Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

23 results about "Multiple attack" patented technology

A network attack defense method, device, intrusion detection equipment, and storage medium.

This application provides a network attack defense method, apparatus, intrusion detection device, and storage medium. Applied to an intrusion detection device, the device maintains multiple attack rules, each labeled with an attack chain tag. The attack chain tag indicates the attack chain to which the attack rule belongs. The method includes: performing intrusion detection on network traffic to determine a first attack rule that the network traffic has hit; the first attack rule is labeled with a target attack chain tag; querying at least one second attack rule labeled with the target attack chain tag from the multiple attack rules; sending the first and second attack rules belonging to the same attack chain to a firewall, so that the firewall performs attack defense according to a protection policy; the protection policy is generated based on the first and second attack rules. The firewall can also perform pre-defense against subsequent attack behaviors based on the attack rules associated with the attack chain, thereby improving the firewall's defense effectiveness.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

Web application firewall vulnerability detection method, device and system based on load variation injection

The invention belongs to the technical field of network security, and particularly relates to a Web application firewall vulnerability detection method based on load variation injection. Comprising the following steps: constructing a unified attack grammar rule base covering multiple attack types; analyzing the original attack load into an abstract syntax tree; carrying out semantic reservation load variation based on the syntax tree to generate a semantic equivalent variation load; performing protection rule detection on the Web application firewall, analyzing a detection result and performing pruning operation on the syntax tree; a Monte Carlo tree search algorithm is utilized, a rule detection mechanism is combined, and a variation path with a high success rate is dynamically evaluated and preferentially tested so as to efficiently generate an antagonistic load capable of bypassing WAF detection; according to the method, the problems of attack failure, low black box test efficiency and insufficient coverage of a single attack type caused by semantic destruction in the prior art are solved, and the WAF rule base vulnerability can be systematically evaluated.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Bionic multi-weapon fighting robot

The utility model relates to the technical field of fighting robots, and provides a bionic multi-weapon fighting robot which comprises a robot body, walking wheels, a driving mechanism, weapon arms, first motors and attack wheels, the walking wheels are rotationally connected to the robot body, the two first motors are arranged above the front ends of the two weapon arms respectively, and the driving mechanism is connected with the attack wheels. The first motor is in driving connection with the attack wheels, a plurality of oblique teeth are arranged on the circumferences of the attack wheels at intervals, the two attack wheels are located below the front ends of the two weapon arms correspondingly, impact blocks are arranged at the front ends of the weapon arms, the rear ends of the two weapon arms are hinged to the front end of the machine body correspondingly, and the driving mechanism is arranged on the machine body. The driving mechanism is in driving connection with the two weapon arms and used for driving the two weapon arms to be close to and separated from each other. The attack function that clamping attack is carried out through the two weapon arms, grinding or smashing and other damage is carried out through the attack wheel is achieved, the attack diversity is improved, multiple attack actions are carried out at the same time, and the attack effectiveness is also guaranteed.
Owner:HEILONGJIANG XUANSU TECHNOLOGY CO LTD

A voiceprint spoofing defense method, device and computer readable storage medium

PendingCN122372302ASound sourcesDecision model
A method, apparatus, and computer-readable storage medium for voiceprint spoofing defense include: acquiring a speech signal to be verified; extracting multi-dimensional features from the speech signal to obtain a multi-dimensional feature vector, wherein the multi-dimensional feature vector includes at least speech text content features, identity features, sound quality features representing recording or synthesis traces, liveness features representing the physiological characteristics of the sound source, and adversarial perturbation features; fusing the multi-dimensional feature vector to obtain a joint feature vector; inputting the joint feature vector into a pre-trained joint risk decision model to obtain a spoofing risk score; and determining the verification result of the speech signal to be verified based on the comparison result of the spoofing risk score and a preset threshold. This application can effectively detect multiple attack modes such as replay attacks, speech synthesis attacks, and adversarial example attacks simultaneously; and accurately detect high-quality spoofing attacks.
Owner:XIANGYANG DAAN AUTOMOBILE TEST CENT

Network monitoring with multiple attack graphs

A computer-implemented method for monitoring a computer network is provided, the method comprising: storing a first attack graph, the attack graph comprising a plurality of nodes each representing an event that may occur within the computer network; storing one or more predetermined variation properties of one or more of the events represented by the nodes, the variation properties being indicative of possible changes to the nodes within the first attack graph; determining a plurality of possible alternative sequences of the nodes in the first attack graph based on the variation properties; generating a plurality of additional attack graphs, each of the additional attack graphs comprising a plurality of the nodes of the first attack graph arranged in one of the possible sequences; and monitoring events within the network to detect a set of events occurring in a sequence that corresponds to one of the additional attack graphs to identify a potential security attack. A computer system including at least one processor and memory storing computer program code configured to perform the said method, and a computer program or computer readable medium comprising instructions that when executed by a computer system cause the computer system to perform the said method are also provided.
Owner:BRITISH TELECOM PLC

A power distribution network black box adversarial sample generation method based on large language model topology reasoning guidance

The application discloses a power distribution network black box confrontation sample generation method based on a large language model topology reasoning guide, which comprises the following steps: determining an attack target of a scheduling task, quantifying a destructive intention of an attacker, and converting a fuzzy attack target into a multi-target attack loss function; using general knowledge and reasoning ability of the large language model, screening out key nodes with the highest attack cost performance, and obtaining a mask vector; under the constraint of the mask vector, generating a specific disturbance vector for a continuous domain or a discrete domain; and performing sample verification. The application introduces a large language model as a topology cognition engine, uses semantic reasoning ability of the large language model to screen out key fragile nodes in a power distribution network, generates an attack mask, and guides a black box optimizer to lock a key subspace through the mask, so that high-quality confrontation samples covering multiple attack targets and action domain types are efficiently generated without accessing an internal structure of the model, and rich robustness training data is provided for intelligent agents.
Owner:XIANGTAN UNIV +1

Security defense method, system and device for controller area network bus and medium

The embodiment of the invention provides a security defense method, system and equipment for a controller area network bus, and a medium, and belongs to the field of communication security of the controller area network bus. The method comprises the following steps: collecting bus communication behavior data through a trusted monitoring node; the method comprises the following steps: acquiring a pre-shared key, constructing a network security threat knowledge graph based on the pre-shared key, generating a dynamic inter-frame interval sequence for each message ID to be sent on a bus based on the pre-shared key and a pseudo-random function, and adjusting at least one defense parameter according to a potential attack path output by the knowledge graph; before a sending node is controlled to send messages, a credible monitoring node calculates legal sending time windows of all the messages based on the same dynamic inter-frame interval sequence; and controlling the trusted monitoring node to monitor the bus, and if the occurrence time of the start bit of the message is detected to be earlier than the legal sending time window, judging that the time sequence is illegal. Microsecond-level real-time active defense covering multiple attack types is achieved, and meanwhile the real-time performance of key messages is guaranteed through dynamic scheduling.
Owner:SINO TRUK JINAN POWER CO LTD

Data-encrypted anti-attack method and system for accessing electric vehicle to power distribution network

The invention discloses a data-encrypted anti-attack method and system for accessing an electric vehicle to a power distribution network. Constructing an attacked behavior model of the charging station system by adopting a Markov decision process; the method comprises the following steps: firstly, defining and collecting intrusible units in a charging station system, finding out an initial access point, starting from the initial access point, traversing all the intrusible units based on a state set and an action set, and generating a plurality of attack paths to form an attack path tree; then, calculating an optimal path and a state value function matrix through a Markov decision process; and training a neural network through the historical state value function matrix, and finally outputting the attacked probability of the charging station system by the neural network so as to judge whether the charging station system is attacked or not. After training is completed, real-time data of a charging station system are obtained, and occurrence of network attacks is judged through first-level threshold early warning and second-level intelligent detection. According to the invention, the network security of the electric vehicle accessing the power distribution network can be effectively improved, and potential attacks can be identified and defended in time.
Owner:STATE GRID LIAONING ELECTRIC POWER CO LTD +2

A Method for Generating Optimal Attack Strategies for Wind Farms Considering DoS and FDIA

This application relates to a method for generating optimal attack strategies for wind farms considering DoS and FDIA attacks. The method includes: first, establishing an optimized control model and an optimal scheduling model for normal operation of the wind turbine; then, constructing an FDIA control command tampering attack model, a DoS attack model, and an FDIA wind speed measurement tampering attack model, respectively; and finally, combining wind turbine operation constraints and attack resource constraints to solve for the attack strategy that maximizes the total power output loss of the wind farm and complete a quantitative assessment of the attack impact. This invention integrates DoS and FDIA attacks into the physical operation constraint framework of the wind turbine, generating an implementable optimal attack strategy with the goal of maximizing power output loss, achieving unified quantitative assessment of multiple attack scenarios, and providing support for the network security risk analysis and protection of wind farms.
Owner:STATE GRID ANHUI ELECTRIC POWER CO LTD ELECTRIC POWER SCI RES INST

AI-driven missile defense system

We provide a missile defense system that utilizes generative AI to perform real-time dynamic analysis and generate defensive measures, thereby improving the responsiveness and flexibility of missile defense. [Solution] This invention provides a missile defense system that utilizes generative AI and ensemble learning with multiple AI models to analyze enemy missile flight data and communication signals in real time and immediately generate jamming signals and interception measures. Through ensemble learning, each AI model analyzes the threat from its own perspective, and the generative AI integrally generates the optimal defense measures. Furthermore, the continuous learning function improves the accuracy of defenses in subsequent instances, and enhances responsiveness and flexibility against irregular threats and multiple attacks. This system dramatically strengthens the ability to defend against diverse attacks.
Owner:中村义一

Accuracy in attack technique labeling in an extended detection system

Techniques for providing a confidence rating for an attack technique tag and a guidance for improving the confidence rating are described. An attack technique analytics engine receives telemetry data, a notification that an attack has been detected using an attack detection source, the notification including an attack technique tag indicating an attack technique used in the attack, and attack technique data including a likelihood of a particular attack technique, from among multiple attack techniques, occurring determined using a particular attack detection source from among multiple attack detection sources. Based on the telemetry, the attack technique tag, and the attack technique data, a confidence rating that the attack corresponds to the attack technique is determined. The attack detection source and attack technique are analyzed to determine a guidance for improving the confidence rating, and the rating and guidance are appended to the attack technique tag.
Owner:CISCO TECHNOLOGY INC

An extensible artificial intelligence attack benchmarking method and system

ActiveCN117312119BResolve the model under testSolve the problem of language restrictionsData setAlgorithm
This invention provides an scalable AI attack benchmark testing method and system. A model conversion module transforms the tested model according to its type and framework, obtaining a converted model that matches the attack framework. The dataset attacks the converted model, yielding a test result. The attack framework invokes various attack algorithms with a standardized format, generates corresponding attack scripts, and then performs several attacks on the converted model, resulting in multiple attack results. When testing the next tested model, the model conversion module again transforms its framework according to its type before launching the attack. The advantages are: it can flexibly convert for different AI models, attacking the converted model to obtain attack results, without needing to rebuild test modules for different AI models, improving attack efficiency, reducing testing costs, and solving the problem of existing testing methods (frameworks) being limited by the tested model and language.
Owner:北京银联金卡科技有限公司

Filter updating method and device, equipment, medium and product

The embodiment of the invention provides a filter updating method and device, equipment, a medium and a product, and relates to the technical field of artificial intelligence. According to the method, diversified mixed samples are generated through disturbance, an adversarial experience library of a filter is expanded, the ability of recognizing multiple attack modes is established in the initial stage, a robustness foundation is laid for coping with dynamic attacks, and then target domain scene data are introduced, so that the robustness of the filter is improved. The information divergence between a mixed sample and a target domain sample is calculated in real time, the environment change degree is accurately quantified, parameter updating is automatically triggered in a real environment, the limitation that a traditional method depends on static rules and fixed period updating is broken through, the rapid response and continuous defense capability to novel threats is achieved, and the method is suitable for popularization and application. And the updating efficiency of the filter is improved.
Owner:CHONGQING NORMAL UNIVERSITY +2

Network security risk trend multidimensional correlation data analysis prediction method

This invention relates to the field of data analysis technology, specifically a method for multi-dimensional correlation data analysis and prediction of cybersecurity risk trends. The method includes: calculating the behavioral entropy value of data for each time slice; selecting abnormal time slices from the data whose behavioral entropy values ​​exceed a preset entropy threshold; and extracting attack behavior features and asset vulnerability features from the abnormal time slices; generating corresponding risk profiles based on the attack behavior features and asset vulnerability features; comparing the risk profiles with a preset threat intelligence database to determine attack chains matching the risk profiles; constructing a risk correlation network corresponding to the attack chains; and inputting the risk correlation network into an initial risk trend prediction model for extrapolation. This invention, by determining the relationship between attacks originating from the same source, can establish correlations between multiple attack behavior features, enabling security teams to better understand attackers' attack patterns and thus optimize defense strategies.
Owner:广州云峰信息科技有限公司

Intelligent agent processing method and device and storage medium

PendingCN121967015ASolve technical problems with poor operational stabilityImprove running stabilitySecuring communicationAttackProtection mechanism
The invention discloses an agent processing method and device and a storage medium. Relates to the field of network information security, and the method comprises the steps: carrying out the security test of multiple types of attack behaviors on an intelligent agent, recording the resistance effect of the intelligent agent to each type of attack behaviors, and generating a security capability evaluation report according to the recorded resistance effect; the security capability evaluation report is converted into a protection strategy through a strategy generation engine, and the protection strategy comprises an adjustment defense configuration rule generated according to the resistance score of the intelligent agent to each type of attack behavior, a defense rule generated according to the resistance result of the intelligent agent to each type of attack behavior, and an attack chain coping rule; and filtering the input information according to the protection strategy and the access control strategy, and intercepting the input information which does not meet the protection strategy and the access control strategy so as to protect the intelligent agent. Through the method and the device, the problem of poor operation stability of the intelligent agent caused by insufficient intelligent agent protection mechanism in related technologies is solved.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Network security risk trend multidimensional correlation data analysis prediction method

The present application relates to the technical field of data analysis, in particular to a network security risk trend multi-dimensional correlation data analysis and prediction method, comprising: calculating the behavior entropy value of each time slice data, screening abnormal time slices with a behavior entropy value greater than a preset entropy threshold value from each time slice data, and extracting attack behavior features and asset vulnerability features from the abnormal time slices; generating a corresponding risk portrait based on the attack behavior features and asset vulnerability features, comparing the risk portrait with a preset threat intelligence library, and determining an attack chain matching the risk portrait; and constructing a risk correlation network corresponding to the attack chain, and inputting the risk correlation network into an initial risk trend prediction model for deduction. Under the judgment of homologous attack relationship, the present application can establish the correlation between multiple attack behavior features, so that the security team can better understand the attack pattern of the attacker, thereby optimizing the defense strategy.
Owner:广州云峰信息科技有限公司

Attack means evaluation device, attack means evaluation method, and computer-readable storage medium

An attack method evaluation device (100) evaluates attack methods used for network attacks. A score calculation unit (110) acquires multiple attack methods and calculates a score representing the effectiveness of the attack against the target system for each of the multiple attack methods. A method selection unit (120) uses the score of each of the multiple attack methods and a threshold (173) to select an attack method that is effective against the target system from the multiple attack methods. A method execution unit (130) executes the selected attack method on the target system and determines whether the attack can achieve the ultimate goal of the network attack based on the execution result of the selected attack method.
Owner:MITSUBISHI ELECTRIC CORP

Model-free adaptive control method for motorcade under trust mapping-driven hybrid attack

The invention discloses a model-free adaptive control method for a motorcade under trust mapping-driven hybrid attacks. The method comprises the following steps of: 1, processing a vehicle state and communication characteristics by utilizing a multi-layer perceptron, outputting a continuous trust value, mapping the continuous trust value into a weight factor through a cumulative distribution function, and correcting an expected distance and a control law in real time; 2, designing a distributed control law based on the expected distance and the relative state error, and constructing an equivalent data model based on input and output data under a model-free adaptive control framework; establishing an exponential stability and serial stability criterion by using a functional and linear matrix inequality, and solving a control gain; and 3, realizing real-time robust suppression and smooth recovery of various attacks of false data injection, replay, camouflage and denial of service by cyclically executing the first two steps. According to the method, the speed consistency and the rapid convergence of the spacing error can be realized in a mixed attack environment, and the robustness and the engineering implementation of fleet control are remarkably improved.
Owner:HANGZHOU VOCATIONAL & TECHN COLLEGE

Attack behavior prediction model training method, attack behavior prediction method and related equipment

The embodiment of the invention discloses a training method of an attack behavior prediction model, an attack behavior prediction method and related equipment, and belongs to the technical field of network security processing. The method comprises the following steps: extracting a plurality of attack entities from original alarm information, and determining an attack event between any two attack entities and attack time corresponding to the attack event; inputting a plurality of sample attack sequences determined by the attack entity, the attack event and the attack time into the attack behavior prediction model, and outputting a predicted attack sequence after shielded information in each sample attack sequence is recovered; and determining a sequence loss value according to each predicted attack sequence and the corresponding tag attack sequence, and performing iterative training on the attack behavior prediction model according to the sequence loss value to obtain a trained attack behavior prediction model which is used for predicting the next attack behavior of the generated target attack behavior to obtain a predicted attack behavior. According to the invention, the accuracy of completely predicting all attack behaviors can be improved.
Owner:PENG CHENG LAB

Accuracy in attack technique labeling in an extended detection system

Techniques for providing a confidence rating for an attack technique tag and a guidance for improving the confidence rating are described. An attack technique analytics engine receives telemetry data, a notification that an attack has been detected using an attack detection source, the notification including an attack technique tag indicating an attack technique used in the attack, and attack technique data including a likelihood of a particular attack technique, from among multiple attack techniques, occurring determined using a particular attack detection source from among multiple attack detection sources. Based on the telemetry, the attack technique tag, and the attack technique data, a confidence rating that the attack corresponds to the attack technique is determined. The attack detection source and attack technique are analyzed to determine a guidance for improving the confidence rating, and the rating and guidance are appended to the attack technique tag.
Owner:CISCO TECHNOLOGY INC

Containerization-based unmanned aerial vehicle safety simulation test system and method

The invention relates to the technical field of unmanned aerial vehicle safety and network safety testing, in particular to an unmanned aerial vehicle safety simulation testing system and method based on containerization. The system comprises a container module group which comprises a plurality of modules, the modules are mutually communicated through a virtual network and are used for simulating different function units of an unmanned aerial vehicle system, and the container module group comprises a flight control module, an accompanying calculation module, a ground control module and a simulation environment module; the linkage control module is in communication connection with each module in the container module group, and the linkage control module comprises a flight state management unit and an attack scene library; the flight state management unit is used for managing the execution process of the unmanned aerial vehicle simulation task according to a plurality of predefined continuous flight stages; the attack scene library is provided with a plurality of attack scene modules; and the linkage control module is configured to respond to the current flight stage determined by the flight state management unit, and select and trigger the attack scene module executed in the current flight stage from the attack scene library.
Owner:XIAN UNIV OF POSTS & TELECOMM

Depth code model robustness improving method and system based on code standardization

The invention discloses a depth code model robustness improvement method and system based on code normalization, and the method comprises the steps: recognizing all identifiers in a code through a static program analysis technology, and replacing the identifiers with meaningless placeholders, so as to eliminate potential attack features; on the basis of the context understanding capability of a large language model, semantic reconstruction is carried out on placeholders, meaningful identifier names are generated, and code semantic information is recovered; using standardized training data to perform distribution alignment fine adjustment on the model, and adopting the same preprocessing process in the reasoning stage to ensure input distribution consistency. According to the method, on three code tasks (clone detection, defect prediction and vulnerability detection) and four mainstream models, the average experience robustness of multiple attack methods is improved by 15.4%-126.0%, and the method is superior to an existing defense method under the condition of 87.9% in 33 test scenes.
Owner:TIANJIN UNIV