Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

81 results about "Attack surface" patented technology

The attack surface of a software environment is the sum of the different points (the "attack vectors") where an unauthorized user (the "attacker") can try to enter data to or extract data from an environment. Keeping the attack surface as small as possible is a basic security measure.

Automated prediction of cybersecurity vulnerabilities

Techniques are disclosed for predicting cybersecurity vulnerabilities automatically in IT assets / targets based on known vulnerabilities of various available technologies / products. This is accomplished by loading and linking one or more ontologies in a graph database containing vulnerability information about the technologies. The assets / targets preferably belong to a bug-bounty program. An optional discovery tool maps the attack surface of each target. A profiler collects the various technologies or traits used by the target and links them to the target. Then the graph database is queried to predict the cybersecurity vulnerabilities associated with the traits and consequently with the targets. The system is preferably implemented with a service-oriented architecture (SOA) so feedback / predictions can be provided to the user in near / real-time.
Owner:BUGCROWD INC

External field equipment trusted access method based on non-addressable stealth gateway

The invention discloses an external field equipment trusted access method based on a non-addressable stealth gateway, which relates to the technical field of network security access, and comprises the following four steps: in a manufacturing period and first access, a certificate authorization machine binds equipment identity and trusted platform module measurement, policy decision point decision, policy execution point implementation and policy subset loading; initiating from the outside of the equipment, establishing an end-to-end trusted channel with the center, and performing inward isolation and transparent bearing on rear-end real services; updating strategies, algorithms and secret keys on line under the control of a unified strategy library; according to the method, the attack surface is reduced, the transformation cost is reduced, non-stop treatment is ensured, the encrypted traffic can be observed and audited, only trusted equipment can reach the center through a trusted channel, and event linkage right descending and certificate state linkage treatment are supported.
Owner:HANGZHOU XENON TECHNOLOGY CO LTD

Asset risk assessment method and device based on attack surface and graph centrality

The invention belongs to the technical field of nuclear power, and particularly relates to an asset risk assessment method and device based on an attack surface and graph centrality. According to the method provided by the invention, on the basis of traditional vulnerability severity assessment, an asset attack surface measurement and graph centrality analysis method is introduced, and vulnerability availability, attack path transmissibility and structure importance of assets in a network are organically fused, so that an asset risk assessment mechanism closer to a real threat environment is formed. Through the method, high-risk vulnerability assets can be identified, nodes having key effects on attack diffusion in the network can be highlighted, and accurate quantification and sorting of risks are realized. The attack surface is closely combined with the network structure; the attack graph analysis fully embodies the key node effect; and the vulnerability severity and the utilization probability are fully fused. And the asset risk level in the network environment can be reflected more accurately.
Owner:CHINA NUCLEAR POWER OPERATION TECH CORP

Predicting attack paths using code analysis

Predicting attack paths using code analysis, including: detecting a vulnerability in code by performing a static code analysis of the code; identifying an attack surface for the vulnerability in a cloud deployment; and generating an alert for the vulnerability by assigning a priority to the alert based on the attack surface.
Owner:FORTINET INC

Information security comprehensive protection system of production enterprise

The invention discloses a production enterprise-oriented information security comprehensive protection system, which comprises a unified security management center, a region boundary protection module, a security computing environment module, a data full life cycle protection module, an authority management module, a threat active defense module and a network security situation awareness module, original dispersed and isolated safety capabilities are integrated into a linkage system through an integrated architecture of a unified safety management center and six functional modules through a unified interface / event bus, so that instant isolation and authentication of a transverse production control area, a management information area and a longitudinal remote operation and maintenance channel are realized, and the transverse penetration blocking rate is remarkably improved; role isolation and dynamic authorization are realized through the authority management module, the attack surface of a supply chain is greatly narrowed, the manual operation and maintenance workload is reduced by about six percent, and the overall safety toughness and operation efficiency of an enterprise are remarkably improved.
Owner:HENGTONG PRECISION COPPER FOIL TECHNOLOGY (DEYANG) CO LTD

Vulnerability analysis method of multi-time scale micro-grid under FDI attack

The invention discloses a vulnerability analysis method of a multi-time-scale micro-grid under FDI attack, which comprises the following steps: decomposing system dynamics of a direct current micro-grid into a fast boundary layer subsystem and a slow order reduction subsystem by using a singular perturbation theory, respectively deducing stability conditions of each subsystem under a false data injection attack condition, and analyzing the vulnerability of the multi-time-scale micro-grid under the false data injection attack condition; and the input state stability of the low-speed subsystem under the FDI attack is proved. The worst deviation of the system state under the attack condition is calculated by constructing a zootope reachable set analysis framework, and the maximum allowable attack amplitude capable of ensuring safe operation of the system is quantified. According to the method, through numerical simulation and hardware experiment verification, a novel attack surface introduced by multi-time scale characteristics can be effectively revealed, and theoretical support and guidance are provided for safe and stable control of the DC micro-grid.
Owner:ZHEJIANG UNIV

Software vulnerability mining method and device based on static analysis and big and small model collaboration, computer equipment and medium

The embodiment of the invention provides a software vulnerability mining method and device based on static analysis and big and small model collaboration.The method comprises the following steps that attack faces are recognized and classified, and a code line annotation node set is generated; performing first-stage filtering on the code line annotation node set based on rules, and performing second-stage filtering on the annotation node set after primary filtering based on a twin neural network; taking a high-confidence node in the high-confidence attack surface set as a tracking starting point, generating a basic data flow diagram, obtaining a front-edge node set through static analysis, expanding the front-edge node set through a large language model and a path expansion algorithm, and generating a complemented data flow diagram; and detecting vulnerabilities based on the complemented data flow diagram to obtain a software vulnerability mining result. According to the scheme, through cooperation of the large language model and the twinning neural network, the false alarm rate is reduced, and the coverage rate and accuracy of vulnerability mining are improved.
Owner:BEIHANG UNIV

Automatic detection of application programming interface (API) attack surfaces

Various embodiments facilitate uncovering an Application Programming Interface (API) attack surface for an organization. In some examples, an apparatus comprises storage media, a processing system, and program instructions stored on the storage media. The apparatus processes Domain Name System (DNS) data to determine a set of possible API servers. The apparatus determines a set of possible Uniform Resource Identifier (URI) paths that may lead to one or more actual API endpoints. The apparatus joins the set of possible API servers with the set of possible URI paths to generate a set of possible API Uniform Resource Locators (URLs). The apparatus performs an API-specific crawl of the set of possible API URLs by submitting API requests to the set of possible API URLs and analyzing responses to determine the one or more actual API endpoints and one or more actual API servers of the set of possible API servers.
Owner:CEQUENCE SECURITY INC

Security event response system and method based on intelligent analysis

The invention discloses a security event response system and method based on intelligent analysis, and relates to the technical field of network security, an asset business load integrated digital model is constructed, a cross-domain attack surface is identified based on cross-environment asset interaction data in the integrated digital model, and basic data support for subsequent simulation and reasoning is formed; based on the obtained asset, business and cross-domain attack surface data, an attack framework and a dynamic attacker portrait are fused to construct a causal knowledge graph, the causal relationship of unknown attacks is complemented through transfer learning and an unsupervised algorithm, and the causal knowledge graph is updated according to the dynamic change of the environment; according to the method, the conversion of the security event from passive tracing to active prediction is realized, high-risk threats are identified in advance through cross-domain attack path simulation and risk quantification, and the defense initiative is improved.
Owner:中交京津冀投资发展有限公司 +1

Network micro-isolation protection method, system and equipment based on zero-trust architecture

The invention relates to the technical field of network security, and particularly discloses a network micro-isolation protection method, system and device based on a zero-trust architecture. Comprising the steps of global unknown service dependency dynamic mining and priority judgment, dynamic attack path evolution prediction based on generative adversarial deduction, attack path root cause analysis and micro-isolation strategy adaptive reinforcement, strategy verification and optimization, and strategy deployment and effect monitoring. Through combination of dynamic taint analysis and generative adversarial deduction, two problems of unknown business dependence identification and dynamic attack path prediction are solved at the same time, hidden dependence formed by temporary transmission of a payment token through a log service can be accurately found and evaluated, and a blind area of an attack surface is eliminated; and the generative AI can be utilized to simulate and deduce how an attacker combines and utilizes zero-day vulnerabilities such as dependence and Log4j variation in a sandbox to generate an unknown threat path which cannot be identified by a traditional method, so that prospective early warning is realized.
Owner:TONGFANG KNOWLEDGE DIGITAL PUBLISHING TECH CO LTD

Software supply chain-oriented code attack surface reduction method and system and storage medium

The invention discloses a software supply chain-oriented code attack surface reduction method and system and a storage medium. The method comprises the following steps of: S1, enhancing a test driven by a document; a large language model is used for understanding program document semantics, needed function features are extracted, and supplementary test cases covering the functions are automatically generated so as to enhance the integrity of input specifications; step S2, multi-consultant collaborative reduced code attack surface analysis; the method comprises the following steps: collecting coverage information when a program runs, proposing deletion candidates of unexecuted codes by a function consultant, identifying potential security risks by a security consultant in combination with a static analysis tool, and generating multi-view deletion suggestions; s3, decision making and verification; analysis results of the function consultant and the safety consultant are submitted to a large language model for comprehensive reasoning. The method has the advantages that the simplification rate is higher, the universality is higher, the significant program scale can be reduced, and the execution efficiency can be improved.
Owner:NAT UNIV OF DEFENSE TECH

Safe starting control method and device, equipment and storage medium

The invention belongs to the technical field of intelligent control, and discloses a secure startup control method and device, equipment and a storage medium, and two independent Flash memories are arranged to store a basic operating system and a complete operating system respectively, so that physical isolation is realized, and an attack chain is blocked. When it is detected that the electronic device is powered on, power is only supplied to the first Flash memory, and after the basic operating system is loaded and operated, power supply to the first Flash memory is cut off, and power is supplied to the second Flash memory; according to the method, the complete operating system is mounted to the memory disk, and after the complete operating system runs, the power supply of the second Flash memory is cut off, so that the first Flash memory can be immediately powered off after the basic operating system is started and runs, the second Flash memory is dynamically switched to, and attack surfaces are reduced; and meanwhile, a memory disk mounting mode is adopted, so that the continuous read-write dependence on the Flash memory can be reduced, the memory resources are optimized, and the reliability and the safety of an operation system are further improved.
Owner:Shenzhen Jinying Tuolian Technology Co., Ltd.

Attack surface tagging using user-configured tag specifications

Techniques for automated attack surface target tagging using user-configured tag specifications are described. An attack surface management (ASM) system tags attack surface targets via use of user-configured tag specifications. The user-configured tag specifications can provide a tag and zero, one, or more conditions to be evaluated to determine whether the tag, and any optionally indicated associated tags, are to be associated with a target. The tag specification can be provided via straightforward graphical user interfaces or in a human-readable data serialization language.
Owner:CISCO TECHNOLOGY INC

Identity verification method, apparatus, device, storage medium, and program product

This application provides an authentication method, apparatus, device, storage medium, and program product, relating to the fintech field or other related fields. The method includes: dynamically creating a dedicated application container for designated personnel before the change implementation window begins, granting them access permissions during the change implementation window, and destroying the container based on the execution status and window lifecycle after the task ends. This process reduces permission residue and environment reuse, effectively solving the security problems of high lateral attack risk, large attack surface, and easy permission abuse caused by long-term exposure of permissions and environment and lack of task-level isolation in traditional operation and maintenance models. The method of this application, while ensuring operational efficiency, enhances the inherent security and proactive defense capabilities of data center change operations.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Attack surface management method based on multi-source information fusion

The application relates to the technical field of network security and discloses an attack surface management method based on multi-source intelligence fusion, which comprises the following steps: collecting original data through a dynamic asset fingerprint library construction module and generating asset portrait data by using a machine learning algorithm; mapping the asset portrait data into a graph database node and an edge through an attack path simulation engine, executing a graph path search algorithm, outputting an attack path simulation result and a business influence score; executing a repair suggestion instruction through an automatic repair verification module, sending a re-simulation request to the attack path simulation engine, and verifying whether the attack path is blocked according to a secondary simulation result. The application can realize real-time discovery of dynamic assets and supply chain risks, accurate quantification of attack path influence by using a graph database, effective cutting of attack paths by repair measures and non-introduction of new risks through a secondary simulation and an abnormality detection mechanism, and dynamic and accurate closed-loop management of attack surface risks.
Owner:CSG EHV POWER TRANSMISSION

Network security test and evaluation system and method

The invention belongs to the technical field of network security, and discloses a network security test and evaluation system and method, and the system comprises an asset and topology automatic discovery module, a threat behavior simulation and attack chain generation module, a security configuration difference analysis module, a risk quantification and evaluation module, and a linkage protection and verification module. The system recognizes network assets and the dependency relationship thereof through passive traffic analysis and active exploration, generates an attack surface model based on an asset structure, constructs a candidate attack chain by using a heuristic search method, and executes threat simulation operation in a controlled environment. The system can also perform difference analysis on the actual configuration of the target asset and the baseline, calculate a risk index in combination with a simulation result, and automatically trigger a protection measure and verify the effectiveness when the risk reaches a threshold value. According to the method, continuous, real and reproducible security assessment can be realized in a complex network environment, and the risk discovery capability and the reliability of a protection strategy are improved.
Owner:李师谦

Trusted starting method for universal virtual machine

The invention discloses a universal virtual machine trusted startup method, which is characterized in that a virtual machine startup measurement module is constructed on the basis of trusted startup of a physical machine, and the virtual machine startup measurement module is positioned in a trusted environment of the physical machine and is measured in a startup process of the physical machine. The virtual machine starting measurement module carries out trusted measurement on key components in the starting process of the virtual machine according to a star trust chain mode, wherein the key components comprise application files. According to the method, the star trust chain is adopted for starting the virtual machine, the length of the trust chain is shortened, attacked faces are reduced, multiple assemblies can be measured at the same time, and the measurement speed is increased; the measurement of the virtual machine not only comprises UEFI firmware, a bootstrap program and a kernel, but also comprises a bootstrap program configuration file and an application file, and a measurement component is more complete and is expanded to an application layer.
Owner:BEIJING UNIV OF TECH

System and method for dynamic network security risk identification based on multi-source information and ai driving

The application relates to the technical field of network security, and discloses a dynamic network security risk identification system and method based on multi-source intelligence and AI driving, which comprises a dynamic attack graph modeling module, an AI-driven attack simulation engine and a cooperation module.The modeling module fuses multi-source heterogeneous intelligence to construct a network attack graph and calculate node intelligence confidence; the AI engine takes the confidence into a state space, uses a dynamic entropy mechanism to real-time adjust the randomness of reinforcement learning exploration to accurately simulate an attack path; and the cooperation module links external attack surface management and a security operation center to execute closed-loop feedback verification of automatic defense response and path elimination.The application establishes a mapping relationship between intelligence confidence and exploration strategy, effectively solves the problems of uneven multi-source data quality and unknown path missing report, realizes an automatic closed loop from risk perception, simulation deduction to effect verification, and significantly improves risk identification accuracy and response timeliness.
Owner:CSG EHV POWER TRANSMISSION

Deception information generation system and method based on attack surface information

PendingCN122460042AInternet privacyAttack
The present invention relates to an attack surface information-based deception information generation system and method, and provides an attack surface information-based deception information generation system and method for protecting a ship by deceiving a network attacker who attacks the ship, impersonating an actual internal system of the ship, identifying signs of an attack at an early stage of the attack, and responding to the signs of the attack at an early stage.
Owner:HANWHA OCEAN CO LTD (KR) +1

Security risk assessment method and system based on attack chain deduction

PendingCN121864343AFinanceSecuring communicationTotal riskAttack
The invention discloses a security risk assessment method and system based on attack chain deduction, relates to the technical field of network security, and solves the problem that security risks are difficult to comprehensively and accurately assess in the prior art. According to the embodiment of the invention, by establishing the asset-vulnerability-attack stage mapping relationship, the whole-process visual modeling of the attack chain from initial reconnaissance to target achievement is realized, the specific effect of the vulnerability in the attack chain is determined, and the problem that the vulnerability linkage effect is neglected in traditional assessment is solved, so that more comprehensive risk assessment is realized; in addition, the mapping relation can be updated in real time according to asset change and new vulnerability discovery, accurate basic data support is provided for attack path generation, and dynamic construction of an attack surface panoramic view is achieved. Besides, by introducing path selected probability parameters, subjective strategy preferences of the attacker are brought into quantitative evaluation of the risk, so that total risk evaluation better fits real attack decision logic, and a more accurate evaluation result is obtained.
Owner:ELECTRIC POWER RES INST OF GUANGXI POWER GRID CO LTD

Processor transient execution vulnerability triggering method based on loop exit prediction mechanism

This invention relates to a method for triggering transient execution vulnerabilities in processors based on a loop exit prediction mechanism, belonging to the field of computer science. First, it detects whether a loop exit predictor exists in the target processor. Then, it trains the loop exit predictor by constructing and repeatedly executing a loop of a specific length, fixing its total iteration count field to a specific value set by the attacker. Next, it triggers the victim to execute long loop code containing boundary checks. When the victim's loop reaches the specified length, the loop exit predictor preemptively predicts a loop exit, forming a transient execution window. Within this window, it bypasses boundary checks, generating out-of-bounds memory access and loading sensitive kernel data into the cache. Finally, it uses cache side-channel technology to recover the data. This invention provides a novel approach to constructing transient execution vulnerabilities, expanding the attack surface of transient execution vulnerabilities in kernel code and significantly improving kernel code security.
Owner:HARBIN INST OF TECH

Verification methods, devices, equipment, and media for power grid attack protection

PendingCN122394897AAttackPower grid
The application relates to a power network attack protection verification method, device, equipment and medium. The method comprises the following steps: determining an attack dimension for a simulation power network; constructing an attack surface model of the simulation power network under the attack dimension based on target data of actual power equipment corresponding to the simulation power network under the attack dimension; performing simulation attack on the attack surface model to obtain a current state of each element in the attack surface model after the element is updated in response to the simulation attack; determining a target element to be attacked according to a protection verification target corresponding to the simulation attack and the current state of each element; performing re-simulation attack on the target element to obtain a target state of the target element after the target element is updated in response to the re-simulation attack; and performing protection effectiveness verification on the simulation power network according to the target state of the target element to obtain a protection verification result of the power network. The method can accurately verify the actual protection effect of the power network.
Owner:ELECTRIC POWER RES INST CHINA SOUTHERN POWER GRID CO LTD

AI-combined front-end js code intelligent analysis method and system based on penetration test

The invention discloses an AI-combined front-end js code intelligent analysis method and system based on penetration testing, belongs to the technical field of artificial intelligence and penetration testing, and aims to solve the technical problem of how to realize AI-driven front-end penetration testing, improve the penetration testing efficiency, coverage and depth and improve the reliability of the penetration testing. According to the technical scheme, the method comprises the steps of intelligent attack surface surveying and mapping, wherein the structure and the function of a target application are fully perceived through an intelligent crawler, static code analysis and AST; wherein the intelligent crawler is a data acquisition tool combined with an artificial intelligence technology; according to static code analysis, the structure of the intelligent crawler is further analyzed, front-end JavaScript codes are analyzed into AST, the AST is structured representation of the codes, the AI understands the logic structure of the codes through the AST, and data flow tracking is carried out more accurately. Performing reverse analysis on the intelligent front-end code; and performing automatic vulnerability identification and attack simulation.
Owner:INSPUR QILU SOFTWARE IND

A method for preventing covert communication in ARM platform caches based on noise loading injection

This invention discloses a method for defending against cached covert communication on an ARM platform based on noise loading injection. Due to the expanding attack surface of TEEs and the vulnerabilities of TrustZone technology in microarchitectural isolation, cached covert communication has become possible. This invention adds a defense mechanism against cached covert communication based on TrustZone technology, designing a cached covert communication defense architecture based on noise loading injection. Based on this architecture, a dynamic monitoring mechanism, a strategy optimization mechanism, and a noise injection mechanism are proposed. The dynamic monitoring mechanism monitors system security and system performance. The strategy optimization mechanism generates the optimal noise injection strategy and calculates the noise injection frequency and intensity in real time. The noise injection mechanism loads data to resist cached covert communication. This defense method improves the security of the original architecture and achieves low performance overhead, balancing system security and performance.
Owner:BEIJING UNIV OF TECH

A method for continuous automated vulnerability mining based on log data

The application discloses a kind of based on log data's continuous automation vulnerability mining method, belong to network and information security technical field.The application can penetrate application surface layer, accurately identify dynamic generation interface, hidden application program interface and deep vulnerability parameter that traditional technology cannot touch, to significantly improve attack entry point coverage in real traffic, realize panoramic coverage of attack surface by quantitative information flow analysis and topology discovery based on data tracing.The application can capture, understand and verify new attack mode including zero-day attack from real traffic in near real time based on static semantics-dynamic time sequence double-layer learning model and closed-loop feedback mechanism, shorten threat response time from several days to several hours, build adaptive threat immunity ability;Through the risk intelligent scheduling mechanism driven by multi-objective genetic algorithm, test resources are preferentially allocated to business critical and highest risk attack entry, to significantly optimize computing resource allocation.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Data transmission security protection method based on dynamic encapsulation and dynamic confusion

This invention discloses a data transmission security protection method based on dynamic encapsulation and dynamic obfuscation, belonging to the field of network security technology. The method includes: receiving client requests and extracting multi-dimensional feature vectors; generating encapsulation instruction sets and obfuscation instruction sets accordingly; performing real-time structural transformation and identifier obfuscation on webpage code based on the encapsulation instruction sets to generate encapsulated code and boot code; performing multi-level obfuscation on business transmission data based on the obfuscation instruction sets and dynamic keys to generate obfuscated data and metadata; assembling the processed code, data, and metadata into a response and sending it; the client transparently restoring the data and executing the code using the boot code; monitoring system operation and dynamically optimizing protection strategies. This invention transforms a fixed attack surface into a continuously fluctuating dynamic defense interface by collaboratively and dynamically mutating the response content of each request, effectively resisting reverse engineering and automated attacks, and achieving proactive, adaptive, and transparent security protection for the user.
Owner:TIANXUN RUIDA COMM TECH CO LTD

Method for detecting risk permission chain attack in Serverless application

The invention relates to a method for detecting risk permission chain attack in Serverless application, which comprises the following steps of: aiming at potential safety hazards caused by permission dispersion, complex dependence among functions and resource cross-account sharing under a Serverless framework, proposing a three-layer progressive attack mode, namely direct vertical permission extraction, indirect vertical permission extraction and cross-account transverse propagation, and designing a'filtering and instantiation 'two-stage detection framework; the method comprises the following steps: firstly, statically analyzing a Serverless application deployment template, identifying all functions and execution permissions thereof, and filtering non-high-risk permissions; performing structured reasoning based on an attack mode, and automatically identifying a permission chain attack path; the system, the device and the medium detect the risk permission chain attack in the Serverless application based on the method. According to the method, an implicit attack surface can be systematically revealed, a visual detection result and a repair suggestion are provided for cloud security operation and maintenance and developers, the Serverless environment security protection capability is remarkably enhanced, and multi-stage and cross-account permission chain attacks are effectively resisted.
Owner:XIDIAN UNIV

Zero-copy port multiplexing method based on Linux kernel

The invention discloses a zero-copy port multiplexing method based on a LINUX kernel. Unified handshake proxy, intelligent socket right of use handover, zero-copy connection handover and service process seamless takeover functions are realized by adopting a mode of customizing a kernel module. The intelligent socket use right handover is that the handover work of the socket use right is completed according to a user-defined rule, the socket connection is handed over to other independent service processes, and the subsequent operation on the socket is carried out by the independent service processes. Zero-copy connection handover is a socket connection copying technology of a self-implementation kernel, a socket file descriptor with established connection is directly handed over to a target service process, and no data copy exists in the handover process. According to the method, direct kernel-level zero-copy data can be realized, load balancing and efficient resource utilization are realized through intelligent flow distribution based on service characteristics, and the security is enhanced by maximally converging an attack surface.
Owner:JIANGSU SHENWANG TECH CO LTD

System defense capability improvement method, device, equipment, medium and program product

The present disclosure provides a system defense capability improvement method, which can be applied to the technical field of information security and the technical field of financial technology. The system defense capability improvement method comprises: in response to the system being attacked, obtaining security requirements and threat intelligence of the system; determining the attack surface and core assets of the system according to the security requirements and the threat intelligence; for the attack surface, configuring a first security policy based on the system layer to obtain a first protection layer, wherein the first protection layer is used for the first camouflage of the core assets; in response to the first protection layer being broken, configuring a second security policy based on the application layer to obtain a second protection layer, wherein the second protection layer is used for the second camouflage of the core assets; and in response to the second protection layer being broken, establishing an emergency mechanism to transfer the core assets. The present disclosure also provides a system defense capability improvement device, equipment, medium and program product.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA