Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

15 results about "Incident analysis" patented technology

An incident analysis involves gathering facts by inspecting the incident scene, interviewing witnesses, reviewing documentation, and analyzing those facts to determine the causal factors. The causal analysis is easier and more effective when it is done in two phases, a primary event analysis and a causal factor analysis.

Event analysis method and device, equipment and storage medium

The invention belongs to the field of big data processing, and particularly relates to an event analysis method, device and equipment and a storage medium, target event information is obtained, the target event information is converted into event feature vectors, the event feature vectors are input into multiple analysis models respectively, and the analysis models output corresponding event types and initial risk levels respectively. Performing similarity matching on the event feature vector and a historical event feature vector of a historical event in a preset knowledge base, screening one or more pieces of historical event information of which the similarity score is greater than a preset threshold, and determining the credibility of each analysis model based on the historical event information and the event type, performing weighted fusion on the initial analysis result based on the credibility of each analysis model, and determining a target risk level corresponding to the target event information; according to the method, by combining multi-model analysis, historical data similarity matching and credibility weighted fusion, the accuracy of risk level judgment of the target event is improved.
Owner:HAINA CLOUD IOT TECH CO LTD +1

A method, apparatus, device and medium for network security incident analysis

PendingCN122293423ALinguistic modelIncident analysis
This application discloses a method, apparatus, device, and medium for network security incident assessment, relating to the field of computer technology. It is applied to a network security incident assessment system. The system deploys a large language model within an analysis chain framework to perform progressive reasoning. The method includes: extracting target assessment features related to network security threats from multi-source heterogeneous data; determining at least one threat hypothesis scenario based on the target assessment features; assigning positive weights to supporting evidence for the scenario and negative weights to rebuttal evidence for the scenario; performing reasoning analysis on the evidence set to generate a target assessment report for the threat hypothesis scenario; the evidence set is obtained based on target evidence carrying the aforementioned weights. This application avoids interference from different contextual scenarios in the judgment; avoids the problem of lack of reasoning basis in the reasoning process; significantly reduces misjudgments and omissions; and solves the problem of insufficient understanding and adaptability of general large language models to network security expertise.
Owner:SANGFOR TECH INC

Group-based fraud detection decisioning

A computer system for detecting and assessing fraud risk employs group-based analysis to identify complex fraud patterns across various industries. The system identifies and analyzes groups of connected incidents by linking related events based on similarities in suspect identifiers, creating a network that reveals broader fraudulent behavior patterns. When processing a new incident, the system compares it against established groups of connected incidents, detecting subtle connections that may indicate relationships to known fraud patterns. This comparison can range from basic identifier matching to sophisticated analysis of multiple data points across different incidents within a group. Based on this comparison, the system generates a comprehensive fraud risk assessment for the new incident, leveraging collective information from grouped incidents to provide a nuanced and accurate evaluation of potential fraud risk. By considering new incidents in the context of established fraud patterns, the system offers insights not possible through individual incident analysis.
Owner:DETECTIVE ANALYTICS IP HOLDINGS LLC

Temporal graph-based anomaly analysis and control in cyber physical systems

ActiveUS12670059B2Incident analysisEngineering
Systems and methods are provided for incident analysis in Cyber-Physical Systems (CPS) using a Temporal Graph-based Incident Analysis System (TGIAS) and / or Transition Based Categorical Anomaly Detection (TCAD). Dynamically gathered multimodal data from a distributed network of sensors across the CPS are preprocessed to identify abnormal sensor readings indicative of potential incidents, and a multi-layered incident timeline graph, representing abnormal sensor readings, relationships to specific CPS components, and temporal sequencing of events is constructed. Severity scores are calculated, and severity rankings are assigned to identified anomalies based on a composite index including impact on CPS operation, comparison with historical incident data, and predictive risk assessments. Probable root causes of incidents and pathways for anomaly propagation through the CPS are identified using causal interference and the incident timeline graph to detect underlying vulnerabilities and predict future system weaknesses. Recommended actions are generated and executed for incident resolution and system optimization.
Owner:NEC CORP

A large model log violation scene processing method, system, device and medium

ActiveCN121257670BInference methodsPathPingIncident analysis
This application discloses a method, system, device, and medium for handling violation scenarios in large-scale model logs, mainly relating to the field of violation handling technology. It aims to address the problems of rigid rules, limited coverage, knowledge silos, lack of correlation, reliance on experts, and high iteration costs in existing solutions. The method includes: tracking behavioral nodes corresponding to several consecutive raw logs to form a behavioral node sequence; comparing the behavioral node sequence with preset legal path sequences in a behavior tree model library to determine if a preset abnormal node sequence exists; when an abnormal node sequence exists, determining whether it conforms to an event sequence corresponding to any rule in the event analysis rule library; if it does, entering the preset alarm scheme corresponding to the event sequence; if it does not, entering the unknown scenario mining process, inputting the abnormal node sequence into a trained second large-scale language model to obtain an initial processing scheme, and inputting the initial processing scheme into a preset verification terminal to obtain the final processing scheme.
Owner:中孚安全技术有限公司

System

PendingJP2026033695AOffice automationIncident analysisData mining
An object of a system according to an embodiment is to share near-miss incidents experienced by employees and prevent mistakes as a whole.SOLUTION: A system includes an input part, an analysis part, a database part, and a provision part. The input unit inputs a near-miss incident event experienced by an employee during work. The analysis unit analyzes the near-miss incident event input by the input unit and extracts a dangerous point and a pattern. The database unit registers the dangerous point and the pattern extracted by the analysis unit in a database. The providing part provides the information registered in the database part so that the employee can access the information.SELECTED DRAWING: Figure 1
Owner:SOFTBANK GROUP CORP

Temporal graph-based incident analysis and control in cyber physical systems

Systems and methods are provided for incident analysis in Cyber-Physical Systems (CPS) using a Temporal Graph-based Incident Analysis System (TGIAS) and / or Transition Based Categorical Anomaly Detection (TCAD). Dynamically gathered multimodal data from a distributed network of sensors across the CPS are preprocessed to identify abnormal sensor readings indicative of potential incidents, and a multi-layered incident timeline graph, representing abnormal sensor readings, relationships to specific CPS components, and temporal sequencing of events is constructed. Severity scores are calculated, and severity rankings are assigned to identified anomalies based on a composite index including impact on CPS operation, comparison with historical incident data, and predictive risk assessments. Probable root causes of incidents and pathways for anomaly propagation through the CPS are identified using causal interference and the incident timeline graph to detect underlying vulnerabilities and predict future system weaknesses. Recommended actions are generated and executed for incident resolution and system optimization.
Owner:NEC CORP

Large model log violation scene processing method, system and device and medium

The invention discloses a large-model log violation scene processing method, system and device and a medium, mainly relates to the technical field of violation processing, and is used for solving the problems of rule stiffness, limited coverage, knowledge islanding, lack of association, dependency on experts and high iteration cost in the existing scheme. Comprising the steps of tracking behavior nodes corresponding to a plurality of continuous original logs to form a behavior node sequence; comparing the behavior node sequence with a preset legal path sequence in a behavior tree model library, and determining whether a preset abnormal node sequence exists or not; when the abnormal node sequence exists, determining whether the abnormal node sequence accords with an event sequence corresponding to any rule in an event analysis rule base, and when the abnormal node sequence accords with the event sequence corresponding to any rule in the event analysis rule base, entering a preset alarm scheme corresponding to the event sequence; and if not, entering an unknown scene mining process, inputting the abnormal node sequence into a trained second large language model to obtain an initial processing scheme, and inputting the initial processing scheme into a preset verification terminal to obtain a final processing scheme.
Owner:中孚安全技术有限公司

Power grid dispatching event analysis method and device and electronic equipment

PendingCN122635883AIncident analysisPower grid
Embodiments of the present application provide a power grid dispatch event analysis method, device and electronic equipment. The method comprises: acquiring multi-source heterogeneous data; preprocessing the multi-source heterogeneous data to form a structured event feature dataset; constructing a multi-layer causal relationship graph based on the event feature dataset; based on the multi-layer causal relationship graph, performing root cause analysis on an occurred power grid dispatch event chain to obtain a root cause analysis result, the root cause analysis result comprising a root node of the power grid dispatch event chain and a causal propagation path from the root node to a symptom event. The method can deeply reveal the occurrence mechanism and evolution law of the power grid dispatch event from the causal perspective, and realize accurate tracing from the symptom event to the root cause event.
Owner:MEIZHOU POWER SUPPLY BUREAU OF GUANGDONG POWER GRID CORP

Lost index acquisition method and device

The invention provides a method and a device for acquiring a loss index. The method comprises the following steps: acquiring a target security event analysis report; identifying a uniform resource locator (URL) in the target security event analysis report; identifying target content corresponding to the path field from the URL; searching a first target language corresponding to the target content in a content-language corresponding relationship, wherein the content-language corresponding relationship comprises various languages and contents correspondingly identified in a path of the URL; and obtaining the IOC from the target security event analysis report based on the first target language. Through the URL of the security event analysis report, the origin of the security event analysis report can be accurately determined, and then the language of the security event analysis report is accurately determined. The target security event analysis report is subjected to IOC identification by adopting a correct language, and the IOC can be correctly identified, so that the accuracy of IOC information acquisition is improved.
Owner:QI AN XIN TECHNOLOGY GROUP INC

Method and device for analyzing operation events, electronic device and storage medium

The present disclosure discloses an operation event analysis method and device, an electronic device and a storage medium. According to the present application, the event knowledge base is constructed based on historical event data and the causal analysis model is trained, the sufficient extraction and fusion analysis of event characteristics are realized, the direct cause and the systematic cause can be accurately identified without relying on manual annotation, the knowledge base and the model are dynamically updated through new event data to improve the generalization ability, the feedback document is automatically associated with the historical experience, the technical effects of improving the operation event analysis efficiency of the nuclear power plant, enhancing the accuracy and comprehensiveness of event cause identification, reducing the occurrence of repetitive failures, strengthening the experience inheritance and risk prevention and control capability, and further ensuring the operation safety and stability of the nuclear power plant are achieved.
Owner:HUANENG NUCLEAR ENERGY TECH RES INST CO LTD +1

Security event analysis using network model context

A security incident analysis method includes: receiving information about a security incident; matching the security incident with one or more contents of a network model representing a system; analyzing additional context associated with the matching one or more contents of the network model; determining risk information about the security incident based at least in part on the analyzed additional context; and outputting an indication of the determined risk information.
Owner:C2A SEC LTD

Language model-based incident analysis and resolution

PendingUS20260252432A1Linguistic modelIncident analysis
A system is described that utilizes one or more large language models (“LLMs”) and prior incident data to (1) summarize a potential root cause for an incident that has occurred and to propose one or more steps or operations to be executed to resolve the incident; and / or (2) identify a new incident, summarize a potential root cause for the incident, and propose one or more steps or operations to resolve the incident. By employing various implementations of the systems and methods utilizing LLMs and / or prior incident data described herein, the incident response and prevention system can quickly and accurately output steps or operations that can be executed to resolve service unavailability that has already occurred and / or can quickly and accurately identify service unavailability incidents that may occur in the future and that can clearly identify what steps or operations to execute to prevent the service unavailability incident from occurring.
Owner:PALANTIR TECHNOLOGIES INC

An apartment-based video monitoring abnormal behavior detection method and system

This invention relates to the field of intelligent video surveillance technology, and discloses a method and system for detecting abnormal behavior in apartment video surveillance. The method includes synchronously acquiring and segmenting the surveillance video stream into time-series video segments with overlapping areas; performing multi-level scene semantic analysis on each video segment; constructing a spatiotemporal correlation network based on the temporal and spatial relationships between video segments, and performing cross-time period behavior correlation analysis to generate continuous behavior chains; matching the behavior chains with an abnormal behavior rule base to determine and mark abnormal events; further, performing multi-dimensional causal tracing of abnormal events to generate an abnormal causal tracing graph, and formulating and executing a hierarchical handling strategy accordingly; finally, dynamically optimizing the rule base using strategy execution feedback data. This invention achieves continuous characterization of behavior chains by constructing a spatiotemporal correlation network, deepens event analysis through causal tracing graphs, and improves the coherence, accuracy, and interpretability of abnormal behavior detection.
Owner:YUXIN (NANJING) NETWORK TECH CO LTD

Equipment fault event analysis method based on data association mining and related equipment

The invention discloses an equipment fault event analysis method based on data association mining and related equipment, and relates to the technical field of power system fault analysis. Time alignment, space matching and causal association are performed on multi-source data such as operation parameters, state monitoring and communication interaction by constructing three types of fault association dimensions of time, space and causal; forming a cross-source data association mapping relation; extracting a fault initial equipment identifier, an occurrence time node, an influence equipment list and a fault performance feature set, reconstructing a propagation path of the fault between the equipment and generating a path map for visualization according to the fault initial equipment identifier, the occurrence time node, the influence equipment list and the fault performance feature set; and organizing the fault generation process, the propagation logic and the influence degree according to the time sequence and the trigger condition, and generating an equipment fault event analysis report.
Owner:STATE GRID SICHUAN ELECTRIC POWER CORP ELECTRIC POWER RES INST