Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

7 results about "Intrusion response" patented technology

Method and apparatus for snapshot management

A method for use in a storage system including a primary storage system and a secondary storage system, the method comprising: starting an asynchronous replication manager; detecting that an intrusion detector has detected an intrusion in the primary storage system; in response to the intrusion being detected, causing the asynchronous replication manager to stop transmission, to a secondary storage system, of replication data associated with any data buckets that are collected by the asynchronous replication manager while allowing the asynchronous replication manager to continue collecting new data buckets; generating an alert that indicates that the intrusion detector has detected the intrusion; receiving a response that is indicative of whether the intrusion is confirmed; when the response indicates that the intrusion is not confirmed, resuming the asynchronous replication manager, and when the intrusion is confirmed, causing the asynchronous replication manager to stop collecting data buckets.
Owner:DELL PROD LP

Method and apparatus for snapshot management

A method for use in a storage system including a primary storage system and a secondary storage system, the method comprising: starting an asynchronous replication manager; detecting that an intrusion detector has detected an intrusion in the primary storage system; in response to the intrusion being detected, causing the asynchronous replication manager to stop transmission, to a secondary storage system, of replication data associated with any data buckets that are collected by the asynchronous replication manager while allowing the asynchronous replication manager to continue collecting new data buckets; generating an alert that indicates that the intrusion detector has detected the intrusion; receiving a response that is indicative of whether the intrusion is confirmed; when the response indicates that the intrusion is not confirmed, resuming the asynchronous replication manager, and when the intrusion is confirmed, causing the asynchronous replication manager to stop collecting data buckets.
Owner:DELL PROD LP

Network intrusion tracing method and system based on behavior analysis

PendingCN121864408AAccurately depict the communication processImprove traceability accuracySecuring communicationHigh level techniquesPathPingAttack
The invention discloses a network intrusion tracing method and system based on behavior analysis, and relates to the technical field of network security. The method comprises the following steps: S1, constructing an attack activity propagation graph and calculating an attack propagation coefficient between nodes; s2, according to behavior data and attack propagation coefficients of each node in the attack activity propagation graph, calculating behavior pulse factors of the nodes, and determining attack participation nodes; s3, calculating a time propagation coefficient of an attack path and constructing an attack time trajectory according to interaction time difference characteristics and behavior pulse factors among the nodes; s4, according to the flow rate, the attack propagation coefficient and the time propagation coefficient between the nodes, calculating a traceability flow overflow index, and generating a potential attack source set; and S5, calculating an attack intensity adjustment coefficient according to the traceability flow overflow index and the flow rate, and triggering a defense strategy response mechanism based on the attack intensity adjustment coefficient. Precise traceability and real-time defense are realized through multi-dimensional behavior analysis, and the network intrusion response efficiency is improved.
Owner:HANGZHOU JIYONG TECHNOLOGY CO LTD

An abnormal network intrusion detection system based on FPGA and artificial intelligence

The application relates to the technical field of network security, in particular to an abnormal network intrusion detection system based on FPGA and artificial intelligence. The system obtains and analyzes network message information of a network link entering the FPGA through a network perception unit, generates a data packet for AI intrusion detection model reasoning based on the obtained data information; an intrusion detection unit is constructed based on an AI model, outputs an intrusion detection result based on the input data packet, so that an intrusion response unit can more accurately determine a response processing mechanism based on the intrusion detection result and adjust the response processing mechanism; the analysis unit determines the intrusion detection state based on the detection rate in the preset period after the adjustment of the response processing mechanism, adjusts the corresponding parameters based on the intrusion detection state, generates AI detection model fine-tuning parameters, so that the intrusion detection state can be more effectively adjusted to be qualified. The application improves the abnormal detection efficiency of high-speed network traffic.
Owner:BEIJING QICE TECH

A federated learning driven low-orbit satellite network adaptive intrusion response control method

PendingCN122316787ADelayed responseEngineering
This invention relates to network information security, specifically to a federated learning-driven adaptive intrusion response control method for low-Earth orbit satellite networks. The method includes: if the risk of a selected defensive action exceeds a set threshold, the action is suspended, an intent vector is generated, and reported to the cluster head node. The current satellite node then selects an optimal action from a set of low-risk action candidates for execution. Upon receiving the intent vector, the cluster head node selects high-reputation nodes with reputation values ​​exceeding a set threshold to initiate consensus. Each high-reputation node evaluates the intent vector based on its local model and votes. If more than two-thirds of the high-reputation nodes reach consensus, the cluster head node sends permission to execute the suspended action to the generated intent vector and increases the satellite node's reputation. If consensus fails, the suspended action is not allowed, and the satellite node's reputation is decreased. This invention addresses key technical challenges such as difficulty in security policy convergence, misjudgment of single-point high-risk situations, and delayed response times.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Industrial control intrusion response security decision-making method based on security reinforcement learning

The invention discloses an industrial control intrusion response security decision-making method based on security reinforcement learning, and the method comprises the steps: 1, building an industrial control system simulation environment, collecting the network layer alarm data of an industrial control system and the operation data of a physical layer sensor and an actuator, synchronously recording the state transition, the reward value and the security cost triggered by a decision-making action, and carrying out the simulation of the industrial control system; and forming attack and defense interaction trajectory data. And 2, analyzing the risk level of a response strategy and learning a better intrusion response strategy according to the trajectory data collected in the step 1 by adopting a hierarchical strategy optimization algorithm, and finally obtaining a safe and effective strategy. And 3, in combination with interaction data and evaluation indexes of simulation operation, counting core indexes such as defense success rates and safety costs of different models, and comprehensively measuring performance differences of response models. Test results prove that the method can effectively resist industrial control network attacks on the premise of maintaining low security risk cost, and collaborative optimization of security cost control and attack defense efficiency is realized.
Owner:BEIJING UNIV OF TECH

A method, system and application of vehicle-mounted Ethernet intrusion detection and defense based on a Transformer encoder

The application discloses a kind of vehicle Ethernet intrusion detection and defense method based on Transformer encoder, comprising the following steps: constructing vehicle Ethernet intrusion detection model, extracting sample data from the database containing normal communication message and / or attack type message pre-set, optimizing the training of the intrusion detection model;Real-time acquisition of real vehicle Ethernet message data, real-time inference is carried out to real data by constructing optimized intrusion detection model, whether the flow is abnormal is judged, and potential network attack or intrusion behavior is identified;According to the intrusion detection result, response unit carries out intrusion alarm and / or intrusion response.The method of the application realizes efficient sequence data processing capability, accurate anomaly detection capability and real-time response capability;At the same time, in order to maintain effective defense to new attack, the system updates the intrusion detection model periodically.The application also discloses a system for implementing the above method, which has a wide range of application scenarios.
Owner:EAST CHINA NORMAL UNIV