Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

38 results about "CVSS" patented technology

The Common Vulnerability Scoring System (CVSS) is a free and open industry standard for assessing the severity of computer system security vulnerabilities. CVSS attempts to assign severity scores to vulnerabilities, allowing responders to prioritize responses and resources according to threat. Scores are calculated based on a formula that depends on several metrics that approximate ease of exploit and the impact of exploit. Scores range from 0 to 10, with 10 being the most severe. While many utilize only the CVSS Base score for determining severity, temporal and environmental scores also exist, to factor in availability of mitigations and how widespread vulnerable systems are within an organization, respectively.

Network threat detection method and device, equipment and storage medium

The invention discloses a network threat detection method, device and equipment and a storage medium, and relates to the technical field of network security, and the method comprises the steps: executing a preset data collection operation to capture initial multi-dimensional data, and carrying out the preset data processing operation on the initial multi-dimensional data to obtain processed multi-dimensional data; executing a preset entity extraction operation on the processed multi-dimensional data to obtain a target entity, storing the target entity in a preset database, and inputting the target entity into a preset long-short-term memory network model to obtain attack time sequence characteristics; inputting the attack time sequence features into a target graph neural network model to construct a target knowledge graph, and determining a cross-device abnormal behavior chain based on the target knowledge graph; and determining an attack chain integrity coefficient according to the cross-device abnormal behavior chain, and determining a network threat event and a target risk level by using the CVSS vulnerability score, the space-time correction factor and the attack chain integrity coefficient to complete network threat detection. The problems of incomplete single-dimensional data coverage, high false alarm rate and the like can be solved.
Owner:INSPUR YUNZHOU (SHANDONG) IND INTERNET CO LTD

Open source software risk detection method and device based on SBOM list, equipment and medium

The invention discloses an open source software risk detection method and device based on an SBOM list, equipment and a medium, and relates to the technical field of software detection. The method comprises the following steps: acquiring an SBOM of target software, and analyzing component information of the SBOM; generating a feature character string according to the component information, and calculating a feature hash value through a hash algorithm; based on a known open source component, analyzing component information and vulnerability information of the component, calculating a feature hash value of the component, and storing the feature hash value to form a feature database; searching a matching item in a feature database based on the feature hash value of the target software component, and if the matching item is found, obtaining a license and vulnerability information of the target software component; if not, marking, manually judging and supplementing the data to the feature database; constructing a license compatibility matrix, and checking the compatibility of the obtained license and the overall license of the project; and comparing the acquired vulnerability information with a feature database, calculating vulnerability severity by combining a CVSS scoring model, and generating a priority repair report. According to the method, the software security detection speed and accuracy are improved.
Owner:NAT IND INFORMATION SECURITY DEV RES CENT

Code fingerprint-based open source component identification and vulnerability detection method

The invention discloses a code fingerprint-based open source component identification and vulnerability detection method, which comprises the following steps of: receiving a local or remote code, extracting a difference file, generating an AST and constructing a code attribute graph; sHA-256 Hash fingerprints and GNN semantic fingerprints are calculated for the function level sub-graphs to form mixed fingerprints, accurate matching is conducted through a Bloom filter, semantic matching is completed through nearest neighbor, and a component version is determined through a distribution difference algorithm. The method comprises the steps that firstly, a component identifier is mapped into a PURL or an SWID, an OSV / NVD library is inquired to obtain a CVE, comprehensive risks are calculated in combination with CVSS, EPSS and dependency depth, and an SBOM and a vulnerability report conforming to CycloneDX or SPDX are output. The method is high in speed and high in accuracy, and the open source risk can be automatically treated in continuous integration.
Owner:GUANGDONG POWER GRID CO LTD +1

Internet of Things vulnerability data restoration system

The invention relates to the technical field of Internet of Things security, in particular to an Internet of Things vulnerability data restoration system, which is used for solving the problems that in the prior art, multi-dimensional vulnerability features cannot be accurately extracted and propagated, potential vulnerabilities cannot be efficiently identified, high-risk vulnerabilities cannot be preferentially processed according to a dynamic resource adjustment strategy, and the vulnerability data restoration efficiency cannot be improved. And the accuracy, the automation level and the response efficiency of vulnerability management are reduced. According to the method, a heterogeneous relation graph between equipment and components is constructed through the vulnerability identification and positioning module, multi-dimensional vulnerability features are accurately extracted and propagated, efficient identification of potential vulnerabilities is realized, priority ranking is performed in combination with CVSS scores and equipment importance, high-risk vulnerabilities are preferentially processed through scientific scores and a dynamic resource adjustment strategy, and the efficiency of vulnerability identification is improved. And the to-be-fixed vulnerability list containing multi-aspect information is generated, so that the vulnerability management accuracy, the automation level and the response efficiency are remarkably improved.
Owner:DONGYING YINZHI INFORMATION TECHNOLOGY CO LTD

Vulnerability severity score prediction method based on large language model and retrieval enhancement

The invention belongs to the technical field of network security, and particularly relates to a vulnerability severity score prediction method based on a large language model and retrieval enhancement. According to the method, an automatic scoring framework integrating data preprocessing, hierarchical CWE classification and an RAG technology is constructed; firstly, redundant noise of vulnerability description is eliminated through a version number cleaning algorithm driven by a regular rule, and then domain knowledge modeling is enhanced in combination with a hierarchical CWE classifier based on MITRE View-1003; and an RAG technology is adopted to fuse semantic features of historical similar vulnerabilities and a large language model generation capability, so that high-precision and interpretable CVSS score prediction is realized. Experiments show that the method can be widely applied to severity score prediction of various types of vulnerabilities, has good prediction robustness and effectiveness, significantly improves vulnerability management efficiency and decision transparency, and provides an effective tool for evaluation and management of software supply chain security.
Owner:FUDAN UNIVERSITY

Network security scene-oriented RAG construction method for CVE-ATTCK association fusion

PendingCN121841709AMake up for the shortcomings of not reflecting the full picture of the attackimprove accuracyKnowledge representationSecuring communicationShardAttack
The invention discloses a CVE-ATTamp (Cascade Vector Enhanced ATTamp) for a network security scene. The invention discloses a CK association fusion RAG construction method, and relates to the technical field of network security. The method comprises the following steps: (1) carrying out structured analysis and vectorization on CVE vulnerability information data, extracting features and fusing CVSS scores to carry out semantic embedding; (2) ATTamp; semantic modeling of a CK threat matrix is carried out, and a threat semantic space containing tactical level information is constructed; (3) heterogeneous knowledge association and graph construction: calculating cross-domain semantic similarity and establishing logic mapping between vulnerabilities and tactics in combination with expert rules to form a heterogeneous knowledge graph; and (4) attack logic-oriented RAG retrieval and generation: retrieving a key attack path sub-graph based on a hybrid scoring mechanism, and driving a large model to generate a security analysis report with logic depth. According to the method, attack logic is stored through mapping, so that the problems that the traditional RAG lacks inference ability and security data fragmentation are solved, and the accuracy and tactical value of automatic threat analysis are remarkably improved.
Owner:TAIZHOU RES INST ZHEJIANG UNIV OF TECH

Quantitative evaluation method and system for industrial control network security defense

The invention discloses a quantitative evaluation method and system for industrial control network security defense. The method comprises the following steps: firstly, constructing an attack graph based on industrial control network topology and vulnerability dependence; performing quantitative evaluation on key assets in combination with node topology centrality and business importance; further integrating dynamic factors such as observability, controllability, vulnerability utilization maturity and patch perfectness on the basis of the CVSS to form a real-time updated DCVSS vulnerability scoring system; and finally, on the basis of an attack unit income / attack cost principle, iteratively calculating a path unit income and generating a minimum cut set type vulnerability repair scheme. The scheme of the invention objectively reflects equipment and vulnerability risks in an industrial control scene, accurately identifies a key protection object, automatically outputs a priority repair list, has the advantages of strong dynamic nature, high interpretability, good expandability and the like, and can provide quantitative decision support for defense strategy formulation and resource allocation of an industrial control network.
Owner:STATE GRID HENAN ELECTRIC POWER ELECTRIC POWER SCI RES INST +2

Honey array transformation configuration generation method and device, medium and electronic equipment

The invention provides a honey array transformation configuration generation method and apparatus, a medium and an electronic device. The method comprises the steps of obtaining TTP information and matching CVE to obtain CVE information; obtaining a CVSS score according to the CVE information, and selecting M mirror images associated with the CVE information with the highest score to generate a corresponding CVE mirror image configuration section; extracting scene feature information according to the TTP information to generate a feature mirror image configuration section; generating honey point configuration segments of newly added honey points and service features according to the TTP information; and mixing the CVE mirror image configuration section, the feature mirror image configuration section and the honey point configuration section to generate a honey array transformation configuration file for transforming trapping scene configuration. According to the method, TTP scene information highly associated with attacking behaviors of an attacker and various threat modeling scales are designed and introduced, mapping from the attacker behaviors to vulnerabilities and services is completed, honey point mirror images interested by the attacker are selected, and a honey array transformation configuration file is generated in a highly self-adaptive mode in combination with the scene information.
Owner:GUANGZHOU UNIVERSITY

Computer-based systems configured for network characterization and management based on risk score analysis and methods of use thereof

PendingUS20250358307A1Securing communicationEngineeringNetwork characterization
A method includes scanning a plurality of hosts in a computer network to obtain, during a predetermined time period, risk information of each instance of vulnerability associated with at least one host of the plurality of hosts, wherein the risk information comprises a common vulnerability scoring system (CVSS) score, an exploitability measurement and a measurement parameter of identified link to one or more bad actors associated with the at least one host, calculating, for the at least one host, a vulnerability risk score (VRS) for each instance of the vulnerability of the at least one host based on the associated risk information, obtaining a representative VRS based at least in part on the VRS for each instance of vulnerability of the at least one host, and facilitating at least one security action based on the representative VRS.
Owner:VIRTUALITICS INC

Vulnerability scoring based on organization-specific metrics

In one example, a non-transitory computer-readable storage medium stores executable program instructions that detect, at a remote device node, vulnerability data associated with an exploitable vulnerability of a target enterprise network; retrieve, by a first local device node, the vulnerability data, which may include a CVSS score, determine, by a second local device node, a vulnerability score VT by determining a first subscore VT1, where the first subscore VT1 is based on a Maximized Confidentiality Impact (MCI) metric that is a modified privacy metric to capture the privacy impact of the exploitable vulnerability, where the first subscore VT1 is also based on a Maximized Highest Impact (MHI) metric to capture reputation damage based on an outsized single impact attribute, and on a Modified Confidentiality (MC) metric, Modified Integrity (MI) metric and Modified Availability (MA) as provided by CVSS; and remediate the exploitable vulnerability based on the vulnerability score VT.
Owner:JPMORGAN CHASE BANK NA

Risk evaluation for a vulnerability assessment system on a data communication network from a collection of threats

A private network is scanned to identify devices, and profiling identified devices for vulnerabilities. A score is determined from a Common Vulnerability Scoring System (CVSS) database for each vulnerability individually that characterizes severity. A score is determined for a collection of vulnerabilities. Exponential tapering functions curb an influence of large numbers of low priority threats on the collection score. The collection threat score increases with severity of the collection of vulnerabilities.
Owner:FORTINET INC

A method, device, medium and electronic equipment for generating a honeycomb transformation configuration

The application provides a honey array transformation configuration generation method and device, a medium and an electronic equipment, comprising: obtaining TTP information matching CVE to obtain CVE information; obtaining CVSS score according to the CVE information, selecting M CVE information associated with the highest score to generate corresponding CVE mirror configuration section; extracting scene feature information according to the TTP information to generate a feature mirror configuration section; generating a new honeypot configuration section of the service feature according to the TTP information; and mixing the CVE mirror configuration section, the feature mirror configuration section and the honeypot configuration section to generate a honey array transformation configuration file for transforming a trapping scene configuration. By designing the TTP scene information highly associated with the attacker's attack behavior and various threat modeling scales, the application completes the mapping of the attacker's behavior to the vulnerability and the service, selects the honeypot mirror of interest of the attacker, and highly adaptively generates the honey array transformation configuration file in combination with the scene information.
Owner:GUANGZHOU UNIVERSITY

Big model-based cvss intelligent scoring and repair decision method and system

The application provides a large model-based CVSS intelligent scoring and repair decision method and system, relates to the technical field of large model decision, and comprises the following steps: when it is detected that a CVSS score version is missing in vulnerability data information, a large model is used to analyze a CVSS index data set and output score index options, and a corresponding CVSS score is calculated; a risk repair data set is constructed according to asset information, vulnerability data and the CVSS score, a targeted repair scheme is generated by the large model, and the repair scheme is sent to a risk device for execution. The application realizes automatic completion of vulnerability scoring and generation of a device customized repair scheme, and improves vulnerability management efficiency.
Owner:JIANGSU BOZHI SOFTWARE TECH CO LTD

Threat assessment method based on logic attack graph, ATTCK and CVSS

The invention discloses a method based on a logic attack graph and ATTamp; the invention discloses a threat assessment method for CK and CVSS, and the method comprises the steps: firstly obtaining preposition information needed by the successful implementation of a technology based on a minimum dependency set theory, setting predicate parameters, selecting proper predicates according to a preset target to form a necessary minimum condition set needed by an inference rule, and finally forming a rule set needed by the input of a MulVAL tool; meanwhile, constructing an input file of a MulVAL tool, and generating a logic attack graph and an attack chain by using the MulVAL tool; then constructing a technical node evaluation model and a vulnerability node evaluation model to comprehensively evaluate nodes in the logic attack graph, and performing normalization processing to obtain risk scores of the nodes; and finally, sorting the risk scores of the nodes according to the node types and reflecting the sorted risk scores in a logic attack graph. According to the method, the understanding depth of a potential attack path is improved, the accuracy of threat degree measurement is ensured, and then high-credibility threat information on an attack graph is fully reflected.
Owner:GUANGZHOU UNIVERSITY +1

An explainability authorization method and device based on natural language processing

The application discloses a kind of explainability authorization method and device based on natural language processing.The method is: 1) obtaining annotated vulnerability description and its corresponding CVSS vector as training data, optimizing pre-trained BERT model to obtain classifier;2) the text description of a target security vulnerability is input into the classifier, and the corresponding CVSS vector of the target security vulnerability is predicted;3) according to the predicted CVSS vector, the severity score of the target security vulnerability is calculated, and the user authorization level is adjusted according to the severity score;4) the input significance method based on gradient is used to analyze the vocabulary in the text description of the target security vulnerability, and the vocabulary that plays a key role in the CVSS vector corresponding to the target security vulnerability predicted by the classifier is obtained as key vocabulary;5) according to the adjusted user authorization level and the key vocabulary, the authorization adjustment explainability text corresponding to the target security vulnerability is generated.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

A risk assessment method and system for large language model vulnerabilities

PendingCN122286781ALinguistic modelAttack
This invention discloses a risk assessment method and system for large language model (LLM) vulnerabilities, relating to the fields of artificial intelligence security and network security technology. The method includes the following steps: semantic-driven vulnerability modeling, constructing a large language model vulnerability feature identification model from three dimensions: attack mechanism, model behavior, and propagation impact; constructing a scoring system, introducing three key indicators—semantic manipulation complexity, model behavior impact, and attack propagation potential—onto the CVSS standard scoring mechanism; designing a scoring transfer judgment mechanism to calculate the score, obtaining the CVSS basic score, constructing an AI-extended risk factor for score transfer, the AI-extended risk factor being calculated from the quantified values ​​of the three key indicators and their corresponding weights, and using the AI-extended risk factor and the CVSS basic score to establish a comprehensive scoring function to obtain the comprehensive score. This invention achieves quantitative assessment and automated scoring of LLM vulnerabilities by extending new risk indicators based on CVSS.
Owner:TIANJIN UNIV

Machine learning techniques for generating common vulnerability scoring system vectors

Some embodiments provide techniques for generating common vulnerability scoring system (CVSS) vectors for vulnerabilities to use in scanning a computing environment for vulnerabilities. The techniques involve obtaining a textual description of a vulnerability; generating inputs for a plurality of ML models using the textual description of the vulnerability; providing the inputs to the plurality of ML models to obtain outputs indicating values of CVSS risk metrics; and storing the values of the CVSS risk metrics indicated by the outputs of the plurality of ML models in a vector to obtain the CVSS vector for the vulnerability.
Owner:RAPID7 INC

Quantitative assessment method for cyber security risk of distribution network cyber-physical system

An automated network security risk quantitative assessment method for a power distribution network cyber-physical system includes: using the Nessus vulnerability scanner to perform a vulnerability scan on a target network; using the MulVAL tool to generate an attack graph using the vulnerability scan results and input network topology and security policies; searching a vulnerability library for corresponding vulnerability descriptions based on the vulnerability scan results, and outputting the vulnerability's CVSS metric classification using a CVSS metric classification prediction model; performing a quantitative system risk assessment based on the attack graph, CVSS metrics, and input physical consequences, and calculating the risk value of each node in the target network. The present invention utilizes open source tools to address the problem of automatic attack graph generation, and uses a CVSS metric classification prediction model to address the problem of CVSS information dependency. Furthermore, by designing multiple classifiers that share a multi-layer network, synchronous classification prediction and classification feature sharing of each CVSS metric are achieved.
Owner:BEIJING JIAOTONG UNIV

Unmanned aerial vehicle intrusion detection method and device based on attack graph learning and flight state evolution

The invention provides an unmanned aerial vehicle intrusion detection method and device based on attack graph learning and flight state evolution, and is suitable for network security protection of a heterogeneous unmanned aerial vehicle cluster. According to the method, firstly, an attack graph is constructed according to system deployment topology, task rules, historical attack logs and CVSS vulnerability score information, and the risk probability of an attack path is quantified; secondly, constructing a multi-modal tensor sequence for the flight state of each unmanned aerial vehicle, and extracting time sequence characteristics such as position, attitude, communication and power; then, attack graph embedding and state evolution information fusion are carried out, a joint feature sequence is constructed, and a depth time sequence neural network is input to identify an attack stage; and finally, intrusion judgment and early warning are carried out based on a path entropy mechanism. Experiments show that the method can effectively detect multi-stage complex attacks, has high precision, high robustness and interpretability, and is suitable for the real-time defense demand of a high-security unmanned system.
Owner:HUBEI CENT CHINA TECH DEV OF ELECTRIC POWER

Vulnerability repair priority evaluation method, system and device and storage medium

PendingCN121389136APlatform integrity maintainanceVulnerability managementSecurity engineering
The invention discloses a vulnerability repair priority evaluation method, system and device and a storage medium, and the method comprises the steps: collecting vulnerability CVSS and EPSS scores, and carrying out normalization and discrimination enhancement processing; based on enterprise risk preference and asset exposure degree, respectively setting weights of CVSS and EPSS scores; performing weighted summation to obtain a vulnerability repair priority score; performing adaptive adjustment on the vulnerability repair priority score according to the vulnerability real-time influence; performing overall priority correction on the vulnerability repair priority score after self-adaptive adjustment in combination with a service scene, asset importance, historical processing conditions of vulnerabilities of the same type and a vulnerability introduction path length; and grading the vulnerabilities based on the vulnerability repair priority score after priority correction, and executing corresponding responses to different levels of vulnerabilities. According to the method, vulnerability management is changed from experience dependence to large-scale security engineering.
Owner:JIANGSU HONGXIN SYST INTEGRATION

A markov attack path prediction method based on cvss

The application discloses a Markov attack path prediction method based on CVSS, and specifically comprises the following steps: step 1, scanning network host vulnerability information to generate a configuration file of.nessus; step 2, generating an attack graph: importing the configuration file generated in the previous step into Mulval, associating information between various host vulnerabilities through Mulval, and generating an attack graph; step 3, constructing a state transition graph: obtaining a simplified state transition graph according to the attack graph generated in step 2; step 4, initializing a Markov probability transition matrix: obtaining a probability transition matrix according to the state transition graph; and step 5, predicting an attack path probability. The method adopts a mode of measuring attack benefits to accurately predict a path to a single vulnerability level, realizes multi-step and multi-time prediction, simplifies the prediction method, and solves the problems of path redundancy, rationality and effectiveness of prior probability setting in the prediction path of the Bayesian model.
Owner:XIAN UNIV OF TECH

Power network security vulnerability scanning evaluation method and system

The invention provides a power network security vulnerability scanning evaluation method and system, and relates to the technical field of power network security. The power network security vulnerability scanning and evaluating system comprises a master control server, a data acquisition module, a protocol analysis module, a vulnerability detection module and an intelligent analysis module, the data acquisition module, the protocol analysis module and the vulnerability detection module are all connected with the master control server, and the intelligent analysis module is carried in the master control server. The data acquisition module is connected with an agent module, and the agent module comprises a lightweight agent scanner and an agent-free scanning module unit. According to the method, the multi-modal risk assessment model is constructed, and the risk thermodynamic diagram conforming to industry characteristics is generated by integrating parameters such as vulnerability CVSS scores, power business influence degrees and repair complexity, so that the vulnerability priority ranking accuracy is greatly improved.
Owner:ELECTRIC POWER RESEARCH INSTITUTE OF STATE GRID NINGXIA ELECTRIC POWER COMPANY +1

Mama-based hot rolled steel strip defect detection method

The invention belongs to the field of machine vision and industrial detection, and aims to solve the problems that CNN global features are weak, Transform calculation is complex and traditional Mamba local features are incomplete so as to realize high-precision and high-efficiency detection of a hot rolled steel strip. The method comprises the steps that 1, a steel surface image is received, a balanced data set is constructed through DDIM data enhancement, and data scarcity is relieved; 2, inputting a pre-trained SpDCH-Mama model (based on SparX-Mama improvement, including a backbone, a CVSS, a Hybrid Enhancement and a detection head), wherein the backbone alternately extracts multi-scale features by a'DPE-DMCA-VSS 'ganglion layer and a'DPE-VSS' common layer; the CVSS is fused with DWConv, Star Block and the like to strengthen local-global feature collaboration; the Hybrid Enhancement initializes the CNN sub-branch of the convolution kernel through Sobel to extract the edge, the VSS sub-branch complements the global, and the dynamic weight and the three-dimensional regularization suppression are subjected to over-fitting; the detection head fuses the features to predict the defect category probability and the bounding box offset; and 3, generating a detection result containing defect types and positions. According to the method, on an NEU-DET data set, the mAP at 0.5 reaches 82.4%, the mAP at 95 reaches 0.464, the method is superior to YOLO series and the like, and the method is suitable for industrial real-time quality inspection.
Owner:GUILIN UNIV OF ELECTRONIC TECH

Dynamic honeypot deployment method and system based on attack graph and Shapley value

The present invention provides a dynamic honeypot deployment method and system based on an attack graph and Shapley values. The method comprises: scanning and probing the protected network at first preset intervals; constructing an attack graph corresponding to the current network environment of the protected network based on the scanning and probing results; calculating the probability of exploitation of each vulnerability within each edge in the attack graph based on the CVSS rating, and defining the difficulty of attacking each edge; calculating the probability of realization of the attack path based on the difficulty of attacking each edge, and obtaining the expected loss of each attack path in the attack graph; constructing a game model, and solving the Shapley value of each edge based on the Monte Carlo method; and sorting all edges in the attack graph based on the Shapley value of each edge to generate an optimal honeypot deployment strategy based on the edge sorting results. The present invention can dynamically adjust the honeypot deployment strategy based on the real-time network security situation during the attack and defense process.
Owner:GUANGZHOU UNIVERSITY

CVSS intelligent scoring and repairing decision-making method and system based on large model

The invention provides a CVSS intelligent scoring and repairing decision-making method and system based on a large model, and relates to the technical field of large model decision-making, and the method comprises the steps: when detecting that a CVSS score version in vulnerability data information is missing, analyzing a CVSS index data set through the large model, outputting scoring index options, and carrying out the calculation to obtain a corresponding CVSS score; and constructing a risk repair data set according to the asset information, the vulnerability data and the CVSS score, generating a targeted repair scheme by the large model, and sending the targeted repair scheme to risk equipment to perform repair. According to the method and the device, automatic complementation of vulnerability scores and generation of a customized equipment repair scheme are realized, and the vulnerability management efficiency is improved.
Owner:JIANGSU BOZHI SOFTWARE TECH CO LTD

A Reinforcement Learning-Based Adaptive Policy Generation Method and System for Heterogeneous Resource Scheduling

This invention relates to a method and system for generating adaptive strategies for heterogeneous resource scheduling based on reinforcement learning, belonging to the field of cloud computing security. The system comprises a container module, a CVSS database exploitation module, a state mapping module, and a defense environment. The method includes: acquiring all container instances in the current cloud environment and storing them in a container pool; recording the heterogeneous attributes and replica count of each type of container instance; calculating the vulnerability exploitation difficulty and multi-dimensional heterogeneity indicators of the current container pool; and using a reinforcement learning model to determine the defense strategy, inputting the current container pool state into the model, deciding on the defense strategy, and calculating the reward value by weighted summation of the vulnerability exploitation difficulty and heterogeneity indicators of the container pool. This invention comprehensively considers the multi-dimensional heterogeneous attributes and real-time state information of containers, adaptively selecting the optimal defense strategy to reduce defense costs and improve the system's real-time response capability and defense effectiveness.
Owner:韩道岐

A method and apparatus for risk assessment of network assets

This application relates to the field of information security technology and discloses a method and apparatus for risk assessment of network assets. The method includes: acquiring alarm data from multiple network assets; determining a threat score for each threat subject based on the alarm data; determining a first risk score for an attack on the first network asset based on the threat score of each threat subject and the weight of each threat subject corresponding to a first network asset among the multiple network assets; determining a second risk score for an attack on the first network asset based on the Common Vulnerability Scoring System (CVSS) score, dynamic risk score, and the number of vulnerabilities in the first network asset; and determining a final risk score for the attack on the first network asset based on the first and second risk scores. Thus, by combining alarm data from multiple network assets with risk assessment from both the perspectives of threat subjects and network assets, the accuracy of identifying potential risks can be improved.
Owner:CHINA TELECOM NETWORK SECURITY TECH CO LTD

Threat intelligence intelligent analysis method based on large model and knowledge graph

The invention relates to a threat intelligence intelligent analysis method based on a large model and a knowledge graph. The threat intelligence intelligent analysis method comprises the steps of performing automatic cleaning, structured extraction and consistent storage on multi-source heterogeneous data; performing multi-modal information retrieval and association; dynamically prompting engineering and reasoning enhancement; threat research and judgment and output can be explained. According to the application, through a two-channel mixed framework in which atlas retrieval and vector retrieval are coordinated, an assembly line of keyword extraction, vector recall, atlas association, fusion duplicate removal and assembly prompting is used, recall coverage and conclusion interpretability are improved, a landing lightweight threat scoring and grading mechanism is provided, and CVSS, ATTamp, ATTamp, ATTamp, ATTamp, ATTamp, ATTamp, ATTamp, ATTamp, ATTamp, ATTamp, ATTamp and ATTamp are CK stage information is combined with retrieval evidences to obtain a unified total score and four-level judgment, so that direct access to an automatic disposal process is facilitated, a structured prompt and an explainable output scheme for evidence alignment are provided, input is organized by using an evidence block, a map path abstract and an event timeline, all conclusions can be traced back to an original text and a link, and the result is more accurate. And processing suggestions oriented to assets and businesses are generated in a linkage manner.
Owner:GUANGZHOU UNIVERSITY

An Industrial Internet Data Security Capability Maturity Assessment Method and System

The present invention belongs to the technical field of data processing. The present invention discloses a method and system for evaluating the capability maturity of industrial Internet data security, including identifying multi-dimensional security data at industrial Internet edge nodes; integrating the multi-dimensional security data and performing mapping relationship analysis to obtain a digital twin; using a vulnerability scanning tool to scan the digital twin to obtain node vulnerability data and calculate the CVSS score; dynamically quantifying the node connection degree weight based on the connectivity and vulnerability heterogeneity of the nodes; performing risk assessment based on the node connection degree weight combined with the CVSS score to obtain the node risk attributes of each node; constructing an attack path probability matrix of the digital twin through a Bayesian network; embedding the obtained node risk attributes and attack path probability matrix into the digital twin to obtain a digital twin simulation model; and effectively evaluating the capability maturity of industrial Internet data security through the combination of multiple technical links.
Owner:SHENZHEN JIANAN RUNXING SAFETY TECH CO LTD

Attack path prediction method and device based on asset analysis and graph convolutional neural network

ActiveCN121690656BAttackEngineering
The present disclosure belongs to the technical field of nuclear power and specifically relates to an attack path prediction method and device based on asset analysis and graph convolutional neural network. The present disclosure realizes rapid positioning and prediction of attack paths and improves the foresight of network security defense by modeling asset vulnerability, constructing an attack graph and utilizing a graph convolutional neural network for reasoning. Through vectorization modeling of asset vulnerability, the present disclosure converts traditional discrete vulnerability evaluation into continuous feature representation, realizing accurate quantification from coarse-grained CVSS score to multi-dimensional vulnerability features. The graph convolutional neural network is introduced for attack path prediction, which can effectively capture high-order adjacency relationships and nonlinear dependence features between assets.
Owner:CHINA NUCLEAR POWER OPERATION TECH CORP