Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

20 results about "Flooding attack" patented technology

Answer Wiki. Flooding Attacks: A SYN flood is a form of denial-of-service attack in which an attacker sends a succession of SYN requests to a target's system in an attempt to consume enough server resources to make the system unresponsive to legitimate traffic.

Synchronous adaptive link flooding attack defense method for heterogeneous networks with multi-dimensional identification

The present invention discloses a synchronous adaptive link flood attack defense method for a multi-dimensional identification heterogeneous network, comprising the following steps: S1, sampling the packet loss rate and link utilization of the network topology link to obtain the current state of the link; S2, extracting the key traffic features of the current state through the Honey Badger optimization algorithm; S3, inputting the key traffic features of the current state into a prediction model based on a spatiotemporal graph convolutional neural network to obtain a DDoS attack traffic prediction value; S4, identifying the attack action of the DDoS attack traffic prediction value, and selecting the optimal defense action through a partially observable Markov decision process model and a reward mechanism; S5, adjusting the defense strategy based on the optimal defense action selected in the current state. The present invention can accurately predict attack behavior and dynamically learn the optimal mitigation strategy in a novel multi-dimensional identification fusion network scenario to maximize normal traffic transmission and minimize the impact of attack traffic on bottleneck links.
Owner:BEIJING JIAOTONG UNIV

Link flooding attack detection method based on artificial intelligence

The invention discloses a link flooding attack detection method based on artificial intelligence, and the method comprises the steps: obtaining a plurality of flow attributes of a to-be-detected data stream in a network in a continuous time period, and constructing a time sequence attribute matrix corresponding to the flow attributes; performing multi-scale sparse sampling processing on the time sequence attribute matrix to generate a corresponding observation feature vector under each scale; inputting the observation feature vector under each scale into a preset reconstruction model for restoration, and obtaining reconstruction attribute data of each flow attribute under each scale; on the basis of the difference between the reconstructed attribute data and the original time sequence attribute matrix, abnormal scores of each flow attribute under different scales are calculated, and a comprehensive abnormal score value of each flow attribute is obtained through fusion; and identifying a suspicious node corresponding to each flow attribute according to the comprehensive abnormal score value, and performing topology co-occurrence analysis on the suspicious nodes of the plurality of flow attributes to determine a final link flooding attack target.
Owner:GCI SCI & TECH

Link flooding attack defense method and system based on data plane programmable SDN

The invention provides a link flooding attack defense method and system based on a data plane programmable SDN (Software Defined Network), and relates to the technical field of network security defense. The method comprises the following steps: carrying out real-time clustering analysis on a Traceroute data packet passing through a switch by adopting an online clustering algorithm based on a weighted Manhattan distance, positioning a suspicious link and sending alarm information to a controller; establishing a link attribute graph sequence by collecting link state data based on the alarm information, and performing abnormal link identification by using a space-time double-attention detection model based on GAT-Seq2Seq to obtain an attack path; and identifying a link flooding attack flow by adopting an attack flow identification method based on reinforcement learning, and discarding the link flooding attack flow at a source end switch of an attack path. According to the method, the link flooding attack defense system with high accuracy, low resource overhead and quick response capability is constructed, so that efficient defense of attacks is realized.
Owner:NORTHEASTERN UNIV AT QINHUANGDAO

Spaceborne Computer Penetration Testing Methods and Systems

ActiveCN121356917BData packAttack
This invention provides a method and system for penetrating spaceborne computers, comprising: identifying and parsing the physical layer, link layer, transport layer, and application layer protocols involved in the target spaceborne computer, completing communication link connectivity and protocol field mapping; designing and generating multiple types of attack payloads based on protocol and functional models, injecting various attack data packets including internal network penetration, lateral movement, flooding attacks, and command replay; real-time collection of multiple operational indicators, status parameters, and abnormal events of the spaceborne computer, performing data processing and feature extraction; setting multi-dimensional anomaly criteria and scoring models, identifying and quantifying abnormal indicators, and outputting risk levels; and performing graded risk assessment based on attack input, abnormal responses, and scoring results, outputting security vulnerabilities and rectification suggestions. This invention is applicable to ground testing, on-orbit evaluation, and related security protection fields of spaceborne computers, improving the security assurance capabilities of satellite systems.
Owner:SHANGHAI JIAOTONG UNIV +1

An agent identity authentication method based on a trust mechanism

PendingCN122640187AAttackEngineering
The application provides an agent identity verification method based on a trust mechanism, belongs to the technical field of artificial intelligence and network security, and is used for solving the problems that in related technologies, external credentials cannot distinguish real agents from fake requests and are vulnerable to prompt injection attacks. In the application, a natural language semantic task is issued by a verification direction request party as a verification task, the request party generates a high-cost natural language response meeting a preset quality constraint, the verification party performs lightweight verification with a lower computing resource than the generation cost, and if the verification is passed, the request party is determined to be an agent with a legal semantic generation capability. The application realizes identity verification based on the endogenous semantic capability of the agent as the trust basis, naturally resists fake and flooding attacks through a cost asymmetry mechanism, and is immune to prompt injection at the protocol level through an output locking mechanism, and can be widely applied to trusted communication scenarios of an agent network.
Owner:LONGTEL INC

A method and device for identifying persistent routing under link flooding attack

The application discloses a kind of link flooding attack under the identification method and device of persistent routing, the method is first collected traffic data from SDN data plane, and the flow characteristics of each link are extracted by SDN controller, to construct flow characteristic dataset and training set;Then construct LSTM classification model and carry out offline training;Again in the flow characteristics of each link under the link flooding attack in SDN controller is input to the LSTM classification model trained, to obtain the flow class of the flow characteristics of each link, to construct flow characteristic class dataset;Finally, flow characteristic class dataset is traversed, and the flood proportion of each link is obtained, further identified and positioned to link flooding attack under persistent routing.The application can accurately identify persistent routing under link flooding attack under the mixed flow including link flooding attack attack flow and benign flow, and is conducive to enhancing the effectiveness and accuracy of persistent routing identification.
Owner:ZHEJIANG LAB

Techniques for generating application layer signatures characterizing advanced application layer flood attack tools

Various disclosed embodiments include methods and systems for generating application layer signatures that characterize advanced application layer attacks. The method includes determining a baseline distribution of applicability of attributes included in a transaction for a protected entity during a peace period; determining an attack distribution of applicability attributes included in the transactions for the protected entity during the ongoing application layer attack; based on the application baseline distribution and the attack distribution of the application attributes, determining a probability that an attacker executes an ongoing application layer attack to generate an attack using at least one attribute; and generating an application layer signature specifying an applicability attribute determined to be qualified based on their respective probabilities, where the application layer signature characterizes a behavior of an attacker performing the ongoing application layer attack.
Owner:RADWARE LTD

CAN bus attack detection method, device and equipment

The invention discloses a CAN bus attack detection method, device and equipment, and relates to the technical field of computers. The method comprises the steps of obtaining a plurality of CAN message messages on a CAN bus within a target duration, and determining a CAN identifier and a message type of each CAN message message; mapping the CAN identifier and the message type corresponding to each CAN message to obtain a symbolized representation corresponding to each CAN message; based on the symbolization representation corresponding to each CAN message, determining the information entropy of each CAN message in the target duration, and based on the multiple information entropies, determining the target information entropy of the CAN bus; and determining an attack detection result for the CAN bus based on the target information entropy, a first reference entropy value corresponding to the CAN bus and a first preset entropy threshold value. By adopting the method, flooding attacks and a small number of replay attacks which disguise high-priority CAN IDs can be detected.
Owner:CHONGQING SELIS PHOENIX INTELLIGENT INNOVATION TECH CO LTD

Concurrent flooding and cloning attack mitigation

A wireless communication process can include obtaining a wireless communication message associated with a source identifier (ID); determining that the source ID is associated with a flooding attack. The process can include filtering, based on determining that the source ID is associated with a flooding attack, wireless communication messages associated with the source ID. Filtering the wireless communication messages includes alternating between a first filtering state and a second filtering state. The first filtering state and the second filtering state are associated with different amounts of filtering.
Owner:QUALCOMM INC

A security communication method for agent interaction

The application provides a security communication method for agent interaction, belongs to the technical field of artificial intelligence and network communication, and is used for solving the problems that the agent identity authentication is unreliable, vulnerable to prompt word injection and flooding attack in the related art. The method comprises the following steps: a verification party generates a semantic challenge and issues it to a request party; the request party generates a natural language semantic response by using a large language model, and embeds API information in the response in a semantic steganography manner; the verification party receives the semantic response and performs legality verification, which comprises whether the semantic correlation and the generation cost are higher than a threshold value; after the verification is passed, the API information is extracted and an invocation is performed, and a structured result is output. The application takes semantic capability as a trust root, realizes integrated identity authentication and secure API invocation through asymmetric cost semantic challenge and semantic steganography, is immune to injection attack from the protocol level, and naturally resists flooding attack.
Owner:LONGTEL INC

Method, device, equipment, storage medium and program product for processing link flooding attack

Embodiments of the present application provide a link flooding attack processing method, device and equipment and a storage medium, comprising: obtaining an ICMP message and calculating an information entropy value of the ICMP message; in the case that the information entropy value is less than a preset early warning threshold, locating a congestion link according to the information entropy value; obtaining current state information of the congestion link and inputting the current state information into a deep reinforcement learning model trained by a convolutional neural network and a Q-learning algorithm through historical state information and historical routing strategies to obtain a current routing strategy; and performing routing processing on the link flooding attack according to the routing strategy. Embodiments of the present application can detect the link flooding attack without increasing additional detection points and can improve the detection accuracy of the link flooding attack. Furthermore, embodiments of the present application can learn strategies from historical traffic and perform traffic engineering on data streams through deep reinforcement learning, thereby more efficiently coping with LFA attacks and improving the service quality of the system.
Owner:ZTE CORP

MCP flooding attack detection method based on behavior characteristics

An MCP flooding attack detection method based on behavior characteristics comprises the following steps: collecting and learning a large amount of legal MCP traffic, extracting parameter length, request interval, nesting depth and response time characteristics, and constructing four-dimensional normal distribution as a legal traffic model based on the parameters, the request interval, the nesting depth and the response time characteristics; the probability density of the feature vector of each new request under the legal model is calculated to judge the abnormal request and the attack type thereof, finally, an SIR infectious disease dynamic model and an ARIMA time sequence model are further innovatively integrated to predict the zombie node scale and the attack trend, and the prediction result is used as input to automatically trigger and adjust a defense strategy; according to the method, botnet attack detection is carried out on the large language model integrated with the MCP protocol by utilizing the multi-dimensional behavior characteristics, so that attack detection and an adaptive defense strategy are effectively realized, and a security protection capability is also provided for a complex network environment in which the large language model is integrated with the MCP protocol; the invention further comprises a system, equipment and a storage medium for implementing the method.
Owner:XI'AN PETROLEUM UNIVERSITY

Defence method and device for flood attack, storage medium and electronic equipment

The present disclosure relates to a defense method and device for a flooding attack, a storage medium and an electronic device, and relates to the technical field of network and security technology. The method comprises: sampling real-time network card traffic of a network server based on a preset sampling frequency to obtain a to-be-processed sampling packet; calculating a real-time traffic rate of a current data flow according to a first byte number and a first flow time, and determining the current data flow as a target data flow when the real-time traffic rate of the current data flow is greater than a preset traffic threshold; extracting a target flow feature of the target data flow from the to-be-processed sampling packet, and generating an access control list rule corresponding to the target data flow according to the target flow feature; updating a current blacklist by using the access control list rule to obtain a target blacklist, and filtering a submitted packet based on the target blacklist to achieve defense against the flooding attack included in the submitted packet. The present disclosure improves the accuracy and timeliness of the defense.
Owner:CHINA TELECOM CORP LTD

Method, device and equipment for detecting attacks on a can bus

The application discloses a CAN bus attack detection method, device and equipment, and relates to the technical field of computers. The method comprises the following steps: acquiring a plurality of CAN message messages on a CAN bus within a target time length, and determining the CAN identifier and message type of each CAN message message; mapping the CAN identifier and message type corresponding to each CAN message message to obtain the symbolic representation corresponding to each CAN message message; determining the information entropy of each CAN message message within the target time length based on the symbolic representation corresponding to each CAN message message, and determining the target information entropy of the CAN bus based on the plurality of information entropies; and determining the attack detection result for the CAN bus based on the target information entropy, the first reference entropy value corresponding to the CAN bus and the first preset entropy value threshold. The method can detect flooding attacks and a small number of replay attacks disguised as high-priority CAN IDs.
Owner:CHONGQING SELIS PHOENIX INTELLIGENT INNOVATION TECH CO LTD

Network security protection method and device for pulling and fusing multi-source information data

The invention discloses a network security protection method and device for pulling and fusing multi-source intelligence data, and relates to the technical field of network security protection, and the method comprises the steps: obtaining message information received by a power system, carrying out the message rationality analysis, and obtaining a message rationality parameter; according to a historical message rationality parameter sequence in a preset time range, processing to obtain a message unreasonable density, and carrying out flooding attack probability analysis to obtain a flooding attack probability; according to the flooding attack probability, carrying out integrated malicious analysis on the message information to obtain a malicious probability; and calculating the attack probability according to the malicious probability and the flooding attack probability, and performing protection processing judgment on the message information. According to the invention, the technical problem of inaccurate network security protection processing in the prior art is solved.
Owner:GUANGXI POWER GRID CORP

Targeted detection backdoor attack system based on generative model

PendingCN122634594AData setAttack model
The application provides a target detection backdoor attack system based on a generative model, which is a brand-new backdoor attack model specially for target detection. The application puts the clean sample and the image obtained by superimposing a mask on the clean sample into a poison generator together with a trigger to generate a poisoned data set; then, the generated poisoned image is sent to a victim detector for detection, so that the backdoor attack has high success rate and does not affect the accuracy of the main task. In addition, the application also constructs a total optimization function, which uses two innovative attack schemes: the FLOODING attack can generate a large amount of false recognition to flood the normal output results, so as to damage the performance of the detector; and the HIDDEN attack makes the object unable to be recognized in the detection system, and presents an 'invisible' state. Through experimental verification, the attack system provided by the application can effectively fill the gap of the existing backdoor attack technology in the deeper regression task, so that the attack effect is significantly improved.
Owner:XIANGTAN UNIV

An attack detection method, apparatus, and electronic device

PendingCN122316775AAttackEngineering
This invention provides an attack detection method, apparatus, and electronic device, applied in the field of vehicle network security technology. The invention acquires anchor messages configured with deadlines, collects the number of arbitration failures, queuing time, and actual transmission time during the transmission process, calculates the queuing waiting time, and generates a deadline violation indicator based on the deadline. Multiple transmission samples are aggregated within a specified sliding window, and a fingerprint vector reflecting the bus resource contention status is generated based on the above parameters. This fingerprint vector is compared with a pre-built adaptive baseline to obtain an anomaly score. When the anomaly score exceeds a preset threshold, a disguised high-priority flooding attack is identified. This invention improves the accuracy and robustness of attack detection by monitoring underlying resource contention characteristics and accurately identifying anomalies caused by disguised high-priority attacks.
Owner:SHENZHEN STREAMING VIDEO TECH

Method and apparatus for protecting and migrating RTP media stream smoothly

PendingCN122420369AMultiplexingSTUN
The application discloses a kind of RTP media stream protection and talk migration smooth method and device, belong to VoIP technical field.In the method, maintain three-state security state machine including open state, learning state and locking state for each RTP transmission instance;In learning state, the continuity of candidate source address is counted, and after timeout, it is forced to lock, and the count is reset based on packet interval analysis detection flooding attack;Tracking SDP negotiation target address, give it priority through right;When detecting talk migration event, recalibrate RTP sequence number offset increment, so that output sequence number keeps continuous increment;In RTCP-MUX multiplexing mode, RTP media packet, RTCP control packet and STUN probe packet are distinguished according to flag bit and payload type range.The application is guaranteed by multidimensional source address security learning and cross-session sequence number continuity, effectively resist address spoofing and flooding attack, realize sequence number seamless continuation in talk transfer scene, ensure downstream receiving end no perception and DTMF signaling integrity.
Owner:XIAMEN XINGZONG DIGITAL TECH CO LTD

Active link flooding attack mitigation method and system

The present invention provides a method and system for mitigating active link flooding attacks, which belongs to the field of network data security protection technology. The method converts the topological features of the entire network and the characteristics of the port link into line graph topological structure characteristics and node characteristics with edges as nodes and nodes as edges, performs convolution reconstruction, measures the suspicious degree of the link according to the comprehensive error between the reconstructed characteristics and the original characteristics, and determines the congested link; combines with the proximal policy optimization algorithm, solves the traffic engineering optimization model, determines the traffic engineering strategy, updates the flow table of the corresponding flow on the relevant path according to the traffic engineering strategy, and transfers the traffic on the congested link to other links. The present invention effectively distinguishes between attack congestion and conventional immediate congestion, reduces the monitoring scope and deployment overhead, perceives the link status at packet granularity, can perceive the attack link congestion more quickly, can adapt to the dynamic network environment to alleviate network congestion, and effectively reduces the execution overhead of the mitigation strategy.
Owner:BEIJING JIAOTONG UNIV