Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

4526 results about "Internet traffic" patented technology

Internet traffic is the flow of data within the entire Internet, or in certain network links of its constituent networks. Common measurements of traffic are total volume, in units of multiples of the byte, or as transmission rates in bytes per certain time units.

Ai-based cybersecurity system and method thereof

An AI-based Cybersecurity System and Method enable real-time detection, analysis, and mitigation of cyber threats within computing networks using adaptive artificial intelligence. The system continuously monitors network traffic, extracts behavioral and contextual attributes, and applies deep learning-based inference to identify anomalous activities indicating security breaches. The method integrates several computational units, including a network monitoring unit, feature extraction unit, artificial intelligence processor, contextual reasoning processor, and decision synthesis unit, to compute a composite risk index quantifying threat likelihood and severity. A classification processor categorizes detected threats into types such as ransomware, phishing, or unauthorized access, while a mitigation control processor initiates automated response actions to isolate compromised nodes and restore network integrity. An adaptive learning processor updates AI models using feedback from confirmed incidents. This provides a scalable, self-evolving cybersecurity framework that minimizes human intervention and enhances resilience against dynamic and zero-day threats.
Owner:PELL REDDY RAJENDER REDDY

Network security big data state evaluation method based on pattern recognition

The invention relates to the technical field of network security, in particular to a network security big data state evaluation method based on pattern recognition, which comprises the following steps of: extracting multi-modal features from a network flow log, a system event log, a host behavior log and threat intelligence data, generating a feature matrix, performing feature dimensionality reduction by adopting an auto-encoding network, and obtaining a network security big data state evaluation result; carrying out attack behavior classification and abnormal mode identification in combination with unsupervised clustering and a graph neural network; constructing an attack transition probability matrix based on a Markov model; forming a time sequence attack chain; predicting an attack development trend; and a dynamic protection instruction is issued to the safety equipment. According to the method, the unknown attack detection capability can be improved, the time sequence attack traceability is enhanced, the security situation assessment is optimized, and the method is suitable for security situation awareness in cloud computing, industrial internet and large-scale network environments.
Owner:SHANDONG ENERGY GRP CO LTD +1

Network security protection method and system applied to regional digital and intelligent asset business

The invention provides a network security protection method and system applied to regional digital and intelligent asset businesses, and the method comprises the steps: collecting asset data flows of a plurality of asset business nodes in a target region, carrying out the threat feature extraction of the asset data flows based on a preset threat knowledge graph, and obtaining a threat feature extraction result; generating a dynamic threat feature vector corresponding to the asset service node; inputting the dynamic threat feature vector into a pre-trained dynamic protection model, and outputting a real-time protection strategy adaptive to the asset service node through a multi-layer decision network in the dynamic protection model; performing strategy execution on the network flow of the asset service node based on the real-time protection strategy, generating a strategy execution result and feeding back the strategy execution result to the dynamic protection model; and performing adaptive optimization on decision parameters of the dynamic protection model according to a strategy execution result, and generating an updated dynamic protection model for a protection decision of a next round of asset business nodes.
Owner:GUIZHOU ANRONG TECH DEV CO LTD +1

Enhanced encrypted traffic analysis via integrated entropy estimation and neural network-based feature hybridization

A method is provided for encrypted network traffic analysis. The method includes capturing network traffic data; calculating entropy of said data to classify traffic as encrypted or non-encrypted; applying statistical and sequential feature hybridization on encrypted traffic to extract comprehensive features; analyzing the features using a neural network model to identify encrypted traffic types and detect anomalies; and refining the analysis based on entropy and neural network insights through a feedback loop.
Owner:LEPTUDE INC

Network traffic anomaly detection model training method and device and readable storage medium

The invention provides a network traffic anomaly detection model training method and device and a readable storage medium, and the method comprises the steps: extracting a traffic statistical feature vector according to original network traffic data, and generating an initial mixed data set; generating a confrontation disturbance sample output enhanced feature matrix based on the initial mixed data set; constructing a self-adaptive feature fusion rule based on the enhanced feature matrix, embedding asset association degree parameters into an attention calculation layer of a feature encoder, and outputting encoding features fusing threat intelligence; inputting the coding features fused with the threat intelligence into a pre-constructed initial detection model, generating false report and missing report correction labels based on the suspicious traffic fragments, and outputting an adversarial sample correction data set; and performing adversarial training on the initial detection model through the adversarial sample correction data set to obtain an incremental detection model for network traffic anomaly detection. According to the invention, the detection precision, the anti-interference capability and the real-time defense response capability of the detection model to novel attacks can be improved.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD

Lightweight malicious network traffic detection method based on heterogeneous modal feature fusion

The invention discloses a lightweight malicious network traffic detection method based on heterogeneous modal feature fusion, and mainly solves the problems of low feature extraction efficiency and insufficient single modal feature representation of the existing method. Comprising the following steps: acquiring and optimizing a network flow data set, preprocessing the network flow data set, and extracting and generating spatial feature, time sequence feature and behavior pattern feature vectors; an improved self-attention mechanism network is constructed, a lightweight heterogeneous modal feature fusion model LMF is designed, multi-modal feature deep fusion is performed through dynamic weight distribution, a lightweight classification model is trained, and the model is utilized to detect network malicious traffic. Through the lightweight heterogeneous modal feature fusion model LMF and in combination with a dynamic weight distribution mechanism, spatial distribution, time sequence dependence and behavior semantic information of network traffic are deeply mined, data processing efficiency, malicious traffic detection accuracy and system robustness are improved, and the method is suitable for efficient malicious traffic identification and defense in the field of network security.
Owner:XIAN TECH UNIV

Network security analysis method and system based on big data

The invention relates to the technical field of network security, in particular to a network security analysis method and system based on big data. Comprising the following steps: collecting related multi-source heterogeneous data of a network, and carrying out standardized processing such as cleaning and de-noising; network analysis is carried out based on the preprocessed data, network traffic is analyzed in real time by using machine learning and deep learning algorithms, and abnormal conditions are detected; constructing a risk prediction model according to a network analysis result and related information, and predicting a future network security risk level; if the risk level exceeds the threshold value, determining a security event source and a responsibility subject through data tracing; and finally, generating a safety response strategy according to risk prediction and data traceability results, and performing disposal. The corresponding system covers the modules of data acquisition, preprocessing, network analysis, risk prediction, data tracing, security response and disposal and the like, and all the modules work cooperatively to form a complete network security analysis and guarantee system, so that the stable operation of the network system is guaranteed.
Owner:QINGDAO MOCHUANG FUTURE INTELLIGENT TECHNOLOGY CO LTD

Information security analysis method and system based on big data

The invention relates to the technical field of information security data processing, and discloses an information security analysis method and system based on big data, and the method comprises the steps: S1, collecting multi-source heterogeneous security related data which comprises a business log, a user behavior track, network traffic, an application program interface calling record, an identity authentication log and a real-time security data flow, preprocessing the collected data to obtain standardized data; and S2, performing entity identification, event extraction and relationship mining based on the standardized data, and constructing a cross-modal threat knowledge graph containing security entity nodes and associated edges. The method solves the problem of monitoring blind areas caused by lack of dynamic association mining capability among data in a traditional method, and particularly aims at distributed, low-frequency and multi-stage hidden attacks, the scheme can accurately recover an attack chain and identify high-risk threats through dynamic matching and path reasoning of a knowledge graph, and the method has a good application prospect. And the detection coverage rate and accuracy in a complex attack scene are remarkably improved.
Owner:BEIJING YUANFANG TIMES TECHNOLOGY CO LTD

Industrial control network security service security guarantee system based on behavior analysis

The invention provides an industrial control network security service security guarantee system based on behavior analysis, which belongs to the technical field of industrial control network security, and comprises a multi-source data fusion acquisition module, a dynamic behavior modeling engine, a federal learning analysis cluster, an attack chain prediction module, a self-adaptive protection strategy executor and a model evolution feedback ring, wherein the multi-source data fusion acquisition module synchronously acquires industrial control network flow (including OPC UA / Modbus / DNP3 protocol analysis), equipment operation logs, user operation behavior fingerprints and physical interface state data, and the physical interface state data comprises electrical characteristic fluctuation monitoring of USB / network interfaces. According to the scheme, through multi-technology fusion and closed-loop design, the problems of static performance, single-dimension analysis defects and response lag of a traditional industrial control security scheme are effectively solved, a comprehensive protection system with dynamic modeling, intelligent decision making, privacy protection and continuous optimization is constructed, and the security and service reliability of an industrial control network are remarkably improved.
Owner:CPI NORTHEAST ENERGY SAVING TECH +1

Network security defense method and system based on incremental network attack analysis learning

The invention discloses a network security defense method and system based on incremental network attack analysis learning. The method comprises the following steps: collecting initial network flow data, and extracting a feature vector; and collecting real-time network flow data, performing segmentation processing based on a sliding time window, extracting time sequence association features from the segmented data, and matching the time sequence association features with the feature library to identify potential attacks or abnormal behaviors. And when the time sequence correlation feature is not matched with the feature library, marking the time sequence correlation feature as a candidate novel attack feature, calculating a mahalanobis distance between the time sequence correlation feature and a known attack feature to determine the attack variability, and dynamically adjusting the weight of the time sequence correlation feature. And inputting the adjusted feature weight and the real-time flow feature into a deep reinforcement learning detection model, and generating and updating a network security defense strategy. The scheme of the invention can effectively identify novel attack behaviors, dynamically respond and optimize defense strategies, and improve network security.
Owner:JIANGSU SIJI TECH SERVICE CO LTD

Network perception anomaly detection system based on big data

The invention, which relates to the technical field of network awareness anomaly detection, discloses a network awareness anomaly detection system based on big data, comprising a data acquisition module, a feature fusion module, a map construction module, a model calculation module, a root cause reasoning module, a threshold decision module and a response control module. The data acquisition module receives network flow data, equipment state data and system log data and outputs a standardized feature set; the feature fusion module is connected with the data acquisition module, dynamically calculates a weight coefficient of each data source based on information entropy, performs feature aggregation of privacy protection through a federated learning framework, and outputs a fusion feature vector; the atlas construction module is connected with the feature fusion module, maintains a network equipment node set and a communication edge set in real time, and updates a space-time association atlas according to a topology change event; and the model calculation module is connected with the atlas construction module, extracts topological features through a space-time diagram convolutional network, and updates a detection model based on an incremental learning mechanism.
Owner:BEIJING SHISHILI TECHNOLOGY CO LTD

Network security threat research and judgment method, system and equipment and storage medium

The invention discloses a network security threat research and judgment method, system and device and a storage medium, and the method comprises the following steps: S1, obtaining network traffic, terminal logs, application program interface calling records and threat intelligence data in real time, carrying out the standardized cleaning and format conversion of the data, and building a unified data lake; s2, matching, identifying and determining threats through a preset known threat feature library, constructing a normal behavior baseline by using an unsupervised learning algorithm, and marking suspicious events deviating from the baseline; s3, for the suspicious event marked in the step S2, mining a potential attack path and an attack intention by combining knowledge graph technology associated asset information, a historical attack chain and a homologous IP address; and S4, based on the attack success probability, the influence asset importance and the diffusion speed, calculating a threat level by adopting a fuzzy comprehensive evaluation model, and generating a research and judgment report containing disposal suggestions.
Owner:CRCC DEV GRP CO LTD +1

Communication network resource optimization method and system based on artificial intelligence

The invention provides a communication network resource optimization method and system based on artificial intelligence, and relates to the technical field of communication optimization, and the method comprises the steps: collecting historical network data, carrying out the feature extraction through time series decomposition and an LSTM algorithm, carrying out the weight calculation of a performance index through combining an attention mechanism, and predicting the network flow through a multi-scale prediction mechanism. And dynamic calibration is carried out based on historical errors, so that the network flow change trend can be accurately predicted, the prediction precision is improved, reasonable distribution and optimal configuration of network resources are realized, and the network operation efficiency is effectively improved.
Owner:BEIJING XUNFENG TIMES SOFTWARE DEVELOPMENT CO LTD

Method and system for detecting and defending cross-domain threats of power system

The invention provides a method and a system for detecting and defending cross-domain threats of a power system. The method comprises the following steps: after carrying out anomaly identification on operation monitoring data of a physical domain node in a target power grid region to obtain an anomaly identification result and carrying out denial of service attack identification according to network flow data of an information domain node to obtain an attack identification result, carrying out abnormal event association analysis on the anomaly identification result and the attack identification result to obtain an attack cross-domain anomaly identification result; according to key nodes and key risk propagation paths in a cross-domain attack chain generated based on a graph theory algorithm, generating an attack tracing atlas, and according to vulnerability information of the key nodes in the atlas, obtaining a corresponding power system topological graph and a corresponding communication network topological graph; and iteratively generating an active defense rule based on a game theory algorithm and a reinforcement learning algorithm, and issuing the active defense rule to the node. According to the method, the cross-domain attack risk is accurately perceived in real time and adaptive security defense is executed through cross-domain abnormal event association analysis, so that the comprehensiveness and reliability of security protection of the power system are improved.
Owner:LISHUI POWER SUPPLY COMPANY OF STATE GRID ZHEJIANG ELECTRIC POWER

Network traffic anomaly detection strategy generation method based on machine learning

The invention relates to a network flow anomaly detection strategy generation method based on machine learning, and belongs to the technical field of machine learning. The method comprises the following steps: firstly, collecting network traffic data in a preset time window, and extracting feature vectors containing traffic, a time sequence and a protocol type; and inputting the feature vector into a long short-term memory auto-encoder model, and calculating a reconstruction error to judge whether the network flow is abnormal or not. Aiming at the abnormal feature vector, adopting a multi-agent depth deterministic strategy gradient algorithm to construct a plurality of cooperative agents, and independently generating a candidate abnormal detection strategy by each agent; through a cross-agent strategy evaluation mechanism, the difference between a joint strategy and a single-agent strategy in the aspect of anomaly detection accuracy is compared, cooperation gain is calculated, strategy exploration parameters of all agents are adjusted according to the cooperation gain, and a global optimal anomaly detection strategy is optimized and determined in real time. According to the method, high-precision and low-missing-report network traffic anomaly detection can be realized, and the method has good self-adaptability and real-time performance.
Owner:SUZHOU XINGYI INFORMATION TECHNOLOGY CO LTD

Network flow threat analysis method based on operating system instruction hierarchy

The invention discloses a network traffic threat analysis method based on operating system instruction hierarchy, which relates to the technical field of network security, and comprises the following steps: monitoring operating system instruction data in real time, constructing a dynamic behavior matrix and generating an instruction-level traffic diagram; analyzing the instruction level flow diagram, calculating first digit distribution of instruction data, comparing the first digit distribution with Benford's Law expected distribution, calculating an instruction behavior deviation degree through a statistical method, generating an abnormal score, performing risk classification in combination with a decision tree classification algorithm, and determining an abnormal instruction; and carrying out abnormal instruction classification by using a graph neural network, and identifying known attack behaviors and unknown abnormal behaviors. According to the method, more accurate attack behavior identification capability can be provided, a complete attack chain can be identified, more intelligent threat analysis is realized, false alarms are reduced, and the detection precision is improved, so that the behavior track of an attacker is accurately traced, and stronger safety protection capability is provided.
Owner:GUANGDONG POWER GRID CO LTD +1

Large language model (LLM) powered detection reasoning solution

Various techniques for LLM powered detection reasoning solutions are disclosed. In some embodiments, a system, a process, and / or a computer program product for an LLM powered detection reasoning solution includes monitoring network traffic at a security platform, wherein the security platform generates a sample based on the monitored network traffic; sending the sample to a security service to generate a Large Language Model (LLM) powered detection and reason, wherein the LLM is prompted to automatically generate a malware or benign verdict and a reason for explaining the verdict; and reporting the LLM powered detection and reason.
Owner:PALO ALTO NETWORKS INC

Message feature extraction method and related equipment

The invention discloses a message feature extraction method and related equipment, and relates to the technical field of feature extraction, and the method comprises the steps: obtaining original message data of target network flow and a corresponding physical layer signal waveform; analyzing the original message data based on a preset protocol layering rule, and determining a multi-layer protocol field set; determining a protocol layer feature vector based on the multi-layer protocol field set; determining a frequency domain feature vector based on the physical layer signal waveform; constructing a cross attention weight matrix based on the protocol layer feature vector and the frequency domain feature vector; and generating a target message feature based on the cross attention weight matrix. According to the method, through dual-mode deep fusion of protocol semantics and physical signals, the analysis capability of the features on encrypted traffic and protocol confusion attacks is enhanced, meanwhile, the feature robustness is improved through dynamic weight distribution and an anti-replay mechanism, and endogenous security features with high discrimination power are provided for complex network threat detection.
Owner:BYZORO NETWORK LTD +1

Network security situation awareness method and device for multi-source data fusion, equipment and medium

The invention relates to a network security situation awareness method and device for multi-source data fusion, equipment and a medium, and the method comprises the steps: respectively collecting kernel logs and network flow data, and carrying out the standardization processing to generate a communication data set; constructing a dynamic process link map, defining a communication type, frequency and data volume, and updating a topological relation in real time; a sliding time window is adopted to count communication time sequence characteristics, and abnormal signals deviating from normal distribution are screened in combination with a time sequence analysis technology; training a robustness classifier model through an adversarial sample enhancement technology, fusing a graph neural network to analyze a dependency relationship between processes, and filtering a false alarm signal; and the hidden channel is accurately identified and alarm information is generated in combination with a dynamic similarity threshold and a threat intelligence gain coefficient, so that the problems of insufficient multi-source data fusion, high false alarm rate of a static rule base, failure in detection of weak signals of the hidden channel and the like in a traditional method are solved. And the real-time perception and response capability of APT attacks in a complex network environment is improved.
Owner:MINXI VOCATIONAL & TECHN COLLEGE

Dynamic access blocking method based on zero trust

The invention relates to the technical field of network security, in particular to a dynamic access blocking method based on zero trust. Comprising the following steps: step 1, collecting whole network flow data in real time in a bypass monitoring mode through a flow mirroring function of a network switch, performing deep packet inspection analysis on the collected original flow data, and extracting network flow characteristic parameters; 2, maintaining a dynamic identity information base; 3, performing real-time behavior analysis on each network session; 4, according to the risk assessment result and the real-time security context, generating a dynamic access control strategy based on a minimum permission principle; 5, implementing access control at the network execution point; and 6, continuously monitoring the network flow and the strategy execution effect, collecting feedback data, optimizing the risk assessment model and the strategy generation algorithm based on the feedback data, and forming closed-loop control. By dynamically updating the identity and asset information, the system can identify new assets or changes in real time, so that the adaptability and response capability of a network environment are improved.
Owner:SHANDONG NETWORK SECURITY TECHNOLOGY CO LTD

Network data intelligent tool system and method based on model context protocol MCP

The invention discloses a network data intelligent tool system and method based on a model context protocol MCP, and relates to the technical field of computer networks. The system comprises an AI analysis main body, an MCP Pcap tool engine, context management, a Pcap data source, various MCP Pcap tools, a Pcap tool gateway interface, a Pcap tool interface and a data packet interface. The invention provides an interaction mechanism of direct embedding and bypass data forwarding in tool calling. According to the method, direct embedded transmission of small-size data in tool calling is supported, separation of data transmission and instruction calling is achieved, the technical bottleneck that large-size Pcap data cannot be efficiently exchanged through a text channel is effectively overcome, efficient processing of the AI model on network packet capture data is achieved, and the data transmission efficiency is improved. And the efficiency and the automation degree of large-scale network traffic analysis are improved.
Owner:SHANGHAI NETIS TECH CO LTD

Method for constructing feature knowledge base of mapping behavior based on deep learning

The disclosure belongs to the technical field of network security, and provides a method for constructing a feature knowledge base of mapping behavior based on deep learning, which includes: data acquisition and preprocessing: extracting five-tuple information and behavior features from network traffic. The disclosure automatically extracts the spatio-temporal features through the deep learning model, and enhances the sensitivity to abnormal behaviors by combining the attention mechanism, thus significantly improving the detection accuracy. The explanatory AI technology is used to automatically generate detection rules, the maintenance cost of manual rules is greatly reduced and the efficiency of rule generation is significantly improved. The feature knowledge base supports dynamic updating, may integrate third-party threat information in real time, and ensures the continuous defense ability against new attacks and variant detection means.
Owner:HUANENG INFORMATION TECH CO LTD

Cluster network flow prediction method based on multi-scale time feature fusion

The invention provides a cluster network flow prediction method based on multi-scale time feature fusion, and belongs to the technical field of computer network flow prediction. The method comprises the following steps: determining a multi-index prediction sequence based on traffic load characteristics of cluster IP instances, and constructing a high-quality time sequence data set; fourier transform and discrete wavelet transform are used for time-frequency feature analysis, and noise filtering and data dimension reduction are completed; projecting sequences of different time granularities to a unified model dimension, performing one-dimensional channel convolution merging, inputting the merged sequences into a time encoder and a cross-channel encoder, and capturing cross-scale long-term time dependence and a coupling relationship between variables; in the loss function design, time domain and frequency domain loss are fused, double-domain error calculation is carried out on a prediction result and a label through Fourier transform, and the robustness of a model to non-stationary fluctuation is enhanced; and through linear layer decoding and reverse normalization processing, the abstract feature is converted into an actual flow prediction value. According to the invention, the precision and reliability of cluster network flow prediction are significantly improved.
Owner:XI AN JIAOTONG UNIV

Deep learning-based wireless intrusion detection

Systems, devices, and methods for wireless intrusion detection based on deep learning are provided. A network device collects legitimate network traffic over a time period and learns a first set of features that represents the legitimate network traffic. The network device generates synthetic network traffic based on the learned first set of features and trains a machine learning model based on the learned first set of features and the synthetic network traffic. Based on the training, the machine learning model learns a second set of features that differentiates the synthetic network traffic from the legitimate network traffic. The devices and methods precisely detect potential security threats, while reducing false positives, thereby ensuring a sensitive and accurate response to genuine anomalies. Further, the devices and methods improve accuracy of detection of potential security threats including known and new attacks in wireless networks, while adapting to evolving attack techniques and network dynamics.
Owner:CISCO TECHNOLOGY INC

Identifying unauthorized entities from network traffic

Systems, methods, and devices to detect unauthorized third-party connections within a network infrastructure, such as by analyzing network traffic data using fuzzy matching and machine learning techniques. One aspect includes receiving network traffic data comprising records of communication events involving network identifiers, determining communication relationships between network entities identified by the network identifiers, accessing entity identifiers associated with known third-party systems, and determining associations between the network identifiers and the entity identifiers using a fuzzy matching process. Other aspects include identifying communication relationships involving the third-party systems based on the associations and detecting unregistered or unknown third-party connections within the network infrastructure. Further aspects include normalizing identifiers, computing string similarity metrics, assigning confidence scores, incorporating external data sources, building network association patterns, comparing current patterns to baseline patterns to detect anomalies, and updating security policies or firewall rules in response to detected anomalies. Additional aspects are provided.
Owner:HSBC GRP MANAGEMENT SERVICES LTD

Adaptive encryption system based on AI intelligent safety management

The invention discloses a self-adaptive encryption system based on AI intelligent security management, which relates to the technical field of information security, and comprises a data acquisition module, a risk assessment module, an encryption algorithm selection module, a key generation and management module, an encryption execution module and an encryption effect feedback module, the data collection module is used for collecting various data in a system operation environment, including but not limited to network flow data, equipment state data and user behavior data; and the risk assessment module analyzes the collected data based on an AI algorithm and assesses the security risk level faced by the current system. The operation environment data is comprehensively collected through the data acquisition module, the security risk level is evaluated in real time through the risk evaluation module based on the AI algorithm, the adaptive encryption algorithm can be dynamically selected according to the risk, the defect that a traditional encryption system is fixed in strategy is overcome, and encryption pertinence and effectiveness are improved.
Owner:HEBI CRYPTOADVANCED TECH RES INST

Big data-based private network data security detection method

The invention discloses a private network data security detection method based on big data, and belongs to the field of security detection, and the method comprises the steps: obtaining a real-time data packet from private network traffic, encoding the data packet through a forward error correction code technology, generating redundancy check information, and obtaining an encoded data packet; if a bit error is detected in the transmission process of the coded data packet, requesting a sending end to retransmit a damaged data packet through an automatic retransmission request mechanism to obtain a retransmitted data packet; adjusting the redundancy of a forward error correction code and a trigger threshold of an automatic retransmission request according to the adaptive error correction parameter, generating an optimized error correction scheme, and obtaining a repaired data packet; and aiming at the alarm processing instruction, automatically adjusting a network flow control strategy, limiting the transmission bandwidth of an abnormal destination, updating the sensitive data fingerprint database, and obtaining optimized protection configuration.
Owner:河北工业职业技术大学

Multi-radio access technology traffic management

Disclosed embodiments generally relate to edge-based multi-Radio Access Technology (RAT) traffic management (TM) solutions to support delay-sensitive traffic over heterogeneous networks. Embodiments include delay-aware TM implementations that split and / or steer network traffic across different RATs for the edge network control plane. Embodiments also include utilization threshold-based implementations to achieve delay-aware multi-path TM at the network's edge. The multi-path TM includes multi-RAT, multi-access, or multi-connectivity traffic routes. Embodiments include strategies to sort users (or devices) for making multi-RAT traffic distribution decisions and to determinate the utilization thresholds. Embodiments also include message exchange mechanisms or learning utilization thresholds and other useful system properties. Other embodiments may be described and / or claimed.
Owner:INTEL CORP

Intelligent tracking and blocking method and system for network attack chain

The invention provides an intelligent tracking and blocking method and system for a network attack chain, and relates to the technical field of network security, and the method comprises the steps: collecting network flow data, building an attack chain propagation path, setting a detection breakpoint, obtaining a data sample, carrying out the causal correlation analysis, extracting a data transmission feature, and converting the data transmission feature into a behavior sequence feature; predicting an attack chain evolution path by adopting a bidirectional feature matching mechanism; a honeypot service and a flow probe are deployed to generate an attacker portrait; and formulating a defense strategy according to the attack intention to realize attack chain blocking. According to the invention, accurate identification, effective tracking and active defense of network attacks can be realized, and the network security protection capability is improved.
Owner:BEIJING YUHONG XINAN TECHNOLOGY CO LTD

Network space security situation awareness detection analysis system and method

The invention discloses a network space security situation awareness detection analysis system and method, and the system comprises a heterogeneous network flow feature deep extraction unit which obtains a flow feature vector through a distributed probe array and an adaptive sampling strategy; the edge computing gateway multi-dimensional threat feature mapping unit realizes feature space mapping through a multi-dimensional feature mapping matrix; the dynamic weight multi-head attention feature fusion unit fuses features by using an optimized multi-head attention mechanism; the time-space sequence security situation evolution modeling unit constructs an evolution model in combination with the time sequence and the fusion features; the security threat risk quantitative evaluation unit carries out risk quantification; and the heterogeneous security policy collaborative response unit generates a response instruction. According to the method, flow collection, feature mapping, fusion, modeling, quantification and response operation are sequentially executed based on all units of the system. According to the method, efficient perception and accurate response of the network space security situation are realized through a multi-unit cooperation and innovation model.
Owner:SOUTHEAST UNIV