Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

178 results about "Attack signature" patented technology

Attack signature. A file containing a data sequence used to identify an attack on the network, typically using an operating system or application vulnerability. Such signatures are used by an Intrusion Detection System (IDS) or firewall to flag malicious activity directed at the system.

Cloud desktop security access control method based on zero-trust architecture

The invention discloses a cloud desktop security access control method based on a zero-trust architecture, belongs to the technical field of network security, and is used for solving the problems of difficulty in hidden attack detection, cross-cloud attack chain breakage and conflict between security control and service continuity in a multi-cloud environment. Firstly, user identity attributes, session metadata and service call logs are aggregated, an identity-resource-behavior triple dynamic graph is constructed, cross-session association features are extracted, and a multi-dimensional behavior baseline is generated. And quantifying the access deviation degree based on the behavior baseline, triggering sensitive operation traceability analysis, constructing a time sequence risk propagation model, identifying latent attack features, predicting a penetration path and outputting a risk propagation coefficient. And finally, dynamically generating a process-level micro-isolation strategy according to a risk result, gradually adjusting the authority through a nonlinear authority attenuation function, inserting a secondary authentication node when unexpected resource jump is detected, reconstructing a communication white list, and realizing collaborative optimization of security protection and service continuity.
Owner:SHENZHEN HUITUO INFORMATION TECH CO LTD

Multi-dimensional security data threat detection method and device based on large model and storage medium

The invention discloses a multi-dimensional security data threat detection method and device based on a large model and a storage medium, and belongs to the technical field of network security, and the method comprises the steps: obtaining multi-dimensional heterogeneous security data, and generating a plurality of basic event descriptions; performing semantic processing on the basic event description to obtain a standardized event description, inputting a pre-trained large language model to perform single-point threat research and judgment, and outputting an event threat evaluation result; splicing the standardized event descriptions of the same target entity into a behavior sequence text, inputting the behavior sequence text into a large language model for multi-stage attack feature analysis, and outputting an attack chain integrity evaluation result; determining a comprehensive threat level based on the event threat assessment result, the attack chain integrity assessment result and the affected asset attribute; and generating a security event analysis report, and extracting the security entities and the association relationships thereof from the report to update the security knowledge graph. The technical breakthrough from traditional'event seeing 'to real'event understanding' is realized.
Owner:GUANGXI POWER GRID CORP

Network information security adaptive threat intelligence analysis and response method and system

The invention provides a network information security adaptive threat intelligence analysis and response method and system. The method comprises the following steps: acquiring an encrypted traffic load byte stream, and segmenting the encrypted traffic load byte stream into a time sequence traffic matrix according to a time window; and analyzing the communication metadata, matching the features of the threat intelligence library, and generating a dynamic threat fingerprint based on protocol compliance and behavior abnormality. And performing multi-stage wavelet packet decomposition on the matrix, extracting the energy spectrum density, the information entropy and the time-frequency variable coefficient of the high-frequency component, and performing weighted fusion to generate a frequency-domain composite abnormal index representing heartbeat signal characteristics. And identifying hidden heartbeat periodicity and protocol violation modes through a multi-mode fusion mechanism in combination with the frequency domain index and the threat fingerprint, and outputting a threat score. And if the attack exceeds the threshold value, intercepting the flow, verifying a new attack feature, and then reversely updating the threat intelligence library to form a defense self-evolution closed loop. According to the method, automatic interception and closed-loop updating of the threat intelligence library are realized, and the defense adaptability is remarkably improved.
Owner:HANGZHOU GUANGMAI TECH

AI-based network security system construction, operation and maintenance method, device and system and medium

The invention relates to an AI-based network security system construction, operation and maintenance method, device and system and a medium. The method comprises the following steps: firstly, acquiring a multi-dimensional data stream, performing feature extraction on the multi-dimensional data stream, and performing dimension reduction by using an algorithm to obtain a low-dimensional feature vector set; fusing an adaptive clustering algorithm according to the vector set to obtain clustering model parameters; extracting novel attack features from the clustering model parameters, and integrating the novel attack features and the clustering model parameters by means of a Bayesian network algorithm to generate a threat situation analysis chart; simulating a multi-scene attack path by utilizing a generative adversarial network algorithm based on the analysis graph, generating a virtual attack data stream and obtaining a defense response result; and finally, aiming at a defense response result, applying a reinforcement learning algorithm to optimize defense strategy parameters, and generating a real-time updated threat situation report after multiple rounds of verification. According to the method, novel attack features can be accurately identified, the accuracy and real-time performance of threat situation awareness are effectively improved, and the ability of a network security system to deal with various complex threats is greatly enhanced.
Owner:GUIZHOU DAILY

Electric power industrial control flow application layer message anomaly detection method and device and electronic equipment

The invention discloses an electric power industrial control flow application layer message anomaly detection method and device and electronic equipment. The method comprises the steps of collecting industrial control network full messages of an electric power system in real time; based on a preset industrial control protocol behavior characteristic spectrum, screening out suspicious traffic fragments deviating from a normal communication normal form from the industrial control network total message to generate a suspicious traffic event chain; performing protocol field regularization processing on the suspicious traffic event chain to extract a cross-level attack feature set; inputting the cross-level attack feature set into an attack identification model subjected to federal learning training for multiple rounds of verification to obtain a determined attack sample of which the attack confidence meets a preset standard; and determining an attack category and a propagation path based on attack sample traceability through the attack characteristic pedigree. According to the method, unknown attacks are captured through a protocol behavior characteristic spectrum, the recognition capability is improved through cross-level characteristic extraction, error and missing report are reduced through federated learning and multi-round verification, and the whole attack process is tracked through event chain and pedigree tracing.
Owner:浙江浙能数字科技有限公司

Data processing method and device, equipment and medium

The invention discloses a data processing method and device, equipment and a medium. The method comprises the steps that a detection threshold value is determined based on a first access traffic log; determining an access behavior for the service domain name based on the number of domain name requests determined by the access traffic indicated by the second access traffic log and a detection threshold; when the access behavior aiming at the service domain name belongs to the abnormal access behavior, taking a behavior determination time point corresponding to the abnormal access behavior as a critical time point, and taking a third access traffic log obtained based on the critical time point as an abnormal access traffic log; when a normal traffic feature determined based on the first access traffic log is obtained, determining an abnormal traffic feature of the service domain name based on the abnormal access traffic log, and performing feature comparison on the abnormal traffic feature and the normal traffic feature to obtain an attack feature of the service domain name; a protection policy for the service domain name is determined based on the attack feature. According to the invention, the security and stability of the business server can be maintained.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

Information security management system based on network operation and maintenance

The invention belongs to the technical field of network information security, and discloses an information security management system based on network operation and maintenance. The method comprises the following steps: periodically acquiring multi-dimensional traffic data of a network node through a traffic acquisition module, and constructing and labeling a network security situation map by means of an asset labeling module; the authority distribution module automatically adjusts the authority of the abnormal access node by analyzing the node access behavior; the threat detection module analyzes the flow in real time, drives the self-adaptive isolation module to quickly isolate threat nodes according to the generated temporary strategy, and updates the joint defense model for cooperative defense; the attack evolution prediction module performs attack path prediction by extracting attack features and optimizes an isolation strategy accordingly; and information leakage is effectively prevented.
Owner:GUANGZHOU PENGLONGJISUANJI TECH CO LTD

Attack detection and source tracing method and apparatus, electronic device, and storage medium

An attack detection and source tracing method includes acquiring entities in a target network environment and interaction event information between the entities and constructing a network event graph with the entities and the interaction event information; determining a graph embedding vector of each interaction event information in the network event graph as feature information based on a preset attack feature recognition model and determining an attack event in the network event graph according to the feature information; determining dependencies between the attack event and remaining interaction event information in the network event graph and searching for a corresponding interaction event information as source tracing information of the attack event according to the dependencies.
Owner:INFORMATION & COMM BRANCH OF STATE GRID JIANGSU ELECTRIC POWER +2

Federal learning poisoning defense method based on time-frequency spectrogram and comparative learning

The invention relates to the technical field of federated learning security, and discloses a federated learning poisoning defense method based on time-frequency spectrogram and comparative learning, which comprises the following steps: receiving model update uploaded by each client, grouping and vectorizing parameters according to model layers, and generating a time-frequency spectrogram by applying short-time Fourier transform to parameter vectors of each layer; based on the time-frequency spectrogram, constructing a positive sample pair through data enhancement, carrying out difficult negative sample mining, and training an encoder by using a contrast loss function to extract an embedded vector with high discriminant power; and performing unsupervised clustering on the embedded vector by using a DBSCAN clustering algorithm, judging the maximum cluster as a benign client, performing final judgment in combination with historical malicious records, and only aggregating model parameters of the benign client to update a global model. According to the invention, high-precision detection of attack features can be realized, and a more universal, more efficient and more practical federal learning poisoning attack defense method is realized.
Owner:SICHUAN UNIV

Network security alarm method and device, electronic equipment and storage medium

The invention provides a network security alarm method and device, electronic equipment and a storage medium, and belongs to the technical field of network security, and the method comprises the steps: obtaining security logs, configuration information and asset importance levels of all security equipment in a network; performing association analysis on the configuration information, and determining attack surface data of each IP point in the network; performing noise reduction and correlation analysis on the security log to obtain processed log information, matching the processed log information with a preset feature library, and filtering alarms of normal service features and alarms of misreported attack features to obtain filtered alarm data; inputting the attack surface data, the asset importance level and the alarm data into a large language model to generate an alarm priority sequence; and executing an automatic response based on the alarm data, the alarm priority sequence and a configured response script. According to the invention, the problem of high false alarm rate of network security alarm in the prior art can be solved.
Owner:BEIJING ANBOTONG TECH CO LTD

System and method to detect and countermeasure RPL attacks in IoT network

A system and a method to detect an attack on an IoT network is disclosed. The IoT network includes interconnection of multiple IoT devices. The method includes receiving, by a network connection device, multiple ICMPv6 network packets from IoT devices and outputting multiple output packets; and matching, by a routing device, a network traffic pattern to attack signatures structured as a taxonomy according to which part of a packet is misused. The taxonomy includes a branch to a data plane attack and a control plane attack, respectively. When an IPv6 RPL packet is detected, the method includes checking for generating, modifying, and replaying attacks by an attacker. When a non-RPL packet is detected, the method includes checking for dropping and leaking packet attacks by the attacker. When the attack is detected, the method includes invoking a solution to the attack. The solution includes mitigation of the attack by the attacker.
Owner:KING FAHD UNIVERSITY OF PETROLEUM AND MINERALS

File-free attack detection method, system and equipment based on multi-view behavior modeling and frequency domain enhanced contrast learning, and medium

The invention discloses a non-file attack detection method, system and device based on multi-view behavior modeling and frequency domain enhancement contrast learning and a medium, and belongs to the technical field of network security, and the method comprises the steps: collecting and coding multi-source behavior data of a target system during operation, and carrying out the unified coding; performing time sequence division on the multi-source behavior data, and constructing a corresponding behavior graph; inputting the divided time sequence into a self-attention mechanism neural network, extracting time domain representation of behaviors, inputting the constructed behavior graph into a graph structure neural network, and extracting structure representation; respectively performing fast Fourier transform on the time domain representation and the structure representation to generate frequency domain representation; constructing a joint contrast learning loss function, and training a consistency detection model; and judging whether the behavior is a file-free attack behavior based on the consistency deviation in combination with an anomaly detection judgment mechanism. According to the method, the non-file-attack characteristic behaviors are accurately identified, and the capability of detecting the non-file-attack in the advanced persistent threats is effectively improved.
Owner:GUANGXI POWER GRID CORP

Cooperative security protection method and device for vehicle-mounted communication link, medium and product

The embodiment of the invention discloses a cooperative security protection method and device for a vehicle-mounted communication link, a medium and a product. The method comprises the following steps: when a communication link of a vehicle is attacked, collecting attack characteristics; acquiring a comprehensive score of an attacked communication link, determining a target strategy template according to the comprehensive score, and uploading an attack feature and the target strategy template to a cloud; when the comparison between the attack feature and the cloud historical attack feature fails, determining that the attack feature is a novel attack feature and performing depersonalization processing to obtain a general attack feature; obtaining result data that the novel attack feature discovery vehicle uses the target strategy template to protect the novel attack feature so as to obtain a general protection strategy; and synchronizing the general attack feature and the general protection strategy to an associated vehicle to perform safety protection. According to the method, identification and depersonalization of novel attacks and generation of universal protection strategies can be realized, and the strategies are synchronized to associated vehicles, so that various attacks can be timely and effectively handled, and the overall protection capability is improved.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

Industrial internet attack and defense situation and risk early warning perception method

The invention discloses an industrial internet attack and defense situation and risk early warning and sensing method, and particularly relates to the field of internet risk early warning and sensing, which comprises the following steps of: acquiring multi-source heterogeneous data, constructing a basic data set covering an attack, service and equipment ternary space, including attack characteristics, service influence and equipment control vectors, and solving the problems of data heterogeneity and dispersion; constructing a triple function based on the data set, respectively quantifying the attack comprehensive threat degree, the influence degree of the attack on the service and the malicious control risk of the equipment, and retaining the characteristics of each dimension; a dynamic network topology model is constructed, nodes, edges and edge weights are defined, an attack propagation path and influence intensity are described, and node state dynamic updating is achieved; and finally, a risk prediction model is constructed by fusing quantitative indexes and topological information, a global risk value is calculated, graded early warning is realized through triple dimensions, a corresponding response mechanism is matched, and the timeliness and effectiveness of industrial internet security protection are improved.
Owner:WANLIAN INDEX (SHANDONG) INFORMATION TECHNOLOGY CO LTD

Unknown attack detection method and system for intelligent network security situation awareness

The invention discloses an unknown attack detection method and system for intelligent network security situation awareness, and the method comprises the steps: obtaining multi-dimensional data of a power grid monitoring system, carrying out the data preprocessing, carrying out the network attack preliminary detection of the multi-dimensional data through a pre-built network security situation awareness framework, and outputting suspected attack data, the method comprises the steps of performing data training on historical attack data through an improved OCN open set classification network, identifying attack features of each known attack type, performing semantic similarity calculation on the attack features and suspected attack data, performing attack feature mapping and clustering on the suspected attack data based on semantic similarity, and obtaining an unknown attack feature clustering result. And according to the unknown attack clustering result, carrying out attack type classification on unknown attacks in the suspected attack data to obtain an unknown attack detection result. The method has the effects of detecting unknown attack means in time, effectively reducing the risk that the power grid system suffers from network attacks and guaranteeing safe and stable operation of the power grid system.
Owner:CHINA DATANG CORPORATION SCIENCE AND TECHNOLOGY GENERAL RESEARCH INSTITUTE +1

Network security attack and defense strategy generation method, system and device fusing knowledge graph and medium

The invention discloses a network security attack and defense strategy generation method, system and device fused with a knowledge graph and a medium, and belongs to the technical field of network security attack and defense strategies, and the method comprises the steps: dynamically constructing a network security knowledge graph containing an attack path and vulnerability association relationship based on multi-source data of a public vulnerability library, dynamic mapping of real-time asset change information and a graph entity is realized through an entity link mechanism, and consistency verification is performed on a mapping relation by using a graph neural network model so as to filter anomalies; structured and unstructured attack feature data are collected in real time from channels such as network traffic, and preprocessing is completed through regular cleaning, feature selection and data quality evaluation; real-time data and a knowledge graph are subjected to multi-dimensional matching, an attack and defense target function of a defense cost target is combined, a candidate strategy set is generated through a genetic algorithm, an incomplete information game model is introduced to calculate sub-game perfect Nash equilibrium to determine an optimal strategy, and a dynamic Bayesian network is utilized to update a strategy transition probability based on historical data.
Owner:GUIZHOU POWER GRID CO LTD

Lightweight SDN attack detection method based on multi-scale iterative attention

The invention discloses a lightweight SDN (Software Defined Network) attack detection method based on multi-scale iterative attention, relates to the technical field of network security, and solves the problem that an SDN attack detection method based on deep learning in the prior art is insufficient in feature selection static state and spatial modeling and gives consideration to both lightweight and high precision. The method is based on a feature contribution degree evaluation mechanism, the most critical features for attack discrimination are screened out in real time, redundant information is eliminated, and the calculation burden is reduced. Moreover, the attack feature map is generated through normalization, time window overlapping slicing and multi-channel space coding, so that the perception capability of a complex attack mode is improved. Besides, a multi-scale iteration attention mechanism is embedded in a lightweight network architecture, key features are highlighted and redundant information is suppressed through multi-granularity convolution extraction and iteration weight fusion, and both lightweight and high-precision detection are realized, so that the method is suitable for real-time network environment and edge device deployment.
Owner:ELECTRIC POWER RES INST OF GUANGXI POWER GRID CO LTD

Security assessment method and device for retrieval enhancement generation system

The embodiment of the invention relates to the technical field of security assessment, and provides a security assessment method and device for a retrieval enhancement generation system, and the method comprises the steps: collecting target data used by the retrieval enhancement generation system; based on the target data, aiming at a plurality of attack types faced by the retrieval enhancement generation system, respectively creating poisoning data corresponding to each attack type; uploading the poisoning data to a knowledge base of a retrieval enhancement generation system to interfere with a working process of the retrieval enhancement generation system; performing multiple rounds of testing on the retrieval enhancement generation system by using the standard test question set to obtain a test result; determining the influence degree of the poisoning data corresponding to each attack type on the retrieval enhancement generation system based on the test result; the vulnerability and attacked features of the retrieval enhancement generation system are evaluated based on the degree of influence. Therefore, poisoning attacks of the retrieval enhancement generation system are carried out under stricter conditions, meanwhile, the concealment of existing attacks is improved, and the safety problem in the retrieval enhancement generation system is relieved.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES +1

Systems and methods for automatic vulnerability mitigation

Disclosed are systems and methods for detecting a vulnerability across programs of an enterprise system and automatically mitigating the vulnerability. The systems and methods utilize artificial intelligence (“AI”) systems to process data received from a particular network, such as systems data, software data, and software configuration data. The AI systems processes the software data and software configuration data and compares the data to known vulnerabilities stored to a database. The system maps the vulnerabilities to attack signatures. When a vulnerability is identified within the network, the AI systems run classification analysis and categorization analysis to determine the probability a vulnerability is a known vulnerability and the category of software it relates to. The system self-executes a rule that enables the attack signatures to protect against the identified vulnerability by either removing or patching.
Owner:TRUIST BANK

Web application firewall rule generation method and device, equipment and medium

The invention relates to a Web application firewall rule generation method and device, equipment and a medium, and the method comprises the steps: obtaining attack feature description information based on log information, latest vulnerability information and user demand information through a large language model; the log information comprises Web request information sent by the client; the newest vulnerability information represents newest vulnerabilities injected in the Web request information; the user demand information represents Web request information needing to be protected by the Web application firewall; calling a target tool through a model context protocol module; generating a Web application firewall rule based on the attack feature description information through the target tool; the target tool is a tool related to Web application firewall rule generation, and the efficiency and accuracy of Web application firewall rule generation are improved.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Industrial Internet of Things LDoS attack intelligent detection method and device

The invention provides an industrial Internet of Things LDoS attack intelligent detection method and device, and relates to the technical field of industrial Internet of Things security, and the method comprises the steps: inputting traffic data into an attack detection fusion model, and outputting the traffic data to obtain an LDoS attack occurrence probability; the method for constructing the attack detection fusion model comprises the following steps: constructing an initial fusion model according to a long-short-term memory network, a convolutional neural network and a graph neural network, dividing a traffic data sample into a training set, a verification set and a test set, and inputting the training set into the initial fusion model for model training; in the training process, according to performance index feedback of the verification set, dynamically adjusting model parameters, optimizing model performance of the model on the test set through multiple rounds of iterative training until expected performance is achieved, and obtaining a trained attack detection fusion model; and when the occurrence probability of the LDoS attack exceeds a preset threshold value, triggering an alarm mechanism, executing a corresponding dynamic defense strategy according to attack characteristics, and recording a dynamic defense processing result.
Owner:CHINA ACADEMY OF INFORMATION & COMM

Systems and methods for vulnerability smart routing

Disclosed are systems and methods for detecting a vulnerability across programs of an enterprise system and notifying remediation agent. The systems and methods utilize artificial intelligence (“AI”) systems to process data received from a particular network, such as systems, software, and software configuration data. The AI systems processes the software and software configuration data and compares the data to known vulnerabilities stored to a database. The system maps the vulnerabilities to attack signatures. When a vulnerability is identified within the network, the AI systems run classification analysis and categorization analysis to determine the probability a vulnerability is a known vulnerability and the category of software it relates to. The AI systems then runs a remediation agent analysis to determine the proper remediation agent to mitigate the vulnerability. Once a remediation agent is determined, a remediation agent is notified of the vulnerability and mitigates the vulnerability by removing or patching.
Owner:TRUIST BANK

Construction method and system of dynamic threat capture system

The invention provides a construction method and system for a dynamic threat capture system, and relates to the technical field of system construction, and the method comprises the steps: obtaining heterogeneous security data, extracting a three-domain behavior portrait, constructing a multi-dimensional feature vector, and recognizing attack features; dynamically constructing a virtual target environment to guide attacks, and obtaining threat data based on multi-modal perception; constructing a feature library for comparison, predicting an attack path, and generating a protection rule; and deploying protection measures to obtain confrontation data, and updating the feature library optimization rule. According to the invention, accurate identification, effective trapping and continuous confrontation of network threats can be realized, and the network security protection capability is improved.
Owner:JIANGSU BOZHI SOFTWARE TECH CO LTD

Malicious request interception system based on multi-dimensional behavior analysis and cloud-ground cooperation

The invention provides a malicious request interception system based on multi-dimensional behavior analysis and cloud-ground collaboration, relates to the technical field of network security, and analyzes normal equipment characteristics, a user behavior sequence and a cloud malicious equipment blacklist by collecting TCP / IP protocol stack characteristics and combining dynamic characteristics of the user behavior sequence. First interception is performed according to an analysis structure, deep identification is performed on a user behavior sequence after the first interception based on time sequence analysis and clustering analysis, and second interception is performed according to an identification result, so that the problems that a static rule cannot identify novel attacks and group attack features are difficult to capture are solved; and carrying out content verification on the user behavior sequence after the second interception, and carrying out third interception according to a verification result, thereby realizing dynamic adaptation of a service scene, solving the problem of poor static rule adaptability, carrying out whole system synchronization on all intercepted malicious logs, avoiding cross-node missed interception of malicious requests, and forming a defense iteration closed loop.
Owner:SHENZHEN INTERNET PIONEER TECH CO LTD

Network security intelligent detection method based on big data

The invention relates to the field of data security, in particular to a network security intelligent detection method based on big data, and the method comprises the steps: collecting network flow data, a terminal system call sequence and a user operation behavior log, and carrying out the data fusion processing to generate a unified behavior event flow; selecting a key behavior event based on an information entropy threshold value, performing time alignment through a dynamic time warping algorithm, and constructing a behavior gene map containing a communication association gene, an operation sequence gene and a behavior time sequence gene; a dynamic behavior baseline model is established by using unsupervised learning, and gene mutation detection and alarm are realized by calculating the deviation degree of each gene dimension; the detection performance is evaluated based on the false alarm rate, model parameters are optimized through a negative feedback mechanism, and acknowledged attack features are stored in a sharable threat gene feature library through a positive feedback mechanism. According to the method, the detection accuracy is continuously improved through a closed-loop learning mechanism, and a self-adaptive safety protection system with self-optimization capability is constructed.
Owner:BEIJING JINBO SHUNCHANG NETWORK TECHNOLOGY CO LTD

Network security knowledge graph construction method and system

The invention relates to the technical field of network security, in particular to a network security knowledge graph construction method and system, and the method comprises the following steps: extracting information from original network traffic, logs and threat intelligence, extracting attack features, classifying and storing the attack features in a knowledge base, screening high-risk nodes, judging weak points, generating dynamic keys, and distributing and storing the dynamic keys. The method comprises the following steps of: extracting attack characteristics, carrying out logic classification, constructing a multi-dimensional associated security data system, identifying a threat path and a high-risk node, combining abnormal detection and path complexity comparison, encrypting basic data, verifying and decrypting, adjusting a security policy rule according to an environment, and executing dynamic adjustment of a network security protection policy. According to the method, hidden weak points are accurately judged, a dynamic key generation and distribution mechanism is adopted, encryption consistency and security are improved, distributed encryption exchange and real-time verification are matched, confidentiality and integrity of data transmission and storage are guaranteed, protection self-adaptive adjustment is achieved according to an environment state matching strategy, and response efficiency and flexibility are improved.
Owner:SICHUAN POLICE COLLEGE

Gateway equipment attack detection method and system

The invention discloses an attack detection method and system for gateway equipment. According to the heterogeneous cooperative defense system based on protocol context awareness provided by the invention, a'kernel mode instruction recombination-user mode adversarial learning 'double-engine architecture is innovatively constructed, and low-delay extraction of attack features and active evolution of a protection strategy are realized. Specifically, the invention provides a migration type adversarial evaluation model, which breaks through the dependence of a traditional detection scheme on protocol grammar, dynamically constructs a cross-protocol attack sample through a generative adversarial network, captures traffic time sequence anomaly in combination with a bidirectional LSTM, and constructs a dynamic graph containing threat propagation probability and resource occupation trend. Therefore, feature migration and generalization modeling can be carried out on unknown or variant attack behaviors, the recognition capability on zero-day attacks and cross-protocol attacks is enhanced, and finally the detection accuracy is improved.
Owner:HUAZHONG UNIV OF SCI & TECH

Multivariate attack feature recognition method and system based on persistent threat attack

The invention is suitable for the technical field of network security, and provides a multivariate attack feature recognition method and system based on persistent threat attacks, and the method comprises the steps: obtaining a real-time traffic data sequence in a target network environment; performing primary anomaly sensing processing on the real-time traffic data sequence to obtain a suspicious traffic fragment set; executing thinking chain reasoning analysis on the suspicious traffic fragment set, and generating an attack behavior reasoning path comprising multi-stage reasoning steps; performing matching verification on the attack behavior reasoning path and a pre-constructed threat intelligence knowledge base, and determining an attack stage and an attack intention of the persistent threat attack; and generating a multivariate attack feature recognition result according to a matching verification result. According to the method, analysis of advanced persistent threat attack multi-stage features is realized through a thinking chain reasoning mode, and the timeliness and reliability of detection are improved, so that the active protection capability of network security is improved.
Owner:CHINA DATANG CORPORATION SCIENCE AND TECHNOLOGY GENERAL RESEARCH INSTITUTE +1

A method and apparatus for detecting lateral movement behavior of encrypted traffic

This invention provides a method and apparatus for detecting lateral movement behavior in encrypted traffic, relating to the field of network security technology. The method includes: first, using an eBPF probe mounted at a critical location in the network protocol stack to capture network traffic data about to be encrypted; second, filtering communication traffic related to lateral movement attacks and matching the relevant communication traffic against predefined lateral movement rules. If a match is found between the traffic and the lateral movement attack rules, it is determined that the target host exhibits lateral movement behavior. Otherwise, a dynamically adjusted behavior model is used to further analyze traffic anomalies, and a security alert is triggered when suspicious behavior is detected. This invention can utilize eBPF combined with known attack characteristics and a behavior analysis model to identify encrypted lateral movement attack behavior, improving the accuracy of identification.
Owner:CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1

Network intrusion prevention method and device and medium

The invention relates to a network intrusion prevention method and device and a medium, and belongs to the technical field of network security. The method comprises the following steps: acquiring a network data packet; matching the network data packet with a pre-established attack feature library to judge whether an attack behavior exists or not; inputting the network data packet into a normal network behavior baseline model to judge whether an abnormal behavior exists or not; if the attack behavior exists and the abnormal behavior exists, generating a potential attack signal, attack type information, an abnormal behavior signal and behavior abnormal degree information; based on the potential attack signal, the attack type information, the abnormal behavior signal and the behavior abnormal degree information, judging whether an intrusion behavior exists or not; and if the intrusion behavior exists, executing a defense action on the intrusion behavior. According to the method and the device, the intrusion is efficiently detected and defended on the OpenWRT platform based on the embedded Linux system.
Owner:四川长虹新网科技有限责任公司