Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

340 results about "Cyber-attack" patented technology

In computers and computer networks an attack is any attempt to expose, alter, disable, destroy, steal or gain unauthorized access to or make unauthorized use of an asset. A cyberattack is any type of offensive maneuver that targets computer information systems, infrastructures, computer networks, or personal computer devices. An attacker is a person or process that attempts to access data, functions or other restricted areas of the system without authorization, potentially with malicious intent. Depending on context, cyberattacks can be part of cyberwarfare or cyberterrorism. A cyberattack can be employed by sovereign states, individuals, groups, society or organizations, and it may originate from an anonymous source.

Systems and methods for formal verification of computer platforms

Systems and methods for mathematical modeling of the hardware and software stack of commodity computer platforms are provided, enabling provable guarantees on memory, device, and program execution. This approach addresses the technical problem of reliance on system agents that rely on implicit trust in the operating environment, which can be exploited by sophisticated attackers using complex threats such as memory access exploits and code / data integrity exploits. The solution provides a proactive, mathematically-backed security solution that eliminates entire classes of cyberattacks by design, ensuring realizable guarantees on commodity computer platforms running hardware and software stack elements at the lowest operating level. This approach has significant advantages over current reactive cybersecurity methods, including reduced complexity and overhead, and increased confidence in the integrity of the system. The solution's main uses include providing mathematically-backed security and availability guarantees for critical infrastructure, financial institutions, and other organizations vulnerable to cyberattacks.
Owner:UBERSPARK INC

System and methods for unforgeable telemetry in the presence of cyberattacks on a computer platform

System and methods are disclosed for providing unforgeable telemetry on computer platforms. Mathematical modeling and theorem proving are utilized to guarantee the integrity of telemetry probe execution flow and trigger, thereby preventing circumvention and tampering of logged probe data. In contrast to current state-of-the-art solutions that rely implicitly on the operating environment, this approach provides a sound and complete assurance of telemetry output. The system enables organizations to map unforgeable telemetry probe data to industry and government cybersecurity regulatory controls, ensuring compliance therewith. This invention addresses the shortcomings of existing solutions, including their vulnerability to sophisticated attacks, operational complexity, and inability to provide unforgeable telemetry data, thereby providing a reliable and accurate monitoring output in the presence of cyberattacks on computer platforms.
Owner:UBERSPARK INC

Data security detection method for signal transmission software

The invention relates to the technical field of data security detection, in particular to a data security detection method for signal transmission software. And obtaining residual time sequence data after decomposition of the plurality of signal-to-noise ratio time sequence data. Because the electromagnetic interference can cause the residual points to present trend characteristics, the value distribution and change trend of the residual points are analyzed, and outliers and trend characteristic values are obtained. The distribution of the outliers subjected to electromagnetic interference is random, so that a local distribution characteristic value is obtained based on the position distribution condition of the outliers. And combining the two indexes to obtain an electromagnetic attribute characteristic value. Furthermore, as the abnormity generated by the network attack is more correlated, the correlation condition of the outliers in the residual time sequence data of the plurality of channels is analyzed and combined with the electromagnetic attribute characteristic value to obtain an electromagnetic interference degree value, and finally, the outliers generated by electromagnetic interference are removed according to the electromagnetic interference degree value to obtain network abnormal points. The detection precision of the network abnormal points is improved, and the safety detection effect is ensured.
Owner:ZHUNJIAN HEBEI TESTING TECH SERVICE CO LTD

System and method for identifying malicious hosts prior to commencement of a cyber-attack

According to one embodiment, host infrastructure analysis logic that attempts to detect a malicious host operating within a network prior to a cyber-attack being conducted by the malicious host is described. The host infrastructure analysis logic includes querying logic, profile confirmation logic, classification logic and reporting logic. The querying logic retrieves salient characteristics associated with a plurality of hosts operating within the network and determines whether any hosts are suspicious. The profile confirmation logic, if a suspicious host is detected, establishes communications with that suspicious host to retrieve additional context information. The classification logic, based on the retrieved information, determines whether the suspicious host is malicious, prior to and without reliance on information associated with a cyber-attack being conducted by that host. The reporting logic outputs analytic results identifying at least the suspicious host is operating as a malicious host.
Owner:GOOGLE LLC

Application-level cybersecurity using multiple stages of classifiers

Various embodiments include systems and methods to implement a security platform providing application-level cyberattack detection using multiple stages of classifiers. The security platform may use requests received by a web service to determine training data to train one or more machine learning models. The training data may be determined by instrumenting an application, such as a web service, with a first stage classifier to determine security events indicative of cyberattacks. The security platform may train machine learning models using aggregations of security events over various periods of time. The machine learning models may serve as second stage classifiers for the security platform.
Owner:RAPID7 INC

Multi-robot cooperative positioning and elastic formation method based on DKCF algorithm

The invention discloses a multi-robot cooperative positioning and elastic formation control method based on a distributed Kalman consistency filtering (DKCF) algorithm. Aiming at the problems of insufficient sensor noise suppression, poor robustness under network attack and the like in the prior art, a dynamic model containing process noise and a sensor model of measurement noise are constructed, and a consistency state estimation method of weighted fusion observation data is provided. According to the method, multi-modal redundant sensor information is fused, and an improved DKCF is combined, so that cooperative state estimation between robots is realized, and the positioning precision in a noise environment is effectively improved; an elastic positioning framework under denial of service attack is established, and the robustness to network attack is enhanced while the formation precision is ensured through the joint design of distributed cooperative position estimation and a formation controller. According to the method, high positioning precision and a stable formation form can still be kept in the face of network attacks of denial of service, and the safety cooperation performance of a multi-robot system in a complex scene is remarkably improved.
Owner:SOUTHEAST UNIV

Method and apparatus for generating cyberattack sequence based on reinforcement learning

Disclosed herein is a method for generating a cyberattack sequence based on reinforcement learning. The method includes generating a cyberattack simulation environment, training a cyberattack agent model based on the cyberattack simulation environment, and generating an attack sequence using the trained cyberattack agent model.
Owner:ELECTRONICS & TELECOMM RES INST

Cyberattack detection using multiple stages of classifiers

Various embodiments include systems and methods to implement a security platform providing cyberattack detection using multiple stages of classifiers. The security platform may use a first stage of classifiers to analyze multiple requests from a client device to a service. The first stage of classifiers may determine an initial indication of whether a request is indicative of a cyberattack and provide the initial indication to a second stage of classifiers. The second stage of classifiers may, based on initial indication of a cyberattack over a period of time, determine whether a cyberattack is underway.
Owner:RAPID7 INC

Automatic incident identification, investigation, and next-step prediction

The disclosed techniques automatically identify cyber-security attacks and predict attack next steps. Descriptions of previously observed cyber-attack campaigns are decomposed into attack campaign steps. Real-time security incident signals are generated by cybersecurity software. Attack campaigns are identified by mapping attack campaign steps to security incident signals. Custom-generated telemetry queries are executed to determine if a missing attack campaign step occurred. A machine learning model generates embeddings for attack campaign steps, security incident signals, and telemetry query responses. A security incident signal or a telemetry query response matches an attack campaign step when their embeddings are within a defined distance. A security alert may be raised when most or all of the attack campaign steps of a particular attack campaign are matched. Attack campaign steps that are not matched to security incident signals or telemetry query results are predicted as attack next steps.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Security alert meta-analysis for identifying causally related evidence of cyberattacks

A security alert meta-analysis (SAMA) system is disclosed capable of identifying causally related evidence of a cyberattack in a computing environment. In embodiments, the system builds a security data graph from security alerts generated by other security monitoring services. The security data graph links related entities (e.g. users and resources) in the computing environment and the entities to their associated security alerts. Edges in the graph are filtered based on edge weights to identify sub-graphs that represent clusters of causally related evidence probative of attacks. The evidence clusters are presented to analysts to be investigated further. In embodiments, the meta-analysis process is implemented as periodic jobs executed on a cluster of worker nodes. Advantageously, the disclosed system is able to filter through large volumes of alerts to reduce false positives, and group related alerts, possibly from different monitoring services, so that they can be investigated together.
Owner:AMAZON TECH INC

Oil and gas pipe network sensor fault intelligent identification method and device and storage equipment

The invention provides an oil and gas pipe network sensor fault intelligent identification method and device and storage equipment, and the method comprises the steps: determining a safety production process data threshold interval of a target oil and gas medium based on the physical parameters of the target oil and gas medium, and obtaining the operation parameters, and determining a sudden change time point when the operation parameters are within a safety production process data threshold interval, determining an abnormal type of the sensor based on the sudden change time point, and distinguishing physical faults (such as natural aging and power depletion) of the sensor and network attacks suffered by the sensor. According to the method, whether the network attack occurs or not can be judged based on the abnormal disturbance time difference of the sensor output data after the control core analysis, the potential sensor anomaly type is identified, the method is suitable for numerous application scenes, the matching degree between the anomaly identification result and the application scenes is improved, and the user experience is improved. Therefore, the sensor network attack and the physical fault are distinguished.
Owner:CHINA UNIV OF PETROLEUM (BEIJING)

Encryption and decryption strategy driven memristor neural network multi-index state estimation method for security assurance

The invention discloses a security guarantee-oriented encryption and decryption strategy-driven memristor neural network multi-index state estimation method. The method comprises the following steps of: 1, establishing a memristor neural network dynamic model with H infinity performance constraint and hybrid attack; 2, performing state estimation on the memristor neural network dynamic model under the driving of an encryption and decryption strategy; 3, calculating an error covariance matrix upper bound and an H infinity performance constraint condition of the memristor neural network; and 4, solving a value of an estimator gain matrix, and realizing memristor neural network state estimation with hybrid network attacks. The method solves the problem that the existing state estimation method cannot process the multi-index state estimation of the memristive neural network with H infinity performance constraint and variance constraint under the driving of encryption and decryption strategies at the same time, so that the estimation accuracy is low, and under the condition that information exists under the encryption and decryption strategies and information at other moments cannot be received, the estimation accuracy is low. And the accuracy of the estimation performance is low.
Owner:HARBIN UNIV OF SCI & TECH

Methods for detecting cyber-attacks and incidents, and systems, apparatuses, and non-transitory computer-readable storage media employing same

Methods, systems, apparatuses, and non-transitory computer-readable storage media for detecting cyber-attacks and incidents are disclosed. A method for detecting network incidents comprises: receiving outputs from a plurality of artificial intelligence (AI) models analyzing a plurality of network operation streams, wherein the plurality of AI models are respectively trained to detect suspicious events corresponding to a potential type of network incident in a respective network operation stream and to output an alert when a suspicious event is detected; determining, from the outputs of the plurality of AI models, a plurality of suspicious events that are associated with an entity; calculating a probability that two or more of the plurality of suspicious events associated with the entity occurred randomly; and outputting an alert based on the probability.
Owner:ROYAL BANK OF CANADA

Micro-grid power distribution method and system based on virtual impedance control

The invention discloses a micro-grid power distribution method and system based on virtual impedance control, and belongs to the technical field of power system control, and the method comprises the following steps: constructing a micro-grid system in which multiple inverters operate in parallel, and simulating the power distribution of a synchronous generator through droop control; establishing a communication topological structure for power information exchange among the inverter nodes; collecting reactive power output by each inverter, and obtaining a virtual impedance value through reactive power deviation among the inverters in the micro-grid system; a virtual impedance controller capable of detecting and resisting network attacks is introduced, and the controller identifies abnormal node signals in real time by performing threshold judgment on the reactive power difference value and performs signal reconstruction by using information of normal nodes to obtain a virtual impedance adjustment value; the virtual impedance value is adjusted in real time according to the reactive power difference value output by each inverter, reference voltage is generated to control the state of an inverter switch, and the reactive power of the system is reasonably distributed. According to the method, network attacks can be detected and resisted in real time, and the stability of the micro-grid system is improved.
Owner:STATE GRID FUJIAN ELECTRIC POWER CO LTD +1

Detecting clean backups and snapshots for subsequent data recovery operations

Mechanisms are provided for identifying clean backups of a monitored computing system. A backup of a state of a computing system is generated. In response, these operations are performed: alert data associated with the monitored computing system is retrieved, where alert data is stored in response to patterns of data accesses indicating a possible cyber-attack on the computing system; a classification engine executes a classification operation on the alert data to determine if it indicates that the state of the monitored computing system was the target of a cyber-attack within a predetermined period of time prior to a time the backup was generated; if so, a first tag is generated for the backup indicating the backup to be corrupted; if not, a second tag for the backup is generated indicating the backup to be clean; and the first or second tag is stored in association with the backup.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Automated generation of behavioral signatures for malicious web campaigns

Techniques for automated generation of behavioral signatures for malicious web campaigns are disclosed. In some embodiments, a system / process / computer program product for automated generation of behavioral signatures for malicious web campaigns includes crawling a plurality of web sites associated with a malware campaign; determining discriminating repeating attributes (e.g., behavior related attributes, which can be determined using dynamic analysis, and static related attributes, which can be determined using static analysis) as malware campaign related footprint patterns, wherein the discriminating repeating attributes are not associated with benign web sites; and automatically generating a human-interpretable malware campaign signature based on the malware campaign related footprint patterns.
Owner:PALO ALTO NETWORKS INC

System and method for building an attack flow graph

System and method for generating an attack flow graph are disclosed. The method includes, receiving a cyber-attack report from a user device, extracting one or more attack actions from the cyber-attack report, extracting one or more attack assets from the cyber-attack report, determining one or more conditions and one or more operators associated with the one or more attack actions and the one or more attack assets. The method further includes, generating a subgraph using the one or more attack actions, the one or more attack assets, the one or more conditions and the one or more operators, generating an attack flow graph, wherein the attack flow graph is generated based on the subgraph, the cyber-attack report and an attack flow schema, and storing the attack flow graph in an attack flow knowledgebase.
Owner:ACCENTURE GLOBAL SOLUTIONS LTD

Systems and methods for anomaly detection

Disclosed herein are systems and methods for anomaly detection. A distributed physical state estimation system determines low-level state estimates covering respective sections of a cyber-physical system based on raw, high-performance measurement data. Low-level state estimates may be determined for a plurality of sections (substations) concurrently. An upper-level state estimate may be derived from the low-level state estimates. Anomalies pertaining to the system may be detected through analysis of the low-level and upper-level state estimates. The anomalies may be analyzed to determined whether the system is exhibiting behavior indicative of a fault, cyber-attack, and / or compromise.
Owner:BATTELLE ENERGY ALLIANCE LLC +2

Communications network intrusion response system training

PCT designated stageWO2025171981A1Knowledge representationMachine learningIntrusion response systemsCyber-attack
The disclosed technology relates to a computer-implemented method of training an intrusion response system, IRS. The method comprises receiving a plurality of rules for responding to cyber-attacks. The method generates additional rules by applying a data augmentation technique to the plurality of rules and provides the plurality of rules and the additional rules as training data to the IRS. Some examples of the method detect a potential threat that matches at least one of the rules in the plurality of rules and additional rules with the IRS, subsequent to training the IRS with the training data.
Owner:BRITISH TELECOM PLC

System and method for generating cyber threat intelligence

The present disclosure provides a system for generating cyber threat intelligence. The system includes a plurality of honeynets configured to emulate one or more services; a plurality of sensors, each sensor associated with a honeynet, each sensor configured to detect cyberattacks on the associated honeynet; a data collector configured to receive data relating to the cyberattacks on the plurality of honeynets; and a computing device configured to detect, from the sensors, one or more cyberattacks on the honeynets based on analysis of network traffic through the honeynets; extract, from detected cyberattacks on the honeynets, a detailed forensic data log based on analysis of content of the data packets pertaining to the cyberattacks on the honeynets; and transmit the detailed forensic data log to the data collector. The data collector stores the detailed forensic data log for further analysis in order to generate cyber threat intelligence.
Owner:WHIZHACK TECH PVT LTD

Attack path prediction method, attack path prediction device, and recording medium

An attack path prediction method includes: obtaining incident information related to a cyberattack on a monitoring target vehicle from a monitor monitoring the monitoring target vehicle; obtaining one or more items of threat information related to a past cyberattack, based on the incident information; and predicting the attack path of the cyberattack on the monitoring target vehicle, based on the one or more items of threat information. The obtaining of the threat information includes: creating a first search query for obtaining the one or more items of threat information, based on the incident information; creating a second search query for which a search condition is more relaxed than for the first search query, based on the incident information, when the number of the items of threat information is less than a predetermined number; and obtaining the one or more items of threat information, using the second search query.
Owner:PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD

Cyber-attack detection in a logging system

Systems, methods, and computer readable storage media described herein for detecting cyber-attacks in a logging system. For instance, operation information for an executing operation is received. A log of the executing operation is generated based on the operation information. During generation of the log, a triggering event is detected based on the executing operation. The triggering event corresponds to a potential cyber-attack. A protective action is performed to mitigate the potential cyber-attack. In a further aspect, the executing operation comprises a plurality of sub-operations. A sub-operation subset of the sub-operations is determined to satisfy a risk logging criterion. The determined sub-operation subset is included in the log without including a first sub-operation of the sub-operations that fails to satisfy the risk logging criterion. In another aspect, a watermark is inserted into a downloaded copy of data, the watermark detectable to determine an original source of exfiltrated data.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Dynamic Cyberattack Mission Planning and Analysis

Cybersecurity mission planning and analysis uses artificial intelligence systems to make red and blue team exercises more comprehensive and effective by supplementing individual expertise, reducing reliance on intuition, and eliminating gaps in knowledge. In an embodiment, a platform for cyberattack missions planning and analysis by red and blue teams is coordinated by a control center. An incident generator generates cyberattack scenarios and events using data from external databases and an internal attack knowledge manager having a knowledge graph of data about the network under attack in conjunction with one or more machine learning algorithms configured to identify potential network vulnerabilities. Red are guided by a machine learning algorithm configured to provide suggestions as to potential successful attack paths. Blue teams are guided by a machine learning algorithm configured to provide suggestions as to potential successful attack paths.
Owner:QPX LLC

DDoS attack prediction method and system based on chaotic mapping echo state network

The invention belongs to the technical field of DDoS attack prediction, and provides a DDoS attack prediction method and system based on a chaotic mapping echo state network. The method comprises the following steps: S10, determining an optimization objective function of a harmony search algorithm as a variance value predicted by an echo state network, and initializing related parameters of the harmony search algorithm; s20, generating an initial weight matrix by using the Logistic-tent chaotic mapping; s30, updating the harmony memory bank, selecting a weight matrix with the optimal fitness from the updated harmony memory bank, and constructing and training an ESN prediction model; and S40, processing the network flow sequence data detected in real time by using the trained ESN prediction model so as to perform DDoS attack prediction. According to the method, the echo state network DDoS attack prediction model based on chaotic mapping is adopted, the time efficiency is improved, and the DDoS attack situation can be effectively predicted in real time.
Owner:HAOHAN DATA

Power distribution network toughness evaluation method based on dynamic disturbance evaluation

The invention discloses a power distribution network toughness evaluation method based on dynamic disturbance evaluation, and relates to the technical field of power systems and automation, and the method comprises the following steps: constructing a disturbance model to simulate the response process of a power distribution network when the power distribution network encounters an extreme disaster or fault, the disturbance model comprises various disturbance scenes such as natural disasters, power equipment faults and network attacks. By introducing the distributed power supply evaluation method based on the dynamic response model, the accuracy of power distribution network toughness evaluation is improved, the response characteristics of photovoltaic power generation and energy storage equipment in an extreme environment can be simulated in real time, and it is ensured that the evaluation result is more accurate. Through a flexible resource scheduling and recovery strategy optimization technology and based on a multi-objective particle swarm optimization algorithm, a post-disaster recovery process is optimized, key loads are scheduled preferentially, recovery time is reduced, power grid recovery efficiency is improved, and emergency response capability and recovery capability of a power distribution network in the face of extreme disasters are enhanced.
Owner:WUXI XINENG REAL ESTATE MANAGEMENT CO LTD

Mitigating malicious network traffic

Disclosed herein are system, method, and computer program product embodiments for mitigating malicious network traffic. A computing device (e.g., a network management device, a control device, etc.) may receive indications of data / information communicated by one or more devices within a network and cause the one or more devices to implement measures to block malicious traffic resulting from multi-vector cyberattacks.
Owner:VERIZON PATENT & LICENSING INC

System, device, and method of protecting users and online accounts against attacks that utilize SIM swap scams

Systems, and methods of protecting users against cyber-attacks that utilize SIM Swap or Email Hijacking. A method includes: (a) detecting that a user is requested to input his genuine email address into an email address field of an account profile page or an account settings page of a computerized service; (b) inserting, into that email address field of that page, a replacement email address that replaces a genuine email address of the genuine user at that computerized service; and later, (c) automatically monitoring and handling, continuously at a remote server or a remote service, incoming email messages that arrive to that replacement email address of that genuine user and that request the genuine user to perform an elevated-security operation or to reset his credentials for accessing that computerized service.
Owner:IRONVEST INC

Information network attack behavior detection method and system

The invention relates to the technical field of information network attack behavior detection, and provides an information network attack behavior detection method and system, and the method comprises the steps: presetting a request permission value for a switch in a network; receiving a control request; after the control request is received, processing the control request based on a condition that a request permission value is greater than a preset threshold value, deducting the request permission value of the switch, and setting a confirmation condition based on a data stream corresponding to the control request; when the confirmation condition is satisfied within a preset time limit, receiving a corresponding confirmation voucher, and increasing a request permission value based on the confirmation voucher; judging whether the switch initiates an attack behavior based on a preset change mode; and when the actual change mode of the switch satisfies the preset change mode, determining that the switch initiates an attack behavior. The method provided by the invention has the effect of detecting the attack behavior that controller resources are used up by using a control plane false request and data plane traffic abnormality is not generated.
Owner:HUADIAN LONGKOU POWER GENERATION CO LTD