Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

21 results about "Attack time" patented technology

In telecommunication, attack time is the time between the instant that a signal at the input of a device or circuit exceeds the activation threshold of the device or circuit and the instant that the device or circuit reacts in a specified manner, or to a specified degree, to the input. Attack time occurs in devices such as clippers, peak limiters, compressors, and voxes.

Network and information security encryption system and method

The invention relates to the technical field of encryption security, in particular to a network and information security encryption system and method. According to the method, based on time distribution of historical attack events and diversified characteristics of attack types, attack credibility is analyzed in combination with attack intervals, attack intensity of current transmission is analyzed, and a dynamic relationship between an attack intensity change trend and current non-attack duration is quantified by comparing historical and local intensity deviations, so that the attack reliability is improved. And analyzing the change condition of the current attack intensity, determining the risk coefficient of the attack borne by the system in combination with the subsequent required transmission condition and the key updating condition, and dynamically adjusting the key updating strategy based on the real-time risk level. According to the method, the security risk of the system is dynamically evaluated by analyzing the time distribution and the attack interval characteristics of the historical attack events and combining the attack type complexity and the data transmission state, and the key updating strategy is adjusted accordingly, so that the protection capability and the operation efficiency of the encryption system are improved, and the information security is improved.
Owner:SHANGRAO DAWAN NETWORK TECHNOLOGY CO LTD

Network attack prediction method and device based on graph neural network, terminal equipment and storage medium

The invention discloses a network attack prediction method and device based on a graph neural network, terminal equipment and a storage medium, and belongs to the technical field of network security, and the method comprises the steps: obtaining an attack event log of an attack event received by a current power grid system, the attack time, the attack frequency, the attack source, the attack target, the attack steps, the attack step time corresponding to each attack step and the attack step frequency are determined; generating an attack graph and attack graph features according to the attack source, the attack target, the attack steps, the attack step time and the attack step frequency; and finally, inputting the attack graph and the attack graph features into a preset attack prediction model, and predicting to obtain a next attack prediction target and a corresponding attack prediction path. By implementing the method and the device, the problem that damage to a power grid system is increased due to the fact that potential attack targets and attack paths in the power grid cannot be predicted and then attack blocking cannot be realized in advance can be solved.
Owner:POWER DISPATCHING CONTROL CENT OF GUANGDONG POWER GRID CO LTD

False alarm detection method and device for network attack alarm, equipment and medium

The invention discloses a false alarm detection method and device for network attack alarm, equipment and a medium, and relates to the field of network security, and the method comprises the steps: constructing a target list corresponding to different log types under each preset time sequence analysis granularity in each time period based on to-be-detected alarm log data of a plurality of time periods in historical data; the target list comprises a target attack time and an attack IP; if the log types and / or attacked IPs are different, the log types are different; constructing three time sequences of each target list, and calculating sequence periods respectively corresponding to the three time sequences; the three time sequences are a log quantity time sequence, an attack IP type time sequence and an attack IP information entropy time sequence; and if the periods of the three sequences are consistent and meet a preset reasonable rule and the attack IP type number of the log type corresponding to the target list meets a type number limiting rule, determining that the alarm log of the log type is a false alarm. The accuracy can be ensured while the false alarm detection efficiency is improved and the cost is reduced.
Owner:CETC CYBERSPACE SECURITY TECH CO LTD

Methods and devices for countering attacks on black-box transferable voiceprint recognition systems based on frequency domain perturbation

This disclosure belongs to the field of nuclear power technology, specifically relating to a method and apparatus for adversarial attacks on a black-box transferable voiceprint recognition system based on frequency domain perturbation. This disclosure considers the characteristic that human hearing's perception of speech signals depends on both the frequency and loudness of the speech signal. By adding adversarial perturbations to frequency ranges insensitive to the human ear, the adversarial samples generated by this method are concealed from the human ear, making them difficult for the human ear to distinguish and causing the model to misclassify. Addressing the problem that most black-box adversarial attack methods require extensive querying of the attack target, resulting in long attack times and impracticality, this disclosure utilizes the transferability of adversarial samples and employs a three-stage iterative method. This method increases the concealment and generation speed of adversarial samples, thereby eliminating the need for extensive querying of the attack target and achieving a high success rate of adversarial attacks against unknown voiceprint recognition systems.
Owner:CHINA NUCLEAR POWER OPERATION TECH CORP

System and method for audio peak limiting

PendingUS20260205084A1Audio frequencyAttack time
Provided are an audio peak limiting system and method, which, by setting a moving maximum window to drive gain calculation, and in combination with matching a moving maximum window length to a delay duration of an audio input signal, suppress a risk of overshoot while enabling a user to flexibly adjust a suitable attack time, and result in a smoother gain curve and reduce distortion in dynamic range processing, thereby achieving a more natural auditory perception.
Owner:HARMAN INT IND INC

Mining method, device and equipment of network attack tool and storage medium

The present disclosure provides a network attack tool mining method, device and equipment, and a storage medium. The method comprises: obtaining security alarm information corresponding to a network attack request to a server, wherein the security alarm information is generated by a network security device when detecting the network attack request; extracting attack information from the security alarm information, the attack information comprising an attack source network protocol address, alarm rule information, an attack time, a universal resource identifier of the attacked server, and the network attack request; and based on the security alarm information and pre-stored related information of at least one network attack tool, mining a target network attack tool corresponding to the network attack request. The above method can mine the target network attack tool corresponding to the network attack request based on parameters in multiple dimensions, thereby improving the accuracy of the mining result of the network attack tool.
Owner:CHINA CITIC BANK CO LTD

Information security encryption system

The invention discloses an information security encryption system, which comprises a data acquisition and preprocessing module, an attack situation feature extraction module, a dynamic risk assessment module, a decision execution module and a model training and self-adaption module, the data acquisition and preprocessing module generates a structured attack log containing attack time, attack type and attack interval; the attack situation feature extraction module is used for receiving the structured attack log, calculating a duration distribution weight by adopting a robust statistical method based on an attack interval duration, calculating an attack continuous weight and generating an attack credible weight in combination with an effective transmission quantity and a data entropy value, and calculating attack complexity based on a time sequence clustering result at an attack moment; and the dynamic risk assessment module is used for calculating time period attack intensity according to the attack credible weight and the attack complexity, calculating an attack intensity change index, performing fusion calculation on the attack intensity change index, a key updating time difference risk and a to-be-transmitted data volume risk, and outputting a bearing risk coefficient.
Owner:JINING UNIV

A method for cracking an integrated circuit encryption circuit state machine

The application belongs to the technical field of integrated circuits, and discloses a cracking method of an integrated circuit encryption circuit state machine, which comprises the following steps: 1, applying excitation to a netlist to extract information; 2, regarding the process of solving a key as a process of state machine reconstruction, and converting the problem into a constraint programming problem; 3, if the number of keys solved by the CP-SAT solver is 1, the attack is ended, and the unique correct key is obtained, otherwise, timing equivalence checking is performed by using Synopsys VC Formal SEQ Application, and further incorrect keys are excluded in combination with Oracles until the unique correct key or multiple equivalent keys are obtained. The attack duration of the application mainly depends on the size of the state machine and the inherent jump relationship in the state machine, and the attack time is short and the efficiency is high.
Owner:ZHEJIANG UNIV

Network intrusion tracing method and system based on behavior analysis

PendingCN121864408AAccurately depict the communication processImprove traceability accuracySecuring communicationHigh level techniquesPathPingAttack
The invention discloses a network intrusion tracing method and system based on behavior analysis, and relates to the technical field of network security. The method comprises the following steps: S1, constructing an attack activity propagation graph and calculating an attack propagation coefficient between nodes; s2, according to behavior data and attack propagation coefficients of each node in the attack activity propagation graph, calculating behavior pulse factors of the nodes, and determining attack participation nodes; s3, calculating a time propagation coefficient of an attack path and constructing an attack time trajectory according to interaction time difference characteristics and behavior pulse factors among the nodes; s4, according to the flow rate, the attack propagation coefficient and the time propagation coefficient between the nodes, calculating a traceability flow overflow index, and generating a potential attack source set; and S5, calculating an attack intensity adjustment coefficient according to the traceability flow overflow index and the flow rate, and triggering a defense strategy response mechanism based on the attack intensity adjustment coefficient. Precise traceability and real-time defense are realized through multi-dimensional behavior analysis, and the network intrusion response efficiency is improved.
Owner:HANGZHOU JIYONG TECHNOLOGY CO LTD

Security deduction method and device, network equipment and readable storage medium

The invention provides a security deduction method and device, network equipment and a readable storage medium, and is applied to the technical field of security. The method comprises the following steps: according to network state information of the twin network and a plurality of preset attack events, obtaining attack time when the attack events execute successful attacks in the twin network before first time; determining each attacked entity corresponding to the successful attack before the first time according to the network state information and the attack time; performing overlay analysis on attack effects generated by successful attacks on each attacked entity to obtain attack evaluation information; and according to the attack evaluation information, adjusting the network state information and / or the attack event of the twin network, and performing security protection configuration on the twin network. By adopting the method, the problems that a security deduction method in the prior art is inaccurate in deduction / simulation and cannot achieve the security drilling effect of a service system in a real network environment can be solved.
Owner:CHINA MOBILE COMM LTD RES INST +1

Security deduction method and apparatus, and network device and readable storage medium

PCT designated stageWO2025261518A1Securing communicationAttackEngineering
Provided in the present disclosure are a security deduction method and apparatus, and a network device and a readable storage medium, which are applied to the technical field of security. The method comprises: on the basis of network state information of a twin network and a plurality of preset attack events, obtaining attack times at which the attack events execute successful attacks on the twin network before a first time; on the basis of the network state information and the attack times, determining each attacked entity corresponding to the successful attacks before the first time; performing superposition analysis on attack effects generated by the successful attacks on each attacked entity, so as to obtain attack assessment information; and on the basis of the attack assessment information, adjusting the network state information of the twin network and / or the attack events, and performing security protection configuration on the twin network. The method can solve the problem whereby, in security deduction methods in the prior art, deduction / simulation is inaccurate and the security drill effect of a service system in a real network environment cannot be achieved.
Owner:CHINA MOBILE COMM LTD RES INST +1

Cryptographic attack identification method and device, equipment and medium

The application relates to a CC attack identification method and device, equipment and medium in the e-commerce technical field, the method comprises the following steps: acquiring a first access index corresponding to each preset time period of an independent station; judging whether the first access index reaches a first preset standard, and determining that the corresponding preset time period is an attacked time period when the first access index reaches the first preset standard; determining the growth speed between the first access index corresponding to each preset time period and the first access index corresponding to the previous preset time period; judging whether the growth speed of the attacked time period reaches a second preset standard, and confirming that the independent station is attacked when the growth speed reaches the second preset standard; determining the growth acceleration between the growth speed corresponding to each preset time period and the growth speed corresponding to the previous preset time period; judging whether the growth acceleration reaches a third preset standard or a fourth preset standard; and determining the attack type of the independent station according to the reached preset standard when the growth acceleration reaches the third preset standard or the fourth preset standard. The application can efficiently and accurately identify various CC attacks and attack types.
Owner:GUANGZHOU HUANJU SHIDAI INFORMATION TECH CO LTD

Internet of Things attack tracing method, device, equipment, storage medium and product

The invention provides an Internet of Things attack tracing method and device, equipment, a storage medium and a product. Comprising the following steps: acquiring an attacked Internet of Things device and an attack time window according to an Internet of Things device log; collecting multi-source communication data, and judging whether a single-hop Internet of Things attack link exists or not according to the multi-source communication data; if it is judged that the single-hop Internet of Things attack link does not exist, a communication graph of the attacked Internet of Things equipment is constructed according to the multi-source communication data; in the communication graph, taking the attacked Internet of Things equipment as a starting point, and obtaining a plurality of candidate multi-hop Internet of Things attack links; obtaining a credibility value of each candidate multi-hop Internet of Things attack link; and determining the candidate multi-hop Internet of Things attack link with the highest credibility value as a final multi-hop Internet of Things attack link. Wherein an end point in the final multi-hop attack link of the Internet of Things is an attack end of the Internet of Things. According to the method provided by the invention, the accuracy of attack tracing in the Internet of Things environment is improved.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD +2

Traffic forwarding method and routing controller

The present invention relates to a traffic forwarding method and routing controller, comprising: detecting network traffic, and when malicious traffic information is detected, determining the network protocol corresponding to the network address requested by the corresponding malicious traffic, and the traffic packet corresponding to the corresponding malicious traffic; generating forwarding rules, and sending the forwarding rules and the traffic packet to an intranet switch, so that the intranet switch sends the traffic packet to the service environment corresponding to the network protocol in a honeypot environment according to the forwarding rules. The present invention weakens the difference between the honeypot network segment and the office network segment, more accurately forwarding malicious traffic to a honeypot environment that is basically consistent with the network environment to be attacked, increasing the difficulty for attackers to distinguish the honeypot environment, inducing attackers to trigger more derivative attack behaviors, extending the attacker's attack time, capturing more unknown attack behaviors, and obtaining more new threat intelligence.
Owner:HARBIN ANTIY TECH

Data processing method and device, equipment and medium

The invention provides a data processing method and device, equipment and a medium. The method is executed by an aggregation node, the aggregation node and a plurality of terminal nodes form an equipment network, and the method comprises the following steps: acquiring aggregation data sent by the terminal nodes; determining first security data of the aggregated data based on a data source and / or a data type of the aggregated data; determining second security data of the terminal node based on the historical data traffic and historical attack times of the terminal node and the connection times of the terminal node and the sink node; determining a security level of the aggregated data based on the first security data and the second security data; and obtaining the security level of each storage device, determining a target storage device corresponding to the converged data based on the security level of the converged data and the security level of each storage device, and storing the converged data through the target storage device. According to the technical scheme of the invention, the security and adaptability of aggregation data storage are improved.
Owner:中国移动通信集团云南有限公司 +1

Data processing method and device, equipment and medium

The invention discloses a data processing method and device, equipment and a medium. The method comprises the steps that an aggregation access log is determined based on a service protection log, and attack time data used for log division is determined based on a service prompt log; dividing the aggregation access log into an attack type traffic log and a non-attack type traffic log based on the attack time data; based on the attack type traffic log and the non-attack type traffic log, determining an attacked target business server in the business servers and a target access device which initiates an illegal access request to the target business server in the access device, and obtaining illegal access data associated with the target business server and the target access device; performing attack degree evaluation on the illegal network address according to the illegal access data to obtain the attack degree of the illegal network address for the target access domain name; the attack degree is used for determining a protection strategy for the illegal network address. By adopting the method and the device, the protection effect on network attacks can be improved.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

Attack behavior prediction model training method, attack behavior prediction method and related equipment

The embodiment of the invention discloses a training method of an attack behavior prediction model, an attack behavior prediction method and related equipment, and belongs to the technical field of network security processing. The method comprises the following steps: extracting a plurality of attack entities from original alarm information, and determining an attack event between any two attack entities and attack time corresponding to the attack event; inputting a plurality of sample attack sequences determined by the attack entity, the attack event and the attack time into the attack behavior prediction model, and outputting a predicted attack sequence after shielded information in each sample attack sequence is recovered; and determining a sequence loss value according to each predicted attack sequence and the corresponding tag attack sequence, and performing iterative training on the attack behavior prediction model according to the sequence loss value to obtain a trained attack behavior prediction model which is used for predicting the next attack behavior of the generated target attack behavior to obtain a predicted attack behavior. According to the invention, the accuracy of completely predicting all attack behaviors can be improved.
Owner:PENG CHENG LAB

Network security early warning method and system based on multi-source data

The invention discloses a network security early warning method and system based on multi-source data, relates to the field of power grid security, and solves the technical problems that in power grid security management, it is difficult to carry out prospective early warning on security attacks suffered by power grid equipment, and potential situation reminding of attack early warning by spatial geometric features of attackers is neglected. According to the method, the threat prediction model is established based on the historical attack record, and the time range and potential propagation equipment of the next attack after the current attack are identified based on the threat prediction model; determining an importance factor of the equipment based on the basic information, and determining a severity factor of the attack based on the attack information; determining a potential threat factor of each device based on the potential propagation device of the next attack, the importance factor and the severity factor; determining an early warning level of each device in a next attack time range based on the potential threat factor of each device, and sending early warning information to a manager based on the early warning level; the accuracy of power grid safety early warning can be improved.
Owner:WUHU POWER SUPPLY COMPANY OF STATE GRID ANHUI ELECTRIC POWER

Echo cancellation method for equipment with AGC (Automatic Gain Control)

PendingCN121811902ASpeech analysisControl theoryAttack time
The invention discloses an echo cancellation method for equipment with AGC (Automatic Gain Control), which comprises the following steps: step 1, presetting a static reference parameter set of the AGC, taking the static reference parameter set as an initial value for dynamically adjusting parameters of the AGC, the static reference parameter set comprising target gain, attack time and release signal duration; 2, setting a triggering condition for triggering and adjusting AGC parameters based on the amplitude characteristics of the multi-channel audio stream monitored by the hardware interface of the equipment; and step 3, when the triggering condition is met, executing an adjustment strategy which is used for adjusting the parameters of the AGC so as to realize echo cancellation by adjusting the parameters of the AGC. According to the method and the device, the AGC parameters are dynamically adjusted, the two triggering conditions are adopted, and the corresponding adjustment strategies are executed, so that the echo can be better eliminated, and the initial echo and the process probability echo are effectively avoided or reduced.
Owner:GUANGZHOU BAOLUN ELECTRONICS CO LTD

Multi-platform multi-target dynamic task allocation method, system, device and medium

The embodiment of the present invention provides a multi-platform multi-target dynamic task allocation method, system, device and medium, which belongs to the field of multi-platform collaborative confrontation. The method includes: using the platform to divide the target action cycle into time windows; constructing a task allocation model; judging whether all targets are completely killed according to the model solution result, if so, taking the minimum total cost of consuming the platform load as the first optimization goal; if not, taking the minimum overall threat remaining to the target as the second optimization goal, using the solve solver to solve the first or second optimization goal, and obtaining the target allocation scheme for each platform channel to confront in each action cycle. Using the action cycle to divide the task time window effectively solves the problem of conflict in the platform's task time on the target and the waste of attack time. According to whether the target is completely killed, the total cost of consuming the platform load or the minimum overall threat remaining to the target is selected as the optimization indicator to ensure the interception effect while minimizing the interception cost.
Owner:NAVAL AVIATION UNIV

Test method, test device, electronic equipment and computer program product

The invention discloses a test method, a test device, electronic equipment and a computer program product, which are applied to the technical field of computer security, and the test method comprises the following steps: under the condition that a first thread occupies a target memory area, releasing a target pointer pointing to the target memory area, and after the first thread releases the target pointer, starting the target pointer to the target memory area; the target pointer is emptied; an interrupt storm is constructed, the opportunity of the first thread to empty the target pointer is delayed, and the interrupt storm is formed by interrupt between processors; in the look-ahead state, a second thread is used for simulating an attack behavior, a test result is generated, and the attack behavior comprises the behavior of reading the data in the target memory area. According to the method and the device, the opportunity of null target pointer of the first thread is delayed, so that longer time is reserved for a simulation attacker to implement a simulation attack behavior, and an inaccurate test result caused by the fact that a security hole cannot be exposed due to too short simulation attack time can be avoided to a certain extent.
Owner:PHYTIUM TECH CO LTD