Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

23 results about "Intrusion prevention system" patented technology

Intrusion prevention systems, also known as intrusion detection and prevention systems, are network security appliances that monitor network and/or system activities for malicious activity. The main functions of intrusion prevention systems are to identify malicious activity, log information about this activity, attempt to block/stop it, and report it. Intrusion prevention systems are considered extensions of intrusion detection systems because they both monitor network traffic and/or system activities for malicious activity. The main differences are, unlike intrusion detection systems, intrusion prevention systems are placed in-line and are able to actively prevent/block intrusions that are detected. More specifically, IPS can take such actions as sending an alarm, dropping the malicious packets, resetting the connection and/or blocking the traffic from the offending IP address. An IPS can also correct Cyclic Redundancy Check errors, unfragment packet streams, prevent TCP sequencing issues, and clean up unwanted transport and network layer options.

Decentralized robot cluster anti-intrusion system and method

The invention discloses a decentralized robot cluster anti-intrusion system and method, and the method is characterized in that the decentralized robot cluster anti-intrusion method comprises the following steps: a plurality of robot entities and sensing equipment jointly form a decentralized network without a central server, all the devices in the network record a unified state log together and are used for updating state information of all the robots and the devices in the network in real time; before communication between robot entities is carried out, one-time identity verification is carried out through a short-distance physical channel, and a temporary session key is generated; when any one robot entity needs to declare or update the own state, verifying the authenticity of the physical state declared by the robot entity by executing a state proving protocol; according to the method, a decentralized directed acyclic graph network architecture is adopted, all robot entities maintain state logs together, and the single-point fault risk of a traditional centralized server is thoroughly eliminated.
Owner:SUZHOU COUPLING INTELLIGENT EQUIPMENT CO LTD

Network security data analysis method and system based on large model, and medium

The invention relates to the technical field of network security, in particular to a network security data analysis method and system based on a large model and a medium. According to the technical scheme, the network security data analysis method based on the large model comprises the following steps: acquiring a multi-source heterogeneous log in real time from a firewall, an intrusion detection system or an intrusion prevention system, a Web application firewall, a server operating system and a service application through a distributed acquisition agent; performing data cleaning on the original log: removing repeated entries, filling missing fields, unifying a timestamp format, and extracting key structured fields including a source IP address, a target IP address, an operation type and a user ID; and performing deep semantic analysis on the cleaned log by using a pre-training large model based on a Transform architecture, and generating vectorized feature representation fused with context semantics. The semantic understanding accuracy of security terminologies is remarkably improved, and the misjudgment defect caused by domain knowledge deficiency of a traditional model is thoroughly overcome.
Owner:STATE GRID HEBEI ELECTRIC POWER CO LTD +1

A rule-matching-based intrusion prevention system adaptive protection method and device

ActiveCN115987588BSecuring communicationHigh level techniquesOriginal dataIntrusion prevention system
The application relates to a rule-matching-based intrusion prevention system adaptive protection method and device. Three table items, a blacklist table, a whitelist table and a shunting table, are embedded in the data processing flow of a rule-matching-based NIDS system, and the three table items are provided with strategies for addition and deletion, so that the system can discard and release some high-concurrent-connection-causing traffic in advance in the early stage of traffic processing based on the original data processing flow, relieve the processing pressure of the system, and effectively solve the system abnormality problem caused by high-concurrent-connection. Compared with the prior art, the application has the remarkable advantages that the system abnormality problem caused by high-concurrent-connection can be effectively solved without affecting the original flow.
Owner:JIANGSU FUTURE NETWORKS INNOVATION

Cloud platform security network architecture

The invention belongs to the technical field of network security, and particularly relates to a cloud platform security network architecture which comprises an edge protection layer, a flow scheduling layer, a dynamic isolation layer, an encryption storage layer and a security control center. The edge protection layer realizes traffic abnormity identification through intelligent firewall group dynamic strategy cooperation and a behavior perception intrusion prevention system; the traffic scheduling layer drives load balancing by using a transfer learning algorithm fused with spatio-temporal characteristics; the dynamic isolation layer generates an access control rule based on the SDN micro-segmentation firewall according to the topology change; the encryption storage layer optimizes SM9 encryption through a regional key management cluster; and the safety management and control center realizes global risk management and control based on situation awareness and hierarchical response. According to the invention, the problems of insufficient cross-domain dynamic protection, contradiction between encryption efficiency and security and the like in a traditional scheme are solved, a full-chain collaborative protection system from traffic access to security management and control is formed, and the security, continuity and intelligent management and control level of cross-domain services of a cloud platform are improved.
Owner:JIANGXI DIGITAL NETWORK INFORMATION SECURITY TECH CO LTD

Intrusion prevention system

PendingUS20260052159A1Security arrangementSecuring communicationComputer networkIntrusion prevention system
An intrusion prevention system, computer-implemented method, computer system and computer program for protecting a network are provided. The system comprises one or more intrusion detection systems. The system further comprises a packet analyser for routing packets within the network that are received from another work. The packet analyser is configured to: receive a packet destined for a computer system within the network; extract one or more features relating to the packet; use a classification model to determine whether the packet is malicious based on the extracted features; prevent delivery of the packet to the computer system in response to determining that the packet is malicious; and deliver the packet to at least one of the intrusion detection systems in the absence of a determination that the packet is malicious. The one or more intrusion detection systems are configured to provide a notification to the packet analyser of any packets that they determine to be malicious. The packet analyser is further configured to train the classification model based on the notification from the one or more intrusion detection systems.
Owner:BRITISH TELECOM PLC

Network intrusion path modeling method and system based on artificial intelligence

The invention belongs to the field of network security monitoring, and particularly relates to a network intrusion path modeling method and system based on artificial intelligence, and the method comprises bait flow isolation, intrusion prevention and encryption prevention. According to the scheme, a lightweight path agent mechanism is adopted, a prediction path is constructed, path agent nodes are reused, key paths instead of nodes of the whole network are selectively monitored, memory and calculation overhead are remarkably reduced, temporary fluctuation and real attacks are effectively distinguished in combination with an exponential smoothing prediction and voting mechanism, malicious node recognition precision is improved, and malicious node recognition efficiency is improved. High-precision intrusion detection and self-adaptive fault tolerance in a resource-constrained environment are realized; a high-frequency rule priority matching mechanism is introduced, a linkage mechanism of a firewall, an intrusion detection system and an intrusion prevention system is constructed, invalid traffic is intercepted, attacks are traced, an authorized node safely obtains a secret key based on a standardized API interface, the protection efficiency is remarkably improved, and the data transmission safety and the secret key management convenience are enhanced.
Owner:徐州恒远高新技术有限公司

A deep learning-based unmanned aerial vehicle intrusion prevention system

This invention discloses a deep learning-based drone intrusion prevention system, comprising the following modules: a data acquisition module for acquiring and preprocessing real-time monitoring data; a target detection and localization module for identifying and localizing drone targets using an improved RTMDet target detection algorithm; a drone behavior prediction module for time-series modeling using the Mamba model; an intrusion behavior determination module for determining whether intrusion criteria are met using preset rules; a multimodal data fusion module for fusing data from different sensors; a threat assessment module for threat assessment using an improved DETR model; a countermeasure selection and execution module for selecting and executing matching countermeasures based on threat levels; and a feedback and monitoring module for monitoring the effectiveness of countermeasures and adjusting strategies in real time. This invention combines deep learning models and multi-sensor data fusion to effectively improve the accuracy and robustness of the drone intrusion prevention system.
Owner:GUANGDONG POLYTECHNIC OF IND & COMMERCE

Application programming interface (API) security

Systems and methods for enhancing API security by identifying anomalous activities in a cloud environment are provided. In one example, the lack of awareness of an external API with respect to how calls to the external API may affect a cluster of a container orchestration platform is addressed. For instance, the views of the external and internal APIs may be combined to achieve better API security by correlating external API calls with undesirable behavior or other anomalies arising in the internal API. Responsive to identifying such undesirable behavior, information (e.g., a host, a source IP, a user, a specific payload) associated with the offending external API call may be added to a network security feature (e.g., a deny list, an IPS, or a WAF) utilized by the external API to facilitate performance of enhanced filtering of subsequent external API calls by the external API on behalf of the internal API.
Owner:NETAPP INC

Host compromise detection method, apparatus, and device

ActiveCN115695031BSecuring communicationFeature extractionIntrusion prevention system
The embodiment of the present application relates to the technical field of computer network, and discloses a host compromise detection method, device and equipment, the method is applied to a firewall, comprising: obtaining the service traffic of a to-be-detected host; performing feature extraction on the service traffic of the to-be-detected host to obtain feature information of the service traffic of the to-be-detected host; matching the feature information with a compromise feature library, and in the case that the feature information matches the compromise feature library, determining that the to-be-detected host is a compromised host, wherein the compromise feature library comprises an intrusion prevention system (IPS) feature library and / or a virus feature library. The technical scheme of the present application can improve the detection accuracy of the compromised host.
Owner:BEIJING ANBOTONG TECH CO LTD

Multilayer deception defense system for cyber threat detection and response

PCT designated stageWO2026049103A1Securing communicationReal systemsEngineering
Disclosed is a multilayer deception defense system for cyber threat detection and response. The disclosed multilayer deception defense system according to an embodiment comprises: a real network; a deception network corresponding to the real network; and a monitoring and response system for monitoring and responding to a cyber attack on one of the real network or the deception network. The real network includes a firewall, an intrusion prevention system, an intrusion detection system, and a real system. The real system includes a deception token, a honey credential, an application layer, an application log, a database, and a web server. The deception network includes a honey pot, an intrusion prevention system, an intrusion detection system, and a honey pot system. The honey pot system includes a deception token, a honey credential, an application layer, an application log, a database, and a web server.
Owner:COONTEC CO LTD

A hierarchical adaptive network intrusion prevention system and method for resource-constrained edge computing scenarios

This invention discloses a layered adaptive network intrusion prevention system and method for resource-constrained edge computing scenarios, comprising: an edge rapid perception layer that collects multimodal data, quickly screens it, and generates structured natural language descriptions; an edge intelligent judgment layer that receives the structured natural language descriptions, performs semantic reasoning through a dynamically fine-tuned large-scale language model, and outputs threat judgment results; a fog-layer regional collaborative aggregation layer that acquires de-identified information generated from the threat judgment results, performs privacy-preserving aggregation and correlation analysis, and outputs regional threat reports and high-value samples; and a cloud-based cognition and evolution layer that generates synthetic threat data based on high-value samples, performs quality control screening, fine-tunes the screened data to obtain new adapters, and distributes them to the edge intelligent judgment layer. This invention achieves adaptive detection, privacy protection, and continuous evolution in resource-constrained environments, improving the defense capability against unknown attacks.
Owner:GUANGDONG POLYTECHNIC NORMAL UNIV

Intrusion prevention system in a communication network and method and apparatus therefor

PendingCN122339720AOpen portEngineering
A method (500), apparatus (200), and system for preventing intrusion in a communication network are disclosed. The method (500) may include retrieving at least one host attribute and port number of an associated host for each of a set of open ports within the communication network (202). A destination host attribute in an Intrusion Prevention System (IPS) rule is matched against at least one host attribute of each of the set of open ports in the communication network (202). The IPS rule is adapted based on the matching result. Based on this adaptation, the IPS rule is selectively applied in the communication network (202).
Owner:CAMBIUM NETWORKS

Domestic gas turbine TCS network security protection method

The invention discloses a domestic gas turbine TCS network security protection method, which relates to the technical field of network security protection, and comprises the following steps: establishing an intrusion detection system and an intrusion prevention system, performing data auditing and abnormal behavior monitoring, performing access control and identity verification, and performing log analysis and centralized management. The security of the TCS network environment is ensured by constructing a defense mechanism of internal detection and external defense; through monitoring and auditing TCS network gas turbine flow data, an instruction message of a gas turbine control system is analyzed in real time, the validity of an instruction is judged in combination with a gas turbine operation condition, a control logic and a technological process, harm from an attack is evaluated, and a grading alarm instruction is triggered; by implementing a role-based access control strategy, the user permission is ensured to be matched with the responsibility, and meanwhile, a multi-factor identity verification mechanism is introduced to enhance the security of an account; through the log analysis system and the security information event management system, security events are collected, analyzed and reported, real-time analysis of the security events is realized, the network security of the domestic gas turbine TCS is effectively protected, and stable operation and data security of the whole system are ensured.
Owner:熊兴武

Intrusion Prevention System

An intrusion prevention system for protecting a network comprising one of more intrusion detection systems (IDS) and a packet analyser. The packet analyser receives a packet, 310, and extracts one or
Owner:BRITISH TELECOM PLC

Technology for phishing awareness and phishing detection

PendingUS20260154420A1Hardware monitoringDigital data authenticationSpear phishingData set
The present disclosure is directed to training email users to enhance awareness of attempted spear phishing by attackers observing user actions to build a model of user susceptibilities using a trained LLM. A service in an intrusion prevention system can receive from one or more accounts linked to an enterprise and provide a message, along with a prompt to the LLM, stimulating the generation of one or more variants of the received messages that exhibit similar content characteristics. The LLM can produce a set of variant messages encompassing these content characteristics, purposefully including one or more phishing traits identified during training with the prelabeled dataset. These variant messages are then transmitted to the relevant accounts to assess interactions with the set. Based on the interactions observed across the accounts, an interaction score is generated to evaluate the efficacy of the user's training to avoid phishing attempts within the enterprise environment.
Owner:CISCO TECHNOLOGY INC

Intrusion prevention device, installation device and intrusion prevention system

ActiveCN223624644UVisible signalling systemsBurglar alarmStructural engineeringIntrusion prevention system
The utility model relates to the field of on-site early warning technology, and provides an anti-intrusion device, an installation device and an anti-intrusion system, comprising a detection part and a support. The bracket comprises a first bracket part and a second bracket part, and the first bracket part is connected with the second bracket part; the detection part is connected with the first support part through a rotating part, the detection part at least comprises an infrared detection mechanism, and when the detection part rotates to a first angle relative to the support part through the rotating part, the infrared detection mechanism is used for detecting the first angle; the second bracket part can be connected with mounting equipment, and the mounting equipment comprises a retractable bracket or a conical roadblock. The detection part is rotatably connected with the first support part through the rotating piece, so that the infrared detection mechanism can rotate to the required direction for early warning; the system can be applied to most road construction sites, has wide applicability and portability, and has multiple early warning functions so as to assist constructors in performing on the road construction sites.
Owner:ZHEJIANG XINAN INTELLIGENT TECH CO LTD

A network security management method, device, equipment and machine readable storage medium

ActiveCN116318903BAttackIntrusion prevention system
This disclosure provides a network security management method, apparatus, device, and machine-readable storage medium. The method includes: obtaining attack signature IDs of attack features identified as false alarms based on an enabled false alarm prevention function; adding the attack signature IDs identified as false alarms to a false alarm prevention hash table; obtaining each attack signature ID associated with each attack behavior reported by the detection engine; matching the obtained attack signature IDs in the false alarm prevention hash table; and determining that the attack behavior associated with the successfully matched attack signature ID is a false alarm. Through the technical solution of this disclosure, for intrusion prevention systems that cannot promptly change or configure the signature database, a whitelist is established based on the attack signature IDs associated with attack behaviors determined to be false alarms. Subsequently, when an attack behavior associated with the same attack signature ID is detected again, it is directly considered a false alarm and the relevant packets are allowed to pass, thereby reducing the false alarm rate.
Owner:NEW H3C SECURITY TECH CO LTD

A network attack processing method, apparatus, device, medium and product

A network attack processing method, device, equipment, medium and product are disclosed. The method comprises: when a network attack event sent by an intrusion prevention system device is received, a target load balancing source address field is obtained, wherein the target load balancing source address field is stored in a device corresponding to the network attack event; an initial address set corresponding to the target load balancing source address field is determined; the initial address set is filtered based on a target whitelist to obtain an attack source address, wherein the target whitelist comprises: an application load device address, a whitelist stored in the intrusion prevention system device, and a whitelist stored in a security operation device, the whitelist stored in the intrusion prevention system device comprises: a translation address, and the whitelist stored in the security operation device comprises: an application system address running in the server and a content distribution network address.
Owner:AGRICULTURAL BANK OF CHINA

Terminal communication network intrusion prevention system based on WAPI

The invention discloses a terminal communication network intrusion prevention system based on WAPI (Wireless Local Area Network Authentication and Privacy Infrastructure). The terminal communication network intrusion prevention system comprises six units, namely a double-domain heterogeneous key negotiation interaction unit and a multi-modal feature vector construction unit. The method comprises the following steps: establishing an asymmetric key negotiation channel by fusing a WAPI triple authentication mechanism and an elliptic curve Diffie-Hellman key exchange protocol, and realizing security key interaction and session key generation; the multi-modal feature vector construction unit comprehensively extracts network flow features from a time domain, a frequency domain and a protocol semantic domain, and accurately identifies intrusion behaviors in combination with a dynamic threshold mechanism of the intrusion feature comparison unit; the elliptic curve encryption authentication processing unit guarantees data packet integrity and identity authentication by using an elliptic curve digital signature algorithm; and the decision control unit integrates authentication and comparison results to generate instructions, and the execution response unit completes defense operations such as network connection blocking and current limiting according to the instructions, so that efficient and reliable intrusion prevention capability is provided for a terminal communication network.
Owner:MAINTENANCE BRANCH OF STATE GRID HEBEI ELECTRIC POWER

Technology for phishing awareness and phishing detection

The present disclosure is directed to training email users to enhance awareness of attempted spear phishing by attackers observing user actions to build a model of user susceptibilities using a trained LLM. A service in an intrusion prevention system can receive from one or more accounts linked to an enterprise and provide a message, along with a prompt to the LLM, stimulating the generation of one or more variants of the received messages that exhibit similar content characteristics. The LLM can produce a set of variant messages encompassing these content characteristics, purposefully including one or more phishing traits identified during training with the prelabeled dataset. These variant messages are then transmitted to the relevant accounts to assess interactions with the set. Based on the interactions observed across the accounts, an interaction score is generated to evaluate the efficacy of the user's training to avoid phishing attempts within the enterprise environment.
Owner:CISCO TECHNOLOGY INC

Application programming interface (API) security

Systems and methods for enhancing API security by identifying anomalous activities in a cloud environment are provided. In one embodiment, the lack of awareness of an external API with respect to how calls to the external API may affect a cluster of a container orchestration platform is addressed. For instance, the views of the external and internal APIs may be combined to achieve better API security by correlating external API calls with undesirable behavior or other anomalies arising in the internal API. Responsive to identifying such undesirable behavior, information (e.g., a host, a source IP, a user, a specific payload) associated with the offending external API call may be added to a network security feature (e.g., a deny list, an IPS, or a WAF) utilized by the external API to facilitate performance of enhanced filtering of subsequent external API calls by the external API on behalf of the internal API.
Owner:NETAPP INC