Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

213 results about "Attack patterns" patented technology

In computer science, attack patterns are a group of rigorous methods for finding bugs or errors in code related to computer security. Attack patterns are often used for testing purposes and are very important for ensuring that potential vulnerabilities are prevented. The attack patterns themselves can be used to highlight areas which need to be considered for security hardening in a software application. They also provide, either physically or in reference, the common solution pattern for preventing the attack. Such a practice can be termed defensive coding patterns.

CAPEC vulnerability management system based on large language model

The invention discloses a CAPEC vulnerability management system based on a large language model, and belongs to the technical field of network security. The system comprises three modules: a vulnerability-CAPEC dynamic mapping module jointly encodes vulnerability description and code context through a bimodal large language model, accurately associates vulnerability logic with a CAPEC attack mode in combination with comparative learning and knowledge graph construction, and breaks through semantic limitation of traditional rule matching; the adversarial repair code generation module is used for generating high-robustness repair codes through adversarial training and syntax tree verification by fusing CAPEC relieving suggestions and code features on the basis of the association result, so that the secondary vulnerability risk is remarkably reduced; and the full-process automatic verification and DevOps integration module performs multi-dimensional security verification such as symbolic execution, fuzzy testing and the like on the generated repair code, and deeply integrates a development tool chain to realize real-time pushing and closed-loop management of a repair scheme.
Owner:BEIJING SHIXING TECH CO LTD

AI protection engine construction method and system based on Web application

The invention relates to the technical field of AI protection, and discloses an AI protection engine construction method and system based on Web application. The method comprises the steps of obtaining a Web application HTTP request and performing semantic analysis to obtain request feature data; performing multi-dimensional threat feature extraction to obtain a Web request threat feature set; performing mode matching on the Web request threat feature set and a preset attack mode library to obtain a threat type judgment result and attack intention information; performing time sequence behavior analysis to obtain a Web behavior abnormal index; comprehensive decision making is carried out through a multi-agent collaborative decision making system, and a defense decision making scheme is obtained; according to the defense decision scheme, a corresponding defense component is selected through a defense execution engine for safety protection, and a Web request processing result is obtained. According to the method, corresponding protection measures can be taken aiming at requests of different risk levels, so that logic vulnerability attacks which are difficult to detect by a traditional system are effectively identified and defended.
Owner:SHAOGUAN COLLEGE

Data security event real-time monitoring method and system

The invention relates to the field of internet attack detection, in particular to a data security event real-time monitoring method and system, and the method comprises data collection, multi-modal fusion, threat detection, causal reasoning, dynamic response and feedback optimization. Compared with the traditional security analysis which depends on isolated data dimension or simple rule association, is difficult to capture a cross-data-source complex attack mode, and is faced with the limitations of low calculation efficiency, slow link traceability, storage access bottleneck and the like in mass data association analysis, the scheme integrates multi-source heterogeneous data into a dynamic association network through graph structure modeling, so that the security analysis efficiency is improved. Hidden association and behavior patterns among users, equipment and IPs are deeply mined by utilizing a GNN framework, the suspicious degree among entities can be accurately quantified, and hidden attack chains can be identified; and meanwhile, a hybrid storage architecture and a query optimization technology are adopted, so that a security analyst can backtrack a complex attack path in a second level while breaking through the bottleneck of large-scale graph data access performance, and the threat hunting efficiency and the high-level attack traceability are remarkably improved.
Owner:JINAN DINGXIA DIGITAL TECHNOLOGY CO LTD

Knowledge graph construction and attack path prediction method for network security

The invention belongs to the technical field of network security, and particularly discloses a network security knowledge graph construction and attack path prediction method, which comprises the following steps: acquiring an attack mode of network threat intelligence; constructing a network security knowledge graph based on the security vulnerability and attack pattern classification standard data and the attack pattern of the network threat intelligence; according to the method, an entity relationship in a network security knowledge graph is predicted based on a graph attention network GAT of text enhancement, an attack path is constructed based on the predicted entity relationship, and text enhancement is to introduce text information corresponding to entity nodes into a multi-head attention mechanism layer of the GAT. According to the method, the network security knowledge graph is constructed and the entity relationships are predicted based on the GAT, so that the entity relationships can be quickly integrated, the attack paths are constructed, the paths reveal security holes and attack modes which may be utilized by attackers, and accurate and efficient attack path prediction can be realized.
Owner:HUAZHONG NORMAL UNIV

Industrial production process APT attack detection method and system based on knowledge graph

The invention relates to the technical field of industrial internet security and artificial intelligence crossing, in particular to an industrial production process APT attack detection method and system based on a knowledge graph, and the method comprises the steps: obtaining industrial production data, carrying out the preprocessing of the obtained industrial production data, and obtaining an APT attack detection result; the preprocessed industrial production data are used as input for dynamic construction of a knowledge graph, known attack mode reasoning is carried out based on the knowledge graph, the known attack mode reasoning comprises the steps that a known attack chain is recognized through multi-hop matching of graph embedding, a time sequence graph convolutional network and an attention mechanism are fused to detect unknown abnormal behaviors, and the known attack chain is subjected to known attack mode reasoning. Data fusion is performed based on the topological relation of the knowledge graph, an attack entry node, an associated entity and a propagation path are positioned according to a data fusion result, and real-time detection and traceability of the hidden attack chain are realized by constructing the equipment-protocol-data stream three-dimensional semantic dynamic knowledge graph and fusing a graph embedding technology and a graph convolutional network.
Owner:HARBIN INST OF TECH AT WEIHAI

Network intrusion intelligent monitoring method and system based on deep learning

The invention provides a network intrusion intelligent monitoring method and system based on deep learning, relates to the field of network security, and solves the technical problem of response lag of an existing defense method. The method comprises the following steps: collecting multi-source data; preprocessing the multi-source data to generate a spatial-temporal feature map; inputting the spatial-temporal feature map into a first model and a second model constructed based on a deep learning algorithm for anomaly detection to obtain a detection result; wherein the first model is used for detecting a known attack mode, and the second model is used for detecting an unknown attack mode; and carrying out hierarchical risk level division on the detection result, and carrying out active defense according to the defense strategy of each risk level. The method is used in the network intrusion monitoring and defense process, intelligent monitoring and active defense of network intrusion are realized through multi-source data acquisition, spatial-temporal feature map generation, dual-model cooperative detection and layered defense strategy implementation, and the real-time performance and initiative of network security protection are improved.
Owner:常德学院

LLM intelligent agent-based security event traceability and response method and system

The invention relates to the field of network security, and provides a security event tracing and response method and system based on an LLM intelligent agent, and the method comprises the steps: collecting log information from network equipment, and extracting a security event with a high threat degree in the log information; identifying an attack mode of the security event based on LLM, and generating a response strategy including atomization operation steps according to the identified attack mode; the natural language instruction in the response strategy is converted into a tool calling instruction through the intelligent agent, and related tools are called to execute specific operation. By constructing an LLM-driven intelligent decision-making body, full-process automation from event analysis to response execution is achieved, the LLM deep reasoning ability and a safety tool chain are innovatively and deeply fused, an unstructured log is converted into an executable disposal scheme through the semantic understanding ability of the LLM deep reasoning ability, and the processing efficiency is improved. And designing a multi-stage reasoning framework of attack mode analysis-target decomposition-tool matching, and supporting dynamic generation of a customized response scheme conforming to an enterprise strategy.
Owner:HUAZHONG UNIV OF SCI & TECH

Network traffic data security assessment method and system based on deep learning

InactiveCN120455172ASecuring communicationNeural learning methodsProbabilistic risk assessmentData set
The invention provides a network traffic data security assessment method and system based on deep learning. The method comprises the following steps: converting original network traffic data into a graph structure data set comprising a topological structure, node attributes and time sequence behaviors; in the process, the time-space fusion input tensor is formed through the association strength between adjacent matrix and Laplacian matrix coding network entities and the fusion of time sequence characteristics extracted by time window slices. Compared with traditional flow analysis which only pays attention to a single protocol or a rate threshold value, the method achieves global relevance expression of network behaviors through graph structure modeling. Through graph structure modeling, multi-dimensional feature fusion and probabilistic risk assessment, the method can adapt to dynamic change of network topology and continuous evolution of an attack mode, so that a final assessment result is more accurate.
Owner:URUMQI VOCATIONAL UNIV

Systems and methods for detecting malicious webassembly modules under source code obfuscation

Systems, methods, and frameworks for detecting malicious WebAssembly (Wasm) modules under source code obfuscation are provided. The system is configured to accurately identify malicious behavior in Wasm modules irrespective of the specific malicious functionality and in the presence of source code obfuscation techniques. The detection process leverages a Vision Transformer (ViT) model to classify a Wasm module as benign or malicious, enabling robust identification of threats across diverse attack patterns. The system operates with substantially low runtime overhead on computing resources, making it suitable for integration into real-time web application environments.
Owner:FLORIDA INTERNATIONAL UNIVERSITY

Power distribution network protection resource dynamic allocation method, system and device and storage medium

The invention discloses a power distribution network protection resource dynamic allocation method, system and device and a storage medium, and relates to the field of power system network security protection, and the method comprises the steps: collecting the operation data of a power distribution network in real time, constructing a multi-dimensional fusion data set, and predicting a potential attack path through an attack path prediction model in combination with a historical attack mode library; performing risk assessment on the predicted potential attack path, and calculating the protection resource demand quantity of each region of the power distribution network in combination with the topological structure of the power distribution network and the importance of key nodes; according to a risk assessment result, dynamic allocation and real-time scheduling of protection resources are realized in combination with a resource constraint condition; the method can grasp the operation of the power distribution network in real time, accurately predict the potential attack path, accurately evaluate the risk and calculate the protection resource demand. Dynamic allocation and real-time scheduling of protection resources are realized, the resources are reasonably utilized, the cost is reduced, the protection effect is improved, and safe and stable operation of the power distribution network under complex network attacks is ensured.
Owner:GUIZHOU POWER GRID CO LTD

System and method for adaptive deception orchestration

The present invention discloses system and method for adaptive deception orchestration is disclosed. The system comprises a dummy asset generation module configured for generating dummy assets upon receipt of defined organizational data from an organization server, a dockerized container creation module configured for generating a plurality of virtual system groups, a virtual private machine client-server communication module configured for establishing a plurality of virtual private networks (VPN) in the plurality of virtual system groups, to provide a secure communication channel, a cyber-attack path orchestration module configured for orchestrating one or more cyber-attack scenario based on a plurality of historical behavioural patterns, an adaptive camouflaging module operatively configured for transferring system logs at a predetermined time interval by masking a chatting application and an intelligence accumulation module operatively connected to the adaptive camouflaging module configured for generating an attack pattern based on the analysis of the system logs.
Owner:INDIAN INSTITUTE OF TECHNOLOGY KANPUR

Heterogeneous atlas-based network attack path prediction method and device, and medium

The invention discloses a heterogeneous atlas-based network attack path prediction method and device and a medium, and relates to the technical field of network security, and the method comprises the following steps: collecting multi-source heterogeneous data, extracting basic entities and relationships to generate structured data, defining nodes and relationship types by using a TPP framework, and generating a real-time heterogeneous atlas by using a dynamic update mechanism; based on the real-time dynamic heterogeneous atlas and the multi-source heterogeneous data, generating an attack association feature matrix, extracting potential threat features through feature fusion, mining attack association paths, and generating an attack path candidate set; constructing a quantum field game model based on the attack path candidate set, generating an evasion path set in combination with a quantum tunneling effect, quickly adapting to attacks through dual variational optimization, and generating a final attack path prediction result and a confidence score; according to the method, the game confrontation model is constructed through the attack path candidate set, and the optimal defense strategy can be quickly found in the face of continuously changing attack modes.
Owner:JIANGSU ELECTRIC POWER INFORMATION TECH

Unknown exploit detection using attack traffic analysis and real-time attack event streaming

Techniques for unknown exploit detection using attack traffic analysis and real-time attack event streaming are disclosed. In some embodiments, a system / process / computer program product for exploit detection using attack traffic analysis and real-time attack event streaming includes receiving a stream that includes a plurality of attack events from a security platform at a cloud security service; generating a cluster of attack events from the stream; and tagging the cluster with an unknown attack pattern for further automated security analysis at the cloud security service, wherein the tagged unknown attack pattern cluster does not match a preexisting signature for a known attack pattern.
Owner:PALO ALTO NETWORKS INC

Domain penetration attack path generation method based on graph structure

The invention discloses a graph structure-based domain penetration attack path generation method, which belongs to the technical field of network security, and comprises the following steps of: constructing a multi-level relation graph comprising a host node, a service node and a user node through automatic detection by taking any host in a domain as a starting point; assigning a weight attribute to the atlas edge based on a vulnerability library and an attack pattern library; an improved heuristic graph search algorithm is adopted, all feasible attack paths and threat scores thereof are generated by integrating the path length, attack difficulty and permission improvement effect, and the problem that the threat scores of all the feasible attack paths are influenced in various scenes and dynamic change domain environments is solved. The technical problems of realizing comprehensive automatic penetration testing, accurately identifying potential attack paths and establishing a systematic threat assessment mechanism are solved, the automation, intelligence and high-efficiency level of domain penetration testing is remarkably improved, and the method has good adaptability, expansibility and practical value and is suitable for popularization and application. And attack path discovery and risk early warning work in a dynamic network environment with high security requirements can be effectively supported.
Owner:NANJING NANZI DIGITAL SECURITY TECH CO LTD

Industrial Internet of Things intrusion detection method based on time sequence clustering

The invention belongs to the technical field of intrusion detection, and discloses an industrial Internet of Things intrusion detection method based on time sequence clustering. An intrusion detection model based on TCN-GRU-Temporal Attention is provided, and the model combines the advantages of long and short term memory processing, dynamic feature capture and key information focusing, and is especially suitable for processing complex time sequence tasks. A multi-dimensional time sequence clustering algorithm based on an evaluation index is provided, k-medoids clustering edge nodes based on DTW are used, and the intrusion detection accuracy and the system response speed in a federated learning environment are improved. The industrial network intrusion detection method provided by the invention also shows good performance under non-independent identically distributed data, and effectively improves the recognition capability for complex attack modes.
Owner:NORTHEASTERN UNIV CHINA

Systems and methods for cohort denial of service attack detection and mitigation

A network monitoring device is connected to a communications network and monitors traffic transmitted to and from a server. The system stores a device fingerprint of devices identified as involved in attacks across the communications network, generates attack patterns for attacks across the communications network based on data packets transmitted or received by the devices during an attack based on the data packets corresponding to the device fingerprint, monitors data packet exchanges between the server and network devices, determines a set of transmission parameters for each of the data packet exchanges, compares the set of transmission parameters for the plurality of data packet exchanges to the attack patterns, and, responsive to determining a match between a first set of transmission parameters and an attack pattern, applies a tag to a network device communicating with the server via the data packet exchange indicating the network device is involved in an attack.
Owner:NETSCOUT SYSTEMS INC

Systems and methods for cohort denial of service attack detection and mitigation

A network monitoring device is connected to a communications network and monitors traffic transmitted to and from a server. The system stores a device fingerprint of devices identified as involved in attacks across the communications network, generates attack patterns for attacks across the communications network based on data packets transmitted or received by the devices during an attack based on the data packets corresponding to the device fingerprint, monitors data packet exchanges between the server and network devices, determines a set of transmission parameters for each of the data packet exchanges, compares the set of transmission parameters for the plurality of data packet exchanges to the attack patterns, and, responsive to determining a match between a first set of transmission parameters and an attack pattern, applies a tag to a network device communicating with the server via the data packet exchange indicating the network device is involved in an attack.
Owner:NETSCOUT SYSTEMS INC

Network intrusion detection method based on improved WGAN sampling and ensemble learning

The invention relates to a network intrusion detection method based on improved WGAN sampling and ensemble learning, and solves the defects that for high-dimensional and class-unbalanced network flow data, a base learner of an integrated model is insufficient in adaptive capacity, noise interference is difficult to restrain, and key attack modes are difficult to mine in the prior art. The method comprises the following steps: acquiring network flow data; performing data enhancement based on a DDWGLO framework; constructing a network intrusion detection model based on Stacking; training a network intrusion detection model; and detecting network intrusion in real time. According to the method, the DDWGLO is adopted for data enhancement, the weight is adaptively allocated based on the Newton-Raphson optimization algorithm improved on the basis of Circle chaotic mapping, and then the accuracy of network intrusion detection is improved.
Owner:ANHUI UNIV

Prompt word injection defense method, electronic equipment and program product

The invention provides a prompt word injection defense method, electronic equipment and a program product, and belongs to the technical field of network security, the method comprises the following steps: receiving a prompt text input by a user; performing input analysis and feature extraction on the prompt text to obtain a high-dimensional feature vector; in combination with a current dialogue context history, performing deep semantic analysis on the prompt text to generate a surface intention vector and a deep intention vector; calculating a semantic conflict degree between the surface intention vector and the deep intention vector; the semantic conflict degree, the matching degree of the high-dimensional feature vector and a known attack mode in a knowledge base and the abnormal degree of the current dialogue context are synthesized, and a comprehensive risk score is calculated; and executing a corresponding response strategy according to the value of the comprehensive risk score.
Owner:CHINA TOWER CO LTD

Threat-informed adversary attack simulation

PendingUS20250310351A1Securing communicationData packAdversary
A dynamic adversary profile is generated for a simulated attack on components of the enterprise network by selecting a profile of at least one specific threat group. The simulated attack is based on historical attack data, threat intelligence feeds, and real-time monitoring of adversary profiles. One or more relevant adversary group profiles is selected. An attack pattern (e.g., an APT attack pattern) is simulated on the components by injecting data packets based on the specific threat group without malicious components of the specific threat group to test security defenses of the components. Logs are collected from the simulated attack pattern. Based on results of the simulated attack pattern, defenses to the simulated attack on components are measured. Optionally, a security action concerning at least one of the components to better protect against an actual attack.
Owner:FORTINET INC

Reentry attack detection system and method based on time sequence transaction aggregation graph network

The invention discloses a reentry attack detection system and method based on a time sequence transaction aggregation graph network, and the method comprises the steps: constructing a time sequence multilateral directed transaction graph through a transaction graph generation module, constructing and enhancing the node and edge representation of a block chain transaction graph through a multilayer mechanism in a time sequence transaction aggregation graph network construction module, and the attack detection module carries out weighted fusion on the node features, the time sequence features and the structural features and then inputs the fused features into a logistic regression classifier, a probability value of a reentry attack behavior is calculated through a Sigmoid function, classification judgment is carried out according to a set threshold value, and a reentry attack detection result is obtained. The reentry attack detection method provided by the invention has a real-time monitoring capability, can accurately identify an ongoing reentry attack behavior, and effectively prevents further loss of contract funds through an instant interception mechanism. The method has high adaptability to a continuously evolving block chain transaction environment, and a novel unknown reentry attack mode can be continuously and effectively detected.
Owner:SOUTHEAST UNIV

Network security vulnerability analysis method and system based on large-model low-rank adaptation fine tuning training

The invention relates to a network security vulnerability analysis method and system based on large-model low-rank adaptation fine tuning training. According to the method, firstly, a large language model is selected and pre-trained, a network security corpus is collected and preprocessed to construct a supervision fine tuning data set, then low-rank adaptive training fine tuning is performed on the pre-trained model based on the supervision fine tuning data set to obtain a network security vulnerability analysis large model, and finally, the model is utilized to monitor and analyze a network system in real time. And identifying and outputting potential security vulnerabilities and attack modes. Compared with the prior art, the method has the advantages of realizing efficient and accurate vulnerability analysis, effectively identifying novel vulnerabilities and the like.
Owner:STATE GRID SHANGHAI MUNICIPAL ELECTRIC POWER CO

Honeypot automatic coping strategy generation method based on large model

The invention discloses a honeypot automatic coping strategy generation method based on a large model. The method comprises the steps of S1, performing semantic analysis on dynamic attack behaviors; s2, performing context-aware threat reasoning; s3, adaptive strategy generation and semantic verification are carried out; s4, strategy executable compiling is carried out; s5, enhancing the efficiency of the closed-loop strategy; according to the method, the authority / service logic contradiction is thoroughly eliminated through a semantic consistency verification mechanism, so that the false alarm rate of the honeypot in the APT attack is reduced; an anti-recognition perturbation code injected by the low-entropy strategy compiling technology breaks through a traditional honeypot periodic response mode, and the fingerprint recognition success rate of an attacker is reduced; a resource penalty function of the Pareto optimal strategy sequence enables a trapping intensity mean value under limited resources to be improved; a double-channel updating mechanism promotes coevolution of a knowledge base and a constraint set, and the response generation speed for an unknown attack mode is shortened.
Owner:SHENZHEN FANYUN SHUZHI TECH CO LTD

Large model adaptive security detection method and system based on four-order linkage

The invention discloses a large model adaptive security detection method and system based on four-order linkage, and the method achieves the security detection of the output content of a large model through four-stage collaborative linkage: in the context consistency reasoning stage, calculating the semantic consistency score of a generated text, a multi-round dialogue history, a user prompt word and an external knowledge base; marking a potential risk; in the causal chain risk detection stage, modeling multiple rounds of dialogues into a causal graph, calculating a risk path probability, matching an attack pattern library, and marking high risks; in the dynamic game optimization stage, a game space of a detector and an attacker is constructed, an optimal detection threshold value is solved, and parameters of each stage are linked and updated; in the cycle state switching stage, switching is carried out between a low-power-consumption monitoring state and a dynamic updating state according to system performance and a risk situation, and a risk level is output by integrating results of the four stages. According to the method, the problems of low hidden attack detection rate, high false alarm, risk non-traceability and resource waste in the prior art are solved, and self-adaption, low false alarm, traceability, high efficiency and energy conservation are realized.
Owner:XIAMEN MEIYABAIKE INFORMATION SECURITY RES INST CO LTD

Complex multi-step attack detection method and system based on interpretable graph neural network, and storage medium

The invention discloses a method and a system for detecting a complex multi-step attack based on an interpretable graph neural network, and a storage medium. The method comprises the following steps: generating a strong negative sample by using priori attack knowledge; inputting the overall graph into a detection model to obtain an attack detection result; and inputting the attack event and the detected attack behavior into an interpreter to obtain the interpretation of the attack behavior. Constructing a traceability graph and an attack mode graph from a system log, aligning the generated traceability graph and attack mode graph, and enhancing an overall graph; pre-training an encoder of a multi-step attack detector on the continuous time dynamic heterogeneous graph by using comparative learning; finely adjusting the model on a small number of real attack samples based on a pre-training model; the relevance between an abnormal event and a preorder event is calculated by using a sniffer, and then an interpretable sub-graph is searched and output by using a Monte Carlo tree under the guidance of the sniffer by a digger. The problems that an existing method is difficult to solve the problem of data imbalance, low in interpretability and the like are solved.
Owner:NARI INFORMATION & COMM TECH +3

Network security operation and maintenance management system and method

The invention discloses a network security operation and maintenance management system and method, and belongs to the field of network security operation and maintenance, and the system comprises a data collection module which is used for collecting equipment logs, analyzing flow data, and deploying a distributed performance probe to collect transaction response time and throughput indexes; the real-time processing module is used for executing streaming window association calculation through an Flink engine, matching an attack mode sequence in combination with a CEP rule engine, and storing performance baseline data; the AI analysis module is used for detecting abnormal behaviors, constructing an equipment access relation graph through GNN, fusing log text and traffic image features, and combining historical performance data to train a load prediction model; the alarm management module is used for generating hierarchical alarms according to knowledge graph reasoning and explaining alarm root causes through an SHAP algorithm; and the test management module is used for drawing a transaction response time distribution diagram and generating a pressure test report. According to the invention, the attack pattern recognition accuracy can be improved.
Owner:GUANGDONG LITONG INFORMATION TECH CO LTD

Prison break prompt word detection method based on reasoning concealment capability quantitative analysis

The invention discloses a prison break cue word detection method based on reasoning concealment capability quantitative analysis, which comprises the following steps of: firstly, disassembling cue words into explainable preconditions and hypotheses through a lexical tree extractor agent to ensure that a logic structure is clear; secondly, designing two indexes including a causality score and a logical naturalness (PPL), and quantitatively evaluating the hiding capability of the cue word; and then, constructing an automatic framework, and finally realizing the generation, detection and harmfulness judgment of the hidden malicious cue word by combining a generative model and an expert model. Therefore, the jailbreak prompt word detection technology provided by the invention not only can efficiently generate diversified jailbreak prompt words with high concealment, but also can provide a more comprehensive reference for large model safety evaluation; the interpretability of concealment can be improved through quantitative analysis, and the model is helped to dynamically identify a novel attack mode; and meanwhile, the method can be used as a component of a safety fence, high-risk prompt words are early warned in real time, and the safety protection efficiency and robustness of a large model are remarkably improved.
Owner:ZHEJIANG UNIV +1

Cross-regional semantic security verification method, system and device based on multi-modal deep learning

The invention relates to the technical field of artificial intelligence security, and relates to a cross-regional semantic security verification method, system and device based on multi-modal deep learning. The method comprises the following steps: carrying out analysis, formatting and feature enhancement on multi-modal data transmitted across security domains through a preprocessing engine, and generating standardized input; the preprocessed data are input into a structure verification unit, a semantic understanding unit and a risk simulation unit in parallel; the structure verification unit detects a known attack mode through a static rule matching engine and a dynamic learning engine and dynamically updates a rule base; the semantic understanding unit generates a multi-modal fusion risk assessment result; the risk simulation unit generates a risk thermodynamic diagram; and the verification decision-making device integrates output results of all the units, and intercepts or releases cross-domain transmission data. According to the method, comprehensive semantic security verification of cross-security domain transmission data is realized, and the confidentiality and integrity of sensitive information in a transmission process are ensured.
Owner:SHANDONG INSPUR SCI RES INST CO LTD

Network intrusion detection method based on adaptive ensemble learning and concept drift detection

The invention discloses a network intrusion detection method based on adaptive ensemble learning and concept drift detection, and the method can improve the detection accuracy and adaptability of an intrusion detection system under the conditions of unknown attacks and data concept drift. The precision of an existing model is remarkably reduced, and manual intervention is needed for recovery. The invention aims to provide a self-adaptive detection framework, so that the system can automatically identify and quickly adjust the failure of the model, autonomously complete the learning of new attacks and the updating of the model, and avoid frequent manual retraining. According to the method, the unknown attack detection capability is improved, and by integrating a plurality of heterogeneous classifiers and dynamically optimizing the combination of the heterogeneous classifiers, the method has stronger detection capability on never seen attack behaviors. Different models identify anomalies from different angles, the coverage rate of unknown attacks is improved, and the defect that a traditional single model misses detection of unknown threats is overcome.
Owner:NANJING FOREST POLICE COLLEGE +1

Malicious traffic detection method fusing CNN-LSTM

The invention discloses a malicious traffic detection method fusing CNN-LSTM, and belongs to the technical field of network security. Comprising a multi-layer feature fusion mechanism of modular design, multi-path parallel learning design and joint optimization of regularization and feature compression. The method has strong automatic feature extraction capability, hidden complex features can be autonomously learned from a large amount of network traffic data, and the detection efficiency and the detection effect are improved; the method has the advantages that the false alarm rate is obviously improved, the complex nonlinear relation can be better processed, and the method has higher learning ability for the attack mode which is difficult to capture by the traditional method; the method has strong generalization ability and can well adapt to a dynamically changing network environment; even in the face of unknown threats, effective detection can be carried out through the similarity of the feature modes; and the data feature capturing capability, concurrency, expression capability and robustness of the model are effectively improved.
Owner:ZHENGZHOU POLICE COLLEGE