Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

92 results about "Attack graph" patented technology

Security event automatic response method based on knowledge graph

The invention provides a knowledge graph-based security event automatic response method, which comprises the following steps of: acquiring multi-source security data, performing de-duplication and standardization processing, and generating a structured security data set; based on the network security ontology model, entities and relationships are extracted from the data set, and a security knowledge graph is constructed through entity alignment and conflict resolution; according to ATTamp; the CK framework divides network subnets, generates attack path diagrams of the subnets, and fuses the attack path diagrams into a global attack graph. Then, abnormal behavior nodes in the security knowledge graph are analyzed, and risk scores of the service layer, the host layer and the system layer are calculated in combination with the global attack graph; and matching a predefined response strategy library based on the risk scores, executing operations such as banning an IP (Internet Protocol), isolating a host or updating firewall rules and the like through an SOAR platform, generating a disposal report and updating a security knowledge graph. According to the invention, the network security event processing efficiency and accuracy can be improved, and the overall security protection capability of the system is enhanced.
Owner:HUANENG INFORMATION TECH CO LTD

Intelligent construction and tracing method and device of attack graph

The invention discloses an intelligent construction and tracing method and device for an attack graph, and relates to the technical field of network security. The method comprises the steps of performing semantic analysis and entity relationship extraction on a multi-source heterogeneous security log according to a predefined structured security data model, and generating a standardized security entity relationship triple set; based on the set, taking an entity in an initial alarm as a starting point, and adopting an iterative closed loop driven by a large language model to dynamically construct an attack graph; and carrying out attack technique and tactics mapping and threat attribution based on the final map, and generating a response strategy of priority ranking. According to the method, automatic and high-precision source tracing and response of the attack chain are realized, and the problems that the prior art depends on static rules and semantic segmentation and lacks dynamic reasoning capability are effectively solved.
Owner:BEIJING CHAITIN TECH CO LTD

Open source component multi-mode dependence risk tracing method and device

The invention relates to an open source component multi-modal dependency risk tracing method and device, and the method comprises the steps: employing a mode of combining static analysis and dynamic analysis to analyze a component dependency relationship of software, and combining AST analysis and construction script analysis; function-level features are extracted, a binary fingerprint database is constructed, the similarity between different versions is analyzed through LSH, behavior patterns in binary codes are analyzed, and hidden dependencies or malicious code injection is detected; the version updating history of the dependent component is analyzed and monitored by using a time sequence, and the vulnerability security of the component is evaluated in combination with attack graph analysis; high-risk components on the path are calculated, potential supply chain attack points are identified, and risk points are subjected to cross validation; a time sequence diagram database is used for recording the component dependency relationship, and time backtracking query is supported. According to the method, a multi-mode dependency analysis method is adopted, potential dependency risks are rapidly identified, and potential supply chain attack risks are timely warned.
Owner:FUJIAN YIRONG INFORMATION TECH +1

Network security attack path prediction system based on graph neural network

The invention discloses a network security attack path prediction system based on a graph neural network, and relates to the technical field of network security, and the system comprises a data collection module which collects network full-link time sequence security data, and outputs standardized time sequence data through time sequence alignment and abnormal noise reduction processing; the time sequence diagram construction module is used for constructing a dynamic attack graph containing nodes and time sequence edges; the feature learning module introduces a time sequence attention mechanism, calculates a time-space fusion attention coefficient based on a graph attention network framework, and outputs a node embedding vector; the reasoning and pruning module is used for generating attack paths based on node embedding vectors and outputting a high-value attack path set; and the analysis decision module is used for carrying out importance sorting on all nodes on the high-value attack path, determining a path core risk point and generating a key node decision basis of the attack path. According to the method, the problem that the traditional technology cannot accurately capture the attack behavior time sequence dependence is solved, and the high-precision prediction of the attack path is realized.
Owner:CHINA POWER INVESTMENT NORTHEAST NEW ENERGY DEV CO LTD

Network security defense strategy optimization method based on machine learning

The invention relates to the field of network security, and particularly discloses a network security defense strategy optimization method based on machine learning, and the method comprises the steps: aggregating isolated security events into attack activity clusters through causal association analysis, constructing a dynamically evolved global attack graph, and improving a defense perspective from a discrete event to a full combat view. In order to realize foresight, a graph neural network is utilized to analyze a graph to identify attack tactics and predict the next intention. A hierarchical reinforcement learning framework is innovatively introduced in the decision-making stage; an upper-layer strategic agent formulates a macroscopic defense target based on a global situation; and the lower-layer tactical agent focuses on the related attack sub-graph under the strategic guidance, and selects and executes the specific tactical action which can reach the target most. The strategy and tactical separated decision-making mode ensures that each defense action serves a long-distance target, so that strategic passivity caused by only taking care of previous threats is avoided.
Owner:STATE GRID HENAN INFORMATION & TELECOMM CO +1

Virtual simulation and security evaluation method and system based on network security target range

The invention discloses a virtual simulation and security evaluation method and system based on a network security target range, and the method comprises the steps: constructing a network asset knowledge graph for describing a virtualized target range environment through information collection; secondly, based on an attack strategy grammar rule base, adopting a Monte Carlo Tree Search (MCTS) algorithm to carry out intelligent attack simulation on the knowledge graph so as to discover a nonlinear and multi-stage attack path; thirdly, constructing a Bayesian attack graph (BAG) based on the knowledge graph, and performing probabilistic and systematic quantitative evaluation on the security risk of each asset node in the network through Bayesian reasoning; and finally, integrating the attack path and the quantitative risk value, and generating a comprehensive assessment report containing a visual path, a risk sequence and a reinforcement suggestion. According to the target range simulation method and device, the problems that existing target range simulation is insufficient in confrontation authenticity, one-sided in safety evaluation and lack of predictability are solved by combining the strategy simulation of the MCTS and the global quantitative analysis of the BAG.
Owner:BEIJING BO YI WANG XUN SCI & TECH CO LTD

Penetration testing method and device, electronic equipment, storage medium and program product

The invention provides a penetration test method and device, electronic equipment, a storage medium and a program product, relates to the technical field of computers, and is used for improving penetration test efficiency. The method comprises the steps of obtaining a network topological graph of a target system, and then generating an attack graph of the target system based on the network topological graph and vulnerability information of each node in the target system; the attack income of each attack path in the attack graph is calculated, and a target attack path with the maximum attack income is obtained; and performing penetration testing based on the target attack path.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD

Cross-domain threat prediction method based on vulnerability analysis and related equipment

The invention discloses a cross-domain threat prediction method based on vulnerability analysis and related equipment, and the method comprises the steps: obtaining a network connection graph and first vulnerability information, carrying out the integration of the network connection graph and the first vulnerability information, and generating the input data of an attack graph generation tool; obtaining a PLC control logic, and generating a target dependency graph according to the PLC control logic; obtaining a logic node according to the target dependency graph; mapping the logic node to a field device in an industrial control system to obtain an attack target; generating an attribute attack graph through the attack graph generation tool according to a preset initial position of an attacker, the attack target and the input data; and extracting a target attack path according to the attribute attack graph to obtain a cross-domain threat prediction result. The method can improve the accuracy of cross-domain threat prediction, and can be widely applied to the technical field of network security and industrial control system security.
Owner:GUANGZHOU UNIVERSITY

Attack detection and processing method and device, electronic equipment, medium and program product

PendingCN121012662ASecuring communicationEntity relation diagramAttack
The invention provides an attack detection and processing method and device, electronic equipment, a medium and a program product, and can be applied to the technical field of big data, the technical field of artificial intelligence and the field of financial science and technology. The method comprises the following steps: acquiring multi-source network security data, and constructing an entity relation graph based on the multi-source network security data; carrying out attack chain analysis on the entity relation graph to obtain an attack chain analysis result; constructing an attack graph based on the attack chain analysis result; and generating a processing strategy based on the attack graph, and executing the processing strategy in response to the fact that the processing strategy is verified to have no service influence.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Self-adaptive security event response method and system based on AI intelligent agent

The invention relates to a self-adaptive security event response method and system based on an AI agent, and belongs to the field of network security, and the method comprises the steps: in an event sensing stage, the AI agent obtains a first to-be-evaluated event according to network multi-source security data collected in real time; in the risk assessment stage, the AI agent obtains an attack graph of a network, and performs adaptive risk analysis on a plurality of paths of a first to-be-assessed event in the attack graph to obtain a security path of the first to-be-assessed event; in the intelligent decision-making stage, the AI agent generates a response decision of the first to-be-evaluated event according to the safety path; and in the response execution stage, the AI agent executes a corresponding safety protection action according to the response decision. The application can improve response efficiency of network security, reduce manual dependence and manual intervention, timely perceive security events and avoid expansion of network asset loss, is suitable for large-scale and diversified network security protection scenes, and can improve protection capability of novel threats.
Owner:BEIJING HUAQING XINAN TECH CO LTD

Automatic penetration test path planning method and system based on agent collaboration

The invention discloses an automatic penetration test path planning method and system based on agent collaboration, and relates to the technical field of network security. Performing initialization starting on the plurality of intelligent agents based on the penetration test target range; collecting the target system and writing the target system into a shared blackboard mechanism; matching the asset feature information with a preset vulnerability knowledge base according to the test strategy mode to generate vulnerability utilization conditions, and constructing a global attack graph according to the asset feature information and the vulnerability utilization conditions; generating an attack path based on the global attack map, executing an attack operation on the target system according to an attack step sequence of the attack path, when an execution result is failure, updating the global attack map according to a feedback failure result, and re-planning to generate a new attack step sequence; and when the execution result is successful, generating a penetration test report for the penetration test target range according to the success result. By implementing the method, the actual demand of deep security assessment of the complex heterogeneous system is met.
Owner:BEIJING YUHONG XINAN TECHNOLOGY CO LTD

Network protection

A computer-implemented method of protecting a network is provided. The method receives security alert data from one or more intrusion detection systems. The security alert data comprises a plurality of security alerts relating to the network. The method generates a plurality of similarity matrices from the security alert data. Each similarity matrix is generated using a different respective similarity function and indicates a respective similarity between each of the security alerts according to that similarity function. The method generates one or more attack graphs from the plurality of similarity matrices. Each attack graph represents a respective set of security alerts, wherein a similarity between each of the security alerts in the set, according to at least one of the similarity matrices, is above a predefined threshold. The method causes one or more predetermined actions to be taken with respect to the network to mitigate a respective attack represented by each of the attack graphs.
Owner:BRITISH TELECOM PLC

A honeycomb array graph dynamic pre-scheduling method based on attack chain timing prediction

PendingCN122640252AAlgorithmInternet traffic
The application provides a honeycomb graph dynamic pre-scheduling method based on attack chain timing prediction, relates to the network security active defense technical field, and comprises attack chain timing sensing and feature preprocessing, dynamic attack graph construction, timing graph neural network attack chain path prediction and array graph pre-scheduling implementation. The application solves the multi-source asynchronous problem by fusing network traffic, host logs and threat intelligence and using timestamp alignment and current interpolation, constructs an attack graph which has timing state and topological correlation, and designs a joint prediction model which adopts a graph attention mechanism to capture topological dependence in space dimension and adopts a gated timing convolution to capture long-term evolution in time dimension.
Owner:INFORMATION & COMMNUNICATION BRANCH STATE GRID JIANGXI ELECTRIC POWER CO

Transverse movement attack path analysis method and system based on virtualized trap network

The invention relates to the technical field of honeypot trapping networks, in particular to a transverse movement attack path analysis method and system based on a virtualized trapping network. The method comprises the steps that system logs of N network nodes in the virtualized trapping network are collected regularly, honeypot servers are deployed in all the network nodes in the virtualized trapping network, and N is an integer larger than or equal to 1; updating the constructed attack path according to the association degree between the system log of the Nth network node and the constructed attack path; traversing the system logs of the N network nodes until the system logs collected in the current period are processed. According to the method, all the log data in all the nodes in the virtualized trapping network are integrated, and a complete and comprehensive attack graph is established, so that comprehensive analysis of cross-system and cross-device behaviors of attackers is realized, and the depth and accuracy of existing analysis are improved.
Owner:GUANGZHOU UNIVERSITY

A vulnerability risk assessment method and apparatus

The application provides a vulnerability risk assessment method and device, constructs a vulnerability attack graph based on an attack path of a system vulnerability, determines an attack income degree in a Nash equilibrium situation based on a fuzzy vulnerability game model as a vulnerability importance degree of a target vulnerability in the vulnerability attack graph, represents the income degree through a triangular fuzzy number, solves the Nash equilibrium after defuzzification, determines a risk parameter of the target vulnerability in combination with the vulnerability importance degree of the target vulnerability, a vulnerability propagation loss and a vulnerability cumulative probability, the attack graph can correlate and comprehensively analyze the vulnerabilities in the network, the game theory can consider the restriction relationship of the attack and defense sides, therefore, on the basis of analyzing the logical relationship of the vulnerabilities, the attack and defense restriction relationship is considered, the defuzzification of the fuzzy number solves the problem that the attack and defense income degree is difficult to quantify due to the uncertainty and fuzziness of the information system, thereby the cumulative probability and the risk parameter of the vulnerability are quantitatively analyzed, and the accuracy of the vulnerability risk assessment is improved.
Owner:AGRICULTURAL BANK OF CHINA

Side-end equipment threat disposal decision-making method, system, equipment and medium

The invention discloses a side-end equipment threat disposal decision-making method, system, equipment and medium, and the method comprises the steps: obtaining an intrusion index of side-end equipment, carrying out the correlation analysis of the intrusion index and a predefined mapping rule, and generating an attack sequence; matching the attack sequence with a predefined attack graph to obtain a target attack graph matched with the attack sequence; constructing an attack action-defense measure mapping table, and mapping and generating a corresponding candidate defense measure list for each attack step node in the target attack graph; comprehensively scoring each defensive measure in the candidate defensive measure list by using a multi-criterion decision-making method to obtain an attack graph containing optimal defensive measure attributes; an attack defense tree is constructed on the basis of an attack graph, security arrangement and automatic response are triggered according to measures in the attack defense tree, and optimal measures are executed, so that more comprehensive attack situation understanding and reasonable distribution of limited security resources are realized.
Owner:GUANGXI POWER GRID CORP

A method and system for assessing vulnerabilities in network communication transmission nodes

This invention belongs to the technical field of computer network security and relates to a method and system for assessing vulnerabilities in network communication transmission nodes. The method includes: matching vulnerabilities based on static attributes of communication nodes, analyzing their exploitation prerequisites and impacts to generate an asset knowledge base; analyzing network topology and access control permissions to generate potential communication topologies; collecting information such as session connections and process activities, and encapsulating it into critical state transition events; determining whether the transition events meet the vulnerability exploitation prerequisites and updating the logical state; generating dynamic attack paths based on the updated logical state and communication topology, constructing a complete attack graph, and calculating a network-wide vulnerability risk score; simulating intervention measures for nodes with risk exposure values ​​greater than a preset threshold, and generating defense hardening strategies based on changes in the risk score. This invention addresses the problem of insufficient accuracy and timeliness in risk assessment results.
Owner:BEIJING JUNAN ZHONGKE INFORMATION TECHNOLOGY CO LTD

Network security target field-based virtual simulation and security evaluation method and system

The application discloses a network security target-based virtual simulation and security evaluation method and system. First, a network asset knowledge graph describing a virtual target environment is constructed through information collection. Second, intelligent attack simulation is performed on the knowledge graph based on an attack strategy syntax rule library using a Monte Carlo tree search (MCTS) algorithm to discover nonlinear and multi-stage attack paths. Third, a Bayesian attack graph (BAG) is constructed based on the knowledge graph to probabilistically and systematically quantitatively evaluate the security risks of asset nodes in the network through Bayesian inference. Finally, the attack paths and quantitative risk values are integrated to generate a comprehensive evaluation report containing visualized paths, risk rankings and reinforcement suggestions. The application solves the problems of insufficient realism of existing target simulation, one-sided security evaluation and lack of predictability by combining strategic simulation of MCTS and global quantitative analysis of BAG.
Owner:BEIJING BO YI WANG XUN SCI & TECH CO LTD

Multimodal large-scale jailbreak risk detection and defense methods and electronic devices

This application discloses a multimodal large-scale jailbreak risk detection and defense method and an electronic device. The method acquires original malicious commands and constructs visual and textual embedding features based on these commands, fusing them to form multimodal embedding fusion features. Based on these features, it generates a model response to the original malicious commands and a jailbreak attack evaluation type for the model response. If a successful jailbreak attack is determined, the corresponding attack text and image are used as the jailbreak attack scheme, and then the model jailbreak risk detection and defense processing is performed based on this scheme. This application, through multimodal embedding fusion features, deeply explores the semantic relationships and feature essence of test commands, extracts the attack text and image combinations of successful jailbreak scenarios, and constructs a jailbreak attack scheme that combines concealment and attack. Based on this, targeted model jailbreak risk detection and defense processing is carried out, improving the model's ability to identify and defend against jailbreak attacks in multimodal scenarios.
Owner:BEIJING QIHOOD TECHNOLOGY CO LTD

Threat assessment method based on logic attack graph, ATTCK and CVSS

The invention discloses a method based on a logic attack graph and ATTamp; the invention discloses a threat assessment method for CK and CVSS, and the method comprises the steps: firstly obtaining preposition information needed by the successful implementation of a technology based on a minimum dependency set theory, setting predicate parameters, selecting proper predicates according to a preset target to form a necessary minimum condition set needed by an inference rule, and finally forming a rule set needed by the input of a MulVAL tool; meanwhile, constructing an input file of a MulVAL tool, and generating a logic attack graph and an attack chain by using the MulVAL tool; then constructing a technical node evaluation model and a vulnerability node evaluation model to comprehensively evaluate nodes in the logic attack graph, and performing normalization processing to obtain risk scores of the nodes; and finally, sorting the risk scores of the nodes according to the node types and reflecting the sorted risk scores in a logic attack graph. According to the method, the understanding depth of a potential attack path is improved, the accuracy of threat degree measurement is ensured, and then high-credibility threat information on an attack graph is fully reflected.
Owner:GUANGZHOU UNIVERSITY +1

Camouflage node deployment method and device, medium and electronic equipment

The invention provides a disguised node deployment method and device, a medium and electronic equipment. The disguised node deployment method comprises the steps of performing structured modeling according to threat intelligence, constructing a Bayesian attack graph, and identifying a key node set and a high-risk path set; constructing an attack and defense strategy according to the key node set, the high-risk path set and the defense deployment condition, performing deployment intention deduction to obtain a candidate deployment set, generating corresponding low-level fingerprint features and high-level interaction features based on the candidate deployment set, and obtaining a disguised node candidate set meeting the consistency requirement; performing deployment training based on the camouflage node candidate set to obtain an optimal strategy function; and selecting an optimal action according to the optimal strategy function, and performing disguised node deployment updating according to the optimal action. By applying the method, the defense system can be endowed with rapid adaptive capacity to environment change, and the authenticity, diversity and intelligent level of the defense system in a complex APT attack scene are improved.
Owner:INFORMATION & COMMNUNICATION BRANCH STATE GRID JIANGXI ELECTRIC POWER CO

Attack graph generation method and system for industrial control systems

This invention provides a method and system for generating attack graphs for industrial control systems. The method includes: extracting comprehensive risk data of the industrial control system to generate ATT&CK initial attack tactic probabilities, ATT&CK attack technique selection probabilities, ATT&CK attack tactic jump probabilities, and the system topology of the industrial control system; generating optimal attack sequences between devices in the industrial control system based on a hidden Markov model according to the ATT&CK initial attack tactic probabilities, ATT&CK attack technique selection probabilities, and ATT&CK attack tactic jump probabilities; and generating an attack graph based on the system topology and optimal attack sequences of the industrial control system. This invention improves the efficiency and comprehensiveness of risk assessment for industrial control systems by comprehensively extracting comprehensive risk data and generating optimal attack sequences between devices to produce attack graphs for assessing the risks of industrial control systems.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

Railway vehicle network security risk detection method, device, equipment and medium

The invention discloses a rail vehicle network security risk detection method, device and equipment and a medium, and relates to the technical field of rail transit. According to the scheme, the network security knowledge graph is constructed in advance and comprises entities generated by fusing network security knowledge, threat intelligence, environment data and behavior data and the relationship of the entities, establishment of the railway vehicle network security special threat intelligence library is achieved, and a verification foundation is laid for railway vehicle attack risk perception; furthermore, each node in the topological structure of the railway vehicle network system is analyzed based on the network security knowledge graph to generate an attack graph containing an attack path, so that the detected attack is associated with a potential attack path, and automatic generation of the attack graph and comprehensive analysis of the attack path are realized; and finally, the network security score of each node in the topological structure of the railway vehicle network system is determined according to the attack graph, so that quantitative evaluation of the security of the network system is realized, and the security of the railway vehicle network is determined more intuitively.
Owner:NAT HIGH SPEED TRAIN QINGDAO TECH INNOVATION CENT

System and method for dynamic network security risk identification based on multi-source information and ai driving

The application relates to the technical field of network security, and discloses a dynamic network security risk identification system and method based on multi-source intelligence and AI driving, which comprises a dynamic attack graph modeling module, an AI-driven attack simulation engine and a cooperation module.The modeling module fuses multi-source heterogeneous intelligence to construct a network attack graph and calculate node intelligence confidence; the AI engine takes the confidence into a state space, uses a dynamic entropy mechanism to real-time adjust the randomness of reinforcement learning exploration to accurately simulate an attack path; and the cooperation module links external attack surface management and a security operation center to execute closed-loop feedback verification of automatic defense response and path elimination.The application establishes a mapping relationship between intelligence confidence and exploration strategy, effectively solves the problems of uneven multi-source data quality and unknown path missing report, realizes an automatic closed loop from risk perception, simulation deduction to effect verification, and significantly improves risk identification accuracy and response timeliness.
Owner:CSG EHV POWER TRANSMISSION

A cloud-edge-end power internet of things vulnerability hazard assessment method and system

A cloud-edge-end power internet of things vulnerability hazard evaluation method and system. The method comprises the following steps: determining an influence factor score and a exploitability factor score of a target vulnerability based on the type of the target vulnerability; calculating a weight using an entropy weight method to determine a basic characteristic evaluation value; determining a time influence evaluation value according to the average time of the target vulnerability being exploited and the number of days of existence; obtaining the data value of a cloud server, the computing resource value of an edge server and the device usage rate of a terminal device, calculating the cloud server value, the edge server value and the terminal value in combination with the deployment quantity and the business value, determining a network asset risk evaluation value based on a bidirectional penetration attack graph; and evaluating the hazard level of the target vulnerability based on the basic characteristic evaluation value, the time influence evaluation value and the network asset risk evaluation value. The scheme improves the accuracy and reliability of the cloud-edge-end power internet of things vulnerability evaluation.
Owner:WUXI POWER SUPPLY BRANCH OF STATE GRID JIANGSU ELECTRIC POWER CO LTD

Artificial intelligence based network security enhancement method and system

The application relates to the field of network security, and particularly relates to a network security enhancement method and system based on artificial intelligence, which comprises the following steps: security data fusion, attack path modeling, node risk identification, abnormality detection model construction and dynamic response decision-making.The application introduces a learnable disturbance sensitive factor on the basis of a consistent attack graph, dynamically adjusts node relations output by a graph attention mechanism, improves the expression capability of a graph structure and the accuracy of attack path identification, and generates attack path information with stronger noise resistance through graph neural network modeling after structure enhancement, and realizes high-precision reasoning of a cross-stage and multi-path attack chain in combination with feature alignment and path fusion technology.The system comprises a security data fusion module, an attack path modeling module, a node risk identification module, an abnormality detection model construction module and a dynamic response decision-making module.
Owner:数力聚(北京)科技有限公司

Honeypot deployment method and device fusing Bayesian attack graph and reinforcement learning algorithm, and computer equipment

The invention relates to a honeypot deployment method and device fusing a Bayesian attack graph and a reinforcement learning algorithm, computer equipment, a computer readable storage medium and a computer program product. The method comprises the following steps: acquiring network observation data associated with an abnormal network activity when detecting that the abnormal network activity exists in a target network; determining updated attack information according to the network observation data and a Bayesian attack graph corresponding to the target network; the updated attack information represents the updated belief state and the updated attack path probability; according to the updated attack information, a defense strategy set for the target network is optimized through a reinforcement learning algorithm, and a honeypot deployment strategy is output based on the updated defense strategy; the attacked probability and the defense efficiency of the target node meet preset conditions; and according to the honeypot deployment strategy, deploying preset honeypot resources on the target node. By adopting the method, the capability of resisting network attack behaviors can be improved.
Owner:CHINA SOUTHERN POWER GRID COMPANY

Methods, systems, equipment and media for multi-source threat intelligence analysis of power information networks

ActiveCN120979831BSemantic analysisKnowledge representationCyber threat intelligenceAttack
This invention relates to the field of threat intelligence analysis technology for power information networks, and provides a method, system, device, and medium for multi-source threat intelligence analysis of power information networks. The method includes acquiring multi-source threat intelligence data to be analyzed from the power information network; extracting and analyzing attack entity relationships from the text intelligence data based on a preset attack entity data model and a preset entity association pattern table to generate an attack reconstruction master graph; extracting and analyzing attack entity relationships from the vulnerability code based on a preset code model and an attack entity retrieval database to generate several attack reconstruction sub-graphs; and merging the attack reconstruction master graph and the various attack reconstruction sub-graphs to generate a target attack reconstruction graph. This invention improves the accuracy and comprehensiveness of attack entity identification by combining an attack entity relationship extraction mechanism based on a unified attack entity data model with a multi-source attack graph reconstruction mechanism, ensuring the reliability of threat detection and attack tracing, and enhancing the security defense capabilities of power information networks.
Owner:STATE GRID ZHEJIANG ELECTRIC POWER CO LTD HANGZHOU POWER SUPPLY CO

Network monitoring with multiple attack graphs

A computer-implemented method for monitoring a computer network is provided, the method comprising: storing a first attack graph, the attack graph comprising a plurality of nodes each representing an event that may occur within the computer network; storing one or more predetermined variation properties of one or more of the events represented by the nodes, the variation properties being indicative of possible changes to the nodes within the first attack graph; determining a plurality of possible alternative sequences of the nodes in the first attack graph based on the variation properties; generating a plurality of additional attack graphs, each of the additional attack graphs comprising a plurality of the nodes of the first attack graph arranged in one of the possible sequences; and monitoring events within the network to detect a set of events occurring in a sequence that corresponds to one of the additional attack graphs to identify a potential security attack. A computer system including at least one processor and memory storing computer program code configured to perform the said method, and a computer program or computer readable medium comprising instructions that when executed by a computer system cause the computer system to perform the said method are also provided.
Owner:BRITISH TELECOM PLC

APT attack path backtracking system based on artificial intelligence

The invention relates to the field of artificial intelligence, in particular to an APT attack path backtracking system based on artificial intelligence, which comprises a multi-source security data acquisition module, a time sequence-semantic hybrid attack graph construction module, an AI-driven attack path reasoning module, an anti-factual causal evaluation module, an evidence credible encapsulation module and a visualization module, according to the scheme, a'time sequence-semantic hybrid attack graph 'is provided, and multi-scale time representation and semantic features are coded on nodes and edges of the graph at the same time, so that composite modeling of attack entities, behavior semantics and time evolution laws is realized, multi-dimensional features of APT attacks are reflected more comprehensively, and the problem of insufficient attack graph expression in the prior art is solved; the method combines an AI-driven reasoning module and an anti-fact causal evaluation mechanism, carries out the dynamic backtracking and verification of an attack path, guarantees the traceability and credibility of a result through evidence credible packaging, and overcomes the defects of fuzzy causal relationship and low path recognition precision of an existing method.
Owner:MIANYANG TEACHERS COLLEGE