Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

34 results about "Application security" patented technology

Application security encompasses measures taken to improve the security of an application often by finding, fixing and preventing security vulnerabilities. Different techniques are used to surface such security vulnerabilities at different stages of an applications lifecycle such as design, development, deployment, upgrade, maintenance.

A security test method, device, equipment, medium and product are applied

PendingCN122333454AApplication securityTesting Methods
The application provides an application security testing method and device, equipment, medium and product, which can be applied to the fields of artificial intelligence technology and financial technology. The method comprises the following steps: determining test information of a to-be-detected application in an operation test process; the test information comprises to-be-detected information called by the to-be-detected application in the operation test process of the to-be-detected application; determining a corresponding compliance baseline of the to-be-detected application based on a pre-trained baseline generation model; the compliance baseline comprises a compliance information call baseline; the compliance information call baseline is used for representing information allowed to be called by the to-be-detected application; determining a baseline deviation between the test information and the determined compliance baseline, and determining a security detection result of the to-be-detected application according to the baseline deviation; the baseline deviation comprises an information deviation between the to-be-detected information and the compliance information call baseline.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Method, apparatus, device and storage medium for application security access

The application relates to the technical field of security verification, and discloses an application security access method and device, equipment and a storage medium, the method comprising the following steps: in response to an application access request input in a browser, determining identity verification information of a user according to the application access request; obtaining a device fingerprint, wherein the device fingerprint is generated by the browser according to device information of the user; performing security check according to the identity verification information and the device fingerprint to obtain a security check result; and performing application access control according to the security check result. The application can ensure that the user can only access the application on a specified security device, and effectively improves the application access security.
Owner:BEIJING HONGTENG INTELLIGENT TECH CO LTD

An application software development test system with real-time vulnerability detection

The application belongs to the technical field of application software development test, and discloses an application software development test system with real-time vulnerability detection, which comprises a code real-time collection module, a multi-dimensional vulnerability detection module, a vulnerability accurate positioning module, a vulnerability risk quantitative evaluation module, a dynamic repair guidance module, a data storage module, a visual interaction module and an iterative optimization module, and each module cooperates to form a whole-process closed-loop vulnerability detection and management and control system. The application software development test system with real-time vulnerability detection is adopted, real-time capture, accurate positioning, risk evaluation and dynamic repair suggestion output of the vulnerability are realized, and the software development test efficiency and application program security are improved.
Owner:BEIJING JIAXINYUAN TECHNOLOGY CO LTD

An ap platform management system and method

PendingCN122310512ASecure stateTerm memory
This application provides an AP platform management system and method. In this system, after receiving a startup request from an in-vehicle application, the EM module directly triggers the HSM module to verify the application's legitimacy. After successful application verification, the EM module triggers the runtime monitoring module to perform security monitoring on the application's real-time runtime data, enabling timely identification of abnormal behaviors caused by memory injection and malicious code execution. Simultaneously, the policy analysis module performs risk analysis based on a preset security policy library and outputs response strategies. The EM module then executes the corresponding security response operations, thereby establishing a complete application security status management system and a closed loop for security incident handling. This achieves deep collaboration between the EM and hardware security modules, providing stable security support covering the entire application lifecycle for the AP platform and effectively enhancing the AP platform's ability to respond to various cybersecurity threats.
Owner:NEUSOFT REACH AUTOMOBILE TECH (SHENYANG) CO LTD

Interceptors to requests external to an application security management system for evaluation and logging

PendingUS20260147876A1Platform integrity maintainanceSafety management systemsApplication procedure
Systems, methods, and computer-readable media are provided for implementing an application security management system. An application instance is executed that uses an interface that wraps external resource access functionality of the application instance. The interface is used to allow access from the application instance to one or more external resources, and an application security management system managing the interface logs requests. A call is received including a request for access to a resource external to the application instance along with metadata about functionality carried out by the application instance in association with the request. A use-case is determined for the request based at least in part on the metadata. The use-case is compared to a set of rules that map different use-cases to different candidate external resources to determine if the request to the resource is valid for the use-case. When the resource is not valid for the use-case, the request is rejected and logged.
Owner:ORACLE INT CORP

Application security testing methods, devices, equipment, storage media, and computer program products

PendingCN122310537AApplication securityInformation acquisition
This application discloses an application security detection method, apparatus, device, storage medium, and computer program product, relating to the field of application security technology. The method includes: verifying the target application file of the application to be launched to obtain the current integrity verification information of the application to be launched; obtaining the integrity record of the target application corresponding to the application to be launched, wherein the target application integrity record stores the initial integrity verification information generated during the installation phase of the application to be launched; and performing security detection on the application to be launched based on the current integrity verification information and the initial integrity verification information to obtain a security detection result. This application can perform security detection based on the current integrity verification information and the initial integrity verification information of the application to be launched before application launch, thereby solving the technical problem that existing application security detection methods cannot promptly detect security threats to installed applications before they run, thus affecting system operational security.
Owner:BEIJING HONGTENG INTELLIGENT TECH CO LTD

A business environment data resource management platform

PendingCN122119989ASecuring communicationFull dataServer appliance
The present application relates to resource management technical field, especially to a kind of business environment data resource management platform.The present application includes application security module, data security module, host security module, network security module and boundary security module;The application security module is responsible for the security protection of audit log and system application;The data security module realizes data backup security by timing increment and full data backup;The host security module provides security protection for server equipment through various protection measures;The network security module ensures the safety of network channel environment, and realizes the monitoring of network channel security protection;The boundary security module ensures the security of boundary and audits the tracking of intrusion detection event.The purpose of the present application is to provide a kind of business environment data resource management platform, to protect the safety of network channel, network channel environment, and handle intrusion event while protecting data security in time.
Owner:国网福建省电力有限公司营销服务中心 +1

An application exception detection method, device, equipment and readable storage medium

ActiveCN117010332BDecompilation/disassemblySemantic analysisEvent triggerTheoretical computer science
The application discloses an application anomaly detection method and device, equipment and a readable storage medium, and related embodiments can be applied to the fields of data security, application security, applet security, cloud security, privacy protection and the like. The method comprises the following steps: constructing a target node structure tree of an application to be detected, which comprises an interactive component and an extended description text; performing word segmentation processing on a target description short text in the target node structure tree to obtain a target description word segmentation; performing similarity matching on the target description word segmentation and word segmentation in a detection information dictionary to determine a detection information type of the target description word segmentation; and determining a detection result according to an event type of an event trigger attribute and the detection information type. By using the application, the cost and time consumption of anomaly detection on the application to be detected can be reduced.
Owner:GUANGZHOU TENCENT TECH CO LTD

Static application security testing tool comprehensive evaluation method, device and equipment

PendingCN122450794ASoftware quality assurancePerformance index
The application belongs to the technical field of software quality assurance and security testing, and specifically discloses a static application security testing tool comprehensive evaluation method, device and equipment. Through the application, a configuration template library is called to load preset detection configurations for each static application security testing tool; each static application security testing tool after loading the configurations is controlled to execute an evaluation task; a comprehensive quantitative score is calculated according to multi-dimensional index values, and the corresponding static application security testing tool is comprehensively evaluated according to the comprehensive quantitative score. In the above manner, the evaluation indexes are defined in the vertical dimension of 'three verticals', the detection capability index, the performance index and the availability index are included in the same framework for systematic and quantitative evaluation, a stereoscopic decision basis is provided for tool selection, and then the corresponding static application security testing tool is comprehensively evaluated according to the comprehensive quantitative score, so that the comprehensiveness and accuracy of the evaluation tool can be effectively improved.
Owner:CHINA STATE SHIPBUILDING CORP LTD RESEARCH INSTITUTE 719 +1

Automated application security onboarding

ActiveUS12645791B2Platform integrity maintainanceSoftware engineeringApplication security
The present invention sets forth a technique for performing automated application security onboarding. The technique includes receiving, via an interactive dashboard, a designation associated with a software application and one or more items of application information associated with the software application. The technique also includes determining, in real-time and based on one or more schemas, that that the one or more items of application information are sufficient for executing one or more of a plurality of software scanning tools. The technique further includes transmitting the designation and the one or more items of application information to the plurality of software scanning tools, analyzing the software application via the plurality of software scanning tools, receiving, from the plurality of software scanning tools, one or more scan results based on the analysis, and displaying the one or more scan results via the interactive dashboard.
Owner:DISNEY ENTERPRISES INC

A testing method, apparatus, and equipment for application-based security interception.

PendingCN122086774AReduce risk of churnEfficient pre-detectionError detection/correctionComputer security arrangementsSoftware engineeringApplication security
This invention discloses a testing method, apparatus, and device for application installation security interception. It relates to the field of mobile application security and automated testing. The method includes: obtaining a detection task for the installation package to be tested from a task queue; downloading the installation package to be tested to the local machine according to its download address; pushing the installation package to be tested to a specified storage path on the target Android device via an Android debugging bridge, and launching a pre-installed auxiliary application on the target Android device via the Android debugging bridge; operating the auxiliary application through a UI automated testing framework to trigger the installation of the installation package to be tested on the target Android device; obtaining the interface information of the target Android device during the installation process through the UI automated testing framework, and determining whether the installation is complete and whether security interception was triggered during the installation process based on the interface information; if the installation is complete, generating a structured test report. This invention enables automated and proactive detection of application installation security risks.
Owner:深圳墨世科技有限公司

An audit and physical security control method for heterogeneous interaction scenarios

The application discloses a kind of audit and physical security control methods for heterogeneous interaction scene, it is related to industrial control security and artificial intelligence application security technical field.The method is applied to the heterogeneous interaction control gateway that is connected in series between control instruction source and controlled end, by accessing and collecting the audio and video data and environmental sensor data of controlled end and environment, enhanced audit metadata is formed in combination with structured control instruction analysis result;Again, multi-dimensional rule matching is carried out using compliance rule engine, and the audit results of release, degradation or blocking are output;For the instruction of release or degradation, timing shaping processing is executed and is mapped as at least one target interface signal Output to controlled end;While real-time monitoring the physical layer state of controlled end interface, trigger hardware fuse and switch to manual input channel when detecting manual input occupation;And through audit log record and feedback evaluation, closed-loop optimization is realized.The method can improve the control security, output stability and event traceability in the heterogeneous interaction control scene.
Owner:孟文俊

Application-driven multi-network switching and data transmission method, device and equipment, and storage medium

The application discloses an application-driven multi-network switching and data transmission method and device, equipment and a storage medium, and relates to the technical field of network communication. When a target network switching request initiated by a target application program is received, an application security identifier is obtained based on the target network switching request. According to a preset session maintenance strategy, the target SIM corresponding to the application security identifier is applied to network data transmission. Since the request parameter actively initiated by the application layer is directly mapped to the target SIM selection of the hardware layer, the problem that the prior art cannot associate the application security identifier with the target SIM to drive network switching according to the request actively initiated by the application is solved, and the beneficial effect that the application security identifier directly drives the selection of the underlying SIM is achieved.
Owner:QUANXUN IOT TECHNOLOGY (JINAN) CO LTD

Security against identity theft in generative artificial intelligence applications

Security against identity theft in generative artificial intelligence applications includes receiving, from a user computing device, an online user prompt to a large language model (LLM), the online user prompt associated with a user identifier, tokenizing the online user prompt to generate a target set of tokens, and tagging each token in the target set based on parts of speech to obtain a tagged target set. Security further includes processing, by a vector embedding model, the tagged target set to generate multiple vector embeddings, processing, by a sequential model, the vector embeddings to generate a target vector, processing, by an anomaly detection model using or trained with a signature of the user identifier, the target vector to detect whether user impersonation exists. Security further includes blocking, in real time with receiving the online user prompt, access to the LLM based on detecting that user impersonation exists.
Owner:INTUIT INC

LLM-based contextual mapping for application security testing with automated test generation

PendingUS20260212025A1User inputSoftware engineering
A computer-implemented method for application security analysis includes ingesting application data including source code and configuration information, processing the data with a large language model to derive a contextual mapping between external interfaces and internal code portions, identifying security vulnerabilities based on the mapping, associating each vulnerability with at least one mapped code portion and an external interface capable of reaching that portion, automatically generating executable security tests from those associations, executing the tests to produce validation outcomes, and updating at least a portion of the contextual mapping responsive to the outcomes. In certain embodiments, the method accepts user input to refine the mapping and supports export of tests to multiple frameworks, enabling repeatable validation and remediation across evolving deployments.
Owner:WALLARM INC

Vehicle state estimation-based application security mode switching system and method

PCT designated stageWO2026106158A1Anti-theft devicesInternal/peripheral component protectionApplication securityLogic module
A vehicle state estimation-based application security mode switching system is disclosed. According to the present invention, the vehicle state estimation-based application security mode switching system comprises: a hypervisor for virtualizing and executing one or more operating systems; and a high-security OS and a low-security OS executed in the hypervisor, wherein the hypervisor comprises: a security mode switching logic module for performing control to switch a security mode of an application in a vehicle according to a change in a security state of the vehicle, and setting a priority of an application directly connected to safety to be high in a security-risk state; and a security mode setting template module for storing a predefined security mode switching rule according to a vehicle state, and providing a template for designating an application priority and function activation / deactivation in security-risk and non-risk states.
Owner:HYOLIMXE CO LTD

Generalized intermediate and lower level source code representations for static application security testing

Source code in a programming language is received. The source code is converted to a generalized intermediate level representation not specific to any programming language. The source code is converted from the generalized intermediate level representation to a generalized lower level representation adapted to a dataflow analysis portion of static application security testing (SAST). The generalized lower level representation is also not specific to any programming language.
Owner:MICRO FOCUS LLC

Automatic online calibration closed-loop control system for belt scale

PendingCN122170994AWeighing apparatus testing/calibrationWeighing apparatus for continuous material flowLoop controlControl system
The present application relates to the technical field of belt scale online calibration and industrial metering control, in particular to a kind of belt scale automatic online calibration closed loop control system, the present application is through the start before double dimension screening, data quality dynamic evaluation in round and round result convergence determination in calibration process, whole process quality quantitative score and parameter application three-grade control, constructs the intelligent closed loop control system covering calibration start, process advance, result management and parameter effect, can reduce the dependence of online calibration on artificial experience, improve the self-adaptability of calibration process, result reliability and parameter application security, suitable for the automatic closed loop control of belt scale online calibration under complex working conditions.
Owner:WESTON INTELLIGENT TECH XUZHOU CO LTD

Source code security analysis and vulnerability verification system based on ai automatic detection engine

This invention discloses a source code security analysis and vulnerability verification system based on an AI-powered automated detection engine, relating to the field of application security. The system includes a candidate vulnerability extraction module, a decompilation and path extraction module, an AI-powered judgment module, a sensitive data de-identification module, an interface reasoning module, a verification request construction module, an active detection module, and a multi-dimensional judgment module. These modules work collaboratively, relying on the AI-powered automated detection engine to construct a fully automated closed loop. The AI-powered judgment module uses a large language model with code understanding, semantic reasoning, and text generation capabilities as its core reasoning unit, deeply participating in the entire process of source code security analysis and vulnerability verification. Combined with functions such as JAR decompilation, path extraction, sensitive data de-identification, and multi-dimensional evidence constraints, it achieves automated verification from candidate risks to real vulnerabilities. This system solves the problems of high false positives, reliance on manual labor, and low automation in traditional code auditing. It possesses advantages such as high accuracy, high automation, wide applicability, and data security compliance, upgrading traditional code detection into a highly reliable and automated source code security analysis and vulnerability verification system, meeting the current technical needs of the source code security detection field. This invention also discloses the method and computer configuration applied to this system.
Owner:汤冬江

Artificial intelligence-based password application risk intelligent assessment method and system

PendingCN122372186ARisk levelPassword
This invention discloses an intelligent assessment method and system for cryptographic application risks based on artificial intelligence, belonging to the field of cryptographic application security assessment technology. This invention divides cryptographic application risk assessment data into multiple dimensions, preprocesses the data, and constructs a four-level label; it uses a two-dimensional scoring method to screen key nodes, extracts related edges, and connects paths to construct a knowledge graph; it sets differentiated collection frequencies according to the importance level of key nodes, identifies anomalies and issues warnings through normal operation threshold ranges; it sets quantitative indicators for node importance and initial risk value calculation indicators, and calculates dynamic risk values ​​by combining the transmission strength of related edges and the path transmission attenuation factor; it divides four risk levels and constructs a mapping rule table, generating an assessment report containing risk level, calculation process, and transmission path, thus achieving intelligent, accurate assessment and dynamic control of cryptographic application risks.
Owner:ZHIXUN CIPHER (SHANGHAI) TESTING TECH CO LTD

Application security management system integrated with application status and sensor data use patterns

PendingUS20260147934A1Digital data protectionSafety management systemsApplication procedure
Systems, methods, and computer-readable media are provided for controlling an application's access to sensors based on application status and / or other metadata. An application security management system accesses a request by an application instance on a device for a given instance of access to an audio, image, location, sensitive data, or network access resource of the device. The request is made to an interface that controls access to the audio, image, location, sensitive data, or network access resource based on stored rules. Metadata associated with the request indicates which state of candidate states the application instance is in at a time of the request and / or past states of the application instance prior to the request. Based at least in part on the given application state or states or a pattern thereof, and at least one of the stored rules, the application security management system determines whether to grant the given instance of access. The application security management system may also log the request and the metadata to a resource access log.
Owner:ORACLE INT CORP

Method and system for application security

Methods and systems for application security. The methods and systems of the invention improve application security and can be used to protect host applications and operating systems from malicious fast applications. A request to access a resource of a computing device is received from an application adapter of a fast application operating within a host application on the computing device. In response to determining that the request is associated with a resource included in a permission list of the fast application, an operating system converts a unique user identifier (UID) of the application adapter to a UID of the host application, the operating system determines whether to allow the request based on the UID of the host application. Otherwise, the operating system determines whether to allow the request based on the UID of the application adapter.
Owner:HUAWEI TECH CO LTD

Method, device, server, medium and product for security detection of cloud-native application

The application discloses a kind of cloud native application security detection method, device, server, medium and product, involve cloud security technical field.The method comprises: in the case where it is determined that cloud native application exists security detection demand, the application operation log of cloud native application is determined, and cloud configuration component accessed by cloud native application;Based on security scanning rule, the application operation log of cloud native application and cloud configuration component are scanned, and the security scanning result of cloud native application is obtained;In the case where security scanning result indicates that there is security risk item, determine the cloud service data threatened by security risk item, cloud native application can call cloud service data in running process;Determine the security repair scheme related to cloud service data, to make based on security repair scheme repair security risk item.Can realize the security risk review process of automation.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

Automatically detecting multi-layer toxic combinations of application security risks in cloud environments

In an embodiment, one or more non-transitory computer-readable media storing sequences of instructions which, when executed using processors, cause the processors to execute, using a runtime security engine deployed within a computing environment: obtaining telemetry data comprising security-related data from microservices executing in the computing environment; accessing risk categories codifying insecure behavior across multiple layers in the computing environment; accessing toxic combination patterns across the layers, the toxic combination patterns being generated based on the risk categories, and each of the toxic combination pattern indicating a high-severity security impact in case of an attack in the computing environment; evaluating the telemetry data against the risk categories and toxic combination patterns, the evaluating producing a customized set of toxic combination patterns specific to the application within the computing environment; and displaying the customized set of toxic combination patterns in real time in a graphical user interface of a computer display device.
Owner:OPERANT AI INC

A large model-based internet of things system password application security evaluation method

PendingCN122316730AShardPassword
This invention relates to the field of cryptographic application evaluation technology, and discloses a method for cryptographic application security evaluation of Internet of Things (IoT) systems based on a large model. The method includes: acquiring target asset information to construct asset identifiers and determining evaluation boundaries based on network topology; collecting heterogeneous evidence within the evaluation boundaries and generating an evidence index by calculating hashes based on the heterogeneous evidence; integrating the cryptographic compliance standards corresponding to the asset identifiers into a control item library, the control item library including compliance entries, and converting the compliance entries into compliance semantic feature vectors; and converting the heterogeneous evidence into evidence semantic feature vectors. This invention employs a heterogeneous evidence hash encapsulation and evidence index intrinsic association technology to achieve full auditability of the evaluation process, enabling one-click traceability from the evaluation conclusion to the original physical evidence, and addressing the shortcomings of existing technologies such as evidence fragmentation, lack of verifiability, and broken evidence chains.
Owner:北京合泰信安信息技术有限公司

Invalidate web sessions present in support uploaded HAR file

PendingUS20260170103A1Digital data authenticationSupporting systemApplication security
Method and apparatus for improve support system service application security. HAR files sent to support system service applications can contain personal or private information. Such personal or private information may be contained in authenticated tokens within the HAR file. The authenticated tokens may still be authenticated when the HAR file reaches the support system service application. Embodiments herein relate to scanning the HAR file, detecting the authenticated tokens within the HAR file, and instructing an action to occur to invalidate the tokens.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

An agent dynamic arrangement and adaptive authorization boundary control method and system

The application belongs to the technical field of large model application security, and provides an agent dynamic arrangement and adaptive authorization boundary control method and system. Theoretical maximum security level before task execution is pre-calculated in a multi-node or complex node cooperation process task chain, and the sensitivity of node output content is re-judged at runtime. When the security level jumps, the environment is upgraded, the output is desensitized, and the task chain is reconstructed. The problem of how to construct a dynamic and uncertain execution process in a large language model that can perform pre-execution security evaluation on the initial task chain, identify implicit reasoning leaks at runtime, dynamically adjust the authorization boundary, ensure the trusted transmission of security level labels, and support low-privilege replacement and breakpoint resume in abnormal situations is solved.
Owner:TIANJIN THINKING CHAIN ARTIFICIAL INTELLIGENCE CO LTD

Automated security analysis of software libraries

A method for identifying security vulnerabilities in a third party software component includes generating a test application for the third party software component. The test application is generated such that every externally accessible data path in the third party component is called. The test application and the third party software component are analyzed using a static application security testing (SAST) code analyzer. One or more test results are obtained from the SAST code analyzer. The one or more test results are used to identify security vulnerabilities in the third party component.
Owner:WELLS FARGO BANK NA

An application security requirement analysis recommendation method based on a knowledge graph

The application discloses a kind of based on knowledge graph's application security requirement analysis recommendation method, this method is by establishing knowledge graph library, and to security requirement knowledge graph search, and security requirement analysis result recommendation, can find the security scene of application adaptation from application function, operation and running environment, and output the multiple security requirements associated with application security scene.It realizes that knowledge graph reasoning operation is carried out by legal regulations knowledge and application security knowledge, can greatly improve the speed of application security requirement analysis, reduces the knowledge dependence of security requirement analysis personnel.
Owner:CHINA TOBACCO SICHUAN IND CO LTD