Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

171 results about "Application security" patented technology

Application security encompasses measures taken to improve the security of an application often by finding, fixing and preventing security vulnerabilities. Different techniques are used to surface such security vulnerabilities at different stages of an applications lifecycle such as design, development, deployment, upgrade, maintenance.

Systems and methods for resolving code vulnerabilities through collaborative agents

Systems and methods for resolving code vulnerabilities through collaborative agents which may include accessing a code base of an identified vulnerability; configuring a plurality of autonomous agents, each comprising a predefined agent role associated with application security remediation process; executing a directed workflow of the plurality of agents, wherein the workflow is a conditional sequence of agent-driven processing steps for generating a proposed resolution to the identified vulnerability; and outputting a candidate resolution for the vulnerability based on results produced by the workflow.
Owner:HARNESS INC

APP data trusted storage and sharing method based on block chain

The invention relates to the field of block chain technology and application security, and discloses a block chain-based APP data trusted storage and sharing method, which comprises the following steps of: maintaining a verifiable state container comprising state data and an access policy dual-Merkel tree under a chain, and recording a root hash of the verifiable state container in the block chain; for different updates, generating corresponding evidences: generating single-step evidences containing Merkel evidences for single-step updates; and generating the composite proof containing the zero-knowledge proof for the complex process. And the intelligent contract can update the root hash in an atomized manner only through verification and certification. During data sharing, data and dual Merkel proof are provided for a consumer to verify data authenticity and access legality. According to the method, complex calculation is arranged under a chain, low cost and constant overhead of on-chain verification are achieved, and meanwhile high-safety data credible storage and refined authority control capacity are provided through a dual-tree dual-certificate mechanism.
Owner:CHENGDU YIDOU TECHNOLOGY CO LTD

Security protection method for power mobile application based on swan-gap microkernel

The invention relates to an electric power mobile application security protection method based on a swan gap microkernel, which comprises the following steps of: S1, establishing a hardware trust root, and storing a device root key and a certificate chain by utilizing a non-tampering storage area built in a chip; s2, establishing a complete trusted boot chain based on a hardware root of trust, and verifying the integrity and credibility of the next layer by each layer from Bootloader to a swan microkernel and then to an application program; s3, constructing a triple authentication system based on user identity, equipment identity and biological characteristics, and performing user authentication; s4, according to a user authentication result, realizing fine-grained authority control based on an RBAC model and ABAC, and ensuring that authority check can be executed during resource access every time by utilizing an IPC security mechanism of a swan micro kernel; and S5, creating an independent execution environment for each power application according to the process isolation capability of the swan microkernel, and ensuring that memories among the applications cannot be mutually accessed through virtual address space isolation. The reliability of power mobile application safety protection is effectively improved.
Owner:STATE GRID INFORMATION & TELECOMM GRP CO LTD +1

Cloud native application security protection and monitoring method and system oriented to financial science and technology

The invention provides a cloud native application security protection and monitoring method and system for financial science and technology, and relates to the technical field of financial science and technology network security, and the method comprises the steps: obtaining multi-dimensional monitoring data, building a security threat knowledge graph, recognizing a high-risk attack path through a graph convolution network, generating a potential threat prediction result, and recognizing an abnormal behavior. And configuring a dynamic honeypot environment, recording behavior tracks of attackers, analyzing attack intentions and technical characteristics, and generating and deploying protection rules in real time. According to the invention, the safety protection capability of the financial cloud environment is improved, and intelligent threat prediction and active defense are realized.
Owner:JIANGSU YAOER LINGJIU TECHNOLOGY SERVICE CO LTD

System and method to securely distribute authenticated and trusted data streams to AI systems

The method provides for securely harvesting and distributing trusted metadata from devices to artificial intelligence (AI) systems. It enables use of cryptographic hashes and signatures on data for supply chain provenance. It is an agentless method to enhance application security by design, and data protection with data authenticity and confidentiality in device to upstream services communications and data sharing. It helps securely harvest, filter, and forward device metadata to webhooks for AI / ML driven data analytics.
Owner:SYMMERA INC

A security management system and method applied to a smart education platform

The application provides a security management system and method applied to a smart education platform, wherein the system comprises: a platform application security management module, which is used for performing security management on a data application layer of the smart education platform; a data security management module, which is used for performing security management on a data storage layer of the smart education platform; and a big data component security management module, which is used for performing security management on a big data basic component layer of the smart education platform. The security management system applied to the smart education platform of the application performs security management on the data application layer, the data storage layer and the big data basic component layer of the smart education platform through the platform application security management module, the data security management module and the big data component security management module, so that the security of the big data platform is ensured.
Owner:CLP YINGSHUO (SHENZHEN) SMART INTERNET CO LTD

Training data generation method and system based on static application security detection

The invention relates to the technical field of static application security detection, and discloses a training data generation method and system based on static application security detection, and the method comprises the steps: analyzing a source code of a target application program, obtaining a key condition variable and a use position, and introducing condition logic on the basis, an unsecure execution path is created that is triggered under a particular runtime condition. And then, according to the conditional logic, generating environment simulation information during operation, verifying the source code sample into which the conditional logic is introduced, determining whether a defect exists in combination with the environment simulation information, and finally generating a defect label. The method effectively solves the problem that an existing SAST tool is difficult to effectively capture the hidden security defect triggered under the specific runtime condition when facing a modern complex software system, especially a micro-service or distributed architecture application.
Owner:SHENZHEN HAIYUNAN NETWORK SECURITY TECH CO LTD

Multi-agent driven safety alarm log simulation generation method

The invention discloses a multi-agent-driven security alarm log simulation generation method, and relates to the technical field of network security, and the method comprises the following steps: S1, obtaining a sample log; s2, on the basis of the sample log, obtaining and defining an overall feature as Ft, a session feature as Fs, a field feature as Fc, an overall rule as Rt, a session rule as Rs and a field rule as Rc; s3, Ft, Fs, Fc, Rt, Rs and Rc are input into the large language model, logs are generated, and the generated logs are classified into overall logs, session logs and field logs; s4-S6, performing outer-layer circulation, middle-layer circulation and inner-layer circulation on the basis of the generated overall log, session log and field log, so as to obtain a final simulation security alarm log set; and S7, performing quality evaluation on the generated simulation security alarm log. According to the method, the security simulation logs meeting the requirements are generated through various agents, and the method is very valuable in scenes such as security testing, security simulation and application security testing.
Owner:BANK OF SHANGHAI

Mobile application security detection method and system based on multi-dimensional features and network behavior fingerprints

The invention provides a mobile application security detection method and system based on multi-dimensional features and network behavior fingerprints, and relates to the technical field of network security, the method comprises the following steps: running a mobile application in a controlled environment, capturing network traffic data generated in the running process of the mobile application, extracting dynamic behavior characteristics including communication frequency, communication type and communication content from the network flow data, constructing a network behavior fingerprint based on the dynamic behavior characteristics, and performing normalization processing on the dynamic behavior characteristics to obtain normalized dynamic behavior characteristics; and in combination with a risk classification threshold and the normalized dynamic behavior characteristics, correcting a scoring result to obtain a final security score. According to the method, the static code layer features and the dynamic flow layer features are comprehensively analyzed, the mobile application type is judged, and efficient traceability is achieved.
Owner:HARBIN INST OF TECH AT WEIHAI +1

POS application security signature system and method based on cloud service

The invention provides a POS application security signature system and method based on cloud service. The system architecture is clearly divided into a front-end service area and a high-security trusted area. The front-end service area is deployed in a special network management area which is logically isolated from the Internet and comprises a Web management background and a Web management background database; the high-security trusted area is a trusted environment, and an application signature server, an application signature server database and a hardware security module are deployed in the high-security trusted area. An application developer accesses the system through a controlled client environment. According to the method, responsibility separation of a submitter, a security officer and a key administrator is realized through role-based access control, hierarchical strong identity authentication is adopted, and a rigorous process is followed; a submitter verifies the hash of a file and then creates a task, the task data is synchronized to a high-security credible area after two security officers approve the task independently in sequence, and two key administrators execute dual control to start an HSM key to complete signature. The whole process operation is recorded in an auditing log which cannot be tampered. According to the invention, automation, high security and compliance of the cloud signature process are realized.
Owner:FUJIAN MOREFUN ELECTRONICS TECH CO LTD

Automated login framework for interacting with dynamically generated login forms

ActiveUS12719858B2Web applicationWeb browser
An automated login framework for dynamic application security testing is disclosed. A web application executing on a computing device is accessed and an automated login framework (ALF) is injected into an onload event of a web browser associated with the web application. The ALF is then accessed with a credential associated with the web application. A login page associated with application is identified by matching links or buttons with a user-defined regular expression and a user-defined wordlist. Then, a login form in the login page is detected by executing a signature technique, a dictionary technique, and a multistep signature technique. The login form is populated using the credential and submitted for authentication, and a status with a confidence score is received indicating whether the authentication was successful or failed.
Owner:RAPID7 INC

Application security test method and device and electronic equipment

The invention discloses an application security test method and device and electronic equipment, and relates to the field of artificial intelligence or other related technical fields, and the method comprises the steps: carrying out the feature extraction of application data of a target application, and obtaining L application features of the target application; determining a demand tag of the target application based on the L application features; determining N test cases corresponding to the target application based on the demand tag of the target application; and performing security testing on the target application based on the N test cases. According to the method and the device, the technical problem of low test efficiency caused by the fact that a tester needs to gradually perform security test case design for different iteration versions of the application in the prior art is solved.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Systems and methods for automated website security testing

Systems and methods are provided for automated website security testing. The systems and methods reduce or eliminate the need for a user to manually click through a web application to perform application security testing by embedding one or more API calls to the application security testing service within an already-existing automated user interface test. When a web page is reached during the user interface that that is desired to be tested using the application security test, a cookie associated with the web page is obtained and provided to the API associated with the application security test. The application security test then returns a result and the user interface test continues. Any number of additional API calls for to the application security test service may be performed for any other number of web pages as the user interface test progresses through the web pages as well.
Owner:AMAZON TECH INC

Large model application security management and control platform

The application discloses a large model application security management and control platform, and relates to the field of large model security application management and control.The platform comprises an MCP protection module, an RAG protection module, an API interface protection module, a secure link module, a gateway application protection module, a data set protection module, a security test evaluation module, a security audit module and a security monitoring and early warning module.The MCP protection module is used for providing security protection when MCP external tools are dispatched.The RAG protection module is used for providing security protection when RAG external data is retrieved.The API interface protection module is used for providing security protection when API interfaces are called.The secure link module is used for providing security protection when data is transmitted.The gateway application protection module is used for providing security protection when a dialogue question and answer is performed.The data set protection module is used for providing data security detection when fine tuning is performed.The security test evaluation module is used for evaluating the large model.The security audit module is used for performing whole-process log auditing on each module.The security monitoring and early warning module is used for performing real-time monitoring on each module, and an early warning is sent when an anomaly is found.The application can provide security protection functions in the large model application process.
Owner:NAT IND INFORMATION SECURITY DEV RES CENT

Enterprise internal application full-life-cycle management system based on micro-service architecture

The invention relates to the technical field of enterprise service collection, in particular to an enterprise internal application full-life-cycle management system based on a micro-service architecture, and the system comprises an application development test module which is used for carrying out the unit test and integration test of a test case through a containerized test environment; the application on-shelf auditing module is used for extracting metadata information in the application deployment package through a standardized configuration analyzer and outputting a compliance application package after passing an approval process; the application operation monitoring module is used for collecting an operation state data set of the compliance application package in real time through a resource probe; the application safety off-shelf module is used for executing off-shelf operation on the compliance application package with the risk assessment result meeting the preset off-shelf condition; and the full life cycle tracking module is used for performing tracking analysis on each module and outputting a visual topological relation graph. According to the method and the system, the whole process from development to off-shelf of the application can be managed and controlled, and the application quality, safety and management efficiency are remarkably improved.
Owner:GUIZHOU EXPRESSWAY GRP

A security test method, device, equipment, medium and product are applied

The application provides an application security testing method and device, equipment, medium and product, which can be applied to the fields of artificial intelligence technology and financial technology. The method comprises the following steps: determining test information of a to-be-detected application in an operation test process; the test information comprises to-be-detected information called by the to-be-detected application in the operation test process of the to-be-detected application; determining a corresponding compliance baseline of the to-be-detected application based on a pre-trained baseline generation model; the compliance baseline comprises a compliance information call baseline; the compliance information call baseline is used for representing information allowed to be called by the to-be-detected application; determining a baseline deviation between the test information and the determined compliance baseline, and determining a security detection result of the to-be-detected application according to the baseline deviation; the baseline deviation comprises an information deviation between the to-be-detected information and the compliance information call baseline.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Component security vulnerability processing method and device, equipment and storage medium

The application provides a component security vulnerability processing method and device, equipment and a storage medium. It relates to the technical field of application security. The method comprises the following steps: based on a full amount warehouse of component risk knowledge, marking the known risk enterprise-level components existing in the enterprise, the version range of the enterprise-level components, and the related applications having a dependency relationship with the enterprise-level components in the pre-constructed component panoramic view, the component panoramic view recording all components in the enterprise and the applications having a dependency relationship with each component; determining the risk level of the enterprise-level components based on the use of the enterprise-level components in each related application; determining the risk processing strategy for the enterprise-level components based on the risk level; and processing the enterprise-level components published in the enterprise component warehouse based on the risk processing strategy. The method of the application solves the problem of poor rectification effect when rectifying the enterprise-level components having security vulnerabilities.
Owner:CCB FINTECH CO LTD

Application security monitoring system and method based on behavior portrait data

The invention discloses an application security monitoring system and method based on behavior portrait data, and relates to the technical field of network security, and the system comprises a flow collection and preprocessing module, a behavior portrait module, a security analysis module and a strategy execution module. The flow acquisition and preprocessing module is deployed in a network access layer and comprises a network probe and a data cleaning unit, the behavior portrait module is connected with a log output end of the flow acquisition terminal, the security analysis module is connected with an output end of the behavior portrait module, and the strategy execution module is connected with an alarm output end of the security analysis module. According to the method, the function of high risk detection rate is realized by establishing the multi-dimensional static behavior model, the behavior baseline is constructed and is quantitatively compared with the real-time behavior, the abnormal behavior which cannot be recognized by a traditional rule base can be found, the false alarm rate is remarkably reduced, and the detection rate of internal threats and advanced persistent threats is improved.
Owner:GUANGDONG POWER GRID CO LTD +1

Method, apparatus, device and storage medium for application security access

The application relates to the technical field of security verification, and discloses an application security access method and device, equipment and a storage medium, the method comprising the following steps: in response to an application access request input in a browser, determining identity verification information of a user according to the application access request; obtaining a device fingerprint, wherein the device fingerprint is generated by the browser according to device information of the user; performing security check according to the identity verification information and the device fingerprint to obtain a security check result; and performing application access control according to the security check result. The application can ensure that the user can only access the application on a specified security device, and effectively improves the application access security.
Owner:BEIJING HONGTENG INTELLIGENT TECH CO LTD

Automatic malicious advertisement identification method and system based on LLM Agent

The invention provides an LLM Agent-based malicious advertisement automatic identification method and system, and the method comprises the steps: generating prompt words based on a user task instruction, a current page state and a knowledge base, inputting the LLM Agent to generate a page operation sequence, and enabling the sequence to comprise the current and potential page states and the jump logic thereof; executing a page operation sequence to simulate page jump, and screening advertisement pages through domain name features and request parameters based on HTTP traffic; sDK metadata, permission information, redirection links and advertisement images are collected for advertisement pages, structured cue words are constructed, LLM is input to conduct association analysis on the four types of data, and a diagnosis report containing malicious behavior classification, risk levels and repair suggestions is obtained. Whether a current advertisement is malicious or not is comprehensively judged through dynamic UI exploration and analysis of an advertisement SDK, permission information, a redirection link and an advertisement image, and a basis is provided for mobile application security assessment.
Owner:UNIV OF JINAN

An application software development test system with real-time vulnerability detection

The application belongs to the technical field of application software development test, and discloses an application software development test system with real-time vulnerability detection, which comprises a code real-time collection module, a multi-dimensional vulnerability detection module, a vulnerability accurate positioning module, a vulnerability risk quantitative evaluation module, a dynamic repair guidance module, a data storage module, a visual interaction module and an iterative optimization module, and each module cooperates to form a whole-process closed-loop vulnerability detection and management and control system. The application software development test system with real-time vulnerability detection is adopted, real-time capture, accurate positioning, risk evaluation and dynamic repair suggestion output of the vulnerability are realized, and the software development test efficiency and application program security are improved.
Owner:BEIJING JIAXINYUAN TECHNOLOGY CO LTD

Secure connection method, device, medium, electronic equipment and program product

An application security connection method, device, medium, electronic equipment and program product. In response to the terminal initiating a DNS request, the domain name information corresponding to the DNS request is determined; when the domain name information is a preset domain name corresponding to a target application, a preset application process is used to add a preset mark to the service request message of the target application, the preset mark is used to identify that the terminal is a preset authorized terminal corresponding to the target application, and the preset application process is an application process deployed on the preset authorized terminal; the service request message with the preset mark is sent to a target server, so that the target server establishes a connection with the target application according to the preset mark. Based on the preset application process adding the preset mark to the service request message from the target application, the traffic data of the target application containing the APP end and the web end is completely captured in the device dimension, and the target server can also control the terminal device logged in the target application by identifying the preset mark.
Owner:BEIJING ZITIAO NETWORK TECH CO LTD

Proxy-based application security access method and system

The invention aims to provide a proxy-based application security access method and system, on one hand, a proxy gateway verifies a user identity in real time and strictly executes an access control strategy; on the other hand, security proxy and flow transfer are provided, users are uniformly proxy to access different applications and services, and a real server address is hidden; meanwhile, communication security is guaranteed, and malicious traffic is intercepted in combination with security detection capability; and as a unified access point, the user access experience is simplified. Through the proxy gateway, targets of identity credibility, application hiding, access controllability and data security are realized.
Owner:XIAN JIAODA JIEPU NETWORK SCI & TECH CO LTD

Mobile application third-party SDK privacy compliance detection method and system and electronic equipment

The invention discloses a mobile application third-party SDK privacy compliance detection method and system and electronic equipment, and relates to the technical field of mobile application security. The compliance detection method mainly comprises the following steps: analyzing a mobile application installation package through static asset detection, extracting an integrated third-party SDK (Software Development Kit) list, and comparing the integrated third-party SDK list with a preset third-party SDK asset library to complete component identification; the method comprises the following steps: running an application in a sandbox environment through dynamic compliance detection, triggering an SDK behavior, carrying out SDK running state detection to find a zombie SDK which is not actually called, carrying out privacy compliance similarity detection at the same time, carrying out semantic similarity comparison on an SDK actual data collection behavior and application privacy policy text declaration content, and judging a consistency compliance risk of the SDK actual data collection behavior and the application privacy policy text declaration content. According to the method, the zombie component in the mobile application integrated third-party SDK and the compliance risk that privacy policy disclosure does not conform can be effectively found, and the detection automation degree and accuracy are improved.
Owner:国家电网有限公司客户服务中心

Cloud-native application security protection and monitoring method and system for financial technology

The application provides a cloud-native application security protection and monitoring method and system for financial technology, relates to the technical field of network security of financial technology, and comprises the following steps: acquiring multidimensional monitoring data, establishing a security threat knowledge graph, identifying a high-risk attack path through a graph convolution network, generating a potential threat prediction result, identifying abnormal behavior, configuring a dynamic honeypot environment, recording the behavior trajectory of an attacker, analyzing attack intention and technical characteristics, and generating and deploying protection rules in real time. The application improves the security protection capability of a financial cloud environment and realizes intelligent threat prediction and active defense.
Owner:JIANGSU YAOER LINGJIU TECHNOLOGY SERVICE CO LTD

Systems and Methods for Deriving Application Security Signals from Application Performance Data

In one embodiment, a method includes receiving, by a network component, application performance data. The application performance data is associated with one or more applications. The method also includes determining to transform, by the network component, the application performance data into application security data, generating, by the network component, a baseline for the application security data, and detecting, by the network component, an anomaly in the baseline. The method further includes determining, by the network component, a potential security threat based on the anomaly.
Owner:CISCO TECHNOLOGY INC

Security detection method and device of mobile application, computer equipment and storage medium

The embodiment of the invention discloses a security detection method and device of a mobile application, computer equipment and a storage medium. The method comprises the following steps: acquiring an installation package file of a target mobile application, and acquiring a decompiled file of the installation package file; performing static risk detection on the decompiled file according to a static risk analysis rule to obtain a static risk analysis result; configuring a Hook point of dynamic instrumentation for the target mobile application according to a static risk analysis result; running the target mobile application, and obtaining running behavior data of the target mobile application through the Hook point; performing dynamic risk detection on the operation behavior data according to a dynamic risk analysis rule to obtain a dynamic risk analysis result; performing feature matching on a preset malicious software feature library and the decompiled file to obtain a malicious software analysis result; and generating a security detection result of the target mobile application according to each analysis result. By implementing the method provided by the embodiment of the invention, the security detection precision of the mobile application can be improved.
Owner:SHENZHEN YEAHKA TECH

Application security lock of an electronic device's application icon dynamic lock graphical user interface

ActiveCN309754194SReference mapKey pressing
1. Name of the product in this design: Application security lock for application icons of electronic devices with dynamic locking graphical user interface. 2. Purpose of this design: An electronic device. 3. The key design feature of this product is its graphical user interface. 4. The image or photo that best illustrates the design points: Design 1 Interface Change State Diagram 3. 5. Design 1 is designated as the basic design. 6. Purpose of the graphical user interface: The overall purpose of the interface is to set a security lock for the application icon based on user operations; the local purpose of the interface is to demonstrate the process of the application being securely locked or unlocked through the dynamic changes of the application icon. 7. Human-computer interaction method of graphical user interface: In Design 1 to Design 3, the main view is the main interface displayed by the electronic device. For example, when the user long-presses an icon in the interface or presses the lock button on the electronic device in the main view, the interface automatically jumps from the main view to the interface change state diagram 1, interface change state diagram 2, interface change state diagram 3, interface change state diagram 4, and interface change state diagram 5 in sequence; the background area in the interface is used to display images, and the specific interface is shown in the reference figure. In Designs 4 to 6, the main view is the main interface displayed by the electronic device. For example, when the user long-presses an icon in the interface or presses the device's unlock button in the main view, the interface automatically jumps from the main view to interface change state diagram 1, interface change state diagram 2, interface change state diagram 3, interface change state diagram 4, and interface change state diagram 5 in sequence. The background area in the interface is used to display images, and the specific interface is shown in the reference figure. In Design 7 and Design 8, the main view is the main interface displayed by the electronic device. For example, when the user clicks an icon in the main view, the interface automatically jumps from the main view to the interface change state diagram 1 and the interface change state diagram 2. The background area in the interface is used to display images, and the specific interface is shown in the reference figure. 8. The dashed lines in the figure represent the parts that do not require protection.
Owner:HUAWEI DEVICE CO LTD

Image recognition-based commercial password application security assessment evidence identification method

The application discloses a commercial password application security evaluation evidence identification method based on image recognition and relates to the technical field of image recognition.The application aims to evaluate the employee senior engineer certificate, extracts information from a multi-modal document by using a Qwen-VL visual language model, generates a vector and labels, is converted into a structured evidence node, is stored in a graph database, a plurality of edges are established according to different correlations, a preliminary evidence network is constructed, certificate nodes are identified, a certificate entity group is formed by clustering, relevant scores are calculated by forward tracing to find supporting evidence, relevant scores are calculated by reverse tracing to find contradictory evidence, the credibility of the certificate entity group is dynamically adjusted, and the influence is propagated according to the updated credibility; abnormal certificates below a threshold value are screened, causes and contradiction points are analyzed, abnormal information is listed, key evidence, contradiction points and correlation paths are visually displayed, and a text description is generated.
Owner:ZHIXUN CIPHER (SHANGHAI) TESTING TECH CO LTD