Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

156 results about "Attack graph" patented technology

Network security space surveying and mapping method, system and equipment based on multi-source data fusion

The invention relates to the field of security surveying and mapping, in particular to a network security space surveying and mapping method, system and device based on multi-source data fusion, and the method comprises the steps: obtaining network security data in real time, and constructing a dynamic network topological graph; calculating a time-varying vulnerability score based on the topological graph and a historical attack log, and predicting an attack path and a propagation probability through a Bayesian network; performing cross-domain fusion on equipment, service and user behavior characteristics by adopting a federated learning framework to generate a dynamic asset portrait; generating a risk thermodynamic diagram in combination with spatial autocorrelation analysis and a multi-index fusion algorithm; a defense strategy effect is simulated based on an attack graph reconstruction engine, a Pareto optimal strategy combination is generated through an NSGA-II algorithm, and closed-loop verification and dynamic parameter correction are realized by utilizing honeypot deployment and flow traction. Therefore, the problems of topology update lag, single risk assessment dimension, cross-domain threat association fracture, defense strategy static stiffness, non-closed loop of a verification system and the like in the traditional technology are solved.
Owner:ELECTRIC POWER SCI RES INST OF STATE GRID XINJIANG ELECTRIC POWER CO LTD

Security event automatic response method based on knowledge graph

The invention provides a knowledge graph-based security event automatic response method, which comprises the following steps of: acquiring multi-source security data, performing de-duplication and standardization processing, and generating a structured security data set; based on the network security ontology model, entities and relationships are extracted from the data set, and a security knowledge graph is constructed through entity alignment and conflict resolution; according to ATTamp; the CK framework divides network subnets, generates attack path diagrams of the subnets, and fuses the attack path diagrams into a global attack graph. Then, abnormal behavior nodes in the security knowledge graph are analyzed, and risk scores of the service layer, the host layer and the system layer are calculated in combination with the global attack graph; and matching a predefined response strategy library based on the risk scores, executing operations such as banning an IP (Internet Protocol), isolating a host or updating firewall rules and the like through an SOAR platform, generating a disposal report and updating a security knowledge graph. According to the invention, the network security event processing efficiency and accuracy can be improved, and the overall security protection capability of the system is enhanced.
Owner:HUANENG INFORMATION TECH CO LTD

Network security protection method and system based on digital twin technology

The invention discloses a network security protection method and system based on a digital twin technology, belongs to the technical field of network security, and is used for solving the technical problems that an attack graph adopted by an existing network risk assessment method has limitation, vulnerability repair and defense depend on experience, and the effectiveness of a defense means is difficult to verify. The method comprises the following steps: constructing a network vulnerability dynamic knowledge graph based on multi-source network vulnerability information; acquiring real-time vulnerability information of the target network, and constructing an attribute attack graph of the target network according to the real-time vulnerability information and the dynamic knowledge graph; expanding the attribute attack graph based on the dynamic knowledge graph to obtain an expanded attribute attack graph; determining a predicted attack path according to the extended attribute attack graph; the attack complexity of the attack path is deduced and predicted in the digital twin model, and a defense strategy is determined according to the attack complexity level; and carrying out validity verification on the defense strategy, and feeding back the defense strategy passing the verification to the network node in the predicted attack path.
Owner:SHANDONG YUNWEI DIGITAL TECHNOLOGY CO LTD

Computer network security threat real-time monitoring method and system

The invention discloses a computer network security threat real-time monitoring method and system, and relates to the technical field of network security, and the method comprises the steps: collecting and preprocessing multi-source network data, organizing the multi-source network data into a behavior sequence according to a time sequence, and forming time sequence behavior data for analysis; constructing an attack atlas based on the preprocessed multi-source network data, and in the atlas construction process, forming dynamic representation of the attack atlas in combination with time attributes of behavior events and inter-entity contexts; time sequence behavior data are input into an RCLNet architecture for analysis, the RCLNet extracts spatial features through CNN, the LSTM captures time features, key behavior features are concerned by using an adaptive attention mechanism, and a high-dimensional behavior embedding vector is generated. High-precision and real-time detection and response to network threats are realized, and the intelligence and actual combat adaptability of the system are greatly improved.
Owner:HENAN UNIV OF ANIMAL HUSBANDRY & ECONOMY

Cloud environment active defense system based on dynamic honey points

The invention provides a cloud environment active defense system based on dynamic honey spots. The system comprises a honey spot deployment and management module which generates and deploys honey spots, manages honey spot layout and provides honey spot information; the dynamic defense control module monitors network flow, perceives an attack path, analyzes attack behavior characteristics, adjusts honey point layout, generates an adjustment instruction and generates alarm information according to the attack behavior characteristics; the attack chain tracking and analyzing module is used for acquiring attack event data for attack behavior tracking, constructing an attack graph for attack path analysis and attack intention prediction and generating a threat intelligence report; and the system integration and management module monitors the running state and the resource use condition of each module, dynamically distributes system computing resources, and sets an interaction unit to provide interaction. According to the system, a complete deception defense mechanism is constructed, a deception environment is constructed by utilizing honey points, the honey points are dynamically adjusted according to attacks, and quick response and accurate countering are ensured through a flexible defense strategy and multi-layer cooperation.
Owner:GUANGZHOU UNIVERSITY +1

Network security analysis early warning system based on artificial intelligence

The invention discloses a network security analysis early warning system based on artificial intelligence, and relates to the technical field of network security, and the system comprises the following steps: S1, constructing a multi-dimensional state table based on original traffic features; s2, generating an attack graph based on a causal relationship by using the state table; s3, extracting a topological evolution path by using an attack graph; s4, performing joint mode mapping by using the state table and the risk path; and S5, performing neural discriminant embedding modeling by using the composite risk event set. Through setting the attack graph based on the causal relationship, the technology significantly improves the integrity of risk propagation condition modeling, and lays a more stable data foundation for intelligent early warning of network security risk propagation. The joint modeling overcomes the problems of insufficient data granularity and incomplete application conditions caused by only depending on adjacency relation or simple condition judgment in the prior art, and can more clearly describe the internal relation between conditions when risk propagation occurs.
Owner:JUXIANG DIGITAL TECH (JIANGSU) CO LTD

Attack fault tree security risk assessment system based on deep reinforcement learning

The invention provides an attack fault tree security risk assessment system based on deep reinforcement learning, and relates to the technical field of information security. The system specifically comprises a network asset data fingerprint scanner module, a deep reinforcement learning network model generation and training module and an automatic penetration test tool set module. The invention aims to determine the optimal attack path from the system attack graph by using deep reinforcement learning. By combining the screened attack paths with various resources and time costs encountered in the actual penetration test, the failure rates of various security risks in the attack fault tree, the success probabilities of various attacks and other indexes can be determined. And finally, establishing an attack fault tree of a power system scene in the embodiment, comparing the attack lethality and the detection capability level of each attack path in a game phase, and qualitatively and quantitatively analyzing the final security capability level of the target system and the damage degree caused by attacks.
Owner:STATE GRID CORP NORTHEAST DIVISION +5

Intelligent construction and tracing method and device of attack graph

The invention discloses an intelligent construction and tracing method and device for an attack graph, and relates to the technical field of network security. The method comprises the steps of performing semantic analysis and entity relationship extraction on a multi-source heterogeneous security log according to a predefined structured security data model, and generating a standardized security entity relationship triple set; based on the set, taking an entity in an initial alarm as a starting point, and adopting an iterative closed loop driven by a large language model to dynamically construct an attack graph; and carrying out attack technique and tactics mapping and threat attribution based on the final map, and generating a response strategy of priority ranking. According to the method, automatic and high-precision source tracing and response of the attack chain are realized, and the problems that the prior art depends on static rules and semantic segmentation and lacks dynamic reasoning capability are effectively solved.
Owner:BEIJING CHAITIN TECH CO LTD

Counter measure strategy construction method and system based on attack intelligence

The invention belongs to the technical field of network security, and discloses a countering measure strategy construction method and system based on attack intelligence. According to the method, firstly, multi-source attack intelligence is fused, and a causal time sequence attack knowledge graph is constructed; then, mapping the atlas on a digital twinborn model based on the IEC 62443 standard, constructing a Bayesian attack graph, and quantifying the risk of each attack path; then, taking the risk, the cost and the operation influence as multiple targets, and adopting an NSGA-II algorithm to generate a Pareto optimal countering strategy set; further, an optimal robust strategy is selected from the strategy set by solving the Stackelberg safety game model; and finally, explaining the decision process by using an interpretable AI technology. According to the method, the problems of passive threat intelligence analysis, static risk assessment, sub-optimal strategy selection and opaque decision-making process in the prior art are solved, and active, quantitative, optimal and credible defense decision-making for the key infrastructure is realized.
Owner:GUANGXI POWER GRID CORP

Method, device and system for constructing attack graph, and storage medium

The embodiment of the invention provides a method, device and system for constructing an attack graph, and a storage medium, and relates to the technical field of network security. The method comprises the steps that based on a test case knowledge base of a target system, an attack graph information expansion algorithm is executed through a knowledge graph technology, and expanded information is obtained; utilizing the expanded information to construct an attribute attack graph of the target system; and carrying out attack path description on vulnerabilities of the target system based on the attribute attack graph. An attack graph information expansion algorithm is executed through a test case knowledge base based on a target system and by means of a knowledge graph technology, information needed for constructing an attack graph can be obtained, potential attack paths can be mined, the attack graph information is expanded, and then a comprehensive and accurate attribute attack graph is constructed. According to the method, effective description of the vulnerability attack path of the target system is realized, so that the constructed attack graph can reflect the security condition of the network system more truly, more scientific decision support is provided for network security management personnel, and the network security protection effect is improved.
Owner:STATE GRID SHANDONG ELECTRIC POWER CO +2

Open source component multi-mode dependence risk tracing method and device

The invention relates to an open source component multi-modal dependency risk tracing method and device, and the method comprises the steps: employing a mode of combining static analysis and dynamic analysis to analyze a component dependency relationship of software, and combining AST analysis and construction script analysis; function-level features are extracted, a binary fingerprint database is constructed, the similarity between different versions is analyzed through LSH, behavior patterns in binary codes are analyzed, and hidden dependencies or malicious code injection is detected; the version updating history of the dependent component is analyzed and monitored by using a time sequence, and the vulnerability security of the component is evaluated in combination with attack graph analysis; high-risk components on the path are calculated, potential supply chain attack points are identified, and risk points are subjected to cross validation; a time sequence diagram database is used for recording the component dependency relationship, and time backtracking query is supported. According to the method, a multi-mode dependency analysis method is adopted, potential dependency risks are rapidly identified, and potential supply chain attack risks are timely warned.
Owner:FUJIAN YIRONG INFORMATION TECH +1

Network security attack path prediction system based on graph neural network

The invention discloses a network security attack path prediction system based on a graph neural network, and relates to the technical field of network security, and the system comprises a data collection module which collects network full-link time sequence security data, and outputs standardized time sequence data through time sequence alignment and abnormal noise reduction processing; the time sequence diagram construction module is used for constructing a dynamic attack graph containing nodes and time sequence edges; the feature learning module introduces a time sequence attention mechanism, calculates a time-space fusion attention coefficient based on a graph attention network framework, and outputs a node embedding vector; the reasoning and pruning module is used for generating attack paths based on node embedding vectors and outputting a high-value attack path set; and the analysis decision module is used for carrying out importance sorting on all nodes on the high-value attack path, determining a path core risk point and generating a key node decision basis of the attack path. According to the method, the problem that the traditional technology cannot accurately capture the attack behavior time sequence dependence is solved, and the high-precision prediction of the attack path is realized.
Owner:CHINA POWER INVESTMENT NORTHEAST NEW ENERGY DEV CO LTD

Situation awareness and linkage disposal system based on dynamic threat modeling driving

The invention discloses a situation awareness and linkage disposal system based on dynamic threat modeling driving, and the system comprises a security data collection and standardization module which is used for collecting security data of a network, a host and an application layer, and carrying out the standardization processing; the dynamic threat modeling module is used for constructing a dynamic threat model; the threat agent modeling and simulation module is used for modeling each node in the threat attack graph into a threat agent; the parameter optimization module is used for globally optimizing parameters and strategy weights of the Monte Carlo tree search network by using a seagull algorithm; the linkage processing decision module is used for configuring a Monte Carlo tree search network based on the optimal parameter group; the safety equipment scheduling module is used for analyzing the optimal linkage disposal decision scheme; and the disposal effect evaluation and feedback module is used for performing multi-dimensional analysis on the disposal feedback data set. According to the invention, accurate situation awareness and linkage processing are provided for the user.
Owner:SHANGHAI VIDE INFORMATION TECHNOLOGY CO LTD

Network security defense strategy optimization method based on machine learning

The invention relates to the field of network security, and particularly discloses a network security defense strategy optimization method based on machine learning, and the method comprises the steps: aggregating isolated security events into attack activity clusters through causal association analysis, constructing a dynamically evolved global attack graph, and improving a defense perspective from a discrete event to a full combat view. In order to realize foresight, a graph neural network is utilized to analyze a graph to identify attack tactics and predict the next intention. A hierarchical reinforcement learning framework is innovatively introduced in the decision-making stage; an upper-layer strategic agent formulates a macroscopic defense target based on a global situation; and the lower-layer tactical agent focuses on the related attack sub-graph under the strategic guidance, and selects and executes the specific tactical action which can reach the target most. The strategy and tactical separated decision-making mode ensures that each defense action serves a long-distance target, so that strategic passivity caused by only taking care of previous threats is avoided.
Owner:STATE GRID HENAN INFORMATION & TELECOMM CO +1

Risk-based vulnerability management

Various systems and methods for providing risk-based vulnerability management are described herein. A system is configured to access an attack graph, the attack graph including exploits represented as preconditions and postconditions; access vulnerability information of a plurality of nodes in the network, the vulnerability information including conditions of the plurality of nodes in the network; access a network connectivity graph that represents a logical network topology of the plurality of nodes in the network; identify a set of attack paths in the attack graph by comparing the conditions of the plurality of nodes in the network with preconditions and postconditions in the attack graph; calculate a risk score for each of the set of attack paths in the attack graph; and present the risk score for each of the set of attack paths.
Owner:MCKESSON CORPORATION

Virtual simulation and security evaluation method and system based on network security target range

The invention discloses a virtual simulation and security evaluation method and system based on a network security target range, and the method comprises the steps: constructing a network asset knowledge graph for describing a virtualized target range environment through information collection; secondly, based on an attack strategy grammar rule base, adopting a Monte Carlo Tree Search (MCTS) algorithm to carry out intelligent attack simulation on the knowledge graph so as to discover a nonlinear and multi-stage attack path; thirdly, constructing a Bayesian attack graph (BAG) based on the knowledge graph, and performing probabilistic and systematic quantitative evaluation on the security risk of each asset node in the network through Bayesian reasoning; and finally, integrating the attack path and the quantitative risk value, and generating a comprehensive assessment report containing a visual path, a risk sequence and a reinforcement suggestion. According to the target range simulation method and device, the problems that existing target range simulation is insufficient in confrontation authenticity, one-sided in safety evaluation and lack of predictability are solved by combining the strategy simulation of the MCTS and the global quantitative analysis of the BAG.
Owner:BEIJING BO YI WANG XUN SCI & TECH CO LTD

Container vulnerability risk assessment method and system based on attack graph model

The invention discloses a dynamic verifiable fuzzy multi-keyword cloud ciphertext search method based on a block chain, and relates to the technical field of cloud native security. According to the method, full-process automatic analysis from vulnerability collection to attack graph generation to vulnerability evaluation is realized by combining vulnerability data of CNNVD, Docker container information and various vulnerability analysis algorithms. The core part in the design is attack graph generation and vulnerability analysis, and the part aims to comprehensively discover vulnerabilities existing in the system as much as possible and evaluate potential safety influences of the vulnerabilities. Through fusion evaluation of the analytic hierarchy process and the improved BP algorithm, the accuracy of vulnerability evaluation can be ensured, and the purpose of providing deeper analysis for the overall security condition of the system through the prediction capability of the neural network can be achieved. According to the multi-angle evaluation mode, the comprehensiveness and scientificity of vulnerability evaluation can be improved, so that a security team is helped to manage security risks in the system more effectively.
Owner:TIANJIN UNIV

Analytical attack graph abstraction for resource-efficiencies

Implementations include methods, systems, computer-readable storage medium for mitigating cyber security risk of an enterprise network. A method includes: receiving an initial analytic attack graph (AAG) that is representative of paths within the enterprise network with respect to at least one target asset, the initial AAG comprising nodes and edges between the nodes; identifying, from the nodes of the initial AAG, a plurality of node groups, each node group including two or more nodes having at least one common attribute; generating an abstract AAG from the initial AAG, the abstract AAG including at least one abstract node, wherein each node group of the initial AAG is represented by a respective abstract node of the abstract AAG; determining a set of remedial actions at least partially based on the abstract AAG; and executing remedial actions in the set of remedial actions to reduce a cyber security risk to the enterprise network.
Owner:ACCENTURE GLOBAL SOLUTIONS LTD

Attack source tracing method and apparatus, device, and medium

PCT designated stageWO2025161307A1Securing communicationFeature extractionAttack
The present application provides an attack source tracing method and apparatus, a device, and a medium. The method comprises: acquiring data related to an attack event, using the data related to the attack event to update a pre-constructed Bayesian attack graph, and determining an attack path with the maximum reachable probability in the updated Bayesian attack graph as a target attack path, wherein the pre-constructed Bayesian attack graph is a Bayesian attack graph constructed on the basis of data related to a historical attack event; and performing feature extraction from the data related to the attack event and the updated Bayesian attack graph, matching the extracted features with pre-formed feature clusters, and determining an attacker corresponding to the successfully matched feature cluster as a target attacker, wherein the pre-formed feature clusters are feature clusters which are formed by clustering the data related to the historical attack event and features extracted from the pre-constructed Bayesian attack graph and represent different attackers. According to the present application, the Bayesian attack graph and the feature clustering are utilized, effectively realizing rapid source tracing of the attack path and the attacker.
Owner:HANGZHOU DPTECH TECH

Traffic mirroring data processing method for local threat tracing

The invention discloses a traffic mirroring data processing method for local threat tracing, and belongs to the field of network security. Aiming at the problems of data redundancy, poor real-time performance, weak traceability and the like in the traditional technology, the technical scheme of dynamic traffic mirroring and preprocessing, multi-dimensional feature aggregation, time decay threat graph construction and a localized traceability engine is constructed. Threat index dynamic sampling, multi-protocol layer feature fusion, entity dependency relationship dynamic recording and attack path real-time tracing are realized through an adaptive mirror image proportional adjustment algorithm, a protocol stack entropy aggregation model, a time decay incidence matrix, an improved Bayesian attack graph and a dynamic programming algorithm. Through multi-scene verification, the threat detection rate reaches 96.8%, the false alarm rate is 2.3%, the traceability time is shortened to 58 seconds, the storage cost is reduced by 61%, and the security protection capability of the industrial control network is effectively improved.
Owner:GUANGXI POWER GRID CORP

Electric power information network multi-source threat intelligence analysis method, system, device and medium

The invention relates to the technical field of power information network threat intelligence analysis, and provides a power information network multi-source threat intelligence analysis method, system and device and a medium, and the method comprises the steps: obtaining to-be-analyzed multi-source threat intelligence data of a power information network; performing attack entity relationship extraction analysis on the text intelligence data according to a preset attack entity data model and a preset entity association mode table to generate an attack reconstruction main graph; carrying out attack entity relationship extraction analysis on the attack vulnerability codes based on a preset code large model and an attack entity retrieval database to generate a plurality of attack reconstruction sub-graphs; and combining the attack reconstruction main graph and the attack reconstruction sub-graphs to generate a target attack reconstruction graph. According to the method, an attack entity relationship extraction mechanism based on a unified attack entity data model is combined with a multi-source attack graph reconstruction mechanism, so that the accuracy and comprehensiveness of attack entity recognition are improved, the reliability of threat detection and attack tracing is ensured, and the security defense capability of the electric power information network is improved.
Owner:STATE GRID ZHEJIANG ELECTRIC POWER CO LTD HANGZHOU POWER SUPPLY CO

Penetration testing method and device, electronic equipment, storage medium and program product

The invention provides a penetration test method and device, electronic equipment, a storage medium and a program product, relates to the technical field of computers, and is used for improving penetration test efficiency. The method comprises the steps of obtaining a network topological graph of a target system, and then generating an attack graph of the target system based on the network topological graph and vulnerability information of each node in the target system; the attack income of each attack path in the attack graph is calculated, and a target attack path with the maximum attack income is obtained; and performing penetration testing based on the target attack path.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD

Cross-domain threat prediction method based on vulnerability analysis and related equipment

The invention discloses a cross-domain threat prediction method based on vulnerability analysis and related equipment, and the method comprises the steps: obtaining a network connection graph and first vulnerability information, carrying out the integration of the network connection graph and the first vulnerability information, and generating the input data of an attack graph generation tool; obtaining a PLC control logic, and generating a target dependency graph according to the PLC control logic; obtaining a logic node according to the target dependency graph; mapping the logic node to a field device in an industrial control system to obtain an attack target; generating an attribute attack graph through the attack graph generation tool according to a preset initial position of an attacker, the attack target and the input data; and extracting a target attack path according to the attribute attack graph to obtain a cross-domain threat prediction result. The method can improve the accuracy of cross-domain threat prediction, and can be widely applied to the technical field of network security and industrial control system security.
Owner:GUANGZHOU UNIVERSITY

Attack detection and processing method and device, electronic equipment, medium and program product

The invention provides an attack detection and processing method and device, electronic equipment, a medium and a program product, and can be applied to the technical field of big data, the technical field of artificial intelligence and the field of financial science and technology. The method comprises the following steps: acquiring multi-source network security data, and constructing an entity relation graph based on the multi-source network security data; carrying out attack chain analysis on the entity relation graph to obtain an attack chain analysis result; constructing an attack graph based on the attack chain analysis result; and generating a processing strategy based on the attack graph, and executing the processing strategy in response to the fact that the processing strategy is verified to have no service influence.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Network attack prediction method and device based on graph neural network, terminal equipment and storage medium

The invention discloses a network attack prediction method and device based on a graph neural network, terminal equipment and a storage medium, and belongs to the technical field of network security, and the method comprises the steps: obtaining an attack event log of an attack event received by a current power grid system, the attack time, the attack frequency, the attack source, the attack target, the attack steps, the attack step time corresponding to each attack step and the attack step frequency are determined; generating an attack graph and attack graph features according to the attack source, the attack target, the attack steps, the attack step time and the attack step frequency; and finally, inputting the attack graph and the attack graph features into a preset attack prediction model, and predicting to obtain a next attack prediction target and a corresponding attack prediction path. By implementing the method and the device, the problem that damage to a power grid system is increased due to the fact that potential attack targets and attack paths in the power grid cannot be predicted and then attack blocking cannot be realized in advance can be solved.
Owner:POWER DISPATCHING CONTROL CENT OF GUANGDONG POWER GRID CO LTD

Quantitative evaluation method and system for industrial control network security defense

The invention discloses a quantitative evaluation method and system for industrial control network security defense. The method comprises the following steps: firstly, constructing an attack graph based on industrial control network topology and vulnerability dependence; performing quantitative evaluation on key assets in combination with node topology centrality and business importance; further integrating dynamic factors such as observability, controllability, vulnerability utilization maturity and patch perfectness on the basis of the CVSS to form a real-time updated DCVSS vulnerability scoring system; and finally, on the basis of an attack unit income / attack cost principle, iteratively calculating a path unit income and generating a minimum cut set type vulnerability repair scheme. The scheme of the invention objectively reflects equipment and vulnerability risks in an industrial control scene, accurately identifies a key protection object, automatically outputs a priority repair list, has the advantages of strong dynamic nature, high interpretability, good expandability and the like, and can provide quantitative decision support for defense strategy formulation and resource allocation of an industrial control network.
Owner:STATE GRID HENAN ELECTRIC POWER ELECTRIC POWER SCI RES INST +2

Self-adaptive security event response method and system based on AI intelligent agent

The invention relates to a self-adaptive security event response method and system based on an AI agent, and belongs to the field of network security, and the method comprises the steps: in an event sensing stage, the AI agent obtains a first to-be-evaluated event according to network multi-source security data collected in real time; in the risk assessment stage, the AI agent obtains an attack graph of a network, and performs adaptive risk analysis on a plurality of paths of a first to-be-assessed event in the attack graph to obtain a security path of the first to-be-assessed event; in the intelligent decision-making stage, the AI agent generates a response decision of the first to-be-evaluated event according to the safety path; and in the response execution stage, the AI agent executes a corresponding safety protection action according to the response decision. The application can improve response efficiency of network security, reduce manual dependence and manual intervention, timely perceive security events and avoid expansion of network asset loss, is suitable for large-scale and diversified network security protection scenes, and can improve protection capability of novel threats.
Owner:BEIJING HUAQING XINAN TECH CO LTD

Network attack graph generation method and device, equipment and storage medium

The invention discloses a network attack graph generation method and device, equipment and a storage medium, and the method comprises the steps: obtaining a network topological graph corresponding to a target network, and determining a plurality of candidate attack paths corresponding to the target network according to the network topological graph; determining a target attack path in the candidate attack paths according to an access constraint condition and a defense constraint condition corresponding to the network topological graph; wherein the access constraint condition is that the candidate attack path does not comprise a predetermined access forbidding edge, and the defense constraint condition is that the candidate attack path does not comprise a predetermined defense edge; and according to the target attack path, generating the network attack graph corresponding to the target network, thereby preventing the generated network attack graph from containing a large number of invalid redundant paths, and improving the practicability of the network attack graph.
Owner:JIANGSU BOZHI SOFTWARE TECH CO LTD

Automatic penetration test path planning method and system based on agent collaboration

The invention discloses an automatic penetration test path planning method and system based on agent collaboration, and relates to the technical field of network security. Performing initialization starting on the plurality of intelligent agents based on the penetration test target range; collecting the target system and writing the target system into a shared blackboard mechanism; matching the asset feature information with a preset vulnerability knowledge base according to the test strategy mode to generate vulnerability utilization conditions, and constructing a global attack graph according to the asset feature information and the vulnerability utilization conditions; generating an attack path based on the global attack map, executing an attack operation on the target system according to an attack step sequence of the attack path, when an execution result is failure, updating the global attack map according to a feedback failure result, and re-planning to generate a new attack step sequence; and when the execution result is successful, generating a penetration test report for the penetration test target range according to the success result. By implementing the method, the actual demand of deep security assessment of the complex heterogeneous system is met.
Owner:BEIJING YUHONG XINAN TECHNOLOGY CO LTD

Power grid network attack chain risk assessment and threat situation awareness blocking method

The invention discloses a blocking method for power grid network attack chain risk assessment and threat situation awareness, and the method comprises the steps: carrying out the blocking of the threat situation awareness based on an attack target, attack time, an attack event type, attack event influence equipment and an attack tool corresponding to each attack event; constructing a first association relationship between every two attack events through a preset attack mode library; constructing a first directed attack graph structure, and based on the first directed attack graph structure, outputting a first blocking probability corresponding to each first node through a graph neural network model; traversing all the first nodes, and screening out all the first nodes of which the first blocking probabilities are greater than a preset screening threshold as blocking nodes; and on the basis of the nodes capable of being blocked, the corresponding threat situation sensing and blocking suggestion report is generated, so that intelligent blocking of the threat situation is realized, and the security of the power system is improved.
Owner:WUQIANG XISHUI POWER PLANT OF WULING ELECTRIC POWER CO LTD