Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

22 results about "Moving target defense" patented technology

Power system moving target defense method based on power flow betweenness and power flow disturbance

The invention discloses a power system moving target defense method based on power flow betweenness and power flow disturbance, and relates to the field of power systems. Calculating to obtain a power flow betweenness and a power flow disturbance index of the normalized power system line; constructing a comprehensive index based on the power flow betweenness and the power flow disturbance index; and determining a to-be-deployed line set according to a preset device deployment number and the comprehensive index. And changing the line impedance value corresponding to the line set to obtain a target measurement matrix, calculating a measurement value residual error after the line impedance value is changed according to the original measurement matrix and the target measurement matrix, and determining an attack success rate based on a size relationship between the measurement value residual error and a detection threshold value. And deploying power system moving target defense according to a result of the attack success rate. According to the invention, the detection effectiveness and the MTD concealment are balanced. A traditional global combination search problem is converted into a linear complexity sorting problem, rapid solving is achieved, calculation efficiency is improved, and rapid generation of a hidden MTD strategy is achieved.
Owner:SICHUAN UNIV

Platform and method for automated moving target defense

The present invention is a system and method for machine-to-machine communication in a Zero Trust environment. The instant invention describes a platform implementation that disables threat actors and their methods that target workload credentials. The platform is an Automated Moving Target Defense (AMTD) platform that creates sidecars that contain algorithms for creating secure keys from user specified dynamic elements, a machine alias ID (MAID), an encryption library, and an envoy proxy. The sidecars are utilized to control access to, and secure messaging traffic between, entities in a non-trusted environment.
Owner:HOPR CORP

Low-overhead moving target defense method and device for false data injection attack

The invention relates to a low-overhead moving target defense method and device for false data injection attacks, and the method comprises the steps: constructing a topological structure of a power grid bus and branches based on actual intelligent power grid data, and associating the branches with an initial admittance value; establishing an initial measurement matrix based on the initial admittance value and the topological structure of the power grid bus and the branches, and constructing a moving target defense strategy based on the initial measurement matrix; based on an invalid branch identification criterion and a topological structure of a power grid bus and a branch, determining an invalid branch in the power grid; based on invalid branches and a greedy selection mechanism, traversing the bus to screen valid branches, and obtaining a modified branch set; and changing admittance values of branches in the branch set based on a moving target defense strategy, changing a measurement matrix, and realizing low-overhead moving target defense. Compared with the prior art, on the premise that the high detection probability is maintained, the number of branches needing to modify admittance and the calculation time are remarkably reduced, and therefore the system defense cost is reduced.
Owner:SHANGHAI UNIV

Distributed Denial of Service Attack Detection Method Based on Mobile Target Defense System

The present invention provides a distributed denial of service attack detection method based on a mobile target defense system. The method comprises obtaining characteristic indicators of a target proxy server of the mobile target defense system within a target time period and the number of users pre-assigned to the target proxy server; determining the load factor of the target proxy server within the target time period based on the characteristic indicators and the number of users; comparing the load factor of the target proxy server with the load factors of other proxy servers within the target time period to obtain a spatial comparison result; comparing the load factor of the target proxy server with the load factors of other time periods of the target proxy server to obtain a temporal comparison result; and determining the proxy server that suffers a distributed denial of service attack based on the temporal comparison result and the spatial comparison result. The present invention can improve the accuracy of distributed denial of service attack detection.
Owner:BEIJING UNIV OF POSTS & TELECOMM

A domain name resolution method suitable for mobile target defense

The application discloses a domain name resolution method suitable for mobile target defense, and comprises the following steps: 1) a domain name system continuous updating device random address flow; 2) an identity authentication-oriented key negotiation flow; 3) a network device identity authentication flow; 4) a network device random address obtaining flow of a communication opposite end device; and 5) a network communication flow. The method can realize convenient authentication and security protection of internet devices, and help to improve the security of next-generation internet devices on the basis of guaranteeing the security of the internet.
Owner:GUILIN UNIV OF ELECTRONIC TECH

Digital archive micro-service system based on mobile target defense

The invention discloses a digital archive micro-service system based on mobile target defense, and the system comprises a digital archive workflow generator which automatically designs a workflow model meeting the demands of a user according to a submitted application; the micro-service application set is used for storing the micro-service application set corresponding to the digital archive management whole process; the heterogeneous running resource pool is used for storing virtual machines corresponding to the diversified operating systems; the mobile target defense scheduler schedules heterogeneous operation resources at a certain probability for different links of the digital archive workflow based on a mobile target defense thought to support service provision; the micro-service assembler assembles a micro-service application into the selected heterogeneous operation resources according to the output workflow model, and instantiation of a micro-service function is achieved; and the digital archive workflow monitor tracks the full-process operation of the archive workflow, and discovers and disposes abnormal micro-service applications in time. According to the invention, the security of the digital archive information system is improved.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

User Access Method and Device Based on Proof-of-Work for Moving Target Defense Systems

This invention provides a user access method and apparatus based on proof-of-work in a mobile target defense system. The method includes receiving a resource request from a target user; allocating the resource request to proxy nodes in a hierarchical proxy cluster through the mobile target defense system, authenticating the target user, obtaining a target proof-of-work task, and returning the target proof-of-work task to the target user; receiving a solution corresponding to the target proof-of-work task from the target user; returning a service result associated with the resource request if the solution is correct; and re-authenticating the target user through the mobile target defense system if the solution is incorrect. By employing the proof-of-work driven user access mechanism provided by this invention, the security and stability of user access are improved in the mobile target defense system.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Network security dynamic defense system and method based on multi-agent joint game and mobile target defense

The invention discloses a network security dynamic defense system and method based on a multi-agent joint game and mobile target defense, and the system comprises an environment sensing module which is used for monitoring network state data in real time, and the network state data comprise traffic features, vulnerability information and attack behaviors; and the multi-agent decision module is composed of a plurality of distributed agents, and each agent performs game strategy decision based on local observation information and shares key data with other agents through a secure communication protocol. Through the combination of the multi-agent joint game and the MTD strategy, the system can adjust the defense strategy in real time and effectively cope with complex attacks such as advanced persistent threats, and based on the Bayesian game model, the defense system can predict possible strategies of attackers in an incomplete information environment, deploy defense measures in advance, reduce response delay and improve the security of the attackers. And meanwhile, the software layer MTD and the network layer MTD are adopted, so that an attacker is difficult to accurately detect system vulnerabilities, and the attack cost is improved.
Owner:BEIJING UNIV OF TECH

Power system false data injection attack defense method based on moving target defense

The invention discloses a power system false data injection attack defense method based on moving target defense, and relates to the technical field of power system state estimation and information security, and the method comprises the steps: building a power system state estimation measurement model; under the condition that measurement noise exists in the system, performing linearization processing on the state estimation measurement model of the power system, and constructing a system measurement Jacobian matrix; under the condition of incomplete measurement configuration, a system equivalent measurement jacobian matrix is constructed according to actual available measurement, and a dimension reduction measurement model is formed; constructing a false data injection attack vector; disturbing the system line parameters; reconstructing a measurement Jacobian matrix after disturbance according to the system parameters after disturbance; and on the basis of the difference of the measurement models before and after disturbance, constructing attack residual detection statistics. The method solves the problems that in an existing moving target defense method, a parameter disturbance strategy lacks quantitative design, and attack detection performance is unstable under the conditions of measurement noise and incomplete measurement.
Owner:CHANGAN UNIV

Methods and apparatus for artificial intelligence model security protection using mobile target defense

An example apparatus includes: an interface circuit system for obtaining a pre-trained detection model; machine-readable instructions; and at least one processor circuitry for being programmed by the machine-readable instructions to perform the following operations: adjusting the pre-trained detection model based on first local behavioral data; and executing the adjusted detection model to detect anomalies in second local behavioral data associated with the apparatus.
Owner:INTEL CORP

System and method for proactive defense against ransomware and infostealer attacks using moving target defense technique

A security system and method implements proactive defense through host operating system isolation and virtualization. The security system and method include a host computer running a host operating system and multiple hosted virtual machines that serve as intermediate connections to isolate the host operating system from external networks. The virtual machines systematically back up data to cloud services having indirect connections to the host computer. An internal virtual private network interconnects the virtual machines, with a designated virtual machine serving as a network gateway to manage traffic flow. A secure controller within the host computer functions as a bridge between user applications and the host operating system, enforcing security protocols and managing core operations to ensure system integrity. The secure controller manages interactions between the virtual machines and cloud services, providing security measures while maintaining operational efficiency through parallel processing architecture.
Owner:KING FAHD UNIVERSITY OF PETROLEUM AND MINERALS

Moving target defense method based on software defined network, software defined network and medium

The invention belongs to the technical field of network security, and provides a moving target defense method based on a software-defined network, the software-defined network and a medium, and the method comprises the steps: firstly obtaining the state information of the software-defined network; then, in combination with an artificial intelligence model, determining a key state feature as a low-dimensional vector representation of a network state of the distributed software defined network; then, constructing a dynamic environment model of the distributed software defined network; and finally, according to an evolutionary game algorithm based on reinforcement learning and the dynamic environment model, determining a moving target defense strategy of the distributed software defined network. According to the method, the high-dimensional state information of the distributed software-defined network is converted into low-dimensional key state features through the artificial intelligence model, so that the curse of dimensionality when a traditional algorithm processes a high-dimensional state space is effectively dealt with, and the algorithm performance is improved; the network state can be accurately perceived, the defense strategy is dynamically adjusted based on a dynamic environment model and an evolutionary game algorithm of reinforcement learning, and the adaptability and effectiveness of the defense strategy are enhanced.
Owner:XINJIANG UNIV OF SCI & TECH

A Mobile Target Defense Method, System and Storage Medium with Measurement Encoding Enhancement

The present invention provides a method, a system and a storage medium for measurement coding enhanced moving target defense. The method includes the following steps: constructing a measurement coding enhanced moving target defense model for power grid data injection attacks; analyzing the detection conditions of power grid data injection attacks; analyzing the deficiencies of the moving target defense model in detecting power grid data injection attacks according to the special case of solely adopting moving target defense; determining the design criterion of the coding matrix when the coding matrix is a diagonal matrix; constructing an optimization problem of measurement coding enhanced moving target defense; designing a heuristic solution algorithm to reduce the comprehensive cost and improve the detection ability of power grid data injection attacks; and performing state estimation and attack detection on the received power grid data according to the optimized measurement coding and moving target defense strategy to detect potential power grid data injection attacks in the data transmission process.
Owner:EAST CHINA UNIV OF SCI & TECH

Android malware adversarial sample detection method based on the concept of mobile target defense

This invention discloses an Android malware adversarial sample detection method based on the concept of mobile target defense. The method includes: a heterogeneous model pool, diversified adversarial training, optimal ensemble learning, and a dynamic update trigger. The heterogeneous model pool is designed for Android software, aiming to provide a heterogeneous orthogonal foundational model for subsequent adversarial training and ensemble learning. The diversified adversarial training is designed for Android malware, generating corresponding detection models for different types of adversarial sample attacks. The optimal ensemble learning is designed for all adversarial detection models, aiming to form a detection capability against all types of adversarial samples. The dynamic update trigger is based on the detection results, updating the construction process of the heterogeneous model pool, diversified adversarial training, and optimal ensemble learning through a mixture of periodic and event-driven triggers. Through the technical solution of this disclosed example, mainstream Android malware adversarial samples can be detected, improving the security of the Android platform.
Owner:SOUTHEAST UNIV

Resource-efficient SDN low-speed flow table overflow attack early detection method

The invention discloses a resource-efficient SDN (Software Defined Network) low-speed flow table overflow attack early detection method, which is characterized by comprising the following steps of: 1) training an early detection model; 2) initializing an early detector of the slow flow table overflow attack; and 3) processing the flow table information of the detected SDN switch. The method is deployed in an SDN controller, can perform high-precision early prediction on the SDN low-speed flow table overflow attack while consuming a small amount of SDN control channel bandwidth resources, and determines a starting time point of a moving target defense measure based on effective time hopping of a flow table item, so that the low-speed flow table overflow attack damage is reduced, and the security of the moving target defense measure is improved. And resource consumption of detection and subsequently started mobile target defense measures is reduced.
Owner:GUILIN UNIV OF AEROSPACE TECH

Power system network attack multi-stage detection method and device based on topology switching

The invention belongs to the technical field of attack detection, and particularly relates to a power system network attack multi-stage detection method and device based on topology switching. The method comprises the following steps: defining a detection capability quantitative index, and deducing a detection capability evaluation matrix; evaluating the influence of line switching on the detection capability based on the matrix; a multi-stage topology switching optimization model is established, and the power generation cost is reduced while the detection capability is maximized; constructing a topology switching-D-FACTS equipment combined moving target defense framework which firstly carries out reactance disturbance and then carries out line switching; and solving the optimization model to determine a transmission line set disconnected at each stage, executing a topology switching operation according to an optimization result, and updating a matrix rank to realize attack detection. According to the method, the power generation cost is minimized while the detection capability is maximized, the detection limit of a single method is broken through in cooperation with D-FACTS-based moving target defense, and the upper detection limit can also be achieved in a system in which D-FACTS equipment cannot fully cover a required line.
Owner:SHANDONG COMP SCI CENTNAT SUPERCOMP CENT IN JINAN +1

Intelligent power grid-oriented advanced persistent threat APT active defense method and system

The invention provides an advanced persistent threat APT active defense method and system for a smart power grid, and the method comprises the steps: completing multi-source fusion scoring through online weak supervision comparative learning, and setting an alarm threshold value which is adaptive to the change of a day and night load; and on the response side, moving target defense driven by reinforcement learning is adopted. In order to guarantee collaborative and long-term reliable operation, the method adopts federated learning robust aggregation and gradient anomaly auditing to protect cross-station training safety, outputs an interpretable evidence chain aligned with a relay protection / scheduling procedure, and supports concept drift online treatment and blue-green / rollback online. Compared with the prior art, on the premise that an existing control link is not changed, early-stage, low-false-alarm, interpretable alarm and rapid disposal of the APT latent and transverse movement stage can be achieved, and the method is suitable for edge / concentration integrated deployment of a transformer substation and a dispatching center.
Owner:ZHANGZHOU POWER SUPPLY COMPANY STATE GRID FUJIANELECTRIC POWER +1

Active attack detection method and system based on moving target defense and event triggering

The invention provides an active attack detection method and system based on moving target defense and event triggering. The method comprises the following steps: establishing a system model based on parameter information related to a continuous time linear system; after the system is attacked by false data injection, determining a defense strategy of the system for a moving target according to the system model; establishing an attack detection model of the system based on the system model and the defense strategy; determining an event triggering mechanism of the system by utilizing the attack detection model; the event triggering mechanism is used for analyzing Zeno behaviors; and based on the defense strategy, the attack detection model and the event triggering mechanism, carrying out attack detection analysis of moving target defense on the system.
Owner:WUHAN INST OF TECH

Power system network attack multi-stage detection method and device based on topology switching

The application belongs to the technical field of attack detection, and more particularly relates to a power system network attack multi-stage detection method and device based on topology switching. The method comprises the following steps: defining a detection capability quantitative index, deducing a detection capability evaluation matrix; based on the matrix, evaluating the influence of line switching on the detection capability; establishing a multi-stage topology switching optimization model, maximizing the detection capability while reducing the power generation cost; constructing a topology switching-D-FACTS device joint mobile target defense framework in which line switching is performed after electric reactance disturbance; solving the optimization model to determine the transmission line set disconnected in each stage, performing topology switching operation according to the optimization result, and updating the matrix rank to realize attack detection. The application maximizes the detection capability while minimizing the power generation cost, and cooperates with the mobile target defense based on D-FACTS to break through the detection limit of a single method, and can also achieve the detection upper bound in a system in which the D-FACTS device fails to cover all the required lines.
Owner:SHANDONG COMP SCI CENTNAT SUPERCOMP CENT IN JINAN +1

Active defense method, device and system for trusted data space

The invention provides an active defense method, device and system for a trusted data space, and the active defense method comprises the data space and the following steps: obtaining a business demand of the data space; generating a plurality of data infrastructures used for executing data operations according to the business requirements; constructing moving target defense and deception defense; when a change strategy of an attack surface in mobile target defense is formulated for the data infrastructure, deploying deception resources of the attack surface and a previous attack surface, capturing an attacker and attack traffic through a honeypot technology, and sending a trigger command; the moving target defense receives the trigger command and migrates the data infrastructure; performing active security defense on the migrated data infrastructure; performing regular rotation on the data infrastructure, and obtaining an optimal rotation period through an attack graph model and an adaptive genetic algorithm; therefore, the active security and the resource balance of the data space are improved.
Owner:XINXIANG UNIV

Hidden attacker identification method and device based on moving target defense system

The invention provides a hidden attacker identification method and device based on a moving target defense system, and belongs to the technical field of network security, the method comprises the following steps: constructing a user-reverse proxy heterogeneous graph of a current time step, the user-reverse proxy heterogeneous graph reflecting an interaction structure of a user and a reverse proxy in the current time step; performing feature learning on the user-reverse proxy heterogeneous graph by using a graph neural network to obtain spatial fusion features; based on the fusion spatio-temporal representation of the previous time step and the spatial fusion features, determining the fusion spatio-temporal representation of the current time step; and inputting the fused spatio-temporal representation of the current time step into a classifier to obtain an abnormal user identification result output by the classifier. According to the method, the user characteristics and the agent side characteristics are jointly modeled through the user-directional agent heterogeneous graph, so that the limitation of evaluation only from the user characteristics is overcome; the spatial fusion features of a plurality of time steps are fused, spatial-temporal features are subjected to conjoint analysis, and persistent hostile attackers are accurately identified.
Owner:BEIJING UNIV OF POSTS & TELECOMM