Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

262 results about "Cyber threat" patented technology

Ai-based cybersecurity system and method thereof

An AI-based Cybersecurity System and Method enable real-time detection, analysis, and mitigation of cyber threats within computing networks using adaptive artificial intelligence. The system continuously monitors network traffic, extracts behavioral and contextual attributes, and applies deep learning-based inference to identify anomalous activities indicating security breaches. The method integrates several computational units, including a network monitoring unit, feature extraction unit, artificial intelligence processor, contextual reasoning processor, and decision synthesis unit, to compute a composite risk index quantifying threat likelihood and severity. A classification processor categorizes detected threats into types such as ransomware, phishing, or unauthorized access, while a mitigation control processor initiates automated response actions to isolate compromised nodes and restore network integrity. An adaptive learning processor updates AI models using feedback from confirmed incidents. This provides a scalable, self-evolving cybersecurity framework that minimizes human intervention and enhances resilience against dynamic and zero-day threats.
Owner:PELL REDDY RAJENDER REDDY

Method and system for automatically executing network security policy based on artificial intelligence large model

The invention provides a network security policy automatic execution method and system based on an artificial intelligence large model, and relates to the technical field of network security, and the method comprises the steps: firstly obtaining a network threat chain data set comprising a threat initiating node, an intermediate propagation node, a target attacked node and propagation path description; calling a pre-trained threat chain analysis large model to carry out hierarchical disassembly and variation trend prediction, outputting a threat chain disassembly map, then extracting a matching strategy gene segment from a preset security strategy gene pool, generating candidate security strategies through model gene recombination and cross-strategy collaborative adaptation, and carrying out threat chain analysis on the candidate security strategies; inputting the candidate strategies, the current network topology and the equipment resource load data into a strategy execution deduction system, outputting an executable security strategy set adaptive to the current network state, finally issuing the executable security strategy set to network security equipment, and collecting execution feedback data for updating the threat chain analysis large model. And automatic, efficient and accurate generation and execution of the network security policy are realized.
Owner:XINYUAN NETWORK TECH CO LTD

Advanced Cybersecurity System for Real-Time Phishing Detection, Account Takeover Fraud Prevention, and Software Repository Optimization Using Machine Learning Techniques

Systems and processes are disclosed for enhancing cybersecurity and optimizing software repositories through integration of web crawling, web scraping, feature engineering, and advanced machine learning algorithms to detect phishing attempts, prevent account takeover fraud, and identify unused code in repositories. The system collects and refines data from various sources, including transaction logs, customer databases, device details, external data sources, and historical fraud data, to build comprehensive datasets. Feature engineering creates new, meaningful features from the refined data, which are used to train and evaluate machine learning models. The best-performing models are deployed in production to monitor incoming communications and transactions in real-time, flagging suspicious activities and optimizing codebases. This processing ensures timely detection and prevention of security threats while maintaining efficient software development processes. Robust protection is provided against evolving cyber threats and enhances software performance and security through continuous learning and adaptation.
Owner:BANK OF AMERICA CORP

Security defense strategy method and system based on AI Agent dynamic optimization

The invention provides a method and a system for dynamically optimizing a security defense strategy based on an AI Agent, and aims to solve the problems that the traditional network security defense strategy is static and cannot adapt to a dynamic network environment and novel network threats, and the processing efficiency of massive security data is low and the response is not timely. The method comprises the following steps: firstly, realizing whole network node data acquisition through a distributed AI Agent, performing accurate identification in combination with a multi-dimensional threat perception and fusion detection mechanism, and establishing a threat parameter quantitative evaluation model; secondly, the AI Agent generates a dynamic defense strategy according to the analysis result of the intelligent threat detection and the real-time state of the network in combination with threat features and risk assessment; and finally, according to the dynamic defense response result, realizing attack path tracking, accurate vulnerability positioning, automatic repair execution and traceability information retention processing. According to the method, real-time sensing and quick response to network threats can be realized, and the hysteresis of a traditional static defense strategy is overcome.
Owner:ZHEJIANG SHUREN UNIV

Network threat real-time detection and defense method and system based on artificial intelligence

The invention belongs to the technical field of network security, and provides a network threat real-time detection and defense method and system based on artificial intelligence. The method comprises the steps of multi-modal data acquisition and preprocessing, dynamic graph feature engineering and knowledge graph collaborative fusion, dual-adaptive model training and optimization, streaming real-time detection and anomaly scoring, DRL-driven hierarchical defense response and automatic disposal, and feedback-driven model adaptive updating and block chain auditing. According to the method, a mixed model of OS-ELM + dual-adaptive ridge regression + federated learning is designed, the training speed is higher than that of CNN, and over-fitting / under-fitting is avoided by dynamically adjusting a regularization coefficient; the federal learning realizes data local training and parameter uploading, and solves the problem of privacy disclosure; knowledge distillation enables the model volume to be reduced, edge equipment deployment is adapted while the accuracy is maintained, and the generalization ability is obviously superior to that of a traditional static model.
Owner:INFORMATION & COMM CO OF STATE GRID XINJIANG ELECTRIC POWER CO LTD

Network security linkage response system based on distributed intrusion detection

PendingCN121125355ASecuring communicationHigh level techniquesDistributed intrusion detectionAttack
The invention discloses a network security linkage response system based on distributed intrusion detection, which belongs to the technical field of network security, aims to improve the comprehensiveness of network threat detection and the timeliness of response, and comprises a distributed lightweight probe, an edge preprocessing and initial judgment module, a central depth analysis module, an intelligent linkage response module and a unified management visualization module. The distributed lightweight probe module collects network security data of each network node; the edge preprocessing and initial judgment module processes the network security data and reports the network security data after initial abnormal detection; the central deep analysis module fuses and associates the reported preprocessed data, and obtains a threat analysis result in combination with AI model analysis, external threat intelligence comparison and attack chain reduction; the intelligent linkage response module matches a preset strategy execution scheme based on the threat analysis result and feeds back an effect; and the unified management visualization module is responsible for configuration management, result display and alarm. According to the invention, accurate identification and rapid linkage response of network threats are realized, and the network security is effectively guaranteed.
Owner:WHARF TECHNOLOGY (HUBEI) CO LTD

Multi-source network threat aggregation analysis method, system and device facing attacker portrait, and storage medium

The invention discloses an attacker portrait-oriented multi-source network threat aggregation analysis method, system and device, and a storage medium, and relates to the technical field of network security threat analysis, and the method comprises the steps: carrying out the multi-source evidence association and semantic aggregation of a standardized event, outputting an edge weight between entities through an evidence energy model, and constructing a threat relation graph; time sequence consistency, spatial dependence and semantic context information are fused, a traceable attention map neural network is constructed for representation learning and clustering, a high-credibility attack portrait and a structured portrait vector are generated, an adaptive risk calculation model is constructed, trend prediction and anti-fact simulation are performed, and a final risk score is obtained. And generating structured processing decision data. According to the method disclosed by the invention, the whole-process intelligent analysis from data perception to decision output is realized, so that threat identification has data uniformity, portrait credibility and risk quantizability, and a modeling, interpretable and reproducible analysis basis is provided for active defense.
Owner:STATE GRID HUNAN ELECTRIC POWER CO +1

Method for cyber threat risk analysis and mitigation in development environments

A method for a cyber security appliance incorporating data from a source code repository, hosted by a software development environment, to identify cyber threats related to source code being stored and developed in that source code repository is provided. The method comprises: receiving, at one or more modules of the cyber security appliance, data indicating a network entity representing a user's interaction with the source code repository; and comparing the data, received from the one or more modules, to one or more machine learning models trained on a normal benign behavior interacting with the source code repository using a normal behavior benchmark describing parameters corresponding to a normal interaction behavior. The method further comprises identifying whether the data indicating the network entities interaction with the source code repository corresponds to behavior that deviates from the normal benign behavior; identifying whether a threshold level of deviation from the normal benign behavior has been exceeded; and, if the threshold level of deviation from the normal benign behavior has been exceeded, determining that a cyber threat may be present and executing an autonomous response to restrict the network entities interaction with the source code repository.
Owner:DARKTRACE HLDG LTD

Identity authentication method and system based on national secret algorithm

The invention discloses an identity authentication method and system based on a national secret algorithm, and the method comprises the steps: building a hierarchical key management system based on a national secret IBE framework, generating a system master key pair through employing an SM2 algorithm, and achieving a decentralized key distribution mechanism; constructing a domain perception differential privacy protection module, defining a privacy budget allocation strategy according to the security level, and adding calibrated Laplace noise to the user identity feature vector; designing a distributed batch matrix multiplication protocol, and decomposing the distributed batch matrix multiplication protocol to a plurality of computing nodes for parallel processing through a secret sharing technology; a zero-knowledge proof verification mechanism is implemented, and identity verification is completed through a commitment scheme based on an SM3 hash algorithm; deploying a self-adaptive key updating strategy, and analyzing threat level change through a threat situation evaluation function; and establishing a secure communication channel based on SM4 symmetric encryption, and performing encryption processing by using the temporary session key. The security and expandability of the system are improved, the privacy of the user is effectively protected, and the system adapts to a dynamically changing network threat environment.
Owner:GUIZHOU BLUESKY INNOVATIVE SCI & TECH CO LTD

Safety monitoring method and system for network traffic

The invention relates to the technical field of network security, in particular to a security monitoring method and system for network traffic. The method comprises the following steps: capturing a network flow data flow in real time, and extracting a network entity and a direct communication relationship to construct a basic communication graph; identifying and quantifying a high-order interaction mode between network entities, and taking the high-order interaction mode as an implicit feature enhanced basic communication graph to generate an enhanced security graph; processing the enhanced security map by using a multi-scale time sequence diagram neural network, and capturing a short-term burst mode and a long-term evolution mode at the same time; a dynamic anomaly score is calculated based on the network entity historical behavior baseline and the current network situation, and a security alert is generated when an adaptive threshold is exceeded. The system correspondingly comprises a flow capture module, a feature extraction module, a high-order mode analysis module, a security map construction module, a multi-scale analysis module, a dynamic risk assessment module and an intelligent alarm module, and comprehensive and accurate network threat detection is realized.
Owner:李达

Network security operation method and device, equipment and storage medium

ActiveCN121530757ASecuring communicationInternet trafficEvolving networks
The invention relates to the technical field of computers, in particular to a network security operation method, device and equipment and a storage medium, and is used for providing a network security operation scheme which can give consideration to efficiency and precision and is adaptive to a current dynamically evolved network threat environment. The method comprises the steps of obtaining to-be-processed operation data, wherein the operation data is obtained by preprocessing network flow data and log data; processing the operation data by using a lightweight model to generate initial alarm data; based on the initial alarm data, carrying out alarm authenticity discrimination and threat level determination through a heavy model, and outputting confirmed threat event information; the threat event information indicates alarm data and threat levels corresponding to threat events confirmed by the heavy model; based on the threat event information, risk disposal is executed, affected asset information is obtained, a traceability evidence obtaining tool is matched, and a standardized evidence obtaining report is generated; and based on the standardized evidence obtaining report, executing vulnerability repair.
Owner:HANGZHOU DPTECH TECH

System for cyber risks evaluation

A method and system for evaluating cyber risk of an entity comprising a risk evaluation module configured to collect risk data on risks of cyber-attacks connected to SaaS, infrastructure, and legal regulations classified by geolocation, industry type, and size of the victim organization, an entity evaluation module for collecting vulnerability data on assets of the entity classified by industry type, geolocation, size and cyber threat vector vulnerabilities and a monetization engine configured to make an assessment of expected financial loss from a specified cyber-attack to an entity classified by geolocation, industry type, and size, based on the risk data.
Owner:LEVY GIL +4

Cyber threat information processing apparatus, cyber threat information processing method, and storage medium storing cyber threat information processing program

A cyber threat information processing method including generating stack trace information of a reader program of an operating system executing a non-executable file at a hooking point of a system call of the operating system when the reader program performs the system call, obtaining a calling function for calling the system call and a variable corresponding to the calling function from the generated stack trace information, and providing description information about the obtained calling function and the variable corresponding to the calling function.
Owner:SANDS LAB INC

Network threat detection method and system fused with multi-modal analysis

The invention relates to the technical field of network threat detection, in particular to a multi-modal analysis-fused network threat detection method and system, which are used for continuously acquiring network traffic, system call logs and cross-domain access records in a cloud computing environment in the power industry. Combining the obtained heterogeneous information into a uniform data stream according to a timestamp and an event identifier; aiming at the formed data stream, carrying out feature expansion on the hidden attack signal by utilizing a behavior pattern deconstruction method; recursive aggregation processing is carried out on the multi-source behavior units, causal chain constraints and role sensitive tags are introduced in the aggregation process, and candidate behavior chains capable of representing the attack evolution process are generated; mapping the candidate behavior chain to a virtual topological structure of a cloud computing environment, and predicting a potential penetration channel based on an attack path deduction algorithm; and triggering an adaptive protection strategy according to the predicted interaction result of the potential permeation channel and the candidate behavior chain. According to the invention, the network threat detection accuracy can be improved.
Owner:STATE GRID XINJIANG ELECTRIC POWER COMPANY HAMI POWERSUPPLY COMPANY

System and method for operating system memory forensics

ActiveUS12511388B1Platform integrity maintainanceMemory forensicsOperational system
Disclosed herein is a cyberthreat detection system for detecting, in real-time, cyberthreats residing within a memory of a targeted computing device. The cyberthreat detection system features an undocumented structure extractor logic and an undocumented offset extractor logic. The undocumented structure extractor logic is configured to identify known, undocumented, memory structures associated with software operating on the targeted computing device. The undocumented offset extractor logic is configured to identify undocumented and unknown memory structures associated with software installed on the targeted computing device.
Owner:FIREEYE SECURITY HOLDINGS US LLC

Network threat risk prediction and dynamic response method based on deep learning

The invention discloses a network threat risk prediction and dynamic response method based on deep learning, and relates to the technical field of network security, and the method comprises the steps: constructing a multi-source heterogeneous data collection layer, collecting various types of data, and carrying out the cleaning standardization; building a threat feature enhancement extraction module, generating multi-dimensional features through three-level feature engineering, and introducing an adversarial sample to enhance the recognition capability; constructing a depth prediction model fused with an attention mechanism, and outputting a multi-period risk value through space-time convolution and gating cycle unit processing; designing a hierarchical dynamic response engine, and making a response strategy according to the risk level; a closed-loop optimization module is established, and evaluation indexes are collected to calculate efficiency scores; a global security collaboration platform is deployed, cross-device linkage and cross-organization intelligence sharing are achieved, and visualization and strategy simulation functions are provided. According to the method, the data processing efficiency and the privacy protection level are improved, the threat prediction precision and the model generalization ability are enhanced, and the intelligence and reliability of network threat defense are comprehensively improved.
Owner:EAST UNIV OF HEILONGJIANG

Cyber threat information processing apparatus, cyber threat information processing method, and storage medium storing cyber threat information processing program

A cyber threat information processing method including receiving a CTI analysis request for a document script from a client; analyzing the document script to obtain analysis information of the CTI for the script; generating a CTI query related to the document script based on the analysis information of the CTI and delivering the CTI query to a natural language model; and providing natural language description information according to the CTI query from the analysis information of the CTI and the natural language model to the client.
Owner:SANDS LAB INC

Method and device for determining network risk value, equipment, medium and program product

The invention discloses a network risk value determination method and device, equipment, a medium and a program product, and the method comprises the steps: obtaining the weight adjustment amount of a target network corresponding to each risk dimension and the influence degree of the weight under different risk dimensions on the network risk value of the target network under the condition that a weight adjustment trigger event is detected; according to each weight adjustment amount and each influence degree, an adjustment loss value is determined, and the adjustment loss value is in positive correlation with the absolute value of the weight adjustment amount and the influence degree; in the plurality of adjustment loss values, determining a weight corresponding to the minimum adjustment loss value as a target weight; and obtaining a data score value corresponding to the target network under each risk dimension, and determining a target network risk value according to the data score value and the corresponding target weight. According to the embodiment of the invention, the network risk assessment result can respond to the change of the network threat situation in real time, and the accuracy of network security risk assessment is improved.
Owner:CHINA MOBILEHANGZHOUINFORMATION TECH CO LTD +1

Dynamic feature optimization leveraging quantum simulation for fake account detection

Robust systems and methods are disclosed for fake account detection on digital platforms, integrating provenance analysis to scrutinize data origins, ownership, and history, thereby unveiling potential sources of fraudulent activities. They leverage dynamic feature generation, using advanced algorithms to assess user behaviors and interactions, ensuring the model stays attuned to the evolving landscape of cyber threats. Incorporating Quantum-assisted optimization, the method employs Quantum algorithms to expedite feature selection, enhancing detection efficiency. Quantum simulation further refines this process, creating sophisticated verification patterns and analytical techniques to distinguish genuine from fake accounts with higher accuracy. A comprehensive analysis amalgamates provenance data, telemetry, and dynamic features, forming a holistic detection approach. This system optimizes features through Quantum simulation, tailoring them to specific business environments, and deploys them via AI-ML DevOps, streamlining orchestration across various operational settings.
Owner:BANK OF AMERICA CORP

Network threat identification and defense method and system based on data enhancement and adversarial evolution

The invention provides a network threat identification and defense method and system based on data enhancement and adversarial evolution, and relates to the technical field of network security defense, and the method comprises the steps: obtaining a log stream of a network event, and carrying out the preprocessing and vectorization of the log stream; performing knowledge base RAG retrieval on the vectorized network events, and retrieving to obtain attack and defense tags of similar network events in a knowledge base; constructing cue words, inputting the cue words into the LLM reasoning model, and predicting the next network attack operation; a double-agent adversarial network mechanism is started in the LLM reasoning model, a reinforcement learning evaluation process is introduced, a multi-objective loss function is constructed, and the multi-objective loss function is used as an optimization index of an attack sample and a standard whether the multi-objective loss function is handed over to a defense agent or not; and the defense agent identifies an attack sample, and improves the discrimination capability of fuzzy attack features by optimizing cue words to obtain a discrimination prediction result. According to the invention, the modeling and prediction capability of the attack sequence is improved.
Owner:INFORMATION COMM COMPANY STATE GRID SHANDONG ELECTRIC POWER

Multi-dimensional threat flow detection method and security protection system based on large language model

The invention relates to the technical field of network security, in particular to a multi-dimensional threat traffic detection method based on a large language model and a security protection system, which are used for solving the problem that when an existing network threat detection and protection system processes multi-source heterogeneous threat traffic from each layer of a network, the threat traffic cannot be detected. The problems of technical bottlenecks such as multi-dimensional flow semantic segmentation, attack behavior modeling shallow stratification, static lag of detection rules and lack of interpretability of response strategies generally exist; according to the method, space-time joint reasoning of attack behaviors is realized by fusing a graph structure and time evolution characteristics through a large language model: modeling is performed in combination with a graph neural network and a time sequence, node representation fusing semantics, a structure and the time sequence is generated, Q-learning path deduction is introduced, a high-value target is accurately identified, and an attack path is restored; and finally, a structured intention containing a target, a condition, a path and a strategy and a behavior chain graph with a time sequence tag are output, so that the accuracy, the interpretability and the perspectiveness of attack intention recognition are remarkably improved.
Owner:CHAOHU UNIV

Network threat intelligent evaluation method and system based on multi-source data fusion and graph neural network

The invention provides a network threat intelligent assessment method and system based on multi-source data fusion and a graph neural network, and the method comprises the steps: marking a path as a high-risk propagation channel if the connection strength of a certain node in a threat propagation path prediction model exceeds a preset threshold value, and obtaining a high-risk propagation channel set; obtaining asset characteristic difference information, such as position criticality and protection intensity, through the high-risk propagation channel set, judging the asset exposure degree, and obtaining an asset exposure degree score; if the threat fine classification result shows that the recovery difficulty quantized value is higher than the average level, adjusting the assessment standard unification framework to obtain a preliminary severity quantized value; and through the preliminary severity quantized value, integrating propagation path prediction and asset exposure degree score, judging the overall threat level, and obtaining a final threat severity assessment report.
Owner:WUHAN KUNPENG INFORMATION TECH CO LTD

Hierarchical Mama and multi-modal fusion unknown network threat detection method based on physical boundary perception

The invention discloses a hierarchical Mama and multi-modal fusion unknown network threat detection method based on physical boundary perception, and relates to the technical field of network space security and artificial intelligence crossing, and the method comprises the steps: carrying out physical boundary perception preprocessing on original network traffic, and extracting byte modal features and statistical modal features; constructing a layered Mama encoder, extracting a load semantic feature of each data packet, and extracting a time sequence interaction feature between the data packets; inputting the byte modal features and the statistical modal features into a multi-modal gating fusion module to generate an anti-confusion stream representation vector; and based on the mask reconstruction pre-training model, calculating a reconstruction error of the input flow. According to the method, the physical level of a network protocol is strictly aligned, stable detection performance can still be kept, extremely high reasoning speed and low video memory occupation are kept, the limitation that a traditional closed set classifier can only recognize known attacks is broken through, and the blank of an efficient flow detection model in the field of open set detection is filled up.
Owner:INNER MONGOLIA UNIV OF TECH

Network threat behavior reasoning method and system based on large model retrieval enhancement

The invention discloses a network threat behavior reasoning method and system based on large model retrieval enhancement, and the method comprises the following steps: a computer system executes the following steps: determining a query target and an associated scene or organization by receiving a network threat analysis query request of a user; retrieving related nodes and relationships from the threat intelligence knowledge graph, and generating an initial reasoning sub-graph; calling a GraphRAG framework, and carrying out semantic matching retrieval on a subgraph node context and an external threat intelligence knowledge base to obtain supplementary evidence; constructing a comprehensive prompt template, inputting the large language model subjected to LoRA fine tuning, and generating a conformity ATTamp; reasoning a conclusion of the CK framework; and finally, supplementing the newly added nodes and the relationship to the knowledge graph, and outputting a structured file or a visual result. According to the method, retrieval enhancement and large model reasoning technologies are combined, the problems of cross-document attack chain restoration and complex threat behavior logical reasoning are effectively solved, and the method has remarkable application value in the aspects of threat intelligence tracing, behavior prediction and defense decision assistance.
Owner:GUIZHOU UNIV

Cyber security system utilizing interactions between detected and hypothesize cyber-incidents

An apparatus may include a set of modules and artificial intelligence models to detect a cyber incident, a simulator to simulate an actual cyber attack of the cyber incident on a network including physical devices being protected by the set of modules and artificial intelligence models; and a feedback loop between i) the set of modules and artificial intelligence models and ii) the simulator, during an ongoing detected cyber incident. An attack path modeling module is configured to feed details of the detected incident by a cyber threat module into an input module of the simulator, and to run one or more hypothetical simulations of that detected incident in order to predict and control an autonomous response to the detected incident. Any software instructions forming part of the set of modules, the artificial intelligence models, and the simulator are stored in an executable form in memories and executed by processors.
Owner:DARKTRACE HLDG LTD

Real-time ransom and security breach detection and prevention

The real-time ransom and security breach detection and prevention system empowers users and system administrators by providing real-time threat detection and prevention by detecting any phishing links, malicious executables and objects, and manipulation of authentication tokens that could potentially escalate a threat into ransom attacks, security breaches or other cyber attacks, and take immediate action by blocking and reporting the potential security breach before escalating into a real attack. The real-time ransom and security breach detection and prevention system generates a first hash of the link, executable, object, or authentication token. Utilizing this generated first hash, the real-time ransom and security breach detection and prevention system calculates a second hash upon user interaction or at runtime and compares the two unique hashes to determine if the link, executable, object, or authentication token is corrupt and terminates the gateway to prevent the cyber-threat from infecting the system.
Owner:IMPERVIOUS WORLD CORP

Electronic voting system

The described voting system comprises two main components: an online verification device and an offline voting device. The verification device utilises a data interface to communicate with central databases for real-time voter verification, employing biometric sensors to ensure accurate voter identification and prevent duplicate voting. This system enhances security by generating a unique verification code for each verified voter. The offline voting device, designed to be immune to network-based threats, uses this code along with biometric verification to authenticate voters. It features a user interface that employs eye gesture technology, allowing voters to select candidates privately and securely through eye movements, without any visible indication of their choices to onlookers. This setup not only protects the integrity of the vote from cyber threats but also safeguards voter privacy and reduces the potential for voter intimidation, for a free, fair, and secure voting process.
Owner:MOHANTA AKASH

System and method for generating dynamic cyber threat models based on application architecture

A system includes a memory configured to store a set of application environment parameters associated with a software application of a plurality of software applications. The system further includes processors for accessing the set of application environment parameters associated with the software application, identifying, based on the set of application environment parameters, a plurality of potential threats and vulnerabilities associated with an execution of the software application in accordance with the current configuration, and executing one or more generative machine-learning models trained to generate a prediction of one or more cyber threat scenarios based on the set of application environment parameters and the plurality of potential threats and vulnerabilities. The prediction of the one or more cyber threat scenarios includes cyber threat scenarios specific to the software application. The processors further output, by the one or more generative machine-learning models, the prediction of the one or more cyber threat scenarios.
Owner:BANK OF AMERICA CORP

Network threat analysis and identification method and system based on network security rules

The invention discloses a network threat analysis and identification method and system based on a network security rule, and relates to the field of network information identification, and the method comprises the steps: collecting large-scale network data; constructing a threat analysis map for the collected data, analyzing the data in combination with the characteristics, screening whether threats exist, and dividing the threats into substantive threats and network speech threats; and different models are constructed for different types of threats, and classification, identification and processing are carried out. According to the method, semantic coding is performed through semantic matching discrimination and antagonism training, graph representation is adopted and pre-trained BERT is introduced, so that more powerful performance is shown when complex network threats are processed, meanwhile, network flow data are collected through the intelligent measurement terminal, the data are sent to the intelligent measurement safety monitoring master station, and the network flow data are transmitted to the intelligent measurement safety monitoring master station. The master station introduces a network security analysis rule, automatically extracts network flow characteristic data, and automatically identifies network threats according to the characteristics of network attacks and by combining a high-performance big data flow processing rule engine.
Owner:YUNNAN POWER GRID CO LTD

Rule-based network-threat detection for encrypted communications

A packet-filtering system configured to filter packets in accordance with packet-filtering rules may receive data indicating network-threat indicators and may configure the packet-filtering rules to cause the packet-filtering system to identify packets comprising unencrypted data, and packets comprising encrypted data. A portion of the unencrypted data may correspond to one or more of the network-threat indicators, and the packet-filtering rules may be configured to cause the packet-filtering system to determine, based on the portion of the unencrypted data, that the packets comprising encrypted data correspond to the one or more network-threat indicators.
Owner:CENTRIPETAL NETWORKS INC