Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

11 results about "Moving target defense" patented technology

Power system moving target defense method based on power flow betweenness and power flow disturbance

The invention discloses a power system moving target defense method based on power flow betweenness and power flow disturbance, and relates to the field of power systems. Calculating to obtain a power flow betweenness and a power flow disturbance index of the normalized power system line; constructing a comprehensive index based on the power flow betweenness and the power flow disturbance index; and determining a to-be-deployed line set according to a preset device deployment number and the comprehensive index. And changing the line impedance value corresponding to the line set to obtain a target measurement matrix, calculating a measurement value residual error after the line impedance value is changed according to the original measurement matrix and the target measurement matrix, and determining an attack success rate based on a size relationship between the measurement value residual error and a detection threshold value. And deploying power system moving target defense according to a result of the attack success rate. According to the invention, the detection effectiveness and the MTD concealment are balanced. A traditional global combination search problem is converted into a linear complexity sorting problem, rapid solving is achieved, calculation efficiency is improved, and rapid generation of a hidden MTD strategy is achieved.
Owner:SICHUAN UNIV

Low-overhead moving target defense method and device for false data injection attack

The invention relates to a low-overhead moving target defense method and device for false data injection attacks, and the method comprises the steps: constructing a topological structure of a power grid bus and branches based on actual intelligent power grid data, and associating the branches with an initial admittance value; establishing an initial measurement matrix based on the initial admittance value and the topological structure of the power grid bus and the branches, and constructing a moving target defense strategy based on the initial measurement matrix; based on an invalid branch identification criterion and a topological structure of a power grid bus and a branch, determining an invalid branch in the power grid; based on invalid branches and a greedy selection mechanism, traversing the bus to screen valid branches, and obtaining a modified branch set; and changing admittance values of branches in the branch set based on a moving target defense strategy, changing a measurement matrix, and realizing low-overhead moving target defense. Compared with the prior art, on the premise that the high detection probability is maintained, the number of branches needing to modify admittance and the calculation time are remarkably reduced, and therefore the system defense cost is reduced.
Owner:SHANGHAI UNIV

A domain name resolution method suitable for mobile target defense

ActiveCN116471594BTransmissionSecurity arrangementDomain nameInternet network
The application discloses a domain name resolution method suitable for mobile target defense, and comprises the following steps: 1) a domain name system continuous updating device random address flow; 2) an identity authentication-oriented key negotiation flow; 3) a network device identity authentication flow; 4) a network device random address obtaining flow of a communication opposite end device; and 5) a network communication flow. The method can realize convenient authentication and security protection of internet devices, and help to improve the security of next-generation internet devices on the basis of guaranteeing the security of the internet.
Owner:GUILIN UNIV OF ELECTRONIC TECH

Network security dynamic defense system and method based on multi-agent joint game and mobile target defense

The invention discloses a network security dynamic defense system and method based on a multi-agent joint game and mobile target defense, and the system comprises an environment sensing module which is used for monitoring network state data in real time, and the network state data comprise traffic features, vulnerability information and attack behaviors; and the multi-agent decision module is composed of a plurality of distributed agents, and each agent performs game strategy decision based on local observation information and shares key data with other agents through a secure communication protocol. Through the combination of the multi-agent joint game and the MTD strategy, the system can adjust the defense strategy in real time and effectively cope with complex attacks such as advanced persistent threats, and based on the Bayesian game model, the defense system can predict possible strategies of attackers in an incomplete information environment, deploy defense measures in advance, reduce response delay and improve the security of the attackers. And meanwhile, the software layer MTD and the network layer MTD are adopted, so that an attacker is difficult to accurately detect system vulnerabilities, and the attack cost is improved.
Owner:BEIJING UNIV OF TECH

Power system false data injection attack defense method based on moving target defense

The invention discloses a power system false data injection attack defense method based on moving target defense, and relates to the technical field of power system state estimation and information security, and the method comprises the steps: building a power system state estimation measurement model; under the condition that measurement noise exists in the system, performing linearization processing on the state estimation measurement model of the power system, and constructing a system measurement Jacobian matrix; under the condition of incomplete measurement configuration, a system equivalent measurement jacobian matrix is constructed according to actual available measurement, and a dimension reduction measurement model is formed; constructing a false data injection attack vector; disturbing the system line parameters; reconstructing a measurement Jacobian matrix after disturbance according to the system parameters after disturbance; and on the basis of the difference of the measurement models before and after disturbance, constructing attack residual detection statistics. The method solves the problems that in an existing moving target defense method, a parameter disturbance strategy lacks quantitative design, and attack detection performance is unstable under the conditions of measurement noise and incomplete measurement.
Owner:CHANGAN UNIV

Methods and apparatus for artificial intelligence model security protection using mobile target defense

An example apparatus includes: an interface circuit system for obtaining a pre-trained detection model; machine-readable instructions; and at least one processor circuitry for being programmed by the machine-readable instructions to perform the following operations: adjusting the pre-trained detection model based on first local behavioral data; and executing the adjusted detection model to detect anomalies in second local behavioral data associated with the apparatus.
Owner:INTEL CORP

System and method for proactive defense against ransomware and infostealer attacks using moving target defense technique

A security system and method implements proactive defense through host operating system isolation and virtualization. The security system and method include a host computer running a host operating system and multiple hosted virtual machines that serve as intermediate connections to isolate the host operating system from external networks. The virtual machines systematically back up data to cloud services having indirect connections to the host computer. An internal virtual private network interconnects the virtual machines, with a designated virtual machine serving as a network gateway to manage traffic flow. A secure controller within the host computer functions as a bridge between user applications and the host operating system, enforcing security protocols and managing core operations to ensure system integrity. The secure controller manages interactions between the virtual machines and cloud services, providing security measures while maintaining operational efficiency through parallel processing architecture.
Owner:KING FAHD UNIVERSITY OF PETROLEUM AND MINERALS

Moving target defense method based on software defined network, software defined network and medium

The invention belongs to the technical field of network security, and provides a moving target defense method based on a software-defined network, the software-defined network and a medium, and the method comprises the steps: firstly obtaining the state information of the software-defined network; then, in combination with an artificial intelligence model, determining a key state feature as a low-dimensional vector representation of a network state of the distributed software defined network; then, constructing a dynamic environment model of the distributed software defined network; and finally, according to an evolutionary game algorithm based on reinforcement learning and the dynamic environment model, determining a moving target defense strategy of the distributed software defined network. According to the method, the high-dimensional state information of the distributed software-defined network is converted into low-dimensional key state features through the artificial intelligence model, so that the curse of dimensionality when a traditional algorithm processes a high-dimensional state space is effectively dealt with, and the algorithm performance is improved; the network state can be accurately perceived, the defense strategy is dynamically adjusted based on a dynamic environment model and an evolutionary game algorithm of reinforcement learning, and the adaptability and effectiveness of the defense strategy are enhanced.
Owner:XINJIANG UNIV OF SCI & TECH

Intelligent power grid-oriented advanced persistent threat APT active defense method and system

The invention provides an advanced persistent threat APT active defense method and system for a smart power grid, and the method comprises the steps: completing multi-source fusion scoring through online weak supervision comparative learning, and setting an alarm threshold value which is adaptive to the change of a day and night load; and on the response side, moving target defense driven by reinforcement learning is adopted. In order to guarantee collaborative and long-term reliable operation, the method adopts federated learning robust aggregation and gradient anomaly auditing to protect cross-station training safety, outputs an interpretable evidence chain aligned with a relay protection / scheduling procedure, and supports concept drift online treatment and blue-green / rollback online. Compared with the prior art, on the premise that an existing control link is not changed, early-stage, low-false-alarm, interpretable alarm and rapid disposal of the APT latent and transverse movement stage can be achieved, and the method is suitable for edge / concentration integrated deployment of a transformer substation and a dispatching center.
Owner:ZHANGZHOU POWER SUPPLY COMPANY STATE GRID FUJIANELECTRIC POWER +1

Active defense method, device and system for trusted data space

The invention provides an active defense method, device and system for a trusted data space, and the active defense method comprises the data space and the following steps: obtaining a business demand of the data space; generating a plurality of data infrastructures used for executing data operations according to the business requirements; constructing moving target defense and deception defense; when a change strategy of an attack surface in mobile target defense is formulated for the data infrastructure, deploying deception resources of the attack surface and a previous attack surface, capturing an attacker and attack traffic through a honeypot technology, and sending a trigger command; the moving target defense receives the trigger command and migrates the data infrastructure; performing active security defense on the migrated data infrastructure; performing regular rotation on the data infrastructure, and obtaining an optimal rotation period through an attack graph model and an adaptive genetic algorithm; therefore, the active security and the resource balance of the data space are improved.
Owner:XINXIANG UNIV