Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

15 results about "Intrusion response" patented technology

Intelligent tablet anti-intrusion system for field communication

The invention relates to the technical field of intelligent tablet communication protection, in particular to an intelligent tablet anti-intrusion system for field communication, which is characterized in that an intelligent tablet device emits a detection signal in a tunnel environment, receives and acquires a response signal from a legal communication node and then extracts multipath characteristic parameters; calculating the multipath statistical characteristics of the current channel according to the multipath characteristic parameters, and performing compensation according to the real-time moving speed of the intelligent tablet equipment and the inertia measurement data to obtain compensated multipath statistical characteristics; performing matching analysis on the compensated multipath statistical characteristics and a tunnel multipath blind area fingerprint database to obtain matching success information; when the matching success information is monitored, judging that the intelligent tablet device is in a communication blind area and starting hierarchical anti-intrusion response; and when it is monitored that the multipath statistical features are recovered to the non-blind area channel mode and secure connection with the legal communication node is reestablished, the anti-intrusion response is quitted, and the blind area event log is uploaded, so that the problem of communication security and stability in the tunnel environment is effectively solved.
Owner:SICHUAN ZHIYUAN LIXING TECHNOLOGY CO LTD

Method and apparatus for snapshot management

A method for use in a storage system including a primary storage system and a secondary storage system, the method comprising: starting an asynchronous replication manager; detecting that an intrusion detector has detected an intrusion in the primary storage system; in response to the intrusion being detected, causing the asynchronous replication manager to stop transmission, to a secondary storage system, of replication data associated with any data buckets that are collected by the asynchronous replication manager while allowing the asynchronous replication manager to continue collecting new data buckets; generating an alert that indicates that the intrusion detector has detected the intrusion; receiving a response that is indicative of whether the intrusion is confirmed; when the response indicates that the intrusion is not confirmed, resuming the asynchronous replication manager, and when the intrusion is confirmed, causing the asynchronous replication manager to stop collecting data buckets.
Owner:DELL PROD LP

Abnormal network intrusion detection system based on FPGA and artificial intelligence

The invention relates to the technical field of network security, in particular to an abnormal network intrusion detection system based on an FPGA and artificial intelligence. According to the system, network message information of a network link entering an FPGA is acquired and analyzed through a network sensing unit, and a data packet used for AI intrusion detection model reasoning is generated based on the acquired data information; the intrusion detection unit is constructed on the basis of an AI model and outputs and judges an intrusion detection result on the basis of an input data packet, so that the intrusion response unit more accurately decides a response processing mechanism on the basis of the intrusion detection result and performs adjustment on the basis of the response processing mechanism; the intrusion detection state is determined through the analysis unit based on the detection rate in the preset period adjusted by the response processing mechanism, the corresponding parameters are adjusted based on the intrusion detection state, the AI detection model fine adjustment parameters are generated, and therefore the intrusion detection state can be adjusted to be qualified more effectively. According to the invention, the high-speed network flow anomaly detection efficiency is improved.
Owner:BEIJING QICE TECH

Method and apparatus for snapshot management

A method for use in a storage system including a primary storage system and a secondary storage system, the method comprising: starting an asynchronous replication manager; detecting that an intrusion detector has detected an intrusion in the primary storage system; in response to the intrusion being detected, causing the asynchronous replication manager to stop transmission, to a secondary storage system, of replication data associated with any data buckets that are collected by the asynchronous replication manager while allowing the asynchronous replication manager to continue collecting new data buckets; generating an alert that indicates that the intrusion detector has detected the intrusion; receiving a response that is indicative of whether the intrusion is confirmed; when the response indicates that the intrusion is not confirmed, resuming the asynchronous replication manager, and when the intrusion is confirmed, causing the asynchronous replication manager to stop collecting data buckets.
Owner:DELL PROD LP

Determining security intrusions during virtual conferences

One example method includes receiving, during a virtual conference hosted by a virtual conference provider, one or more audio or video streams from one or more client devices connected to the virtual conference, each client device associated with a participant attending the virtual conference; providing, to a trained machine learning ("ML") model, the received one or more audio or video streams to determine a potential security intrusion; in response to receiving an indication of a potential security intrusion from the trained ML model: generating an indication of the potential security intrusion; and providing the indication to one or more client devices of the one or more client devices.
Owner:ZOOM COMMUNICATIONS INC

Network intrusion tracing method and system based on behavior analysis

PendingCN121864408AAccurately depict the communication processImprove traceability accuracySecuring communicationHigh level techniquesPathPingAttack
The invention discloses a network intrusion tracing method and system based on behavior analysis, and relates to the technical field of network security. The method comprises the following steps: S1, constructing an attack activity propagation graph and calculating an attack propagation coefficient between nodes; s2, according to behavior data and attack propagation coefficients of each node in the attack activity propagation graph, calculating behavior pulse factors of the nodes, and determining attack participation nodes; s3, calculating a time propagation coefficient of an attack path and constructing an attack time trajectory according to interaction time difference characteristics and behavior pulse factors among the nodes; s4, according to the flow rate, the attack propagation coefficient and the time propagation coefficient between the nodes, calculating a traceability flow overflow index, and generating a potential attack source set; and S5, calculating an attack intensity adjustment coefficient according to the traceability flow overflow index and the flow rate, and triggering a defense strategy response mechanism based on the attack intensity adjustment coefficient. Precise traceability and real-time defense are realized through multi-dimensional behavior analysis, and the network intrusion response efficiency is improved.
Owner:HANGZHOU JIYONG TECHNOLOGY CO LTD

An abnormal network intrusion detection system based on FPGA and artificial intelligence

The application relates to the technical field of network security, in particular to an abnormal network intrusion detection system based on FPGA and artificial intelligence. The system obtains and analyzes network message information of a network link entering the FPGA through a network perception unit, generates a data packet for AI intrusion detection model reasoning based on the obtained data information; an intrusion detection unit is constructed based on an AI model, outputs an intrusion detection result based on the input data packet, so that an intrusion response unit can more accurately determine a response processing mechanism based on the intrusion detection result and adjust the response processing mechanism; the analysis unit determines the intrusion detection state based on the detection rate in the preset period after the adjustment of the response processing mechanism, adjusts the corresponding parameters based on the intrusion detection state, generates AI detection model fine-tuning parameters, so that the intrusion detection state can be more effectively adjusted to be qualified. The application improves the abnormal detection efficiency of high-speed network traffic.
Owner:BEIJING QICE TECH

Intrusion response method, apparatus, device and readable storage medium

The application provides an intrusion response method, device and equipment and a readable storage medium, and relates to the field of intrusion monitoring. The method comprises the following steps: determining a target feature contour according to an infrared thermal image frame and a visible light image frame corresponding to any synchronization moment; generating a first intrusion response in the case that the target feature contour and a first monitoring area in a to-be-monitored area overlap, and the similarity between the target feature contour and a preset edge contour is greater than a preset threshold, the first intrusion response being used for indicating and informing a monitoring personnel; generating a second intrusion response in the case that the target feature contour and a second monitoring area in the to-be-monitored area overlap, the second intrusion response being used for indicating and informing an intruder; and the monitoring level of the first monitoring area is less than the monitoring level of the second monitoring area. The application generates different responses in different monitoring areas, which not only improves the accuracy of suspicious personnel detection, but also improves the accuracy and rationality of the intrusion response.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD

A federated learning driven low-orbit satellite network adaptive intrusion response control method

PendingCN122316787ADelayed responseEngineering
This invention relates to network information security, specifically to a federated learning-driven adaptive intrusion response control method for low-Earth orbit satellite networks. The method includes: if the risk of a selected defensive action exceeds a set threshold, the action is suspended, an intent vector is generated, and reported to the cluster head node. The current satellite node then selects an optimal action from a set of low-risk action candidates for execution. Upon receiving the intent vector, the cluster head node selects high-reputation nodes with reputation values ​​exceeding a set threshold to initiate consensus. Each high-reputation node evaluates the intent vector based on its local model and votes. If more than two-thirds of the high-reputation nodes reach consensus, the cluster head node sends permission to execute the suspended action to the generated intent vector and increases the satellite node's reputation. If consensus fails, the suspended action is not allowed, and the satellite node's reputation is decreased. This invention addresses key technical challenges such as difficulty in security policy convergence, misjudgment of single-point high-risk situations, and delayed response times.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Industrial control cross-layer security decision method based on partial observable markov decision

The application discloses an industrial control cross-layer security decision-making method based on a partially observable Markov decision, which comprises the following steps: step 1, using a monitoring system to perform state sensing on an industrial control system with partially observable state information, and collecting training data through continuous interaction between a model and the industrial control system; step 2, using a T-DRQN deep reinforcement learning method based on a POMDP decision-making framework to combine the data obtained through the interaction with historical observation information for training; and step 3, using alarm information of network layer device nodes and physical layer sensor readings to evaluate the response effect of an intrusion response strategy, and using these indexes to analyze the difference in response performance between different models. The application can effectively resist multi-stage cross-layer attacks from the cyberspace to the physical space, adopts a double-branch network structure, more obviously distinguishes state value and action advantage, and thus more accurately and efficiently guides the intrusion response decision-making, and is more suitable for processing industrial control scenes with partially observable system state information.
Owner:BEIJING UNIV OF TECH

Industrial control intrusion response security decision-making method based on security reinforcement learning

The invention discloses an industrial control intrusion response security decision-making method based on security reinforcement learning, and the method comprises the steps: 1, building an industrial control system simulation environment, collecting the network layer alarm data of an industrial control system and the operation data of a physical layer sensor and an actuator, synchronously recording the state transition, the reward value and the security cost triggered by a decision-making action, and carrying out the simulation of the industrial control system; and forming attack and defense interaction trajectory data. And 2, analyzing the risk level of a response strategy and learning a better intrusion response strategy according to the trajectory data collected in the step 1 by adopting a hierarchical strategy optimization algorithm, and finally obtaining a safe and effective strategy. And 3, in combination with interaction data and evaluation indexes of simulation operation, counting core indexes such as defense success rates and safety costs of different models, and comprehensively measuring performance differences of response models. Test results prove that the method can effectively resist industrial control network attacks on the premise of maintaining low security risk cost, and collaborative optimization of security cost control and attack defense efficiency is realized.
Owner:BEIJING UNIV OF TECH

A method, system and application of vehicle-mounted Ethernet intrusion detection and defense based on a Transformer encoder

The application discloses a kind of vehicle Ethernet intrusion detection and defense method based on Transformer encoder, comprising the following steps: constructing vehicle Ethernet intrusion detection model, extracting sample data from the database containing normal communication message and / or attack type message pre-set, optimizing the training of the intrusion detection model;Real-time acquisition of real vehicle Ethernet message data, real-time inference is carried out to real data by constructing optimized intrusion detection model, whether the flow is abnormal is judged, and potential network attack or intrusion behavior is identified;According to the intrusion detection result, response unit carries out intrusion alarm and / or intrusion response.The method of the application realizes efficient sequence data processing capability, accurate anomaly detection capability and real-time response capability;At the same time, in order to maintain effective defense to new attack, the system updates the intrusion detection model periodically.The application also discloses a system for implementing the above method, which has a wide range of application scenarios.
Owner:EAST CHINA NORMAL UNIV

Vehicle cyber intrusion response method, device, and computer-readable storage medium

The application provides a vehicle network intrusion response method, device and computer readable storage medium, which analyzes security event data in a vehicle network in real time, discovers potential security risks in time, and provides a basis for subsequent processing. Alarm information is generated by analyzing the security event data, so as to respond in time when the network intrusion behavior occurs and improve the response speed. Then, the alarm information is deeply analyzed to determine whether it is a real threat, and the threat level of the network intrusion behavior is determined in response to the result whether the alarm information is a real threat, so that corresponding measures can be taken according to different threat levels. The defense measures in the intrusion response strategy corresponding to the threat level can effectively cope with the threat of network intrusion behavior, thereby improving the security and reliability of the vehicle network as a whole.
Owner:ZHEJIANG GEELY HLDG GRP CO LTD +2

Determining security intrusions during virtual conferences

One example method includes receiving, during a virtual conference hosted by a virtual conference provider, one or more audio or video streams from one or more client devices connected to the virtual conference, each client device associated with a participant attending the virtual conference; providing, to a trained machine learning (“ML”) model, the received one or more audio or video streams to determine a potential security intrusion; in response to receiving an indication of a potential security intrusion from the trained ML model: generating an indication of the potential security intrusion; and providing the indication to one or more client devices of the one or more client devices.
Owner:ZOOM VIDEO COMM INC

Power plant personnel positioning management platform

The invention discloses a power plant personnel positioning management platform, relates to the technical field of personnel positioning, and solves the technical problems that differential correction strategies are not designed for static and dynamic scenes of a power plant, and a partial region management scheme only pays attention to a high-risk region and neglects fine management of a normal region. Static drift and dynamic track errors are reduced through static confidence region anchoring and dynamic step length self-adaptive adjustment in combination with gyroscope direction angle correction, the problem of positioning distortion in a complex environment is solved, static and dynamic states are judged in a multi-dimensional mode based on the three-axis acceleration, the stride frequency and the position change rate, a switching buffer mechanism is added, the misjudgment rate is reduced, and the positioning accuracy is improved. High-frequency monitoring and qualification verification are adopted in a high-risk area, normal monitoring is performed in a working period in a normal area, and only the electronic fence is activated in a non-working period, so that safety is guaranteed, privacy is protected, and abnormal intrusion response time in the non-working period is shortened.
Owner:JINING XINNENG THERMAL POWER CO LTD