Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

2273 results about "Internet traffic" patented technology

Internet traffic is the flow of data within the entire Internet, or in certain network links of its constituent networks. Common measurements of traffic are total volume, in units of multiples of the byte, or as transmission rates in bytes per certain time units.

Ai-based cybersecurity system and method thereof

An AI-based Cybersecurity System and Method enable real-time detection, analysis, and mitigation of cyber threats within computing networks using adaptive artificial intelligence. The system continuously monitors network traffic, extracts behavioral and contextual attributes, and applies deep learning-based inference to identify anomalous activities indicating security breaches. The method integrates several computational units, including a network monitoring unit, feature extraction unit, artificial intelligence processor, contextual reasoning processor, and decision synthesis unit, to compute a composite risk index quantifying threat likelihood and severity. A classification processor categorizes detected threats into types such as ransomware, phishing, or unauthorized access, while a mitigation control processor initiates automated response actions to isolate compromised nodes and restore network integrity. An adaptive learning processor updates AI models using feedback from confirmed incidents. This provides a scalable, self-evolving cybersecurity framework that minimizes human intervention and enhances resilience against dynamic and zero-day threats.
Owner:PELL REDDY RAJENDER REDDY

Dynamic access blocking method based on zero trust

The invention relates to the technical field of network security, in particular to a dynamic access blocking method based on zero trust. Comprising the following steps: step 1, collecting whole network flow data in real time in a bypass monitoring mode through a flow mirroring function of a network switch, performing deep packet inspection analysis on the collected original flow data, and extracting network flow characteristic parameters; 2, maintaining a dynamic identity information base; 3, performing real-time behavior analysis on each network session; 4, according to the risk assessment result and the real-time security context, generating a dynamic access control strategy based on a minimum permission principle; 5, implementing access control at the network execution point; and 6, continuously monitoring the network flow and the strategy execution effect, collecting feedback data, optimizing the risk assessment model and the strategy generation algorithm based on the feedback data, and forming closed-loop control. By dynamically updating the identity and asset information, the system can identify new assets or changes in real time, so that the adaptability and response capability of a network environment are improved.
Owner:SHANDONG NETWORK SECURITY TECHNOLOGY CO LTD

Control method of multi-protocol switching anti-quantum security gateway

The invention relates to a control method for a multi-protocol switching anti-quantum security gateway, and the method comprises the steps: carrying out the safety self-inspection of a hardware environment after the security gateway is powered on, generating a unique root key of equipment based on a physical unclonable function, continuously collecting and analyzing the network traffic characteristics, and carrying out the self-inspection of the hardware environment. Based on a machine learning model, a quantum attack mode is identified and an encryption algorithm mode is dynamically decided, protocol analysis is carried out on a communication data packet, dynamic conversion and adaptation are carried out between a traditional protocol and an anti-quantum cryptography protocol according to an instruction and a preset rule, and an anti-quantum cryptography engine is called to carry out encryption or signature operation. And dynamically deriving and managing a session key in a complete period based on a root key, switching an algorithm mode, a communication protocol and a key in a linkage manner according to a quantum attack detection result, and starting anti-side channel attack protection and hardware security response. According to the method, active protection of the security gateway on quantum attacks, multi-protocol seamless compatibility and full-life-cycle security management of keys are realized.
Owner:WEIDE GUANGDONG INFORMATION TECH CO LTD

Network traffic anomaly detection method based on aggregation type mimicry distillation

The invention relates to the field of data detection, in particular to a network traffic anomaly detection method based on aggregated mimicry distillation. According to the method, protocol level analysis is carried out on traffic through a multi-branch feature extraction network, and a unified representation vector is generated through a cross-layer fusion mechanism; calculating a first abnormal score based on a protocol perception weighted confrontation soft contrast mechanism; a heterogeneous teacher model is constructed and dynamically weighted and aggregated, and the student model generates a second abnormal score through knowledge distillation learning; forming a heterogeneous redundant detection pool by the student model, the teacher model and the rule detector, dynamically selecting the detector and applying adaptive disturbance to obtain a third abnormal score; and dynamically fusing the three types of abnormal scores to output a detection result. According to the method, the problems of protocol semantic segmentation, weak boundary sample discrimination, knowledge migration simplification and defense path predictability are effectively solved, and the detection accuracy, robustness and dynamic defense capability are remarkably improved.
Owner:EAST CHINA JIAOTONG UNIVERSITY +1

Hybrid neural network-based cellular network traffic space-time prediction method and system

The invention provides a cellular network flow space-time prediction method and system based on a hybrid neural network, and belongs to the technical field of intelligent communication. The method adopts a layered deep neural network architecture, and comprises a data embedding layer, a space-time coding layer, a feature fusion layer and an output layer. The data embedding layer maps a historical traffic sequence, cross-domain external data and metadata into high-dimensional features; the space-time coding layer is used for respectively fusing one-dimensional causal convolution and a Mama neural network to extract multi-scale time features and densely connecting convolution and a multi-head attention mechanism to capture multi-scale space features through time and space modeling branches; the feature fusion layer realizes adaptive weighted fusion of spatial-temporal features, cross-domain features and metadata features by using a gating fusion mechanism; and the output layer performs linear transformation on the fusion features to generate a final prediction result. According to the method, the spatial-temporal dynamic capture of the service traffic is accurate, the prediction curve is highly fit with the true value, and the accurate prediction of the multi-service traffic of the cellular network is realized.
Owner:CHINA UNIV OF PETROLEUM (EAST CHINA)

Sequential network flow prediction method and system based on swarm intelligence parameter optimization

The invention provides a sequential network traffic prediction method and system based on swarm intelligence parameter optimization, and relates to the technical field of network traffic prediction. The method comprises the following steps: acquiring indexes such as throughput packet loss rate and round-trip delay of a target link by using a network probe, and performing deletion filling normalization and multi-scale decomposition to obtain a standardized traffic sequence; calculating information entropy, constructing a traffic complexity feature vector, and dividing a training set and a verification set; constructing a hybrid depth prediction model composed of a one-dimensional convolutional network and a gating cycle unit, and establishing a hyper-parameter search space; using particle swarm optimization and entropy-driven inertia weight adjustment and mutation probability mapping to reconstruct a speed and position updating strategy, and iteratively outputting a global optimal hyper-parameter; and generating a benchmark prediction result according to full-amount training, extracting a residual error, training a nonlinear residual error compensation model to carry out superposition correction and reverse normalization, obtaining a final flow prediction result, and improving prediction precision and generalization ability.
Owner:TIANJIN UNIV OF COMMERCE

Network security event tracing method, system and device based on AI and medium

The invention discloses an AI-based network security event tracing method, system and device and a medium, and the method specifically comprises the steps: constructing a network entity association graph based on a multi-modal data set, mining the implicit association between entities through a graph convolutional network, recognizing an APT attack chain, and obtaining graph feature data; based on the multi-modal data set, an LSTM-Transform hybrid model is adopted to analyze time sequence characteristics of network traffic, slow penetration and low-frequency detection behaviors are detected, and time sequence characteristic data are obtained; based on the graph feature data and the time sequence feature data, high-value features are screened through a genetic algorithm, and cross-modal combination features are generated by using a depth auto-encoder; based on cross-modal combination features, a network environment digital twin is constructed, an attack diffusion path is simulated, and a service influence range is quantified. According to the method, accurate tracing of the network security event is realized, and the detection and tracking capabilities of complex network attacks and the intelligent level of a response strategy are comprehensively improved.
Owner:ANHUI SANQI JIYU NETWORK TECH CO LTD

Efficient processing method and system for online troubleshooting of information department

The invention discloses an efficient processing method and system for online troubleshooting of the information department, and relates to the technical field of automatic operation and maintenance, and the system comprises a multi-modal data acquisition module, a dynamic knowledge graph construction module, a reinforcement learning driven self-healing module, an edge co-processing module and a cross-domain privacy calculation module. According to the method, the limitation of traditional single-dimensional monitoring is broken through, multi-source heterogeneous data such as server performance, container state and network flow are fused, a high-timeliness and high-consistency decision information base is constructed through unified time sequence alignment and semantic standardization, and a panoramic view is provided for dynamic analysis; based on an incremental learning mechanism and a causal inference engine, a service topology dependency relationship is updated in real time, a deep root cause is accurately positioned, and a cross-system and cross-level complex fault combination is solved.
Owner:BENGBU JINSE INFORMATION TECHNOLOGY CO LTD

Neuro-Generative Adversarial System for real-time detection and combating of malware morphing in high-density edge networks

ActiveDE202025106911U1Platform integrity maintainanceData packEmbedded security
A system for real-time detection and mitigation of morphing malware in high-density edge networks, consisting of: a data acquisition unit configured to receive, normalize, and encode multimodal telemetry data streams originating from at least one of the following domains: network traffic, process behavior, system call sequences, binary instruction traces, and control flow graphs; the data acquisition unit is further configured to compute feature embeddings over sliding time windows and apply privacy-preserving redactions prior to storage; a generative neural processor that is operationally coupled to the data acquisition unit and configured to generate synthetic morphing malware variants by learning probabilistic transformations of previously observed malicious data representations, maintaining semantic functionality while varying structural and behavioral features; a discriminative neural processor trained adversarially with the generative neural processor, wherein the discriminative neural processor is configured to detect morphing malware by evaluating a probability distribution over multimodal telemetry embeddings and classifying anomalous process and flow behaviors in real time; a coordination processor that is communicatively connected to both the generative neural processor and the discriminative neural processor and is configured to orchestrate adversarial co-training, regulate detection thresholds, calculate reinforcement-based penalties for false negative results, and trigger countermeasures as soon as a detection confidence level exceeds a predefined adaptive threshold; a secure, system-integrated inference and enforcement unit configured to perform low-latency countermeasures at the network edge, including selective packet filtering, flow isolation, process interruption, or system microsegmentation, based on instructions from the coordinating processor; and a hardware-embedded security enclave that is embedded in the system and configured to store cryptographic keys, neural model parameters, and integrity affirmation data to ensure the confidentiality, authenticity, and immutability of model artifacts and policy configurations.
Owner:ANAJAVADIDHODDI RAMACHANDRA NAIK CHAYAPATHI BENGALURU +7

Network traffic anomaly real-time detection method based on deep learning

The invention relates to the technical field of network flow detection, in particular to a real-time network flow anomaly detection method based on deep learning, and the system comprises the following steps: S1, carrying out the real-time collection and preprocessing of multi-modal data; s2, performing dynamic feature engineering and sliding window statistics; s3, carrying out online adaptive threshold initialization; s4, multi-modal deep learning model reasoning is carried out; s5, updating the adaptive threshold in real time; s6, abnormal decision making and confidence coefficient calibration; s7, generating interpretability analysis; and S8, performing real-time feedback and online learning. According to the scheme, the capability of detecting hidden and complex attacks is remarkably improved through multi-modal data fusion and dynamic feature engineering, network traffic, system logs, user behavior data and external threat intelligence are synchronously collected, and traffic statistical features, time sequence change features, frequency domain features and distribution features are extracted in real time by using a sliding window mechanism.
Owner:WUXI YUANSHUCHENG TECHNOLOGY CO LTD

Private network dynamic access control method and system

The invention discloses a private network dynamic access control method and system, and relates to the technical field of network security and access control. The method comprises the following steps: acquiring equipment behavior data and network flow data in a private network, performing feature construction, and generating equipment trust features and network behavior features; and carrying out multi-dimensional risk assessment model training based on the equipment trust features and the network behavior features, carrying out real-time risk assessment on access requests or entities in the private network through the trained multi-dimensional risk assessment model, and generating a real-time risk score through a weighted aggregation function. According to the invention, through the multi-modal feature fusion model based on an attention mechanism, deep association of static attributes and dynamic behavior features of equipment is realized, and a real-time risk score is generated in combination with a multi-dimensional risk assessment model and a weighted aggregation algorithm. The limitation that in traditional access control, the evaluation dimension is single, the static strategy lags behind, and dynamic threats cannot be reflected is effectively overcome, and the accuracy and interpretability of private network access risk perception are remarkably improved.
Owner:GUANGZHOU TRUSTMO INFORMATION SYST CO LTD

System and method for artificial intelligence-driven anomaly detection in encrypted network traffic without decryption

A system and method for detecting anomalies in encrypted network traffic without decrypting encrypted payloads is disclosed. The invention comprises a hardware-accelerated pipeline including a packet acquisition unit configured to extract observable header attributes and timestamp values, a signal analysis unit implemented using digital signal processing circuitry to generate temporal and spectral characteristics of encrypted packet flows, and a morphometric extraction unit that produces encrypted-flow descriptors based on statistical dispersion, burst patterns, and ciphertext variability. A behavioral graph construction unit generates graph-structured representations of encrypted flows using incremental state-transition encoding. An artificial-intelligence inference unit employing a tensor-processing processor performs multi-stage anomaly analysis through temporal reconstruction, attention-based weighting of descriptors, and graph-structural deviation assessment to compute anomaly scores without decrypting any payload. A secure response control unit evaluates the scores against policy thresholds and performs mitigation actions while preserving confidentiality.
Owner:SEELAM SRI RANGANATH

Computer-implemented system and method for cybersecurity threat analysis using federated machine learning and hierarchical task networks

ActiveUS12500920B2Machine learningSecuring communicationHierarchical task networkInternet traffic
A system and method for cyber exploitation path analysis and response using federated networks to minimize network exposure and maximize network resilience, with the ability to simulate complex and large scale network traffic through the use of federated training networks, by gathering network entity information, establishing baseline behaviors for each entity, and monitoring each entity for behavioral anomalies that might indicate cybersecurity concerns. Further, the system and method involve incorporating network topology information into the analysis by generating a model of the network, annotating the model with risk and criticality information for each entity in the model and with a vulnerability level between entities, and using the model to evaluate cybersecurity risks to the network. Lastly, network attack path analysis and automated task planning for minimizing network exposure and maximizing resiliency is performed with machine learning, generative adversarial networks, hierarchical task networks, and Monte Carlo search trees.
Owner:QOMPLX INC

Method and system for detecting abnormal traffic of multi-receptive field network based on endogenous security attribute

The invention provides a multi-receptive-field network abnormal flow detection method and system based on endogenous security attributes, and relates to the technical field of network security and abnormal flow intelligent detection. The method comprises the following steps: firstly, performing multi-scale flow representation, preprocessing and data enhancement on network flow data to obtain enhanced input flow data; local features are extracted through basic convolution, and local and global fusion features are obtained based on a double-branch network comprising a multi-receptive field convolution branch and a Mama-self-attention branch; deep fusion representation is formed through multi-round feature extraction and tensor fusion, and finally binary classification and fine-grained classification results are output through global pooling and a linear classification layer. According to the method, high-precision, high-robustness and high-real-time detection of the abnormal traffic of the complex network is realized under low calculation overhead.
Owner:ZHEJIANG UNIV

Dynamic network security defense method and system for real-time network state adaptation

The invention provides a dynamic network security defense method and system oriented to real-time network state adaptation, and the method comprises the steps: building a standardized state vector sequence through collecting key indexes, such as network flow rate, abnormal connection ratio, topology change frequency, protocol distribution deviation degree and the like; based on the sequence, utilizing a time sequence prediction model embedded with a structured attention mechanism to predict attack risk trends of a plurality of time windows in the future in a prospective manner; and in combination with the current state and the risk trend, dynamically selecting an optimal strategy path in a predefined defense action map, mapping the optimal strategy path into a standardized control command which can be executed by equipment, and dispatching, issuing and executing the standardized control command according to the priority. According to the method, closed-loop self-adaptive defense from state perception and risk prediction to strategy generation and execution is realized, and the real-time performance, intelligence and engineering deployability of a network security system are remarkably improved.
Owner:GUANGDONG ZHUOYUE ZHIYUN INFORMATION ENGINEERING CO LTD

Small sample modeling stability evaluation method and system based on Bootstrap resampling

ActiveCN121144767ASmall sampleAlgorithm
The invention discloses a small sample modeling stability evaluation method and system based on Bootstrap resampling, and particularly relates to the technical field of computers and data intellectualization, the method comprises the following steps: completing data preprocessing and stable stage identification under a unified time base, and forming a segment set; an average block length is used as a decision quantity, an SBB is optimized to construct a sample space, and an optimal block length is determined in combination with variance consistency and nominal coverage rate consistency criteria; carrying out re-sampling training around short / medium / long scales, and collecting layered indexes such as prediction, parameters and features; stability calculation and empirical coverage rate calibration are completed based on intra-scale statistics and inter-scale weighted mixing, and a pseudo-stationary diagnosis score is output; and finally, engineering judgment and backspacing optimization are carried out according to the coverage rate, the correlation maintenance and the risk threshold. The system records random seeds, block metadata and model version generation evidence pointers, has the characteristics of traceability and reverifiability, and is suitable for scenes of production lines, network traffic, finance and the like.
Owner:BAIWEIJINKE (SHANGHAI) INFORMATION TECH CO LTD

Network information operation and maintenance system based on AI multiple modes

ActiveCN121262103ABiological modelsTransmissionInformation OperationsInternet traffic
The invention provides a network information operation and maintenance system based on AI multi-modality, and belongs to the technical field of network information operation and maintenance. Heterogeneous operation and maintenance data such as network flow, equipment state, audio alarm and thermal imaging are acquired through an acquisition unit, and various features are extracted in parallel by using a multi-modality feature extraction module to form a unified multi-dimensional feature vector; a hierarchical anomaly detection architecture is established, lightweight and deep anomaly detection models are deployed on an edge side and a cloud end respectively, different modal features are intelligently fused through an attention mechanism by adopting a multi-modal feature fusion model, and a detection threshold is optimized in real time according to a network state by using an adaptive threshold dynamic adjustment Bayesian algorithm. And a multi-modal fusion decision engine is constructed to perform weighted fusion on the anomaly detection result and dynamically adjust the modal weight, so that the technical problem of insufficient accuracy of multi-modal operation and maintenance data fusion processing is solved.
Owner:SHANDONG WUKESONG ELECTRIC TECH CO LTD

Network encryption attack detection method based on deep learning

The invention discloses a network encryption attack detection method based on deep learning. The method comprises the following steps: acquiring encrypted network traffic to generate a target communication channel; constructing a micro-perturbation excitation set, and generating a micro-perturbation excitation record; acquiring response indexes of each protocol layer, and generating a cross-layer disturbance response time sequence; constructing a cross-protocol-layer associated disturbance trajectory diagram; calculating a cross-layer coupling matrix and a disturbance response topology fingerprint, sending the cross-protocol-layer associated disturbance trajectory diagram and the cross-layer coupling matrix into a cross-layer topology constraint Neural ODE for numerical integration evolution, and generating a disturbance response continuous time hidden state trajectory; and calculating an encryption attack risk score, and generating an encryption attack detection result. According to the method, active perturbation and cross-layer topology constraint Neural ODE modeling are adopted, encryption channel dynamic fingerprint extraction is realized, and the method has high-precision, high-sensitivity and strong-interpretation attack detection capability.
Owner:BEIJING ZHONGKUANG ZHIWANG TECHNOLOGY CO LTD

Network traffic anomaly detection and identification method based on artificial intelligence

The invention discloses a network traffic anomaly detection and identification method based on artificial intelligence, and the method comprises the following steps: obtaining original network traffic data, carrying out the preprocessing, and carrying out the fusion construction of a multi-layer traffic language field tensor; behavior semantic modeling and path structure coding are carried out; constructing a behavior event sequence tensor, inputting the behavior event sequence tensor into the improved RetNet model, and outputting a behavior drift response vector; performing deviation analysis on the behavior drift response vector and the target behavior intention trajectory tensor, and constructing an abnormal evolution graph of abnormal growth and propagation; performing type classification and causal analysis according to the abnormal evolution graph, and outputting an abnormal type label and a causal path set; constructing a minimum disturbance sample, and performing comparative reasoning to generate an abnormal credibility change interval and an anti-robust score; and updating the abnormal knowledge graph and executing incremental updating. According to the invention, high-precision, interpretable and robust anomaly detection and classification analysis in a complex network environment can be realized.
Owner:HEBEI MANSHU TECHNOLOGY CO LTD

Data center server resource allocation method and system based on dynamic load balancing

The invention belongs to the technical field of computers, and particularly relates to a data center server resource allocation method and system based on dynamic load balancing, and the method comprises the steps: collecting a physical resource state, instance constraint and network flow through a multi-dimensional probe, constructing a dynamic weighted load scoring model, and introducing a migration penalty term to correct node load evaluation; solving maximum weight matching of the bipartite graph with constraint by combining a Hungary algorithm, and realizing global optimal mapping of the migration instance and a target node; a memory, a CPU and network resources are pre-configured before migration, a delay recovery mechanism is triggered after migration, and the service quality is guaranteed. The system comprises a resource acquisition module, a score generation module, a matching solution module, a pre-configuration module, a self-adaptive period adjustment module and the like. The cluster resource utilization rate is obviously improved by 28%, hotspots are reduced by 76%, the SLA default rate is reduced by 92%, meanwhile, energy is saved by 15%, and collaborative optimization of efficiency and service quality is achieved.
Owner:DOUXIN DATA TECHNOLOGY (HARBIN) CO LTD

Power network security inspection system

The invention belongs to the technical field of power network inspection, and particularly relates to a power network security inspection system which comprises a multi-source sensing module, an edge calculation module, a zero-trust security verification module, a core analysis module, an execution module and a feedback optimization module. Through an edge-cloud collaborative architecture, sensors, network flow and video data are fused in real time, the detection efficiency is improved, a physical equipment state and zero-trust dynamic authority control are introduced, 'physical-digital 'dual verification is realized, real threats and false alarms are marked, algorithm parameter adjustment is guided, and a feedback optimization module continuously reduces the false alarm rate through a closed loop mechanism; full-dimension safety protection of the power network is realized through modular design, dynamic branch processing and a closed-loop optimization mechanism; the threat level and the risk assessment result are dynamically adjusted through the environmental risk correction factor, the risk misjudgment rate is reduced, and the fault prediction accuracy in extreme weather is improved.
Owner:BEIJING SIMPLE NETWORK SECURITY TECH CO LTD

Power monitoring system intrusion detection method and system based on flow analysis

The invention relates to the field of electric power monitoring, in particular to an electric power monitoring system intrusion detection method and system based on flow analysis. The method comprises the following steps: collecting network traffic, analyzing and recombining to obtain structured session data; time sequence behavior features and function code distribution features are extracted to construct a multi-dimensional feature set; inputting the feature set into a compliance rule base and a behavior baseline model in parallel, and respectively outputting a rule matching result and an abnormal deviation degree score; generating a comprehensive threat index by adopting a weighted decision fusion strategy; and when the index exceeds a dynamic threshold value, intrusion is determined and an alarm is given. According to the invention, the problem of insufficient precision and adaptability caused by single feature dimension and isolated detection mechanism is solved.
Owner:LINZHANG POWER SUPPLY BRANCH OF STATE GRID HEBEI ELECTRIC POWER CO LTD +2

Subway network flow prediction method and device based on correlation modeling and storage medium

The invention relates to the technical field of artificial intelligence, and provides a subway network traffic prediction method based on association modeling, comprising: acquiring a heterogeneous data source of a target subway network; the heterogeneous data sources are cleaned, aligned and fused, and a time-space association data set is constructed; based on the subway network topology and the real-time passenger flow state, constructing a dynamic relation graph representing the dynamic interaction between the line and the station; the space-time correlation data set and the dynamic relation graph are utilized to cooperatively train a space-time prediction module and a relation reasoning module in an alternate optimization mode, and the relation reasoning module iteratively updates an edge weight in the dynamic relation graph through a graph attention mechanism and a space-time convolution operation; and based on the dynamic relation graph and the optimized space-time prediction module, carrying out multi-step prediction on the passenger flow in the future period and outputting a prediction uncertainty quantitative index. According to the technical scheme of the application, the accuracy and reliability of subway passenger flow prediction are significantly improved by fusing multi-source data and dynamically modeling the site association relationship.
Owner:SUZHOU UNIV OF SCI & TECH

Power metering system network security situation analysis method and system based on big data

The invention provides an electric power metering system network security situation analysis method and system based on big data, and relates to the technical field of electric power system information security. According to the method, network traffic, system logs, security alarms, asset information, vulnerability records and external threat intelligence are collected, a security data lake is constructed, and security situation factors are extracted; outputting an anomaly detection result and a threat classification result by using the unsupervised anomaly detection model and the supervised threat classification model; calculating an asset security risk value and an overall security risk value by combining the vulnerability severity and the asset importance, and generating an overall security index, an attack threat level and a vulnerability level; and a time sequence prediction model is further constructed based on the network security situation indexes, and future situation prediction and security early warning are realized. According to the invention, comprehensive perception, accurate analysis and active defense of the network security situation can be realized.
Owner:HARBIN INSTITUTE OF TECHNOLOGY (SHENZHEN) (INSTITUTE OF SCIENCE AND TECHNOLOGY INNOVATION HARBIN INSTITUTE OF TECHNOLOGY SHENZHEN)

Full-unloading regular matching system and method based on FPGA (Field Programmable Gate Array)

The invention relates to a full-unloading regular matching system and method based on an FPGA (Field Programmable Gate Array). The system comprises a regular rule compiling unit and an FPGA full matching unit, the regular rule compiling unit is used for receiving a regular rule set, extracting each rule fixed feature substring, compiling the uniform format isomorphic NFA, and constructing a mapping relation table of the substrings and the corresponding NFA; the FPGA full matching unit comprises a parallel high-speed character string matching engine array, a character string-NFA mapping table module, a full-quantity regular data memory, a reconfigurable general NFA engine module and a matching result output module; and the reconfiguration engine module is used for executing full unloading regular matching on the input network traffic: scanning the traffic through the engine array, screening to-be-verified traffic containing a fixed feature substring and outputting a substring identifier, querying the NFA identifier through the mapping table module, and loading NFA matching by the reconfiguration engine module. By adopting the method, low delay and high throughput performance of regular matching in a high-speed network environment can be ensured.
Owner:NAT UNIV OF DEFENSE TECH

Asset vulnerability detection method and device, electronic equipment and storage medium

The invention discloses an asset vulnerability detection method and device, electronic equipment and a storage medium, and relates to the technical field of network security, and the method comprises the steps: actively sending a multi-protocol detection packet to scan a target network segment, and obtaining a first asset set; passively monitoring network traffic to extract asset feature information, and obtaining a second asset set to generate an asset list; port scanning tasks of all assets are dispatched to a plurality of scanning nodes in a distributed and parallel mode, dynamic port scanning is carried out according to a descending order of a plurality of key elements in combination with a port scanning optimization model based on risk prediction, and a full-amount port risk map is constructed; the static layer is matched with known vulnerabilities; the dynamic layer identifies suspicious behaviors deviating from a normal behavior baseline through an anomaly detection algorithm, and obtains an asset vulnerability detection result in combination with a cross validation method; according to the invention, the detection requirements of asset full coverage and early threat discovery in a complex network environment are met.
Owner:GUANGDONG ORIENTAL THOUGHT TECH

AI model intelligent training and reasoning integrated method and system

The invention provides an AI model intelligent training and reasoning integration method and system, and the method comprises the following steps: receiving a model training instruction, and carrying out the preprocessing of original data, and obtaining a training data set; executing model training based on the training data set, monitoring task priorities and resource requirements through a dynamic resource scheduling algorithm, and dynamically adjusting training resource allocation according to a real-time monitoring result; when the model reaches a preset performance index, performing model pruning and quantification to generate an optimization model, and performing parameter fine tuning on the optimization model to obtain a final deployment model; generating reasoning service configuration according to calculation characteristics of the final deployment model, migrating the model and the configuration to a reasoning environment, and starting reasoning service; and dynamically adjusting the number of reasoning nodes according to the real-time network flow of the reasoning service. By implementing the technical scheme provided by the invention, through bidirectional dynamic resource scheduling and model deep optimization, the computing resource utilization rate and the model deployment efficiency are improved, and the high availability of the reasoning service is guaranteed.
Owner:BEIJING HIZHI TECH CO LTD

Cloud platform malicious code detection method and device based on security big model, and medium

The invention discloses a cloud platform malicious code detection method and device based on a security big model, and a medium, belongs to the technical field of network security, and aims to solve the technical problem of how to realize efficient and accurate malicious code identification and response and guarantee the security of a cloud platform. According to the technical scheme, the method comprises the following steps: collecting and preprocessing multi-modal data: collecting the multi-modal data of codes, logs, network traffic and computer software threat information in a cloud platform, and preprocessing the multi-modal data to obtain the preprocessed multi-modal data; constructing a large security model: constructing the large security model by adopting a hybrid expert architecture and a multi-modal encoder; deploying and using the security big model: deploying the security big model by adopting a containerization technology and a cloud native technology; and malicious code detection based on the security big model: monitoring malicious codes of the cloud platform in combination with multi-modal reasoning of malicious features and behaviors, restoring an attack path and generating a response strategy.
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

System and method to detect and countermeasure RPL attacks in IoT network

A system and a method to detect an attack on an IoT network is disclosed. The IoT network includes interconnection of multiple IoT devices. The method includes receiving, by a network connection device, multiple ICMPv6 network packets from IoT devices and outputting multiple output packets; and matching, by a routing device, a network traffic pattern to attack signatures structured as a taxonomy according to which part of a packet is misused. The taxonomy includes a branch to a data plane attack and a control plane attack, respectively. When an IPv6 RPL packet is detected, the method includes checking for generating, modifying, and replaying attacks by an attacker. When a non-RPL packet is detected, the method includes checking for dropping and leaking packet attacks by the attacker. When the attack is detected, the method includes invoking a solution to the attack. The solution includes mitigation of the attack by the attacker.
Owner:KING FAHD UNIVERSITY OF PETROLEUM AND MINERALS

API monitoring security audit model based on government affair system

The invention discloses an API (Application Program Interface) monitoring security audit model based on a government affair system, which relates to the technical field of network security, and comprises the following steps: collecting and converging network traffic of each collection point; analyzing the distribution condition of APIs in the collected flow, identifying and displaying key information, meanwhile, realizing data real-time processing, data stream splitting, data reading and writing and offline data analysis, and detecting risk behaviors by utilizing a rule strategy library; aPI asset weaknesses are identified and marked, state management is supported, and an attacker portrait, security study and judgment and attack traceability model is constructed; and pushing and displaying risk model early warning, realizing multi-dimensional data source real-time association analysis based on a big data framework, automatically converging alarms to form an event file, and linking with automatic arrangement to complete event response and report generation. According to the method, the problem of insufficient security and stability of the government affair system is solved, and complex attacks and advanced persistent threats can be identified more accurately.
Owner:上海市大数据中心