Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

15 results about "Attack response" patented technology

Firewall policy generation method and device, equipment, medium and program product

The invention provides a firewall policy generation method and device, equipment, a medium and a program product, and relates to the field of financial science and technology or the field of big data. The method comprises the steps that asset information and calling relation data of a service system are obtained, a network flow logic model is generated based on the asset information and the calling relation data, and the network flow logic model comprises a topological structure model used for describing the interior of the service system and a communication link between the service system and an external system, generating a firewall policy according to the network flow logic model; the firewall policy refuses access of all IPs to a specified port of the database by default, and the recorded specific IPs are released only through a white list; according to the method, the automation level of strategy configuration and the attack response speed are improved, so that the real-time defense requirement is efficiently met.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

A network threat response system based on multi-agent cooperation

This invention discloses a network threat response system based on multi-agent cooperation, comprising: a trace configuration agent for generating behavioral configuration chains; a configuration aggregation module for generating threat configuration clusters; a trajectory inference agent for generating a threat trajectory grid; a resonance modeling module for executing a pulse-constrained resonance aggregation algorithm to form a threat intent resonance network; a probe pulse agent for executing cooperative probe pulses to form a cooperative probe pulse record set; a response graph generation module for generating an attack response graph; a resonance adjudication agent for constructing an attack relationship graph and executing an improved Tarjan algorithm, introducing a pulse resonance adjudication mechanism to identify strongly connected attack units and determine the minimum blocking node set; and a response execution module for executing network threat response based on the minimum blocking node set. This invention achieves efficient network threat response through the pulse-constrained resonance aggregation algorithm and the improved Tarjan algorithm.
Owner:ORDOS KEXUAN INFORMATION TECH CO LTD

Dynamic HQoS-driven deterministic network potential safety hazard real-time response method and system

The invention discloses a dynamic HQoS-driven deterministic network potential safety hazard real-time response method and system, and belongs to the technical field of data communication networks, and the method comprises the steps: obtaining flow data, and building a deterministic service baseline; and selecting the flow data exceeding the deterministic service baseline for analysis, and outputting and marking a threat level. And monitoring the marked flow data, and after the data is recovered, recovering the original resource configuration according to the gradient and marking. And constructing a dynamic HQoS strategy and synchronously executing attack response and service recovery based on the dynamic HQoS strategy. According to the method, the traffic data are detected and analyzed, when a security problem occurs in a deterministic network, potential safety hazards can be detected in real time, degradation, speed limiting and isolation processing are carried out according to the detected threat level, and the service quality of key services is ensured. The dynamic HQoS can directly trigger the adjustment of the resource scheduling strategy according to the security detection result, so that the network adaptability is enhanced while the limitation of static resources is overcome.
Owner:CHINA TOWER CO LTD

Cyber ​​attack response support system, cyber attack response support method, and cyber attack response support program

To provide a cyber attack countermeasure support system, method and program for designing an appropriate countermeasure against a cyber attack.SOLUTION: A cyber attack countermeasure support system 1000 designs countermeasures against a cyber attack on a predetermined target system. The cyber attack countermeasure support system comprises: a storage unit 120 that stores one or more attacker profiles 122 including an attack purpose and attack technique of an attacker performing the cyber attack, and one or more defender profiles 123 including a defense purpose and defense technique of a defender performing defense against the cyber attack; and a countermeasure design unit 111 that uses a system model 121 for reproducing a state of the target system and outputting index values of one or more indices indicating a performance of the target system corresponding to the state of the target system to design a countermeasure for each of combinations of the attacker profiles 122 and the defender profiles 123.SELECTED DRAWING: Figure 1
Owner:HITACHI LTD

Center for disease control network resilience assessment and attack adaptive response system based on digital twinning

PendingCN122394888AAttackSimulation
The present application relates to the technical field of digital twinning, in particular to a disease control center network elasticity evaluation and attack adaptive response system based on digital twinning. It comprises: a digital twinning modeling unit for constructing a digital twinning model containing a business-network correlation matrix and a business tolerance threshold; an elasticity evaluation unit for generating the elasticity coefficient of each network node or link; an attack detection unit for monitoring attacks and generating an alarm containing the attack type; a response strategy generation unit for generating a candidate response strategy according to the attack type and the elasticity coefficient; a strategy evaluation and admission unit for simulating the execution of the candidate strategy in the twinning model, calculating the business interruption risk index, and allowing deployment to the physical network when the preset risk threshold condition is met. The system realizes multi-dimensional quantitative evaluation of network elasticity through a digital twinning model, and guarantees the continuous operation of disease control business during the attack response process through a strategy simulation admission mechanism.
Owner:万源市疾病预防控制中心

Deception as a service (DAAS) system with large scale deployment of template-based decoys

A deception as a service (DaaS) system configures a decoy to generate a decoy instance, and projects the decoy instance into a user network. The DaaS system receives, by the decoy in the deception system, from an edge point in the user network, an attack request on the decoy instance by an attacker, generates an attack response by the decoy based at least in part on the attack request; and sends the attack response to the attacker. The attack response may include erroneous information, such as a lure file or lure credentials.
Owner:FORTINET INC

Diagnostic service attack test method and system based on vehicle control local area network

The invention relates to a diagnosis service attack test method and system based on a vehicle control local area network. The method comprises the following steps: sending a specified diagnosis message to at least two physical identities based on a vehicle control local area network, and effectively screening out a target identity capable of executing a diagnosis protocol based on all specified response messages corresponding to the specified diagnosis message; sending attack messages corresponding to the basic diagnosis service to the target identity label according to a preset frequency based on the whole vehicle control local area network, and determining attack response messages and attack delay time corresponding to the attack messages so as to expect to find possible vulnerabilities of the vehicle in advance; according to the method, the attack score of the target identity label is determined based on all the attack messages, all the attack response messages and all the attack delay time, and the attack test result of the target identity label is obtained based on the attack score, so that the vehicle can be rectified in time based on the attack test result, and the safety and stability of the whole vehicle are guaranteed.
Owner:CHINALIGHT SOLAR

A power transmission system attack scenario identification method considering information-physical interaction

The application relates to the technical field of power information physical system security, and discloses a power transmission system attack scene identification method considering information physical interaction. A DAD attack and defense model is constructed, a plurality of typical attack scenes are generated, historical load data, attack schemes and defense schemes are collected; a classification network is trained to learn the mapping relationship between the system operation state and the corresponding worst attack response; a gradient descent method is used to optimize the network parameters, and a Lagrange function and an information physical coupling penalty term are introduced; after training, attack scene prediction is carried out; taking minimizing the expected loss of the system as an optimization objective, the optimized defense resource configuration scheme is obtained through iterative solution of C&CG. Through the multi-stage collaborative optimization strategy, the TCPS resilience under the information physical collaborative attack is improved, the system can quickly respond and recover when facing a dynamic attack environment, and the overall system stability and security are enhanced.
Owner:SICHUAN UNIV

Real service mirror image-based honeypot response data generation method and honeypot defense system

The invention relates to the technical field of honeypot defense, in particular to a honeypot response data generation method based on a real service mirror image and a honeypot defense system. The honeypot response data generation method comprises the following steps: forwarding an attack request to a honeypot response module, and searching a rule table to determine an attack response action matched with the attack request; and when the first response data matched with the attack response action cannot be queried in a template library, calling a sandbox environment module to return second response data according to the attack response action. And the real service mirror image response request of the target system is read in the sandbox environment module, so that the honeypot is prevented from being broken due to too rigid response data. Moreover, the honeypot defense system requests the response cache module, the honeypot response module and the sandbox environment module level by level, and returns response data requested by an attacker, so that the response speed can be increased, and the consumption of computing resources can be reduced.
Owner:GUANGZHOU UNIVERSITY

Real-time and independent cyber-attack monitoring and automatic cyber-attack response system

ActiveCA3168656CCyber-attackAttack
A cyber safety system that provides a real-time and indepen- dent cyber-attack monitoring and automatic cyber-attack response. The cy- ber safety system comprises a cyber monitoring logic to generate a cyber at- tack signal in response to a cyber attack event. The cyber safety system fur- ther comprises an automatic segmentation controller to generate a plurality of segmentation voltage signals or a plurality of segmentation messages in response to the cyber attack signal. The cyber safety system further compris- es a plurality of firewalls configured to invoke firewall rulesets depending upon an input voltage signal level of the plurality of segmentation voltage signals or the plurality of segmentation messages to segment a site network in a plurality of site network segments and to control one or more physical devices as response to the cyber attack event.
Owner:SIEMENS INDUSTRY INC

Method and system for realizing industrial honeypot network based on multi-core electric power IED (Intelligent Electronic Device)

The invention relates to the technical field of network security, and discloses a method and system for realizing an industrial honeypot network based on multi-core electric power IED equipment, and the method comprises the steps: carrying out the preprocessing of traffic, and redirecting and forwarding the traffic to a processor core of the electric power IED equipment; generating multi-dimensional vectors of a plurality of distribution nodes and mimicry data, and determining the distribution nodes and the mimicry data according to the probability of the distribution nodes; based on a honeypot network kernel, forwarding the attack data to an associated electric power IED device in combination with the distribution node and the mimicry data, and generating mimicry data corresponding to the attack data by using a dense network client associated with the electric power IED device; and mimicry data returned by the secret network client is integrated, and a final attack response is generated and sent to the attack source. According to the method, one-step generation of trapping data and distribution nodes on the premise of local data security can be realized, real-time analysis, quick response and effective cheating of attack traffic are realized, and the overall security protection level of an industrial control system is fundamentally improved.
Owner:GUODIAN NANJING AUTOMATION

High-hiding attack detection and traceability method and system for Internet of Vehicles

The invention provides a high-hiding attack detection and traceability method and system for the Internet of Vehicles, and the method achieves the deep and comprehensive analysis of the data of the node devices of the Internet of Vehicles through the collection of the multi-aspect data of each node device in the Internet of Vehicles and the extraction of the multi-aspect features of the multi-aspect data through a target attack detection model. The accuracy of the attack detection result output based on the feature is improved, and the target attack detection model is obtained by training based on the simulated hidden attack data in advance, so that the target attack detection model has relatively high detection efficiency and accuracy for the high-hidden attack data. Besides, the target traceability graph of the Internet of Vehicles is constructed and attack traceability is performed through a corresponding graph search algorithm, so that automatic traceability of the attack path is realized, the attack traceability efficiency and the attack response efficiency are improved, and the security and stability of the Internet of Vehicles are ensured.
Owner:UNIV OF SCI & TECH BEIJING +1

Honeypot response data generation method based on large language model and honeypot defense system

The invention relates to the technical field of honeypot defense, in particular to a honeypot response data generation method based on a large language model and a honeypot defense system.The method comprises the steps that first response data matched with an attack response action is queried in a template library, and if query matching succeeds, the first response data is sent to an attacker; and if the query matching fails, generating second response data associated with the attack response action through the large language model, and sending the second response data to the attacker. And according to the method, the generated response data are stored in the response cache, and the response data are directly given in the response cache when a new attack request arrives. According to the application, the response data reserve of the honeypot for uncommon attack means is enriched through the large language model, and the response to the attacker request is quickly made through the response cache, so that the response delay is reduced, and the large language model is frequently called.
Owner:GUANGZHOU UNIVERSITY

Network data encryption and privacy protection system in cloud environment

The application relates to the technical field of cloud computing, in particular to a network data encryption and privacy protection system in a cloud environment, which comprises a key management unit driven by a wolf swarm algorithm, an encryption algorithm optimization unit, a privacy protection strategy dynamic adjustment unit and a security monitoring and abnormal response unit. The cloud environment network data encryption and privacy protection system is constructed based on the wolf swarm algorithm, high-security keys are dynamically generated and distributed through the key management unit, the encryption algorithm optimization unit balances the security performance and resource consumption, the privacy protection strategy unit realizes multi-target dynamic game and compliance guarantee, the security monitoring unit completes distributed attack detection and cooperative defense, and relying on the cooperative feedback mechanism between units, the intelligent encryption protection, dynamic strategy adjustment and efficient attack response of data in the whole life cycle in the cloud environment are realized, and the system security, resource utilization and compliance ability are significantly improved.
Owner:HUNAN WUXIANG ELECTRIC POWER TECH CO LTD

Electric power large language model red team attack test case generation method and related device

The invention belongs to the field of electric power intelligent application, and discloses an electric power large language model red team attack test case generation method and related device.The method comprises the steps that state data are obtained, and iteration is carried out to generate the steps that a preset attack strategy selection model is called according to the state data, obtaining a current attack strategy, generating a new test case through a preset red team large model in combination with the state data, taking the new test case as the current test case to update the state data, and calculating a diversity benefit value and a singleness risk value of the current attack strategy according to all the current test cases; generating empirical data according to a calculation result, and updating a preset attack strategy selection model according to the empirical data; and after iteration is completed, obtaining the test case with the test case attack response being effective in all the test cases as the electric power large language model red team attack test case. According to the method, the diversity and quality of the test cases can be effectively improved, and comprehensive test and optimization of the electric power large language model are supported.
Owner:STATE GRID SHANGHAI MUNICIPAL ELECTRIC POWER CO