Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

22 results about "Attack tree" patented technology

Attack trees are conceptual diagrams showing how an asset, or target, might be attacked. Attack trees have been used in a variety of applications. In the field of information technology, they have been used to describe threats on computer systems and possible attacks to realize those threats. However, their use is not restricted to the analysis of conventional information systems. They are widely used in the fields of defense and aerospace for the analysis of threats against tamper resistant electronics systems (e.g., avionics on military aircraft). Attack trees are increasingly being applied to computer control systems (especially relating to the electric power grid ). Attack trees have also been used to understand threats to physical systems.

Exposure management system and a method for exposure management

An exposure management system and an exposure management method for assessing exposure of assets of an organization, the assets comprising at least one host, such as a computer or a server. The method comprises creating a model of the organization controlling the assets, creating models of plurality of threat actors able to attack the assets of the organization, producing a reduced set of threat actors relevant for the organization based on the relevance of a specific threat actor to the organization in view of the created threat actor models and the created model of the organization. The method further comprises, for each threat actor of the reduced set of threat actors, determining available attack paths for the assets of the organization with an attack path simulator and combining the determined available attack paths for the assets of the organization to attack trees for a specific threat actor.
Owner:F SECURE CORP

Information security risk assessment method for train wireless network control system

ActiveCN121218180AParticular environment based servicesFor mass transport vehiclesWireless networked control systemAttack
The invention relates to the technical field of train wireless network communication, in particular to an information security risk assessment method for a train wireless network control system, which comprises the following steps of: establishing an attack tree model according to a risk assessment object, assessing the occurrence possibility of a security event by using a triangular fuzzy number, analyzing attack paths, and calculating the interval probability of each attack path, the method comprises the following steps: obtaining a point probability according to an attack path interval probability, calculating an attack occurrence possibility, evaluating a security event influence by using a fuzzy analytic hierarchy process, calculating a security event risk value by quantifying the occurrence possibility and an influence value of the security event, and determining a risk level and a security level of a system according to a system risk evaluation value. And formulating corresponding protection requirements. According to the method, the information security risk of the train wireless network control system is effectively evaluated and managed, a basis is provided for formulating an effective security protection strategy, and the overall security capability of the train wireless network is improved.
Owner:DALIAN JIAOTONG UNIVERSITY

Vehicle safety assessment method and device based on AI-assisted attack tree, equipment and medium

The invention discloses a vehicle safety assessment method and device based on an AI-assisted attack tree, equipment and a medium, and belongs to the technical field of computers. The method comprises the following steps: automatically generating an attack tree containing a dynamic risk level by adopting a hierarchical agent workflow based on a vehicle type architecture; extracting a threat scene from the attack tree and generating a structured description; matching a historical knowledge base by utilizing a retrieval enhancement generation technology, and generating an asset list and a threat score through a large language model; and synthesizing the attack tree and the scoring result to generate an evaluation conclusion containing security disposal suggestions. According to the technical scheme, the attack tree can be automatically generated based on the vehicle model architecture, intelligent scoring is linked, finally, the safety evaluation conclusion containing specific disposal suggestions is output, and the evaluation efficiency, accuracy and engineering practicability are remarkably improved.
Owner:ZHEJIANG YANGTZE RIVER DELTA INTERNET OF VEHICLES SECURITY TECH CO LTD

Dynamic confrontation-oriented multi-dimensional risk real-time assessment method and system

The invention relates to the technical field of risk assessment, and provides a multi-dimensional risk real-time assessment method and system for dynamic confrontation. The method comprises the following steps: accessing a data source to execute data acquisition, and establishing a multi-source dynamic data set; carrying out attack intention and behavior attribution analysis on the multi-source dynamic data set, and outputting an attacker strategy intention graph; modeling an attacker strategy by using a random game based on the strategy intention graph, and configuring a dynamic attack tree; constructing a conditional dependency graph according to the dynamic attack tree path dependency relationship, and mapping the conditional dependency graph into a Bayesian network structure; according to a Bayesian network, a risk propagation model is constructed, a node state is updated, and risk probability mapping is established, so that the technical problem that a traditional static risk assessment method cannot reflect risk evolution in a dynamic confrontation process in real time is solved, and the aim of improving the risk evolution in a dynamic confrontation process is achieved through collection and analysis of a multi-dimensional dynamic data source. And real-time modeling and risk propagation evaluation of attacker behaviors are realized, so that the technical effects of improving the adaptive capability and the real-time response capability of network security protection are achieved.
Owner:CHINA SOUTHERN POWER GRID COMPANY

A multi-round jailbreaking defense method and device for a text-to-sql system

The application discloses a kind of multi-round jailbreak defense methods and devices for Text-to-SQL system, it is related to network security technical field, the method includes: based on multi-round Text-to-SQL dataset Construction contains multi-class attack scene's jailbreak attack dataset, constructs and trains the attacker model based on pre-training language model, to generate multi-round natural language question with attack intention, establish multi-round jailbreak attack tree, to structured representation by attack target decomposition Multiple-step attack path, based on attack tree generation with semantic coherence multi-round attack question sequence, the sequence is input target Text-to-SQL system, execute the SQL query of its output, and according to evaluation index quantification attack effectiveness, the present application can systematize gradually progressive jailbreak attack in multi-round dialogue Simulation, realize the automatic testing and evaluation of Text-to-SQL model security, provide basis for system reinforcement and defense strategy formulation.
Owner:SICHUAN INFORMATION TECH COLLEGE

An attack method clustering and attribution method for attack patterns

The application provides an attack method clustering and attribution method for attack patterns, and relates to the technical field of network security. The attack method clustering and attribution method comprises the following steps: collecting threat intelligence original data and extracting data based on a large language model to obtain attack information; inputting the attack information into a retrieval enhancement generation framework to generate triplets, fusing the triplets with a network security knowledge graph to obtain TTPs data; clustering the TTPs data based on a Gaussian mixture clustering model, and enhancing the Gaussian mixture clustering model based on the structure entropy of TTP nodes to obtain a soft clustering result; constructing an attack tree based on the soft clustering result, performing weight distribution based on an attention mechanism, and matching the attack tree in the knowledge graph based on a similarity calculation method to obtain an attribution result. The application provides a complete attack behavior attribution implementation framework, combines the advantages of cutting-edge technologies, and can realize efficient, accurate, reliable, scalable and highly interpretable attribution.
Owner:GUANGZHOU UNIVERSITY

A train wireless network control system information security risk assessment method

ActiveCN121218180BParticular environment based servicesFor mass transport vehiclesWireless networked control systemAttack
The present application relates to train wireless network communication technical field, specifically to a kind of train wireless network control system information security risk assessment method, including according to the object of risk assessment to establish attack tree model, the possibility of security event is assessed using triangular fuzzy number and occurs, attack path is analyzed, and the interval probability of each attack path is calculated, point probability is obtained according to attack path interval probability, the possibility of attack is calculated, the influence of security event is evaluated using fuzzy analytic hierarchy process, the possibility of security event and impact value are quantified, security event risk value is calculated, the risk level and security level of system are determined according to system risk assessment value, corresponding protection requirements are formulated.The present application effectively evaluates and manages the information security risk of train wireless network control system, provides basis for formulating effective security protection strategy, and improves the overall security capability of train wireless network.
Owner:DALIAN JIAOTONG UNIVERSITY

Automated attack path analysis and evaluation method and device based on large language model

The present disclosure provides an automated attack path analysis and assessment method and device based on a large language model. The method comprises: first, determining the system architecture to be analyzed, and determining the attack entry and attack exit, constructing a label tree, and extracting the target information of each label node in the label tree; using the large language model to analyze the potential attack surface and attack purpose of each label node in the label tree; then obtaining the domain knowledge corresponding to the system architecture to be analyzed, and then generating an attack tree based on the target information of each label node, the corresponding potential attack surface, the attack purpose, and the domain knowledge; finally, evaluating the feasibility of the attack tree and scoring it based on the large language model, and optimizing the target attack tree. This embodiment overcomes the problems of subjectivity, update difficulty, and information abstraction of traditional threat database-based methods, and at the same time has cross-domain application capabilities, and is suitable for a variety of fields such as smart cars, smart ships, industrial equipment, drones, aerospace, etc.
Owner:BEIJING GOUAN TECH CO LTD

Data security protection method for photovoltaic power station under smart grid environment

ActiveCN119696899BSecuring communicationAttackAttack tree
The application discloses a data security protection method for a photovoltaic power station in a smart grid environment, and relates to the technical field of smart water supply equipment inspection, and comprises the following steps: step one: using an attack tree model and a threat model to identify and evaluate the data security risks of the photovoltaic power station, and evaluating the risk level; at the same time, based on a blockchain technology, a unique digital identity is generated for the photovoltaic power station equipment and its business scene, and access control is implemented. The data security protection method for the photovoltaic power station in the smart grid environment can not only efficiently process a large amount of data, but also ensure the security and integrity of the data in the transmission, storage and processing process, can avoid information leakage or malicious attacks, improve the data security of the photovoltaic power station, and guarantee the safe and stable operation of the power system.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD

A knowledge graph-based attack tree automatic construction method

PendingCN122316761AScale modelAttack
This invention discloses an automated method for constructing vehicle-mounted attack trees based on knowledge graphs and large-scale model agents, relating to the field of vehicle-mounted information security technology. The invention includes the following steps: S1, constructing an ontology model of a vehicle-mounted attack domain knowledge graph, defining two types of entities: threat nodes and threat scenario nodes, causal relationship types, and entity attribute constraints; S2, collecting vehicle-mounted security threat data and constructing a vehicle-mounted attack knowledge graph with a directed acyclic graph structure; S3, acquiring electronic and electrical architecture asset data of the target vehicle system and extracting asset security attributes through an asset identification agent; S4, constructing an attack topology graph from system modeling data, enumerating all reachable attack paths from externally exposed nodes to the target asset. This invention, through the collaboration of large-scale model agents and vehicle-mounted attack knowledge graphs, achieves fully automated construction of vehicle-mounted attack trees, ensuring attack path integrity with quantifiable path coverage metrics, and improving construction efficiency and attack path integrity.
Owner:BEIJING SIGEVOROYE INTELLIGENT TECHNOLOGY CO LTD

System and method for enhancing threat and risk assessment with zero trust access control integration

Embodiments of the present disclosure relates to a system (100) and method (300) for enhancing Threat and Risk Assessment (TARA) through the integration of Zero Trust Access Control (ZT-AC) principles. The system (100) utilizes a processor (104) to acquire and analyze system assets, define strict access policies based on Zero Trust, and categorize vulnerabilities by their relevance and impact. The system (100) maps threats to assets, incorporates ZT-AC policies to minimize exposure, and develops AI-powered attack tree models to simulate potential attack scenarios. The system (100) validates adherence to Zero Trust principles, simulates mitigating effects within attack trees, and scores risk based on likelihood, impact, and ZT-AC mitigations. Detailed cybersecurity risk assessments are generated, providing actionable recommendations for refining Zero Trust policies and improving overall security.
Owner:SURYAWANSHI SACHIN +4

An AI-assisted attack tree-based vehicle security evaluation method, device, equipment and medium

ActiveCN121907609BLinguistic modelRisk rating
The application discloses an AI-assisted attack tree-based vehicle safety evaluation method, device, equipment and medium, and belongs to the technical field of computers. The method comprises the following steps: automatically generating an attack tree containing a dynamic risk level based on a vehicle architecture by adopting a hierarchical intelligent agent workflow; extracting a threat scenario from the attack tree and generating a structured description; matching a historical knowledge base by using a retrieval enhancement generation technology, and generating an asset list and a threat score by a large language model; and generating an evaluation conclusion containing a safety disposal suggestion by comprehensively combining the attack tree and the score result. The technical scheme can automatically generate an attack tree based on a vehicle architecture and link intelligent scoring, finally output a safety evaluation conclusion containing specific disposal suggestions, and significantly improve the evaluation efficiency, accuracy and engineering practicability.
Owner:ZHEJIANG YANGTZE RIVER DELTA INTERNET OF VEHICLES SECURITY TECH CO LTD

Dynamic defense method and system fused with water conservancy network security situation awareness

PendingCN121841792ASecuring communicationAttackFuzzy membership function
The invention belongs to the technical field of dynamic defense, and particularly relates to a dynamic defense method and system fused with water conservancy network security situation awareness, so as to solve the technical problems that data isomerism is difficult to process, model static state lacks timeliness, threat prediction is incomplete, and defense decisions are not balanced in an existing attitude awareness method. The defense method comprises the following steps: constructing a multi-layer attack tree model of the water conservancy network; obtaining heterogeneous security data collected by monitoring nodes in a network, quantifying the heterogeneous security data into normalized threat values in one-to-one correspondence with leaf nodes in the model based on an asset vulnerability incidence matrix and a situation element fuzzy membership function, and taking the normalized threat values as conditional occurrence probabilities of the leaf nodes; and traversing all attack paths in the multi-layer attack tree model, and executing an operation on any path. According to the defense method, interference to normal operation of the water conservancy core business is reduced, and balance between safety and business is achieved.
Owner:HENAN WATER INVESTMENT SOIL & WATER RESOURCES DEV CO LTD

Computer-readable recording medium, risk calculation method, and risk calculator

A non-transitory computer-readable recording medium stores therein a risk calculation program that causes a computer to execute a process including, storing a weight for every attack condition, calculated with reference to a usage rate of each of the attack conditions, and a presence rate of each of a plurality of specification elements contained in a specification of the AI system, regarding the conditions for establishing the attack, the presence rate being defined in specifications of a plurality of existing AI systems, identifying an establishment status of the attack condition, with reference to information regarding the specification element extracted from information regarding the specification of an AI system subject to the risk determination, and calculating a risk score for every attack tree of the AI system subject to the risk determination, with reference to the weight for every attack condition, and the identified establishment status of the attack condition.
Owner:FUJITSU LTD

A large model-based tara risk quantification modeling method

This invention discloses a large-scale model-based TARA risk quantification modeling method, relating to the field of vehicle-mounted information security technology. The invention includes the following steps: Step a: Using a system modeling agent, the vehicle system architecture document is parsed to extract components, communication channels, and data flows, establishing a structured asset model; Step b: Using an asset identification agent, the seven-dimensional security attributes of each asset are identified, completing standardized annotation of asset security attributes; Step c: Using a damage scenario agent, standardized damage scenarios are generated based on a damage knowledge graph, and a four-dimensional impact assessment is performed; Step d: Using a threat analysis agent, threat scenarios are generated based on damage scenarios and a threat knowledge graph, an attack tree is constructed, and compliance mapping is performed. This invention achieves fully automated risk quantification of the TARA process through multi-agent phased collaboration and scenario reasoning enhanced by dual knowledge graphs, eliminating human subjective bias and improving the consistency and completeness of assessment results.
Owner:BEIJING SIGEVOROYE INTELLIGENT TECHNOLOGY CO LTD

A multi-round jailbreaking attack evaluation method and device for a Text-to-SQL system

The application discloses a kind of multi-round jailbreak attack evaluation method and device for Text-to-SQL system, it is related to network security technical field, the method includes: based on multi-round Text-to-SQL dataset Construction contains multi-class attack scene's jailbreak attack dataset, constructs and trains the attacker model based on pre-training language model, to generate multi-round natural language question with attack intention, establish multi-round jailbreak attack tree, to structured representation by attack target decomposition Multiple-step attack path, based on attack tree generation with semantic coherence multi-round attack question sequence, the sequence is input target Text-to-SQL system, execute the SQL query of its output, and according to evaluation index quantification attack effectiveness, the present application can systematize gradually progressive jailbreak attack in multi-round dialogue, realize the automatic testing and evaluation of Text-to-SQL model security, provide basis for system reinforcement and defense strategy formulation.
Owner:SICHUAN INFORMATION TECH COLLEGE

Risk assessment method, system and device for in-vehicle wireless communication and medium

The embodiment of the invention provides a risk assessment method, system and device for in-vehicle wireless communication and a medium, and belongs to the technical field of vehicle safety. The method comprises the following steps: acquiring functional module information of a vehicle; according to the function module information, each function module configured by the vehicle is divided into a first type of modules and a second type of modules, damage scenes of the first type of modules and the second type of modules are determined according to the first preset dimension, the first type of modules apply the star flash communication technology, and the second type of modules do not apply the star flash communication technology; constructing a forward attack tree and a reverse attack tree based on the damage scene, and aggregating the forward attack tree and the reverse attack tree according to the first type of modules and the second type of modules to obtain a target attack tree; and calculating a feasibility score for the target attack tree according to a second preset dimension, and determining a risk assessment result of the vehicle according to the feasibility score and the damage scene. The embodiment of the invention aims to improve the wireless communication security of the vehicle.
Owner:CHINA FAW CO LTD

Multi-round jail break attack evaluation method and device for Text-to-SQL system

The invention discloses a multi-round jailbreak attack evaluation method and device for a Text-to-SQL system, and relates to the technical field of network security, the method comprises the following steps: constructing a jailbreak attack data set containing multiple types of attack scenes based on a multi-round Text-to-SQL data set, constructing and training an attacker model based on a pre-training language model, the method comprises the steps of generating a multi-round natural language question with an attack intention, establishing a multi-round jail break attack tree, structurally representing a multi-step attack path formed by decomposing an attack target, generating a multi-round attack question sequence with semantic coherence based on the attack tree, inputting the sequence into a target Text-to-SQL system, and executing an SQL query output by the target Text-to-SQL system. According to the method, the progressive jailbreak attack in multiple rounds of dialogues can be systematically simulated, the security of the Text-to-SQL model is automatically tested and evaluated, and a basis is provided for system reinforcement and defense strategy formulation.
Owner:SICHUAN INFORMATION TECH COLLEGE

Automated security compliance for system nodes

Disclosed herein are embodiments of systems, methods, and products comprise an analytic server, which improves security of a system. The analytic server may monitor the system by retrieving status information from various devices within the system. The analytic server may generate an attack tree model based on a set of aggregation rules that are configured based on the monitored status information. The analytic server may detect one or more attacks by associating the status information with corresponding nodes of the attack tree model and executing a logic of the attack tree model. The analytic server may determine aggregated impact and risk metrics and calculate an impact score for each attack based on aggregated impact and risk metrics. The analytic server may generate reports comprising the one or more attacks ranked based on the impact scores. The analytic server may respond to one or more attacks by taking automated actions.
Owner:ARCHITECTURE TECH CORP

Non-transitory computer-readable recording medium, generation method, and information processing device

A non-transitory computer-readable recording medium has stored therein a generation program that causes a computer to execute a process including, acquiring tree structure information indicating a structure of an attack tree, the attack tree including pieces of information of a plurality of first nodes each of with which information indicating an attack that is established is associated and a plurality of second nodes with which a first condition for establishing the attack is associated, acquiring a damage degree in a case where the attack is established, acquiring a first easiness degree indicating easiness of satisfying the first condition, calculating a second easiness degree indicating easiness of the attack based on the tree structure information and the first easiness degree, calculating priority for taking a countermeasure against the attack associated with the first node based on the damage degree and the second easiness degree.
Owner:FUJITSU LTD

Risk calculation program, risk calculation method, and risk calculation device

The invention relates to a risk calculation program, a risk calculation method, and a risk calculation device. In the present invention, a computer executes: a process for storing a weight for each attack condition calculated on the basis of a usage rate for each of the attack conditions, which is an element for establishing a prescribed attack on an AI system, and a presence rate; the presence rate is the presence rate under a plurality of existing AI system specifications for each of a plurality of specification elements which are elements included in the AI system specifications and which are related to conditions for the establishment of the attack; accepting specification information of the AI system of the risk determination object; for each pre-created attack tree, on the basis of the specification element information extracted from the specification information of the AI system of the risk determination object, determining the establishment state of the attack condition; a risk value for each of the attack trees of the AI system to be subjected to risk determination is calculated on the basis of the weight for each of the attack conditions and the established condition of the attack condition.
Owner:FUJITSU LTD

Information security detection method, device, equipment and medium

The application discloses an information security detection method, device, equipment and medium, and the method comprises the following steps: creating an attack tree corresponding to a preset attack list, and determining a workflow corresponding to each attack path of the attack tree; acquiring a metric of a leaf node of the attack path, determining a first weight value of the workflow corresponding to the attack path according to the metric; sorting the workflow according to the first weight value, performing attack test on each workflow according to the sorting order, and obtaining a detection result of the attack test of each workflow. The application improves the timeliness of attack test on the attack path with a higher priority.
Owner:CHINA MOBILE GROUP ZHEJIANG +1