Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

63 results about "Cyber threat intelligence" patented technology

Knowledge graph construction and attack path prediction method for network security

The invention belongs to the technical field of network security, and particularly discloses a network security knowledge graph construction and attack path prediction method, which comprises the following steps: acquiring an attack mode of network threat intelligence; constructing a network security knowledge graph based on the security vulnerability and attack pattern classification standard data and the attack pattern of the network threat intelligence; according to the method, an entity relationship in a network security knowledge graph is predicted based on a graph attention network GAT of text enhancement, an attack path is constructed based on the predicted entity relationship, and text enhancement is to introduce text information corresponding to entity nodes into a multi-head attention mechanism layer of the GAT. According to the method, the network security knowledge graph is constructed and the entity relationships are predicted based on the GAT, so that the entity relationships can be quickly integrated, the attack paths are constructed, the paths reveal security holes and attack modes which may be utilized by attackers, and accurate and efficient attack path prediction can be realized.
Owner:HUAZHONG NORMAL UNIV

Techniques for providing artificial intelligence mediated curation of access and content within a cyber threat intelligence platform

Techniques are described herein for providing artificial intelligence mediated curation of access and content within a cyber threat intelligence platform. An example system includes: one or more memories, and one or more processors. The example system may receive, from a node, an input indicating a cyber threat type; identify, by a trained AI model, cyber threat intelligence content objects, each of the objects being (a) contributed by one or more nodes having access to the distributed ledger or (b) generated by the trained AI model; evaluate, by the trained AI model, each object to: determine relevance values corresponding to each of object, and generate (i) a curated set of cyber threat intelligence content objects based on the relevance values and (ii) a recommended cyber threat practice; and transmit the recommended cyber threat practice and an indication of the curated set of cyber threat intelligence content objects to the node.
Owner:TEACHERS INSURANCE & ANNUITY ASSOC OF AMERICA

Network threat knowledge automatic extraction method, electronic equipment and storage medium

The invention discloses a network threat knowledge automatic extraction method, electronic equipment and a storage medium, and the method comprises the following steps executed by a computer hardware system: collecting threat intelligence data related to an APT organization from a multi-source network security text, and processing the threat intelligence data to generate a standardized corpus; using the pre-training sentence vector model to generate semantic embedding for a corpus input text and a manual annotation example library text, and retrieving similar examples to construct an ICL prompt template; inputting a large language model subjected to LoRA fine tuning, and extracting structured triples of multiple types of entities and semantic relationships; generating standardized entity nodes and updated relation information by adopting semantic aggregation; and constructing an APT organization network threat intelligence knowledge graph and outputting a structured file. The method provides key technical support for APT attack tracing, threat situation awareness and automatic security policy generation.
Owner:GUIZHOU UNIV

Broadcasting and television network security operation method and system based on large model

The invention discloses a broadcast television network security operation method and system based on a large model, and the method comprises the steps: collecting log, network flow and terminal behavior data in real time, storing the data in a Kafka message queue, receiving the data through an AI intelligent noise reduction module, extracting alarm text semantic features through an XLM-ROBERTa model, and carrying out the noise filtering through combining with a multi-classification model, thereby obtaining high-value data; inputting the high-value data and security document knowledge corresponding to the network threat intelligence into an RAG knowledge base module, generating enhanced context information data through knowledge extraction, vectorization storage and similarity retrieval, inputting the enhanced context information data into a cue word of a reply model, and outputting a first threat analysis reply; inputting the high-value data and the first threat analysis reply into a multi-model MOE architecture, distributing tasks through a gating network, integrating expert network output results, and generating a second threat analysis reply and a corresponding attack thermodynamic diagram; and executing feedback optimization operation of the corresponding module based on the second threat analysis reply, thereby improving the safety operation efficiency of the broadcast television network.
Owner:NINGBO RADIO & TELEVISION GRP

Techniques for leveraging proof-of-contribution on a distributed cyber threat intelligence platform

Techniques are described herein for providing leveraging proof-of-contribution on a distributed cyber threat intelligence platform. An example system includes one or more memories, and one or more processors. The system may receive, from a node, an input associated with cyber threat intelligence; store, by a smart contract of the smart contracts engine, the input in a distributed ledger as part of a set of cyber threat intelligence content, the distributed ledger being accessible by one or more nodes; evaluate, by a trained AI model of the AI engine, a proof-of-contribution protocol for the node by: validating the input as received from the node, and determining a valuation of the input to the set of cyber threat intelligence content; and adjust a level of voting power allocated to the node, in accordance with the valuation.
Owner:TEACHERS INSURANCE & ANNUITY ASSOC OF AMERICA

Systems and methods for improving cybersecurity using detection and response models and data valuation frameworks

A method can include determining, by one or more processing circuits, a cybersecurity resilience posture of an entity. The method can include identifying or generating, by the one or more processing circuits, at least one token comprising a proof or a posture state corresponding with the cybersecurity resilience posture of the entity. The method can include determining, by the one or more processing circuits using a cyber threat intelligence (CTI) model, at least one of a quantitative value or a qualitative value corresponding to the at least one token. The method can include updating, by the one or more processing circuits, a cybersecurity profile of the entity corresponding to at least one protection product.
Owner:AS0001 INC

A method for generating network threat rules based on threat intelligence

The present invention relates to a method for generating network threat rules based on threat intelligence, and relates to the field of network security. This application crawls open-source network threat intelligence; uses image analysis prompts to guide a multi-modal language model to convert image-based open-source network threat intelligence into text-based; unifies the content format to obtain initial network threat intelligence; uses a language model to assist in filtering the initial network threat intelligence; an agent uses a voting method to identify the first type of entity and the second type of entity from the filtered network threat intelligence and establish a connection; uses Sigma rules to create prompts to control the agent to create Sigma rules based on the associated first type of entity and the second type of entity extracted from the network threat intelligence block in the filtered network threat intelligence block; uses Sigma rules to optimize prompts, and Sigma rule verification prompts control the language model used by the agent to optimize and verify the generated Sigma rules.
Owner:JIANGSU RUINING XINCHUANG TECH CO LTD

Distributed Cyber Threat Intelligence Platform

Techniques are described herein for providing a distributed cyber threat intelligence platform. An example system includes a set of cyber threat intelligence content stored on a distributed ledger accessible by one or more nodes. The example system further includes an artificial intelligence (AI) engine configured to: receive a node input from a new device indicating a node type to be established for the new device, generate one or more responses to the node input, and establish a new node for the new device on the distributed ledger that corresponds to the node type. The example system further includes a smart contracts engine configured to: receive, from the new node, a second input associated with cyber threat intelligence, store the second input in the distributed ledger as part of the set of cyber threat intelligence content, and transmit the second input to the one or more nodes.
Owner:TEACHERS INSURANCE & ANNUITY ASSOC OF AMERICA

Electric power information network multi-source threat intelligence analysis method, system, device and medium

The invention relates to the technical field of power information network threat intelligence analysis, and provides a power information network multi-source threat intelligence analysis method, system and device and a medium, and the method comprises the steps: obtaining to-be-analyzed multi-source threat intelligence data of a power information network; performing attack entity relationship extraction analysis on the text intelligence data according to a preset attack entity data model and a preset entity association mode table to generate an attack reconstruction main graph; carrying out attack entity relationship extraction analysis on the attack vulnerability codes based on a preset code large model and an attack entity retrieval database to generate a plurality of attack reconstruction sub-graphs; and combining the attack reconstruction main graph and the attack reconstruction sub-graphs to generate a target attack reconstruction graph. According to the method, an attack entity relationship extraction mechanism based on a unified attack entity data model is combined with a multi-source attack graph reconstruction mechanism, so that the accuracy and comprehensiveness of attack entity recognition are improved, the reliability of threat detection and attack tracing is ensured, and the security defense capability of the electric power information network is improved.
Owner:STATE GRID ZHEJIANG ELECTRIC POWER CO LTD HANGZHOU POWER SUPPLY CO

Artificial intelligence for cyber threat intelligence

A system includes a processing device, operatively coupled to memory, to receive a prompt that is associated with a potential security threat on a computer network. The system applies a first large language model (LLM) to the prompt to generate a first instruction that is associated with a first agent that is to handle the first instruction, and routes the first instruction to the first agent. The first agent applies a second LLM in association with a first data source to obtain a first data that is associated with the potential security threat. The system applies a third LLM at least to the first data, to generate a data output that is associated with the potential security threat on the computer network.
Owner:FORESCOUT TECHNOLOGIES INC

Cyber threat detection based on threat context, threat changes, and / or impact status

Aspects described herein may relate to cyber threat detection based on threat context and / or threat changes. Cyber threat intelligence (CTI) data may be received from a CTI provider. Endpoint data that indicates evidence that endpoints are cyber threats may be determined based on the CTI data. The endpoint data may be analyzed and / or compared to stored data associated with the endpoint. The analysis and / or comparison may be performed to determine whether evidence that the endpoint is a cyber threat has changed. Based on any changes, dispositions for the endpoint may be determined and sent. The dispositions may change how devices filter network traffic associated with the endpoint. Alternatives to default dispositions may be determined based on a impact of blocking potentially legitimate network traffic to and / or from the endpoints. Machine-learning models may assist in processing and analyzing CTI data, performing threat monitoring, and / or determining feeds that include the dispositions.
Owner:CENTRIPETAL NETWORKS INC

System and method for generating cyber threat intelligence

The present disclosure provides a system for generating cyber threat intelligence. The system includes a plurality of honeynets configured to emulate one or more services; a plurality of sensors, each sensor associated with a honeynet, each sensor configured to detect cyberattacks on the associated honeynet; a data collector configured to receive data relating to the cyberattacks on the plurality of honeynets; and a computing device configured to detect, from the sensors, one or more cyberattacks on the honeynets based on analysis of network traffic through the honeynets; extract, from detected cyberattacks on the honeynets, a detailed forensic data log based on analysis of content of the data packets pertaining to the cyberattacks on the honeynets; and transmit the detailed forensic data log to the data collector. The data collector stores the detailed forensic data log for further analysis in order to generate cyber threat intelligence.
Owner:WHIZHACK TECH PVT LTD

Network threat intelligence structured processing method and system based on artificial intelligence

The invention relates to the technical field of crossing of artificial intelligence and network security, in particular to a network threat intelligence structured processing method and system based on artificial intelligence. The method comprises the following steps: acquiring unstructured original threat intelligence and performing credibility evaluation on an intelligence source; based on a large language model and knowledge graph enhanced retrieval, a step-by-step analysis plan for original threat intelligence is generated; dynamically calling a tool to execute an information extraction subtask corresponding to each step in the analysis plan to obtain a preliminary extraction result; performing multi-dimensional confidence evaluation on the preliminary extraction result; and taking the preliminary extraction result with the confidence higher than or equal to a threshold as a final result, and outputting the final result in a formatting manner and updating the final result to the knowledge graph. According to the method, the problem that unstructured multi-mode threat intelligence is difficult to convert into structured data which is readable by a machine, self-consistent in logic and capable of being put into actual combat in the prior art is solved, and the improvement of attack chain understanding depth and integrity is realized.
Owner:DATA SPACE RES INST

Systems and methods for cyber threat detection based on new and / or updated cyber threat intelligence

Systems, methods, and apparatuses are described for detection and / or analysis of cyber threats based on updated cyber threat intelligence associated with cyber threats. Packet filtering output data such as logs of packet communications and / or copies of packets may be generated based on first cyber threat intelligence associated with a cyber threat. Updated criteria based on subsequent updated cyber threat intelligence may then be applied to the packet filtering output data.
Owner:CENTRIPETAL NETWORKS INC

Network threat analysis method and system based on learning evolutionary game

According to the network threat analysis method and system based on the learning evolutionary game provided by the invention, the expected benefit of sharing is analyzed through modeling, quantitative analysis is carried out by adopting the learning evolutionary game, and a reasonable incentive strategy is obtained, so that the sharing and utilization efficiency of network threat intelligence is promoted; each entity enterprise inquires from the open community to obtain the required threat intelligence, analyzes the threat intelligence and deploys own network defense measures, so that the network security defense capability is improved, and the problems that in the prior art, the capability of providing a large number of resources is difficult, the data sharing and exchanging capability is weak, and a large number of continuous network attacks are difficult to defend are solved.
Owner:北京国瑞数智技术有限公司

Efficient Threat Context-Aware Packet Filtering for Network Protection

A threat intelligence gateway (TIG) may protect TCP / IP networks from network (e.g., Internet) threats by enforcing certain policies on in-transit packets that are crossing network boundaries. The policies may be composed of packet filtering rules with packet-matching criteria derived from cyber threat intelligence (CTI) associated with Internet threats. These CTI-derived packet-filtering rules may be created offline by policy creation and management servers, which may distribute the policies to subscribing TIGs that subsequently enforce the policies on in-transit packets. Each packet filtering rule may specify a disposition that may be applied to a matching in-transit packet, such as deny / block / drop the in-transit packet or pass / allow / forward the in-transit packet, and also may specify directives that may be applied to a matching in-transit packet, such as log, capture, spoof-tcp-rst, etc. Often, however, the selection of a rule's disposition and directives that best protect the associated network may not be optimally determined before a matching in-transit packet is observed by the associated TIG. In such cases, threat context information that may only be available (e.g., computable) at in-transit packet observation and / or filtering time, such as current time-of-day, current TIG / network location, current TIG / network administrator, the in-transit packet being determined to be part of an active attack on the network, etc., may be helpful to determine the disposition and directives that may best protect the network from the threat associated with the in-transit packet. The present disclosure describes examples of methods, systems, and apparatuses that may be used for efficiently determining (e.g., accessing and / or computing), in response to the in-transit packet, threat context information associated with an in-transit packet. The threat context information may be used to efficiently determine the disposition and / or one or more directives to apply to the in-transit packet. This may result in dispositions and / or directives being applied to in-transit packets that better protect the network as compared with solely using dispositions and directives that were predetermined prior to receiving the in-transit packet.
Owner:CENTRIPETAL NETWORKS INC

Machine learning based cyber threat intelligence system and related methods

Methods and systems for network scanning activity detection are disclosed. The methods and systems include: obtaining darknet data from darknet monitoring sensors; applying the darknet data to a trained machine learning model; obtaining one or more labels of honeypot data corresponding to the darknet data based on the trained machine learning model; and provide a result of threat behaviors of internet protocols based on the one or more labels. Other aspects, embodiments, and features are also claimed and described.
Owner:THE PENN STATE RES FOUND INC +1

Network threat analysis method and system based on improved evolutionary game

According to the network threat analysis method and system based on the improved evolutionary game, shared expected benefits are analyzed through modeling, quantitative analysis is carried out through the learning evolutionary game, a reasonable incentive strategy is obtained, meanwhile, a user selects a game strategy through autonomous learning, returned incentive is corrected, and the network threat analysis efficiency is improved. Optimal screening of threat intelligence is realized, sharing and utilization efficiency of network threat intelligence is better promoted, network security defense capability is improved, and the defects that the prior art is lack of reinforcement learning capability, needs to depend on a large number of intelligence resources, can only passively receive incentives and intelligence returned by communities, and is poor in security defense capability are overcome. And protection and defense cannot be fully carried out according to the self condition maximization.
Owner:北京国瑞数智技术有限公司

Cyber threat detection based on threat context, threat changes and / or impact status

Aspects described herein may relate to cyber threat detection based on threat context and / or threat changes. Cyber threat intelligence (CTI) data may be received from a CTI provider. Endpoint data that indicates evidence that endpoints are cyber threats may be determined based on the CTI data. The endpoint data may be analyzed and / or compared to stored data associated with the endpoint. The analysis and / or comparison may be performed to determine whether evidence that the endpoint is a cyber threat has changed. Based on any changes, dispositions for the endpoint may be determined and sent. The dispositions may change how devices filter network traffic associated with the endpoint. Alternatives to default dispositions may be determined based on a impact of blocking potentially legitimate network traffic to and / or from the endpoints. Machine-learning models may assist in processing and analyzing CTI data, performing threat monitoring, and / or determining feeds that include the dispositions.
Owner:CENTRIPETAL NETWORKS INC

Methods and systems for efficient adaptive logging of cyber threat incidents

A packet-filtering network appliance such as a threat intelligence gateway (TIG) protects TCP / IP networks from Internet threats by enforcing certain policies on in-transit packets that are crossing network boundaries. The policies are composed of packet filtering rules derived from cyber threat intelligence (CTI). Logs of rule-matching packets and their associated flows are sent to cyberanalysis applications located at security operations centers (SOCs) and operated by cyberanalysts. Some cyber threats / attacks, or incidents, are composed of many different flows occurring at a very high rate, which generates a flood of logs that may overwhelm computer, storage, network, and cyberanalysis resources, thereby compromising cyber defenses. The present disclosure describes incident logging, in which a single incident log efficiently incorporates the logs of the many flows that comprise the incident, thereby potentially reducing resource consumption while improving the informational / cyberanalytical value of the incident log for cyberanalysis when compared to the component flow logs. Incident logging vs. flow logging can be automatically and adaptively switched on or off depending on the combination of resource consumption and informational / cyberanalytical value.
Owner:CENTRIPETAL NETWORKS INC

Training method and triple extraction method of network threat intelligence triple extraction model based on prompt enhancement and joint learning

The present invention discloses a training method for a network threat intelligence triple extraction model based on prompt enhancement and joint learning, and a triple extraction method, comprising: S1: constructing a question template; S2: constructing a decoder; S3: establishing a first mapping from labeled answer words to relationship labels and a second mapping from relationship labels to answer semantic words; predicting the probability that the relationship of an entity pair is a certain answer word; S4: inputting the hidden layer representation and the embedding vector of the learnable answer semantic word into the relationship prediction layer to obtain a prediction head; S5: selecting the answer word with the highest probability and mapping it to the relationship label according to the first mapping to obtain a predicted relationship; S6: calculating the total loss; S7: performing pre-training; and S8: training the model using a training dataset to obtain a triple joint extraction model. By inputting network threat intelligence data into the model, relationship triples can be obtained. The present invention adopts a joint extraction framework to effectively solve the problem of lack of interaction between entity and relationship tasks.
Owner:GUANGZHOU UNIVERSITY

Adaptive encrypted system for analyzing cyber threat data using two-stage causal inference and homomorphic anomaly embeddings

An adaptive, encrypted data analysis system for cyber threats, consisting of: a secure data interface unit configured to receive cyber threat telemetry data originating from a variety of distributed computing resources, including network infrastructure devices, endpoint systems, cloud workloads, and application servers, wherein the received cyber threat telemetry data includes network interaction records, authentication activity data, process execution data, behavioral traces, and temporal event information, and wherein the cyber threat telemetry data is received in an encrypted state; a cryptographic coding unit that is operationally coupled with the secure data interface unit and is configured to transform the received encrypted cyber threat telemetry data into a variety of encrypted anomaly embedding representations by performing feature normalization, temporal alignment, and semantic coding operations prior to encryption, and is further configured to apply homomorphic encryption to generate ciphertext-based anomaly embeddings that preserve mathematical operability; a homomorphic anomaly inference processor that is operationally coupled with the cryptographic coding unit and is configured to perform encrypted analytical operations directly on the ciphertext-based anomaly embeddings, wherein the homomorphic anomaly inference processor is configured to compute encrypted deviation indicators that represent behavioral deviations from encrypted baseline profiles without performing any decryption at any stage of the computation; a first causal inference unit that is operationally coupled with the homomorphic anomaly inference processor and is configured to create encrypted local causal dependency representations by evaluating conditional relationships between encrypted anomaly embeddings corresponding to individual system components, user interactions, and execution contexts, thereby deriving causally attributable sources of detected anomalies; a second causal inference unit that is operationally coupled with the first causal inference unit and configured to aggregate encrypted local causal dependency representations across a variety of computing resources to derive encrypted global causal propagation representations that indicate coordinated or multi-stage cyber threat behavior spanning multiple system domains; an adaptive learning control unit operationally coupled with the cryptographic coding unit, the homomorphic anomaly detection processor, and the first and second causal inference units, wherein the adaptive learning control unit is configured to update encrypted baseline behavior profiles and encrypted causal dependency parameters based on validated threat findings while maintaining all learning operations within an encrypted computation domain; and a secure output control unit that is operationally coupled with the second causal inference unit and configured to generate cyber threat intelligence signals that include encrypted risk indicators, threat classification outputs, and response prioritization information, with the generated outputs excluding the disclosure of underlying plaintext cyber threat telemetry.
Owner:MUTHU SHANMUGAM SALEM +1

Large-scale exchange of cyber threat intelligence via routing protocols

The techniques described herein provide a transport mechanism for large-scale exchange of cyber threat intelligence between entities and / or within an entity. Cyber threats evolve rapidly, and entities face challenges in efficiently sharing threat intelligence at “network speed” and applying mitigations across their networks. Existing techniques lack scalability, real-time updates, and coordination among organizations. Moreover, there is no existing technique for large-scale exchange of cyber threat intelligence. Additionally identifying threat data is often performed manually and is subjective. The techniques described herein provide mechanisms that leverage BGP or other routing protocols to facilitate large-scale threat intelligence exchange and mitigation across entities in real-time. The techniques described herein enable entities, including cloud providers, internet service providers, and others, to collaboratively mitigate cyber threats by disseminating real-time confirmed and actionable threat intelligence across their networks.
Owner:CISCO TECHNOLOGY INC

Network threat intelligence sharing method and related device

The invention belongs to the technical field of network space security, and discloses a network threat intelligence sharing method and related device.The method comprises the steps that network threat intelligence is obtained and encrypted to obtain an intelligence ciphertext, the intelligence ciphertext is stored in a local server, and a hash value of the intelligence ciphertext is obtained and stored in a private chain; and obtaining a keyword of the network threat intelligence, generating an intelligence keyword index by using a searchable encryption method according to the keyword of the network threat intelligence, and storing the intelligence keyword index to the alliance chain. The local security and privacy of the network threat intelligence are realized based on encrypted storage and the block chain, and the network threat intelligence is prevented from being tampered locally. Meanwhile, the information keyword index is stored in the alliance chain to achieve keyword sharing, specific content of the network threat information is not disclosed, and the retrievability, the safety, the privacy and the non-tampering performance of the network threat information in sharing are achieved.
Owner:CHINA ELECTRIC POWER RESEARCH INSTITUTE CO LTD +3

Methods and systems for efficient network protection

Methods and systems are disclosed for integrating cyber threat intelligence (CTI), threat metadata, and threat intelligence gateways with analysis systems to form efficient and effective system for active, proactive, and reactive network protection. A network gateway may be composed of multiple stages. A first stage may include a threat intelligence gateway (TIG). A second stage may include one or more cyber analysis systems that ingest TIG-filtered communications and associated threat metadata signals. A third stage may include network protection logic that determines which protective actions. The gateway may be provisioned and configured with rules that specify the network protection policies to be enforced. The gateway may ingest all communications flowing between the protected network and the unprotected network.
Owner:CENTRIPETAL NETWORKS INC

Small sample named entity recognition method and system based on prompt learning

The invention provides a small sample named entity recognition method and system based on prompt learning, and belongs to the field of named entity recognition, and the method comprises the steps: S1, collecting a network threat intelligence report, and carrying out the preprocessing to obtain a corpus; constructing a vocabulary for pre-training a mask language model based on a corpus to obtain a pre-training model CTIBERT; s2, constructing a CTINER data set based on a corpus; s3, task prompts composed of identity prompts, background information and position prompts are constructed; s4, based on SBERT and Jaccard similarity, selecting a sentence with the closest similarity to the sequence X to be recognized from the CTINER data set for demonstration; and S5, inputting the task prompt, the SBERT, the Jaccard sentence demonstration and the to-be-identified sequence X into the named entity identification network together, and outputting a predicted entity tag. According to the method, the performance of the small sample named entity recognition model is improved.
Owner:CAPITAL NORMAL UNIVERSITY

Methods, systems, equipment and media for multi-source threat intelligence analysis of power information networks

This invention relates to the field of threat intelligence analysis technology for power information networks, and provides a method, system, device, and medium for multi-source threat intelligence analysis of power information networks. The method includes acquiring multi-source threat intelligence data to be analyzed from the power information network; extracting and analyzing attack entity relationships from the text intelligence data based on a preset attack entity data model and a preset entity association pattern table to generate an attack reconstruction master graph; extracting and analyzing attack entity relationships from the vulnerability code based on a preset code model and an attack entity retrieval database to generate several attack reconstruction sub-graphs; and merging the attack reconstruction master graph and the various attack reconstruction sub-graphs to generate a target attack reconstruction graph. This invention improves the accuracy and comprehensiveness of attack entity identification by combining an attack entity relationship extraction mechanism based on a unified attack entity data model with a multi-source attack graph reconstruction mechanism, ensuring the reliability of threat detection and attack tracing, and enhancing the security defense capabilities of power information networks.
Owner:STATE GRID ZHEJIANG ELECTRIC POWER CO LTD HANGZHOU POWER SUPPLY CO

Method and system for analyzing cybersecurity threats and improving defensive intelligence

Disclosed is a cyber threat intelligence platform configured to: a) designate a virtual machine as an attacker machine; b) designate a virtual machine as a victim machine; c) receive cyberattack data representative of a cyberattack executed by the attacker machine against the victim machine; e) receive defense action data representative of a defense action executed by the victim machine against the cyberattack; f) mark a first point in time when the cyberattack is executed, and mark a second point in time when the defense action is initiated; g) compare the first point in time with the second point in time to ascertain an attack-defense time lapse as a performance measure for computer system threat management of cyberattacks or defense actions, and h) view or analyze cyberattack and defense actions for effectiveness, including perspectives derived from the relative timing of the actions as indicated on the time lapse.
Owner:THREATOLOGY INC

Network threat intelligence analysis system based on Agent RAG and knowledge graph

The invention relates to the technical field of network security, and provides a network threat intelligence analysis system based on Agent RAG and a knowledge graph, and the system comprises a security scene recognition module which is used for outputting a judgment result whether the judgment result can be executed or not; the intention recognition module is used for screening associated fields from the threat knowledge field list; the retrieval enhancement module is used for fusing and generating a structured retrieval result set; the task planning module is used for planning and generating a task execution chain comprising at least one subtask; the task execution module is used for calling a large language model to perform reasoning and information integration and outputting an initial analysis result; and the security back-off module is used for triggering a corresponding security back-off strategy and generating a final analysis result. According to the method, an intelligent analysis framework fusing an Agent dynamic RAG closed loop, a multi-layer semantic knowledge network and a full-process security bottom-taking mechanism is constructed, so that deep semantic understanding of network threat intelligence is realized.
Owner:GUANGZHOU UNIVERSITY

Method for detecting and predicting cyber threats in industrial environments

The invention relates to a method for detecting and predicting cyber threats in industrial environments using cyber threat intelligence (CTI), comprising: I) identifying threats (200) and classifying same through the analysis of TTP measures and IOC / IOA indicators, including a basic and advanced CTI process for unidentified known / similar threats and zero-day vulnerabilities; ii) identifying trends and campaigns (300), detecting patterns and repeated events, analysing attack behaviours and characteristics in order to predict trends and campaigns directed towards specific devices, industrial sectors or clients; iii) generating dictionaries updated with remote access attempts in order to analyse data used in attacks; and iv) generating use cases in order to manage incidents, anticipating changes to known threats. The method is based on multilevel modelling (L1, L2,..., Ln): the input (11) from a threat capture system feeds to a basic CTI (12) at the first level, resulting in initial information (21), relating to both attackers and threats (22), which is input into the advanced CTI (23) at the next level and so on until the last one, in order to obtain the final information (30) relating to cyber attacks and attackers.
Owner:TELEFONICA CYBERSECURITY & CLOUD TECH S L U