Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

991 results about "Event data" patented technology

Event data is a synonym to an audit trail. Modern computer software applications and IT infrastructure have adopted the term event data over audit trail. Events are typically recorded in logs and there is no standard for the format of event type data. Examples of the use of this new term to describe audit trails are becoming more common and the term is cited in the documentation of the Microsoft Event Viewer which provides visibility into events in the following logs: Application log, security log, System log, Directory service log, File Replication service log and DNS server log.

Real-time video analysis method based on deep learning

The invention relates to the technical field of computer vision, and discloses a real-time video analysis method based on deep learning. The method comprises the following steps: acquiring a real-time video stream through image acquisition equipment, and performing frame segmentation processing to generate a continuous video frame sequence; and extracting features of the video frame sequence by using a pre-trained convolutional neural network to obtain a multi-dimensional feature vector, inputting the multi-dimensional feature vector into the time sequence analysis model to calculate dynamic relevance, and outputting an inter-frame movement track and object behavior features. And constructing a scene understanding map containing a spatial position and a time evolution relationship according to the above-mentioned data, and carrying out abnormal event detection and generating event marking data based on the map. And performing semantic analysis on the event marking data, determining an abnormal event type and a confidence score, triggering a real-time alarm signal according to a result, and updating a historical event database. In the analysis process, the resource occupancy rate of the system is continuously monitored, the calculation precision is dynamically adjusted, a degradation processing mechanism is started when a preset threshold value is exceeded, and key area analysis is preferentially guaranteed.
Owner:HANGZHOU SIYUAN INFORMATION TECH CO LTD

Dynamic path optimization method based on response time domain attenuation

The invention discloses a dynamic path optimization method based on response time domain attenuation, and relates to the technical field of artificial intelligence and intelligent path planning, and the method comprises the steps: generating a node network composed of navigation points, terrain units or interaction regions, and forming a node network topology structure; generating a dynamic state feature set used for describing game scene changes, and forming input data used for follow-up node priority dynamic adjustment; converting the dynamic state feature set into node-level standardized event data, and distributing the node-level standardized event data to a node state management module through an event bus; setting a current node priority for each node in a node state management module based on the node-level standardized event data; forming a time domain attenuation model of the node priority; the priority recovery coefficient is improved; in the path planning stage, executing a dynamic path search algorithm to generate a passing path with the minimum total cost and the optimal path smoothness; when it is detected that player operation or scene change causes node response mutation, a local re-planning mechanism is triggered, smooth path transition is achieved, and overall jumping is avoided. According to the method, the problems of path congestion, frequent switching and unsmoothness caused by lack of dynamic node state and event response calculation in the prior art are solved. Through node priority time domain attenuation and dynamic path optimization, the technical effects of smooth path, efficient passing and node load balancing are achieved.
Owner:NETLIHENG TECHNOLOGY DEVELOPMENT (BEIJING) CO LTD

Operation and maintenance service automation safety compliance detection system and method

The invention relates to the technical field of operation and maintenance safety compliance, and discloses an operation and maintenance service automation safety compliance detection system and method. The system comprises an operation and maintenance event acquisition unit, a strategy execution unit, a compliance analysis unit, a strategy optimization unit and a violation tracing unit. The operation and maintenance event acquisition unit captures operation and maintenance operation events and execution environment parameters in real time, packages the operation and maintenance operation events and the execution environment parameters into event data packets and transmits the event data packets to the strategy execution unit; the strategy execution unit extracts a reference strategy rule from the security strategy library, performs matching verification on the event and generates a result; the compliance analysis unit analyzes compliance fluctuation characteristics through a multi-dimensional compliance deviation model in combination with historical records; the strategy optimization unit dynamically adjusts the event capture frequency and corrects a strategy matching rule according to the fluctuation characteristics; the violation tracing unit counts the risk cumulant and generates a violation tracing instruction when the risk cumulant exceeds a preset capacity. According to the system, automation and dynamic adjustment of operation and maintenance safety compliance detection are realized, and a risk accumulation process can be effectively tracked.
Owner:HEBEI HUAJIA ELECTRONIC TECHNOLOGY CO LTD

Browser user behavior recording intelligent workflow generation and execution method and system

The invention discloses an AI-based browser user behavior recording intelligent workflow method and system, and relates to the technical field of workflow management.The method comprises the steps that interaction behaviors are recorded in a browser, and normalized event data are generated; the input recording cooperative agent performs user task intention analysis and abstracts the user task intention into a structured workflow; inputting a recording test agent for verification, and adjusting the structured workflow to obtain a verified target workflow; the browser is driven to automatically execute and monitor the execution state, a self-repairing strategy is triggered for adjustment when the execution state is abnormal, and the target workflow is updated when self-repairing succeeds. Through the technical scheme of the invention, standardized modeling and precipitation of the browser event flow are realized, the workload of establishing an automatic process is reduced, the use threshold of establishing the browser automatic process is reduced, the execution success rate and stability of the target workflow are improved, and the user experience is improved. And the robustness and the long-term maintainability of the automatic process are effectively improved.
Owner:BAR-HEADED GOOSE (HANGZHOU) INTELLIGENT TECHNOLOGY CO LTD

System and Method for Event-Driven Video Synthesis Using Textual Descriptions

A video generation framework that is controllable, unsupervised and based on events (CUBE) includes an event camera, which captures changes in light intensity at each pixel of a scene asynchronously and generates event camera data. A text-to-image diffusion model that is conditioned on textual descriptions integrates the event camera data to control video synthesis. Further, an edge extraction module translates event data into a format usable by the text-to-image diffusion model, whereby the diffusion model synthesizes detailed and contextually accurate videos based on textual prompts. Further, an improved system (CUBE Plus) includes a content frame identification module which selectively identifies and uses only the most information-rich event segments of the event camera data to drive cross-frame attention, and an event driven attention mechanism that allows the framework to focus on event-dense moments.
Owner:THE UNIVERSITY OF HONG KONG

Systems and methods for detecting insider threats

Methods, systems, and techniques for detecting insider threat incidents are disclosed, comprising: receiving event data from a computing device of an event to be analyzed for an insider threat; accessing a vector database storing vector representations of known insider threat incidents; and determining a risk that the event is an insider threat incident based on the event data and the vector representations of the known insider threat incidents.
Owner:ROYAL BANK OF CANADA

System and method for intelligent dynamic marketplace

PendingUS20260050879A1CommerceRecommendation modelNeuroevolution
A dynamic marketplace system leveraging store and warehouse mobility features a neuroevolution (NE) engine, an electronic device, and a request handler facilitating communication between the electronic device and the NE engine. The NE engine interfaces with a data storage system and an event handler receiving real-time event data from a public cloud services processor. An intentions handler interprets user intention data to predict user behavior. The NE engine, integrated with a processor, generates a predictive evolutionary model for the marketplace based on request, event, and intention data. An AI agent processor within the NE engine creates a recommendation model for mobile retail vendors, devises route plans, and deploys vendors to strategic locations.
Owner:FALCONET SOLUTIONS INC

Aperiodic ship scheduling method and system considering uncertain harbor time, and medium

The invention discloses an irregular ship scheduling method and system considering uncertain harbor time, and a medium, and belongs to the technical field of shipping management. The method comprises the following steps: collecting ship, cargo, port and interference event data; generating an initial scheduling scheme by adopting a greedy strategy; generating multiple groups of random interference scenes based on Monte Carlo simulation; a two-stage stochastic programming model is constructed, in the first stage, income maximization serves as a target, and an initial plan is generated through damage and repair operator iterative optimization by means of a self-adaptive large neighborhood search algorithm; in the second stage, aiming at each interference scene, a recovery network is constructed for the influenced goods, and an optimal recovery strategy and adjustment cost are solved by utilizing a shortest path algorithm; and finally, outputting a scheduling scheme including a ship path, a navigational speed and a multi-scene recovery strategy through iterative optimization. According to the method, the earnings and the operation efficiency of the shipping companies are improved, the adjustment cost caused by uncertainty is reduced to the greatest extent, the benefits of the shipping companies and cargo owners can be balanced in a complex scheduling problem, and the service quality is improved.
Owner:HARBIN ENG UNIV

Generative artificial intelligence-based multi-stage composite event processing

A data platform monitors a compute environment by performing multi-stage heuristic analysis of event data representing a plurality of events occurring within the environment. The platform utilizes multiple event analyzers, each configured according to a distinct analysis heuristic, to evaluate different subsets of the event data and generate corresponding output signals. A higher-level event analyzer applies a further heuristic to the multiple output signals to generate a composite alert signal, indicating whether the combination of analyzed events collectively represents a security intrusion or other anomalous condition of sufficient severity to warrant alerting. Based on the composite alert signal, the platform performs an alert-based operation, such as generating a user-facing alert, initiating an automated mitigation, or updating a contextual model of system behavior. By combining the analytical outputs of heterogeneous heuristics, the disclosed architecture enhances the accuracy and contextual relevance of automated intrusion detection within complex computing environments.
Owner:FORTINET INC

Automatic Detection and Handling of Security-Related Anomalies by Utilizing Machine Learning and a Large Language Model

PendingUS20260135874A1Securing communicationOrganizational resourceOrganizational context
Automatic detection and handling of security-related anomalies by utilizing machine learning and a large language model (LLM). A computerized method for detecting and handling security threats in an organizational network of an organization includes: (a) collecting event data that pertain to organizational users, organizational devices, and organizational resources of the organizational network; (b) constructing user profiles, device profiles, and resource profiles; (c) constructing Organizational Context information that pertains to organizational users, organizational devices, and organizational resources; (d) constructing a time-series of events, enriched with the Organizational Context information; (e) analyzing the time-series of events using a Machine Learning process that detects an anomalous event, and automatically generating an alert message pertaining to and describing the anomalous event.
Owner:VARONIS SYSTEMS INC

Network security alarm intelligent identification method and device

The invention discloses a network security alarm intelligent identification method and device, and relates to the technical field of network security alarm identification, and the method comprises the steps: carrying out the preprocessing of original data from network traffic, log files, user behavior records, a firewall and an intrusion detection system, and obtaining a multi-dimensional security event data set; node modeling and edge relation modeling are carried out based on a GNN and the multi-dimensional security event data set, and cross-system and cross-time-dimension security event association features are extracted to obtain a high-dimensional context sensing feature vector set; a time sequence anomaly detection model is constructed based on a high-dimensional context sensing feature vector set and a time sequence analysis technology, the high-dimensional context sensing feature vector set is input into the time sequence anomaly detection model, and weighting calculation is performed on each time step by extracting time dependent features and combining an Attention mechanism. Outputting an abnormal score vector corresponding to each time point; and constructing a behavior deviation function based on the multi-dimensional security event data in combination with deep learning data.
Owner:STATE GRID GANSU ELECTRIC POWER RESEARCH INSTITUTE

Security event tracing and response management platform suitable for wind and light storage station

The invention discloses a security event traceability and response management platform suitable for a wind and light storage station. The platform comprises a station edge layer and a cloud middle platform layer. The station edge layer comprises an acquisition and isolation unit, a time synchronization and evidence shaping unit and a credible evidence storage and equipment snapshot unit; the evidence storage module is used for underlying data acquisition, time synchronization, evidence shaping and credible evidence storage to form original event data and an encrypted evidence chain; the cloud middle platform layer comprises a cross-domain causal atlas and root cause analysis engine, a control physical consistency verification model, a hierarchical response and energy storage security state control unit, a drill and strategy verification unit and a redisk and adaptive optimization unit; the method is used for cross-domain causal analysis, control consistency verification, hierarchical response decision and strategy redisk optimization. Unified acquisition, credible recording and cross-domain traceability of security events are realized, event sources and propagation paths can be accurately identified in a complex operation environment, and closed-loop control of security response is supported.
Owner:XIAN THERMAL POWER RES INST CO LTD +1

Network security operation and maintenance automatic analysis response system based on artificial intelligence

The invention relates to the technical field of network security, in particular to a network security operation and maintenance automatic analysis and response system based on artificial intelligence, which comprises an operation sensing module for acquiring a server state, extracting a security log, monitoring a network protocol and a transmission direction, identifying a performance bottleneck, sorting event data and generating a sensing summary sheet, the path offset identification module tracks a cross-domain path, identifies an abnormal path and generates an offset list; the behavior chain construction module sorts an event sequence and generates a behavior chain graph; the response processing module arranges processing steps, records a response process, generates an operation and maintenance execution sequence, synthesizes an output module to complete a process and generates an analysis result. According to the invention, by comparing the server resources with the historical reference, the abnormity is identified, and the event behavior basis is provided. And tracking cross-domain path lag and abnormity, and positioning threats. Arranging event data, and constructing an attack chain. The automatic response improves the speed and accuracy, shortens the response time, and enhances the attack handling capability.
Owner:HANGZHOU XIANGLIANG IOT TECHNOLOGY CO LTD

Machine learning model for managing security threat alerts for a compute environment

Data platforms described herein are configured to monitor a compute environment and to use machine learning models for managing security threat alerts for the compute environment. Such a data platform may identify, based on event data indicative of events occurring in the compute environment, a set of detected security threats present within the compute environment. Using a machine learning model trained based on previous event data indicative of events that occurred previously, the data platform may reduce the set of detected security threats to form a subset of prioritized security threats. The data platform may then provide security threat alerts for the compute environment in a manner that emphasizes alerts associated with prioritized security threats over alerts associated with other detected security threats of the set of detected security threats. Corresponding methods, systems, and products are also disclosed.
Owner:FORTINET INC

Power grid snapshot replaying method and device based on distributed event traceability

The invention discloses a power grid snapshot playback method and device based on distributed event traceability, and belongs to the field of power systems, and the method comprises the steps: collecting time sequence event data generated by a power grid in real time according to a distributed time sequence library, and storing the time sequence event data in real time; when the time sequence event data meets any one of a time period triggering condition, an event counting triggering condition and a state mutation triggering condition, collecting current equipment operation information of a power grid to generate a power grid snapshot, and storing the snapshot to a MongoDB database by adopting an NoSQL storage method; and in response to a state query request of a user containing a plurality of device IDs and target time points corresponding to the device IDs, judging a playback type, if the request is a single-snapshot playback request, performing playback according to the device IDs and the target time points, and if the request is a multi-snapshot playback request, performing playback according to the device IDs and the corresponding target time points. Therefore, by implementing the method and the device, the replay efficiency of the power grid snapshot can be improved.
Owner:ELECTRIC POWER RES INST OF GUANGDONG POWER GRID CO LTD

Insurance short video content generation method and device, medium and program product

The invention discloses an insurance short video content generation method and device, a medium and a program product, and relates to the technical field of artificial intelligence. Semantic analysis is performed on hot event data to extract core risk elements, so that the system can capture risk features concerned by the current society. The core risk elements are matched with the guarantee demands of the potential users, the guarantee gap is determined, and the association mapping between the hot event risks and the guarantee demands is established, so that the determination of the target insurance product has risk guidance. And determining a cue word generation strategy from a preset strategy library and inputting the cue word generation strategy into the insurance field large language model to generate a first draft of the content, thereby realizing automatic generation of the content. And in combination with a preposed compliance detection mechanism, the compliance of the generated content is ensured. Quick response and generation of the insurance short video content are realized, and the content generation efficiency is improved.
Owner:BEIJING ZHIBAO HUIZHONG DIGITAL TECHNOLOGY CO LTD

Dynamic self-adaptive intelligent scheduling method for harbor storage yard

The invention relates to the technical field of intelligent scheduling and management and control of a harbor storage yard, and discloses a dynamic self-adaptive intelligent scheduling method of the harbor storage yard, and the method constructs a closed-loop process including environmental anomaly collaborative diagnosis, scheduling strategy dynamic reconstruction, and scheme execution and feedback based on a storage yard three-dimensional digital twinborn model and a multi-objective optimization scheduling model. The method comprises the following steps: collecting operation physical sign data of a plurality of devices in real time, and carrying out collaborative analysis and reasoning on the operation physical sign data, a device performance baseline and a historical environment event database, so as to diagnose hidden physical anomalies; according to the abnormal type and the task attribute, the weight or constraint of the optimization model is dynamically adjusted, and a self-adaptive scheduling scheme is generated; and finally, continuously updating the baseline library and the event library by executing feedback to realize online learning and optimization of the system. According to the method, the defects of a traditional scheduling method in the aspects of three-dimensional visualization, multi-objective optimization and dynamic response of environment anomalies are effectively overcome, and the intelligent level, safety and efficiency of port storage yard operation are remarkably improved.
Owner:INTELLIGENT TECH CO LTD OF CHINESE CONSTR THIRD ENG BUREAU

RPA operation report automatic generation method based on full-service process data fusion and financial robot thereof

The invention provides an RPA operation report automatic generation method based on full-business process data fusion and a financial robot thereof, and the method comprises the steps: collecting task logs, business action events and context data generated in the execution process of the financial robot, and standardizing the task logs, the business action events and the context data into a unified event unit; constructing a flow path diagram based on the event time sequence; performing structure comparison on the trajectory diagrams of different service periods, identifying node addition and deletion or path rearrangement, and generating a structure attribution result; combining the attribution result and the event data to construct a structure perception type semantic index; and finally, automatically filling the indexes and attribution contents into the financial operation report template to generate a complete report. The method does not need to depend on a process definition file, can automatically restore a real execution path, achieves the interpretability analysis of process change and the full-automatic generation of a report, and remarkably improves the accuracy, integrity and decision support capability of financial RPA operation analysis.
Owner:GUANGDONG SUYUAN TECH CO LTD

Production line intelligent scheduling system and multi-device cooperative control method

The invention relates to the technical field of scheduling control, and provides a production line intelligent scheduling system and a multi-device cooperative control method, and the method comprises the steps: obtaining event data of a production line, recognizing a causal relationship between a device and a task, generating a causal graph network of the production line, and broadcasting a causal influence factor. The capability performance of the equipment is predicted and mapped into equipment capability constraints to judge whether to broadcast subpackage requests and determine takeover equipment or not, a causal graph network is updated in a closed loop mode, causal influence factors are broadcast, production state changes can be sensed in real time, potential risks can be accurately predicted, and optimization decisions can be quickly made; efficient configuration of production resources and stable operation of the production process are achieved, the production cost is effectively reduced, and the production efficiency and the product quality are improved.
Owner:GUANGDONG YANGGE NEW MATERIAL TECH CO LTD

Grouting project spewing prediction method and system

The invention provides a gushing prediction method and system for grouting engineering, and belongs to the technical field of tunnel and underground engineering construction safety monitoring. The method comprises the following steps: collecting grouting pressure, flow, slurry viscosity and micro-seismic event data; calculating a slurry resistance index and a micro-seismic event aggregation density; inputting the initial gushing risk index into a pre-trained machine learning model to obtain an initial gushing risk index and a confidence score; according to whether the confidence score is lower than a preset threshold, selecting direct early warning or entering a parameter correction path; when the confidence coefficient is low, dynamic correction factors are generated based on scores and risk changes, the calculation weight of the slurry resistance index is adjusted, corrected parameters are obtained, and secondary prediction is carried out; and integrating the initial prediction result and the secondary prediction result to obtain a final risk index, and executing graded early warning. According to the invention, the accuracy and reliability of gushing risk prediction are improved through a confidence-driven double-path decision and parameter on-line adaptive correction, and a constructed early warning mechanism.
Owner:CHINA CONSTR SEVENTH ENG DIVISION CORP LTD +2

Apparatus and method for model agnostic fraud risk assessment

An apparatus and method for fraud-risk assessment. Event data including identification, transactional, geospatial, biometric, and behavioral signals, are received and processed by a scoring module employing one or more analytical models to generate a score. Based at least in part on the score, a security action is selected and a risk-tiered alert is generated. An audit record including the score, rationale, action, timestamps, and associated data characteristics is stored in one or more datastores configured for secure, verifiable, or immutable recordkeeping. The operations may be performed in any order or in parallel. Embodiments include velocity controls for real-time flows and post-event workflows to escalate to external recipients, create or update an investigation case, or supply features for model retraining, while preserving auditability.
Owner:PASCAL SEBASTIAN +1

Power supply service digital graph linkage monitoring, control and early warning method

The invention relates to a power supply service digital graph linkage monitoring, control and early warning method. The method comprises the following steps: performing space-time anchoring processing on power supply service multi-source heterogeneous data corresponding to a target power grid to obtain space-time anchor event data; according to the space-time anchor point event data, carrying out space-time knowledge fusion on a multi-source association relationship of the target power grid to obtain power supply service space-time knowledge graph data; according to the power supply service space-time knowledge graph data, performing multi-task risk prediction on the power supply service risk of the target power grid in a preset prediction time window to obtain a dynamic early warning trigger result; according to the dynamic early warning triggering result, performing causal attribution anti-fact deduction on the risk rise key driving factor of the power supply service risk to obtain an interpretable early warning result; the interpretable early warning result is used for performing behavior disposal arrangement on the target power grid. By adopting the method, the prospective prediction of the risk can be realized.
Owner:NORTH CHINA GRID MEASUREMENT CENT +1

Systems and methods for distributed ledger-based auditing

A trusted node in a distributed ledger audit system may identify first audit event data for a first audit event from a first computing resource on a messaging bus; generate a first hash of a subset of the first audit event data; write the first audit event data to a storage location; create a first block comprising a subset of the first audit event data and a header comprising the first hash; and write the first block to a scoped distributed ledger. A verification node may generate a third hash from the first hash and a second hash for a second block for a second audit event; create a third block comprising the third hash in a header of the third block and the subset of first audit event data and the subset of second audit even data; and write the second block to an audit distributed ledger.
Owner:JPMORGAN CHASE BANK NA

Power grid abnormal event handling method and system based on knowledge graph

The invention relates to the technical field of power grid exception handling, and discloses a power grid exception event handling method and system based on a knowledge graph. The method comprises the following steps: collecting time sequence data flow and space coordinate information of a power grid abnormal event in real time through multi-source sensing equipment, and fusing equipment operation parameters to construct a dynamic event data pool; performing graph structure conversion on the dynamic event data pool based on a knowledge graph topological connection relationship, calculating event node propagation path intensity and generating an event propagation network model; key abnormal indexes are separated out from the model by adopting a multi-modal feature extraction technology, risk probability calculation is completed in combination with an adaptive learning algorithm, and an abnormal risk distribution diagram is output; and classifying event levels according to the graph, and automatically generating a processing instruction sequence. According to the method, omnibearing data perception and accurate analysis of the abnormal events of the power grid are realized, an event propagation rule is clearly presented, risk assessment is enabled to be closer to an actual operation state, and accurate guidance is provided for abnormal disposal.
Owner:GANSU SHINING SCI & TECH

Micro-service processing system

The micro-service processing system provided by the embodiment of the invention comprises an event identification module which is used for defining a business domain event type and registering an event attribute structure; the event bus module constructs a distributed communication network containing a dual-channel message queue, and the event bus module implements partition routing according to event types; the event processing module is composed of an event producer and a consumer which are executed asynchronously, the event producer packages service actions into a standardized event data packet, and the consumer processes subscription events through a thread pool; the event storage module adopts a hierarchical log database for persistence of an event sequence and supports reestablishment of a service state according to a timestamp; and the security control module is used for implementing service authentication and event content encryption on a transmission layer. Through event bus dual-channel design, sender box transaction binding and hierarchical storage optimization, millisecond-level event processing delay is realized while the reliability of distributed transactions is ensured, and second-level state recovery can be realized based on a complete event log when a service fault occurs.
Owner:HUANENG ZHAOCAI DIGITAL TECHNOLOGY CO LTD +1

Server-based mechanics help determination from aggregated user data

Techniques for improving a user video game experience are described. In an example, a computer system receives event data from a plurality of user devices. Each event data includes an identifier of an activity in a video game and data indicating completion of the activity. The identifier can be predefined in program code of the video game. The identifier and completion data can be received based on an execution of the program code. The event data is processed to determine a video game mechanic suggestion to help a player complete the activity.
Owner:SONY INTERACTIVE ENTERTAINMENT LLC

RPA mouse and keyboard control method and system for Wayland desktop

The invention belongs to the technical field of computer man-machine interaction and automatic control, and particularly relates to an RPA mouse and keyboard control method and system for a Wayland desktop. The method comprises the following steps: S1, creating and registering a virtual input device supporting mouse and keyboard functions in a user space by accessing a virtual input device interface provided by an operating system kernel; s2, current activity display output is detected, and screen resolution information is obtained; s3, the server program monitors a preset local Unix domain socket path for receiving a control instruction from the client; s4, the client sends a control request to the local Unix domain socket path in a structured format, and the server receives and analyzes the control request; s5, the server side maps the analyzed control request into a corresponding kernel input event sequence according to the operation type; meanwhile, by writing event data into the virtual input device, an input event is injected into the system so as to simulate a control operation on the graphic desktop.
Owner:浙江实在智能科技有限公司

Threat intelligence data processing method and related equipment

The embodiment of the invention provides a threat intelligence data processing method and related equipment. The method comprises the following steps: acquiring an associated knowledge graph constructed based on multi-source threat intelligence data and network asset data; acquiring a real-time operation data flow in the monitoring network, determining asset data associated with the real-time operation data flow based on the associated knowledge graph, and performing priority matching based on the corresponding comprehensive risk value to obtain a priority corresponding to the real-time operation data flow; generating context associated data corresponding to the real-time operation data flow based on the associated asset data, and obtaining standard event data based on the corresponding priority, the real-time operation data flow and the context associated data; and matching the standard event data based on the at least one detection research and judgment rule corresponding to the research and judgment label to obtain the target research and judgment label, and generating the target processing instruction based on the processing strategy corresponding to the target research and judgment label, thereby improving the threat response efficiency and the closed-loop processing accuracy.
Owner:PENG CHENG LAB

Cloud-side collaborative electric energy quality monitoring method and system

The invention provides a cloud-edge collaborative power quality monitoring method and system. The method comprises the following steps: S1, edge acquisition and preprocessing; s2, performing anomaly detection and event triggering; s3, cloud modeling and recognition: receiving abnormal event data from a plurality of edge nodes, and constructing a space-time diagram model representing the association relationship of each monitoring node in combination with the topological structure and historical data of the industrial park power distribution network; identifying the type, the occurrence position, the influence range and the severity of the power quality abnormal event, and outputting corresponding alarm information; s4, model updating and alarm interpretation: performing model adaptive updating based on data of the abnormal event, performing online training optimization on the power quality anomaly detection model, and issuing updated model parameters to each edge node to improve subsequent detection performance; and carrying out interpretation generation on the alarm information, and generating an interpretable alarm report oriented to operation and maintenance personnel. According to the invention, efficient fusion analysis and intelligent alarm of the multi-source electric energy quality data can be realized.
Owner:GUANGDONG POLYTECHNIC OF ENVIRONMENTAL PROTECTION ENG

Intelligent lock identification method based on time sequence diagram neural network

The invention discloses an intelligent lock recognition method based on a time sequence diagram neural network, and the method comprises the following steps: collecting multi-source event data of an intelligent lock, unifying the format, embedding codes, and generating an event feature vector set; constructing a time-varying multi-relation graph, and executing message passing and feature aggregation to obtain a neighborhood aggregation result; constructing a dual-frequency memory time sequence diagram neural network, and extracting long-term and short-term behavior characteristics in slow-frequency and fast-frequency memory units; inputting the slow frequency memory state and the fast frequency memory state into a gating fusion layer, and combining time and scene information to generate a full-time-domain embedded vector; calculating identity matching, abnormal risk and forgery credibility, and outputting a comprehensive identification result; and executing instant response and security processing according to an identification result, and carrying out network updating. According to the method, the sequence diagram neural network and the double-frequency memory mechanism are utilized, multi-element dynamic recognition of the intelligent lock is achieved, and the method has the advantages of being high in self-learning, high in recognition accuracy and excellent in safety robustness.
Owner:BEIJING SURESOURCE TECH