Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

39 results about "Attack analysis" patented technology

Attack surface analysis is an assessment of the total number of exploitable vulnerabilities in a system or network or other potential computer attack target. IT security workers and hackers both use attack surface analysis to detect security weaknesses in a system.

Multi-source network risk information fusion and risk assessment method and system

The invention belongs to the technical field of network security, and particularly relates to a multi-source network risk information fusion and risk assessment method, which comprises the following steps of: extracting nodes and edges of a real-time event through an entity extraction tool, and constructing a multi-source heterogeneous threat knowledge graph based on the nodes and the edges; calculating a random walk transition probability matrix of the edge, and calculating a time-sensitive personalized random walk value based on the random walk transition probability matrix; a graph neural network model is adopted for training, graph neural network embedding and prediction are carried out in combination with the features of the nodes, and the classification probability is output; and carrying out three-dimensional sub-graph segmentation on the predicted multi-source heterogeneous threat knowledge graph, constructing a mapping index, carrying out aggregation calculation to obtain a propagation path and path popularity of a high-risk node, analyzing a sub-graph evolution trend and carrying out early warning. The method is suitable for carrying out dynamic analysis and prediction on multi-dimensional attack risks, and trend attack analysis of the industry changing along with time is achieved.
Owner:THE THIRD RES INST OF MIN OF PUBLIC SECURITY

Honeynet-based attack trapping and analyzing method and system

The invention discloses an attack trapping and analyzing method and system based on a honeynet, and relates to the technical field of attack analysis, and the method comprises the steps: collecting attack interaction data and an associated attack chain trajectory set; dividing attack behavior units, and constructing a behavior space attitude matrix; constructing a two-dimensional behavior relationship graph, performing interpolation enhancement of sub-time granularity, and raising the dimension of the interpolated behavior node into a three-dimensional semantic space; performing attack path trend analysis on the attack behavior unit, and constructing an attack path bending rule model; and inputting parameters such as the attack chain trajectory set and behavior nodes in the three-dimensional semantic space into the attack path bending rule model, outputting a trapping response strategy, and dynamically adjusting the honeynet environment. According to the invention, the type and position of the honeypot can be automatically adjusted according to the attack behavior change, the structure definition and processing precision of the attack behavior data are effectively improved, and the attack behavior identification result can be conveniently and directly used for trapping strategy optimization.
Owner:INFORMATION & COMMNUNICATION BRANCH STATE GRID JIANGXI ELECTRIC POWER CO

Attack analysis device, attack analysis method, and storage medium

An attack analysis device acquires a security log generated by a security sensor mounted on each of a plurality of electronic control units configuring an electronic control system, sets a log package in which a plurality of the security logs are packaged, estimates an attack received by the electronic control system based on the log package, and outputs attack information indicating the estimated attack.
Owner:DENSO CORP

A deep spoofing detection and tracing system for network phishing attacks

PendingCN122394861APathPingAttack
The application discloses a kind of deep fake detection and tracing systems for network phishing attack, including the following steps: multi-source data acquisition module is used to form pre-processing multi-source data;Feature extraction module is used to form associated feature data;Association graph generation module is used to build fake content association layer and phishing propagation association layer, form unified attack association graph;Path screening construction module is used to identify effective relationship section, and build calculation path set;Similarity calculation backwrite module is used to perform PathSim similarity calculation, form the unified attack association graph after state update;Iterative calculation update module is used to re-execute PathSim similarity calculation, form candidate association result;Back-checking analysis output module is used to verify based on fake evidence and propagation evidence, and convert the candidate association result after verification into attack analysis result.The application improves the accuracy of deep fake content identification in network phishing attack scenario.
Owner:NINGXIA PUSHI INFORMATION TECH SERVICE CO LTD

Attack analysis device, attack analysis method, and attack analysis program

An attack analysis device (100) includes an analysis priority changing unit (130) that, when a target device receives a target attack that is a network attack, changes an analysis priority corresponding to the target device on the basis of the content of the target attack, the target device being a device provided in an attack target system that is provided with a plurality of devices. Each of the plurality of devices is provided with an analysis priority. When a plurality of devices provided in a system to be attacked are set as a device group to be attacked, if each device included in the device group to be attacked is subjected to a network attack, the device group to be attacked is analyzed according to an analysis priority corresponding to each device included in the device group to be attacked. Network attacks for each device included in the attack target device group are sequentially analyzed.
Owner:MITSUBISHI ELECTRIC CORP

Wireless network attack analysis method and system based on large model prompt project

The invention discloses a wireless network attack analysis method and system based on a large model prompt project. The method mainly comprises an offline stage and an online analysis stage. The offline stage mainly comprises the following steps: (1) constructing an attack knowledge base; and (2) constructing a prompt template. In the online analysis stage, the system periodically executes the following steps: (1) simulation data collection; (2) scene description generation; (3) template assembly is prompted; (4) large language model attack reasoning; (5) extracting parameters of the large language model; (6) simulating an attack result; and (7) updating the knowledge base and the template. According to the method, powerful context understanding, logical reasoning and common sense capabilities of a large language model are utilized to replace a traditional machine learning model, and automatic analysis of complex network attack behaviors in a large amount of simulation data is realized; the big language model reasoning output is converted into a structured attack result through the prompt project, so that the interpretability of attack analysis in a complex and changeable wireless network is greatly improved, and the overhead of manual analysis is remarkably reduced.
Owner:NANJING UNIV OF SCI & TECH

Attack monitoring device, attack monitoring system, and attack monitoring method

This attack monitoring device 100 mounted on a vehicle V includes: a vehicle-side attack analysis unit 122 that analyzes a log of a first monitoring target 501 on the basis of a threat scenario to calculate the possibility of a cyber attack occurring; and an offload determination unit 124 that determines whether to cause a server-side attack analysis unit 222, which is installed in a server 200 outside of the vehicle V and analyzes a log of a second monitoring target 502 on the basis of the threat scenario to calculate an occurrence possibility of a cyber attack, to execute an offload of processing for the analysis of the log of the first monitoring target 501 by the vehicle-side attack analysis unit 122.
Owner:ASTEMO LTD

Network attack processing method, system and device, storage medium and program product

The embodiment of the invention provides a network attack processing method, system and device, a storage medium and a program product. In the process of performing security protection on the target host, when a suspicious behavior on the target host is detected, behavior data corresponding to the suspicious behavior can be obtained, an interception rule corresponding to the suspicious behavior is obtained according to the behavior data, and the interception rule is determined by using an attack analysis model. The attack analysis model is obtained by training the behavior data sample of the process corresponding to the historical network attack behavior, so that the attack analysis model can better master the knowledge of the network attack field. When the behavior data of the process with the suspicious behavior is analyzed, the attack analysis model can identify and judge the behavior of the process more accurately, so that an interception rule with higher confrontation is generated. Therefore, the potential security threats corresponding to the suspicious behaviors can be quickly and accurately processed, the risk of missing potential attacks is reduced, and the defense capability is improved.
Owner:ALIBABA CLOUD COMPUTING CO LTD

Attack monitoring apparatus, attack monitoring system, and attack monitoring method

To provide an attack monitoring apparatus, an attack monitoring system, and an attack monitoring method which enable cyber attack monitoring to be continued with an in-vehicle system with limited resources.SOLUTION: An attack monitoring apparatus 100 mounted on a vehicle V includes: a vehicle-side attack analysis unit 122 which analyzes a log of a first monitoring target 501 based on a threat scenario, to calculate the probability of occurrence of cyberattack; a server-side attack analysis unit 222 which is mounted on a server 200 outside the vehicle V and analyzes a log of a second monitoring target 502 based on the threat scenario, to calculate the probability of occurrence of cyberattack; and an offloading determination unit 124 which determines whether to offload the process of the vehicle-side attack analysis unit 122 to analyze the log of the first monitoring target 501.SELECTED DRAWING: Figure 2
Owner:ASTEMO LTD

Attack analysis device, attack analysis method, and attack analysis program

Provided is a technology that enables highly accurate analysis of a cyber-attack against a vehicle. An attack analysis device (47) comprises a determination section (472, S102) which is configured to: determine whether correspondence information matches a pre-set type of the attack, in which correspondence information a system log that is a log of an electronic control system and a communication log that is a log of communications between the electronic control system and the outside of a vehicle are associated with each other; and determine whether an target element representing at least one of a component of the electronic control system and the electronic control system is being violated.
Owner:DENSO CORP

Method and apparatus for handling risk events in encrypted traffic

This application discloses a method and apparatus for handling risk events in encrypted traffic. The method includes: synchronously collecting network modality data and host modality data through an eBPF program assembly with multiple function entry points pre-deployed in the Linux kernel to obtain collected network events; transmitting the network events to a user-space receiver via the Perf Buffer data transmission mechanism to append a global high-precision timestamp and host identifier to the network events to obtain network traffic; generating a comprehensive risk score for the network events based on the network traffic, combined with a pre-trained bimodal deep learning model and a cross-modal attention fusion module; and triggering an alarm and writing the network event as a risk event into a graph database when the comprehensive risk score exceeds a preset threshold. Using this application, lateral movement attacks can be effectively detected and defended, improving the accuracy of encrypted risk detection and enabling users to gain a more comprehensive understanding of attack behavior, thereby enabling more effective attack analysis and response.
Owner:HANGZHOU WEIMING XINKE TECH CO LTD +1

Cyber attack processing method and system, device, storage medium, and program product

Embodiments of the present disclosure provide a cyber attack processing method and system, a device, a storage medium, and a program product. In the process of performing security protection on a target host, when a suspicious behavior on the target host is detected, behavior data corresponding to the suspicious behavior may be acquired, and an interception rule corresponding to the suspicious behavior is acquired on the basis of the behavior data, wherein the interception rule is determined by using an attack analysis model. The attack analysis model is obtained by training behavior data samples of processes corresponding to historical cyber attack behaviors, and therefore, the attack analysis model can better grasp knowledge in the field of cyber attacks. When analyzing behavior data of a process of the suspicious behavior, the attack analysis model can more accurately identify and determine the behavior of the process, thereby generating a more adversarial interception rule. Therefore, it is convenient to quickly and accurately process potential security threats corresponding to suspicious behaviors, the risk of missing potential attacks is reduced, and the defensive capability is improved.
Owner:CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD +1

Attack analysis device

PendingCN120604231APlatform integrity maintainanceIn vehicleAttack analysis
An attack analysis device according to the present invention is provided with: an abnormality acquisition unit that acquires information relating to an abnormality of an in-vehicle device; a security event detection unit that detects a security event of the in-vehicle device; a distance acquisition unit that acquires a distance connecting a shortest path between an abnormal event occurrence location at which the abnormal event occurs and a security event occurrence location at which the security event occurs; and a determination unit that determines the relevance between the abnormal situation and the security event on the basis of the distance.
Owner:ASTEMO LTD

Attack analysis device, attack analysis method, and storage medium

An attack analysis device includes attack abnormality relationship information indicating a relationship among (i) attack information indicating an attack possible to be received by an electronic control system, (ii) an estimation abnormality information indicating an abnormality estimated to be occurred when the attack is received, and (iii) commonized estimation abnormality location information indicating a commonized estimation abnormality location, which is a location of the abnormality estimated to be occurred when the electronic control system receives the attack and commonized between the electronic control system and a different electronic control system. The attack analysis device estimates an attack received by the electronic control system with reference to the attack abnormality relationship information.
Owner:DENSO CORP

APT attack analysis technology based on LLM and RAG

The invention relates to an APT (Advanced Persistent Threat) attack analysis technology based on LLM (Logical Language Model) and RAG (Random Access Gateway), which is used for automatically analyzing an APT attack detection result and generating an APT survey report in a natural language form. The automatic APT attack analysis system provided by the invention comprises the following three key subsystems: 1, a CTI information extraction system based on LLM intelligent agent structure alignment: using an atlas extractor and an atlas inspector intelligent agent to automatically construct a CTI atlas structurally aligned with a traceability graph from CTI according to a predefined mode; and 2, an RAG system based on a GNN retrieval model: using a graph similarity matching model to retrieve a CTI graph corresponding to the traceability graph. And 3, an APT attack analysis system capable of autonomously and dynamically planning a reasoning process is used, so that traceable and automatic APT attack analysis of the reasoning process is realized. The method can be used for network attack analysis including but not limited to APT attacks, and the efficiency and accuracy of network attack analysis can be effectively improved.
Owner:BEIHANG UNIV

Safety alarm method, device and equipment based on chain analysis and medium

The invention discloses a security alarm method, device and equipment based on chain analysis and a medium, is applied to a security alarm system and relates to the technical field of network security, and the method comprises the following steps: constructing a target context object based on target data of a preset data source, and transmitting the target context object to a filtering node in an analysis link for data filtering, filtering to obtain a filtered object; determining data features of the filtered object, and sending the filtered object to a target analysis node corresponding to the data features in an analysis link for attack analysis to obtain an attack analysis result; and carrying out secondary attack analysis on the attack analysis result based on a preset analysis model, and pushing an obtained target processing result to a corresponding processing platform through an output node in an analysis link, so that the processing platform carries out corresponding security alarm or information pushing based on the target processing result. Therefore, it can be ensured that data of different types of processing nodes can be processed in time, and then alarm accuracy is ensured.
Owner:HANGZHOU ANHENG INFORMATION SECURITY TECH CO LTD

DDoS attack visual detection method based on multi-dimensional feature combination analysis

The application discloses a DDoS attack visual detection method based on multi-dimensional feature combination analysis, multi-dimensional traffic feature extraction, a lightweight attack detection model, DDoS attack knowledge graph construction, a graph-constrained attack behavior interpretation large model, attack visual detection display and the like to realize visual detection of network attacks. The application improves the visualization level and reduces the false alarm rate. The multi-dimensional feature combination method and the lightweight security detection model provide rich information for subsequent network attack knowledge graph establishment and professional interpretation based on a large language model. The constructed knowledge graph about network attacks can enhance the rigorousness of the thinking deduction of the large model and reduce the occurrence of model hallucinations. The enhanced large model can make more professional explanations and analyses on existing network attacks, thereby reducing the huge workload of manual attack analysis, and striving for a valuable time window for timely and accurate response to network attacks and deployment of defense.
Owner:BEIJING LANYUN TECH CO LTD +1

Artificial intelligence driven network intrusion detection method, system and equipment

The invention belongs to the technical field of network security detection, and provides an artificial intelligence-driven network intrusion detection method, system and device. The method comprises the steps of multi-source metadata extraction and preprocessing, causal feature discovery and selection, meta learning detection model reasoning, known attack screening, causal comparative analysis and branch judgment, adaptive threshold adjustment and interpretable report generation. According to the method, initial parameters of three layers of MLP are optimized by adopting an MAML framework, so that the model can be quickly adapted only by a small amount of fine tuning in a zero-day attack and few-sample scene, and the limitation that traditional machine learning depends on a large number of historical samples is broken through; meanwhile, by constructing a baseline normal causal graph and an abnormal causal graph, adopting GED to quantify the similarity of the two graphs and accurately distinguishing zero-day attack and concept drift based on a preset threshold value, the industrial pain point that zero-day attack detection is difficult is solved, misinformation caused by concept drift is avoided, it is ensured that resources are only used for real attack analysis, and the detection efficiency is improved.
Owner:INFORMATION & COMM CO OF STATE GRID XINJIANG ELECTRIC POWER CO LTD

Data attack protection system based on artificial intelligence

The invention relates to the technical field of data security, and discloses a data attack protection system based on artificial intelligence, comprising: acquiring internal data and external data for accessing an enterprise server and a database based on a data acquisition layer; obtaining internal characteristics of the internal data according to the internal data, wherein the internal characteristics are demission tendency values; and acquiring external characteristics of the external data according to the external data, wherein the external characteristics are external attack confidence coefficients. According to the method, the internal personnel behavior risk is dynamically associated with the external attack intention for the first time by constructing the composite threat model of the internal abnormal probability model and the external attack confidence coefficient, the model reinforces the external threat weight through parameter constraint, the defect of internal and external attack splitting analysis in a traditional scheme is effectively overcome, and the security of the internal and external attack is improved. The method can accurately recognize a composite attack scene in which an internal person leaks a certificate and cooperates with external invasion, and remarkably reduces the missing report rate.
Owner:GUANGXI POWER GRID CORP

A network attack research and judgment method, system, program product, device and medium

The embodiment of the application provides a network attack research and judgment method, system, program product, device and medium, the system deploys multiple intelligent agents, and the method comprises the following steps: inputting an attack sample into an attack feature extraction intelligent agent, constructing an attack feature library based on the extracted attack features; inputting a network security log into a field extraction intelligent agent, and obtaining the extracted attack related fields; inputting the attack feature library and the attack related fields into an attack analysis module, obtaining attack analysis data of the attack analysis module based on the attack feature library on the attack related fields; inputting threat intelligence data, asset data and attack analysis data into a comprehensive analysis report intelligent agent, obtaining an analysis report, including attack results, attack severity, influence range and attack technology; inputting the analysis report into an attack disposal module, and obtaining an attack disposal plan. The attack research and judgment process is realized by using the intelligent agent, the analysis and judgment capability for the known attack is improved, the unknown attack behavior is identified, and the closed-loop protection measure is formed.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

APT detection and analysis method

The invention relates to the technical field of network attack protection, and discloses an APT detection and analysis method, which comprises the following steps of: obtaining a plurality of multi-source audit logs of a target network in a time sequence and key log data in each multi-source audit log, and combining all the key log data to obtain a key log data group; obtaining an APT hidden attack characteristic value according to the change condition of each key log data set; calculating an APT attack analysis coefficient according to the feature metric value; the method comprises the steps of detecting and analyzing key log data in a sequential sequence, presetting an APT attack analysis coefficient, judging whether a target network has an APT attack risk or not according to the APT attack analysis coefficient and the preset APT attack analysis coefficient, determining a feature value of an APT hidden attack behavior by detecting and analyzing a change condition of the key log data in the sequential sequence, and realizing intelligent assessment of the APT attack risk, so that the accuracy of risk detection is improved. And the stability and security of the target network are ensured.
Owner:HUANENG INFORMATION TECH CO LTD

An APT attack analysis method for a software-defined deception defense system

This invention discloses an APT attack analysis method for software-defined deception defense systems. Addressing the limitations of existing methods in handling dispersed attack behaviors and the lack of associations for new entities, this method first constructs an APT knowledge graph by extracting threat intelligence. Second, it integrates newly captured attack entities from deception nodes, using semantic and interactive discriminant models to filter and determine attack associations. Then, it constructs attack chain paths reflecting the attack evolution logic by performing multi-hop concatenation based on predicted relation triples. Finally, it extracts path features for risk quantification assessment and dynamically optimizes the deployment and configuration strategies of decoy resources accordingly. This method integrates fragmented attack behaviors into a continuous path structure, enabling the calculability of risk intensity and directly linking analysis results to defense strategies, significantly improving the dynamic response capability and resource utilization efficiency of the deception defense system.
Owner:GUANGZHOU UNIVERSITY HUANGPU RESEARCH INSTITUTE +1

Attack analysis device, attack analysis method, and attack analysis program

An attack analysis device (100) comprises an analysis priority change unit (130) for changing an analysis priority according to a target device based on the content of a targeted attack when the target device is exposed to the targeted attack, which is a cyberattack. The device is a target device available to an attack targeting system comprising a plurality of devices, each assigned an analysis priority. Assuming that the plurality of devices available to the attack targeting system constitute an attack targeting device group, and that the devices contained in the attack targeting device group are exposed to cyberattacks, the cyberattacks against the devices contained in the attack targeting device group are analyzed in sequence according to the analysis priorities corresponding to the devices contained in the attack targeting device group.
Owner:MITSUBISHI ELECTRIC CORP

An industrial control protocol identification and attack resistance processing method, system and server

PendingCN122394935ADistribution controlAttack
The application discloses a kind of industrial control protocol identification and attack processing method, system and server, and relates to data processing. Multiple-source interaction records in industrial control network are acquired to construct protocol attachment track and assign control location identification, and based on control location identification, occupation relationship and protocol shadow chain are formed. Real-time messages are mapped to protocol shadow chain to perform occupation verification to identify free control fragments, and active probing behavior is identified in combination with detection control location identification. Control is decoupled for abnormal behavior and imported into a limited redemption channel to form attack analysis texture, and based on attack analysis texture, traceability identification, hierarchical disposal and protocol attachment track and protocol shadow chain are synchronously updated. By implementing the technical solution, in a complex network environment where the host station and the field device are located, the context loss problem caused by the difficulty in reconstructing the protocol session due to the attack behavior of the attacker is solved, so as to improve the accuracy of industrial control protocol identification, enhance the anti-attack capability and improve the control accuracy of the industrial control system.
Owner:HANXING TONGHENG TECH GRP CO LTD +2

Network vulnerability visualization mining analysis system

ActiveCN121530758BSecuring communicationAttackVisual mining
The present application relates to the technical field of security protocol vulnerability analysis, and discloses a network vulnerability visual mining and analysis system, which comprises an extraction unit, a security analysis unit, a protocol mapping unit, a vulnerability identification unit, an attack analysis unit and a vulnerability mining unit. Through the cooperative analysis of the multiple units, a visual protocol vulnerability atlas is finally generated, handshake stage version negotiation sequence and state conversion can be clearly presented, version rollback points and downgrade attack abnormal patterns are directly exposed, security state and attack influence are determined, vulnerability identification accuracy and analysis efficiency are improved, and dynamic and visual security protection is provided for enterprise intranet multi-TLS protocol version service.
Owner:HANGZHOU HUAYI ZHILIAN TECHNOLOGY CO LTD

A honeynet-based attack trapping and analysis method and system

The application discloses a kind of attack trapping and analysis method and system based on honeynet, it is related to attack analysis technical field, including: attack interaction data and associated attack chain trajectory set are collected;Divide attack behavior unit, construct behavior space posture matrix;Two-dimensional behavior relationship atlas is constructed, interpolation enhancement is carried out to sub-time granularity, and the behavior node after interpolation is upgraded to three-dimensional semantic space;Attack path trend analysis is carried out to attack behavior unit, and attack path bending law model is constructed;Attack chain trajectory set, the behavior node in three-dimensional semantic space and the like parameter are input into attack path bending law model, and output is trapping response strategy, and dynamically adjusts honeynet environment.The application can automatically adjust honeypot type and position according to attack behavior change, effectively improve the structural clarity and processing precision of attack behavior data, and facilitate to directly use attack behavior identification result for trapping strategy optimization.
Owner:INFORMATION & COMMNUNICATION BRANCH STATE GRID JIANGXI ELECTRIC POWER CO

Single machine-cloud honeypot defense method based on open Internet

The invention discloses a stand-alone-cloud honeypot defense method based on the open Internet, and the method comprises the following steps: building of a decoy environment, including stand-alone honeypot defense and cloud honeypot defense, decoy attackers to actively attack by simulating different types of vulnerabilities and traps, monitoring of intrusion behaviors, and building of a cloud honeypot defense system. The behaviors of an attacker are monitored and recorded in detail by setting built-in monitoring software and an external monitoring system, and post-processing measures comprise information extraction for attack analysis, alarm generation, vulnerability repair and defense, reverse tracking (traceability) of an attack source and legal action taking. The invention belongs to the field of network security, and particularly relates to a stand-alone-cloud honeypot defense method based on the open Internet.
Owner:DONGGONG RISHENG (CHENGDU) TECHNOLOGY CO LTD

Visual mining and analyzing system for network vulnerabilities

ActiveCN121530758ASecuring communicationAttackVisual mining
The invention relates to the technical field of security protocol vulnerability analysis, and discloses a network vulnerability visual mining analysis system, which comprises an extraction unit, a security analysis unit, a protocol mapping unit, a vulnerability identification unit, an attack analysis unit and a vulnerability mining unit, and finally generates a visual protocol vulnerability graph through collaborative analysis of a plurality of units. According to the method, a version negotiation sequence and state conversion in a handshake stage can be clearly presented, a version backspace point and a degradation attack abnormal mode are visually exposed, a security state and attack influence are determined, vulnerability identification accuracy and analysis efficiency are improved, and dynamic and visual security protection is provided for enterprise intranet multi-TLS protocol version service.
Owner:HANGZHOU HUAYI ZHILIAN TECHNOLOGY CO LTD

Correlating compromised home internet of things devices with distributed denial of service attacks

ActiveUS12676883B2Internet privacyAttack
A distributed denial of service (“DDoS”) attack profiler can determine a plurality of DDoS attack properties associated with a DDoS attack that utilizes an Internet of Things (“IoT”) device operating in communication with a home gateway. The DDoS attack profiler can create a DDoS attack profile and can provide a DDoS attack report based upon the DDoS attack profile to a correlator. An IoT device profiler can determine a plurality of IoT device properties and can create, based upon the plurality of IoT device properties, an IoT device profile. The IoT device profiler can create an anomaly report that identifies an anomaly associated with the IoT device. The correlator can correlate the DDoS attack report with the anomaly report to determine if a match exists. In response to determining that the match exists, the home gateway system can store the bot match record in a bot match repository.
Owner:AT&T INTELLECTUAL PROPERTY I L P

Social Engineering Threat Assessment Platform (SETAP)

The present disclosure provides a method, a computing platform, and a system for social engineering threat assessment. The method, conducted by a computing platform having one or more processors, includes converting social engineering threat data into one or more templates, simulating one or more social engineering attacks for a target based on the one or more templates, analyzing the one or more simulated social engineering attacks for the target; executing the one or more simulated social engineering attacks for the target based on analysis results by initiating one or more simulated vishing phone calls to the target, receiving, from a computing device associated with the target, response data responsive to the one or more simulated vishing phone calls, and providing, as feedback, execution results to one or more parties.
Owner:BANK OF AMERICA CORP