Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

192 results about "Internet security" patented technology

Internet security is a branch of computer security specifically related to not only Internet, often involving browser security and the World Wide Web, but also network security as it applies to other applications or operating systems as a whole. Its objective is to establish rules and measures to use against attacks over the Internet. The Internet represents an insecure channel for exchanging information, which leads to a high risk of intrusion or fraud, such as phishing, online viruses, trojans, worms and more.

Industrial network risk perception and collaborative early warning method based on dynamic risk map

The invention discloses an industrial network risk perception and collaborative early warning method based on a dynamic risk map, and relates to the technical field of industrial internet security, and the method comprises the steps: S1, multi-source perception deployment; s2, heterogeneous data fusion acquisition; s3, constructing a knowledge graph engine; s4, analyzing depth data; s5, performing dynamic risk assessment; and S6, intelligent early warning decision making. According to the industrial network risk perception and collaborative early warning method based on the dynamic risk map, through fusion perception of OT layer data such as equipment states and process parameters, the problems of single perception dimension, evaluation lagging and disjunction in the prior art are solved, the false alarm rate is extremely low, and the method is suitable for popularization and application. Particularly, a dynamic adjustment mechanism of a time-varying risk weight matrix is improved, novel attacks can be dynamically responded, meanwhile, cross-domain risk conduction analysis is achieved, the accuracy and response speed of industrial network security early warning are improved, and meanwhile a closed-loop mechanism of attack path prediction and disposal suggestions is constructed.
Owner:BEIJING ANDY TECH CO LTD

Industrial production process APT attack detection method and system based on knowledge graph

The invention relates to the technical field of industrial internet security and artificial intelligence crossing, in particular to an industrial production process APT attack detection method and system based on a knowledge graph, and the method comprises the steps: obtaining industrial production data, carrying out the preprocessing of the obtained industrial production data, and obtaining an APT attack detection result; the preprocessed industrial production data are used as input for dynamic construction of a knowledge graph, known attack mode reasoning is carried out based on the knowledge graph, the known attack mode reasoning comprises the steps that a known attack chain is recognized through multi-hop matching of graph embedding, a time sequence graph convolutional network and an attention mechanism are fused to detect unknown abnormal behaviors, and the known attack chain is subjected to known attack mode reasoning. Data fusion is performed based on the topological relation of the knowledge graph, an attack entry node, an associated entity and a propagation path are positioned according to a data fusion result, and real-time detection and traceability of the hidden attack chain are realized by constructing the equipment-protocol-data stream three-dimensional semantic dynamic knowledge graph and fusing a graph embedding technology and a graph convolutional network.
Owner:HARBIN INST OF TECH AT WEIHAI

Dynamic trust evaluation method and system for heterogeneous convergence network nodes

The invention relates to the technical field of Internet security, in particular to a dynamic trust evaluation method and system for heterogeneous fusion network nodes, and the method comprises the steps: carrying out the dynamic modeling of a network into a space-time heterogeneous graph based on a network architecture of a cloud-edge cooperative industrial Internet of Things, and enabling the space-time heterogeneous graph to comprise a sensing layer node, an edge layer node and a cloud node; performing joint embedding characterization on the dynamic topology by using a knowledge graph embedding technology, and extracting node attributes and spatial-temporal characteristics of interaction; multi-source feature interaction is fused based on a cross attention mechanism, and the weight of a trust factor is dynamically adjusted through a multi-time-slot feature; and updating the trust evaluation model through an incremental learning strategy, and establishing a dynamic mapping relationship between a trust evaluation value and an equipment time sequence behavior mode. According to the method, continuous and accurate evaluation of the dynamic trust of the network nodes under the zero-trust architecture is realized by fusing the space-time diagram representation learning and the cross attention mechanism, and the anti-attack capability and the safety performance of the industrial Internet of Things are enhanced.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

Industrial internet security situation analysis method and system based on support vector regression

The invention provides an industrial internet security situation analysis method and system based on support vector regression, and relates to the technical field of industrial internet security, and the method comprises the steps: collecting alarm data, and recognizing a homologous alarm event through a time window sliding mode; establishing a time sequence propagation matrix, calculating a propagation probability, constructing an attack scene graph and extracting features; calculating a security situation index by using a support vector regression model; and selecting an optimal protection node combination based on the node centrality and the protection decision tree. According to the method, the threat propagation path can be accurately identified, the security situation can be quantified, and the precise protection of the industrial internet environment can be realized.
Owner:NAT IND INFORMATION SECURITY DEV RES CENT

Industrial internet security supervision method and system

The invention relates to the field of data processing, in particular to an industrial internet security supervision method and system, and the method comprises the steps: obtaining the operation data of equipment in industrial internet security supervision, setting an initial k value for each data point in the operation data, obtaining the neighborhood data points of each data point, and setting an initial k value for each data point; calculating a reference weight of the neighborhood data points based on the Euclidean distance and the acquisition time sequence of the neighborhood data points, calculating a density uniformity degree of each data point according to the reference weight, and correcting the initial k value according to a ratio between the density uniformity degree of the data points and a preset density threshold value to obtain a significant k value; and performing LOF anomaly detection on each data point by using the significant k value to obtain the anomaly degree of each data point, and detecting corresponding abnormal equipment in the industrial internet. According to the method, the proper k value is adaptively selected according to the actual distribution characteristics of the data points, so that the abnormal data points are detected more accurately, and misinformation and missing report are reduced.
Owner:SHANXI NETCHINA INFORMATION IND CO LTD

Industrial internet security management method and system based on multiple keys

The invention relates to the technical field of data transmission, and discloses a multi-key-based industrial internet security management method and system, and the method comprises the steps: collecting to-be-encrypted storage data, carrying out the analysis, obtaining an importance score, and determining an encryption mode; when composite encryption is carried out, the resource utilization rate is collected to determine a composite encryption scheme, and whether time sequence chaos temporary storage is carried out on the to-be-encrypted storage data or not is judged; the encrypted data and the vacancy rate after encryption are collected, a storage target sequence of the encrypted data is determined, and a similar voting value of each database in the encrypted data and the storage target sequence is obtained to determine a target database; and calculating a first hash value and a second hash value of the encrypted data, comparing the hash values, and verifying the integrity of the stored data. According to the method, the encryption failure and system delay risks are reduced, and the storage efficiency of the encrypted data under the resource shortage condition is improved.
Owner:BEIJING TONGFANG LEGENDSILICON TECH CO LTD

Industrial internet security monitoring control system

The invention relates to the field of industrial internet safety monitoring, and particularly discloses an industrial internet safety monitoring control system which comprises a network safety monitoring module, a control logic monitoring module, a traceability analysis module and an early warning execution module. The network security monitoring module analyzes a network attack risk level and an illegal access risk level through traffic baseline comparison, attack feature matching and risk model assessment; the control logic monitoring module identifies control logic abnormity based on the equipment operation state data and triggers a verification alarm; the traceability analysis module adopts a decision tree algorithm, combines the operation log, the behavior track and the version updating record, and judges that the tampering reason is misoperation, malicious tampering or system updating; and the early warning execution module triggers differentiated grading early warning according to the risk grade and tampering reason classification. The system can effectively identify external attacks, illegal access and logic tampering behaviors, and the security protection capability of the industrial internet is improved.
Owner:SHANXI ELECTRIC POWER CO POWER COMM CENT

Large security model construction method and application for industrial internet security protection

The invention relates to the technical field of large language models and network security, in particular to a security large model construction method and application for industrial internet security protection, and the method comprises the following steps: loading a base large model GLM-4, constructing a knowledge retrieval module, and accessing MITRE ATTamp; a CK knowledge base; the MITRE ATTamp; performing knowledge feature embedding vectorization on the safety knowledge in the CK knowledge base; establishing a vector database storage and retrieval module; a retrieval enhancement generation mechanism is started, and a test data set mitre-ttp-mapping is loaded; respectively constructing a local model and a comparison model, and carrying out a model comparison experiment; and evaluating the performance of the constructed security big model in a network security situation analysis task, evaluating the improvement effect of the model after applying a retrieval enhancement generation (RAG) mechanism, and outputting an RAG-based security big model scheme. The method and the device are suitable for security situation assessment in multiple scenes such as enterprises, industries and mobile scenes, and the accuracy and the interpretability of security content generation can be improved.
Owner:TONGJI UNIV +1

Knowledge destruction attack method and device based on RAG system, and medium

The invention discloses a knowledge destruction attack method and device based on an RAG system and a medium, and relates to the technical field of internet security, and the method comprises the steps: inputting a target question and an error answer into the RAG system, and generating an initial confrontation text; performing multiple rounds of iterative optimization processing on the initial adversarial text to obtain a target adversarial text; inputting the target adversarial text into a knowledge base corresponding to the RAG system; the RAG system responds to a question demand input by a user, and retrieves and outputs a question answer corresponding to the question demand from the knowledge base; and inputting the question demand and the question answer into a large language model, so that the large language model outputs a wrong answer corresponding to the target question. The method and the device are used for solving the problems of low output result precision, poor attack effectiveness and low concealment when knowledge destruction attack is carried out based on an RAG system in the prior art, and the precision of the output result is improved under the condition that the knowledge destruction attack is effectively carried out with high concealment.
Owner:TAIHU LAB OF DEEPSEA TECH SCI +1

System and method for routing-based internet security

Method and system for improving the security of storing digital data in a memory or its delivery as a message over the Internet from a sender to a receiver using one or more hops is disclosed. The message is split at the sender into multiple overlapping or non-overlapping slices according to a slicing scheme, and the slices are encapsulated in packets each destined to a different relay server as an intermediate node according to a delivery scheme. The relay servers relay the received slices to another other relay server or to the receiver. Upon receiving all the packets containing all the slices, the receiver combines the slices reversing the slicing scheme, whereby reconstructing the message sent.
Owner:MAY PATENTS LTD

Domain name resource record TTL tampering traceability positioning method based on analytic chain reasoning

The invention discloses a domain name resource record TTL tampering traceability positioning method based on analytic chain reasoning, and belongs to the technical field of Internet security monitoring. The method comprises the following steps: deploying a system which comprises a special server for managing a domain name, a plurality of repeaters and a plurality of recursive resolvers located at the upstream of the repeaters, and setting a TTL reference value stored in the special server; selecting a target transponder, and initiating a plurality of DNS query requests with time intervals to the target transponder by a user; and determining a cache mode of the target transponder based on the TTL value in the response corresponding to each DNS query request, and determining an object tampering the TTL reference value based on the cache mode of the target transponder and the TTL value in the response corresponding to each DNS query request. The method is used for realizing hierarchical positioning of TTL tampering responsibilities.
Owner:NAT UNIV OF DEFENSE TECH +1

Industrial internet security situation assessment and prediction method and system based on multi-stage feature enhancement and spatial-temporal feature fusion

The invention belongs to the technical field of industrial Internet security, and discloses an industrial Internet security situation assessment and prediction method and system based on multi-stage feature enhancement and spatial-temporal feature fusion, and the method comprises the steps: collecting multivariate data in an industrial Internet, carrying out the feature analysis, carrying out the missing value processing, abnormal value elimination, and normalization operation, and carrying out the prediction of the security situation of the industrial Internet. Forming a standardized security situation data sequence; extracting features of the security situation data sequence by using the constructed situation assessment model based on multi-stage enhancement; and on the basis of the extracted features of the security situation data sequence, constructing a situation prediction model based on spatio-temporal feature fusion to realize attack identification and prediction.
Owner:ELECTRIC POWER RES INST STATE GRID SHANXI ELECTRIC POWER

Network intrusion detection method and system based on multi-modal deep learning

The invention belongs to the technical field of Internet security, and discloses a multi-modal deep learning-based network intrusion detection method and system, which comprises the steps of carrying out collection and modal attribution on multi-source data from different channels, constructing a time-continuous multi-track dynamic sensing track set, integrating a modal attention distribution mechanism, and carrying out multi-modal deep learning. According to the modal energy sensing complexes of each type of modals under different sensing orbits, dynamically distributing modal parameters, and outputting an initial index tensor after multi-orbit modal fusion; receiving an initial index tensor, and establishing a cross-modal dependency relationship by constructing a bidirectional response tensor between a modal and an orbit; constructing a semantic trigger matrix based on semantic tags in a cross-modal dependency relationship, adopting a cross-modal residual connection mechanism, retaining low-order modal coupling features through a parallel residual path, and outputting modal linkage nodes; according to the invention, the identification capability of detection on complex intrusion behaviors is improved, and more comprehensive and accurate detection on complex network attack behaviors is realized.
Owner:聊城大学东昌学院 +1

Industrial internet operating system security risk prediction method and system based on knowledge graph

The invention relates to an industrial Internet operating system security risk prediction method based on a knowledge graph, and the method comprises the steps: collecting the security risk data of an industrial Internet operating system, and carrying out the preprocessing of the data; based on the preprocessed security risk data, constructing a security risk knowledge graph of the industrial internet operating system; constructing and training an industrial internet security risk prediction model based on the knowledge graph; and predicting real-time data of an industrial internet operating system by using the trained industrial internet security risk prediction model based on the knowledge graph, judging whether the system has a risk of occurrence of a security event, and generating a security risk prediction report according to a prediction result. Compared with the prior art, the method has the advantages that multi-source heterogeneous data such as equipment, users, application programs, vulnerabilities and security event response strategies are integrated, complex relations of the multi-source heterogeneous data are fully mined, and the security situation of the system can be more comprehensively and deeply grasped.
Owner:TONGJI UNIV

Consolidated Domain Management with DNS-Anchored Authority

An Internet domain designates a Domain Authority (DA) via a DNS record as a consolidated and trusted entity for collecting, validating, storing, and distributing domain-related information, including devices associated with the domain, services it provides, capabilities it supports, identities acting on its behalf, and policies governing access to its resources. The DA performs cross-category validation to ensure consistency across these information types and may publish information into DNS for compatibility, serve it dynamically through APIs, or deliver it over other secure channels. By inheriting DNS's trust model while replacing its rigid record-based structure with a unified and extensible framework, the DA provides stronger and more flexible management of domain data while enabling incremental deployment of new Internet security and capability features.
Owner:SWAMINATHAN KISHORE

Industrial internet attack and defense situation and risk early warning perception method

The invention discloses an industrial internet attack and defense situation and risk early warning and sensing method, and particularly relates to the field of internet risk early warning and sensing, which comprises the following steps of: acquiring multi-source heterogeneous data, constructing a basic data set covering an attack, service and equipment ternary space, including attack characteristics, service influence and equipment control vectors, and solving the problems of data heterogeneity and dispersion; constructing a triple function based on the data set, respectively quantifying the attack comprehensive threat degree, the influence degree of the attack on the service and the malicious control risk of the equipment, and retaining the characteristics of each dimension; a dynamic network topology model is constructed, nodes, edges and edge weights are defined, an attack propagation path and influence intensity are described, and node state dynamic updating is achieved; and finally, a risk prediction model is constructed by fusing quantitative indexes and topological information, a global risk value is calculated, graded early warning is realized through triple dimensions, a corresponding response mechanism is matched, and the timeliness and effectiveness of industrial internet security protection are improved.
Owner:WANLIAN INDEX (SHANDONG) INFORMATION TECHNOLOGY CO LTD

System and method for routing-based internet security

Method and system for improving the security of storing digital data in a memory or its delivery as a message over the Internet from a sender to a receiver using one or more hops is disclosed. The message is split at the sender into multiple overlapping or non-overlapping slices according to a slicing scheme, and the slices are encapsulated in packets each destined to a different relay server as an intermediate node according to a delivery scheme. The relay servers relay the received slices to another other relay server or to the receiver. Upon receiving all the packets containing all the slices, the receiver combines the slices reversing the slicing scheme, whereby reconstructing the message sent.
Owner:MAY PATENTS LTD

Large-screen video content review method and device, and storage medium

The application discloses a large-screen video content review method and device and a storage medium, relates to the technical field of Internet security, and comprises the following steps: obtaining a video to be reviewed, performing decoupling processing on the video to be reviewed, obtaining an audio stream and multiple video frames in the video to be reviewed, and converting the audio stream into an audio text; performing a text compliance detection operation on the audio text to obtain a first text review result corresponding to the audio text; performing an image compliance detection operation on the video frames to obtain an image review result corresponding to the video frames; if any one of the first text review result and the image review result is non-compliant, determining that a video review result of the video to be reviewed is non-compliant, and replacing the video to be reviewed with a preset compliant video to enable the preset compliant video to be played on a large-screen display device, thereby solving the technical problem of low recognition accuracy of single-mode detection in a complex scene and improving the accuracy and reliability of video content review.
Owner:SHENZHEN WANWU SECURITY TECH CO LTD

Big data risk early warning and evaluation method based on artificial intelligence

The invention relates to the field of internet security, and discloses a big data risk early warning and evaluation method based on artificial intelligence, comprising the following steps: step S1, collecting original security data from a heterogeneous data source; s2, constructing a global causal model; s3, constructing and evolving an event causal evolution diagram so as to establish directed edges with weights among the nodes; s4, dynamically evaluating the ability level of the attacker; s5, performing adversarial intention projection; s6, calculating a dynamic risk score; and generating an early warning when the score exceeds an early warning threshold. According to the method, asymmetric information flows among event types are quantified through transfer entropy, and a context evidence fusion mechanism is combined, so that a real causal relationship and a simple statistical correlation can be distinguished; the defect that a high false alarm rate is easily generated based on rule or simple threshold matching is overcome, so that the event causal evolution diagram can accurately reflect the internal logic and time sequence characteristics of an attack behavior, and the accuracy of complex threat perception is improved.
Owner:ZHEJIANG UNIV OF SCI & TECH

Industrial internet intrusion detection method based on multi-discriminator condition classification generative adversarial network

The invention relates to an industrial internet intrusion detection method based on a multi-discriminator condition classification generative adversarial network, and belongs to the field of industrial internet security. The method comprises the steps that a class imbalance data set of intrusion detection is acquired, and the class imbalance data set comprises a plurality of normal samples, attack samples with the number smaller than that of the normal samples and labels corresponding to all the samples; preprocessing the class imbalance data set, and dividing the data set; establishing a multi-discriminator condition classification generative adversarial network, and performing pre-training based on the divided data set; generating various attack samples through a pre-trained multi-discriminator condition classification generative adversarial network to obtain a class balance data set; establishing an intrusion detection model, and training the intrusion detection model by adopting the class balance data set; the trained intrusion detection model is used for real-time intrusion detection. According to the method, the problem of low detection rate of minority class attacks caused by unbalanced data samples in traditional intrusion detection is solved.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Symmetrical searchable encryption method and device, electronic equipment and storage medium

The invention provides a symmetric searchable encryption method and device, electronic equipment and a storage medium, and belongs to the technical field of industrial internet security, and the method comprises the steps: obtaining a keyword, an operation type and a file identifier of a to-be-updated file; and according to the keyword, the operation type and the file identifier, obtaining a data block related to the keyword, sending the data block to a server for storage, and updating preset index storage to realize update encryption. According to the keyword, the operation type and the file identifier of the to-be-updated file, the data block only related to the keyword is determined so as to ensure that the server cannot know the specific insertion time of the searched file and the storage position of the file, the non-adaptive file injection attack can be coped with, the safety is improved, and the user experience is improved. And the server only needs to store the data blocks related to the keywords, so that the resource overhead is reduced, and the method can be suitable for an actual industrial internet environment.
Owner:CHINA MOBILEHANGZHOUINFORMATION TECH CO LTD

Industrial internet security access equipment group and automatic security access method thereof

The invention discloses an industrial internet security access device group and an automatic security access method thereof. The device group comprises a remote security access device CPE deployed on the field side of a service terminal and a master station security access device BNG deployed in a security connection area of a service master station. A master station security access device BNG is deployed in a security connection area of a service master station, and a remote security access device CPE on a service terminal field side firstly encapsulates data and then forwards the data to the master station security access device BNG when a new service terminal initiates request data, so that the service terminal can access the data to the master station security access device BNG. After the data are analyzed and classified through a master station security access device BNG, the classified data are forwarded to a network service unit, and security authentication and IP address allocation are carried out on the wireless public network access terminal; the boundary defensive performance of the industrial internet is improved, it is ensured that the industrial internet service terminal is safely accessed through the wireless virtual private network, and the security vulnerability existing in the prior art is solved.
Owner:CHONGQING JINGXUN INFORMATION TECH CO LTD

Lightweight encryption method and system for industrial real-time data stream

The invention relates to the technical field of industrial internet security communication, and discloses a lightweight encryption method and system for an industrial real-time data stream, and the method comprises the following steps: intercepting an original data packet, and carrying out the deep packet detection to extract a network layer quintuple and application layer metadata; matching an optimal strategy in a strategy rule set according to the feature vector and generating a scheduling instruction; in response to the instruction, calling a corresponding pre-compilation password operation pipeline to carry out differential encryption processing on the load; and constructing a fixed-length security policy head containing the algorithm template identifier, and packaging and sending the fixed-length security policy head. According to the invention, task fragmentation is carried out by using a consistent Hash technology so as to ensure processing order-preserving. By adopting a lightweight message structure without handshake negotiation and a multi-level strategy scheduling mechanism, content-based fine-grained security protection is realized, and the communication requirements of low delay and high certainty are met while the security of industrial control data is ensured.
Owner:MAINTENANCE & TEST CENTRE CSG EHV POWER TRANSMISSION CO

Malicious task script detection method and system based on federal map learning

The invention belongs to the technical field of internet security, and particularly relates to a malicious task script detection method and system based on federal map learning, and the method comprises the steps: obtaining a PowerShell script, and carrying out the preprocessing of the PowerShell script, and obtaining a standardized abstract syntax tree; constructing a directed acyclic command flow graph based on the normalized abstract syntax tree, obtaining an adjacent matrix according to the command flow graph, and performing word embedding on the command flow graph to obtain a node feature matrix; performing GAT training on the node feature matrix and the adjacent matrix to obtain vector representation of the command flow graph, inputting the vector representation of the command flow graph into a preset federal learning detection model for detection, judging whether the script is a malicious script or not, outputting a judgment result, and deeply analyzing the script structure and semantics by constructing an abstract syntax tree and the command flow graph to obtain the malicious script. According to the method, wider confusion technologies and attack techniques including attacks without specific keywords can be detected, and the problem that attackers update the attack methods and cannot effectively detect the attacks is avoided.
Owner:XIDIAN UNIV

System and method for routing-based internet security

Method and system for improving the security of storing digital data in a memory or its delivery as a message over the Internet from a sender to a receiver using one or more hops is disclosed. The message is split at the sender into multiple overlapping or non-overlapping slices according to a slicing scheme, and the slices are encapsulated in packets each destined to a different relay server as an intermediate node according to a delivery scheme. The relay servers relay the received slices to another other relay server or to the receiver. Upon receiving all the packets containing all the slices, the receiver combines the slices reversing the slicing scheme, whereby reconstructing the message sent.
Owner:MAY PATENTS LTD

Accident early warning method based on dynamic deduction of physical information risk field

The invention belongs to the technical field of industrial internet, safety early warning and artificial intelligence crossing, and particularly relates to an accident advanced early warning and active intervention method and system for complex industrial systems (such as energy, chemical engineering and traffic), which integrate digital twinning, a physical information neural network and deep reinforcement learning. Comprising the following steps: multi-physics field coupling sensing and data assimilation; constructing and initializing a physical information risk field; performing dynamic inversion and deduction on a risk field; identifying a risk fission point and generating an intervention path; and through advanced early warning and strategy simulation feedback, interpretable insight of risk generation, conduction and evolution paths is realized, an active intervention strategy is finally generated, and an intelligent early warning and risk management and control closed loop is formed.
Owner:LUOHE POWER SUPPLY OF HENAN ELECTRIC POWER CORP

Internet security monitoring method based on big data

The invention discloses an Internet security monitoring method based on big data, and the method comprises the steps: obtaining network topology data in real time through the deployment of a three-dimensional visualization engine, generating a three-dimensional network structure model, and mapping network nodes and a connection relation into a spatial dimension. According to the method, a multi-dimensional data fusion algorithm is adopted, security indexes are associated with network topology, and a comprehensive security situation view is generated. Meanwhile, historical attack data are trained by using a machine learning algorithm, and potential attack paths and risk nodes are predicted in combination with real-time data. When an abnormal behavior is detected, a path tracking module is triggered to obtain a moving track of an attacker in a network, and key path nodes are highlighted in a three-dimensional model. Through the mode, the visual presentation and real-time monitoring of the network security situation are realized, and the efficiency and the accuracy of network security management are improved.
Owner:GUANGZHOU KAIYAS TECHNOLOGY CO LTD

An industrial Internet security control method for complex attacks

The present invention discloses an industrial Internet security control method for complex attacks, relates to the field of industrial Internet, and is used to solve the problem that the current industrial Internet security protection system cannot achieve effective defense and targeted defense, and cannot dynamically adjust its own defense. The method includes: step S1, analyzing the network connection risk situation of the production link connected to the industrial Internet, and analyzing to obtain the risk equipment rate of the production link; step S2, analyzing the historical intrusion situation of the production link connected to the industrial Internet, and analyzing to obtain the risk impact value of the production link; step S3, setting a corresponding security control strategy for the production link connected to the industrial Internet based on the risk equipment rate and the risk impact value; step S4, dynamically updating the security control strategy of the production link connected to the industrial Internet according to the attack situation. The present invention realizes targeted defense and dynamic defense of the industrial Internet when facing complex attacks.
Owner:NANJING SINOVATIO TECHNOLOGY CO LTD

Internet service security situation awareness system

The invention discloses an internet service security situation awareness system, which relates to the field of internet security, and comprises a service security management center which is provided with a data acquisition module, a data reference module, a situation analysis module, a data processing module, a security evaluation module and a risk awareness module; the data acquisition module acquires enterprise data flow information; the data reference module is used for constructing a security situation assessment parameter map; the situation analysis module is used for acquiring basic quantitative evaluation data corresponding to the corresponding enterprise data flow information; the data processing module is used for constructing a simulation virtual attack model; the security evaluation module is used for acquiring simulation quantitative evaluation data corresponding to the corresponding enterprise data flow information according to the simulation virtual attack model; the risk perception module is used for acquiring corresponding risk early warning information according to the quantitative evaluation data; according to the invention, the accuracy and timeliness in the security situation awareness process are improved to a certain extent.
Owner:ZHEJIANG SHUNQIYI MEDICAL TECHNOLOGY CO LTD

Security protection method and device for IPv6 network attack, electronic equipment and medium

The invention provides a security protection method for IPv6 network attacks, and relates to the technical field of Internet security. The method comprises the steps that a backbone network topology structure is built, the backbone network topology structure comprises an access layer router and a core layer router, and the access layer router and the core layer router are communicated in advance; a BGP4 + routing protocol is deployed based on the backbone network topology structure, and the BGP4 + routing protocol is used for enabling routers in the whole network in the backbone network topology structure to achieve BGP4 + routing reachability; an address control routing strategy is configured based on the backbone network topology structure, and the address control routing strategy is configured to be capable of notifying a forbidden target address to the whole network through a BGP4 + routing protocol; and in response to matching of the attack traffic with the target address in the access layer router, blocking the attack traffic to complete security protection. The invention further provides a security protection device for the IPv6 network attack, electronic equipment and a medium.
Owner:CERNET CORP