Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

129 results about "Attack patterns" patented technology

In computer science, attack patterns are a group of rigorous methods for finding bugs or errors in code related to computer security. Attack patterns are often used for testing purposes and are very important for ensuring that potential vulnerabilities are prevented. The attack patterns themselves can be used to highlight areas which need to be considered for security hardening in a software application. They also provide, either physically or in reference, the common solution pattern for preventing the attack. Such a practice can be termed defensive coding patterns.

Systems and methods for detecting malicious webassembly modules under source code obfuscation

Systems, methods, and frameworks for detecting malicious WebAssembly (Wasm) modules under source code obfuscation are provided. The system is configured to accurately identify malicious behavior in Wasm modules irrespective of the specific malicious functionality and in the presence of source code obfuscation techniques. The detection process leverages a Vision Transformer (ViT) model to classify a Wasm module as benign or malicious, enabling robust identification of threats across diverse attack patterns. The system operates with substantially low runtime overhead on computing resources, making it suitable for integration into real-time web application environments.
Owner:FLORIDA INTERNATIONAL UNIVERSITY

Systems and methods for cohort denial of service attack detection and mitigation

A network monitoring device is connected to a communications network and monitors traffic transmitted to and from a server. The system stores a device fingerprint of devices identified as involved in attacks across the communications network, generates attack patterns for attacks across the communications network based on data packets transmitted or received by the devices during an attack based on the data packets corresponding to the device fingerprint, monitors data packet exchanges between the server and network devices, determines a set of transmission parameters for each of the data packet exchanges, compares the set of transmission parameters for the plurality of data packet exchanges to the attack patterns, and, responsive to determining a match between a first set of transmission parameters and an attack pattern, applies a tag to a network device communicating with the server via the data packet exchange indicating the network device is involved in an attack.
Owner:NETSCOUT SYSTEMS INC

Systems and methods for cohort denial of service attack detection and mitigation

A network monitoring device is connected to a communications network and monitors traffic transmitted to and from a server. The system stores a device fingerprint of devices identified as involved in attacks across the communications network, generates attack patterns for attacks across the communications network based on data packets transmitted or received by the devices during an attack based on the data packets corresponding to the device fingerprint, monitors data packet exchanges between the server and network devices, determines a set of transmission parameters for each of the data packet exchanges, compares the set of transmission parameters for the plurality of data packet exchanges to the attack patterns, and, responsive to determining a match between a first set of transmission parameters and an attack pattern, applies a tag to a network device communicating with the server via the data packet exchange indicating the network device is involved in an attack.
Owner:NETSCOUT SYSTEMS INC

Prompt word injection defense method, electronic equipment and program product

The invention provides a prompt word injection defense method, electronic equipment and a program product, and belongs to the technical field of network security, the method comprises the following steps: receiving a prompt text input by a user; performing input analysis and feature extraction on the prompt text to obtain a high-dimensional feature vector; in combination with a current dialogue context history, performing deep semantic analysis on the prompt text to generate a surface intention vector and a deep intention vector; calculating a semantic conflict degree between the surface intention vector and the deep intention vector; the semantic conflict degree, the matching degree of the high-dimensional feature vector and a known attack mode in a knowledge base and the abnormal degree of the current dialogue context are synthesized, and a comprehensive risk score is calculated; and executing a corresponding response strategy according to the value of the comprehensive risk score.
Owner:CHINA TOWER CO LTD

Honeypot automatic coping strategy generation method based on large model

The invention discloses a honeypot automatic coping strategy generation method based on a large model. The method comprises the steps of S1, performing semantic analysis on dynamic attack behaviors; s2, performing context-aware threat reasoning; s3, adaptive strategy generation and semantic verification are carried out; s4, strategy executable compiling is carried out; s5, enhancing the efficiency of the closed-loop strategy; according to the method, the authority / service logic contradiction is thoroughly eliminated through a semantic consistency verification mechanism, so that the false alarm rate of the honeypot in the APT attack is reduced; an anti-recognition perturbation code injected by the low-entropy strategy compiling technology breaks through a traditional honeypot periodic response mode, and the fingerprint recognition success rate of an attacker is reduced; a resource penalty function of the Pareto optimal strategy sequence enables a trapping intensity mean value under limited resources to be improved; a double-channel updating mechanism promotes coevolution of a knowledge base and a constraint set, and the response generation speed for an unknown attack mode is shortened.
Owner:SHENZHEN FANYUN SHUZHI TECH CO LTD

Large model adaptive security detection method and system based on four-order linkage

The invention discloses a large model adaptive security detection method and system based on four-order linkage, and the method achieves the security detection of the output content of a large model through four-stage collaborative linkage: in the context consistency reasoning stage, calculating the semantic consistency score of a generated text, a multi-round dialogue history, a user prompt word and an external knowledge base; marking a potential risk; in the causal chain risk detection stage, modeling multiple rounds of dialogues into a causal graph, calculating a risk path probability, matching an attack pattern library, and marking high risks; in the dynamic game optimization stage, a game space of a detector and an attacker is constructed, an optimal detection threshold value is solved, and parameters of each stage are linked and updated; in the cycle state switching stage, switching is carried out between a low-power-consumption monitoring state and a dynamic updating state according to system performance and a risk situation, and a risk level is output by integrating results of the four stages. According to the method, the problems of low hidden attack detection rate, high false alarm, risk non-traceability and resource waste in the prior art are solved, and self-adaption, low false alarm, traceability, high efficiency and energy conservation are realized.
Owner:XIAMEN MEIYABAIKE INFORMATION SECURITY RES INST CO LTD

Prison break prompt word detection method based on reasoning concealment capability quantitative analysis

The invention discloses a prison break cue word detection method based on reasoning concealment capability quantitative analysis, which comprises the following steps of: firstly, disassembling cue words into explainable preconditions and hypotheses through a lexical tree extractor agent to ensure that a logic structure is clear; secondly, designing two indexes including a causality score and a logical naturalness (PPL), and quantitatively evaluating the hiding capability of the cue word; and then, constructing an automatic framework, and finally realizing the generation, detection and harmfulness judgment of the hidden malicious cue word by combining a generative model and an expert model. Therefore, the jailbreak prompt word detection technology provided by the invention not only can efficiently generate diversified jailbreak prompt words with high concealment, but also can provide a more comprehensive reference for large model safety evaluation; the interpretability of concealment can be improved through quantitative analysis, and the model is helped to dynamically identify a novel attack mode; and meanwhile, the method can be used as a component of a safety fence, high-risk prompt words are early warned in real time, and the safety protection efficiency and robustness of a large model are remarkably improved.
Owner:ZHEJIANG UNIV +1

Large model security evaluation method based on multi-dimensional adversarial attack

The invention discloses a large model security evaluation method based on multi-dimensional adversarial attack, and the method comprises the steps: generating an adversarial sample sequence through constructing multi-dimensional attack scene description and combining the characteristics of data availability damage and system integrity violation, optimizing sample parameters in a black box attack mode, and precisely positioning a weak link of a model. And meanwhile, based on a risk quantized value sequence and a safety portrait mechanism, reinforcing demand data is extracted and a protection path is generated through reverse optimization, and finally, the protection capability of the model is remarkably improved. Through a closed-loop mechanism of scene generation, sample optimization and risk assessment, a complex attack environment is effectively dealt with, and the safety and stability of the system are guaranteed.
Owner:HUNAN CYBERSECURITY DIGITAL INFORMATION SECURITY TECHNOLOGY CO LTD

Internet-of-things safety real-time monitoring and protecting system

The invention discloses an internet of things security real-time monitoring and protection system, which carries out adversarial sample enhancement by introducing a generative adversarial network constrained by a physical rule so as to solve the problem of insufficient model training caused by scarcity of attack samples, and deeply mines long-time-sequence feature association of heterogeneous data in combination with time sequence stacking and a long-short-term memory network so as to realize real-time monitoring and protection of the internet of things security. Therefore, a closed-loop process from state sensing to threat research and judgment to precise blocking is realized. Through the mode, not only can the sensitivity and the recognition precision of scarce attack modes be remarkably improved and the false alarm rate be effectively reduced, but also microsecond-level real-time monitoring and precise blocking of a hardware level can be realized based on a microcode control instruction; therefore, high-reliability protection guarantee is provided for information physical safety of key infrastructures such as a novel electric power system and the like.
Owner:STATE GRID HENAN INFORMATION & TELECOMM CO

Ethical control and content authentication method for generative AI

The application relates to the field of generative artificial intelligence, and discloses an ethical control and content authentication method of generative AI, which comprises the following steps: analyzing generative content characteristics and predicting attack modes, dynamically adjusting a watermark embedding strategy, and enhancing robustness by using redundant coding, optimizing watermark embedding by using game theory, guaranteeing watermark integrity, verifying watermark effectiveness by using multi-modal authentication analysis, and finally realizing automatic copyright protection by using blockchain and smart contract; the application also provides an ethical control and content authentication system of generative AI, which comprises a content analysis module, a watermark embedding module and the like. Through a game model between a protector and an attacker, optimal dynamic adjustment of the watermark embedding strategy is realized, the watermark can be adaptively adjusted to ensure its effectiveness under different attack modes, and the problem that the watermark is easily tampered with or removed under a confrontational attack is effectively avoided.
Owner:北京思普艾斯科技有限公司

Intelligent detection and self-adaptive repair method for network security vulnerabilities of networked automobiles

The invention relates to the technical field of network security of networked automobiles, and discloses an intelligent detection and self-adaptive repair method for network security vulnerabilities of networked automobiles, and the method comprises the steps that a security probe collects bus communication data, application layer protocol data and system operation logs in a vehicle, and generates a security state data set; the security management and control platform receives real-time data to construct a security state matrix, extracts abnormal behaviors, protocol violation and other characteristics by analyzing the matrix, combines attack behavior modeling, attack intensity gradient calculation and an adaptive repair model, outputs space-time propagation characteristics of security threats, updates a data set, and identifies a potential attack mode; and dynamically deploying a protection strategy according to an attack mode, wherein the protection strategy comprises operations such as sub-domain mapping, access control updating, communication encryption and resource isolation. According to the method, intelligent detection and self-adaptive repair of network security vulnerabilities of networked automobiles are realized, and the accuracy and real-time performance of security protection are improved.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD

Poison data identification method, storage medium and system

The invention discloses a poisoning data identification method, a storage medium and a system, and relates to the technical field of machine learning safety, data quality and model maintenance. The identification method comprises the steps of obtaining an original data set; obtaining an original data set; numbering each data record in the original data set in sequence to obtain a new data set with numbers; performing dimension reduction processing on the new data set to obtain a dimension-reduced data set; performing feature calculation on the dimension reduction data set, and outputting a data record number and a feature value of the data record; and according to the characteristic value of the data record, identifying poisoning data. According to the method, dependence on a specific attack mode and a prior model is abandoned, the method can adapt to various types of poisoning attacks, high detection precision and operation efficiency are kept in a high-dimensional data environment, and a stable and reliable technical means is provided for safety protection of an artificial intelligence system.
Owner:INFORMATION & COMM BRANCH OF STATE GRID JIANGSU ELECTRIC POWER

Active defense method for adversarial denial of service attack in micro-service scenario

ActiveCN121333708BQuality of serviceAttack
The application discloses an active defense method against adversarial denial of service attacks in a microservice scenario. First, multi-source index collection probes are deployed in the microservice system and combined with centralized aggregation processing. Then, the system attack and defense process is modeled as a zero-sum game problem of double reinforcement learning agents. The defense strategy is optimized in the alternating update using the adversarial training mechanism, allowing the defender to gradually converge to a robust optimal strategy. On this basis, a multi-dimensional discrete deep Q network is introduced. Through shared feature extraction and multi-head independent output, efficient generation of multi-dimensional expansion and contraction defense decisions is achieved. A loss balancing mechanism is used to accelerate convergence. Finally, a closed-loop optimization mechanism is combined to trigger lightweight incremental training when new attack patterns are detected or defense effectiveness decreases, dynamically updating part of the network weights to maintain the adaptability of the strategy. This scheme can achieve intelligent, automated and efficient defense of microservice systems in adversarial attack environments, significantly improving system security and service quality.
Owner:SOUTHEAST UNIV

Permeation test effect evaluation method and system based on attack mode framework

The invention relates to the technical field of information security, in particular to a penetration test effect evaluation method and system based on an attack mode framework, and the method comprises the steps: firstly, constructing an evaluation model comprising a target layer, a criterion layer and an index layer; the evaluation indexes under each criterion are weighted through a large language model, and the indexes are quantitatively scored by experts. And for each criterion, on the basis of a grey theory, calculating a comprehensive evaluation vector of the criterion by using index scores, weights, a preset comment set and a whitening weight function so as to obtain a quantitative score and a qualitative evaluation result. And finally, calculating a final comprehensive evaluation result of the target layer by integrating the quantitative score vectors and the criterion weights of all the criteria. During decision making, the final result needs to be combined with the qualitative evaluation conclusion of each criterion so as to formulate a comprehensive and targeted security reinforcement strategy. According to the invention, the accuracy of penetration test effect evaluation is improved.
Owner:AIR FORCE UNIV PLA

Multi-model cooperative alarm log noise reduction and attack threat research and judgment method

PendingCN122640234ALinguistic modelAttack
The application discloses a multi-model cooperative alarm log noise reduction and attack threat research and judgment method, and the specific process is as follows: firstly, the data preprocessing is carried out on the multi-source heterogeneous security alarm log, then the two-stage reasoning is carried out by using the cascade classification model based on the light gradient boosting machine, and the attack state is identified; for the high-priority alarm screened out, the context-containing prompt word is constructed, the large language model is called for deep research and judgment, and the intelligent cache mechanism based on the feature hash is introduced, so that the similar attack mode is quickly and accurately identified, and finally, the end-to-end security research and judgment report is output in combination with the automatic flow processing and breakpoint continuation mechanism. The application solves the problems of high alarm false alarm rate and low research and judgment efficiency in the current security operation.
Owner:XIAN UNIV OF TECH

An Incremental Dynamic Data Extraction Method Based on Expert Models

This invention relates to the field of network security technology and discloses an incremental dynamic data extraction method based on an expert model. The method includes: generating a local attack attribution subgraph; protecting privacy through homomorphic encryption and differential privacy; using a federated graph neural network to identify cross-organizational attack patterns; reconstructing cross-domain attack chains through Markov chain analysis; verifying the attack path based on zero-knowledge proofs; and outputting a threat level score. This invention resolves the contradiction between data privacy protection and collaborative analysis in cross-organizational APT attack detection, achieving accurate identification and reconstruction of cross-domain attack chains while protecting the sensitive data of each organization.
Owner:BEIJING ZHONGWEI SHENGDING TECH CO LTD

Attack technology prediction method and device based on large language model

The invention provides an attack technology prediction method and device based on a large language model. The method comprises the steps of obtaining historical attack data of an attacker and performing data modeling to construct a bipartite graph; generating a structured context according to the bigraph, and inputting the structured context into a large language model; and constructing a prediction cue word, guiding the large language model to carry out attack technology prediction according to the structured context by the prediction cue word to obtain a preliminary prediction result, and carrying out attack stage filtering and sorting screening on the preliminary prediction result according to a set standard to obtain a final attack technology prediction result. By applying the method, the recommendation ability of the large language model can be stimulated, the adaptability and learning ability of the large language model to a specific security task can be improved, the scene learning ability of the large language model can be fully utilized, a new attack mode can be effectively dealt with, the dependence on a large amount of annotation data is reduced, and the user experience is improved. Particularly, under the condition that data is scarce or the cold start problem is serious, the accuracy of the generated result can be improved.
Owner:GUANGZHOU UNIVERSITY

Recognition method of request data, electronic equipment and storage medium

The invention relates to the technical field of network security, and discloses a request data identification method, electronic equipment and a computer readable storage medium, and the method comprises the steps: obtaining request data received by a target server; inputting the request data into a pre-trained first model to obtain a first recognition result, the first recognition result including an attack behavior recognition result and an attack tool recognition result; inputting the request data into a pre-trained second model to obtain a second identification result, the second identification result comprising an attack mode identification result; and generating a target identification result of the request data according to the first identification result and the second identification result, so as to give an alarm to the request data according to the target identification result. Through the above mode, the accuracy of identifying the security of the request stream is improved.
Owner:AUTEL UNITED CREATION SOFTWARE DEV CO LTD

Network attack detection method fusing block chain double-layer verification mechanism and large language model

The invention provides a network attack detection method fusing a block chain double-layer verification mechanism and a large language model. The method comprises the following steps: converting extracted numeric features into natural language text description by utilizing a data conversion method based on instruction learning so as to realize alignment of traffic data and semantic space; designing three heuristic prompt strategies of direct decision, comparison decision and thinking decision in a large language model by applying a decision reasoning module so as to strengthen the recognition capability of an attack mode; performing result extraction on a reasoning conclusion generated by the large language model, mapping the result into threat classification output, and performing credible auditing chaining on model output through a block chain second-layer verification mechanism to support multi-party rechecking; accurate detection of network attacks is realized through a closed-loop evidence obtaining capability of data, judgment and rechecking formed by linkage of an on-chain event and an off-chain storage.
Owner:ZHONGYUAN ENGINEERING COLLEGE

High-risk attack identification and dynamic defense method for electric power information physical system

PendingCN121727799ABiological modelsSecuring communicationAttackColored petri
The invention discloses a high-risk attack identification and dynamic defense method for an electric power information physical system, and relates to the field of safety of the electric power information physical system. The method comprises the following steps: firstly, constructing a weight coloring Petri network seven-tuple model, and describing the cross-domain propagation time sequence characteristics of the continuous load redistribution attack in an information-physical network by introducing a time delay parameter; then optimizing the attack triggering and migration probability based on mixed strategy Nash equilibrium; a top-k sequence mining algorithm is adopted to identify a high-risk attack mode from the attack event sequence, and a vulnerability index is defined to quantify the threat degree of the attack; and finally, modeling defense resource allocation as a combined dobby machine problem, and realizing self-adaptive adjustment of a defense strategy through a weight updating mechanism and sliding window optimization. According to the method, an active defense system of'accurate perception-intelligent decision-closed loop optimization 'can be formed, so that the defense capability of an electric power information physical system facing continuous load redistribution attacks is improved.
Owner:YANSHAN UNIV

Attack detection at low sampling rate in round-trip timing estimation

A wireless device includes a receiver adapted with Bluetooth® low energy (BLE) capability and logic at least one of coupled to or integrated within the receiver. The logic obtains, based on a received packet, a received signal. The logic identifies, based on the received signal and a reference signal, a fractional timing metric associated with the received signal. The logic calculates, based on the received signal, the reference signal, and an attack pattern, a correlation metric. The logic adjusts, based on the fractional timing metric, the correlation metric. The logic determines, based on the adjusted correlation metric and one or more thresholds, whether an attack is present in received signal.
Owner:INFINEON TECHNOLOGIES AMERICAS CORP

Mail system advanced threat tracing and detection method and system based on dynamic attribute graph

The invention discloses a mail system advanced threat traceability and detection method and system based on a dynamic attribute graph, and relates to the technical field of network security, and the technical scheme is characterized in that the method comprises the steps: collecting an operation log of a mail server in real time, and extracting a standardized field; based on a predefined graph ontology, mapping a log entity into nodes such as a user, a network address, a session, a resource and the like, mapping an operation behavior into a directed edge with a timestamp and a weight, and constructing a dynamic traceability graph; defining a malicious sub-graph topology template for a specific attack mode; searching matched connected sub-graphs in real time in the traceability graph by using a sub-graph isomorphic matching algorithm; and when matching succeeds, generating an alarm and extracting a sub-graph as a traceability evidence. According to the method, discrete log behaviors are correlated through a graph theory method, complex attack behaviors such as silence rule thunder burying, parasitic account aggregation and geographical kinetic energy abnormity can be effectively recognized, and the initiative and accuracy of mail security defense are remarkably improved.
Owner:PEKING UNIV

A network intrusion detection model end-to-end adversarial training defense method and device

This invention relates to the field of network security technology, and more particularly to a method and apparatus for adversarial training and defense of a network intrusion detection model. The method includes: dynamically outputting attack strategies based on traffic feature vectors and current strategy parameters using an adversarial strategy generator; imposing restrictions on perturbations in the problem space through adversarial domain constraints to ensure that the generated adversarial samples conform to network protocol specifications and feature logic consistency requirements; and forming a dynamic game mechanism by alternately executing adversarial training and strategy parameter optimization between the intrusion detection model and the adversarial strategy generator. This allows the model to gradually improve its defense capabilities against mixed threats in the feature space and problem space as it continuously adapts to increasingly complex attack patterns, ultimately achieving a synergistic improvement in the robustness and generalization of the intrusion detection model.
Owner:CHINA STATE SHIPBUILDING CORP LTD RESEARCH INSTITUTE 719

system

We provide the system. [Solution] A means for collecting data from multiple terminals within a distributed network in order to detect abnormal patterns in real time, A data analysis means for generating normal activity patterns and creating a reference pattern based on the aforementioned data, A threat prediction method using generative AI that detects anomalies that deviate from the aforementioned standard pattern and predicts future attack patterns, An automated response means that automatically generates and executes countermeasures in response to anomalies detected by the threat prediction means, Alert sending means for notifying the administrator of the results of the response by the automated response means. A system that includes this.
Owner:SOFTBANK GROUP CORP

Method and device for identifying C2 address, electronic equipment and storage medium

The invention provides a method and device for identifying a C2 address, electronic equipment and a storage medium, and relates to the technical field of security. According to the method, the C2 address is identified by analyzing the Botnet traffic, identifying the traffic of DNS and TCP protocol sessions and counting the traffic characteristics, so that the key characteristics of Botnet communication can be captured in time without depending on a preset rule, and the attack mode of a novel Botnet virus family can be quickly adapted. Compared with a traditional detection method based on IDS, the scheme effectively solves the problem that the defense capability is lagged due to attack changes, the real-time performance and accuracy of detection are greatly improved, network defense can respond to new threats more quickly, and the overall network security protection efficiency is enhanced.
Owner:QI AN XIN TECHNOLOGY GROUP INC

Defense method and system for perceptual poisoning

The invention discloses a defense method for perceptual poisoning, which is used for coping with perceptual poisoning attacks in federal learning target detection tasks by introducing suspicious client detection based on cosine similarity, self-adaptive learning rate adjustment and a dynamic defense interval mechanism, and realizing robustness training and stable defense of a system. The method can solve the technical problems that an existing defense method based on statistical anomaly detection depends on single-round gradient statistical characteristics, it is difficult to keep stable performance under the non-IID data condition, and the method is prone to being affected by noise fluctuation, so that the misjudgment rate is high. And the technical problems that the existing defense method based on trust scoring and weighted aggregation generally adopts a fixed learning rate or a linear attenuation strategy in a trust degree updating process, cannot flexibly adapt to a dynamically changing attack mode, easily causes defense response delay and causes insufficient system robustness are solved.
Owner:HUNAN UNIV

Block chain data driven zero-knowledge proof intelligent security protection method and system

The invention discloses a blockchain data-driven zero-knowledge proof intelligent security protection method and system, and belongs to the technical field of blockchains, and the key point of the technical scheme is that a layered architecture design is adopted, the system comprises a data layer, an analysis layer, a proof layer and a protection layer, and the layers cooperate to realize intelligent and adaptive blockchain security protection. According to the method, block chain data analysis and a zero-knowledge proof technology are organically combined, and automatic security policy execution is realized through the smart contract. The system firstly trains a protection model based on historical transaction data, and identifies an abnormal transaction mode; when a suspicious transaction is detected, a zero-knowledge proof verification mechanism is triggered, and a transaction initiator is required to provide a corresponding validity proof; meanwhile, the system can dynamically adjust security strategies and protection measures according to changes of attack modes, and the intelligent and self-adaptive security protection effect is achieved.
Owner:XIAMEN SLOWMIST TECHNOLOGY CO LTD

ATTACK DETECTION AT LOW SAMPLING RATE WHEN ESTIMATING THE TIME RUN OUT

A wireless device comprises a receiver designed with Bluetooth® Low Energy (BLE) capability and logic that is paired with and / or integrated into the receiver. Based on a received packet, the logic receives a signal. Using the received signal and a reference signal, the logic identifies a fractional timing metric associated with the received signal. Based on the received signal, the reference signal, and an attack pattern, the logic calculates a correlation metric. Based on the fractional timing metric, the logic adjusts the correlation metric. Based on the adjusted correlation metric and one or more thresholds, the logic determines whether an attack is present in the received signal.
Owner:INFINEON TECHNOLOGIES AMERICAS CORP

Method for discovering SQL (Structured Query Language) injection attack behavior based on chaotic parting dimension

PendingCN121333647AChaos modelsNon-linear system modelsData packSQL injection
The invention discloses a method for discovering SQL injection attack behaviors based on chaotic parting dimensions, and the method specifically comprises the steps: S1, data collection and feature extraction: obtaining HTTP request data, including SQL query data; extracting the characteristics of the SQL injection attack, wherein the characteristics comprise special characters, SQL keywords and potential malicious structures; s2, calculating a parting dimension; s3, setting a classification dimension threshold value, and if the classification dimension of the selected SQL statement is higher than the threshold value, judging that the SQL statement is an SQL injection attack; and S4, performing anomaly detection and response. The invention mainly relates to the technical field of network security, chaos theory and typing analysis. According to the method, the data is analyzed by using the typing dimension in the chaos theory, the accuracy and efficiency of attack detection are further improved, and nonlinear characteristics and complexity in an attack mode can be revealed, so that the method has advantages in coping with complex attacks.
Owner:XIAMEN ANSCEN NETWORK TECH CO LTD

Large model agent execution method and device, equipment and medium

The invention discloses a large model agent execution method and device, equipment and a medium, and relates to the field of artificial intelligence, and the method comprises the steps: obtaining an interaction context of a first large model; analyzing the interaction context to obtain context analysis data based on the large analysis model; wherein the context analysis data comprises a first intention, an access tool set, a source trust level label of each section of context and a plurality of prediction attack modes; based on the context analysis data, constructing a first security policy based on a preset policy construction method; wherein the first security policy is associated with a task corresponding to the first intention; and constructing a first execution environment according to the first intention, and after the first security policy is loaded to the first execution environment, executing a task corresponding to the first intention through the first execution environment agent. According to the method, the large model agent task can be safely and reasonably executed.
Owner:THE FIFTH AFFILIATED HOSPITAL OF GUANGZHOU MEDICAL UNIV