Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

414 results about "Event correlation" patented technology

Event correlation is a technique for making sense of a large number of events and pinpointing the few events that are really important in that mass of information. This is accomplished by looking for and analyzing relationships between events.

Early warning method and system for operation and maintenance delivery abnormal event based on cloud platform

The invention discloses an operation and maintenance delivery abnormal event early warning method and system based on a cloud platform, and relates to the technical field of event early warning. The method comprises the steps of collecting a real-time operation data set of an operation and maintenance delivery link, performing multi-dimensional analysis based on the real-time operation data set, and constructing a multi-dimensional monitoring data set; performing context correlation analysis on the multi-dimensional monitoring data set, and constructing dynamic baseline parameters; deviation degree calculation is carried out on the real-time operation data set, a data deviation value is generated to trigger the cloud platform to carry out abnormal event judgment of operation and maintenance delivery, and an abnormal judgment result is obtained; performing event association according to an abnormality judgment result, determining an abnormality risk level, synchronizing the abnormality risk level to a cloud platform for tracing, generating a multi-level early warning instruction, and pushing the multi-level early warning instruction to a target terminal for graded warning. The technical problem that early warning of the operation and maintenance delivery event is not accurate and timely enough in the prior art is solved, and the technical effect of improving the accuracy and timeliness of early warning of the abnormal event is achieved.
Owner:WUXI LANSHAN INFORMATION TECH CO LTD

Language model collaborative target event processing method and device, equipment and medium

The invention relates to the technical field of artificial intelligence, can be applied to business scenes such as financial science and technology and medical health, and discloses a target event processing method, device, equipment and medium based on language model collaboration.The method comprises the steps that a target event is monitored and recognized, multi-source data associated with the target event are collected, the multi-source data are fused to generate fused data, and the fused data are sent to a server; and inputting the fusion data into a pre-training language model to generate a decision scheme, performing decision coordination and matching based on the decision scheme, distributing a processing agent, executing a matched decision task by using the processing agent, and generating a decision result. According to the invention, through fusion of multi-source data and pre-training language model deep reasoning and combination of an intelligent agent dynamic cooperation mechanism, intelligent perception, rapid response and cooperative processing of complex events are realized, and the adaptive ability and processing efficiency of the system in response to unknown faults and complex tasks are improved.
Owner:PING AN TECH (SHENZHEN) CO LTD

Automatic template generation method and system based on UG software

The invention belongs to the technical field of intelligent manufacturing and automatic design optimization, and discloses an automatic template generation method and system based on UG software, and the method comprises the steps: capturing a sketch operation event flow, carrying out the deep binding of geometric parameters and tolerance rules, generating a technology enhancement parameter set, and constructing a dual-channel instruction set; synchronously generating a two-dimensional engineering drawing projection and a three-dimensional expansion drawing preview; detecting conflicts in real time, and calling an exception correction plan library for dynamic correction; generating a zero-conflict BREP boundary model and a correction track log, and establishing a log-plan library mapping relation; generating an enhanced BERP model through a template drawing optimization mechanism; further generating a processing path instruction set, and integrating the processing path instruction set into a process compliance template drawing package; generating a cross-platform manufacturing package; constructing a quality index set, and generating an abnormal event association graph; and calculating a rule parameter adjustment amount, dynamically updating the process rule base, generating a global strategy packet, and reversely injecting sketch parameter constraints to form a continuous optimization cycle.
Owner:河北鑫泰轴承锻造有限公司

Security event association analysis and question and answer method and system and medium

The invention provides a security event association analysis and question answering method and system and a medium, and the method comprises the following steps: context-aware query completion: receiving an original query input by a user, obtaining a historical record of a current dialogue, and forming a context enhanced query according to the original query and the historical record of the current dialogue; dynamic task identification: outputting a prediction task model according to the context enhancement query in combination with a dynamic task identification strategy; multi-dimensional retrieval: performing multi-dimensional retrieval on the prediction task model to obtain a final knowledge context packet; and knowledge-driven response generation: generating a knowledge-driven response based on the knowledge context packet, and outputting a final security analysis report after the generated content passes verification. According to the method, efficient, accurate and explainable intelligent association analysis of the multi-source heterogeneous security data is realized by constructing a multi-dimensional knowledge base, designing a dynamic task recognition mechanism and realizing context-aware query completion.
Owner:HARBIN INSTITUTE OF TECHNOLOGY (SHENZHEN) (INSTITUTE OF SCIENCE AND TECHNOLOGY INNOVATION HARBIN INSTITUTE OF TECHNOLOGY SHENZHEN)

Electricity consumption information acquisition intelligent configuration method based on pattern recognition algorithm

The invention discloses an electricity utilization information acquisition intelligent configuration method based on a pattern recognition algorithm, and relates to the technical field of intelligent power grids, and the method comprises the steps: collecting a directional data stream, inputting a federal map neural network to construct a power distribution network physical connection relation, and generating a spatio-temporal topological feature vector; extracting a current effective value component of the directional data flow as an electrical load sequence, extracting an equipment state code to identify a voltage sag event, injecting voltage sag event associated disturbance into the electrical load sequence in combination with an event propagation path weight of a spatio-temporal topological feature vector, and generating an anti-fact sample set; and compressing the new configuration strategy through a knowledge distillation engine, and outputting an event response logic and a parameter adjustment instruction to form an executable configuration strategy. According to the method, through anti-fact sample generation and reinforcement learning optimization under spatial-temporal topological feature vector constraint, a physical rule deep embedding decision is realized.
Owner:HANGZHOU HUALONG ELECTRONIC TECH CO LTD

Intelligent prediction method and system applied to system log security audit

The invention provides an intelligent prediction method and system applied to system log security audit, and the method comprises the steps: firstly obtaining a historical log data set of a power monitoring system, carrying out the event correlation modeling, generating a log event correlation model, generating a security event prediction rule library based on the log event correlation model through a rule mining algorithm, and carrying out the prediction of the security event. And then obtaining a real-time log data stream, inputting the log event association model to obtain a real-time event association result, matching the real-time event association result with the rule base to generate an abnormal event prediction result, finally generating a security audit report according to the abnormal event prediction result, sending the security audit report to the power monitoring terminal, and updating rule base parameters according to feedback information. Therefore, the abnormal event in the power monitoring system can be predicted in advance, and the intelligent level and the safety guarantee capability of system safety auditing are improved.
Owner:XINYUAN NETWORK TECH CO LTD

Grassroots social governance intelligent decision support system and method based on multi-modal fusion

InactiveCN120746326AData processing applicationsSemantic analysisIntelligent decision support systemDecision making support systems
The invention discloses an intelligent decision support system and method for grassroots social governance based on multi-modal fusion. The method comprises the following steps: S1, acquiring and preprocessing multi-modal data in the field of grassroots social governance; s2, constructing a heterogeneous graph structure according to the data type and the treatment subject category; s3, extracting single-modal features respectively and generating cross-modal dynamic association features; s4, performing collaborative optimization on the heterogeneous graph structure and the cross-modal fusion parameters by adopting a flying fox optimization algorithm; s5, analyzing data in real time according to the optimized heterogeneous graph, and generating potential risk early warning, event trend prediction and event association deduction information; s6, pushing an auxiliary decision-making scheme and a disposal strategy in real time; and S7, continuously optimizing the heterogeneous graph structure by using a feedback result. The decision-making efficiency and accuracy of grassroots social governance are effectively improved.
Owner:INNER MONGOLIA GUOFENG NETWORK TECHNOLOGY CO LTD

User behavior tracking and portrait generation system

The invention provides a user behavior tracking and portrait generation system, which is characterized in that multi-source original behavior data is acquired through a data acquisition module, and a standard behavior event stream is generated through cleaning and standardization; the behavior modeling module is used for carrying out cross-event association and self-defined time window combination modeling on a standard event flow based on a configurable rule engine to generate a complex event flow; the real-time processing and calculation module performs real-time aggregation calculation on the complex event stream, generates a real-time behavior index, a trigger signal and an incremental portrait snapshot in combination with a preset rule, and pushes a behavior trigger signal to a downstream service system; the user portrait management module dynamically updates user tag weights and values according to the real-time indexes, and generates a target user portrait tag library and a lightweight tag change event stream; the data storage and query module stores data of each link; and the visual configuration and operation and maintenance module issues a configuration instruction through a visual interface, and monitors full-link operation and task scheduling. And real-time accurate portrait construction and instant service response are realized.
Owner:DIGITAL HAINAN CO LTD

Credit investigation management system, credit investigation management method and equipment based on cloud edge collaboration

The invention provides a cloud edge collaboration-based credit investigation management system, a credit investigation management method and equipment. The credit investigation management system comprises an edge node and a central management and control device. The edge node obtains credit behavior data generated when the user executes the target event, and inputs the credit behavior data, event associated data corresponding to the target event and a historical credit score of the user into a credit evaluation model deployed in the local of the edge node in advance, obtaining a credit score increment output by the credit evaluation model after the user executes the target event; the credit score increment is uploaded to a central management and control device; and the central management and control equipment updates the historical credit score according to the received credit score increment to obtain the latest credit score of the user, and sends the latest credit score to the edge node so as to replace the local historical credit score of the edge node through the latest credit score.
Owner:QIANTANG CREDIT INFORMATION CO LTD

Event attribution convergence method and device, equipment and medium

The invention relates to the technical field of artificial intelligence, can be applied to business scenes such as machine room monitoring, financial science and technology and medical health, and discloses an event attribution convergence method, device and equipment and a medium. Analyzing and generating an attribution parameter table containing attribution parameters and probability values by utilizing a pre-training language model, analyzing concurrency and association convergence conditions of event data pairs to generate association degrees among events, dynamically updating the attribution parameter table according to the association degrees, receiving to-be-processed event data, judging whether the to-be-processed event data exist in the attribution parameter table or not, and if yes, executing the next step; and if yes, executing hierarchical convergence judgment and executing convergence or release, and if not, executing model-assisted convergence and executing convergence or release. According to the method, automatic extraction and dynamic updating of the attribution parameters are achieved by combining the historical convergence data and the pre-training language model, the convergence mode is selected according to the matching condition, the event association recognition accuracy and convergence processing adaptivity are improved, and the processing efficiency is improved.
Owner:PING AN TECH (SHENZHEN) CO LTD

Data flow supervision method and system

The invention relates to the technical field of data processing, and provides a data flow supervision method and system.The method comprises the steps that log data and safety data of different systems are collected, various risk key features related to risk events are obtained through analysis, multi-dimensional risk event correlation analysis is conducted, risk links corresponding to the risk events are constructed, and the risk events are monitored; performing risk assessment calculation on each risk link, determining a risk level of each risk link, and identifying a collaborative risk behavior; and on the basis of the obtained feature matching calculation result, the obtained semantic matching analysis result and the case quality score of each candidate case obtained by matching, performing comprehensive evaluation on each candidate case matched with the to-be-identified event, and determining a final candidate case. According to the invention, the risk event identification precision is improved.
Owner:CHINA UNICOM ONLINE INFORMATION TECHNOLOGY CO LTD

Heterogeneous database synchronization method and device, electronic equipment and storage medium

The invention relates to a heterogeneous database synchronization method and device, electronic equipment and a storage medium, and the method comprises the steps: analyzing a transaction log of a source database, extracting and generating an abstract syntax tree of a DDL event, and carrying out the node-level syntax conversion of the abstract syntax tree according to the database type of a target database and a preset syntax mapping rule base, and obtaining an equivalent DDL operation sequence of the target database, blocking a data processing operation corresponding to the database object associated with the DDL event, and executing the equivalent DDL operation sequence on the target database. The whole-process intelligent processing of the isomerous database DDL is realized without depending on manpower, the equivalent DDL operation sequence of the target database having semantic consistency with the DDL event of the source database is obtained through dynamic replenishment and deep analysis of the DDL event and the context semantics of the DDL event in combination with the grammar mapping rule base, the processing efficiency of isomerous database DDL synchronization is improved, and the processing efficiency of isomerous database DDL synchronization is improved. And meanwhile, the safety and reliability of synchronous processing can be ensured.
Owner:JINZHUAN INFORMATION TECHNOLOGY CO LTD

Reactor turn-to-turn short circuit monitoring method fusing magnetic field difference method and loss factor method

The invention relates to the technical field of electromagnetic data processing, in particular to a reactor turn-to-turn short circuit monitoring method fusing a magnetic field difference method and a loss factor method. According to the method, a plurality of event pairs are constructed by adopting an event correlation method, fundamental decoupling of fault features of thermal response and normal working condition fluctuation is realized by comparing differences between event response features and standard event response features corresponding to working condition data, and dynamic thermal response deviation is obtained. Two-dimensional diagnosis features are mapped into a parameter space by using a parameter space method, so that the position of a mapping point represents the dynamic trend of a fault, tracking is carried out based on the position, a future state can be determined in advance based on the trend before a fault result occurs, and the problem of monitoring time lag is solved. And an effective fusion diagnosis result is obtained for reference of workers.
Owner:UHV CO OF STATE GRID HEILONGJIANG ELECTRIC POWER CO LTD

Urban public security risk chain identification method and system based on graph neural network

The invention provides an urban public security risk chain identification method and system based on a graph neural network, and relates to the technical field of public security risk management.The method comprises the steps that an event association topological graph is constructed, and an optimal sampling path is determined by adopting a self-adaptive two-way jump sampling algorithm; identifying logic breaking points, searching potential transition events to construct a complete risk chain, and finally calculating credibility scores based on conduction strength characteristics to screen the risk chain. According to the invention, the implicit association in the risk chain can be automatically found, the risk early warning precision is improved, and a scientific basis is provided for urban public safety management decisions.
Owner:HANGZHOU ZHUIXING VIDEO TECH CO LTD

Network security event association detection method based on big data analysis

The invention relates to the technical field of information security, in particular to a network security event association detection method based on big data analysis. Comprising the following steps: data acquisition; feature extraction and fusion; correlation detection is carried out, wherein an improved Apriori-Bayesian fusion algorithm is adopted, and discretization processing is carried out on the event feature vectors; mining a frequent item set by using an improved Apriori algorithm; and risk assessment and result output. According to the method, an improved Apriori-Bayesian fusion algorithm is adopted, discretization processing is carried out on event feature vectors according to types, meanwhile, a security event weight factor is introduced to calculate the item set weighted support degree, and a minimum support degree threshold value is dynamically adjusted to mine a frequent item set; the association confidence coefficient is calculated in combination with the Bayesian network, and the confidence coefficient is corrected through the space-time association coefficient, so that the association relationship between the network security events can be scientifically judged, the problems of limited association judgment accuracy and lack of quantitative correction in the traditional technology are solved, and the association false alarm and missing report probability is reduced.
Owner:STATE GRID INFORMATION & TELECOMM BRANCH

Video processing method and system based on big data technology

The invention discloses a video processing method and system based on a big data technology, and constructs an intelligent video processing system with semantic driving, man-machine collaboration and continuous evolution by fusing advanced technologies such as big data processing, bimodal AI analysis, knowledge graph, natural language understanding and feedback learning. Compared with a traditional video monitoring system, the scheme has the advantages that the retrieval efficiency, the semantic understanding depth, the event association analysis capability, the user interaction experience, the system self-optimization capability and the like are remarkably improved, and the problems of incomplete seeing, difficulty in finding, inaccuracy in judgment and poor use are effectively solved.
Owner:HANGZHOU LINPIN SECURITY TECH CO LTD

Network security alarm intelligent identification method and device

The invention discloses a network security alarm intelligent identification method and device, and relates to the technical field of network security alarm identification, and the method comprises the steps: carrying out the preprocessing of original data from network traffic, log files, user behavior records, a firewall and an intrusion detection system, and obtaining a multi-dimensional security event data set; node modeling and edge relation modeling are carried out based on a GNN and the multi-dimensional security event data set, and cross-system and cross-time-dimension security event association features are extracted to obtain a high-dimensional context sensing feature vector set; a time sequence anomaly detection model is constructed based on a high-dimensional context sensing feature vector set and a time sequence analysis technology, the high-dimensional context sensing feature vector set is input into the time sequence anomaly detection model, and weighting calculation is performed on each time step by extracting time dependent features and combining an Attention mechanism. Outputting an abnormal score vector corresponding to each time point; and constructing a behavior deviation function based on the multi-dimensional security event data in combination with deep learning data.
Owner:STATE GRID GANSU ELECTRIC POWER RESEARCH INSTITUTE

Cross-layer security event real-time association and attack path tracing method, system and equipment based on unified entity atlas

The invention discloses a cross-layer security event real-time association and attack path tracing method, system and device based on a unified entity atlas. The method comprises the following steps: step 1, constructing and dynamically maintaining the unified entity atlas; step 2, real-time event association based on graph calculation; step 3, automatic tracing of a bidirectional attack path; according to the method, data islands are broken through unified entity maps and cross-layer entity alignment fusion, a global entity view covering multiple levels is formed, and the integrity and accuracy of attack cognition are greatly improved; real-time processing of data access, atlas updating and event association is realized based on a streaming architecture, cross-layer attack signs can be captured in time, and the average detection and response time is remarkably shortened; an attack chain is automatically reconstructed through an automatic two-way traceability mechanism, a potential transverse movement path is analyzed, manpower is liberated, and the emergency response threshold and cost are reduced; abnormality is identified through entity behavior association, dependence on a fixed rule base is avoided, and the potential of resisting unknown threats is achieved.
Owner:北京国御网络安全技术有限公司

API security monitoring and analysis system

The invention relates to the technical field of API monitoring, and discloses an API security monitoring and analysis system. The system comprises an acquisition module used for acquiring and preprocessing inbound and outbound traffic of an API gateway to obtain normalized API call data; the feature extraction module is used for extracting API behavior features and API structure features; the establishing module is used for establishing an API behavior security baseline and an API structure security baseline; the anomaly detection module is used for carrying out two-dimensional anomaly detection and generating an abnormal event record; and the generation module is used for carrying out security event association analysis based on the abnormal event record and generating an API security event report and a defense strategy. The method ensures the reservation of complete API interaction details, solves the problem of fuzzy security event reconstruction, and can effectively cope with continuously changing API security threats.
Owner:深圳华科讯通科技有限公司

Event correlation analysis and early warning system of security information management platform

The invention discloses an event association analysis and early warning system for a security information management platform, and the system comprises an event identifier generation module, an event feature association module, an abnormal event discrimination module, an early warning response execution module, and an early warning triggering module, a data storage module and a behavior verification module. The event identifier generation module determines the association importance in combination with the event emergency level, the type label and the occurrence frequency, and generates a unique identifier; the event feature association module integrates initial, stage and continued feature acquisition values, and compares the values with a reference to form a result; the abnormal event judgment module determines an abnormal monitoring quantity by analyzing a state and the like, and identifies abnormal associated information; and the early warning response execution module optimizes a response path based on a multi-dimensional model in combination with the association importance and historical data. The system improves event identification accuracy, feature association comprehensiveness and the like, and is suitable for security and protection information management.
Owner:GUANGDONG MINGKONG TECH CO LTD

User health data intelligent acquisition and management system based on data analysis

The invention relates to the technical field of health information processing, and particularly discloses a user health data intelligent acquisition and management system based on data analysis, which performs event analysis and standardized coding on original health data to generate a user-level standardized event sequence; automatically constructing a causal structure network representing the causal relationship between the event types by analyzing the time delay dependence between the event types and executing a conditional independence test; further, instantiating a specific event into a node according to the causal network and a personal event sequence, establishing an edge with tense and causal composite attributes, and constructing a personalized event association network; performing data completion and prediction through multi-hop attribute propagation and multi-path evidence aggregation based on the network, and outputting a result with confidence evaluation; and dynamically optimizing the network by using a high-confidence result, and analyzing an influence propagation path of a key event to generate a personalized health analysis conclusion.
Owner:JIANGXI ANYIJIA AGRICULTURAL TECHNOLOGY CO LTD

Information security detection method

The invention relates to an information security detection method, and belongs to the technical field of information security. The detection method comprises the following steps: collecting network data of a target system and host behavior logs to construct a basic data set; extracting characteristics such as a communication mode and a system call sequence from the data set and standardizing; a multi-source log is fused through a time synchronization mechanism and an event association algorithm, and a behavior association relationship is constructed; performing anomaly detection on the behavior sequence by using a deep learning model, and outputting a quantitative anomaly score; a multi-dimensional verification mechanism is triggered based on a detection result, automatic processing or manual rechecking is achieved, integrity is ensured in combination with a data mirror image and an agent program, and the problems of data one-sidedness and the like of a traditional method are solved.
Owner:ZHONGGONG GAOYUAN (BEIJING) AUTOMOBILE TESTING TECH CO LTD

Data processing method and system based on network security service

The invention provides a data processing method and system based on network security service, relates to the technical field of network data security processing, and realizes structured expression and behavior extraction of potential threats in encrypted communication by establishing a new data structure and behavior association model. By introducing a context causal chain modeling mechanism, associating the originally isolated security events into a complete attack path; by establishing a set of event grading mechanism based on comprehensive scoring of service criticality, response cost and attack propagation path, threat processing does not distribute resources blindly and averagely, but performs intelligent scheduling according to priority, so that the resource utilization efficiency is improved; a structured and executable defense instruction or blocking strategy can be generated according to an analysis result, man-machine cooperation or full-automatic response is supported, and response efficiency and strategy adaptability are remarkably improved. And a set of intelligent data processing solution which is oriented to a network security service practical application scene and has high availability and high expansibility is constructed.
Owner:HUBEI JINCHU NETWORK TECH

System and method of advanced event ranking and correlation for threat detection

Systems and methods for advanced event ranking and correlation for threat detection. A method includes real-time processing of events with stateful threat detection, combining immediate detection capabilities with sophisticated threat analysis. A method further includes multi-stage processing in a detection engine, where generic events from endpoint detection and response (EDR) agents are scored and enriched to provide extended context based on machine learning models for event scoring, enriched events correlation, and applying security rules to detect threats.
Owner:ACRONIS INT

Fault diagnosis method and device, electronic equipment and storage medium

The invention relates to the technical field of vehicles, and discloses a fault diagnosis method and device, electronic equipment and a storage medium, the fault diagnosis method comprises the following steps: after a vehicle triggers a fault event, obtaining abnormal detection data and driving scene data associated with the fault event in the operation process of the vehicle; analyzing the correlation between the abnormal detection data and the driving scene data to obtain a correlation analysis result; fault diagnosis is conducted on the vehicle based on the correlation analysis result and historical associated data, a fault diagnosis result corresponding to the fault event is obtained, and the historical associated data is determined based on historical operation data of the vehicle and / or abnormal data of other vehicles when the fault event occurs. And potential safety hazards and maintenance cost of the vehicle are reduced.
Owner:ZHEJIANG GEELY HLDG GRP CO LTD +1

Construction data management system and method for intelligent building mechanical and electrical installation

The invention discloses a construction data management system and method for intelligent building mechanical and electrical installation, and relates to the technical field of intelligent construction, and the method comprises the steps: collecting the multi-source data of a construction site, carrying out the real-time analysis and matching, recognizing a disturbance event, and associating to a corresponding component of a BIM model and a construction plan target process; extracting resource information, calculating the influence of disturbance on subsequent processes, and generating a coupled digital twinborn model; progress and resource deviation analysis is carried out, the construction scheme change influence is simulated, and a comprehensive deviation report is output; calling a knowledge base historical scheme, generating a correction scheme in combination with a current resource state, simulating an implementation effect, and executing after examination and approval; and monitoring the execution of the correction scheme in real time, comparing the actual progress, updating the knowledge base and the BIM model, and forming reusable experience entries.
Owner:RUNXIN INTELLIGENT TECH CO LTD

Distributed environment multi-mode intelligent monitoring system

The invention discloses a distributed environment multi-modal intelligent monitoring system, which belongs to the technical field of environment monitoring and comprises a sensing node module, a sensing control module, a communication synchronization module, an acquisition fusion module, a data modeling module, a modal analysis module, a simulation maintenance module, a visual decision module and a safety protection module. According to the method, the time precision of cross-node data transmission and event association is ensured, network self-healing and continuous operation can be maintained when part of nodes fail or communication is interfered, long-term autonomous operation is realized, the maintenance cost is reduced, and a monitoring network can adapt to different working conditions and structure changes.
Owner:NANJING YIXINTONG CONTROL EQUIP TECH CO LTD

Geomechanical data visualization method, device, equipment and medium

The invention relates to a geomechanical data visualization method, device and equipment and a medium thereof. The method comprises the following steps: acquiring original data containing rock mass structural characteristics and temperature and humidity environmental parameters, and completing grid division and load and displacement constraint boundary condition setting by adopting finite element analysis to obtain a rock mass stress distribution model; core mechanical parameter evolution of rock mass at different time nodes is simulated based on the model, and a dynamic stress distribution sequence is generated; identifying and marking stress overrun potential event association points through a threshold value, extracting a key time-space change trend, and inputting the key time-space change trend into the time-space dynamic model to obtain a risk prediction distribution diagram containing a risk level, a coverage range and an occurrence probability; and constructing a three-dimensional dynamic view by adopting visual rendering, analyzing a mechanical parameter full-cycle evolution path and geological event association mode, and outputting a three-dimensional dynamic result integrating multi-dimensional information. According to the method, the problems of static data presentation and event association deficiency in the traditional technology can be solved, and the scientificity and the high efficiency of geological engineering analysis are improved.
Owner:NORTH CHINA UNIV OF WATER RESOURCES & ELECTRIC POWER

Tracking, evaluating, and improving responses to malicious threats in a network security system

Disclosed are systems and methods for identifying threat events in an enterprise network and managing detection rules and responses to the events. A threat intelligence computer system can receive information about a detected threat event including a phase of attack and a detected domain of the threat event, apply at least one tag to the detected event that associates the event with at least one of the rules triggered in response to detecting the event, evaluate the tagged rules against the information, flag the event as having an improvement opportunity, determine whether the rule tagged to the event is a candidate for improvement, generate, based on the determination, instructions for improving the rule, generate a prioritization scheme indicating an order to address the instructions to improve the rule amongst instructions to improve various threat detection rules, and generate and return output indicating the prioritization scheme for presentation at user devices.
Owner:TARGET BRANDS INC

Cyber security system to enrich the analysis of a cyber security incident

A clustering foundational AI model analyzes for, collects data about, and then outputs the role and / or function of an entity in a network and / or in an organization. The clustering foundational AI model clusters data together so that similar roles and / or functions can be readily identified to supply additional contextual information about the entity involved in the alert and / or event, and then outputs the role and / or function for the entity associated with the alert and / or event to assist in an investigation. The clustering foundational AI model adds the additional contextual information about the role and / or function of the entity upon receiving the alert and / or event. A UI receives the additional contextual information about the role and / or function of the entity in the network and / or organization and then presents both the alert and / or event and the additional contextual information that allows a user to gain contextual information about the alert and / or event.
Owner:DARKTRACE HLDG LTD