Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

2 results about "Intrusion response" patented technology

A federated learning driven low-orbit satellite network adaptive intrusion response control method

PendingCN122316787ADelayed responseEngineering
This invention relates to network information security, specifically to a federated learning-driven adaptive intrusion response control method for low-Earth orbit satellite networks. The method includes: if the risk of a selected defensive action exceeds a set threshold, the action is suspended, an intent vector is generated, and reported to the cluster head node. The current satellite node then selects an optimal action from a set of low-risk action candidates for execution. Upon receiving the intent vector, the cluster head node selects high-reputation nodes with reputation values ​​exceeding a set threshold to initiate consensus. Each high-reputation node evaluates the intent vector based on its local model and votes. If more than two-thirds of the high-reputation nodes reach consensus, the cluster head node sends permission to execute the suspended action to the generated intent vector and increases the satellite node's reputation. If consensus fails, the suspended action is not allowed, and the satellite node's reputation is decreased. This invention addresses key technical challenges such as difficulty in security policy convergence, misjudgment of single-point high-risk situations, and delayed response times.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

A method, system and application of vehicle-mounted Ethernet intrusion detection and defense based on a Transformer encoder

The application discloses a kind of vehicle Ethernet intrusion detection and defense method based on Transformer encoder, comprising the following steps: constructing vehicle Ethernet intrusion detection model, extracting sample data from the database containing normal communication message and / or attack type message pre-set, optimizing the training of the intrusion detection model;Real-time acquisition of real vehicle Ethernet message data, real-time inference is carried out to real data by constructing optimized intrusion detection model, whether the flow is abnormal is judged, and potential network attack or intrusion behavior is identified;According to the intrusion detection result, response unit carries out intrusion alarm and / or intrusion response.The method of the application realizes efficient sequence data processing capability, accurate anomaly detection capability and real-time response capability;At the same time, in order to maintain effective defense to new attack, the system updates the intrusion detection model periodically.The application also discloses a system for implementing the above method, which has a wide range of application scenarios.
Owner:EAST CHINA NORMAL UNIV