Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

25 results about "Information systems security" patented technology

Information systems security, more commonly referred to as INFOSEC, refers to the processes and methodologies involved with keeping information confidential, available, and assuring its integrity. It also refers to: Access controls, which prevent unauthorized personnel from entering or accessing a system.

Information system security evaluation method and device, electronic equipment and storage medium

PendingCN121030748APlatform integrity maintainanceKnowledge representationAttackInformation systems security
The embodiment of the invention provides an information system security evaluation method and device, electronic equipment and a storage medium, and the method comprises the steps: obtaining an evaluation index model corresponding to a security evaluation request, and obtaining a simulation system corresponding to a target information system; performing vulnerability scanning on the simulation system based on the scanning missing tool and the MDATA knowledge base to obtain a corresponding first scanning result and a corresponding second scanning result, and performing scanning result fusion analysis based on the MDATA knowledge base to obtain a system risk assessment result of the simulation system; obtaining an optimized attack strategy based on the system risk assessment result and the MDATA knowledge base, and obtaining an optimized defense strategy based on the system risk assessment result and the expert knowledge base; the attack and defense test is performed on the simulation system based on the optimized attack strategy and the optimized defense strategy to obtain the attack and defense test result, and the security evaluation result of the target information system is obtained based on the evaluation index model and the attack and defense test result, so that the accuracy of evaluating the information system is improved.
Owner:PENG CHENG LAB

Evaluation method for security performance of information system

The invention discloses a method for evaluating the security performance of an information system. The method comprises the following steps: S1, matching an asset security baseline and compliance; s2, a dynamic security situation awareness step; s3, a multi-agent collaborative evaluation step; according to the information system safety performance assessment method, through real-time perception and trend prediction, the crossing from static assessment to dynamic early warning is realized, the adaptability to dynamic risks is improved, meanwhile, a multi-dimensional assessment system integrating asset compliance, dynamic situation and service toughness is established, and the assessment efficiency is improved. According to the method, firstly, multi-agent collaboration and topological correlation analysis are adopted, system key paths and deep correlation risks are accurately recognized, the risk recognition depth is improved, finally, evaluation full-process automation and model self-learning optimization are achieved, the evaluation efficiency is greatly improved, and the method is suitable for large-scale popularization and application. And the continuous advancement of the method is ensured.
Owner:STATE GRID HENAN ELECTRIC POWER CO MENGZHOU POWER SUPPLY CO

Network security evaluation system and method based on generative artificial intelligence

The invention discloses a network security evaluation system and method based on generative artificial intelligence, and belongs to the technical field of network and information security, and the system comprises a dynamic attack scene generation module, an automatic evaluation module, a user feedback collection module, an adaptive strategy optimization module, a multi-modal data fusion evaluation module, and a visual report generation module. The method comprises the steps of collecting desensitization threat intelligence and constructing an attack template, generating simulation attack data in an isolation environment through a generative AI, scheduling a test task and calculating indexes such as a detection rate and a false alarm rate, combining a user feedback optimization strategy and fusing multi-source data to construct a risk map, and finally generating an interactive evaluation report. According to the network security evaluation system and method based on generative artificial intelligence, comprehensive, continuous and intelligent evaluation of the security protection capability of an information system is realized through dynamic attack scene generation, multi-modal data fusion and a self-evolution evaluation strategy.
Owner:SHENZHEN HENGDE TESTING TECH CO LTD

Non-tampering operation and maintenance auditing system based on block chain

PendingCN121961756AFinanceVisual data miningResource consumptionInformation systems security
The invention provides a non-tampering operation and maintenance auditing system based on a block chain, and the system comprises a multi-source auditing data collection module, a block chain evidence storage engine, an intelligent contract auditing module, a cross-scene cooperative auditing module and a visual auditing platform, and all the modules cooperate according to a preset logic to form a closed-loop auditing system. According to the method, the problems of uncredible data, incomplete coverage, poor compliance adaptation, early warning lagging, insufficient cross-scene consistency and the like of a traditional operation and maintenance auditing system are solved, and through deep fusion of a block chain technology and an intelligent algorithm, auditing data full-link credible evidence storage, risk real-time perception, compliance automatic adaptation and cross-scene consistent tracing are realized; on the premise of guaranteeing the security and compliance of an information system, the auditing efficiency is improved, the operation and maintenance interference and resource consumption are reduced, and the operation and maintenance auditing requirements under complex IT architectures in multiple industries such as finance and government affairs are met.
Owner:HAINAN GESHAN NETWORK TECH CO LTD

Security test system and method for electric power information system

The invention discloses an electric power information system safety test system and method, and the system comprises a test management scheduling platform, a multi-level test execution engine, a real-time lossless collection and monitoring module, an intelligent analysis and decision engine, a digital twin simulation test platform, and a system self-protection and toughness evaluation module. According to the security test system and method for the electric power information system, all-around and deep security coverage of the electric power information system is realized, the breadth and depth of vulnerability discovery are remarkably improved, meanwhile, a real-time security test with lossless business is realized, high continuity and high availability of electric power production business are guaranteed, and secondly, the security of the electric power information system is improved. The intelligent and automatic testing process is realized, and the testing efficiency and the accurate decision-making capability of safety management are greatly improved.
Owner:STATE GRID HENAN ELECTRIC POWER CO WENXIAN POWER SUPPLY CO

Dynamic authority management system and method and multi-source heterogeneous message middleware

ActiveCN121000532AArtificial lifeDigital data authenticationMonitoring systemInformation systems security
The invention discloses a dynamic authority management system and method and multi-source heterogeneous message middleware, and relates to the field of authority management. The system comprises a monitoring system, a risk assessment system, an intelligent agent system and an authority management system. The monitoring system monitors user behaviors in real time to obtain real-time user behavior data; the risk assessment system performs comprehensive risk analysis on the real-time user behavior data to generate a real-time risk assessment result; the intelligent agent system comprises a plurality of intelligent agents with different functions, the intelligent agent system uses each intelligent agent to independently evaluate real-time user behavior data according to a real-time risk evaluation result to generate a voting result, and the voting result of each intelligent agent is synthesized to generate a final permission adjustment scheme; and the permission management system determines whether to execute the final permission adjustment scheme or not, and if the user behavior is recovered to be normal after the final permission adjustment scheme is executed, the user permission is automatically recovered. The user experience can be improved while the security of the information system is guaranteed.
Owner:BEIJING XINQIAO INFORMATION TECH CO LTD

Intelligent password service platform

The application relates to the technical field of information system security, and particularly discloses an intelligent password service platform, which comprises a service gateway, a synchronization module, a general server, a reverse proxy server and a plurality of password devices; the synchronization module is used for synchronizing key resources of password devices of the same type after the password devices access a network; the general server is provided with a virtual module and a load balancing module; the load balancing module is used for connecting the password devices after the key resources are synchronized; the virtual module is used for virtually changing physical resources of secret devices into resource clouds of different types through a virtualization technology; the service gateway is used for obtaining a calling application of a third-party application service interface; the service gateway is also used for analyzing the calling application and determining service requests facing different resource clouds according to the analyzed results. The technical scheme of the application has high expansibility, can be flexibly networked, is convenient for reusing and does not waste existing resources.
Owner:CHONGQING AEROSPACE INFORMATION CO LTD

A method for early warning of security vulnerability risks of an information system based on big data

ActiveCN118194290BOriginal dataThe Internet
The application discloses a kind of information system security vulnerability risk early warning method based on big data, comprising the following steps: step S1, the index library is established to enterprise internal various levels various types of information systems, network equipment, application software, and safety related data is collected;Step S2, integrate the security intelligence on Internet and third party vulnerability database, obtain the latest security vulnerability information, and carry out classified storage;Step S3, the original data collected is cleaned and preprocessed;Step S4, big data analysis and mining;Step S5, security vulnerability assessment and classification;Step S6, early warning trigger and notification;Step S7, establish security decision support system, provide reasonable security decision suggestion, the third party vulnerability database is collected, stored and analyzed in the application, realize the accurate detection and evaluation of potential vulnerability of business system, network and application program etc. each aspect, and timely security risk early warning and repair suggestion.
Owner:POWERCHINA HEBEI ELECTRIC POWER SURVEY & DESIGN INST CO LTD

A dynamic permission management system, method, and multi-source heterogeneous message middleware

ActiveCN121000532BArtificial lifeDigital data authenticationMonitoring systemInformation systems security
This application discloses a dynamic permission management system, method, and multi-source heterogeneous message middleware, relating to the field of permission management. The system includes a monitoring system, a risk assessment system, an intelligent agent system, and a permission management system. The monitoring system monitors user behavior in real time, obtaining real-time user behavior data. The risk assessment system performs comprehensive risk analysis on the real-time user behavior data, generating real-time risk assessment results. The intelligent agent system includes multiple intelligent agents with different functions. Each intelligent agent individually evaluates the real-time user behavior data based on the real-time risk assessment results, generates voting results, and combines the voting results of each intelligent agent to generate a final permission adjustment scheme. The permission management system decides whether to execute the final permission adjustment scheme. If user behavior returns to normal after executing the final permission adjustment scheme, the user's permissions are automatically restored. This application can improve user experience while ensuring information system security.
Owner:BEIJING XINQIAO INFORMATION TECH CO LTD

Information system code vulnerability detection method and system based on artificial intelligence large model

PendingCN122333476AAlgorithmEngineering
The embodiment of the application provides a kind of information system code vulnerability detection method and system based on artificial intelligence big model, belong to information system security field.The method comprises: obtaining the source code of information system to be detected;The source code is preprocessed;The code after preprocessing is input into pre-trained artificial intelligence big model and is analyzed multidimensionally;Potential vulnerabilities in the code are identified based on the analysis results, and the vulnerability detection results and repair suggestions are output.It reduces false positives and false negatives, improves the accuracy and coverage of vulnerability detection, can detect complex vulnerabilities that are difficult to detect by traditional methods, and is efficient and widely applicable.
Owner:ANHUI JIYUAN TESTING TECH CO LTD

Information system security protection method and system based on dynamic feedback

ActiveCN120934885ASecuring communicationInformation systems securityDistributed computing
The invention provides an information system security protection method and system based on dynamic feedback, and belongs to the technical field of system security and task scheduling. The method comprises the following steps: acquiring workflow feedback information of an information system in a current period; determining a plurality of workflow sub-graphs based on the workflow feedback information; each sub-container corresponds to one workflow sub-graph; identifying a first dependency relationship among the plurality of workflow sub-graphs, and constructing a security link graph; determining a security protection strategy of the information system in the current period based on the security link diagram; the security link diagram comprises a plurality of workflow nodes; the security protection strategy comprises configuring a first security protection level of each workflow node and a second security protection level of each sub-container. The system is used for implementing the method. According to the technical scheme of the invention, a multi-level accurate security protection strategy of the information system can be realized.
Owner:CHINA CYBER SECURITY REVIEW CERTIFICATION AND MARKET SUPERVISION BIG DATA CENT

Intelligent information system security detection and adaptive protection method based on deep learning

The invention discloses an intelligent information system security detection and adaptive protection method based on deep learning, which relates to the technical field of information system security protection, and learns a risk mode and predicts an attack probability by collecting historical security event data and adopting a convolutional neural network and long and short-term memory network combined model; secondly, network flow, system logs and user behaviors are monitored in real time through an adaptive protection module, abnormity is dynamically detected, and a protection mechanism is triggered; then, system configuration is automatically optimized according to detection and prediction results, and operations such as vulnerability repair and permission adjustment are completed; then generating a detailed report containing risks, vulnerabilities and reinforcement measures; and finally, performing retest through a tool consistent with the initial test, comparing reinforcement effects, and generating an online evaluation report. The method aims at automatically identifying and defending potential security threats in a system through training and real-time detection of a deep learning model, and dynamically optimizing a protection strategy, so that the security of an information system before the information system is online is improved.
Owner:EZHOU POWER SUPPLY COMPANY STATE GRID HUBEI ELECTRIC POWER

Dynamic permission allocation method and system based on iris recognition and real-time state monitoring

The invention provides a dynamic permission allocation method and system based on iris recognition and real-time state monitoring, and relates to the technical field of information system security, and the method comprises the steps: firstly collecting an iris texture image containing details such as eye iris sphincter contraction form and real-time state monitoring data containing information such as physical space coordinates; performing feature anchoring processing on the two to generate associated feature bodies which synchronously establish bidirectional mapping through timestamps, calling a historical permission interaction database to mine scene matching association, generating an adaptation rule pool, obtaining an initial permission scheme through matching of the associated feature bodies, tracking operation behavior data, and obtaining an initial permission scheme; the method comprises the steps of analyzing the degree of adaptation, feeding back and optimizing an adaptation rule pool, dynamically adjusting a permission range to generate a dynamic permission result, finally synchronizing the dynamic permission result to a permission management and control node and an associated operation terminal, executing a permission instruction and recording a permission change track to form a traceable data chain, thereby improving the security, flexibility and accuracy of permission distribution.
Owner:ZHONGTIAN KEYANG APPLIED TECHNOLOGY (SHANGHAI) CO LTD

Commercial vehicle personal data protection method and system based on two-factor authentication

PendingCN122093086AImplement automatic lockingImplement permission downgradeSecuring communicationDriver/operatorIn vehicle
The invention provides a commercial vehicle personal data protection method and system based on two-factor authentication, and belongs to the field of vehicle-mounted information system safety. The method comprises the following steps: receiving a user login request, starting a two-factor authentication process, and synchronously performing Bluetooth near-field verification and face biological feature recognition; determining a user identity type according to an authentication result, and loading a corresponding permission template; continuously monitoring a user authentication state and context environment information during the session; dynamically adjusting an available function and a data access range of the current account based on a monitoring result; and when it is detected that the user leaves, a protection mechanism is automatically triggered, and the account permission is limited or the session is locked. According to the method, through two-factor continuous authentication and dynamic authority management, the problems of data residue, no protection in leaving the vehicle, identity false use, extensive authority management and the like in a commercial vehicle driver random matching scene are effectively solved, and the safety and privacy protection level of vehicle-mounted personal data are remarkably improved.
Owner:CHERY COMMERCIAL VEHICLE (ANHUI) CO LTD

A digital power grid network security protection effectiveness quantitative evaluation method, system, device and medium based on a semantic event chain

The application discloses a kind of based on semantic event chain's digital electric network network security protection efficiency quantification evaluation method, system, equipment and medium, belong to network security and electric power information system security protection technical field, including acquisition heterogeneous data constructs semantic event graph;High-dimensional embedding vector is generated through graph neural network model;Complete attack path is constructed;Comprehensive success probability is calculated as baseline risk quantification index;Simulate the risk quantification index after protection after protection measure deployment;Get protection efficiency quantification score;Generate protection strategy adjustment suggestion and security response instruction.The application realizes end-to-end probabilistic quantification evaluation to complex multi-hop complete attack path by constructing semantic event graph and graph neural network embedding, calculates comprehensive success probability quantification protection measure efficiency, generates protection strategy adjustment suggestion and security response instruction, improves the identification, evaluation and response capability of power grid security threat.
Owner:INFORMATION CENT OF YUNNAN POWER GRID CO LTD

Improved role-based access control method and device

The invention relates to the field of information system access control, and particularly provides an improved role-based access control method and device, which are used for controlling role nodes based on a role access control model, temporarily controlling or releasing the authority of a specified role, and improving the access control efficiency. The authority of a specified role and a direct or indirect superior role thereof can be temporarily controlled or released; role-based access control controls operating rights to system resources by binding a user or group to a particular role. Compared with the prior art, the security of the information system can be improved, the security operation and maintenance management efficiency is improved, and the cost is reduced.
Owner:上海沄熹科技有限公司

Multi-parameter collaborative optimization control method and system for singular system under DoS attack

The invention relates to the field of information system security control, in particular to a multi-parameter collaborative optimization control method and system for a singular system under a DoS attack, and the method comprises the steps: building a singular system model and a DoS attack model; a reduced-order observer is constructed by solving a Sylvester equation, and a controller is designed in combination with the output of the reduced-order observer; establishing a closed-loop augmentation system based on control of a reduced-order observer; establishing sufficient conditions for enabling the closed-loop augmentation system to meet regularity, no pulse and asymptotically stable; performing iterative optimization by adjusting scalar parameters and solving a linear matrix inequality group, so as to cooperatively design gain parameters of a reduced-order observer and gain parameters of a controller, and finally determining a group of scalar parameter values; and calculating the maximum duration of the DoS attack and the minimum operation time required by the controller to realize collaborative optimization of the singular system stability and the operation cost. The problem that cost and complexity are increased due to a full-order observer control problem is solved.
Owner:INSPUR GENERSOFT CO LTD

Multi-dimensional self-adaptive container credibility evaluation method and system

The invention relates to the technical field of Dcoker information system security, in particular to a multi-dimensional self-adaptive container credibility evaluation method and system, and the method comprises the following steps: S1, deploying a test sample container on a host test board system by using a Docker client, and enabling the sample container to execute an instruction of an internal application program; s2, capturing and quantifying performance parameters of the sample container to obtain a signature sequence of the parameters; s3, obtaining an autocorrelation value of the context of the parameter according to the signature sequence of the parameter; s4, obtaining a direct trust value according to the autocorrelation value of the context of the parameter; s5, obtaining an interaction trust value according to the autocorrelation value and the direct trust value of the context of the parameter; and S6, obtaining a direct trust weight and an interactive trust weight according to the direct trust value and the interactive trust value, thereby obtaining a comprehensive trust value of the sample container. Compared with a traditional safety detection method, the method has the advantages that the detection accuracy is high, real-time adjustment can be carried out according to the parameter change of the container, and the adaptability is higher.
Owner:JIANGSU UNIV OF SCI & TECH

Safety communication platform of medical information system

The invention belongs to the technical field of safety communication, and provides a safety communication platform of a medical information system, which comprises the following steps of: establishing a historical sequence table according to the sequence of files checked by a doctor in a historical period, sorting to-be-transmitted files according to the historical sequence table to obtain a transmission sequence table, predicting the flow of each file to be transmitted in the predicted transmission time and performing stability analysis, performing secondary encryption on the file to be transmitted with unstable flow in the predicted transmission time according to the file sensitivity, predicting the transmission time of the file to be transmitted after the secondary encryption, and transmitting the file to be transmitted based on the transmission sequence table. And a dynamic adjustment strategy is formulated for the transmission priority of the to-be-transmitted file according to the predicted transmission time of the to-be-transmitted file after secondary encryption, so that the problem that the medical file transmission efficiency and security are unbalanced is solved, the file transmission security is ensured, and the file transmission efficiency is improved.
Owner:GUANGZHOU DEV ZONE HOSPITAL

Risk repair method and device for information system, equipment and storage medium

The invention relates to the technical field of information system safety protection, can be applied to the technical field of finance and medical treatment, and discloses a risk repair method and device for an information system, equipment and a storage medium. The method comprises the steps that based on a vulnerability recognition model, single-point vulnerabilities are recognized according to bottom layer codes, configuration parameters and operation data of an information system; on the basis of a graph convolutional network model, vulnerability propagation is identified according to a heterogeneous graph and single-point vulnerabilities constructed by an information system to obtain a risk state graph; determining each target repair strategy corresponding to each single-point vulnerability based on a multi-target optimization reward function according to the risk state diagram and a pre-configured candidate repair strategy; according to each target repair strategy, performing risk repair on the information system based on the code generation tool to obtain a repair system; and verifying the repair system, and when the verification is passed, determining that the information system is successfully repaired. And full-life-cycle intelligent management of the vulnerability of the information system is realized.
Owner:KANG JIAN INFORMATION TECH (SHENZHEN) CO LTD

Risk identification and evaluation method based on GB20984 standard and matrix method

The invention discloses a risk identification and evaluation method based on a GB20984 standard and a matrix method, and relates to the technical field of information system security risk assessment, and the method comprises the following steps: S1, determining the risk assessment range and target of an assessment object, and determining the basis and criterion of risk assessment of the assessment object; s2, performing asset identification, threat identification and vulnerability identification on the evaluation object, constructing an asset assignment table, a threat assignment table and a vulnerability assignment table, and performing asset assignment, threat assignment and vulnerability assignment on the evaluation object; and S3, constructing a risk calculation matrix which can be dynamically adjusted, and evaluating the risk level according to the value of the risk calculation matrix. According to the method, the asset value is integrated in the threat possibility-vulnerability severity two-dimensional framework, rapid judgment and evaluation decision of the risk size are realized by using the preset matrix, and an evaluation method which meets the standard, has relatively high operability and is visual in result is provided for information system risk management.
Owner:ZHONGKE DIGITAL MEASUREMENT (WUXI) TECH CO LTD

Risk prediction method and system combining iris recognition and behavior pattern learning

The invention provides a risk prediction method and system combining iris recognition and behavior pattern learning, and relates to the technical field of information system security, and the method comprises the steps: firstly collecting iris core features and behavior sequence data including an operation behavior sequence, a space movement sequence and a resource access sequence; associating individual historical behavior data based on iris core features, grouping according to behavior types, extracting features to generate an individual behavior baseline, collecting current behavior sequence data in real time, extracting current features, comparing the current features with the individual behavior baseline to calculate a deviation degree, performing attribution analysis on the behavior features exceeding a preset deviation threshold value, and obtaining an iris feature sequence; the method comprises the steps of judging a deviation reason in combination with individual identities, scene information and task information, generating a deviation attribution result, finally generating a risk prediction result containing risk types, occurrence probability quantization intervals and influence ranges in combination with historical corresponding relations based on the deviation attribution result and the deviation degree, and synchronously outputting risk intervention suggestions. And the efficiency and effect of risk management are effectively improved.
Owner:ZHONGTIAN KEYANG APPLIED TECHNOLOGY (SHANGHAI) CO LTD

Multi-parameter collaborative optimization control method and system for singular system under DoS attack

The application relates to the field of information system security control, in particular to a multi-parameter collaborative optimization control method and system for a singular system under DoS attack. The method comprises the following steps: establishing a singular system model and a DoS attack model; constructing a reduced-order observer by solving a Sylvester equation, and designing a controller in combination with the output of the reduced-order observer; establishing a closed-loop augmented system based on the reduced-order observer control; establishing sufficient conditions for the closed-loop augmented system to meet the regular, impulse-free and asymptotically stable; iteratively optimizing by adjusting scalar parameters and solving a linear matrix inequality set, so as to collaboratively design the gain parameters of the reduced-order observer and the gain parameters of the controller, and finally determine a group of scalar parameter values; and calculating the maximum duration of the DoS attack and the minimum running time required by the controller, so as to realize the collaborative optimization of the stability of the singular system and the running cost. The method solves the problems of cost and complexity increase caused by the full-order observer control.
Owner:INSPUR GENERSOFT CO LTD

A method for evaluating security performance of information system for level protection construction

ActiveCN115470482BPlatform integrity maintainanceSystem protectionInformation systems security
The application discloses a kind of information system security performance evaluation methods for level protection construction, belong to information system field, for solving the problem that information system is mostly fixed security protection level, file analysis module carries out protection analysis to the protection file in temporary storage module, obtains the file protection value of protection file and sends to performance adaptation module, the security performance of information system is analyzed using security analysis module, obtains the system protection value of information system and sends to performance adaptation module, the protection performance of protection file and information system is adapted by performance adaptation module, corresponding preset security level is obtained according to file protection value and system protection value, preset security level is compared to generate performance adaptation signal or performance increment signal, the security protection level of the application changes information system fixed, and the security protection level of information system is intelligently adjusted in combination with the protection requirement of file.
Owner:任国强

Automatic information system security vulnerability checking system and method based on artificial intelligence

PendingCN121902156ADigital data information retrievalDigital data protectionEngineeringInformation systems security
The invention discloses an automatic checking system and method for security vulnerabilities of an information system based on artificial intelligence, and the system comprises an asset collection client which is used for collecting system information of a target information system, packaging the system information into a structured data format, and obtaining the packaged system information; the data transmission module is connected with the asset acquisition client and is used for uploading the packaged system information to a central database through a security encryption channel; the artificial intelligence module is connected with the central database and used for analyzing the packaged system information to obtain a first vulnerability analysis result, and the first vulnerability analysis result comprises at least one of vulnerability data, vulnerability levels and vulnerability repair strategies.
Owner:CHINA CONSTR BANK CORP (DALIAN BRANCH)