Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

205 results about "Cyber-attack" patented technology

In computers and computer networks an attack is any attempt to expose, alter, disable, destroy, steal or gain unauthorized access to or make unauthorized use of an asset. A cyberattack is any type of offensive maneuver that targets computer information systems, infrastructures, computer networks, or personal computer devices. An attacker is a person or process that attempts to access data, functions or other restricted areas of the system without authorization, potentially with malicious intent. Depending on context, cyberattacks can be part of cyberwarfare or cyberterrorism. A cyberattack can be employed by sovereign states, individuals, groups, society or organizations, and it may originate from an anonymous source.

System and methods for unforgeable telemetry in the presence of cyberattacks on a computer platform

System and methods are disclosed for providing unforgeable telemetry on computer platforms. Mathematical modeling and theorem proving are utilized to guarantee the integrity of telemetry probe execution flow and trigger, thereby preventing circumvention and tampering of logged probe data. In contrast to current state-of-the-art solutions that rely implicitly on the operating environment, this approach provides a sound and complete assurance of telemetry output. The system enables organizations to map unforgeable telemetry probe data to industry and government cybersecurity regulatory controls, ensuring compliance therewith. This invention addresses the shortcomings of existing solutions, including their vulnerability to sophisticated attacks, operational complexity, and inability to provide unforgeable telemetry data, thereby providing a reliable and accurate monitoring output in the presence of cyberattacks on computer platforms.
Owner:UBERSPARK INC

Automatic incident identification, investigation, and next-step prediction

The disclosed techniques automatically identify cyber-security attacks and predict attack next steps. Descriptions of previously observed cyber-attack campaigns are decomposed into attack campaign steps. Real-time security incident signals are generated by cybersecurity software. Attack campaigns are identified by mapping attack campaign steps to security incident signals. Custom-generated telemetry queries are executed to determine if a missing attack campaign step occurred. A machine learning model generates embeddings for attack campaign steps, security incident signals, and telemetry query responses. A security incident signal or a telemetry query response matches an attack campaign step when their embeddings are within a defined distance. A security alert may be raised when most or all of the attack campaign steps of a particular attack campaign are matched. Attack campaign steps that are not matched to security incident signals or telemetry query results are predicted as attack next steps.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Security alert meta-analysis for identifying causally related evidence of cyberattacks

A security alert meta-analysis (SAMA) system is disclosed capable of identifying causally related evidence of a cyberattack in a computing environment. In embodiments, the system builds a security data graph from security alerts generated by other security monitoring services. The security data graph links related entities (e.g. users and resources) in the computing environment and the entities to their associated security alerts. Edges in the graph are filtered based on edge weights to identify sub-graphs that represent clusters of causally related evidence probative of attacks. The evidence clusters are presented to analysts to be investigated further. In embodiments, the meta-analysis process is implemented as periodic jobs executed on a cluster of worker nodes. Advantageously, the disclosed system is able to filter through large volumes of alerts to reduce false positives, and group related alerts, possibly from different monitoring services, so that they can be investigated together.
Owner:AMAZON TECH INC

Micro-grid power distribution method and system based on virtual impedance control

The invention discloses a micro-grid power distribution method and system based on virtual impedance control, and belongs to the technical field of power system control, and the method comprises the following steps: constructing a micro-grid system in which multiple inverters operate in parallel, and simulating the power distribution of a synchronous generator through droop control; establishing a communication topological structure for power information exchange among the inverter nodes; collecting reactive power output by each inverter, and obtaining a virtual impedance value through reactive power deviation among the inverters in the micro-grid system; a virtual impedance controller capable of detecting and resisting network attacks is introduced, and the controller identifies abnormal node signals in real time by performing threshold judgment on the reactive power difference value and performs signal reconstruction by using information of normal nodes to obtain a virtual impedance adjustment value; the virtual impedance value is adjusted in real time according to the reactive power difference value output by each inverter, reference voltage is generated to control the state of an inverter switch, and the reactive power of the system is reasonably distributed. According to the method, network attacks can be detected and resisted in real time, and the stability of the micro-grid system is improved.
Owner:STATE GRID FUJIAN ELECTRIC POWER CO LTD +1

Detecting clean backups and snapshots for subsequent data recovery operations

Mechanisms are provided for identifying clean backups of a monitored computing system. A backup of a state of a computing system is generated. In response, these operations are performed: alert data associated with the monitored computing system is retrieved, where alert data is stored in response to patterns of data accesses indicating a possible cyber-attack on the computing system; a classification engine executes a classification operation on the alert data to determine if it indicates that the state of the monitored computing system was the target of a cyber-attack within a predetermined period of time prior to a time the backup was generated; if so, a first tag is generated for the backup indicating the backup to be corrupted; if not, a second tag for the backup is generated indicating the backup to be clean; and the first or second tag is stored in association with the backup.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Cyber-attack detection in a logging system

Systems, methods, and computer readable storage media described herein for detecting cyber-attacks in a logging system. For instance, operation information for an executing operation is received. A log of the executing operation is generated based on the operation information. During generation of the log, a triggering event is detected based on the executing operation. The triggering event corresponds to a potential cyber-attack. A protective action is performed to mitigate the potential cyber-attack. In a further aspect, the executing operation comprises a plurality of sub-operations. A sub-operation subset of the sub-operations is determined to satisfy a risk logging criterion. The determined sub-operation subset is included in the log without including a first sub-operation of the sub-operations that fails to satisfy the risk logging criterion. In another aspect, a watermark is inserted into a downloaded copy of data, the watermark detectable to determine an original source of exfiltrated data.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Dynamic Cyberattack Mission Planning and Analysis

Cybersecurity mission planning and analysis uses artificial intelligence systems to make red and blue team exercises more comprehensive and effective by supplementing individual expertise, reducing reliance on intuition, and eliminating gaps in knowledge. In an embodiment, a platform for cyberattack missions planning and analysis by red and blue teams is coordinated by a control center. An incident generator generates cyberattack scenarios and events using data from external databases and an internal attack knowledge manager having a knowledge graph of data about the network under attack in conjunction with one or more machine learning algorithms configured to identify potential network vulnerabilities. Red are guided by a machine learning algorithm configured to provide suggestions as to potential successful attack paths. Blue teams are guided by a machine learning algorithm configured to provide suggestions as to potential successful attack paths.
Owner:QPX LLC

Security measure support device and security measure support method

PCT designated stageWO2026150788A1Cyber-attackAttack
A security measure support device (100) comprises an input unit (181) that inputs security measure information that indicates security measures against cyber-attacks on systems that include a plurality of devices, a storage unit (120) that stores attack scenarios (see attack scenario database (140)) that indicate attack sequences for the cyber-attacks, an update unit (113) that, on the basis of an updated system that is a system that includes devices to which security measures have been applied in accordance with the security measure information, identifies devices to which security measures have been applied that are included in the attack scenarios stored at the storage unit (120), substitutes the devices to which security measures have been applied for the devices of other systems to update the attack scenarios and create updated attack scenarios, and an output unit (182) that outputs the updated attack scenarios.
Owner:HITACHI LTD

system

The system according to this embodiment aims to detect cyberattacks early and take appropriate countermeasures. [Solution] The system according to the embodiment comprises a monitoring unit, a detection unit, a countermeasure unit, and an analysis unit. The monitoring unit monitors network traffic. The detection unit detects unauthorized access and system intrusion from the traffic monitored by the monitoring unit. The countermeasure unit takes appropriate countermeasures against cyberattacks detected by the detection unit. The analysis unit analyzes past attack methods and predicts future attacks.
Owner:SOFTBANK GROUP CORP

Systems, methods, and devices for preventing credential passing attacks

PendingUS20260205484A1TicketData pack
A system and method for the detection and mitigation of Kerberos golden ticket, silver ticket, and related identity-based cyberattacks by passively monitoring and analyzing Kerberos and authentication operations within the network. The system and method provide real-time detections of identity attacks using time-series data and data pipelines, and by transforming the stateless Kerberos protocol into stateful protocol. A packet capturing agent is deployed on the network where captured time-series Kerberos and related event and log information is processed in distributed computational graph (DCG) stages where declarative rules determine if an attack is being carried out and what type of attack it is.
Owner:SENTINELONE INC

Networking attack detection system and method for intelligent networked automobile based on data and knowledge fusion

The invention discloses a network attack detection system and a network attack detection method for a digital-aware-fused intelligent connected automobile, and relates to an intelligent vehicle technology. The system comprises a vehicle end data generation module, a road side unit data acquisition module, a cloud end attack detection module and a detection result display module. The method comprises the two steps of online real-time detection and offline training, during offline training, a training database containing multiple attack types is firstly constructed, then a data driving model is constructed based on a hierarchical vector Transformer model, and finally constraints in vehicles, between vehicles and between vehicles and lanes are fused, so that the data driving model is constructed. Weak, medium and strong constraints are divided according to the relevance between the constraints and the attacks, and a differential fusion scheme is designed. According to the method, deep fusion of data driving and knowledge guiding is realized, spatio-temporal features are extracted in a layered manner, high-precision map information is fused, attack detection precision and interpretability are improved, various network attacks can be effectively detected, and safe and efficient operation of an intelligent networked automobile is guaranteed.
Owner:XIAMEN UNIV

Adversarial training for malicious protocol data unit detection with field value perturbations

A modular adversarial training data generator (“generator”) generates adversarial training data for a machine learning (ML) model to detect malicious protocol data units (PDUs). The adversarial training data mimics high volume cyberattacks by perturbing PDUs to bypass malicious detection systems. For Hypertext Transfer Protocol (HTTP) PDUs, the generator rearranged, replaces, and grid searches values of HTTP header fields to generate the adversarial training data. The generator further biases grid search based on metrics for values of HTTP header fields that quantify impact of replacing the values on malicious verdicts by ML models trained on the adversarial training data.
Owner:PALO ALTO NETWORKS INC

Unmanned ship safe dynamic positioning method based on switching fuzzy wavelet network

The invention discloses an unmanned ship safe dynamic positioning method based on a switching fuzzy wavelet network, and the method comprises the steps: building and constructing a switching LPV networked unmanned ship system according to the number of shipborne equipment, designing an event triggering mechanism, and constructing an attack detection observer and a detector in a shore-based system for possible spoofing attacks in communication; designing a safety controller in combination with a switching fuzzy wavelet network and an attack detector, introducing a shore-ship event triggering mechanism, further designing a special attack detector and a control input compensator, and generating a safe event triggering control input; a closed-loop system is constructed by integrating an attack detection observer, an unmanned ship system and control input, and a stable condition of the system is given through theoretical analysis, so that safe dynamic positioning of the unmanned ship under potential network attacks is realized; according to the method, the estimation accuracy can be improved, the safety is improved, and safe dynamic positioning of the networked unmanned ship is realized.
Owner:DALIAN MARITIME UNIVERSITY

Real-time cybersecurity strategic prioritization systems and methods

The system inputs at least one security log file from a first data domain into a first machine learning (ML) model. The system compute, using an output from the first ML model, a weighted sentiment value for one or more of the multiple cybersecurity events. The system detects, using a second ML model, an anomaly in a first cybersecurity event of the multiple cybersecurity events. The system correlates, using a third ML model, the anomaly in the first cybersecurity event to a different anomaly in a second cybersecurity event associated with a second data domain. The system determines, using a fourth machine learning model, a cybersecurity action to minimize a cyberattack. The system determines, using the fourth model, a predicted impact to the telecommunication network associated. The system generates a prioritization ranking of every cybersecurity action and executes each cybersecurity action based on the prioritization ranking.
Owner:T MOBILE US INC

Systems and methods for formal verification of computer platforms

Systems and methods for mathematical modeling of the hardware and software stack of commodity computer platforms are provided, enabling provable guarantees on memory, device, and program execution. This approach addresses the technical problem of reliance on system agents that rely on implicit trust in the operating environment, which can be exploited by sophisticated attackers using complex threats such as memory access exploits and code / data integrity exploits. The solution provides a proactive, mathematically-backed security solution that eliminates entire classes of cyberattacks by design, ensuring realizable guarantees on commodity computer platforms running hardware and software stack elements at the lowest operating level. This approach has significant advantages over current reactive cybersecurity methods, including reduced complexity and overhead, and increased confidence in the integrity of the system. The solution's main uses include providing mathematically-backed security and availability guarantees for critical infrastructure, financial institutions, and other organizations vulnerable to cyberattacks.
Owner:UBERSPARK INC

Cyber-attack detection and prevention system

The present invention relates to a system for protecting against cyber-attacks on a host machine, comprising: (a) at least one MTS, connected to the bus lines, of said memory device(s), of said host, for sampling the electrical signals, intended for said memory device(s); (b) at least one MRMU, connected to said MTS(s), for receiving said sampled signals from said MTS(s) and translating said sampled signals for reconstructing the physical and virtual memory content of said host, into at least one MLM of said host machine; (c) a memory, connected to said MRMU, for storing said at least one MLM; and (d) an IPU, connected to said MRMU(s), and connected to said memory, for detecting, identifying, and analyzing at least one EOI within the reconstructed host memory content, on said memory, and for classifying said at least one EOI as legitimate or malicious.
Owner:YIFRACH AMICHAI CHAIM +2

Detection of cyber attacks driven by compromised large language model applications

A method includes receiving, at a large language model, a prompt injection cyberattack. The method includes executing the large language model. The large language model takes the prompt injection cyberattack and generates a first output. The method includes receiving, by a guardian controller, the first output. The guardian controller includes a classification machine learning model and a security application. The method includes determining a probability that the first output is poisoned by the prompt injection cyberattack. Determining the probability includes providing the first output to the classification machine learning model and executing the classification machine learning model to generate the probability. The method includes determining whether the probability satisfies a threshold. The method includes enforcing, by the security application and responsive to the probability satisfying the threshold, a security scheme on use of the first output by a control application. Enforcing the security scheme mitigates the prompt injection cyberattack.
Owner:INTUIT INC

Systems and methods for a secure keyless system

Methods and systems are provided for securing vehicle access from cyberattacks via a keyless system. In an embodiment, a method for a vehicular keyless entry system is provided, comprising processing, at a vehicle, a keyless-entry transmission carrying an identification (ID) code portion; decrypting the ID code portion of the keyless-entry transmission using a private key of the vehicle; detecting whether the decrypted ID code portion matches one of a plurality of predetermined function codes of the vehicle; and executing a functionality of the vehicle corresponding with a function code of the vehicle that matches the decrypted ID code portion.
Owner:HARMAN INT IND INC

Long-term cyber attack variant prediction

A computer-implemented method of generating training data for a cyber-attack detection machine learning, 'ML', model, the computer-implemented method comprising: obtaining a network metadata feature set characteristic of each of one or more known categories of cyber-attack; and generating predicted network metadata representing a plurality of predicted variants of each of the one or more known categories of cyber-attack, based on the respective network metadata feature set.
Owner:BRITISH TELECOM PLC

Detection of cyber attacks driven by compromised large language model applications

A method including receiving, at a large language model, a prompt injection cyberattack. The method also includes executing the large language model. The large language model takes, as input, the prompt injection cyberattack and generates a first output. The method also includes receiving, by a guardian controller, the first output of the large language model. The guardian controller includes a machine learning model and a security application. The method also includes determining a probability that the first output of the large language model is poisoned by the prompt injection cyberattack. The method also includes determining whether the probability satisfies a threshold. The method also includes enforcing, by the guardian controller and responsive to the probability satisfying the threshold, a security scheme on use of the first output of the large language model by a control application. Enforcing the security scheme mitigates the prompt injection cyberattack.
Owner:INTUIT INC

Systems and methods for high speed and secure provisioning and management of bare metal resources

Bare metal resources can be securely provisioned to computer systems using a switch that toggles connections between (1) a storage target such as a disk and a remote source of data and (2) the storage target and the bare metal resource. In this fashion, the toggled connections provide isolations of the bare metal resource that make it less susceptible to cyberattack. While the remote source-storage target connection is enabled, data such as an operating system and / or boot information for the bare metal resource can be transferred from the remote source to the storage target. While the bare metal resource-storage target connection is enabled, the remote source-storage target connection is disabled and the operating system and / or boot information can be transferred from the storage target to the bare metal resource. The bare metal resource can then boot based on this operating system and / or boot information.
Owner:NET THUNDER LLC

Developing forensic projections for data volumes using snapshots

The disclosure describes a system for developing a forensic projection for data lost in a cyberattack. After identifying a cyberattack causing a loss of data in the data volume, the system identifies a snapshot of the portion of the data volume affected by the cyberattack. The system estimates, based on the snapshot, an amount of lost data caused by the cyberattack. The system then determines based at least on the amount of lost data, a data loss metric.
Owner:NETAPP INC

Power supply and demand control apparatus, power supply and demand control method, and program

Provided is a power supply demand control device, including: a reception unit configured to collect electric vehicle information that is information on an electric vehicle and also collect power information that is information on power of a facility; a filter unit configured to determine a specific electric vehicle that is suspected of being cyberattacked based on the electric vehicle information; and a dispatch planning unit configured to determine an electric vehicle to be sent to a facility where power shortage is forecasted based on the power information from one or more electric vehicles selected among a plurality of electric vehicles for which the electric vehicle information has been collected, excluding the specific electric vehicle.
Owner:NIPPON TELEGRAPH & TELEPHONE CORP

Digital asset guard service provision system

A system is provided robustly protects important information from high-level cyberattacks and physical destruction, including cryptographic analysis using quantum computers and electromagnetic pulse attacks, while enabling restoration without theft by a third party. The system encrypts and partitions file data using predetermined encryption and division algorithms based on a customer specified parameter, allots each file data to multiple sets of distributed file management groups comprising node groups at multiple bases in different regions of the world, distributes and records the file data to be saved in the nodes located at each base that belong to corresponding distributed file management groups, generates and encrypts index information of each distributed and recorded corresponding file data, and records the index information in node groups of a specified base in the consortium chain.
Owner:INTERTRADE +2

Cyber resilient trade-off evaluation systems for operational technology environments, including related methods and computer readable media

A system comprises one or more networks including a digital twin and one or more cyber system components. The digital twin is configured to emulate at least a portion of a physical system of an operational technology (OT) system. One or more processors of the system are configured to select a mitigative response measure to enable in the one or more networks for execution in response to a simulated cyber attack; determine a physical system reaction and a cyber system reaction responsive to the simulated cyber attack and the mitigative response measure; and determine a resilience level of an OT system enabled with the mitigative response measure responsive to the physical system reaction and the cyber system reaction.
Owner:UNIVERSITY OF IDAHO +1

Vehicle safety analysis system, vehicle safety analysis methods and procedures

The vehicle safety analysis system of the present invention includes: an acquisition unit that acquires sensor log data related to in-vehicle devices mounted on a vehicle; a determination unit that determines whether the sensor log data acquired by the acquisition unit is sensor log data generated based on a phenomenon not caused by a cyber attack, based on status information indicating the status of the vehicle; an analysis unit that excludes the sensor log data generated based on a phenomenon not caused by the cyber attack and analyzes the sensor log data acquired by the acquisition unit; and an output unit that outputs the analysis result obtained by the analysis unit.
Owner:NTT SECURITY (JAPAN) KK

Adaptive AI Cybersecurity System for Threat Identification, Prevention, and Device Monitoring

The present invention relates to an AI-driven cybersecurity system that provides adaptive protection by identifying, mitigating, and preventing cyber threats in real-time. The system leverages advanced machine learning algorithms to detect anomalies in network traffic, enabling the identification of potential threats, which are then neutralized through automatic adjustments to firewall rules and network configurations. The system includes a tracing module capable of locating the source of cyberattacks by analyzing IP addresses and other network metadata, allowing for comprehensive incident reporting. Additionally, the invention logs and monitors all devices connecting to the network, both via Wi-Fi and hardline access, ensuring security compliance and detecting unauthorized activity. The system's adaptive approach ensures continuous protection by automatically updating security measures and reporting detailed findings to security personnel for future prevention.
Owner:DAVIS ALEXANDER