively solved, the capability of discovering unknown threats and advanced persistent threats is improved, and intelligentization, initialization and continuation of industrial internet security threat discovering are realized.
Owner:SAISHENG IND TECH RES INST (QINGDAO) CO LTD

APT attack detection method based on traffic context deep mining features

The invention provides an APT (Advanced Persistent Threat) attack detection algorithm based on traffic context deep mining features, which comprises the following steps of: firstly, deeply mining five types of features with distinction degrees, namely packet level features, flow level features, DNS (Domain Name Server) traffic features, TCP (Transmission Control Protocol) traffic features and traffic encryption features of traffic from three dimensions of data packets, data flows and host-level data; then, the overall structure of the SJTU-APT23 data set is recognized in a visual mode through PCA visual correlation analysis and t-SNE visual correlation analysis in sequence, distribution of APT flow data and the relation between the extracted features are known, and the validity of the features is analyzed; and finally, using a random forest model, an SVM (Support Vector Machine) model and a KNN (K Nearest Neighbor) model to identify the APT traffic in the malicious software based on the deep-mined features, trying to classify the organization to which the APT traffic belongs, and proving the effectiveness of the extracted features from the perspective of practice. The invention provides an APT (Advanced Persistent Threat) attack detection method based on traffic context deep mining features, which can accurately identify APT traffic in malicious software traffic.
Owner:YANCHENG POWER SUPPLY CO STATE GRID JIANGSU ELECTRIC POWER CO

Persistent threat attack tracing method and system based on knowledge graph

The invention is suitable for the technical field of network security, and provides a persistent threat attack tracing method and system based on a knowledge graph, and the method comprises the steps: carrying out the staged semantic annotation of obtained multi-source heterogeneous evidence data based on a preset attack life cycle stage ontology model, and generating a current attack stage entity set; matching and associating the current attack stage entity set with a traceability knowledge graph, and performing traceability reasoning on the current attack stage entity set which is not matched with the instance evidence layer based on a meta-learning driven small sample inference engine to obtain a traceability reasoning result; and outputting a visual report containing a complete attack chain path and a quantitative attribution list based on a traceability reasoning result. According to the method, the staged logic of the attack is combined with the inference capability of the double-layer knowledge graph, so that accurate attack behavior association and organization attribution can still be realized under the condition of a small number of even zero samples, and the accuracy and timeliness of advanced persistent threat attack tracing are effectively improved.
Owner:CHINA DATANG CORPORATION SCIENCE AND TECHNOLOGY GENERAL RESEARCH INSTITUTE +1