Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

8233 results about "Attack" patented technology

In computer and computer networks an attack is any attempt to destroy, expose, alter, disable, steal or gain unauthorized access to or make unauthorized use of an asset.

Network mapping behavior anomaly detection method and system based on machine learning

A network mapping behavior anomaly detection method and system based on machine learning is provided. The method includes: collecting dual-source traffic data, generating a structured log data set through dual-source log fusion engine; performing subgraph matching calculation to obtain a mapping behavior deviation degree; generating communication data containing a watermark identifier in a session corresponding communication path; verifying whether attack events carry the watermark identifier; generating a network mapping behavior anomaly detection report. According to the disclosure, an adaptive attack behavior model is constructed through a multi-modal feature vector based on structured logs and a graph protocol mapping rule base, so that the cognitive robustness to protocol camouflage and path drift is fundamentally enhanced, a real-time verification chain of detection results is built, and traditional passive detection is transformed into self-proof active defense through cross verification of watermark carrying state and behavior trajectory.
Owner:HUANENG INFORMATION TECH CO LTD

Analyzable anti-attack network security method and system based on AI unified model

The invention provides an analyzable anti-attack network security method and system based on an AI unified model. The method comprises the following steps: S1, carrying out attack source tracing and attack mode identification on an input data stream; s2, performing protocol structure analysis and grammar element extraction on the input data stream in a grammar verification layer, and starting a grammar rule matching process to obtain a grammar exception perception set; s3, fusing attack vector information on the basis of a grammar anomaly perception set in a semantic analysis layer, constructing a semantic relation graph, and outputting a semantic risk vector; s4, taking the semantic risk vector as input, combining a business scene, resource constraint and strategy preference, modeling a defense target, and outputting an optimal response path; and S5, forming a model evolution path based on local feedback and global collaboration. Through a three-layer full-information analysis mechanism and behavior feedback driving, interpretable recognition of attack intentions and collaborative optimization of defense paths are realized, attack recognition is comprehensive, response decision is accurate, and strategy evolution is controllable.
Owner:SHENZHEN CESTBON TECH CO

System and method for monitoring and analyzing security event logs of power grid communication network in real time

The invention discloses a security event log real-time monitoring and analyzing system and method for a power grid communication network, and relates to the technical field of network security management. The causal relationship graph building module is used for building a causal relationship graph of the target power grid communication network; the multi-dimensional correlation analysis module is used for collecting and analyzing multi-source heterogeneous log data in real time; the abnormal security event identification module is used for identifying an abnormal security event according to the causal relationship graph and the multi-dimensional correlation analysis result; and the attack chain tracking response module is used for tracking the attack chain. According to the method, the technical problem that the existing power grid communication network security monitoring lacks tracking of abnormal event evolution from the time dimension and cannot accurately identify and track a multi-stage attack chain is solved, and the effects of dynamically tracking the evolution process of the abnormal event and identifying a potential attack chain by establishing a time causal chain graph are achieved. And the detection precision and the response speed of the attack behavior are improved.
Owner:HAINAN POWER GRID CO LTD

Network traffic anomaly detection model training method and device and readable storage medium

The invention provides a network traffic anomaly detection model training method and device and a readable storage medium, and the method comprises the steps: extracting a traffic statistical feature vector according to original network traffic data, and generating an initial mixed data set; generating a confrontation disturbance sample output enhanced feature matrix based on the initial mixed data set; constructing a self-adaptive feature fusion rule based on the enhanced feature matrix, embedding asset association degree parameters into an attention calculation layer of a feature encoder, and outputting encoding features fusing threat intelligence; inputting the coding features fused with the threat intelligence into a pre-constructed initial detection model, generating false report and missing report correction labels based on the suspicious traffic fragments, and outputting an adversarial sample correction data set; and performing adversarial training on the initial detection model through the adversarial sample correction data set to obtain an incremental detection model for network traffic anomaly detection. According to the invention, the detection precision, the anti-interference capability and the real-time defense response capability of the detection model to novel attacks can be improved.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD

Cloud desktop security access control method based on zero-trust architecture

The invention discloses a cloud desktop security access control method based on a zero-trust architecture, belongs to the technical field of network security, and is used for solving the problems of difficulty in hidden attack detection, cross-cloud attack chain breakage and conflict between security control and service continuity in a multi-cloud environment. Firstly, user identity attributes, session metadata and service call logs are aggregated, an identity-resource-behavior triple dynamic graph is constructed, cross-session association features are extracted, and a multi-dimensional behavior baseline is generated. And quantifying the access deviation degree based on the behavior baseline, triggering sensitive operation traceability analysis, constructing a time sequence risk propagation model, identifying latent attack features, predicting a penetration path and outputting a risk propagation coefficient. And finally, dynamically generating a process-level micro-isolation strategy according to a risk result, gradually adjusting the authority through a nonlinear authority attenuation function, inserting a secondary authentication node when unexpected resource jump is detected, reconstructing a communication white list, and realizing collaborative optimization of security protection and service continuity.
Owner:SHENZHEN HUITUO INFORMATION TECH CO LTD

Computer network information security monitoring method, system, equipment and medium

The invention relates to the technical field of network security, in particular to a computer network information security monitoring method, system and device and a medium, and the method comprises the steps: obtaining encrypted traffic data and application log data in a network environment, and constructing a space-time associated original data set based on the encrypted traffic data and the application log data; performing protocol analysis on the original data set with the time-space association to generate a protocol fingerprint feature vector; inputting the protocol fingerprint feature vector and the application log data into a preset heterogeneous multi-modal analysis model, and obtaining a multi-dimensional security situation assessment result containing a threat level and an attack path; and based on the multi-dimensional security situation assessment result, generating a dynamic defense strategy instruction set through a reinforcement learning algorithm, and issuing a strategy instruction to a network execution node in real time. The method and the device have the effects of realizing real-time accurate detection of encryption threats and constructing a dynamic defense system with balanced security and efficiency.
Owner:李俊磊 +1

Attack path risk mitigation by a data platform

An illustrative method includes scanning a compute environment associated with an entity and identifying one or more attack paths from a network to one or more datasets associated with the entity. The one or more attack paths each include a series of risk artifacts within the compute environment that can be exploited by an attacker to access the one or more datasets. The method further includes generating one or more attack path risk scores associated with the one or more attack paths and indicative of one or more levels of risk that the one or more attack paths could be exploited to access the one or more datasets. A risk mitigation operation associated with the one or more attack paths is performed based on the one or more attack path risk scores.
Owner:FORTINET INC

Information security analysis method and system based on big data

The invention relates to the technical field of information security data processing, and discloses an information security analysis method and system based on big data, and the method comprises the steps: S1, collecting multi-source heterogeneous security related data which comprises a business log, a user behavior track, network traffic, an application program interface calling record, an identity authentication log and a real-time security data flow, preprocessing the collected data to obtain standardized data; and S2, performing entity identification, event extraction and relationship mining based on the standardized data, and constructing a cross-modal threat knowledge graph containing security entity nodes and associated edges. The method solves the problem of monitoring blind areas caused by lack of dynamic association mining capability among data in a traditional method, and particularly aims at distributed, low-frequency and multi-stage hidden attacks, the scheme can accurately recover an attack chain and identify high-risk threats through dynamic matching and path reasoning of a knowledge graph, and the method has a good application prospect. And the detection coverage rate and accuracy in a complex attack scene are remarkably improved.
Owner:BEIJING YUANFANG TIMES TECHNOLOGY CO LTD

Industrial control network security service security guarantee system based on behavior analysis

The invention provides an industrial control network security service security guarantee system based on behavior analysis, which belongs to the technical field of industrial control network security, and comprises a multi-source data fusion acquisition module, a dynamic behavior modeling engine, a federal learning analysis cluster, an attack chain prediction module, a self-adaptive protection strategy executor and a model evolution feedback ring, wherein the multi-source data fusion acquisition module synchronously acquires industrial control network flow (including OPC UA / Modbus / DNP3 protocol analysis), equipment operation logs, user operation behavior fingerprints and physical interface state data, and the physical interface state data comprises electrical characteristic fluctuation monitoring of USB / network interfaces. According to the scheme, through multi-technology fusion and closed-loop design, the problems of static performance, single-dimension analysis defects and response lag of a traditional industrial control security scheme are effectively solved, a comprehensive protection system with dynamic modeling, intelligent decision making, privacy protection and continuous optimization is constructed, and the security and service reliability of an industrial control network are remarkably improved.
Owner:CPI NORTHEAST ENERGY SAVING TECH +1

Network security threat research and judgment method, system and equipment and storage medium

The invention discloses a network security threat research and judgment method, system and device and a storage medium, and the method comprises the following steps: S1, obtaining network traffic, terminal logs, application program interface calling records and threat intelligence data in real time, carrying out the standardized cleaning and format conversion of the data, and building a unified data lake; s2, matching, identifying and determining threats through a preset known threat feature library, constructing a normal behavior baseline by using an unsupervised learning algorithm, and marking suspicious events deviating from the baseline; s3, for the suspicious event marked in the step S2, mining a potential attack path and an attack intention by combining knowledge graph technology associated asset information, a historical attack chain and a homologous IP address; and S4, based on the attack success probability, the influence asset importance and the diffusion speed, calculating a threat level by adopting a fuzzy comprehensive evaluation model, and generating a research and judgment report containing disposal suggestions.
Owner:CRCC DEV GRP CO LTD +1

Dynamic honey point collaborative intelligent threat trapping system and method based on genetic algorithm

The invention discloses a dynamic honey point collaborative intelligent threat trapping system and method based on a genetic algorithm in the technical field of network security, and the system comprises a multi-source information collection and dual-mode output module, a reinforcement learning strategy engine, a graph neural network prediction module, a digital twin simulation environment, a strategy verification and optimization module, and a real network defense execution module. A dynamic honey point deployment strategy is generated in real time through a reinforcement learning strategy engine, and the problem of strategy stiffness is solved; a third-generation non-dominated sorting genetic algorithm (NSGA-III) multi-objective optimization algorithm is used for coordinating honey point density adjustment, trip line sensitivity calibration and other actions; attacking path risks are quantified based on a threat scoring formula, digital twin environment pre-verification and high-risk node precise protection are driven, closed-loop linkage of threat perception, strategy optimization and active trapping is finally achieved, and the intelligent defense capability capable of achieving autonomous evolution is formed.
Owner:积至(海南)信息技术有限公司

Network security analysis early warning system based on artificial intelligence

The invention discloses a network security analysis early warning system based on artificial intelligence, and the system comprises a data collection layer which captures full flow based on DPI, aggregates firewall logs, terminal behaviors and threat intelligence, and constructs a structured data pool; through TLS fingerprint identification of AI driving, the encrypted traffic is penetrated, and a sampling strategy is dynamically adjusted in combination with reinforcement learning. The intelligent analysis layer is used for carrying out cross validation on known threats and abnormal behaviors; the time sequence CNN extracts encrypted traffic features, and a novel threat detector is rapidly generated by using historical attack fragments in combination with a meta-learning framework; sHAP value driving dynamic feature selection and optimization feature vector input; the decision-making early warning layer is used for fusing multi-source features through a Bayesian network and generating 0-100 score risk scores; a self-adaptive threshold module is combined to adjust a score threshold in real time, and a high-risk event is pushed; the collaborative response layer is used for triggering a preset decision tree, deploying a GAN dynamic honeypot to trap an attacker and reversely tracing; the Neo4j visually restores the attack path, and blocking is executed after the threat is confirmed by a progressive response mechanism.
Owner:CHINA GEOLOGICAL SURVEY XINING NATURAL RESOURCES COMPREHENSIVE SURVEY CENT

Network attack detection method based on dynamic graph coding

The invention belongs to the technical field of network security, provides a network attack detection method based on dynamic graph coding, and solves the problems of poor dynamic adaptability of an attack path and missing of timing constraint in the prior art. The method comprises the following steps: constructing a dynamic threat map, extracting a triple of heterogeneous threat intelligence by using a RoBERTa model, and adding a timestamp and a confidence attribute; a dynamic graph encoder for time sequence perception is designed, semantic and evolution laws are fused through periodic time coding and a multi-head time sequence attention mechanism, and feature weights are adjusted in combination with a gating residual layer; an event-driven incremental updating strategy is adopted, and node similarity is calculated to achieve local subgraph updating; a time sequence rule base is established, three-dimensional parameter verification attack chain time sequence logic is defined, and abnormity is judged through conflict scores; and finally, integrating a graph updating module, a dynamic coding module and a constraint analysis module to realize multi-source threat feature matching and attack detection. According to the method, the adaptability of attack path evolution is improved through dynamic graph modeling and real-time increment updating.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Multi-modal large model confrontation safety detection method and system

The invention relates to the technical field of artificial intelligence security, and discloses a multi-modal large model confrontation security detection method and system, and the method comprises the steps: obtaining initial multi-modal data from original data sources, such as images, texts and audios, simulating the behavior of an attacker through reinforcement learning to generate a confrontation sample, and generating a cross-domain confrontation sample through transfer learning, extracting a multi-modal feature vector; the modal weight is dynamically adjusted through an attention mechanism based on the feature vector, the vulnerable modal weight is reduced, the credible modal weight is enhanced, inconsistency between abnormal modals is recognized in combination with disturbance analysis, and a weighted feature vector is output; abnormal input is detected by comparing semantic relevance of different modes, if semantic conflicts are found, an alarm is triggered, input is refused, and a corrected feature vector is output; and dynamically closing the untrusted mode and enhancing the trusted mode based on the semantic verification result, and outputting a final security detection result. According to the invention, the security of the multi-modal large model in a complex attack environment can be improved.
Owner:GUANGZHOU ZHANGDONG INTELLIGENT TECH CO LTD

Industrial network risk perception and collaborative early warning method based on dynamic risk map

The invention discloses an industrial network risk perception and collaborative early warning method based on a dynamic risk map, and relates to the technical field of industrial internet security, and the method comprises the steps: S1, multi-source perception deployment; s2, heterogeneous data fusion acquisition; s3, constructing a knowledge graph engine; s4, analyzing depth data; s5, performing dynamic risk assessment; and S6, intelligent early warning decision making. According to the industrial network risk perception and collaborative early warning method based on the dynamic risk map, through fusion perception of OT layer data such as equipment states and process parameters, the problems of single perception dimension, evaluation lagging and disjunction in the prior art are solved, the false alarm rate is extremely low, and the method is suitable for popularization and application. Particularly, a dynamic adjustment mechanism of a time-varying risk weight matrix is improved, novel attacks can be dynamically responded, meanwhile, cross-domain risk conduction analysis is achieved, the accuracy and response speed of industrial network security early warning are improved, and meanwhile a closed-loop mechanism of attack path prediction and disposal suggestions is constructed.
Owner:BEIJING ANDY TECH CO LTD

Financial network security defense method and system based on multiple Agents and dynamic large model

The invention discloses a financial network security defense method and system based on multiple Agents and a dynamic large model. A detection Agent is deployed in an edge layer, financial network node flow data and system logs are collected in real time, time sequence features are extracted through a lightweight convolutional network, and a preliminary anomaly score is generated. And the cloud layer constructs a decision Agent, receives the feature abstract transmitted by the edge node in an encrypted manner, inputs the feature abstract into a dynamic large model for multi-modal feature fusion, and outputs defense action probability distribution. And the intelligence Agent constructs a cross-institution federated learning network. And constructing a dynamic game engine, constructing a revenue matrix based on the attack cost and the defense revenue, solving a Nash equilibrium strategy, and generating an optimal defense instruction set. And dynamically allocating detection tasks according to the threat level and the edge computing power state. According to the method, efficient acquisition and analysis are realized, the abnormal behavior recognition capability is improved, support is provided for making a defense strategy, the defense strategy is optimized, and the intelligent, automatic and efficient levels of defense are improved.
Owner:HUAYING (SHANGHAI) INFORMATION TECH CO LTD

Data security processing method and system based on distributed storage

The invention relates to a data security processing method and system based on distributed storage, and relates to the technical field of computer information processing. The method comprises the following steps: cutting data into encryption fragments with a configurable number by adopting a dynamic fragmentation strategy, and generating a physically isolated dynamic check block in combination with a timestamp to realize tampering prevention; a dynamic threshold value is dynamically calculated based on the data sensitivity index and the node load, and the node is optimized through the reliability score for cooperative decryption; a database table is divided into independent marshalling storage according to main foreign key association, foreign key fields are encrypted by adopting cross keys, and cross-marshalling access needs to meet a multi-key threshold condition; an intelligent threat perception engine is constructed, access logs and threat intelligence are analyzed in real time, and key rotation, fragment replacement and joint defense response mechanisms are dynamically triggered. According to the invention, full life cycle protection of data is realized, and the problems of key leakage risk and cross-table association attack are effectively solved.
Owner:WUHAN ANYU INFORMATION SECURITY TECH CO LTD

Information security adaptive protection method and system based on artificial intelligence

The invention discloses an information security adaptive protection method and system based on artificial intelligence, and relates to the field of security protection, and the method comprises the steps: dynamically collecting multi-dimensional asset data through distributed nodes, carrying out the edge calculation preprocessing, and extracting features through a deep learning model; carrying out threat identification by fusing LSTM time sequence analysis, an isolated forest and a multi-modal AI detection engine of a knowledge graph; outputting a risk level based on an improved analytic hierarchy process and a fuzzy evaluation model; the AI strategy engine combines the risk level and the business scene to generate an optimal protection strategy, and continuous optimization is carried out through reinforcement learning; a standardized instruction is linked with safety equipment to execute protection, and interception effect closed-loop optimization is fed back in real time; a whole process log is stored through a block chain, and an attack evidence chain is generated through an AI traceability model. The method has the advantages that the information security protection capability is comprehensively improved through hierarchical data acquisition, multi-modal threat detection, scientific situation evaluation, dynamic generation of an optimization protection strategy and combination of block chain evidence storage and AI traceability.
Owner:HEFEI XINGSHENG NETWORK TECH CO LTD

Network situation monitoring system and method

The invention relates to the technical field of network monitoring, and provides a network situation monitoring system and method.The method comprises the steps that entities and relations of multi-source data are extracted through a sensing fusion module, a network situation map is constructed in combination with causal rules of an attack behavior knowledge base, and causal association of attack chains is recognized in combination with time sequence analysis and a causal discovery algorithm; the problems of attack chain identification fragmentation and risk path prediction distortion in the prior art are solved. The simulation verification module generates a dynamic mirror image based on a behavior feature library of an entity so as to construct an isolation simulation environment, and associates the causal strength of an attack chain with a defense effect to calculate an efficiency value so as to provide a precise basis for defense strategy screening; and the response feedback module takes the efficiency value as a reward function, optimizes a defense strategy through reinforcement learning, updates a network situation map, an attack behavior knowledge base and an isolation simulation environment through a feedback mechanism, and remarkably improves the coping capacity of the system to complex attacks and attack variations.
Owner:JIANGSU ZHIMENG INTELLIGENT TECH CO LTD

Network defense agent system based on large language model

The invention belongs to the field of network security, and particularly discloses a network defense agent system based on a large language model. Through the design of the sensing layer, the decision analysis layer and the action execution layer, comprehensive protection of network threats is realized. The sensing layer is responsible for collecting original information from multiple channels and converting the original information into standardized data; the decision analysis layer performs modeling and threat reasoning on attack behaviors, evaluates a risk level and predicts subsequent actions; and the action execution layer specifically executes defense operation according to the defense strategy scheme output by the decision analysis layer. In addition, the application also constructs a data set oriented to attack and defense confrontation, records a complete attack sequence, defense response and effect evaluation thereof, and provides a reliable basis for continuous learning of defense agents. Experimental results show that the framework provided by the invention is superior to the traditional method in the aspects of attack detection accuracy, attack chain identification and defense strategy generation, and has stronger adaptability and real-time response capability.
Owner:HUAZHONG NORMAL UNIV +1

System and Method for Improving Cybersecurity of a Network

A system and method for mitigating cyber-attacks against a target network comprising interconnected note that is implemented by Open Systems Interconnection (OSI) layers monitors the target network for detecting vulnerabilities across one or more OIS layers. a virtual network comprising a virtualized representation of the target network where the virtual network includes one or more virtual nodes that are annotated with identified vulnerabilities of one or more corresponding nods of the target network. A reference database can be configured to store records of known cyber-attacks and their corresponding mitigations where cyber-attacks on the virtual network are simulated based on records of known cyber-attacks and successful cyber-attacks. An AI engine can be configured to generate one or more mitigation actions based on simulation of the cyber-attacks before implementing the one or more mitigation actions to the target network.
Owner:THE GOVERNMENT OF THE UNITED STATES OF AMERICA AS REPRESENTED BY THE SEC OF HOMELAND SECURITY

System and Method for Network Weight Compression and Intrusion Detection

A system and method for neural network weight compression with intrusion detection capabilities that optimizes model storage and transmission while providing security. The system analyzes weight characteristics to identify statistical properties within different neural network layers, generates optimized encoding schemes based on the analysis, and creates reference distributions for security verification. The compression process employs a multi-resolution approach that produces a progressive representation with base and enhancement layers, enabling flexible deployment across diverse computing environments. Security markers and statistical fingerprints can be embedded throughout the encoded representation, allowing for detection of unauthorized modifications during transmission or deployment. The system monitors encoded weight streams, measures distribution divergence against reference baselines, and generates alerts when statistical anomalies indicate potential tampering. This approach achieves superior compression ratios while maintaining model performance and providing robust protection against increasingly sophisticated attacks targeting neural network weights.
Owner:ATOMBEAM TECH INC

Real-time monitoring and protection method and system for security data of Internet of Things

The invention belongs to the technical field of computers, and particularly relates to an Internet of Things security data real-time monitoring and protection method and system, and the method comprises the steps: collecting equipment communication and state data through an edge agent, and analyzing and extracting standardized metadata; constructing an equipment behavior contour vector based on a sliding window, and dynamically maintaining a global equipment topological graph; triggering a primary alarm in combination with behavior deviation detection and topology abnormity; outputting a threat score and an attack intention through rule matching and Bayesian network double-engine collaborative reasoning; and executing automatic response according to grading, and feeding back and correcting a behavior baseline to realize closed-loop optimization. The system comprises a data acquisition module, a protocol analysis module, a behavior modeling module, a topology maintenance module, an anomaly detection module, a collaborative reasoning module, an automatic response module and a baseline correction module. Through full-link real-time modeling and cross-device collaborative analysis, the attack detection rate is significantly increased to 98% or above, the false alarm rate is lower than 2%, the response delay is controlled within 800 milliseconds, and the security and adaptive ability of the Internet of Things system are enhanced.
Owner:HEBEI XIONGAN WEILI TECHNOLOGY CO LTD

Container mirror image security management method and system

The invention relates to the technical field of data access security, and discloses a container mirror image security management method and system, and the method comprises the steps: constructing a container mirror image, generating a differential encryption key through a strategy center, carrying out the encryption strategy of a kernel dependence layer, a runtime environment layer, an application code layer and a sensitive configuration layer, and forming a hierarchical protection basis. If an access request is triggered, firstly collecting equipment fingerprints and geofence information and evaluating an environmental risk score, verifying access authority and an access scene matching degree through attribute-based encryption, analyzing operation track characteristics in real time, identifying an abnormal mode, and if the three-layer verification is passed, generating a temporary access token; according to the method, access request authority is verified, a temporary access token is matched, key fragments are synthesized, a master key is only temporarily generated in a memory and encrypted and stored, and through combination of a double-layer encryption channel and inner-layer and outer-layer defense, the anti-attack ability of container mirror image transmission is improved, and man-in-the-middle attack and data tampering are effectively coped with.
Owner:NANJING TORTOISE & HARE RACE SOFTWARE RES INST CO LTD

Data security event real-time monitoring method and system

The invention relates to the field of internet attack detection, in particular to a data security event real-time monitoring method and system, and the method comprises data collection, multi-modal fusion, threat detection, causal reasoning, dynamic response and feedback optimization. Compared with the traditional security analysis which depends on isolated data dimension or simple rule association, is difficult to capture a cross-data-source complex attack mode, and is faced with the limitations of low calculation efficiency, slow link traceability, storage access bottleneck and the like in mass data association analysis, the scheme integrates multi-source heterogeneous data into a dynamic association network through graph structure modeling, so that the security analysis efficiency is improved. Hidden association and behavior patterns among users, equipment and IPs are deeply mined by utilizing a GNN framework, the suspicious degree among entities can be accurately quantified, and hidden attack chains can be identified; and meanwhile, a hybrid storage architecture and a query optimization technology are adopted, so that a security analyst can backtrack a complex attack path in a second level while breaking through the bottleneck of large-scale graph data access performance, and the threat hunting efficiency and the high-level attack traceability are remarkably improved.
Owner:JINAN DINGXIA DIGITAL TECHNOLOGY CO LTD

Cloud data anomaly detection and safety response system based on artificial intelligence

The invention discloses a cloud data anomaly detection and safety response system based on artificial intelligence, relates to the technical field of data processing, and solves the problems that firstly, an incremental compression algorithm is difficult to store and preprocess multi-source heterogeneous data; secondly, it is difficult to fuse statistical analysis and a deep learning model, locate outliers and analyze abnormal semantics in unstructured data, and then it is difficult to effectively predict a potential attack path; then, on the premise that data security and traceability are guaranteed, correlation analysis of cross-node anomalies is difficult to achieve so as to identify distributed attacks; and finally, an attack and defense confrontation model is difficult to construct for safety response, and the safety response effect is difficult to evaluate. According to the method, cloud environment data are processed through an adaptive probe cluster and the like, multiple models are fused to generate anomaly detection features and predict attack paths, and response and evaluation are carried out through reinforcement learning and digital twinning by means of cooperative detection such as federated learning and the like.
Owner:GUANGZHOU PENGJIE TECH CO LTD

Compute resource risk mitigation by a data platform

An illustrative method includes identifying, based on a scan of a compute environment associated with an entity, a plurality of attack paths from one or more networks to one or more datasets associated with the entity and determining a set of one or more attack paths included in the plurality of attack paths that include a particular risk artifact. Based on one or more characteristics of the set of one or more attack paths, a risk score specific to the particular risk artifact may be determined and a risk mitigation operation associated with the particular risk artifact may be performed.
Owner:FORTINET INC

Bidirectional authentication security mobile communication method and system based on public key digital fingerprint

The invention discloses a bidirectional authentication secure mobile communication method and system based on a public key digital fingerprint, and belongs to the technical field of communication security. The method specifically comprises the following steps: S1, digital certificate application and issuing: a mobile terminal and a service server respectively use an encryption algorithm to generate an asymmetric key pair which comprises a public key and a private key, an entity submits a CSR file which comprises a public key, entity identity information and an extension field to a CA, and the CA strictly audits the entity identity and issues a digital certificate; and performing digital signature on the public key and the entity information by using a CA private key after the auditing is passed. Two-way identity authentication is achieved, communication safety is improved, a traditional scheme only supports one-way authentication of a client to a server and is prone to phishing attack and identity false use, digital certificates are exchanged before communication between a mobile terminal and a service server, the legality of the certificates is verified through a public key of a CA root certificate, and the authenticity of the identities of the two parties is ensured. A bidirectional authentication mechanism effectively prevents man-in-the-middle attack and identity counterfeiting problems, and the security risk is greatly reduced.
Owner:HAINAN SOFTWARE VOCATIONAL & TECH COLLEGE

Federal learning-based industrial equipment fault prediction system and privacy protection method

The invention discloses an industrial equipment fault prediction system based on federated learning and a privacy protection method, and relates to the field of industrial equipment fault prediction. The data acquisition preprocessing module extracts fault features through compressed sensing downsampling, screens and uploads the fault features; the federal learning training module adopts a layered architecture and a dynamic algorithm to schedule a learning rate; the fault prediction and diagnosis module constructs a space-time diagram neural network and fuses a physical model to improve generalization; the privacy protection security communication module performs homomorphic encryption storage and zero-knowledge proof verification update; the knowledge graph construction reasoning module constructs a dynamic graph, locates a fault root cause through causal reasoning, and supports cross-device knowledge migration. By adopting the quantum and federated learning technology, the industrial equipment fault diagnosis accuracy is high, the attack resistance is high, the encryption efficiency is greatly improved, the model training time is shortened, cross-equipment knowledge migration is realized, the operation and maintenance cost is reduced, and the intelligent operation and maintenance development of the industrial equipment is promoted.
Owner:GUOSHU INTELLIGENCE (CHANGZHOU) DIGITAL TECHNOLOGY CO LTD

Payment scene-oriented interaction intention recognition and error correction system

The invention, which relates to the technical field of payment security, discloses a payment-scene-oriented interaction intention identification and error correction system comprising an input analysis module, an intention simulation module, a dynamic decision module, a biological verification module, an audit evidence storage module, and a cross-scene knowledge migration module. According to the method, multi-modal data such as voice, texts, images and touch tracks are integrated, structured feature vectors are generated through a cross-modal attention network, the problem of incomplete single-modal coverage is solved, cross-modal data consistency verification is achieved based on a unified semantic tag system, and the reliability of input sources is graded by combining equipment fingerprints and geographic positions, so that the reliability of the input sources is improved. A high-risk transaction protection capability is enhanced, a generative adversarial network is utilized to construct a virtual attack sample library, attacks such as tampering with characters similar in shape and AI faking voiceprints are simulated, unknown threats are actively defended through cosine similarity matching, a user historical behavior statistical model is integrated, and known risks such as high-frequency small-amount transfer are passively intercepted. And a closed-loop incremental learning continuous optimization model is supported.
Owner:QUANZHOU NORMAL UNIV