Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

271 results about "Intrusion detection system" patented technology

An intrusion detection system (IDS) is a device or software application that monitors a network or systems for malicious activity or policy violations. Any malicious activity or violation is typically reported either to an administrator or collected centrally using a security information and event management (SIEM) system. A SIEM system combines outputs from multiple sources and uses alarm filtering techniques to distinguish malicious activity from false alarms.

Deep learning-based wireless intrusion detection

Systems, devices, and methods for wireless intrusion detection based on deep learning are provided. A network device collects legitimate network traffic over a time period and learns a first set of features that represents the legitimate network traffic. The network device generates synthetic network traffic based on the learned first set of features and trains a machine learning model based on the learned first set of features and the synthetic network traffic. Based on the training, the machine learning model learns a second set of features that differentiates the synthetic network traffic from the legitimate network traffic. The devices and methods precisely detect potential security threats, while reducing false positives, thereby ensuring a sensitive and accurate response to genuine anomalies. Further, the devices and methods improve accuracy of detection of potential security threats including known and new attacks in wireless networks, while adapting to evolving attack techniques and network dynamics.
Owner:CISCO TECHNOLOGY INC

Market supervision data exchange platform migration and security enhancement method and system based on credential environment

The invention discloses a market supervision data exchange platform migration and security enhancement method and system based on a credential environment, and relates to the technical field of network security. In the data migration process, the consistency and privacy protection of the data are ensured through Hash check and a multi-party security computing technology; a domestic commercial cryptographic algorithm and a quantum resistance encryption technology are introduced, so that the protection capability of the platform to existing security threats is effectively improved, and the resistance to future quantum computing threats is enhanced; an intrusion detection system and a virtual honeypot node are integrated, and a defense strategy is monitored and updated in real time in combination with a deep learning model, so that novel attack behaviors can be detected and coped with in real time; according to an intrusion detection alarm and a block chain audit result, a security policy and resource allocation are dynamically adjusted in combination with a machine learning technology, it is ensured that high-risk nodes are monitored in time, resource allocation is automatically optimized, and the resource utilization efficiency and security of the system are improved.
Owner:江苏省市场监督管理局数据中心

Network security intrusion detection system and method fused with graph neural network

The invention discloses a network security intrusion detection system and method fusing a graph neural network, and the method comprises the steps: collecting multi-source flow data in a network operation process, constructing an induction topological graph through employing a graph convolution modeling technology, and revealing a deep incidence relation between network nodes; a hidden attack mode is identified by adopting a multi-layer graph propagation and resonance enhancement technology, and high-quality node embedding representation is generated through a graph attention mechanism and abnormal resonance amplification; an attack behavior map is extracted by combining depth map learning and a map pooling technology, and a self-adaptive protection strategy is generated through map inversion mapping and dynamic topological transformation; an interlaced detection sequence is constructed by adopting a multi-layer detection rule decomposition and graph optimization sorting technology, and a self-adaptive response signal is generated through active defense prediction and time difference bottleneck analysis, so that intelligent detection, accurate analysis and self-adaptive protection of network intrusion behaviors are realized, and the intelligent level and protection effect of network security protection are improved.
Owner:CHANGCHUN INST OF TECH

A centralized computer network traffic monitoring and intrusion detection system for a computer network

A centralized network traffic monitoring and intrusion detection system (1) comprising a system log aggregation module (110) including a means for receiving (111), a means for decoding (112) the user's syslog, a means for comparing (113) the data from the means for decoding, and a means for indexing (114) the tagged data and storing the indexed data. The system (1) also comprises an analysis and alert module (120) including a means for fetching (121) the indexed data, a means for checking and correlating (122) the retrieved indexed data, a means for analysing (123) the checked and correlated data, a means for compiling (124) the analysed and prioritized data and generating a report, and a means for alerting (124). The system (1) further includes a Bad IP Feed module (130) including a means for generating (131) updated lists of bad IP addresses and hostnames and automatically updating a user's network devices.
Owner:E LOCK CORP

Intrusion detection system and method based on machine learning

The invention relates to the technical field of network security, in particular to an intrusion detection system and method based on machine learning, and the system comprises a dynamic feature selection module which dynamically generates a feature mask through a reinforcement learning strategy network, and selects an optimal feature subset in real time according to an action return function # imgabs0 #; the lightweight detection module adopts a depth separable convolution structure, implements mixed precision quantization and structured pruning, and takes dynamic ReLU as an activation function; the incremental learning engine is used for restraining the weight through dynamic regularization based on a Fisher information matrix on the basis of a local cache data online fine tuning model; and the edge-cloud collaboration module is used for performing homomorphic encryption and differential privacy processing on model parameter differences, and updating a global model through a robust federated aggregation algorithm. Based on lightweight edge deployment and real-time incremental learning, the calculation overhead is reduced, and the robustness is improved.
Owner:GUANGXI UNIVERSITY OF TECHNOLOGY

Intrusion detection system applied to network security field

The invention relates to the technical field of network security, in particular to an intrusion detection system applied to the field of network security, which can accurately identify potential attack behaviors and reduce misjudgment rate by extracting session time sequence characteristics, separating load and behavior metadata and generating a behavior semantic primitive set. Discrete behavior semantic primitives are aggregated into intention propagation nodes, a multi-order attack dependency relationship is deduced, a multi-order attack intention propagation map is generated, the relationship between an attack path and the nodes can be clearly presented, and a key attack link can be positioned; according to graph topology vulnerability distribution, detection strategy template parameters are automatically generated and dynamically adjusted, different attack scenes can be adapted in real time, and the accuracy and flexibility of a detection strategy are improved; through real-time monitoring and marking of a key attack path, triggering of a cross-device cooperative defense mechanism, and generation of a region isolation instruction and a flow cleaning rule, transverse penetration and longitudinal deepening of an attack chain can be blocked, and attack diffusion is prevented.
Owner:CHINA YANGTZE POWER

Embedded intrusion detection system for industrial controllers

An intrusion detection system can be embedded in an industrial controller to detect an attack on an industrial control system. The intrusion detection system can detect an attack by determining if there are anomalies related to the network traffic in the industrial control system and / or by determining if the devices (e.g., sensors and actuators) connected to the industrial controllers of the industrial control system are not operating within expected ranges. To assist in determining if the devices of the industrial control system are not operating properly, the industrial controllers can also be networked together in a peer-to-peer network that permits each industrial controller to share its state information with the other industrial controllers.
Owner:UNIVERSITY OF ALABAMA

Power grid intrusion detection system based on artificial intelligence

The invention relates to the technical field of data processing, and discloses an artificial intelligence-based power grid intrusion detection system, which comprises a three-dimensional data cube construction module, a three-dimensional data cube feature extraction module, a feature fusion module, an attack probability prediction module, an attack credibility evaluation module and an intrusion protection module, aligning timestamps among the communication flow, the equipment state and the node topological relation of the power grid to generate a three-dimensional data cube of the power grid; abnormal node propagation characteristics and a flow time sequence mode are extracted; fusing the abnormal node propagation features and the time features of the flow time sequence mode through a cross-channel attention mechanism to obtain a fused feature vector; inputting the fusion feature vector into a full connection layer to obtain an attack probability; when the attack probability exceeds a preset threshold value, starting a sandbox verification process, and generating an attack credibility score; and issuing a network isolation and channel switching instruction based on the attack credibility score. The accuracy of power grid intrusion detection can be improved.
Owner:GUIZHOU POWER GRID CO LTD

System and method for detecting intrusion into in-vehicle network

An embodiment intrusion detection system for detecting intrusions in an in-vehicle network includes a message queue module configured to store network messages collected from the in-vehicle network in a message queue, a memory configured to securely store a ruleset comprising a set of detection rules used in a plurality of detection techniques, a rule engine configured to apply the plurality of detection techniques to the collected network messages to detect security events and configured to determine a severity score and a reliability score for each detected security event, and an interface manager configured to transmit detection reports to a remote backend server in response to detection of the security events.
Owner:HYUNDAI MOTOR CO LTD +1

Regional intrusion detection system and method

The invention provides a region intrusion detection system and method, and the system comprises a video collection module which is used for collecting the current image data of a detection region in real time; the AI analysis module is used for performing primary screening on the human body area according to the image data, identifying preset key points of the human body area and generating a judgment result of the intrusion behavior according to the identified preset key points; the PLC control module is used for executing the sudden stop operation of the production equipment when the AI analysis module judges that the intrusion behavior occurs in the detection area; the management platform module is used for providing a visual configuration interface of a dynamic detection area, can accurately identify human body invasion behaviors of a dangerous operation area in a factory, greatly reduces the safety accident rate of the factory, can accurately identify human body invasion behaviors by identifying preset key points of a human body area, and improves the safety of the factory. False alarm and unnecessary shutdown operation are avoided, and the production efficiency is further improved.
Owner:SAILUN GRP CO LTD

New energy automobile in-vehicle network real-time intrusion detection system based on edge calculation

The invention provides a new energy automobile in-vehicle network real-time intrusion detection system based on edge computing, which relates to the field of new energy automobile network security and intrusion detection and comprises an in-vehicle edge computing node, a vehicle-mounted communication interface and a regional collaboration module. The in-vehicle edge computing node, the vehicle-mounted communication interface and the regional collaboration module form a distributed collaboration architecture to realize in-vehicle network real-time intrusion detection and dynamic defense, and the in-vehicle edge computing node is deployed in a vehicle electronic control unit and a gateway, collects and analyzes network traffic and sensor data, executes a local defense decision, and sends the local defense decision to the regional collaboration module. The system monitors the controller local area network flow, the electronic control unit state and the sensor signal of the in-vehicle network in real time through edge calculation, network abnormity and physical attack signs can be found in time, the safety risk caused by delay detection is effectively avoided, and the efficiency and timeliness of in-vehicle network monitoring are improved. The system adopts intelligent analysis methods such as a topological immune reconstruction algorithm and a photon trajectory aggregation algorithm.
Owner:CHONGQING YISHI INTELLIGENT TECHNOLOGY CO LTD

APT attack detection method based on log traceability graph

The invention discloses an APT attack detection method based on a log traceability graph, and belongs to the technical field of network security. In order to solve the problem of concealment of APT attacks at a system entity level in the prior art, the method mainly adopts the combination of a log traceability graph and a text sentiment analysis technology, and effectively enhances the predictive ability and mobility of an intrusion detection system by means of traceability graph construction, sentence representation, multi-task pre-training learning and the like. According to the invention, efficient and accurate detection of APT attacks at a system entity level can be realized, the precision and applicability of an intrusion detection system are improved, the method adapts to different system environments, and the identification capability of potential threats is enhanced.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

Ensemble intrusion detection system for IoT platforms

PendingUS20250384131A1Platform integrity maintainanceData packDynaset
An automated method and system for modeling intrusion detection on an Internet of Things network preprocess received raw data packets. The raw data packets are converted to a packet capture file, which is converted to a comma separated value (CSV) file. The CSV file is filtered to create normal and abnormal CSV files. An attack is identified in the abnormal CSV file. Features associated with the attack are labeled and classified as an attack type. The abnormal and normal CSV files are merged. Redundant data is removed from the merged file, which is added to a concatenated file with other merged files. Features are extracted from the concatenated file and a machine language (ML) model is built using the extracted features. ML classifiers are determined for each merged file for the ML model to build an ensemble ML model. A dynamic ensemble of ML classifiers detects evolving attack types.
Owner:MORGAN STATE UNIVERSITY

Endogenous security OS construction method and device based on intelligent agent and control calculation

The invention belongs to the technical field of information security, and relates to an endogenous security OS construction method and device based on intelligent agent and control computing, and the method comprises the steps: constructing an underlying security base based on a hardware trusted root and a microkernel; based on the bottom-layer security base, defining and deploying a hierarchical multi-intelligent agent with a specific function; establishing a multi-agent communication and interaction protocol stack for the multi-intelligent agent; based on a multi-agent communication and interaction protocol stack, an intelligent collaborative scheduling algorithm oriented to multi-objective optimization is developed; an endogenous security mechanism integrating active defense and passive response; and carrying out full-life-cycle security situation assessment on the endogenous security operation system. Dynamic intrusion detection can be carried out, an intrusion detection system (IDS) based on machine learning is deployed, a normal behavior mode of an intelligent agent is learned, and abnormal tampering behaviors, DoS attacks, communication anomalies and the like are identified.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Vehicle-mounted CAN bus intrusion detection system and method

The invention discloses a vehicle-mounted CAN bus intrusion detection system and method, and the system is obtained based on the training of an improved compression network model, and the improved compression network model comprises a convolution layer, a pooling layer, a plurality of dynamic feature extraction modules, a convolution mapping layer, a global average pooling layer, and a classification output layer. The dynamic feature extraction module comprises a compression layer and an expansion branch, the compression layer adopts 1 * 1 depth separable convolution to perform feature compression, the expansion branch adopts 1 * 1 and 3 * 3 depth separable convolution, and the channel feature expression ability is enhanced through feature splicing; and after splicing output, a channel attention module is accessed to optimize channel feature distribution and suppress redundant information, so that the feature extraction and classification discrimination capability of the network is improved. The system can detect abnormal traffic of a vehicle-mounted network, realizes high accuracy, low delay and efficient processing capability, adapts to a vehicle-mounted environment with limited resources, and solves the problems of high complexity, slow response and limited deployment of an existing intrusion detection system.
Owner:JIANGSU SAIZHI DIGITAL SECURITY TECHNOLOGY CO LTD

Network security alarm intelligent identification method and device

The invention discloses a network security alarm intelligent identification method and device, and relates to the technical field of network security alarm identification, and the method comprises the steps: carrying out the preprocessing of original data from network traffic, log files, user behavior records, a firewall and an intrusion detection system, and obtaining a multi-dimensional security event data set; node modeling and edge relation modeling are carried out based on a GNN and the multi-dimensional security event data set, and cross-system and cross-time-dimension security event association features are extracted to obtain a high-dimensional context sensing feature vector set; a time sequence anomaly detection model is constructed based on a high-dimensional context sensing feature vector set and a time sequence analysis technology, the high-dimensional context sensing feature vector set is input into the time sequence anomaly detection model, and weighting calculation is performed on each time step by extracting time dependent features and combining an Attention mechanism. Outputting an abnormal score vector corresponding to each time point; and constructing a behavior deviation function based on the multi-dimensional security event data in combination with deep learning data.
Owner:STATE GRID GANSU ELECTRIC POWER RESEARCH INSTITUTE

Automobile electronic intrusion determination method and device based on multi-source fusion data

An automotive electronic intrusion determination method, apparatus and device based on multi-source fusion data, and a storage medium, the method comprising: performing filtering processing and fusion processing on obtained CAN bus data, vehicle-mounted entertainment system data, Internet of Vehicles data and vehicle state data to generate multi-dimensional feature vector data; marking a corresponding early warning level for the multi-dimensional feature vector data to generate a multi-source fusion data set; training a preset neural network based on the multi-source fusion data set to generate an automobile electronic intrusion detection model; and based on the automobile electronic intrusion detection model, according to the obtained target CAN bus data, target vehicle-mounted entertainment system data, target Internet of Vehicles data and / or target vehicle state data, obtaining an early warning level output by the automobile electronic intrusion detection model so as to determine whether the current vehicle is invaded or not. The technical problems that the false alarm rate is high and complex attacks are difficult to recognize due to the fact that an automobile electronic intrusion detection system depends on a single data source are solved.
Owner:ZHIXIN CONTROL SYST CO LTD

Vehicle-mounted CAN bus intrusion detection system and method based on comparison self-supervised learning

The invention provides a vehicle-mounted CAN bus intrusion detection system and method based on comparison self-supervised learning. The system comprises a data preprocessing module which is used for receiving a CAN bus data stream in real time, performing feature extraction on each CAN message in the CAN bus data stream to generate a multi-dimensional feature vector, and stacking the feature vectors of W continuous messages by adopting a sliding window method to construct a two-dimensional time sequence sample; the intrusion detection model is used for reasoning the two-dimensional time sequence sample and outputting a classification label; the intrusion detection model is trained through a multi-task joint training method, and the training method fuses an unsupervised reconstruction task, a supervised classification task and a self-supervised contrast learning task; and the decision module is used for judging whether a CAN bus intrusion behavior exists or not according to the classification label output by the intrusion detection model. And the purposes of high efficiency, light weight of the model and capability of accurately identifying various attacks are achieved.
Owner:WUXI UNIV +2

Real-time intrusion detection system and method based on deep learning

The invention discloses a real-time intrusion detection system and method based on deep learning, and aims to solve the problem that when the existing deep learning intrusion detection technology processes high-dimensional network flow data, the information fidelity and the real-time processing efficiency are difficult to consider at the same time. According to the system and the method, a heterogeneous feature decoupling and fusion network architecture is adopted, high-dimensional feature vectors are losslessly decomposed into feature subsets of static state, time sequence, graph topology association and the like, deep learning is carried out by a parallel coding subsystem, cross-modal fusion attention self-adaptive aggregation is carried out, and finally classification judgment is realized. According to the scheme, on the basis of keeping the integrity of high-dimensional data, the detection capability and the real-time processing efficiency of unknown attacks are remarkably improved, and the self-adaptability and the robustness are improved.
Owner:CHENGDU EAGLE INFORMATION TECH CO LTD

Internet of Things intrusion detection system and method based on graph neural network

The invention relates to the technical field of network security, and discloses an Internet of Things intrusion detection system and method based on a graph neural network. According to the system and the method, original flow data can be effectively collected from a network through a data collection and preprocessing module, IP address randomization, feature normalization and target coding are carried out, it is ensured that generated data is suitable for graph structure modeling, a graph structure construction module converts preprocessed data into graph structure representation, and the graph structure representation is realized. A clear network topology is formed by utilizing feature initialization of nodes and edges, the graph coding and feature extraction module deeply extracts and updates the features of the nodes and the edges through an improved graph encoder, the feature representation capability of the model is enhanced by introducing a contrast loss function, the recognition precision of potential intrusion behaviors is improved, and the recognition efficiency of the potential intrusion behaviors is improved. And the model training and classification judgment module performs accurate classification on the network traffic by using the trained model, identifies and outputs an intrusion detection result, and improves the accuracy and efficiency of intrusion detection in the Internet of Things environment.
Owner:GUANGDONG UNIV OF TECH +1

Method and device for generating antagonistic malicious traffic

The invention relates to an adversarial malicious traffic generation method and device, and belongs to the technical field of network security. The method specifically comprises the following steps: generating a malicious traffic feature vector and a benign traffic feature vector, and adding noise into the malicious traffic feature vector; the malicious traffic features added with the noise are input into a generator, the pre-trained generator generates an antagonistic malicious traffic feature vector and carries out variation, and a varied malicious traffic feature vector is generated; inputting the varied malicious traffic feature vector and the varied benign traffic feature vector into an intrusion detection system NIDS, and inputting a prediction result of the NIDS into a discriminator; the discriminator classifies the prediction result of the NIDS and outputs a probability value, and the probability value is used as a generator to create a new award against variation malicious traffic characteristics; through adversarial training between the generator and the discriminator, the generator generates a malicious traffic feature vector that avoids adversarial of an intrusion detection system NIDS.
Owner:BEIJING INST OF TECH +1

A network security monitoring system to deal with APT attacks

The present invention belongs to the field of network attack detection, and specifically relates to a network security monitoring system for responding to APT attacks. The system comprises an industrial control network gateway security device, an industrial control network management system, and an industrial control network security operations center. The industrial control network gateway security device includes a behavioral data collection module for collecting network traffic and system activity data from various devices, including intrusion detection systems and flow probes, and providing the data to the industrial control network management system. The industrial control network management system includes a data preprocessing module, a subgraph generation module, a behavioral feature extraction module, and a model training and anomaly detection module. The module preprocesses raw data, generates traceability graphs and subgraphs, extracts behavioral features, and establishes a classification model for anomaly detection. The industrial control network security operations center includes a risk warning reporting module that visually reports detected risks to security operations personnel and generates detailed analysis reports.
Owner:TONGJI UNIV

Preservation of network integrity in changing network conditions triggered by data harvesting for retrospective decryption

ActiveUS20260058985A1Securing communicationNetwork conditionsNetwork integrity
A method for enhancing security of data, code, and / or network components by introducing a layer of integrity management that adapts to changing conditions within a network. The method may include use of a processor to perform intrusion analysis using an intrusion detection system and / or prevention system, behavioral analysis by accessing user logs to see if behavior is within a normal range, and / or geolocation analysis to see if the piece of data, section of code, and / or network component are within their usual surroundings. When there is a concern of a data breach, leak, and / or hack, the processor may initiate a response that detects other pieces of data, sections of code, and / or network components in proximity, initiates a self-destruct mechanism, triggers hardware to perform outside of operational specifications, and contains the spread of the data breach, leak, and / or hack through shutdown procedures, isolating affected systems, and / or alerting security personnel.
Owner:BANK OF AMERICA CORP

Self-adaptive scheduling industrial internet data acquisition control system and strategy

The invention discloses a self-adaptive scheduling industrial internet data acquisition control system and strategy, and relates to the technical field of industrial internet data acquisition and self-adaptive scheduling control, and the system comprises a data sensing layer, a deployment multi-type intelligent sensor group, an edge gateway and a hybrid communication module. The sensor supports multi-protocol adaptive access and dynamically switches sampling frequency, the edge gateway preprocesses original data, and the communication module guarantees stable transmission through wired and wireless hybrid networking; the self-adaptive scheduling layer comprises a task grading unit, a load monitoring unit and a dynamic scheduling unit; the edge calculation layer is used for processing tasks with high real-time performance; the cloud collaboration layer stores data and mines, analyzes and constructs an equipment model; the security protection layer realizes identity verification, data encryption and intrusion detection; and the system management layer manages the full life cycle of the equipment and divides user permissions. According to the system, the problem of traditional industrial internet data acquisition scheduling pain points is solved, and the overall operation efficiency and safety of the system are effectively improved.
Owner:LUAN YILI INNOVATION TECH CO LTD

Lightweight CAN bus intrusion detection method based on enhanced active learning

The invention discloses a lightweight CAN (Controller Area Network) bus intrusion detection method based on enhanced active learning, which optimizes an annotation strategy in a sample selection process through a label self-adaptive optimization mechanism, an enhanced learning-driven strategy adjustment capability and a resource-controllable dynamic reasoning architecture, can efficiently utilize annotation data, and improves the detection efficiency. The workload and cost of manual annotation are greatly reduced, the overall annotation requirement is reduced, the utilization efficiency of annotation resources is improved, a lightweight inference model set and an accurate inference model set are combined by designing a double-stage inference gating algorithm based on reinforcement learning, inference calculation can be dynamically adjusted according to actual needs, and the annotation efficiency is improved. And uncertain samples are transferred into a precise reasoning model set for further judgment, so that the use of overall computing resources is optimized, the computing burden of an intrusion detection system is reduced, meanwhile, the response speed is increased, the sustainable optimization capability of the model is enhanced, and the detection precision and the adaptive capability are improved.
Owner:ZHEJIANG UNIV +1

Deep learning-based wireless intrusion detection

Systems, devices, and methods for wireless intrusion detection based on deep learning are provided. A network device collects legitimate network traffic over a time period and learns a first set of features that represents the legitimate network traffic. The network device generates synthetic network traffic based on the learned first set of features and trains a machine learning model based on the learned first set of features and the synthetic network traffic. Based on the training, the machine learning model learns a second set of features that differentiates the synthetic network traffic from the legitimate network traffic. The devices and methods precisely detect potential security threats, while reducing false positives, thereby ensuring a sensitive and accurate response to genuine anomalies. Further, the devices and methods improve accuracy of detection of potential security threats including known and new attacks in wireless networks, while adapting to evolving attack techniques and network dynamics.
Owner:CISCO TECHNOLOGY INC

A vehicle-mounted CAN bus intrusion detection system and method

The present invention discloses an in-vehicle CAN bus intrusion detection system and method. The system is based on an improved compression network model trained on a convolutional layer, a pooling layer, multiple dynamic feature extraction modules, a convolutional mapping layer, a global average pooling layer, and a classification output layer. The dynamic feature extraction module includes a compression layer and an expansion branch. The compression layer uses 1×1 depthwise separable convolution for feature compression, while the expansion branch uses 1×1 and 3×3 depthwise separable convolutions. Feature concatenation enhances channel feature expression. The concatenated output is connected to a channel attention module to optimize channel feature distribution and suppress redundant information, thereby enhancing the network's feature extraction and classification capabilities. The system can detect abnormal traffic in the in-vehicle network with high accuracy, low latency, and efficient processing capabilities. It is adaptable to resource-constrained in-vehicle environments and addresses the high complexity, slow response, and limited deployment issues of existing intrusion detection systems.
Owner:JIANGSU SAIZHI DIGITAL SECURITY TECHNOLOGY CO LTD

System and method for ai-based intrusion behaviour analysis

A system for an automated real-time intrusion detection based on predictive analytics of intrusion-related data, including a processor of an intrusion detection (ID) node configured to host a machine learning (ML) module and connected to at least one captured data source entity node over a network and a memory on which are stored machine-readable instructions that when executed by the processor, cause the processor to: acquire intrusion-related captured data from the at least one captured data source entity node; parse the captured data to derive a plurality of key features; query a local intrusions' database to retrieve local historical intrusions'-related data associated with previous intrusion detection parameters based on the plurality of key features; generate at least one feature vector based on the plurality of key features and the local historical intrusions'-related data; and provide the at least one feature vector to the ML module for generating a predictive model configured to produce at least one intrusion detection parameter for generation of an intrusion detection verdict.
Owner:GOLDSTEIN STEVEN W

Network intrusion traffic detection method, system and device, and storage medium

The invention discloses a network intrusion traffic detection method, system and device, and a storage medium, which are applied to power grid traffic detection. According to the method, a mask-reconstruction-based pre-training strategy and an improved single center loss function are provided, a SupMAE strategy is adopted in the pre-training stage, network traffic is processed through an encoder, a decoder and a classification head, and reconstruction and classification losses are calculated to optimize a model; the improved stable single-center loss function enhances the detection capability and generalization performance of the model on unknown abnormal data. Parameters such as an optimizer and a learning rate are set in stages in the training process. Experimental results on different data sets are superior to those of an existing method, network intrusion flow can be effectively detected, detection precision and efficiency are improved, reliable guarantee is provided for network safety, and the method is suitable for intrusion detection systems of various network environments.
Owner:NARI TECH CO LTD +1

Network security intrusion detection method and system based on large model

The invention provides a network security intrusion detection method and system based on a large model, and relates to the technical field of network security, and the method comprises the steps: monitoring and obtaining a plurality of access behavior data sequences in a current time period, carrying out node difference comparison through employing an access behavior reference comparison table, and constructing a deviation node distribution sequence; performing node similarity comparison on the plurality of access behavior data sequences, performing same-frequency node identification, and constructing a same-frequency node distribution sequence; in combination with the large model, potential attack node distribution and potential attack probability distribution are obtained through prediction according to the deviation node distribution sequence and the same-frequency node distribution sequence, and a node detection strategy is made for detection. The objective of the invention is to solve the problems of low detection accuracy, response lag, easy missing report and the like of an intrusion detection system in a complex network environment due to the lack of effective identification of a cooperative behavior mode among a plurality of access nodes in a traditional detection method. And the accuracy, the real-time performance and the active defense capability of intrusion detection can be remarkably improved.
Owner:JIANGSU GUOBAO INFORMATION SYST EVALUATION CENT CO LTD