Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

34 results about "Information infrastructure" patented technology

An information infrastructure is defined by Ole Hanseth (2002) as "a shared, evolving, open, standardized, and heterogeneous installed base" and by Pironti (2006) as all of the people, processes, procedures, tools, facilities, and technology which supports the creation, use, transport, storage, and destruction of information.

Data cleaning method for ship information infrastructure fault diagnosis

The invention discloses a data cleaning method for ship information infrastructure fault diagnosis, and belongs to the field of data processing. The method specifically relates to a preprocessing method of ship information infrastructure monitoring data and a data cleaning method for distinguishing fault data and dirty data. Through data preprocessing, a consistent and complete data set is constructed for subsequent data cleaning. At the moment, abnormal values in the data set are divided into interference data and abnormal equipment states, the abnormal equipment state values have important significance for subsequent fault diagnosis, and the interference data can influence model training. According to the method, a mode of combining FP-Growth and DBSCAN algorithms is adopted, and the characteristics that cabin equipment is complex in coupling and one fault often generates derivative alarms are utilized, so that equipment fault points and interference points are reasonably distinguished. Through the ship information infrastructure fault diagnosis-oriented data cleaning method, the problems of fuzzy data quality and low model precision caused by application of traditional fault diagnosis to ship information infrastructures can be solved.
Owner:CHINA SHIPBUILDING RES INST (SEVENTH RES INST OF CHINA STATE SHIPBUILDING CORP)

Campus risk prevention and control system based on multi-modal data fusion and space-time modeling

The invention provides a campus risk prevention and control system based on multi-modal data fusion and space-time modeling, which relates to the technical field of campus safety management and comprises a multi-source data acquisition module, a space-time modeling module, a data fusion and alignment module, an intelligent risk analysis and early warning module and a visualization and linkage response module. The multi-source data acquisition module is used for acquiring multi-modal heterogeneous data from an existing campus information system and performing time sequence synchronization and desensitization processing; according to the method, multi-source data of existing campus videos, access control, wireless, consumption and mobile terminals and the like are integrated, monitoring blind areas and track breakpoints of a single data source are effectively eliminated through space-time alignment and semantic feature fusion, the accuracy and continuity of personnel positioning and track reconstruction are remarkably improved, existing information infrastructures of the campus are fully utilized, and the safety of the campus is improved. Special sensors or high-cost hardware do not need to be additionally installed on a large scale, deployment and maintenance cost is reduced, and the method can be suitable for campus scenes of different scales to be popularized and applied.
Owner:INTERNATIONAL COLLEGE OF RENMIN UNIVERSITY OF CHINA (SUZHOU RESEARCH INSTITUTE)

Penetration testing method and system based on multi-source data association and risk aggregation

PendingCN121814444ASecuring communicationRisk quantificationCritical information infrastructure
The invention provides a penetration testing method and system based on multi-source data association and risk aggregation, and the method comprises the steps: firstly carrying out the automatic collection and normalization processing of heterogeneous security data from penetration testing, source code detection, vulnerability scanning and the like, and breaking an information island; and intelligent association and attack path discovery are carried out on discrete vulnerabilities based on an attack chain model, and a dynamic risk quantification model fusing a business influence weight and attack path complexity is innovatively introduced to carry out comprehensive risk assessment. According to the technical scheme, the problems of data splitting, single analysis dimension and disjunction between risk assessment and services of a traditional scheme are effectively solved, accurate identification and quantitative grading of composite attack chain risks are finally achieved, the safety analysis operation efficiency is remarkably improved, expert knowledge is solidified in the system, and the safety analysis efficiency is improved. And a visual and reliable data support is provided for safety investment decision-making of key information infrastructure industries such as power generation and the like.
Owner:XIAN THERMAL POWER RES INST CO LTD +1

Network security risk prediction and prevention method and system based on big data

PendingCN121396539ABiological modelsSecuring communicationCritical information infrastructureInternet traffic
The invention relates to the technical field of information, and discloses a network security risk prediction and prevention method and system based on big data, and the method and system comprise a data collection module, a data processing module, a risk prediction module, a strategy generation module, a response execution module, and an optimization feedback module. Network traffic, system logs, user behaviors and threat intelligence data are converged in real time through a distributed acquisition module, a high-dimensional feature vector is generated by fusing time sequence, statistics and semantic features through feature engineering, automatic responses such as traffic filtering and access control are executed, and an incremental learning mechanism dynamic optimization model is constructed; according to the method, multi-source data fusion analysis is realized, the attack detection coverage rate and response timeliness are improved, real-time risk prediction and dynamic defense are supported, the high-risk attack interception efficiency is improved, continuous evolution of the model is realized through incremental learning, and the novel attack detection rate and the resource efficiency are improved in a breakthrough manner; and an efficient active defense capability is provided for the key information infrastructure.
Owner:YANGJIANG YUEFENG TECHNOLOGY CO LTD

Key information infrastructure safety monitoring and early warning method based on level protection data

PendingCN121441559ABiological modelsSecuring communicationData streamCritical information infrastructure
The invention discloses a key information infrastructure safety monitoring and early warning method based on level protection data. A network safety monitoring and early warning framework is formed based on introduction of a risk engine unit, an event engine unit and an early warning engine unit. The risk engine unit operates in a near-line calculation mode and carries out active structural threat surface analysis, the event engine unit serves as an online real-time component to keep normal operation, a professional model is used for achieving cross-data-stream multi-mode threat detection, and when the event engine unit triggers a high-confidence alarm, the early warning engine unit is started; and after the early warning engine unit is started, a detection threshold value is dynamically adjusted by implementing self-adaptive high-sensitivity monitoring so as to capture subtle activities after the vulnerability. According to the scheme of the invention, a comprehensive, intelligent and adaptive network security solution is provided, and security operation can be effectively promoted to proceed from isolated event alarm to real network toughness.
Owner:THE THIRD RES INST OF MIN OF PUBLIC SECURITY

Network security product interconnection method and system based on elastic scheduling

PendingCN122660927APathPingCritical information infrastructure
The application discloses a network security product interconnection and intercommunication method and system based on elastic scheduling, and belongs to the technical field of network security. In order to solve the technical problems of poor compatibility, difficulty in dynamically adapting network environment fluctuation and low cooperative defense efficiency caused by manufacturer barriers among network security products, the application obtains standard data by uniformly converting the protocols, interfaces and data formats of each security product; determines target scheduling instructions based on the standard state data and performs elastic adjustment of paths, tasks and resources by using a strategy and a value network; generates global threat intelligence based on standard threat data and distributes cooperative protection strategies; and performs abnormal monitoring and self-repairing on the adjusted running state. The application can be widely applied to the key information infrastructure scene of multi-type security product cooperative protection, and significantly improves the resource utilization rate and the reliability of network defense.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

Generative large model-based network attack behavior prediction method, system and device, and medium

PendingCN121261948ABiological modelsSecuring communicationInternet trafficCritical information infrastructure
The invention relates to the technical field of network attack behavior prediction, and discloses a network attack behavior prediction method, system and device based on a generative large model, and a medium. The generalization ability of the model is improved by combining cross-industry attack scene migration and self-supervised pre-training, feature fusion is optimized by using an attention mechanism, the interpretability of a defense decision is improved while the prediction accuracy is ensured, and a possible coping strategy of an attacker is deduced in advance based on a strategy optimization method of an attack-defense game tree; and defense actions can be automatically generated and executed, so that intelligent and closed-loop network protection is realized. The method is obviously superior to the prior art in the aspects of attack prediction accuracy, defense decision intelligence, system expandability and the like, and particularly has important application value in security protection of key information infrastructures such as a power system and the like.
Owner:GUIZHOU POWER GRID CO LTD

Anti-quantum classical channel authentication method, device, equipment and medium

PendingCN121984721Aimprove securityImprove authentication efficiencyKey distribution for secure communicationUser identity/authority verificationCommunications securityInformation infrastructure
The invention relates to the technical field of communication security, and discloses an anti-quantum classical channel authentication method, device, equipment and medium, and the method comprises the steps: detecting whether the communication is established for the first time between transmitting end equipment and receiving end equipment which carry out quantum signal transmission; if the communication is established for the first time, authenticating a classical channel between the sending end equipment and the receiving end equipment by using an anti-quantum signature; if the communication is not established for the first time, generating a message verification code based on a key in an authentication quantum key pool, and authenticating a classical channel between the sending end equipment and the receiving end equipment; and after the classical channel authentication is passed, obtaining a quantum key, and storing the quantum key into an encryption quantum key pool and an authentication quantum key pool. Through the method and the device, the technical problems that in the prior art, key management is complex, a traditional signature algorithm is easily cracked by a quantum computer, and the security requirement of future information infrastructure is difficult to meet are solved.
Owner:CRSC RESEARCH & DESIGN INSTITUTE GROUP CO LTD

Systems and methods for a connected computing resource and event / activity identification information infrastructure using near existential or existential biometric identification of humans

Connected computing enables the use of highly diverse environments that support operating frameworks for contemporary civilization. But computing productivity and trustworthiness are undermined by such environments' largely inchoate organization. These environments and their identity infrastructures are fragmented, and unnecessarily unreliable, insecure, and insufficiently informative due to current computing entity (e.g., resource) identification infrastructure design, which lacks root identification reliability. Such reliability is enabled herein by a fundamentally accurate and authenticity ensuring, near-existential or existential quality, biometrically and liveness based, portable identification and provenance infrastructure. Such an infrastructure provides ubiquitously available identification information that can be used universally for identification processes. Such biometrically and liveness-based identification information can be contemporaneously acquired and securely fused with or otherwise bound to associated entity identification information sets. Such sets are used to identify and assess entity suitability and / or authenticity, and / or establish user identity (specific human entity) for personal, societal, and organizational activities.
Owner:ADVANCED ELEMENTAL TECHNOLOGIES INC

Power monitoring system vulnerability index prediction method based on text classification and related device

The invention discloses an electric power monitoring system vulnerability index prediction method based on text classification and a related device, and belongs to the technical field of electric power monitoring system vulnerability evaluation. The method comprises the following steps: firstly, constructing an evaluation system comprising specific environment indexes of a power system, extracting deep semantic features of a vulnerability description text through a lightweight pre-training language model DistilBERT, and realizing parallel prediction of multiple indexes such as attack vectors and permission requirements by adopting a multi-task learning framework. And carrying out interpretability analysis on a model decision process by combining an integrated gradient algorithm, and identifying key semantic features influencing a prediction result. According to the method, the automation level and the result credibility of vulnerability assessment are effectively improved, and intelligent technical support is provided for security protection of power key information infrastructures.
Owner:STATE GRID ANHUI ELECTRIC POWER CO LTD +3

Data cabin and cabinet

The embodiment of the utility model relates to the technical field of information infrastructure, in particular to a data cabin and a cabinet. The embodiment of the utility model aims to solve the problems that the number of devices in the cabinet is large, cold air circulation in the cabinet is affected, and heat dissipation of the devices is not facilitated. According to the data cabin provided by the embodiment of the invention, a plurality of cabinets are arranged in a first direction to form a first row of equipment cabinets, the first direction is the width direction of the cabinets, each cabinet comprises a back plate, a top plate and a bottom plate, the back plate is located between the top plate and the bottom plate, a channel is defined by a closed structure and the plurality of cabinets, and a refrigeration device and an air duct are located in the cabinets. The refrigerating device is closer to the bottom plate than the air guide cylinder, the air outlet of the refrigerating device is closer to the channel than the air inlet of the refrigerating device, the air guide cylinder is closer to the top plate than the refrigerating device, the first opening of the air guide cylinder faces the channel, and the second opening of the air guide cylinder faces the back plate, so that cold air is guided to the back plate and can flow along the back plate. And the heat flows through each communication device, so that the heat dissipation effect of each communication device is improved.
Owner:HUAWEI TECH CO LTD

Methods and systems for predicting onset and progression of medical conditions

Provided herein are computer-implemented methods and systems for predicting the onset or progression of medical conditions using data from electronic health records (EHR) or electronic medical records (EMR), such as time-stamped blood-test values, in combination with trained predictive models. In some aspects, the predictive models comprise statistical or machine-learning algorithms trained using supervised learning on labeled clinical data. The disclosed methods and systems can generate individualized risk scores, classify subjects relative to operating thresholds, and optionally generate or record treatment recommendations in an EHR or EMR. The methods and systems can be applied to human or non-human subjects, enabling early detection of medical conditions, personalized risk assessment, and integration with healthcare information infrastructure.
Owner:MOR RES APPL LTD +1

Fault information processing system and electronic equipment

The invention provides a fault information processing system and electronic equipment, and belongs to the technical field of information infrastructure. The system comprises a control unit, a data collection unit and a data storage unit on a main control unit, the control unit comprises a bus interface, and the data collection unit comprises a management unit. The control unit is configured to switch the multiplexer to the control unit through a selection signal, so that the bus interface is connected with the management unit through the multiplexer to form an I2C channel, the control unit is used as an I2C master end, and the management unit is used as an I2C slave end; when the main control unit is abnormal, the integrated HDT software is called, fault information is obtained through the I2C channel, and the fault information is stored in the data storage unit; and when the fault information collection is completed, sending the fault information to an external device, and carrying out fault analysis and processing. According to the invention, the control unit is used as the main end of the data collection unit for fault collection, so that the fault positioning time is shortened.
Owner:HYGON INFORMATION TECH CO LTD

Geographic sales allocation system for estimating the source of pharmaceutical sales

This invention provides a correspondence relationship extraction system that automatically extracts rationally linked medical institutions by calculating the geographical distance between pharmacies / drugstores and medical institutions using their latitude and longitude information, and setting appropriate distance thresholds based on the patient's travel range according to whether the institution is in an urban or rural area, as well as a method for estimating sales by medical institution on a recording medium. [Solution] The information processing system 100 normalizes the address information of pharmacies and medical institutions 110, obtains latitude and longitude using a geographic information API or the like 120, extracts medical institutions within a predetermined distance from the pharmacy 150, calculates a score inversely proportional to the distance to the extracted medical institutions 160, and allocates the pharmacy sales to each medical institution according to the score ratio 170. Furthermore, by outputting the allocation results and linking them with an analysis support platform, a probability model, and a sales support visualization tool 180, it provides an information infrastructure that contributes to understanding prescription practices, sales evaluation, and the advancement of marketing measures.
Owner:TCROSS INC

Wireless ad hoc network quantum security authentication method and related device

The invention belongs to the field of wireless ad hoc networks, and discloses a wireless ad hoc network quantum security authentication method and a related device, in a master station mode, a quantum protection key is written into equipment offline and is used for encrypting a one-time quantum authentication key, and symmetric challenge-response authentication is realized through ciphertext transmission and decryption; in the independent mode of the device, the device generates quantum random public and private keys and requests for a digital certificate, the server signs with a root certificate and then distributes, and certificate exchange and challenge-response authentication are supported. By adopting the method, the network security is remarkably improved, illegal access and data leakage are effectively prevented, stable operation of the key information infrastructure is ensured, the authentication reliability is enhanced, and different deployment requirements are met.
Owner:ZHONGSHAN XINTONG COMM CO LTD

Method and system for nuclear power plant key information infrastructure asset management

The invention belongs to the field of nuclear power, and particularly relates to a nuclear power plant key information infrastructure asset management method and system, and the method comprises the steps: 1, designing a nuclear power plant key information infrastructure asset data field list; 2, intelligently drawing a network topological graph according to the nuclear power plant key information infrastructure asset data; 3, off-line acquisition, processing and storage are carried out on nuclear power plant key information infrastructure asset data; and 4, performing preventive maintenance analysis on the nuclear power plant key information infrastructure asset data. According to the invention, comprehensive, efficient and safe management of nuclear power plant key information infrastructure assets can be realized, and emergency purchase and equipment replacement frequency can be reduced by identifying problems in advance and taking measures.
Owner:CNNC NUCLEAR POWER OPERATION MANAGEMENT CO LTD

Key information infrastructure-oriented network security operation situation awareness method

The invention belongs to the technical field of network security, and discloses a key information infrastructure-oriented network security operation situation awareness method, which comprises the following steps of: acquiring multi-modal original data of a CII, generating multi-target semantic tagged data through multi-target semantic tag labeling, and storing the multi-target semantic tagged data into a database; constructing an asset-event-business index dynamic association graph based on business topology; fusing to obtain a comprehensive situation entropy, and judging a risk to generate a risk response trigger signal; searching a defense immune memory bank for mode matching, generating a candidate treatment action set, and obtaining Pareto optimal treatment actions and matched corresponding resource requirements through multi-objective optimization screening; matching a preset three-level resource pool to execute a processing action, and synchronously monitoring the four-dimensional efficiency data to obtain a processing result and four-dimensional monitoring data; and quantifying a disposal effect through four-dimensional evaluation, reversely optimizing a full-link rule, updating a defense immune memory bank, and reversely associating to a multi-target semantic tag labeling link to form a closed-loop iteration situation awareness link.
Owner:HENAN CANCER HOSPITAL

Self-adaptive instruction system design suitable for disease control data collection

The invention mainly solves the following problems: aiming at the problems of low operation and maintenance efficiency, high security risk, opaque operation and the like of server remote management in an intranet isolation environment, a self-adaptive instruction system design suitable for disease control data collection is provided: multi-channel adaptation: three instruction transmission modes of SSH, Kafka and HTTP are integrated, and different network environment requirements are adapted. And safe penetration: internal network isolation is penetrated through a standardized protocol, so that remote operation is realized without modifying the existing network architecture. And operation tracing: adopting a unique instruction ID to realize full-link tracing, and meeting the requirements of the equal guarantee 2.0 compliance auditing. Authority control: instruction-level authority management is supported, and safety risks caused by excessive authorization are avoided. And file transmission: integrating a software package distribution function, and supporting remote system upgrading and maintenance. The market demand is that secret-related institutions such as disease control and the like urgently need remote operation and maintenance schemes meeting insurance waiting requirements. An enterprise needs to improve the IT operation and maintenance efficiency on the premise that the safety is not reduced; and the product advantages are that the operation efficiency is improved by more than 80%, and the field operation and maintenance requirements are reduced. Mainstream network protocols are supported, and the deployment adaptability is high. A complete operation log record is provided, and safety auditing is facilitated. High-risk ports do not need to be opened, and the safety is better than that of a traditional scheme. Through the advantages, the design provides a safe, efficient and compliant intranet server remote management solution, and the operation and maintenance management level of the key information infrastructure is remarkably improved.
Owner:DIGITAL HEALTH CHINA TECHNOLOGIES CO LTD

Systems and methods for a connected computing resource and event / activity identification information infrastructure using near existential or existential biometric identification of humans

Connected computing enables the use of highly diverse environments that support operating frameworks for contemporary civilization. But computing productivity and trustworthiness are undermined by such environments' largely inchoate organization. These environments and their identity infrastructures are fragmented, and unnecessarily unreliable, insecure, and insufficiently informative due to current computing entity (e.g., resource) identification infrastructure design, which lacks root identification reliability. Such reliability is enabled herein by a fundamentally accurate and authenticity ensuring, near-existential or existential quality, biometrically and liveness based, portable identification and provenance infrastructure. Such an infrastructure provides ubiquitously available identification information that can be used universally for identification processes. Such biometrically and liveness-based identification information can be contemporaneously acquired and securely fused with or otherwise bound to associated entity identification information sets. Such sets are used to identify and assess entity suitability and / or authenticity, and / or establish user identity (specific human entity) for personal, societal, and organizational activities.
Owner:ADVANCED ELEMENTAL TECHNOLOGIES INC

Key information infrastructure safety operation system and acquisition device

PendingCN121923793AUser identity/authority verificationBiological modelsCritical information infrastructureMarkov algorithm
The invention belongs to the technical field of safety operation, and particularly relates to a key information infrastructure safety operation system and an acquisition device, the system depends on a federated node network and a dual uplink criterion to realize whole-process safety management and control; the federated node network comprises a federated monitoring node subnet and a dynamic security mapping chain, the subnet is composed of multiple types of function nodes, and the mapping chain is constructed based on a block chain algorithm; the edge monitoring module analyzes a device state and distinguishes uplink and unuplink devices, and the risk assessment module combines a hidden Markov algorithm and an HSV mapping space to generate a risk map; the uplink monitoring module completes uplink judgment, real-time abnormity monitoring and downlink processing; through an SEIR model, a voting algorithm and the like, equipment identity verification, risk gradient visualization, abnormal early warning and dynamic uplink-downlink management and control are achieved, it is ensured that uplink equipment continuously meets the safety criterion, and the operation safety and stability of key information infrastructures are improved.
Owner:ZHEJIANG ZHENENG ELECTRIC POWER

Automatic model compliance examination method and system based on black box test multi-scene coverage

PendingCN122045073AError detection/correctionBiological modelsCritical information infrastructureThree dimensionality
The invention belongs to the technical field of artificial intelligence, and particularly relates to an automatic model compliance examination method and system based on black box test multi-scene coverage. According to the scheme, an input space is defined by constructing an intelligent sampling mechanism fusing business semantics, a key area is sampled in a high-density mode, a structured algorithm feature library containing a basic algorithm, a variety and an industry special template is established, and a model algorithm type is determined by adopting a double-track recognition mechanism fusing candidate screening, symbolic regression and AI analysis. And based on a reversible risk scoring model, the risk is quantified from the information retention degree, the mapping complexity and the confusion degree in a three-dimensional manner, and finally a structured compliance review report is generated. According to the method, the black box model deployed in the trusted execution environment can be subjected to automatic, quantifiable and traceable compliance review under the condition of no source code access, and the method is particularly suitable for the field of key information infrastructures with high compliance requirements such as electric power.
Owner:ELECTRIC POWER RES INST OF STATE GRID ZHEJIANG ELECTRIC POWER COMAPNY

A key information infrastructure-oriented hierarchical protection automation evaluation system

PendingCN122160129ASecuring communicationCritical information infrastructureAttack
The application discloses a kind of key information infrastructure-oriented level protection automation evaluation system, it is related to information security technical field, the method includes: performing asset identification and graph construction, by scanning and analyzing network environment, obtain multi-dimensional attribute and construct weight right and responsibility corresponding relationship graph atlas;Attack simulation and mode marking are executed, attack path is generated based on atlas and attack behavior is marked mode;Risk assessment and analysis are executed, and attack path and marked mode are quantitatively calculated using hybrid model, and risk assessment report is generated;Evaluation result generation and feedback are executed, and integrated analysis result generates automated evaluation report.The system includes asset identification and graph construction module, attack simulation and mode marking module, risk assessment and analysis module and system control and coordination module.The application can realize the fine modeling of key information infrastructure asset, dynamically simulate real attack scene, improve the practicality and accuracy of risk assessment.
Owner:BEIJING YOULUE SECURITY TECH CO LTD

Endogenous safety mimicry method and system based on non-invasive technology

PendingCN121864366ASecuring communicationAttackCritical information infrastructure
The invention relates to the technical field of cloud computing and network security, in particular to an endogenous security mimicry method and system based on a non-intrusive technology. Endogenous security mimicry of the cloud service system is realized through a non-intrusive service mimicry execution arrangement component, a dynamic heterogeneous executor pool, a mimicry scheduler, a multi-mode intelligent adjustor and a security management center. The method can endow the system with the endogenous security capability on the premise that the target system does not need to be transformed, effectively defend attacks based on unknown vulnerabilities and backdoors, remarkably improve the reliability and availability of the system, and is suitable for key information infrastructure scenes with high security requirements such as cloud computing, financial science and technology, government affair platforms and the like. And the toughness of the system to unknown threats is obviously improved.
Owner:SONGSHAN LAB

6G-based power grid communication method, equipment and system

The invention discloses a 6G-based power grid communication method, equipment and system, and belongs to the technical field of wireless communication and intelligent power grids. The method comprises the following steps: sensing a power grid service flow, and accurately mapping the power grid service flow to special network slices such as protection control, acquisition monitoring, mobile inspection and the like; terahertz and an intelligent metasurface technology are adopted at an air interface to realize ultra-low time delay and ultra-high reliability transmission; dynamically unloading a calculation task to an optimal edge node through computing power routing to realize local rapid decision; the real-time sensing and intelligent linkage of the state of the power grid facility are realized by utilizing the 6G sensing and calculation integration capability; and an endogenous security mechanism such as physical layer security and a block chain is introduced to guarantee the communication security. The corresponding device and system are used for implementing the method. The problem that the existing power grid communication technology cannot meet the requirements of a novel power system on the aspects of mass connection, extremely low time delay, ultrahigh reliability, intelligent endogenous property and the like is solved, and a solid information infrastructure is provided for constructing a future intelligent power grid.
Owner:南京市嘉隆电气科技股份有限公司

Method and system for realizing fault diagnosis of IT equipment and application system based on fault analysis model

ActiveCN116389225BEnergy efficient computingTransmissionIt equipmentInformation Operations
The application discloses a method and system for realizing IT equipment and application system fault diagnosis based on a fault analysis model, and aims to solve the problem of difficulty in analyzing and troubleshooting faults in information operation and maintenance fault analysis. The application utilizes information topology technology to perform associated management on asset allocation information, operation log data and monitoring index data of various information infrastructures in an oil field, can display all components of an application at one time, and can provide information such as states of each component and association between components in the system; the object fault analysis topology graph can be generated through object relationship mapping and object monitoring and asset allocation information, and can directly reflect running states of various objects, thereby providing a decision basis for information production command. Through comprehensive utilization of various technologies, the topology technology is comprehensively applied in information operation and maintenance fault analysis business, a unique information system fault diagnosis method is formed, and a powerful fault analysis means is provided for fault problems occurring in information operation and maintenance in the oil and gas industry.
Owner:PETROCHINA CO LTD

Monitoring facility security graphical user interface for electronic devices

ActiveCN309849693SGraphical user interfaceCritical information infrastructure
1. The name of the design product: monitoring facility security graphical user interface for electronic device. 2. The use of the design product: an electronic device. 3. The design points of the design product: the graphical user interface content in the screen, the electronic device is the existing design. 4. The picture or photo that best shows the design points: front view. 5. The product hardware part is a conventional design, and the rear view, left view, right view, top view and bottom view are omitted. 6. The use of the graphical user interface: the design product is used to prompt the user to view the key information infrastructure through the monitoring view. 7. The area of the graphical user interface in the product: the user can interact by clicking the interface button or module to load the subsequent graphical user interface or run the application.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Construction method of large digital twin reservoir management system

The invention provides a large-scale digital twin reservoir management system construction method, which comprises an entity project, an information infrastructure, a digital twin platform and an intelligent application, and is characterized in that the entity project comprises a project dam area, a reservoir area, upstream and downstream influence areas, buildings and electromechanical equipment; the information infrastructure comprises monitoring sensing equipment, a communication network, engineering automation control and an engineering basic environment, the digital twin platform comprises a model base, a knowledge base and a multi-dimensional multi-spatio-temporal data model, and the intelligent application comprises flood control benefit-making intelligent forecast scheduling, engineering safety intelligent analysis and early warning and production operation intelligent comprehensive management. According to the invention, it is ensured that reservoir management personnel can know current water and rain conditions, gates, safety monitoring and video monitoring information of a reservoir in real time, and can also timely predict future reservoir area water level change conditions and dam body safety and stability conditions through model calculation; and a manager is reminded to timely link the PLC system to open the gate for flood discharge.
Owner:HANGZHOU HUACHEN POWER CONTROL ENG CO LTD +1

Trusted security protection method and equipment based on network isolation

PendingCN121567449ASecuring communicationCritical information infrastructureSecurity software
The invention relates to the technical field of network isolation security, and provides a credible security protection method and equipment based on network isolation, and the method comprises the steps: setting a security software module between business software deployed in an extranet and a gatekeeper between the extranet and an intranet; before the service software initiates access to the intranet equipment, the security software module and the gatekeeper perform bidirectional security authentication based on the digital certificate, and the identity and integrity of the service software are verified in the authentication process; only after the authentication step is successfully completed, a trusted security data transmission channel is established between the security software module and the gatekeeper; and in the process that the service software performs service interaction with the intranet equipment through the security data transmission channel, the security software module and the gatekeeper cooperatively execute continuous security protection. According to the invention, the security defense line is substantially moved forward and extends to the service software, so that strong identity authentication of the access subject is realized, and the overall security of the key information infrastructure is systematically improved.
Owner:SHANGHAI GIDEKANG TECHNOLOGY CO LTD

Key information infrastructure association evaluation system and method based on large language model

PendingCN121283762AInference methodsSecuring communicationLinguistic modelCritical information infrastructure
The invention discloses a key information infrastructure association evaluation system and method based on a large language model, and the method comprises the steps: firstly extracting information from multi-source heterogeneous data through an entity extraction and relationship discovery engine based on large language model driving, and constructing and updating a unified risk knowledge graph; then, parallelly starting intrusion trace analysis and service logic security analysis, and writing an analysis result back to the knowledge graph for enriching; thirdly, calculating and generating an attack path from an attack entrance to a core target and a corresponding script based on the knowledge graph containing the threat analysis result; and finally, performing multi-mode empirical verification on the generated attack script, and feeding back a verification result to the knowledge graph to form a closed loop. According to the scheme provided by the invention, risk discovery, association analysis, attack simulation and closed-loop verification of the key information infrastructure can be automatically carried out, isolated security data points are converted into linked attack paths, and the evaluation depth, breadth and efficiency are remarkably improved.
Owner:THE THIRD RES INST OF MIN OF PUBLIC SECURITY

Attack data processing method, electronic equipment and storage medium

PendingCN121151068ASecuring communicationCritical information infrastructureAttack
The embodiment of the invention provides an attack data processing method, electronic equipment and a storage medium, and the method comprises the steps: firstly, in response to an attack instruction for a test system, selecting a plurality of test attack templates from a plurality of unified attack templates based on system state data of the test system, the plurality of unified attack templates are generated in advance based on a unified template language; then, based on the tactical identifiers in the plurality of test attack templates, determining an execution dependency relationship among the plurality of test attack templates, and based on the execution dependency relationship, generating an attack directed graph; and finally, generating a test execution scheme based on the attack directed graph, and performing simulation attack on the test system based on the test execution scheme, thereby remarkably improving the efficiency, accuracy and reproducibility of advanced persistent threat simulation in the key information infrastructure.
Owner:PENG CHENG LAB