Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

126 results about "Attack surface" patented technology

The attack surface of a software environment is the sum of the different points (the "attack vectors") where an unauthorized user (the "attacker") can try to enter data to or extract data from an environment. Keeping the attack surface as small as possible is a basic security measure.

Intelligent network attack surface prediction method and system based on deep learning

The invention relates to an intelligent network attack surface prediction method and system based on deep learning, and belongs to the technical field of network security and information, and the method comprises the steps: obtaining network asset information, vulnerability distribution information and external threat intelligence data in a target network environment, and carrying out the preprocessing to generate a standardized data set; inputting the standardized data set into a pre-trained deep learning model to extract a feature vector related to the network attack; reasoning and analyzing a potential attack link based on the feature vector and the knowledge graph, and combining an association relationship among a network asset node, a vulnerability node and a threat intelligence node in the knowledge graph; and finally, according to a reasoning analysis result, evaluating an intrusion path possibly utilized by an attacker, outputting an attack surface prediction result, and presenting the attack surface prediction result in the form of an attack path list. According to the scheme, a potential attack link can be subjected to deep reasoning analysis, an intrusion path possibly utilized by an attacker can be accurately predicted, and the effectiveness of network security protection is improved.
Owner:BEIJING HUAYUNAN INFORMATION TECH CO LTD

Security event tracing system and method based on attack chain analysis

The invention discloses a security event traceability system and method based on attack chain analysis, relates to the technical field of data security protection, and is used for realizing multi-level perception of attack activities by building a multi-modal killing chain probe matrix as a structured data basis. Modeling analysis is carried out on attack behaviors of different levels through a deep heterogeneous feature extraction architecture, multi-dimensional features are fused into a cross-layer joint feature vector, a 3D attack deduction sand table is constructed according to the cross-layer joint feature vector, the propagation path and probability of APT attack are simulated, a high-dimensional attack curved surface is drawn, and a 3D attack deduction sand table is constructed according to the cross-layer joint feature vector. And key path nodes and potential transverse diffusion directions are identified, and a defense strategy knowledge graph is constructed according to a modeling result. The traceability system breaks through barriers among threat detection, attack understanding and defense response through a stage linkage mode of'probe sensing-intention recognition-path modeling-defense deduction ', and realizes accurate traceability and efficient disposal of security events.
Owner:SHANGRAO DAWAN NETWORK TECHNOLOGY CO LTD

Network security alarm method and device, electronic equipment and storage medium

The invention provides a network security alarm method and device, electronic equipment and a storage medium, and belongs to the technical field of network security, and the method comprises the steps: obtaining security logs, configuration information and asset importance levels of all security equipment in a network; performing association analysis on the configuration information, and determining attack surface data of each IP point in the network; performing noise reduction and correlation analysis on the security log to obtain processed log information, matching the processed log information with a preset feature library, and filtering alarms of normal service features and alarms of misreported attack features to obtain filtered alarm data; inputting the attack surface data, the asset importance level and the alarm data into a large language model to generate an alarm priority sequence; and executing an automatic response based on the alarm data, the alarm priority sequence and a configured response script. According to the invention, the problem of high false alarm rate of network security alarm in the prior art can be solved.
Owner:BEIJING ANBOTONG TECH CO LTD

Internet-Exposed Device Discovery

A cloud-based, external attack surface management (or EASM) service identifies computers, servers, smartphones, and other devices that are exposed to the public Internet. Any device that can connect to the public Internet may be vulnerable to cybersecurity attacks. The EASM service identifies a device exposed to the public Internet by comparing connection notifications to an address scan of the entire Internet. The connection notifications are sent by cybersecurity sensory agents installed at client devices. When a connection notification and the address scan of the entire Internet references a matching IP address and / or a matching port within a timeframe, the corresponding device is identified as being exposed to the public Internet.
Owner:CROWDSTRIKE

Mimicry defense driven network endogenous security protection method

The invention discloses a mimicry defense driven network endogenous security protection method, which solves the problems of fixed attack surface, high key management risk and insufficient self-healing capability of the traditional network static architecture. The method comprises the steps that hardware, a system and an application layer multilevel heterogeneous execution body are constructed, a unique identifier is distributed, and the state is monitored through heartbeat; the heterogeneous requests are stored in a red-black tree cache after being subjected to standardization processing; performing dynamic voting based on weighted majority in a 100-millisecond window, and isolating an executor and recording a block chain log when the executor is abnormal; the response integrity is verified through ECDSA signature, if the response is greater than or equal to half of the execution bodies, the response is consistent, and otherwise, a rollback mechanism is triggered; and periodically or event-driven dynamically reconstructing an executor pool, and combining a two-stage key alternation system of a transmission private key and a root public key. According to the method, the network endogenous security is improved through dynamic heterogeneous redundancy and automatic closed-loop protection.
Owner:INFORMATION & COMM COMPANY OF QINGHAI ELECTRIC POWER +1

Cloud-based zero trust network access service

Infrastructure for zero trust network access (ZTNA) is deployed as a cloud-based service remotely from a customer premises where user applications are hosted. By connecting an appliance on the customer premises to the cloud-based service through a secure tunnel or the like, an application hosted on the customer premises can then be accessed externally as a ZTNA application without the customer premises opening a firewall to public networks or otherwise exposing potential attack surfaces to the customer premises.
Owner:SOPHOS LTD

Automated prediction of cybersecurity vulnerabilities

Techniques are disclosed for predicting cybersecurity vulnerabilities automatically in IT assets / targets based on known vulnerabilities of various available technologies / products. This is accomplished by loading and linking one or more ontologies in a graph database containing vulnerability information about the technologies. The assets / targets preferably belong to a bug-bounty program. An optional discovery tool maps the attack surface of each target. A profiler collects the various technologies or traits used by the target and links them to the target. Then the graph database is queried to predict the cybersecurity vulnerabilities associated with the traits and consequently with the targets. The system is preferably implemented with a service-oriented architecture (SOA) so feedback / predictions can be provided to the user in near / real-time.
Owner:BUGCROWD INC

External field equipment trusted access method based on non-addressable stealth gateway

The invention discloses an external field equipment trusted access method based on a non-addressable stealth gateway, which relates to the technical field of network security access, and comprises the following four steps: in a manufacturing period and first access, a certificate authorization machine binds equipment identity and trusted platform module measurement, policy decision point decision, policy execution point implementation and policy subset loading; initiating from the outside of the equipment, establishing an end-to-end trusted channel with the center, and performing inward isolation and transparent bearing on rear-end real services; updating strategies, algorithms and secret keys on line under the control of a unified strategy library; according to the method, the attack surface is reduced, the transformation cost is reduced, non-stop treatment is ensured, the encrypted traffic can be observed and audited, only trusted equipment can reach the center through a trusted channel, and event linkage right descending and certificate state linkage treatment are supported.
Owner:HANGZHOU XENON TECHNOLOGY CO LTD

Dynamic defense switching period optimization method and device, medium and electronic equipment

The invention provides a dynamic defense switching period optimization method and device, a medium and electronic equipment, and the method comprises the steps: initializing defense resources and attack surface reset time, and defining a strategy space constraint of a defense switching period; defining a game framework; constructing an attack and defense revenue function; initializing a particle swarm, calculating the fitness value of each particle, iteratively updating the speed and position of the particle, calculating the fitness value of the updated particle, and judging whether to update the individual optimal solution and the global optimal solution according to the updated particle fitness value, the original individual optimal solution and the global optimal solution; when a preset iteration termination condition is met, iteration is terminated, and a Nash equilibrium strategy of the attacker and the defender is obtained; and extracting a switching period from the Nash equilibrium strategy as an optimal dynamic defense switching period. By applying the method, the dynamic counterbalance relationship between attacker and defender strategies can be comprehensively analyzed, and the optimal dynamic defense switching period capable of giving consideration to the defense effect and the system stability can be obtained.
Owner:GUANGZHOU UNIVERSITY

Security communication platform and method constructed based on security control and trusted network connection

The invention relates to the technical field of network security and communication, in particular to a security communication platform and method constructed based on security control and trusted network connection. The security communication platform comprises a security management and control center platform, a trusted password service platform, a trusted network connection optimization architecture, a distributed network architecture, a security shared memory mechanism, an application cluster system and a trusted VPN function module, the security management and control center platform is deployed in a core network, and a trusted platform module is arranged in the security management and control center platform as a global trusted root. By constructing an integrated platform of the trusted security management and control system and the secure and trusted intelligent VPN, triple security assurance of trusted access terminal, trusted network connection and trusted data transmission can be realized, and the requirements of a key information system on high security, high reliability and high adaptation of network communication are met; the defects of the traditional VPN in the aspects of attack surface control, encryption capability, identity authentication, systematic defense and the like are overcome.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Zero Trust Policy Engine for Controlling Access to Network Applications

Disclosed is a method for implementing a Zero Trust Architecture (ZTA) to secure network resources by eliminating lateral threat movement and minimizing attack surfaces. A zero trust policy engine, positioned inline between user devices and network resources, receives and evaluates access requests by verifying user and device identities along with context information. Based on dynamic risk scores derived from these evaluations, the engine enforces least-privileged, identity-based access policies, selectively granting access exclusively to authorized resources. Connections are terminated and re-established through secure proxy techniques, with continuous inspection of traffic for threats and data loss. Adaptive security measures, including isolation through pixel-streaming and context-aware access adjustments, further enhance protection. This architecture integrates seamlessly with cloud-based security service platforms, supporting workload-to-workload security, external entity integration, and comprehensive compliance reporting through audit trails and dashboards.
Owner:ZSCALER INC

Asset risk assessment method and device based on attack surface and graph centrality

The invention belongs to the technical field of nuclear power, and particularly relates to an asset risk assessment method and device based on an attack surface and graph centrality. According to the method provided by the invention, on the basis of traditional vulnerability severity assessment, an asset attack surface measurement and graph centrality analysis method is introduced, and vulnerability availability, attack path transmissibility and structure importance of assets in a network are organically fused, so that an asset risk assessment mechanism closer to a real threat environment is formed. Through the method, high-risk vulnerability assets can be identified, nodes having key effects on attack diffusion in the network can be highlighted, and accurate quantification and sorting of risks are realized. The attack surface is closely combined with the network structure; the attack graph analysis fully embodies the key node effect; and the vulnerability severity and the utilization probability are fully fused. And the asset risk level in the network environment can be reflected more accurately.
Owner:CHINA NUCLEAR POWER OPERATION TECH CORP

Predicting attack paths using code analysis

Predicting attack paths using code analysis, including: detecting a vulnerability in code by performing a static code analysis of the code; identifying an attack surface for the vulnerability in a cloud deployment; and generating an alert for the vulnerability by assigning a priority to the alert based on the attack surface.
Owner:FORTINET INC

Integrating Deception-Based Attack Intelligence with External Attack Surface Management (EASM) Data

The invention provides systems and methods for integrating deception-based attack intelligence with External Attack Surface Management (EASM) vulnerability data to enhance cybersecurity threat detection and mitigation. The method collects deception data, including attack details and Common Vulnerabilities and Exposures (CVE) identifiers, or classifies attacks into Common Weakness Enumeration (CWE) categories using AI when no CVE is present. EASM tools scan external-facing assets to identify CVE-linked vulnerabilities, which are also mapped to CWE categories. A matching procedure correlates deception and EASM data by identifying CVE matches for known vulnerabilities or CWE matches for broader structural weaknesses. Alerts are generated to prioritize patching efforts and proactive defenses, ensuring actionable responses to imminent threats or systemic vulnerabilities. By automating classification, correlation, and alerting, the invention reduces manual effort, accelerates remediation, and offers a scalable solution for modern organizations to adapt to evolving cyber threats.
Owner:ZSCALER INC

Method for managing cybersecurity threat and attack surface, and device for performing same

The present invention relates to a method for managing a cybersecurity threat and attack surface, and a device for performing the method. The method for managing a cybersecurity threat and attack surface may comprise: a step in which a cybersecurity management device collects attack surface information and security threat information; and a step in which the cybersecurity management device automatically verifies the validity of the security threat information through automated testing on the basis of the attack surface information and security threat information.
Owner:IN THE FOREST CO LTD

Information security comprehensive protection system of production enterprise

The invention discloses a production enterprise-oriented information security comprehensive protection system, which comprises a unified security management center, a region boundary protection module, a security computing environment module, a data full life cycle protection module, an authority management module, a threat active defense module and a network security situation awareness module, original dispersed and isolated safety capabilities are integrated into a linkage system through an integrated architecture of a unified safety management center and six functional modules through a unified interface / event bus, so that instant isolation and authentication of a transverse production control area, a management information area and a longitudinal remote operation and maintenance channel are realized, and the transverse penetration blocking rate is remarkably improved; role isolation and dynamic authorization are realized through the authority management module, the attack surface of a supply chain is greatly narrowed, the manual operation and maintenance workload is reduced by about six percent, and the overall safety toughness and operation efficiency of an enterprise are remarkably improved.
Owner:HENGTONG PRECISION COPPER FOIL TECHNOLOGY (DEYANG) CO LTD

Data processing method and cluster, computing device, computer readable storage medium, and computer program product

Embodiments of the present disclosure provide a data processing method and cluster, a computing device, a computer readable storage medium, and a computer program product. The data processing method is applied to an application program interface service unit of the data processing cluster. The method comprises: receiving a data processing request sent by a client for a target storage unit, wherein the data processing request carries data to be processed and a unit path of the target storage unit; analyzing the data to be processed, and when it is determined on the basis of an analysis result that the data attribute of the data to be processed is a target data attribute, encrypting the data to be processed to obtain ciphertext data and an encryption key; and sending the ciphertext data and the encryption key to the target storage unit on the basis of the unit path, thereby minimizing an attack surface of a malicious user to a node level, and reducing the risk of sensitive data leakage.
Owner:CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD

A dynamic encryption and authentication data transmission optimization method

The application discloses a kind of dynamic encryption and authentication data transmission optimization method, it is related to information security technical field, including the following steps: according to the topology of communication system and security protection demand, monitoring node is planned and deployed;After the deployment of monitoring node, real-time acquisition network layer and application layer multidimensional network environment data information, and the data collected are preprocessed, and the standardized data set is established.The application can accurately identify potential malicious attacks by real-time acquisition of multidimensional network environment data by monitoring node, combined with feature engineering and machine learning to evaluate network security posture;When detecting attack behavior, actively prevent weak encryption degradation, improve encryption strength and authentication level, shorten key update cycle, effectively prevent sensitive data leakage;At the same time, combined with multi-channel path switching and collaborative response, isolate risk propagation path, reduce attack surface, significantly improve the security and stability of communication system in malicious environment.
Owner:CHINA YANGTZE POWER

Vulnerability analysis method of multi-time scale micro-grid under FDI attack

The invention discloses a vulnerability analysis method of a multi-time-scale micro-grid under FDI attack, which comprises the following steps: decomposing system dynamics of a direct current micro-grid into a fast boundary layer subsystem and a slow order reduction subsystem by using a singular perturbation theory, respectively deducing stability conditions of each subsystem under a false data injection attack condition, and analyzing the vulnerability of the multi-time-scale micro-grid under the false data injection attack condition; and the input state stability of the low-speed subsystem under the FDI attack is proved. The worst deviation of the system state under the attack condition is calculated by constructing a zootope reachable set analysis framework, and the maximum allowable attack amplitude capable of ensuring safe operation of the system is quantified. According to the method, through numerical simulation and hardware experiment verification, a novel attack surface introduced by multi-time scale characteristics can be effectively revealed, and theoretical support and guidance are provided for safe and stable control of the DC micro-grid.
Owner:ZHEJIANG UNIV

Software vulnerability mining method and device based on static analysis and big and small model collaboration, computer equipment and medium

The embodiment of the invention provides a software vulnerability mining method and device based on static analysis and big and small model collaboration.The method comprises the following steps that attack faces are recognized and classified, and a code line annotation node set is generated; performing first-stage filtering on the code line annotation node set based on rules, and performing second-stage filtering on the annotation node set after primary filtering based on a twin neural network; taking a high-confidence node in the high-confidence attack surface set as a tracking starting point, generating a basic data flow diagram, obtaining a front-edge node set through static analysis, expanding the front-edge node set through a large language model and a path expansion algorithm, and generating a complemented data flow diagram; and detecting vulnerabilities based on the complemented data flow diagram to obtain a software vulnerability mining result. According to the scheme, through cooperation of the large language model and the twinning neural network, the false alarm rate is reduced, and the coverage rate and accuracy of vulnerability mining are improved.
Owner:BEIHANG UNIV

Automatic detection of application programming interface (API) attack surfaces

Various embodiments facilitate uncovering an Application Programming Interface (API) attack surface for an organization. In some examples, an apparatus comprises storage media, a processing system, and program instructions stored on the storage media. The apparatus processes Domain Name System (DNS) data to determine a set of possible API servers. The apparatus determines a set of possible Uniform Resource Identifier (URI) paths that may lead to one or more actual API endpoints. The apparatus joins the set of possible API servers with the set of possible URI paths to generate a set of possible API Uniform Resource Locators (URLs). The apparatus performs an API-specific crawl of the set of possible API URLs by submitting API requests to the set of possible API URLs and analyzing responses to determine the one or more actual API endpoints and one or more actual API servers of the set of possible API servers.
Owner:CEQUENCE SECURITY INC

Security event response system and method based on intelligent analysis

The invention discloses a security event response system and method based on intelligent analysis, and relates to the technical field of network security, an asset business load integrated digital model is constructed, a cross-domain attack surface is identified based on cross-environment asset interaction data in the integrated digital model, and basic data support for subsequent simulation and reasoning is formed; based on the obtained asset, business and cross-domain attack surface data, an attack framework and a dynamic attacker portrait are fused to construct a causal knowledge graph, the causal relationship of unknown attacks is complemented through transfer learning and an unsupervised algorithm, and the causal knowledge graph is updated according to the dynamic change of the environment; according to the method, the conversion of the security event from passive tracing to active prediction is realized, high-risk threats are identified in advance through cross-domain attack path simulation and risk quantification, and the defense initiative is improved.
Owner:中交京津冀投资发展有限公司 +1

Network micro-isolation protection method, system and equipment based on zero-trust architecture

The invention relates to the technical field of network security, and particularly discloses a network micro-isolation protection method, system and device based on a zero-trust architecture. Comprising the steps of global unknown service dependency dynamic mining and priority judgment, dynamic attack path evolution prediction based on generative adversarial deduction, attack path root cause analysis and micro-isolation strategy adaptive reinforcement, strategy verification and optimization, and strategy deployment and effect monitoring. Through combination of dynamic taint analysis and generative adversarial deduction, two problems of unknown business dependence identification and dynamic attack path prediction are solved at the same time, hidden dependence formed by temporary transmission of a payment token through a log service can be accurately found and evaluated, and a blind area of an attack surface is eliminated; and the generative AI can be utilized to simulate and deduce how an attacker combines and utilizes zero-day vulnerabilities such as dependence and Log4j variation in a sandbox to generate an unknown threat path which cannot be identified by a traditional method, so that prospective early warning is realized.
Owner:TONGFANG KNOWLEDGE DIGITAL PUBLISHING TECH CO LTD

Software supply chain-oriented code attack surface reduction method and system and storage medium

The invention discloses a software supply chain-oriented code attack surface reduction method and system and a storage medium. The method comprises the following steps of: S1, enhancing a test driven by a document; a large language model is used for understanding program document semantics, needed function features are extracted, and supplementary test cases covering the functions are automatically generated so as to enhance the integrity of input specifications; step S2, multi-consultant collaborative reduced code attack surface analysis; the method comprises the following steps: collecting coverage information when a program runs, proposing deletion candidates of unexecuted codes by a function consultant, identifying potential security risks by a security consultant in combination with a static analysis tool, and generating multi-view deletion suggestions; s3, decision making and verification; analysis results of the function consultant and the safety consultant are submitted to a large language model for comprehensive reasoning. The method has the advantages that the simplification rate is higher, the universality is higher, the significant program scale can be reduced, and the execution efficiency can be improved.
Owner:NAT UNIV OF DEFENSE TECH

A dynamic attack surface transformation active defense system for a production system

The application discloses a kind of dynamic attack surface transformation active defense system for production system, it is related to network security field, the active defense system includes: system support module, interface interpreter module, mobile target construction module, dynamic arrangement module, management module, information processing module, threat monitoring module;System support module provides the camouflage function of network service, file system and user account, and is converted into standard interface by interface interpreter module for upper module call, mobile target construction module interacts with system support module by interface interpreter, supports dynamic arrangement camouflage resource, dynamic arrangement module adjusts the attack surface characteristics of system resource according to the real-time threat information provided by threat monitoring module, when potential attack is found by threat monitoring module, threat information is passed to management module, and dynamic arrangement module is triggered to adjust, information processing module records log and shows system state and threat alarm, assist administrator decision-making.
Owner:NO 15 INST OF CHINA ELECTRONICS TECH GRP

Safe starting control method and device, equipment and storage medium

The invention belongs to the technical field of intelligent control, and discloses a secure startup control method and device, equipment and a storage medium, and two independent Flash memories are arranged to store a basic operating system and a complete operating system respectively, so that physical isolation is realized, and an attack chain is blocked. When it is detected that the electronic device is powered on, power is only supplied to the first Flash memory, and after the basic operating system is loaded and operated, power supply to the first Flash memory is cut off, and power is supplied to the second Flash memory; according to the method, the complete operating system is mounted to the memory disk, and after the complete operating system runs, the power supply of the second Flash memory is cut off, so that the first Flash memory can be immediately powered off after the basic operating system is started and runs, the second Flash memory is dynamically switched to, and attack surfaces are reduced; and meanwhile, a memory disk mounting mode is adopted, so that the continuous read-write dependence on the Flash memory can be reduced, the memory resources are optimized, and the reliability and the safety of an operation system are further improved.
Owner:Shenzhen Jinying Tuolian Technology Co., Ltd.

Attack surface tagging using user-configured tag specifications

Techniques for automated attack surface target tagging using user-configured tag specifications are described. An attack surface management (ASM) system tags attack surface targets via use of user-configured tag specifications. The user-configured tag specifications can provide a tag and zero, one, or more conditions to be evaluated to determine whether the tag, and any optionally indicated associated tags, are to be associated with a target. The tag specification can be provided via straightforward graphical user interfaces or in a human-readable data serialization language.
Owner:CISCO TECHNOLOGY INC

Identity verification method, apparatus, device, storage medium, and program product

This application provides an authentication method, apparatus, device, storage medium, and program product, relating to the fintech field or other related fields. The method includes: dynamically creating a dedicated application container for designated personnel before the change implementation window begins, granting them access permissions during the change implementation window, and destroying the container based on the execution status and window lifecycle after the task ends. This process reduces permission residue and environment reuse, effectively solving the security problems of high lateral attack risk, large attack surface, and easy permission abuse caused by long-term exposure of permissions and environment and lack of task-level isolation in traditional operation and maintenance models. The method of this application, while ensuring operational efficiency, enhances the inherent security and proactive defense capabilities of data center change operations.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Attack surface management method based on multi-source information fusion

The application relates to the technical field of network security and discloses an attack surface management method based on multi-source intelligence fusion, which comprises the following steps: collecting original data through a dynamic asset fingerprint library construction module and generating asset portrait data by using a machine learning algorithm; mapping the asset portrait data into a graph database node and an edge through an attack path simulation engine, executing a graph path search algorithm, outputting an attack path simulation result and a business influence score; executing a repair suggestion instruction through an automatic repair verification module, sending a re-simulation request to the attack path simulation engine, and verifying whether the attack path is blocked according to a secondary simulation result. The application can realize real-time discovery of dynamic assets and supply chain risks, accurate quantification of attack path influence by using a graph database, effective cutting of attack paths by repair measures and non-introduction of new risks through a secondary simulation and an abnormality detection mechanism, and dynamic and accurate closed-loop management of attack surface risks.
Owner:CSG EHV POWER TRANSMISSION