Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

17 results about "Information security risk assessment" patented technology

Intelligent archive information security protection method and system

The invention discloses an intelligent archive information security protection method and system, and belongs to the technical field of information security protection. The method is used for solving the technical problem that the reliability and interpretability of an algorithm for archive information security protection in an existing scheme cannot be actively supervised and optimized. Initial weight distribution of sensitive levels is realized through an analytic hierarchy process, the Bayesian network quantifies the influence degree of real-time risk factors, weights are dynamically adjusted in combination with time attenuation factors, finally, a multi-dimensional archive information security risk assessment model capable of being dynamically optimized is constructed, an explicit logic basis is provided through rule reasoning, and an archive information security risk assessment model is established. A machine learning model quantifies a risk probability and explains key features, multi-source information is fused through a D-S evidence theory, finally, a decision path is tracked through a visual tree diagram, and multi-dimensional improvement of risk identification accuracy-decision transparency-system adaptability is realized through adaptive parameter adjustment and closed-loop optimization of an abnormal response strategy.
Owner:SHANDONG HANGDUO INFORMATION TECHNOLOGY CO LTD

Automatic information security risk assessment

The invention relates to a method for the automatic assessment of information security risks, especially for the automatic assessment of information security risks in an information technology, IT, infrastructure, and to a corresponding system for the automatic information security risk assessment.
Owner:FRAUNHOFER GESELLSCHAFT ZUR FORDERUNG DER ANGEWANDTEN FORSCHUNG EV

Information security risk assessment method for train wireless network control system

ActiveCN121218180AParticular environment based servicesFor mass transport vehiclesWireless networked control systemAttack
The invention relates to the technical field of train wireless network communication, in particular to an information security risk assessment method for a train wireless network control system, which comprises the following steps of: establishing an attack tree model according to a risk assessment object, assessing the occurrence possibility of a security event by using a triangular fuzzy number, analyzing attack paths, and calculating the interval probability of each attack path, the method comprises the following steps: obtaining a point probability according to an attack path interval probability, calculating an attack occurrence possibility, evaluating a security event influence by using a fuzzy analytic hierarchy process, calculating a security event risk value by quantifying the occurrence possibility and an influence value of the security event, and determining a risk level and a security level of a system according to a system risk evaluation value. And formulating corresponding protection requirements. According to the method, the information security risk of the train wireless network control system is effectively evaluated and managed, a basis is provided for formulating an effective security protection strategy, and the overall security capability of the train wireless network is improved.
Owner:DALIAN JIAOTONG UNIVERSITY

Information security risk quantification method based on risk hazard and asset structure decomposition

The present disclosure relates to the technical field of information security, in particular to an information security risk quantification method based on risk hazard and asset structure decomposition, comprising calculating a hazard quantification value of each vulnerability on each bottom-layer asset generating each information security risk based on a probability value and an influence value of each vulnerability on each bottom-layer asset of a business information asset system facing each vulnerability; merging at least two asset categories and the bottom-layer assets corresponding to the two asset categories, generating a weighted hypermatrix of the merged bottom-layer assets using a network analysis method, and solving a weight of each bottom-layer asset based on the weighted hypermatrix; and calculating an overall information security risk value of the business information asset system based on the hazard quantification value and the weight. The method comprehensively considers asset system structure and vulnerability risk distribution structure, flexibly utilizes a network analysis method for asset correlation importance analysis, and performs comprehensive information security risk evaluation and analysis of the system.
Owner:CHINA SOFTWARE TESTING CENT

An API-based information security risk assessment method and system

This invention discloses an API-based information security risk assessment method, which includes: using traffic analysis to acquire API assets within an enterprise; using a sensitive data identification model to identify and locate sensitive data in log files or files; integrating a vulnerability rule set to detect vulnerabilities in APIs through an API vulnerability detection model; setting up an automatic behavioral risk monitoring engine to monitor and issue early warnings in real time for abnormal API calls to obtain data; constructing a network attack monitoring model; using a risk monitoring model trained based on historical monitoring data to draw API risk chain relationships, and combining clue association ranking analysis to infer suspicious data leakage paths; comprehensively recording API data usage behavior; and using a matrix method to calculate risks and generate an API information security risk assessment report. This method can establish a comprehensive API security risk assessment system, effectively identifying and managing API security risks and protecting enterprise data security.
Owner:SHENZHEN PENGQUAN TECHNOLOGY CO LTD

Power Internet of Things information security risk assessment method

The invention discloses an electric power Internet of Things information security risk assessment method, and relates to the technical field of power generation risk assessment. Internet of Things equipment is installed in a power plant area, and an aggregation local area network is established based on the position information of the installed Internet of Things equipment and a wireless communication mode; setting an operation mode of the Internet of Things equipment based on the established aggregation local area network, periodically collecting environmental parameters and equipment state parameters in a power plant area based on the set Internet of Things equipment, analyzing the periodically collected environmental parameters and equipment state parameters in the power plant area, and constructing a risk analysis model; meanwhile, the power generation process of the power plant is evaluated in real time by collecting power generation indexes of the power plant in real time and a constructed risk analysis model, and risk prediction is performed on the subsequent power generation process of the power plant in a digital twinborn mode based on the power generation indexes of the power plant collected in real time and a real-time evaluation result. And the real-time performance of risk assessment of the power internet of things is improved.
Owner:国能四川天明发电有限公司 +1

A Multi-Dimensional Dynamic Information Security Risk Assessment System and Method for Detection Platforms

ActiveCN122093175AReal-time safety margin synchronizationmeet tolerance boundariesSecuring communicationAttackFalse alarm
This invention discloses a multi-dimensional information security risk dynamic assessment system and method for detection platforms, relating to the field of information security technology. It collects multi-dimensional operational parameters such as assets, vulnerabilities, and attacks, converting them into risk factors. An initial comprehensive risk index is calculated using a radial basis function algorithm. Real-time business load is sensed to calculate weight offsets, and risk weights are redistributed and normalized, updating the risk index. A sliding assessment cycle is used to clean the sequence, and quantile regression is applied to determine a basic threshold. This basic threshold is then adjusted using historical statistical data of the load status to generate a dynamic risk threshold. When the risk index exceeds the dynamic threshold, a risk is identified and a response is triggered. This achieves accurate risk fusion and adaptive judgment, reduces response lag, and improves assessment accuracy, aiming to solve the problems of insufficient risk perception and high false alarm rates in complex environments.
Owner:江苏省软件产品检测中心

Intrinsic safety management and control method integrating function safety and information safety

The invention provides an intrinsic safety management and control method integrating function safety and information safety, and relates to the technical field of intelligent industrial control, and the method comprises the steps: determining a multi-dimensional scene data record and a unique scene code identifier; calculating risk indexes based on a preset functional safety and information safety risk assessment model, performing correction fusion according to dynamic parameters in combination with the personnel exposure degree, the ignition probability and the accident risk influence coefficient to obtain a comprehensive dynamic risk level, automatically generating dynamic risk decision content for unacceptable risks, and performing risk assessment according to the dynamic risk decision content. Such as instrument-equipment fault decision, maintenance decision, personnel management and control decision, function safety and information safety protection measure decision and the like, and full-life-cycle collaborative risk management and control of the industrial process are realized. According to the method, the problems of difficulty in unifying multi-source data, lack of modeling, scene expression and risk analysis algorithms and the like in the aspect of functional security and information security integrated dynamic risk analysis and decision making in the prior art are solved.
Owner:INSTR TECH & ECONOMY INST P R CHINA

Road geographic information safety risk assessment method for open test of intelligent network connection automobile

The invention discloses an intelligent connected vehicle open test road geographic information safety risk assessment method, and relates to the technical field of road safety assessment, and the method comprises the steps: obtaining open test road geographic environment data, carrying out the preprocessing of the open test road geographic environment data, and obtaining the preprocessed region data; performing security risk factor identification on the preprocessed regional data to obtain data security risk factors; calculating a security risk score of each data security risk element; and performing security risk assessment through the security risk score to obtain an assessment result. According to the evaluation method, various potential safety risk factors in the open test road geographic environment can be comprehensively considered, and scientific and reliable geographic information safety guarantee is provided for the open test of the intelligent connected automobile through accurate calculation and evaluation. According to the method, the safety of the test road is improved, and powerful support is provided for research, development and popularization of the intelligent networked automobile.
Owner:GUANGZHOU URBAN PLANNING & DESIGN SURVEY RES INST +1

A train wireless network control system information security risk assessment method

ActiveCN121218180BParticular environment based servicesFor mass transport vehiclesWireless networked control systemAttack
The present application relates to train wireless network communication technical field, specifically to a kind of train wireless network control system information security risk assessment method, including according to the object of risk assessment to establish attack tree model, the possibility of security event is assessed using triangular fuzzy number and occurs, attack path is analyzed, and the interval probability of each attack path is calculated, point probability is obtained according to attack path interval probability, the possibility of attack is calculated, the influence of security event is evaluated using fuzzy analytic hierarchy process, the possibility of security event and impact value are quantified, security event risk value is calculated, the risk level and security level of system are determined according to system risk assessment value, corresponding protection requirements are formulated.The present application effectively evaluates and manages the information security risk of train wireless network control system, provides basis for formulating effective security protection strategy, and improves the overall security capability of train wireless network.
Owner:DALIAN JIAOTONG UNIVERSITY

Intelligent networked automobile information security risk assessment method and system

The invention is suitable for the technical field of intelligent network connection automobiles, and provides an intelligent network connection automobile information safety risk assessment method and system, and the method comprises the steps: obtaining real-time road condition abstract data in a preset road section in a specific road, historical passing track data of a target vehicle, and a vehicle group target direction corresponding to a vehicle-to-vehicle temporary relay; and extracting low-precision road condition information dynamically related to the target vehicle from the real-time road condition abstract data, and determining a predicted course consistency index and a predicted residence persistence index of the target vehicle based on the low-precision road condition information. The future driving trend and the stopping capability of the vehicle can be predicted under the condition that the vehicle does not need to open an accurate destination or a continuous track; and dynamically correcting the predicted value by taking the historical average angle deviation proportion as a correction factor, and generating a predicted comprehensive dynamic score value capable of comprehensively reflecting a direction deviation risk, a communication interruption risk and a potential malicious relay risk.
Owner:安徽中科星驰自动驾驶技术有限公司

Information security risk assessment and detection integrated system and method

The invention discloses an information security risk assessment and detection integrated system and method, and relates to the technical field of computer information security, the method comprises the steps of multi-source log acquisition, structured processing, dynamic compliance modeling, intention discriminant analysis and risk response linkage, and a behavior baseline model is constructed by performing semantic analysis and clustering on historical operation logs; according to the scheme, the semantic features and the compliance index of the current operation are combined, the threat confidence coefficient is calculated, deliberate damage, non-malicious damage or normal operation is automatically judged, a corresponding response strategy is triggered, deep fusion of risk assessment and anomaly detection can be achieved, and the active defense capacity of an information system is improved.
Owner:江苏省软件产品检测中心

Network information security risk assessment system based on AI

The invention relates to an AI-based network information security risk assessment system. The method comprises the following steps that: a data processing module acquires risk index data of a network topology region, and performs feature extraction on the risk index data to generate a risk feature vector; and the correlation analysis module performs similarity matrix calculation based on each risk feature vector to obtain correlation relationship data among different types of vectors, then inputs the data into a neural network model to construct a parameter correlation graph, and extracts network effect features among the data. And the feature fusion module calculates the correlation influence degree of each parameter according to the network effect features to obtain a corresponding global influence weight, and performs weighted fusion on the risk feature vectors based on the global influence weight to generate comprehensive feature representation. And finally, the risk assessment module inputs the comprehensive feature representation into a trained risk assessment model to obtain a risk score of the current security situation. According to the system, more efficient, intelligent and accurate evaluation of network security risks is realized, and stable and safe operation of a network information system is guaranteed.
Owner:ZHONGLIAN TAIDE (BEIJING) INFORMATION TECHNOLOGY CO LTD

An intelligent network connected vehicle information security risk assessment method and system

The application is suitable for the field of intelligent networked automobile technology, and provides an intelligent networked automobile information security risk assessment method and system.The method comprises the following steps: acquiring real-time road condition summary data in a preset road section in a specific road, historical passing track data of a target vehicle, and a vehicle group target direction corresponding to a vehicle-to-vehicle temporary relay; extracting low-precision road condition information related to the dynamic of the target vehicle from the real-time road condition summary data, and determining a predicted heading consistency index and a predicted residence persistence index of the target vehicle based on the low-precision road condition information.The future driving trend and residence capacity of the vehicle can be predicted without the vehicle publicly disclosing the accurate destination or continuous track; and the predicted value is dynamically corrected by taking the historical average angle deviation proportion as a correction factor, so as to generate a predicted comprehensive dynamic score value which can comprehensively reflect the direction deviation risk, the communication interruption risk and the potential malicious relay risk.
Owner:安徽中科星驰自动驾驶技术有限公司

Wind power system information security risk assessment method and device

The invention discloses a wind power system information security risk assessment method and device, and the method comprises the steps: building a multi-source data fusion model through collecting the multi-source heterogeneous data of a wind power plant group, obtaining a multi-dimensional data observation tensor, building a wind power system information dynamic behavior baseline model of a self-adaptive space-time diagram neural network based on the multi-dimensional data observation tensor, and carrying out the wind power system information security risk assessment. On the basis of the difference value between the output of the wind power system information dynamic behavior baseline model and actual data, a wind power plant group information collaborative intelligent safety risk assessment model is constructed, and accurate description and intelligent risk assessment of wind power system information behaviors are achieved. Therefore, the information security protection level and the long-term operation stability of the wind power system in a complex and changeable environment are improved, and the technical problems that the security situation of the system is difficult to comprehensively describe and the time-varying property of the operation state of the wind power system and the working condition drift problem are not fully considered in an existing wind power system information security assessment method are solved.
Owner:ELECTRIC POWER RES INST CHINA SOUTHERN POWER GRID CO LTD

Power Internet of Things Information Security Risk Assessment Method, Device, Equipment and Medium

The present invention discloses a method, device, equipment and medium for assessing information security risks of an electric power Internet of Things, and belongs to the field of information security technology. The method comprises: obtaining asset data and corresponding security vulnerability data in an electric power scenario, wherein the security vulnerability data includes frequency data of security incidents; constructing an information security risk assessment index system for an electric power Internet of Things system through the asset data and security vulnerability data; assigning weights to the index data in the information security risk assessment index system; and assessing the information security risks of an electric power Internet of Things system based on the frequency data of security incidents and weight data. The present invention optimizes expert scoring weights through a particle swarm optimization algorithm and a logistic chaos map, thereby alleviating the subjectivity of strong reliance on manual scoring, while ensuring that the weights have expert experience fidelity.
Owner:STATE GRID JIANGSU ELECTRIC POWER CO LTD RESEARCH INSTITUTE +2

Information security risk assessment method for optimizing SND based on improved PFS algorithm

PendingCN120915477AKernel methodsFuzzy logic based systemsPythagorean fuzzy setsImproved algorithm
The invention introduces an improved hooking fuzzy set (PFS) algorithm which is used for optimizing software defined network (SDN) information security risk assessment. The risk assessment of the SDN environment needs to consider the inherent uncertainty. A traditional evaluation method has limitation in the aspect of processing the uncertainty, and the research adopts a hook-of-thigh fuzzy set theory to express risk factors as fuzzy variables, so that the evaluation accuracy is improved. The invention provides an analytic hierarchy process and a decision test and evaluation laboratory method. The methods are combined with a stock hooking fuzzy set, so that the comprehensive performance of an SDN risk assessment model can be effectively improved, and a researcher adjusts key parameters in a traditional SDN risk assessment algorithm to adapt to special requirements of an SDN environment by optimizing the traditional SDN risk assessment algorithm. The accuracy of the evaluation model is improved through the improvement, in short, the method has remarkable advantages in the field of information security, and various information systems can be helped to accurately and effectively evaluate and cope with potential security threats.
Owner:王超 +2