Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

4046 results about "Internet traffic" patented technology

Internet traffic is the flow of data within the entire Internet, or in certain network links of its constituent networks. Common measurements of traffic are total volume, in units of multiples of the byte, or as transmission rates in bytes per certain time units.

Ai-based cybersecurity system and method thereof

An AI-based Cybersecurity System and Method enable real-time detection, analysis, and mitigation of cyber threats within computing networks using adaptive artificial intelligence. The system continuously monitors network traffic, extracts behavioral and contextual attributes, and applies deep learning-based inference to identify anomalous activities indicating security breaches. The method integrates several computational units, including a network monitoring unit, feature extraction unit, artificial intelligence processor, contextual reasoning processor, and decision synthesis unit, to compute a composite risk index quantifying threat likelihood and severity. A classification processor categorizes detected threats into types such as ransomware, phishing, or unauthorized access, while a mitigation control processor initiates automated response actions to isolate compromised nodes and restore network integrity. An adaptive learning processor updates AI models using feedback from confirmed incidents. This provides a scalable, self-evolving cybersecurity framework that minimizes human intervention and enhances resilience against dynamic and zero-day threats.
Owner:PELL REDDY RAJENDER REDDY

Enhanced encrypted traffic analysis via integrated entropy estimation and neural network-based feature hybridization

A method is provided for encrypted network traffic analysis. The method includes capturing network traffic data; calculating entropy of said data to classify traffic as encrypted or non-encrypted; applying statistical and sequential feature hybridization on encrypted traffic to extract comprehensive features; analyzing the features using a neural network model to identify encrypted traffic types and detect anomalies; and refining the analysis based on entropy and neural network insights through a feedback loop.
Owner:LEPTUDE INC

Network traffic anomaly detection model training method and device and readable storage medium

The invention provides a network traffic anomaly detection model training method and device and a readable storage medium, and the method comprises the steps: extracting a traffic statistical feature vector according to original network traffic data, and generating an initial mixed data set; generating a confrontation disturbance sample output enhanced feature matrix based on the initial mixed data set; constructing a self-adaptive feature fusion rule based on the enhanced feature matrix, embedding asset association degree parameters into an attention calculation layer of a feature encoder, and outputting encoding features fusing threat intelligence; inputting the coding features fused with the threat intelligence into a pre-constructed initial detection model, generating false report and missing report correction labels based on the suspicious traffic fragments, and outputting an adversarial sample correction data set; and performing adversarial training on the initial detection model through the adversarial sample correction data set to obtain an incremental detection model for network traffic anomaly detection. According to the invention, the detection precision, the anti-interference capability and the real-time defense response capability of the detection model to novel attacks can be improved.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD

Lightweight malicious network traffic detection method based on heterogeneous modal feature fusion

The invention discloses a lightweight malicious network traffic detection method based on heterogeneous modal feature fusion, and mainly solves the problems of low feature extraction efficiency and insufficient single modal feature representation of the existing method. Comprising the following steps: acquiring and optimizing a network flow data set, preprocessing the network flow data set, and extracting and generating spatial feature, time sequence feature and behavior pattern feature vectors; an improved self-attention mechanism network is constructed, a lightweight heterogeneous modal feature fusion model LMF is designed, multi-modal feature deep fusion is performed through dynamic weight distribution, a lightweight classification model is trained, and the model is utilized to detect network malicious traffic. Through the lightweight heterogeneous modal feature fusion model LMF and in combination with a dynamic weight distribution mechanism, spatial distribution, time sequence dependence and behavior semantic information of network traffic are deeply mined, data processing efficiency, malicious traffic detection accuracy and system robustness are improved, and the method is suitable for efficient malicious traffic identification and defense in the field of network security.
Owner:XIAN TECH UNIV

Network security analysis method and system based on big data

The invention relates to the technical field of network security, in particular to a network security analysis method and system based on big data. Comprising the following steps: collecting related multi-source heterogeneous data of a network, and carrying out standardized processing such as cleaning and de-noising; network analysis is carried out based on the preprocessed data, network traffic is analyzed in real time by using machine learning and deep learning algorithms, and abnormal conditions are detected; constructing a risk prediction model according to a network analysis result and related information, and predicting a future network security risk level; if the risk level exceeds the threshold value, determining a security event source and a responsibility subject through data tracing; and finally, generating a safety response strategy according to risk prediction and data traceability results, and performing disposal. The corresponding system covers the modules of data acquisition, preprocessing, network analysis, risk prediction, data tracing, security response and disposal and the like, and all the modules work cooperatively to form a complete network security analysis and guarantee system, so that the stable operation of the network system is guaranteed.
Owner:QINGDAO MOCHUANG FUTURE INTELLIGENT TECHNOLOGY CO LTD

Information security analysis method and system based on big data

The invention relates to the technical field of information security data processing, and discloses an information security analysis method and system based on big data, and the method comprises the steps: S1, collecting multi-source heterogeneous security related data which comprises a business log, a user behavior track, network traffic, an application program interface calling record, an identity authentication log and a real-time security data flow, preprocessing the collected data to obtain standardized data; and S2, performing entity identification, event extraction and relationship mining based on the standardized data, and constructing a cross-modal threat knowledge graph containing security entity nodes and associated edges. The method solves the problem of monitoring blind areas caused by lack of dynamic association mining capability among data in a traditional method, and particularly aims at distributed, low-frequency and multi-stage hidden attacks, the scheme can accurately recover an attack chain and identify high-risk threats through dynamic matching and path reasoning of a knowledge graph, and the method has a good application prospect. And the detection coverage rate and accuracy in a complex attack scene are remarkably improved.
Owner:BEIJING YUANFANG TIMES TECHNOLOGY CO LTD

Industrial control network security service security guarantee system based on behavior analysis

The invention provides an industrial control network security service security guarantee system based on behavior analysis, which belongs to the technical field of industrial control network security, and comprises a multi-source data fusion acquisition module, a dynamic behavior modeling engine, a federal learning analysis cluster, an attack chain prediction module, a self-adaptive protection strategy executor and a model evolution feedback ring, wherein the multi-source data fusion acquisition module synchronously acquires industrial control network flow (including OPC UA / Modbus / DNP3 protocol analysis), equipment operation logs, user operation behavior fingerprints and physical interface state data, and the physical interface state data comprises electrical characteristic fluctuation monitoring of USB / network interfaces. According to the scheme, through multi-technology fusion and closed-loop design, the problems of static performance, single-dimension analysis defects and response lag of a traditional industrial control security scheme are effectively solved, a comprehensive protection system with dynamic modeling, intelligent decision making, privacy protection and continuous optimization is constructed, and the security and service reliability of an industrial control network are remarkably improved.
Owner:CPI NORTHEAST ENERGY SAVING TECH +1

Network perception anomaly detection system based on big data

The invention, which relates to the technical field of network awareness anomaly detection, discloses a network awareness anomaly detection system based on big data, comprising a data acquisition module, a feature fusion module, a map construction module, a model calculation module, a root cause reasoning module, a threshold decision module and a response control module. The data acquisition module receives network flow data, equipment state data and system log data and outputs a standardized feature set; the feature fusion module is connected with the data acquisition module, dynamically calculates a weight coefficient of each data source based on information entropy, performs feature aggregation of privacy protection through a federated learning framework, and outputs a fusion feature vector; the atlas construction module is connected with the feature fusion module, maintains a network equipment node set and a communication edge set in real time, and updates a space-time association atlas according to a topology change event; and the model calculation module is connected with the atlas construction module, extracts topological features through a space-time diagram convolutional network, and updates a detection model based on an incremental learning mechanism.
Owner:BEIJING SHISHILI TECHNOLOGY CO LTD

Network security threat research and judgment method, system and equipment and storage medium

The invention discloses a network security threat research and judgment method, system and device and a storage medium, and the method comprises the following steps: S1, obtaining network traffic, terminal logs, application program interface calling records and threat intelligence data in real time, carrying out the standardized cleaning and format conversion of the data, and building a unified data lake; s2, matching, identifying and determining threats through a preset known threat feature library, constructing a normal behavior baseline by using an unsupervised learning algorithm, and marking suspicious events deviating from the baseline; s3, for the suspicious event marked in the step S2, mining a potential attack path and an attack intention by combining knowledge graph technology associated asset information, a historical attack chain and a homologous IP address; and S4, based on the attack success probability, the influence asset importance and the diffusion speed, calculating a threat level by adopting a fuzzy comprehensive evaluation model, and generating a research and judgment report containing disposal suggestions.
Owner:CRCC DEV GRP CO LTD +1

Network traffic anomaly detection strategy generation method based on machine learning

InactiveCN120415800ANeural learning methodsSecuring communicationInternet trafficCollaborative intelligence
The invention relates to a network flow anomaly detection strategy generation method based on machine learning, and belongs to the technical field of machine learning. The method comprises the following steps: firstly, collecting network traffic data in a preset time window, and extracting feature vectors containing traffic, a time sequence and a protocol type; and inputting the feature vector into a long short-term memory auto-encoder model, and calculating a reconstruction error to judge whether the network flow is abnormal or not. Aiming at the abnormal feature vector, adopting a multi-agent depth deterministic strategy gradient algorithm to construct a plurality of cooperative agents, and independently generating a candidate abnormal detection strategy by each agent; through a cross-agent strategy evaluation mechanism, the difference between a joint strategy and a single-agent strategy in the aspect of anomaly detection accuracy is compared, cooperation gain is calculated, strategy exploration parameters of all agents are adjusted according to the cooperation gain, and a global optimal anomaly detection strategy is optimized and determined in real time. According to the method, high-precision and low-missing-report network traffic anomaly detection can be realized, and the method has good self-adaptability and real-time performance.
Owner:SUZHOU XINGYI INFORMATION TECHNOLOGY CO LTD

Network security situation awareness method and device for multi-source data fusion, equipment and medium

The invention relates to a network security situation awareness method and device for multi-source data fusion, equipment and a medium, and the method comprises the steps: respectively collecting kernel logs and network flow data, and carrying out the standardization processing to generate a communication data set; constructing a dynamic process link map, defining a communication type, frequency and data volume, and updating a topological relation in real time; a sliding time window is adopted to count communication time sequence characteristics, and abnormal signals deviating from normal distribution are screened in combination with a time sequence analysis technology; training a robustness classifier model through an adversarial sample enhancement technology, fusing a graph neural network to analyze a dependency relationship between processes, and filtering a false alarm signal; and the hidden channel is accurately identified and alarm information is generated in combination with a dynamic similarity threshold and a threat intelligence gain coefficient, so that the problems of insufficient multi-source data fusion, high false alarm rate of a static rule base, failure in detection of weak signals of the hidden channel and the like in a traditional method are solved. And the real-time perception and response capability of APT attacks in a complex network environment is improved.
Owner:MINXI VOCATIONAL & TECHN COLLEGE

Dynamic access blocking method based on zero trust

The invention relates to the technical field of network security, in particular to a dynamic access blocking method based on zero trust. Comprising the following steps: step 1, collecting whole network flow data in real time in a bypass monitoring mode through a flow mirroring function of a network switch, performing deep packet inspection analysis on the collected original flow data, and extracting network flow characteristic parameters; 2, maintaining a dynamic identity information base; 3, performing real-time behavior analysis on each network session; 4, according to the risk assessment result and the real-time security context, generating a dynamic access control strategy based on a minimum permission principle; 5, implementing access control at the network execution point; and 6, continuously monitoring the network flow and the strategy execution effect, collecting feedback data, optimizing the risk assessment model and the strategy generation algorithm based on the feedback data, and forming closed-loop control. By dynamically updating the identity and asset information, the system can identify new assets or changes in real time, so that the adaptability and response capability of a network environment are improved.
Owner:SHANDONG NETWORK SECURITY TECHNOLOGY CO LTD

Network data intelligent tool system and method based on model context protocol MCP

The invention discloses a network data intelligent tool system and method based on a model context protocol MCP, and relates to the technical field of computer networks. The system comprises an AI analysis main body, an MCP Pcap tool engine, context management, a Pcap data source, various MCP Pcap tools, a Pcap tool gateway interface, a Pcap tool interface and a data packet interface. The invention provides an interaction mechanism of direct embedding and bypass data forwarding in tool calling. According to the method, direct embedded transmission of small-size data in tool calling is supported, separation of data transmission and instruction calling is achieved, the technical bottleneck that large-size Pcap data cannot be efficiently exchanged through a text channel is effectively overcome, efficient processing of the AI model on network packet capture data is achieved, and the data transmission efficiency is improved. And the efficiency and the automation degree of large-scale network traffic analysis are improved.
Owner:SHANGHAI NETIS TECH CO LTD

Method for constructing feature knowledge base of mapping behavior based on deep learning

The disclosure belongs to the technical field of network security, and provides a method for constructing a feature knowledge base of mapping behavior based on deep learning, which includes: data acquisition and preprocessing: extracting five-tuple information and behavior features from network traffic. The disclosure automatically extracts the spatio-temporal features through the deep learning model, and enhances the sensitivity to abnormal behaviors by combining the attention mechanism, thus significantly improving the detection accuracy. The explanatory AI technology is used to automatically generate detection rules, the maintenance cost of manual rules is greatly reduced and the efficiency of rule generation is significantly improved. The feature knowledge base supports dynamic updating, may integrate third-party threat information in real time, and ensures the continuous defense ability against new attacks and variant detection means.
Owner:HUANENG INFORMATION TECH CO LTD

Deep learning-based wireless intrusion detection

Systems, devices, and methods for wireless intrusion detection based on deep learning are provided. A network device collects legitimate network traffic over a time period and learns a first set of features that represents the legitimate network traffic. The network device generates synthetic network traffic based on the learned first set of features and trains a machine learning model based on the learned first set of features and the synthetic network traffic. Based on the training, the machine learning model learns a second set of features that differentiates the synthetic network traffic from the legitimate network traffic. The devices and methods precisely detect potential security threats, while reducing false positives, thereby ensuring a sensitive and accurate response to genuine anomalies. Further, the devices and methods improve accuracy of detection of potential security threats including known and new attacks in wireless networks, while adapting to evolving attack techniques and network dynamics.
Owner:CISCO TECHNOLOGY INC

Identifying unauthorized entities from network traffic

Systems, methods, and devices to detect unauthorized third-party connections within a network infrastructure, such as by analyzing network traffic data using fuzzy matching and machine learning techniques. One aspect includes receiving network traffic data comprising records of communication events involving network identifiers, determining communication relationships between network entities identified by the network identifiers, accessing entity identifiers associated with known third-party systems, and determining associations between the network identifiers and the entity identifiers using a fuzzy matching process. Other aspects include identifying communication relationships involving the third-party systems based on the associations and detecting unregistered or unknown third-party connections within the network infrastructure. Further aspects include normalizing identifiers, computing string similarity metrics, assigning confidence scores, incorporating external data sources, building network association patterns, comparing current patterns to baseline patterns to detect anomalies, and updating security policies or firewall rules in response to detected anomalies. Additional aspects are provided.
Owner:HSBC GRP MANAGEMENT SERVICES LTD

Adaptive encryption system based on AI intelligent safety management

The invention discloses a self-adaptive encryption system based on AI intelligent security management, which relates to the technical field of information security, and comprises a data acquisition module, a risk assessment module, an encryption algorithm selection module, a key generation and management module, an encryption execution module and an encryption effect feedback module, the data collection module is used for collecting various data in a system operation environment, including but not limited to network flow data, equipment state data and user behavior data; and the risk assessment module analyzes the collected data based on an AI algorithm and assesses the security risk level faced by the current system. The operation environment data is comprehensively collected through the data acquisition module, the security risk level is evaluated in real time through the risk evaluation module based on the AI algorithm, the adaptive encryption algorithm can be dynamically selected according to the risk, the defect that a traditional encryption system is fixed in strategy is overcome, and encryption pertinence and effectiveness are improved.
Owner:HEBI CRYPTOADVANCED TECH RES INST

Big data-based private network data security detection method

The invention discloses a private network data security detection method based on big data, and belongs to the field of security detection, and the method comprises the steps: obtaining a real-time data packet from private network traffic, encoding the data packet through a forward error correction code technology, generating redundancy check information, and obtaining an encoded data packet; if a bit error is detected in the transmission process of the coded data packet, requesting a sending end to retransmit a damaged data packet through an automatic retransmission request mechanism to obtain a retransmitted data packet; adjusting the redundancy of a forward error correction code and a trigger threshold of an automatic retransmission request according to the adaptive error correction parameter, generating an optimized error correction scheme, and obtaining a repaired data packet; and aiming at the alarm processing instruction, automatically adjusting a network flow control strategy, limiting the transmission bandwidth of an abnormal destination, updating the sensitive data fingerprint database, and obtaining optimized protection configuration.
Owner:河北工业职业技术大学

Multi-radio access technology traffic management

Disclosed embodiments generally relate to edge-based multi-Radio Access Technology (RAT) traffic management (TM) solutions to support delay-sensitive traffic over heterogeneous networks. Embodiments include delay-aware TM implementations that split and / or steer network traffic across different RATs for the edge network control plane. Embodiments also include utilization threshold-based implementations to achieve delay-aware multi-path TM at the network's edge. The multi-path TM includes multi-RAT, multi-access, or multi-connectivity traffic routes. Embodiments include strategies to sort users (or devices) for making multi-RAT traffic distribution decisions and to determinate the utilization thresholds. Embodiments also include message exchange mechanisms or learning utilization thresholds and other useful system properties. Other embodiments may be described and / or claimed.
Owner:INTEL CORP

Intelligent tracking and blocking method and system for network attack chain

The invention provides an intelligent tracking and blocking method and system for a network attack chain, and relates to the technical field of network security, and the method comprises the steps: collecting network flow data, building an attack chain propagation path, setting a detection breakpoint, obtaining a data sample, carrying out the causal correlation analysis, extracting a data transmission feature, and converting the data transmission feature into a behavior sequence feature; predicting an attack chain evolution path by adopting a bidirectional feature matching mechanism; a honeypot service and a flow probe are deployed to generate an attacker portrait; and formulating a defense strategy according to the attack intention to realize attack chain blocking. According to the invention, accurate identification, effective tracking and active defense of network attacks can be realized, and the network security protection capability is improved.
Owner:BEIJING YUHONG XINAN TECHNOLOGY CO LTD

Network space security situation awareness detection analysis system and method

The invention discloses a network space security situation awareness detection analysis system and method, and the system comprises a heterogeneous network flow feature deep extraction unit which obtains a flow feature vector through a distributed probe array and an adaptive sampling strategy; the edge computing gateway multi-dimensional threat feature mapping unit realizes feature space mapping through a multi-dimensional feature mapping matrix; the dynamic weight multi-head attention feature fusion unit fuses features by using an optimized multi-head attention mechanism; the time-space sequence security situation evolution modeling unit constructs an evolution model in combination with the time sequence and the fusion features; the security threat risk quantitative evaluation unit carries out risk quantification; and the heterogeneous security policy collaborative response unit generates a response instruction. According to the method, flow collection, feature mapping, fusion, modeling, quantification and response operation are sequentially executed based on all units of the system. According to the method, efficient perception and accurate response of the network space security situation are realized through a multi-unit cooperation and innovation model.
Owner:SOUTHEAST UNIV

Intention-driven low earth orbit satellite network SRv6 routing control method

An intention-driven low-orbit satellite network SRv6 routing management and control method comprises the following steps: step 1, receiving and analyzing a user service demand from an application layer, and generating a corresponding intention label according to a service type; step 2, collecting state information of a satellite network in real time, tracking and recording satellite node position change and link state conversion, and establishing a complete network state database; 3, calculating a routing path meeting the service quality requirement by adopting an improved breadth-first search algorithm; 4, monitoring the state change of the inter-satellite link in real time; step 5, continuously monitoring fault events in the network, immediately starting a pre-calculated standby path when a fault is detected, updating a corresponding SRv6SID list, and performing rapid path switching; and step 6, dynamically adjusting the network flow. The method not only can adapt to the dynamic characteristics of the low earth orbit satellite network, but also can effectively meet the differentiated service requirements, and has the rapid fault recovery and load balancing capability.
Owner:XIDIAN UNIV

Graph neural network and reinforcement learning techniques for connection management

The present disclosure provides connection management techniques based on graph neural networks (GNN) and deep reinforcement learning (DRL) to optimize user association and load balancing. A graph structure of a communication network is considered for the GNN architecture and DRL is used to learn parameters of the GNN algorithm / model. Connection management is defined as a combinatorial graph optimization problem, and the DRL mechanism uses the underlying graph to learn weights of the GNN for an optimal user connections or associations. The connection management techniques can consider local network features to make better decisions to balance network traffic load while network throughput is also maximized. Implementations are provided based on edge computing frameworks include the Open RAN (O-RAN) architecture. Other embodiments may be described and / or claimed.
Owner:INTEL CORP

Power monitoring system distribution network security management active defense system

The invention relates to the technical field of network security management, in particular to an active defense system for power monitoring system distribution network security management. The safety monitoring unit is used for collecting and analyzing network data in real time; the intrusion detection unit is used for identifying suspicious activities and attack signs; the risk assessment unit further analyzes the suspicious activities and the attack signs and assesses the influence degree of the suspicious activities and the attack signs on the power grid security; and the decision support response unit provides coping strategy suggestions according to the result of the risk assessment and executes the provided countermeasures. By integrating the safety monitoring unit, the intrusion detection unit, the risk assessment unit and the decision support response unit, real-time collection, analysis and processing of network data are realized. Particularly, the intrusion detection unit adopts an advanced network flow behavior recognition model and a system log behavior recognition model, so that behaviors which are not consistent with a normal communication mode and abnormal operation records in a system log can be effectively recognized.
Owner:STATE GRID SHANDONG ELECTRIC POWER CO

Malicious encrypted traffic detection method based on cross-modal alignment and graph sequence fusion

The invention provides a malicious encrypted traffic detection method based on cross-modal alignment and graph sequence fusion, and belongs to the technical field of information security. The invention relates to a multi-modal encrypted traffic detection model GGT-Net, which is a multi-modal encrypted traffic detection model, and is characterized in that the multi-modal encrypted traffic detection model is a multi-modal encrypted traffic detection model GGT-Net which is integrated with a graph convolutional network (GCN) and a gated loop unit (GRU). According to the model, protocol structure features and statistical sequence features of network traffic are independently modeled, multi-modal features are fused through a Transform module, and the specific steps are feature extraction and TLS interaction field analysis, statistical feature standardization and protocol diagram structuring, sequence information processing and diagram convolution feature learning and multi-modal feature fusion. And finally classifying and discriminating. According to the invention, the accuracy and generalization performance of encrypted traffic detection are obviously improved.
Owner:GANSU INST OF POLITICAL SCI & LAW

Control method of multi-protocol switching anti-quantum security gateway

The invention relates to a control method for a multi-protocol switching anti-quantum security gateway, and the method comprises the steps: carrying out the safety self-inspection of a hardware environment after the security gateway is powered on, generating a unique root key of equipment based on a physical unclonable function, continuously collecting and analyzing the network traffic characteristics, and carrying out the self-inspection of the hardware environment. Based on a machine learning model, a quantum attack mode is identified and an encryption algorithm mode is dynamically decided, protocol analysis is carried out on a communication data packet, dynamic conversion and adaptation are carried out between a traditional protocol and an anti-quantum cryptography protocol according to an instruction and a preset rule, and an anti-quantum cryptography engine is called to carry out encryption or signature operation. And dynamically deriving and managing a session key in a complete period based on a root key, switching an algorithm mode, a communication protocol and a key in a linkage manner according to a quantum attack detection result, and starting anti-side channel attack protection and hardware security response. According to the method, active protection of the security gateway on quantum attacks, multi-protocol seamless compatibility and full-life-cycle security management of keys are realized.
Owner:WEIDE GUANGDONG INFORMATION TECH CO LTD

Hardware-accelerated flexible steering rules over service function chaining (SFC)

Technologies for configuring flexible hardware-accelerated rules in a Service Function Chaining (SFC) architecture are described. A DPU includes an acceleration hardware engine to provide a single accelerated data plane, and a processing device that generates a first virtual bridge and a second virtual bridge. The first virtual bridge is controlled by a first network service hosted on the DPU and has a first set of one or more network rules. The second virtual bridge has a second set of one or more user-defined network rules. The processing device generates a combined set of network rules based on the first set of one or more network rules and the second set of one or more user-defined network rules. The acceleration hardware engine processes network traffic data in the single accelerated data plane using the combined set of network rules.
Owner:MELLANOX TECHNOLOGIES LTD(IL)

Abnormal traffic detection method based on time sequence

The invention discloses an abnormal traffic detection method based on a time sequence, and the method comprises the steps: firstly mining time sequence mode features of original network traffic data streams under different time scales through integrating a plurality of basic anomaly detection models, and generating a corresponding anomaly score for each feature; secondly, performing normalization processing on abnormal scores generated by each model, and combining the abnormal scores as soft tags and time sequence feature coding vectors; further performing aggregation analysis on the fused features so as to realize efficient aggregation and deep expression of a complex sequential relationship and a potential abnormal mode; and finally, abnormal traffic detection of the original network traffic data flow is realized through the meta classifier. Through the mode, the limitation of a traditional single model or shallow statistical analysis method in the aspects of generalization ability, complex scene adaptability, real-time intelligent decision and the like is broken through, and a new generation of network abnormal flow detection solution with higher robustness is provided for an actual application scene.
Owner:STATE GRID HENAN INFORMATION & TELECOMM CO +1

Network information security monitoring system

The invention relates to the technical field of information security, and discloses a network information security monitoring system, which comprises the following modules: a data collection module used for collecting data from network traffic, system logs and user behaviors in real time; the data processing module adopts a Z-score standardized processing technology to unify different features to the same scale so as to ensure that the mean value of the features is 0 and the standard deviation is 1, thereby improving the comparability between the features; and the threat detection module analyzes the processed data based on a machine learning algorithm and identifies possible network security threats. Through cooperative work of all the modules, comprehensive real-time data collection, accurate threat detection, practical response execution and continuous feedback optimization are realized, the network security threat handling capacity is integrally improved, and network information security monitoring work is stably and efficiently carried out for a long time. The problem that a response strategy of a traditional network information security monitoring system lacks pertinence and timeliness is solved.
Owner:WUHAN DINGCHENG WEIDU TECHNOLOGY CO LTD

Network intrusion detection method and system based on edge attention learning

The invention discloses a network intrusion detection method and system based on edge attention learning, and a storage medium, and the method comprises the steps: converting an original network flow into a network flow diagram, and constructing a training diagram and a test diagram under the condition that a coarse-grained label and a fine-grained label are reserved; edge embedding representation is obtained through edge feature reservation, adaptive weight distribution and multi-layer feature extraction of the training graph and the test graph; based on the edge embedding representation, performing coarse-grained detection to identify a basic attack category, and performing fine-grained classification by using multi-scale feature fusion related to global graph attributes; and adversarial training: through initializing adversarial disturbance and optimizing disturbance based on loss function gradient iteration, superposing final disturbance into the training graph, and based on loss function back propagation updating, obtaining a trained network intrusion detection model. The method provided by the invention can effectively capture the depth characteristics of the key attack and maintain the stable detection performance in the confrontation environment.
Owner:HARBIN INSTITUTE OF TECHNOLOGY (SHENZHEN) (INSTITUTE OF SCIENCE AND TECHNOLOGY INNOVATION HARBIN INSTITUTE OF TECHNOLOGY SHENZHEN)