Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

31 results about "Attack analysis" patented technology

Attack surface analysis is an assessment of the total number of exploitable vulnerabilities in a system or network or other potential computer attack target. IT security workers and hackers both use attack surface analysis to detect security weaknesses in a system.

Honeynet-based attack trapping and analyzing method and system

The invention discloses an attack trapping and analyzing method and system based on a honeynet, and relates to the technical field of attack analysis, and the method comprises the steps: collecting attack interaction data and an associated attack chain trajectory set; dividing attack behavior units, and constructing a behavior space attitude matrix; constructing a two-dimensional behavior relationship graph, performing interpolation enhancement of sub-time granularity, and raising the dimension of the interpolated behavior node into a three-dimensional semantic space; performing attack path trend analysis on the attack behavior unit, and constructing an attack path bending rule model; and inputting parameters such as the attack chain trajectory set and behavior nodes in the three-dimensional semantic space into the attack path bending rule model, outputting a trapping response strategy, and dynamically adjusting the honeynet environment. According to the invention, the type and position of the honeypot can be automatically adjusted according to the attack behavior change, the structure definition and processing precision of the attack behavior data are effectively improved, and the attack behavior identification result can be conveniently and directly used for trapping strategy optimization.
Owner:INFORMATION & COMMNUNICATION BRANCH STATE GRID JIANGXI ELECTRIC POWER CO

Attack analysis device, attack analysis method, and storage medium

An attack analysis device acquires a security log generated by a security sensor mounted on each of a plurality of electronic control units configuring an electronic control system, sets a log package in which a plurality of the security logs are packaged, estimates an attack received by the electronic control system based on the log package, and outputs attack information indicating the estimated attack.
Owner:DENSO CORP

A deep spoofing detection and tracing system for network phishing attacks

PendingCN122394861APathPingAttack
The application discloses a kind of deep fake detection and tracing systems for network phishing attack, including the following steps: multi-source data acquisition module is used to form pre-processing multi-source data;Feature extraction module is used to form associated feature data;Association graph generation module is used to build fake content association layer and phishing propagation association layer, form unified attack association graph;Path screening construction module is used to identify effective relationship section, and build calculation path set;Similarity calculation backwrite module is used to perform PathSim similarity calculation, form the unified attack association graph after state update;Iterative calculation update module is used to re-execute PathSim similarity calculation, form candidate association result;Back-checking analysis output module is used to verify based on fake evidence and propagation evidence, and convert the candidate association result after verification into attack analysis result.The application improves the accuracy of deep fake content identification in network phishing attack scenario.
Owner:NINGXIA PUSHI INFORMATION TECH SERVICE CO LTD

Attack analysis device, attack analysis method, and attack analysis program

An attack analysis device (100) includes an analysis priority changing unit (130) that, when a target device receives a target attack that is a network attack, changes an analysis priority corresponding to the target device on the basis of the content of the target attack, the target device being a device provided in an attack target system that is provided with a plurality of devices. Each of the plurality of devices is provided with an analysis priority. When a plurality of devices provided in a system to be attacked are set as a device group to be attacked, if each device included in the device group to be attacked is subjected to a network attack, the device group to be attacked is analyzed according to an analysis priority corresponding to each device included in the device group to be attacked. Network attacks for each device included in the attack target device group are sequentially analyzed.
Owner:MITSUBISHI ELECTRIC CORP

Wireless network attack analysis method and system based on large model prompt project

The invention discloses a wireless network attack analysis method and system based on a large model prompt project. The method mainly comprises an offline stage and an online analysis stage. The offline stage mainly comprises the following steps: (1) constructing an attack knowledge base; and (2) constructing a prompt template. In the online analysis stage, the system periodically executes the following steps: (1) simulation data collection; (2) scene description generation; (3) template assembly is prompted; (4) large language model attack reasoning; (5) extracting parameters of the large language model; (6) simulating an attack result; and (7) updating the knowledge base and the template. According to the method, powerful context understanding, logical reasoning and common sense capabilities of a large language model are utilized to replace a traditional machine learning model, and automatic analysis of complex network attack behaviors in a large amount of simulation data is realized; the big language model reasoning output is converted into a structured attack result through the prompt project, so that the interpretability of attack analysis in a complex and changeable wireless network is greatly improved, and the overhead of manual analysis is remarkably reduced.
Owner:NANJING UNIV OF SCI & TECH

Network attack processing method, system and device, storage medium and program product

PendingCN121530601ABiological modelsSecuring communicationAttackSuspicious behaviour
The embodiment of the invention provides a network attack processing method, system and device, a storage medium and a program product. In the process of performing security protection on the target host, when a suspicious behavior on the target host is detected, behavior data corresponding to the suspicious behavior can be obtained, an interception rule corresponding to the suspicious behavior is obtained according to the behavior data, and the interception rule is determined by using an attack analysis model. The attack analysis model is obtained by training the behavior data sample of the process corresponding to the historical network attack behavior, so that the attack analysis model can better master the knowledge of the network attack field. When the behavior data of the process with the suspicious behavior is analyzed, the attack analysis model can identify and judge the behavior of the process more accurately, so that an interception rule with higher confrontation is generated. Therefore, the potential security threats corresponding to the suspicious behaviors can be quickly and accurately processed, the risk of missing potential attacks is reduced, and the defense capability is improved.
Owner:ALIBABA CLOUD COMPUTING CO LTD

Attack analysis device, attack analysis method, and attack analysis program

Provided is a technology that enables highly accurate analysis of a cyber-attack against a vehicle. An attack analysis device (47) comprises a determination section (472, S102) which is configured to: determine whether correspondence information matches a pre-set type of the attack, in which correspondence information a system log that is a log of an electronic control system and a communication log that is a log of communications between the electronic control system and the outside of a vehicle are associated with each other; and determine whether an target element representing at least one of a component of the electronic control system and the electronic control system is being violated.
Owner:DENSO CORP

Method and apparatus for handling risk events in encrypted traffic

This application discloses a method and apparatus for handling risk events in encrypted traffic. The method includes: synchronously collecting network modality data and host modality data through an eBPF program assembly with multiple function entry points pre-deployed in the Linux kernel to obtain collected network events; transmitting the network events to a user-space receiver via the Perf Buffer data transmission mechanism to append a global high-precision timestamp and host identifier to the network events to obtain network traffic; generating a comprehensive risk score for the network events based on the network traffic, combined with a pre-trained bimodal deep learning model and a cross-modal attention fusion module; and triggering an alarm and writing the network event as a risk event into a graph database when the comprehensive risk score exceeds a preset threshold. Using this application, lateral movement attacks can be effectively detected and defended, improving the accuracy of encrypted risk detection and enabling users to gain a more comprehensive understanding of attack behavior, thereby enabling more effective attack analysis and response.
Owner:HANGZHOU WEIMING XINKE TECH CO LTD +1

Cyber attack processing method and system, device, storage medium, and program product

Embodiments of the present disclosure provide a cyber attack processing method and system, a device, a storage medium, and a program product. In the process of performing security protection on a target host, when a suspicious behavior on the target host is detected, behavior data corresponding to the suspicious behavior may be acquired, and an interception rule corresponding to the suspicious behavior is acquired on the basis of the behavior data, wherein the interception rule is determined by using an attack analysis model. The attack analysis model is obtained by training behavior data samples of processes corresponding to historical cyber attack behaviors, and therefore, the attack analysis model can better grasp knowledge in the field of cyber attacks. When analyzing behavior data of a process of the suspicious behavior, the attack analysis model can more accurately identify and determine the behavior of the process, thereby generating a more adversarial interception rule. Therefore, it is convenient to quickly and accurately process potential security threats corresponding to suspicious behaviors, the risk of missing potential attacks is reduced, and the defensive capability is improved.
Owner:CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD +1

Attack analysis device, attack analysis method, and storage medium

An attack analysis device includes attack abnormality relationship information indicating a relationship among (i) attack information indicating an attack possible to be received by an electronic control system, (ii) an estimation abnormality information indicating an abnormality estimated to be occurred when the attack is received, and (iii) commonized estimation abnormality location information indicating a commonized estimation abnormality location, which is a location of the abnormality estimated to be occurred when the electronic control system receives the attack and commonized between the electronic control system and a different electronic control system. The attack analysis device estimates an attack received by the electronic control system with reference to the attack abnormality relationship information.
Owner:DENSO CORP

APT attack analysis technology based on LLM and RAG

The invention relates to an APT (Advanced Persistent Threat) attack analysis technology based on LLM (Logical Language Model) and RAG (Random Access Gateway), which is used for automatically analyzing an APT attack detection result and generating an APT survey report in a natural language form. The automatic APT attack analysis system provided by the invention comprises the following three key subsystems: 1, a CTI information extraction system based on LLM intelligent agent structure alignment: using an atlas extractor and an atlas inspector intelligent agent to automatically construct a CTI atlas structurally aligned with a traceability graph from CTI according to a predefined mode; and 2, an RAG system based on a GNN retrieval model: using a graph similarity matching model to retrieve a CTI graph corresponding to the traceability graph. And 3, an APT attack analysis system capable of autonomously and dynamically planning a reasoning process is used, so that traceable and automatic APT attack analysis of the reasoning process is realized. The method can be used for network attack analysis including but not limited to APT attacks, and the efficiency and accuracy of network attack analysis can be effectively improved.
Owner:BEIHANG UNIV

Safety alarm method, device and equipment based on chain analysis and medium

The invention discloses a security alarm method, device and equipment based on chain analysis and a medium, is applied to a security alarm system and relates to the technical field of network security, and the method comprises the following steps: constructing a target context object based on target data of a preset data source, and transmitting the target context object to a filtering node in an analysis link for data filtering, filtering to obtain a filtered object; determining data features of the filtered object, and sending the filtered object to a target analysis node corresponding to the data features in an analysis link for attack analysis to obtain an attack analysis result; and carrying out secondary attack analysis on the attack analysis result based on a preset analysis model, and pushing an obtained target processing result to a corresponding processing platform through an output node in an analysis link, so that the processing platform carries out corresponding security alarm or information pushing based on the target processing result. Therefore, it can be ensured that data of different types of processing nodes can be processed in time, and then alarm accuracy is ensured.
Owner:HANGZHOU ANHENG INFORMATION SECURITY TECH CO LTD

DDoS attack visual detection method based on multi-dimensional feature combination analysis

The application discloses a DDoS attack visual detection method based on multi-dimensional feature combination analysis, multi-dimensional traffic feature extraction, a lightweight attack detection model, DDoS attack knowledge graph construction, a graph-constrained attack behavior interpretation large model, attack visual detection display and the like to realize visual detection of network attacks. The application improves the visualization level and reduces the false alarm rate. The multi-dimensional feature combination method and the lightweight security detection model provide rich information for subsequent network attack knowledge graph establishment and professional interpretation based on a large language model. The constructed knowledge graph about network attacks can enhance the rigorousness of the thinking deduction of the large model and reduce the occurrence of model hallucinations. The enhanced large model can make more professional explanations and analyses on existing network attacks, thereby reducing the huge workload of manual attack analysis, and striving for a valuable time window for timely and accurate response to network attacks and deployment of defense.
Owner:BEIJING LANYUN TECH CO LTD +1

Artificial intelligence driven network intrusion detection method, system and equipment

The invention belongs to the technical field of network security detection, and provides an artificial intelligence-driven network intrusion detection method, system and device. The method comprises the steps of multi-source metadata extraction and preprocessing, causal feature discovery and selection, meta learning detection model reasoning, known attack screening, causal comparative analysis and branch judgment, adaptive threshold adjustment and interpretable report generation. According to the method, initial parameters of three layers of MLP are optimized by adopting an MAML framework, so that the model can be quickly adapted only by a small amount of fine tuning in a zero-day attack and few-sample scene, and the limitation that traditional machine learning depends on a large number of historical samples is broken through; meanwhile, by constructing a baseline normal causal graph and an abnormal causal graph, adopting GED to quantify the similarity of the two graphs and accurately distinguishing zero-day attack and concept drift based on a preset threshold value, the industrial pain point that zero-day attack detection is difficult is solved, misinformation caused by concept drift is avoided, it is ensured that resources are only used for real attack analysis, and the detection efficiency is improved.
Owner:INFORMATION & COMM CO OF STATE GRID XINJIANG ELECTRIC POWER CO LTD

APT detection and analysis method

The invention relates to the technical field of network attack protection, and discloses an APT detection and analysis method, which comprises the following steps of: obtaining a plurality of multi-source audit logs of a target network in a time sequence and key log data in each multi-source audit log, and combining all the key log data to obtain a key log data group; obtaining an APT hidden attack characteristic value according to the change condition of each key log data set; calculating an APT attack analysis coefficient according to the feature metric value; the method comprises the steps of detecting and analyzing key log data in a sequential sequence, presetting an APT attack analysis coefficient, judging whether a target network has an APT attack risk or not according to the APT attack analysis coefficient and the preset APT attack analysis coefficient, determining a feature value of an APT hidden attack behavior by detecting and analyzing a change condition of the key log data in the sequential sequence, and realizing intelligent assessment of the APT attack risk, so that the accuracy of risk detection is improved. And the stability and security of the target network are ensured.
Owner:HUANENG INFORMATION TECH CO LTD

An APT attack analysis method for a software-defined deception defense system

This invention discloses an APT attack analysis method for software-defined deception defense systems. Addressing the limitations of existing methods in handling dispersed attack behaviors and the lack of associations for new entities, this method first constructs an APT knowledge graph by extracting threat intelligence. Second, it integrates newly captured attack entities from deception nodes, using semantic and interactive discriminant models to filter and determine attack associations. Then, it constructs attack chain paths reflecting the attack evolution logic by performing multi-hop concatenation based on predicted relation triples. Finally, it extracts path features for risk quantification assessment and dynamically optimizes the deployment and configuration strategies of decoy resources accordingly. This method integrates fragmented attack behaviors into a continuous path structure, enabling the calculability of risk intensity and directly linking analysis results to defense strategies, significantly improving the dynamic response capability and resource utilization efficiency of the deception defense system.
Owner:GUANGZHOU UNIVERSITY HUANGPU RESEARCH INSTITUTE +1

Attack analysis device, attack analysis method, and attack analysis program

An attack analysis device (100) comprises an analysis priority change unit (130) for changing an analysis priority according to a target device based on the content of a targeted attack when the target device is exposed to the targeted attack, which is a cyberattack. The device is a target device available to an attack targeting system comprising a plurality of devices, each assigned an analysis priority. Assuming that the plurality of devices available to the attack targeting system constitute an attack targeting device group, and that the devices contained in the attack targeting device group are exposed to cyberattacks, the cyberattacks against the devices contained in the attack targeting device group are analyzed in sequence according to the analysis priorities corresponding to the devices contained in the attack targeting device group.
Owner:MITSUBISHI ELECTRIC CORP

An industrial control protocol identification and attack resistance processing method, system and server

PendingCN122394935ADistribution controlAttack
The application discloses a kind of industrial control protocol identification and attack processing method, system and server, and relates to data processing. Multiple-source interaction records in industrial control network are acquired to construct protocol attachment track and assign control location identification, and based on control location identification, occupation relationship and protocol shadow chain are formed. Real-time messages are mapped to protocol shadow chain to perform occupation verification to identify free control fragments, and active probing behavior is identified in combination with detection control location identification. Control is decoupled for abnormal behavior and imported into a limited redemption channel to form attack analysis texture, and based on attack analysis texture, traceability identification, hierarchical disposal and protocol attachment track and protocol shadow chain are synchronously updated. By implementing the technical solution, in a complex network environment where the host station and the field device are located, the context loss problem caused by the difficulty in reconstructing the protocol session due to the attack behavior of the attacker is solved, so as to improve the accuracy of industrial control protocol identification, enhance the anti-attack capability and improve the control accuracy of the industrial control system.
Owner:HANXING TONGHENG TECH GRP CO LTD +2

Network vulnerability visualization mining analysis system

ActiveCN121530758BSecuring communicationAttackVisual mining
The present application relates to the technical field of security protocol vulnerability analysis, and discloses a network vulnerability visual mining and analysis system, which comprises an extraction unit, a security analysis unit, a protocol mapping unit, a vulnerability identification unit, an attack analysis unit and a vulnerability mining unit. Through the cooperative analysis of the multiple units, a visual protocol vulnerability atlas is finally generated, handshake stage version negotiation sequence and state conversion can be clearly presented, version rollback points and downgrade attack abnormal patterns are directly exposed, security state and attack influence are determined, vulnerability identification accuracy and analysis efficiency are improved, and dynamic and visual security protection is provided for enterprise intranet multi-TLS protocol version service.
Owner:HANGZHOU HUAYI ZHILIAN TECHNOLOGY CO LTD

A honeynet-based attack trapping and analysis method and system

The application discloses a kind of attack trapping and analysis method and system based on honeynet, it is related to attack analysis technical field, including: attack interaction data and associated attack chain trajectory set are collected;Divide attack behavior unit, construct behavior space posture matrix;Two-dimensional behavior relationship atlas is constructed, interpolation enhancement is carried out to sub-time granularity, and the behavior node after interpolation is upgraded to three-dimensional semantic space;Attack path trend analysis is carried out to attack behavior unit, and attack path bending law model is constructed;Attack chain trajectory set, the behavior node in three-dimensional semantic space and the like parameter are input into attack path bending law model, and output is trapping response strategy, and dynamically adjusts honeynet environment.The application can automatically adjust honeypot type and position according to attack behavior change, effectively improve the structural clarity and processing precision of attack behavior data, and facilitate to directly use attack behavior identification result for trapping strategy optimization.
Owner:INFORMATION & COMMNUNICATION BRANCH STATE GRID JIANGXI ELECTRIC POWER CO

Visual mining and analyzing system for network vulnerabilities

ActiveCN121530758ASecuring communicationAttackVisual mining
The invention relates to the technical field of security protocol vulnerability analysis, and discloses a network vulnerability visual mining analysis system, which comprises an extraction unit, a security analysis unit, a protocol mapping unit, a vulnerability identification unit, an attack analysis unit and a vulnerability mining unit, and finally generates a visual protocol vulnerability graph through collaborative analysis of a plurality of units. According to the method, a version negotiation sequence and state conversion in a handshake stage can be clearly presented, a version backspace point and a degradation attack abnormal mode are visually exposed, a security state and attack influence are determined, vulnerability identification accuracy and analysis efficiency are improved, and dynamic and visual security protection is provided for enterprise intranet multi-TLS protocol version service.
Owner:HANGZHOU HUAYI ZHILIAN TECHNOLOGY CO LTD

Correlating compromised home internet of things devices with distributed denial of service attacks

ActiveUS12676883B2Internet privacyAttack
A distributed denial of service (“DDoS”) attack profiler can determine a plurality of DDoS attack properties associated with a DDoS attack that utilizes an Internet of Things (“IoT”) device operating in communication with a home gateway. The DDoS attack profiler can create a DDoS attack profile and can provide a DDoS attack report based upon the DDoS attack profile to a correlator. An IoT device profiler can determine a plurality of IoT device properties and can create, based upon the plurality of IoT device properties, an IoT device profile. The IoT device profiler can create an anomaly report that identifies an anomaly associated with the IoT device. The correlator can correlate the DDoS attack report with the anomaly report to determine if a match exists. In response to determining that the match exists, the home gateway system can store the bot match record in a bot match repository.
Owner:AT&T INTELLECTUAL PROPERTY I L P

Social Engineering Threat Assessment Platform (SETAP)

The present disclosure provides a method, a computing platform, and a system for social engineering threat assessment. The method, conducted by a computing platform having one or more processors, includes converting social engineering threat data into one or more templates, simulating one or more social engineering attacks for a target based on the one or more templates, analyzing the one or more simulated social engineering attacks for the target; executing the one or more simulated social engineering attacks for the target based on analysis results by initiating one or more simulated vishing phone calls to the target, receiving, from a computing device associated with the target, response data responsive to the one or more simulated vishing phone calls, and providing, as feedback, execution results to one or more parties.
Owner:BANK OF AMERICA CORP

Power distribution terminal information-physical bidirectional cross-domain attack analysis method

The application discloses a power distribution terminal information-physical bidirectional cross-domain attack analysis method and belongs to the field of network security. Analysis and research are conducted from two aspects of a multi-source bidirectional cross-domain attack entrance and attack target positioning and multi-region cross-domain attack link construction. The multi-source bidirectional cross-domain attack entrance and attack target positioning aims to detect vulnerabilities of terminal device software and hardware function modules, establish a mapping relationship list of the vulnerabilities and device states, and position the bidirectional cross-domain attack entrance and attack target. The multi-region cross-domain attack propagation link construction aims to analyze information between devices and physical connection coupling relationships according to business logic, establish a physical information multi-region cross-domain coupling model in combination with a power distribution network architecture, and calculate the most possible cross-domain attack propagation link so as to carry out targeted defense. Through analysis of two stages of vulnerability exploitation and attack propagation in the attack process, accurate characterization of the cross-domain attack can be formed.
Owner:ZHEJIANG UNIV

DDoS attack visual detection method based on multi-dimensional feature combinatorial analysis

The invention discloses a DDoS (Distributed Denial of Service) attack visual detection method based on multi-dimensional feature combinatorial analysis. Visual detection of network attacks is realized through multi-dimensional flow feature extraction, a lightweight attack detection model, DDoS attack knowledge graph construction, a graph-constrained attack behavior interpretation large model, attack visual detection display and the like. According to the method, the visualization level is improved, and the false alarm rate is reduced. A multi-dimensional feature combination method and a lightweight security detection model provide abundant information for subsequent network attack knowledge graph establishment and professional interpretation based on a large language model; the constructed knowledge graph about the network attack can enhance the thinking derivation preciseness of a large model and reduce the occurrence of model illusion; the enhanced large model can perform more professional interpretation and analysis on the existing network attack, thereby reducing the huge workload of manual attack analysis, and winning a precious time window for timely and accurately responding to the network attack and deploying defense.
Owner:BEIJING LANYUN TECH CO LTD +1

Data transmission method and device, computer program product and storage medium

The invention provides a data transmission method and device, a computer program product and a storage medium, relates to the field of information security, and can realize protection of data security. The method comprises the steps that a first APN6 message is acquired, the first APN6 message comprises an application awareness identifier APN ID, the APN ID comprises a data security identifier, and the data security identifier is used for indicating the security level of the first APN6 message; the APN ID in the first APN6 message is analyzed, and a data security identifier is obtained; encrypting the first APN6 message based on an encryption mode corresponding to the data security identifier to obtain a second APN6 message; and sending the second APN6 message so as to realize the transmission of the APN6 service. According to the application, the secure transmission of the APN6 message can be realized, the attack threshold is improved, the attack analysis and tampering difficulty is increased, the damage resistance is improved, and differentiated encryption can be realized.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD

Automated security compliance for system nodes

Disclosed herein are embodiments of systems, methods, and products comprise an analytic server, which improves security of a system. The analytic server may monitor the system by retrieving status information from various devices within the system. The analytic server may generate an attack tree model based on a set of aggregation rules that are configured based on the monitored status information. The analytic server may detect one or more attacks by associating the status information with corresponding nodes of the attack tree model and executing a logic of the attack tree model. The analytic server may determine aggregated impact and risk metrics and calculate an impact score for each attack based on aggregated impact and risk metrics. The analytic server may generate reports comprising the one or more attacks ranked based on the impact scores. The analytic server may respond to one or more attacks by taking automated actions.
Owner:ARCHITECTURE TECH CORP

Attack analysis device, attack analysis method, and non-transitory computer readable medium

An attack analysis device (100) includes an analysis priority change unit (130) to change an analysis priority corresponding to a target device in accordance with a content of a target attack when the target device is subjected to the target attack being a cyberattack, the target device being a device provided to an attack target system including a plurality of devices each being set with an analysis priority. Assuming that the plurality of devices provided to the attack target system form an attack target device group, when the devices included in the attack target device group are subjected to cyberattacks, the cyberattacks against the devices included in the attack target device group are analyzed in order according to analysis priorities corresponding to the devices included in the attack target device group.
Owner:MITSUBISHI ELECTRIC CORP

A method and system for constructing an uncertainty attack resource graph

The embodiment of the application provides a kind of based on the construction method and system of uncertainty attack resource atlas, it is related to network security technical field.The construction method based on the uncertainty attack resource atlas includes: obtaining the original data of gang attack behavior;According to the original data, the data extraction of the gang attack is carried out, and the association relationship data between attack resource entities is obtained;According to the pre-set confidence algorithm, the association relationship data is processed, and confidence information is obtained;According to the association relationship data and the confidence information, uncertainty atlas is constructed.The construction method based on the uncertainty attack resource atlas can realize the technical effect of improving the effectiveness of gang attack analysis.
Owner:NAT COMP NETWORK & INFORMATION SECURITY MANAGEMENT CENT

Model security evaluation method, device and storage medium

PendingCN122594440AInternet privacyAttack
The application discloses a model security evaluation method and device and a storage medium. The method comprises the following steps: obtaining a prompt word containing model attack content for generating an agent output, and obtaining an initial prompt word; inputting the initial prompt word into a defense agent for attack analysis, and obtaining rebuttal opinions corresponding to the initial prompt word; determining the model attack content recognized in the prompt word based on the rebuttal opinions, optimizing the model attack content recognized in the prompt word, and obtaining a model attack prompt word; and sending the model attack prompt word to a model to be evaluated for security evaluation. The generation agent automatically adjusts the concealment and logical rigor of the attack strategy according to the real-time feedback of the defense agent, directly repairs the attack vulnerabilities in the prompt word, generates a model attack prompt word with anti-vulnerability, improves the quality of the model attack prompt word, and can automatically, continuously and efficiently find the security vulnerabilities of the model to be evaluated.
Owner:ZHEJIANG DAHUA TECH CO LTD