Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

97 results about "Internet security" patented technology

Internet security is a branch of computer security specifically related to not only Internet, often involving browser security and the World Wide Web, but also network security as it applies to other applications or operating systems as a whole. Its objective is to establish rules and measures to use against attacks over the Internet. The Internet represents an insecure channel for exchanging information, which leads to a high risk of intrusion or fraud, such as phishing, online viruses, trojans, worms and more.

Knowledge destruction attack method and device based on RAG system, and medium

The invention discloses a knowledge destruction attack method and device based on an RAG system and a medium, and relates to the technical field of internet security, and the method comprises the steps: inputting a target question and an error answer into the RAG system, and generating an initial confrontation text; performing multiple rounds of iterative optimization processing on the initial adversarial text to obtain a target adversarial text; inputting the target adversarial text into a knowledge base corresponding to the RAG system; the RAG system responds to a question demand input by a user, and retrieves and outputs a question answer corresponding to the question demand from the knowledge base; and inputting the question demand and the question answer into a large language model, so that the large language model outputs a wrong answer corresponding to the target question. The method and the device are used for solving the problems of low output result precision, poor attack effectiveness and low concealment when knowledge destruction attack is carried out based on an RAG system in the prior art, and the precision of the output result is improved under the condition that the knowledge destruction attack is effectively carried out with high concealment.
Owner:TAIHU LAB OF DEEPSEA TECH SCI +1

Domain name resource record TTL tampering traceability positioning method based on analytic chain reasoning

ActiveCN121396674AInference methodsSecuring communicationDomain nameAdministrative domain
The invention discloses a domain name resource record TTL tampering traceability positioning method based on analytic chain reasoning, and belongs to the technical field of Internet security monitoring. The method comprises the following steps: deploying a system which comprises a special server for managing a domain name, a plurality of repeaters and a plurality of recursive resolvers located at the upstream of the repeaters, and setting a TTL reference value stored in the special server; selecting a target transponder, and initiating a plurality of DNS query requests with time intervals to the target transponder by a user; and determining a cache mode of the target transponder based on the TTL value in the response corresponding to each DNS query request, and determining an object tampering the TTL reference value based on the cache mode of the target transponder and the TTL value in the response corresponding to each DNS query request. The method is used for realizing hierarchical positioning of TTL tampering responsibilities.
Owner:NAT UNIV OF DEFENSE TECH +1

Industrial internet security situation assessment and prediction method and system based on multi-stage feature enhancement and spatial-temporal feature fusion

The invention belongs to the technical field of industrial Internet security, and discloses an industrial Internet security situation assessment and prediction method and system based on multi-stage feature enhancement and spatial-temporal feature fusion, and the method comprises the steps: collecting multivariate data in an industrial Internet, carrying out the feature analysis, carrying out the missing value processing, abnormal value elimination, and normalization operation, and carrying out the prediction of the security situation of the industrial Internet. Forming a standardized security situation data sequence; extracting features of the security situation data sequence by using the constructed situation assessment model based on multi-stage enhancement; and on the basis of the extracted features of the security situation data sequence, constructing a situation prediction model based on spatio-temporal feature fusion to realize attack identification and prediction.
Owner:ELECTRIC POWER RES INST STATE GRID SHANXI ELECTRIC POWER

Consolidated Domain Management with DNS-Anchored Authority

An Internet domain designates a Domain Authority (DA) via a DNS record as a consolidated and trusted entity for collecting, validating, storing, and distributing domain-related information, including devices associated with the domain, services it provides, capabilities it supports, identities acting on its behalf, and policies governing access to its resources. The DA performs cross-category validation to ensure consistency across these information types and may publish information into DNS for compatibility, serve it dynamically through APIs, or deliver it over other secure channels. By inheriting DNS's trust model while replacing its rigid record-based structure with a unified and extensible framework, the DA provides stronger and more flexible management of domain data while enabling incremental deployment of new Internet security and capability features.
Owner:SWAMINATHAN KISHORE

Industrial internet attack and defense situation and risk early warning perception method

The invention discloses an industrial internet attack and defense situation and risk early warning and sensing method, and particularly relates to the field of internet risk early warning and sensing, which comprises the following steps of: acquiring multi-source heterogeneous data, constructing a basic data set covering an attack, service and equipment ternary space, including attack characteristics, service influence and equipment control vectors, and solving the problems of data heterogeneity and dispersion; constructing a triple function based on the data set, respectively quantifying the attack comprehensive threat degree, the influence degree of the attack on the service and the malicious control risk of the equipment, and retaining the characteristics of each dimension; a dynamic network topology model is constructed, nodes, edges and edge weights are defined, an attack propagation path and influence intensity are described, and node state dynamic updating is achieved; and finally, a risk prediction model is constructed by fusing quantitative indexes and topological information, a global risk value is calculated, graded early warning is realized through triple dimensions, a corresponding response mechanism is matched, and the timeliness and effectiveness of industrial internet security protection are improved.
Owner:WANLIAN INDEX (SHANDONG) INFORMATION TECHNOLOGY CO LTD

System and method for routing-based internet security

Method and system for improving the security of storing digital data in a memory or its delivery as a message over the Internet from a sender to a receiver using one or more hops is disclosed. The message is split at the sender into multiple overlapping or non-overlapping slices according to a slicing scheme, and the slices are encapsulated in packets each destined to a different relay server as an intermediate node according to a delivery scheme. The relay servers relay the received slices to another other relay server or to the receiver. Upon receiving all the packets containing all the slices, the receiver combines the slices reversing the slicing scheme, whereby reconstructing the message sent.
Owner:MAY PATENTS LTD

Large-screen video content review method and device, and storage medium

The application discloses a large-screen video content review method and device and a storage medium, relates to the technical field of Internet security, and comprises the following steps: obtaining a video to be reviewed, performing decoupling processing on the video to be reviewed, obtaining an audio stream and multiple video frames in the video to be reviewed, and converting the audio stream into an audio text; performing a text compliance detection operation on the audio text to obtain a first text review result corresponding to the audio text; performing an image compliance detection operation on the video frames to obtain an image review result corresponding to the video frames; if any one of the first text review result and the image review result is non-compliant, determining that a video review result of the video to be reviewed is non-compliant, and replacing the video to be reviewed with a preset compliant video to enable the preset compliant video to be played on a large-screen display device, thereby solving the technical problem of low recognition accuracy of single-mode detection in a complex scene and improving the accuracy and reliability of video content review.
Owner:SHENZHEN WANWU SECURITY TECH CO LTD

Big data risk early warning and evaluation method based on artificial intelligence

The invention relates to the field of internet security, and discloses a big data risk early warning and evaluation method based on artificial intelligence, comprising the following steps: step S1, collecting original security data from a heterogeneous data source; s2, constructing a global causal model; s3, constructing and evolving an event causal evolution diagram so as to establish directed edges with weights among the nodes; s4, dynamically evaluating the ability level of the attacker; s5, performing adversarial intention projection; s6, calculating a dynamic risk score; and generating an early warning when the score exceeds an early warning threshold. According to the method, asymmetric information flows among event types are quantified through transfer entropy, and a context evidence fusion mechanism is combined, so that a real causal relationship and a simple statistical correlation can be distinguished; the defect that a high false alarm rate is easily generated based on rule or simple threshold matching is overcome, so that the event causal evolution diagram can accurately reflect the internal logic and time sequence characteristics of an attack behavior, and the accuracy of complex threat perception is improved.
Owner:ZHEJIANG UNIV OF SCI & TECH

Lightweight encryption method and system for industrial real-time data stream

The invention relates to the technical field of industrial internet security communication, and discloses a lightweight encryption method and system for an industrial real-time data stream, and the method comprises the following steps: intercepting an original data packet, and carrying out the deep packet detection to extract a network layer quintuple and application layer metadata; matching an optimal strategy in a strategy rule set according to the feature vector and generating a scheduling instruction; in response to the instruction, calling a corresponding pre-compilation password operation pipeline to carry out differential encryption processing on the load; and constructing a fixed-length security policy head containing the algorithm template identifier, and packaging and sending the fixed-length security policy head. According to the invention, task fragmentation is carried out by using a consistent Hash technology so as to ensure processing order-preserving. By adopting a lightweight message structure without handshake negotiation and a multi-level strategy scheduling mechanism, content-based fine-grained security protection is realized, and the communication requirements of low delay and high certainty are met while the security of industrial control data is ensured.
Owner:MAINTENANCE & TEST CENTRE CSG EHV POWER TRANSMISSION CO

Malicious task script detection method and system based on federal map learning

The invention belongs to the technical field of internet security, and particularly relates to a malicious task script detection method and system based on federal map learning, and the method comprises the steps: obtaining a PowerShell script, and carrying out the preprocessing of the PowerShell script, and obtaining a standardized abstract syntax tree; constructing a directed acyclic command flow graph based on the normalized abstract syntax tree, obtaining an adjacent matrix according to the command flow graph, and performing word embedding on the command flow graph to obtain a node feature matrix; performing GAT training on the node feature matrix and the adjacent matrix to obtain vector representation of the command flow graph, inputting the vector representation of the command flow graph into a preset federal learning detection model for detection, judging whether the script is a malicious script or not, outputting a judgment result, and deeply analyzing the script structure and semantics by constructing an abstract syntax tree and the command flow graph to obtain the malicious script. According to the method, wider confusion technologies and attack techniques including attacks without specific keywords can be detected, and the problem that attackers update the attack methods and cannot effectively detect the attacks is avoided.
Owner:XIDIAN UNIV

Accident early warning method based on dynamic deduction of physical information risk field

The invention belongs to the technical field of industrial internet, safety early warning and artificial intelligence crossing, and particularly relates to an accident advanced early warning and active intervention method and system for complex industrial systems (such as energy, chemical engineering and traffic), which integrate digital twinning, a physical information neural network and deep reinforcement learning. Comprising the following steps: multi-physics field coupling sensing and data assimilation; constructing and initializing a physical information risk field; performing dynamic inversion and deduction on a risk field; identifying a risk fission point and generating an intervention path; and through advanced early warning and strategy simulation feedback, interpretable insight of risk generation, conduction and evolution paths is realized, an active intervention strategy is finally generated, and an intelligent early warning and risk management and control closed loop is formed.
Owner:LUOHE POWER SUPPLY OF HENAN ELECTRIC POWER CORP

An industrial internet vulnerability library establishment method

ActiveCN122021854BSolve deviationSolve the problem of inaccurate confidence assessmentThe InternetIndustrial Internet
The present application belongs to the technical field of industrial internet security, and relates to an industrial internet vulnerability library establishment method, which solves the problems of low construction quality, weak traceability, insufficient continuous evolution ability and difficulty in supporting deep security application of the existing vulnerability library. The present application obtains industrial internet multi-source vulnerability data and external feedback data, obtains extraction results and initial confidence based on multi-source vulnerability data by adopting rule extraction and remote supervision deep learning joint extraction, divides the certainty knowledge base and the to-be-reviewed queue according to the double threshold after the confidence is optimized by the graph convolution network, analyzes the external feedback data of the samples in the to-be-reviewed queue as the instant reward signal, optimizes the sampling strategy and updates the model through deep reinforcement learning, extracts triples from the certainty knowledge base to build a knowledge graph and generate a version hash chain regularly, and obtains a structured vulnerability knowledge base containing a hash chain and confidence evaluation. The present application realizes high-precision construction and dynamic optimization of the vulnerability library.
Owner:北京中关村实验室

Industrial internet security operation and maintenance risk assessment method and system

The invention discloses an industrial internet security operation and maintenance risk assessment method and system, and relates to the technical field of data management.The industrial internet security operation and maintenance risk assessment method comprises the steps that initial information collection is conducted on an industrial internet operation environment, risk links are constructed, and primary risk links are further analyzed and screened out; then obtaining dynamic operation data of each primary risk link, performing priority ranking based on the dynamic comprehensive risk score, and dynamically adjusting response triggering measures of the primary risk links at the same time to realize pertinence and timeliness of risk disposal; and finally, through cross validation of multi-level risk links, evaluation of actual effects of each adjustment measure and fine adjustment of a network security policy, potential risks can be effectively identified and quantified, a protection policy can be dynamically adjusted, the high-risk link disposal efficiency can be improved, and the security and stability of the whole system can be ensured. Therefore, the scientificity, controllability and reliability of industrial internet security operation and maintenance are obviously enhanced.
Owner:BEIJING HI TECH TECH

5G industrial internet security access control method and device

The invention provides a 5G industrial internet security access control method and device. Comprising the steps that a 5G industrial terminal initiates an access request to an edge network element, and industrial environment electromagnetic interference intensity and a terminal 5G signal to noise ratio corresponding to the access request are collected in real time; according to the collected industrial environment electromagnetic interference intensity and the signal-to-noise ratio of the terminal 5G signal, a safety access threshold is dynamically calculated in combination with the safety level of the terminal; based on the calculated security access threshold, cooperatively allocating channel resources and edge network element computing power resources in combination with the total occupancy rate of 5G private network channels and terminal encryption computing power requirements; acquiring the encryption delay of the edge network element to the terminal data, and correcting the effective success rate of the secure access of the terminal according to the cooperatively distributed resource weight and the encryption delay; if the corrected security access effective success rate reaches a preset threshold 0.8, the terminal is allowed to access the 5G industrial internet, and the security and stable operation of the SDN network in the key field can be guaranteed.
Owner:HUANENG HULUNBEIER ENERGY DEV CO LTD

A method and system for assessing data security protection capabilities in the industrial internet

PendingCN122093138ARealize high-precision detectionReduce false alarm rateSecuring communicationTopology mappingPathPing
This invention relates to the field of industrial internet security technology, and discloses a method and system for evaluating industrial internet data security protection capabilities. The method includes acquiring network traffic logs and system response records; performing time-series correlation analysis and sequence causal relationship completion based on the logs and records to obtain a dynamic evolution sequence of attack behavior; constructing an attack path graph model and parsing the correlation structure based on the sequence to obtain an attack path correlation structure; identifying high-latency paths and calculating response time differences to obtain a set of high-latency paths; extracting time feature vectors and quantifying the similarity of protection effectiveness from this set to obtain a quantitative score for path protection effectiveness; combining the score and difference index to perform a comprehensive risk assessment of physical topology mapping and node cascade failure analysis to obtain the system's comprehensive protection weaknesses; and performing adaptive scenario reconstruction closed-loop verification based on the weaknesses. This method can achieve accurate evaluation and dynamic verification of system protection weaknesses in complex adversarial scenarios.
Owner:北京优信新星科技有限公司

Industrial internet security analysis system based on digital twinning

The invention discloses an industrial internet security analysis system based on digital twinning, which belongs to the technical field of industrial internet security and comprises a platform end and a user end. Monitoring the industrial internet of the user in real time to obtain monitoring data; obtaining various potential safety problems according to the industrial internet information, and marking corresponding simulation association tags for the potential safety problems; analyzing the monitoring data according to various potential safety problems to obtain each target safety problem, identifying simulation association tags among the target safety problems, and forming a corresponding simulation problem combination according to the simulation association tags; the simulation problems are combined and sent to a platform end; and the platform end receives the simulation problem combination of each user end in real time, generates a problem simulation model of the simulation problem combination according to the industrial internet information, and performs analogue simulation on the problem simulation model through the problem simulation combination to obtain an analogue simulation result.
Owner:HUNAN VOCATIONAL COLLEGE OF SCI & TECH

Multi-dimensional encryption transmission protection method and system for cross-border payment

The present application relates to a multi-dimensional encryption transmission protection method and system for cross-border payment, belonging to the field of electronic digital data processing, more specifically to the field of Internet security services, the method comprising: using a gradient boosting decision tree and deep cross network fusion model to intelligently analyze a dynamic multi-dimensional encryption strategy uniquely corresponding to a current cross-border payment transaction according to each item of basic data associated with the current cross-border payment transaction. The present application also relates to a multi-dimensional encryption transmission protection system for cross-border payment. Through the present application, in view of the technical problems in the prior art that the encryption transmission protection strategies for each cross-border payment are difficult to balance security, transaction efficiency and power saving, and the corresponding key protection capability is insufficient, a gradient boosting decision tree and deep cross network fusion model designed with a customized structure is used to intelligently analyze a unique dynamic multi-dimensional encryption strategy for each cross-border payment transaction according to each item of basic data selected in a targeted manner, thereby solving the above technical problems.
Owner:GUANGZHOU HELIBAO PAYMENT TECH CO LTD

Industrial control instruction stream anomaly detection method and device based on deep learning

The invention discloses an industrial control instruction stream anomaly detection method and device based on deep learning, and relates to the technical field of energy industry internet security. The method comprises the following steps: restoring to generate an interactive session with a complete context based on a directionally collected industrial control instruction and an equipment state data stream; performing semantic structured processing on the instruction in the interaction session to generate structured semantic information which can be understood by a machine; taking the interaction session and the corresponding structured semantic information as a training sample, and constructing and training an instruction stream semantic model and an instruction stream execution effect prediction model; processing the real-time industrial control instruction stream, and inputting the processed real-time industrial control instruction stream into the instruction stream semantic model and the instruction stream execution effect prediction model to obtain a prediction result; and judging an anomaly detection result of the real-time industrial control instruction flow according to the output prediction result and an anomaly judgment rule.
Owner:CSG EHV POWER TRANSMISSION

Trojan virus-based mail processing method, device and equipment and storage medium

The application relates to the technical field of Internet security, and discloses a mail processing method and device based on a Trojan virus, equipment and a storage medium, the method comprises the following steps: when a Trojan virus mail is not intercepted, target account information of the Trojan virus mail is determined; virus characteristic information of the Trojan virus mail is obtained according to the target account information; a security linkage equipment is determined according to the virus characteristic information; and the Trojan virus mail is processed by linkage through the security linkage equipment. Compared with the prior art, the Trojan virus mail needs to be manually detected, and then manually processed. However, when the Trojan virus mail is detected, the security linkage equipment is determined according to the virus characteristic information corresponding to the Trojan virus mail, and then the Trojan virus mail is processed by linkage through the security linkage equipment, so that the processing efficiency of the Trojan virus mail is improved.
Owner:BEIJING HONGTENG INTELLIGENT TECH CO LTD

Abnormal application detection method and device, equipment and storage medium

The invention provides an abnormal application detection method and device, equipment and a storage medium, and relates to the technical field of computer security, in particular to the fields of artificial intelligence, mobile internet security, malicious code analysis, software homology detection and the like. According to the specific implementation scheme, a configuration file of a to-be-recognized application is analyzed to obtain bottom-layer features, and the bottom-layer features are used for representing the essential and difficult-to-change deep-layer features of the to-be-recognized application; performing multi-view feature extraction of at least two dimensions on the bottom-layer features, and extracting structural features and semantic features from the multi-view features; the multi-view features are used for representing that the to-be-identified application is analyzed and described from a plurality of different dimensions or angles; according to the structural features and the semantic features, obtaining an application fingerprint used for identifying the identity of the to-be-identified application; and performing anomaly detection on the to-be-identified application according to the application fingerprint.
Owner:BEIJING BAIDU NETCOM SCI & TECH CO LTD +1

Domain name parser cache mode identification method based on time sequence consistency analysis

The invention discloses a domain name parser cache mode recognition method based on time sequence consistency analysis, and belongs to the technical field of internet security monitoring. The method comprises the following steps: continuously sending domain name query commands for the same domain name to a target repeater for multiple times, and obtaining message data, the message data comprises an IP address of an upstream recursion resolver used for data collection in a message returned by the domain name server in response to each domain name query command, time when the domain name server receives the domain name query command and a TTL value of a resource record in a domain name query response; the detector continuously sends version query commands for obtaining the software version of the same domain name server to the target transponder for multiple times, query data is obtained, and the query data comprises version information in messages returned by the domain name server in response to the version query commands; and determining that the cache mode of the target transponder is a transparent mode based on the message data and the query data. According to the method, the caching behavior of the DNS transponder is accurately identified.
Owner:NAT UNIV OF DEFENSE TECH +1

Industrial internet security threat discovery method and system based on large model

The invention discloses an industrial internet security threat discovery method and system based on a large model, and relates to the technical field of industrial internet security. The method comprises the following steps: collecting and preprocessing multi-source heterogeneous security data in the industrial internet; converting the processed multi-modal data into a unified joint feature vector; performing context-aware reasoning on the feature vector by using a large language model subjected to instruction fine tuning, and outputting a threat degree evaluation result; constructing a dynamic threat graph based on an evaluation result, and performing association analysis on a multi-step attack chain; and continuously optimizing the model according to the feedback information. The system comprises corresponding modules. According to the method, the problems of detection lag, single analysis dimension and incapability of deeply perceiving complex threats in a traditional method are effectively solved, the capability of discovering unknown threats and advanced persistent threats is improved, and intelligentization, initialization and continuation of industrial internet security threat discovering are realized.
Owner:SAISHENG IND TECH RES INST (QINGDAO) CO LTD

Short message signature intelligent filing verification system

The invention discloses a short message signature intelligent filing verification system, and belongs to the technical field of Internet security services. According to the method, the problem that security defects exist in the face of key leakage, permission abuse and content fraud due to the fact that the prior art depends on a static key and a fixed strategy and lacks a behavior analysis and security mechanism is solved, and the authenticity and legality of a filing subject are ensured by introducing multi-factor authentication and combining a behavior portrait technology; based on dynamic trust evaluation and permission policy adjustment, intelligent access permission management is realized, normal business requirements can be met, abnormal behaviors can be timely handled, and system security is guaranteed; through Hash operation and dynamic instruction binding, the uniqueness and non-tampering performance of each short message request are ensured; and based on a response mechanism driven by a multi-layer check and decision tree model, efficient, safe and reliable operation of short message communication is further guaranteed.
Owner:深圳众投互联信息技术有限公司

CNN-BiLSTM hybrid architecture security situation analysis method of 5G + MEC private network

The invention discloses a CNN-BiLSTM hybrid architecture security situation analysis method of a 5G + MEC private network, and relates to the technical field of industrial Internet security and deep learning application. Comprising the steps that S1, preprocessed multi-dimensional heterogeneous data are received, the data format of the multi-dimensional heterogeneous data is unified into JSON, and data standardization is completed; s2, creating a CNN-BiLSTM hybrid architecture model, wherein the model comprises a CNN spatial feature extraction layer, a BiLSTM time sequence feature capture layer and an attention mechanism feature enhancement layer; and S3, outputting a threat identification result, a park security situation score, a risk early warning level and a probability of the CNN-BiLSTM hybrid architecture model, and providing a decision basis for a security response module.
Owner:INSPUR TIANYUAN COMM INFORMATION SYST CO LTD

Industrial internet multi-vulnerability association analysis method

The invention belongs to the technical field of industrial internet security, relates to an industrial internet multi-vulnerability association analysis method, and aims to solve the problems of insufficient feature fusion and misalignment of static analysis and path mining in the prior art. The method comprises the following steps: acquiring a standardized data set; extracting node topology, vulnerability permission and defense dynamic features, and generating a fusion feature matrix; predicting vulnerability elements based on the fusion feature matrix, and combining defense effect completion and filtering to generate a vulnerability element set; constructing a rule knowledge base; constructing a ternary weighted heterogeneous graph based on the quantitative features, the vulnerability element set and the rule knowledge base, and weighting directed edges; dividing node levels of the ternary weighted heterogeneous graph, based on an attack cost model, introducing a vulnerability privilege lifting logic constraint search path, mining an attack path with the minimum total cost, performing association analysis, and outputting a high-threat attack path list. According to the method, the comprehensiveness, the dynamicity and the accuracy of vulnerability association analysis are improved, and the high-threat attack path can be effectively identified.
Owner:北京中关村实验室

An internet security monitoring platform

PendingCN122453305AThe InternetSlide plate
The application relates to the technical field of monitoring platforms, in particular to an internet security monitoring platform, which comprises a data input layer for receiving order information, an analysis layer for analyzing order data, a monitoring layer for real-time order monitoring, and an execution layer for user operation on the order; the execution layer comprises an execution module, the execution module comprises a chassis, a support rod is fixedly connected to the upper side of the chassis, a top plate is fixedly connected to the support rod, an annular groove is formed in the top plate, a plurality of slide rods are slidably connected in the annular groove, a pressing plate is fixedly connected to the upper end of each slide rod, a panel is fixedly connected to the upper side of each pressing plate, a sliding plate is slidably connected to the outer side of each slide rod, a spring is fixedly connected between each corresponding sliding plate and pressing plate, a sleeve is slidably connected to the bottom of each slide rod, an electromagnet is glued in the interior of each sleeve, a polar plate is fixedly connected to the bottom of each sleeve, a sliding groove is formed in the chassis, and an electrode I and an electrode II are glued in the sliding groove; the internet security monitoring platform has the beneficial effect of realizing timely error correction of user orders.
Owner:关慕结

Method and device for preventing application program from being secondarily packaged and released and electronic equipment

The invention provides a method and device for preventing an application program from being secondarily packaged and released and electronic equipment, and relates to the technical field of internet security. The method comprises the steps that a dynamic secret key request initiated by a client is received, and the dynamic secret key request carries a temporary public key, application signature information, a device unique identifier and a timestamp; verifying the legality of the client based on the application signature information and the timestamp; when the verification result is legal, generating a dynamic symmetric key, binding the dynamic symmetric key with the application signature information and the unique identifier of the equipment, and setting the validity period of the key; and encrypting the dynamic secret key by adopting the temporary public key, and transmitting the encrypted dynamic secret key back to the client, so that communication data between the server and the client are encrypted and transmitted through the dynamic symmetric secret key in the subsequent period of validity of the secret key. The secondary packaging APP with the tampered signature cannot pass the verification of the server to obtain the effective key and cannot normally use the core service, so that the APP is fundamentally prevented from being packaged and released for the second time.
Owner:GUANGZHOU XINYU NETWORK TECH CO LTD

Industrial internet data security access method based on cloud edge collaboration

The invention relates to the technical field of industrial internet security access, and discloses an industrial internet data security access method based on cloud-edge collaboration, which comprises the following steps: step 1, edge security control equipment acquires multi-dimensional original data of field production and environment in real time, analyzes the multi-dimensional original data by using a built-in working condition quantification model, and stores the analyzed multi-dimensional original data; calculating and generating a working condition grading label representing the current field state; step 2, the edge security control device pre-constructs data views with different data granularities for the multi-dimensional original data in the local storage space; edge multi-dimensional data collection and working condition semantic quantification are adopted, local multi-granularity view pre-construction is combined, the effect of authorizing views on demand for different function subjects is achieved, and compared with the scheme that data lacks edge business semantic marking in the prior art, the problem of mixed transmission of production and environmental protection data is solved; and core process parameters are not easy to shield effectively when supervision data are opened.
Owner:CHONGQING XINYIYUAN INTELLIGENT TECH CO LTD

Industrial internet security gateway access control method based on NFV

The invention relates to the field of industrial internet security, and discloses an NFV-based industrial internet security gateway access control method, which comprises the following steps: acquiring equipment core information, and generating a core permission release decision through multi-dimensional rule matching and abnormal mode detection; in combination with the NFV function chain, a security module corresponding to the non-core permission of the equipment is loaded in a delayed manner to form preliminary non-core permission state information, the preliminary non-core permission state information is compared with historical data of the equipment, an abnormal scoring algorithm is utilized to evaluate potential risks, an abnormal behavior judgment result is generated, if the equipment is abnormal, an intrusion induction and behavior tracking module is triggered in the NFV function chain, and the abnormal behavior judgment result is generated. And guiding the abnormal equipment to a controllable environment to execute operation, generating an abnormal behavior training data set, and if the equipment is normal equipment, incorporating the operation data, the operation sequence and the state information into the abnormal behavior training data set, and generating an optimized authority strategy basis. The method has the advantages that the safety and the active protection capability are improved.
Owner:SHANGHAI AOZHENG NETWORK TECHNOLOGY CO LTD

An industrial internet multi-vulnerability correlation analysis method

ActiveCN122069111BData setAttack
The application belongs to the technical field of industrial internet security, and relates to an industrial internet multi-vulnerability correlation analysis method, aiming to solve the problems of insufficient feature fusion, static analysis and inaccurate path mining in the prior art. The method comprises the following steps: obtaining a standardized data set; extracting node topology, vulnerability permission and defense dynamic features to generate a fusion feature matrix; predicting vulnerability elements based on the fusion feature matrix, combining defense effect completion and filtering to generate a vulnerability element set; constructing a rule knowledge base; constructing a three-element weighted heterogeneous graph based on the quantified features, the vulnerability element set and the rule knowledge base, and weighting the directed edges; dividing the node levels of the three-element weighted heterogeneous graph, searching for a path with the minimum total cost based on an attack cost model and by introducing vulnerability power-up logic constraints, mining the attack path with the minimum total cost, performing correlation analysis, and outputting a list of high-threat attack paths. The application improves the comprehensiveness, dynamics and accuracy of vulnerability correlation analysis, and can effectively identify high-threat attack paths.
Owner:北京中关村实验室