Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

7 results about "Insider attack" patented technology

An insider attack is a malicious attack perpetrated on a network or computer system by a person with authorized system access.

Protection method and system for preventing file leakage in cloud space

The invention discloses a protection method and system for preventing file leakage in a cloud space, and the method comprises the steps: encrypting a file stored in the cloud space by a user in the cloud space, and enabling the user to remotely log in and access the cloud space to carry out the cloud file operation of the file. The access trace of the user for accessing the cloud space last time needs to be provided for decrypting the file. A user private key is protected by a symmetric key associated with a user name, a user password HASH and an access trace, a file encryption key is decrypted by using the user private key obtained by decryption, all files stored in a cloud space by a user are encrypted and stored, and the key is subjected to multiple protection, so that all files are encrypted and stored by an internal attacker, a manager or an external attacker. Even if the user name and the password and even all private information of the user stored in the system are obtained, the file stored in the cloud space by the user cannot be decrypted.
Owner:STATE GRID LIAONING SHENYANG ELECTRIC POWER SUPPLY COMPANY +2

A Post-Quantum Secure Linkable Ring Signature Method and System Resistant to Internal Attacks

This invention discloses a post-quantum secure linkable ring signature method and system resistant to internal attacks, comprising: a first service device generating public parameters; each user device generating its own public-private key pair using the public parameters and sending its public key to the first service device for registration; the first service device verifying all received identity information and forming a public key ring from the public keys of all verified user devices and making it public; when any user device needs to send a message to a second service device, it generates a ring signature containing a linkable tag based on its own private key, the message, and the public key ring, and sends the ring signature and the message to the second service device; the second service device performing security verification on each ring signature and, after successful verification, verifying whether different ring signatures belong to the same user device based on the linkable tag. This invention can protect user privacy in anonymous scenarios, enable multiple signatures from the same user, and resist attacks from within.
Owner:XIAN UNIV OF POSTS & TELECOMM

API security monitoring and risk analysis system

The invention relates to the technical field of API security monitoring, and discloses an API security monitoring and risk analysis system, which comprises an intelligent sampling module used for intelligently sampling interface calling flow in an enterprise API gateway system to obtain a standardized API calling data set; the feature extraction module is used for performing multi-dimensional security feature extraction to obtain an API calling security feature set; the real-time processing module is used for performing real-time processing to obtain a potential attack type judgment result; the mode matching module is used for carrying out behavior sequence analysis and mode matching to obtain an API attack behavior characteristic spectrum and a real-time threat level; according to the method and the system, the session token leakage attack and the privilege internal attack are effectively prevented, and the security of API calling is improved.
Owner:深圳华科讯通科技有限公司

A distributed data storage security protection system

This invention relates to the field of data storage protection technology and discloses a distributed data storage security protection system. The invention includes a data sharding and commitment unit, a high-fidelity deception shard generation unit, an obfuscated storage control unit, an immune verification and reading unit, and a distributed commitment and graph management unit. By dividing logical data objects into real data shards and constructing a Merkle tree to generate the Merkle tree root, high-fidelity deception shards are generated by extracting the structural features of the real shards. Real and deception shards are obfuscated and stored on multiple nodes. During reading, the shards and proof paths returned by multiple nodes are cross-validated based on the Merkle tree root to identify compromised nodes and trigger an immune response, including node marking, alarm broadcasting, and data self-healing. This invention can effectively respond to internal attacks and highly covert deception attacks, improving the security and reliability of the distributed storage system.
Owner:HEBEI MINGWEI DIGITAL TECHNOLOGY CO LTD

A trust management method for a fog node in edge computing

ActiveCN116244700BPathPingData set
This invention belongs to the interdisciplinary fields of edge computing, privacy and security, and machine learning. It discloses a trust management method for fog nodes in edge computing. First, it calculates the fog node's trust value based on subjective trust value, indirect trust value, and capability trust value. The Bellman equation is used to solve for the shortest trust path, resulting in an initial dataset containing the three trust attributes of the fog node. This initial dataset is divided into a training set and a test set. The dataset is preprocessed by blurring the distribution range of the trust values. The trust attribute with the largest information gain in the training set is calculated as the splitting attribute. The training set is then divided into several subsets. The partitioning terminates if all fog nodes in a subset belong to the same category or if all candidate attributes of a fog node have been used. After generating a decision tree, a loss function is used to prune the decision tree. This invention demonstrates reliability and effectiveness in detecting malicious nodes and internal attacks.
Owner:NANJING UNIV OF POSTS & TELECOMM

A database insider attack detection method, system, device and medium based on ensemble learning

A database insider attack detection method, system, device and medium based on ensemble learning, the method comprises the following steps: obtaining logs and human resource forms in a database, and preprocessing the obtained data; dividing a training set and a validation set; splitting and recombining to construct a training set and a validation set of query syntax data set, query result data set and insider information data set; training respective sub-models using the training set, optimizing the sub-models through the validation set, and obtaining optimal sub-models; fusing the three sub-models to form a trained integrated model, calculating an alarm threshold, and confirming data stealing behavior; obtaining newly generated logs and human resource forms from the database, preprocessing the new data; reconstructing a new data set; inputting the new data set into the optimal sub-model and the integrated model to determine data stealing behavior; the present application reduces the false detection rate and the missed detection rate, improves the detection accuracy, and effectively improves the comprehensive performance of the model.
Owner:XIDIAN UNIV

Practical quantum privacy comparison protocol method based on Bell state and rotation operation

The invention discloses a Bell state and rotation operation-based practical quantum privacy comparison protocol method, which comprises the following steps that: a semi-honest third party prepares S and records the state of the S, and first particles and second particles in all Bell states are respectively utilized to form S1 and S2; first eavesdropping detection is carried out, if the first eavesdropping detection passes, the first participant and the second participant respectively obtain S1 and S2, and the next step is continued, otherwise, communication is stopped; the first participant and the second participant act rotation operations Ry (piX) and Ry (piY) on the S1 and the S2 respectively to obtain SA and SB and send the SA and the SB to the semi-honest third party; the semi-honest third party sequentially executes Bell-based measurement on the SA and the SB to obtain a measurement result, if the measurement result is consistent with the quantum sequence S, the semi-honest third party declares that the privacy information of the first participant and the privacy information of the second participant are the same, otherwise, the privacy information of the first participant and the privacy information of the second participant are different. According to the method, possible information leakage is effectively prevented, the capability of resisting external and internal attacks of the method provided by the invention is remarkably enhanced, and the technical threshold and the cost of implementation are greatly reduced.
Owner:JINJIANG COLLEGE OF SICHUAN UNIV