Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

231 results about "Application security" patented technology

Application security encompasses measures taken to improve the security of an application often by finding, fixing and preventing security vulnerabilities. Different techniques are used to surface such security vulnerabilities at different stages of an applications lifecycle such as design, development, deployment, upgrade, maintenance.

Systems and methods for resolving code vulnerabilities through collaborative agents

Systems and methods for resolving code vulnerabilities through collaborative agents which may include accessing a code base of an identified vulnerability; configuring a plurality of autonomous agents, each comprising a predefined agent role associated with application security remediation process; executing a directed workflow of the plurality of agents, wherein the workflow is a conditional sequence of agent-driven processing steps for generating a proposed resolution to the identified vulnerability; and outputting a candidate resolution for the vulnerability based on results produced by the workflow.
Owner:HARNESS INC

Automatated application vulnerability triage management

A method and system for classifying a triage-related message related to a software application security technical problem is provided. A triage-related classification is generated for the triage-related message by applying a processor-implemented machine learning model that has been trained to analyze the text of the triage-related message. The generated triage-related classification is sent to a user for remediating the software application security technical problem.
Owner:SALESFORCE INC

Mobile application security access method based on randomness

The invention provides a mobile application security access method based on randomness, and relates to the field of mobile application security, and the method comprises the steps: firstly, sending request information to a server through a client, and then carrying out the risk assessment of the request information through the server by using a deep learning algorithm, including the extraction of a user identity, an operation type and context information; and in combination with real-time security threat intelligence, dynamic response coding characteristics are generated by utilizing structured and semantic coding technologies, and the risk level of the request is calculated, so that the challenge complexity is dynamically adjusted, and random challenges are generated and sent to the client. And after the client responds, the server verifies the correctness so as to decide whether to continue service processing or deny access. Thus, risks can be quantified within milliseconds, the delay and stiffness problems of a traditional static strategy are solved, and efficient safety protection and good user experience balance are achieved.
Owner:STATE GRID HENAN INFORMATION & TELECOMM CO

APP data trusted storage and sharing method based on block chain

The invention relates to the field of block chain technology and application security, and discloses a block chain-based APP data trusted storage and sharing method, which comprises the following steps of: maintaining a verifiable state container comprising state data and an access policy dual-Merkel tree under a chain, and recording a root hash of the verifiable state container in the block chain; for different updates, generating corresponding evidences: generating single-step evidences containing Merkel evidences for single-step updates; and generating the composite proof containing the zero-knowledge proof for the complex process. And the intelligent contract can update the root hash in an atomized manner only through verification and certification. During data sharing, data and dual Merkel proof are provided for a consumer to verify data authenticity and access legality. According to the method, complex calculation is arranged under a chain, low cost and constant overhead of on-chain verification are achieved, and meanwhile high-safety data credible storage and refined authority control capacity are provided through a dual-tree dual-certificate mechanism.
Owner:CHENGDU YIDOU TECHNOLOGY CO LTD

Multimodal large language model (LLM)-based threat modeling

Disclosed are various approaches for multimodal large language model (LLM) based threat modeling. The multimodal LLM based threat modeling can include a system or method that can input, into a threat modeling multimodal LLM, prompting data that includes audio data, image data, and LLM instructions to generate application security data. The threat modeling multimodal LLM can generate and provide application security data that includes at least one of: threat data, weakness data, security control data, a security risk summarization, an application threat model, or any combination thereof.
Owner:AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC

Security protection method for power mobile application based on swan-gap microkernel

The invention relates to an electric power mobile application security protection method based on a swan gap microkernel, which comprises the following steps of: S1, establishing a hardware trust root, and storing a device root key and a certificate chain by utilizing a non-tampering storage area built in a chip; s2, establishing a complete trusted boot chain based on a hardware root of trust, and verifying the integrity and credibility of the next layer by each layer from Bootloader to a swan microkernel and then to an application program; s3, constructing a triple authentication system based on user identity, equipment identity and biological characteristics, and performing user authentication; s4, according to a user authentication result, realizing fine-grained authority control based on an RBAC model and ABAC, and ensuring that authority check can be executed during resource access every time by utilizing an IPC security mechanism of a swan micro kernel; and S5, creating an independent execution environment for each power application according to the process isolation capability of the swan microkernel, and ensuring that memories among the applications cannot be mutually accessed through virtual address space isolation. The reliability of power mobile application safety protection is effectively improved.
Owner:STATE GRID INFORMATION & TELECOMM GRP CO LTD +1

System and method to securely distribute authenticated and trusted data streams to ai systems

PCT designated stage expiredWO2025159775A2Securing communicationData streamConfidentiality
The method provides for securely harvesting and distributing trusted metadata from devices to artificial intelligence (Al) systems. It enables use of cryptographic hashes and signatures on data for supply chain provenance. It is an agentless method to enhance application security by design, and data protection with data authenticity and confidentiality in device to upstream services communications and data sharing. It helps securely harvest, filter, and forward device metadata to webhooks for AI / ML driven data analytics.
Owner:SYMMERA INC

Commercial password application security assessment evidence identification method based on image identification

The invention discloses a commercial password application security assessment evidence identification method based on image identification, relates to the technical field of image identification, and aims to assess employee advanced engineer certificates, extract information from multi-modal documents by using a Qwen-VL visual language model, generate vectors, label the vectors, convert the vectors into structured evidence nodes and store the structured evidence nodes in a graph database. Establishing various edges according to different associations, and constructing a preliminary evidence network; identifying certificate nodes, and clustering to form a certificate entity group; a correlation score is calculated by searching the support evidence through forward traceability, a correlation score is calculated by searching the contradiction evidence through reverse traceability, the credibility of the certificate entity group is dynamically adjusted, and the influence is propagated according to the updated credibility; and screening abnormal certificates lower than a threshold value, analyzing causes and contradictory points, listing abnormal information, visually displaying key evidences, the contradictory points and associated paths, and generating text description.
Owner:ZHIXUN CIPHER (SHANGHAI) TESTING TECH CO LTD

Mobile application security assessment and automatic detection method

The invention relates to the field of application security detection, and provides a mobile application security assessment and automatic detection method, which adopts a data processing technology based on artificial intelligence to carry out syntactic analysis and semantic understanding on an obtained code of a mobile application program so as to obtain a code semantic structured coding feature. Meanwhile, semantic embedding coding is carried out on a set of security vulnerability rules extracted from the security vulnerability rule base to obtain a set of security vulnerability rule semantic embedding coding features; then, a detection result is automatically obtained based on dynamic query analysis representation of a set of code semantic structured coding features and security vulnerability rule semantic embedded coding features, and a security alarm prompt is generated in response to the detection result under the condition that the confidence coefficient of security vulnerabilities in the mobile application program exceeds a preset threshold value. In this way, the accuracy and reliability of the security vulnerability detection result can be effectively improved.
Owner:STATE GRID HENAN INFORMATION & TELECOMM CO

Cloud native application security protection and monitoring method and system oriented to financial science and technology

The invention provides a cloud native application security protection and monitoring method and system for financial science and technology, and relates to the technical field of financial science and technology network security, and the method comprises the steps: obtaining multi-dimensional monitoring data, building a security threat knowledge graph, recognizing a high-risk attack path through a graph convolution network, generating a potential threat prediction result, and recognizing an abnormal behavior. And configuring a dynamic honeypot environment, recording behavior tracks of attackers, analyzing attack intentions and technical characteristics, and generating and deploying protection rules in real time. According to the invention, the safety protection capability of the financial cloud environment is improved, and intelligent threat prediction and active defense are realized.
Owner:JIANGSU YAOER LINGJIU TECHNOLOGY SERVICE CO LTD

System and method to securely distribute authenticated and trusted data streams to AI systems

The method provides for securely harvesting and distributing trusted metadata from devices to artificial intelligence (AI) systems. It enables use of cryptographic hashes and signatures on data for supply chain provenance. It is an agentless method to enhance application security by design, and data protection with data authenticity and confidentiality in device to upstream services communications and data sharing. It helps securely harvest, filter, and forward device metadata to webhooks for AI / ML driven data analytics.
Owner:SYMMERA INC

A security management system and method applied to a smart education platform

The application provides a security management system and method applied to a smart education platform, wherein the system comprises: a platform application security management module, which is used for performing security management on a data application layer of the smart education platform; a data security management module, which is used for performing security management on a data storage layer of the smart education platform; and a big data component security management module, which is used for performing security management on a big data basic component layer of the smart education platform. The security management system applied to the smart education platform of the application performs security management on the data application layer, the data storage layer and the big data basic component layer of the smart education platform through the platform application security management module, the data security management module and the big data component security management module, so that the security of the big data platform is ensured.
Owner:CLP YINGSHUO (SHENZHEN) SMART INTERNET CO LTD

Prison break attack method, device and equipment for testing model defense mechanism

The invention provides a prison break attack method, device and equipment for testing a model defense mechanism, and relates to the field of artificial intelligence application security. A jailbreak attack method for testing a model defense mechanism comprises the following steps: setting a plurality of behavior templates and a jailbreak attack suffix to generate a prompt statement for inputting a model; based on the prompt statement, performing optimization and token updating on the prison break attack suffix; inputting a prompt statement containing the prison break attack suffix subjected to optimization and token updating into a preset model, and performing iterative updating on the prison break attack suffix according to the output content of the model; and determining a stable jailbreak attack suffix in the iteratively updated jailbreak attack suffixes. According to the embodiment of the invention, the stable and effective jailbreak attack suffixes can be selected, and the attack performance and efficiency of the model are improved.
Owner:启元实验室

Training data generation method and system based on static application security detection

The invention relates to the technical field of static application security detection, and discloses a training data generation method and system based on static application security detection, and the method comprises the steps: analyzing a source code of a target application program, obtaining a key condition variable and a use position, and introducing condition logic on the basis, an unsecure execution path is created that is triggered under a particular runtime condition. And then, according to the conditional logic, generating environment simulation information during operation, verifying the source code sample into which the conditional logic is introduced, determining whether a defect exists in combination with the environment simulation information, and finally generating a defect label. The method effectively solves the problem that an existing SAST tool is difficult to effectively capture the hidden security defect triggered under the specific runtime condition when facing a modern complex software system, especially a micro-service or distributed architecture application.
Owner:SHENZHEN HAIYUNAN NETWORK SECURITY TECH CO LTD

Multi-agent driven safety alarm log simulation generation method

The invention discloses a multi-agent-driven security alarm log simulation generation method, and relates to the technical field of network security, and the method comprises the following steps: S1, obtaining a sample log; s2, on the basis of the sample log, obtaining and defining an overall feature as Ft, a session feature as Fs, a field feature as Fc, an overall rule as Rt, a session rule as Rs and a field rule as Rc; s3, Ft, Fs, Fc, Rt, Rs and Rc are input into the large language model, logs are generated, and the generated logs are classified into overall logs, session logs and field logs; s4-S6, performing outer-layer circulation, middle-layer circulation and inner-layer circulation on the basis of the generated overall log, session log and field log, so as to obtain a final simulation security alarm log set; and S7, performing quality evaluation on the generated simulation security alarm log. According to the method, the security simulation logs meeting the requirements are generated through various agents, and the method is very valuable in scenes such as security testing, security simulation and application security testing.
Owner:BANK OF SHANGHAI

Mobile application security detection method and system based on multi-dimensional features and network behavior fingerprints

The invention provides a mobile application security detection method and system based on multi-dimensional features and network behavior fingerprints, and relates to the technical field of network security, the method comprises the following steps: running a mobile application in a controlled environment, capturing network traffic data generated in the running process of the mobile application, extracting dynamic behavior characteristics including communication frequency, communication type and communication content from the network flow data, constructing a network behavior fingerprint based on the dynamic behavior characteristics, and performing normalization processing on the dynamic behavior characteristics to obtain normalized dynamic behavior characteristics; and in combination with a risk classification threshold and the normalized dynamic behavior characteristics, correcting a scoring result to obtain a final security score. According to the method, the static code layer features and the dynamic flow layer features are comprehensively analyzed, the mobile application type is judged, and efficient traceability is achieved.
Owner:HARBIN INST OF TECH AT WEIHAI +1

Software vulnerability detection method and system based on expert knowledge optimization

The invention belongs to the field of application security, and particularly discloses a software vulnerability detection method and system based on expert knowledge optimization. The method comprises the following steps: preprocessing a program source code text of software to be tested, and determining each suspected vulnerability code statement in the program source code text; performing slice extraction on each suspected vulnerability code statement by utilizing vulnerability code feature semantic information to obtain a code text slice corresponding to each suspected vulnerability code statement; the vulnerability code feature semantic information is obtained according to expert knowledge analysis; and inputting each code text slice and a first preset prompt word into a vulnerability detection model to obtain vulnerability detection report information of the to-be-detected software output by the vulnerability detection model. By means of the software vulnerability detection method and device, the software vulnerability detection efficiency can be improved, and meanwhile the software vulnerability detection precision and the detection effect are effectively improved.
Owner:HUAZHONG UNIV OF SCI & TECH +1

Code cleanup tool in business applications

Security can be improved in business application, such as an enterprise resource planning (“ERP”) system, by detecting and automatically cleaning or fixing custom code of systems / applications. In one embodiment, a Cleanup Tool enables the removal of programming errors using automation that can minimize security risks for a business application. The Cleanup Tool may include an automated correction engine that automates code correction. An Access Analyzer analyzes access through various systems / applications within the business application.
Owner:ONAPSIS INC

POS application security signature system and method based on cloud service

The invention provides a POS application security signature system and method based on cloud service. The system architecture is clearly divided into a front-end service area and a high-security trusted area. The front-end service area is deployed in a special network management area which is logically isolated from the Internet and comprises a Web management background and a Web management background database; the high-security trusted area is a trusted environment, and an application signature server, an application signature server database and a hardware security module are deployed in the high-security trusted area. An application developer accesses the system through a controlled client environment. According to the method, responsibility separation of a submitter, a security officer and a key administrator is realized through role-based access control, hierarchical strong identity authentication is adopted, and a rigorous process is followed; a submitter verifies the hash of a file and then creates a task, the task data is synchronized to a high-security credible area after two security officers approve the task independently in sequence, and two key administrators execute dual control to start an HSM key to complete signature. The whole process operation is recorded in an auditing log which cannot be tampered. According to the invention, automation, high security and compliance of the cloud signature process are realized.
Owner:FUJIAN MOREFUN ELECTRONICS TECH CO LTD

Automated login framework for interacting with dynamically generated login forms

ActiveUS12719858B2Web applicationWeb browser
An automated login framework for dynamic application security testing is disclosed. A web application executing on a computing device is accessed and an automated login framework (ALF) is injected into an onload event of a web browser associated with the web application. The ALF is then accessed with a credential associated with the web application. A login page associated with application is identified by matching links or buttons with a user-defined regular expression and a user-defined wordlist. Then, a login form in the login page is detected by executing a signature technique, a dictionary technique, and a multistep signature technique. The login form is populated using the credential and submitted for authentication, and a status with a confidence score is received indicating whether the authentication was successful or failed.
Owner:RAPID7 INC

Application security test method and device and electronic equipment

The invention discloses an application security test method and device and electronic equipment, and relates to the field of artificial intelligence or other related technical fields, and the method comprises the steps: carrying out the feature extraction of application data of a target application, and obtaining L application features of the target application; determining a demand tag of the target application based on the L application features; determining N test cases corresponding to the target application based on the demand tag of the target application; and performing security testing on the target application based on the N test cases. According to the method and the device, the technical problem of low test efficiency caused by the fact that a tester needs to gradually perform security test case design for different iteration versions of the application in the prior art is solved.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Systems and methods for automated website security testing

Systems and methods are provided for automated website security testing. The systems and methods reduce or eliminate the need for a user to manually click through a web application to perform application security testing by embedding one or more API calls to the application security testing service within an already-existing automated user interface test. When a web page is reached during the user interface that that is desired to be tested using the application security test, a cookie associated with the web page is obtained and provided to the API associated with the application security test. The application security test then returns a result and the user interface test continues. Any number of additional API calls for to the application security test service may be performed for any other number of web pages as the user interface test progresses through the web pages as well.
Owner:AMAZON TECH INC

Large model application security management and control platform

The application discloses a large model application security management and control platform, and relates to the field of large model security application management and control.The platform comprises an MCP protection module, an RAG protection module, an API interface protection module, a secure link module, a gateway application protection module, a data set protection module, a security test evaluation module, a security audit module and a security monitoring and early warning module.The MCP protection module is used for providing security protection when MCP external tools are dispatched.The RAG protection module is used for providing security protection when RAG external data is retrieved.The API interface protection module is used for providing security protection when API interfaces are called.The secure link module is used for providing security protection when data is transmitted.The gateway application protection module is used for providing security protection when a dialogue question and answer is performed.The data set protection module is used for providing data security detection when fine tuning is performed.The security test evaluation module is used for evaluating the large model.The security audit module is used for performing whole-process log auditing on each module.The security monitoring and early warning module is used for performing real-time monitoring on each module, and an early warning is sent when an anomaly is found.The application can provide security protection functions in the large model application process.
Owner:NAT IND INFORMATION SECURITY DEV RES CENT

Enterprise internal application full-life-cycle management system based on micro-service architecture

The invention relates to the technical field of enterprise service collection, in particular to an enterprise internal application full-life-cycle management system based on a micro-service architecture, and the system comprises an application development test module which is used for carrying out the unit test and integration test of a test case through a containerized test environment; the application on-shelf auditing module is used for extracting metadata information in the application deployment package through a standardized configuration analyzer and outputting a compliance application package after passing an approval process; the application operation monitoring module is used for collecting an operation state data set of the compliance application package in real time through a resource probe; the application safety off-shelf module is used for executing off-shelf operation on the compliance application package with the risk assessment result meeting the preset off-shelf condition; and the full life cycle tracking module is used for performing tracking analysis on each module and outputting a visual topological relation graph. According to the method and the system, the whole process from development to off-shelf of the application can be managed and controlled, and the application quality, safety and management efficiency are remarkably improved.
Owner:GUIZHOU EXPRESSWAY GRP

A security test method, device, equipment, medium and product are applied

The application provides an application security testing method and device, equipment, medium and product, which can be applied to the fields of artificial intelligence technology and financial technology. The method comprises the following steps: determining test information of a to-be-detected application in an operation test process; the test information comprises to-be-detected information called by the to-be-detected application in the operation test process of the to-be-detected application; determining a corresponding compliance baseline of the to-be-detected application based on a pre-trained baseline generation model; the compliance baseline comprises a compliance information call baseline; the compliance information call baseline is used for representing information allowed to be called by the to-be-detected application; determining a baseline deviation between the test information and the determined compliance baseline, and determining a security detection result of the to-be-detected application according to the baseline deviation; the baseline deviation comprises an information deviation between the to-be-detected information and the compliance information call baseline.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Component security vulnerability processing method and device, equipment and storage medium

The application provides a component security vulnerability processing method and device, equipment and a storage medium. It relates to the technical field of application security. The method comprises the following steps: based on a full amount warehouse of component risk knowledge, marking the known risk enterprise-level components existing in the enterprise, the version range of the enterprise-level components, and the related applications having a dependency relationship with the enterprise-level components in the pre-constructed component panoramic view, the component panoramic view recording all components in the enterprise and the applications having a dependency relationship with each component; determining the risk level of the enterprise-level components based on the use of the enterprise-level components in each related application; determining the risk processing strategy for the enterprise-level components based on the risk level; and processing the enterprise-level components published in the enterprise component warehouse based on the risk processing strategy. The method of the application solves the problem of poor rectification effect when rectifying the enterprise-level components having security vulnerabilities.
Owner:CCB FINTECH CO LTD

Execution code provision method and software development system

A solution that can ensure the security of an application program is provided. An execution code provision method includes: a step of generating a source code according to a user operation; a step of generating an intermediate representation from the source code; a step of verifying whether or not the intermediate representation satisfies a predetermined rule or regulation; and a step of realizing execution of an execution code generated from the intermediate representation when the intermediate representation satisfies the predetermined rule or regulation.
Owner:CONNECTFREE CORP

Power communication network fault handling method based on security analysis

The invention discloses an electric power communication network fault handling method based on security analysis, and relates to the technical field of electric power, and the method comprises the steps: obtaining fault data of an electric power communication network, and carrying out the data analysis of the fault data, and obtaining a fault reason; based on the fault reason, extracting an emergency scheme corresponding to the fault reason, and performing simulation implementation on the emergency scheme to obtain application defect data of the emergency scheme; performing security analysis on the application defect data to obtain an application security risk of the emergency scheme, and performing utilization rate analysis on the application defect data to obtain resource utilization flexibility of the emergency scheme; based on the safety risk, obtaining a risk emphasis of the safety risk, and performing risk adjustment on the emergency scheme according to the risk emphasis; and based on the resource utilization flexibility, waste redundant resources in the emergency scheme are obtained, and resource disposal is carried out according to the redundant resources. The method has the effect of improving the safety and flexibility of the emergency scheme of the power communication network in the actual use process.
Owner:MERL (TIANJIN) ELECTRIC EQUIP CO LTD +2