Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

148 results about "Attack surface" patented technology

The attack surface of a software environment is the sum of the different points (the "attack vectors") where an unauthorized user (the "attacker") can try to enter data to or extract data from an environment. Keeping the attack surface as small as possible is a basic security measure.

Information security management method based on data processing

The invention discloses an information security management method based on data processing, and particularly relates to the field of information security management, comprising multi-source heterogeneous data acquisition, multi-dimensional feature index calculation, comprehensive threat detection calculation and adaptive threat decision. According to the method, the covert communication channel is accurately identified by constructing the encrypted traffic multi-mode detection model and combining protocol fingerprint entropy and traffic self-similarity analysis; an improved entropy weight fusion algorithm is adopted, collaborative analysis of system process abnormity, network behavior offset and hardware degradation is achieved, and a cross-dimension attack chain is reconstructed; a storage medium physical feature-cryptographic module runtime joint monitoring mechanism is created for the first time, hardware layer physical attacks and cryptographic side channel vulnerabilities are synchronously defended through temperature-delay correlation evaluation and key derivation density analysis, a complete attack surface from a physical layer to an application layer is covered, and the security is improved. And the detection precision and the response real-time performance of the complex threats are obviously improved.
Owner:ANHUI WEIZHI INTERNET OF THINGS TECHNOLOGY CO LTD

Exposure and Attack Surface Management Using a Data Fabric

The disclosed embodiments provide systems and methods for continuous exposure and attack surface management using a data fabric. Data from multiple heterogeneous cybersecurity sources, including vulnerability scanners, threat intelligence, cloud security tools, and endpoint monitoring systems, is ingested and integrated into a semantically harmonized representation, such as a security knowledge graph. This unified data model normalizes, correlates, and contextualizes diverse cybersecurity information, enabling comprehensive and real-time assessment of an organization's cybersecurity risk posture. Automated workflows trigger proactive remediation actions based on dynamically calculated exposure metrics. Additional embodiments leverage the same data fabric architecture to support specialized cybersecurity use cases, including unified vulnerability management (UVM), cyber asset attack surface management (CAASM), continuous threat exposure management (CTEM), and asset exposure management (AEM).
Owner:AVALOR TECH LTD

Intelligent network connection automobile penetration test path generation method and system based on knowledge graph

The invention relates to the technical field of automobile network security, in particular to an intelligent networked automobile penetration test path generation method and system based on a knowledge graph, and the method comprises the steps: constructing an intelligent networked automobile intranet penetration test security knowledge graph through fusing multi-source heterogeneous data based on an intranet E / E architecture; generating a potential attack path based on the knowledge graph by using a depth-first search algorithm of dynamic pruning optimization; a multi-dimensional space-time risk assessment framework is utilized to quantify path threat intensity and execution feasibility, and quantitative assessment on the generated attack path is realized; and according to an evaluation result, selecting a high-risk and feasible attack path to carry out an actual penetration test, and discovering security vulnerabilities and weaknesses in the system. According to the method, the attack surface is fully covered, the high-value attack path is efficiently generated, the threat intensity and the execution feasibility are accurately and quantitatively evaluated, and the safety test efficiency and accuracy of the intelligent network connection automobile intranet are remarkably improved.
Owner:SONGSHAN LAB

Network risk assessment model construction method and system based on AI large model

The invention discloses a network risk assessment model construction method and system based on an AI large model, and relates to the technical field of artificial intelligence and network security, and the method comprises the following steps: S1, a participating node splits a large model into a plurality of semantic independent fragmentation units through a dynamic fragmentation mechanism based on local multi-source heterogeneous data; according to the network risk assessment model construction method and system based on the AI large model, through a dynamic fragmentation federated distillation learning framework, the inherent contradiction between data privacy protection and AI large model training efficiency in cross-mechanism cooperation is effectively solved. A ten-billion-level parameter model is disassembled into semantic independent units by adopting a self-adaptive parameter fragmentation mechanism, the communication overhead is reduced on the premise of ensuring physical isolation of sensitive data in combination with a local differential privacy and parameter confusion technology, and meanwhile, cross-domain fusion of threat features and attack surface blind spot detection are realized through a layered distillation verification system. And the APT attack detection rate is improved.
Owner:SHANGHAI YINDI NETWORK TECHNOLOGY CO LTD

Intelligent network attack surface prediction method and system based on deep learning

The invention relates to an intelligent network attack surface prediction method and system based on deep learning, and belongs to the technical field of network security and information, and the method comprises the steps: obtaining network asset information, vulnerability distribution information and external threat intelligence data in a target network environment, and carrying out the preprocessing to generate a standardized data set; inputting the standardized data set into a pre-trained deep learning model to extract a feature vector related to the network attack; reasoning and analyzing a potential attack link based on the feature vector and the knowledge graph, and combining an association relationship among a network asset node, a vulnerability node and a threat intelligence node in the knowledge graph; and finally, according to a reasoning analysis result, evaluating an intrusion path possibly utilized by an attacker, outputting an attack surface prediction result, and presenting the attack surface prediction result in the form of an attack path list. According to the scheme, a potential attack link can be subjected to deep reasoning analysis, an intrusion path possibly utilized by an attacker can be accurately predicted, and the effectiveness of network security protection is improved.
Owner:BEIJING HUAYUNAN INFORMATION TECH CO LTD

Security event tracing system and method based on attack chain analysis

The invention discloses a security event traceability system and method based on attack chain analysis, relates to the technical field of data security protection, and is used for realizing multi-level perception of attack activities by building a multi-modal killing chain probe matrix as a structured data basis. Modeling analysis is carried out on attack behaviors of different levels through a deep heterogeneous feature extraction architecture, multi-dimensional features are fused into a cross-layer joint feature vector, a 3D attack deduction sand table is constructed according to the cross-layer joint feature vector, the propagation path and probability of APT attack are simulated, a high-dimensional attack curved surface is drawn, and a 3D attack deduction sand table is constructed according to the cross-layer joint feature vector. And key path nodes and potential transverse diffusion directions are identified, and a defense strategy knowledge graph is constructed according to a modeling result. The traceability system breaks through barriers among threat detection, attack understanding and defense response through a stage linkage mode of'probe sensing-intention recognition-path modeling-defense deduction ', and realizes accurate traceability and efficient disposal of security events.
Owner:SHANGRAO DAWAN NETWORK TECHNOLOGY CO LTD

RAG-based multi-dimensional network penetration test vulnerability mining method

The invention provides an efficient multi-dimensional network penetration testing method based on RAG, which comprises the following steps: firstly, identifying sub-domain names possibly existing in a target website, and sequentially expanding attack surfaces of penetration testing to obtain vulnerability information pairs; secondly, a design model generated based on retrieval enhancement is adopted, vulnerability information pairs are extracted from the queue to be utilized, knowledge items related to local knowledge base retrieval and network intelligent search retrieval are utilized, and finally, a large model generates vulnerability utilization information according to the knowledge items; acquiring target machine permission for the previously acquired vulnerability information pair construction command injector, and further scanning other hosts of the intranet accessed by the target skipping machine; finally, combining vulnerability information obtained by penetration testing, utilizing a large model to sort vulnerabilities existing in different assets, and outputting penetration testing reports for different assets. According to the method and the system, comprehensive penetration testing of cross-network and cross-system is realized, security experts are helped to quickly identify, verify and repair vulnerabilities in a complex and changeable network environment, and high-efficiency and low-cost network security maintenance is realized.
Owner:SOUTHEAST UNIV

Network security alarm method and device, electronic equipment and storage medium

The invention provides a network security alarm method and device, electronic equipment and a storage medium, and belongs to the technical field of network security, and the method comprises the steps: obtaining security logs, configuration information and asset importance levels of all security equipment in a network; performing association analysis on the configuration information, and determining attack surface data of each IP point in the network; performing noise reduction and correlation analysis on the security log to obtain processed log information, matching the processed log information with a preset feature library, and filtering alarms of normal service features and alarms of misreported attack features to obtain filtered alarm data; inputting the attack surface data, the asset importance level and the alarm data into a large language model to generate an alarm priority sequence; and executing an automatic response based on the alarm data, the alarm priority sequence and a configured response script. According to the invention, the problem of high false alarm rate of network security alarm in the prior art can be solved.
Owner:BEIJING ANBOTONG TECH CO LTD

Internet-Exposed Device Discovery

A cloud-based, external attack surface management (or EASM) service identifies computers, servers, smartphones, and other devices that are exposed to the public Internet. Any device that can connect to the public Internet may be vulnerable to cybersecurity attacks. The EASM service identifies a device exposed to the public Internet by comparing connection notifications to an address scan of the entire Internet. The connection notifications are sent by cybersecurity sensory agents installed at client devices. When a connection notification and the address scan of the entire Internet references a matching IP address and / or a matching port within a timeframe, the corresponding device is identified as being exposed to the public Internet.
Owner:CROWDSTRIKE

Mimicry defense driven network endogenous security protection method

The invention discloses a mimicry defense driven network endogenous security protection method, which solves the problems of fixed attack surface, high key management risk and insufficient self-healing capability of the traditional network static architecture. The method comprises the steps that hardware, a system and an application layer multilevel heterogeneous execution body are constructed, a unique identifier is distributed, and the state is monitored through heartbeat; the heterogeneous requests are stored in a red-black tree cache after being subjected to standardization processing; performing dynamic voting based on weighted majority in a 100-millisecond window, and isolating an executor and recording a block chain log when the executor is abnormal; the response integrity is verified through ECDSA signature, if the response is greater than or equal to half of the execution bodies, the response is consistent, and otherwise, a rollback mechanism is triggered; and periodically or event-driven dynamically reconstructing an executor pool, and combining a two-stage key alternation system of a transmission private key and a root public key. According to the method, the network endogenous security is improved through dynamic heterogeneous redundancy and automatic closed-loop protection.
Owner:INFORMATION & COMM COMPANY OF QINGHAI ELECTRIC POWER +1

Cloud-based zero trust network access service

Infrastructure for zero trust network access (ZTNA) is deployed as a cloud-based service remotely from a customer premises where user applications are hosted. By connecting an appliance on the customer premises to the cloud-based service through a secure tunnel or the like, an application hosted on the customer premises can then be accessed externally as a ZTNA application without the customer premises opening a firewall to public networks or otherwise exposing potential attack surfaces to the customer premises.
Owner:SOPHOS LTD

Automated prediction of cybersecurity vulnerabilities

Techniques are disclosed for predicting cybersecurity vulnerabilities automatically in IT assets / targets based on known vulnerabilities of various available technologies / products. This is accomplished by loading and linking one or more ontologies in a graph database containing vulnerability information about the technologies. The assets / targets preferably belong to a bug-bounty program. An optional discovery tool maps the attack surface of each target. A profiler collects the various technologies or traits used by the target and links them to the target. Then the graph database is queried to predict the cybersecurity vulnerabilities associated with the traits and consequently with the targets. The system is preferably implemented with a service-oriented architecture (SOA) so feedback / predictions can be provided to the user in near / real-time.
Owner:BUGCROWD INC

External field equipment trusted access method based on non-addressable stealth gateway

The invention discloses an external field equipment trusted access method based on a non-addressable stealth gateway, which relates to the technical field of network security access, and comprises the following four steps: in a manufacturing period and first access, a certificate authorization machine binds equipment identity and trusted platform module measurement, policy decision point decision, policy execution point implementation and policy subset loading; initiating from the outside of the equipment, establishing an end-to-end trusted channel with the center, and performing inward isolation and transparent bearing on rear-end real services; updating strategies, algorithms and secret keys on line under the control of a unified strategy library; according to the method, the attack surface is reduced, the transformation cost is reduced, non-stop treatment is ensured, the encrypted traffic can be observed and audited, only trusted equipment can reach the center through a trusted channel, and event linkage right descending and certificate state linkage treatment are supported.
Owner:HANGZHOU XENON TECHNOLOGY CO LTD

Dynamic defense switching period optimization method and device, medium and electronic equipment

The invention provides a dynamic defense switching period optimization method and device, a medium and electronic equipment, and the method comprises the steps: initializing defense resources and attack surface reset time, and defining a strategy space constraint of a defense switching period; defining a game framework; constructing an attack and defense revenue function; initializing a particle swarm, calculating the fitness value of each particle, iteratively updating the speed and position of the particle, calculating the fitness value of the updated particle, and judging whether to update the individual optimal solution and the global optimal solution according to the updated particle fitness value, the original individual optimal solution and the global optimal solution; when a preset iteration termination condition is met, iteration is terminated, and a Nash equilibrium strategy of the attacker and the defender is obtained; and extracting a switching period from the Nash equilibrium strategy as an optimal dynamic defense switching period. By applying the method, the dynamic counterbalance relationship between attacker and defender strategies can be comprehensively analyzed, and the optimal dynamic defense switching period capable of giving consideration to the defense effect and the system stability can be obtained.
Owner:GUANGZHOU UNIVERSITY

Security communication platform and method constructed based on security control and trusted network connection

The invention relates to the technical field of network security and communication, in particular to a security communication platform and method constructed based on security control and trusted network connection. The security communication platform comprises a security management and control center platform, a trusted password service platform, a trusted network connection optimization architecture, a distributed network architecture, a security shared memory mechanism, an application cluster system and a trusted VPN function module, the security management and control center platform is deployed in a core network, and a trusted platform module is arranged in the security management and control center platform as a global trusted root. By constructing an integrated platform of the trusted security management and control system and the secure and trusted intelligent VPN, triple security assurance of trusted access terminal, trusted network connection and trusted data transmission can be realized, and the requirements of a key information system on high security, high reliability and high adaptation of network communication are met; the defects of the traditional VPN in the aspects of attack surface control, encryption capability, identity authentication, systematic defense and the like are overcome.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Zero Trust Policy Engine for Controlling Access to Network Applications

Disclosed is a method for implementing a Zero Trust Architecture (ZTA) to secure network resources by eliminating lateral threat movement and minimizing attack surfaces. A zero trust policy engine, positioned inline between user devices and network resources, receives and evaluates access requests by verifying user and device identities along with context information. Based on dynamic risk scores derived from these evaluations, the engine enforces least-privileged, identity-based access policies, selectively granting access exclusively to authorized resources. Connections are terminated and re-established through secure proxy techniques, with continuous inspection of traffic for threats and data loss. Adaptive security measures, including isolation through pixel-streaming and context-aware access adjustments, further enhance protection. This architecture integrates seamlessly with cloud-based security service platforms, supporting workload-to-workload security, external entity integration, and comprehensive compliance reporting through audit trails and dashboards.
Owner:ZSCALER INC

Asset risk assessment method and device based on attack surface and graph centrality

The invention belongs to the technical field of nuclear power, and particularly relates to an asset risk assessment method and device based on an attack surface and graph centrality. According to the method provided by the invention, on the basis of traditional vulnerability severity assessment, an asset attack surface measurement and graph centrality analysis method is introduced, and vulnerability availability, attack path transmissibility and structure importance of assets in a network are organically fused, so that an asset risk assessment mechanism closer to a real threat environment is formed. Through the method, high-risk vulnerability assets can be identified, nodes having key effects on attack diffusion in the network can be highlighted, and accurate quantification and sorting of risks are realized. The attack surface is closely combined with the network structure; the attack graph analysis fully embodies the key node effect; and the vulnerability severity and the utilization probability are fully fused. And the asset risk level in the network environment can be reflected more accurately.
Owner:CHINA NUCLEAR POWER OPERATION TECH CORP

Predicting attack paths using code analysis

Predicting attack paths using code analysis, including: detecting a vulnerability in code by performing a static code analysis of the code; identifying an attack surface for the vulnerability in a cloud deployment; and generating an alert for the vulnerability by assigning a priority to the alert based on the attack surface.
Owner:FORTINET INC

Web Components-based component-level security protection system and method

The invention relates to a Web Compents-based component-level security protection system and a Web Compents-based component-level security protection method, and belongs to the technical field of crossing of network security and front-end engineering technologies. Through deep binding of a security policy and a component life cycle, the method comprises the following steps: 1) injecting a security monitoring logic in a key stage of a user-defined element life cycle; 2) automatically inserting a context-aware purification code when the template is compiled; 3) constructing an independent security sandbox based on the shadow DOM; and 4) supporting dynamically updated component-level CSP strategy configuration. According to the scheme, the security policy is introduced into the Web Components, so that the XSS attack surface can be reduced, the policy false alarm rate can be reduced, and the fine-grained security protection capability is provided for the Web application.
Owner:BEIJING INST OF COMP TECH & APPL

Attack path prediction method, device and equipment of train control system and medium

The embodiment of the invention discloses an attack path prediction method and device of a train control system, equipment and a medium. The method comprises the following steps: according to hardware data and software data of equipment in the train control system, determining an attack surface node, an attack node, a resource state node, a cause event node, a risk event node, a defense measure node and a pointing relationship among the nodes in an attack process of the train control system; constructing a Bayesian attack graph model according to the attack surface node, the attack node, the resource state node, the cause event node, the risk event node, the defensive measure node and the pointing relationship among the nodes; and based on the Bayesian attack graph model, determining a risk evaluation index of each candidate attack path, and predicting a target attack path for the train control system. According to the scheme, the Bayesian attack graph model is improved and refined, so that the attack path is represented more accurately, the influence of defense measures is considered, and the attack path is analyzed more comprehensively.
Owner:CRSC RESEARCH & DESIGN INSTITUTE GROUP CO LTD

Integrating Deception-Based Attack Intelligence with External Attack Surface Management (EASM) Data

The invention provides systems and methods for integrating deception-based attack intelligence with External Attack Surface Management (EASM) vulnerability data to enhance cybersecurity threat detection and mitigation. The method collects deception data, including attack details and Common Vulnerabilities and Exposures (CVE) identifiers, or classifies attacks into Common Weakness Enumeration (CWE) categories using AI when no CVE is present. EASM tools scan external-facing assets to identify CVE-linked vulnerabilities, which are also mapped to CWE categories. A matching procedure correlates deception and EASM data by identifying CVE matches for known vulnerabilities or CWE matches for broader structural weaknesses. Alerts are generated to prioritize patching efforts and proactive defenses, ensuring actionable responses to imminent threats or systemic vulnerabilities. By automating classification, correlation, and alerting, the invention reduces manual effort, accelerates remediation, and offers a scalable solution for modern organizations to adapt to evolving cyber threats.
Owner:ZSCALER INC

Method for managing cybersecurity threat and attack surface, and device for performing same

The present invention relates to a method for managing a cybersecurity threat and attack surface, and a device for performing the method. The method for managing a cybersecurity threat and attack surface may comprise: a step in which a cybersecurity management device collects attack surface information and security threat information; and a step in which the cybersecurity management device automatically verifies the validity of the security threat information through automated testing on the basis of the attack surface information and security threat information.
Owner:IN THE FOREST CO LTD

Operating system security assessment method based on attack-fault tree

The invention relates to an attack-fault tree-based operating system security evaluation method, which comprises the following steps of: aiming at an attack-fault tree-based operating system, evaluating an attack surface exposure risk result of an exposure element in a simulated attack scene; based on an attack surface exposure risk result, performing adaptive adjustment on a security evaluation algorithm and algorithm parameters of an operation system defense mechanism; based on the self-adaptively adjusted security evaluation algorithm and algorithm parameters, evaluating a defense mechanism of the operating system to obtain a defense mechanism evaluation result; based on matrix operation, quantifying the comprehensive influence of the attack surface exposure risk result and the defense mechanism evaluation result on the overall security state of the operating system to obtain a preliminary comprehensive risk value; and obtaining real-time operation data of the operating system, correcting the preliminary comprehensive risk value, and generating a comprehensive security assessment result of the operating system. According to the invention, the mutual influence of multiple aspects is comprehensively considered, so that the final comprehensive safety assessment result is more accurate.
Owner:BEIJING JIAOTONG UNIV

Information security comprehensive protection system of production enterprise

The invention discloses a production enterprise-oriented information security comprehensive protection system, which comprises a unified security management center, a region boundary protection module, a security computing environment module, a data full life cycle protection module, an authority management module, a threat active defense module and a network security situation awareness module, original dispersed and isolated safety capabilities are integrated into a linkage system through an integrated architecture of a unified safety management center and six functional modules through a unified interface / event bus, so that instant isolation and authentication of a transverse production control area, a management information area and a longitudinal remote operation and maintenance channel are realized, and the transverse penetration blocking rate is remarkably improved; role isolation and dynamic authorization are realized through the authority management module, the attack surface of a supply chain is greatly narrowed, the manual operation and maintenance workload is reduced by about six percent, and the overall safety toughness and operation efficiency of an enterprise are remarkably improved.
Owner:HENGTONG PRECISION COPPER FOIL TECHNOLOGY (DEYANG) CO LTD

Data processing method and cluster, computing device, computer readable storage medium, and computer program product

Embodiments of the present disclosure provide a data processing method and cluster, a computing device, a computer readable storage medium, and a computer program product. The data processing method is applied to an application program interface service unit of the data processing cluster. The method comprises: receiving a data processing request sent by a client for a target storage unit, wherein the data processing request carries data to be processed and a unit path of the target storage unit; analyzing the data to be processed, and when it is determined on the basis of an analysis result that the data attribute of the data to be processed is a target data attribute, encrypting the data to be processed to obtain ciphertext data and an encryption key; and sending the ciphertext data and the encryption key to the target storage unit on the basis of the unit path, thereby minimizing an attack surface of a malicious user to a node level, and reducing the risk of sensitive data leakage.
Owner:CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD

Prioritization of attack techniques against an organization

ActiveUS12401673B2Securing communicationAttackEvent mapping
One or more systems, devices, computer program products and / or computer-implemented methods provided herein relate to prioritization of attack techniques and cyber security events. According to an embodiment, an attack prioritization engine can receive security events, train an artificial intelligence model to rank respective cyber security events as a function of risk, and output a prioritization of security events to address. A mapping component can map asset vulnerabilities to attack techniques. A calculation component can calculate and aggregate scores for respective attack techniques. An attack surface component can extract features from the aggregation of scores to rank attack techniques and determine an attack surface. The mapping component can further map security events to the attack techniques.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

A dynamic encryption and authentication data transmission optimization method

The application discloses a kind of dynamic encryption and authentication data transmission optimization method, it is related to information security technical field, including the following steps: according to the topology of communication system and security protection demand, monitoring node is planned and deployed;After the deployment of monitoring node, real-time acquisition network layer and application layer multidimensional network environment data information, and the data collected are preprocessed, and the standardized data set is established.The application can accurately identify potential malicious attacks by real-time acquisition of multidimensional network environment data by monitoring node, combined with feature engineering and machine learning to evaluate network security posture;When detecting attack behavior, actively prevent weak encryption degradation, improve encryption strength and authentication level, shorten key update cycle, effectively prevent sensitive data leakage;At the same time, combined with multi-channel path switching and collaborative response, isolate risk propagation path, reduce attack surface, significantly improve the security and stability of communication system in malicious environment.
Owner:CHINA YANGTZE POWER

Vulnerability analysis method of multi-time scale micro-grid under FDI attack

The invention discloses a vulnerability analysis method of a multi-time-scale micro-grid under FDI attack, which comprises the following steps: decomposing system dynamics of a direct current micro-grid into a fast boundary layer subsystem and a slow order reduction subsystem by using a singular perturbation theory, respectively deducing stability conditions of each subsystem under a false data injection attack condition, and analyzing the vulnerability of the multi-time-scale micro-grid under the false data injection attack condition; and the input state stability of the low-speed subsystem under the FDI attack is proved. The worst deviation of the system state under the attack condition is calculated by constructing a zootope reachable set analysis framework, and the maximum allowable attack amplitude capable of ensuring safe operation of the system is quantified. According to the method, through numerical simulation and hardware experiment verification, a novel attack surface introduced by multi-time scale characteristics can be effectively revealed, and theoretical support and guidance are provided for safe and stable control of the DC micro-grid.
Owner:ZHEJIANG UNIV

Software vulnerability mining method and device based on static analysis and big and small model collaboration, computer equipment and medium

The embodiment of the invention provides a software vulnerability mining method and device based on static analysis and big and small model collaboration.The method comprises the following steps that attack faces are recognized and classified, and a code line annotation node set is generated; performing first-stage filtering on the code line annotation node set based on rules, and performing second-stage filtering on the annotation node set after primary filtering based on a twin neural network; taking a high-confidence node in the high-confidence attack surface set as a tracking starting point, generating a basic data flow diagram, obtaining a front-edge node set through static analysis, expanding the front-edge node set through a large language model and a path expansion algorithm, and generating a complemented data flow diagram; and detecting vulnerabilities based on the complemented data flow diagram to obtain a software vulnerability mining result. According to the scheme, through cooperation of the large language model and the twinning neural network, the false alarm rate is reduced, and the coverage rate and accuracy of vulnerability mining are improved.
Owner:BEIHANG UNIV