Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

416 results about "Cyber threat" patented technology

Ai-based cybersecurity system and method thereof

An AI-based Cybersecurity System and Method enable real-time detection, analysis, and mitigation of cyber threats within computing networks using adaptive artificial intelligence. The system continuously monitors network traffic, extracts behavioral and contextual attributes, and applies deep learning-based inference to identify anomalous activities indicating security breaches. The method integrates several computational units, including a network monitoring unit, feature extraction unit, artificial intelligence processor, contextual reasoning processor, and decision synthesis unit, to compute a composite risk index quantifying threat likelihood and severity. A classification processor categorizes detected threats into types such as ransomware, phishing, or unauthorized access, while a mitigation control processor initiates automated response actions to isolate compromised nodes and restore network integrity. An adaptive learning processor updates AI models using feedback from confirmed incidents. This provides a scalable, self-evolving cybersecurity framework that minimizes human intervention and enhances resilience against dynamic and zero-day threats.
Owner:PELL REDDY RAJENDER REDDY

Automated Mapping of Raw Data into a Data Fabric

The disclosed embodiments provide systems and methods for automated mapping of raw data into a data fabric. An innovative approach leveraging Artificial Intelligence (AI)-powered tools and a data fabric to automate the ingestion, transformation, and integration of raw data into a unified model is introduced. By automating the data mapping process, organizations can reduce reliance on manual methods and accelerate their ability to utilize robust insights for exposure management and attack surface reduction. The disclosed solution provides a scalable architecture for unifying cybersecurity signals across cloud and hybrid environments, enabling real-time decision-making and improved organizational resilience against cyber threats
Owner:AVALOR TECH LTD

Method and system for safely sharing traffic edge computing data

The invention relates to the technical field of traffic data processing, and discloses a traffic edge computing data security sharing method and system, and the method comprises the steps: collecting traffic edge computing network multi-source heterogeneous data, and carrying out the classification standardization processing to generate a structured data set; designing a dynamic data sharing security protocol based on a multi-party security computing protocol and a homomorphic encryption algorithm; verifying the authority of a requester in a multi-level manner by using an attribute-based access control model and a zero-knowledge proof mechanism, and generating a dynamic access token; storing data by adopting a fragmentation storage and redundancy encryption strategy, and recording storage information through a hash chain; and dynamically adjusting the encryption strength and the sharing strategy according to the network threat level and the data sensitivity. The method effectively guarantees safe sharing of traffic data, accurately controls access authority, improves storage and sharing efficiency, adapts to complex network environment changes, and provides powerful support for development of an intelligent traffic system.
Owner:ZHENGZHOU UNIV +1

Lightweight AI security policy adaptive deployment method for edge device

The invention relates to the technical field of edge device security policy deployment, in particular to an edge device-oriented lightweight AI security policy adaptive deployment method. The method comprises the following steps: collecting operation state information of edge equipment, and constructing a current multi-dimensional environment vector and a sliding window feature vector; constructing a strategy candidate library, constructing a strategy adaptability scoring function based on the current multi-dimensional environment vector and a real-time perceived network threat event, and scoring and sorting all candidate strategy items to obtain a strategy execution candidate set; and performing scheduling optimization on the strategy execution candidate set by adopting a multi-objective optimization algorithm, and selecting a strategy combination with the highest deployment score as a deployment result. According to the method, a multi-dimensional strategy adaptability scoring function is constructed, candidate strategy items are screened according to current network threat events and system resource conditions, a strategy screening mechanism from fixed template type configuration to resource awareness and attack scene linkage is converted, and the pertinence and accuracy of strategy deployment are improved.
Owner:BEIJING XINJIE TECHNOLOGY CO LTD

Network threat detection method and device, equipment and storage medium

The invention discloses a network threat detection method, device and equipment and a storage medium, and relates to the technical field of network security, and the method comprises the steps: executing a preset data collection operation to capture initial multi-dimensional data, and carrying out the preset data processing operation on the initial multi-dimensional data to obtain processed multi-dimensional data; executing a preset entity extraction operation on the processed multi-dimensional data to obtain a target entity, storing the target entity in a preset database, and inputting the target entity into a preset long-short-term memory network model to obtain attack time sequence characteristics; inputting the attack time sequence features into a target graph neural network model to construct a target knowledge graph, and determining a cross-device abnormal behavior chain based on the target knowledge graph; and determining an attack chain integrity coefficient according to the cross-device abnormal behavior chain, and determining a network threat event and a target risk level by using the CVSS vulnerability score, the space-time correction factor and the attack chain integrity coefficient to complete network threat detection. The problems of incomplete single-dimensional data coverage, high false alarm rate and the like can be solved.
Owner:INSPUR YUNZHOU (SHANDONG) IND INTERNET CO LTD

A system for securing cloud-based large language models through cyber threat defense and compliance monitoring

A system (100) for securing cloud-based large language models through cyber threat defense and compliance monitoring, comprising: (a) an access control and authentication module configured to authenticate users and applications using role-based access control (RBAC) and multi-factor authentication (MFA); (b) a data protection and encryption module configured to encrypt data in transit and at rest and to anonymize sensitive input / output data using cryptographic techniques; (c) a threat detection and behavior monitoring module employing machine learning algorithms to identify anomalies and detect potential cyber threats in real time;(d) a regulatory compliance monitoring module configured to continuously assess system operations against applicable regulatory frameworks and generate alerts in the event of deviations from the regulations; (e) an incident response and mitigation module configured to automatically execute predefined response actions upon detection of threats or regulatory violations; (f) a logging, auditing, and forensic analysis module configured to securely log system activities, interactions, and threat events with cryptographic integrity protection; and (g) a governance and policy management module configured to define, update, and enforce organizational AI usage and compliance policies via the cloud-based LLM infrastructure.
Owner:ULAGANATHAN ILAKIYA

Computer network security threat real-time monitoring method and system

The invention discloses a computer network security threat real-time monitoring method and system, and relates to the technical field of network security, and the method comprises the steps: collecting and preprocessing multi-source network data, organizing the multi-source network data into a behavior sequence according to a time sequence, and forming time sequence behavior data for analysis; constructing an attack atlas based on the preprocessed multi-source network data, and in the atlas construction process, forming dynamic representation of the attack atlas in combination with time attributes of behavior events and inter-entity contexts; time sequence behavior data are input into an RCLNet architecture for analysis, the RCLNet extracts spatial features through CNN, the LSTM captures time features, key behavior features are concerned by using an adaptive attention mechanism, and a high-dimensional behavior embedding vector is generated. High-precision and real-time detection and response to network threats are realized, and the intelligence and actual combat adaptability of the system are greatly improved.
Owner:HENAN UNIV OF ANIMAL HUSBANDRY & ECONOMY

Techniques for providing artificial intelligence mediated curation of access and content within a cyber threat intelligence platform

Techniques are described herein for providing artificial intelligence mediated curation of access and content within a cyber threat intelligence platform. An example system includes: one or more memories, and one or more processors. The example system may receive, from a node, an input indicating a cyber threat type; identify, by a trained AI model, cyber threat intelligence content objects, each of the objects being (a) contributed by one or more nodes having access to the distributed ledger or (b) generated by the trained AI model; evaluate, by the trained AI model, each object to: determine relevance values corresponding to each of object, and generate (i) a curated set of cyber threat intelligence content objects based on the relevance values and (ii) a recommended cyber threat practice; and transmit the recommended cyber threat practice and an indication of the curated set of cyber threat intelligence content objects to the node.
Owner:TEACHERS INSURANCE & ANNUITY ASSOC OF AMERICA

Method and system for automatically executing network security policy based on artificial intelligence large model

The invention provides a network security policy automatic execution method and system based on an artificial intelligence large model, and relates to the technical field of network security, and the method comprises the steps: firstly obtaining a network threat chain data set comprising a threat initiating node, an intermediate propagation node, a target attacked node and propagation path description; calling a pre-trained threat chain analysis large model to carry out hierarchical disassembly and variation trend prediction, outputting a threat chain disassembly map, then extracting a matching strategy gene segment from a preset security strategy gene pool, generating candidate security strategies through model gene recombination and cross-strategy collaborative adaptation, and carrying out threat chain analysis on the candidate security strategies; inputting the candidate strategies, the current network topology and the equipment resource load data into a strategy execution deduction system, outputting an executable security strategy set adaptive to the current network state, finally issuing the executable security strategy set to network security equipment, and collecting execution feedback data for updating the threat chain analysis large model. And automatic, efficient and accurate generation and execution of the network security policy are realized.
Owner:XINYUAN NETWORK TECH CO LTD

Network security decision-making method and device based on large language model

The invention provides a network security decision-making method and device based on a large language model. The method comprises the following steps: collecting network state data and converting the network state data into natural language description; determining a semantic feature vector corresponding to the natural language description, and retrieving target threat knowledge matched with the semantic feature vector in a knowledge base storing various basic network threat knowledge; generating an analysis prompt text in combination with the target threat knowledge and the natural language description, inputting the analysis prompt text into a large language model, sequentially executing network threat analysis steps indicated in a preset thinking chain according to the analysis prompt text, and determining a network anomaly attribution and a corresponding protection strategy; and issuing the protection strategy to each distributed execution unit deployed in the target network environment, and converting the protection strategy into an equipment configuration command and executing the equipment configuration command. A closed-loop intelligent defense process from information perception to semantic understanding to collaborative response can be realized, and the real-time performance, the accuracy and the expandability of a security decision are improved.
Owner:CHINA INFORMATION SAFETY RES INST CO LTD +1

Network threat knowledge automatic extraction method, electronic equipment and storage medium

The invention discloses a network threat knowledge automatic extraction method, electronic equipment and a storage medium, and the method comprises the following steps executed by a computer hardware system: collecting threat intelligence data related to an APT organization from a multi-source network security text, and processing the threat intelligence data to generate a standardized corpus; using the pre-training sentence vector model to generate semantic embedding for a corpus input text and a manual annotation example library text, and retrieving similar examples to construct an ICL prompt template; inputting a large language model subjected to LoRA fine tuning, and extracting structured triples of multiple types of entities and semantic relationships; generating standardized entity nodes and updated relation information by adopting semantic aggregation; and constructing an APT organization network threat intelligence knowledge graph and outputting a structured file. The method provides key technical support for APT attack tracing, threat situation awareness and automatic security policy generation.
Owner:GUIZHOU UNIV

Advanced Cybersecurity System for Real-Time Phishing Detection, Account Takeover Fraud Prevention, and Software Repository Optimization Using Machine Learning Techniques

Systems and processes are disclosed for enhancing cybersecurity and optimizing software repositories through integration of web crawling, web scraping, feature engineering, and advanced machine learning algorithms to detect phishing attempts, prevent account takeover fraud, and identify unused code in repositories. The system collects and refines data from various sources, including transaction logs, customer databases, device details, external data sources, and historical fraud data, to build comprehensive datasets. Feature engineering creates new, meaningful features from the refined data, which are used to train and evaluate machine learning models. The best-performing models are deployed in production to monitor incoming communications and transactions in real-time, flagging suspicious activities and optimizing codebases. This processing ensures timely detection and prevention of security threats while maintaining efficient software development processes. Robust protection is provided against evolving cyber threats and enhances software performance and security through continuous learning and adaptation.
Owner:BANK OF AMERICA CORP

Multi-level power network threat collaborative identification method and system

The invention relates to the technical field of power system network security, in particular to a multi-level power network threat collaborative identification method and system, and the method comprises the steps: obtaining an attack behavior data set according to multi-source attack data collected by transformer substations of different voltage levels in a multi-level power network, generating an attack semantic feature set based on the attack behavior data set; analyzing the real-time threat intelligence data based on the attack semantic feature set, and extracting cross-site time sequence mode features; obtaining a coordination action event sequence according to the cross-site time sequence mode characteristics; analyzing a threat propagation path of the attack load among different substations according to the coordination action event sequence to obtain a cross-site threat association feature map; and obtaining a threat association identification result according to the cross-site threat association feature map. According to the method, the attack load characteristics of the multi-level power network and cross-site time sequence cooperative behavior analysis are fused, so that the cross-site cooperative attack behavior is efficiently identified, and the network security protection capability of the power system is improved.
Owner:STATE GRID ZHEJIANG ELECTRIC POWER CO LTD HANGZHOU POWER SUPPLY CO

Security defense strategy method and system based on AI Agent dynamic optimization

The invention provides a method and a system for dynamically optimizing a security defense strategy based on an AI Agent, and aims to solve the problems that the traditional network security defense strategy is static and cannot adapt to a dynamic network environment and novel network threats, and the processing efficiency of massive security data is low and the response is not timely. The method comprises the following steps: firstly, realizing whole network node data acquisition through a distributed AI Agent, performing accurate identification in combination with a multi-dimensional threat perception and fusion detection mechanism, and establishing a threat parameter quantitative evaluation model; secondly, the AI Agent generates a dynamic defense strategy according to the analysis result of the intelligent threat detection and the real-time state of the network in combination with threat features and risk assessment; and finally, according to the dynamic defense response result, realizing attack path tracking, accurate vulnerability positioning, automatic repair execution and traceability information retention processing. According to the method, real-time sensing and quick response to network threats can be realized, and the hysteresis of a traditional static defense strategy is overcome.
Owner:ZHEJIANG SHUREN UNIV

Network threat report attack knowledge graph automatic construction method and system based on large language model, storage medium and program product

The invention relates to a network threat report attack knowledge graph automatic construction method and system based on a large language model, a storage medium and a program product, and the method comprises the steps: carrying out the iterative processing of extracted entities and relationships through a clustering method based on the large language model, and generating an initial attack knowledge graph; according to the invention, aggregation processing is carried out on a plurality of technology example threat reports belonging to the same attack technology through an attack technology graph template generation mechanism, a standardized attack technology standardized template library is established, and automatic attack technology tagging of new threat reports is realized by adopting an attack technology alignment method based on Word2Vec and WordNet, so that the automatic attack technology tagging of the new threat reports is realized. And a complete attack technology knowledge graph is constructed, so that a security analyst can quickly understand an attack path and a key threat point, and the automation degree and the accuracy of threat intelligence analysis are remarkably improved.
Owner:STATE GRID SHANGHAI MUNICIPAL ELECTRIC POWER CO +1

Industrial network threat state monitoring method and system

The invention discloses an industrial network threat state monitoring method and system, belongs to the technical field of industrial system security, solves the limitation of single flow detection through collaborative analysis of fused flow characteristics, equipment logs, threat intelligence and vulnerability scanning data, establishes a real-time association mechanism of log events and flow anomalies, and improves the safety of the system. Threat confirmation and response time is shortened from a traditional hour level to a minute level, and active strategy adjustment is realized based on linkage of a configuration baseline deviation degree and a vulnerability scanning result.
Owner:BEIJING ANDY TECH CO LTD

Network threat real-time detection and defense method and system based on artificial intelligence

The invention belongs to the technical field of network security, and provides a network threat real-time detection and defense method and system based on artificial intelligence. The method comprises the steps of multi-modal data acquisition and preprocessing, dynamic graph feature engineering and knowledge graph collaborative fusion, dual-adaptive model training and optimization, streaming real-time detection and anomaly scoring, DRL-driven hierarchical defense response and automatic disposal, and feedback-driven model adaptive updating and block chain auditing. According to the method, a mixed model of OS-ELM + dual-adaptive ridge regression + federated learning is designed, the training speed is higher than that of CNN, and over-fitting / under-fitting is avoided by dynamically adjusting a regularization coefficient; the federal learning realizes data local training and parameter uploading, and solves the problem of privacy disclosure; knowledge distillation enables the model volume to be reduced, edge equipment deployment is adapted while the accuracy is maintained, and the generalization ability is obviously superior to that of a traditional static model.
Owner:INFORMATION & COMM CO OF STATE GRID XINJIANG ELECTRIC POWER CO LTD

Large-scale encrypted traffic frame-by-frame clustering analysis method based on big data architecture

The invention provides a large-scale encrypted traffic frame-by-frame clustering analysis method based on a big data architecture, and relates to the technical field of big data, and the method comprises the steps: carrying out the data partitioning and storage of target encrypted data obtained through the preprocessing of original encrypted traffic data; based on a clustering visualization result obtained by visualizing a target clustering result obtained by carrying out frame clustering analysis on the target encrypted data, judging whether a data traffic abnormal behavior exists or not, and when the data traffic abnormal behavior exists, generating an abnormal analysis report; and an abnormal analysis report is transmitted to safety management personnel so as to take corresponding measures in time for defense. The method comprises the following steps: visualizing a target clustering result obtained by carrying out frame clustering analysis after processing and partition storage on encrypted traffic data based on a big data architecture, identifying traffic data exception, generating an exception analysis report when the exception exists, and transmitting the exception analysis report to safety management personnel to take corresponding measures for defense. The network threat identification capability is effectively enhanced, and the overall protection level of network security is further improved.
Owner:BEIJING QITIAN ANXIN TECH CO LTD

Network security linkage response system based on distributed intrusion detection

PendingCN121125355ASecuring communicationHigh level techniquesDistributed intrusion detectionAttack
The invention discloses a network security linkage response system based on distributed intrusion detection, which belongs to the technical field of network security, aims to improve the comprehensiveness of network threat detection and the timeliness of response, and comprises a distributed lightweight probe, an edge preprocessing and initial judgment module, a central depth analysis module, an intelligent linkage response module and a unified management visualization module. The distributed lightweight probe module collects network security data of each network node; the edge preprocessing and initial judgment module processes the network security data and reports the network security data after initial abnormal detection; the central deep analysis module fuses and associates the reported preprocessed data, and obtains a threat analysis result in combination with AI model analysis, external threat intelligence comparison and attack chain reduction; the intelligent linkage response module matches a preset strategy execution scheme based on the threat analysis result and feeds back an effect; and the unified management visualization module is responsible for configuration management, result display and alarm. According to the invention, accurate identification and rapid linkage response of network threats are realized, and the network security is effectively guaranteed.
Owner:WHARF TECHNOLOGY (HUBEI) CO LTD

Cyber threat information processing apparatus, cyber threat information processing method, and storage medium storing cyber threat information processing program

Provided is a cyber threat information processing method including receiving a CTI analysis request for assembly code from a client; analyzing the assembly code to obtain analysis information of the CTI for the assembly code; generating a CTI query related to a file based on the analyzed CTI and delivering the CTI query to a natural language model; and providing natural language description information according to the CTI query obtained from the CTI for the assembly code and the natural language model.
Owner:SANDS LAB INC

Real-time detection of network threats using a graph-based model

The present disclosure gives methods and systems to perform intrusion detection on a computing system using streaming embedding and detection alongside other improvements. Intrusion detection may be implemented by recording events occurring within a computing system in an audit log. From this audit log, a provenance graph representing the events and causal relationships of the events occurring within the computing system may be generated. The provenance graph may be supplemented, by a pseudo-graph that connects each event occurring in the computing system to one or more root causes. Then, a neural network may be trained to represent behavior of the computing system based on this pseudo-graph. The present disclosure also gives other systems and methods of intrusion detection and modeling computing system behavior.
Owner:THE BOARD OF TRUSTEES OF THE UNIV OF ILLINOIS

Artificial intelligence cyber security analyst

An analyzer module forms a hypothesis on what are a possible set of cyber threats that could include the identified abnormal behavior and / or suspicious activity with AI models trained with machine learning on possible cyber threats. The Analyzer analyzes a collection of system data, including metric data, to support or refute each of the possible cyber threat hypotheses that could include the identified abnormal behavior and / or suspicious activity data with the AI models. A formatting and ranking module outputs supported possible cyber threat hypotheses into a formalized report that is presented in 1) printable report, 2) presented digitally on a user interface, or 3) both.
Owner:DARKTRACE HLDG LTD

A method for generating network threat rules based on threat intelligence

The present invention relates to a method for generating network threat rules based on threat intelligence, and relates to the field of network security. This application crawls open-source network threat intelligence; uses image analysis prompts to guide a multi-modal language model to convert image-based open-source network threat intelligence into text-based; unifies the content format to obtain initial network threat intelligence; uses a language model to assist in filtering the initial network threat intelligence; an agent uses a voting method to identify the first type of entity and the second type of entity from the filtered network threat intelligence and establish a connection; uses Sigma rules to create prompts to control the agent to create Sigma rules based on the associated first type of entity and the second type of entity extracted from the network threat intelligence block in the filtered network threat intelligence block; uses Sigma rules to optimize prompts, and Sigma rule verification prompts control the language model used by the agent to optimize and verify the generated Sigma rules.
Owner:JIANGSU RUINING XINCHUANG TECH CO LTD

Multi-source network threat aggregation analysis method, system and device facing attacker portrait, and storage medium

The invention discloses an attacker portrait-oriented multi-source network threat aggregation analysis method, system and device, and a storage medium, and relates to the technical field of network security threat analysis, and the method comprises the steps: carrying out the multi-source evidence association and semantic aggregation of a standardized event, outputting an edge weight between entities through an evidence energy model, and constructing a threat relation graph; time sequence consistency, spatial dependence and semantic context information are fused, a traceable attention map neural network is constructed for representation learning and clustering, a high-credibility attack portrait and a structured portrait vector are generated, an adaptive risk calculation model is constructed, trend prediction and anti-fact simulation are performed, and a final risk score is obtained. And generating structured processing decision data. According to the method disclosed by the invention, the whole-process intelligent analysis from data perception to decision output is realized, so that threat identification has data uniformity, portrait credibility and risk quantizability, and a modeling, interpretable and reproducible analysis basis is provided for active defense.
Owner:STATE GRID HUNAN ELECTRIC POWER CO +1

Network threat evidence fixation technology for solving traceability evidence chain deficiency

The invention discloses a network threat evidence fixation technology for solving source tracing evidence chain deficiency, and belongs to the field of network security. Aiming at the problems of distributed log time sequence chaos, easy tampering of virtual environment metadata, difficult association of cross-platform attack traces and the like existing in the traditional evidence obtaining technology, the invention constructs a technical system of dynamic data capture and space-time fusion modeling, evidence chain reconstruction and distributed verification, anti-quantum storage and security solidification. A self-adaptive sensor network is constructed through an improved BFGS algorithm, a space-time fusion evidence model is provided, and an improved MPT structure and a lattice-based cryptographic algorithm are designed in combination with a time sequence Petr i network and a Byzantine fault-tolerant protocol. Tests show that the attack feature capture rate reaches 91%, the cross-platform attack association accuracy rate reaches 93%, the quantum signature resistance speed is 1200 times per second, and the problem of source tracing evidence chain deficiency is effectively solved.
Owner:GUANGXI POWER GRID CORP

Method for cyber threat risk analysis and mitigation in development environments

A method for a cyber security appliance incorporating data from a source code repository, hosted by a software development environment, to identify cyber threats related to source code being stored and developed in that source code repository is provided. The method comprises: receiving, at one or more modules of the cyber security appliance, data indicating a network entity representing a user's interaction with the source code repository; and comparing the data, received from the one or more modules, to one or more machine learning models trained on a normal benign behavior interacting with the source code repository using a normal behavior benchmark describing parameters corresponding to a normal interaction behavior. The method further comprises identifying whether the data indicating the network entities interaction with the source code repository corresponds to behavior that deviates from the normal benign behavior; identifying whether a threshold level of deviation from the normal benign behavior has been exceeded; and, if the threshold level of deviation from the normal benign behavior has been exceeded, determining that a cyber threat may be present and executing an autonomous response to restrict the network entities interaction with the source code repository.
Owner:DARKTRACE HLDG LTD

Intelligent control method and system of Internet protection gateway

The invention relates to the technical field of network security, and discloses an intelligent control method and system for an Internet protection gateway, and the method comprises the following steps: obtaining network flow, and extracting a multi-mode state feature; and performing causal reasoning in combination with the knowledge graph to generate causal features. After fusing the two features, inputting the two features to three agents, namely a flow analysis agent, a response strategy agent and a resource scheduling agent, for collaborative decision, and generating a security strategy and a resource scheme; according to the scheme, dynamic deployment is carried out on heterogeneous computing resources, flow processing is completed, and data are recorded; and finally, iteratively optimizing the agent model by utilizing the disposal data, and applying the optimized model to the next round of decision. According to the method, the multi-modal state features including the basic features, the application layer semantics and the time sequence information are extracted, the network security knowledge graph is further constructed for causal relationship reasoning, and isolated network events are placed in a wider logic relationship for analysis, so that the depth and accuracy of network threat identification are improved.
Owner:BAIGE ONLINE (XIAMEN) DIGITAL TECHNOLOGY CO LTD

Identity authentication method and system based on national secret algorithm

The invention discloses an identity authentication method and system based on a national secret algorithm, and the method comprises the steps: building a hierarchical key management system based on a national secret IBE framework, generating a system master key pair through employing an SM2 algorithm, and achieving a decentralized key distribution mechanism; constructing a domain perception differential privacy protection module, defining a privacy budget allocation strategy according to the security level, and adding calibrated Laplace noise to the user identity feature vector; designing a distributed batch matrix multiplication protocol, and decomposing the distributed batch matrix multiplication protocol to a plurality of computing nodes for parallel processing through a secret sharing technology; a zero-knowledge proof verification mechanism is implemented, and identity verification is completed through a commitment scheme based on an SM3 hash algorithm; deploying a self-adaptive key updating strategy, and analyzing threat level change through a threat situation evaluation function; and establishing a secure communication channel based on SM4 symmetric encryption, and performing encryption processing by using the temporary session key. The security and expandability of the system are improved, the privacy of the user is effectively protected, and the system adapts to a dynamically changing network threat environment.
Owner:GUIZHOU BLUESKY INNOVATIVE SCI & TECH CO LTD

Network abnormal behavior detection and dynamic defense method and system

The invention provides a network abnormal behavior detection and dynamic defense method and system, and the method comprises the steps: collecting multi-source data which comprises network flow data, terminal behavior data, application log data and threat intelligence data; performing anomaly analysis on the network flow data through an auto-encoder to obtain an anomaly result; taking the terminal behavior data, the application log data and the threat intelligence data as input data; analyzing the input data through a graph neural network to obtain a transverse penetration behavior; performing strategy adjustment, dynamic isolation and vulnerability repair according to the attribute of the abnormal result and the attribute of the transverse penetration behavior; through anomaly detection of the graph neural network and anomaly detection of the auto-encoder, novel unknown network threats and intrusion attacks are effectively dealt with; the accuracy of network threat alarm is effectively improved; and automatically optimizing a detection model and a defense strategy based on environment change and attack feedback.
Owner:BEIJING SUMAVISION PAYMENT TECH CO LTD +1

Safety monitoring method and system for network traffic

The invention relates to the technical field of network security, in particular to a security monitoring method and system for network traffic. The method comprises the following steps: capturing a network flow data flow in real time, and extracting a network entity and a direct communication relationship to construct a basic communication graph; identifying and quantifying a high-order interaction mode between network entities, and taking the high-order interaction mode as an implicit feature enhanced basic communication graph to generate an enhanced security graph; processing the enhanced security map by using a multi-scale time sequence diagram neural network, and capturing a short-term burst mode and a long-term evolution mode at the same time; a dynamic anomaly score is calculated based on the network entity historical behavior baseline and the current network situation, and a security alert is generated when an adaptive threshold is exceeded. The system correspondingly comprises a flow capture module, a feature extraction module, a high-order mode analysis module, a security map construction module, a multi-scale analysis module, a dynamic risk assessment module and an intelligent alarm module, and comprehensive and accurate network threat detection is realized.
Owner:李达