Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

78 results about "Advanced persistent threat" patented technology

An Advanced Persistent Threat (APT) is a stealthy computer network threat actor, typically a nation state or state-sponsored group, which gains unauthorized access to a computer network and remains undetected for an extended period . In recent times, the term may also refer to non-state sponsored groups conducting large-scale targeted intrusions for specific goals.

Communication data intelligent safety supervision system based on big data

The invention relates to the technical field of big data security analysis and network information security, in particular to a communication data intelligent security supervision system based on big data, which comprises a data acquisition module used for extracting standardized entity behavior feature vectors from multi-source heterogeneous communication data; the baseline modeling module is used for dynamically generating a multi-dimensional behavior baseline portrait based on the historical sequence of the entity behavior feature vectors; the anomaly detection module is used for comparing the real-time entity behavior feature vector with the multi-dimensional behavior baseline portrait so as to calculate a micro anomaly score; the atlas construction module is used for screening the micro-anomaly events according to whether the micro-anomaly score exceeds a preset threshold value or not, and quantifying association confidence among the screened events so as to construct an attack chain atlas; the risk quantification module is used for aggregating the characteristics of the attack chain atlas to determine a systematic risk score; according to the method, the discovery capability and response efficiency of complex attacks such as advanced persistent threats and the like are greatly improved.
Owner:STATE GRID JIBEI ELECTRIC POWER COMPANY LIMITED CHENGDE POWER SUPPLY +1

APT attack active defense method based on four-honey system

The invention provides an APT (Advanced Persistent Threat) attack active defense method based on a four-honey system. The APT attack active defense method comprises the following steps: collecting events fed back by a defense component in the four-honey system and external threat intelligence to obtain safety observation data, and generating an alignment sub-graph representing a relationship between anchored tactical behaviors; performing explicit relation reasoning and implicit relation reasoning by combining the aligned sub-graph and the APT knowledge graph to realize attack intention prediction so as to generate a candidate attack intention set and confidence distribution thereof; generating an optimal deployment strategy under the constraint of a system resource state, and packaging the optimal deployment strategy into an executable work order; calling resources for deployment and generating a deployment state receipt to complete construction of a new trapping environment; and collecting attacker behavior data, evaluating strategy validity according to the attacker behavior data and the deployment strategy, and updating the strategy deployment priority. The method can be applied to real-time strategy adaptation and automatic resource scheduling of attack behavior evolution, and the flexibility and continuous interference capability in a complex attack and defense environment are remarkably improved.
Owner:GUANGZHOU UNIVERSITY

APT attack detection method, device and equipment

ActiveCN120979783ABiological modelsSecuring communicationNode compromiseAttack
The invention discloses an APT (Advanced Persistent Threat) attack detection method, device and equipment. The method comprises the following steps: constructing and updating a space-time diagram based on multi-source security data; calculating only aiming at the change sub-graph influenced by the change node to obtain a node threat score so as to determine a high-risk node; extracting an operation behavior of the high-risk node, determining a tactical stage to which the operation behavior belongs by using a preset attack tactical system, and forming a security event comprising a timestamp, a behavior description vector and a tactical stage label; determining the causal degree by analyzing the time interval, tactical intention consistency and tactical stage coherence between any two security events; mapping the security events and the causality degree into nodes and edges of an event directed graph; and determining an attack path from candidate attack paths with relatively high accumulated edge weights in the event directed graph. According to the method and the device, real-time and accurate detection and automatic attack chain reconstruction of the APT attack are realized.
Owner:CHINA TELECOM NETWORK SECURITY TECH CO LTD

API monitoring security audit model based on government affair system

The invention discloses an API (Application Program Interface) monitoring security audit model based on a government affair system, which relates to the technical field of network security, and comprises the following steps: collecting and converging network traffic of each collection point; analyzing the distribution condition of APIs in the collected flow, identifying and displaying key information, meanwhile, realizing data real-time processing, data stream splitting, data reading and writing and offline data analysis, and detecting risk behaviors by utilizing a rule strategy library; aPI asset weaknesses are identified and marked, state management is supported, and an attacker portrait, security study and judgment and attack traceability model is constructed; and pushing and displaying risk model early warning, realizing multi-dimensional data source real-time association analysis based on a big data framework, automatically converging alarms to form an event file, and linking with automatic arrangement to complete event response and report generation. According to the method, the problem of insufficient security and stability of the government affair system is solved, and complex attacks and advanced persistent threats can be identified more accurately.
Owner:上海市大数据中心

File-free attack detection method, system and equipment based on multi-view behavior modeling and frequency domain enhanced contrast learning, and medium

The invention discloses a non-file attack detection method, system and device based on multi-view behavior modeling and frequency domain enhancement contrast learning and a medium, and belongs to the technical field of network security, and the method comprises the steps: collecting and coding multi-source behavior data of a target system during operation, and carrying out the unified coding; performing time sequence division on the multi-source behavior data, and constructing a corresponding behavior graph; inputting the divided time sequence into a self-attention mechanism neural network, extracting time domain representation of behaviors, inputting the constructed behavior graph into a graph structure neural network, and extracting structure representation; respectively performing fast Fourier transform on the time domain representation and the structure representation to generate frequency domain representation; constructing a joint contrast learning loss function, and training a consistency detection model; and judging whether the behavior is a file-free attack behavior based on the consistency deviation in combination with an anomaly detection judgment mechanism. According to the method, the non-file-attack characteristic behaviors are accurately identified, and the capability of detecting the non-file-attack in the advanced persistent threats is effectively improved.
Owner:GUANGXI POWER GRID CORP

Attack behavior analysis engine construction method based on deep learning

The invention discloses an attack behavior analysis engine construction method and system based on deep learning, and belongs to the technical field of power system network security. The method comprises the following steps of: firstly, performing deep syntax tree analysis on an electric power industrial control protocol by constructing a multilayer feature extraction module for business semantic decoupling, and realizing semantic mapping from a network message to a business operation intention and generating a three-dimensional feature tensor in combination with a pre-constructed electric power business knowledge graph; secondly, designing a dynamic adversarial training mechanism, synthesizing a high-simulation adversarial sample by adopting a Wasserstein generative adversarial network obeying power business logic constraints, and continuously optimizing the robustness of the detection model; and finally, establishing a topology-aware graph neural network attack detection model, converting an equipment connection relationship of physical scenes such as a transformer substation into a graph structure, and analyzing a cross-node attack propagation chain by using a graph convolutional network. According to the method, the detection precision and the response speed of complex attacks such as advanced persistent threats are remarkably improved.
Owner:GUANGXI POWER GRID CORP

APT network attack identification method and system

The embodiment of the invention discloses an APT (Advanced Persistent Threat) network attack identification method, which comprises the following steps: collecting multi-source data from a plurality of data sources, and filtering current attack behavior data from the multi-source data; performing multi-dimensional similarity calculation on the current attack behavior data and the APT organization intelligence in the multi-modal threat knowledge graph to obtain a comprehensive similarity, the multi-modal threat knowledge graph being obtained by modeling after the multi-dimensional attack data and the threat intelligence are fused; nodes in the multi-modal threat knowledge graph are used for representing APT organizations, TTP, used tools and attack targets, and edges connected with the nodes are used for representing relationships among entities represented by the nodes; and based on the comprehensive similarity and the multi-modal threat knowledge graph, performing attribution reasoning on the APT organization of the current attack behavior data to obtain the identity information of the attacker. According to the method, unknown threats can be identified, the identity information of an attacker can be obtained through accurate reasoning, and the utilization rate of intelligence is improved.
Owner:QI AN XIN TECHNOLOGY GROUP INC

Communication data analysis system and method for network security

The invention discloses a communication data analysis system and method for network security, and relates to the technical field of computer internet. Time sequence features, protocol semantic features and interactive topology features of communication session historical data are extracted based on network flow data; the method comprises the following steps of: acquiring a time sequence feature, a protocol semantic feature and an interactive topology feature, fusing the time sequence feature, the protocol semantic feature and the interactive topology feature into a unified high-dimensional feature vector, acquiring a communication behavior record and a communication behavior dynamic feature vector of network equipment in a communication network, calculating a digital feature of a coupling relationship evaluation value, and when a certain communication session occurs, judging whether the communication session occurs or not. The method comprises the following steps of: calculating real-time coupling relationship evaluation values among network equipment, quantifying the difference degree of the real-time coupling relationship evaluation values through digital characteristics, accumulating the coupling relationship evaluation values in the process of performing a certain communication session, calculating the total anomaly degree of the communication session, and calculating the abnormal degree of the communication session. The method aims at solving the problems that advanced persistent threats are difficult to effectively recognize, feature expression is insufficient and the perceptual ability is weak in the prior art.
Owner:YANCHENG HUAFEI DATA TECHNOLOGY CO LTD

Firewall dynamic policy adaptation method and system based on big data

The invention discloses a firewall dynamic policy adaptation method and system based on big data, and the method comprises the steps: collecting multi-source heterogeneous data in a network, and constructing a dynamic network entity map in real time; processing the time sequence of the atlas by using a preset time sequence diagram attention network model to obtain a behavior fingerprint vector representing the behavior state of the entity, and calculating the risk score of the entity; when the risk score exceeds a risk threshold value, automatically generating a temporary security policy for managing and controlling the access behavior of the entity; and managing the life cycle of the temporary security policy, and automatically updating, renewing or cancelling according to the entity risk state change. According to the method, the network entity behavior baseline is constructed and the risk prediction is carried out, so that the conversion from passive defense to active defense is realized, the security policy can be automatically and accurately generated and managed, advanced persistent threats and zero-day attacks can be effectively coped with, and the self-adaptability and the intelligent level of network defense are improved.
Owner:HANGZHOU TAICHENG NETWORK TECH CO LTD

Multivariate attack feature recognition method and system based on persistent threat attack

The invention is suitable for the technical field of network security, and provides a multivariate attack feature recognition method and system based on persistent threat attacks, and the method comprises the steps: obtaining a real-time traffic data sequence in a target network environment; performing primary anomaly sensing processing on the real-time traffic data sequence to obtain a suspicious traffic fragment set; executing thinking chain reasoning analysis on the suspicious traffic fragment set, and generating an attack behavior reasoning path comprising multi-stage reasoning steps; performing matching verification on the attack behavior reasoning path and a pre-constructed threat intelligence knowledge base, and determining an attack stage and an attack intention of the persistent threat attack; and generating a multivariate attack feature recognition result according to a matching verification result. According to the method, analysis of advanced persistent threat attack multi-stage features is realized through a thinking chain reasoning mode, and the timeliness and reliability of detection are improved, so that the active protection capability of network security is improved.
Owner:CHINA DATANG CORPORATION SCIENCE AND TECHNOLOGY GENERAL RESEARCH INSTITUTE +1

Model device for data flow monitoring based on government affair system

The invention belongs to the technical field of data flow, and discloses a data flow monitoring model device based on a government affair system. By solving the problem that government affair public data generally lacks security monitoring blind spots of overall government affair public data flow monitoring, the depth and breadth of security monitoring are effectively improved, so that the problem that a traditional security protection means is difficult to deal with advanced persistent threats, large-scale sensitive data leakage and novel threats of complex network attacks is solved. Through safety supervision and safety panoramic analysis of government affair public data flow monitoring, a result after safety data analysis is analyzed according to research and judgment analysis, authorization analysis and flow supervision process analysis of flow data safety monitoring and supervision design, and cross-platform, cross-department and cross-level unified data safety situation presentation and centralized management are realized.
Owner:上海市大数据中心

Implementation method and system of dual access control mechanism based on block chain and encryption machine

The invention relates to the technical field of data security and access control, in particular to an implementation method and system of a dual access control mechanism based on a block chain and an encryption machine, and the implementation method comprises the steps of authority management based on a smart contract, encryption machine dynamic key generation, dual access control, and exception handling and auditing. The method has the beneficial effects that the non-tampering property of authority distribution and operation records is ensured through a distributed account book technology of the block chain, and a double-layer security barrier of logic credibility and physical isolation is formed in combination with hardware-level key protection (such as a security chip HSM) of an encryption machine. And the anti-attack capability is improved, the block chain resists data tampering and insider disintegration, the encryption machine prevents key side channel attacks, and the double mechanisms can cope with complex attack modes such as man-in-the-middle attacks, replay attacks and advanced persistent threats (APT).
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

An important activity network security attack early warning method

The application provides a kind of important activity network security attack early warning method before including: according to the system features of heavy protection system, construct deception system, deception system includes Web real-time communication module and multiple simulation interaction module, design false login function, the deception system is deployed in cloud server;Attack record of deception system and attack record of heavy protection system are de-duplication processing and obtain attack record set;Analysis of the access behavior information of attacker determines the type of attacker, design targeted defense measures;Generate early warning report and send early warning report and targeted defense measures to heavy protection system.The application of the method can collect data through the deception system, dynamically generate a security warning report and assess the risk of the attacker.Based on the early warning results, the heavy protection system can be guided to take defensive measures to improve the defense capabilities.The deception capability and dynamic defense level of the heavy protection system can be effectively enhanced, and the ability to deal with advanced persistent threats is improved.
Owner:GUANGZHOU UNIVERSITY

Network elasticity capability assessment method, device, equipment and medium

The invention relates to the technical field of computers, and discloses a network elasticity capability evaluation method and device, equipment and a medium, and the method comprises the steps: determining a network elasticity capability measurement index set matched with a submitted object; scoring each network elasticity capability measurement index in the network elasticity capability measurement index set to obtain a scoring set of the network elasticity capability measurement index set in different dimensions; summarizing the obtained score sets on different dimensions to obtain a target score corresponding to each network elasticity capability measurement index; and summarizing the target scores layer by layer according to a hierarchical structure of a preset network elasticity evaluation index system to obtain a network elasticity capability score of the submitted object, and determining a network elasticity capability evaluation result of the submitted object according to the network elasticity capability score. According to the technical scheme provided by the invention, the evaluation accuracy of the recovery capability of the network security system in the face of advanced persistent threats can be improved.
Owner:PURPLE MOUNTAIN LAB

Application security monitoring system and method based on behavior portrait data

The invention discloses an application security monitoring system and method based on behavior portrait data, and relates to the technical field of network security, and the system comprises a flow collection and preprocessing module, a behavior portrait module, a security analysis module and a strategy execution module. The flow acquisition and preprocessing module is deployed in a network access layer and comprises a network probe and a data cleaning unit, the behavior portrait module is connected with a log output end of the flow acquisition terminal, the security analysis module is connected with an output end of the behavior portrait module, and the strategy execution module is connected with an alarm output end of the security analysis module. According to the method, the function of high risk detection rate is realized by establishing the multi-dimensional static behavior model, the behavior baseline is constructed and is quantitatively compared with the real-time behavior, the abnormal behavior which cannot be recognized by a traditional rule base can be found, the false alarm rate is remarkably reduced, and the detection rate of internal threats and advanced persistent threats is improved.
Owner:GUANGDONG POWER GRID CO LTD +1

A method and system for predicting cybersecurity situation based on artificial intelligence

This invention relates to the field of network security technology and discloses a network security situation prediction method and system based on artificial intelligence, comprising the following steps: embedding controllable Trojan data into user-facing software by uploading network data; collecting hardware information data of the software and software status data of the user-facing software based on a data acquisition module; extracting feature vectors from the hardware information data and software status data; and then having a third party evaluate the security coefficient of the controllable Trojan data. This invention, by proactively embedding a controllable, fingerprint-hidden authorized Trojan in a real software environment for attack and defense drills, overturns the passive mode of traditional security detection that relies on historical attack characteristics or static rule bases. This enables proactive perception and discovery of attack clues for unknown threats and advanced persistent threats, greatly improving the system's predictability of potential risks.
Owner:SHANDONG DINGXIA INTELLIGENT TECH CO LTD +1

Malicious domain name identification system and method based on DNS collision

The invention aims to provide a malicious domain name identification system and method based on DNS collision. The system comprises a data acquisition module, an active domain name resolution module, a data cleaning and sorting module, a preliminary matching and screening module, an AI research and judgment module and a storage module. According to the system and the method, active detection and high-confidence verification are organically combined, a brand-new malicious domain name recognition and tracing normal form is constructed, advanced persistent threats which are most hidden and most cunning can be effectively found and traced, and the important blank of a system in the prior art is filled.
Owner:NAT COMPUTER NETWORK & INFORMATION SECURITY MANAGEMENT CENT GUANGXI BRANCH

APT attack detection method and system based on mask strategy and graph auto-encoder

The invention discloses an APT (Advanced Persistent Threat) attack detection method based on a mask strategy and a graph auto-encoder. The method comprises the following steps: 1, constructing a log traceability graph, and carrying out noise reduction on the log traceability graph; 2, nodes needing to be masked in the log traceability graph are masked through a mask node selector; step 3, training a mask graph auto-encoder, and representing features through a corresponding benign graph obtained by the graph auto-encoder; 4, constructing a corresponding to-be-detected log traceability graph, and performing noise reduction on the log traceability graph; establishing a mapping relation between the traceability graph node and the system log entity; 5, obtaining graph representation features of the nodes to be detected; 6, calculating an abnormal score, and judging whether a node corresponding to the graph representation feature is abnormal or not according to whether the score exceeds an abnormal threshold or not; and step 7, obtaining abnormal entity entries which are entity entries detected by the method and related to the APT attack. And a better APT attack detection effect is obtained.
Owner:HANGZHOU ADAPTIVE TECH CO LTD

Network attack attribution analysis and responsibility determination method based on causal reasoning

The invention discloses a network attack attribution analysis and responsibility determination method based on causal reasoning, and belongs to the technical field of network security. According to the method, multi-source heterogeneous data are integrated through data acquisition and preprocessing, a causal graph is constructed to mine a potential causal relationship, a causal path of an attack behavior is defined and dynamically updated, attribution analysis is performed by using a causal reasoning algorithm, the intention and ability of an attacker are clarified, the responsibility proportion is evaluated in combination with laws and regulations, and a report is output. And meanwhile, an analysis result is displayed through a visual tool, and the model is optimized based on user feedback. The method is suitable for the fields of enterprise network security protection, cloud service provider security operation, national network security supervision and the like, advanced persistent threats can be effectively dealt with, the interpretability and legal applicability of analysis results are improved, and scientific basis and technical support are provided for responsibility confirmation and risk control of network security events.
Owner:INFORMATION & COMM CO OF STATE GRID SHAANXI ELECTRIC POWER CO LTD

A network threat detection and blocking system based on multi-dimensional behavioral analysis

This invention relates to the field of network threat detection technology and discloses a network threat detection and blocking system based on multi-dimensional behavioral analysis. The system includes: constructing a service-independent behavioral profile container with baseline maturity self-checking capabilities; identifying attack intent based on heuristic rules; adaptively focusing analysis weights on specific behavioral dimensions corresponding to the intent for scoring; and ultimately achieving bypass blocking of malicious sessions. This invention avoids the fragmented understanding and excessive alerts caused by traditional methods that chase scattered attack features by deducing from behavioral appearances and focusing on the attacker's core intent. It can proactively construct logically coherent attack chains from massive amounts of data, achieving accurate perception and response to advanced persistent threats.
Owner:HANGZHOU RONGZHIXING TECH CO LTD

Industrial internet security threat discovery method and system based on large model

The invention discloses an industrial internet security threat discovery method and system based on a large model, and relates to the technical field of industrial internet security. The method comprises the following steps: collecting and preprocessing multi-source heterogeneous security data in the industrial internet; converting the processed multi-modal data into a unified joint feature vector; performing context-aware reasoning on the feature vector by using a large language model subjected to instruction fine tuning, and outputting a threat degree evaluation result; constructing a dynamic threat graph based on an evaluation result, and performing association analysis on a multi-step attack chain; and continuously optimizing the model according to the feedback information. The system comprises corresponding modules. According to the method, the problems of detection lag, single analysis dimension and incapability of deeply perceiving complex threats in a traditional method are effectively solved, the capability of discovering unknown threats and advanced persistent threats is improved, and intelligentization, initialization and continuation of industrial internet security threat discovering are realized.
Owner:SAISHENG IND TECH RES INST (QINGDAO) CO LTD

APT attack detection method based on traffic context deep mining features

The invention provides an APT (Advanced Persistent Threat) attack detection algorithm based on traffic context deep mining features, which comprises the following steps of: firstly, deeply mining five types of features with distinction degrees, namely packet level features, flow level features, DNS (Domain Name Server) traffic features, TCP (Transmission Control Protocol) traffic features and traffic encryption features of traffic from three dimensions of data packets, data flows and host-level data; then, the overall structure of the SJTU-APT23 data set is recognized in a visual mode through PCA visual correlation analysis and t-SNE visual correlation analysis in sequence, distribution of APT flow data and the relation between the extracted features are known, and the validity of the features is analyzed; and finally, using a random forest model, an SVM (Support Vector Machine) model and a KNN (K Nearest Neighbor) model to identify the APT traffic in the malicious software based on the deep-mined features, trying to classify the organization to which the APT traffic belongs, and proving the effectiveness of the extracted features from the perspective of practice. The invention provides an APT (Advanced Persistent Threat) attack detection method based on traffic context deep mining features, which can accurately identify APT traffic in malicious software traffic.
Owner:YANCHENG POWER SUPPLY CO STATE GRID JIANGSU ELECTRIC POWER CO

Persistent threat attack tracing method and system based on knowledge graph

The invention is suitable for the technical field of network security, and provides a persistent threat attack tracing method and system based on a knowledge graph, and the method comprises the steps: carrying out the staged semantic annotation of obtained multi-source heterogeneous evidence data based on a preset attack life cycle stage ontology model, and generating a current attack stage entity set; matching and associating the current attack stage entity set with a traceability knowledge graph, and performing traceability reasoning on the current attack stage entity set which is not matched with the instance evidence layer based on a meta-learning driven small sample inference engine to obtain a traceability reasoning result; and outputting a visual report containing a complete attack chain path and a quantitative attribution list based on a traceability reasoning result. According to the method, the staged logic of the attack is combined with the inference capability of the double-layer knowledge graph, so that accurate attack behavior association and organization attribution can still be realized under the condition of a small number of even zero samples, and the accuracy and timeliness of advanced persistent threat attack tracing are effectively improved.
Owner:CHINA DATANG CORPORATION SCIENCE AND TECHNOLOGY GENERAL RESEARCH INSTITUTE +1

Internet of things terminal network security early warning platform based on artificial intelligence

The invention discloses an Internet of Things terminal network security early warning platform based on artificial intelligence, which performs cross-domain feature alignment on information domain and physical domain data analyzed at a bottom layer, and innovatively converts the information domain and physical domain data into a time sequence texture grey-scale map, thereby utilizing the characteristics of a convolutional neural network on a spatial receptive field, and improving the security of the Internet of Things terminal network security early warning platform. And deeply extracting potential semantic association and time sequence evolution laws among the heterogeneous data streams. Finally, through full-connection classification and real-time estimation of threat probability, a full-link early warning closed loop from multi-dimensional feature fusion, deep feature mining to defense instruction automatic generation is realized, and the security defense efficiency and response speed of the industrial-grade Internet of Things in the face of advanced persistent threats are greatly improved.
Owner:STATE GRID HENAN INFORMATION & TELECOMM CO

Attack profiling system and method based on graph association

The application discloses an attack portrait system and method based on atlas association, relates to the technical field of network security, and aims to solve the problems of scattered threat IP behavior information, difficulty in dynamically displaying and tracing attack chains, and lack of intelligent identification of attack group coordination. The system comprises a data access and standardization module, a threat IP coordination body management module, a multi-dimensional portrait analysis module, an atlasized coordination body analysis module, and a closed-loop research and disposal module. By constructing a unified graph calculation data model, a coordination body object, multi-dimensional portrait factors, and a four-layer attack association atlas, and combining a SOAR automatic disposal mechanism, a full-process closed loop is realized from multi-source data fusion, coordinated attack gang identification to risk assessment and automatic blocking. The application significantly improves the identification, analysis and response capability of advanced persistent threats and complex coordinated attacks.
Owner:SICHUAN YILAN SITUATION TECH CO LTD

Rendering Blockchain Operations Resistant to Advanced Persistent Threats (APTs)

A permissioned blockchain, using off-chain storage, provides advantages over blockchains that rely on consensus and / or store information within the blockchain. Advantages include enhanced viability, compactness, and the ability to register material with distribution limitations (e.g., military classified). Examples create an immutable public record of data signatures that confirm when data is intact, without distributing the data itself, so that widespread availability of the blockchain (beyond those privileged to see the data) advantageously increases the size of the community that is able to detect spoofing or forgery attempts. A permissioning entity limits submissions to manage blockchain growth, foreclosing problematic material that may risk long-term viability. Examples render blockchain operations resistant to advanced persistent threats (APTs), leverage digital signatures as additional trust elements for high-risk data, link records to track pedigree and enable identification of superseded (obsolete) data, and leverage out-of-band date proof to enable independent verification of integrity and no-later-than data-of-existence.
Owner:TENET 3 LLC

Multi-task dynamic collaborative advanced persistent threat detection method and device

The invention discloses a multi-task dynamic collaborative advanced persistent threat detection method, and relates to the technical field of network security. The method comprises the following steps: firstly, cleaning security texts such as security logs and threat intelligence, and creating a domain dictionary for standardized mapping; then, a RoBERTa-based multi-task learning framework is constructed, three task heads of maliciousness analysis, tactical-association extraction and threat index detection are deployed in parallel on the basis of a shared encoder, and attack intention, attack elements and threat index high-order feature vectors are extracted respectively; and finally, the core is to introduce a bidirectional dynamic cooperation module, the module realizes vector splicing and weighting of high-order feature vectors in the three tasks through a gating fusion mechanism, generates a joint feature vector fused with multi-party semantic information, feeds back the joint feature vector to each task head, realizes information cooperation and decision mutual identification among the tasks, and finally outputs a threat report. According to the method, hidden threat information can be deeply identified, and the detection accuracy of complex attacks such as advanced persistent threats and the like is remarkably improved.
Owner:QINGDAO OCEAN SHIPPING MARINERS COLLEGE

Digital mine network security situation awareness method and system

The invention belongs to the technical field of industrial internet security, and particularly relates to a digital mine network security situation awareness method and system, and the method comprises the following steps: S1, accessing the network flow of a mine industrial switch, deconstructing a data packet into an instruction domain, an address domain and a load domain through protocol analysis, and extracting a timestamp and the binary content of each domain; s2, calculating the Shannon entropy of the protocol field in the current time window, and calculating the abnormal entropy increase index of the protocol field according to the average entropy value and the standard deviation under the historical normal working condition, thereby evaluating the hidden channel risk; and S3, extracting physical values in the continuous data packets, and calculating a physical inertia conflict coefficient according to the maximum change rate allowed by the physical parameters of the equipment. According to the method, the physical law is introduced as a safety criterion, so that the false alarm rate is effectively reduced, and precise perception of advanced persistent threats is realized.
Owner:CHINA ELECTRIC CLOUD INFORMATION TECH CO LTD

Attack scenario processing method and device for power monitoring system based on attack chain matching

The application discloses an attack scene processing method and device for a power monitoring system based on attack chain matching. The method comprises the following steps: obtaining target attack chain data of a power monitoring system; processing the target attack chain data to obtain target attack chain features; searching for at least one similar attack chain feature based on the target attack chain features; and processing attack scene information corresponding to the similar attack chain features and the target attack chain features by using a large language model to obtain disposal suggestion information corresponding to the target attack chain data. The present scheme can more accurately identify network attacks on the power monitoring system in combination with the target attack chain data, especially can accurately identify complex attack scenes such as advanced persistent threats (APTs), and can timely formulate reasonable disposal suggestion information through the large language model, thereby effectively improving the security of the power monitoring system.
Owner:STATE GRID INFORMATION & TELECOMM BRANCH +1

Autonomous generative pre-trained ai driven purple teaming solution for simulating advanced persistent threats and generating tailored risk remediation

Devices, systems, and methods for AI-driven security exercises emulate evolving threats across varied environments to proactively assess and strengthen resilience. AI models fuse external knowledge and best practices to design safe, multi-step simulations orchestrated by lightweight agents that elicit realistic, non-disruptive defensive behavior. The platform ingests operational signals and environment descriptions to adapt scenarios in a vendor-agnostic, environment-aware way. Iterative campaigns expand coverage and translate outcomes into qualitative likelihood and impact indicators for comparative risk views by asset and service. The system outputs machine-readable guidance summarizing effective and ineffective defenses, mapping findings to simulated paths, and recommending prioritized improvements across key control domains, aligned to governance and assurance expectations. By uniting adaptive simulation, continuous context, and outcome-driven guidance, the invention exposes material risk, focuses remediation on highest-value areas, and demonstrates measurable improvement over time.
Owner:PLURILOCK SECURITY SOLUTIONS INC