Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

208 results about "Intrusion detection system" patented technology

An intrusion detection system (IDS) is a device or software application that monitors a network or systems for malicious activity or policy violations. Any malicious activity or violation is typically reported either to an administrator or collected centrally using a security information and event management (SIEM) system. A SIEM system combines outputs from multiple sources and uses alarm filtering techniques to distinguish malicious activity from false alarms.

Deep learning-based wireless intrusion detection

Systems, devices, and methods for wireless intrusion detection based on deep learning are provided. A network device collects legitimate network traffic over a time period and learns a first set of features that represents the legitimate network traffic. The network device generates synthetic network traffic based on the learned first set of features and trains a machine learning model based on the learned first set of features and the synthetic network traffic. Based on the training, the machine learning model learns a second set of features that differentiates the synthetic network traffic from the legitimate network traffic. The devices and methods precisely detect potential security threats, while reducing false positives, thereby ensuring a sensitive and accurate response to genuine anomalies. Further, the devices and methods improve accuracy of detection of potential security threats including known and new attacks in wireless networks, while adapting to evolving attack techniques and network dynamics.
Owner:CISCO TECHNOLOGY INC

Network security intrusion detection system and method fused with graph neural network

The invention discloses a network security intrusion detection system and method fusing a graph neural network, and the method comprises the steps: collecting multi-source flow data in a network operation process, constructing an induction topological graph through employing a graph convolution modeling technology, and revealing a deep incidence relation between network nodes; a hidden attack mode is identified by adopting a multi-layer graph propagation and resonance enhancement technology, and high-quality node embedding representation is generated through a graph attention mechanism and abnormal resonance amplification; an attack behavior map is extracted by combining depth map learning and a map pooling technology, and a self-adaptive protection strategy is generated through map inversion mapping and dynamic topological transformation; an interlaced detection sequence is constructed by adopting a multi-layer detection rule decomposition and graph optimization sorting technology, and a self-adaptive response signal is generated through active defense prediction and time difference bottleneck analysis, so that intelligent detection, accurate analysis and self-adaptive protection of network intrusion behaviors are realized, and the intelligent level and protection effect of network security protection are improved.
Owner:CHANGCHUN INST OF TECH

Intrusion detection system applied to network security field

The invention relates to the technical field of network security, in particular to an intrusion detection system applied to the field of network security, which can accurately identify potential attack behaviors and reduce misjudgment rate by extracting session time sequence characteristics, separating load and behavior metadata and generating a behavior semantic primitive set. Discrete behavior semantic primitives are aggregated into intention propagation nodes, a multi-order attack dependency relationship is deduced, a multi-order attack intention propagation map is generated, the relationship between an attack path and the nodes can be clearly presented, and a key attack link can be positioned; according to graph topology vulnerability distribution, detection strategy template parameters are automatically generated and dynamically adjusted, different attack scenes can be adapted in real time, and the accuracy and flexibility of a detection strategy are improved; through real-time monitoring and marking of a key attack path, triggering of a cross-device cooperative defense mechanism, and generation of a region isolation instruction and a flow cleaning rule, transverse penetration and longitudinal deepening of an attack chain can be blocked, and attack diffusion is prevented.
Owner:CHINA YANGTZE POWER

Embedded intrusion detection system for industrial controllers

An intrusion detection system can be embedded in an industrial controller to detect an attack on an industrial control system. The intrusion detection system can detect an attack by determining if there are anomalies related to the network traffic in the industrial control system and / or by determining if the devices (e.g., sensors and actuators) connected to the industrial controllers of the industrial control system are not operating within expected ranges. To assist in determining if the devices of the industrial control system are not operating properly, the industrial controllers can also be networked together in a peer-to-peer network that permits each industrial controller to share its state information with the other industrial controllers.
Owner:UNIVERSITY OF ALABAMA

Power grid intrusion detection system based on artificial intelligence

The invention relates to the technical field of data processing, and discloses an artificial intelligence-based power grid intrusion detection system, which comprises a three-dimensional data cube construction module, a three-dimensional data cube feature extraction module, a feature fusion module, an attack probability prediction module, an attack credibility evaluation module and an intrusion protection module, aligning timestamps among the communication flow, the equipment state and the node topological relation of the power grid to generate a three-dimensional data cube of the power grid; abnormal node propagation characteristics and a flow time sequence mode are extracted; fusing the abnormal node propagation features and the time features of the flow time sequence mode through a cross-channel attention mechanism to obtain a fused feature vector; inputting the fusion feature vector into a full connection layer to obtain an attack probability; when the attack probability exceeds a preset threshold value, starting a sandbox verification process, and generating an attack credibility score; and issuing a network isolation and channel switching instruction based on the attack credibility score. The accuracy of power grid intrusion detection can be improved.
Owner:GUIZHOU POWER GRID CO LTD

Ensemble intrusion detection system for IoT platforms

PendingUS20250384131A1Platform integrity maintainanceData packDynaset
An automated method and system for modeling intrusion detection on an Internet of Things network preprocess received raw data packets. The raw data packets are converted to a packet capture file, which is converted to a comma separated value (CSV) file. The CSV file is filtered to create normal and abnormal CSV files. An attack is identified in the abnormal CSV file. Features associated with the attack are labeled and classified as an attack type. The abnormal and normal CSV files are merged. Redundant data is removed from the merged file, which is added to a concatenated file with other merged files. Features are extracted from the concatenated file and a machine language (ML) model is built using the extracted features. ML classifiers are determined for each merged file for the ML model to build an ensemble ML model. A dynamic ensemble of ML classifiers detects evolving attack types.
Owner:MORGAN STATE UNIVERSITY

Endogenous security OS construction method and device based on intelligent agent and control calculation

The invention belongs to the technical field of information security, and relates to an endogenous security OS construction method and device based on intelligent agent and control computing, and the method comprises the steps: constructing an underlying security base based on a hardware trusted root and a microkernel; based on the bottom-layer security base, defining and deploying a hierarchical multi-intelligent agent with a specific function; establishing a multi-agent communication and interaction protocol stack for the multi-intelligent agent; based on a multi-agent communication and interaction protocol stack, an intelligent collaborative scheduling algorithm oriented to multi-objective optimization is developed; an endogenous security mechanism integrating active defense and passive response; and carrying out full-life-cycle security situation assessment on the endogenous security operation system. Dynamic intrusion detection can be carried out, an intrusion detection system (IDS) based on machine learning is deployed, a normal behavior mode of an intelligent agent is learned, and abnormal tampering behaviors, DoS attacks, communication anomalies and the like are identified.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Network security alarm intelligent identification method and device

The invention discloses a network security alarm intelligent identification method and device, and relates to the technical field of network security alarm identification, and the method comprises the steps: carrying out the preprocessing of original data from network traffic, log files, user behavior records, a firewall and an intrusion detection system, and obtaining a multi-dimensional security event data set; node modeling and edge relation modeling are carried out based on a GNN and the multi-dimensional security event data set, and cross-system and cross-time-dimension security event association features are extracted to obtain a high-dimensional context sensing feature vector set; a time sequence anomaly detection model is constructed based on a high-dimensional context sensing feature vector set and a time sequence analysis technology, the high-dimensional context sensing feature vector set is input into the time sequence anomaly detection model, and weighting calculation is performed on each time step by extracting time dependent features and combining an Attention mechanism. Outputting an abnormal score vector corresponding to each time point; and constructing a behavior deviation function based on the multi-dimensional security event data in combination with deep learning data.
Owner:STATE GRID GANSU ELECTRIC POWER RESEARCH INSTITUTE

Automobile electronic intrusion determination method and device based on multi-source fusion data

An automotive electronic intrusion determination method, apparatus and device based on multi-source fusion data, and a storage medium, the method comprising: performing filtering processing and fusion processing on obtained CAN bus data, vehicle-mounted entertainment system data, Internet of Vehicles data and vehicle state data to generate multi-dimensional feature vector data; marking a corresponding early warning level for the multi-dimensional feature vector data to generate a multi-source fusion data set; training a preset neural network based on the multi-source fusion data set to generate an automobile electronic intrusion detection model; and based on the automobile electronic intrusion detection model, according to the obtained target CAN bus data, target vehicle-mounted entertainment system data, target Internet of Vehicles data and / or target vehicle state data, obtaining an early warning level output by the automobile electronic intrusion detection model so as to determine whether the current vehicle is invaded or not. The technical problems that the false alarm rate is high and complex attacks are difficult to recognize due to the fact that an automobile electronic intrusion detection system depends on a single data source are solved.
Owner:ZHIXIN CONTROL SYST CO LTD

Vehicle-mounted CAN bus intrusion detection system and method based on comparison self-supervised learning

The invention provides a vehicle-mounted CAN bus intrusion detection system and method based on comparison self-supervised learning. The system comprises a data preprocessing module which is used for receiving a CAN bus data stream in real time, performing feature extraction on each CAN message in the CAN bus data stream to generate a multi-dimensional feature vector, and stacking the feature vectors of W continuous messages by adopting a sliding window method to construct a two-dimensional time sequence sample; the intrusion detection model is used for reasoning the two-dimensional time sequence sample and outputting a classification label; the intrusion detection model is trained through a multi-task joint training method, and the training method fuses an unsupervised reconstruction task, a supervised classification task and a self-supervised contrast learning task; and the decision module is used for judging whether a CAN bus intrusion behavior exists or not according to the classification label output by the intrusion detection model. And the purposes of high efficiency, light weight of the model and capability of accurately identifying various attacks are achieved.
Owner:WUXI UNIV +2

Real-time intrusion detection system and method based on deep learning

The invention discloses a real-time intrusion detection system and method based on deep learning, and aims to solve the problem that when the existing deep learning intrusion detection technology processes high-dimensional network flow data, the information fidelity and the real-time processing efficiency are difficult to consider at the same time. According to the system and the method, a heterogeneous feature decoupling and fusion network architecture is adopted, high-dimensional feature vectors are losslessly decomposed into feature subsets of static state, time sequence, graph topology association and the like, deep learning is carried out by a parallel coding subsystem, cross-modal fusion attention self-adaptive aggregation is carried out, and finally classification judgment is realized. According to the scheme, on the basis of keeping the integrity of high-dimensional data, the detection capability and the real-time processing efficiency of unknown attacks are remarkably improved, and the self-adaptability and the robustness are improved.
Owner:CHENGDU EAGLE INFORMATION TECH CO LTD

A network security monitoring system to deal with APT attacks

The present invention belongs to the field of network attack detection, and specifically relates to a network security monitoring system for responding to APT attacks. The system comprises an industrial control network gateway security device, an industrial control network management system, and an industrial control network security operations center. The industrial control network gateway security device includes a behavioral data collection module for collecting network traffic and system activity data from various devices, including intrusion detection systems and flow probes, and providing the data to the industrial control network management system. The industrial control network management system includes a data preprocessing module, a subgraph generation module, a behavioral feature extraction module, and a model training and anomaly detection module. The module preprocesses raw data, generates traceability graphs and subgraphs, extracts behavioral features, and establishes a classification model for anomaly detection. The industrial control network security operations center includes a risk warning reporting module that visually reports detected risks to security operations personnel and generates detailed analysis reports.
Owner:TONGJI UNIV

Preservation of network integrity in changing network conditions triggered by data harvesting for retrospective decryption

ActiveUS20260058985A1Securing communicationNetwork conditionsNetwork integrity
A method for enhancing security of data, code, and / or network components by introducing a layer of integrity management that adapts to changing conditions within a network. The method may include use of a processor to perform intrusion analysis using an intrusion detection system and / or prevention system, behavioral analysis by accessing user logs to see if behavior is within a normal range, and / or geolocation analysis to see if the piece of data, section of code, and / or network component are within their usual surroundings. When there is a concern of a data breach, leak, and / or hack, the processor may initiate a response that detects other pieces of data, sections of code, and / or network components in proximity, initiates a self-destruct mechanism, triggers hardware to perform outside of operational specifications, and contains the spread of the data breach, leak, and / or hack through shutdown procedures, isolating affected systems, and / or alerting security personnel.
Owner:BANK OF AMERICA CORP

Self-adaptive scheduling industrial internet data acquisition control system and strategy

The invention discloses a self-adaptive scheduling industrial internet data acquisition control system and strategy, and relates to the technical field of industrial internet data acquisition and self-adaptive scheduling control, and the system comprises a data sensing layer, a deployment multi-type intelligent sensor group, an edge gateway and a hybrid communication module. The sensor supports multi-protocol adaptive access and dynamically switches sampling frequency, the edge gateway preprocesses original data, and the communication module guarantees stable transmission through wired and wireless hybrid networking; the self-adaptive scheduling layer comprises a task grading unit, a load monitoring unit and a dynamic scheduling unit; the edge calculation layer is used for processing tasks with high real-time performance; the cloud collaboration layer stores data and mines, analyzes and constructs an equipment model; the security protection layer realizes identity verification, data encryption and intrusion detection; and the system management layer manages the full life cycle of the equipment and divides user permissions. According to the system, the problem of traditional industrial internet data acquisition scheduling pain points is solved, and the overall operation efficiency and safety of the system are effectively improved.
Owner:LUAN YILI INNOVATION TECH CO LTD

Lightweight CAN bus intrusion detection method based on enhanced active learning

The invention discloses a lightweight CAN (Controller Area Network) bus intrusion detection method based on enhanced active learning, which optimizes an annotation strategy in a sample selection process through a label self-adaptive optimization mechanism, an enhanced learning-driven strategy adjustment capability and a resource-controllable dynamic reasoning architecture, can efficiently utilize annotation data, and improves the detection efficiency. The workload and cost of manual annotation are greatly reduced, the overall annotation requirement is reduced, the utilization efficiency of annotation resources is improved, a lightweight inference model set and an accurate inference model set are combined by designing a double-stage inference gating algorithm based on reinforcement learning, inference calculation can be dynamically adjusted according to actual needs, and the annotation efficiency is improved. And uncertain samples are transferred into a precise reasoning model set for further judgment, so that the use of overall computing resources is optimized, the computing burden of an intrusion detection system is reduced, meanwhile, the response speed is increased, the sustainable optimization capability of the model is enhanced, and the detection precision and the adaptive capability are improved.
Owner:ZHEJIANG UNIV +1

Deep learning-based wireless intrusion detection

Systems, devices, and methods for wireless intrusion detection based on deep learning are provided. A network device collects legitimate network traffic over a time period and learns a first set of features that represents the legitimate network traffic. The network device generates synthetic network traffic based on the learned first set of features and trains a machine learning model based on the learned first set of features and the synthetic network traffic. Based on the training, the machine learning model learns a second set of features that differentiates the synthetic network traffic from the legitimate network traffic. The devices and methods precisely detect potential security threats, while reducing false positives, thereby ensuring a sensitive and accurate response to genuine anomalies. Further, the devices and methods improve accuracy of detection of potential security threats including known and new attacks in wireless networks, while adapting to evolving attack techniques and network dynamics.
Owner:CISCO TECHNOLOGY INC

A vehicle-mounted CAN bus intrusion detection system and method

The present invention discloses an in-vehicle CAN bus intrusion detection system and method. The system is based on an improved compression network model trained on a convolutional layer, a pooling layer, multiple dynamic feature extraction modules, a convolutional mapping layer, a global average pooling layer, and a classification output layer. The dynamic feature extraction module includes a compression layer and an expansion branch. The compression layer uses 1×1 depthwise separable convolution for feature compression, while the expansion branch uses 1×1 and 3×3 depthwise separable convolutions. Feature concatenation enhances channel feature expression. The concatenated output is connected to a channel attention module to optimize channel feature distribution and suppress redundant information, thereby enhancing the network's feature extraction and classification capabilities. The system can detect abnormal traffic in the in-vehicle network with high accuracy, low latency, and efficient processing capabilities. It is adaptable to resource-constrained in-vehicle environments and addresses the high complexity, slow response, and limited deployment issues of existing intrusion detection systems.
Owner:JIANGSU SAIZHI DIGITAL SECURITY TECHNOLOGY CO LTD

Lightweight Internet of Vehicles intrusion detection system and method based on parallel CNN-Mama fusion network

The invention discloses a lightweight Internet of Vehicles intrusion detection system and method based on a parallel CNN-Mama fusion network, and the system comprises a data receiving module, a data preprocessing module, a pseudo-color image construction module which is used for mapping network flow data into a three-channel pseudo-color image and carrying out the scaling of the three-channel pseudo-color image, and a data processing module which is used for processing the three-channel pseudo-color image. The parallel double-branch network is composed of a CNN space branch and a Mama sequence branch, the fusion judgment module is used for carrying out average fusion on output of the parallel double-branch network and outputting a final detection category, the CNN space branch is used for extracting a local texture pattern and cross-feature coupling relation, and the Mama sequence branch is used for extracting long-distance dependency features; when the system is oriented to CICIDS2018 class 11 fine-grained multi-classification tasks, under the conditions that classes are extremely unbalanced and minority classes of samples are scarce, stable distinguishing of normal traffic and multiple attack types can still be achieved, and good engineering application value is achieved.
Owner:CHANGCHUN UNIV

Railway yard foreign matter intrusion detection system and method based on infrared thermal imaging

The invention relates to a railway yard foreign matter intrusion detection system and method based on infrared thermal imaging. The system comprises an intelligent scheduling system which is used for obtaining route information matched with an operation task under the condition that the railway yard has the operation task; the intelligent vehicle-mounted system is used for detecting a locomotive position matched with the route information; the foreign matter detection system is used for determining a driving front limit area of the locomotive based on the route information and the position of the locomotive and acquiring an infrared thermal imaging image corresponding to the driving front limit area; and sending alarm information to an intelligent vehicle-mounted system under the condition of determining that foreign matters exist in the driving front limit area based on the infrared thermal imaging image, so that the intelligent vehicle-mounted system controls the state of the locomotive based on the alarm information. By adopting the system provided by the invention, the foreign matter detection accuracy of the railway yard can be improved.
Owner:SHENHUA BAOSHEN RAILWAY GRP +1

Network protection

A computer-implemented method of protecting a network is provided. The method receives security alert data from one or more intrusion detection systems. The security alert data comprises a plurality of security alerts relating to the network. The method generates a plurality of similarity matrices from the security alert data. Each similarity matrix is generated using a different respective similarity function and indicates a respective similarity between each of the security alerts according to that similarity function. The method generates one or more attack graphs from the plurality of similarity matrices. Each attack graph represents a respective set of security alerts, wherein a similarity between each of the security alerts in the set, according to at least one of the similarity matrices, is above a predefined threshold. The method causes one or more predetermined actions to be taken with respect to the network to mitigate a respective attack represented by each of the attack graphs.
Owner:BRITISH TELECOM PLC

A Lightweight Vehicle Network Intrusion Detection System and Method Based on Parallel CNN-Mamba Fusion Network

This invention discloses a lightweight vehicle network intrusion detection system and method based on a parallel CNN-Mamba fusion network. The system includes a data receiving module, a data preprocessing module, a pseudo-color image construction module for mapping network traffic data into a three-channel pseudo-color image and scaling it, and a parallel dual-branch network composed of a CNN spatial branch and a Mamba sequence branch for averaging and fusing the outputs of the parallel dual-branch network to output the final detection category. The CNN spatial branch is used to extract local texture patterns and cross-feature coupling relationships, and the Mamba sequence branch is used to extract long-distance dependent features. When facing the CICIDS2018 11-class fine-grained multi-class classification task, the system can still stably distinguish between normal traffic and various attack types under the conditions of extremely imbalanced classes and scarce minority class samples, and has good engineering application value.
Owner:CHANGCHUN UNIV

Intrusion detection system

This invention provides an intrusion detection system that prevents the system from mistakenly identifying the entry of workers or other personnel into restricted areas as an intrusion. [Solution] The intrusion detection system 1 determines that an intrusion into the restricted area R has occurred when a human Z is detected within the restricted area R. However, if multiple human Zs are detected within the restricted area R, and the colors of the same body part detected for each of the multiple human Zs fall within a predetermined color range, then it is not determined that an intrusion into the restricted area R has occurred.
Owner:ASILLA INC

Method and system for improving cloud native environment intrusion detection efficiency

The invention discloses a method and a system for improving cloud native environment intrusion detection efficiency. The method comprises the following steps: monitoring whether load configuration resources arranged in a cluster are changed or not; wherein in the cluster, a corresponding load configuration resource is set for each working load, and one working load relates to a plurality of instances; generating a corresponding intrusion detection rule set according to the changed target load configuration resources; according to a plurality of target instances related to a target workload corresponding to the target load configuration resource, determining a plurality of target nodes for operating the plurality of target instances from the cluster; sending the intrusion detection rule set to the plurality of target nodes, so that host intrusion detection systems on the plurality of target nodes execute detection operation based on the intrusion detection rule set; according to the invention, the efficiency and accuracy of intrusion detection are significantly improved, and more efficient and intelligent security protection is provided for the cloud native environment.
Owner:QI AN XIN TECHNOLOGY GROUP INC

Trans-vehicle CAN bus intrusion detection method capable of transferable codebook remapping

The invention discloses a transferable codebook remapping cross-vehicle type CAN bus intrusion detection method, which belongs to the technical field of intrusion detection, and comprises the following steps: obtaining source vehicle type characteristics from a CAN message of a source vehicle type, learning a codebook, and quantifying the source vehicle type characteristics and the codebook into a source vehicle type symbol sequence and a source vehicle type histogram with a fixed length; inputting into a classifier in a discrete space for training; and collecting a target vehicle model sample from a target vehicle model, establishing a remapping table from a target code word to a source code word in combination with the feature similarity of the target vehicle model and the source vehicle model and a co-occurrence mode when the code word is used, aligning a symbol of a histogram of the target vehicle model to a symbol space of the source vehicle model, and detecting the target vehicle model by using a trained classifier. According to the invention, a lightweight reusable representation and remapping mechanism is provided for cross-vehicle intrusion detection, the accuracy, stability and interpretability of attack recognition are improved, and the application range of a vehicle intrusion detection system under the conditions of multiple vehicle types and small samples is expanded.
Owner:HANGZHOU UNIV OF ELECTRONIC SCI & TECH PINGHU DIGITAL TECH INNOVATION RES INST CO LTD +1

Managing and deploying custom intrusion detection system signature policies

Methods and systems for deploying intrusion detection system (IDS) policies to IDS programs are disclosed. Each IDS instance can monitor a data feed (e.g., comprising computer network traffic) in accordance with a set of “signatures” or “rules” associated with its policy, and can issue alerts if any elements of that network traffic match those signatures or rules. An intrusion signature management module can receive IDS signatures from one or more signature sources and store those signatures in a filesystem. The intrusion signature management module can produce rule files based on these IDS signatures, e.g., containing subsets of the received IDS signatures. These rule files can be provided to a version control server, and can later be accessed by an orchestration module. The orchestration module can deploy these rule files to their respective IDS programs, enabling those IDS programs to monitor their respective data feeds in accordance with the rule files.
Owner:VISA INTERNATIONAL SERVICE ASSOCIATION

Intrusion detection system using CRC in vehicle network and method thereof

An intrusion detection method performed by an intrusion detection system using CRC includes receiving in-vehicle CAN data in units of frame, generating first feature information by extracting a CAN ID from the in-vehicle CAN data in units of frame and performing zero padding, generating second feature information by extracting a CRC field from the in-vehicle CAN data in units of frame and performing the zero padding, training a learning model by setting the first feature information and the second feature information as input data and labeling, as output data, whether the CAN data is attack data or normal data, and detecting whether the CAN data is normal data or attack data by extracting a CAN ID and a CRC field from the received in-vehicle CAN data when training of the learning model is completed and inputting the CAN ID and the CRC field to the learning model.
Owner:FOUND OF SOONGSIL UNIV IND COOP

System and method for intrusion detection of malware traffic

A system-on-a-chip (SoC) and corresponding method implement an intrusion detection system. The SoC comprises a plurality of hardware engines. The SoC employs the plurality of hardware engines to implement the intrusion detection system. The intrusion detection system is capable of detecting malware traffic in (i) a non-encrypted traffic stream, (ii) an encrypted traffic stream that can be decrypted by the SoC, and (iii) an encrypted traffic stream that cannot be decrypted by the SoC. The intrusion detection system performs an action responsive to detecting the malware traffic. The action is performed toward preventing malicious activity otherwise caused by the malware traffic.
Owner:MARVELL ASIA PTE LTD

Platform End Intrusion Detection System Based on Multimodal Front Fusion

This invention relates to the field of image recognition technology and discloses a platform end intrusion detection system based on multimodal pre-fusion, comprising: an image acquisition module for acquiring visible light and infrared images; an effectiveness evaluation module for identifying feature failure areas using the changing gradient of the local information entropy map; a feature modulation module for suppressing visible light failure areas and achieving infrared feature gain compensation based on mask weights to generate a fused feature map; a spatial alignment module for calculating offset vectors using feature anchor points to correct coordinate alignment deviations; and a target detection module for identifying intrusion targets using multimodal features. This invention utilizes information entropy to guide feature scheduling logic, blocking the flow of invalid features caused by high-contrast light fields during the extraction stage, eliminating physical drift of the sensor optical axis, and ensuring the robustness of the system in maintaining target recognition in the platform end environment.
Owner:HUNAN YOULIANG ELECTRONIC TECH CO LTD

An online maintenance and overload control method for a vehicle-mounted multi-source IDS alarm correlation tracking graph

PendingCN122339939AArea networkIn vehicle
This invention discloses an online maintenance and overload control method for multi-source IDS alarm correlation tracing graphs in vehicles. Rule-based intrusion detection systems (IDS) are deployed in the vehicle host domain, vehicle Ethernet domain, and Controller Area Network (CAN) to generate alarms. At the vehicle gateway electronic control unit (ECU) side, multi-source alarms undergo event standardization, sliding time window buffering and waterline out-of-order tolerance, deduplication aggregation, and indexed candidate retrieval. Under the condition of satisfying alarm correlation judgment rules, a directed alarm tracing graph is incrementally constructed. By suppressing forks and overloads through in / out-degree limits, node / edge budgets, and priority pruning, combined with two-stage expiration recycling and tracking record solidification, stable alarm correlation and tracing are achieved under resource-constrained conditions. This method can be used for real-time tracing and offline forensic analysis on the vehicle side.
Owner:ZHEJIANG UNIV +1