Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

108 results about "Attack strategy" patented technology

Energy internet intelligent key node identification and elasticity enhancement method based on semantic digital twinning and adversarial evolution deduction

The invention discloses an energy internet intelligent key node identification and elasticity enhancement method and system, and the method comprises the steps: 1, constructing and dynamically maintaining a semantic enhanced energy internet digital twin super network and a multi-modal knowledge graph, fusing multi-dimensional information, and achieving the self-evolution and dynamic reasoning capability; 2, based on the model, fusing multi-time scale prediction data, and adaptively evaluating the dynamic comprehensive criticality of the node through an intention-function-resource-vulnerability four-layer penetrating traceability model; 3, aiming at the key nodes, generating an intelligent attack strategy by utilizing a generative adversarial network, deducing an information physical cascade failure process by combining multi-agent deep reinforcement learning, and quantitatively evaluating the system elasticity; and step 4, based on an evaluation result, generating a self-adaptive security reinforcement and dynamic reconstruction decision oriented to active immunity and elastic optimization. According to the method, the accuracy and the dynamism of key node identification can be remarkably improved.
Owner:GUODIAN NANJING AUTOMATION

Virtual simulation and security evaluation method and system based on network security target range

The invention discloses a virtual simulation and security evaluation method and system based on a network security target range, and the method comprises the steps: constructing a network asset knowledge graph for describing a virtualized target range environment through information collection; secondly, based on an attack strategy grammar rule base, adopting a Monte Carlo Tree Search (MCTS) algorithm to carry out intelligent attack simulation on the knowledge graph so as to discover a nonlinear and multi-stage attack path; thirdly, constructing a Bayesian attack graph (BAG) based on the knowledge graph, and performing probabilistic and systematic quantitative evaluation on the security risk of each asset node in the network through Bayesian reasoning; and finally, integrating the attack path and the quantitative risk value, and generating a comprehensive assessment report containing a visual path, a risk sequence and a reinforcement suggestion. According to the target range simulation method and device, the problems that existing target range simulation is insufficient in confrontation authenticity, one-sided in safety evaluation and lack of predictability are solved by combining the strategy simulation of the MCTS and the global quantitative analysis of the BAG.
Owner:BEIJING BO YI WANG XUN SCI & TECH CO LTD

Information system security evaluation method and device, electronic equipment and storage medium

PendingCN121030748APlatform integrity maintainanceKnowledge representationAttackInformation systems security
The embodiment of the invention provides an information system security evaluation method and device, electronic equipment and a storage medium, and the method comprises the steps: obtaining an evaluation index model corresponding to a security evaluation request, and obtaining a simulation system corresponding to a target information system; performing vulnerability scanning on the simulation system based on the scanning missing tool and the MDATA knowledge base to obtain a corresponding first scanning result and a corresponding second scanning result, and performing scanning result fusion analysis based on the MDATA knowledge base to obtain a system risk assessment result of the simulation system; obtaining an optimized attack strategy based on the system risk assessment result and the MDATA knowledge base, and obtaining an optimized defense strategy based on the system risk assessment result and the expert knowledge base; the attack and defense test is performed on the simulation system based on the optimized attack strategy and the optimized defense strategy to obtain the attack and defense test result, and the security evaluation result of the target information system is obtained based on the evaluation index model and the attack and defense test result, so that the accuracy of evaluating the information system is improved.
Owner:PENG CHENG LAB

Unmanned aerial vehicle threat intention prediction method and device and storage medium

The invention relates to an unmanned aerial vehicle threat intention prediction method and device and a storage medium, and is applied to the technical field of anti-unmanned aerial vehicles. The method specifically comprises the steps that through multi-modal deep feature fusion and deep adversarial learning, the system can extract deeper and more abstract unmanned aerial vehicle behavior mode features from multi-source heterogeneous data, so that accurate prediction of the real threat intention of the unmanned aerial vehicle is achieved, the limitation that a traditional method is only based on surface feature judgment is overcome, and the accuracy of the unmanned aerial vehicle threatening intention prediction is improved. The transformation of threat assessment from post-event analysis to pre-event prediction is realized; in the deep adversarial learning framework, various complex unmanned aerial vehicle threat behavior modes including disguise, interference and novel attack strategies can be simulated, and meanwhile, the recognition capability is continuously improved in adversarial training, so that the system can still keep high accuracy and low false alarm rate when facing unknown or variable threats, and the safety of the system is improved. And the robustness and adaptability of the system are obviously enhanced.
Owner:HANGZHOU LANDE INTELLIGENT TECHNOLOGY CO LTD

Black box code search model backdoor attack method based on learnable discrete code transformation

A black box code search model backdoor attack method based on learnable discrete code transformation comprises the steps that a learnable backdoor generator is constructed, and malicious codes with backdoors are generated on the premise that internal parameters of a damaged model are not accessed through the learnable discrete code transformation. Firstly, an agent model capable of simulating victim model behaviors is trained through query-response data; secondly, on the proxy model, a discrete selection process is differentiable by using a re-parameterization sampling technology, and a backdoor generator is trained in combination with a multi-objective loss function so as to realize effectiveness and concealment of backdoor implantation; according to the method, the limitation of a black box is successfully bypassed by constructing the proxy model, and a new possibility is provided for an attacker. A backdoor generation process is integrated into a differentiable training framework through learnable discrete transformation, so that end-to-end learnability is realized, and an attack strategy can be automatically optimized.
Owner:NANJING UNIV OF POSTS & TELECOMM

Large model output data security detection method and system based on adversarial attack

The invention discloses a large model output data security detection method and system based on adversarial attacks. The method comprises the following steps: constructing and optimizing a strategy space containing a plurality of attack strategies, and grading and sorting the strategies to improve the attack efficiency; generating a single-strategy antagonism prompt by the attack model according to the optimized strategy space, and performing effectiveness evaluation and feedback correction on the prompt by the judgment model; inputting a prompt passing the evaluation into the target large model to obtain a response, and performing malicious degree scoring on the response by the judgment model; and if the single-strategy attack is not successful, introducing an optimization mechanism based on a genetic algorithm, generating a more complex multi-strategy antagonism prompt through strategy variation and crossover, and carrying out iterative attack until the target large model is successfully broken into the prison. According to the method, the security defects of the large model can be efficiently and comprehensively detected in a self-adaptive and multi-strategy attack mode.
Owner:CHINA ACADEMY OF INFORMATION & COMM

Industrial network attack strategy prediction and defense decision-making system

The invention relates to the technical field of industrial control system network security, and discloses an industrial network attack strategy prediction and defense decision-making system, which comprises a semantic modeling module used for analyzing a configuration and communication file construction function and variable coupling hypergraph, and describing causal mapping from a network instruction to a physical variable; the dynamic evolution module is used for reconstructing a phase space based on the physical time sequence data, identifying an implicit coupling relationship and updating a hypergraph structure; the strategy prediction module is used for deducing a physical trajectory after instruction execution by combining the hypergraph and the phase space model, and judging a destructive attack strategy according to the maximum Lyapunov index; and the defense decision module triggers a virtual-real state bifurcation mechanism, generates an inertia compensation signal to maintain physical stability, and generates and constructs feedback data to cheat an attacker. According to the method, through cross-domain coupling modeling and dynamic deduction, physical destructiveness is accurately predicted, production maintenance and attack spoofing are considered through virtual-real bifurcation, and the reliability of defense decision making is effectively improved.
Owner:国能神福(石狮)发电有限公司

Big language model safety detection system, device and equipment based on double-model adversarial evaluation

The invention relates to a big language model security detection system, device and equipment based on double-model adversarial evaluation, and the method comprises the steps: carrying out the variation of sensitive vocabularies through a dynamic load variation technology based on user configuration and an attack strategy template, generating diversified attack loads, and carrying out the recognition of a big language model according to the generated attack loads. Attack testing is carried out through a double-model adversarial evaluation architecture, model response content and a security judgment result are obtained, a risk score is calculated through a multi-dimensional quantitative scoring method according to the security judgment result, and a comprehensive security risk evaluation report is generated. According to the method, diversified hidden attacks are generated through a plug-in strategy library and a dynamic load variation technology; a double-model adversarial architecture is adopted, attack and detection roles are separated, an unbiased test closed loop is realized, multi-dimensional indexes are fused based on an information entropy-analytic hierarchy process, a risk assessment value is calculated, a report is generated, and scientific and accurate quantitative assessment of the security of the large language model is realized.
Owner:CHINA IND INTERNET RES INST

Attack data generation and large model training method and device, equipment and storage medium

The invention provides an attack data generation and large model training method and device, equipment and a storage medium, and belongs to the technical field of artificial intelligence, and the method comprises the steps: inputting guide content into an attack language model to obtain an attack prompt, determining the attack prompt with the highest attack success rate as a target attack, and collecting attack data related to the target attack prompt. According to the method, the attack language model is excited by the initial guide content to generate diversified attack prompts, and the most effective attack prompt is screened out based on the attack success rate to serve as the target attack prompt for data collection, so that various attack prompts can be automatically generated, and the workload of manually designing the attack prompts is reduced; in addition, the validity and quality of the collected attack data can be ensured through a screening mechanism, and a rich and accurate data basis is provided for subsequent model security evaluation and attack strategy optimization, so that potential vulnerabilities of the target language model can be found more comprehensively, and the security and reliability of the model are improved.
Owner:HEFEI IFLY DIGITAL TECH CO LTD

Method, device and equipment for evaluating survivability of SPN (Shortest Path Network), and readable medium

The invention discloses an survivability evaluation method, device and equipment of an SPN (Shortest Path Network) and a readable medium. Constructing an SPN network initialization model based on the actual SPN network operation state of the to-be-evaluated area, wherein the SPN network initialization model comprises network nodes corresponding to actually deployed transmission network elements and a network structure of IP routing connection relationships of the network nodes; setting node load and node capacity of each network node; setting at least one simulation attack strategy aiming at the SPN network initialization model; attacking the network nodes in the SPN network initialization model based on a simulation attack strategy, distributing the node load of the network node which fails after attack to other network nodes, and monitoring whether the redistributed network node is overloaded and fails until no new network node fails; and determining a survivability index based on the number of non-invalid nodes in the SPN network initialization model and the number of total network nodes, and performing survivability evaluation. According to the scheme of the invention, survivability evaluation for SPN network characteristics can be realized.
Owner:SHANXI CHINA MOBILE COMM CORP +1

Intelligent internet-of-things visual centralized control system platform and method based on digital twinborn technology

The invention relates to the technical field of Internet of Things data management, and discloses an intelligent Internet of Things visual centralized control system platform and method based on a digital twinborn technology, and the platform comprises a multi-source data collection module which outputs a physical equipment heterogeneous data stream with a timestamp; the data storage and management module is used for receiving the heterogeneous data stream and outputting a standardized data packet; the quantum edge processing module is used for performing cross-modal feature compression on the standardized data packet and outputting a dimension reduction feature flow; the causal fusion engine module is used for constructing a dynamic causal topology network based on the dimension reduction feature flow; an adversarial evolution twinborn body module; and a visual centralized control module. A three-level attack strategy of sensor spoofing, parameter tampering and cascading failure is optimized through a generative adversarial network, an attack vector is generated under the constraint of an equipment physical rule, the physical feasibility of an attack is verified through a discriminator, a conduction path of the attack in a causal topology is simulated, dynamic optimization and risk conduction deduction of the attack strategy are realized, and the risk conduction deduction of the attack strategy is realized. And the risk pre-judgment capability is improved.
Owner:JIANGSU SANER SHIYUAN DIGITAL TECHNOLOGY CO LTD

An attack-defense confrontation method and system based on chemical engineering dynamic simulation

A method and system for attack and defense based on dynamic simulation in chemical engineering includes: constructing an adversarial training environment for chemical equipment and processes using dynamic simulation units; setting attack and defense training parameters through a task configuration unit and generating corresponding fault interference test cases from a fault interference mode library; the attacker selecting a fault interference test case, adjusting the fault interference parameters using an attack strategy, and injecting it into the adversarial training environment; the defender receiving alarm information from the fault interference test cases and performing handling operations on them; and an evaluation unit performing real-time evaluation and display. This invention, through the deep integration of dynamic simulation technology and attack and defense mechanisms, upgrades chemical skills training from static procedure drills to dynamic engineering practice, providing core technical support for the cultivation of highly skilled personnel in the process industry, and has significant economic and social value.
Owner:BEIJING EAST SIMULATION & CONTROL TECH CO LTD

Failure analysis method and related device, electronic device and storage medium

The application discloses a failure analysis method and related device, electronic equipment and storage medium, wherein the failure analysis method comprises: detecting based on the description document of the target agent to obtain the design elements of the target agent; analyzing based on the failure mode knowledge base and each design element to determine the first element suspected of existing failure risk and the first risk degree of the first element in each design element; selecting the first element as the second element based on the first risk degree of each first element; generating the test session and the adjudication rule of the second element based on the attack strategy knowledge base and the second element; determining the test reply of the second element based on the adjudication rule of the second element to obtain the second risk degree of the second element. The above scheme can identify the failure risk of the agent in advance before the agent goes online, and quantize the failure risk.
Owner:IFLYTEK CO LTD

Data-driven information physical system hidden attack design method and device

The invention provides a data-driven information physical system hidden attack design method and device, and relates to the technical field of information physical system security. The method comprises the steps of obtaining data of a normal closed-loop operation stage of the cyber-physical system, defining a signal structure, constructing a data matrix, obtaining a stable image expression of the cyber-physical system, obtaining a stable nuclear expression according to the stable image expression, constructing a stable nuclear expression under attack, defining a concealment measure, and setting a concealment constraint. And obtaining a feasible hidden attack set under constraint, defining a performance degradation index, designing a performance optimization problem, solving the performance optimization problem to obtain optimal attack input, and realizing data-driven information physical system hidden attack design. According to the method, the defects of a traditional attack design method which depends on an accurate model or is limited to open-loop hypothesis in the actual industry are effectively overcome, the feasibility and destructive power of an attack strategy in a real closed-loop environment are improved, and the method is suitable for a wider information physical system.
Owner:UNIV OF SCI & TECH BEIJING

Self-adaptive large model hint attack and security evaluation method based on feedback learning

The invention provides an adaptive large model hint attack and security assessment method based on feedback learning, and belongs to the technical field of artificial intelligence security. The method comprises the following steps: constructing an attack library containing a plurality of text transformation attack strategies, and obtaining expression data of the attack strategies on a target model; the success rate, the average score and the R value and the Q value of the attack strategy are calculated through the data, and the optimal attack strategy is selected in a descending order according to the Q value; applying the strategy to an original malicious prompt to generate adversarial input, submitting the adversarial input to a target model, judging whether an attack is successful or not through a pre-training evaluation model score, if yes, re-selecting the strategy, if yes, updating statistical data, re-calculating the score, and iteratively trying the strategy according to a Q value until a preset condition is met; and finally recording a test process and generating a report. According to the method, the security evaluation of the large model is realized, the success rate and efficiency of attack testing are improved, an empirical basis is provided for the design of a large model defense mechanism, and the application security of the large model is ensured.
Owner:QILU UNIVERSITY OF TECHNOLOGY (SHANDONG ACADEMY OF SCIENCES) +1

Building collapse strategy pool generation method and strike strategy generation method

The invention discloses a frame building collapse strategy pool generation method and a strike strategy generation method. A building collapse strike strategy rapid generation method comprises the following steps: step 1, giving building description parameter values; 2, the number of hit columns is given; step 3, initializing and selecting a strike strategy number; 4, building collapse area calculation is carried out; 5, calculating the corrected collapse area of the first strike strategy; 6, if yes, executing the next step; otherwise, repeating the steps 4-5 until the correction values of the calculation results of the collapse areas of all the strike strategies are generated; step 7, selecting the maximum value from the maximum value, and giving a corresponding strike strategy number; 8, if yes, the building cannot be collapsed due to the current number of the hit columns; otherwise, the first strike strategy is a building collapse strike strategy. The method is suitable for the conditions of different building description parameters and the number of hit columns, the hit strategy can be rapidly calculated, and the generation time of the hit strategy is the second level.
Owner:XIAN MODERN CHEM RES INST

Attack and defense strategy game method and system for multi-uav target assignment

The application provides a kind of multi-unmanned aerial vehicle target allocation attack-defense strategy game method and system. Multi-unmanned aerial vehicle formation information of first unmanned aerial vehicle formation and second unmanned aerial vehicle formation is acquired to generate strategy pair of multiple unmanned aerial vehicles according to unmanned aerial vehicle information, and strategy group set of multi-unmanned aerial vehicle formation is generated according to strategy pair, strategy pair can include current unmanned aerial vehicle, attack-defense strategy and strategy target;Attack-defense strategy includes attack strategy, avoidance strategy and interference strategy. By calculating the probability distribution of each unmanned aerial vehicle under different attack-defense strategies, a payoff matrix is constructed, and a zero-sum game matrix model is further generated. Based on the zero-sum game matrix model, the attack-defense strategy game solution of multi-unmanned aerial vehicle target allocation is solved. The application fully considers the three attack-defense strategies of unmanned aerial vehicles, and solves the attack-defense strategy game solution, thereby improving the solution quality of unmanned aerial vehicle target allocation problem.
Owner:江淮前沿技术协同创新中心 +1

A multi-unmanned agent-oriented cooperative fire attack strategy generation method

ActiveCN116451782BGenetic algorithmsConcurrent computationEvolutionary computation
The application provides a multi-unmanned agent-oriented cooperative firepower attack strategy generation method, and belongs to the field of intelligent game strategy generation. The method comprises the following steps: constructing an adversarial environment, generating an initial strategy population, performing parallel calculation on the fitness of the strategy population, performing crossover and mutation on the strategy population, and iteratively evolving the strategy population. The application solves the problems of large calculation amount and long training time of the intelligent game strategy generation method, represents the strategy as an action sequence, constructs fitness based on game winning rate, uses parallel multi-opening evolutionary calculation method, and intelligently, automatically and efficiently generates a cooperative firepower attack strategy with the fitness as the optimization target.
Owner:THE 54TH RESEARCH INSTITUTE OF CHINA ELECTRONICS TECHNOLOGY GROUP CORPORATION

Load replacement attack defense method and device based on topology switching and power flow regulation

The present application belongs to the field of electric digital data processing, and particularly relates to a load replacement attack defense method and device based on topology switching and power flow regulation. The defense method solves the optimal joint deployment strategy by constructing a double-layer Stackelberg game model for cooperatively defending the load replacement attack by integrating intelligent soft switches and remote control switches, wherein the upper defense model plans to comprehensively consider the constraint conditions such as voltage regulation, power flow balance, radial network structure and continuity, so as to minimize the equipment investment-operation cost and voltage out-of-limit index; in the lower attack model, the optimal attack strategy of the resource-limited attacker is generated under the given defense strategy of the defender to maximize the voltage deviation. The problems that the traditional topology switching-based defense method has response lag, limited regulation capacity, and the mitigation strategy of deploying only intelligent soft switches faces high deployment cost and poor defense effect are solved.
Owner:QILU UNIVERSITY OF TECHNOLOGY (SHANDONG ACADEMY OF SCIENCES) +1

Network game strategy generation method based on node average path constraint

The application discloses a network game strategy generation method based on node average path constraint, and the method comprises the following steps: acquiring the topological structure of a network, determining the strategy set of an attack party and a defense party, and constructing a basic model of the network game; calculating the shortest path between nodes in each attack strategy and each defense strategy, taking the average value, and obtaining the average path corresponding to each attack strategy and each defense strategy; setting a constraint function based on the average path, so that the selection probability of each attack strategy and each defense strategy is less than the corresponding function value, and obtaining the strategy constraint set of the attack party and the strategy constraint set of the defense party; representing the network performance by a maximum connected piece scale index, calculating the income of the attack party and the defense party under each strategy profile, and obtaining the income matrix of the network game model; and replacing the basic model of the network game with a linear programming problem for solving, and obtaining the mixed strategy Nash equilibrium solution of the attack party and the defense party.
Owner:NAT UNIV OF DEFENSE TECH

Large language model self-adaptive security protection method and system, and storage medium

PendingCN122457379A
The application provides a large language model adaptive security protection method and system, and a storage medium, the method breaks the hysteresis of the traditional defense strategy by constructing a three-agent collaborative architecture of an attack strategy generator, a dynamic defense device and a defense and attack environment evaluator, combining a double-layer optimization and a dynamic evolution mechanism, driving a two-way iteration relying on attack and defense utility quantitative scores, and synchronously evolving the defense capability and the attack evolution; the method constructs a double-layer defense capability for coping with the current situation and predicting the future by real-time adaptation of the defense parameters to the current attack and pre-judgment of the new attack by the defense parameter, improves the generalization to unknown attacks; the method strengthens the learning and identification of high uncertainty attacks by combining meta-learning attack evolution and threat entropy weighted loss, reduces the bypass probability of new attacks; the method balances the security and usability of the large language model by using a dynamic threshold judgment, realizes adaptive and highly reliable security protection in an open scene, and has better generalization.
Owner:SHENZHEN SHENNONG INFORMATION TECHNOLOGY CO LTD

Denial of service attack strategy making method for consistency control of multi-agent system

The DoS attack strategy making method based on the multilayer cut points is provided for consistency control of the multi-agent system, and the state consistency of the multi-agent system is effectively influenced under the condition that it is guaranteed that the attacker consumes relatively little energy. The method comprises the steps that a multi-agent system consistency model and a DoS attack model are established, an objective function is obtained by taking energy consumption of an attacker and a system consistency error as two indexes, multi-layer cut points are used for replacing an attack action space to improve the optimization efficiency of the objective function, and an attack strategy is obtained by optimizing the objective function. The attack research essence is to guarantee the improvement of the system security performance, and the method provided by the invention can be used as a link for testing the system security to help discover the defects in the aspect of system defense.
Owner:NANJING UNIV OF AERONAUTICS & ASTRONAUTICS

Anti-attack method and network equipment

The invention provides an anti-attack method and network equipment, and the method comprises the steps: a carrier level network address translation CGN creates an anti-attack table for an access user, and when the user meets an attack condition, the message flow of the user is processed according to an anti-attack strategy in the anti-attack table of the user. Through the method, the CGN aims at the attack prevention of the user level.
Owner:NEW H3C TECH CO LTD

A network intrusion detection model end-to-end adversarial training defense method and device

This invention relates to the field of network security technology, and more particularly to a method and apparatus for adversarial training and defense of a network intrusion detection model. The method includes: dynamically outputting attack strategies based on traffic feature vectors and current strategy parameters using an adversarial strategy generator; imposing restrictions on perturbations in the problem space through adversarial domain constraints to ensure that the generated adversarial samples conform to network protocol specifications and feature logic consistency requirements; and forming a dynamic game mechanism by alternately executing adversarial training and strategy parameter optimization between the intrusion detection model and the adversarial strategy generator. This allows the model to gradually improve its defense capabilities against mixed threats in the feature space and problem space as it continuously adapts to increasingly complex attack patterns, ultimately achieving a synergistic improvement in the robustness and generalization of the intrusion detection model.
Owner:CHINA STATE SHIPBUILDING CORP LTD RESEARCH INSTITUTE 719

Network security target field-based virtual simulation and security evaluation method and system

The application discloses a network security target-based virtual simulation and security evaluation method and system. First, a network asset knowledge graph describing a virtual target environment is constructed through information collection. Second, intelligent attack simulation is performed on the knowledge graph based on an attack strategy syntax rule library using a Monte Carlo tree search (MCTS) algorithm to discover nonlinear and multi-stage attack paths. Third, a Bayesian attack graph (BAG) is constructed based on the knowledge graph to probabilistically and systematically quantitatively evaluate the security risks of asset nodes in the network through Bayesian inference. Finally, the attack paths and quantitative risk values are integrated to generate a comprehensive evaluation report containing visualized paths, risk rankings and reinforcement suggestions. The application solves the problems of insufficient realism of existing target simulation, one-sided security evaluation and lack of predictability by combining strategic simulation of MCTS and global quantitative analysis of BAG.
Owner:BEIJING BO YI WANG XUN SCI & TECH CO LTD

New energy automobile CAN bus UDS diagnosis attack test method and system and medium

The invention discloses a new energy automobile CAN bus UDS diagnosis attack test method and system and a medium, and aims to quickly discover potential security holes in the design of a diagnosis system by simulating an actual attack behavior so as to provide reference for security improvement of a vehicle diagnosis system. According to the method, the diagnosis ID is predicted, so that the possible diagnosis ID range is effectively reduced, and the diagnosis ID collection efficiency and accuracy are improved. On the basis, a dynamic attack strategy generation module is utilized, attack parameters are optimized through reinforcement learning, the sending period and data content of the message are dynamically adjusted in combination with an attack feedback result, and a more targeted attack strategy is generated, so that the attack success rate is improved. The specific test comprises diagnosis ID collection, basic service attack request, DID collection and tampering and abnormal request attack test, and the safety of the vehicle diagnosis system is comprehensively analyzed.
Owner:CHINA AUTOMOTIVE ENG RES INST +1

Efficient private protocol reverse analysis method and system

PendingCN121396677ASecuring communicationReverse analysisProtocol Keyword
The invention provides an efficient private protocol reverse analysis method and system, and the method comprises the steps: recognizing the basic information of a protocol through static analysis, and deducing a protocol structure through dynamic analysis; on the basis of the protocol structure, performing semantic recognition on the key field; based on a semantic recognition result, a cognitive attack decision network is constructed as a decision core, intelligent scheduling of execution components such as a generative adversarial network is realized, and protocol key fields and fine-grained semantic analysis and intelligent attack vectors are constructed. A cognitive attack decision network is introduced as an intelligent decision core and is combined with a generative attack network, so that the method is not limited to single attack load generation, is responsible for formulating and optimizing an advanced attack strategy, intelligently dispatches various attack generation components at a lower layer, can recognize the meaning of each protocol field in a finer-grained manner, and improves the attack efficiency. And then targeted feedback and optimization are performed, so that higher-level intelligence is achieved.
Owner:CHINESE PEOPLES LIBERATION ARMY ARMY SERVICES UNIVERSITY

A robust adversarial training framework for multi-agent reinforcement learning energy system

ActiveCN116306903BMachine learningNeural learning methodsStrategy trainingAlgorithm
The present application relates to a kind of robust confrontation training framework for multi-agent reinforcement learning energy system, comprising: constructing an adversarial agent to generate adversarial attack, and modeling as adversarial partially observable stochastic game system;Fixed pre-trained victim multi-agent strategy, train an optimal deterministic confrontation strategy to produce bounded disturbance;Fixed optimal confrontation attack strategy, improve the robustness of victim strategy under optimal attacker through adversarial training.The beneficial effects of the present application are: the present application models adversarial attack as an attack adversary based on single-agent reinforcement learning, and learns the strongest attack strategy considering attack constraints.Mathematically, the problem is constructed as a confrontation Markov game, and the performance of the integrated energy management system based on multi-agent reinforcement learning is improved through robust confrontation training.
Owner:ZHEJIANG ZHENENG YUEQING POWER GENERATION CO LTD +1

Computer Network Intrusion Detection and Prevention Methods Based on Anomaly Data Analysis

This application discloses a computer network intrusion detection and defense method based on anomaly data analysis, relating to the field of computer network technology. The method includes: collecting a multi-dimensional dataset; extracting the correlations between anomaly data to form an anomaly correlation rule set; fusing multi-source features to form an anomaly feature set; establishing an intelligent agent model; the intelligent agent executing an attack task; inputting the anomaly data set into the intrusion detection model to obtain the first-stage detection result; comparing and analyzing the first-stage detection result with the first-stage simulated attack result to obtain feedback information; optimizing the second-stage attack strategy and executing the optimized second-stage attack strategy to obtain the second-stage detection result; extracting anomaly features to form a final anomaly feature set; generating repair instructions based on the final anomaly feature set and executing the repair instructions to repair the computer network. This application's method overcomes the limitations of single attack simulation and deepens the two-stage attack optimization, improving detection accuracy.
Owner:XIANYANG VOCATIONAL TECHN COLLEGE

Defensive strategy self-generation method and system for intelligent device cluster

The application discloses a defense strategy self-generating method and system for a smart device cluster, and belongs to the technical field of network security of a smart device cluster. The system comprises a network modeling module, an attack strategy integration module and a defense strategy dynamic generation module. The method comprises the following steps: a network attack and defense game model is constructed to represent a network attack and defense scene of the current smart device cluster; the network topology of the smart device cluster is acquired, and an attack strategy and an action path are selected according to the network topology; attack behaviors are performed on the smart device cluster according to the attack strategy; the defense strategy dynamic generation module acquires a defense matrix of the current smart device cluster and the detection capability of each network node cluster, and a deep reinforcement learning model is used to generate a defense strategy. The application solves the problems of poor adaptability, insufficient cooperation and unreasonable resource scheduling in the traditional defense technology of the smart device cluster network, and greatly improves the overall efficiency of network security defense.
Owner:韩道岐