Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

154 results about "Intrusion detection system" patented technology

An intrusion detection system (IDS) is a device or software application that monitors a network or systems for malicious activity or policy violations. Any malicious activity or violation is typically reported either to an administrator or collected centrally using a security information and event management (SIEM) system. A SIEM system combines outputs from multiple sources and uses alarm filtering techniques to distinguish malicious activity from false alarms.

Intrusion detection system applied to network security field

The invention relates to the technical field of network security, in particular to an intrusion detection system applied to the field of network security, which can accurately identify potential attack behaviors and reduce misjudgment rate by extracting session time sequence characteristics, separating load and behavior metadata and generating a behavior semantic primitive set. Discrete behavior semantic primitives are aggregated into intention propagation nodes, a multi-order attack dependency relationship is deduced, a multi-order attack intention propagation map is generated, the relationship between an attack path and the nodes can be clearly presented, and a key attack link can be positioned; according to graph topology vulnerability distribution, detection strategy template parameters are automatically generated and dynamically adjusted, different attack scenes can be adapted in real time, and the accuracy and flexibility of a detection strategy are improved; through real-time monitoring and marking of a key attack path, triggering of a cross-device cooperative defense mechanism, and generation of a region isolation instruction and a flow cleaning rule, transverse penetration and longitudinal deepening of an attack chain can be blocked, and attack diffusion is prevented.
Owner:CHINA YANGTZE POWER

Ensemble intrusion detection system for IoT platforms

PendingUS20250384131A1Platform integrity maintainanceData packDynaset
An automated method and system for modeling intrusion detection on an Internet of Things network preprocess received raw data packets. The raw data packets are converted to a packet capture file, which is converted to a comma separated value (CSV) file. The CSV file is filtered to create normal and abnormal CSV files. An attack is identified in the abnormal CSV file. Features associated with the attack are labeled and classified as an attack type. The abnormal and normal CSV files are merged. Redundant data is removed from the merged file, which is added to a concatenated file with other merged files. Features are extracted from the concatenated file and a machine language (ML) model is built using the extracted features. ML classifiers are determined for each merged file for the ML model to build an ensemble ML model. A dynamic ensemble of ML classifiers detects evolving attack types.
Owner:MORGAN STATE UNIVERSITY

Endogenous security OS construction method and device based on intelligent agent and control calculation

The invention belongs to the technical field of information security, and relates to an endogenous security OS construction method and device based on intelligent agent and control computing, and the method comprises the steps: constructing an underlying security base based on a hardware trusted root and a microkernel; based on the bottom-layer security base, defining and deploying a hierarchical multi-intelligent agent with a specific function; establishing a multi-agent communication and interaction protocol stack for the multi-intelligent agent; based on a multi-agent communication and interaction protocol stack, an intelligent collaborative scheduling algorithm oriented to multi-objective optimization is developed; an endogenous security mechanism integrating active defense and passive response; and carrying out full-life-cycle security situation assessment on the endogenous security operation system. Dynamic intrusion detection can be carried out, an intrusion detection system (IDS) based on machine learning is deployed, a normal behavior mode of an intelligent agent is learned, and abnormal tampering behaviors, DoS attacks, communication anomalies and the like are identified.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Network security alarm intelligent identification method and device

The invention discloses a network security alarm intelligent identification method and device, and relates to the technical field of network security alarm identification, and the method comprises the steps: carrying out the preprocessing of original data from network traffic, log files, user behavior records, a firewall and an intrusion detection system, and obtaining a multi-dimensional security event data set; node modeling and edge relation modeling are carried out based on a GNN and the multi-dimensional security event data set, and cross-system and cross-time-dimension security event association features are extracted to obtain a high-dimensional context sensing feature vector set; a time sequence anomaly detection model is constructed based on a high-dimensional context sensing feature vector set and a time sequence analysis technology, the high-dimensional context sensing feature vector set is input into the time sequence anomaly detection model, and weighting calculation is performed on each time step by extracting time dependent features and combining an Attention mechanism. Outputting an abnormal score vector corresponding to each time point; and constructing a behavior deviation function based on the multi-dimensional security event data in combination with deep learning data.
Owner:STATE GRID GANSU ELECTRIC POWER RESEARCH INSTITUTE

Automobile electronic intrusion determination method and device based on multi-source fusion data

An automotive electronic intrusion determination method, apparatus and device based on multi-source fusion data, and a storage medium, the method comprising: performing filtering processing and fusion processing on obtained CAN bus data, vehicle-mounted entertainment system data, Internet of Vehicles data and vehicle state data to generate multi-dimensional feature vector data; marking a corresponding early warning level for the multi-dimensional feature vector data to generate a multi-source fusion data set; training a preset neural network based on the multi-source fusion data set to generate an automobile electronic intrusion detection model; and based on the automobile electronic intrusion detection model, according to the obtained target CAN bus data, target vehicle-mounted entertainment system data, target Internet of Vehicles data and / or target vehicle state data, obtaining an early warning level output by the automobile electronic intrusion detection model so as to determine whether the current vehicle is invaded or not. The technical problems that the false alarm rate is high and complex attacks are difficult to recognize due to the fact that an automobile electronic intrusion detection system depends on a single data source are solved.
Owner:ZHIXIN CONTROL SYST CO LTD

Vehicle-mounted CAN bus intrusion detection system and method based on comparison self-supervised learning

The invention provides a vehicle-mounted CAN bus intrusion detection system and method based on comparison self-supervised learning. The system comprises a data preprocessing module which is used for receiving a CAN bus data stream in real time, performing feature extraction on each CAN message in the CAN bus data stream to generate a multi-dimensional feature vector, and stacking the feature vectors of W continuous messages by adopting a sliding window method to construct a two-dimensional time sequence sample; the intrusion detection model is used for reasoning the two-dimensional time sequence sample and outputting a classification label; the intrusion detection model is trained through a multi-task joint training method, and the training method fuses an unsupervised reconstruction task, a supervised classification task and a self-supervised contrast learning task; and the decision module is used for judging whether a CAN bus intrusion behavior exists or not according to the classification label output by the intrusion detection model. And the purposes of high efficiency, light weight of the model and capability of accurately identifying various attacks are achieved.
Owner:WUXI UNIV +2

Real-time intrusion detection system and method based on deep learning

The invention discloses a real-time intrusion detection system and method based on deep learning, and aims to solve the problem that when the existing deep learning intrusion detection technology processes high-dimensional network flow data, the information fidelity and the real-time processing efficiency are difficult to consider at the same time. According to the system and the method, a heterogeneous feature decoupling and fusion network architecture is adopted, high-dimensional feature vectors are losslessly decomposed into feature subsets of static state, time sequence, graph topology association and the like, deep learning is carried out by a parallel coding subsystem, cross-modal fusion attention self-adaptive aggregation is carried out, and finally classification judgment is realized. According to the scheme, on the basis of keeping the integrity of high-dimensional data, the detection capability and the real-time processing efficiency of unknown attacks are remarkably improved, and the self-adaptability and the robustness are improved.
Owner:CHENGDU EAGLE INFORMATION TECH CO LTD

Preservation of network integrity in changing network conditions triggered by data harvesting for retrospective decryption

ActiveUS20260058985A1Securing communicationNetwork conditionsNetwork integrity
A method for enhancing security of data, code, and / or network components by introducing a layer of integrity management that adapts to changing conditions within a network. The method may include use of a processor to perform intrusion analysis using an intrusion detection system and / or prevention system, behavioral analysis by accessing user logs to see if behavior is within a normal range, and / or geolocation analysis to see if the piece of data, section of code, and / or network component are within their usual surroundings. When there is a concern of a data breach, leak, and / or hack, the processor may initiate a response that detects other pieces of data, sections of code, and / or network components in proximity, initiates a self-destruct mechanism, triggers hardware to perform outside of operational specifications, and contains the spread of the data breach, leak, and / or hack through shutdown procedures, isolating affected systems, and / or alerting security personnel.
Owner:BANK OF AMERICA CORP

Self-adaptive scheduling industrial internet data acquisition control system and strategy

The invention discloses a self-adaptive scheduling industrial internet data acquisition control system and strategy, and relates to the technical field of industrial internet data acquisition and self-adaptive scheduling control, and the system comprises a data sensing layer, a deployment multi-type intelligent sensor group, an edge gateway and a hybrid communication module. The sensor supports multi-protocol adaptive access and dynamically switches sampling frequency, the edge gateway preprocesses original data, and the communication module guarantees stable transmission through wired and wireless hybrid networking; the self-adaptive scheduling layer comprises a task grading unit, a load monitoring unit and a dynamic scheduling unit; the edge calculation layer is used for processing tasks with high real-time performance; the cloud collaboration layer stores data and mines, analyzes and constructs an equipment model; the security protection layer realizes identity verification, data encryption and intrusion detection; and the system management layer manages the full life cycle of the equipment and divides user permissions. According to the system, the problem of traditional industrial internet data acquisition scheduling pain points is solved, and the overall operation efficiency and safety of the system are effectively improved.
Owner:LUAN YILI INNOVATION TECH CO LTD

Lightweight Internet of Vehicles intrusion detection system and method based on parallel CNN-Mama fusion network

The invention discloses a lightweight Internet of Vehicles intrusion detection system and method based on a parallel CNN-Mama fusion network, and the system comprises a data receiving module, a data preprocessing module, a pseudo-color image construction module which is used for mapping network flow data into a three-channel pseudo-color image and carrying out the scaling of the three-channel pseudo-color image, and a data processing module which is used for processing the three-channel pseudo-color image. The parallel double-branch network is composed of a CNN space branch and a Mama sequence branch, the fusion judgment module is used for carrying out average fusion on output of the parallel double-branch network and outputting a final detection category, the CNN space branch is used for extracting a local texture pattern and cross-feature coupling relation, and the Mama sequence branch is used for extracting long-distance dependency features; when the system is oriented to CICIDS2018 class 11 fine-grained multi-classification tasks, under the conditions that classes are extremely unbalanced and minority classes of samples are scarce, stable distinguishing of normal traffic and multiple attack types can still be achieved, and good engineering application value is achieved.
Owner:CHANGCHUN UNIV

Network protection

A computer-implemented method of protecting a network is provided. The method receives security alert data from one or more intrusion detection systems. The security alert data comprises a plurality of security alerts relating to the network. The method generates a plurality of similarity matrices from the security alert data. Each similarity matrix is generated using a different respective similarity function and indicates a respective similarity between each of the security alerts according to that similarity function. The method generates one or more attack graphs from the plurality of similarity matrices. Each attack graph represents a respective set of security alerts, wherein a similarity between each of the security alerts in the set, according to at least one of the similarity matrices, is above a predefined threshold. The method causes one or more predetermined actions to be taken with respect to the network to mitigate a respective attack represented by each of the attack graphs.
Owner:BRITISH TELECOM PLC

A Lightweight Vehicle Network Intrusion Detection System and Method Based on Parallel CNN-Mamba Fusion Network

This invention discloses a lightweight vehicle network intrusion detection system and method based on a parallel CNN-Mamba fusion network. The system includes a data receiving module, a data preprocessing module, a pseudo-color image construction module for mapping network traffic data into a three-channel pseudo-color image and scaling it, and a parallel dual-branch network composed of a CNN spatial branch and a Mamba sequence branch for averaging and fusing the outputs of the parallel dual-branch network to output the final detection category. The CNN spatial branch is used to extract local texture patterns and cross-feature coupling relationships, and the Mamba sequence branch is used to extract long-distance dependent features. When facing the CICIDS2018 11-class fine-grained multi-class classification task, the system can still stably distinguish between normal traffic and various attack types under the conditions of extremely imbalanced classes and scarce minority class samples, and has good engineering application value.
Owner:CHANGCHUN UNIV

Intrusion detection system

This invention provides an intrusion detection system that prevents the system from mistakenly identifying the entry of workers or other personnel into restricted areas as an intrusion. [Solution] The intrusion detection system 1 determines that an intrusion into the restricted area R has occurred when a human Z is detected within the restricted area R. However, if multiple human Zs are detected within the restricted area R, and the colors of the same body part detected for each of the multiple human Zs fall within a predetermined color range, then it is not determined that an intrusion into the restricted area R has occurred.
Owner:ASILLA INC

Trans-vehicle CAN bus intrusion detection method capable of transferable codebook remapping

The invention discloses a transferable codebook remapping cross-vehicle type CAN bus intrusion detection method, which belongs to the technical field of intrusion detection, and comprises the following steps: obtaining source vehicle type characteristics from a CAN message of a source vehicle type, learning a codebook, and quantifying the source vehicle type characteristics and the codebook into a source vehicle type symbol sequence and a source vehicle type histogram with a fixed length; inputting into a classifier in a discrete space for training; and collecting a target vehicle model sample from a target vehicle model, establishing a remapping table from a target code word to a source code word in combination with the feature similarity of the target vehicle model and the source vehicle model and a co-occurrence mode when the code word is used, aligning a symbol of a histogram of the target vehicle model to a symbol space of the source vehicle model, and detecting the target vehicle model by using a trained classifier. According to the invention, a lightweight reusable representation and remapping mechanism is provided for cross-vehicle intrusion detection, the accuracy, stability and interpretability of attack recognition are improved, and the application range of a vehicle intrusion detection system under the conditions of multiple vehicle types and small samples is expanded.
Owner:HANGZHOU UNIV OF ELECTRONIC SCI & TECH PINGHU DIGITAL TECH INNOVATION RES INST CO LTD +1

Managing and deploying custom intrusion detection system signature policies

Methods and systems for deploying intrusion detection system (IDS) policies to IDS programs are disclosed. Each IDS instance can monitor a data feed (e.g., comprising computer network traffic) in accordance with a set of “signatures” or “rules” associated with its policy, and can issue alerts if any elements of that network traffic match those signatures or rules. An intrusion signature management module can receive IDS signatures from one or more signature sources and store those signatures in a filesystem. The intrusion signature management module can produce rule files based on these IDS signatures, e.g., containing subsets of the received IDS signatures. These rule files can be provided to a version control server, and can later be accessed by an orchestration module. The orchestration module can deploy these rule files to their respective IDS programs, enabling those IDS programs to monitor their respective data feeds in accordance with the rule files.
Owner:VISA INTERNATIONAL SERVICE ASSOCIATION

Intrusion detection system using CRC in vehicle network and method thereof

An intrusion detection method performed by an intrusion detection system using CRC includes receiving in-vehicle CAN data in units of frame, generating first feature information by extracting a CAN ID from the in-vehicle CAN data in units of frame and performing zero padding, generating second feature information by extracting a CRC field from the in-vehicle CAN data in units of frame and performing the zero padding, training a learning model by setting the first feature information and the second feature information as input data and labeling, as output data, whether the CAN data is attack data or normal data, and detecting whether the CAN data is normal data or attack data by extracting a CAN ID and a CRC field from the received in-vehicle CAN data when training of the learning model is completed and inputting the CAN ID and the CRC field to the learning model.
Owner:FOUND OF SOONGSIL UNIV IND COOP

System and method for intrusion detection of malware traffic

A system-on-a-chip (SoC) and corresponding method implement an intrusion detection system. The SoC comprises a plurality of hardware engines. The SoC employs the plurality of hardware engines to implement the intrusion detection system. The intrusion detection system is capable of detecting malware traffic in (i) a non-encrypted traffic stream, (ii) an encrypted traffic stream that can be decrypted by the SoC, and (iii) an encrypted traffic stream that cannot be decrypted by the SoC. The intrusion detection system performs an action responsive to detecting the malware traffic. The action is performed toward preventing malicious activity otherwise caused by the malware traffic.
Owner:MARVELL ASIA PTE LTD

Platform End Intrusion Detection System Based on Multimodal Front Fusion

This invention relates to the field of image recognition technology and discloses a platform end intrusion detection system based on multimodal pre-fusion, comprising: an image acquisition module for acquiring visible light and infrared images; an effectiveness evaluation module for identifying feature failure areas using the changing gradient of the local information entropy map; a feature modulation module for suppressing visible light failure areas and achieving infrared feature gain compensation based on mask weights to generate a fused feature map; a spatial alignment module for calculating offset vectors using feature anchor points to correct coordinate alignment deviations; and a target detection module for identifying intrusion targets using multimodal features. This invention utilizes information entropy to guide feature scheduling logic, blocking the flow of invalid features caused by high-contrast light fields during the extraction stage, eliminating physical drift of the sensor optical axis, and ensuring the robustness of the system in maintaining target recognition in the platform end environment.
Owner:HUNAN YOULIANG ELECTRONIC TECH CO LTD

An online maintenance and overload control method for a vehicle-mounted multi-source IDS alarm correlation tracking graph

PendingCN122339939AArea networkIn vehicle
This invention discloses an online maintenance and overload control method for multi-source IDS alarm correlation tracing graphs in vehicles. Rule-based intrusion detection systems (IDS) are deployed in the vehicle host domain, vehicle Ethernet domain, and Controller Area Network (CAN) to generate alarms. At the vehicle gateway electronic control unit (ECU) side, multi-source alarms undergo event standardization, sliding time window buffering and waterline out-of-order tolerance, deduplication aggregation, and indexed candidate retrieval. Under the condition of satisfying alarm correlation judgment rules, a directed alarm tracing graph is incrementally constructed. By suppressing forks and overloads through in / out-degree limits, node / edge budgets, and priority pruning, combined with two-stage expiration recycling and tracking record solidification, stable alarm correlation and tracing are achieved under resource-constrained conditions. This method can be used for real-time tracing and offline forensic analysis on the vehicle side.
Owner:ZHEJIANG UNIV +1

A network security intrusion detection system and method based on a fusion graph neural network

The application discloses a network security intrusion detection system and method based on a fusion graph neural network, collects multi-source traffic data in the network operation process, constructs an induced topology graph by using a graph convolution modeling technology, and reveals deep correlation between network nodes; a multi-layer graph propagation and resonance enhancement technology is used to identify a hidden attack mode, a high-quality node embedding representation is generated through a graph attention mechanism and abnormal resonance amplification; a deep graph learning and graph pooling technology is combined to extract an attack behavior graph, an adaptive protection strategy is generated through graph inversion mapping and dynamic topology transformation; a multi-graph layer detection rule decomposition and graph optimization sorting technology is used to construct an interleaved detection sequence, an adaptive response signal is generated through active defense prediction and time difference bottleneck analysis, intelligent detection, accurate analysis and adaptive protection of network intrusion behavior are realized, and the intelligent level and protection effect of network security protection are improved.
Owner:CHANGCHUN INST OF TECH

Intrusion detection system and method based on hybrid neural network CNN-DNN

The application discloses an intrusion detection system and method based on a hybrid neural network CNN-DNN. The method specifically comprises the following steps: acquiring network traffic data with labels; converting character, text and other information in the network traffic data into numbers and performing a normalization operation; finally, reducing the dimension of the network traffic data by using a combined autoencoder; and constructing a hybrid neural network CNN-DNN. The application adopts the CNN-DNN hybrid neural network to analyze data, has high accuracy, adopts the combined autoencoder, can perform dimension reduction processing on input data of different dimensions, can flexibly highlight key features or feature combinations, and improves the calculation efficiency.
Owner:HANGZHOU DIANZI UNIV

Railway perimeter intrusion detection system and method based on multi-modal fusion

The invention provides a railway perimeter intrusion detection system and method based on multi-modal fusion. Comprising a front-end multi-mode detection module used for acquiring a vibration optical fiber detection signal, a video image signal and a radar detection signal; the edge computing terminal comprises a visual analysis unit which is used for detecting a long-distance small target and a short-distance target by using a detection head formed by an additional detection branch and a high-level detection branch arranged on a shallow feature map of the target detection network; the equipment state monitoring unit is used for generating equipment state data; the multi-modal fusion unit is used for generating perimeter intrusion event data and equipment abnormal event data; and the communication unit is connected with the multi-mode fusion unit and is used for receiving the perimeter intrusion event data and the equipment abnormal event data and packaging the data to generate an alarm message. According to the method and the device, the remote small target detection precision can be improved, the multi-modal fusion robustness under the abnormal condition of the equipment is improved, and the accuracy of determining and reporting the perimeter intrusion and the equipment abnormality is improved.
Owner:BEIJING HOLLYSYS

Hydropower station perimeter intrusion detection system and method based on Leiyu fusion

The hydropower station perimeter intrusion detection system comprises a radar monitoring module, a video monitoring module, a data processing module, a communication module, a control module, a power supply module, an early warning module, a data storage module and a compatible integration module. The radar monitoring module adopts laser radar equipment, and targets such as intruded foreign personnel in the surrounding environment are obtained by transmitting radar waves to the surrounding environment of the hydropower station and receiving and reflecting the radar waves. The accuracy and reliability of the hydropower station perimeter intrusion detection system are improved by adopting the Leiyu fusion technology and combining various technical means, so that the perimeter safety of the hydropower station is guaranteed. Meanwhile, the system has the advantages of real-time performance and reliability, the system can be compatibly integrated to a hydropower station electronic precaution system platform, new technical means and support are provided for hydropower station safety management, and the system has great significance in improving the safety level and accuracy of a hydropower station perimeter intrusion detection system.
Owner:POWERCHINA HUADONG ENG CORP LTD

Bio-neural navigation and intelligent intrusion detection for UAV systems

This invention presents a bio-neural navigation and intelligent intrusion detection system for UAVs, inspired by the head direction (HD) system in fruit flies. The navigation system uses a neural network-based architecture to process visual inputs and maintain orientation with a ring attractor network, enabling stable, autonomous flight in complex, GPS-denied environments. The multi-modal intrusion detection module integrates visual, radar, and acoustic sensor data to detect, classify, and respond to intrusions or obstacles in real-time. Combining supervised and unsupervised machine learning, it performs threat assessments and initiates adaptive responses like evasive maneuvers and dynamic re-routing. The integration of bio-neural navigation and intrusion detection ensures secure, autonomous UAV operations with enhanced situational awareness and threat management. This system is ideal for autonomous surveillance, urban air traffic management, and military reconnaissance, where adaptive navigation is critical.
Owner:CHANDRA SHUBHAM

Security support system

Provided is a security support system capable of setting a detection rule or setting a basic operation of each intrusion detection system, provided in a target system having a plurality of devices, using a small amount of manpower. The security support system inputs information about a plurality of devices of a target system, information about network topology, specification information about each piece of communication data, information about each piece of past communication data, information about each intrusion detection system, and log information about a detected attack or abnormality into a trained artificial intelligence, and causes the artificial intelligence to generate one or both of a recommended setting of a detection rule of each intrusion detection system and a recommended setting of a basic operation of each intrusion detection system.
Owner:MITSUBISHI ELECTRIC MOBILITY CORP

A gan adversarial sample generation method based on a fusion attention mechanism

The application discloses a GAN adversarial sample generation method based on a fusion attention mechanism and belongs to the cross technical field of network security and deep learning. The method comprises the following steps: acquiring network flow sample data, and performing image reconstruction and standardization processing on the input network flow data; constructing a GAN basic model containing an attention mechanism and pre-training the GAN basic model; optimizing core hyperparameters based on the pre-training result, and determining an optimal perturbation size; selecting the pre-trained model for integrated recombination, constructing an integrated GAN model, and completing joint training; generating adversarial samples by using the integrated GAN model, performing performance evaluation on the adversarial samples by using a target intrusion detection system; and outputting optimal adversarial samples that pass the evaluation and corresponding generation strategies. The application can improve the effectiveness and applicability of adversarial sample generation, provide a technical reference for enhancing the robustness of a target IDS, and support network security defense optimization of specific scenes such as EV charging infrastructure.
Owner:NANJING UNIV OF SCI & TECH

Space vehicle intrusion detection system (IDS)

Systems, devices, methods, and computer-readable media for space vehicle security are provided. A space vehicle can include a navigational controller configured to determine a mode of the space vehicle, a power supply configured to provide power to components of the space vehicle, a transceiver configured to determine whether a communications channel to a ground station is open, and an intrusion detection monitor configured to monitor for non-nominal outputs from components of the space vehicle, the components that are monitored are variable based on a power level of the power supply, a connectivity state of the transceiver, and the mode.
Owner:RAYTHEON CO

A dynamic security defense method and system based on thermal migration and deep learning

ActiveCN116318779BAttackHoneypot
The application discloses a kind of dynamic security defense method and system based on thermal migration and deep learning, by preliminary discrimination of traffic using intrusion detection system, again using the malicious traffic detection module based on deep learning review and determine as malicious traffic, SDN controller forwards traffic to low interaction honeypot, when attack depth reaches critical point, the copy of normal host of timed snapshot is activated as high interaction honeypot by honeypot management system, then using redirection forwarding engine TCP_REPAIR agent switches connection to high interaction honeypot.The application relates to the field of network defense technology, uses the malicious traffic detection technology based on deep learning, accurately shunts encrypted or non-encrypted normal and malicious traffic, makes up the defect that traditional defense system can only detect non-encrypted traffic, simultaneously using TCP thermal migration technology, optimizes the shortcomings of long time consumption and non-concealed switching in traditional TCP connection switching process, effectively improves the dynamic defense capability of system and utilization rate and decoy capability of honeypot cluster.
Owner:GUILIN UNIV OF ELECTRONIC TECH

Intrusion detection system of enterprise data information management platform

The invention discloses an intrusion detection system of an enterprise data information management platform, which relates to the technical field of data processing, and comprises an acquisition module, an analysis module and a decision module: the acquisition module is used for acquiring basic data and establishing a first defense line according to the basic data; the analysis module is used for acquiring abnormal data according to the first defense line, entering a second defense line and acquiring the abnormal data according to the second defense line; and the decision module is used for matching the abnormal data with the vulnerability data, if matching succeeds, repairing the abnormal data and the vulnerability data, and if matching fails, updating the vulnerability data. According to the method, a large number of normal requests are filtered out through the first defense line, only suspicious or abnormal data can enter the second defense line which consumes more resources for deep analysis, the hierarchical processing mechanism reasonably distributes computing resources, the performance bottleneck caused by one-step complex analysis is avoided, and the overall processing efficiency of the system is improved.
Owner:ZHICHENG TECH CO LTD